SlideShare a Scribd company logo
1 of 15
Choose
YourOwn
Adventure
Hacking the
cybersecurity
profession
@ BSidesCharm 2019
B. Andrzejewski
Disclaimers
Yup, I must say these things…
Personal Views
These do not
represent my
employers
(past or present)
Personal
Experiences
Nobody’s journey
is the same
Results may vary.
Lots of
Memes
Lots of memes,
all the memes
(I like memes)
2
B. Andrzejewski 3
About Me
• 20+ yrs IT w/ 10+ yrs InfoSec
(1099, Academia, Healthcare,
Military, Federal, Large Enterprise)
• Help customers through “bad day”
events (…and preventing them)
• Former 8yr Fed in DoD & DHS
• Specialize in Incident Response,
AppSec, DevSecOps, CloudSec, &
VulnSec (fluent in Dev, Ops, RMF)
• Interview and phone screen at
least twice a week (or more…)
B. Andrzejewski
My Journey Into InfoSec
Web Developer
Dot Com Boom (and
bust) for Content
Management and
eCommerce systems.
Again for military.
IT Support
Home, college
computer lab,
residential dial up,
and small business.
IT Procurement
Standardized IT
vendors, goods, and
services. Set policies
and processes for IT
asset lifecycle.
System Admin
System admin
supporting 400+
servers, 10,000
endpoints as Tier 2 &
3 support.
Military Outreach
Public Affairs and
Community Relations.
Conferences,
communications, joint
exercises, and vendor
demos.
4
B. Andrzejewski
How I stepped into this…
○ 2008 - Ran proxy and endpoint security as Healthcare SysAdmin
• Fought Conficker backdooring our network and finding Child Porn from employee
○ 2009- Accidently landed at largest government Digital Forensics lab in the world
• Hired as DoD Contractor to develop PHP applications (for more pay!)
• Programmed and organized DF exercises to general public for DoD, academia, & non-profits
(US Cyber Challenge, NCCDC, CyberPatriot, CSAW)
• Helped defined DF Knowledge, Skills, and Abilities (KSAs) into public Outreach programs
(CDFAE, CNCI-8, NIST)
• Took the “opportunity” as organization’s RDT&E Program Manager and technical lead for cyber
threat information sharing between DoD, DHS, US CyberCom, FBI Cyber, Dept. of Energy w/
MITRE + JHU APL – became v1 of STIX and TAXII (CNCI-5 / ESSA)
5
B. Andrzejewski
How I stepped into this…
○2015 - Leveled up as a Lead Security Engineer
• Defended the biggest immigration systems in the world – in the cloud!
• Developed “Trust, then verify” purple team exercises to validate blue team
tools, processes, procedures (TTPs)
• Organized requested audits from DHS IG, GAO, and congressional inquiries
• Represented DHS as technical SME - taught others in DHS and Fed space about
CloudSec, AppSec, Incident Response, and DevSecOps – even to RMF
• Spoke at OPM on Cybersecurity workforce needs
○2018 – Left Feds for commercial security consulting
6
2016 DHS CISO’s Security
Engineer of the Year
B. Andrzejewski 7
CNCI-8
I was
here Circa2009
B. Andrzejewski
NICE Cybersecurity Workforce Framework
8
https://niccs.us-cert.gov/
Analyze Collect &
Operate
Investigate Operate &
Maintain
Protect &
Defend
Securely
Provision
Started as CNCI-8 with DoD, DHS, IC, & NIST
Morphed into DHS US-CERT as NICE Framework in 2010
Lays out knowledge, skills, and abilities needed to each cyber profession job type
Grew “legs” starting in 2017 with Executive Order 13800
B. Andrzejewski 9
InfoSec’s
Continuous
Dumpster Fires
• HR job description dysentery
• Exodus by exclusion of
individuals and burnout
• Security “curmudgeons” vs.
resources & budgets
• Internal org promotion
• Imposter syndrome
B. Andrzejewski
Now What?
“No battle plan survives contact with the enemy.”
- Helmuth von Moltke the Elder
• Infosec is not:
• A linear path or planned progression
• Certification(s) and degrees(s)
• Culture of “no” w/o risk assessment
• InfoSec is:
• For those that like to ask “why” –
either to break, build, or resolve
• Focusing on the outcomes
• Continuous evolution to your threats
• InfoSec requires:
• Keeping work-life balance in check
• Watching for burn-out
B. Andrzejewski
The Adventure - InfoSec “Guilding” Pathway
Opportunity to Grow
Apprentice
Learn and train to a
specific skillset to learn
the craft with
supervision.
Refining Skills
Journeyman
Able to work
independently without
supervision, add
additional skills, and
mentor apprentices
Artisans
Master
Able to work
independently, mentor
others, and lead teams
11
No one way in Generalize & specialize
(Pivot or rabbit hole)
Sorcerers and
sorceresses
B. Andrzejewski
• Passion for your tradecraft
• Use blogs, competitions,
classroom, online learning
• Sharing experiences back
• Mentoring & blogging
• Writing down how you
solved problem X with
methods A & B
• Presenting & volunteering
• Teamwork over “rock star”
• Translate “security-esse”
into tangible risks & costs
• Processes
• Resources vs. time
• Ability to communicate
• Verbally
• Written
• Presentation
• Depth
• Basics (OSes, Networks)
• Security Tooling Experience
• Security Concepts
• Bonus: Automation
• Breath
• Types of hands on
• Individual vs. team efforts
Planning your Next Advance
Continuous Learning
12
Soft Skills Abilities Tech Depth & Breath
What Recruiters are looking for
B. Andrzejewski
Execute your Next Advance
○ Evaluate where you are vs. to go
• Look every quarter where you are
• Figure out what “is next” to learn
• Keep an eye out for new opportunities
○ Know your worth
• Apply & interview often to “market set” - even
if happy or to use to counter for promotions
• Ask for a salary “where you will not laugh”
• Never disclose your current compensation
• Look at the *total* package (salary, stock,
healthcare, time off, 401k match)
13
B. Andrzejewski
On Resume and At Interview
○ For Resume
• Place your key, most recent skills at *top* of resume
• List about your experiences – both personal & professional
• “Elevator pitch” one liner on what your position does
• What you are working on (without giving away confidentiality)
• Where you went “beyond the call of duty” – not long hours
○ At Interview
• Respond about experiences in STAR (situation, task, action,
result) format
• Talk about *your* contributions to the team – not what team did
• Ask interviewers about their challenges and “team” environment –
these are *early* indicators of organization’s culture
14
B. Andrzejewski
○ There is not one linear or
“wrong” path
○ Include and raise others to
teach the guild’s “tradecraft”
○ Continuously learn via home
labs, competitions, CTFs,
training, Bsides, blogs, etc.
○ Always re-assess your career
every 2-3 years for the next
“best” hop and to know your
“market” worth Summary
No journey into InfoSec is the same

