ConvoCourses: Recent Episodes

ConvoCourses

Cyber Security Compliance and IT Jobs

View Details

ConvoCourses.com

View Details

Here is how I used AI to get a job recently

View Details

AI definitely had an impact on my recent job journey.

View Details

We talk about GRC

View Details

https://youtube.com/live/U_haUXrWZ1Q

SIGN UP FOR FREE COURSES πŸ“š
http://convocourses.com (Join the Group)
http://convocourses.net (Shop)

JOIN THE NEWSLETTER πŸ“¨
https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share

CHECK US OUT HERE 🌐
Website: http://convocourses.org
Instagram: https://instagram.com/convocourses
TikTok: https://www.tiktok.com/@convocourses
Facebook: https://www.facebook.com/ConvoCourses-108091850619388
LinkedIn: https://www.linkedin.com/in/convocourses/

LISTEN TO THE PODCAST 🎧
Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278
RSS Feed: https://feeds.captivate.fm/convocourses/

BOOKS ON AMAZON πŸ“–
http://amazon.com/author/brucexwrites

JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ
https://booksprout.co/reviewer/team/35902/convocourses

convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

SIGN UP FOR FREE COURSES πŸ“š
http://convocourses.com (Join the Group)
http://convocourses.net (Shop)

JOIN THE NEWSLETTER πŸ“¨
https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share

CHECK US OUT HERE 🌐
Website: http://convocourses.org
Instagram: https://instagram.com/convocourses
TikTok: https://www.tiktok.com/@convocourses
Facebook: https://www.facebook.com/ConvoCourses-108091850619388
LinkedIn: https://www.linkedin.com/in/convocourses/

LISTEN TO THE PODCAST 🎧
Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278
RSS Feed: https://feeds.captivate.fm/convocourses/

BOOKS ON AMAZON πŸ“–
http://amazon.com/author/brucexwrites

JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ
https://booksprout.co/reviewer/team/35902/convocourses

convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

SIGN UP FOR FREE COURSES πŸ“š
http://convocourses.com (Join the Group)
http://convocourses.net (Shop)

JOIN THE NEWSLETTER πŸ“¨
https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share

CHECK US OUT HERE 🌐
Website: http://convocourses.org
Instagram: https://instagram.com/convocourses
TikTok: https://www.tiktok.com/@convocourses
Facebook: https://www.facebook.com/ConvoCourses-108091850619388
LinkedIn: https://www.linkedin.com/in/convocourses/

LISTEN TO THE PODCAST 🎧
Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278
RSS Feed: https://feeds.captivate.fm/convocourses/

BOOKS ON AMAZON πŸ“–
http://amazon.com/author/brucexwrites

JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ
https://booksprout.co/reviewer/team/35902/convocourses

convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

https://youtube.com/live/FQ_Gber76EU

check out professor black ops: https://www.youtube.com/@professorblackops-cybersec1168

SIGN UP FOR FREE COURSES πŸ“š
http://convocourses.com (Join the Group)
http://convocourses.net (Shop)

JOIN THE NEWSLETTER πŸ“¨
https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share

CHECK US OUT HERE 🌐
Website: http://convocourses.org
Instagram: https://instagram.com/convocourses
TikTok: https://www.tiktok.com/@convocourses
Facebook: https://www.facebook.com/ConvoCourses-108091850619388
LinkedIn: https://www.linkedin.com/in/convocourses/

LISTEN TO THE PODCAST 🎧
Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278
RSS Feed: https://feeds.captivate.fm/convocourses/

BOOKS ON AMAZON πŸ“–
http://amazon.com/author/brucexwrites

JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ
https://booksprout.co/reviewer/team/35902/convocourses

convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

SIGN UP FOR FREE COURSES πŸ“š
http://convocourses.com (Join the Group)
http://convocourses.net (Shop)

JOIN THE NEWSLETTER πŸ“¨
https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share

CHECK US OUT HERE 🌐
Website: http://convocourses.org
Instagram: https://instagram.com/convocourses
TikTok: https://www.tiktok.com/@convocourses
Facebook: https://www.facebook.com/ConvoCourses-108091850619388
LinkedIn: https://www.linkedin.com/in/convocourses/

LISTEN TO THE PODCAST 🎧
Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278
RSS Feed: https://feeds.captivate.fm/convocourses/

BOOKS ON AMAZON πŸ“–
http://amazon.com/author/brucexwrites

JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ
https://booksprout.co/reviewer/team/35902/convocourses

convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

https://youtube.com/live/jweGSLb_zgU

SIGN UP FOR FREE COURSES πŸ“š

http://convocourses.com (Join the Group)

http://convocourses.net (Shop)

JOIN THE NEWSLETTER πŸ“¨

https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share

CHECK US OUT HERE 🌐

Website: http://convocourses.org

Instagram: https://instagram.com/convocourses

TikTok: https://www.tiktok.com/@convocourses

Facebook: https://www.facebook.com/ConvoCourses-108091850619388

LinkedIn: https://www.linkedin.com/in/convocourses/

LISTEN TO THE PODCAST 🎧

Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278

RSS Feed: https://feeds.captivate.fm/convocourses/

BOOKS ON AMAZON πŸ“–

http://amazon.com/author/brucexwrites

JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ

https://booksprout.co/reviewer/team/35902/convocourses

convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

https://youtube.com/live/Slam57hVRYs

I have been in GRC for years and I have just transitioned into Cloud. Day 0: How did I do it Preparation of GRC vs Cloud Open topics πŸŽ™οΈ New to streaming or looking to level up? Check out StreamYard and get $10 discount! 😍 https://streamyard.com/pal/d/4632689196662784 SIGN UP FOR FREE COURSES πŸ“š http://convocourses.com (Join the Group) http://convocourses.net (Shop) JOIN THE NEWSLETTER πŸ“¨ https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share CHECK US OUT HERE 🌐 Website: http://convocourses.org Instagram: https://instagram.com/convocourses TikTok: https://www.tiktok.com/@convocourses Facebook: https://www.facebook.com/ConvoCourses-108091850619388 LinkedIn: https://www.linkedin.com/in/convocourses/ LISTEN TO THE PODCAST 🎧 Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278 RSS Feed: https://feeds.captivate.fm/convocourses/ BOOKS ON AMAZON πŸ“– http://amazon.com/author/brucexwrites JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ https://booksprout.co/reviewer/team/35902/convocourses #convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

https://youtube.com/live/VuiCYeVHr2s

Lets check out the biggest GRC news as of AUG 2025! We will also take questions. πŸŽ™οΈ New to streaming or looking to level up? Check out StreamYard and get $10 discount! 😍 https://streamyard.com/pal/d/4632689196662784 SIGN UP FOR FREE COURSES πŸ“š http://convocourses.com (Join the Group) http://convocourses.net (Shop) JOIN THE NEWSLETTER πŸ“¨ https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share CHECK US OUT HERE 🌐 Website: http://convocourses.org Instagram: https://instagram.com/convocourses TikTok: https://www.tiktok.com/@convocourses Facebook: https://www.facebook.com/ConvoCourses-108091850619388 LinkedIn: https://www.linkedin.com/in/convocourses/ LISTEN TO THE PODCAST 🎧 Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278 RSS Feed: https://feeds.captivate.fm/convocourses/ BOOKS ON AMAZON πŸ“– http://amazon.com/author/brucexwrites JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ https://booksprout.co/reviewer/team/35902/convocourses #convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

https://youtube.com/live/Gcv1lLgbicE

I have been in this career path since 2000. This is an honest take on the 2025 IT market. πŸŽ™οΈ New to streaming or looking to level up? Check out StreamYard and get $10 discount! 😍 https://streamyard.com/pal/d/4632689196662784 SIGN UP FOR FREE COURSES πŸ“š http://convocourses.com (Join the Group) http://convocourses.net (Shop) JOIN THE NEWSLETTER πŸ“¨ https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share CHECK US OUT HERE 🌐 Website: http://convocourses.org Instagram: https://instagram.com/convocourses TikTok: https://www.tiktok.com/@convocourses Facebook: https://www.facebook.com/ConvoCourses-108091850619388 LinkedIn: https://www.linkedin.com/in/convocourses/ LISTEN TO THE PODCAST 🎧 Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278 RSS Feed: https://feeds.captivate.fm/convocourses/ BOOKS ON AMAZON πŸ“– http://amazon.com/author/brucexwrites JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ https://booksprout.co/reviewer/team/35902/convocourses #convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

The journey ends with me getting a Cloud Security position. When I started, I really was not sure how this would end. But I got the job. Heres how.

SIGN UP FOR FREE COURSES πŸ“š
http://convocourses.com (Join the Group)
http://convocourses.net (Shop)

JOIN THE NEWSLETTER πŸ“¨
https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share

CHECK US OUT HERE 🌐
Website: http://convocourses.org
Instagram: https://instagram.com/convocourses
TikTok: https://www.tiktok.com/@convocourses
Facebook: https://www.facebook.com/ConvoCourses-108091850619388
LinkedIn: https://www.linkedin.com/in/convocourses/

LISTEN TO THE PODCAST 🎧
Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278
RSS Feed: https://feeds.captivate.fm/convocourses/

BOOKS ON AMAZON πŸ“–
http://amazon.com/author/brucexwrites

JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ
https://booksprout.co/reviewer/team/35902/convocourses

convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

I just read an article by Chris Hughes called: GRC is Ripe For a Revolution. The name alone pissed me off. but as i read it, I realized he has some great points.. - https://www.resilientcyber.io/p/grc-is-ripe-for-a-revolution He talks about GRC being outdated, antiquated, and ineffective. There are too many frameworks and its too slow. It needs to changes. πŸŽ™οΈ New to streaming or looking to level up? Check out StreamYard and get $10 discount! 😍 https://streamyard.com/pal/d/4632689196662784 SIGN UP FOR FREE COURSES πŸ“š http://convocourses.com (Join the Group) http://convocourses.net (Shop) JOIN THE NEWSLETTER πŸ“¨ https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share CHECK US OUT HERE 🌐 Website: http://convocourses.org Instagram: https://instagram.com/convocourses TikTok: https://www.tiktok.com/@convocourses Facebook: https://www.facebook.com/ConvoCourses-108091850619388 LinkedIn: https://www.linkedin.com/in/convocourses/ LISTEN TO THE PODCAST 🎧 Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278 RSS Feed: https://feeds.captivate.fm/convocourses/ BOOKS ON AMAZON πŸ“– http://amazon.com/author/brucexwrites JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ https://booksprout.co/reviewer/team/35902/convocourses #convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

​ @professorblackops-cybersec1168 and I talk about GRC, AI, and Cloud. We are both contractors working for the US govt. There are many changes happening in real time. Not gonna lie, 2025 is batshit crazy! And its not slowing down. Here are some of the topics: I just passed the AWS CCP & AZ900? What cloud skills and tech should sharpen? What is the most powerful skill / technology / tool / method or framework listed on your resume that employers past and present seem to really needs and want? What are the top 5 Cloud certifications? I am an IT pro or cybersecurity guy, I want to move toward AI. What do you suggest I start with? Is your organization starting to implement AI and automation? How is AI impacting GRC? Is it impacting GRC? Whats happening with the IT Job market 2025? As a long time IT professional, what is your opinion about the speed of AI development? Will it take our jobs? Would you be interested in doing a book or a course on AWS or Cloud in GovTech? πŸŽ™οΈ New to streaming or looking to level up? Check out StreamYard and get $10 discount! 😍 https://streamyard.com/pal/d/4632689196662784 SIGN UP FOR FREE COURSES πŸ“š http://convocourses.com (Join the Group) http://convocourses.net (Shop) JOIN THE NEWSLETTER πŸ“¨ https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share CHECK US OUT HERE 🌐 Website: http://convocourses.org Instagram: https://instagram.com/convocourses TikTok: https://www.tiktok.com/@convocourses Facebook: https://www.facebook.com/ConvoCourses-108091850619388 LinkedIn: https://www.linkedin.com/in/convocourses/ LISTEN TO THE PODCAST 🎧 Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278 RSS Feed: https://feeds.captivate.fm/convocourses/ BOOKS ON AMAZON πŸ“– http://amazon.com/author/brucexwrites JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ https://booksprout.co/reviewer/team/35902/convocourses #convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

works cited: https://deepmind.google/discover/blog/alphaevolve-a-gemini-powered-coding-agent-for-designing-advanced-algorithms/ (alphabet) https://ai-2027.com/ (Daniel Kokotajlo, Scott Alexander and others) https://www.amazon.com/Coming-Wave-Technology-Twenty-first-Centurys-ebook/dp/B0BSKW45KB (mustafa suleyman) Where I am currently learning: https://www.udemy.com/course/ai-900-azure-ai-fundamentals-complete-exam-prep/?couponCode=LEARNNOWPLANS https://learn.microsoft.com/en-us/azure/ai-foundry/ Slides: https://the-impact-of-superhuman-v64wfqp.gamma.site/ https://gamma.app/docs/AlphaEvolve-Gemini-Powered-Algorithm-Design-6f5pt16glmxmsvc?mode=doc πŸŽ™οΈ New to streaming or looking to level up? Check out StreamYard and get $10 discount! 😍 https://streamyard.com/pal/d/4632689196662784 SIGN UP FOR FREE COURSES πŸ“š http://convocourses.com (Join the Group) http://convocourses.net (Shop) JOIN THE NEWSLETTER πŸ“¨ https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share CHECK US OUT HERE 🌐 Website: http://convocourses.org Instagram: https://instagram.com/convocourses TikTok: https://www.tiktok.com/@convocourses Facebook: https://www.facebook.com/ConvoCourses-108091850619388 LinkedIn: https://www.linkedin.com/in/convocourses/ LISTEN TO THE PODCAST 🎧 Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278 RSS Feed: https://feeds.captivate.fm/convocourses/ BOOKS ON AMAZON πŸ“– http://amazon.com/author/brucexwrites JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ https://booksprout.co/reviewer/team/35902/convocourses #convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

SIGN UP FOR FREE COURSES πŸ“š
http://convocourses.com (Join the Group)
http://convocourses.net (Shop)

JOIN THE NEWSLETTER πŸ“¨
https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share

CHECK US OUT HERE 🌐
Website: http://convocourses.org
Instagram: https://instagram.com/convocourses
TikTok: https://www.tiktok.com/@convocourses
Facebook: https://www.facebook.com/ConvoCourses-108091850619388
LinkedIn: https://www.linkedin.com/in/convocourses/

LISTEN TO THE PODCAST 🎧
Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278
RSS Feed: https://feeds.captivate.fm/convocourses/

BOOKS ON AMAZON πŸ“–
http://amazon.com/author/brucexwrites

JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ
https://booksprout.co/reviewer/team/35902/convocourses

convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

SIGN UP FOR FREE COURSES πŸ“š
http://convocourses.com (Join the Group)
http://convocourses.net (Shop)

JOIN THE NEWSLETTER πŸ“¨
https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share

CHECK US OUT HERE 🌐
Website: http://convocourses.org
Instagram: https://instagram.com/convocourses
TikTok: https://www.tiktok.com/@convocourses
Facebook: https://www.facebook.com/ConvoCourses-108091850619388
LinkedIn: https://www.linkedin.com/in/convocourses/

LISTEN TO THE PODCAST 🎧
Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278
RSS Feed: https://feeds.captivate.fm/convocourses/

BOOKS ON AMAZON πŸ“–
http://amazon.com/author/brucexwrites

JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ
https://booksprout.co/reviewer/team/35902/convocourses

convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

SIGN UP FOR FREE COURSES πŸ“š
http://convocourses.com (Join the Group)
http://convocourses.net (Shop)

JOIN THE NEWSLETTER πŸ“¨
https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share

CHECK US OUT HERE 🌐
Website: http://convocourses.org
Instagram: https://instagram.com/convocourses
TikTok: https://www.tiktok.com/@convocourses
Facebook: https://www.facebook.com/ConvoCourses-108091850619388
LinkedIn: https://www.linkedin.com/in/convocourses/

LISTEN TO THE PODCAST 🎧
Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278
RSS Feed: https://feeds.captivate.fm/convocourses/

BOOKS ON AMAZON πŸ“–
http://amazon.com/author/brucexwrites

JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ
https://booksprout.co/reviewer/team/35902/convocourses

convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

SIGN UP FOR FREE COURSES πŸ“š
http://convocourses.com (Join the Group)
http://convocourses.net (Shop)

JOIN THE NEWSLETTER πŸ“¨
https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share

CHECK US OUT HERE 🌐
Website: http://convocourses.org
Instagram: https://instagram.com/convocourses
TikTok: https://www.tiktok.com/@convocourses
Facebook: https://www.facebook.com/ConvoCourses-108091850619388
LinkedIn: https://www.linkedin.com/in/convocourses/

LISTEN TO THE PODCAST 🎧
Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278
RSS Feed: https://feeds.captivate.fm/convocourses/

BOOKS ON AMAZON πŸ“–
http://amazon.com/author/brucexwrites

JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ
https://booksprout.co/reviewer/team/35902/convocourses

convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

SIGN UP FOR FREE COURSES πŸ“š
http://convocourses.com (Join the Group)
http://convocourses.net (Shop)

JOIN THE NEWSLETTER πŸ“¨
https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share

CHECK US OUT HERE 🌐
Website: http://convocourses.org
Instagram: https://instagram.com/convocourses
TikTok: https://www.tiktok.com/@convocourses
Facebook: https://www.facebook.com/ConvoCourses-108091850619388
LinkedIn: https://www.linkedin.com/in/convocourses/

LISTEN TO THE PODCAST 🎧
Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278
RSS Feed: https://feeds.captivate.fm/convocourses/

BOOKS ON AMAZON πŸ“–
http://amazon.com/author/brucexwrites

JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ
https://booksprout.co/reviewer/team/35902/convocourses

convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

Today we are talking to a Cloud Security Architect. This is a mentor and friend of mine, Rob Rodriguez, one of the most talented IT professionals I have ever worked with. Some of the questions: What do your daily and weekly responsibilities look like as a Cloud Security Architect? Which cloud platforms do you focus on the mostβ€”AWS, Azure, or GCPβ€”and why? For someone transitioning into cloud security, especially from a GRC or traditional IT background, where should we start? What areas or skills should we focus on first? Looking back, which certifications, degrees, or experiences had the biggest impact on your career advancement or opened the most doors? How do you view the current job market in cybersecurity and cloud security? It seems a bit tighter and more competitiveβ€”what’s your take? As a Marine veteran, what were the key lessons or values that shaped your career in tech and leadership? What advice would you give a veteran or someone considering military service? You’ve worked across both DoD and commercial enterpriseβ€”how different are the security priorities, and what lessons translate well between them? What’s your approach to staying current in such a rapidly evolving field like cloud and security? Are there resources you consistently rely on? At your level, how do you balance technical hands-on work with leadership and strategy? What advice would you give to someone who wants to grow into an architect role? With your experience at Skyhigh, ECS, and McAfeeβ€”what trends are you seeing in cloud security tooling (e.g., SSE, DLP, CASB)? What skills do you think will be critical in 2025 and beyond? πŸŽ™οΈ New to streaming or looking to level up? Check out StreamYard and get $10 discount! 😍 https://streamyard.com/pal/d/4632689196662784 SIGN UP FOR FREE COURSES πŸ“š http://convocourses.com (Join the Group) http://convocourses.net (Shop) JOIN THE NEWSLETTER πŸ“¨ https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share CHECK US OUT HERE 🌐 Website: http://convocourses.org Instagram: https://instagram.com/convocourses TikTok: https://www.tiktok.com/@convocourses Facebook: https://www.facebook.com/ConvoCourses-108091850619388 LinkedIn: https://www.linkedin.com/in/convocourses/ LISTEN TO THE PODCAST 🎧 Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278 RSS Feed: https://feeds.captivate.fm/convocourses/ BOOKS ON AMAZON πŸ“– http://amazon.com/author/brucexwrites JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ https://booksprout.co/reviewer/team/35902/convocourses #convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

Today we are talking to a Cloud Security Architect. This is a mentor and friend of mine, Rob Rodriguez, one of the most talented IT professionals I have ever worked with. Some of the questions: What do your daily and weekly responsibilities look like as a Cloud Security Architect? Which cloud platforms do you focus on the mostβ€”AWS, Azure, or GCPβ€”and why? For someone transitioning into cloud security, especially from a GRC or traditional IT background, where should we start? What areas or skills should we focus on first? Looking back, which certifications, degrees, or experiences had the biggest impact on your career advancement or opened the most doors? How do you view the current job market in cybersecurity and cloud security? It seems a bit tighter and more competitiveβ€”what’s your take? As a Marine veteran, what were the key lessons or values that shaped your career in tech and leadership? What advice would you give a veteran or someone considering military service? You’ve worked across both DoD and commercial enterpriseβ€”how different are the security priorities, and what lessons translate well between them? What’s your approach to staying current in such a rapidly evolving field like cloud and security? Are there resources you consistently rely on? At your level, how do you balance technical hands-on work with leadership and strategy? What advice would you give to someone who wants to grow into an architect role? With your experience at Skyhigh, ECS, and McAfeeβ€”what trends are you seeing in cloud security tooling (e.g., SSE, DLP, CASB)? What skills do you think will be critical in 2025 and beyond? πŸŽ™οΈ New to streaming or looking to level up? Check out StreamYard and get $10 discount! 😍 https://streamyard.com/pal/d/4632689196662784 SIGN UP FOR FREE COURSES πŸ“š http://convocourses.com (Join the Group) http://convocourses.net (Shop) JOIN THE NEWSLETTER πŸ“¨ https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share CHECK US OUT HERE 🌐 Website: http://convocourses.org Instagram: https://instagram.com/convocourses TikTok: https://www.tiktok.com/@convocourses Facebook: https://www.facebook.com/ConvoCourses-108091850619388 LinkedIn: https://www.linkedin.com/in/convocourses/ LISTEN TO THE PODCAST 🎧 Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278 RSS Feed: https://feeds.captivate.fm/convocourses/ BOOKS ON AMAZON πŸ“– http://amazon.com/author/brucexwrites JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ https://booksprout.co/reviewer/team/35902/convocourses #convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

SIGN UP FOR FREE COURSES πŸ“š http://convocourses.com (Join the Group) http://convocourses.net (Shop) JOIN THE NEWSLETTER πŸ“¨ https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share CHECK US OUT HERE 🌐 Website: http://convocourses.org Instagram: https://instagram.com/convocourses TikTok: https://www.tiktok.com/@convocourses Facebook: https://www.facebook.com/ConvoCourses-108091850619388 LinkedIn: https://www.linkedin.com/in/convocourses/ LISTEN TO THE PODCAST 🎧 Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278 RSS Feed: https://feeds.captivate.fm/convocourses/ BOOKS ON AMAZON πŸ“– http://amazon.com/author/brucexwrites JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ https://booksprout.co/reviewer/team/35902/convocourses #convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

SIGN UP FOR FREE COURSES πŸ“š http://convocourses.com (Join the Group) http://convocourses.net (Shop) JOIN THE NEWSLETTER πŸ“¨ https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share CHECK US OUT HERE 🌐 Website: http://convocourses.org Instagram: https://instagram.com/convocourses TikTok: https://www.tiktok.com/@convocourses Facebook: https://www.facebook.com/ConvoCourses-108091850619388 LinkedIn: https://www.linkedin.com/in/convocourses/ LISTEN TO THE PODCAST 🎧 Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278 RSS Feed: https://feeds.captivate.fm/convocourses/ BOOKS ON AMAZON πŸ“– http://amazon.com/author/brucexwrites JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ https://booksprout.co/reviewer/team/35902/convocourses #convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

SIGN UP FOR FREE COURSES πŸ“š http://convocourses.com (Join the Group) http://convocourses.net (Shop) JOIN THE NEWSLETTER πŸ“¨ https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share CHECK US OUT HERE 🌐 Website: http://convocourses.org Instagram: https://instagram.com/convocourses TikTok: https://www.tiktok.com/@convocourses Facebook: https://www.facebook.com/ConvoCourses-108091850619388 LinkedIn: https://www.linkedin.com/in/convocourses/ LISTEN TO THE PODCAST 🎧 Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278 RSS Feed: https://feeds.captivate.fm/convocourses/ BOOKS ON AMAZON πŸ“– http://amazon.com/author/brucexwrites JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ https://booksprout.co/reviewer/team/35902/convocourses #convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

SIGN UP FOR FREE COURSES πŸ“š http://convocourses.com (Join the Group) http://convocourses.net (Shop) JOIN THE NEWSLETTER πŸ“¨ https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share CHECK US OUT HERE 🌐 Website: http://convocourses.org Instagram: https://instagram.com/convocourses TikTok: https://www.tiktok.com/@convocourses Facebook: https://www.facebook.com/ConvoCourses-108091850619388 LinkedIn: https://www.linkedin.com/in/convocourses/ LISTEN TO THE PODCAST 🎧 Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278 RSS Feed: https://feeds.captivate.fm/convocourses/ BOOKS ON AMAZON πŸ“– http://amazon.com/author/brucexwrites JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ https://booksprout.co/reviewer/team/35902/convocourses #convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

SIGN UP FOR FREE COURSES πŸ“š http://convocourses.com (Join the Group) http://convocourses.net (Shop) JOIN THE NEWSLETTER πŸ“¨ https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share CHECK US OUT HERE 🌐 Website: http://convocourses.org Instagram: https://instagram.com/convocourses TikTok: https://www.tiktok.com/@convocourses Facebook: https://www.facebook.com/ConvoCourses-108091850619388 LinkedIn: https://www.linkedin.com/in/convocourses/ LISTEN TO THE PODCAST 🎧 Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278 RSS Feed: https://feeds.captivate.fm/convocourses/ BOOKS ON AMAZON πŸ“– http://amazon.com/author/brucexwrites JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ https://booksprout.co/reviewer/team/35902/convocourses #convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

SIGN UP FOR FREE COURSES πŸ“š http://convocourses.com (Join the Group) http://convocourses.net (Shop) JOIN THE NEWSLETTER πŸ“¨ https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share CHECK US OUT HERE 🌐 Website: http://convocourses.org Instagram: https://instagram.com/convocourses TikTok: https://www.tiktok.com/@convocourses Facebook: https://www.facebook.com/ConvoCourses-108091850619388 LinkedIn: https://www.linkedin.com/in/convocourses/ LISTEN TO THE PODCAST 🎧 Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278 RSS Feed: https://feeds.captivate.fm/convocourses/ BOOKS ON AMAZON πŸ“– http://amazon.com/author/brucexwrites JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ https://booksprout.co/reviewer/team/35902/convocourses #convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

SIGN UP FOR FREE COURSES πŸ“š http://convocourses.com (Join the Group) http://convocourses.net (Shop) JOIN THE NEWSLETTER πŸ“¨ https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share CHECK US OUT HERE 🌐 Website: http://convocourses.org Instagram: https://instagram.com/convocourses TikTok: https://www.tiktok.com/@convocourses Facebook: https://www.facebook.com/ConvoCourses-108091850619388 LinkedIn: https://www.linkedin.com/in/convocourses/ LISTEN TO THE PODCAST 🎧 Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278 RSS Feed: https://feeds.captivate.fm/convocourses/ BOOKS ON AMAZON πŸ“– http://amazon.com/author/brucexwrites JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ https://booksprout.co/reviewer/team/35902/convocourses #convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

SIGN UP FOR FREE COURSES πŸ“š http://convocourses.com (Join the Group) http://convocourses.net (Shop) JOIN THE NEWSLETTER πŸ“¨ https://dashboard.mailerlite.com/forms/1328320/146086011895547193/share CHECK US OUT HERE 🌐 Website: http://convocourses.org Instagram: https://instagram.com/convocourses TikTok: https://www.tiktok.com/@convocourses Facebook: https://www.facebook.com/ConvoCourses-108091850619388 LinkedIn: https://www.linkedin.com/in/convocourses/ LISTEN TO THE PODCAST 🎧 Apple Podcasts: https://podcasts.apple.com/us/podcast/convocourses/id1500188278 RSS Feed: https://feeds.captivate.fm/convocourses/ BOOKS ON AMAZON πŸ“– http://amazon.com/author/brucexwrites JOIN THE ADVANCED READERS GROUP πŸ•΅οΈβ€β™‚οΈ https://booksprout.co/reviewer/team/35902/convocourses #convocourses #CyberSecurity #TechCareers #ITJobs #EntryLevelTech #NISTRMF

View Details

In this one, we talk about how the NIST Cybersecurity Framework 2.0 can be used as a way to learn governance, risk management, and compliance.

