2.5 years in cyber and want my career to be focused in incident response/vulnerability management in the next year. Which certs do you recommend I prepare and sit for?

like
Posting as :
works at
You are currently posting as works at

John Strand from Black Hills Info Sec is running a SOC core skills training session next week, Monday to Friday. It’s a pay what you can afford course, 5hrs a day. I’d recommend you take this course if you have the time to just double check that this is something you want to do as the certs can be expensive. What’s unique about this course is I THINK we’re going to get literal hands on training which is super rare to get. Find him on LinkedIn and have a mooch!

For context, I’ve been transitioning into cyber since Jan last year and I’ve taken Net+, AZ-900 and I’m also on OffSec’s Fundamentals program along with studying for Sec+. I’m aiming to take the OSCP/OSWE early 2025.

like

Not sure what’s next. All these trainings cost a lot of $$$

like

CySA+ isn’t too bad for that.

SANS has a number of courses but they’re vastly more expensive.

When you get your CISSP they have a
Somewhat incident response related add on, don’t recall which one.

Thank you so much! I was looking at SANS but the price is jarring. My plan is to find a role where the company will pay for that exam.

like

What cyber work did you do at EY? The best entry level training for IR would be the BTL1. Getting into IR is pretty tough and most want GCFE/GCFA. Idc what anyone says SANs is the gold standard in terms of certifications/HR filter.

They were tool and readiness assessments. I agree on the TTX. I’ve tailored my resume to incident response and bring up the TTXs I’ve done in screening calls and get a positive response.

I personally think those aren’t diverse or highly skills and you will either get bored or you’ll be cut. I personally think you should focus more on infrastructure security which covers a lot of things, like AWS, terraform, threat modeling

I did GRC/IAM-VM- IR- and now I’m doing more infrastructure security and trying to build toward appsec and cloud

You can try e-learn security’s Threat hunting and Incident response. It’s hands on and sharpens your intellect around DF, identifying vulns, and TH. Not sure if it’s recognized in your jurisdiction though

So which is it? Lol IR or VM. Those two are very different

I want to be skilled in both.

Related Posts

How long it take from senior2 to Asst. Manager?
Joined in May this year as S2.

like

Best consulting firms for PE work (CDD,Value Creation)? Looking for the best firm for exit ops to PE ops eventually. Thanks!

like

Any EU attorneys who went for an LL. M. in international commercial law (or other) in Europe?

If so have you found it "worth" the year of your time? I am currently working at a firm that specializes mostly on commercial law and has a lot of foreign clients. I have some options regarding the possible LL. M. One of them is little less prestigeous that would allow me to stay working at law firm as I am studying. The other would mean taking a year off work and pursuing the LL. M, Thanks for help

like

What is the level of senior control management specialist?. What does the career graph look like in terms of promotion?. Help please

like

Hi Sharks,

Need your advise urgently.

Can you please suggest which would be better in terms of WLB, flexibility, growth, job security.

YOE: 4.4 years
Tech stack: Azure data factory, data lake, Azure databricks, Logic App, SQL, Pyspark (basic)


Offer:

Optum - 19.16 [16 Fixed + 15% variable + pf (offer letter is not received yet) ]

LTIMindtree: 21.50 (40 to 50k will be variable) Offer letter is not received yet

like

CAIA vs CFA?

like

I have 6+ years of experience, wanted to switch to other organisations as I am not feeling comfortable,this is 5 th company

like

I want to exit to MBB but if that’s not a possibility what are the next best consulting firms? Looking for at least midsize firms (non-boutiques).

like

Which is better for growth within industry? FP&A or controller route?

like

My dilemma… I am an injury adjuster at a carrier experiencing high inventory that’s barely manageable. A competitor offered a higher salary and manageable workload. BUT, I would like to get into underwriting. I applied for UW position w/ a different carrier and they’ve made an offer. It’s lower than my current salary and significantly lower than what I’d make by taking the first offer. Do I take the high salary and stay in claims or go for UW in hopes it will be best in long run?

