<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Breaking into the industry from a software process engineering background in Career Discussions</title>
    <link>https://community.isc2.org/t5/Career-Discussions/Breaking-into-the-industry-from-a-software-process-engineering/m-p/44034#M3171</link>
    <description>&lt;P&gt;If your still active in software development there has been more of a need for security engineering. In addition to being proficient in specific code ( .net, etc.) there is a need to understand vulnerabilities found in tools such as Fortify where a developer needs to fix/maj/minor releases in addition to integration with technologies (DB, ITL, web, access management, SIM, etc.). So I would consider learning new coding techniques for use in the Cloud, security tools that might required software coding/scripting, and even penetration testing.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Mar 2021 14:51:22 GMT</pubDate>
    <dc:creator>RRoach</dc:creator>
    <dc:date>2021-03-17T14:51:22Z</dc:date>
    <item>
      <title>Breaking into the industry from a software process engineering background</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Breaking-into-the-industry-from-a-software-process-engineering/m-p/44020#M3165</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; With more than 20 years experience implementing managing and leading Software Development and Software Configuration Management teams,&amp;nbsp; I have almost completed formalising my knowledge with ISC accreditations (CISSP,CSSLP,CCSP and soon the CISSP-ISSMP).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; I have found as I have studied that there are many more commonalities with what I have been doing at an enterprise and large programme level for decades - everything from the technical understanding of the concepts through to how to prepare and implement strategies plans and cultural change through education,&amp;nbsp; enablement and governance.&amp;nbsp; So it's been a pretty natural step to get the necessary qualifications.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I must say I do like how the ISC exam questions are clearly written fly people with the practical implementation experience rather than just looking for exam takers to repeat by rote.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It appears that people coming from a software engineering background seem to be quite rare in cyber security.&amp;nbsp; For example,&amp;nbsp; when I was looking for someone to endorse me for the CISSP,&amp;nbsp; I found only 2 of my linkedin contacts of over 1000 people who were CISSPs,&amp;nbsp; for example.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But herein lies my problem.&amp;nbsp; I get the impression now that many recruiters don't quite know how to stereotype me now.&amp;nbsp; &amp;nbsp;When they look at my experience,&amp;nbsp; they don't see roles directly with security in them - even though a large part of what I have been doing has been ensuring teams respect the CIA triad.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am even seeing roles that touch on software application security in the posting,&amp;nbsp; and when the recruiter sends through their clients original request there was a much heavier focus on software than the other aspects. They had actually modified the requirements for the posting so it was less software centric.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else experienced this sort of thing?&amp;nbsp; Do you have any pointers?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a bit of background,&amp;nbsp; when Devops started to take off and I saw teams spinning up AWS instances using their credit cards instead of working with the infrastructure and security teams,&amp;nbsp; I took a conscious decision to remain in SCM as I viewed and still view Devops as a subset of Software Configuration Management - or at least to the extent to which I have employed the discipline over the years,&amp;nbsp; in any case.&amp;nbsp; I think incidents like the Solarflares hack is probably a good example of how the focus on availability and schedules has predominated in the Software sector is resulting in adverse outcomes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway,&amp;nbsp; &amp;nbsp;if anyone has any tips here,&amp;nbsp; I would really appreciate it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 02:13:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Breaking-into-the-industry-from-a-software-process-engineering/m-p/44020#M3165</guid>
      <dc:creator>JackSussmilch</dc:creator>
      <dc:date>2021-03-17T02:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: Breaking into the industry from a software process engineering background</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Breaking-into-the-industry-from-a-software-process-engineering/m-p/44034#M3171</link>
      <description>&lt;P&gt;If your still active in software development there has been more of a need for security engineering. In addition to being proficient in specific code ( .net, etc.) there is a need to understand vulnerabilities found in tools such as Fortify where a developer needs to fix/maj/minor releases in addition to integration with technologies (DB, ITL, web, access management, SIM, etc.). So I would consider learning new coding techniques for use in the Cloud, security tools that might required software coding/scripting, and even penetration testing.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 14:51:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Breaking-into-the-industry-from-a-software-process-engineering/m-p/44034#M3171</guid>
      <dc:creator>RRoach</dc:creator>
      <dc:date>2021-03-17T14:51:22Z</dc:date>
    </item>
  </channel>
</rss>

