got a calling for a career in cyber security? maybe you want to … · if you’re manchester based...

2
Hi! I’m Ben, a recent graduate from Manchester University and now one of the junior security consultants here at NCC Group Everyone’s journey into cyber security is different, the important thing is to find what works for you. For example, I found writing scripts and tools helped me to understand new concepts more than attempting CTF challenges... e great thing about security is it applies to everything we do, therefore it’s important to choose something you enjoy and then consider it from a security point of view. I’ve listed some useful tips and resources below to help get you started on your path to the best career ever! Humble Bundle You can find bundles of security related books at relatively cheap prices Check out local meetups If you’re Manchester based make sure you check out ‘ManchesterGreyHats’, they run monthly meetups and workshops on security related topics. Keep up to date with the latest news I mainly use Twitter for this, it’s a great way to keep up to date with the latest vulnerabilities as well as finding useful blogs on security topics. There are a bunch of useful things to learn but I would reccomend starting with the below... Scripting languages Linux command line Understanding network protocols Common web application vulnerabilites Basic tools such as Burp suite, Nmap and Metasploit Here are some useful resources to help you learn... Immersive Labs https://www.immersivelabs.com/ Hack The Box https://www.hackthebox.eu/ OverTheWire http://overthewire.org/wargames/ Cryptopals https://cryptopals.com/ Web Security Academy https://portswigger.net/web-security Got a calling for a career in Cyber Security? Maybe you want to become a penetration tester but dont know where to begin... Well, we’re here to help! This handy guide will tell you more about the tips, tricks and resources required to point you in the right direction for a career in the InfoSec community.

Upload: others

Post on 16-Oct-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Got a calling for a career in Cyber Security? Maybe you want to … · If you’re Manchester based make sure you check out ‘ManchesterGreyHats’, they run monthly meetups and

Hi! I’m Ben, a recent graduate from Manchester University and

now one of the junior security consultants here at NCC Group

Everyone’s journey into cyber security is different, the important thing is to find what works for you. For example, I found writing scripts and tools helped me

to understand new concepts more than attempting CTF challenges...

The great thing about security is it applies to everything we do, therefore it’s important

to choose something you enjoy and then consider it from a security point of view.

I’ve listed some useful tips and resources below to help get you started on your path

to the best career ever!

Humble Bundle

You can find bundles of security related books at relatively cheap prices

Check out local meetups

If you’re Manchester based make sure you check out ‘ManchesterGreyHats’, they run monthly meetups and workshops on security related topics.

Keep up to date with the latest news

I mainly use Twitter for this, it’s a great way to keep up to date with the latestvulnerabilities as well as finding useful blogs on security topics.

There are a bunch of useful things to learn but I would reccomend starting with the below...

Scripting languages

Linux command line

Understanding network protocols

Common web application vulnerabilites

Basic tools such as Burp suite, Nmap and Metasploit

Here are some useful resources to help you learn...

Immersive Labs https://www.immersivelabs.com/

Hack The Box https://www.hackthebox.eu/

OverTheWire http://overthewire.org/wargames/

Cryptopals https://cryptopals.com/

Web Security Academy https://portswigger.net/web-security

Got a calling for a career in Cyber Security? Maybe you want to become a penetration tester but dont know where to begin...

Well, we’re here to help! This handy guide will tell you more about the tips, tricks and resources required to point you in the right direction for a career in the InfoSec community.

Page 2: Got a calling for a career in Cyber Security? Maybe you want to … · If you’re Manchester based make sure you check out ‘ManchesterGreyHats’, they run monthly meetups and

Hi I’m Saira!

I’m a student at the University ofManchester while on a placement year here at NCC Group. As both a student and intern I’ve outlined below a couple of things that have helped me to break through the barriers into the security industry...

A good starting point to learning more about security is gaining a basic understanding of network protocols and network design, which in turn will then help you to understand common threats vulnerabilities.

Once you have a basic understanding of these, you can start putting it into practice through online labs such as HackTheBox and HackThisSite

To gain a more in depth knowledge, books such as The Hacker’s Playbook are great because they are written by InfoSec professionals.

For networking and general career advice I highly recommend attending any InfoSec meetups in your area, they often hold CTFs and workshops which are not only valuable but fun as well!

See if there are any InfoSec societies at your university, I have one called ‘Crackchester’ who hold CTFs and workshops quite regularly.

Hi I’m Ryan, Talent Specialist at NCC Group. I’d like to give you some advice on making sure your CV is cyber secure when it comes applying for your first role in security!

So, what made you decide to get into InfoSec and where do you want your career to go? Perhaps its penetration testing or maybe you enjoy the forensics side of things. Whatever it might be, talk about your aspirations and motivations in your CV – it may change in the future, but it’s doesn’t hurt to have some sort of plan, as hiring managers will likely ask you about this.

Events and conferences are a big part of InfoSec – we even have our own internal conference called NCC Con. If I could give you one piece of advice, it would be to go to as many events as you can. You’ll most likely find a ‘Bsides’ event close to you, there is also Blackhat, 44con, and regular local Defcon meetups to name a few. Getting out to these events are fantastic for networking opportunities and allow us to put a face to a name.

Got questions? Feel free to connect with me on LinkedIn, contact me at [email protected] and follow our Careers account on Twitter @nccgroupcareers