Certifications for fresh grad

bluegreen

Junior Member
Joined
Mar 25, 2018
Messages
1
Reaction score
0
Hi all,
I am new to this community so would like some advice on getting certifications.
Currently am an undergrad in local uni. Would like to go into Cybersecurity field in future, either in pentesting or conducting analytics (network forensics etc)

Abit of background info:
-Participated in CTFs occasionally since 2013, but never won or get top few.
-Managed to get Pentesting intern role in CSA (Cyber Security Agency of SG)
-Doing Info Systems/Data Analytics double major in uni.
-Doing Uni research project on Cyber Attack Topology and Visualisation (Visual Analytics kind of project)
-Data Protection Officer (DPO) certified (It was sponsored)

Currently, would like to beef my knowledge and resume up with more certifications. Preferably with CITREP+ subsidy as I still student only, but I can afford up to 1K + Citrep 2k subsidy for students = 3k certification cost.

Currently, only CEH seems applicable to my situation (CISSP, CCSP needs working experience, SANS courses too ex. Considering OSCP, but not sure about commitment yet (sch has been insane + not CITREP subsidised).

Anyone can advise if CEH will value-add to my Resume, or is it indeed looked down upon by recruiters/interviewers? Also, anyone knows of potential certifications that I can look at? I don't wish to restrict myself to just pentesting certs, so Im open to other aspects (CISA, CIPP/A etc).

Thanks for all the guidance! :)
 

Lastexile

Arch-Supremacy Member
Joined
Mar 6, 2004
Messages
11,718
Reaction score
126
Just one company's job description

https://careers.mwrinfosecurity.com/Jobs/Advert/1094208?cid=1642&FromSearch=False

juFL2ln.png


I would rather you go read some books and setup some labs on your own, then put it on your resume.
 
Last edited:

slashershot

Arch-Supremacy Member
Joined
May 5, 2012
Messages
21,662
Reaction score
5,336
Save up/ask around for sponser and take OSCP.

OSCP is the most legit course I've ever taken. I've learnt more from it than my entire 3 years in poly. :s22::s22::s22:

IMO, any pentesting company worth their salt will ask for OSCP at least and ignore CEH. If they want CEH, likely is audit and compliance just to meet government regulations.

I mean if you have time and $$ go for RHEL and MCSA too. So can at least show you know your way around these OS. :\

PM me if you wan know more about OSCP.
 

seesiang

Member
Joined
Oct 17, 2011
Messages
415
Reaction score
5
Save up/ask around for sponser and take OSCP.

OSCP is the most legit course I've ever taken. I've learnt more from it than my entire 3 years in poly. :s22::s22::s22:

IMO, any pentesting company worth their salt will ask for OSCP at least and ignore CEH. If they want CEH, likely is audit and compliance just to meet government regulations.

I mean if you have time and $$ go for RHEL and MCSA too. So can at least show you know your way around these OS. :\

PM me if you wan know more about OSCP.

RedHat and Microsoft will not value add to Digital Security. Dont get me wrong, i am not saying it is useless. I came from RHCE version 5 and MCSA 2003. But the route that I took, it is simply too long.

Alternative, try elearnsecurity.com

OSCP is having same difficulties as eCPPT.

- To Thread starter, try to read OWASP top 10 guidelines and try burp during your free time.

-- OSSTMM, IBTRM, gov8 may help for TS too.
 

SajiAkihiro

Junior Member
Joined
May 6, 2016
Messages
12
Reaction score
0
True. It’s good to try elearnsecurity. Did a few courses with them but definitely wasn’t for the cert recognition (don’t think it’s widely recognised in SG) but they do deliver the knowledge in a more learner friendly way then Offsec does. Speaking from my experience in taking courses from both vendors. Do correct me if I’m wrong. 😂

If you have no hands on experience in IS or Specifically pen test, I think elearn is a pretty good place to start if you have the $$ to spare. If no $$ straight to OSCP would be best route though.

RedHat and Microsoft will not value add to Digital Security. Dont get me wrong, i am not saying it is useless. I came from RHCE version 5 and MCSA 2003. But the route that I took, it is simply too long.

Alternative, try elearnsecurity.com

OSCP is having same difficulties as eCPPT.

- To Thread starter, try to read OWASP top 10 guidelines and try burp during your free time.

-- OSSTMM, IBTRM, gov8 may help for TS too.
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top