View Details

http://convocourses.com

View Details

convocourses.com

View Details

convocourses.com

View Details

http://convocourses.com

View Details

convocourses.com

View Details

https://convocourses.net articles: https://www.reuters.com/technology/cybersecurity/t-mobile-hacked-massive-chinese-breach-telecom-networks-wsj-reports-2024-11-16/

https://www.politico.com/news/2024/11/14/rand-paul-kneecap-cisa-00189698

https://www.darkreading.com/threat-intelligence/mastercard-bet-recorded-future-win-cti

Sign up for free courses! http://convocourses.com http://convocourses.net

  • (Discounts and free stuff) Join advanced readers group: https://booksprout.co/reviewer/team/35902/convocourses Join the Newsletter: https://convocourses.aweb.page/p/9ec4fef1-07b2-4a1a-9834-6817785d9e7d

View Details

https://convocourses.net

View Details

https://convocourses.net

View Details

https://convocourses.net

View Details

http://convocourses.net

View Details

http://convocourses.net

View Details

Check out Will Reed at Better Every Day Cyber:

https://bettereverydaycyber.com/

View Details

http://convocourses.net

My focus on this one was purely answering tiktok, youtube questions live.

Join us next time at 1pm MST SAT

View Details

http://convocourses.net

View Details

http://convocourses.net

View Details

http://convocourses.net

View Details

http://convocourses.net

View Details

video:

https://youtube.com/live/_Qz7VAIaQDI

http://convocourses.net

View Details

https://youtube.com/live/l_jx9KjeJkI

http://convocourses.net

The Zero Trust security model is a cybersecurity framework that operates on the principle of "never trust, always verify." Unlike traditional security models that rely on a strong perimeter defense, Zero Trust assumes that threats can come from both outside and inside the network. Therefore, no user or system should be trusted by default, regardless of whether they are inside or outside the network perimeter.

Here are the key principles and components of the Zero Trust security model:

Verify Explicitly: Authenticate and authorize based on all available data points, including user identity, location, device health, service or workload, data classification, and anomalies.

Least Privilege Access: Limit user access with just-in-time and just-enough-access (JIT/JEA), risk-based adaptive policies, and data protection to reduce the risk of lateral movement.

Assume Breach: Assume that a breach has already occurred or will occur. Minimize the blast radius and segment access by using micro-segmentation and real-time threat detection and response.

Micro-Segmentation: Divide the network into smaller, more manageable segments to prevent lateral movement of threats within the network.

Continuous Monitoring and Validation: Implement continuous monitoring and validation of user and device activity to detect and respond to anomalies in real-time.

Strong Authentication: Use multi-factor authentication (MFA) and other advanced authentication mechanisms to ensure that only legitimate users can access resources.

Device Security: Ensure that devices accessing the network are secure, trusted, and compliant with security policies.

Data Protection: Encrypt data at rest and in transit, and implement data loss prevention (DLP) measures to protect sensitive information.

Implementing a Zero Trust security model requires a shift in thinking and architecture, involving the integration of various security technologies and practices to create a robust and adaptive security posture.

View Details

http://convocoures.net

View Details

http://convocourses.net

View Details

http://convocourses.net

View Details

https://www.amazon.com/Cyber-FISMA-Compliance-Cybersecurity-Privacy-ebook/dp/B0D4KR6F2C

convocourses.net

View Details

http://convocourses.net

View Details

http://convocourses.net

View Details

https://twitter.com/TheSecMaster1/status/1780213575921111347 Sign up for free courses! http://convocourses.com http://convocourses.net - (Discounts and free stuff) Join advanced readers group: https://booksprout.co/reviewer/team/35902/convocourses Join the Newsletter: https://convocourses.aweb.page/p/9ec4fef1-07b2-4a1a-9834-6817785d9e7d Check us out here: http://convocourses.org http://instagram.com/convocourses https://www.facebook.com/ConvoCourses-108091850619388 https://www.linkedin.com/in/convocourses/ Podcasts: https://convocourses.podbean.com/ https://podcasts.apple.com/us/podcast/convocourses/id1500188278 Books on Amazon: http://amazon.com/author/brucexwrites #convocourses #cybersecurity #isso #nistrmf #rmf #usajobs#itjobs

View Details

http://convocourses.net

View Details

Check out Chris at https://www.youtube.com/@TechWokePodcast

You can reach out to Chris as a consultant here:

https://topmate.io/techwoke

View Details

http://convcourses.net

View Details

http://convocourses.net

View Details

http://convocourses.net

View Details

http://convocourses.net

View Details

for a limited time only, the FISMA Compliance book is being offered at a discount:

https://a.co/d/06493yI

http://convocourses.net

View Details

http://convocourses.net

View Details

http://convocourses.net

View Details

convocourses.net

https://youtube.com/live/VxIcFjm9uBg

View Details

http://convocourses.net

https://youtube.com/live/w2BxnBkSOJU

View Details

http://convocourses.net

https://www.youtube.com/live/Wu1DHW3VueA?si=DJqI_DDxphFRDOGK

Introduction

  • Brief introduction of Bruce, his background in cybersecurity, and the purpose of Convo Courses.

Personal Journey in Cybersecurity

  • Bruce's initial fascination with cybersecurity and IT.
  • Transition from passion to profession.
  • Reflections on career longevity and personal growth.

Career Development and Financial Planning

  • The importance of planning beyond the day-to-day job.
  • Strategies for using income to build passive income streams.
  • Real estate and publishing as examples of passive income sources.

Advice for Aspiring IT and Cybersecurity Professionals

  • Encouragement for newcomers to consider their long-term career goals.
  • Importance of financial planning and investment in passive income.

Networking and Mentorship

  • The value of meeting people who have successfully exited the "rat race."
  • Insights from mentors on building financial independence through passive income.

The Evolving Landscape of IT and Cybersecurity

  • Discussion on the impact of AI and technological advancements.
  • Personal experiences and perspectives on the changing nature of IT work.

Corporate Experiences and Personal Growth

  • Anecdotes from Bruce's time in the corporate world.
  • Learning from challenges and using them to pivot towards entrepreneurship.

Entrepreneurial Ventures and Lessons Learned

  • Experiences with blogging and creating online content.
  • The significance of perseverance, experimentation, and learning from failure.

Engaging with the Audience

  • Q&A session with viewers.
  • Advice on career choices, technical skills, and job market insights.

Cybersecurity Certifications and Career Tips

  • Discussion on CISSP certification and its value.
  • Tips for gaining experience and standing out in the cybersecurity field.

Closing Thoughts

  • Summarization of key points discussed.
  • Encouragement for viewers to think big and plan for the future.
  • Invitation for topic suggestions for future discussions.

This format aims to capture the essence of Bruce's dialogue, providing clear sections that can be easily expanded upon with more detailed bullet points or narrative descriptions as needed. Each section would be designed to offer actionable insights, drawing from Bruce's extensive experience and personal journey within the field of cybersecurity and beyond.

