Post

Cyber Security Career Notes

Cyber Security Career Notes

The below notes encompasses career-related notes, management and operational notes in Cyber security.

Career

Cyber Security RoadMap

Below are the basics to get started in Cyber security
Networking Basics

1
2
3
TCP/IP
How the web works
Understanding routers, switches, firewalls and IDS/IPS

Operating system basics

1
2
Linux: Most importantly the file system structure and terminal usage
Windows: Most importantly understanding the Registry, Task Manager, Startups and the file system structure

Programming

1
2
3
Python: At least be able to read and interpret code. Necessary for web application penetration testing, interpreting exploits and creating scripts 
Javascript: At least be able to read and interpret code. Necessary for web application penetration testing

Basic Hacking Concepts

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
Phishing attacks
DDOS attacks 
Cryptography
Password cracking
MITIM
Social Engineering
Web Application hacking
Physical security
Malware analysis
Digital forensics
OSINT
Car hacking
Mobile hacking
IoT hacking
Database Hacking
Cloud Hacking
```bash
## Before You Get Hired

### Jobs to seek before you get into cybersecurity

```bash
- IT Help Desk
- Network Admin
- System Admin
- Network Engineer
- Devops
- Developer ( web or software)
```bash
### Recommended Certifications

Starting in Cyber as an entry level

  • GIAC Information Security Fundamentals (GISF)
  • GIAC Security Essentials (GSEC)
  • COMPTIA SEC+
  • SSCP ```bash Starting in Pentesting
1
2
3
4
5
6
7
8
- COMPTIA Pentest+
- eLearnSecurity Junior Penetration Tester
- OSCP
- eLearnSecurity Certified Professional Penetration Tester
- GIAC Penetration Tester (GPEN)
```bash
Advancing in Pentesting

  • OSEP
  • GIAC Exploit Researcher and Advanced Penetration Tester
  • GIAC Web Application Penetration Tester
  • GIAC Cloud Penetration Tester
  • GIAC Assessing and Auditing Wireless Networks
  • eLearnSecurity Certified Penetration Tester eXtreme
  • OSWP
  • eLearnSecurity Web Application Penetration Tester
  • eLearnSecurity Web Application Penetration Tester eXtreme ```bash Starting in SOC and Blue team
1
2
3
4
5
6
7
8
9
10
11
12
13
14
- CSX-P
- GIAC Certified Enterprise Defender (GCED)
- Cisco CCNA Cyber ops
- COMPTIA Cyber Security Analyst
- IBM Cyber Security Analyst
- GIAC Certified Intrusion Analyst (GCIA)
- GIAC Security Operations Certified (GSOC)
- GIAC Open Source Intelligence (GOSI)
- GIAC Certified Detection Analyst (GCDA)
- eLearnSecurity Certified Incident Responder
- eLearnSecurity Network Defense Professional
```bash
Threat Hunting and Intelligence

  • eLearnSecurity’s Certified Threat Hunting Professional
  • GIAC Cyber Threat Intelligence (GCTI) ```bash Computer Forensics
1
2
3
4
5
6
7
- eLearnSecurity Certified Digital Forensics Professional
- EC-Council CHFI
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Network Forensic Analyst (GNFA)
```bash
Reverse Engineering, Exploit Development and Malware Analysis

