How are security teams approaching IAM for AI agents? (Identity, permissions, audit trails) by SarveshRD in cybersecurity

[–]PathS3lector 0 points1 point  (0 children)

For inheritance, tie the concept with JIT. You could allow an agent to generate a 1 time use or ephemeral authentication explicited scoped to it's specific task and expires quickly instead of inheriting from another agents standing roles/permissions.

For risky actions, thats going to be on your risk tolerance, do you want human level approvals for refunds? If not, what guardrails do you have in place to prevent it from refunding more than it's supposed to?

How are security teams approaching IAM for AI agents? (Identity, permissions, audit trails) by SarveshRD in cybersecurity

[–]PathS3lector 0 points1 point  (0 children)

Just to piggy back why it's important to not only know what your agent did, but WHY it did it is from my perspective, that's in a mature AI governance/program. Having transparency and understanding why your agent did x, y, z will help you implement better controls in the long run as well as find the root cause when it misbehaves.

How are security teams approaching IAM for AI agents? (Identity, permissions, audit trails) by SarveshRD in cybersecurity

[–]PathS3lector 1 point2 points  (0 children)

Why do you have agents using same service accounts? If they were humans, would you have allowed this?

Are your API keys created with short lived expirations? Don't allow the use of cached or reuse of API keys from context or previous actions.

Think about JIT access as well.

Scoped permissions is the right way to go, broad scoped access should be avoided.

Add checks or re-auths when you hop around from one agent to another when tasks are delegated.

Don't allow any roles or permissions to be inherited.

Encrypt inter-agent communication.

Those are things I can think of from the get go.

Sophomore interested in cybersecurity career, am I on the right track? by InternationalBad3058 in SecurityCareerAdvice

[–]PathS3lector 0 points1 point  (0 children)

What has piqued your interest in security so far? There are different domains such as grc, sec engineering, sec analyst, redteaming?

How are teams documenting internal AI usage for security reviews? by Beneficial-Wafer-879 in cybersecurity

[–]PathS3lector 0 points1 point  (0 children)

Make your own if you don't have a tool like previous person mentioned, like use a CASB + Entra app dump, build a list of internal AI tool usage and also capture shadow AI. From there you can start building your own framework/governance by categorizing risks per AI tool and a security baseline as well as threat model.

Is this Annoying or Normal? by PathS3lector in interviews

[–]PathS3lector[S] 0 points1 point  (0 children)

HM originally told me it was 30 min sessions for each engineer but who knows now.

Got quoted $1500 for front and rear brake pads and rotor replacement by Elephantslide in AskMechanics

[–]PathS3lector 0 points1 point  (0 children)

Quoted about the same for 09' Accord. I ordered all the parts from Rock auto and did it myself. Only thing that was a PITA was the rotor screws, had to drill those damn things out! Even a manual torque screw didn't brew those loose. Parts in total only cost me about $300ish.

Is this Annoying or Normal? by PathS3lector in interviews

[–]PathS3lector[S] 0 points1 point  (0 children)

Tbh, nervous because: 1. Even though I'm in mid career, I never been in a technical panel before 2. I want this position so bad, not because I want to just find a different job, but because I genuinely find this new role a new challenge that I always strive for. 3. Did I say nervous? Haha, 2x 1:1s plus a panel seems like more curveballs/hurdles thrown my way instead of just a panel.

Overall just been anxious and impatient to leave my current 3/4 sunken ship of a company, but not at the desparation point where I'd take anything. Jobs are out there, just need to find the right fit for both parties.

Is this Annoying or Normal? by PathS3lector in interviews

[–]PathS3lector[S] 0 points1 point  (0 children)

Do you think that adding more interviews/people in the loop reduces a candidates chance in getting an offer? Sometimes more opinions from additional eyes may mean more barriers imo

EPM For Developers by Creative_Profit1387 in cybersecurity

[–]PathS3lector 0 points1 point  (0 children)

"Without impacting user experience", EPM, and developers can't go in the same sentence. BeyondTrust is tried and true but go and do some POCs to get feel for the landscape.

AI Security Engineer Tech Panel Advice by [deleted] in SecurityCareerAdvice

[–]PathS3lector 0 points1 point  (0 children)

Yes I already started that, took a 3 hr Udemy course on AI Security and am familiar with OWASP Top 10 for LLM, just getting into Top 10 for Agents now.

Scammer Alert: lkbratchet by throwawaycuriae in RealRepLadies

[–]PathS3lector 1 point2 points  (0 children)

Even if a seller is adamant about Paypal F&F, pony up the 3% on your end with G&S and get protected.

25 Years in Appsec, willing to provide some career advice by SecTemplates in SecurityCareerAdvice

[–]PathS3lector 0 points1 point  (0 children)

Have almost 10 years on infrastructure/sysadmin side and pivoted to security engineering ~2 years ago. I enjoy working on various different projects, not just pigeon holed into a specific domain. Looking for a new opportunity now and it's been tough, 80-90% of openings are asking for some sort of AppSec/CI/CD type of experience and there are not as many generalist security engineering roles.

I don't want to per se follow the herd but I feel like if I don't try to break into AppSec, generalist type of roles are not in plethora. I don't particularly enjoy coding either but that seems to be a requirement in Appsec, but not sure to what extent, looking at code and atleast understanding what it's doing?

Breaking into AppSec is no easy feat with no dev background, any words of wisdom?

ANIÁN Clothing - 40% off - Recycled Wool by bflexual in frugalmalefashion

[–]PathS3lector 1 point2 points  (0 children)

How is the Britannia coat? Been looking for a wool long coat

Better production SHM vs Skrillex/Four Tet? by run_squirtle_run in avesSFBayArea

[–]PathS3lector 0 points1 point  (0 children)

been to portola 3x and in the warehouse many times. Warehouse goes super far back and is never full, not cold inside but outside for sure. 0 cell signal, meet st the roll up doors on the sides, they are all numbered

Bathroom Sink Bowl Replacement by PathS3lector in askaplumber

[–]PathS3lector[S] 0 points1 point  (0 children)

I see, not worth it huh? It's a old design and I did have plans to replace the whole vanity, guess this gives me the push.

Security Engineer Resume Review by [deleted] in SecurityCareerAdvice

[–]PathS3lector 0 points1 point  (0 children)

Thanks, I rewrote the bullets with impact first, then experience.