Hey guys, this is Bruce and welcome to Convo Courses. Every week I do this and I'm talking about cyber security from a GRC perspective. I'm an insider. I've been doing cyber security for a very long time and normally I do this at one Mountain Standard time, but I had some business to do and as promised, I'm back. I'm a bit late because I had some stuff I had to take care of. What I wanted to talk about is what I do. When I first got into cybersecurity IT, I just did it because it was cool. It was fun. It was amazing. It's like magic to me. It's so amazing how it all works together and stuff. And as I've gotten older, it's just become a job. I'm not saying that that's bad or anything. It just is what it is. I've been doing it a very long time and now it's to the point where I got to think about, okay, where am I going with this? What's the end goal? What do I want to accomplish at the end of the road when this is all said and done? What do I want to leave to my family? When am I going to stop? So I've been thinking about that for quite some time, not just thinking about it, but doing something about it. And what I've been doing is using the income, my salary, my high salary to build passive income streams. And there's many, many things you can do for passive income. I just started doing something that worked for me and something that was more in my lane, which is like publishing and in real estate. So those are the things that I mainly focus on with my income. And it's just I guess I wanted to talk about it because it's important to think about where you want to go with this. Like if you're trying to get into cybersecurity, if you're trying to get if you just started IT or you want to get into it, you're a college student, you're in high school, whatever the case may be. And you're thinking, man, you know, IT is cool or I want to do it. It's a lot of jobs. They get paid a lot of money. It's job security, blah, blah, blah. At some point, maybe not today, maybe not tomorrow, but at some point in your career, you're going to have to think about where do I want this to go? What's the end goal? Am I just going to work a nine to five until I retire? What am I trying to do with this? And so that's what I've had to think about for the last 10 years. not just thinking about it but doing something about it so I just started trying different businesses I would use some of the income that I have to try different things and some of them worked and some of them didn't work sometimes it worked but it wasn't for me you know but the thing is you got to keep trying and failing just fail forward keep on trying different things um What's amazing is the people I've met. I've met some really amazing people who've done it all kinds of ways, all kinds of creative ways to get out of the rat race, meaning get out of the struggle. They don't struggle anymore with finances. They don't struggle with the treadmill of capitalism. They have mastered it. They have mastered it. And all the people who have mastered it all have passive income streams, I've noticed. They don't have to have a job. And I've met people who did it with real estate in different ways by either flipping houses or doing Airbnbs or doing tax liens, just doing rentals, regular rentals. I've met people doing property management. So there's many, many ways to do just real estate. And then I've met people who did, what do you call them? Homes for the elderly. I met people who just saved and put away a bunch of money in stocks and are going to be wealthy that way or are wealthy that way. I've met some people who did a combination of those things. I've met Just all kinds of people who did it their way. They were creative. One thing they all have in common is they have enough income to where they don't have to work a nine to five anymore if they don't want to. Some of them, they still work a nine to five because they're still like building a nest egg. And some of them, they have like a business and they like working that business. They like actually being there and working the business and all that kind of stuff. So seeing that these people kind of became like mentors to me. I would follow what they did. I would, I would ask them questions about what, how did they do it? What, what, what did they do? And all of them had to invest their own money or time to get to a point where to get to a point where they, their, their time was so valuable that they, that they didn't, It was more valuable for them to spend time on their business than their time at their job. So that's one thing I've noticed about a lot of them. And it's just something you should think about. And another thing is one of the reasons why you should consider doing IT and cybersecurity and progressing is that once you get to a certain income level, Obviously, your life changes. But one thing that happens is you have this surplus of income and you you've got to think about what you want to do with it. You have this little bit. It could be like an extra thousand. You like all your bills are paid. You know, you groceries are done like you. You're good. Right. You could probably even loan people money or whatever. Give people money, whatever. But you still have this extra cash. And so you got to think about, okay, what do I want to do with this money? And I would suggest that you invested in some kind of passive method of passive income. It doesn't have to be what I'm doing. It should be something that you find that works for you. And so that is a great reason to get into IT and cybersecurity because it's a high paying job. It's They're always going to need somebody doing IT. I know there's all these fears about LLMs and artificial intelligence and all that kind of stuff, but I would say that it's going to be more of a threat to not know it than to think it's going to just take all jobs. There's still... I don't think it's going to take all jobs. I think that's... hyperbole. I think it's just, we don't really know what's going to happen with it, right? One thing for sure that we know is it's going to change humanity. That's for sure. That's probably more scary. I'm surprised more people don't talk about that. What's more scary about AI is it's going to change us, just like this phone did, just like the internet did. It's changed us. We're no longer the same. We're not the same species that we were hundreds Before the internet, we're not the same. We're rapidly changing into something else. And I don't know what the hell that is, but we are not the same species that we were before. And AI is gonna speed up that process. We are gonna be different. And people keep talking about jobs. We have way more stuff to worry about than jobs. Way more stuff to worry about than jobs. It's gonna change us fundamentally as a species. And I don't know where that leads us to, but jobs is the least of our worries. That said, while we still have this thing going on, get into I.T., get into cybersecurity. You'll have all this extra income and it allows you to have a more freedom to build something that you for yourself and for your family. I'm somebody who comes from very humble beginnings, like I came from nothing and. I can tell you there's different stages and levels to this. When I first started out, like as a kid, we're struggling to survive. And so you're not thinking about necessarily, it's not real to you. $100,000 a year is not real. When you're struggling poor, it's just, it's delusional. I didn't know anybody who made 100,000 or maybe I did, but I didn't know that they made 100,000. I didn't have any friends that I knew made 100,000. It wasn't real. So it just didn't seem real at that level. It didn't seem real. And then once I started making my own income, I started meeting, my network changed. I started meeting other people who are also doing their own thing, other young people who are also doing their own thing, living their own life, doing their own thing. And I started running with that crowd. And then I started meeting older heads who are already doing, real estate and business and stuff they were talking a lot about it and I'd be like what is what what's this you're talking about this is while still in the military I got out of the military and I thought when I got out that I was going to get a corporate job make like 80 and and be cool and then just retire with that one corporation little that I know that corporations don't give don't care so much about humans. They care about the bottom line. They care about their money. So they're not really trying to take care of people. Maybe 50 years ago, they used to do that. But that's no longer the case. And I'm not trying to discourage you from going to a company. Yeah, by all means, do it. But just realize it's a stepping stone. And that's what I realize is that you're not going to stick with one company. Not anymore. Like I said, maybe 50 years ago. It's just very different now. And I got into the corporate world. I think the thing that turned me around with corporations, the thing that made me not lose hope, but think of them differently and see the reality of what was really going on is that one time my my wife at the time got really sick um she had like a pulmonary embolism or something like in her leg I mean she had like something in her leg like she had to go to uh the doctor she was out in the hospital for like three days and I asked I had just gotten hired and I asked the company I said You know, is it okay if I, I just bought a house, you know, we just moved in and we had a little baby and I said, hey, I know you guys just hired me, but can I get three days off because I need to take care of my kid. I don't have anybody here. I just moved to the state. And they were just like, well, we can't do it. It's against company policy. And it was some kind of politics that they were playing. My immediate supervisor basically wouldn't allow me to do it. It's just weird. And I'm just like, what? And it just dawned on me, these people do not give a damn about me. They really don't care. And I was like, well, why should I care about them? If they don't care about me or my family, then why am I sacrificing myself I'll do anything for these guys. I'm like, so I'm a fool. And after that, you know, it just, I just realized, man, I got to do something else. I'm not going to quit my job, but I got to figure something else out. Because if this is how it's going to be, I got to do something else, right? Because while I'm in the military, military take care of you. Military, like you have a brotherhood. If you stay with the military, you stay 20 years, they're going to give you retirement. It's not like that on the outside. And I, it just, it was a hard lesson to learn. And I said, okay, you know what, what I'm going to do is I'm going to start a business. That was the first time I was like, I'm going to start a business. And, um, the first business I did this now, this is crazy. First thing I did was blog. I made a blog and, um, it was back when blog could make a blog can make money. I mean, it could still could, but this was like, right. The early stages of blogs where blogs were brand new and people were making all this money off of blogs. And I started this blog and it got pretty popular, but now before it got popular, I remember I made 10 cents and I was super excited. I was like, I made 10 cents, you know, after writing a few articles or whatever. And the only reason I was happy is because I realized if I can make 10 cents, I can make a dollar. If I can make a dollar, I can make $10. If I can make $10, I can make a hundred dollars a day. If I can make a hundred dollars a day, you know what I mean? And that was true. what happened was the blog got really popular and it ended up landing me my first hundred thousand dollar job and allowed me to publish my first, uh, the first thing I published was like for a, it was like a pamphlet, uh, for this company. And, uh, they had me go around the world and teach, teach from this pamphlet that I wrote. And I made a little over a hundred thousand for the first time. So that blog, And one time I wrote an article, it went viral. It was making like $100 a day for a while, which at the time was crazy. And I don't know. It just opened my eyes. You never know what's going to work. So you should just try different things. And I've tried a lot of stuff, man. I've tried stuff that absolutely did not work. But I've tried things that really did work. And that's what you got to do. Just try different things. All right, I got some questions here. Thank you guys for watching. I appreciate it. Kind of a different flow right now. I just want to have you guys think a little bit bigger, especially if this is your goals. If you're trying to do IT, if this is what you're trying to do, start thinking about your future, what you want for your family far in the future, and what you can do. Somebody asked me or said, would you recommend starting at a big tech company or a small non-tech with higher pay long term. Think of it differently. What you want, the ideal job is one where you have a little bit of extra time. Like they're not, what do I mean by that? So what I'm trying to say is, I would take a little less pay to have a little bit more uh, a less stress personally. Um, but you could also go for high pay that will allow you to take some of that pay and re either reinvest it into a 401k, buy stocks, uh, buy bonds. If that's what you're into, um, play around with, with, uh, swing trading. If that's what you're into, try, try different things. You could use, if you make a, if you go to a big company and they pay you a whole bunch of money, um, or a small company and they pay you a whole bunch of money, use some of that money to invest it in. Try things, real estate, try stocks, try business, try different things. Use it as a stepping stone. As far as which one would I try, you said non-technical with higher pay or big tech. I'm just going to tell you from my experience. Smaller companies are more... There's more like a person to person feeling with smaller companies. I've worked from for literally like a two man company all the way up to multibillion dollar companies and international multibillion dollar companies and for the government. And I can tell you some of the best experiences I had was with smaller companies. And maybe this is just anecdotal, like maybe it's just my experience and maybe it's different for everybody. But in all the small companies I worked for, it was more one-on-one. I was a person. I wasn't just a number. At the large companies, I was just a number. I might have had a real good team and everything, but at the end of the day, they can replace you in a heartbeat. And because of that, they don't really value the person as much as they used to. But smaller companies, they really took their time to develop each person. And I really miss that feeling of being on this team. And with that said, when you're in a small company, it's kind of like you're in a big ocean being kind of rocked by all the market By the market that's happening, you know, whereas when you're in a big ass company, it's like you're on an ocean liner and the economy is rocking. But the boat is just going like this, you know, it's kind of wavering a bit. You're not being tossed on the sea by the economy or whatever's happening, market forces or whatever. So there's tradeoffs for different things. At the end of the day, it depends on what you want to do. Just think long term, like think big, think your entire lifespan and what you want. for yourself and for your kids and for your kids' kids. When it's all said and done, when you are nothing more than a memory, you want to have a look back and create some sort of legacy. This is one stepping stone in a long line of steps you're going to take. So just think of it. Think big is what I would say to make your decision. And that way, when you do make a decision, it'll mean something. It'll be one step in the right direction that you're going. So I hope that helps. I'm just telling you my experience with small companies and big companies and all that kind of stuff. If you went for the big money, non-tech big money, you can use that money to invest it and do what you want. And the big companies got a little bit more of... What feels like security and maybe have a little bit more time on your hands to mess around and you can use that time to tinker and mess with something else. Probably the money is what I would take, to be honest with you. Let me see. Forty Rock says a four rock says. Is IT cybersecurity still hiring? I have three years of technical support and two years of SQL development. I've been unemployed since November and I cannot get a help desk position. Open up what you're willing to take for Rock. What I would recommend is possibly going back into SQL development, be open to that, be open to technical support. um lean on your skills um a lot of times I'll give you an example of one time there was a time when I i was really wanting to get um into more technical stuff and I did I actually landed a job in a technical position as a field technician And I did know it at the time, but I took a huge pay cut because my specialty was in cybersecurity. I just didn't want to do it anymore. I just didn't want to do policies and all that kind of stuff anymore. I just didn't want to do it. So I was like, man, I want to do more hardcore stuff. And I found a job, but I took like a, I don't know, 45% pay cut. I mean, it was a lot, man. I had no idea. If I could go back, I realized my mistake was that I didn't lean on my strengths. Lean on your strengths. Your strengths are, you said, two years of SQL development. Not a lot of people know SQL, bro. That's a special skill and all the things that come with it. I guarantee you, you're not tapping into all of the skill sets that you have with SQL. SQL is very special. Very special, because that means you could work in, and correct me if I'm wrong, but with SQL, you can work in several different database environments, because many of the largest databases, relational databases and object-oriented databases, they use some sort of SQL. MySQL, Oracle, right? They use some sort of SQL. So lean heavily on your SQL experience. What you could do to see what types of keywords to put in your resume so you can quote unquote lean into your strengths is look at other people's resume. Go to LinkedIn. Go to LinkedIn right now. If you happen to be watching me, go to LinkedIn and type in SQL development. And then don't look at jobs just yet, right? That'll come next. What you want to do first is look at other people's resumes. Look who comes up on there and look at their resumes. Not all people put their entire resume out there or profile rather, but some people do. Look at their profile. Check out their profile and see what they're putting, what keywords. I guarantee you a lot of the stuff that they're doing, that they're the keywords, that the key phrases that they use are referring to skills and things that you have done in your two years with SQL development. Put that shit on your resume. Put it on your resume. Because don't just aim for a help desk job. Broaden your horizon. That's what I'm trying to tell you to do. And these guys on here who have IT experience, they'll tell you, man, listen, a lot of these guys are looking for your skill set. Mike chimed in. He says, some of these firms, non-tech, you are You're just a number, yeah, absolutely. Okay, so my man Mike is talking to you. Let me see who else is out here talking. Oh man, TikTok is crazy. Is it necessary to do help desk before jumping into cybersecurity analyst? Not necessarily help desk, but like a tier one type position. I mean, let me see if I can explain it better. The first point of contact for fixing technical problems, it's not always called help desk. Sometimes it's called customer support, technical support. field technician. There's different names for it, but they're normally the first person that you talk to. They're normally the first person you talk to when you have some kind of a problem with your internet, with the computer. It's not always just help desk. We kind of use that as a blanket term because that's probably the most known term for That first tier person that you talk to. But you get the idea. So I would say it's best. You don't absolutely have to. Like I've seen people who were cybersecurity analysts who did not have a solid help desk background. But the best people started from the bottom. worked their way up. They were field technicians and then they were help desk or field technician or customer support or something like that. And then they kind of graduated to this other level. I've seen people who skip rungs, like people who are just thrown right into systems system and administrators creating accounts and things like that. And then they were working with server problems or updating servers and stuff, and they never really touched help desk per se. I've seen people who went directly in the networking straight out of basic training, went to some technical school and then went straight to that or went straight from college to do that or They had some sort of background networking, did network, junior network administrator, and then went to something else, cybersecurity analyst or forensics or whatever. They did something else. So it's not absolutely necessary, but let me explain a little bit about cybersecurity analyst. That's one of the skill sets that I've had, something I've done in the past. A cybersecurity analyst... Um, when, when I was doing it was somebody who was, they were monitoring, they were doing a lot of, of monitoring of the network. We were monitoring the network using tools like scene, which is a security information event manager, uh, that looked at all the logs going on the network. We would look at, uh, we had. IPS, IDS, which is intrusion detection or intrusion prevention systems that we would have to know how to block certain ports or whatever, certain source IPs. We have to know different types of attacks. We were looking at the network, right? And determining if we were being attacked or if there was some kind of a threat that was on the network. That was our job as a cybersecurity and we were analyzing the network. And then sometimes we'd have to escalate it to the incident response team, or we'd have to do something like that. So that said, think about it. A cybersecurity analyst has to know quite a bit about how the network works, like how networking itself works. Because they're looking at logs over the network. And you have to know How TCP IP works and all that kind of stuff, because you're looking sometimes you're looking at packets going across the network. And sometimes we even break open packets to look at what was going on. Right. So you have to know a bit about network engineer, how networks work. You have to know the difference between a server and a workstation and how they work together. You have to know that you have to have the basics nailed down. You know, you have to know what ports are, like at least like common ports and how they work, how they can be exploited. So you kind of have to know like two or three different things and start linking them together for cybersecurity analyst work. It takes very talented people to be good at it. And I'm not saying I was good at it. I wasn't. I was just a newcomer. I was a new guy who was fascinated by it. You know, I could... I could get around, but I wasn't like one of the more skilled guys on the team. I was learning stuff. But what I'm getting at is you have to have the basics nailed down in order to do a job like cybersecurity analyst work, right? I'm not saying you have to be a master at it or some kind of brilliant person at it, but you – Even to do the basics, you have to have some basic skills, basic like help desk type skills down, first tier skills down. Somebody said, bro, where do I start? Start where you are. Consider your industry. If you happen to be from student, zero to hero. If you're a student, you can start right now. If you're in some sort of industry already, like you're in the healthcare industry, you're in the pharmaceutical industry, you're in the retail industry, you're in, you name it, restaurant, and all of them use IT, you can start where you are. if you're a student uh you're in a special position because um now if you're a high schooler shoot they they have clubs that you can start right now start doing computer start learning computer stuff right now um start fixing people's computers right now start coding right now um there's things you can do right now as a high schooler to to do the hell I know people who Um, who got a CompTIA started getting cybersecurity certifications in high school, um, just to get, get the knowledge now, um, and to build themselves up, to go to a vocational school or to go to a community college or college university or whatever, to build up their skills. Or hell, start your own business doing fixing people's computers. You know, you can get that good at it. And then that stuff you can put on a resume or just keep building, scaling your own business from high school. College is I mean, college is a huge pivot point because in college, like you don't have to wait to get your degree. You don't have to wait like you shouldn't wait. Start being a working student right away. If you're on campus, see if you can help them out, help. Help out the campus to figure out what vulnerabilities they have. See if there's a working student program. Hell, even if it's remote, like if you're doing college remotely, they might still have a working student program. look into it they have apprenticeships they have internships they have all kinds of uh sometimes I have like a b2b uh university to business pipeline um ask you got to get yourself in there and ask uh where you can start as a college student college students probably have the best they're probably in the best position to get themselves uh get the ball rolling for their career But they got to start now. Like a lot of times they just wait until they get their degree and they're like, oh, I can't get a job, you know, like get start now, right now. Now, if you happen to be, let's say you forget the student, you're not a student no more, you're in the world, you're a healthcare professional. You know more about HIPAA than I do. And HIPAA is one of the primary laws that is used to protect patient data. That can get your foot in the door right there. I mean, that right there is huge. That's a huge step in the right direction. Now, you still have to learn all the basics of information technology, but you have a good foothold in that industry. If you happen to be in retail, did you know that all the times that you're taking people's credit cards, the whole system in the background is taking all that information has to have to have to have something called PCI compliance. You can start learning a little bit about that. See if you see if you can get involved with their IT department. If everyone has one, Taco Bell has one. Walmart has one. Everybody has an IT department. Everyone start get see if they'll let you do a lateral move over there or start learning shadow marketing. shadowing somebody who already does it. And in whatever retail space you're in, you'd be surprised. Look at their career page. They might have something where they're looking for IT professionals at TJ Maxx or whatever. And I'm being serious. It's not a joke. Like whatever, start where you are. That's what I'm telling you to do. And then once you get that money, right, you get that pay bump. Don't look, listen, I know you want a better lifestyle and I'm not telling you to not have a better lifestyle, but use some of that income to start building some passive income streams. And if you don't know what that is, you might want to Google it. You might want to Google it because it's important and they don't teach it in school. But I'm telling you right now, it's important to do it. This is not me trying to get. I don't have a course on passive income streams. Right. I thought about it, but I don't have one. OK, I'm not trying to sell you anything. Right. I'm just trying to tell you, like, if you don't know what passive income is, look it up. That's what I'm trying to tell you. It's a life changer. It can change your life. So look into it. Let me see here. Getting some more comments and stuff. And I'm only going to do about an hour, guys. So I got about 30 minutes. I was on here earlier. I was doing one of my AirBVs. And now I'm here to do the real work here. Okay. Susie says, I hope I'm pronouncing that correctly. I'm sure I'm not. After getting your CISSP, did you find some of the content helpful on the job? or was it mainly a confidence booster currently studying for the exam? I'm curious. I'm going to say something that you're probably not going to like. I'm going to say something that's probably controversial, but I'm going to tell you the truth. The CISSP is so general that it really didn't, I can't say that it helped in any capacity. And I know that's not what you want to hear. You want to hear that there's a magic wand, that you take some certification and magical things happen. The magic was that everybody wanted to hire me after I got the goddamn thing. That was the magic. There are certifications that I could say that were extremely technically useful that I saw the things I was using on that certification in real life, like things like the CCNA. Cisco certification, like those Cisco certifications are the real, they're the real deal, right? What other certifications would I say were extremely useful? The Microsoft certification, the technical vendor level certifications doing their vendor level stuff is very, very useful. Qualys, like that was, that's not a big certification. It's not marketing. talked about but it's qualis is a scanner it's a network scanner and that stuff the stuff that I learned um that I had that that were on that was on the test that's the stuff that we're actually using uh at the organization I worked at so the vendor level certifications are very very much useful um I would say the security plus was very useful even though it's not vendor specific Security Plus was useful because it's talking about stuff that you're going to... Let me put it to you this way. Security Plus is usually introduced to people who are fairly new into cybersecurity. So it opens up... It's kind of touching on many different things that you might not have ever been introduced to for the first time. By the time you get to the CISSP, you kind of have some level of, you've touched a lot of different security by the time you actually take the cert. You take the cert, and the way they word it, how can I explain it without losing the CISSP? The way that they word it is like, it's a, what do they call it? Let me put it to you like this. They'll ask you a question, and the hardest part is the answers. Because you'll have two answers you can kind of throw away, and then they'll have two answers that are both right, but one's more right than the other. That's hard. That's the hard part about the CISSP. Would I say it helped me? I can't know. There's nothing on there that I could say, yeah, that right there, that's... That was on the, you know, I'm not quoting the CISSP. Like, it's not, I will say this, it's highly marketable. It's a great, it changed my life. As soon as I got it, people were like, oh, it was like I was a lawyer or some shit. It was like I had to pass the bar or something. It single-handedly changed my life. You could probably get the CISSP and not have a degree. With some years you got, of course, you have to have experience, but you could probably, that damn thing is so effective. It's so effective that as soon as you get it, like, so many people hire you just to say they, oh, we have a CISSP on the board in our IT department. He's a CISSP, you know, or whatever. That said, you know, just because you have a CISP doesn't mean I'm magically no shit because there's a lot of dumbass CISPs, you know. So I'm sorry I had to take the magic out of it. The magic is that you will get paid and people will hire you. So that just, you know, it is what it is. Let me see. I just got my Security+. six months ago, but I'm still struggling to get a job. How much experience concern, Jay? How much experience do you have? Because the certification alone is not, including the CISSP, is not enough to land you a job. They really, employers want a, they want to see that you can do the work. And that requires, and the best way to see that is via your experience. So wherever you can get experience, get experience. There's been a lot of questions about what search should I get or, you know, I get a lot of those kinds of questions, but the questions I get less of that should be asked is how do I get experience? That's a harder question for me to answer for you, but also it's, It's the best question because that's what they're really looking for. I'm not saying you shouldn't have a security plus. Security plus is fire. CISSP, I just told you, if single-handedly changed my life, it's great. A degree is, you know, people are talking shit about degrees, but if you're doing technical work, you're going to be an engineer, you're going to be doing this for a while, a degree is important. Because the longer you stay in this career path, the more competitive it gets. And the degree is very competitive. So those certs, those degrees, all the pieces of paper, those are important, right? There's an important half in your arsenal, right? But it's like you're sharpening the blades. But the best thing you can have is is experience. The best thing, that's the meat on the plate. Got to have experience. It's very, very, very important. So can't stress that enough, right? Wherever you can get it, you can get it in school, while you're still in school, wherever industry you're in, try to get it there. Wherever you can get experience that you can put something that you can put on your resume, on your profile to say, I did X, Y, and Z for this company. If you can do that, that's That's where the meat is at. Yes, get the Security Plus. Yes, get the CISP. Yes, get cloud certifications. Yes, all that, right? But those are just tools in your arsenal, right? You got to be able to wield the sword, and that's where the skill set comes in. Let me see. Got more questions, comments, complaints on here. How long should I stay in corporate? I just started my career in big tech. It depends on what your ultimate goal is. I would say stay, ride that gravy train as long as you need to. Ride that gravy train as far as it'll take you. Make them fire you. Keep collecting that check and then use that check To brick by brick build something bigger for yourself and for your family. As long as you need to, brother. Use it to build your own corporation. Use it to build your nest egg, your 401k. Use it to, especially if they're doing like that shit where they say, okay, if you put a dollar in, we'll put $3. Yes, do that shit. Ride that gravy train as far as it'll take you. Let me see here. Let me see. Let's see. I've got some more questions, comments, complaints here. Do you have a step by step how to be an ISO course? I do. If that's what you're looking for, you came to the right man. because that's exactly what I have. I have a course specifically for ISOs. I'm glad you asked that question, because that brings us to a commercial break. This is brought to you by Risk Management Framework, ISO. This is what the course is called. And this is a book, by the way, that I wrote. This is coming directly from my own personal experience. I tell you, in plain English, what this job entitles, and specifically from the perspective of an information system security officer, how to do this work for risk management framework, NIST 800. I've got two books. One focuses on the NIST 837, and one focuses on the NIST 853. I remember talking to one of my peers, and I was telling him, hey, man, I was trying to get him in with me to write books and stuff. I'm like, man, I've got this course, and I want you to help me build it. And he says, man, why would people pay for something that they can get for free? You can get this for free. All this shit here is for free on the internet. But when you read it, it sounds like just go read it. You'll see for yourself what it sounds like. When I first started learning this stuff, I was like, what the fuck? What am I reading here? It doesn't tell you what you're supposed to do. It does, but it takes 15 paths to Sunday to get to the point. What I'm doing is getting straight to the point and telling you from my experience in the Department of Defense and a couple other federal organizations exactly what you need to do, where you need to focus on, and where to not waste your time. That's what I'm doing. So it's from the perspective of somebody who's done it before. And I'm telling you how it is. So and then once you read this, all the other shit will make more sense. So, yes, I do have a course. It's out there right now. Go to convocourses.net. I've got a bunch of discounts that you can use. Huge, huge. You got to go through it. There's lots of stuff that's out there. Huge discounts been putting out over the years. And if you can't afford it, you can just get this book right here. I've got two of them and that's on Amazon. It's also on my site and it'll walk you through it. It's just stuff I wrote that I wish somebody would have told me when I first started doing this stuff. and explains it in a way that's just straight to the point like here's what you need to do then do this don't worry about this focus on this that's what the book is about that's what the course is about I hope that helps um what do you recommend to leverage your existing salary credit now I know dave ramsey is not going to agree with this but credit other people's money um leverage your set, your existing salary. A couple of things, a couple of things. It's a great fucking question. So listen, a couple of things I use credit, manage your credit. I'm not telling you if you can't manage your credit, if you don't have no discipline, do it. Don't do not do it. Go watch Dave Ramsey. Listen to everything he says, put money in an envelope and pay everything with that shit. Right. But if you can, if you have restraint, right, you're not going to, Go buy a Lamborghini with the money that the bank gives you. And you're trying to build a legacy. You're trying to build something for your kids and your family. Credit, loans, shit like that. Business credit. You don't even have to use your own personal credit if you have an LLC, if you have a business. If you have a bank account that has money going into it, After about two years, they'll give you a loan based off of that LLC. That's based off your bid. They'll give you money from your bid. They'll give your business money and it doesn't mess with your own personal credit. But yeah, that's one thing I use is credit, loans, stuff like that, other people's money. And then I use my high salary to pay that debt down or manage that debt effectively. So that's one thing you can use. And if you're doing real estate, you basically have to use other people's money. So um another thing I do I've done before not doing it currently but if I had the opportunity I probably would uh is uh over it's called over employment so what you do is you just get two jobs if you work from home you can work two jobs you can have one part-time job and one full-time job two part-time jobs or you can you could do uh what a lot of i.t guys do is they just hop from um They'll do what's called 10 99s. They won't be a full-time employee. Let's jump from contract to contract to contract and do like three months here, four months here, nine months here at these different companies. And sometimes doing it two at a time and doing that shit, you can make 200, $300,000 easy doing that, you know? So, um, that's another way you can leverage your, your existing salary. Another thing is, uh, uh, do, do, uh, have a side hustle, side incomes. Um, this is something I've been doing for many, many years and my favorite thing to do. And it's stuff like this. This is a side hustle. It does pretty good. It does pretty good. It does. All right. You know, I'm not rich or anything. I mean, look where I'm at, you know what I'm saying? But, uh, it does. Okay. You know, um, what else do I do? I mean, that's pretty much it. Um, loans credit uh making sure I maintain my credit and build using other people's money to do the bank's money to do what I need to do and managing that money with my salary right um that's one thing I do uh and then over employment I do from time to time where I'm not really a fan of it these days because I really need my time for me and my family my kids and everything um And then the other thing is side hustles. That's what I do to leverage. I use my salary to build. There's a lot of leverage you can use. These tools are very, very useful. Very, very, very useful. Let me see. Dewart says, can you work two jobs if you have a secret clearance? It's not so much about the secret clearance. It's about the agreement you have with the company. So it depends on the agreement you have with the company. Some companies are very strict and say, look, you agree to work with us eight hours a day. There's a couple of things. Okay. Let me, let me back out a little bit. Number one, you cannot have a conflict of interest. All right. You can't have a con meaning you can't work for Lockheed Martin and Northrop Grumman for this, for, for competing contracts or some shit. Like you can't, you can't work for this company and it's competing with this company and they're on the same contract or something. Like you can't, have conflicts of interest. What's a real good example of a conflict of interest? Look, you can't have a conflict of interest. That's all I'm going to say about it. You can't. Don't do it. Don't do it. It's not worth it. And then sometimes the organization that you're working for will flat out say, look, we want you to work eight hours a And that's what you're supposed to do. You're going to work eight hours for them. But they can't stop you from working some hours on the weekends. If Saturday and Sunday is yours, they don't own you. Am I right or wrong? They do not own you. Even if you have a secret, top secret, it doesn't matter. They don't own you. You're a human being. You have rights. So after hours, they don't own you. You can work after hours. Now, you can't work during their time during their, you know, so the secret clearance doesn't say that you cannot work for anyone else, right? It just says you cannot share the Volge information that they've, that's sensitive, you know? So that's what, don't do that, you know? So, yeah, it doesn't, a secret clearance doesn't matter in that regard. You can still be over, you know, uh, overemployed, but don't have a conflict of interest. Don't do not do it. Like you can't, we'll be a conflict of interest. Like if you work for the government as a GS, and then you also work as a contractor on the same contract, that's probably a conflict of interest, stuff like that. Are you two competing companies where one, they have one has this special sauce and this one has a special sauce. And then you, You don't want to do stuff like that, right? It's just, you might get yourself in some legal trouble if you do something like that. They're very clear with you. And some companies, what you can do, the company I'm currently working for, they said, look, If you work for another company, just let us know. They say, look, we can't stop you from working for this other company. Now, you can't work during the hours we want you to. Like, if you're working for us, we're not expecting you to be using our stuff to work on theirs. No way. This is our stuff. You know, you work on our time. If you clock eight hours. You're working for us. Right. That's understood. That's what this contract you're signed. So they just said the company I'm working for is like, look, just let us know. You know, that's that's it. Just let us know. And they you know, they can't stop you. Let me see. What other questions do we have here? Somebody said, what if you know how to. What if I know how to build computers? That's a really great first step. I've got a little course, a free course about this where I talk about the levels to help people understand where they have to go to get from point A to point B. And I say the first step is to become a geek. That means to get interested in computers, learn everything you can about it, learn a common body of knowledge. And so, yeah, become a geek. Learn, take computers apart, put them together. But that's only one aspect of it, right? You need to learn networking. You should probably learn a little bit about cloud technology. You should probably learn a little bit about networking technology. Maybe you mess around with a little bit of scripting or code. There's a lot of different aspects of IT to learn. Frameworks is a really good one to learn. Start learning the common body of knowledge beyond just building computers, like learn the whole landscape. That's cool that you know what mountains are, but what about valleys? What about rivers? Learn the whole map of how this landscape works from a distance, like how all this is laid out, how people are using information technology. You want to have a bird's eye view of how all this works, and that's the common body of knowledge, something that all of us have, regardless of whether you are a software engineer or a database guy or a help desk person. cybersecurity person. All of us have some idea of how IPs work. All of us have some idea of how it was a server versus a workstation. All of us have some idea of what cloud technology is. All of us know the layout, the lay of the land. So you still have to know that piece. Now, you might be a master of building computers. You could run circles around me with building computers. I've built a computer in many, many years. But that's not the only thing that you have to learn, right? So from geek, I talk about going to trying to land your first job. From there, from geek to getting your first job, now you're talking about possibly going to school, possibly getting yourself a certification. A plus certification would be something you would probably kill, you know, because it's all about how computers, the components work and how software works with the components, all that kind of stuff. So from geek, landing your first job. Now, let's say you actually get that technical support job and you talk about how to go from there to do a specialization. Cybersecurity is the one that I talk about. What kinds of things as an IT professional do you need to know to get in the door of a cybersecurity type job? So that's the kind of stuff I talk about. But Building computers is one aspect of it, and that's a great aspect to start with. I would recommend you look at the common body of knowledge in CompTIA A+, especially if you're very, very new to IT. I'm taking AWS solution architect exam on Monday. Oh, man, that's awesome. I've been thinking about doing AWS. I have not had time. I would really like to. I'm working on my CCNA next month. CCNA is no joke. I like it. Somebody says, I have a CISSP and master trying to find a job, but people want experience. Yeah. Experience is super important. What can you do to get experience? It depends on where you're at. If you're a student, maybe what you could do is go to your campus, go to your college campus and see if you can get on their IT team. Don't say that help desk is beneath you. Do it. That's experience. Get in there and fix some computers. Get in there and image some computers. do laptops, fix laptops, figure out how the laptop connects to the network. Put that experience on your resume. Try to be a working student if you still have a connection with your school. Even if it's a remote school, you'd be surprised. Sometimes they need help with their equipment that's out there in the field. You could do freelance work and start your own If you know a lot, you're CISSP, if you know a lot about a certain thing, a lot of CISPs are a mile deep in like one or two things. Take that skill set, whether it's scripting or running scans or building networks or whatever you do, whatever you are professional on, do freelance work for local companies or find some organizations. If you have a church, if you go to a church or some kind of other local community, whatever it is, interface with them and try to see if you can do work for them. Do it for free if you can. Do work for some organization so you can put that on your resume. Another thing you can do, one thing Ryan brought up that I just didn't think of it all this whole time, but join an organization called the ISSA. So this is a local – they have local chapters everywhere. In almost every major city, they have a local chapter. And this organization, they meet like monthly. And it's a bunch of information system security people and IT professionals, system admins, help desk people, captains of industry, CEOs are there, CIOs are there, chief information security officers are there. You name it, they're there. And they all meet about once a month in a city, in whatever city you happen to be in, and They're talking about career paths. If you have a CISSP, hell, sometimes they have jobs there and ways to get experience. You could talk to some of the old heads there and say, look, man, I'm trying to get in this field. I've got a CISSP. I got a master's degree. I specialize in writing scripts. How can I get experience? What do I have to do? to get experience for this field. The ISSA is the Information Systems Security Association. They have one in every single state. They have one in almost every city. Well, probably not in every city, every major city, but every state has one. And I think there's even some in other countries. So look that up and try to network with those people. Because with With all of your pedigree of prestigious papers, you should be able to land yourself a job, if nothing else, an internship or something. Somebody said create projects and post them on GitHub. That's another way to do it, especially if you know Python or something or if you know any kind of software projects. Put that on GitHub and you can put that on your resume. So there's a lot of different ways to do it. It depends on where you're at. Somebody says, I have a portfolio with five complex cloud projects. How can I get into the field? Any tips? Hmm. How could you get into? A lot of times when people say this to me, it's usually experience and their resume. It's one of the two things. It's usually one of those things that are stopping them from getting their foot in the door. Pretty clear. It's usually one of those things. They send me their resume and I look through it and it's usually one of those things. I don't know. I don't know what to say. But how could you do it? I think you've got to continue to build out your as much experience as you can. And it's hard. I mean, it's difficult because that's where the real rubber meets the road. That's where the real meat is at, is your experience. It's the hardest part. You've got to talk to people. It's hard. You've got to get out there. You've got to network. So like I said, you could try the local ISSA chapter. I mean, they've got a whole bunch of people you can network with and figure something out. I mean, you have cloud experience. Do you have any certifications that might help you out? If you don't have one, maybe try to get some certifications under your belt. That's one thing you could try. Let me see. Oh, Ryan, how you doing, man? He says, I'm presenting on election security on February 28th at Pikes Peak ISC2 chapter meeting. That's awesome. So these are the kinds of people you want to network with, cybersecurity professionals, IT professionals who are out there. They have this in your area. LinkedIn, one of the hidden gems of LinkedIn is is that if you go there, there's a bunch of forums. In your local area, there'll be a bunch of meetings, a bunch of forums, a bunch of people presenting. Sometimes they'll have job fairs that are local to you. Join those groups. Join some of those groups. And a lot of times people are trading jobs back and forth. Another pretty good resource is Reddit. Reddit might have some pretty good resources for you as well. um reddit has a lot of professionals who are talking back and forth and it's a good way to network with like-minded people who are in the same position um and uh finding finding out new stuff that's kind of bubbling up in the industry uh let me see here I got some other stuff going on here and I'm going to end this real soon guys I appreciate all the people jumping on here um Or can I find your book? Go to Amazon, type Bruce Brown Convo Courses. You'll find a bunch of my books. Risk Management Framework is just one of them. Another place you can look at is convocourses.net. You'll also see free stuff. Ryan's got a free book. I linked his on there. He's got a free book that is walking you through how to study for the ISE2 CGRC, formerly the CAP, Governance, Risk, and Compliance Certification. So we've got free stuff, discounted stuff on there. At the end of the day, what we're trying to do is help people to make your life easier to get into this field, stay in this field, and level up if you already are in this field. Let me see. Emmanuel says, let me see this one. Emmanuel says, which MOS will you advise a 25 Bravo or a 25 Hotel for a start in cybersecurity? 25 Bravo. I thought that was an IT guy. 25 Bravo is in the Army MOS. Ryan's Army. He might be able to answer this. Ryan, what do you think about this question here? Emmanuel is asking, which MOS you would advise a 25 Bravo for a start in cybersecurity? Ryan says, 25 Bravo is a great start. Yeah, that is a great start because that's an IT, yes, and that's an IT specialist, as a matter of fact. So that is a great start. Don't do that. What are you doing? OK, I'm wrapping it up. I'm wrapping it up. Let me see. I'm going to stop this thing. I'm going to answer one more question. Ryan's taking care of the manual. He says, get a network plus or security plus ASAP. That's a great security plus. I would highly recommend a security plus. Oh, boy. OK, I think it's time. OK, one more question. OK, one more question. Okay, I got a bunch of Army guys jumping on here, giving great advice on TikTok. Do I have experience with overlays? A bit, a bit. 25 Delta, 17 Charlie, 25 Bravo. You locked in for six years. Man, I've got a lot of Army guys on here. and highly transferable to civilian sector. Okay, that's where we're going to end this. So 25 Bravo, let me tell you something. If you're a 25 Bravo, and they have an equivalent for this in every branch of the military. I believe the Air Force, they changed it. It used to be a three char... Oh, my Lord. Oh, my Lord. They changed it. It used to be called a three... 3Charlie. 3Charlie. Man, my brain. 3Charlie. 3COX1. That's what it was. 3COX1. That's what it used to be called. But it's no longer called that. So I don't know what they call it these days. 3Delta or something? 17Delta? I don't remember. But every branch has a 25 Bravo equivalent. And it's an IT professional. And somebody on TikTok nailed it. So he said that It is highly transferable to the civilian world. And he is absolutely right. So I was a, I'm an old head. So when I was in the air force, it was called a three Charlie, a three CLX one is what we called it. And a computer operator, same thing as a 25 Bravo. And I was, the thing is, and I don't know how they do it in the army. An army has really sharp IT guys. especially the warrant officers. Very impressive. But the thing is, the Air Force will specialize you in certain things. A computer operator, you could narrow down into firewalls. You could go into network engineering. You could go into not software engineering. That was a completely different field. But you get databases. You could focus on one kind of one area. And once you got out, I mean, you have certifications. If you put the effort in, you had a degree. Listen, if you have a year or more left, I would highly, highly recommend you get a degree. Because look, All of the training, all the way back to boot camp, all the way back to boot camp is going to go towards your degree. You have some credits there that are transferable to your degree. So you're probably only a few points away, maybe six credits, maybe 10 credits away from an associate's degree. Once you get the associate's degree, you have maybe, what is it, 60 more credits? I want to say 60 more credits, and then you have a bachelor's degree. That may sound crazy, like a lot of work, but it's actually not that much work. It's a few classes. Maybe not a few, maybe 10. Look, it's going to be some work, but You can get out with a bachelor's degree within a year. You can be within arm's reach of a bachelor's degree. At the very least, get an associate's degree because literally that's like two classes away. If you have one year left in the military and you are a 25 Bravo, hell, whatever MOS you're in, listen, get your damn degree. Just get the damn degree. All you got to do is go to – they've got a unit on base. I don't know what the Army calls it, but there's a unit on base that you can go to. They'll tell you exactly. They'll have a counselor. They'll break down. They'll take all the credits you already have. They'll say, listen, you went to boot camp. That's six credits. You went to 25 Bravo school. That's – You've got 30 credits for that, right? And of these 40 credits you have, you can apply 25 of them to this associate's degree. You only need two classes. This is what they're going to tell you. You only need two classes. You need one in math and you need one in history and you need one. And basically you can clep your way out of it. Clep is a test. You can just take a test and then they'll give you credits and then bam, you have a degree. Just do it, man. And then it's more, put it to you this way, it's more money. If you want more money, then just do it. Just go through this little bit of process that you have to do. Let them take your transcripts from the military, consolidate them, and you're going to boost up your income by like 15% to 25% when you get out of the military. And then also what Ryan said, Security+. Get a certification. And now you have experience, you have a degree, and you have a certification. And you're very, very deadly. You're very competitive. Very competitive. It's hard out here. It's hard out here on the outside, man. They don't just magically give you stuff here. Like, you got to work for this shit. But the good news is you're in a place where you can really sharpen some swords and come out swinging. All right. That's it, guys. I got to get off of this thing. I appreciate everybody. Remember what I said, like use this as a stepping a stepping stone, like use this as this is one step. You got to go to the next step, whether that's to level up your career, to make. big money as a director and retire with a bunch of 401k money or use this money to go start a business, use this money to invest in real estate. Use it to build up passive income streams because you can't do this forever, guys. You cannot do this forever. I know if you're 30 or you're 20, you think, oh, I'm going to... You just don't even think about it. You think you're going to live forever, man. Then you start seeing your friends die. I'm not trying to bring you down or anything, but I'm just telling you, like, life has an expiration date. And you got to start thinking about, okay, what's my plan? What am I trying to do? You can use this field as a way to go to another level and level up your family, too, and the people you love. So... Just some words of advice from an old guy. I hope some of you guys, I hope at least one of you guys listen to what I'm saying because it can change your life. All right, guys, I'll talk to you guys on the next week. Give me some suggestions of what we should talk about next. Sometimes I just get on here and ramble. So, all right, guys, talk to you later.

