visit
I am always amused to tell new friends about my job because no one knows what a security consultant is. Some confused security with securities (as in the stock market, which Hong Kong famous for), some only know about IT. On one occasion, my friend asked why I studied at university and became a security guard.
For me, I am more like a security guard than an IT guy. As I always say to my colleagues, to keep a different mindset than IT staff. The main differences are: Security will not improve efficiency or productivity, but Confidentiality, Integrity, and Availability (CIA).
My colleagues always said I know something new as I am different. Yes, I agree. But it doesn’t mean that I am a freak or genius to do a better job. I obtained my Master of Computer Forensics.Yet, I was only a Science undergraduate working at nightshift to save money for the tuition when I started my career. By telling you my story, I hope more people will be interested in pursuing InfoSec careers even they do not have experience.Most people would tell you to find your passion for being successful in your career. I think it is what makes success in all parts of life. To find a job in cybersecurity, you need to show your interest in this field.
Studying a tertiary education in InfoSec is one of the methods. Writing about security also works (but it may need more to start writing). The purpose of the proof is to let people, especially employers, know that you like InfoSec.Taking the was my way to show my enthusiasm. The CISSP exam uses Computerized Adaptive Testing (CAT) for all English exams now. It was a six-hour straight examination on pencil and paper when I took the exam. My exam started at 0900 to 1500. I only left my chair once for the toilet.
Passing the exams do not necessarily demonstrate that you are an expert in the field. However, it can tell companies you studied in the area and spent hours of effort on the subject related to the job.Most people who took the exam with me are working in the field. But why not take the exam to learn about the area first then gain experience along with the career? Studying for InfoSec exams can help you gain the necessities in this job.There are different levels of exams for different kinds of positions, such as what I mentioned. For example :Studying for the exams was not easy, especially for a rookie. It will be easier if you like the contents. But the best thing about passing these exams is about learning a common language with other real professionals.
Speaking a common language does not necessarily need field experience. Like you do not need to live in Japan to know Japanese. It is a crucial advantage if you can understand questions in a job interview with security professionals.
You show the interviewer that you know the subject but do not have experience. Moreover, you indicate your interest in the field and also the know-how of the basic concepts. By that point, you are ready to learn more and find your more specific area of interest.You can learn the language in different ways. Taking an exam is one way. Or like learning a real language, reading more on that subject would unquestionably help. I read different kinds of magazines in InfoSec and online media, like , Hacknoon, and .
Is experience a must?I once saw a LinkedIn post about getting into a cybersecurity career. The passion of this instructor admired me as I also taught, although not full-time. He pointed out to work in this field may require a full spectrum of IT knowledge.You need to know the basics. The key is the width of knowledge, not the depth. To suit yourself in a job, you need to know what kind of work would fit into your domain but not the others.
If you glance at , you can find the “width” of the things we need to learn later in the job. It is recommended to know the meaning of the eight domains to get started.
Do not worry. No one can be an expert in all domains. The focus at the beginning is the “What”, not how or why. As this industry is so dynamic, we need to update our knowledge continually; otherwise, we are no better than junior associates.
Just like driving a car do not need to understand every part inside the engine. To find a job in Cybersecurity, you do not need experience in all IT aspects. Instead, you can learn all technical knowledge from training and your day-to-day operational tasks.
Later I found out it was very relevant to what I need in my job. I thanked my mum for that. But she and I do not know it will go that far. Think differently makes a considerable difference from the beginning and along with my career.
In a security professional’s daily life, our primary goal is not to make sure everything is running as expected but to make sure the unexpected or unknown are minimized or mitigated. When everything is considered and handled, IT should be happy and business as usual — Nothing happens.
Being a great security professional is not just about how excellent your technical skills. It would be best if you were particular about the choices or suggestions based on the different contextual information you had.To know more about what is a Security Mindset entails, please refer to my previous article.//gzht888.com/what-i-learned-about-cybersecurity-after-becoming-an-issapr-o71834rt
As I did not have any working experience in the field, passing the CISSP exam does not immediately certify the profession. I was only called “The Associate of (ISC)².” According to
A candidate who doesn’t have the required experience to become a CISSP may become an Associate of (ISC)² by successfully passing the CISSP examination. The Associate of (ISC)² will then have six years to earn the five years required experience.But I got certified with only four years of experience. If you prepare for the examinations like me, to study the rules before examining the contents, you will find :
If you are interested in an InfoSec career, I dare you not to afraid if you do not have any experience. Instead, be prepared, like any other job, to let people know you are open to the challenge. As a Chinese saying goes, “You need to show your back to the public if you want people to give you a push.”
Below are the areas you can begin with:Also published at