Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 47 guests and 4 members online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
General Certification
What is it like being an ethical hacker?
EH-Net
May 20, 2013, 01:54:21 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
General Certification
(Moderator:
don
) >
What is it like being an ethical hacker?
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: What is it like being an ethical hacker? (Read 4302 times)
0 Members and 1 Guest are viewing this topic.
Hacks McSpack
Newbie
Offline
Posts: 3
What is it like being an ethical hacker?
«
on:
July 06, 2010, 11:18:39 AM »
Hello all.
I'm pondering on my career in the future, and an ethical hacker is a career I am interested in.
I’ve currently in college (I live in the UK), one of my courses is an A level in ICT. I will also be hoping to start university in 2011.
I have some questions about ethical hacking careers that I would like answering, if you don’t mind?
What is the role and responsibilities of an ethical hacker?
I don’t want to seem rude in asking, but what is the money like? I’ve seen jobs for ethical hackers and information risk consultant (which i believe is another term for ethical hacker?), with the salary to be around £50k-£70k a year. Is this true for most jobs?
Where do you work? This may seem like a weird question, but, do you have a permanent place of work, or do you work nearby to your employer? Like, if a bank asks you to test their system, would you work in a nearby cafe on a laptop?
Thank you for taking the time to read this, and hopefully answering my questions.
Logged
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: What is it like being an ethical hacker?
«
Reply #1 on:
July 06, 2010, 11:53:57 AM »
Where to start? The women? The money? The fame?
While an information risk consultant might do some ethical hacking, I would expect that role to be focused mostly on risk management. Terminology varies quite a bit in this industry though, so review the responsibilities/qualifications for such a role. "Penetration tester" is the title that's most synonymous with ethical hacker. My official title is "Information Security Analyst," but I also do more than just penetration testing.
Money ranges based on skill. I know some people that make six figures while some of the unskilled newbies we mold right of college make help-desk wages.
I do remote work (i.e. external penetration test) out of our office, and I regularly go on-site (2-3 weeks per month) for the variety of on-site services we perform. I have friends at different companies and they do remote work from home and also go on-site. I wouldn't expect anyone to work professionally from a coffee shop or other semi-public network as there would likely be legal risks involved with that.
As far as the work itself goes, once a penetration test is assigned to me, I work with the client to verify IP address ranges, setup scheduling, address any special needs, etc. Once we're all squared away, the actual testing begins with information gathering, mapping, and so on. Upon completion of the test, I write a detailed report explaining the issues found, what the consequences were, and provide general direction for remediation. This last part is where I see a lot of people struggle and become unhappy. It's definitely not fun, but it's a necessary evil for a quality test. I spend a significant portion of my time writing reports, so be sure you're able/willing to handle that aspect of the job as well.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
Hacks McSpack
Newbie
Offline
Posts: 3
Re: What is it like being an ethical hacker?
«
Reply #2 on:
July 06, 2010, 12:37:56 PM »
Hey, thanks for the reply.
So, an "Information risk consultant" asses risks and how they can be avoided, and "Information Security analyst" is someone who tries to hack into a system?
For the work itself, thanks for saying your roles and responsibilities.
It seems quite an interesting job. Everyday a new challenge.
And as for the reports, I do not mind doing them at all.
Once you have gained the qualifications of ethical hacking from university, is it hard to get your first job? And is it easy to pick up on what you need to do? Like, as if you were just doing what you were taught in university? Or is it a step up from that? (if that makes sense?).
Logged
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: What is it like being an ethical hacker?
«
Reply #3 on:
July 06, 2010, 12:50:04 PM »
Quote from: Hacks McSpack on July 06, 2010, 12:37:56 PM
Hey, thanks for the reply.
Anytime! Welcome to the forums, btw
Quote from: Hacks McSpack on July 06, 2010, 12:37:56 PM
So, an "Information risk consultant" asses risks and how they can be avoided, and "Information Security analyst" is someone who tries to hack into a system?
Like I said, titles are all over the place and are not consistent at all. I wouldn't necessarily define an Information Security Analyst that way. I also do risk assessments, IT audits, social engineering, and security awareness training. Penetration tester is just one of the hats I wear.
Quote from: Hacks McSpack on July 06, 2010, 12:37:56 PM
Once you have gained the qualifications of ethical hacking from university, is it hard to get your first job? And is it easy to pick up on what you need to do? Like, as if you were just doing what you were taught in university? Or is it a step up from that? (if that makes sense?).
It's usually pretty difficult to go right into a security role. IMHO, you end up selling yourself a bit short even if you can manage it. You'll more than likely have to get started doing systems and/or network administration and work you way into the security side of things from there. As always, you can't secure what you don't understand.
I would say it's a leap up from anything you'd do in school. I spend hours a day outside of work just trying to keep current and learn things I feel I'm weak in. You really have to enjoy learning and working with this type of stuff as a hobby to really take things to the next level.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
Hacks McSpack
Newbie
Offline
Posts: 3
Re: What is it like being an ethical hacker?
«
Reply #4 on:
July 06, 2010, 06:11:27 PM »
Would you say it's a good career to get into?
What are the pro's and cons of it?
Logged
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: What is it like being an ethical hacker?
«
Reply #5 on:
July 07, 2010, 06:11:44 PM »
Quote from: Hacks McSpack on July 06, 2010, 06:11:27 PM
Would you say it's a good career to get into?
It really depends on the person. I think it's great for me. YMMV.
As far as jobs go, this field seems to be increasingly more popular. It seems like it will stay that way for the foreseeable future.
Quote from: Hacks McSpack on July 06, 2010, 06:11:27 PM
What are the pro's and cons of it?
Like I mentioned before, you really need to be passionate about the material and enjoy working with it. If it's just appealing because you're after a big check or it seems exotic, you're not going to last. It's going to take a lot of time outside of business hours. I would wager that most of us are ok with that because we also consider it to be a hobby.
I also see others get frustrated and quit because they're not willing to put in the time mastering the fundamentals and want to do exciting work right off the bat. Like I said, you'll more than likely have to put in some time as a systems and/or network administrator. You're only going to be able to do a half-assed job (at best) if you don't develop a solid understanding of TCP/IP first.
What appeals to me is the fact that things are constantly changing, and I'm constantly learning. As you can see, what may be considered a con to some people is a pro to me. That's why the answer to a lot of your questions are going to be, "it depends." I enjoy doing challenging work and having to think critically. Some want a job that's slower-paced with less pressure. I think you get the idea...
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
Re: What is it like being an ethical hacker?
«
Reply #6 on:
July 09, 2010, 11:45:30 AM »
I covered a lot of those questions in my talk on DIY Career in Ethical Hacking. There's a PG and an R rated version. You can find them as well as some pretty extensive reviews of CEH, CISSP and GPEN. They will give you a great idea of what they cover and what possible career paths you can get from them. Look here:
http://www.ethicalhacker.net/content/category/7/15/24/
Hope it helps,
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(91) by
r0ckm4n
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.