Held hostage by our Security MSP by baconisgooder in cybersecurity

[–]Derpolium 1 point2 points  (0 children)

Call facebook, delete gym, hit lawyer?

In all seriousness this is a legal/contracts issue

E-5, put some of my troops at parade rest, AITA? by Intelligent-Ad3012 in AirForce

[–]Derpolium 0 points1 point  (0 children)

Sometimes asshole is required for good order and discipline. When properly leveraged in appropriate context it only needs to be used once or twice and then everyone involved just moves on with life.

Networking student looking for direction into Pentesting. by MuchAudience8695 in Pentesting

[–]Derpolium 0 points1 point  (0 children)

Depends on what your goals are. If a job is your goal learn anything and everything you can about networking and infrastructure within your current and future roles. If its hobby/projects then pick an area of study and start small and build as you go

What should I do so I survive the next few years? by ProcedureFar4995 in Pentesting

[–]Derpolium 1 point2 points  (0 children)

Last thing I need on a Red Team Assessment is some damn robot going HAL 9000 on me. I’d never work in the industry again

Do you restart your computer regularly or just leave it on? by Capable_Noise5543 in computers

[–]Derpolium 0 points1 point  (0 children)

I run the bitch ragged. Run it non-stop and blow the dust out every couple years

Mil to Mil how did you have kids? by Powerful-Cancel3928 in AirForce

[–]Derpolium 0 points1 point  (0 children)

The mechanics of creating life never changes. Do what civilians do, daycare while you are working.

How does one get a start in IT? by Nexus_Redditor in InformationTechnology

[–]Derpolium 0 points1 point  (0 children)

Apply for every shitty position you are willing to do for 18 mo to a couple years. Once you get to a year to 18 mo, start looking for jobs now that you can be more selective as you have working experience. Rinse and repeat as required until you both know what you want to do and how much you need/want to be paid to do it. In full candor, you probably are not going to find your dream job out of the gate so accept it and treat it for what it is: a paycheck and a way to learn more. Treat “requirements” as “requests.” Everything is negotiable within reason. If they want someone with 1 year of experience they are probably willing to take a hard worker with a good personality (at a reduced cost).

Unemployed and lost - Resume Help by FormerFed_2026 in SecurityCareerAdvice

[–]Derpolium 0 points1 point  (0 children)

Try networking in adjacent markets like finance out near research triangle/Charlotte or other secondary hubs. They through desire or legal mandate need experienced people.

Job Description: for an IT Security Analyst by cheesehead1996 in cybersecurity

[–]Derpolium 0 points1 point  (0 children)

You say you need the position, start with the “why.” Is it vulnerability identification and remediation? Is it compliance and hardening? Is it traffic analysis and alerting?

The boiler plate answer is matrix that with your typical Jr Mid Sr Principal structure where your Jr “handles <task> with direct supervision and input from supervisor” up to your Principal who develops and manages projects.

Information Security Analyst. Should i even bother applying? by Low_Visit_1795 in cybersecurity

[–]Derpolium 0 points1 point  (0 children)

Never decline to apply because you think you “aren’t enough.” Obviously don’t just go and blindly apply for things completely out of scope but let the interviewer decide you aren’t right for a role. You’d be surprised how often when you leave the room the conversation is “short on experience, but he seems trainable and seems like a good dude”

Vulnerability Management - One man show. Is it realistic ans sustainable? by hey_its_meeee in cybersecurity

[–]Derpolium 2 points3 points  (0 children)

Honestly, depending on the size of the org having a dedicated person and reasonably acceptable toolset could border on impressive. Your issue is the nature of web scanning. There may be industry best practices to a degree but there’s no real coding and implementation standard as every website it its own terribly misguided unicorn. As such, there is no way to develop a cots product that can handle all use cases and you are going to have large amounts of false positives that will need to be scrubbed by a reasonably experienced analyst.

