SlideShare a Scribd company logo
Choose
YourOwn
Adventure
Hacking the
cybersecurity
profession
@ BSidesCharm 2019
B. Andrzejewski
Disclaimers
Yup, I must say these things…
Personal Views
These do not
represent my
employers
(past or present)
Personal
Experiences
Nobody’s journey
is the same
Results may vary.
Lots of
Memes
Lots of memes,
all the memes
(I like memes)
2
B. Andrzejewski 3
About Me
• 20+ yrs IT w/ 10+ yrs InfoSec
(1099, Academia, Healthcare,
Military, Federal, Large Enterprise)
• Help customers through “bad day”
events (…and preventing them)
• Former 8yr Fed in DoD & DHS
• Specialize in Incident Response,
AppSec, DevSecOps, CloudSec, &
VulnSec (fluent in Dev, Ops, RMF)
• Interview and phone screen at
least twice a week (or more…)
B. Andrzejewski
My Journey Into InfoSec
Web Developer
Dot Com Boom (and
bust) for Content
Management and
eCommerce systems.
Again for military.
IT Support
Home, college
computer lab,
residential dial up,
and small business.
IT Procurement
Standardized IT
vendors, goods, and
services. Set policies
and processes for IT
asset lifecycle.
System Admin
System admin
supporting 400+
servers, 10,000
endpoints as Tier 2 &
3 support.
Military Outreach
Public Affairs and
Community Relations.
Conferences,
communications, joint
exercises, and vendor
demos.
4
B. Andrzejewski
How I stepped into this…
○ 2008 - Ran proxy and endpoint security as Healthcare SysAdmin
• Fought Conficker backdooring our network and finding Child Porn from employee
○ 2009- Accidently landed at largest government Digital Forensics lab in the world
• Hired as DoD Contractor to develop PHP applications (for more pay!)
• Programmed and organized DF exercises to general public for DoD, academia, & non-profits
(US Cyber Challenge, NCCDC, CyberPatriot, CSAW)
• Helped defined DF Knowledge, Skills, and Abilities (KSAs) into public Outreach programs
(CDFAE, CNCI-8, NIST)
• Took the “opportunity” as organization’s RDT&E Program Manager and technical lead for cyber
threat information sharing between DoD, DHS, US CyberCom, FBI Cyber, Dept. of Energy w/
MITRE + JHU APL – became v1 of STIX and TAXII (CNCI-5 / ESSA)
5
B. Andrzejewski
How I stepped into this…
○2015 - Leveled up as a Lead Security Engineer
• Defended the biggest immigration systems in the world – in the cloud!
• Developed “Trust, then verify” purple team exercises to validate blue team
tools, processes, procedures (TTPs)
• Organized requested audits from DHS IG, GAO, and congressional inquiries
• Represented DHS as technical SME - taught others in DHS and Fed space about
CloudSec, AppSec, Incident Response, and DevSecOps – even to RMF
• Spoke at OPM on Cybersecurity workforce needs
○2018 – Left Feds for commercial security consulting
6
2016 DHS CISO’s Security
Engineer of the Year
B. Andrzejewski 7
CNCI-8
I was
here Circa2009
B. Andrzejewski
NICE Cybersecurity Workforce Framework
8
https://niccs.us-cert.gov/
Analyze Collect &
Operate
Investigate Operate &
Maintain
Protect &
Defend
Securely
Provision
Started as CNCI-8 with DoD, DHS, IC, & NIST
Morphed into DHS US-CERT as NICE Framework in 2010
Lays out knowledge, skills, and abilities needed to each cyber profession job type
Grew “legs” starting in 2017 with Executive Order 13800
B. Andrzejewski 9
InfoSec’s
Continuous
Dumpster Fires
• HR job description dysentery
• Exodus by exclusion of
individuals and burnout
• Security “curmudgeons” vs.
resources & budgets
• Internal org promotion
• Imposter syndrome
B. Andrzejewski
Now What?
“No battle plan survives contact with the enemy.”
- Helmuth von Moltke the Elder
• Infosec is not:
• A linear path or planned progression
• Certification(s) and degrees(s)
• Culture of “no” w/o risk assessment
• InfoSec is:
• For those that like to ask “why” –
either to break, build, or resolve
• Focusing on the outcomes
• Continuous evolution to your threats
• InfoSec requires:
• Keeping work-life balance in check
• Watching for burn-out
B. Andrzejewski
The Adventure - InfoSec “Guilding” Pathway
Opportunity to Grow
Apprentice
Learn and train to a
specific skillset to learn
the craft with
supervision.
Refining Skills
Journeyman
Able to work
independently without
supervision, add
additional skills, and
mentor apprentices
Artisans
Master
Able to work
independently, mentor
others, and lead teams
11
No one way in Generalize & specialize
(Pivot or rabbit hole)
Sorcerers and
sorceresses
B. Andrzejewski
• Passion for your tradecraft
• Use blogs, competitions,
classroom, online learning
• Sharing experiences back
• Mentoring & blogging
• Writing down how you
solved problem X with
methods A & B
• Presenting & volunteering
• Teamwork over “rock star”
• Translate “security-esse”
into tangible risks & costs
• Processes
• Resources vs. time
• Ability to communicate
• Verbally
• Written
• Presentation
• Depth
• Basics (OSes, Networks)
• Security Tooling Experience
• Security Concepts
• Bonus: Automation
• Breath
• Types of hands on
• Individual vs. team efforts
Planning your Next Advance
Continuous Learning
12
Soft Skills Abilities Tech Depth & Breath
What Recruiters are looking for
B. Andrzejewski
Execute your Next Advance
○ Evaluate where you are vs. to go
• Look every quarter where you are
• Figure out what “is next” to learn
• Keep an eye out for new opportunities
○ Know your worth
• Apply & interview often to “market set” - even
if happy or to use to counter for promotions
• Ask for a salary “where you will not laugh”
• Never disclose your current compensation
• Look at the *total* package (salary, stock,
healthcare, time off, 401k match)
13
B. Andrzejewski
On Resume and At Interview
○ For Resume
• Place your key, most recent skills at *top* of resume
• List about your experiences – both personal & professional
• “Elevator pitch” one liner on what your position does
• What you are working on (without giving away confidentiality)
• Where you went “beyond the call of duty” – not long hours
○ At Interview
• Respond about experiences in STAR (situation, task, action,
result) format
• Talk about *your* contributions to the team – not what team did
• Ask interviewers about their challenges and “team” environment –
these are *early* indicators of organization’s culture
14
B. Andrzejewski
○ There is not one linear or
“wrong” path
○ Include and raise others to
teach the guild’s “tradecraft”
○ Continuously learn via home
labs, competitions, CTFs,
training, Bsides, blogs, etc.
○ Always re-assess your career
every 2-3 years for the next
“best” hop and to know your
“market” worth Summary
No journey into InfoSec is the same