View Details

http://convocourses.net

On this one, I am answering questions on Youtube from viewers.

To assist with your request, I'll first need to gather the video's transcript data. Please hold on while I perform this step.


This video features Bruce, the host of the Combo Courses podcast, discussing various topics related to GRC (Governance, Risk Management, and Compliance), cybersecurity, and IT from his extensive experience in the field. He addresses questions about entering and advancing within these fields, explains the workings of GRC, and shares insights on the benefits and challenges of being a 1099 contractor versus a full-time employee. Additionally, he offers advice on how college graduates can build projects related to GRC for their resumes, touching on practical steps to gain relevant experience and leverage existing skills for career advancement in cybersecurity and GRC roles.

Takeaways

  • 🌐 GRC Explained: Understanding the role and importance of governance, risk management, and compliance in cybersecurity.
  • πŸ’‘ Career Paths: Insight into the pros and cons of being a 1099 contractor vs. a full-time employee.
  • πŸŽ“ For Students: Tips for college students on creating GRC-related projects to enhance resumes.
  • πŸš€ Skill Development: Strategies for acquiring and applying skills in cybersecurity and GRC.
  • 🀝 Networking and Experience: Emphasis on gaining experience and building a professional network for career growth.
  • πŸ“ˆ Professional Growth: Advice on certifications and degrees to advance in the IT and cybersecurity fields.
  • πŸ”’ Cybersecurity Careers: Exploring non-technical roles in cybersecurity and how to transition into them.
  • πŸ›‘οΈ Practical Advice: Real-world examples of how to practically apply GRC principles in various settings.
  • πŸ’Ό Leveraging Backgrounds: How to use your background, such as healthcare experience, to enter GRC roles.
  • 🧰 Tools and Techniques: Discussion on tools and techniques for risk assessments and compliance checks.

Summary

  1. Bruce shares insights on GRC and cybersecurity from his experience, highlighting the field's dynamics.
  2. He discusses the differences between being a 1099 contractor and a full-time employee, including financial and operational aspects.
  3. For college students, Bruce suggests projects like updating security policies or conducting risk assessments to build a resume.
  4. He emphasizes the importance of certifications and degrees for advancing in IT and cybersecurity.
  5. Bruce advises on leveraging existing backgrounds, like healthcare, for a career in GRC.
  6. Practical tools and techniques for conducting risk assessments and ensuring compliance are covered.
  7. Networking and gaining practical experience are highlighted as crucial for career advancement.
  8. The podcast addresses audience questions, offering tailored advice for specific career queries.
  9. Bruce touches on the stress factors in cybersecurity roles and strategies for managing them.
  10. The video serves as a comprehensive guide for anyone looking to enter or progress within the cybersecurity and GRC fields.

Diagram

Let's create a summary diagram to visually represent the key points discussed in the video.

Diagram

Below is the visual summary of the key points discussed in the video:

Summary Diagram

View Details

On this one we talk a little about ISO 27001:2022

http://convocourses.net

https://youtube.com/live/sLn_OkJMMN4

View Details

Free cybersecurity GRC information security stuff:

http://convocourses.net

the video: https://youtube.com/live/v3zU7sartu0

In this power-packed episode of the Courses Podcast, dive headfirst into the multifaceted world of Governance, Risk & Compliance (GRC) with host Bruce. He unravels the ins and outs of Information Technology and Cybersecurity, addressing fantastic listener questions and adding valuable insights from his vast experience. Perfect for IT professionals or cybersecurity enthusiasts, it’s a treasure trove of knowledge and a chance to interact with the experts.

Listen to Bruce as he details the challenges of vendor risk management, spotlighting industry giants like Microsoft, Cisco, and Palo Alto. Understand how vendor relationships influence risk and learn enticing strategies for risk mitigation. Plus, explore vulnerability management, software patching, and how to tackle software weaknesses with practical insights from Bruce.

Aspiring for a career in IT or Cybersecurity? Get guidance on various career paths, the importance of security frameworks like NIST 800, NIST CSF, ISO 27001, and SOC 2, plus valuable tips on certifications that can boost your career like the H.C.I.S.P.P. This episode is your comprehensive guide to the exciting and evolving world of IT and Cybersecurity.

Listen to the first-hand experiences of dealing with large-scale enterprise IT systems, particularly within the Department of Defense (DoD). The discussion covers everything from insecure default configurations to skilled personnel, highlighting the complexity and challenges faced in large IT operations.

Take a deep dive into the basics of Information Technology (IT) and cybersecurity, from ports and protocols to the advent of AI and quantum computing. Regardless of your experience level, this conversation offers valuable insights and will inspire continuous learning.

Master the art of assessing controls and security measures in IT, learning from the best in the industry. From creating a security assessment plan to the importance of self-assessments, understand the complete picture of IT security in this informative episode.

As an added bonus, gain expert book recommendations on IT and Cyber Security, learn resume-building tactics for a tough job market, and pick up hacks for maximizing your online visibility. Whether you’re a seasoned IT professional or on the road to entering the IT industry, this episode of the Courses Podcast will fuel your learning journey.

View Details

http://convocourses.net

View Details

Today we are talking to Ryan LeVier

Check him out on Linkedin: https://www.linkedin.com/in/ryanlevier/

check out his guide for the CGRC (free): https://tinyurl.com/TheMangoV2

more free stuff at convocourses.net

View Details

http://convocourses.net

View Details

http://convocourses.net

View Details

http://convocourses.net

View Details

This week we talk about Governance, Risk and Compliance and what it takes to get into GRC.

check out convocourses.net for free stuff.

View Details

This is a brief introduction to governance, risk, and compliance (GRC).

Join my advanced readers team: https://booksprout.co/reviewer/team/35902/convocourses Join the Newletter: http://convocourses.net

View Details

Question: Out of GRC analyst, sca, isso, and security compliance analyst; which roles are the easiest to do the overemployed thing?

http://convocourses.net (DEALS)

Discount on books (limited time): NIST CSF Bundle: https://www.amazon.com/dp/B0CLL3HR5N

newsletter: https://convocourses.com

View Details

security certification roadmap:

https://pauljerimy.com/security-certification-roadmap/

http://convocourses.com

CODE: blackfriday2023x

http://convocourses.net

View Details

http://convocourses.net

View Details

the book:

https://www.amazon.com/dp/B0CLL3HR5N

View Details

http://convocourses.net

find me on linkedin:

https://www.linkedin.com/in/bruce-cissp-rmf/

Discord:

https://discord.gg/BYWaScfDwj

View Details

http://convocoures.net

check out the careers:

https://steampunk.com/

View Details

On vacation in the Philippines.

View Details

http://convocourses.net

View Details

http://convocourses.com

View Details

http://convocourses.net

video: https://www.youtube.com/watch?v=W1flDklH5fU

View Details

The concept of IT risk management can be applied to all of life.Β 

http://convocourses.net

View Details

http://convocourses.net

View Details

http://convocourses.net

View Details

free for limited time:

https://www.amazon.com/Security-Program-Policy-Cybersecurity-Framework-ebook/dp/B0CDF6GX74

http://convocourses.com

View Details

http://convocourses.net

View Details

Someone asked what they should do.Β 

a) community college

b) military

c) self study

We talk about my recommendation in the podcast.

View Details

http://convocourses.com

View Details

http://convocourses.com

View Details

http://convocourses.com

View Details

Free for limited time:

https://www.amazon.com/Cybersecurity-Framework-Information-Systems-Security-ebook/dp/B0C8YH5HXH

http://convocourses.com

View Details

.99 cents (limited time):

https://www.amazon.com/Cybersecurity-Framework-Information-Systems-Security-ebook/dp/B0C8YH5HXH

http://convocourses.com

View Details

http://convocourses.com

See the video:

https://youtube.com/live/1uUqDz4EK_I

View Details

http://convocourses.com

View Details

The video version:

https://www.youtube.com/watch?v=o1dNaLg0XZM&t=2s

http://convocourses.com

View Details

http://convocourses.com

View Details

http://convocourses.com

get stigs: https://public.cyber.mil/stigs/

View Details

http://convocourses.com

get stigs: https://public.cyber.mil/stigs/

View Details

More on http://convocourses.com

View Details

https://securitycompliance.thinkific.com/courses/rmf-isso-security-control-assessment

View Details

http://convocourses.com

View Details

check us out on:

http://convocourses.com

View Details

Free for limited time:

https://www.amazon.com/dp/B0C57CDTLR

View Details

Free book:

https://www.amazon.com/dp/B0C57CDTLR

View Details

atomic habits

https://www.amazon.com/Atomic-Habits-James-Clear-audiobook/dp/B07RFSSYBH

12 week year

https://www.amazon.com/12-Week-Year-Others-Months/dp/B08DFFS7K8

Can't hurt me

https://www.amazon.com/Cant-Hurt-Me-David-Goggins-audiobook/dp/B07KKP62FW

View Details

We talk about the differences between ISSO, ISSE and ISSM. I am currently an ISSO.Β 

check out huge discounts here:

https://www.convocourses.net

View Details

Episodes are live at 1pm MST Saturday

check out discounts and free stuff here: https://www.convocourses.net

https://youtube.com/live/adF3_G9BCNA

View Details

https://convocourses.net

View Details

what the video:

https://www.youtube.com/live/EFgbE_a7EPQ?feature=share

View Details

For sales on products and services:

https://convocourses.net

Join the community here:

  • https://convocourses.com
  • http://youtube.com/@convocourses
  • https://www.tiktok.com/@convocourses
  • https://www.facebook.com/convocourses/

View Details

https://convocourses.net

my linked in:

https://www.linkedin.com/in/bruce-cissp-rmf/

View Details

http://convocourses.net

View Details

https://convocourses.net

video version here:

https://youtube.com/live/vRYMrtzf5ms

View Details

check out https://www.convocourses.com for more

View Details

http://convocourses.net

The keywords you are looking for are "eligible for a clearance"

https://youtube.com/live/px9FDENHrvc

View Details

This book will be released for free on the convocourses newsletter. Join now at convocourses.com

View Details

Here is the video:

https://youtube.com/live/1uyRVmqULFo

Join us at convocourses.com

huge discounts at https://convocourses.net

View Details

http://www.convocourses.net

View Details

contact@convocourses.comΒ 

waiting for your suggestions

View Details

To download the POAM in this podcast go to convocourses.com

A Plan of Action and Milestones (POA&M) is a document that identifies tasks needing to be accomplished to remediate or mitigate risks to a system. It is a requirement under NIST 800-53, which is a guideline for federal agencies and contractors to follow when managing their information security programs. A NIST 800 POA&M, therefore, is a POA&M that is developed in compliance with NIST 800-53 standards.

The NIST 800 POA&M details the resources required to accomplish the elements of the plan, any milestones for meeting the tasks, and scheduled milestone completion dates [1]. The document is continuously updated as progress is made towards remediation, making it a living, dynamic document [2]. The POA&M is a critical tool for anyone responsible for tracking and reporting compliance issues or risks identified for a system [3].

NIST 800-53r5 recommends the use of security automation software to support the POA&M process. This software can help with tracking POA&M items and milestones, and integrate with ticketing systems for streamlined management of remediation activities [2].

View Details

GRC is governance, risk and compliance. The governments framework for GRC is NIST 800-37, but there are other ways to implement GRC.

For more about the NST 800 check out:

https://securitycompliance.thinkific.com/courses/rmf-isso-foundations

View Details

We answer some GRC questions.Β 

View Details

Here are some of these tasks you will do as a GRC professional.

View Details

Here is what I want to do in 2023. HOw about you!!?

View Details

The first step of getting better is the recognize a problem. Sexism is a problem in IT and cybersecurity.Β 

View Details

We talk about NIST 800 PL and then about 2 hours of open topics on cybersecurity jobs, GRC and so much more.

join us: http://convocourses.com

Follow along: https://csrc.nist.gov/Projects/risk-management/sp800-53-controls/release-search#/controls?version=5.1&security_baseline=High

Buy my F%# book: https://www.amazon.com/dp/B0B6PWGXJZ?binding=paperback&searchxofy=true&ref_=dbs_s_aps_series_rwt_tpbk&qid=1670091918&sr=8-1

video:

https://youtu.be/Fa_XxdVlMfo

View Details

https://linktr.ee/convocourses

free resume template:

https://securitycompliance.thinkific.com/courses/resume

amazon:

https://www.amazon.com/Cybersecurity-Jobs-Resume-Marketing-Book-ebook/dp/B0BJC3ZTMF

View Details

http://convocourses.com

View Details

http://convocourses.com

NIST 800: https://csrc.nist.gov/Projects/risk-management/sp800-53-controls/release-search#/families?version=5.1

cis controls: https://www.cisecurity.org/controls

iso 27001 https://www.itgovernance.co.uk/iso27001

View Details

Check out the downloadables here:

https://securitycompliance.thinkific.com/courses/convocourses-archive

View Details

Free resume:

Cybersecurity Resume Sample

tiktok.com/@convocourses

youtube.com/@convocourses

I get constant cybersecurity job offers. It actually get annoying. I wrote a book about how I have been able to do this if you are interested:Β Cybersecurity Jobs Resume Marketing: Book 1 Find Cybersecurity jobs. This downloadable pdf has free sample resumes and a bonus on how to get a work from home cybersecurity job! But if you want to quick summary, here it is. This is due to 3 things that I do effectively:

  • ATS style resume
  • Cybersecurity job keywords
  • Market the resume

This combination would work in any career path, but since I know cybersecurity so well I am able to gather keyword easier.

View Details

We talk about SA-Controls from the NIST 800 security framework.Β 

Checkout http:://convocourses.com

View Details

For more go to http://convocourses.com

http://youtube.com/@convocourses

http://tiktok.com/@convocoursesΒ 

View Details

https://niccs.cisa.gov/workforce-development/cyber-career-pathways-tool

careerjet.com

View Details

  1. Government contracts can be unstable

  2. Cybersecurity is often very stressful

View Details

We talk about what cybersecurity certifications should you do.Β 

View Details

I had a bunch of interviews for cybersecurity jobs. Here is what they asked me.Β 

spoiler alert: they asked a lot about cloud!!

View Details

I am writing a series of books that will focus on cybersecurity jobs. How to get cybersecurity jobs and the categories of cybersecurity.Β 

In this podcast, I answer a few questions.Β 

View Details

For more check out: http://convocourses.com Β 

Convocourses Podcast: Continuous Monitoring, Foreign Nationals

View Details

Check out full video:

https://www.youtube.com/watch?v=9A11RNfy3AU

View Details

This is from 2020 but is still relevant.Β 

here is the video:

https://www.youtube.com/watch?v=zFKC9_vr2io&t=2s

View Details

https://www.youtube.com/watch?v=p3dGCHFVeSA

check out convocourses.com

View Details

https://www.youtube.com/watch?v=p3dGCHFVeSA

check out convocourses.com

View Details

See the video here:

https://www.youtube.com/watch?v=1LkfH1TI3rk

More training:

http://convocourses.com

https://securitycompliance.thinkific.com/courses/rmf-isso-nist-800-53-controls-book-2-nist-800-control-families-in-each-rmf-step

Today. I'm actually gonna train on access controls and documentation that goes with it.

So we're gonna be talking about something a little bit different. Normally what I do is I go through jobs, break all of those jobs down and then talk about like how to get the jobs. And then I break down what the employer wants to see. But today we're gonna do some actual training. now, if you're interested in this training, if you want to go deeper, if you want to deep dive, cuz I'm only gonna cover like a few security controls, but if you want a deep dive, if you really want to know this stuff, then I have a couple of courses for you.

I've got a risk management information system, security officer foundations course, if you want to actually know it from a scratch, like you, you're an it person. You, this is not for entry level type person. The risk management framework foundations is gonna assume that you have some level of it background.

And from there I build on what you already know and it walks you through how to get into risk management framework, how to do the actual information system security officer work. So if you want to deep dive into this, go to combo courses.com and go check those courses out. I also have this what you're about to see as one slice of.

Some of the stuff that I'm putting into a new course that I'm developing right now. And if you want to have a full blown, you want to really check it out. I've gotta free. The first port portion of the course is actually free right now. If you go to convo courses.com you sign in and you can actually see the context of what I'm talking about.

And it's a lot of really good stuff, but right now let's get into access controls and some of the documentation. Let me see here. All right. So here are the access controls. These are actually, these are all the security controls and why you're seeing two sets of these is that one is from risk management framework, 37 version one and one.

The bottom one is from version two. That's coming. That's already out right now, but there's a set of N 853 controls that are coming soon. And so that's what you're seeing right now on the screen. So the top one is from version four version. Is it version three or version four? The top one you're seeing is from the current version of the 800 nest, 853 controls.

The bottom one is the one that's in draft right now, but it should be out. I think this year is when they recently pushed it out to some other date. So anyway, so those are, that's what you're seeing. You're seeing access controls. You're seeing at controls, training controls, MP controls, media protection, physical controls, all these different controls, that I'm gonna cover all of these in the training, I'm gonna be releasing a month over month until we get all the way to the end. And then I also ask questions if you purchase the actual course, but right now we're gonna focus on just. AC controls and just a few of those AC controls, by the way.

If it would take us, it is gonna be many lessons to actually break down all that just AC controls. There's 25 of 'em right now as up the time of this recording. All right. So first of all, what are access controls? So access controls are what an organization uses to control physical. Not it's just not, it's not just logical con controls, not just access to the information, but it also includes access to the system itself.

So some of that is in there, but it also includes things like roles. My cats in here, this is live by the way. , this is gonna conclude things like role based privileges. It's gonna include things like. Separation of duties. There's a lot of different things, but let's talk about access.

What is access? It's the ability to make use of any system or resource. So somebody walks into your facility and they want access to your servers, right? They need access. So access control is the process of granting or denying specific requests and obtaining obtaining access access, obtaining access to that information is what we're talking about here.

And so the N 800 controls, actually it goes through a breakdown of how an organization goes about managing access to the information. All right. So these top six controls. Are some of the most important ones. And I talk about this in greater detail in the course, in the part of the free course, I talk a little bit about it, but I go in more depth in the one that's coming out.

I'm gonna try to release it this month, but I talk about C one C two, and now we're gonna right now, we're gonna talk about C three, a C three access control three is access enforcement. So what is access enforcement? It is the organization's ability to implement the actual access control policies. So not only does your organization have to put a policy in place that talks about how to control access a C three says not you have to implement it.

How have they implemented this the actual access. To the information like you're saying in this document that you have access controls. And you're saying that a person has to be trained before they come in. You're saying now, do you do it, are, is it implemented throughout your organization? All right.

So that's what we're gonna talk about. All right. Let me show you what I'm talking about. You could follow along, feel free to follow along with me. If you like, what I'm doing is I am on this. Let me see if I can give you this link here. If you wanna follow along. Nope. I can't sign into the chat, but where I'm at is N dot it's nvd.n.gov.

If you wanna follow along with me, that's where I'm at right now. So you go to Google and type in nvd.n.gov. You'll find it. And if you go to, once you get there, you'll click on the families like this. Let me just show you real quick. Click on the families that this site has. All the families breaks each one down, as you can see here.

And then I went to access controls and you got access control one, two, and now we're on three. So I'm clicking on three right here. If you wanna follow along, you can also just download the PDF, the N 853 PD PDFs PDF, and then look at 853 C three, and you'll find everything we're seeing right here.

So what are we talking about here? This right here breaks down. What a C three is access enforcement. All right, so let's just look at the actual description here. Let me just make this a little bit bigger so we can read this together and then we're gonna interpret it. The information system. Enforces approved, authorized authorization for logical access to information and in and system resources in accordance with the applicable access control policy.

All right, so let's break this down. So the information system enforces information system, what is an information system? It's a computer, it's a server. It's a workstation. It's a Cisco device. It's an internetworking device. It's a firewall information system covers all like that ground. It's a very general term, but it, where we're saying here, the C three says it enforces whatever system that is.

Let's say it's a windows 6, 20 16 server. It enforces approved authorizations for logical access to the information system. So in other words, there's logical. What do we mean by logical? So there's technical. Things in place on the system that enforce what you have written in your security policy. That is what they're saying here.

So logical access, I'll give you a specific example on our example of a server 2016 windows server, right? So a logical access would be, or enforcement of that logical access would be username and password. Simple enough. So if you written, if you, if your organization wrote in your policy that everyone who comes in has to have a username and the username has to be.

20 characters the username has to fit a certain certain policy. And then the password has to fit certain policy. Password has to be 14 characters long has to use upper lowercase, all that stuff's in your policy, right? They're saying that you have to have implemented that into the actual server itself.

And and before I show you how you, as an information system, security officer can actually check this out and make sure that the organization's doing it. Let's just deep dive into this a little bit further.

All right. So in here it's lives finishing out the sentence. It says the information and system resource in in the, in accordance with applicable access control policies. Yeah. There. So there you go. The organization writes the policy and then the system has to actually implement what you said in the policy.

That's what it's saying right here. That's really the name of the game here. So as an information system, security officer, I've been doing this for a long time. And the name of the game is the organization creates a policy, right? The policy states, what the rules are to having access to your environment.

And then you're making sure as the information system, security officer, you are making sure that all of those policies are documented and they're that they're in place. And if they're not in place, you have. Work it out with the stakeholders. And one of the things that you can do is a plan of action and milestone, but that's for a whole nother discussion.

Okay. So let's, this is look at a little bit more of this so we can get more details, supplemental guide. So this is a great supplemental guides are great because they put it in plain English. What they're saying here. So once again, if you're joining this late, this is AC three and I'm talking about we're interpreting it.

And then we're talking about how to implement this as an information system security officer. All right. So let's get back into this. The supplemental guide says access control policies, and it says identified based policies, role based policy control, matrix cryptography. So these are some of the things you might put in your security control in your access control policy or your overall security policy.

That's just why they're examples. They're just giving you some examples. So control. Access between activities, entities, or subjects. So they're talking about, here are some examples you might have cryptography that cryptographer cryptography might be between might be between the user object and a file.

So they're trying to be the way they write these is try to be as general as possible so that the organization has the freedom to implement the level of security that they need for their environment. Cuz there's many kinds of environments. That's why they write these like this.

All right. And they said, okay, give you an example of different kinds of entities, active entities and subjects, users or processes acting on behalf of users. Passive entities or objects. See just what I just said. So they're saying that the access control policy will have some sort of a role based or a cryptography or something between different objects within the environment.

That's what they're saying here in this guidance, but let me show you, let's put this in action. Let's put this in action. Let me see, what can we do here? Okay. Where I'm at right now is what's called AC. We're on C three, but I'm on a document called 800 dash 53. A here's how you can determine whether or not your organization is actually implementing the AC three in access enforcement.

You go to, this is just one of the things you can do by the way. One of the, one of the main things that I do, you go to 853, a. And 853 a is how you assess each one of the controls, all the controls, the act has every single one of the controls. So 853, a the reason why so useful is because when it's, whenever a system is assessed, this document is what they actually use.

