Pentesting Career Path: From Junior Pentester to Red Team: How to Get Into Red Team Ethical Hacking

Поделиться
HTML-код
  • Опубликовано: 26 ноя 2024

Комментарии • 34

  • @WithSandra
    @WithSandra  2 года назад +5

    Please tell me you liked the GIFs LOL. I have some big news to share the end of next week and can't wait to tell your guys the great news! (Hint: it's career related 😁💻 ) What other cyber security career paths would you want to hear about?

  • @Razadog98
    @Razadog98 2 года назад +27

    CEH and PenTest+ looks good for HR but personally I don't think pentesters should strive to get multiple choice certs. They should be looking to do certs that are practical. For example, TCM Security certs, eJPT and OSCP is defs the way to go now. If you plan on being a pentester (which is highly practical role) then shouldn't you do PRACTICAL based certs?? Doing CEH and PenTest+ might get you an interview, but won't allow you to performance well in your role.

    • @WithSandra
      @WithSandra  2 года назад +3

      Definitely agree! The OSCP and equivalent certs are definitely the ones that prove your ethical hacking skills a lot more than a CEH/Pentest+, but for someone's early-mid career, it'll be a stretch to get those certs which is why the CEH is just an easier option when starting out, agree that it really is to look good for HR and get your foot in the door for those first few pentesting jobs. But if someone's serious about their pentesting career, the certs you listed are 100% the way to go when they're ready to further their actual hacking skills!

    • @SuikodenGR
      @SuikodenGR 2 года назад +2

      @@WithSandra As someone who is just starting to work on their Security +, have a BA in Cyber Security and have nearly 20 year in the Navy with a current Valid security Clearance, I really want to strive for a career as a Junior Pen Tester (no skills as a hacker).
      But I do plan to go for other certs like Ethical Hacker and Penetration Tester Certs. Also some coding such as Python, C# and Cloud Programming.
      Should take my first test within 4 months and then work on the other two certs while learning on basic.
      Hopefully this might be enough for a DoD entry-level job

    • @thenotoriouscam1
      @thenotoriouscam1 2 года назад +1

      From a cost base analysis the PenTest+ would actually be the best "first" (Security+ should be true first) red team cert as it will open the door for you. I think it's double the price of the eJPT, however it also has double the recognition and you just need to land a job so you can have your employer pay for the rest of your certs.

    • @SuikodenGR
      @SuikodenGR 2 года назад

      @@thenotoriouscam1 excellent comment :D

    • @user-dx2dm8oq8g
      @user-dx2dm8oq8g 5 месяцев назад

      I'm doing the oscp right now, that was my mentality too. I'd aim for practical certs even if the content is a little outdated then learn what's current to adjust. It really gives you confidence in your skills, teaches you the methodology. Then you can practice doing bug bounty and CTFs. I heard bad things about the CEH, I'd only do it if my employer paid for it, but I'd def read the course material in my free time.

  • @mikecr3297
    @mikecr3297 2 года назад +1

    WTF
    Last time I saw your video you were discussing how did you get the entry-level job in cyber security and now you are on the red team already?
    DAMN, what a beast.

    • @WithSandra
      @WithSandra  2 года назад +2

      LOL OMG I wish😂 This video is a walkthrough of the typical career path i’ve seen others take in pentesting across the different mentors i’ve had, there’s no way i’d make it to red team in just 2 years haha! But appreciate that you’d even think I could 😆 thanks for watching since the beginning tho☺️!

  • @justinmorales4635
    @justinmorales4635 2 года назад +1

    You really helped me out I appreciate you and these videos

  • @omarj1664
    @omarj1664 Год назад

    Thank you so much for sharing I feel like a failure not matter what I do

  • @johnczech7074
    @johnczech7074 2 года назад

    This was really cool Sandra! Thank you beautiful lady! Hope you guys had a nice valentine's day!

