Unlocking Your Cybersecurity Career – Part 2: Initial Access

资讯 7个月前 admin
67 0 0

Welcome back to the series, and I hope you have made some progress in your cybersecurity career! In this blog post, we will look at the next step I go through when I look for a new job: The résumé. A small note: This will not tell you how to write a résumé. Instead, it includes recommendations to improve your existing one.
欢迎回到该系列,我希望您在网络安全职业生涯中取得了一些进展!在这篇博文中,我们将看看我在寻找新工作时要经历的下一步:简历。一个小提示:这不会告诉你如何写简历。相反,它包括改进现有建议的建议。

What is a Résumé?
什么是简历?

Before we look at how to make or improve our résumé, we first need to know what it is. Oxford Learner’s Dictionary defines the word as: “a written record of your education and the jobs you have done, that you send when you are applying for a job[.]”. In addition, the Wikipedia entry for “résumé” also makes a great point in that “a résumé is a marketing document[…]”. 
在我们研究如何制作或改进我们的简历之前,我们首先需要知道它是什么。牛津学习者词典将这个词定义为:“您在申请工作时发送的关于您的教育和您所做的工作的书面记录[.]”。此外,维基百科关于“简历”的条目也提出了一个很好的观点,即“简历是一份营销文件[…]”。

There is a great thing that I can’t remember where I heard from, but it states that every interaction you have is a transaction of some kind. If you’re in sales, this is obvious; either you can sell the prospect your product, or they can sell you a reason or excuse not to buy from you.
有一件很棒的事情我不记得我从哪里听到的,但它指出你的每一次互动都是某种交易。如果您从事销售工作,这是显而易见的;您可以向潜在客户出售您的产品,或者他们可以向您出售不向您购买的理由或借口。

Essentially, you can think of the hiring process as a form of “procurement.”
从本质上讲,您可以将招聘流程视为一种“采购”形式。

What is “Procurement”? 什么是“采购”?

“Now what is ‘procurement’? What in the world does ANY of this have to do with my cybersecurity career?” I hear you ask. Well, Investopedia defines it as such: 
“现在什么是’采购’?这些与我的网络安全职业有什么关系?我听到你问。好吧,Investopedia是这样定义的:

“Procurement is obtaining or purchasing goods or services, typically for business purposes.”
“采购是获取或购买商品或服务,通常出于商业目的。

So what does this have to do with us getting a job? Well, an example of procurement could be that the city wants to build a bridge. To do so, they start a procurement process and invite contractors to place “procurement bids” which contain price, the amount of time it will take, and so on.
那么这和我们找工作有什么关系呢?嗯,采购的一个例子可能是城市想要建造一座桥梁。为此,他们启动采购流程,并邀请承包商下达“采购投标”,其中包含价格、所需时间等。

Does it sound familiar yet? If not, what if instead of the city wanting to build a bridge, a company wants someone to perform services on their behalf to the company’s clients? In this case, the procurement process would essentially be the job description, and you are the contractor, offering to sell your time and expertise.
听起来熟悉吗?如果没有,如果不是城市想要建造一座桥梁,而是公司希望有人代表他们为公司的客户提供服务怎么办?在这种情况下,采购流程本质上就是职位描述,您是承包商,愿意出售您的时间和专业知识。

That is where the résumé comes in. It is the document you submit to the company saying what experience you have, what your expertise is, and what you have to offer to the company. In short, you have to sell yourself. And you have to become the best salesperson of yourself that has ever lived. That is unless you want someone else (a recruiter) to sell you. But you can never be 100% certain of what they say about you or how they will portray you to potential companies.
这就是简历的用武之地。这是您提交给公司的文件,说明您拥有什么经验,您的专业知识是什么,以及您必须为公司提供什么。简而言之,你必须推销自己。你必须成为有史以来最好的销售人员。除非你想让别人(招聘人员)卖给你。但是你永远无法100%确定他们对你的评价,或者他们将如何向潜在的公司描绘你。

So now that we know what a résumé is, and what role it fills in you landing your first job in your cybersecurity career, it is time to get started.
因此,既然我们知道了简历是什么,以及它在您在网络安全职业生涯中找到第一份工作时扮演什么角色,是时候开始了。

The Importance of Crafting an Effective Résumé
制作有效简历的重要性

To make sure we have everything we need, take out the list you made in the last blog post. We will use that list for this part, as you will make one résumé for each company. 
为了确保我们拥有所需的一切,请取出您在上一篇博客文章中列出的列表。我们将在这一部分使用该列表,因为您将为每家公司制作一份简历。

To begin with, I would recommend using a template. There are thousands upon thousands of them online. Some are better than others. I will only recommend the one I use personally: “Awesome CV” by “posquit0”. In addition to a CV, it also allows you to make a résumé and a cover letter in the same style. It can be slightly tricky to set up, but since you are (probably) here to start a cybersecurity career, I am sure you can figure it out. 
首先,我建议使用模板。网上有成千上万的人。有些比其他的更好。我只会推荐我个人使用的那个:“posquit0”的“真棒简历”。除了简历,它还允许您制作相同风格的简历和求职信。设置起来可能有点棘手,但由于您(可能)在这里开始网络安全职业生涯,我相信您可以弄清楚。

Tailoring Your Résumé Template for a Cybersecurity Career
为网络安全职业定制简历模板

I will say this. Résumés come in various shapes and sizes. I am not an authority in writing them, nor do I pretend to be. To reiterate what I said in the first post in the series: This series is based on what worked for me and my experience. You might have regional differences as well, so make sure to pay attention to that. An example of this would be Japan, where domestic companies don’t use CV or résumé, but the Japanese 履歴書 (rirekisho), which is more of an even more condensed CV, and where you have to include certain information.
我会这样说。简历有各种形状和大小。我不是写它们的权威,我也不会假装是。重申我在系列的第一篇文章中所说的话:这个系列是基于对我有用的东西和我的经验。您可能也有地区差异,因此请务必注意这一点。这方面的一个例子是日本,国内公司不使用简历或简历,而是使用日本履歴书(rirekisho),这更像是一份更浓缩的简历,并且您必须包含某些信息。

Even so, there are a few key things to keep in mind:
即便如此,还是要记住一些关键事项:

  • Your résumé should not be longer than two pages. This is the general rule, but I guess that you wouldn’t be here if you knew when to go over two pages.
    您的简历不应超过两页。这是一般规则,但我想如果你知道什么时候看两页,你就不会在这里。
  • When you write your experience, include quantitative data.
    当您编写经验时,请包括定量数据。
  • If you have work experience, work experience comes before education.
    如果你有工作经验,工作经验先于教育。

For that last point, at least in Sweden and Japan (and probably many other places), once you have a couple of years of experience, no one cares about your education. Okay, they might care if you are applying for a C-suite job, but apart from that, they probably won’t.
对于最后一点,至少在瑞典和日本(可能还有许多其他地方),一旦你有几年的经验,没有人关心你的教育。好吧,他们可能会关心您是否在申请最高管理层的工作,但除此之外,他们可能不会。

The Structure 结构

Here is the structure or layout that I used for my résumé, and some details on a few of them:
以下是我用于简历的结构或布局,以及其中一些的一些细节:

  1. Name and other information
    姓名和其他信息
  2. Experience 经验
  3. Skills & Certifications 技能和认证
  4. Education 教育
  5. Extracurricular Activities
    课外活动
  6. Interests 利益

Experience 经验

This is where I list all relevant experience. I have had many odd jobs in the past including, but not limited to telemarketing, brick-and-mortar store employee, and web developer. If I apply for a job as a cybersecurity specialist, working as a telemarketer isn’t relevant. As such, I wouldn’t have included it. However, the store job I have included sometimes depends on what the company values and what the job description says. For example, if the job description includes assisting the sales team during pre-sales meetings, the experience of dealing with customers and the interpersonal skills I gained from that job would be useful for that role.
这是我列出所有相关经验的地方。我过去做过很多零工,包括但不限于电话营销、实体店员工和网络开发人员。如果我申请网络安全专家的工作,那么电话推销员的工作就无关紧要了。因此,我不会包括它。但是,我包括的商店工作有时取决于公司重视什么以及职位描述的内容。例如,如果职位描述包括在售前会议期间协助销售团队,那么与客户打交道的经验以及我从该工作中获得的人际交往技巧对该角色很有用。

The thing to take away from this is just because your experience isn’t in the same (or even adjacent) industry, it can still be applicable. Remember, this is a marketing document. Sell yourself!
从中得到的只是因为你的经验不是在同一个(甚至相邻的)行业,它仍然可以适用。请记住,这是一份营销文件。推销自己!

Skills & Certifications 技能和认证

As with the experience section, include items relevant to the job description and exclude those that aren’t.
与经验部分一样,包括与职位描述相关的项目,并排除与职位描述无关的项目。

Extracurricular Activities
课外活动

This is just where I include things that don’t fit anywhere else. For example, in my cybersecurity résumé, I include things like details on my home lab, any talks or cybersecurity groups I’ve participated in, and things like learning platforms where I am doing continued learning to show motivation and that I keep improving, rather than going stagnant. 
这只是我包含不适合其他任何地方的东西的地方。例如,在我的网络安全简历中,我包括诸如家庭实验室的详细信息,我参加过的任何讲座或网络安全小组,以及诸如学习平台之类的内容,在这些平台上,我正在继续学习以显示动力,并且我不断改进,而不是停滞不前。

Some Recommendations 一些建议

Now that I’ve shown you what I do, I will include a YouTube video by Cyber Insecurity which helped me modify my résumé:
现在我已经向您展示了我的工作,我将包括一个由Cyber Insecurity制作的YouTube视频,它帮助我修改了我的简历:

Leveraging LinkedIn for Networking in Your Cybersecurity Journey
在网络安全之旅中利用LinkedIn进行网络交流

And for the final recommendation: Get yourself LinkedIn. Yes, I know you might not like the platform. But the truth is that there are jobs on there, and networking helps a lot in this industry (and many others). It is estimated that roughly 80% of all jobs are landed through some form of networking (friend of a friend, meeting the new employer at a networking event, etc.). In addition, it is estimated that somewhere around 70% of jobs never end up on public job listing sites, but are filled via networking or referrals. The exact data on this depends on where you look, but there are quite a few articles out there on the subject, such as this article by Forbes from 2020.
最后的建议是:让自己LinkedIn。是的,我知道你可能不喜欢这个平台。但事实是,那里有工作,网络在这个行业(以及许多其他行业)有很大帮助。据估计,大约80%的工作是通过某种形式的网络(朋友的朋友,在社交活动中与新雇主见面等)获得的。此外,据估计,大约 70% 的工作从未出现在公共职位列表网站上,而是通过网络或推荐来填补的。这方面的确切数据取决于您在哪里查看,但是有很多关于该主题的文章,例如福布斯2020年的这篇文章。

Once you get your LinkedIn and start setting it up, Cyber Insecurity has another couple of videos on YouTube called “Hack Your LinkedIn”. You can click here for the first video.
一旦你拿到LinkedIn并开始设置它,Cyber Insecurity在YouTube上还有另外几个视频,叫做“破解你的LinkedIn”。您可以单击此处观看第一个视频。

Conclusion 结论

Getting started in your cybersecurity career isn’t easy. Today we went over a few of the things that I do and some tips for when writing your résumé (you remembered to use quantitative data, right? Right?)
开始您的网络安全职业生涯并不容易。今天我们回顾了我所做的一些事情以及撰写简历时的一些技巧(您记得使用定量数据,对吗?对吧?

In the next blog post in this series, I will go over a few ideas for how to get some experience despite all jobs seemingly requiring 3-5 years of experience to begin with.
在本系列的下一篇博文中,我将介绍一些想法,说明如何获得一些经验,尽管所有工作似乎都需要 3-5 年的经验。

原文始发于dao-security:Unlocking Your Cybersecurity Career – Part 2: Initial Access

版权声明:admin 发表于 2023年10月10日 上午10:35。
转载请注明:Unlocking Your Cybersecurity Career – Part 2: Initial Access | CTF导航

相关文章

暂无评论

您必须登录才能参与评论!
立即登录
暂无评论...