More Related Content

Similar to Choose your own adventure: hacking the cybersecurity profession (BSidesCharm 2019)

Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...
Stephen Cobb
 
TOA - How to survive a TechDD workshop
TOA - How to survive a TechDD workshopTOA - How to survive a TechDD workshop
TOA - How to survive a TechDD workshop
Chris Philipps
 
Energize 2013 slides
Energize 2013 slidesEnergize 2013 slides
Energize 2013 slides
Norris Krueger
 
Using Expertise - The Story So Far
Using Expertise - The Story So FarUsing Expertise - The Story So Far
Using Expertise - The Story So Far
Matthew Moore
 
How to pitch your biotech idea
How to pitch your biotech ideaHow to pitch your biotech idea
How to pitch your biotech idea
Villgro Innovations Foundation
 
Seed Fundraising and Angels; Entrepreneurs Roundtable Accelerator (ERA)
Seed Fundraising and Angels;  Entrepreneurs Roundtable Accelerator (ERA)Seed Fundraising and Angels;  Entrepreneurs Roundtable Accelerator (ERA)
Seed Fundraising and Angels; Entrepreneurs Roundtable Accelerator (ERA)
Thomas Wisniewski
 
MBA Presentation 042015_v4
MBA Presentation 042015_v4MBA Presentation 042015_v4
MBA Presentation 042015_v4
Bill Crowe
 
How to shine in a Tech DD
How to shine in a Tech DDHow to shine in a Tech DD
How to shine in a Tech DD
Chris Philipps
 
