Getting your foot in the door or finding your next gig in cyber security is sometimes a daunting task. Just like hacking, a methodology is needed to succeed. Here's how I see the core components (this methodology will evolve over time):
Aquire Skillsets / Experience
Establish Credibility
The Resume
Network
Find Opportunities
The Interview
Negotiation
Excelling
This blog is on Finding Opportunities in the scene.
Normal Methods
The normal methods to look for roles are sites like LinkedIn, Indeed, and ZipRecruiter. All have very generic ways to find jobs:
The pro-tip within this normal way of scouting for positions is that in cyber security, many roles have different names. Let's take the example of a "Penetration Tester". Let me list the different keywords associated with this type of role so you can understand the word-soup that might get in the way:
Penetration Tester
Pentester
Red Team(er)
Offensive Security Engineer
Security Researcher
Security Analyst
Security Engineer
Security Consultant
Application/Network Security Engineer
Security Tester
and more...
Now, I know that conflating all these titles can trigger some folk. I'm not saying they are all the same. What I'm saying is that they all can share a certain portion of skills for someone searching for a role. The point is to illustrate that you should do some research on adjacent or alternative names for roles you look for on these sites.
The Quarterly Reddit Hiring Threads
The 1st "hack" is wielding the power of the quarterly Reddit /Netsec Hiring threads. One of Reddit's most popular cybersecurity subreddits is /netsec. Each quarter they start a thread for prospective employers looking to hire cyber security talent.
These threads are invaluable. Not only should you be parsing them for the current quarter, but an aspiring hacker should be looking at everything from the past 2 years.
In these threads, even if a role is closed/filled, they give you a contact to reach out to. Here's another pro-tip from someone who has hired multiple hundreds of security people in his career:
There is almost always a role for an exceptional candidate. In cybersec it's REALLY hard to find good people. If you find one, often a hiring manager can "move things around" to open up a role.
So.. parse these threads and apply to the ones that interest you. If a company you are interested in is on there but they don't have a role posted for your skillset, don't be afraid to reach out to the contact and ask if they might soon. Persistence is key.
For your convenience here are the last two years of Hiring Threads for you to peruse:
https://www.reddit.com/r/netsec/comments/tx4yd2/rnetsecs_q2_2022_information_security_hiring/
https://www.reddit.com/r/netsec/comments/rv3x4r/rnetsecs_q1_2022_information_security_hiring/
https://www.reddit.com/r/netsec/comments/q0quoi/rnetsecs_q4_2021_information_security_hiring/
https://www.reddit.com/r/netsec/comments/oo8qnn/rnetsecs_q3_2021_information_security_hiring/
https://www.reddit.com/r/netsec/comments/mi5lrc/rnetsecs_q2_2021_information_security_hiring/
https://www.reddit.com/r/netsec/comments/kogzlg/rnetsecs_q1_2021_information_security_hiring/
https://www.reddit.com/r/netsec/comments/j4zo8f/rnetsecs_q4_2020_information_security_hiring/
https://www.reddit.com/r/netsec/comments/hlcimh/rnetsecs_q3_2020_information_security_hiring/
https://www.reddit.com/r/netsec/comments/ft6xvx/rnetsecs_q2_2020_information_security_hiring/
https://www.reddit.com/r/netsec/comments/eo3wgn/rnetsecs_q1_2020_information_security_hiring/
Conference Hiring Boards (ShmooCon)
The 2nd place an aspiring cyber security person should be looking is conference hiring boards. Local infosec and cybersec conferences are increasingly having a "board" where prospective employers can recruit. Some, like ShmooCon's, post them online.
Similar to the Reddit hiring threads, ShmooCon and Rob Fuller (@mubix) post a yearly hiring board for each conference. Apply the same principles from the Reddit threads to these boards. Here are the last three:
Marcus Carey's Twitter Hiring Threads
Marcus is an amazing author and "OG" of the cyber security scene. I personally look up to him and Rob (Mubix) a ton. Marcus periodically posts hiring threads on Twitter where prospective cybersec employers or related contacts can reply with openings. Apply the same principles as the Reddit and ShmooCon list here. In addition, you get real contacts you can talk to on Twitter for these places and roles. Very useful. Here are the last few years' threads by Marcus:
5/18/2022 | https://twitter.com/marcusjcarey/status/1526945260697427974 |
3/28/2022 | https://twitter.com/marcusjcarey/status/1508431180957470725 |
2/25/2022 | https://twitter.com/marcusjcarey/status/1497287852849303559 |
12/15/2021 | https://twitter.com/marcusjcarey/status/1471117852371402757 |
12/1/2021 | https://twitter.com/marcusjcarey/status/1466044424278794249 |
11/15/2021 | https://twitter.com/marcusjcarey/status/1460246206072848393 |
11/1/2021 | https://twitter.com/marcusjcarey/status/1455157676799770636 |
10/15/2021 | https://twitter.com/marcusjcarey/status/1448997091905138690 |
10/1/2021 | https://twitter.com/marcusjcarey/status/1443923654652403742 |
9/15/2021 | https://twitter.com/marcusjcarey/status/1438198500366356487 |
8/27/2021 | https://twitter.com/marcusjcarey/status/1431330219332456454 |
8/12/2021 | https://twitter.com/marcusjcarey/status/1425892834775871489 |
7/23/2021 | https://twitter.com/marcusjcarey/status/1418644364931239941 |
7/9/2021 | https://twitter.com/marcusjcarey/status/1413467981389041664 |
6/29/2021 | https://twitter.com/marcusjcarey/status/1409866824318173187 |
6/15/2021 | https://twitter.com/marcusjcarey/status/1404872718680473611 |
5/25/2021 | https://twitter.com/marcusjcarey/status/1397187131542581249 |
5/13/2021 | https://twitter.com/marcusjcarey/status/1392831442355466241 |
5/27/2021 | https://twitter.com/marcusjcarey/status/1387029261777719298 |
3/26/2021 | https://twitter.com/marcusjcarey/status/1375510404453912580 |
3/03/2021 | https://twitter.com/marcusjcarey/status/1367232557662797831 |
2/12/2021 | https://twitter.com/marcusjcarey/status/1360281404282707969 |
1/21/21 | https://twitter.com/marcusjcarey/status/1352285496874041345 |
1/5/2021 | https://twitter.com/marcusjcarey/status/1346572489946779650 |
Final Notes
The above are four tremendous resources to find open roles and contacts in cyber security. I would be remiss if I didn't mention my friend @PhillipWylie who also shares my passion for getting new people into the field. Throughout Phil's Twitter, conference talks, and podcast you can find all sorts of useful hacks to find gigs in cyber security.
6/17 Update -
Another resource that JUST got created by @gadievron aimed at helping those who've been laid off find new roles in CyberSecurity. Over 200 roles posted:
6/18 Update -
One more source that I forgot to include is related to the “networking“ section of the methodology but probably fits here too. This source is:
Slack and Discord channels
In any given large city there are somewhere between 3-10 different cyber security meetups. These are things like DEFCON groups, Owasp groups, ISSA groups, Cloud Security Groups, etc, etc.
Most of the live meetups maintain a discord or slack channel and these channels have sub channels for hiring where people post job openings, often before they even hit the internet. In addition, local conferences (bsides, ++) have channels like this too sometimes.
An aspiring hacker could find a ton of these servers local to them and search out jobs.
With the world opening up to more remote positions whose to say you need to limit yourself to your local ones 😉🤔🧐
Comments