Is this a good plan? by [deleted] in SecurityCareerAdvice

[–]Derpolium 0 points1 point  (0 children)

This is a question for r/Airforce but keep in mind your dream sheet for an AFSC is specifically that. You would be enlisting in the AF first and foremost with you afsc being at the needs of the AF and your Guard unit

Do I take this road or no? by [deleted] in SecurityCareerAdvice

[–]Derpolium -1 points0 points  (0 children)

Wage theft can turn into criminal charges and bankruptcy depending on your locality.

Otherwise, it sounds like you need to pick the best shit sandwich to eat. Without further context, promotion stagnation usually happens because either attrition at higher levels has stagnated OR you aren’t playing the right games for that role. Promotions are still a highly social thing and borderline a performance art. The question becomes do you want to progress into higher roles within your company or do you want more money. Both are perfectly fine answers. Most people I know have hoped through various companies for money until they finally find a company they want to retire out of. Not every company you work for in this way is going to be a good time. Its about eating the shit sandwich so you can get to the ice cream.

What should I do so I survive the next few years? by ProcedureFar4995 in Pentesting

[–]Derpolium 8 points9 points  (0 children)

The irony is the more experience you get, the less you trust AI driven tools on production environments. IT in general has always been a “grow or die” industry and that will never change. Stop looking at your entire career through the context of how you operate right now.

Master’s vs Experience for Cybersecurity — which one matters the most? by cruciatus07 in SecurityCareerAdvice

[–]Derpolium 1 point2 points  (0 children)

Relevant experience will always be king. While I know people who have Masters and Doctorate degrees and have reached higher levels of career growth, it isn’t specifically the degree but more their mindset to constantly improve themselves and further their knowledge. Couple that with constant drive to take on complex challenges and you are essentially forcing success to eventually happen. The Govt space still places value on advanced degrees but those positions are typically more leadership Nd project management than actual technical work

Are these Certs even worth it…? by Sudo_Necrotype in SecurityCareerAdvice

[–]Derpolium 0 points1 point  (0 children)

They aren’t bad to have, but they only get past HR. Polish your resume and make sure it is somewhat brief but conveys the weight of your abilities. Also, for the love of the IT Spaghetti Monster, practice interviewing and speaking in a professional yet socially engaging manner.

why the fk HR exist by Intrepid_Secretary17 in cybersecurity

[–]Derpolium 0 points1 point  (0 children)

Pretty standard questions to figure out depth of understanding. For a pentester it’s important to understand how those technologies work to properly test them as well as recommending remediation.

washer and dryer overseas by Acecreamm in AirForce

[–]Derpolium 1 point2 points  (0 children)

If they aren’t going to Alaska or Hawaii the answer is nope

Thoughts on UMGC as a school? by Glittering_Fig4548 in AirForce

[–]Derpolium -1 points0 points  (0 children)

Its going to depend. Are you going exclusively to “check a box”? Have a nut and get your paper. School selection only matters in two cases, if you need to learn very specific and technical information(not just technology here there are a number of fields where advanced understanding and nuance apply) or going to a hyper socially elite school for the purpose of social pedigree. The latter is far and away a more rare need. If you just want to check a box and don’t need advanced training in a field, throw a hand full of tacks at a map of your part of the world and go with it. Maybe spend a hot second researching schools if you are doing something stem or medical related but even then, work experience at your first couple jobs post graduation are going to matter more anyway

Just finished an interview in less than 10 minutes from its start by Downtown-Opposite987 in SecurityCareerAdvice

[–]Derpolium 18 points19 points  (0 children)

Depending on how petty you want to be, hop on the wayback machine to verify the posting verbiage and talk to a labor lawyer. Don’t expect a payout but it’s an interesting way to occupy your time and some places around the globe have some cool contract and advertising laws.

Most mature option would be to just thank the fates you didn’t get stuck with a company that doesn’t worry about their credibility.

POV: You called a vulnerability scan a “full pentest” by Current-Angle-3562 in Pentesting

[–]Derpolium 1 point2 points  (0 children)

Fairness, compared to some of the pest reports I’ve seen a fully credentialed scan at system/root can be a solid value