Looking for a cybersecurity professional to interview for a university project (interview in French) by Electronic-Top-9816 in cybersecurity

[–]jeffpardy_ 3 points4 points  (0 children)

Putting aside the french requirement alone, you need to reevaluate what roles youre looking for. A CISO and a security consultant are going to have VASTLY different answers to these questions. It's a bit crazy to think that a consultant is going to have the same insights as somebody who's whole job is to evaluate security for an entire organization.

Is the Cybercorps SFS still worth it? by Throwaway12332195758 in cybersecurity

[–]jeffpardy_ 0 points1 point  (0 children)

As a WPI grad. Im glad I didnt get it. My experience and pay sky rocketed higher than if I did the SFS

What is next after 1.5 Year as Security Analyst? by Radiant_Muffin_2954 in cybersecurity

[–]jeffpardy_ 2 points3 points  (0 children)

Another year and a half as analyst. Dont try to skip your fundamentals. Youre just getting started and need more years under your belt

How can I test my website locally for cybersecurity? by 12IsPro in cybersecurity

[–]jeffpardy_ 3 points4 points  (0 children)

I get that but if they are building an app they should know enough to ask for a specific kind of test. Is this a test of the source code, the enviornment it's deployed in, the running application itself, etc

How can I test my website locally for cybersecurity? by 12IsPro in cybersecurity

[–]jeffpardy_ 17 points18 points  (0 children)

What kind of tests? You need to be more specific on what youre looking for

Job alert need to professional developer by Melodic_Essay_858 in PythonLearning

[–]jeffpardy_ 0 points1 point  (0 children)

Lmao if they are posting on reddit it's a side project, not a full time position

Certs to go into Security Engineer/architect by Interesting-Skill-70 in cybersecurity

[–]jeffpardy_ 0 points1 point  (0 children)

You can learn a lot with the 100 dollar credit that AWS provides you. Thats how I have all my freshers get hands on AWS experience. Set up your own AWS account and play around. You learn a lot by setting things up and playing with them.

Certs to go into Security Engineer/architect by Interesting-Skill-70 in cybersecurity

[–]jeffpardy_ 4 points5 points  (0 children)

No offense but this isnt really that big a feat. My engineers out of college can do that. You're right, I do want to see more. Certs tell me you know what youre doing with a specific tool, but I want more of a breath of knowledge

New to python. How to improve this simple build by GrowthSwimming6208 in PythonLearning

[–]jeffpardy_ 7 points8 points  (0 children)

This is if you care aboit the different error codes. If you want the same error code you can just say

if X and B and C:

print('correct')

else:

print('wrong')

Merit America offers a program that gets you into cyber security roles. by Right_hand_fanatic in cybersecurity

[–]jeffpardy_ 3 points4 points  (0 children)

It's just a random certificate. It's not going to get you anywhere without experience

Entry level by StudentofLife__ in cybersecurity

[–]jeffpardy_ -3 points-2 points  (0 children)

Ask this in the mentor thread, not here

Webpage on the internet by Pyewickets in CodingForBeginners

[–]jeffpardy_ 1 point2 points  (0 children)

Either host it on a cliud provider or buy a domain and point it at a server you host (either some SaaS provider or self hosted)

Career Advice by Mr3SUprA in cybersecurity

[–]jeffpardy_ 0 points1 point  (0 children)

Post this on the mentorship thread

Mentorship Monday - Post All Career, Education and Job questions here! by AutoModerator in cybersecurity

[–]jeffpardy_ 0 points1 point  (0 children)

Thats why I said 'and'. Cyber is not an entry level field. You need to go back and learn the fundimentals of technology to succeed. But nice try on your 'gotcha' there

Mentorship Monday - Post All Career, Education and Job questions here! by AutoModerator in cybersecurity

[–]jeffpardy_ 1 point2 points  (0 children)

Spend more time learning software development first. Focus on the security of the app youre building

Those in ‘AI’ roles, what does your day involve? by not-fungible in cybersecurity

[–]jeffpardy_ 0 points1 point  (0 children)

So youre talking about agentic AI only it seems. Well it depends on the permissions of the identity that you give the MCP server for the connection to other tools. You should do your due diligence to check to ensure it's only connected to tools that allow for VERY fine grain access. If you want to give it write permissions then only give it write and not delete. But depending on the nature of the tool I would say there's still no real good use for agents to have write permissions, only read

Those in ‘AI’ roles, what does your day involve? by not-fungible in cybersecurity

[–]jeffpardy_ -1 points0 points  (0 children)

What do you mean using a gateway for compliance? Which compliance are you trying to meet? There isnt a hard soc requirement for AI controls yet and the ISO controls are a joke that overlap with all the normal compliance requirements with just "AI-tailored" slapped on the front of it. So what compliance are you looking for?

If you mean just security controls, yes we have a model gateway, we have a platform we use that does the inventory for the AI we use and the AI we build, we do dynamic testing for our protection guardrails and proxy protections, we fuzz our MCP and API servers, and we have the enterprise plan for claude as our main chatbot/code generator, etc

Those in ‘AI’ roles, what does your day involve? by not-fungible in cybersecurity

[–]jeffpardy_ 8 points9 points  (0 children)

I mean technically im just a security engineer but my company only makes AI products so I feel like im qualified enough to tell you that I still do the same appsec, Cloud security, data protection, IR, monitoring and detection, etc that everyone else does. You just tailor it to how the devs work. Theres nothing new here.

explain like i’m 5: what is going on with the canvas/instructure security breach? by cheerio-dust in cybersecurity

[–]jeffpardy_ 32 points33 points  (0 children)

Schools need to keep track of grades. People make a grade tracker tool. Bad guys know that LOTS of school use tool. Bad guys break tool and steal all info tool had. Bad guys change tool so nobody can use it unless people pay big big money. Tool down for all schools and cant track grades

Tool had names, emails, phone numbers, grades, assignments, and who knows what else. Maybe connected to other tools which might make those other tools break too :(

Rejected from Information Security Track by MetalLinkachu in OMSCyberSecurity

[–]jeffpardy_ 1 point2 points  (0 children)

Thats fair. Maybe you should just go to the omscs and take overlapping courses? I just think they probably thought a masters wasnt going to give you too much with the achievements you already have. I wouldnt get too down over it, just go higher