Learning Insights for the New Year [WEBINAR]
Learning Insights for the New Year [WEBINAR]Learning Insights for the New Year [WEBINAR]
Learning Insights for the New Year [WEBINAR]
Kineo
 
class1 MBA
class1 MBAclass1 MBA
class1 MBA
PinkWarissara
 
So, you wanna be a pen tester ctsc2017
So, you wanna be a pen tester   ctsc2017So, you wanna be a pen tester   ctsc2017
So, you wanna be a pen tester ctsc2017
Adrien de Beaupre
 
Be the Captain of Your Career
Be the Captain of Your Career Be the Captain of Your Career
Be the Captain of Your Career
Jack Molisani
 
Lecture on Innovation at Startups at ESADE
Lecture on Innovation at Startups at ESADELecture on Innovation at Startups at ESADE
Lecture on Innovation at Startups at ESADE
Michael Wolfe
 
Startup Engineering Flashpoint Batch 3 Better Startups Faster
Startup Engineering   Flashpoint Batch 3   Better Startups FasterStartup Engineering   Flashpoint Batch 3   Better Startups Faster
Startup Engineering Flashpoint Batch 3 Better Startups Faster
merrickfurst
 
Pitching the Plan and Financial Projections
Pitching the Plan and Financial ProjectionsPitching the Plan and Financial Projections
Pitching the Plan and Financial Projections
The Capital Network
 
Entrepreneurship Northwest - Accelerating ideas into reality - Open 2011
Entrepreneurship Northwest - Accelerating ideas into reality - Open 2011Entrepreneurship Northwest - Accelerating ideas into reality - Open 2011
Entrepreneurship Northwest - Accelerating ideas into reality - Open 2011
the nciia
 
CSA Fall Summit 2017
CSA Fall Summit 2017CSA Fall Summit 2017
CSA Fall Summit 2017
Chad Hoffmann
 
Ten lessons I painfully learnt while moving from software developer to entrep...
Ten lessons I painfully learnt while moving from software developer to entrep...Ten lessons I painfully learnt while moving from software developer to entrep...
Ten lessons I painfully learnt while moving from software developer to entrep...
Wojciech Seliga
 
What is the Martin Trust Center for MIT Entrepreneurship & Why Is it So Awesome?
What is the Martin Trust Center for MIT Entrepreneurship & Why Is it So Awesome?What is the Martin Trust Center for MIT Entrepreneurship & Why Is it So Awesome?
What is the Martin Trust Center for MIT Entrepreneurship & Why Is it So Awesome?
Massachusetts Institute of Technology
 
Keynote: Innovation, Leadership, and Psychology
Keynote: Innovation, Leadership, and PsychologyKeynote: Innovation, Leadership, and Psychology
Keynote: Innovation, Leadership, and Psychology
Ikhlaq Sidhu
 

Similar to Choose your own adventure: hacking the cybersecurity profession (BSidesCharm 2019) (20)

Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...
 
TOA - How to survive a TechDD workshop
TOA - How to survive a TechDD workshopTOA - How to survive a TechDD workshop
TOA - How to survive a TechDD workshop
 
Energize 2013 slides
Energize 2013 slidesEnergize 2013 slides
Energize 2013 slides
 
Using Expertise - The Story So Far
Using Expertise - The Story So FarUsing Expertise - The Story So Far
Using Expertise - The Story So Far
 
How to pitch your biotech idea
How to pitch your biotech ideaHow to pitch your biotech idea
How to pitch your biotech idea
 
Seed Fundraising and Angels; Entrepreneurs Roundtable Accelerator (ERA)
Seed Fundraising and Angels;  Entrepreneurs Roundtable Accelerator (ERA)Seed Fundraising and Angels;  Entrepreneurs Roundtable Accelerator (ERA)
Seed Fundraising and Angels; Entrepreneurs Roundtable Accelerator (ERA)
 
MBA Presentation 042015_v4
MBA Presentation 042015_v4MBA Presentation 042015_v4
MBA Presentation 042015_v4
 
How to shine in a Tech DD
How to shine in a Tech DDHow to shine in a Tech DD
How to shine in a Tech DD
 
Learning Insights for the New Year [WEBINAR]
Learning Insights for the New Year [WEBINAR]Learning Insights for the New Year [WEBINAR]
Learning Insights for the New Year [WEBINAR]
 
class1 MBA
class1 MBAclass1 MBA
class1 MBA
 
So, you wanna be a pen tester ctsc2017
So, you wanna be a pen tester   ctsc2017So, you wanna be a pen tester   ctsc2017
So, you wanna be a pen tester ctsc2017
 
