Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Wibla
Feb 16, 2011

BonHair posted:

Preferably, get a buddy you can set up fake meetings with, since calendar time marked "busy" will often just get ignored by the meeting people.

Be ruthless when declining meetings. They'll get the point sooner or later. Or they'll make do without you in that meeting.

Diva Cupcake posted:

What's it like being on vacation?

I'm not on vacation :colbert:

(See also: the above).

Adbot
ADBOT LOVES YOU

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Definitely ask for an agenda for any meeting, so you can figure out how to not be there.

(Sometimes it’s easier to go to the meeting and just work on something in the background instead, though.)

kensei
Dec 27, 2007

He has come home, where he belongs. The Ancient Mariner returns to lead his first team to glory, forever and ever. Amen!


Subjunctive posted:

Definitely ask for an agenda for any meeting, so you can figure out how to not be there.

(Sometimes it’s easier to go to the meeting and just work on something in the background instead, though.)

This is how I live my management life

Internet Explorer
Jun 1, 2005





I don't work on things in the background in meetings. If I'm wasting my time in a meeting, I'm wasting my time in a meeting. I'm not going to risk being expected to have comprehended something in a meeting or doing a poor job on a task because I can't concentrate. My current job is all meetings. I get nothing done. I tell my boss and their boss that I don't have time to get things done. That's their problem.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Cannon_Fodder posted:

I'm inheriting a massive vulnerability debt and taking on a vulnerability management position with very little experience.


Piss and poo poo. Here we go.

Welcome to vuln management. It doesn't get better. I ran our vuln management for about 4 years before building it out to something proper that can be reasonably handled by another team (in the security office). I like to think I've seen everything, but please do prove me wrong with any novel nightmares you come across.

Sickening
Jul 16, 2007

Black summer was the best summer.

ChubbyThePhat posted:

Welcome to vuln management. It doesn't get better. I ran our vuln management for about 4 years before building it out to something proper that can be reasonably handled by another team (in the security office). I like to think I've seen everything, but please do prove me wrong with any novel nightmares you come across.

I had a meeting with my CISO last week on the topic of vuln management. They are a very modern, progressive CISO whose opinion I think a great deal of. Saying that, the shift they want to take with it is just so absurd that it makes me second guess every decision they have ever made.

The company has an eroding ownership of infrastructure and resources. The low bar of creating infrastructure has created a gigantic vacuum of "what now" after it exists. SRE/DEVOPS/WHATEVERYOUWANTTOCALLSHIT teams never truly aligned their goals with maintaining infrastructure and resources after it exists. Devs live to build poo poo and abandon it. Basically every team in existence desires the ability to create and abandon everything but what the infrastructure makes possible.

My CISO is looking to expand the scope of security even more. They have a vision of SecOps to architect, create, deploy, and maintain OS vuln, app vuln, config vuln, network vuln, and CI/CD vuln for every aspect of the company. The very notion of "we can't rely on the rest of the company to do what we demand, so we are going to do it ourselves" and its never going to loving work. Our teams are going to crush themselves under boundless scope and responsibility. We are just going to fail.

Darchangel
Feb 12, 2009

Tell him about the blower!


Diva Cupcake posted:

What's it like being on vacation?

Yes, please. Let me live vicariously through you.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Sickening posted:

My CISO is looking to expand the scope of security even more. They have a vision of SecOps to architect, create, deploy, and maintain OS vuln, app vuln, config vuln, network vuln, and CI/CD vuln for every aspect of the company. The very notion of "we can't rely on the rest of the company to do what we demand, so we are going to do it ourselves" and its never going to loving work. Our teams are going to crush themselves under boundless scope and responsibility. We are just going to fail.

