Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 33 guests and 1 member online
You are here:
Home
Resources
Career Central
I think the bar is dropping...
EH-Net
May 19, 2013, 10:53:53 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
Career Central
(Moderator:
don
) >
I think the bar is dropping...
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: I think the bar is dropping... (Read 746 times)
0 Members and 1 Guest are viewing this topic.
3xban
Hero Member
Offline
Posts: 605
I think the bar is dropping...
«
on:
March 21, 2013, 07:38:57 PM »
I learned a long time ago that you should always keep your options open. So naturally I always keep my resume updated and for the most part available on the job boards. Over the last year or so I've gotten a number of calls/emails for various security jobs. I would say many are contract based but there were a good number that were full time, only on the other side of the country. So it is safe to say, there are many jobs out there for Information Security pros ("you're welcome" - Capt. Obvious). When I made my way over to this career from the general IT Infrastructure realm, I always figured I would stay on the defensive side. I never considered I would have the skill to be a full time pen-tester, though I do enjoy the feeling of the challenge. I always figured I was better tooled for defense.
Then I had a phone interview with a local security firm. The admin who contacted me didn't mention anything about the job she was contacting me for. I asked, she still didn't say. The fact that this particular firm was calling me was enough to peak my interest. So I had the interview, honestly as phone interviews go, it went pretty good. We had a good conversation and even after telling them I wasn't interested in the commute, they still tried to pull me in. Now the job was for pen/vuln testing, again told them I wasn't really looking for that type of position, but they persisted. So they gave me their "technical" interview. It consisted some questions about Nessus which apparently required me to just know how to use it. I then proceeded to tell them a story of a recent assessment I did at work and mentioned SQLi. They asked me about that. So I mentioned about inputting javascript/SQL code into form fields to see if it returns data and that was apparently enough for them to consider me worth pursuing. Mind you I only know of the process of how these things are carried out and how to protect a site against them. So the call went on with them asking how far I was from another city and that they were thinking of opening an office roughly 30 minutes from me. They even suggested I still come in to meet them and such. Figured they get the hint that I wasn't interested. Then I get a call the following week to schedule an in-house interview. I declined and apologized if I lead them to believe I was interested (even though I said I wasn't on the original call).
Could I have done the work? Don't know, I imagine if I made it my focus, I probably could. Is it something I would like doing? At this time probably more than what I am currently doing, but not for an almost 2 hour commute along with regular travel around the country. Just thought I would share. There is plenty of work to be had out there. The population of skilled InfoSec pros is growing, but not as fast as the job openings. If you have "security" anywhere in your resume, you will most likely get a call from some outsourced recruiter or a company who doesn't really know what they want but someone says they need a security guy. Anyway sorry for the book, but figured I'd share the story.
Good luck out there!
Logged
Certs: GCWN
(@)Dewser
Grendel
Full Member
Offline
Posts: 241
Re: I think the bar is dropping...
«
Reply #1 on:
March 21, 2013, 09:47:45 PM »
Thanks for posting this - I have a lot of students / inquiries that wonder if there are jobs in this field. I think they don't believe me that there are that many opportunities, or they think I sound too Pollyannic.
I've even seen job requests come to the university that say "no experience needed... we will teach them what they need to do" for pentesting. That's amazing, if you ask me.
Anyway, again, thanks for sharing... 3xban is correct, the jobs are out there.
Logged
- Thomas Wilhelm, MSCS MSM
ISSMP CISSP SCSECA SCNA IEM
Web Site:
http://HackingDojo.com
Author:
Professional Penetration Testing
Ninja Hacking
Penetration Tester's Open Source Toolkit
Metasploit Toolkit for Penetration Testing
Netcat Power Tools
impelse
Hero Member
Offline
Posts: 564
Re: I think the bar is dropping...
«
Reply #2 on:
March 22, 2013, 12:13:30 AM »
In my area a saw a lot of security analyst jobs, if I compare tot he last year it grew a lot.
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
alucian
Full Member
Offline
Posts: 225
Re: I think the bar is dropping...
«
Reply #3 on:
March 22, 2013, 07:38:10 AM »
Thanks for the story.
I believe that the average quality of security pros is not increasing. The problem is that they just don't keep the peace witht the advances in the field. I know is hard, and I know that it requires a lot of effort, but the ones passionate about this will pay the price.
I am just looking arround me and... things are not that good.
I don't want to go into details, not now.
I love this forum
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: I think the bar is dropping...
«
Reply #4 on:
March 22, 2013, 05:42:26 PM »
The problem with a lot of offensive positions is that you often have to be willing to relocate and/or travel. We've struggled filling the couple positions we've opened over the last year, and I know many other organizations are having the difficulty. MaXe literally moved halfway around the world for the gig he's at now. Working out the logistics may be more challenging than actually finding a position.
«
Last Edit: March 23, 2013, 01:54:57 AM by ajohnson
»
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
impelse
Hero Member
Offline
Posts: 564
Re: I think the bar is dropping...
«
Reply #5 on:
March 22, 2013, 05:47:12 PM »
Quote from: ajohnson on March 22, 2013, 05:42:26 PM
The probably with a lot of offensive positions is that you often have to be willing to relocate and/or travel. We've struggled filling the couple positions we've opened over the last year, and I know many other organizations are having the difficulty. MaXe literally moved halfway around the world for the gig he's at now. Working out the logistics may be more challenging than actually finding a position.
I notice that, I just saw one that it is talking about 50% travel. My job was 90% travel (around the city). Normally when I see a job with travel I always think between states.
What about the telecommute, doesn't work for you guys?
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
3xban
Hero Member
Offline
Posts: 605
Re: I think the bar is dropping...
«
Reply #6 on:
March 22, 2013, 08:43:50 PM »
I think at this point the demand is so high that companies are moving away from trying to find the expert to looking for someone with the ability to become the expert. The experts are all hired and hopefully happy. But there are plenty of new guys out there just aching for a chance to get into the field. I think the biggest thing teachers like Grendel can do is emphasize the learning doesn't stop and the employer may not always be willing to send you off to the $4K SANS course. Like any career if you want to succeed you need to work at it on and off hours. A friend of mine tells me I need to unplug but I don't think he quite gets the fact that when I come home and fire up the lab, that is me unplugging. I can't do somethings I want to do at work, so I do them in the home lab. It also is me educating myself on what is new out there in the world of InfoSec. I will say that the actual unplugging is me grabbing the camera and the hiking boots to head off into the hills for some fresh air. I tend to appreciate that more when I've spent the week working and learning, the brain needs to switch gears every so often.
Also for those of you with students, one more thing to recommend... If they want to find opportunities, they need to get out there and network. Go to the local security groups (ISSA, Hackerspaces, etc...). Get to events like B-Sides and even venture into local user groups for like Linux or OWASP. Not only will they have the opportunity to learn something or even teach something, they will get to know some people in their area. Another suggestion is to work your way to doing a talk. It gets your name out there and hopefully shows people you know a thing or two about something. The same friend of mine that tells me to unplug also tells me I should do a talk. Though I still have no idea what it would be about.
Anyway glad I sparked some discussion. Oh and on the topic of Telecommuting, I have a total of 2 hours of driving a day for my job. So luckily my current position allows for me to either work from home or work from our SOC which is much closer than my office. I think the idea of telecommuting is great but I also thing face time in the office is also important. There are somethings that are best collaborated on in person.
Logged
Certs: GCWN
(@)Dewser
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(85) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.