Hello, recently passed the CC Exam, my ultimate goal is to work towards a job in the ethical hacking side of things. I have 3 years of basic IT and Coding. 8 years in finances/management role in the auto industry. I have heard mixed reviews about getting CEH certificate and that it won't help land a job. I am network to get any kind of entry position so I can start building my work experience while I also build my knowledge. Just not sure what areas of knowledge/courses/bootcamps, etc I should chase.
Thanks in advance.
@emb021 If you have links to negative comments, would you send to me privately. As I said, I had personally not heard anything negative but I could be out of touch.
tqvm
Appreciate all the replies. After doing more research in my area. I am going to take a pause on focusing on a specific area when my foundation knowledge is limited. My only goal right now is to network and work on courses/certificates that will help me land a job. I can work up from there. Started as a lot kid and became a finance manager in auto industry. Biggest thing is always work experience and I enjoy learning as I grow.
@Dey93 I don't know enough about CompTIA's training to recommend it. You can probably get decent training from other sources. Thing is at this point, Sec+ is just better known as CC, thus its still worth it to get it.
I have to agree with @nkeaton comments regarding CompTIA going "for profit". Another thing I noticed is that if you go to their site and want to see all their certs, they actual show you all their certificates and certifications together, which is a little deceiving, IMO. You have to look closely at the logos to figure out which is which. Certificates and certifications are NOT the same.
I would also recommend you read the comments on this thread regarding EC-C.
@dcontesti I can say, as have others, that there ARE folks with negative feelings about the CEH. I've heard complaints about the quality of the questions (spelling and grammar issues), as well as the other issues with ECC. There are several infosec pros in my area who don't care for them and I respect their viewpoints on this.
@Dey93 You might want to see if there is an active local OWASP chapter. That is the only security group that I am aware of that deals somewhat with that specialty. I don't remember if discussed in the CC, but everyone should be at least aware of OWASP's Top 10. owasp.org/Top10/2025/0x00_2025-Introduction They also have some very good tools available. CSA also does this for cloud. cloudsecurityalliance.org/press-releases/2024/08/06/cloud-security-alliance-releases-top-threats-to-cloud-computing-2024-report
So far what I have been told is that CompTIA Sec+ is essential for most hiring employers in my area. Is it recommended to do the course via the CompTIA site or is their a better course recommendation?
Thanks!
@Dey93 Congratulations on your CC. That is a great first step. Unfortunately everyone unfamiliar with cybersecurity wants to be an ethical hacker or pentester because it sounds cool, and occasionally it is when not writing reports and all of the other tedious tasks that come with it. Since defensive and offensive security are not profit centers, there are very few positions with many people wanting to fill them. Offensive security has very few positions except in a company that sells those services, and they will want experience. I am one of many that believes that ECC needs to be boycotted to eventually go out of business. ECC has always been over priced, has a long history of mistreating their female employees, and of having labs that were not great. A few years ago they had some major ethical violations. You can look for thor ceh if want details as he is well respected and known internationally. He earned a CEH and gave it up over these incidents. Where I work, we will hire someone with an ECC certification because is not their ethics that is in question, only ECC's lack of ethics. We will never create any new ones though. Oddly it seems to be the men that are the most infuriated about it. Paraphrasing what you will read from Thor, ECC said that women are too stupid to be in cybersecurity. The men say that the organization insulted their wives, mothers, daughters, etc. We have our folks do CySA+ and/or PenTest+ depending on their role. I have only ever heard good things from others about OSCP and eJPT. My employer does not recognize them because do not have a continuing education component or would know more about them. From those that I know, I would recommend either of them over anything that ECC offers.
Congrats on passing the CC.
I have only heard positive reviews on the CEH. Networking is great especially to help you get started on your new career.
d
@Dey93 You noted you're networking to get a position. Hopefully it's with local people who already work in the field. They can probably give you better advise then here as we don't know your local area.
There is some negative feels toward CEH and EC-Council. I won't repeat it, but on another thread regarding certs someone pointed out some of the issues.
You might want to take a look at CompTIA and their Sec+, Net+, Pentest+ certs. While I have issues with them going for-profit, those are still decent certs. Understand that certs aren't a "golden ticket" to a job...
More expensive are the SANS certs, but there are ways to get around the cost (look up "Work Study"). Also check out groups like Hack the Box and Offensive Security.
Many local community colleges/tech schools are doing cybersecurity training. How good that might be I have no idea, or how well they are at getting people into the industry. Local people would better be able to tell you.
Hope this helps. Am sure others here will add to this.
Hello, recently passed the CC Exam, my ultimate goal is to work towards a job in the ethical hacking side of things. I have 3 years of basic IT and Coding. 8 years in finances/management role in the auto industry. I have heard mixed reviews about getting CEH certificate and that it won't help land a job. I am network to get any kind of entry position so I can start building my work experience while I also build my knowledge. Just not sure what areas of knowledge/courses/bootcamps, etc I should chase.
Thanks in advance.