|
|
|
|
|
by jpgvm
1693 days ago
|
|
My point is thus. You can't legitimately argue that you can reasonably understand modern security without understanding modern exploitation techniques. Furthermore you also can't say that a certification that doesn't test for any of this knowledge would then be useful for filtering candidates that have said knowledge. That is not an argument from ignorance, that is simple fact. If you are hiring for "security" at an enterprise company where the role generally consists of vendor management then sure, CISSP is probably exactly what you need/want. If the certification was worth something it would feature more prominently in requirements for companies with excelent security orgs. Notice it's completely absent from https://www.tesla.com/careers/search/job/security-engineer-f... and https://boards.greenhouse.io/cloudflare/jobs/1727694?gh_jid=... and https://jobs.apple.com/en-au/details/200293563/product-secur... Instead note the prominence of proven vulns, low level language experience, etc. Lesson is simple. If you want to be good (and paid a shit ton) disregard certs, acquire CVEs. |
|