Or some parts of this document is what they might use name. The assessor might even not even know that they're using 853 a but all the assessment stuff comes from this source document. So it's very useful. Okay. So first of all, assessment objectives for a C three, determine if the information system forces approved authorizations for logical access is what we just read.

So the assessor has to make sure that number one, You have a security policy, right? Or some kind of a policy and that a policy addresses access controls. Now the assessor, one of their objectives is to make sure that the logical, the technical security features that you put on your system are in place and they match what you, what was written by and approved by your organization, in the security policy.

That's all they're doing. They're saying, okay. What do you have in your security policy? All right. Are you doing that on this window? 16, 20 16 server. Let's see. That's what they'll do. They'll just say, okay. Log into the system. You'll log into the system and it meets that just you logging in meets one of the access controls, because one of the access controls is that everybody will have a role.

Everybody will have a username password. Everyone will have a role. And then what they might do is say, okay, log in. Let me see you log in with a normal user account. And then they'll say, okay, now try to access this this file system that, that you're not supposed to access. They'll tell you to access, say the audit logs or something, a normal user shouldn't be able to access the audit logs.

So that's the kind of things that they do now. Let me show you something else. Potential assessment methods and objectives. So this is things that a, an assessor can use to assess whether or not you have implemented a C three. You can either examine, you can interview or you can test, right? So normally for AC three, from what I've seen, they do two things.

They look at your your access control policy, which is normally in your security policy. And then they see, they say, okay, let me see what you got. Let me see you do it. Let me see you access that system. Let me see you access the backup drives, and then they're determining whether or not you can.

So that's one of the things that they do now. Let's go to another control here. Let's go to the next control. And I'm gonna go through a few controls here for you guys.

Let's go to AC four and this is information flow enforcement. We're gonna talk very briefly about this one and won't spend a lot of time on it, but it is important just so you know, what is AC four information flow enforcement is the organization controlling the flow of data. And is it documented as an information system, security officer?

Those are the main questions for AC four. So let's go ahead and let me show you what we're talking about here. We're gonna go to C4 and I'm still on nvd.n.gov. And I just want to, if you're joining me late, you can just, you can follow along if you want, but I'm on nvd.n.gov, 853. Here we are. We're gonna interpret it.

And then I'm gonna show you how it's implemented, how some of the things that you can do to actually check on it. So AC controls, let's see, let's just go right to the description here. Here we are. And it says the information system we already described what the information system is enforces approved authorizations for controlling the flow of information within the system and between interconnected systems based on what the organization says, right?

They don't the N doesn't tell you, tell the organization what those control policies, what you should. What elements should be controlled. They allow the organization to control. And that's why they say interconnection systems based on organization defined flow information flow policy. So the organization defines what the flow, the information flow is.

And then you're suppo the informa. The organization has to enforce those policies that they put forth. So one of the main things that I have seen done to document information flow enforcement is a diagram. So a diagram that kind of maybe looks like this, it has firewalls. Let's go through this.

This is on the N this is on cisco.com, by the way, network diagram, it has a DMZ, it has three servers in the DMZ, right? And we can see our DMZ is connected to a switch. The switch is. Connecting two different networks. Those networks are protected by these two different firewalls. Here's one land, but that's behind a firewall and it has some VPNs that are connected to the internet, right?

So this one has more exposure than these ones over here. This is the inside of our organization. So this one's behind an internal firewall. So this is an external firewall and this is an internal firewall. And so this right here is showing what kind of flow enforcement we have. So we're just saying that our data just doesn't go out everywhere.

It's controlled. We have a inter protected sanctum here with land computers, with all of our protected data on it. And then we have outside systems. We have a. We have a protection from the internet. So this is actually the internet. Maybe we have VPN clients that log in or guest accounts that can log in to certain limited resources that we have out there.

But what we're saying with flow control is that we're our, data's not going anywhere, not I've seen this done and documented different ways. Another way that I've documented in the past, or I've seen other organizations documented is to just have a list of all of the land. If you have land and building five, a land and building seven and a land and building 10, you would just list out here's the lands.

And here's what they connect to. You could have like in a spreadsheet and explain what's going on with those things. All right. So I'm gonna go ahead and move on from this one. And I'm going to address a couple of more access controls real quick. We're gonna go straight into. these two right here.

We're gonna talk about AC five separation of duties and ACC six privileged least privileged. These ones right here are probably the most overlooked security controls in the AC control family. And the reason I say that is because a lot of organizations, I go to one of the main vulnerabilities that they have is they either give too many permissions to users that don't need it, or they don't separate.

They don't separate the different organization, organizational duties. And it's an easy one to do, especially if you're in a smaller, if you're in a smaller organization where you only have 10 users, a lot of times those 10 users will have 10 different hats. You know what I mean is your security guy will do all the administrator work and they'll do all the system analyst work.

And then they'll also. be making multimillion dollar choices for the whole organization that they don't, that's not separation of duties. And sometimes you don't really need, multiple people cuz you, you have five computers, five assets and you don't really need a bunch of people to do all these different jobs.

So this is this one, these two right here are foundational. Like you, you real, the organization really needs to have these, but I notice a lot of people don't have them. Let's dive into what these actually mean. Cuz I realize I'm probably talking about stuff that you don't, you might not understand.

So let's go back here. I'm on nvd.n.gov once again, and I'm going to go to families just to show you how I got here and I'm gonna go to AC controls and then I'm gonna go to. I'm gonna go to separation of duties. I just wanna explain what separation of duties is, and then we'll go to C six lease privilege.

All right, here we are right here and I see some people joining me. Thanks for watching. I'll be answering questions after I cover these two items right here. All right. AC five separation of duties. What is separation of duties?

What do you do with separation of duties? The organization? This is N 853. The organization, whatever organization you work for, this is what they will do. The organization operates organization, defined duties of individuals. What does this mean? Let me interpret it for. All right. So it says the organization, if it's the department of health and human services, if it's the department of agriculture, the department of labor and Maine, whatever organization it is the organization, let's say the department of health and human services separates whatever or whatever duties that they define.

So the organization has to actually define different duties and then they separate the duties. So the N is not telling you, yay. Veely all sec, cyber security people can't do any kind of administrator work or administrator work. Can't do firewall work or a server guy. Can't be also be a firewall guy.

That's not what they're saying. They're saying that where it makes sense. You're gonna separate duties apart. So if you have. And what you're trying to avoid is conflict of interest. That's what, the reason why you're trying to do it. And there's certain places where it makes sense. If you are in a very small organization, you don't really have to necessarily, if you don't have the resources to do it, or if there's no reason to do it, if you don't have a server that's controlling a thousand different systems or a hundred different systems, you probably don't really need separation to duties.

You can have your ISSO, your information system, security guy also do some the firewall and also look at logs, and there's no conflict of interest, but if you have a whole bunch of computers systems and you, can't not even possibly track all the users on a day to day basis. And there's data.

There's thousands of terabytes of data coming in now of your network. Yes. You probably even want to think about separation duties. You probably want to have a whole security unit that, that also watches the administrators and then separate administrator. That is controlled by a whole nother office.

All right. Let's keep reading this and get an idea of what's going on. You have to document the separation of duties of these individuals that the organization has deemed necessary to have, right? So if you have a firewall team and you have a server team, you have to document that these are the individuals who control this.

And these are the roles that control these items here. Define information system, access, authorizations to support separation of duties. So you're gonna define what level of access these people have. and then what systems that they have access to. So that's what, in a nutshell, that's what you're doing.

That's what separation of duties is. And like I said, I do see this one violated quite a bit. It's a kind of find it's a foundational best practice that you do in larger organizations, especially, or medium size organizations. Let's get a little bit more supplemental guidance on this separation of duties, addresses the potential for abuse of authorized privileges and helps to reduce the risk of malevolent activities without collusion.

What does that mean? So think about it urine, a large organization like Lockheed Martin has a large contract with a. Health and human services. Now I don't have any pre I've never worked for Lockheed. I don't have any pre any kind of special information on either one of these things.

I'm about to say this is pure speculation on my part. So if I accidentally guess it was an accident. Okay. so anyway, Lockheed Martin I've never worked for has a large contract with health and human services, they have a thousand computers and 10,000 users, right? So these 10,000 users let's say, are managed on on a server and on several different act active do active directory servers somebody, one of the administrators is doing something they shouldn't do.

They are making new users over and over again. Why do we have 10,000 users? Somebody is making new users. . So in this case you would wanna have separation of duties so that this person who's abusing their power is monitored by a whole nother organization. This is just one example of separation of duties.

By the way, you could have a security operations team. And what their job is to do is to watch everything on the network. They're not only watching data going in and out of the network, but they're also watching users. Maybe they have a flag set up to whenever somebody creates a new user, they can see who created the user, what account made that user, when did they made that user?

And then, and maybe they even set up something like a justification, like a why? So every time you make a new user account, you have to make a justification and go through the SOC team. That is one way that you can make it so that these people aren't abusing their power. And that's what they're saying here.

Separation of duties addresses the potential for abuse of author authorized privileges, cuz somebody could give themselves more privilege or they can make 15 other accounts and then make all those accounts, these secret backdoor user accounts that allow them in and in inside access. There's just so many different things you can do if you don't have separation of duties in a large environment.

And that's really mainly what it's for. So you wanna do it when it's, when it makes sense to do it. All right. So I think we beat that dead horse. Let's keep going here. And then what we'll do is, ah, show you how you can document separation of duties. But for now let's talk about the next item, which is least privilege is this one right here.

ACC six least privilege. Let's go into this one and talk about least privilege, access, control, least privilege. And if you're, if you don't have any context here, if you're, you just jumped on this live and you're like, man, what's what is he talking about? What is N special publication? 853 rev four.

What is that? What's going on? If you're interested in actually knowing more about this kind of this field, this path, what I'm talking about is security compliance, specifically with N and I have a whole course. If you're interested, it's called risk management framework, information system, security officer foundations, and it talks about it talks about how to do security compliance using the N standard.

But then I have another one coming out real soon. That talks about how to document everything I'm talking about to you. Now, I give you context of how it all works. I tell I'll break down different documentation and I'm gonna go through. All the families or most of the families, I don't know if I'm gonna cover all of them, but I'm gonna cover most of the families in that.

In that course, that's coming out soon. So go ahead and check that out on combo courses.com. If you're interested. All right, let's keep going here. Least privilege. Now this one right here, this one's near and dear to my heart. This is something that many different organizations I would say most of the organizations that I've ever worked for violate this one.

The reason why is because we as human beings are. We wanna do the least amount of work for the greatest amount of impact . So if there's a way that we can give somebody, if we have a really smart system administrator in our organization, and we want that server fixed this guy, who's really the smartest guy in the organization does Cisco routers, but we also want him, we just start giving this person all of these different privileges that they don't need.

That's one of the things that happens with least privilege. Another thing we'll do, and, or especially in large organizations, is we will we'll have say a thousand different users, right? And the users don't really need, they only need to access their workstation, but they keep coming up with these different things that happen.

Like maybe they have this annoying popup and we restricted their laptop to where they can only do their job. They can only, but they got this annoying popup. So every time they get this popup, they contact the help desk. And they're like, Hey, could you guys fix this popup after a while? The help desk is okay.

Forget it. Let's just give these guys local admin privileges so that they can fix it themselves. And then they tell 'em how to fix it. But they, and then it's just local admin privileges. What could possibly go wrong with that? A lot can go wrong with that. that's another violation of least privilege.

What is least privilege? Let's talk about it. The organization employs a principle of least privilege, allowing only authorized access for users which are necessary to accomplish the assigned tasks in accordance with the organization's mission or business function. What did I just say? So what I'm saying is you only give people the privileges that they need to do their job period, full stop.

That's it that's what least privilege is. the, like I said, the reason why this is violated is because we are lazy. We want to do the easiest thing possible, and it's harder to give people limited privileges when every time they need extra privileges, they have to go and ask, they gotta play mother may eye to go get access to the logs or this popup just keeps popping up.

I wanna stop it. So lease privileges. It's one of the biggest issues I've that I've seen in organizations. Let's look at the supplemental guidance here, organizations the organization employs lease privilege for specific duties and information systems. The principle of least privilege is also applied to information system processes, ensuring that the processes operate at a privileged level, no higher than necessary to accomplish the required organizational or business mission or business function.

You only give the privileges that are needed to do the job period. So runaway privileges is one of the biggest issues in most organizations. I've in 90% of the organizations I've been to, this is the biggest violation, and this is the one that gets the most people in trouble. Let's talk about how to document these two controls that we just talked about here.

What I'm gonna do is bring up, I'm gonna bring up a couple things. If you're doing risk management framework, documentation is the name of the game. We, the reason why we document so much. And I know I talked to some of my system, administrators who are very technical they're all their head is always, deep in the weeds on how to implement these systems or set up a new Linux server or whatever.

So they don't have time for documentation a lot of times, or at least how they feel. But the reason why documentation is so important to somebody who does what I do, which is security compliance, is that if we don't have documentation, a lot of times we don't know who has privileges and who don't, we don't know what privileges are needed here or to this person or what role we even have sometimes.

Organizations are so large that they don't even know what roles they have and they don't even know what roles have, what privileges and the reason why is because they didn't document it. So you have to make sure that you document and that's why it's so important. One of the biggest reasons why we have to document is is having a security baseline.

If you don't document, you don't know what baseline you have. And a lot of times that's the reason why you have a legacy system out there on windows 2003 or windows 2000 or something like that in the year 2020, and then there's no support for that system. And so it's out there and you didn't even know it was out there.

So that's why you have to document document. Let's talk about documentation here. So what I'm gonna do is I'm gonna bring up an example of how you would. These two controls. What this is here is a one example, one format of a system security plan. This is system security plan right here. And what we were just looking at is ACC six here's ACC six, right here, C six.

And how will we document this? So in a system security plan, normally you have an implementation statement. And so that's what we're gonna put right here. And normally this thing will say, okay, did you tailored it in? What did you, is it implemented or not? Is it tailored in or is it tailored out?

Meaning did you, it is implemented and if you didn't have it, let's say we didn't we know we need least privilege, but we don't have it. We would say. Now, keep in mind, this is just one way to document into a security plan. I there's also, here's a, let me just show you real quick, another way that you can document it like this.

If you wanted to, this is a word document and this word documents a template. I've seen organizations do it like this before. A little easier to on the eyes. I think easier on the eyes, but harder to deal with when you have large amounts of data than a spreadsheet, spreadsheets, in my opinion are easier, but there's another level that's above this that most organizations, large organizations are going to, which is like a database.

You put that stuff in a database and the re it's way easier to deal with in a database. Cause the more data that you have on these spreadsheets the more confusing it gets, the more you lose track of things. So what kind of control is it? it's a common control inherited, which is something we talk about in the course.

And then here's where we, the implementation statement comes in. So we would say something like this least let's say our organization is Lockheed gen general. I'm just making stuff up. Adheres to the principle of least privilege

by enforcing a global policy

GPO. So that it's a technical way that they are enforcing all privileges throughout the whole environment. You're just saying what the organization is doing. This is how you document, you're not making this stuff up. All right. Let me just be very clear about this in the real world. What you okay. My head is covering this up.

Let me just move myself outta the way here before I that's what I typed right there. So let me just be very clear. You're not making this stuff up as an information system, security officer, as a security compliance person, whether you work for the bank or the government or hospital, you're not making any of this stuff up.

You're gathering the information from the organiz. So you, that means you have to bring in stakeholders. That's the people who do this stuff on a regular basis. That means it might even mean you're CIO. It might mean you're CFO. It might mean you're the actual people implementing it, the system administrators, or maybe you're the system administrator, or maybe it's already written in their, another policy somewhere else.

You would grab that information and then you're gonna put it into this system. Security plan. All of our system security documents are focused on security. Like you might have, HR has their own documents. The architects guys have their own documents. The technical team have their wikis and their work instructions and their all that stuff.

We are focused on the security features of this system. And so that's what we're doing. We're gathering from all these other existing documents where we can, and we're interp, we're putting those into pouring those into our system security. Plan now another place that's really good. Let me move my face here.

Another place that's really good to document these security features is a security policy. A security policy is really good, cuz you can really break down. You can really break down each individual item with a security policy. I've got a C four, a C five, a C, 11, and many other things.

So in the security policy, I can really focus in and say, here's what we have here and be very specific. And you're not making this stuff up. You're getting it from the actual people who know the system. So that's what you have to do as a system security person. And that's AC the AC controls in a nutshell.

And like I said, if you're interested in this. You can go check out combo courses, if you want to deep dive into this kind of stuff. And now I'm gonna open up to any kind of questions that anybody has to let you know what's going on. Any questions whatsoever about anything we talked about is a great opportunity to talk about it.

I see a few people here that's joined me a cyber security guy. How do you ever defeat your arrival hacker? So I think that it's, there's, that's not how that's not how I would format. That's not how I see it. That's not my perspective on how what's going on here. So what's going on is you're controlling your data as best your POS as possible in your organization.

It's not, you're not defeating an individual person. This is just how I see it. This is not personal. The way I see it is I am working for my organization to protect their information. I'm working for their interest. So whatever their interest is I, that's what I'm protecting. And it's a team effort.

It's not me against some random hacker out there. And then, from the hackers perspective, from the malicious criminal hackers perspective, cuz some hackers are good from a malicious attacker's perspective. It's not personal. They just, they have a mission too. And it's either money or it's, it is activism.

Or, and they're not usually just going after one organization, they're going after many organizations and seeing what works and me as a cybersecurity guy, same thing. I'm just working for the interest of my organization. And it's a team effort. I'm working with several other people who. This guy does firewalls.

This guy does vulnerability management. This other person is the CEO of the company. They have to manage all of the resources of the company. They have a fiduciary responsibility for the organization's information. So there's many different people working on this. It's not me against one lone hacker.

And then from the hackers perspective, from the attacker's perspective, it's nothing personal. They just want to find the weakest link. And they're just usually what they'll do is they'll search the whole, a whole spectrum of the internet to look for the weakest link or to look for free information that's being given out there that they can use that information to infiltrate the weakest person who's out there.

So that's it guys. If there's no other questions I'm going to. Go ahead and go, oh wait, I got somebody here. Let me see. They said I need a job and I don't have any information system security background coming from a Lenox system engineering background. What will be the best advice? What would be your advice?

Please help me. This is easy. If you have a Lennox background you don't. So right now, even with the virus, even with all the stuff's happening, even with the lockdown, now it has slowed down. Like I, some of the employers that have talked to me said that there's right now, there's a free hiring freeze going on throughout.

That's hiring freeze going on, for obvious reasons. You can't do interviews in person. You can't, you don't know what, we don't know how long this is gonna last. We don't know. For large organizations, they don't know what kind of what their fiscal year is gonna look like if they're losing sales, depends on what kind of industry they're in.

But there's just a lot of uncertainty right now. So obviously the markets have slown down a lot. But that being said, people do still need information system, security officers. So if I were you, here's what I would do. If I were you, here's one of the things that, and I have a whole series about this, by the way, I would go to indeed.com.

I've gotta, if you're interested in this, I got an entire series that talks about, I got a whole series that talks about how to market yourself and that's what it's all about. Marketing yourself. I would go to indeed.com. Here's one of the places I would go to Mr. Bun me golden. And then I will type in, I don't know what your skillset is, but you said Lenox is pretty hot.

What kind of Linux is it? Red hat. You gotta be specific. Let's say red hat. I'm gonna assume you're a red hat, Lenox guy, red hat. I'm gonna assume you're a red hat administrator.

All right. And where, what, where are you? Where are you at? Let's say you are I'm gonna assume you're in Texas, Houston, Texas. You're a red hat administrator. I have, I'd have to know more about what you have going on to, to actually help you out in a more realistic way. But I'm assuming you're a red hat administrator and that you have about five years of experience and you are in Houston, Texas, and I'm gonna go find jobs now.

I'm assuming you're in the us. So now look at this. DC. And you're looking for a job. Come on, man. Come on, man. This always blows my mind. DC is one of the hottest areas for it, DC, Virginia, that whole area is hot. Like I, there's not almost, there's barely a week that goes by to somebody from from Washington.

DC is not trying to contact me about a job. The thing is most of us it guys, and it's not your fault. Your profession is technical, right? We're not marketers thing is you wanna market your resume. You wanna market yourself. That's the key. That's the whole key to this whole thing. If you're interested in this, you have somebody else having you watching this kind of thing.

I gotta you go to combo courses.com. You're gonna go check out my course. It talks about how to, how I've been able to have not only a job. but a six figure job working from home for the last X years. And I'm not some freaking genius, man. I'm not some freaking prodigy. I'm not some freaking genius.

The only thing that se separates me from other people is that I work really hard. That's it? I know having seen extremely brilliant people. I know I'm not one of those guys. I know I'm not one of those guys, everything I do, I have to work my ass off for. So that said, and I, I have a level of success that allows me to take care of my family, my wife and kids and travel the world and do what I want, if, when I want, how I want.

But anyway, okay. Back to your question, you said, how do I find a job? You're I'm assuming you're a red. Okay. So you said red hat, six and seven in Washington, DC. All right. So let's look at this. I would go. indeed.com I would make, I would upload my resume. See this. It says, upload your resume. If you're following the law, if you're really hungry, man, you could, right now, I'm gonna show you how to do it.

Upload your resume, fill this out. Don't just upload it. Fill out the complete profile. If you look at my course walks you through everything. What kind of key words to use, how to find the right keyword, all that kind of stuff. If you're not interested in that, you wanna get it for free. I'll show you right now, upload your resume.

Fill out the entire profile. Alright. Put in all, every one of your skills in there don't even leave one out. Cuz there's a place where it allows you to put your skills in how to it allows you to put in all, every place you've ever worked. How many years of experience do you have if you don't mind me asking.

Okay, so red hat administrator. Now look at this and let me show you something. . So if you look at this, it'll tell you who's hiring like right now. And these two places, one in Virginia, one in DC are hiring right now. Right now. It means they have an urgent hiring. They really need somebody who knows this stuff.

So here's S AIC, SIS IIC is a good company, by the way. At least when I was doing it many years ago, the guy you got medical industry, you've got Linux. There's a couple of industries that lend themselves or four years, man. That's perfect. So there's a couple industries that really lend themselves to you work in almost anywhere in almost any industry.

And one of those is Linux is super hot. It, somebody always need it needs it because they just don't. We just don't have enough people who know it now. So what I did was I clicked on this top one right here, and let's just break this thing apart. Let's look at this. So these guys will tell you what they need from you.

If you don't fit this, then move on to the next thing. The magic of putting your resume into indeed.com, putting it, uploading it and putting all your skills is that after a while, indeed. Now it's not the best algorithm. I'm gonna show you a better one in a second, but it's but the thing about it is once you put your stuff in there, it will match up different jobs that fit your resume.

So right here, as we're looking, we're being very active and we're looking at this job here they require a bachelor's degree. Do you have a bachelor's degree? If you have a bachelor's degree, guess what? This that's great. Good for you. Demonstrate experience with system engineering to include network design documentation installation.

Now, like I said, if you don't fit this, go onto the next job. If you do apply. Now, if you put your resume in there, when you hit apply, now it'll take your resume and it sends it to them.

let me show you what let's keep going here. All right. This one is Exel logic administrator remote. This is a remote position right here. Look at this. You just go through what requirements, what re skill requirements. And now they want Oracle. I don't know if Oracle, but if you don't know Oracle move on to the next one.

We want Linux administrator. We want red hat administrator, S a I C. Now here's S CICS. One of their job pages here. Pretty good company. And let me see here. Yeah. See, look at this happiness score. I never seen that before. I think I clicked the wrong thing here. We wanted, I wanted to actually see the job.

So let's just go to the job itself of S a I. Okay. It's talking about a little bit about S a I C, and we're looking at the job screwed. This is what you do. If you're really hungry for a job, you go through every single one of these, every single one. And you find a match for you. But if you put your resume in, it does have to work for you because the hour room's gonna match you up with certain jobs, but you don't want to just wait for that.

You wanna put that in there, let it do this work. And then you want to be extremely active and look at every one of these and look at which ones look at the duties. If you can do it, apply for it. If it's a really long drive, factor that into your final decision, you wanna probably find something closer to you, but don't rule it out, right?

Don't like, I'm the type of person. If I need to feed my family, I'll work at freaking McDonald's man. I'll work the fries. And then at night I'll Moonlight and deliver pizzas, do what you gotta do. To take care of yourself and your family. You know what I mean? So let's go to the next one system administrator, but you don't have to do that.

You're a Lenox administrator. You don't have to, you don't have to flip burgers. You don't have to, Lenox administrator is no joke and you have four years of experience. You should have a really good job right now. And I'm gonna show you how to get one. All right. So bottom line go through every one of these upload your resume, and then you can type in your location, your skillset right here, you can search 'em.

But the big thing is to upload your resume. Now, lemme show you something else. LinkedIn. If you're in the us, LinkedIn is one of the best sites to find jobs. I'm gonna show you a better one after this, a better one than LinkedIn, in my personal opinion. couple better ones for LinkedIn. Now, in my course, I tell you exactly how I'm able to.

Get so many job opportunities from LinkedIn. This, I don't have a lot of people who actively follow me here, but I could tell you most of the people who contact me, these are real opportunities for me. So what I did was what you're gonna do is you're gonna fill out, you're gonna sign up on LinkedIn and you're gonna fill completely fill out this profile, completely fill it out.

And the more you fill it out, the more targeted that it will be the more targeted the traffic you're gonna get. The more targeted, the people who contact you, the technical recruiters that contact you the more targeted they'll be towards you. And that way more peop the most of the people who contact you will be legitimate jobs for you, fill it out.

But here's another thing you can do. red hat, Linux administrator. Look at this. You can join groups, right? Join groups. Here's another thing you can do.