More Related Content

Similar to Choose your own adventure: hacking the cybersecurity profession (BSidesCharm 2019)

Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...Stephen Cobb
 
TOA - How to survive a TechDD workshop
TOA - How to survive a TechDD workshopTOA - How to survive a TechDD workshop
TOA - How to survive a TechDD workshopChris Philipps
 
Using Expertise - The Story So Far
Using Expertise - The Story So FarUsing Expertise - The Story So Far
Using Expertise - The Story So FarMatthew Moore
 
Seed Fundraising and Angels; Entrepreneurs Roundtable Accelerator (ERA)
Seed Fundraising and Angels;  Entrepreneurs Roundtable Accelerator (ERA)Seed Fundraising and Angels;  Entrepreneurs Roundtable Accelerator (ERA)
Seed Fundraising and Angels; Entrepreneurs Roundtable Accelerator (ERA)Thomas Wisniewski
 
MBA Presentation 042015_v4
MBA Presentation 042015_v4MBA Presentation 042015_v4
MBA Presentation 042015_v4Bill Crowe
 
How to shine in a Tech DD
How to shine in a Tech DDHow to shine in a Tech DD
How to shine in a Tech DDChris Philipps
 
Learning Insights for the New Year [WEBINAR]
Learning Insights for the New Year [WEBINAR]Learning Insights for the New Year [WEBINAR]
Learning Insights for the New Year [WEBINAR]Kineo
 
So, you wanna be a pen tester ctsc2017
So, you wanna be a pen tester   ctsc2017So, you wanna be a pen tester   ctsc2017
So, you wanna be a pen tester ctsc2017Adrien de Beaupre
 
