InfoSec professional advice to university students

14
Obsidis Consortia, Inc. So, you want to become a InfoSec professional? José L. Quiñones-Borrero, BS MCP, MCSA, MCT, CEH, CEI, GCIH, GPEN, RHCSA

description

This presentation was given at the Interamerican University Aguadilla PR to a group of graduating student and faculty members.

Transcript of InfoSec professional advice to university students

Page 1: InfoSec professional advice to university students

Obsidis Consortia, Inc.

So, you want to become a InfoSec professional?

José L. Quiñones-Borrero, BSMCP, MCSA, MCT, CEH, CEI, GCIH, GPEN, RHCSA

Page 2: InfoSec professional advice to university students

What is OC, Inc?

• Obsidis Consortia, Inc. [OC, Inc.] is a non-profit organization that promotes security awareness in the community and supports professional development of security professionals, students and enthusiasts in Puerto Rico. OC, Inc. has develop and is supporting initiatives like the Init6 Security User Group, Professional Training & Workshops, Network and Security Systems Simulation Scenarios (Capture the Flag), Security BSides Puerto Rico Conference and a Community Outreach Program.

Page 3: InfoSec professional advice to university students

.. so what do you need?

• Formal Education

• Skills

• Certifications

• Community

• Experience

Page 4: InfoSec professional advice to university students

Skills

• Networking– TCP/IP, Routing, Switching, Cisco CLI

• Operating Systems– Windows, Linux (Red Hat or Debian), OS X

• Virtualization & Cloud– ESXi, Hyper-V, Xen, KVM, Amazon, Rackspace

• Services– DNS, HTTP, Mail, Storage

Page 5: InfoSec professional advice to university students

… more skills

• Databases– MySQL, PostgreSQL, MSSQL

• WebApps– PHP, ASPX

• Scripting & Programming– C, C++, .Net– Python, Ruby, Perl– Bash, Powershell, CMD

Page 6: InfoSec professional advice to university students

Vendor Certifications

• Microsoft– MCTS, MCITP, MCSA, MCSE

• Cisco– CCNA, CCNP

• Red Hat– RHCSA, RHCE

• Vmware– VCP

• Others– Juniper, Fortinet,

Page 7: InfoSec professional advice to university students

… other certs

• CompTIA– A+, Network+, Security+, Linux +

• EC Council– CEH, CHFI …

• SANS Institute– GIAC …

• ISC2– CISSP

Page 8: InfoSec professional advice to university students

Roadmap

Area Fundamentals Intermediate Advance Top Managerial

NetworksNetwork +, CCNA CCNP CCIE CCAr

Windows MTA, MCTS MCITP, MCSA MCSE MCALinux LPI, Linux + RHCSA RHCE RHCADevelopment MCTS MCSD

SecuritySecurity +, GSEC CEH, CHFI, GCIH

OSCP, GPEN, GWAP OSCE

CISSP, GSEC, Security +

Others CSM, CISA PMI

Page 9: InfoSec professional advice to university students

Community

• User Groups– Init 6 Security Group– Stratups PR– Python Interest Group

• Social Media– Twitter, Google +, Linkedin, “Facebook”

• Networking– Student associations, Professional associations

(ISA, ISACA, ACFE, ISOC, IEEE)

Page 10: InfoSec professional advice to university students

How to get experience

• Do an Internship

• Set a Home Lab

• Do research and publish it

• Capture the Flag Events

Page 11: InfoSec professional advice to university students

Set you own lab

• eBay.com– Switches, routers, firewalls

• Workstation– 2-4 Cores, 8-16GB RAM, Dual Monitor, RAID 0 HDs

• Virtualization– Vmware Workstation or VirtualBox

• Reference Books– On everything.

Page 12: InfoSec professional advice to university students

… so, you want to become a InfoSec professional?

… learn, practice, share and love it!

Page 13: InfoSec professional advice to university students

Open Discussion …

• Q & A

• How can we help?

• How you can help your selves?