Visualização de leitura

For folks in here, it's important to know that people who are currently looking for a job is much more likely to be on Reddit than someone who already has a job

I am not saying at all that people here are all unemployed. A lot of people are employed.

But Reddit is not always real life.

Something worth keeping in mind whenever you're gauging the job market from this sub: the people posting are skewed toward those who are currently looking for work. If you already have a job and aren't hunting, you're way less likely to hop on here and comment about how the market's going — you're just… working.

submitted by /u/Exact-Advantage-3190
[link] [comments]

I want to transition from an AppSec role to Cloud Security. How feasible is this and how should I study?

I just want to state, when I get assigned to projects or help builders secure their apps, of course this includes at least some exposure to cloud security because all apps live in the cloud. A lot of my time goes to threat modeling, secure code review, and helping apps find threats in their design.

That said, I feel like my day-to-day is heavily weighted toward application-layer concerns, things like design flaws, api security, a lot of code review, etc.

For those of you who've made a similar transition (or work in cloud security and hire from AppSec backgrounds): How transferable are AppSec skills in practice? I'd assume threat modeling and understanding attacker mindset translate well, but what gaps should I expect?

What should I focus on studying? I'm thinking AWS/Azure/GCP certifications, but I'm not sure which ones actually matter vs. just being resume flair

Any resources, labs, or projects you'd recommend for building hands-on cloud security experience outside of work? Appreciate any advice. Trying to be intentional about this

submitted by /u/Exact-Advantage-3190
[link] [comments]

Security engineer, 5 years at FAANG. What are my realistic options in this market?

Quick background: about 5 years as a security engineer at a FAANG company. Mix of application security, threat modeling, and product security. Fairly comfortable across the SDLC, work directly with dev teams, and have shipped real security outcomes.

My coding skills need work to be honest, I need to take a month or two to get up to speed, but I feel fairly confident in other domains with a bit of studying.

submitted by /u/Exact-Advantage-3190
[link] [comments]
❌