like

Does anyone know how the ease or difficulty of moving from business services tax (partnerships, private equity etc) to transfer pricing?

like

I've an offer from Ericsson as Senior Tech lead and am expecting an offer from VMware as Senior member of Technical staff. Which company is the best in terms of Job security, Career Growth and work life balance ? Which company should I join.

like

How is Corporate VC typically viewed by those in industry? What makes a “good” Corporate VC over others? Coming from T2 consulting and was wondering if Corporate VC is an easier stepping stone to VC.

like

Trying to get a 45 y/o sibling in to consulting (was an entrepreneur prior in the restaurant industry). No college degree but willing to bust his but to learn. Books/online courses recommended pls

funny

For all the 🐠 that switched from consulting to product, which role provided you with more tangible skills? I know I’m making some broad strokes here, but thought it might open other discussions as well

like

Hello Fishes,

Currently working as a Business Analyst with PwC. Got a call from Hexaware. Is it worth it shifting from PwC to Hexaware? Any suggestions??

like

I have 2 offers : EY India

EY INDIA - 15 LPA FIXED + 2.2 L BONUS + 50K JB
LTI - 18 LPA FIXED + 1 L retirals + 75k JB

Which one should I join in terms of WLB, growth etc.

YOE - 3.2
Tech - Servicenow

Please suggest, it's URGENT!!!!

like

Hello All, In the next couple of months i am targeting companies like Apple , American express, Salesforce, Microsoft etc. Can anyone please share the required skill set and preparation strategy for these companies? YoE - 4 years Current skill set - Advanced SQL , Pyspark,Azure services, Hadoop ecosystem , shell scripting, Power BI

I am not very good at DSA.

Apple Microsoft Salesforce Amazon

like

Hi fishes,
I need guidance for EY GDS SaT_Strategy Hub_Senior Analyst. I have 1.5 Yoe but the role mentioned 3-6 yoe.
Is it still worth applying or is there any analyst role for this?
PS: experience post Tier 2 MBA

like

Hello! I’m currently a Administrative assistant now working at a major medical system in Baltimore. I’ve previously worked for 10 years as a medical assistant in a variety of specialties and primary care. Lately, I’ve been feeling a bit stuck as to my next step. Part of me want to go into management, another part is saying go get your RN, and the other is saying go into Social Work. I’m all over the place. Any ideas? And how would I be able to cross over to management?

like

More Posts

Any investors in the woodlands Texas for single family homes, rent looks good as per Zillow , good school district and houses are still affordable compared to Dallas and Austin

like

How to know the GGID for checking final settlement payslip

Did anyone file AOS and i140 together (assuming your priority date is current at the time of PERM approval)? What was the process like and how long did it take to get your GC from PERM approval date?

Does anyone knows notice period in Hexaware during probation period. They have not mentioned anything on offer letter though .

like
like

I was recently laid off and I am actively search for a new role. I am mainly targeting Business Analyst, ScrumMaster, Product Analyst, roles but I am open to others.

Must be located in Austin, Texas or fully remote.

EXP
5 Mo- Business Analyst 3
1.5 Y- Venture Capital Associate
1.5 Y- Strategic Planning Analyst

Certifications
ScrumMaster
Specialist Accounting and Finance
Specialist Business Intelligence

Contact
737-707-5156
ajaspercannon@gmail(dot)com
www.linkedin(dot)com/in/jcstrategy

like

AST still rallying despite just over 150 watchers on StockTwits and pretty low social media coverage... tends to get spiked down after a run, so might want to wait, but something’s up

like

Do MBB firms usually give temporary accommodation to look for a place for people relocating from outside?

smart

That's a cool idea!

like

Hi,
I am Mahesh
Now ready to join immediately for Accounts Payable with 25 years experience in proper books keeping and accounting of manufacturing tower crane and civil engineering. I hope you are doing well for me.

Thanks for your support.


