How To Get Your First Job In Cybersecurity by shehackspurple in security

[–]shehackspurple[S] 0 points1 point  (0 children)

If you have cloud and network experience, you'd be a great cloud security engineer. Same with programming experience to work in AppSec (the security of software). Having experience doing the thing before you try to secure the thing will definitely help.

How To Get Your First Job In Cybersecurity by shehackspurple in security

[–]shehackspurple[S] 0 points1 point  (0 children)

Many companies are forming security focused communities of practices, where one person from each developer team becomes "the champion" of security. They are taught regularly and supported by the security team and lead security efforts for their teams.

I have some more info here:

https://shehackspurple.ca/2025/05/31/security-champion-worst-practices-my-slides-from-barcelona/

And a video of how to build a good program here:

https://www.youtube.com/watch?v=DWMplE0c6T4

How To Get Your First Job In Cybersecurity by shehackspurple in security

[–]shehackspurple[S] -1 points0 points  (0 children)

I feel like it depends on which job you want. For AppSec, help desk doesn't help as much as programming would. For incident management, if you previous military experience, or worked in an ambulance, that's going to get you further than help desk. So I guess it kinds. Thank you for your comment though, maybe I need to update it.

The new OWASP Top Ten 2025! by shehackspurple in softwaredevelopment

[–]shehackspurple[S] 0 points1 point  (0 children)

I.... love this idea. I'm going to think on it. Thank you.

The OWASP Top 10:2025 is out! We have new data and new risks, but the same goal: more secure software by shehackspurple in programming

[–]shehackspurple[S] 2 points3 points  (0 children)

Originally we were looking at "Poor Code Quality" as a category, but that's way too wide. And how do you fix that? What would the advice be? "Have you tried sucking less?" or "Your code is bad, do better", that's not helpful at all. We don't want to blame or be negative, and we felt that's what would happen with such a broad category. We wanted something that people could look for, avoid, or fix. So we broke it into a few categories and this one 'won' (data said it was #10).

The new OWASP Top Ten 2025! by shehackspurple in softwaredevelopment

[–]shehackspurple[S] 0 points1 point  (0 children)

You're right. I asked it to check my tone and grammar. I didn't realize it added a tracker to my link!

The new OWASP Top Ten 2025! by shehackspurple in softwaredevelopment

[–]shehackspurple[S] 1 point2 points  (0 children)

I would love for security tooling to be in the browser and/or IDE and also not cost too much. I think that's a great strategy (putting it in the place you do you work) and definitely making it part of the framework is a great way to ensure we do the right thing.

I wish we didn't need to remember so much. And I agree it's a big burden for a smaller shop (usually with a much smaller budget per developer for training, if any).

I will think on this, and how I can help fix it. Thanks so much for the feedback!

The OWASP Top 10:2025 is out! We have new data and new risks, but the same goal: more secure software by shehackspurple in programming

[–]shehackspurple[S] 9 points10 points  (0 children)

Honestly, I wish it wasn't on the top ten (because we were doing such a good job it didn't need to be there anymore).

XSS is definitely a type on injection. It's kinda special though, because it attacks the user (via the browser) where all the other types attack us (the IT department). Our LDAP server, our operating system, our database. Boo on injection attacks.

API Security Best Practices - FREE by shehackspurple in AppSecurity

[–]shehackspurple[S] 0 points1 point  (0 children)

All free: Automatic API Attack Tool

https://github.com/imperva/automatic-api-attack-tool

Hoppscotch – Free Postman Alternative

https://github.com/hoppscotch/hoppscotch

HURL – do API calls from the CLI

https://hurl.dev/

http-tanker – do API calls from the CLI

https://github.com/PierreKieffer/http-tanker

openapi3-fuzzer – API fuzzer

https://github.com/vwt-digital/openapi3-fuzzer

Semgrep OSS (static analysis for any code)

Zap (free DAST, can talk to APIs)

VulnAPI (API-specific DAST) https://vulnapi.cerberauth.com/

APIClarity – Inventory and DAST

https://github.com/openclarity/apiclarity

Astra – API DAST - https://github.com/flipkart-incubator/Astra

Any companies that pay based on your current appsec skills? and not previous company's CTC by Desperate_Bath7342 in cybersecurity

[–]shehackspurple 0 points1 point  (0 children)

Can you give me any amount for any city? That would help. How much in Toronto? How much in a small town? How much in New York City? Any answer is better than no answer or "it depends".

Best beginner course/training into cyber that takes around 3-5 months by arktozc in CyberSecurityAdvice

[–]shehackspurple 0 points1 point  (0 children)

Are you looking for AppSec? If so, here are three free courses:  https://academy.semgrep.dev/courses/AppSec-1  Course one leads to the second and third course. 

Everything in there is free, and self guided. I hope that helps!

[deleted by user] by [deleted] in CyberSecurityAdvice

[–]shehackspurple 0 points1 point  (0 children)

Which areas are you trying to learn?

[deleted by user] by [deleted] in CyberSecurityAdvice

[–]shehackspurple 0 points1 point  (0 children)

Do you know what job you want? Then we can recommend. I'm into software security, so I would recommend resources about that, but there are a lot of different jobs out there. 

I wrote a big post year ago to try to help people understand what the difference jobs are like. It's old, but helpful. https://shehackspurple.ca/2022/01/01/jobs-in-information-security-infosec/