Skip to content

Comment on Ask HN: Starting a career in security at 40?parent

Comments

I've been in the security industry since 1997. The last 13 years of that were spent building consulting teams --- amusingly, the first of which was one of the largest app pentesting firms in the country, and the current one is focused on "blue-teamers", as you put it. I have no idea what "regulations" you're referring to, and am certain that certifications --- very much including OSCP --- mean fuck-all in the real world.

In the UK at least there has been a strong drive to regulate security companies through organisations like CREST and CHECK. The problem is that its an industry with a massive amount of hidden information. If somebody does a pen test on an corporate network and says "we didn't find any vulnerabilities" how does a company know if they have actually done a thorough check or if the network is genuinely secure?

Yes in an ideal world we wouldn't need certifications or exams or anything but this isn't an ideal world.

I don't know what part of "there are no certificates required to do this kind of work" I'm failing to communicate. My last company was acquired by NCC Group, a UK public company, and I haven't met anyone from the UK side who was certified either.

I never once said that certifications are required to do this work though did I?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.