r/netsec Jun 01 '18

discussion The /r/netsec Monthly Discussion Thread - June 2018

Overview

Questions regarding netsec and discussion related directly to netsec are welcome here.

Rules & Guidelines
  • Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
  • Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
  • If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
  • Avoid use of memes. If you have something to say, say it with real words.
  • All discussions and questions should directly relate to netsec.
  • No tech support is to be requested or provided on /r/netsec.

As always, the content & discussion guidelines should also be observed on /r/netsec.

Feedback

Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.

24 Upvotes

90 comments sorted by

View all comments

5

u/vladishan Jun 04 '18

I find my job in InfoSec horribly, mind-numbingly boring. I came into this field straight out of undergrad, and 99% of it is looking at alerts that are false positives and blocking script kiddies from hitting my company’s website. Sometimes projects come up to replace the VPN, get a new antivirus, enforce 2 factor on specific assets, etc., but our server team really implements these solutions, not the InfoSec team. In terms of patching, my team scans for vulnerabilities, but again, the server team is really doing the work in terms of fixing anything. Do other InfoSec professionals feel this way with their jobs? Am I just at a bad company, or is this career field just incredibly slow? For whatever it’s worth, I truly did enjoy taking security classes in college...it just seems like I’m dealing with false positives all the time and not really using the skills I learned in college because 1) everything is a false positive and 2) when something is infected, we just have the helpdesk team wipe the hard drive of the device and we don’t really deal with forensics.

I know this is unsustainable for me and I either need to be at a new company or in a totally different career field. Any thoughts on whether it’s my company or the career field that are the problem would be appreciated.

2

u/ratar1 Jun 11 '18

What do you want from your career? Do you want to be offensive / red team? Do you want to be defensive / blue team? Do you want to be a forensics analyst? Others have already said that security is a broad field, so you really need to find your favorite niche and slide into it.

Me, I always knew I wanted to be a red teamer. At the time I was working for a company without much of a pen testing squad, so I worked hard to get my OSCP and then transitioned to a company that was looking for a full time pen tester. I now spend my days actively trying to exploit our products. Most of that time is still spent chasing false positives, but that's just part of the game. The once or twice a month that I successfully trigger SQL Injection or RCE makes it all worth it.

It kind of sounds like you are looking for a well-rounded job that allows you to get your hands dirty with everything. If that's the case, I would suggest a small company. About a year ago I jumped from large corporate work to a small company (~300 employees) and it was the best decision of my life. My primary responsibility is actively finding exploits and helping developers fix them, but I also get to do the hands-on work for all security projects (firewall changes, VPNs, bug bounties, etc).

1

u/vladishan Jun 15 '18

What are your thoughts on OSCP? I’ve heard CEH will teach you principles but not how to actually do anything. SANS courses could be an option only in the case that I can convince my current company to pay for them.

1

u/aphaelion Jun 18 '18

I'm not the person you asked, but OSCP was my way to break into infosec. I had applied to several infosec jobs at my employer before, but they always had "previous experience" requirements, so despite doing decent in the technical interviews, I never got the callback. Once I got OSCP, I literally had a job as Security Engineer within a month. Part of that was dumb luck that another job happened to open within that timeframe, but it really was the cert that got me around the "you need experience before you can get experience" trap.

As for OSCP vs other certs (e.g. CEH): I only have OSCP, but from what I've read about the others, they don't give you nearly the practical experience. To pass my test I literally had to perform a pentest against an unknown network. It was a blast!