Be the Captain of Your Career
Be the Captain of Your Career Be the Captain of Your Career
Be the Captain of Your Career
 
Lecture on Innovation at Startups at ESADE
Lecture on Innovation at Startups at ESADELecture on Innovation at Startups at ESADE
Lecture on Innovation at Startups at ESADE
 
Startup Engineering Flashpoint Batch 3 Better Startups Faster
Startup Engineering   Flashpoint Batch 3   Better Startups FasterStartup Engineering   Flashpoint Batch 3   Better Startups Faster
Startup Engineering Flashpoint Batch 3 Better Startups Faster
 
Pitching the Plan and Financial Projections
Pitching the Plan and Financial ProjectionsPitching the Plan and Financial Projections
Pitching the Plan and Financial Projections
 
Entrepreneurship Northwest - Accelerating ideas into reality - Open 2011
Entrepreneurship Northwest - Accelerating ideas into reality - Open 2011Entrepreneurship Northwest - Accelerating ideas into reality - Open 2011
Entrepreneurship Northwest - Accelerating ideas into reality - Open 2011
 
CSA Fall Summit 2017
CSA Fall Summit 2017CSA Fall Summit 2017
CSA Fall Summit 2017
 
Ten lessons I painfully learnt while moving from software developer to entrep...
Ten lessons I painfully learnt while moving from software developer to entrep...Ten lessons I painfully learnt while moving from software developer to entrep...
Ten lessons I painfully learnt while moving from software developer to entrep...
 
What is the Martin Trust Center for MIT Entrepreneurship & Why Is it So Awesome?
What is the Martin Trust Center for MIT Entrepreneurship & Why Is it So Awesome?What is the Martin Trust Center for MIT Entrepreneurship & Why Is it So Awesome?
What is the Martin Trust Center for MIT Entrepreneurship & Why Is it So Awesome?
 
Keynote: Innovation, Leadership, and Psychology
Keynote: Innovation, Leadership, and PsychologyKeynote: Innovation, Leadership, and Psychology
Keynote: Innovation, Leadership, and Psychology
 

Recently uploaded

Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
SOFTTECHHUB
 
Introducing Milvus Lite: Easy-to-Install, Easy-to-Use vector database for you...
Introducing Milvus Lite: Easy-to-Install, Easy-to-Use vector database for you...Introducing Milvus Lite: Easy-to-Install, Easy-to-Use vector database for you...
Introducing Milvus Lite: Easy-to-Install, Easy-to-Use vector database for you...
Zilliz
 
GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...
GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...
GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...
Neo4j
 
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
Edge AI and Vision Alliance
 
Microsoft - Power Platform_G.Aspiotis.pdf
Microsoft - Power Platform_G.Aspiotis.pdfMicrosoft - Power Platform_G.Aspiotis.pdf
Microsoft - Power Platform_G.Aspiotis.pdf
Uni Systems S.M.S.A.
 
Climate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing DaysClimate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing Days
Kari Kakkonen
 
Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !
KatiaHIMEUR1
 
PCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase TeamPCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase Team
ControlCase
 
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdfUnlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Malak Abu Hammad
 
20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
Matthew Sinclair
 
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdfObservability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Paige Cruz
 
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
Neo4j
 
Video Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the FutureVideo Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the Future
Alpen-Adria-Universität
 
Mind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AIMind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AI
Kumud Singh
 
GraphSummit Singapore | The Art of the Possible with Graph - Q2 2024
GraphSummit Singapore | The Art of the  Possible with Graph - Q2 2024GraphSummit Singapore | The Art of the  Possible with Graph - Q2 2024
GraphSummit Singapore | The Art of the Possible with Graph - Q2 2024
Neo4j
 
Introduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - CybersecurityIntroduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - Cybersecurity
mikeeftimakis1
 
GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024
GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024
GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024
Neo4j
 
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
SOFTTECHHUB
 
“I’m still / I’m still / Chaining from the Block”
“I’m still / I’m still / Chaining from the Block”“I’m still / I’m still / Chaining from the Block”
“I’m still / I’m still / Chaining from the Block”
Claudio Di Ciccio
 
A tale of scale & speed: How the US Navy is enabling software delivery from l...
A tale of scale & speed: How the US Navy is enabling software delivery from l...A tale of scale & speed: How the US Navy is enabling software delivery from l...
A tale of scale & speed: How the US Navy is enabling software delivery from l...
sonjaschweigert1
 

Recently uploaded (20)

Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
 
Introducing Milvus Lite: Easy-to-Install, Easy-to-Use vector database for you...
Introducing Milvus Lite: Easy-to-Install, Easy-to-Use vector database for you...Introducing Milvus Lite: Easy-to-Install, Easy-to-Use vector database for you...
Introducing Milvus Lite: Easy-to-Install, Easy-to-Use vector database for you...
 
GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...
GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...
GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...
 
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
 
Microsoft - Power Platform_G.Aspiotis.pdf
Microsoft - Power Platform_G.Aspiotis.pdfMicrosoft - Power Platform_G.Aspiotis.pdf
Microsoft - Power Platform_G.Aspiotis.pdf
 
Climate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing DaysClimate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing Days
 
Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !
 
PCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase TeamPCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase Team
 
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdfUnlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
 
20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
 
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdfObservability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
 
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
 
Video Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the FutureVideo Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the Future
 
Mind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AIMind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AI
 
GraphSummit Singapore | The Art of the Possible with Graph - Q2 2024
GraphSummit Singapore | The Art of the  Possible with Graph - Q2 2024GraphSummit Singapore | The Art of the  Possible with Graph - Q2 2024
GraphSummit Singapore | The Art of the Possible with Graph - Q2 2024
 
Introduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - CybersecurityIntroduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - Cybersecurity
 
GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024
GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024
GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024
 
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
 
“I’m still / I’m still / Chaining from the Block”
“I’m still / I’m still / Chaining from the Block”“I’m still / I’m still / Chaining from the Block”
“I’m still / I’m still / Chaining from the Block”
 
A tale of scale & speed: How the US Navy is enabling software delivery from l...
A tale of scale & speed: How the US Navy is enabling software delivery from l...A tale of scale & speed: How the US Navy is enabling software delivery from l...
A tale of scale & speed: How the US Navy is enabling software delivery from l...
 

Choose your own adventure: hacking the cybersecurity profession (BSidesCharm 2019)

