Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 33 guests online
You are here:
Home
Resources
Career Central
What type of security job would suit my personality?
EH-Net
May 19, 2013, 05:34:00 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
Career Central
(Moderator:
don
) >
What type of security job would suit my personality?
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: What type of security job would suit my personality? (Read 7536 times)
0 Members and 1 Guest are viewing this topic.
Cuddles
Newbie
Offline
Posts: 2
What type of security job would suit my personality?
«
on:
August 11, 2011, 09:14:39 AM »
I'm currently a Linux sys admin who is thinking of getting into security. I spend a good deal of free time "playing" with security concepts because I find them interesting. The problem for me though, is that I can't seem to pick a specialty. I like forensics and find some of it interesting, but there's no way I'd want to do just that full time. I enjoyed the Pentesting with Backtrack/OSCP course and would like to continue to develop these skills, but I'm not certain that I'd want to pentest all day every day. (Or write the reports for that matter). I don't mind researching vulnerabilities, but I wouldn't want a job fuzzing and looking through code for bugs. And so on and so forth.
Is there any type of position that would allow me to be something of a security generalist, playing with all the various realms within security? Would it be better to just focus on a particular field, work in it for a couple of years before moving on to another? Are any fields more capable of handling what I refer to as my "intellectual ADHD" by being more variable and dynamic than others?
«
Last Edit: August 11, 2011, 09:17:54 AM by Cuddles
»
Logged
tturner
Sr. Member
Offline
Posts: 432
Re: What type of security job would suit my personality?
«
Reply #1 on:
August 11, 2011, 10:21:05 AM »
Be the security guy for a small to medium sized organization and that's exactly what you will be doing. In a larger organization you will likely have to specialize.
Logged
Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP
WIP: OSWP, GSSP-JAVA, GXPN
Udacity on hold, again. I suck.
http://sentinel24.com/blog
@tonylturner
http://bsidesorlando.org
chrisj
Hero Member
Offline
Posts: 1163
Re: What type of security job would suit my personality?
«
Reply #2 on:
August 11, 2011, 10:25:15 AM »
Maybe I'll get flamed for this, but what's wrong with Security Defense with a side of Incident Response?
Here's my thinking: Leverage the position you have as a system admin, and start tossing up some monitoring tools. Get centralized log servers, with automated scripts parsing the logs and emailing you the information you need. Set up a couple of packet capture devices on the network. My favorite was my linux box with wireshark connected to a span port watching all the internal traffic going out to the internet.
Use your pentest skills against those boxes. If you have company buy off on the monitoring systems, and you maintain them, you can test them. My argument was, these boxes capture all the data in the company, you don't want some random person to come along and abuse internal secrets.
On occasion, get a snapshot or other copy of a box in production, virtualize the copy, and then test against that. (Use the forensic skills to get a clean copy). Don't just try to pen-test it, do a full review of the copy to make sure it's not been popped.
The above was kind of what I was doing at my last job.
"Oh the network is slow? Hang on..." 30 minutes later "Network is slow because you have 15 people listening to Pandora, 5 watching the Laker's game from last night, 1 person torrenting something, and about 40 people on Youtube. Plus a bunch of traffic going to the old 172.31 network because the Help Desk hasn't finished re-imaging, and the traffic is looping between us and the network provider and the edge system at the datacenter." < true story.
Logged
OSWP, Sec+
chrisj
Hero Member
Offline
Posts: 1163
Re: What type of security job would suit my personality?
«
Reply #3 on:
August 11, 2011, 10:26:38 AM »
Quote from: tturner on August 11, 2011, 10:21:05 AM
Be the security guy for a small to medium sized organization and that's exactly what you will be doing. In a larger organization you will likely have to specialize.
The problem is convincing the company they need you. Small to medium company, why do we need a security person, no one will want to attack us. (was the guy at a small company, mainly I got to do security because I had nothing else to do, and they didn't like it).
Logged
OSWP, Sec+
lorddicranius
Sr. Member
Offline
Posts: 447
Re: What type of security job would suit my personality?
«
Reply #4 on:
August 11, 2011, 10:49:15 AM »
Quote from: chrisj on August 11, 2011, 10:26:38 AM
Quote from: tturner on August 11, 2011, 10:21:05 AM
Be the security guy for a small to medium sized organization and that's exactly what you will be doing. In a larger organization you will likely have to specialize.
The problem is convincing the company they need you. Small to medium company, why do we need a security person, no one will want to attack us. (was the guy at a small company, mainly I got to do security because I had nothing else to do, and they didn't like it).
This is
exactly
my problem at my current position. Because the company is so small, they don't see a need for security.
Logged
GSEC, eCPPT, Sec+
WCNA
Full Member
Offline
Posts: 187
Re: What type of security job would suit my personality?
