Remote Exploit Forums

Go Back   Remote Exploit Forums > Specialist Topics > Pentesting


Pentesting Specific topics related to legal penetration testing

   

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-23-2007, 08:14 PM
seven's Avatar
Member
 
Join Date: May 2007
Posts: 99
Default Finding a job or intern.

Hello all.
I am currently an Info. Sec student in college. How would i go about finding a security audit firm internship or job? I look on monster.com but mostly they are position for network administration ( which i have no problem doing either, but i prefer auditing and pentesting. )
If i do see a position, they want atleast 3 years experience. How do i get this experience under my belt? How did you(if you are in a security audit firm or pentest for your company or others ) start your career?
Reply With Quote
  #2 (permalink)  
Old 05-23-2007, 09:42 PM
theprez98's Avatar
Super Moderator
 
Join Date: Apr 2007
Location: Maryland
Posts: 2,556
Default

Quote:
Originally Posted by seven View Post
Hello all.
I am currently an Info. Sec student in college. How would i go about finding a security audit firm internship or job? I look on monster.com but mostly they are position for network administration ( which i have no problem doing either, but i prefer auditing and pentesting. )
If i do see a position, they want atleast 3 years experience. How do i get this experience under my belt? How did you(if you are in a security audit firm or pentest for your company or others ) start your career?
You may have to find a general networking admin job for a few years just to get some experience under your belt.
__________________
theprez98
"I want peace on earth and goodwill toward men."
"We are the United States Government. We don't do that sort of thing!"
Reply With Quote
  #3 (permalink)  
Old 05-23-2007, 09:54 PM
seven's Avatar
Member
 
Join Date: May 2007
Posts: 99
Default

Quite a few of my friends who have graduated have gotten the internship at Cisco and have also been hired. I am next line to get an internship there as my friends will recommend me ( and i feel confident enough that i am able to qualify without help ) Would this be a step in the right direction? I would like to have a career in pentesting as this is what i have been interested in since freshman year of high school.
Sure making alot of money from Cisco is great, but i would also like to make alot of money from doing that i love to do aswell.
Reply With Quote
  #4 (permalink)  
Old 05-24-2007, 02:07 AM
theprez98's Avatar
Super Moderator
 
Join Date: Apr 2007
Location: Maryland
Posts: 2,556
Default

Quote:
Originally Posted by seven View Post
Quite a few of my friends who have graduated have gotten the internship at Cisco and have also been hired. I am next line to get an internship there as my friends will recommend me ( and i feel confident enough that i am able to qualify without help ) Would this be a step in the right direction? I would like to have a career in pentesting as this is what i have been interested in since freshman year of high school.
Sure making alot of money from Cisco is great, but i would also like to make alot of money from doing that i love to do aswell.
I wouldn't have any doubt that working at Cisco you will gain a lot of valuable experience. It will quite obviously be vendor-specific (what job isn't), but you'll get some experience under the belt and probably some certs to go with it.
__________________
theprez98
"I want peace on earth and goodwill toward men."
"We are the United States Government. We don't do that sort of thing!"
Reply With Quote
  #5 (permalink)  
Old 05-24-2007, 04:51 PM
seven's Avatar
Member
 
Join Date: May 2007
Posts: 99
Default

Ok, so i suppose the Cisco job will benefit me greatly. But how do i slowly branch into security auditing? Do i ask to do it ( after some years working that is )? Or would i have to learn how to be a pentester somewhere else after i have some certs and experience?
Reply With Quote
  #6 (permalink)  
Old 05-24-2007, 07:43 PM
thorin's Avatar
Senior Member
 
Join Date: Feb 2006
Location: Northern Hemisphere
Posts: 2,545
Default

Have you done any personal/professoinal "networking"?

ie: Gone to local OWASP, ISACA, ISSA, etc... meetings?
Created a profile on linkedin.com?
Done any external training, ie: CISSP etc...?

Does your course include a co-op placement?

Instead of checking "official" job postings have you approached any local consulting shops or info sec. firms to see if they had any intern positions available?

Are any of your family (even extended family) in IT or other high tech careers? Have you talk to them about summer jobs or internships?

Does your program do any type of Security Paper (essay/research) competition that is judged by local sec firms? (One of the local community colleges here does that and our firm is amongst the judges....great way to get your name out there). This might be a great idea to bounce off some of your profs.

Additionally if you're profs. were once practicing Info Sec professionals (I really hope they were) then ask them about local User Groups or Professional Organizations (as mentioned earlier).

Last edited by thorin; 05-24-2007 at 07:45 PM.
Reply With Quote
  #7 (permalink)  
Old 05-24-2007, 08:09 PM
seven's Avatar
Member
 
Join Date: May 2007
Posts: 99
Default

no not yet. i am going into my third year of college but i will definitely be looking into to those things that you have mentioned. My last semester ( next year and a half. ) i have to do an internship which will most likely be at cisco if i cant find one in a sec. firm.

I have another question. After i graduate i only have a BA. If i get hired after my internship ( most of my friends were ) should i accept or go off to grads school and get my masters in info sec? Should i take schooling after i have a job? like night classes? My adulthood is just starting and i would really like to enter it on the right foot.
Reply With Quote
  #8 (permalink)  
Old 05-25-2007, 02:44 AM
Junior Member
 
Join Date: Apr 2007
Posts: 5
Default

Quote:
no not yet. i am going into my third year of college but i will definitely be looking into to those things that you have mentioned. My last semester ( next year and a half. ) i have to do an internship which will most likely be at cisco if i cant find one in a sec. firm.

I have another question. After i graduate i only have a BA. If i get hired after my internship ( most of my friends were ) should i accept or go off to grads school and get my masters in info sec? Should i take schooling after i have a job? like night classes? My adulthood is just starting and i would really like to enter it on the right foot.
After having just graduated with my Masters last wednesday I would suggest that you take the job if offered. While a Masters degree is great, it can never teach you the things that you will learn from actually doing some network admin, sys admin, or security admin work.

I agree with what the other users have said in that you need to ask around for companies that might offer internships.

I had a guy apply for a job we were advertising for, and in his cover letter mentioned that he'd be willing to do an internship, that caught my attention, and I offered him an internship.
Reply With Quote
  #9 (permalink)  
Old 05-25-2007, 12:40 PM
thorin's Avatar
Senior Member
 
Join Date: Feb 2006
Location: Northern Hemisphere
Posts: 2,545
Default

I agree with EternalRampage, take the job. You can always decide to do your masters after you have some experience under your belt (which will only help). Plus, you might get lucky a find an employer that's willing to pay for some or all of it for you under their training budget.
Reply With Quote
  #10 (permalink)  
Old 05-29-2007, 04:42 PM
Junior Member
 
Join Date: Mar 2007
Posts: 10
Default

Quote:
Originally Posted by seven View Post
Hello all.
I am currently an Info. Sec student in college. How would i go about finding a security audit firm internship or job? I look on monster.com but mostly they are position for network administration ( which i have no problem doing either, but i prefer auditing and pentesting. )
If i do see a position, they want atleast 3 years experience. How do i get this experience under my belt? How did you(if you are in a security audit firm or pentest for your company or others ) start your career?
Definitely look for Audit and Risk departments in firms. They'll have you evaluating systems, looking for any holes that could present ...well, risks. That could include pentesting, depending on the firm and on the client. Look into Deloitte & Touche, as well as Ernst & Young. I know they have such departments and that they do employ people in infosec roles.

Good luck!
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 12:22 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2