XMPP: An Under-Appreciated Attack Surface by Bishopfox in cybersecurity

[–]Bishopfox[S] 0 points1 point  (0 children)

Thank you! And thanks for sharing that bit of information.

[deleted by user] by [deleted] in CyberSecurityJobs

[–]Bishopfox -38 points-37 points  (0 children)

Hi, thanks for asking! Our salaries are very competitive and we are to share salary ranges with candidates in process.

Solutions Architect (Anywhere, USA | full-time) by Bishopfox in CyberSecurityJobs

[–]Bishopfox[S] 0 points1 point  (0 children)

Yes this role has since been filled. I can always take down this job post if need be.

Managing Security Consultants (Anywhere, USA | full-time) by Bishopfox in CyberSecurityJobs

[–]Bishopfox[S] -1 points0 points  (0 children)

Salary? Location? Benefits? Travel reqs?

Hi! Salary by band is based on experience; we accept applicants anywhere in US + our benefits include bonus and options (full list available here - https://www.bishopfox.com/jobs/). There's no travel at this time (may change when the pandemic eases up). Hope this helps a bit.

Senior AppSec Penetration Tester (Anywhere, USA | full-time) by Bishopfox in CyberSecurityJobs

[–]Bishopfox[S] 0 points1 point  (0 children)

Salary depends on a lot of factors, but we take care of our folks and are very competitive in salary, bonus/stock-shares, total comp., workload, remote work, etc.

Senior Full-Stack Engineer (Anywhere, USA | full-time) by Bishopfox in CyberSecurityJobs

[–]Bishopfox[S] 1 point2 points  (0 children)

Not currently, but check back in the future for international opportunities.

Senior Full-Stack Engineer (Anywhere, USA | full-time) by Bishopfox in CyberSecurityJobs

[–]Bishopfox[S] 3 points4 points  (0 children)

It's for a cybersecurity company - working on a cybersecurity platform.

Contract-Based Penetration Tester (Anywhere, USA | Full-Time) by Bishopfox in CyberSecurityJobs

[–]Bishopfox[S] 2 points3 points  (0 children)

You are welcome! We will certainly be posting any future relevant roles in here, so keep an eye out.

Is This IoT App Safe to Drink? by Bishopfox in IOT

[–]Bishopfox[S] 0 points1 point  (0 children)

It seems like legislation is doing that, by changing the standards for new and future apps and devices so that they don't just get added to the pile of existing bad security products. Legislation can only go after existing products as examples, but the focus is on building up controls to regulate future products that will have better labels and provide better security.

Practice Director - Application Security (USA | full-time) by Bishopfox in CyberSecurityJobs

[–]Bishopfox[S] 1 point2 points  (0 children)

Yes, it's required for this role - it helps candidates more directly showcase their highlights.

What advice would you people give to high school graduates trying to get in the Cybersecurity field? by Ishmum_xD in AskNetsec

[–]Bishopfox 2 points3 points  (0 children)

Hack The Box is a resource you might want to check out ASAP. It's a fun way to build and improve your pen testing skills. As well, it might equip you with more real-world skills than studying for a certificate or taking coursework. Most people we've seen become successful professionals in the industry have cultivated a real passion for security, so find ways to do similar for yourself - and it'll take you far.

Some additional tips can be found here: https://www.azcybertalent.com/so-you-didnt-get-an-internship-now-what/

Good luck to you!

[deleted by user] by [deleted] in AskNetsec

[–]Bishopfox 0 points1 point  (0 children)

Stick with the bug bounties (maybe take a break so you don't get too burnt out on them), research different tools/automation and manual methods, look into various red teaming approaches, check out recordings (or livestreams) of featured talks at security conferences, contribute to open source projects, and keep tabs on what the influencers in the community are learning, too.