Any pen testing experts have any advice on what an aspiring tester ABSOLUTELY has to know before they can be an effective tester? I’m thinking both hard and soft skills.

I’m thinking about developing the skill in spare time as a retirement free-lance option (I have lots of time).

like
Posting as :
works at
You are currently posting as works at

You need to understand the application/ infrastructure design and how it works and potential vulnerabilities. Within the next 10 years, most actual pentests will be exectued by AI as AI is actually well suited for it with the human operator driving the strategy the AI will use to execute the pentest.

like

You need to know that for the most part pen testing is seen as a necessary hurdle for most business projects to clear to get through a stage gate. Your work will often be something that hinders the business achieving its goal and so most of your clients will do their utmost to ignore and belittle any risks you identify as they see no value in what you will produce.

Related Posts

How much ZS offer to there consultants?

like

I am quite early in my career and currently working on my masters in data science. Any tips on what kind of projects I should include on my resume and if I should include them?

like

How long before joining do we get on boarding mail?

Hey Guys, does anyone know if jp has plans to call people to office full time from next year? I have my joining date as 1st November and want to know if they’ll continue with the hybrid model or no?

Is anybody using WACOM CINTIQ Pro 24"? I am contemplating getting one but wondering if I will be able to use a mouse/tablet along with it. I heavily use InDesign and wonder if I can use a mouse/tablet when I need to without unplugging it. Thanks in advance!

like

Im a RN and took on a new role working in Home Health. I chose this position because My husband & I recently moved to PA with our 2 kids (1&3), with no family available for his residency program with a hospital. If you know that life, I’m pretty much the main parent for our kids. I don’t want to work in the hospital/floor work anymore; nor do I believe the hrs are flexible enough. I need a job that’s flexible for the kids but pays >$44/hr. Maybe remote or hybrid? Please help w/ suggestions.

like

Lol shots fired

Post Photo
likefunny

Litecoin is stable AF lately

like

When does EY announce promotions/raises?

like

Hi guys, what's the standard salary range for a digital strategist?

like

Are Comptia certificates worthy?

Any San Francisco peeps have a good accountant who specializes in taxes for freelancers/contractors?

How much protein do I need it intake to grow muscle? I rather not gain fat. I am 200lb.

like

Has anyone here have the ridge or ekster wallet? If so what are your thoughts

like

My team and I are looking at upgrading our invoicing system for catering gigs as our catering popularity is growing in our area.
Looking for BEO/invoicing/contract software that’s easy to use, saves menus, and not too terribly expensive. Recommendations?

like

Made a mistake: I bought a watch instead of an iPad for grad school use.

like

Found out today my toxic manager bad mouthed me to an HR rep in a different division. This correlated with his bad management and abusive behavior. Luckily the new manager I’ll soon be working with dismissed it. Her words of wisdom “reflect on what you could have done differently, you can only control your actions”. How does that resonate for you? Have you had similar experiences?

like

Looking for book recommendations on strategy/strategic thinking. Something along the lines of Contagious but open to any options. Thanks in advance!

like

Cold showers hit different

like

Additional Posts in Cyber Security Bowl

Views on carbon black as a product?

helpful

Is there a demand for privacy professionals? Been seeing this discussed more and more recently

like

Any EY PPMD 🐠 willing to chat/connect? Interested in learning more about the cyber practice. I’m a new campus hire in the Hoboken office. Thanks in advance!

like

Can anyone recommend a good book/materials to prep for the CIPP/CIPM? 🙏🏽

Anyone working in Pharma industry?

like

Any company is hiring EU citizens and helping with visa? interested in moving to USA. I'm lawyer, cissp, cisa, cipp/e and specialized n data privacy, cybersec ops and risk management with 8+ years exp

like

Privacy fish - Anyone taken the CIPM and can share what the exam is like?

Content outline seems like application of standard consulting approach, so how do they test it on an exam?

Thinking of moving from Big4 cyber to Accenture cyber. Any major differences (other than no channel restrictions).

like

Any thoughts on the CISM certification?

like

Joining a group that specializes in incident response. Any recommendations on things I can do this summer to prepare on fundamentals/certs?

like

Anyone currently enrolled or will be enrolled in the online masters cyber degree at Georgia Tech?

like

AWS Cloud question- what the difference between an SCP and IAM? Thanks in advance

like

Anyone know what kind of experience or certifications I should be aiming to get if I'm trying to break into a pentest role? I just graduated last year and have about a year of sysadmin experience and am trying to get into it asap. So, I'm already applying/job hunting and probably won't get much replies but. Should I be looking at more security analyst/admin roles first? Going for certs? Getting a masters? Wondering what I can do to improve my chances. TIA

like

We’re hiring across the board at KPMG for cyber / cyber risk work - shoot me a DM if interested. (Pays well!)

likehelpful

How did you decide your speciality in Cybersecurity? Did you naturally gravitate towards one area?

like

Have any of you pursued a graduate certificate in cyber security? If so, did you find any value in it? I currently have Bachelors and Sec+. I’m looking to obtain my AWS CCP in the few coming weeks and was looking for what to get next. I entertain the idea of continuing to pursue my education but I don’t want to incur too much debt with a masters.

like

Currently stuck in risk but interested in Cyber. Have done one related engagement from a regulatory perspective. But a lot of posts here making me think it’s harder to break into than I expected (non-technical background). If you had a six sigma green belt / supply chain degree/exp., would you still go through the effort of going into Cyber or take easy risk money being offered / easier transition back to supply chain? 2-3 YOE and trying to decide career course, any advice highly appreciated

like

Has anyone gone through the deloitte cyber risk interview process recently? How many interviews did you have and how was the process?? Salary?

like

Anyone at Protiviti in their Cybersecurity consulting practice willing to chat? Looking to inquire about pay, culture, etc. Thanks!

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal