|
|
|
|
|
by avenueb
3473 days ago
|
|
10+ year info sec veteran here. I think first order of business is do you want to be a specialist or a generalist? Application security is but one piece (albeit in many cases a very important piece). I chose generalist and I am happy to have done so. Today I am diving into Strict Transport Security, yes, but also working with HR and IT on our employee onboarding and off-boarding process, reviewing vendor and customer contracts and federal compliance requirements. Privacy, Regulations and Law, Compliance, IT and infrastructure security, corporate IT security, and yes application security - every day I deal with all of the above and I love that. And a great foundation into all the things a security person may do, I cannot recommend the CISSP enough go for the CISSP (or, alternatively, CISA) certification. |
|