Slashdot Mirror


IT Security Interviews Exposed

Ben Rothke writes "Information security is a hot career area and is among the strongest fields within IT for growth and opportunity. With excellent long-term career prospects, increasing cybersecurity vulnerabilities and an increase in security & privacy regulations and legislation, the demand for security professionals is significant. Even with a bright future, that does not necessarily mean that a career in information security is right for everyone. What differentiates an excellent security professional from a mediocre one is their passion for the job. With that, IT Security Interviews Exposed is a mixed bag of a book. For those that are looking for an information security spot and have the requisite passion for the job, much of the information should already be known. For someone who lacks that passion and simply wants a security job, their lack of breadth will show and the information in the book likely won't be helpful, unless they have a photographic memory to remember all of the various data points." Read below for the rest of Ben's review. IT Security Interviews Exposed: Secrets to Landing Your Next Information Security Job author Chris Butler pages 218 publisher Wiley rating 8 reviewer Ben Rothke ISBN 0471779873 summary Good review for a pro, but not for newbies. If you find information security challenging and either want a job in the field or are looking for a better job in the field, the book will be quite valuable. But for those looking for a hot security job, their lackings will likely show through on in interview, even with the help of this book.

As to the actual content, chapter 1 provides a good overview of how to find, interview and get a security job. The chapter contains many bits of helpful information, especially to those whose job seeking skills are deficient. A good piece of advice the author's state is that one should never pay a fee for headhunting services. There are many people that call themselves recruiters, but are nothing more than fax servers who charge for the service. The burden to pay is always on the hiring firm, and a job seeker should be extremely suspicious of anyone requesting a fee to find them a position.

I would hope that in future editions of the book, the authors expand on chapter one. The chapter itself in fact could easily me made into a book in its own right. As part of the job search process, many job searchers often do not ask themselves enough fundamental questions if they are indeed in the right place in their career. Such an approach is taken by Lee Kushner, founder and CEO of the information security recruitment firm LJ Kushner and Associates. Kushner formulated the following 7 questions that every information security job candidate should ask themselves:

1. What are my long and short term plans?

2. What are my strengths and weaknesses?

3. What skills do I need to develop?

4. Have I acquired a new skill during the past year?

5. What are my most significant career accomplishments and will I soon achieve another one?

6. Have I been promoted over the past three years?

7. What investments have I made in my own career?

The other 9 chapters of the book all have the same format; an overview of the topic, and then various questions and interviewer may pose. The reality that these topics of network and security fundamentals, firewalls, regulations, wireless, security tools, and more, are essential knowledge for a security professional. Anyone trying to go through a comprehensive information security interview and wing it by reviewing the material will likely only succeed if the interviewer is inept. Anyone attempting to mimic the questions and answers in the book in a real-world interview will immediately be found to be a sham if the interviewer deviates even slightly from the script, which should be expected.

What really separates a good candidate from a great candidate is hands-on, practical and real-world security experience. Such a candidate won't need a question and answer format to showcase themselves in an interview. Their experience should shine, and not their ability to rattle of security acronyms.

If a company is serious about hiring qualified people, the interview process should not be about short technical questions and acronym definitions. It should entail an open discussion with significant give and take. Having a candidate detail their methodology for deploying and configuring a firewall should be given more credence than their ability to define the TCP the three-way handshake.

Ultimately, the efficacy of the book is in the disposition of the reader. For the security newbie who wants a crash course in security in order to quickly land a security job, heaven help the company that would hire such a person. While one should indeed not judge a book by its cover; this book's cover and title may lead some readers to think that the book is their golden ticket to a quick landing into a great career. The breadth of information that a security professional needs to know precludes and short of cramming or quick introductions. Those with a lack of security experience attempting to use this book to hide their shortcomings will only embarrass themselves on an interview.

On the other hand, for the reader who has a background in information security who wants an update on network and security fundamentals, they will find IT Security Interviews Exposed a helpful title. The book contains a plethora of valuable information written in a clear and easy to read style. In a little over 200 pages, the book is able to provide the reader with a good review of what they know or may have forgotten. Used in such a setting by such a reader makes the book a most helpful tool for the serious security professional looking to advance their career.

Ben Rothke is a security consultant with BT INS and the author of Computer Security: 20 Things Every Employee Should Know.

You can purchase IT Security Interviews Exposed: Secrets to Landing Your Next Information Security Job from amazon.com. Slashdot welcomes readers' book reviews -- to see your own review here, read the book review guidelines, then visit the submission page.

5 of 74 comments (clear)

  1. Isn't that the problem, though? by morgan_greywolf · · Score: 4, Insightful

    Anyone trying to go through a comprehensive information security interview and wing it by reviewing the material will likely only succeed if the interviewer is inept. I find a lot of times, interviewers are inept. I've sat on both sides of the interview table and I can tell you that the decision makers rarely have much technical background, and technical people rarely have much insight into reading a person's level of fitness for the job from a personal skills or personality point of view. And it's rare that a decision-making manager is both a fantastic manager with keen personal insights and a technical person with up-to-date skills and experience.
  2. True of all professions by SiriusStarr · · Score: 2, Insightful

    Isn't it true of all professions that passion is what distinguishes the okay from the excellent? There might be some exceptions, but it holds in the vast majority of cases. It's always about your devotion to the job and what you bring to it. I don't think IT Security is unique in this sense. This is most certainly a ripe and growing profession, however, with the proliferation of cyber-crimes.

    --
    Fear the penguin.
  3. Rain, Parades, and Outsourcing by deweycheetham · · Score: 2, Insightful

    | "Information security is a hot career area and is among the strongest fields within IT for growth and opportunity. With excellent long-term career prospects, increasing cybersecurity vulnerabilities and an increase in security & privacy regulations and legislation, the demand for security professionals is significant..." |

    Not to rain on Chris Butler's parade or anything, but this position can be outsourced to anywhere in the world with a communications line and a back office, event thou your Security Consultant has an office just down the street.

  4. Qualifications... by Anonymous Coward · · Score: 5, Insightful


    What really separates a good candidate from a great candidate is hands-on, practical and real-world security experience.


    As a self made high level infosec professional, albeit one who of his own volition too a promotion to a maangement level in a different IT area, I would like to say that this is not true. Here are a few things that makes a great infosec candidate:

    1. Communication skills: A proper infosec pro does not do much technical work outside of running security systems. Even this is irrelevant in larger orgs - you have offshore resources for this work. What a security pro does do, however, is interface with all manner of technical and non-technical cross-functional teams. A normal day could include techincal meetings with networkops teams to go over firewall pinhole rules, a governance meeting with controllers, presentations to upper management on new initiatives, and policy making decision with lawyers. Communication is key.

    2. Ability to see the larger picture: One of my favorite sayings was that infosec's job was not to say "no", but to say "yes, and here's how to do it safely". Too many infosec practitioners, including ones with years and years of experience, turn into technology luddites. That is 180 degrees off what a true infosec practitioner does. Your job isn't to limit people, but to enable them to do their jobs better and safer - better is true for all IT roles, safer is true for infosec.

    3. Adequate technical background: I don't care what your background is in, but I would like to see a solid technical background. I don't want you doing risk analysis on firewalls, application security reviews, or hardware/software recommendations without being able to understamd the bsic concepts behind the technology.

    So, given the above and no security experience versus a complete nerd with no social skills and an attitude honed from 10 years of treating his "security" job as an excuse to say "no" to every request so he can go back to web surfing... ERRR, "keeping abreast of vulnerabilities", I take the former every time. Infosec experience be damned.

  5. A hot career? Passion? by Anonymous Coward · · Score: 1, Insightful

    If you're getting into infosec for any other reason than the fact that you're a natural paranoid who's horrified at the careless stupidity of the majority; you're wasting everyones time!