  • eLearnSecurity Certified Reverse Engineer
  • eLearnSecurity Certified eXploit Developer
  • eLearnSecurity’s eLearnSecurity Certified Malware Analysis Professional
  • GIAC Reverse Engineering Malware (GREM)
  • GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) ```bash Auditing and Compliance
1
2
3
4
5
6
- CISA
- CDPSE
- COBIT certifications suite from ISACA
```bash
Management

  • CISM
  • CISSP
  • CRISC
  • CGEIT
  • COMPTIA Advanced Security Practitioner
  • GIAC Strategic Planning, Policy, and Leadership (GSTRT)
  • GIAC Security Leadership (GSLC) ```bash

    Cyber Security Roles

SOC Analyst

What does it look like?

1
2
3
4
- SOC analysts are divided into three tiers: L1,L2,L3
- Tier one deals with the initial investigation of an event. They decide whether an event qualifies as an incident and if so escalate it to Tier two analysts otherwise they drop it as false positive.

- Tier two and tiere 3 analysts do the thourough investigation on the incident.These folks mainly are specialized in forensics, reversing  and network analysis.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
- As an independent SOC, you will have to know how to discover Indicators of compromise when analyzing malicious files/URLs and add them to the IPS and other security tools.

- Proficiency in using Splunk, PaloAlto firewall, Cisco ASA,Fortinet, Crowdstrike,sentinel,etc.
```bash
#### Security Engineer

##### Roles

```bash
- Owns the overall security of an organization. The main person responsible for securing an organization's digital assets.
- Ensures that the organization's cyber security risk is minimized at all times.
- Devises strategies and creates systems that minimize the risk posed by cyber security threats to an organization.
- Periodically conducts tests to ensure the robustness of the cyber security posture of an organization, identifies weak points, and prepares mitigations.
- Develops and implements secure network solutions.  
- Architects and engineers trustworthy, reliable, and secure systems.
- Collaborates and coordinates with other teams to establish security protocols across the organization
```bash
##### Required Qualifications

  • 0-2 years of experience with IT administration, helpdesk, networks or security operations.
  • Basic understanding of computer networks, operating systems, and programming.
  • Basic understanding of security concepts such as Governance, Risk and Compliance (GRC). ```bash

    FAQs

Why it’s becoming hard to get hired.

1
2
- There are saturation currently in the entry level jobs.
- Large chunk of companies are getting started to form a cyber security department hence they need an expert to start constituting the department.

What to do about it
The below are not to be followed in order. You can consider them as recommendations to check according to your situation.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
- Get hands on certifications. As a start, OSCP or COMPTIA Pentest+ for the offnesive side and COMPTIA Sec+ for the defensive side.

- Look for job openings that ask for intermediate or expert level job

- You may try getting an IT job at the beginning. Having experience in IT helps tremendously when you shift into cyber security.

- BS in computer science or engineering helps also tremendously but not obligatory if you have IT experience and certifications in security.

- Don't apply for entry level jobs if you got master degree or have certifications because you will be seen as overqualified. On the contrary, if you want an entry level position, make your CV reflects that.

- Internship helps in getting a position since many internships turn into actual jobs.

- Bear in mind that experience even in IT, networking, devops,etc is more preferable than a fresh graduate in cyber security.

- Join cyber security expos/ job fairs / conferences and other events. Apart from the knowledge, it builds your network.

- Having practical projects is also helpful. This includes starting a blog, YouTube channel, collaboration work,etc.

- Doing CTFs and proven record on sites such as tryhackme and hackthebox would help. Connecting and helping other fellow members of these sites would also help.

What advice can be given to a beginner who wants to get hired in cybersecurity?
Look at job postings create a résumé that mirrors what
they are asking for if you already have the skills (Maybe a resume for every job posting you apply to). If you don’t have the skills, I recommend using your free time to learn those missing skills by reading,
using open source software, and consuming any free training you can find. Even if you don’t have the necessary degree, years of experience, or certifications, there is still hope. Don’t limit yourself and think that you aren’t good enough for a job based solely on those requirements. If you believe that you have the skills to do a job, you should always apply.

Focusing on security is good, but having a well-rounded skill set will make you a
better security professional in the long run.

Another way to gain expertise is to teach others or speak at conferences. Preparing talks, you probably learn more than just the limited knowledge set required to actually perform the work. This exercise bore much fruit because of the prep time required and the connections it made by forcing you to get up and talk about it. By speaking about a topic, you inevitably talk to people who attended your session, and you’ll end up hearing about a unique experience or perspective that furthers your understanding.
What is the best way to get a red team job?
The best way to get a red team job is to have or gain a skill such as internetworking, system administration, or software engineering and start out in a blue team role. Getting into a blue team You can network internally and externally from your organization at
local events and regional cybersecurity conferences. There are a couple of certifications tailored to red teaming that can get you noticed by red teams looking to add some human resources.

Its also recommended downloading virtual machines and web applications (Hackthebox, Tryhackme, Vulnhun)that have vulnerabilities on them when trying to learn at home.

Do you need a college degree or certification to be a cybersecurity professional?
Years ago you might need to have a college degree but now in 2023, In technology, especially software development, you can prove your knowledge through blogging, YouTube videos, podcasting, and working on open source projects. GitHub is the new résumé for software developers. However, education is
always a good thing and does help.

After You Get Hired

FAQs

Are Penetration Tests are always a recommended to be implemented first for any organization’s security posture?
The organization can first start with vulnerability
management and getting policy and governance into play.

What are valuable things to do to keep growing?
If you are currently looking to get into a cybersecurity job, the most important trait that many hiring managers look for is your ability to self-study and learn new skills. You should “learn how to learn” and apply new skills. You’ll drastically increase your value on the job market.

If you are hiring blue teamers, you should look for instances where they picked up new skills on their own.

Learning Resources

VMs and CTFs

1
2
3
4
5
6
7
8
9
10
11
12
13
14
Ctftime.org
Ctf365.com
Overthewire.org
Hackthissite.org
HackTheBox
Vulnhub
TryHackMe
Immesrive Labs
pentesterlab.com
hacker-project.com
hackerforever.com
```bash
### Podcasts

Brakeing Down Security Cyberwire Darknet Diaries Defensive Security Podcast Open Source Security Podcast SANS ISC Daily Security Weekly

1
2
3
4
5
6
7
8
9
### Courses Platforms

1- Coursera

```bash
https://www.coursera.org/
```bash
2- Edx

https://www.edx.org/

1
2
3
4
5
6
7
3- IT Master short courses

```bash
https://learn.itmasters.edu.au/login/index.php
```bash
4- Iversity

https://iversity.org/en

1
2
3
4
5
6
7
5- Academic Earth

```bash
https://academicearth.org/
```bash
6- Alison Courses

https://alison.com/

1
2
3
4
5
6
7
7- FreeIT Training channel

```bash
https://www.youtube.com/@itfreetraining
```bash
8- SANS Security Courses

https://www.sans.org/cyber-security-courses/?msc=main-nav

1
2
3
4
5
6
7
8
9
### Tutorials

Networking Tutorials

```bash
https://www.omnisecu.com/
```bash
Coding Tutorials

https://www.w3schools.com/

1
2
3
4
5
6
7
How to Hack subreddit

```bash
https://www.reddit.com/r/HowToHack/
```bash
### Books

Defensive Security Handbook: Best Practices for Securing Infrastructure by Amanda Berlin and Lee Brotherston

Blue Team Handbook: Incident Response Edition by Don Murdoch

Blue Team Field Manual by Alan J. White and Ben Clark

Intelligence-Driven Incident Response: Outwitting the Adversary by Scott Roberts and Rebekah Brown

Building an Information Security Awareness Program: Defending Against Social Engineering and Technical Threats by Bill Gardner and Valerie Thomas

How to Measure Anything in Cybersecurity Risk by Douglas Hubbard and Richard Seiersen

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
### Articles and News

```bash
https://www.govinfosecurity.com/
https://www.securityweek.com/
https://www.infosecurity-magazine.com/
https://thehackernews.com/
https://www.getsafeonline.org/
https://resources.infosecinstitute.com/
https://www.aldeid.com
https://securityaffairs.com/
https://www.cisecurity.org/
https://www.sans.org/
https://null-byte.wonderhowto.com/
```bash
### Webinars and Podcasts

https://www.brighttalk.com/ ```bash

Forums

bash http://www.waraxe.us/ bash

This post is licensed under CC BY 4.0 by the author.