Be the Captain of Your Career
Be the Captain of Your Career Be the Captain of Your Career
Be the Captain of Your Career Jack Molisani
 
Lecture on Innovation at Startups at ESADE
Lecture on Innovation at Startups at ESADELecture on Innovation at Startups at ESADE
Lecture on Innovation at Startups at ESADEMichael Wolfe
 
Startup Engineering Flashpoint Batch 3 Better Startups Faster
Startup Engineering   Flashpoint Batch 3   Better Startups FasterStartup Engineering   Flashpoint Batch 3   Better Startups Faster
Startup Engineering Flashpoint Batch 3 Better Startups Fastermerrickfurst
 
Pitching the Plan and Financial Projections
Pitching the Plan and Financial ProjectionsPitching the Plan and Financial Projections
Pitching the Plan and Financial ProjectionsThe Capital Network
 
Entrepreneurship Northwest - Accelerating ideas into reality - Open 2011
Entrepreneurship Northwest - Accelerating ideas into reality - Open 2011Entrepreneurship Northwest - Accelerating ideas into reality - Open 2011
Entrepreneurship Northwest - Accelerating ideas into reality - Open 2011the nciia
 
CSA Fall Summit 2017
CSA Fall Summit 2017CSA Fall Summit 2017
CSA Fall Summit 2017Chad Hoffmann
 
Ten lessons I painfully learnt while moving from software developer to entrep...
Ten lessons I painfully learnt while moving from software developer to entrep...Ten lessons I painfully learnt while moving from software developer to entrep...
Ten lessons I painfully learnt while moving from software developer to entrep...Wojciech Seliga
 
What is the Martin Trust Center for MIT Entrepreneurship & Why Is it So Awesome?
What is the Martin Trust Center for MIT Entrepreneurship & Why Is it So Awesome?What is the Martin Trust Center for MIT Entrepreneurship & Why Is it So Awesome?
What is the Martin Trust Center for MIT Entrepreneurship & Why Is it So Awesome?Massachusetts Institute of Technology
 
Keynote: Innovation, Leadership, and Psychology
Keynote: Innovation, Leadership, and PsychologyKeynote: Innovation, Leadership, and Psychology
Keynote: Innovation, Leadership, and PsychologyIkhlaq Sidhu
 

Similar to Choose your own adventure: hacking the cybersecurity profession (BSidesCharm 2019) (20)

Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...
 
TOA - How to survive a TechDD workshop
TOA - How to survive a TechDD workshopTOA - How to survive a TechDD workshop
TOA - How to survive a TechDD workshop
 
Energize 2013 slides
Energize 2013 slidesEnergize 2013 slides
Energize 2013 slides
 
Using Expertise - The Story So Far
Using Expertise - The Story So FarUsing Expertise - The Story So Far
Using Expertise - The Story So Far
 
How to pitch your biotech idea
How to pitch your biotech ideaHow to pitch your biotech idea
How to pitch your biotech idea
 
Seed Fundraising and Angels; Entrepreneurs Roundtable Accelerator (ERA)
Seed Fundraising and Angels;  Entrepreneurs Roundtable Accelerator (ERA)Seed Fundraising and Angels;  Entrepreneurs Roundtable Accelerator (ERA)
Seed Fundraising and Angels; Entrepreneurs Roundtable Accelerator (ERA)
 
MBA Presentation 042015_v4
MBA Presentation 042015_v4MBA Presentation 042015_v4
MBA Presentation 042015_v4
 
How to shine in a Tech DD
How to shine in a Tech DDHow to shine in a Tech DD
How to shine in a Tech DD
 
Learning Insights for the New Year [WEBINAR]
Learning Insights for the New Year [WEBINAR]Learning Insights for the New Year [WEBINAR]
Learning Insights for the New Year [WEBINAR]
 
class1 MBA
class1 MBAclass1 MBA
class1 MBA
 
So, you wanna be a pen tester ctsc2017
So, you wanna be a pen tester   ctsc2017So, you wanna be a pen tester   ctsc2017
So, you wanna be a pen tester ctsc2017
 
Be the Captain of Your Career
Be the Captain of Your Career Be the Captain of Your Career
Be the Captain of Your Career
 