    • @WithSandra
      @WithSandra  2 года назад

      Thanks so much John! :D Hope you had a great Valentine's as well!

  • @BigBowener
    @BigBowener 2 года назад

    Hey Sandra loved this video thank you so much for sharing!

    • @WithSandra
      @WithSandra  2 года назад

      Thanks for watching Luca!☺️

  • @riviperera2857
    @riviperera2857 2 года назад

    Loved the video 🤩🔥

    • @WithSandra
      @WithSandra  2 года назад

      Thank you so much for watching Rivi :)!

  • @kerrydor9519
    @kerrydor9519 2 года назад

    I am a cybersecurity student and I wanted hear your opinion about specializing in blockchain security? I have a interest in crypto and I was told by my professor it a relatively new area that not all of people have experience in.

    • @WithSandra
      @WithSandra  2 года назад

      Hi Kerry, thanks for watching! I actually really wanted to make a video about security with blockchain, the blockchain itself is inherently secure, what's not secure is human error that may be in the actual code and under certain conditions, so it'll be interesting to see what skills/tools will come out of that area, it's likely going to be a very technical role and will definitely need specialized skills! I'd say go for it if this is something you're interested, more and more companies are definitely going to take advantage of the perks of using blockchain not just for cyptocurrencies, wishing you the best of luck and keep us updated :D Lmk if there's anything you think I should include in the video on blockchain security!

    • @kerrydor9519
      @kerrydor9519 2 года назад

      @@WithSandra Thanks Sandra, will do! As for the video, it be nice if you can include a high level overview of how the blockchain is inherently secure. In addition, overlay the job responsibilities and also go in depth of ways to get a specialization in blockchain security.

  • @feroztia
    @feroztia 2 года назад

    Hi Sandra! Thank you so much for your videos, it's really useful :) Currently I'm studying with Coursera (Google IT Support and IBM Cybersecurity course) and practising in Python. I really wanna join Red Team in the future and I got really inspired by your videos!

  • @sparkeyluv
    @sparkeyluv 2 года назад

    I’m super interested. Are you ok with speaking with me more about this? I don’t mind email.

  • @denisleonard1565
    @denisleonard1565 2 года назад

    Hi Sandra, are you in a Rad team ir Blue team?

  • @vijayanandraj7112
    @vijayanandraj7112 2 года назад

    Hi, I am want to do my graduation in cybersecurity course. In taxes

    • @WithSandra
      @WithSandra  2 года назад

      Hi Vijay, thanks so much for watching! :) I'd definitely recommend majoring in Cyber security, whether its a degree or if you join a bootcamp, good luck!

  • @monk9008
    @monk9008 2 года назад +1

    Hey

    • @WithSandra
      @WithSandra  2 года назад +1

      Hey @Monk thanks for watching! :)

  • @cowsecurity
    @cowsecurity 2 года назад +1

    Hello there Sanda,
    Hope you are doing well.
    I am trying to get started into cyber-security as a penetration tester .As a fresher which certification should i go for sec+ && pentest+ or OSCP ?

    • @cycleof7s438
      @cycleof7s438 2 года назад +2

      I'm no Sandra but I can say the OSCP might be a shocker for someone fresh in the game. Sec+ is good for getting in front of HR for a job and although no hands-on, it will give you a good intro into cyber. For someone like yourself, I would recommend to take an affordable networking course online to understand subnetting and the basics of networking. Then, Sec+, eJPT and THEN attempt to tackle the OSCP. Good luck!

  • @Ravi-wi5gx
    @Ravi-wi5gx 2 года назад

    Hi

    • @WithSandra
      @WithSandra  2 года назад

      Hi Yelamareddy :D You're earlier than me! Thanks for watching!! :)

  • @TripleA679
    @TripleA679 Год назад +1

    Im just curious, do people really get a Pentest job after getting Pentest + or CEH?

    • @furkanyaman7298
      @furkanyaman7298 Год назад

      Nope, they are to look good for HR and perhaps visibility