Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 40 guests online
You are here:
Home
Resources
Career Central
Don't Blow Your Next IT Security Job Interview
EH-Net
May 24, 2013, 09:40:04 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
Career Central
(Moderator:
don
) >
Don't Blow Your Next IT Security Job Interview
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Don't Blow Your Next IT Security Job Interview (Read 8322 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4169
Editor-In-Chief
Don't Blow Your Next IT Security Job Interview
«
on:
May 29, 2009, 12:02:56 PM »
I had a conversation recently with someone in the pen testing field that I had noticed had no problem getting job offers in this horrible economy. When talking to him, you can tell right away, he knows his stuff. And it's not just rote memorization of cert exam answers. Now he doesn't know everything, and he will readily admit it. He is also very willing to learn anything and everything. This kind of attitude and eventual knowledge gain has just kept him climbing the ladder to better and higher paying jobs. So I was wondering what it is that many out there are complaining about. This Eye-opening article by Roger Grimes tells me.
http://www.infoworld.com/d/security-central/dont-blow-your-next-it-security-job-interview-226
Hope it helps,
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
Ants
Newbie
Offline
Posts: 25
Re: Don't Blow Your Next IT Security Job Interview
«
Reply #1 on:
May 29, 2009, 12:33:35 PM »
I find that article slightly depressing. I think that I wouldn't make it as far as the interview stage due to my lack of experience but I could answer all of those questions.
But I guess that I will just continue studying and learning because I find Security fascinating and challenging and I am sure that I will eventually succeed.
Logged
CEH, GPEN, GCFW
impelse
Hero Member
Offline
Posts: 565
Re: Don't Blow Your Next IT Security Job Interview
«
Reply #2 on:
May 29, 2009, 01:23:47 PM »
I liked a lot the article, I prefer to read before begin to pursue a certification, but I always use the certification to get knowledge and go a little deep.
This is the information I am looking for, to tell you the true about the interviews.
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
timmedin
Sr. Member
Offline
Posts: 469
Re: Don't Blow Your Next IT Security Job Interview
«
Reply #3 on:
May 29, 2009, 11:39:10 PM »
The most intelligent and outstanding people I know say "I don't know" more often than most of the other people I know. There is a lot to be said for saying "I don't know, but I know how to find out." There is something to be said about confidence, but if you are wrong you are going to look like an idiot.
Hal Pomeranz (Deer Run Associates and blog.commandlinekungfu.com contributor) wrote a blog post about one of his favorite questions to ask interviewees.
http://blog.commandlinekungfu.com/2009/03/episode-10-finding-names-of-files.html
Most don't know the answer to his question, but knowing where to look for the answer is 90% of the solution.
Logged
twitter.com/timmedin |
http://blog.securitywhole.com
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Don't Blow Your Next IT Security Job Interview
«
Reply #4 on:
May 31, 2009, 06:17:32 AM »
Don, thanks for linking to the article as it's a good read.
I'll second the suggestion of 'Don't know', one of the best bits of advice I was given when starting in the IT field is that one of the best answers to a question (obviously knowing the answer is prefered
) is 'I don't know, but I'll find out and get back to you'. Unfortunately, this doesn't always transistion well in interview situations, I know of an interview were the candidate's answer to every technical question was 'I'd use Google to find out', as far as I know he is still looking for a job...
From an general perspective this could be depressing, but if you know your stuff then look on the brightside, you should be a prime candidate (if you can get your CV past HR....)
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
dalepearson
Sr. Member
Offline
Posts: 357
Re: Don't Blow Your Next IT Security Job Interview
«
Reply #5 on:
June 01, 2009, 03:53:57 AM »
Don,
this is a good article, and sadly I think it does reflect the situation alot of us are in when it comes to hiring, and getting hired.
I have said it many times, but a passion for security is one of the most important things, alot of the rest comes as a by product.
Seems so many of the candidates they speak of lacked this passion, didnt want to learn, etc.
So many people seem to think the job should be given to them as they believe they are super elite. I am a firm believer those that know it, dont need to continually advertise it.
Like Andrew says, the hardest thing is getting your CV past the recruiters and HR departments who dont know there Conf
l
icker either
Logged
:: Subliminal Hacking ::
/
:: Security Active Blog ::
sgt_mjc
Sr. Member
Offline
Posts: 294
Re: Don't Blow Your Next IT Security Job Interview
«
Reply #6 on:
June 01, 2009, 07:30:27 AM »
You know, I agree that getting by the recruiter/hr can be a real pain. However, using your network doesn't hurt any. It does help to know some one where you are looking and that will often get you in the door for that crucial interview.
Take for example, the folks here. Between us, we all know a lot of people and most of would be willing to help some one get started. Look at all the advice available here in this thread alone. And chance are, if one of us doesn't work where you are looking, we might know a some one that does. So my advice, along with all of the above, is to keep plugging away at getting in the door, but also use your network of contacts.
Logged
Mike Conway
CISSP
CompTia Security +
C|EH
dalepearson
Sr. Member
Offline
Posts: 357
Re: Don't Blow Your Next IT Security Job Interview
«
Reply #7 on:
June 01, 2009, 07:34:17 AM »
I agree on using your networking.
However I have also been let down by putting a good work in for a friend of a guy who used to work for me.
He never showed up for the interview, then asked to have another one, and no show again. Its not the end of the world, but its your good name on the line.
Just be mindful.
Logged
:: Subliminal Hacking ::
/
:: Security Active Blog ::
UNIX
Hero Member
Offline
Posts: 1235
Re: Don't Blow Your Next IT Security Job Interview
«
Reply #8 on:
June 02, 2009, 03:23:49 AM »
I read the article now too. I guess it is very important to know at least the theoretical basics of possible attack vendors and some countermeasurse you can start. Often people won't be asked something very specialized as the interviewer wants first to see if the person has at least a general knowledge on the field he is applying for.
In my experience it also often helps to just talk and show that you are very interested and commited to security. When you can show some certificates or projects where you have worked in your spare free-time on it surely will help and will maybe even be the last thing needed to get employed.
Some things mentioned in the article are naturally though such as not bad talking about your former employ or display yourself as an leet hacker. As soon as the interviewer gets the feeling that you are not serious or doubt your legitimate actions you surely won't get the job.
Logged
former33t
Full Member
Offline
Posts: 226
Re: Don't Blow Your Next IT Security Job Interview
«
Reply #9 on:
June 03, 2009, 04:20:29 PM »
Don, good article. I've been there on the hiring side, not in security, but with system administration. I ran into a supposed MCSE that didn't know Windows had default hidden shares for every volume.
timmedin, you are
so
on the money about the people who are willing to admit they don't know something. Amazing how infrequently people fit this bill. Thanks for linking to the article with the find command. I haven't used xargs in some years. I'd have used 'grep -l' if asked.
I do remember having to use xargs in the old Solaris 6 and 7 days when the find that shipped with Solaris sucked so bad it wouldn't interpret some standard switches correctly. Hadn't thought about it in at least two or three years though.
Logged
Certifications: CREA, MCSE: Security, CCNA, Security+, other junk
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.