That scope is purely infinite and is not achievable under any circumstance :staredog:

Obviously you know this, I'm just doubling down on it seems you have a CISO who has taken to heart the idea of "if you want something done, do it yourself". Here's you hoping you can talk them out of it and into a more reasonable path of process creation to hand out specific remediation work. Let it be known I also hate this solution in smaller corps, but I will take it over either the extremes of 'we do it all' and 'pray other teams do it themselves'.

evil_bunnY
Apr 2, 2003

Wibla posted:

Be ruthless when declining meetings. They'll get the point sooner or later. Or they'll make do without you in that meeting.
One of my favorite things to do at work is asking for meeting agendas and telling people what we can do for them or telling them how things will shake out instead of attending.

Subjunctive posted:

(Sometimes it’s easier to go to the meeting and just work on something in the background instead, though.)
One of the many benefits of remote.

Sickening posted:

The company has an eroding ownership of infrastructure and resources. The low bar of creating infrastructure has created a gigantic vacuum of "what now" after it exists. SRE/DEVOPS/WHATEVERYOUWANTTOCALLSHIT teams never truly aligned their goals with maintaining infrastructure and resources after it exists. Devs live to build poo poo and abandon it. Basically every team in existence desires the ability to create and abandon everything but what the infrastructure makes possible.
"write less code"

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
I have been tasked with standing up an OpenCTI instance for us; sure sounds great. Anyone ever build this before or am I essentially being given another pet project for me to turn into the greybeard over?

Mustache Ride
Sep 11, 2001



Do misp, it'll integrate better with your tools and it's the same price.

Potato Salad
Oct 23, 2014

nobody cares


Seconding misp here

Mike Cartwright
Oct 29, 2011

state of the art


Anyone want to guess salary for this position? Title: Offensive Security Specialist. Based in Berlin. :)

KozmoNaut
Apr 23, 2008

Happiness is a warm
Turbo Plasma Rifle


Unpaid internship.

CLAM DOWN
Feb 13, 2007




Mike Cartwright posted:



Anyone want to guess salary for this position? Title: Offensive Security Specialist. Based in Berlin. :)

€35000

Mike Cartwright
Oct 29, 2011

state of the art



Yep pretty close.

Badly Jester
Apr 9, 2010


Bitches!
To put that into perspective for the non-German/EU goons: the lowest end of their range is barely more than minimum wage.

Mike Cartwright
Oct 29, 2011

state of the art
Not all of them are this bad, but this is one of the worst ones I've seen in a while. Could have added GSE.

Kazinsal
Dec 13, 2011

Mike Cartwright posted:



Yep pretty close.

The top end of that is about what I make as a desperately underpaid network engineer in Vancouver, and I have to live an hour by transit from the office to be able to afford rent.

I thought our garbage wages were loving criminal, but holy poo poo, Berlin's got us beat.

Mike Cartwright
Oct 29, 2011

state of the art

Kazinsal posted:

The top end of that is about what I make as a desperately underpaid network engineer in Vancouver, and I have to live an hour by transit from the office to be able to afford rent.

I thought our garbage wages were loving criminal, but holy poo poo, Berlin's got us beat.

I used to work in a NOC 10+ yrs ago and I think I made the middle of that range.

spankmeister
Jun 15, 2008






Cost of living isn't comparable between Vancouver and Berlin, but it's still a pitiful wage for Berlin standards.

Kazinsal
Dec 13, 2011

spankmeister posted:

Cost of living isn't comparable between Vancouver and Berlin, but it's still a pitiful wage for Berlin standards.

I looked it up, and the average rent in downtown Berlin for a one-bedroom apartment is about 2/3 of what the same would be in downtown Vancouver.

Apparently I need to learn German.

Mike Cartwright
Oct 29, 2011

state of the art

Kazinsal posted:

I looked it up, and the average rent in downtown Berlin for a one-bedroom apartment is about 2/3 of what the same would be in downtown Vancouver.

Apparently I need to learn German.

Depends on the neighborhood. Prices are fluctuating, you can get one bedroom for 700-800EUR, a 2br in Kreuzberg for 900EUR is a "steal" - it really depends.

