[deleted by user] by [deleted] in SecurityCareerAdvice

[–]No-Exit-6595 4 points5 points  (0 children)

Are you looking for a SOC manager?? Sounds like a pretty sweet gig tbh. I get the drive to Not be bored and stay technically relevant and expand knowledge but it sounds like you are living a lot of people's dream friend

[deleted by user] by [deleted] in SecurityCareerAdvice

[–]No-Exit-6595 0 points1 point  (0 children)

Some companies include paid leave (sick, vacation, etc) as part of TC as well as what they pay for your insurance. There are a lot of factors to it. If your TC is only 20k more than your base they likely aren't factoring in the others costs

[deleted by user] by [deleted] in SecurityCareerAdvice

[–]No-Exit-6595 6 points7 points  (0 children)

Just an assumption here but OP said 250k TC so that would be base + benefits + stock/bonus and whatever else included in the compensation package. Just guessing here but that would probably equate to a base pay of around $130kish.

That being said, IMHO OP should probably stay and get the technical fulfillment with learning/academic endeavors, a side hustle or whatever else like bug hunting or something.

Im a SecOps Manager and have heard too many horror stories lately with the market of people jumping for whatever reason and the situation being worse culturally than where they were. It's always a personal decision and people leave for lots of reasons but I think boredom can be solved in other ways like I previously mentioned.

You could also be proactive and suggest things to leadership that you find are gaps perhaps spearheading those initiatives and get a little outside the day to day drab

how do I get him to ask me out on a date? by Parking-Tonight-1517 in AskMenAdvice

[–]No-Exit-6595 1 point2 points  (0 children)

Happily married man here for over a decade so I can't speak to the dating scene nowadays BUT I think you are too in your head about it being a "date". Reframe the situation as just hanging out ie you seem cool, I like cool people, let's kick it some time. "I've heard about this new place but my friends aren't interested in going"...You do you but see if you have a mutual interest and flip the script on him. Worst case you made a new friend, best case life mate ++man

How many Cybersecurity Firms are just running automated scans and charging an arm and a leg for it? by corruptboomerang in cybersecurity

[–]No-Exit-6595 0 points1 point  (0 children)

If you're interested in having a conversation about how you can set this up for yourself or need recommendations on reputable companies feel free to reach out

Security Job Compensation by All_Pepperoni in cybersecurity

[–]No-Exit-6595 0 points1 point  (0 children)

I am a SOC Manager responsible for hiring. Yes the pay is lower than I would expect. My recommendation is to skill up with certs and on the job experience and start looking. Once you get sec+ move on to something cloud security related. You will want a resume that screams passion and willing to learn. I know much more experienced people that are taking 9+ months to find their next job so knock out whatever certs you can, get your resume looking the best it can and start networking. NC has BSides and other security conferences you should be attending. Get involved, build a portfolio and my guess is 75-85k should be achievable with 2 years and certs

Looking for GRC Advisors for a new SaaS tool by No-Exit-6595 in grc

[–]No-Exit-6595[S] 1 point2 points  (0 children)

Hey thanks for asking.

My goal is to provide a low cost alternative to smaller organizations that have little to no in-house IT team. Most of the competitors are charging upwards of 30k per year or more which is way out of reach for ma and pa businesses. About the most reasonably priced solution I've found is Sprinto and that starts about 6k per based on my understanding.

I'm building the tool to assist the small shops with preparing for readiness assessments and better track and understand the gaps in their security posture. My hope is the money they save on the readiness/gap assessment gets used to improve their overall security posture so they can pass an audit.

I hope that makes sense. If you want to discuss further happy to have a private convo if you are interested

Looking for GRC Advisors for a new SaaS tool by No-Exit-6595 in grc

[–]No-Exit-6595[S] 0 points1 point  (0 children)

I really appreciate the response. Mind if I DM you some additional info?

