Security Software Engineer
From my perspective, it seems like industry security (in the software development & web development space) is non-existent. Is it even worth finishing a computer science degree at this point?
Is security software development a thing?
That everyone wants it an nobody wants to pay for it.
More on reddit.comSecure software development?
What is secure software development?
What is a secure software development policy?
How do You Protect your software?
If someone wants to get into Security side of development, what are some projects / concepts they should preparare like (SAML,OAUTH2.0, Access controls, Kubernetes etc..,)
Granted I am new to the industry, I have never seen an entire industry shutdown and choose not to hire people.
One of my mentors said I should be seeking industry security and not job security, but at this point, where is even that?
I see how companies are not hiring, I see how the qualifications for a junior developer have grown to include that of mid-level developers and I am lead to wonder, "Why try to break into an industry that itself grants no job opportunities?"
I feel like to keep getting schooling after schooling and training after training without getting that first job opportunity is flushing money down the toilet.
I am considering moving from software development to UI/UX design yet I hear that this is over saturated too.
And what is all this news about Ghost jobs? What is this? Jobs being posted that companies have no intention of filling?
Where are the jobs in web/software development and how can I actually get one? Just an entry level, basic, first dev job job. (lol)
If you have a job in tech, how did you break in?
Thanks.
I’ve heard a lot about this kind of position, but there’s not much on Reddit about it. What do we know about this line of work?
That everyone wants it an nobody wants to pay for it.
There is a large field in this sector. Ultimately someone codes the software that runs the Crowdstrike, Logrhythm, Sumo, Jira, Metasploit, SentinelOne, Bitdefender, Cisco, etc software. There is a lot of money in this area as enterprises will spend lots of $$$ for a piece of mind. That said, to develop this, any coder can do. However, to be the one designing and planning it, will require a lot more specialized training and either proven ability or higher education. Fortinet does not let anyone program their AI just because they say "I can program AI" from a 40 hour course.
If you are interested in the field, I would highly suggest getting a traditional CS degree and then slowly working your way through the ranks. I also suggest focusing on Security (for the general defense principles) and OS (to understand low layer interactions of memory).
If you were targeting more of how to integrate Security with Software development, a field called Sec DevOPS has been emerging and larger companies have been employing a dedicated security expert that understands the encryptions and security procedures but is less adept at the coding. The expert may also be tasked with triaging code analysis and would need to determine whether or not the code analyzer pointing out a non-zero Null is a potential vector for exploitation or not.
Curious why there is no such course in the cyber infosec program. Core infosec curriculum is overview (IIS), computer/OS, network, and crypto covering key technical areas, but nothing for software. We can take OMSCS software development process, but that's a general CS course. The program should offer something like this:
https://pe.gatech.edu/courses/secure-software-development#tab-overview
Thoughts?
I'm confused. I've been researching jobs and I see that big tech companies (FANG) recruit software engineers that specialize in "security".
So are they security engineers? Or are they just SWE's that develop code for...security?
What's the distinction? Security Engineer seems to be a catch-all word and I'm not sure what it exactly means. I know of other roles such as Pen-Tester and SOC analyst, but again, not sure how that relates to a security SWE.