So you're gonna join groups. You're gonna make a complete profile. I hope you're taking notes. And then you're going to admin. We're gonna look for jobs. We just typed in red hat, Linux, admin, and these are all the other people who are also admins. Now look at this. I want you to take note of this. This guy came up number two.

This means technical recruiters are literally typing this in red hat, Lennox administrator. And they're seeing this guy's face. Why is this guy number one? Think about it. Why is this guy? Number one? Why is he coming up? Why is everybody seeing this guy's face? Why is he getting so many job opportunities?

He filled out his complete profile. That's why he filled this entire profile out. That's why he is getting so many jobs. That's what you have to do. Now, if I go to this next, now I'm actually looking for jobs here. So let's just keep scrolling. Now note how this is broken, broke down. So see it has, it starts off with other people.

Then it talks about the jobs and then groups should be here somewhere. I'm looking. Yeah here's different. Oh, these are different companies. You can follow the companies. If you follow them every time they come out with a new something new they'll, it'll pop up in your messages or notifications.

But what I'm looking for is jobs. I'm gonna say, see all, if you're following along. And once again, what we're gonna do is we're gonna go through every one of these, even though this says Kafka engineer, analyst, I'm gonna go see what this is. I don't know what this is. It says promoted. I usually avoid the promoted ones.

Because they're paying for it, but that's fine. Even check those wounds out too. It's telling you where, what location? Oh, look, we didn't put our location in. Let's make sure we put our location. You said Washington, DC, Baltimore. Look at this Washington, Baltimore, one of the hottest places for jobs by the way.

And they pay a great amount of money, especially if you're willing to travel. Okay. So this one is, I don't know if Splunk, but Splunk developer. Okay. So that's not what we want. Let's keep going. We want some more like Linux kind of administrator type work. This one's looking for sci clearance.

I'm assuming that you don't know as you don't have that. That's a clearance. Not a lot of people have it. I don't have a Ts S C I, I don't think anymore. That's Splunk. Let's skip that one. Let's go to the next one. So if you, if it's obvious, you don't know that, just move on to the next one, but this one right here.

this one deserves our in our time. Let's look at this one. What are they looking for now? Notice I'm just, I'll come back to this later. They're talking about what kind of business it is. It's women owned and all this kind of stuff. I'll come back to that right now. When I'm looking for is what is in the job description?

Can I do it? Nope. Look at this. It says security. Does TSS C I clearance. I don't have a clearance, so let's keep it moving. Notice how I'm just going through these. If I don't if there's any indication I can't do the job I move on. And the reason why is because I got stuff to do, I need to find people who are a good fit for me.

That's what we're doing. We're trying to find what's the best fit for our Linux red hat administrator in Washington, Baltimore. Is this even in the same right location, Virginia. Okay. I could drive there. Security plus requirements. Do you have a security plus, do you have any kind of security clearances?

okay. I'm assuming not. And this is asking for Oracle stuff, so no, I'm gonna move on. This is how you do it right here. Now my, it looks like my search is not great. So what I'm gonna do is I'm gonna change my keyword here. I'm gonna go to, I'm gonna call this red hat, Linux administrate.

Look at this man. I can barely spell you're a Lenux administrator and I'm a American with one language who can barely spell. And if I can get a job, you can get a job. that's all I'm saying all. Okay. Look at this rest in Virginia. Okay. That's not too far from Washington. You're willing to make the drive, but security clearance.

So we can't do that one. Let's keep going here. Security clearance. Raytheon. Raytheon is a, is an okay company. They get a lot of contracts, so you'll see tons of jobs from these guys must be a us citizen and S sci clearance. Okay. Moving on now, I'm assuming that in the east coast, this is one of the problems we have is looking for jobs with that don't require clearance.

So I'm moving on to general dynamics. Another very large company has 10,000 employees. Let's see here. Okay. Here we go. Scope of work. They explain to you what you, what they're expecting from you. Looking for requirements, education, no degree, 10 years of trip wire experience. Okay. If you don't have trip wire experience, let's move on.

So you need to go through every one of these. After you make your profile. First thing you want to do go tod.com put in your profile, go to linkedin.com, make a profile. Once you make the profile, it starts to find jobs that fit you. The reason why this is coming up with stuff that fits me is because I have my pro I have my, I already have a very full profile there.

So it's automatically searching things that fit me. So it's I'm having a hard time finding stuff that fits you. That's why it's very imperative that you do this. Okay. Let's look at these skills right here. They're saying in-depth knowledge of HBSS. Okay. Let's I'm assuming you all know that let's just keep going.

Red hot platform and applications administrator. So I'm assuming this one's a software engineer, somewhat qualifications. This one might fit. You obtain a public trust clearance. Okay. So this one might fit you because. , they're not looking for a sci clearance, which not everybody can get or has, but public trust clearances just means that they'll do a background check on you and you don't have to be a us citizen.

You could be a green car holder or whatever, but public trust is easier to get five years experience with red hat. You said four, you could still pull it off. I would still apply for it. I'd apply for this one. This one might be good for you. Actually, I would look at this one right here. Look at this co this is some stuff you can learn.

Cold fusion. They're saying three to five years of WebSphere experience. If you have that, I'd apply for this one that we're getting closer. All right, let's keep going. Let's go. Keep going down here. You get the idea. You're gonna go through every one of these and try to find a match. All right. Try to find a match for you.

If it doesn't, if it in anything's out of place, the closer you get to a match. You wanna apply for those jobs, right? The closer you get to a match, the better, because those are gonna be give you the most probability of actually getting an interview with them. Now, let me show you a couple of other places that are really good to apply for there's dice.com, which is probably the best technical place to find a job in the United States of America.

So what you would do is go to dice.com and then type in red hat, Linux. You know what? Let's change it up. Let's type in Linux administrator. There we go right there. See this look at, take note of this. Look at this, see how this keyword popped up. That means this is highly searched and they have tons of jobs for this, but then they also have other job titles here, too.

Linux administration, Linux administrator. senior Linux administrator, an Sr senior administrator. There's many different ones. What you wanna do is click one of the ones that fit closest to you. Let's look at another keyword red hat. Let's see what pops up with, let red hat look at this. See all these keyword.

These are the key words you want to use all these keywords right here. These ones that people are typing in these people that have hot jobs that you're looking for. But I wanna go back to Lenox administrator. And then this is the one right here. And then we gotta type in a location. You said Washington and Washington DC, boom, fine jobs.

So y'all notice all these jobs. Look at it. Look how technical all these technical jobs. Look how this one's way better than indeed and way better than LinkedIn, as far as search options go for technical people. What another thing you wanna do is don't look for anything too old. If it's months old, then just forget it.

This one's one hour, this one's nine days. This one's 12 hours, 12 hours, 10, 10 hours, two hours. These are just recently posted some of these, right? I said there was a hiring freeze, but look at this one hour, 16 days ago, 30 days ago, I would avoid these one. That's a long time. If it's after 30 days, I would not apply for that.

But you never know, never know this one 11 hours ago, one day ago, one hour ago, Restin VA two days ago. That's not too far from where you live. Linux engineer, Linux, admin experience. You get the idea, but what you wanna do is make yourself a full blown profile.

View Details

See the video here:

https://www.youtube.com/watch?v=1LkfH1TI3rk

More training:

http://convocourses.com

https://securitycompliance.thinkific.com/courses/rmf-isso-nist-800-53-controls-book-2-nist-800-control-families-in-each-rmf-step

Today. I'm actually gonna train on access controls and documentation that goes with it.

So we're gonna be talking about something a little bit different. Normally what I do is I go through jobs, break all of those jobs down and then talk about like how to get the jobs. And then I break down what the employer wants to see. But today we're gonna do some actual training. now, if you're interested in this training, if you want to go deeper, if you want to deep dive, cuz I'm only gonna cover like a few security controls, but if you want a deep dive, if you really want to know this stuff, then I have a couple of courses for you.

I've got a risk management information system, security officer foundations course, if you want to actually know it from a scratch, like you, you're an it person. You, this is not for entry level type person. The risk management framework foundations is gonna assume that you have some level of it background.

And from there I build on what you already know and it walks you through how to get into risk management framework, how to do the actual information system security officer work. So if you want to deep dive into this, go to combo courses.com and go check those courses out. I also have this what you're about to see as one slice of.

Some of the stuff that I'm putting into a new course that I'm developing right now. And if you want to have a full blown, you want to really check it out. I've gotta free. The first port portion of the course is actually free right now. If you go to convo courses.com you sign in and you can actually see the context of what I'm talking about.

And it's a lot of really good stuff, but right now let's get into access controls and some of the documentation. Let me see here. All right. So here are the access controls. These are actually, these are all the security controls and why you're seeing two sets of these is that one is from risk management framework, 37 version one and one.

The bottom one is from version two. That's coming. That's already out right now, but there's a set of N 853 controls that are coming soon. And so that's what you're seeing right now on the screen. So the top one is from version four version. Is it version three or version four? The top one you're seeing is from the current version of the 800 nest, 853 controls.

The bottom one is the one that's in draft right now, but it should be out. I think this year is when they recently pushed it out to some other date. So anyway, so those are, that's what you're seeing. You're seeing access controls. You're seeing at controls, training controls, MP controls, media protection, physical controls, all these different controls, that I'm gonna cover all of these in the training, I'm gonna be releasing a month over month until we get all the way to the end. And then I also ask questions if you purchase the actual course, but right now we're gonna focus on just. AC controls and just a few of those AC controls, by the way.

If it would take us, it is gonna be many lessons to actually break down all that just AC controls. There's 25 of 'em right now as up the time of this recording. All right. So first of all, what are access controls? So access controls are what an organization uses to control physical. Not it's just not, it's not just logical con controls, not just access to the information, but it also includes access to the system itself.

So some of that is in there, but it also includes things like roles. My cats in here, this is live by the way. , this is gonna conclude things like role based privileges. It's gonna include things like. Separation of duties. There's a lot of different things, but let's talk about access.

What is access? It's the ability to make use of any system or resource. So somebody walks into your facility and they want access to your servers, right? They need access. So access control is the process of granting or denying specific requests and obtaining obtaining access access, obtaining access to that information is what we're talking about here.

And so the N 800 controls, actually it goes through a breakdown of how an organization goes about managing access to the information. All right. So these top six controls. Are some of the most important ones. And I talk about this in greater detail in the course, in the part of the free course, I talk a little bit about it, but I go in more depth in the one that's coming out.

I'm gonna try to release it this month, but I talk about C one C two, and now we're gonna right now, we're gonna talk about C three, a C three access control three is access enforcement. So what is access enforcement? It is the organization's ability to implement the actual access control policies. So not only does your organization have to put a policy in place that talks about how to control access a C three says not you have to implement it.

How have they implemented this the actual access. To the information like you're saying in this document that you have access controls. And you're saying that a person has to be trained before they come in. You're saying now, do you do it, are, is it implemented throughout your organization? All right.

So that's what we're gonna talk about. All right. Let me show you what I'm talking about. You could follow along, feel free to follow along with me. If you like, what I'm doing is I am on this. Let me see if I can give you this link here. If you wanna follow along. Nope. I can't sign into the chat, but where I'm at is N dot it's nvd.n.gov.

If you wanna follow along with me, that's where I'm at right now. So you go to Google and type in nvd.n.gov. You'll find it. And if you go to, once you get there, you'll click on the families like this. Let me just show you real quick. Click on the families that this site has. All the families breaks each one down, as you can see here.

And then I went to access controls and you got access control one, two, and now we're on three. So I'm clicking on three right here. If you wanna follow along, you can also just download the PDF, the N 853 PD PDFs PDF, and then look at 853 C three, and you'll find everything we're seeing right here.

So what are we talking about here? This right here breaks down. What a C three is access enforcement. All right, so let's just look at the actual description here. Let me just make this a little bit bigger so we can read this together and then we're gonna interpret it. The information system. Enforces approved, authorized authorization for logical access to information and in and system resources in accordance with the applicable access control policy.

All right, so let's break this down. So the information system enforces information system, what is an information system? It's a computer, it's a server. It's a workstation. It's a Cisco device. It's an internetworking device. It's a firewall information system covers all like that ground. It's a very general term, but it, where we're saying here, the C three says it enforces whatever system that is.

Let's say it's a windows 6, 20 16 server. It enforces approved authorizations for logical access to the information system. So in other words, there's logical. What do we mean by logical? So there's technical. Things in place on the system that enforce what you have written in your security policy. That is what they're saying here.

So logical access, I'll give you a specific example on our example of a server 2016 windows server, right? So a logical access would be, or enforcement of that logical access would be username and password. Simple enough. So if you written, if you, if your organization wrote in your policy that everyone who comes in has to have a username and the username has to be.

20 characters the username has to fit a certain certain policy. And then the password has to fit certain policy. Password has to be 14 characters long has to use upper lowercase, all that stuff's in your policy, right? They're saying that you have to have implemented that into the actual server itself.

And and before I show you how you, as an information system, security officer can actually check this out and make sure that the organization's doing it. Let's just deep dive into this a little bit further.

All right. So in here it's lives finishing out the sentence. It says the information and system resource in in the, in accordance with applicable access control policies. Yeah. There. So there you go. The organization writes the policy and then the system has to actually implement what you said in the policy.

That's what it's saying right here. That's really the name of the game here. So as an information system, security officer, I've been doing this for a long time. And the name of the game is the organization creates a policy, right? The policy states, what the rules are to having access to your environment.

And then you're making sure as the information system, security officer, you are making sure that all of those policies are documented and they're that they're in place. And if they're not in place, you have. Work it out with the stakeholders. And one of the things that you can do is a plan of action and milestone, but that's for a whole nother discussion.

Okay. So let's, this is look at a little bit more of this so we can get more details, supplemental guide. So this is a great supplemental guides are great because they put it in plain English. What they're saying here. So once again, if you're joining this late, this is AC three and I'm talking about we're interpreting it.

And then we're talking about how to implement this as an information system security officer. All right. So let's get back into this. The supplemental guide says access control policies, and it says identified based policies, role based policy control, matrix cryptography. So these are some of the things you might put in your security control in your access control policy or your overall security policy.

That's just why they're examples. They're just giving you some examples. So control. Access between activities, entities, or subjects. So they're talking about, here are some examples you might have cryptography that cryptographer cryptography might be between might be between the user object and a file.

So they're trying to be the way they write these is try to be as general as possible so that the organization has the freedom to implement the level of security that they need for their environment. Cuz there's many kinds of environments. That's why they write these like this.

All right. And they said, okay, give you an example of different kinds of entities, active entities and subjects, users or processes acting on behalf of users. Passive entities or objects. See just what I just said. So they're saying that the access control policy will have some sort of a role based or a cryptography or something between different objects within the environment.

That's what they're saying here in this guidance, but let me show you, let's put this in action. Let's put this in action. Let me see, what can we do here? Okay. Where I'm at right now is what's called AC. We're on C three, but I'm on a document called 800 dash 53. A here's how you can determine whether or not your organization is actually implementing the AC three in access enforcement.

You go to, this is just one of the things you can do by the way. One of the, one of the main things that I do, you go to 853, a. And 853 a is how you assess each one of the controls, all the controls, the act has every single one of the controls. So 853, a the reason why so useful is because when it's, whenever a system is assessed, this document is what they actually use.

Or some parts of this document is what they might use name. The assessor might even not even know that they're using 853 a but all the assessment stuff comes from this source document. So it's very useful. Okay. So first of all, assessment objectives for a C three, determine if the information system forces approved authorizations for logical access is what we just read.

So the assessor has to make sure that number one, You have a security policy, right? Or some kind of a policy and that a policy addresses access controls. Now the assessor, one of their objectives is to make sure that the logical, the technical security features that you put on your system are in place and they match what you, what was written by and approved by your organization, in the security policy.

That's all they're doing. They're saying, okay. What do you have in your security policy? All right. Are you doing that on this window? 16, 20 16 server. Let's see. That's what they'll do. They'll just say, okay. Log into the system. You'll log into the system and it meets that just you logging in meets one of the access controls, because one of the access controls is that everybody will have a role.

Everybody will have a username password. Everyone will have a role. And then what they might do is say, okay, log in. Let me see you log in with a normal user account. And then they'll say, okay, now try to access this this file system that, that you're not supposed to access. They'll tell you to access, say the audit logs or something, a normal user shouldn't be able to access the audit logs.

So that's the kind of things that they do now. Let me show you something else. Potential assessment methods and objectives. So this is things that a, an assessor can use to assess whether or not you have implemented a C three. You can either examine, you can interview or you can test, right? So normally for AC three, from what I've seen, they do two things.

They look at your your access control policy, which is normally in your security policy. And then they see, they say, okay, let me see what you got. Let me see you do it. Let me see you access that system. Let me see you access the backup drives, and then they're determining whether or not you can.

So that's one of the things that they do now. Let's go to another control here. Let's go to the next control. And I'm gonna go through a few controls here for you guys.

Let's go to AC four and this is information flow enforcement. We're gonna talk very briefly about this one and won't spend a lot of time on it, but it is important just so you know, what is AC four information flow enforcement is the organization controlling the flow of data. And is it documented as an information system, security officer?

Those are the main questions for AC four. So let's go ahead and let me show you what we're talking about here. We're gonna go to C4 and I'm still on nvd.n.gov. And I just want to, if you're joining me late, you can just, you can follow along if you want, but I'm on nvd.n.gov, 853. Here we are. We're gonna interpret it.

And then I'm gonna show you how it's implemented, how some of the things that you can do to actually check on it. So AC controls, let's see, let's just go right to the description here. Here we are. And it says the information system we already described what the information system is enforces approved authorizations for controlling the flow of information within the system and between interconnected systems based on what the organization says, right?

They don't the N doesn't tell you, tell the organization what those control policies, what you should. What elements should be controlled. They allow the organization to control. And that's why they say interconnection systems based on organization defined flow information flow policy. So the organization defines what the flow, the information flow is.

And then you're suppo the informa. The organization has to enforce those policies that they put forth. So one of the main things that I have seen done to document information flow enforcement is a diagram. So a diagram that kind of maybe looks like this, it has firewalls. Let's go through this.

This is on the N this is on cisco.com, by the way, network diagram, it has a DMZ, it has three servers in the DMZ, right? And we can see our DMZ is connected to a switch. The switch is. Connecting two different networks. Those networks are protected by these two different firewalls. Here's one land, but that's behind a firewall and it has some VPNs that are connected to the internet, right?

So this one has more exposure than these ones over here. This is the inside of our organization. So this one's behind an internal firewall. So this is an external firewall and this is an internal firewall. And so this right here is showing what kind of flow enforcement we have. So we're just saying that our data just doesn't go out everywhere.

It's controlled. We have a inter protected sanctum here with land computers, with all of our protected data on it. And then we have outside systems. We have a. We have a protection from the internet. So this is actually the internet. Maybe we have VPN clients that log in or guest accounts that can log in to certain limited resources that we have out there.

But what we're saying with flow control is that we're our, data's not going anywhere, not I've seen this done and documented different ways. Another way that I've documented in the past, or I've seen other organizations documented is to just have a list of all of the land. If you have land and building five, a land and building seven and a land and building 10, you would just list out here's the lands.

And here's what they connect to. You could have like in a spreadsheet and explain what's going on with those things. All right. So I'm gonna go ahead and move on from this one. And I'm going to address a couple of more access controls real quick. We're gonna go straight into. these two right here.

We're gonna talk about AC five separation of duties and ACC six privileged least privileged. These ones right here are probably the most overlooked security controls in the AC control family. And the reason I say that is because a lot of organizations, I go to one of the main vulnerabilities that they have is they either give too many permissions to users that don't need it, or they don't separate.

They don't separate the different organization, organizational duties. And it's an easy one to do, especially if you're in a smaller, if you're in a smaller organization where you only have 10 users, a lot of times those 10 users will have 10 different hats. You know what I mean is your security guy will do all the administrator work and they'll do all the system analyst work.

And then they'll also. be making multimillion dollar choices for the whole organization that they don't, that's not separation of duties. And sometimes you don't really need, multiple people cuz you, you have five computers, five assets and you don't really need a bunch of people to do all these different jobs.

So this is this one, these two right here are foundational. Like you, you real, the organization really needs to have these, but I notice a lot of people don't have them. Let's dive into what these actually mean. Cuz I realize I'm probably talking about stuff that you don't, you might not understand.

So let's go back here. I'm on nvd.n.gov once again, and I'm going to go to families just to show you how I got here and I'm gonna go to AC controls and then I'm gonna go to. I'm gonna go to separation of duties. I just wanna explain what separation of duties is, and then we'll go to C six lease privilege.

All right, here we are right here and I see some people joining me. Thanks for watching. I'll be answering questions after I cover these two items right here. All right. AC five separation of duties. What is separation of duties?

What do you do with separation of duties? The organization? This is N 853. The organization, whatever organization you work for, this is what they will do. The organization operates organization, defined duties of individuals. What does this mean? Let me interpret it for. All right. So it says the organization, if it's the department of health and human services, if it's the department of agriculture, the department of labor and Maine, whatever organization it is the organization, let's say the department of health and human services separates whatever or whatever duties that they define.

So the organization has to actually define different duties and then they separate the duties. So the N is not telling you, yay. Veely all sec, cyber security people can't do any kind of administrator work or administrator work. Can't do firewall work or a server guy. Can't be also be a firewall guy.

That's not what they're saying. They're saying that where it makes sense. You're gonna separate duties apart. So if you have. And what you're trying to avoid is conflict of interest. That's what, the reason why you're trying to do it. And there's certain places where it makes sense. If you are in a very small organization, you don't really have to necessarily, if you don't have the resources to do it, or if there's no reason to do it, if you don't have a server that's controlling a thousand different systems or a hundred different systems, you probably don't really need separation to duties.

You can have your ISSO, your information system, security guy also do some the firewall and also look at logs, and there's no conflict of interest, but if you have a whole bunch of computers systems and you, can't not even possibly track all the users on a day to day basis. And there's data.

There's thousands of terabytes of data coming in now of your network. Yes. You probably even want to think about separation duties. You probably want to have a whole security unit that, that also watches the administrators and then separate administrator. That is controlled by a whole nother office.

All right. Let's keep reading this and get an idea of what's going on. You have to document the separation of duties of these individuals that the organization has deemed necessary to have, right? So if you have a firewall team and you have a server team, you have to document that these are the individuals who control this.

And these are the roles that control these items here. Define information system, access, authorizations to support separation of duties. So you're gonna define what level of access these people have. and then what systems that they have access to. So that's what, in a nutshell, that's what you're doing.

That's what separation of duties is. And like I said, I do see this one violated quite a bit. It's a kind of find it's a foundational best practice that you do in larger organizations, especially, or medium size organizations. Let's get a little bit more supplemental guidance on this separation of duties, addresses the potential for abuse of authorized privileges and helps to reduce the risk of malevolent activities without collusion.

What does that mean? So think about it urine, a large organization like Lockheed Martin has a large contract with a. Health and human services. Now I don't have any pre I've never worked for Lockheed. I don't have any pre any kind of special information on either one of these things.

I'm about to say this is pure speculation on my part. So if I accidentally guess it was an accident. Okay. so anyway, Lockheed Martin I've never worked for has a large contract with health and human services, they have a thousand computers and 10,000 users, right? So these 10,000 users let's say, are managed on on a server and on several different act active do active directory servers somebody, one of the administrators is doing something they shouldn't do.

They are making new users over and over again. Why do we have 10,000 users? Somebody is making new users. . So in this case you would wanna have separation of duties so that this person who's abusing their power is monitored by a whole nother organization. This is just one example of separation of duties.

By the way, you could have a security operations team. And what their job is to do is to watch everything on the network. They're not only watching data going in and out of the network, but they're also watching users. Maybe they have a flag set up to whenever somebody creates a new user, they can see who created the user, what account made that user, when did they made that user?

And then, and maybe they even set up something like a justification, like a why? So every time you make a new user account, you have to make a justification and go through the SOC team. That is one way that you can make it so that these people aren't abusing their power. And that's what they're saying here.

Separation of duties addresses the potential for abuse of author authorized privileges, cuz somebody could give themselves more privilege or they can make 15 other accounts and then make all those accounts, these secret backdoor user accounts that allow them in and in inside access. There's just so many different things you can do if you don't have separation of duties in a large environment.

And that's really mainly what it's for. So you wanna do it when it's, when it makes sense to do it. All right. So I think we beat that dead horse. Let's keep going here. And then what we'll do is, ah, show you how you can document separation of duties. But for now let's talk about the next item, which is least privilege is this one right here.

ACC six least privilege. Let's go into this one and talk about least privilege, access, control, least privilege. And if you're, if you don't have any context here, if you're, you just jumped on this live and you're like, man, what's what is he talking about? What is N special publication? 853 rev four.

What is that? What's going on? If you're interested in actually knowing more about this kind of this field, this path, what I'm talking about is security compliance, specifically with N and I have a whole course. If you're interested, it's called risk management framework, information system, security officer foundations, and it talks about it talks about how to do security compliance using the N standard.

But then I have another one coming out real soon. That talks about how to document everything I'm talking about to you. Now, I give you context of how it all works. I tell I'll break down different documentation and I'm gonna go through. All the families or most of the families, I don't know if I'm gonna cover all of them, but I'm gonna cover most of the families in that.

In that course, that's coming out soon. So go ahead and check that out on combo courses.com. If you're interested. All right, let's keep going here. Least privilege. Now this one right here, this one's near and dear to my heart. This is something that many different organizations I would say most of the organizations that I've ever worked for violate this one.

The reason why is because we as human beings are. We wanna do the least amount of work for the greatest amount of impact . So if there's a way that we can give somebody, if we have a really smart system administrator in our organization, and we want that server fixed this guy, who's really the smartest guy in the organization does Cisco routers, but we also want him, we just start giving this person all of these different privileges that they don't need.

That's one of the things that happens with least privilege. Another thing we'll do, and, or especially in large organizations, is we will we'll have say a thousand different users, right? And the users don't really need, they only need to access their workstation, but they keep coming up with these different things that happen.

Like maybe they have this annoying popup and we restricted their laptop to where they can only do their job. They can only, but they got this annoying popup. So every time they get this popup, they contact the help desk. And they're like, Hey, could you guys fix this popup after a while? The help desk is okay.

Forget it. Let's just give these guys local admin privileges so that they can fix it themselves. And then they tell 'em how to fix it. But they, and then it's just local admin privileges. What could possibly go wrong with that? A lot can go wrong with that. that's another violation of least privilege.

What is least privilege? Let's talk about it. The organization employs a principle of least privilege, allowing only authorized access for users which are necessary to accomplish the assigned tasks in accordance with the organization's mission or business function. What did I just say? So what I'm saying is you only give people the privileges that they need to do their job period, full stop.

That's it that's what least privilege is. the, like I said, the reason why this is violated is because we are lazy. We want to do the easiest thing possible, and it's harder to give people limited privileges when every time they need extra privileges, they have to go and ask, they gotta play mother may eye to go get access to the logs or this popup just keeps popping up.

I wanna stop it. So lease privileges. It's one of the biggest issues I've that I've seen in organizations. Let's look at the supplemental guidance here, organizations the organization employs lease privilege for specific duties and information systems. The principle of least privilege is also applied to information system processes, ensuring that the processes operate at a privileged level, no higher than necessary to accomplish the required organizational or business mission or business function.

You only give the privileges that are needed to do the job period. So runaway privileges is one of the biggest issues in most organizations. I've in 90% of the organizations I've been to, this is the biggest violation, and this is the one that gets the most people in trouble. Let's talk about how to document these two controls that we just talked about here.

What I'm gonna do is bring up, I'm gonna bring up a couple things. If you're doing risk management framework, documentation is the name of the game. We, the reason why we document so much. And I know I talked to some of my system, administrators who are very technical they're all their head is always, deep in the weeds on how to implement these systems or set up a new Linux server or whatever.

So they don't have time for documentation a lot of times, or at least how they feel. But the reason why documentation is so important to somebody who does what I do, which is security compliance, is that if we don't have documentation, a lot of times we don't know who has privileges and who don't, we don't know what privileges are needed here or to this person or what role we even have sometimes.

Organizations are so large that they don't even know what roles they have and they don't even know what roles have, what privileges and the reason why is because they didn't document it. So you have to make sure that you document and that's why it's so important. One of the biggest reasons why we have to document is is having a security baseline.

If you don't document, you don't know what baseline you have. And a lot of times that's the reason why you have a legacy system out there on windows 2003 or windows 2000 or something like that in the year 2020, and then there's no support for that system. And so it's out there and you didn't even know it was out there.

So that's why you have to document document. Let's talk about documentation here. So what I'm gonna do is I'm gonna bring up an example of how you would. These two controls. What this is here is a one example, one format of a system security plan. This is system security plan right here. And what we were just looking at is ACC six here's ACC six, right here, C six.

And how will we document this? So in a system security plan, normally you have an implementation statement. And so that's what we're gonna put right here. And normally this thing will say, okay, did you tailored it in? What did you, is it implemented or not? Is it tailored in or is it tailored out?

Meaning did you, it is implemented and if you didn't have it, let's say we didn't we know we need least privilege, but we don't have it. We would say. Now, keep in mind, this is just one way to document into a security plan. I there's also, here's a, let me just show you real quick, another way that you can document it like this.

If you wanted to, this is a word document and this word documents a template. I've seen organizations do it like this before. A little easier to on the eyes. I think easier on the eyes, but harder to deal with when you have large amounts of data than a spreadsheet, spreadsheets, in my opinion are easier, but there's another level that's above this that most organizations, large organizations are going to, which is like a database.

You put that stuff in a database and the re it's way easier to deal with in a database. Cause the more data that you have on these spreadsheets the more confusing it gets, the more you lose track of things. So what kind of control is it? it's a common control inherited, which is something we talk about in the course.

And then here's where we, the implementation statement comes in. So we would say something like this least let's say our organization is Lockheed gen general. I'm just making stuff up. Adheres to the principle of least privilege

by enforcing a global policy

GPO. So that it's a technical way that they are enforcing all privileges throughout the whole environment. You're just saying what the organization is doing. This is how you document, you're not making this stuff up. All right. Let me just be very clear about this in the real world. What you okay. My head is covering this up.

Let me just move myself outta the way here before I that's what I typed right there. So let me just be very clear. You're not making this stuff up as an information system, security officer, as a security compliance person, whether you work for the bank or the government or hospital, you're not making any of this stuff up.

You're gathering the information from the organiz. So you, that means you have to bring in stakeholders. That's the people who do this stuff on a regular basis. That means it might even mean you're CIO. It might mean you're CFO. It might mean you're the actual people implementing it, the system administrators, or maybe you're the system administrator, or maybe it's already written in their, another policy somewhere else.

You would grab that information and then you're gonna put it into this system. Security plan. All of our system security documents are focused on security. Like you might have, HR has their own documents. The architects guys have their own documents. The technical team have their wikis and their work instructions and their all that stuff.

We are focused on the security features of this system. And so that's what we're doing. We're gathering from all these other existing documents where we can, and we're interp, we're putting those into pouring those into our system security. Plan now another place that's really good. Let me move my face here.

Another place that's really good to document these security features is a security policy. A security policy is really good, cuz you can really break down. You can really break down each individual item with a security policy. I've got a C four, a C five, a C, 11, and many other things.

So in the security policy, I can really focus in and say, here's what we have here and be very specific. And you're not making this stuff up. You're getting it from the actual people who know the system. So that's what you have to do as a system security person. And that's AC the AC controls in a nutshell.

And like I said, if you're interested in this. You can go check out combo courses, if you want to deep dive into this kind of stuff. And now I'm gonna open up to any kind of questions that anybody has to let you know what's going on. Any questions whatsoever about anything we talked about is a great opportunity to talk about it.

I see a few people here that's joined me a cyber security guy. How do you ever defeat your arrival hacker? So I think that it's, there's, that's not how that's not how I would format. That's not how I see it. That's not my perspective on how what's going on here. So what's going on is you're controlling your data as best your POS as possible in your organization.

It's not, you're not defeating an individual person. This is just how I see it. This is not personal. The way I see it is I am working for my organization to protect their information. I'm working for their interest. So whatever their interest is I, that's what I'm protecting. And it's a team effort.

It's not me against some random hacker out there. And then, from the hackers perspective, from the malicious criminal hackers perspective, cuz some hackers are good from a malicious attacker's perspective. It's not personal. They just, they have a mission too. And it's either money or it's, it is activism.

Or, and they're not usually just going after one organization, they're going after many organizations and seeing what works and me as a cybersecurity guy, same thing. I'm just working for the interest of my organization. And it's a team effort. I'm working with several other people who. This guy does firewalls.

This guy does vulnerability management. This other person is the CEO of the company. They have to manage all of the resources of the company. They have a fiduciary responsibility for the organization's information. So there's many different people working on this. It's not me against one lone hacker.

And then from the hackers perspective, from the attacker's perspective, it's nothing personal. They just want to find the weakest link. And they're just usually what they'll do is they'll search the whole, a whole spectrum of the internet to look for the weakest link or to look for free information that's being given out there that they can use that information to infiltrate the weakest person who's out there.

So that's it guys. If there's no other questions I'm going to. Go ahead and go, oh wait, I got somebody here. Let me see. They said I need a job and I don't have any information system security background coming from a Lenox system engineering background. What will be the best advice? What would be your advice?

Please help me. This is easy. If you have a Lennox background you don't. So right now, even with the virus, even with all the stuff's happening, even with the lockdown, now it has slowed down. Like I, some of the employers that have talked to me said that there's right now, there's a free hiring freeze going on throughout.

That's hiring freeze going on, for obvious reasons. You can't do interviews in person. You can't, you don't know what, we don't know how long this is gonna last. We don't know. For large organizations, they don't know what kind of what their fiscal year is gonna look like if they're losing sales, depends on what kind of industry they're in.

But there's just a lot of uncertainty right now. So obviously the markets have slown down a lot. But that being said, people do still need information system, security officers. So if I were you, here's what I would do. If I were you, here's one of the things that, and I have a whole series about this, by the way, I would go to indeed.com.

I've gotta, if you're interested in this, I got an entire series that talks about, I got a whole series that talks about how to market yourself and that's what it's all about. Marketing yourself. I would go to indeed.com. Here's one of the places I would go to Mr. Bun me golden. And then I will type in, I don't know what your skillset is, but you said Lenox is pretty hot.

What kind of Linux is it? Red hat. You gotta be specific. Let's say red hat. I'm gonna assume you're a red hat, Lenox guy, red hat. I'm gonna assume you're a red hat administrator.

All right. And where, what, where are you? Where are you at? Let's say you are I'm gonna assume you're in Texas, Houston, Texas. You're a red hat administrator. I have, I'd have to know more about what you have going on to, to actually help you out in a more realistic way. But I'm assuming you're a red hat administrator and that you have about five years of experience and you are in Houston, Texas, and I'm gonna go find jobs now.

I'm assuming you're in the us. So now look at this. DC. And you're looking for a job. Come on, man. Come on, man. This always blows my mind. DC is one of the hottest areas for it, DC, Virginia, that whole area is hot. Like I, there's not almost, there's barely a week that goes by to somebody from from Washington.

DC is not trying to contact me about a job. The thing is most of us it guys, and it's not your fault. Your profession is technical, right? We're not marketers thing is you wanna market your resume. You wanna market yourself. That's the key. That's the whole key to this whole thing. If you're interested in this, you have somebody else having you watching this kind of thing.

I gotta you go to combo courses.com. You're gonna go check out my course. It talks about how to, how I've been able to have not only a job. but a six figure job working from home for the last X years. And I'm not some freaking genius, man. I'm not some freaking prodigy. I'm not some freaking genius.

The only thing that se separates me from other people is that I work really hard. That's it? I know having seen extremely brilliant people. I know I'm not one of those guys. I know I'm not one of those guys, everything I do, I have to work my ass off for. So that said, and I, I have a level of success that allows me to take care of my family, my wife and kids and travel the world and do what I want, if, when I want, how I want.

But anyway, okay. Back to your question, you said, how do I find a job? You're I'm assuming you're a red. Okay. So you said red hat, six and seven in Washington, DC. All right. So let's look at this. I would go. indeed.com I would make, I would upload my resume. See this. It says, upload your resume. If you're following the law, if you're really hungry, man, you could, right now, I'm gonna show you how to do it.

Upload your resume, fill this out. Don't just upload it. Fill out the complete profile. If you look at my course walks you through everything. What kind of key words to use, how to find the right keyword, all that kind of stuff. If you're not interested in that, you wanna get it for free. I'll show you right now, upload your resume.

Fill out the entire profile. Alright. Put in all, every one of your skills in there don't even leave one out. Cuz there's a place where it allows you to put your skills in how to it allows you to put in all, every place you've ever worked. How many years of experience do you have if you don't mind me asking.

Okay, so red hat administrator. Now look at this and let me show you something. . So if you look at this, it'll tell you who's hiring like right now. And these two places, one in Virginia, one in DC are hiring right now. Right now. It means they have an urgent hiring. They really need somebody who knows this stuff.

So here's S AIC, SIS IIC is a good company, by the way. At least when I was doing it many years ago, the guy you got medical industry, you've got Linux. There's a couple of industries that lend themselves or four years, man. That's perfect. So there's a couple industries that really lend themselves to you work in almost anywhere in almost any industry.

And one of those is Linux is super hot. It, somebody always need it needs it because they just don't. We just don't have enough people who know it now. So what I did was I clicked on this top one right here, and let's just break this thing apart. Let's look at this. So these guys will tell you what they need from you.

If you don't fit this, then move on to the next thing. The magic of putting your resume into indeed.com, putting it, uploading it and putting all your skills is that after a while, indeed. Now it's not the best algorithm. I'm gonna show you a better one in a second, but it's but the thing about it is once you put your stuff in there, it will match up different jobs that fit your resume.

So right here, as we're looking, we're being very active and we're looking at this job here they require a bachelor's degree. Do you have a bachelor's degree? If you have a bachelor's degree, guess what? This that's great. Good for you. Demonstrate experience with system engineering to include network design documentation installation.

Now, like I said, if you don't fit this, go onto the next job. If you do apply. Now, if you put your resume in there, when you hit apply, now it'll take your resume and it sends it to them.

let me show you what let's keep going here. All right. This one is Exel logic administrator remote. This is a remote position right here. Look at this. You just go through what requirements, what re skill requirements. And now they want Oracle. I don't know if Oracle, but if you don't know Oracle move on to the next one.

We want Linux administrator. We want red hat administrator, S a I C. Now here's S CICS. One of their job pages here. Pretty good company. And let me see here. Yeah. See, look at this happiness score. I never seen that before. I think I clicked the wrong thing here. We wanted, I wanted to actually see the job.

So let's just go to the job itself of S a I. Okay. It's talking about a little bit about S a I C, and we're looking at the job screwed. This is what you do. If you're really hungry for a job, you go through every single one of these, every single one. And you find a match for you. But if you put your resume in, it does have to work for you because the hour room's gonna match you up with certain jobs, but you don't want to just wait for that.

You wanna put that in there, let it do this work. And then you want to be extremely active and look at every one of these and look at which ones look at the duties. If you can do it, apply for it. If it's a really long drive, factor that into your final decision, you wanna probably find something closer to you, but don't rule it out, right?

Don't like, I'm the type of person. If I need to feed my family, I'll work at freaking McDonald's man. I'll work the fries. And then at night I'll Moonlight and deliver pizzas, do what you gotta do. To take care of yourself and your family. You know what I mean? So let's go to the next one system administrator, but you don't have to do that.

You're a Lenox administrator. You don't have to, you don't have to flip burgers. You don't have to, Lenox administrator is no joke and you have four years of experience. You should have a really good job right now. And I'm gonna show you how to get one. All right. So bottom line go through every one of these upload your resume, and then you can type in your location, your skillset right here, you can search 'em.

But the big thing is to upload your resume. Now, lemme show you something else. LinkedIn. If you're in the us, LinkedIn is one of the best sites to find jobs. I'm gonna show you a better one after this, a better one than LinkedIn, in my personal opinion. couple better ones for LinkedIn. Now, in my course, I tell you exactly how I'm able to.

Get so many job opportunities from LinkedIn. This, I don't have a lot of people who actively follow me here, but I could tell you most of the people who contact me, these are real opportunities for me. So what I did was what you're gonna do is you're gonna fill out, you're gonna sign up on LinkedIn and you're gonna fill completely fill out this profile, completely fill it out.

And the more you fill it out, the more targeted that it will be the more targeted the traffic you're gonna get. The more targeted, the people who contact you, the technical recruiters that contact you the more targeted they'll be towards you. And that way more peop the most of the people who contact you will be legitimate jobs for you, fill it out.

But here's another thing you can do. red hat, Linux administrator. Look at this. You can join groups, right? Join groups. Here's another thing you can do.

So you're gonna join groups. You're gonna make a complete profile. I hope you're taking notes. And then you're going to admin. We're gonna look for jobs. We just typed in red hat, Linux, admin, and these are all the other people who are also admins. Now look at this. I want you to take note of this. This guy came up number two.

This means technical recruiters are literally typing this in red hat, Lennox administrator. And they're seeing this guy's face. Why is this guy number one? Think about it. Why is this guy? Number one? Why is he coming up? Why is everybody seeing this guy's face? Why is he getting so many job opportunities?

He filled out his complete profile. That's why he filled this entire profile out. That's why he is getting so many jobs. That's what you have to do. Now, if I go to this next, now I'm actually looking for jobs here. So let's just keep scrolling. Now note how this is broken, broke down. So see it has, it starts off with other people.

Then it talks about the jobs and then groups should be here somewhere. I'm looking. Yeah here's different. Oh, these are different companies. You can follow the companies. If you follow them every time they come out with a new something new they'll, it'll pop up in your messages or notifications.

But what I'm looking for is jobs. I'm gonna say, see all, if you're following along. And once again, what we're gonna do is we're gonna go through every one of these, even though this says Kafka engineer, analyst, I'm gonna go see what this is. I don't know what this is. It says promoted. I usually avoid the promoted ones.

Because they're paying for it, but that's fine. Even check those wounds out too. It's telling you where, what location? Oh, look, we didn't put our location in. Let's make sure we put our location. You said Washington, DC, Baltimore. Look at this Washington, Baltimore, one of the hottest places for jobs by the way.

And they pay a great amount of money, especially if you're willing to travel. Okay. So this one is, I don't know if Splunk, but Splunk developer. Okay. So that's not what we want. Let's keep going. We want some more like Linux kind of administrator type work. This one's looking for sci clearance.

I'm assuming that you don't know as you don't have that. That's a clearance. Not a lot of people have it. I don't have a Ts S C I, I don't think anymore. That's Splunk. Let's skip that one. Let's go to the next one. So if you, if it's obvious, you don't know that, just move on to the next one, but this one right here.

this one deserves our in our time. Let's look at this one. What are they looking for now? Notice I'm just, I'll come back to this later. They're talking about what kind of business it is. It's women owned and all this kind of stuff. I'll come back to that right now. When I'm looking for is what is in the job description?

Can I do it? Nope. Look at this. It says security. Does TSS C I clearance. I don't have a clearance, so let's keep it moving. Notice how I'm just going through these. If I don't if there's any indication I can't do the job I move on. And the reason why is because I got stuff to do, I need to find people who are a good fit for me.

That's what we're doing. We're trying to find what's the best fit for our Linux red hat administrator in Washington, Baltimore. Is this even in the same right location, Virginia. Okay. I could drive there. Security plus requirements. Do you have a security plus, do you have any kind of security clearances?

okay. I'm assuming not. And this is asking for Oracle stuff, so no, I'm gonna move on. This is how you do it right here. Now my, it looks like my search is not great. So what I'm gonna do is I'm gonna change my keyword here. I'm gonna go to, I'm gonna call this red hat, Linux administrate.

Look at this man. I can barely spell you're a Lenux administrator and I'm a American with one language who can barely spell. And if I can get a job, you can get a job. that's all I'm saying all. Okay. Look at this rest in Virginia. Okay. That's not too far from Washington. You're willing to make the drive, but security clearance.

So we can't do that one. Let's keep going here. Security clearance. Raytheon. Raytheon is a, is an okay company. They get a lot of contracts, so you'll see tons of jobs from these guys must be a us citizen and S sci clearance. Okay. Moving on now, I'm assuming that in the east coast, this is one of the problems we have is looking for jobs with that don't require clearance.

So I'm moving on to general dynamics. Another very large company has 10,000 employees. Let's see here. Okay. Here we go. Scope of work. They explain to you what you, what they're expecting from you. Looking for requirements, education, no degree, 10 years of trip wire experience. Okay. If you don't have trip wire experience, let's move on.

So you need to go through every one of these. After you make your profile. First thing you want to do go tod.com put in your profile, go to linkedin.com, make a profile. Once you make the profile, it starts to find jobs that fit you. The reason why this is coming up with stuff that fits me is because I have my pro I have my, I already have a very full profile there.

So it's automatically searching things that fit me. So it's I'm having a hard time finding stuff that fits you. That's why it's very imperative that you do this. Okay. Let's look at these skills right here. They're saying in-depth knowledge of HBSS. Okay. Let's I'm assuming you all know that let's just keep going.

Red hot platform and applications administrator. So I'm assuming this one's a software engineer, somewhat qualifications. This one might fit. You obtain a public trust clearance. Okay. So this one might fit you because. , they're not looking for a sci clearance, which not everybody can get or has, but public trust clearances just means that they'll do a background check on you and you don't have to be a us citizen.

You could be a green car holder or whatever, but public trust is easier to get five years experience with red hat. You said four, you could still pull it off. I would still apply for it. I'd apply for this one. This one might be good for you. Actually, I would look at this one right here. Look at this co this is some stuff you can learn.

Cold fusion. They're saying three to five years of WebSphere experience. If you have that, I'd apply for this one that we're getting closer. All right, let's keep going. Let's go. Keep going down here. You get the idea. You're gonna go through every one of these and try to find a match. All right. Try to find a match for you.

If it doesn't, if it in anything's out of place, the closer you get to a match. You wanna apply for those jobs, right? The closer you get to a match, the better, because those are gonna be give you the most probability of actually getting an interview with them. Now, let me show you a couple of other places that are really good to apply for there's dice.com, which is probably the best technical place to find a job in the United States of America.

So what you would do is go to dice.com and then type in red hat, Linux. You know what? Let's change it up. Let's type in Linux administrator. There we go right there. See this look at, take note of this. Look at this, see how this keyword popped up. That means this is highly searched and they have tons of jobs for this, but then they also have other job titles here, too.

Linux administration, Linux administrator. senior Linux administrator, an Sr senior administrator. There's many different ones. What you wanna do is click one of the ones that fit closest to you. Let's look at another keyword red hat. Let's see what pops up with, let red hat look at this. See all these keyword.

These are the key words you want to use all these keywords right here. These ones that people are typing in these people that have hot jobs that you're looking for. But I wanna go back to Lenox administrator. And then this is the one right here. And then we gotta type in a location. You said Washington and Washington DC, boom, fine jobs.

So y'all notice all these jobs. Look at it. Look how technical all these technical jobs. Look how this one's way better than indeed and way better than LinkedIn, as far as search options go for technical people. What another thing you wanna do is don't look for anything too old. If it's months old, then just forget it.

This one's one hour, this one's nine days. This one's 12 hours, 12 hours, 10, 10 hours, two hours. These are just recently posted some of these, right? I said there was a hiring freeze, but look at this one hour, 16 days ago, 30 days ago, I would avoid these one. That's a long time. If it's after 30 days, I would not apply for that.

But you never know, never know this one 11 hours ago, one day ago, one hour ago, Restin VA two days ago. That's not too far from where you live. Linux engineer, Linux, admin experience. You get the idea, but what you wanna do is make yourself a full blown profile.

View Details

We talk about taking a Red Hat Admin to Cybersecurity resume and security controls for changing operating systems.Β 

2020 podcast that is still relevant. https://www.youtube.com/watch?v=E5i_ImjtJss

View Details

We talk about taking a Red Hat Admin to Cybersecurity resume and security controls for changing operating systems.Β 

2020 podcast that is still relevant. https://www.youtube.com/watch?v=E5i_ImjtJss

View Details

See the video:

https://www.youtube.com/watch?v=ZATU40nemZg&t=2s

There are ways to get into cybersecurity and information technology. With little or no experience.

In this podcast, I explain how to do that. Some things I've learned along the way in my 20 plus years of experience. And we keep open topics. So we talking about a lot of different Now this one is from 2020. A lot of things were happening as you know, in 2020, the pandemic was happening with all these protests in America and all that stuff. I try not to talk about that stuff too much but it does come up from time to time i focus mainly on cyber security stuff so if you're interested in knowing how to get into it with little or no experience check out this podcast

Hope you enjoy this one. I I do weekly. I missed last week. Um, had some stuff going on, but here I am this week, and today we're gonna cover, we're gonna cover some questions that I recently got. So if you have any questions at, at any time throughout this, just feel free to ask and I will I'll cover it. But one of the common questions I I've been getting lately is how do I get into it with no little or no experience?

And so more than one person has been asking, for some reason questions go in sets like somebody will ask me and then like three other people ask me the same question. So I would like to cover that what, um, and give you some resources and stuff like that. But before we. I should let you, uh, I should, I just want to give condolences to, to, to the, all the people who have passed away, do the COVID 19, I'm still bunkered in still, um, uh, staying at home and stuff just like I'm supposed to do.

And hopefully you guys are staying safe as far as the job market is concerned. Uh, it's pretty much the same. It's kind of a freeze going on with hiring new people that said, I am still getting job offers, uh, and opportunities in my inbox. Just not as many, not nearly as many as I was before. And also, um, like the company I'm working for, they have kind of a hiring freeze, but they, they did hire some people like at the tail at the very beginning of this COVID 19.

So we actually do have new people, but they're kind of slowing it down. Cause we don't know financially. where the wind's blowing as far as the company and as far as clients and stuff like that. So that's kind of what's going on with COVID 19. And if you guys, uh, have any anecdotal, uh, personal experiences on what's going on in your wherever, you're from feel free to let us know.

Um, you guys are looking at the same data that I'm looking at, so that's, what's going on with it. And let's just go ahead and dive into this. Let me see if I could bring up the questions I've been getting. And, uh, yeah. So several people have been asking me this question right here. I dunno if you could see this, but I'm just gonna go ahead and read it and it says, um, Hey, what if you have zero experience and just got your security plus cert everyone seems to want new graduates or people with five years of experience.

Also, I don't have a security clearance. So I gotten this question several times, um, from several different people. From all over, uh, from, from LinkedIn, from my email box. Uh, and then there's a couple other people who have, who have asked that very question. So I'm gonna go ahead and answer it to the best of my ability.

And bef before I start on this, I should let you know that I actually have a course that talks about this very thing. So if you go to combo courses.com or you can go to security, compliance, dot, think.com, combo courses.com, easier to remember. You'll see some courses that I have, one of the free courses that I have that talks about my, my perspective on how do you get into it?

