how to be employed at the soc of tomorrow... today

53
Ryan Kovar – Staff Security Strategist Splunk How to be employed at the SOC of tomorrow… today.

Upload: ryan-kovar

Post on 22-Jan-2018

79 views

Category:

Presentations & Public Speaking


0 download

TRANSCRIPT

Page 1: How to be employed at the SOC of tomorrow... today

Ryan Kovar – Staff Security Strategist

Splunk

How to be employed at the SOC of tomorrow… today.

Page 2: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

• 17 years of cyber security experience

• Worked in US/UK Public Sector and DOD most recently in nation state hunting roles

• Enjoys clicking too fast, long walks in the woods, and data visualization

• Current role on Security Practice team focuses on incident/breach response, threat intelligence, and research

• Currently interested in automating methods to triage data collection for IR analyst review.

• Also investigating why printers are so insubordinate ಠ_ಠ

2

Staff Security Strategist

Minster of the OODAloopers

@meansec

Ryan Kovar: CISSP, MSc(Dist)

Page 3: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

- Where we come from

- Where are we today

- Changes

- Tomorrow

- Conclusion

Agenda

Page 4: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

How did we I get here…

Page 5: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 6: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

- 5000+ users

- 20+ servers

- 5732 feet of cat 5

- Way too many printer repairs

System Administrator

Page 7: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

- Contractor with NCIS/SOCA

- Unix SysAdmin

- Database security

- Baby’s first development

Systems Engineer

Page 8: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

- Created a SOC/NOC

- Moved into fulltime Security

- Dealt with incident handling and compliance

- So many audits… so many.

- SOX SOX SOX SOX SOX SOX PCI

Security Engineer

Page 9: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

- 100% nationstate hunting focus

- 2/3 R&D 1/3 analysis

- Much fun.

“Senior Principal” Security Engineer

Page 10: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

- Research

- Development

- Hunting with customers

- Building things

Staff Security Strategist

Page 11: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Where can we go today?

Page 12: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 13: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 14: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

But times they are a changing

Page 15: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 16: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 17: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 18: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 19: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 20: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 21: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 22: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

I’m not hear to spread FUD, but…

Page 23: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 24: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

- High Cost of Labor- Small Pool of Workers- Great Need

Page 25: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 26: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 27: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Hypothesis: Cyber Security roles will

greatly shrink in the next 10 years

Page 28: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 29: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 30: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 31: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 32: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 33: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

How can you prepare for tomorrow… today

Page 34: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Learn basic development skills

Page 35: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 36: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 37: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Learn Statistics

Page 38: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 39: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 40: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 41: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Learn to communicate

Page 42: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 43: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 44: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 45: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 46: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Learn to be curious

Page 47: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 48: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 49: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Page 50: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Conclusions

Page 51: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

- Our field is not a special snowflake

- The need for cybersecurity analysts and engineers greatly outstrips available pool of qualified personnel

- Businesses will figure out a way to fill the skill gap… with robots.

Historically good times turn to bad times

Page 52: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

- You can’t expect to work in this world and not learn how to deal with overwhelming amounts of data

- There is a plethora of free or cheap learning tools

- Volunteering is good for the community and your CV

Professional Development is gooooood

Page 53: How to be employed at the SOC of tomorrow... today

How to be employed in the SOC of tomorrow… Today

Speak better. Write more gooder.