1 of 27

Cyber Careers

2 of 27

Careers in Cyber Security

  • There are a LOT of different jobs within cyber security
    • Not just hacking
  • It’s a good thing!
    • Options
    • Opportunity to specialize
    • Or be a generalist
  • A Day in the life Example
    • Solving Challenges

3 of 27

Security Architecture

  • Creating and implementing the security systems
  • Work with IT folks to design and implement into IT systems
  • Base skills
    • Networking
    • Systems Engineering
    • Software Development
  • Example job titles
    • Security Engineer
    • Security Architect
    • Network Security Engineer

4 of 27

Security Operations

  • Working to detect threats, protect systems, and eradicate active threats
  • Base skills
    • Networking
    • Systems Engineering
    • Risk Analysis
    • Security Intelligence
  • Example job titles
    • Incident Responder
    • Disaster Recovery Specialist
    • Cyber Security Analyst

5 of 27

Secure Software Development

  • Write secure code for production, test and debug, check for security issues
  • Base skills
    • Software development
    • Testing for security flaws
    • Review existing code
  • Example job titles
    • Secure Software Developer
    • Application Security Engineer
    • Security Software Tester

6 of 27

Threat Intelligence

  • Works to understand the threats to an organization/network
    • Technical threats (develop TTPs)
    • Other threats (attacker motivation, market competition, etc)
  • Base Skills
    • Security Intelligence
    • Human Intelligence
    • Information Systems
  • Example job titles
    • Intelligence Analyst
    • Intelligence Operations Specialist
    • Military Intelligence

7 of 27

Risk Assessment

  • Auditing information systems for risks, vulnerabilities, etc
  • Base Skills
    • Networking
    • Systems Engineering
    • Risk Analysis
  • Example job titles
    • Penetration tester
    • IT Auditor
    • Application Security Analyst
    • Security Consultant

8 of 27

Governance

  • Makes sure laws, regulations, and company procedures are followed – management involvement
  • Base Skills
    • Risk Analysis
    • Cyber Law
    • Training and Education
  • Example job titles
    • Information Security Manager
    • Security Administrator
    • Information Security Officer

9 of 27

User Education and Career Development

  • Training non-technical users on relevant security concepts
  • Continuous training for specialized security personnell
  • Base Skills
    • Training and Education
    • Other skills relevant to the content area
  • Example job titles
    • Security Awareness Trainer
    • Cybersecurity Educator

10 of 27

Where are Cybersecurity Jobs?

  • Everywhere
  • Most organizations need something
  • Larger organizations likely have security in house
  • Smaller might turn to a service provider organization
  • Security shouldn’t be an afterthought

11 of 27

Entry Level Job Examples

  • Penetration Tester
  • SOC Analyst
  • Digital Forensics/Incident Response
  • Malware Analyst

12 of 27

Penetration Tester

  • Find flaws in customer environments
    • Network
    • Hardware
    • Software
  • Educate the customer
    • Why the vulnerability exists
    • How it can be taken advantage of
    • How to fix the vulnerability
    • How to protect their environment
  • Reporting! ☺

13 of 27

Penetration Tester

  • What you’ll do at an entry level
    • Vulnerability scanning
    • Report writing
      • Key to be able to communicate findings to the customer!
        • What was found
        • How to fix the issues
  • Good skills as an entry level penetration tester
    • Some experience in IT or blue team work
      • Able to understand IT environments
      • Able to help the customer remediate issues in their specific environment

14 of 27

Penetration Tester

  • Various backgrounds are fine
  • Different specialties are fine and can help you be unique
    • Programming
      • Able to create custom exploits
      • Able to show customer how vulnerabilities can be exploited
    • Customer service
      • Good at social engineering
      • Customer communications

15 of 27

Penetration Tester

  • Practice!
  • CTF events
    • Capture the Flag
    • Various types of cybersecurity challenges
  • HTB
    • Hack the Box
    • Find vulnerabilities in a system, break in

  • Technical skills will be key

16 of 27

SOC Analyst

  • Security Operations Center
    • Monitoring a network from a security perspective
    • Most larger organizations have one in house
    • Smaller organizations often use a service provider (MSSP)
  • Front line of defense
  • First person to see and act on security alerts
    • Provide analysis on alerts
      • Do we need to take action? Is something bad happening here?
      • Is this a false positive? Can we ignore this? Or fix the alert?

17 of 27

SOC Analyst – Skills

  • Knowledge of IT systems
    • How networks work
    • How computers work
  • Network defense
  • Critical thinking
    • Troubleshooting
    • Problem solving
    • Puzzles!
  • More advanced levels
    • Reverse engineering/malware analysis
    • Computer forensics

18 of 27

SOC Analyst - Levels

  • SOC analyst 1
    • Triage, initial assessment
    • Escalate if necessary
  • SOC analyst 2
    • Incident response
    • Assess and remediate serious events from the tier 1 analysts
  • SOC analyst 3
    • Threat hunting
    • Looking for unknowns, not often working off of alerts
    • Work deeper to understand threats, actions around previous incidents

19 of 27

SOC Analyst

  • Pros
    • Something different almost every day
    • At the front line of defense – first to see an incident

  • Cons
    • Someone is likely on call 24/7
    • Alert fatigue

20 of 27

Digital Forensics/Incident Response

  • Help an organization during an intrusion event
    • Find out what happened
    • Find out how the intruders got in
    • Remediate the issues – stop the bleeding
    • Get the organization back online
  • Incident Response
    • On site, initial triage, stop the bleeding initially
  • Digital Forensics
    • Deeper forensic investigation, doesn’t have to be on-site

21 of 27

DFIR - Skills

  • Soft skills are extremely important
    • Working with folks on their worst day
    • Need to help them remain calm and have a good experience
  • Technical skills
    • Knowledge of IT systems
      • Systems administration
      • Network administration
    • Log analysis
    • Dead disk and live forensics
    • Any specific expertise can help
      • Networking, programming, databases, mobile devices, memory forensics, etc.
  • https://dfir.training

22 of 27

DFIR

  • Pros
    • Fast-paced, exciting
    • Opportunity to dive into attacker’s work
      • Different every time
      • Challenging
    • Front line of active defense
  • Cons
    • 24/7 on call
    • Might need to drop what you’re doing and go on site ASAP

23 of 27

Malware Analyst

  • Discover how malware works
    • How it hides itself
    • What it does
    • How to detect it
  • Escalations Malware Analyst
    • Working in coordination with an IR team, or similar
    • Analyzing malware from live events
  • Collections Malware Analyst
    • Collecting malware from various sources
    • Extract key knowledge (TTPs) to create threat indicators
    • Populate threat feeds and detection tools

24 of 27

Malware Analyst - Skills

  • Curiosity
    • The malware you’re analyzing is unknown
    • Building knowledge on how the malware works
  • Research skills
  • Dynamic analysis
    • Running malware in a save environment (sandbox)
    • Watch it run, understand how it works, what it does
  • Static analysis
    • Code analysis
    • All sorts of languages, particularly lower level languages like assembly

25 of 27

Malware Analyst

  • Pros
    • Challenging
    • Always finding new things
    • Opportunity to share new things with the community
  • Cons
    • Largely self-paced, not a lot of direction
      • How do you go from and unknown sample to knowing everything about it?
      • Not always a playbook
    • Must be motivated

26 of 27

27 of 27

Recap

  • Penetration Tester – Finding vulnerabilities through offense
  • SOC Analyst – Initial triage of possible intrusions
  • DFIR – Deeper analysis of active incidents, or past incidents
  • Malware Analyst – Work to understand how malware works, and how to detect it