Lecture on Innovation at Startups at ESADE
Lecture on Innovation at Startups at ESADELecture on Innovation at Startups at ESADE
Lecture on Innovation at Startups at ESADE
 
Startup Engineering Flashpoint Batch 3 Better Startups Faster
Startup Engineering   Flashpoint Batch 3   Better Startups FasterStartup Engineering   Flashpoint Batch 3   Better Startups Faster
Startup Engineering Flashpoint Batch 3 Better Startups Faster
 
Pitching the Plan and Financial Projections
Pitching the Plan and Financial ProjectionsPitching the Plan and Financial Projections
Pitching the Plan and Financial Projections
 
Entrepreneurship Northwest - Accelerating ideas into reality - Open 2011
Entrepreneurship Northwest - Accelerating ideas into reality - Open 2011Entrepreneurship Northwest - Accelerating ideas into reality - Open 2011
Entrepreneurship Northwest - Accelerating ideas into reality - Open 2011
 
CSA Fall Summit 2017
CSA Fall Summit 2017CSA Fall Summit 2017
CSA Fall Summit 2017
 
Ten lessons I painfully learnt while moving from software developer to entrep...
Ten lessons I painfully learnt while moving from software developer to entrep...Ten lessons I painfully learnt while moving from software developer to entrep...
Ten lessons I painfully learnt while moving from software developer to entrep...
 
What is the Martin Trust Center for MIT Entrepreneurship & Why Is it So Awesome?
What is the Martin Trust Center for MIT Entrepreneurship & Why Is it So Awesome?What is the Martin Trust Center for MIT Entrepreneurship & Why Is it So Awesome?
What is the Martin Trust Center for MIT Entrepreneurship & Why Is it So Awesome?
 
Keynote: Innovation, Leadership, and Psychology
Keynote: Innovation, Leadership, and PsychologyKeynote: Innovation, Leadership, and Psychology
Keynote: Innovation, Leadership, and Psychology
 

Recently uploaded

Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr LapshynFwdays
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Wonjun Hwang
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 

Recently uploaded (20)

Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 

Choose your own adventure: hacking the cybersecurity profession (BSidesCharm 2019)

  • 2. B. Andrzejewski Disclaimers Yup, I must say these things… Personal Views These do not represent my employers (past or present) Personal Experiences Nobody’s journey is the same Results may vary. Lots of Memes Lots of memes, all the memes (I like memes) 2
  • 3. B. Andrzejewski 3 About Me • 20+ yrs IT w/ 10+ yrs InfoSec (1099, Academia, Healthcare, Military, Federal, Large Enterprise) • Help customers through “bad day” events (…and preventing them) • Former 8yr Fed in DoD & DHS • Specialize in Incident Response, AppSec, DevSecOps, CloudSec, & VulnSec (fluent in Dev, Ops, RMF) • Interview and phone screen at least twice a week (or more…)
  • 4. B. Andrzejewski My Journey Into InfoSec Web Developer Dot Com Boom (and bust) for Content Management and eCommerce systems. Again for military. IT Support Home, college computer lab, residential dial up, and small business. IT Procurement Standardized IT vendors, goods, and services. Set policies and processes for IT asset lifecycle. System Admin System admin supporting 400+ servers, 10,000 endpoints as Tier 2 & 3 support. Military Outreach Public Affairs and Community Relations. Conferences, communications, joint exercises, and vendor demos. 4
  • 5. B. Andrzejewski How I stepped into this… ○ 2008 - Ran proxy and endpoint security as Healthcare SysAdmin • Fought Conficker backdooring our network and finding Child Porn from employee ○ 2009- Accidently landed at largest government Digital Forensics lab in the world • Hired as DoD Contractor to develop PHP applications (for more pay!) • Programmed and organized DF exercises to general public for DoD, academia, & non-profits (US Cyber Challenge, NCCDC, CyberPatriot, CSAW) • Helped defined DF Knowledge, Skills, and Abilities (KSAs) into public Outreach programs (CDFAE, CNCI-8, NIST) • Took the “opportunity” as organization’s RDT&E Program Manager and technical lead for cyber threat information sharing between DoD, DHS, US CyberCom, FBI Cyber, Dept. of Energy w/ MITRE + JHU APL – became v1 of STIX and TAXII (CNCI-5 / ESSA) 5
  • 6. B. Andrzejewski How I stepped into this… ○2015 - Leveled up as a Lead Security Engineer • Defended the biggest immigration systems in the world – in the cloud! • Developed “Trust, then verify” purple team exercises to validate blue team tools, processes, procedures (TTPs) • Organized requested audits from DHS IG, GAO, and congressional inquiries • Represented DHS as technical SME - taught others in DHS and Fed space about CloudSec, AppSec, Incident Response, and DevSecOps – even to RMF • Spoke at OPM on Cybersecurity workforce needs ○2018 – Left Feds for commercial security consulting 6 2016 DHS CISO’s Security Engineer of the Year
  • 7. B. Andrzejewski 7 CNCI-8 I was here Circa2009
  • 8. B. Andrzejewski NICE Cybersecurity Workforce Framework 8 https://niccs.us-cert.gov/ Analyze Collect & Operate Investigate Operate & Maintain Protect & Defend Securely Provision Started as CNCI-8 with DoD, DHS, IC, & NIST Morphed into DHS US-CERT as NICE Framework in 2010 Lays out knowledge, skills, and abilities needed to each cyber profession job type Grew “legs” starting in 2017 with Executive Order 13800
  • 9. B. Andrzejewski 9 InfoSec’s Continuous Dumpster Fires • HR job description dysentery • Exodus by exclusion of individuals and burnout • Security “curmudgeons” vs. resources & budgets • Internal org promotion • Imposter syndrome
  • 10. B. Andrzejewski Now What? “No battle plan survives contact with the enemy.” - Helmuth von Moltke the Elder • Infosec is not: • A linear path or planned progression • Certification(s) and degrees(s) • Culture of “no” w/o risk assessment • InfoSec is: • For those that like to ask “why” – either to break, build, or resolve • Focusing on the outcomes • Continuous evolution to your threats • InfoSec requires: • Keeping work-life balance in check • Watching for burn-out
  • 11. B. Andrzejewski The Adventure - InfoSec “Guilding” Pathway Opportunity to Grow Apprentice Learn and train to a specific skillset to learn the craft with supervision. Refining Skills Journeyman Able to work independently without supervision, add additional skills, and mentor apprentices Artisans Master Able to work independently, mentor others, and lead teams 11 No one way in Generalize & specialize (Pivot or rabbit hole) Sorcerers and sorceresses
  • 12. B. Andrzejewski • Passion for your tradecraft • Use blogs, competitions, classroom, online learning • Sharing experiences back • Mentoring & blogging • Writing down how you solved problem X with methods A & B • Presenting & volunteering • Teamwork over “rock star” • Translate “security-esse” into tangible risks & costs • Processes • Resources vs. time • Ability to communicate • Verbally • Written • Presentation • Depth • Basics (OSes, Networks) • Security Tooling Experience • Security Concepts • Bonus: Automation • Breath • Types of hands on • Individual vs. team efforts Planning your Next Advance Continuous Learning 12 Soft Skills Abilities Tech Depth & Breath What Recruiters are looking for
  • 13. B. Andrzejewski Execute your Next Advance ○ Evaluate where you are vs. to go • Look every quarter where you are • Figure out what “is next” to learn • Keep an eye out for new opportunities ○ Know your worth • Apply & interview often to “market set” - even if happy or to use to counter for promotions • Ask for a salary “where you will not laugh” • Never disclose your current compensation • Look at the *total* package (salary, stock, healthcare, time off, 401k match) 13
  • 14. B. Andrzejewski On Resume and At Interview ○ For Resume • Place your key, most recent skills at *top* of resume • List about your experiences – both personal & professional • “Elevator pitch” one liner on what your position does • What you are working on (without giving away confidentiality) • Where you went “beyond the call of duty” – not long hours ○ At Interview • Respond about experiences in STAR (situation, task, action, result) format • Talk about *your* contributions to the team – not what team did • Ask interviewers about their challenges and “team” environment – these are *early* indicators of organization’s culture 14
  • 15. B. Andrzejewski ○ There is not one linear or “wrong” path ○ Include and raise others to teach the guild’s “tradecraft” ○ Continuously learn via home labs, competitions, CTFs, training, Bsides, blogs, etc. ○ Always re-assess your career every 2-3 years for the next “best” hop and to know your “market” worth Summary No journey into InfoSec is the same