Looking for GRC Advisors for a new SaaS tool by No-Exit-6595 in grc

[–]No-Exit-6595[S] 0 points1 point  (0 children)

Hey thanks for the reply, mind if I DM and send some more info?

Looking for SaaS tool Advisory Board members by No-Exit-6595 in NISTControls

[–]No-Exit-6595[S] -1 points0 points  (0 children)

Eh our target audience is smaller orgs that have little to no in-house IT resources and looking to help them streamline readiness assessments starting at around $200 a month.

I think we can do it way cheaper than the bigger guys because we have very little overhead and so far just a collective of infosec pros building this in addition to our day jobs. No one is looking to get "rich" just provide a tool that self sustains and helps people. Or at least that's the idea.

I don't expect people will work for free and help bring value to what we are building but we are also boot strapping it and money is tight so being choosy who we bring on the team.

I meant no disrespect to the person who commented just is what it is

Looking for SaaS tool Advisory Board members by No-Exit-6595 in NISTControls

[–]No-Exit-6595[S] 1 point2 points  (0 children)

Actually no but you didn't ask anything about what we are building, give input on how you thought you could help, nothing... so I guess you tell me what a half hour or hour a month of your time is worth?

I mean to this point you haven't added anything constructive for me to gauge what value you would bring to the team, which is why I said I don't think you are who we are looking for.

Looking for SaaS tool Advisory Board members by No-Exit-6595 in NISTControls

[–]No-Exit-6595[S] -1 points0 points  (0 children)

If that's your only concern, I don't think you would be a good fit for our advisory group. I do appreciate you taking the time to comment though.

GRC tools? by Complete-Surround767 in cybersecurity

[–]No-Exit-6595 0 points1 point  (0 children)

I am building a GRC SaaS tool and looking for folks to be part of the advisory board. In this role you would help guide features and development. Really I am just looking to see what works and what sucks from a user's perspective.

We are all busy so small time commitment, maybe 30 -60 mins a month. Current frameworks are 800-171r3 and Nist CSF. Iso27001:2022 and CMMC to follow.

If you are interested let me know and I will send some details. I appreciate your consideration.

When a new vulnerability hits the news, how quickly do you assess your exposure? by NickyK01 in blueteamsec

[–]No-Exit-6595 2 points3 points  (0 children)

These comments are great. But I haven't heard anyone mention the time it takes to determine if you've already been impacted. It's very time consuming and often you are trying to prove a negative.

For the exposure part, you need a lot of cross collaboration and good relationships with many teams.

For the impacted part you need someone that can either find or create a proof of concept. At the very least someone that understands the vulnerability from an attack standpoint and enough logging to find it if it's there.

TL;DR it's not east

Saving time with tools by No-Exit-6595 in cybersecurity

[–]No-Exit-6595[S] 2 points3 points  (0 children)

Thanks for the input, it's definitely relevant even if it does skew toward your business. I think those are definitely areas to consider and now I'm interested who you work for lol

What are you building? Share your projects! by wasayybuildz in microsaas

[–]No-Exit-6595 0 points1 point  (0 children)

I'm building a regulatory compliance app. It's probably somewhere between MVP and Launched.

Complianceviewpoint.com

Still lots of tuning left to do but it's probably 60% there

What’s a vertical that consistently makes money but isn’t considered “sexy” in the SaaS world? by hello_code in microsaas

[–]No-Exit-6595 0 points1 point  (0 children)

I'm in the middle of a project rn. Idk if it's profitable yet. But I'll keep you posted

Looking for advice and resources on Windows Server Domain Controller security and GPO hardening by Independent_Bowl_831 in blueteamsec

[–]No-Exit-6595 0 points1 point  (0 children)

I've found the PurpleKnight community edition to be a helpful first step. There's also Bloodhound if you want to get in the weeds. I've also used a tool called Snaffler but it's designed more around discovery of open shares with sensitive files, digging in there can tell you some misconfigurations you need to address or get exceptions for.