  • 2. B. Andrzejewski Disclaimers Yup, I must say these things… Personal Views These do not represent my employers (past or present) Personal Experiences Nobody’s journey is the same Results may vary. Lots of Memes Lots of memes, all the memes (I like memes) 2
  • 3. B. Andrzejewski 3 About Me • 20+ yrs IT w/ 10+ yrs InfoSec (1099, Academia, Healthcare, Military, Federal, Large Enterprise) • Help customers through “bad day” events (…and preventing them) • Former 8yr Fed in DoD & DHS • Specialize in Incident Response, AppSec, DevSecOps, CloudSec, & VulnSec (fluent in Dev, Ops, RMF) • Interview and phone screen at least twice a week (or more…)
  • 4. B. Andrzejewski My Journey Into InfoSec Web Developer Dot Com Boom (and bust) for Content Management and eCommerce systems. Again for military. IT Support Home, college computer lab, residential dial up, and small business. IT Procurement Standardized IT vendors, goods, and services. Set policies and processes for IT asset lifecycle. System Admin System admin supporting 400+ servers, 10,000 endpoints as Tier 2 & 3 support. Military Outreach Public Affairs and Community Relations. Conferences, communications, joint exercises, and vendor demos. 4
  • 5. B. Andrzejewski How I stepped into this… ○ 2008 - Ran proxy and endpoint security as Healthcare SysAdmin • Fought Conficker backdooring our network and finding Child Porn from employee ○ 2009- Accidently landed at largest government Digital Forensics lab in the world • Hired as DoD Contractor to develop PHP applications (for more pay!) • Programmed and organized DF exercises to general public for DoD, academia, & non-profits (US Cyber Challenge, NCCDC, CyberPatriot, CSAW) • Helped defined DF Knowledge, Skills, and Abilities (KSAs) into public Outreach programs (CDFAE, CNCI-8, NIST) • Took the “opportunity” as organization’s RDT&E Program Manager and technical lead for cyber threat information sharing between DoD, DHS, US CyberCom, FBI Cyber, Dept. of Energy w/ MITRE + JHU APL – became v1 of STIX and TAXII (CNCI-5 / ESSA) 5
  • 6. B. Andrzejewski How I stepped into this… ○2015 - Leveled up as a Lead Security Engineer • Defended the biggest immigration systems in the world – in the cloud! • Developed “Trust, then verify” purple team exercises to validate blue team tools, processes, procedures (TTPs) • Organized requested audits from DHS IG, GAO, and congressional inquiries • Represented DHS as technical SME - taught others in DHS and Fed space about CloudSec, AppSec, Incident Response, and DevSecOps – even to RMF • Spoke at OPM on Cybersecurity workforce needs ○2018 – Left Feds for commercial security consulting 6 2016 DHS CISO’s Security Engineer of the Year
  • 7. B. Andrzejewski 7 CNCI-8 I was here Circa2009
  • 8. B. Andrzejewski NICE Cybersecurity Workforce Framework 8 https://niccs.us-cert.gov/ Analyze Collect & Operate Investigate Operate & Maintain Protect & Defend Securely Provision Started as CNCI-8 with DoD, DHS, IC, & NIST Morphed into DHS US-CERT as NICE Framework in 2010 Lays out knowledge, skills, and abilities needed to each cyber profession job type Grew “legs” starting in 2017 with Executive Order 13800
  • 9. B. Andrzejewski 9 InfoSec’s Continuous Dumpster Fires • HR job description dysentery • Exodus by exclusion of individuals and burnout • Security “curmudgeons” vs. resources & budgets • Internal org promotion • Imposter syndrome
  • 10. B. Andrzejewski Now What? “No battle plan survives contact with the enemy.” - Helmuth von Moltke the Elder • Infosec is not: • A linear path or planned progression • Certification(s) and degrees(s) • Culture of “no” w/o risk assessment • InfoSec is: • For those that like to ask “why” – either to break, build, or resolve • Focusing on the outcomes • Continuous evolution to your threats • InfoSec requires: • Keeping work-life balance in check • Watching for burn-out
  • 11. B. Andrzejewski The Adventure - InfoSec “Guilding” Pathway Opportunity to Grow Apprentice Learn and train to a specific skillset to learn the craft with supervision. Refining Skills Journeyman Able to work independently without supervision, add additional skills, and mentor apprentices Artisans Master Able to work independently, mentor others, and lead teams 11 No one way in Generalize & specialize (Pivot or rabbit hole) Sorcerers and sorceresses
  • 12. B. Andrzejewski • Passion for your tradecraft • Use blogs, competitions, classroom, online learning • Sharing experiences back • Mentoring & blogging • Writing down how you solved problem X with methods A & B • Presenting & volunteering • Teamwork over “rock star” • Translate “security-esse” into tangible risks & costs • Processes • Resources vs. time • Ability to communicate • Verbally • Written • Presentation • Depth • Basics (OSes, Networks) • Security Tooling Experience • Security Concepts • Bonus: Automation • Breath • Types of hands on • Individual vs. team efforts Planning your Next Advance Continuous Learning 12 Soft Skills Abilities Tech Depth & Breath What Recruiters are looking for
  • 13. B. Andrzejewski Execute your Next Advance ○ Evaluate where you are vs. to go • Look every quarter where you are • Figure out what “is next” to learn • Keep an eye out for new opportunities ○ Know your worth • Apply & interview often to “market set” - even if happy or to use to counter for promotions • Ask for a salary “where you will not laugh” • Never disclose your current compensation • Look at the *total* package (salary, stock, healthcare, time off, 401k match) 13
  • 14. B. Andrzejewski On Resume and At Interview ○ For Resume • Place your key, most recent skills at *top* of resume • List about your experiences – both personal & professional • “Elevator pitch” one liner on what your position does • What you are working on (without giving away confidentiality) • Where you went “beyond the call of duty” – not long hours ○ At Interview • Respond about experiences in STAR (situation, task, action, result) format • Talk about *your* contributions to the team – not what team did • Ask interviewers about their challenges and “team” environment – these are *early* indicators of organization’s culture 14
  • 15. B. Andrzejewski ○ There is not one linear or “wrong” path ○ Include and raise others to teach the guild’s “tradecraft” ○ Continuously learn via home labs, competitions, CTFs, training, Bsides, blogs, etc. ○ Always re-assess your career every 2-3 years for the next “best” hop and to know your “market” worth Summary No journey into InfoSec is the same