Yours Sincerely

Mahesh Shinde

like

Folks applying for Data and Analytics roles in the industry at M, SM, D Levels, what technical/functional topics do you prepare for on the Analytics side?

like

Wearing to work today

Post Photo
likeuplifting

1.What are different band levels in LTI?
2.Is senior specialist level above the manager level in terms of payscale/destination?
3.What does working in salesforce vertical looks like & onshore opp. for US visa holders?
4.Avg hike / variable pay per year?
5.What is the notice period in LTI?
6.Any hidden components included in salary that can be avoided or restructed before joining?
7.What can be avg hike for 9 yrs of Exp in senior specialist track?

Thanks in advance,it will cover most of the quer

like

How is pega practice in LTI ?

like

Hello, everyone. My team is looking for a fundraising professional for principal gifts.

like

New joiners at Amazon,
When do we get the mail to select asset and delivery of the laptop? My joining is after a month,can I call my recruiter if i don't get a mail maybe 20 days before joining

Amazon

Did anyone got into Natwest as a fresher offcampus? (As a software engineer)

like

Who should I start, Joe Mixon or Chris Thompson? 🧐

CGI folks. Please help! What's the salary bracket for 5 years experience. Tech stack Java +ReactJS Full Stack.
Current company Deloitte. Current CTC: 14.38 fix + 10% variable.
Let me know what hike shud I ask !!

I have the offer discussion round with Tiger Analytics for a data scientist role in Toronto.
I want to know how much should I quote for the role.
I have 2 yoe as a data scientist and 2 years of experience as a software developer.

like

Additional Posts in Cyber Security Bowl

Curious how MBB's cybercapabilities are viewed within the cyber world. Experiences, thoughts?

like
like

Currently stuck in risk but interested in Cyber. Have done one related engagement from a regulatory perspective. But a lot of posts here making me think it’s harder to break into than I expected (non-technical background). If you had a six sigma green belt / supply chain degree/exp., would you still go through the effort of going into Cyber or take easy risk money being offered / easier transition back to supply chain? 2-3 YOE and trying to decide career course, any advice highly appreciated

like

Can anyone recommend a good book/materials to prep for the CIPP/CIPM? 🙏🏽

Would you expense a speeding ticket on your way to an IR?

funnylike

Any recommended study material for CIPP and/or CIPM (still debating the two)?

New to the U.S., is the Healthcare Industry (via HIPAA), the only industry in the U.S. that legally mandates having a designated Privacy Officer? So for example, although GLBA has obvious privacy requirements, unlike with healthcare, financial institutions in the U.S. are not mandated by law to have a designated Privacy Officer?

like

Privacy fish - Anyone taken the CIPM and can share what the exam is like?

Content outline seems like application of standard consulting approach, so how do they test it on an exam?

Hey all, I have been working in Identity and access management space at EY for past 4 years. Need help with understanding best exit opportunities?

Anyone at Protiviti in their Cybersecurity consulting practice willing to chat? Looking to inquire about pay, culture, etc. Thanks!

like

Anyone ever heard of or worked for Sygnia?

like

Thinking about getting the AWS Cloud Practitioner certification. Does EY have any amazon resources or training materials that they provide? Any advise from people who have taken it before? Thanks!

like

Anyone familiar with Istari-Global and their collective of cyber risk companies? What’s their perception in the market? Opportunity to join US team. Thanks!

like

is CRISC worth it? dont see it coming up as much as others

like

AWS Cloud question- what the difference between an SCP and IAM? Thanks in advance

like

Any tips or tricks for CSX certification?

like

Any EY PPMD 🐠 willing to chat/connect? Interested in learning more about the cyber practice. I’m a new campus hire in the Hoboken office. Thanks in advance!

like

CohnReznick hiring for cyber/tech risk/privacy team. Looking for seniors and managers. Anyone interested?

funnylike

Deloitte Cyber, how long did it take you to receive an offer after final interview?

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal