How to get into what we used to do...
Time for a lesson - Image by Freepik

How to get into what we used to do...

This is a quick post I co-wrote with Indy Neogy, with insightful advice on how to make the kind of career moves we made:


I am Nick Drage , an experienced Cyber Security Consultant, with great advice about getting into the Penetration Testering profession:

  • Make the most of your connections. Interpersonal relationships are the best way to hear about new positions, you might even be able to apply for them before they’re public.
  • Don’t worry about qualifications, there’s relatively few people looking for this kind of work, and qualifications are few and far between. The ability to learn is more important than what you know now.
  • Penetration testing employers and internal teams will be able to give you time to learn, so don’t worry if your individual abilities aren’t “joined up” yet.
  • The work is relatively solitary, or in small teams, so while your inter-personal skills are useful they’re not something employers seek, and they’re not really something you can demonstrate.
  • The entire field of knowledge is relatively small, so you’ll be able to enter as a generalist, and remain a generalist - or at least maintain several specialisms simultaneously.

I’m Indy Neogy , and from having a consulting firm, this is how I got into university teaching:

  • Build up some specialist knowledge and crucially practical experience, that relates to a field students learn about, in my case intercultural communication.?
  • Get to know some people who work in the area and then meet some of the ones who do some teaching as well, probably via the professional bodies for the field.
  • Have some kind of related qualification - in my case Masters level helps, but full qualifications are not essential. It doesn’t need to be directly related, mine wasn’t.
  • Show the desire to teach. You don’t need to become a full-blown academic, research doesn’t have to be your thing. There are places where teaching is the priority. So long as you are happy to learn new things as well as what you already know and read around so you aren’t left behind by new developments.
  • Some institutions will be happy to help you learn on the job and support your development as a teacher.


Also the other thing you’ll need is Time Travel. Our advice is based on our experience, which is based on our relative situations ten to twenty years ago.

A CGI rendition of the time machine from Jules Verne's book... well, of the film of the book.
Picture courtesey of Pixabay, you can probably find some plans online to help you build it too.

Do you have a time travel machine? You don’t? Then the main take-away from this piece is to be mindful of what time period the advice you read applies to. If well-meaning veterans are telling you what worked for them, their experience is probably out of date.


For penetration testing, while the security community is still important, penetration testing qualifications are far more important for entry level positions now than they were for Nick.

For university level teaching, while practical knowledge can still get you a foot in the door at times, a PhD and research portfolio have become more and more common requirements even at institutions that used to emphasise teaching.

So the one point you should take from us is that, when looking for advice on how to get into an industry, don’t speak to the “seasoned veterans”, speak to the people with slightly more experience than you.


Among other roles, Nick is now a Cyber Security Strategist, do contact him if you want a sounding board for thinking about your bigger decisions in the cyber domain. Or if you want to discuss about how to use professional wargames for decision rehearsal.


Among other roles/skills, Indy is now a Executive Coach, do contact him if you want to improve your strategic mindset. He is also available to teach intercultural communication and international business.

The time travel observations are helpful to keep in mind. Authentic networking is key - many of my positions came from being asked to do them.

回复

要查看或添加评论,请登录

Nick Drage的更多文章

  • The Friend Device - it raises so many questions.

    The Friend Device - it raises so many questions.

    With the very recent announcement of the release of the Friend device we had a quick discussion in the Path Dependence…

    5 条评论
  • If you're trying to do too much, just do less.

    If you're trying to do too much, just do less.

    Often a post of article on LinkedIn, or similar sites, will explain - quite rightly - that sometimes it's good to focus…

    7 条评论
  • What can the "Brotherly Shove" teach us about strategic response?

    What can the "Brotherly Shove" teach us about strategic response?

    Strategic response is a fancy phrase for “the situation has changed, how do you respond?” Every one of us that has…

    5 条评论
  • Resources for Generalists - The "Range-o-Verse"

    Resources for Generalists - The "Range-o-Verse"

    After a recent conversation around what being a "generalist" is, what it means, and how to use that in the job market -…

    50 条评论
  • Don't react to this article, unless you really like notifications.

    Don't react to this article, unless you really like notifications.

    How often can you edit an article on LinkedIn? I started writing something in public but it didn't get that much…

  • Startup Security Strategy

    Startup Security Strategy

    On making decisions and foreseeing consequences You’ve a killer concept and the passion to take it far. You’ve done…

    1 条评论
  • On Planning the Destruction of the Rebel Alliance

    On Planning the Destruction of the Rebel Alliance

    Last week, as part of the Connections Online conference, I look part in a "Red Teaming Workshop". For this exercise we…

    8 条评论
  • Strategies for a VUCA World - Part 1 - Is VUCA bearing down on you?

    Strategies for a VUCA World - Part 1 - Is VUCA bearing down on you?

    Speculative fiction author William Gibson is famous for saying "The future is already here – it's just not evenly…

    6 条评论
  • How Can We Help Each Other?

    How Can We Help Each Other?

    How Can We Help Each Other? What’s your preferred working situation - completely alone and self-driven? As half of a…

    6 条评论
  • Do You Have A Resilience Strategy?

    Do You Have A Resilience Strategy?

    In light of recent outages in cloud services, such as AWS and Insteon, it’s time to plan how your organisation would…

    3 条评论

社区洞察

其他会员也浏览了