And no need for German. You'll pick it up anyway.

spankmeister
Jun 15, 2008






Kazinsal posted:

I looked it up, and the average rent in downtown Berlin for a one-bedroom apartment is about 2/3 of what the same would be in downtown Vancouver.

Apparently I need to learn German.

You don't need to speak German in Berlin, especially if you work in tech.

Badly Jester
Apr 9, 2010


Bitches!
Alternatively, don't discourage someone from learning the language of where they're considering moving to. Being able to speak German is going to be useful in Germany, particularly if you don't want to remain trapped in the "expat" bubble.

Thanks Ants
May 21, 2004

#essereFerrari


Learning languages of where you move to is basic politeness, though in Germany if the locals detect that you can't quite master German they will quickly switch to English and not really give you much of a chance to learn. The opposite of France.

some kinda jackal
Feb 25, 2003

 
 
Doing pentests for the exposure

evil_bunnY
Apr 2, 2003

Kazinsal posted:

I thought our garbage wages were loving criminal, but holy poo poo, Berlin's got us beat.
Up to very recently berlin rents were extremely affordable.

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS
Taking bets on whether this will make Splunk more expensive

https://investor.cisco.com/news/new...ld/default.aspx

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Blinkz0rz posted:

Taking bets on whether this will make Splunk more expensive

https://investor.cisco.com/news/new...ld/default.aspx

I for one am looking forward to seeing Cisco work their licensing magic

cr0y
Mar 24, 2005



Mike Cartwright posted:



Anyone want to guess salary for this position? Title: Offensive Security Specialist. Based in Berlin. :)

Well do you have on of the following certifications?

Maybe they missed two letters instead of one and are hoping that you have none certifications.

Diva Cupcake
Aug 15, 2005

Blinkz0rz posted:

Taking bets on whether this will make Splunk more expensive

https://investor.cisco.com/news/new...ld/default.aspx
Can't believe this actually happened.

some kinda jackal
Feb 25, 2003

 
 
Mildly surprised it wasn't Oracle


I texted my friend who's the Splunk business owner at work and he lost it. I think I ruined his day before 8am lol

Thanks Ants
May 21, 2004

#essereFerrari


That's the product dead then, expect some really half-arsed integrations that need three racks of VM hosts to act as licensing servers

wargames
Mar 16, 2008

official yospos cat censor

rafikki posted:

I for one am looking forward to seeing Cisco work their licensing magic

i don't see how it could get worse, unless you need a splunk cert to get the license.

Zorak of Michigan
Jun 10, 2006


wargames posted:

i don't see how it could get worse, unless you need a splunk cert to get the license.

Oh, I think you aren't digging nearly as deep as a properly desperate executive. Just imagine it. "We've heard some customers complain that our pricing model is difficult for them to manage due to fluctuating ingest bandwidth needs. We've decided to make a more flexible set of options built around Splunk Infrastructure Credits (SICs) which can be used for ingest-based or a new capacity-based licensing model. Telemetry in new editions of Splunk will phone home and tell us how many SICs you're using, and you'll be billed accordingly. We'll be publishing the details of SIC calculations in the future."

Mustache Ride
Sep 11, 2001



But they already do that. That's the Splunk Cisco cloud svc model

Thanks Ants
May 21, 2004

#essereFerrari


Don't forget your DNA licenses required to host the Splunk services

Calypso Hippo
Dec 29, 2008

Free Air! No Oppression!
Going through the wringer right now with security engineer interviews and every company thinks they are Google. 4 or 5 rounds of final interviews, each with a Leetcode algorithms round. I have 9 hours of interviews scheduled for the beginning of next week. :dumbgun:

Adbot
ADBOT LOVES YOU

FungiCap
Jul 23, 2007

Let's all just calm down and put on our thinking caps.
Soooo is everyone else seeing a massive increase in QR code phishing for o365 logins?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply