2022-05-19

My infosec career evaluation

I read Daniel Miessler’s article and liked it. So I tried to evaluate myself against it.

  • βœ… come from one of these backgrounds
    • system administration πŸ‘ˆ
    • networking
    • development
  • βœ… have a good foundation in all these and a decent strength in one
    • system administration (Linux, LDAP, hardening, …)
    • networking (TCP/IP, switching, routing, protocols, …)
    • programming (concepts, scripting, OOP basics) πŸ‘ˆ
  • βœ… have some relevant certifications (CCNA, CISSP, LPIC-2, CCENT, CKAD)
  • βœ… nurture your programming skills; you can build websites, tools, PoCs, …
  • βœ… stay up to date (twitter, email digests, …)
  • βœ… have a lab (AWS + home server)
  • βœ… be always working on (GitHub) projects
  • βœ… make contributions (on GitHub)
  • 🚫 practice with bug bounties (BugCrowd, HackerOne)
  • βœ… have a presence (web site, blog, Twitter)
  • βœ… network with others (interact on Twitter, go to conferences, …)
  • 🚫 respond to Call for Papers (CFP)
  • βœ… professionalism
    • dependability
    • speak concisely
    • tighten up you writing
    • learn to present
  • βœ… understand the business
  • βœ… have a passion
  • βœ… you’re in your 30’s, 40’s, or 50’s, and things are looking good :-)
  • 🀏 financial knowledge
  • βœ… management experience (managing people not only projects)
  • 🀏 extensive network (know a good percentage of the major players in infosec and business)
  • 🀏 dress/etiquette :-)
  • βœ… advanced education
  • 🚫 media savvy (trained to speak with the media about various topics)
  • 🀏 tech/business hybrid (be able to speak and work with devs and managers)
  • 🀏 creativity (able not only execute what you’re given but come up with new ideas and approaches to problems on a regular cadence)

Some of the above attributes are applicable only to certain career phases (junior, senior, team lead). Others are universal.