«
Reply #5 on:
August 11, 2011, 11:58:32 AM »
Quote
Would it be better to just focus on a particular field, work in it for a couple of years before moving on to another?
How about this for a completely unexpected answer?
It doesn't matter.
If you are anything like me (and I expect there are a lot of people here like me), no job will ever satisfy you. I'm an information junkie and a person that loves to learn. Once I've mastered a skill, I usually get bored and move on to something else. Recently, I've been racking up certs (4 in the last year). Before that, even though my job is in IT, I went off on a completely different tangent- macroeconomics (due to the crash and recession).
Before I was in IT, I was a telecom tech....topped out in that field in 3 years and moved to IT. Before that was a
bunch
of different professions. I'm in my 50's now and I have realized that no one job will ever satisfy me. At least with computer technology there is always something new right around the corner.
http://www.ted.com/talks/harald_haas_wireless_data_from_every_light_bulb.html
I took some of those psychological career path tests you see online once and found them completely useless. So my suggestion is go just with your gut and see where it takes you. Only
you
know what suits you best. And if it doesn't work out then move on. One day you may find out that you're like me and that the journey is the best part of life.
Logged
ISC2 Associate, WCNA, CWNA, OSCP, Network+
3xban
Hero Member
Offline
Posts: 605
Re: What type of security job would suit my personality?
«
Reply #6 on:
August 11, 2011, 12:12:52 PM »
The thing I like about Info Sec is that there are so many avenues of interesting topics and skills to persue. This is also the thing I hate most. My biggest problem is focus. I will be concentrating on one thing and then I come across something that leads me to branch off it and next thing I know I spent two days working that problem and almost completely forgot what I was working on.
This time around I am in an Incident Respons position, but more on the investigative side. Right now I am stuck looking at logs and answering to the mothership when they magically spot something and then it magically appears. My old position I was a generalist, Security Admin and the responsibilities ranged from patching and AV to network configurations, firewall rule modifcations and a few other duties tossed in for good measure.
Now I have settled on working on malware analysis, I find it interesting to know how some of these annoying little programs do their dirty work. Hopefully I will focus on this for a while and in between things I will work on pentesting skills.
But I would agree the best thing to do is get into a position where you are THE security guy for a SMB. After you have the ability to play with everything then maybe you will find that one area that you excel in. Good luck!!
Logged
Certs: GCWN
(@)Dewser
Cuddles
Newbie
Offline
Posts: 2
Re: What type of security job would suit my personality?
«
Reply #7 on:
August 11, 2011, 03:38:52 PM »
Thanks for the responses. There's a lot of good stuff here for me to consider.
Unfortunately, this response is probably going to be the closest to the mark:
Quote from: WCNA on August 11, 2011, 11:58:32 AM
It doesn't matter.
If you are anything like me (and I expect there are a lot of people here like me), no job will ever satisfy you.
Logged
chrisj
Hero Member
Offline
Posts: 1163
Re: What type of security job would suit my personality?
«
Reply #8 on:
August 11, 2011, 09:01:43 PM »
Quote from: Cuddles on August 11, 2011, 03:38:52 PM
Thanks for the responses. There's a lot of good stuff here for me to consider.
Unfortunately, this response is probably going to be the closest to the mark:
Quote from: WCNA on August 11, 2011, 11:58:32 AM
It doesn't matter.
If you are anything like me (and I expect there are a lot of people here like me), no job will ever satisfy you.
I used to feel that way a long time ago. But I also learned a long time a go (not as long though), its not the work that fulfills, and thus satisfies you, it's what we do that is. Meaning the sum of our work.
I worked for a publishing company, focused on the MBAs, and other Master and higher classes. I felt like my work had no meaning, didn't make a difference in the grand scheme of things. Now, the people I work for, I spend most of my time setting up VPNs between Health Information Exchanges, hospitals, labs, and doctor offices so patient data can transfer around faster in a more secure manner. I actually feel like what I'm doing might help someone get treated faster or better. It's work below me, but I think this is the happiest I've been working in a long time.
Logged
OSWP, Sec+
impelse
Hero Member
Offline
Posts: 563
Re: What type of security job would suit my personality?
«
Reply #9 on:
August 11, 2011, 10:28:07 PM »
I used to work in a company that they said that they were very small so secuirty was not important. I did not care.
I learnt a little bit nmap and metasploit so I begin to scan every server and machine I was working on. Later begin to turn on firewall in the machine and closed ports that we did not need, at the same time I was working with my Microsoft exams, everything begin to make sence.
I moved to another company (IT provider) and now all the experiments I did a basic testing give me more confidents and when we got a problem like a phone/server sistem is hacked or is working very bad they send me...... It is a way to learn and open doors.
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(6) by
Grendel
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.