How do you get into cyber security with little or no experience? And I talk about it here. I break everything down. I talk about what I would do if I was in like, starting from scratch, knowing what I know now, what would I do? um, and this is from an insider's perspective, what would I do to get in? And so here's some of the topics that I cover.

And so very briefly, I'm gonna summarize some of the stuff that's in here, but if you're interested in this, it is free right now. Um, the reason why I made it free recently is because people are hurting. People are wanting to change and I can see the service industry and several other industries are destroyed.

I'm fine. My job's fine. Um, even if I lost my job right now, I'm certain I could get a job very quickly. It's because I'm in it. And I realize that I'm, you know, I'm a very privileged growing field. And so I encourage a lot of people who, who are looking for a stability to, to get into this field because it's, we definitely need people.

We need people with experience. We need people with, with patients. Um, and you might be surprised you might be in an industry that compliments getting into it. A lot of people I think are kind of shook by all the technical stuff you have to know. But to be honest with you, there's some aspects of our career field that are not very technical and I will talk about those things.

So there you go. There's a free course for you. If you want to jump on there and then I've got some other paid stuff that's also in there, sign up is free. The course is free and it's to help people out. So there you go. All right, what would I do? What would I do? And I got some stuff lined up to tell you like other people's perspective on it.

What, what I would do is number one, I would look at my current experience. Cause as I said, some experience that you may have in the service industry, in the medical industry, in banking, whatever you do it, may you be, might be surprised how much it could compliment getting into it. And I'll give you a couple examples.

In retail, let's say you work retail or your customer service. You're a front facing person who a customer comes up to and has to interact with the way this can help, can help you if you're getting into it, is that a lot of ITP professionals are not good with people. They're not, they're just not good at talking to me, myself included.

I'm I'm I mean, I'm now I'm damn near 50, so I, I know how to speak. I've been, I've done so many things. I've been baptized by fire so many times I've talked, you know, I've done briefings for generals. I've done briefing for, uh, C level execs. I so many times that now it's just, it feels natural to me. I still get nervous and stuff cuz it's just not my I'm not an extrovert.

Uh, so what I'm getting at is a lot of us, it professionals we're good at technical stuff, but not so good. Usually at face to face interaction. So if you're at a customers facing. Um, whether it's retail or if it's, uh, if you're working in, um, the front, your clerk store clerk, or even, uh, you work at McDonald's or anything like that, you have to interact with people on a regular basis.

You have to have a, you know, you have to be professional at all times. You have to approach things in a certain way, from the perspective of the company, you know, you have to maintain this face. That right there already is way above what a lot of it professionals. Skill sets entail. Um, a lot of us don't have it.

We just don't, we're just not very, we don't have a we're just not good at it. You know, so right there, you already have a skill set that is very useful for help desk for customer it customer service, believe it or not, there's an it customer service that is still alive and well in the United States. Not just in India, not just in the Philippines, not just in the us.

We have a lot of customer service representative spots. Um, and as, without naming any names without, without naming my clients or anything like that, I was. Few weeks ago, maybe a couple months ago I was, uh, at a client's location and one of our client was saying, yeah, we need, we need it. Security, not, we need it customer, uh, customer service people, and we just can't keep him.

And he was, he was this guy explaining like, man, we just really need, you know, so there is, there are jobs out there for customer service and sometimes some of the entry level positions will train you on the job and you have like a script, uh, and you'll have to interact with people, but they have a script and a walkthrough of how to fix certain things.

Um, so if I was to start now, if I starting off had no experience at all, what I would do is look at my own skills that I already have. So that's one, I just named one skillset that you probably already have. If you're a customer, uh, customer service representative, that's actually a very good skill to have.

Now you still have to learn the basics of it. You still have to learn. Uh, things like what's in the, at the, um, compt a plus certification which breaks down what, what goes in the hardware and software, how it all works together. You still have to have a basic understanding of that stuff. Um, if you're getting in the it, right.

Um, another skill set that you might have is if you've worked in a bank, so banks, their security and their terminology is different. They call assessments, auditing, you know, they, they are always looking for auditors. Somebody who's gonna look at comp. They kind of see the world from a, like a CPA's perspective, you know?

So it's, uh, different terminology, different frameworks, like security compliance frameworks that they have to meet, that banks have to meet a certain compliance. And then you might have to have compliance for PCI. Like that's the card readers. Um, there's Sarbanes Oxley that you might have to learn. There might be some things that you already know that I don't know, Haven never.

Work directly in a banking environment. You know, I've done assessments and stuff for different organizations, but not, I've never worked for a bank. You know, I've never been an employee there. So you may already have some skills. You may already know some terminology. You may have already taken security, basic security training that is very specialized for you as a teller or you as a loan officer or you working in a financial sector, you probably have some skills and some terminology that I, I don't even have with 20 plus years of, um, security and it experience.

So that's another one. Another one is he, the healthcare industry, healthcare industry has, uh, different frameworks and different practices that they use on a regular basis. That is very important in their field, which is like HIPAA is one of them and protecting, uh, the. Healthcare information. So there's a whole realm of things.

You've probably already gotten the training. If you work in the healthcare industry about what HIPAA is and how to protect, uh, electronic, uh, private healthcare information and all those things. So you already have some skills, some of that stuff you can actually literally put on your resume and it's legit.

If you, like I said, customer service, that's legit. Um, healthcare, if your healthcare industry, you know, HIPAA you've been to this or that class, you've done this or that training you've protect this or that per, uh, personnel's information that's you could put that on your resume. Um, what else did I mention banking?

Same thing. There's certain things that you already have certain skills you already have. You can literally put in a resume and it will, uh, help you now that said most people are not gonna, uh, hire you without any. information. If you don't have, um, a it certification, if you've never taken a class in it, if you don't have any it experience whatsoever, you gotta go out and get it.

So it's, that's the thing you gotta go out now, if it was me, what I would do is I would go volunteer. If I would work. If I work at Walmart, you know, I would, I would see if the, it guys at work in Walmart, there's it guys there. See if I can volunteer my time to work with them, knowing that that experience that I get from volunteering with them can be put on my resume.

You know, if you're, if you, or excuse me, if, if you're allowed to get in there and do it, then yeah, they're gonna, you can put that. On your resume. Um, if you go to church, like church might have an it, like they might want to hook up their wifi server there, you, you might volunteer to help 'em out, uh, wifi, uh, hotspots or whatever, you know, they have there, you might volunteer to help them out.

Um, so there's a lot of volunteer stuff that you can do. You gotta see what's on your resume. Put that stuff on your resume. Um, see what get, dive into it. Learn its another thing I would do. I would hit the books, get in there, start studying, uh, to learn how this stuff all works together. That's what I would do is in entry level is not gonna be overnight.

It's gonna take some hard work, but what I wanna do right now is look at some tips that some people have brought up here. This article right here brings up a couple of things from leader quest.com. Leader quest online.com is where I'm at. It says seven tips for getting into it. With zero experience. Let me see if there's any of this that I can agree with or stuff that I think you should know, um, reexamine and apply for your past experience in it industry.

Yep. That's what I just said. Um, and it's just to kind of read it real quickly, like a little part of it. It might be, it might seem like to you, like you have none, none of the skills that you need, but soft skills can be surprisingly important. Exactly. Soft skills are like non-technical skills because, uh, we need people who can talk to people.

You know what I mean? Customer service people are very good at talking to people. They, they have training and they, it says, for example, if you were looking into starting to help desk position, a common entry level, it role, uh, things like communication, customer service familiarity with Microsoft office.

Yeah, those skills are, you can put on your resume. So right there, you know, that's one, use your past skills, put those on your, find out and see that's the reason why you have to dive into it. Cuz you don't know anything about it. Once you start diving in, you'll start finding, well, I've done this before, put it on your resume.

If you've done it before in a professional. So you don't even know, you don't even realize how experienced you already have in it, or even it security. If you've ever, uh, done it, training in your company, if you, if you've ever been in any kind of company and they gave you access to a computer more than likely what they had to do is sit you down and say, okay, um, here's the things you don't do on our computer, right?

When you log into this computer, when we give you this count, here's the things you don't do. So you have to have some kind of standardized security awareness training. Um, some of that training that you've had to use. Like, whether it's you, uh, create, you had to have an account made, you had to, um, do anything with the computers.

You need to look at what you've done and put that on your resume. But as you dive into it, you'll be able to realize things like, okay, audit logs are super important. Logging in, in a, an account creation. Having an account is super important. Uh, training is super important. Policies are super important.

There's certain aspects like when you look at secur, normally from somebody from the outside, looking in, they look at a it person, all they think about is a person taking a computer apart, putting it back together, or a person staring at a computer and typing stuff into the computer. I don't even know what, what they're typing.

there's so many things that go into this field. It's so big. It goes into all often all these different, uh, categories and some of 'em are not even technical, to be honest with you. You're not even that tech one example of. Just kind of go off on a tangent here is, is called project management, proj, and also known as, uh, program manager or project, uh, project manager.

Those two basically are very needed in many different, um, it roles, uh, it units will use a program manager or a project manager to manage giant projects that are going on. They don't have to be technical. They have to know very little about it stuff, cuz they're not diving in the weeds. They don't have to know.

They have to know some of the terminology. They have to know how to work with people and stuff like that. And that's my wife right there. Gimme a second here. So yeah, they have to know certain things, uh, related to the project, but not, not super. They don't have to be super technical because they're not in the weeds.

All right. So let's keep going for, with this thing. Uh, get. It certifications. This is actually something a lot of people do when they contact me. They say, Hey Bruce, I got this a plus certification. How can I get a job? I've been applying for jobs and I can't get one. Um, it's actually a really good step forward because it's showing that you have the initiative it's showing that you have learned, you're learning a common body of knowledge.

Uh, and then you should start to, you'll start to realizing things you've actually done. Like if you actually take the, a plus certification, you actually take the security plus certification. Any of those certifications, you'll start to think. Well, you know, you'll be reading through it and studying and stuff and you'll be realize, damn, I've done this before.

And that's the kind of stuff you wanna put on your resume, you know? So there's so many different aspects of it. As you learn more, you'll, you'll start to realize what you've already done. So it kind of mentions a couple certifications here. So entry level certifications, like the I L certification compt security plus network plus security plus.

These are all good entry level certifications. And some people will hire you just off the strength of that, but they do want you to have some level of experience more times than not, but some entry level jobs. If you just have one those certifications, they will hire you. Um, said you have to apply for certain certifications.

You can't apply for a, uh, junior level cyber security, uh, position with a, just a security plus and no experience. It won't work. Um, it says junior, so you're like, oh it, well, it's a junior certification. No, listen. So there's different tiers here. All right. So, and I wish, let me see if I can show you like a visualization so you can get an idea of the tier system that you have.

I till kind of does a pretty good job of showing this. Let me see if I can find that I till is like, um, A library of different processes. It maps out different things that have to happen within an information technology, um, within the information technology and in any large organization, they have this great breakdown of the different tiers that you have.

And I'm looking for something there's like a lot of maps and stuff here. Here's what I'm, lemme just show you what I'm looking at here. They have this really good breakdown of the different levels that I'm, I'm thinking of right now. That is really good at showing you like where you, where you should really start because you can't start in the middle and with a, just a security plus or an a plus you gotta start from the beginning, think of your own career, you know, think of your own career.

Somebody can't just walk in off the streets and then suddenly be in the middle. You know what I mean? Um, let me see, this looks kind of like what I'm talking about. Yeah. This kind of looks like it. Let me see if I can get a better picture of this. This map is kind what I'm talking about. So here's ital and it breaks down different aspects of an organization that has it services.

Um, and that's, that's what it's all about. When you start off you're you're not starting in the middle. You're not starting here. You know what I mean? You're not starting. So a lot of jobs that you, that people say, Hey, I've been applying for all these jobs and I can't get in a job. They're applying for mid-tier positions.

Like they already know, okay, I'm not a manager, I'm not a middle manager, man. I'm not gonna be able to. But what they don't realize is that the job they're applying for a lot of times are middle. Level, you're gonna be on like a service desk type position. You're gonna start from the bottom. This is where most people start.

Even if you go on a program manager, which has, which has no technical, very little technical skills, I should say, cuz you do have to know like office when Microsoft office and the Gantt charts and stuff like that. But which you can learn very quickly, but even those jobs it's non-technical you still have to start from the bottom.

And so that's what this is kind of kind of showing here. The service desk has a many different layers on top of it. Even service desks gets extremely advanced all the way to management, you know, who answers directly to the CIO and, and higher management positions. But you gotta start from the bottom. And how do you find these positions?

Let me, let me show you. So if you go to just go to Google, like we don't have to get fancy. Let's just go to Google. If you type in entry level, um, project manager, let's say we were going for a project manager job, just Google. It's gonna go on your local, wherever you're from. It's gonna start from there.

And you'll have a bunch of entry level positions starting from where you're from. If you're willing, willing to move, you'll find way more positions. If you're willing to move. If you're, if you're flexible in, in location, then it'll, it'll be some of these project management jobs are actually, um, or actually, uh, work from home positions as well.

You can get, find these from, uh, work from home, but here's a couple of entry level project coordinator, project manager type positions. They're gonna tell you what they expect from you. And most of 'em are, look this one, one to two years. You know, you can apply for it, but they're saying, look, we expect you to have some experience.

We expect you to have this kind of bachelor's degree, you know? So there are still things that you caveats that you need to, to, to have. Um, so that, yeah, that's just to give you in a nutshell, like that's a couple things on the list of a person with no experience trying to get an it, let's just read a couple more here.

Your degree in another field may be a huge asset and this is true. Like a lot of positions in it will actually take science degrees. They'll take, uh, engineering degrees that are not necessarily computer based. And let me just read a little bit, says you may be tearing your hair out with regret, wondering why you used all your time in college to get a degree that isn't helping you and your quest for a long term career.

Many employers are more. Inclined to offer you a job because you have accomplished that feat and earning a degree, instead of focusing on how your degree may have cost you money and, and blah, blah, blah, um, uh, focus on ways your degree can help apply for moving for a degree moving forward in the it career field.

And this is, yeah, I would say this is true. Like, especially if you have a technical degree, not all degrees are gonna help you. You know what I mean? If you have a, if you have an, um, art degree, it's probably not. I mean, unless you're doing like a AutoCAD or something, or if you're doing engineering and you need to learn 3d modeling, then that might art might help you.

But if you're doing straight up it fixing computers, or if you're, you know, it it's science degrees might help you, engineering degrees might help you. just being completely honest. Not all degrees are gonna help you out, but they're saying here in this article, a philosophy major, I think this is a stretch philosophy major, uh, has a deep understanding of a logic and unique way of approaching challenges.

I, I guess I, you know, I don't know about that. I just tell you from my experience, normally, when companies are hiring people, they're looking for technical type degrees, philosophy degree. I don't know that it's gonna help you. So I, I kind of disagree with this portion, what you could do. If you have a major in philosophy, you have a master's degree in philosophy, it could help you to get an it degree, go back to college, get a minor in it.

And you, you know, you're doing less classes, but you're gonna, you're gonna still get, uh, your degree faster provided they, they accept your, your previous credits. Okay, so be open to start from the bottom. This is absolutely important. Um, you gotta start from the bottom, right? If you have zero experience, you gotta expect to come in and learn so super important.

Um, you can't start from the middle and think you're gonna get a job. You need to type in entry, go to Google type in our LinkedIn or wherever you're at type in entry level position and this entry level position. And that, um, especially the thing is if you have, if you were trying to get an entry level, position and network engineering or net, uh, uh, beginning in, uh, security, it's probably not gonna happen cuz once you get to networking or servers or if you get it's kind of a, the next step, it's another tier.

It's another support tier. That's very specialized. You have to start from the bottom first, which is help desk, customer service. you know, junior level help desk positions, uh, is the best way to get that experience, but you can also volunteer too. Okay. So don't forget the power of networking, talk to people, you know, if you happen to be at a job, um, and you, you know, there's an it department and you want to get experience, you are you're in a gold mine, especially if the company allows you to help out.

You can. Even, what I would do is if I was so hungry to get into this field is I was willing to work extra just to learn. Not to get paid, not over time just to learn cuz I realized the value experience and it's really paid off in the long run. It's a long term plan that I had and it worked teach yourself relevant technical skills also very important.

Absolutely. You gotta get in there and, and once you do that, you can actually use that to put some of that stuff that you've learned on your resume by saying familiar with this, familiar with that. Meaning. Yeah, I've never done. I've never used this thing before, but I'm familiar with it. I've read about it.

I have a lab at home that I worked on. I'm familiar with it. You know, you can even say that you have a lab in your house where you take care of a, uh, a Splunk system that's collecting logs on 45 different virtual systems. You know what I mean? Like you can, you can put stuff like that on your resume. Um, look for crossover positions.

Yep. This is what I was talking about. You happen to be in a field. They might have a, an it workers there that you can go and ask them or ask, see if you can laterally, move over there and start learning stuff. Some companies will allow you to do that. So a lot of the stuff that they talked about in here actually have talked about in this free course, it, if you happen to be in entry level and you have no experience, this is a great opportunity for you to, uh, dive into this.

It's about four hours. I think of video and, and, uh, slides, presentation and stuff like that. You can watch it at your leisure on all devices. Go ahead and go check it out and it's free. All right. So let me see, I'm gonna switch gears here. And there's some people been watching me. Thanks guys for watching.

Appreciate you guys. I got, uh, spades 93 says how can, how can anyone, how can one established. Uh, two to three years in administrative, how can one established a bit with two to three years in administrative support, get, uh, transitioned into cybersecurity position. I'll be taking my security plus exam in two weeks.

Okay. This is right up. What we're talking about. This is great. So this is exactly. If you're still watching this spade, this is for you. This is exactly what I'm talking about. So you're in a administrative supportive position. What I would do is number one, just like this is number, and this is what I'm talking about in this course.

This is why this course is IPO is, is, uh, important. Cuz I, this is exactly what I I'm saying. Okay. If you're a beginner, you have no zero experience. Here's where you start. If you were an it geek, meaning, meaning you don't, you've never held a position, but you do, you do stuff online at your house. You like to mess around and tinker around with things in your home.

I I'm saying like, here's how you evolve from that point. Cuz you need to go to the next level. If you're a beginner, you need to become an it geek. If you're an it geek, next level is a security. Plus get those courses in there, start volunteering places and become an it professional. And then once you're an it professional, you start to focus in on whatever field you can go into forensics.

You can go into cyber security, you can go into, uh, cyber and analyst, work, threat analysis work. There's so many different aspects and so many different places you can go once. You're an it professional and to, uh, hone in your skills and have one specialized skill. Not just cybersecurity by the way. So yeah, so exactly what I'm talking about is for you.

If you're an administrative support person, this is what I'm talking about. You already have soft skills that, um, That you can apply to your current resume. You probably, even as an administrative person, you may even have technical skills. You need to see the thing is, as you dive into security, plus, as you get into the a plus certification or whatever certification as you start cracking those books and start doing, looking at the common body of knowledge that goes in the it, you'll start to realize, man, I've done that before you wanna put that on your resume.

Like as an I'm trying to think of an, an administrative support person, like the kind of things that they might do is like personnel security. So personnel security, meaning you vet people who come into your, and I'm just guessing what your job is. So bear with me. So a person who, a new person, a person who's coming in off somewhere else, they're coming into your organization.

An administrative support person might be in charge of doing things like personnel security, meaning they conduct like a brief background check. They maybe they. Call their supervisor and call that's personnel security. That's something that you can legitimately put on your resume to say, yes, here's some security I've done.

What other kinds of administrative support stuff have, uh, that I could point to would be kind of like, um, uh, security awareness training. Everybody has to have that. I'm sure you've had some kind of cyber security awareness training, or if you've ever caught an email from a, from a, uh, fishing attack, that's another thing that you might have done.

Like there, a lot of times organizations will do their own fishing attacks or actual fishing attacks will come into your email box and you caught you spot one. Like this, this email looks weird. I'm gonna send this to the security support team. Guess what? You could put that on your resume. You know, that's one thing out, it's a small thing, but the thing is you put enough of those small things that you've done on your resume and it looks like.

They're, it's not that you're painting some fake picture, but you're saying here's the actual exposure that I've had in it. Another thing that you may have helped out is like, if you had to stay a while with the it department to help them to load patches or something, maybe they want you to stick around and, uh, reboot your system and they're, and you're, so you're actually coordinating and assisting them to, uh, put patches on a, on a system.

Uh, another thing like that, this article actually mentions and is also in my course, my free course is that get in the certifications does help. I do agree with that. It does help. It's not the end all be all. You definitely want. Don't wanna start there, stop me. You don't wanna stop there. Um, and starting from the bottom.

So all of these things help. Another thing is, um, using, they mentioned it in here. I think they said it was called. Teach yourself relevant skills. Yeah. We already know about that crossover positions. Yeah. This is a good one. So if you're in an administrative position, there's it guys you might wanna try to get in there, like the even volunteer, uh, a couple hours for free, like be like I'm off right now, but I wanna learn this so bad that you go in there coordinate a time.

Like you don't want to, you, you wanna be on their time. Right. So if there's like a swing shift and the it guys are there at get permission to legitimately go in there and learn from them. Or even do work with them that is even better. Cuz you can put that on your resume and, and every all experience equals money in it.

All right. So he says I've triage computer issues, uh, at my position as an AA. Exactly. So that's the kind of stuff you can put on your resume and that's really good stuff. That's the kind of stuff that you wanna put on your resume. Okay. I've got some other questions here. DD says, hi Bruce. I have been applying for jobs for over 15 and over 15 interviews and still no job offers, what am I doing wrong?

So DD, I would have to, if you tapping to still be on, um, I get this a lot from people saying I've applied for all these jobs and from my position. And I, I, I realize I have a kind of a, um, filtered position. It's kind of, um, through my eyes. There's so many job openings. I it's shocking when people say that, but I don't know your context.

Like, I don't know how much experience you have. I don't know what you're applying for. I don't. So what you want to do is you wanna match your skillset. Let me just see if I can bring up what I was looking at before you wanna match whatever skillset you have with positions that are out there. So in this example, right here are these jobs here.

I'll use this one. I just opened up here, right? This is for a junior project analyst. Sorry, a junior project engineer, right at Kelly services in Colorado Springs, Colorado. Excuse me. Now look at this job title. What we just read project engineer. They are looking for three to one to 2, 1, 2, 3 years of experience.

They're looking for a bachelor's degree, they're looking for necessary 3d modeling design. So here's what I do.

Here's my technique. What I do is I look for jobs that I have the skills for. Um, so for example, this says junior level one to two years of experience, one to three years of experience, right. As a project engineer. Okay. I make sure I have that education, uh, education level bachelor's degree in these items.

Right. I make sure I have that. I match myself up with that career path. No, you might be thinking well, Bruce, I don't have a year experience. I don't have 3d modeling. I don't have, are you telling me that I'm supposed to go get this job get three years? Where do I get the three years experience? Okay.

Listen to what I'm saying right here. Check this out. So you have to find a job that already matches the skills you already have, right? Not, not necessarily, if you're just kind of shooting around, if you're just like throwing resumes out there, that's not going to work as effectively as finding somebody you already match up with you already have these skills, find somebody who matches that same skill.

That's all I do. That's all I do. And now, nowadays you got tools like Google. This is cool. This is a cool little tool and everything, but the best tools are ones that have built in job search algorithms that are built specifically for that. Google's very good at search. Very good at research. Awesome way to, and I would definitely put that in your toolbox, but linked in is.

Incredible LinkedIn, you can do exactly what I'm telling you to do. Like, what you do is you fill out a LinkedIn profile, right? Fill it out in complete completely. Then what you now have a whole course about how to do it. What my exact techniques, in what keywords I use tools to find keywords, all that kind of stuff, go to convo courses.com.

You'll find it there, but let me just summarize some things that are very important for you right now for free. So what you do is you take your current skills and I'm assuming you're an it guy right now. If you're, if you're a NBE, that's totally different. That's what we were just talking about. That's entry level, that's volunteer work.

That's something else entirely. If you have it experience, take your resume. Match your resume. What skills you already have with something you find on LinkedIn on career jet on indy.com on dice.com on all these different algorithms, search engines, um, that are specialized in jobs. That's what I do. And it works.

So let me just give you another, let me just show you what I'm talking about here. I'm gonna find one of my real profiles out here on LinkedIn. Let me just, I just gotta sign in real quick. If I could sign in what's going on here, why is it lead me all these different directions? Okay, here we go. So check this out.

Here's my real LinkedIn profile, right? And I, I've not looked at this in a while, so, but here, I hope there's no surprises in here, but here's my real LinkedIn profile right here. And I feel it completely out. I don't even have that many connections. Here's the thing. Many people I know have way more connections than I do, but somehow I get all of these very targeted positions.

Why, why is that? Cause I feel this completely out from top to bottom. So once I do that, this, this tool linked in finds jobs for me, it lines me up and suggests certain jobs for me. When I do a search, if I was to type in, um, it security, it's gonna find jobs in my location. It'll find jobs that, um, that accept my degree, accept my certifications.

It's not blasting everything out. It's, it's looking for stuff that's within, uh, 30 miles from. So there's tons of stuff. And it also shows here's another little gym. It also shows other people with my similar skills, people resulting in it security like this guy, if I was a type click on this guy's resume, I'll see all the stuff that he does now.

This is the owner of black heels information. So he's not what I'm talking about. um, a better job description would be, uh, it securities too. Generic. I'll just say, okay, let's just, let's just go risk management framework. This is pretty specific, um, analyst or engineer. This is very specific to what I do.

It's a very, it's a very specific thing. Another thing I could have typed in is cybersecurity engineer, cyber security analysts. There's lots of different things I could have typed in it. Security is too broad. All right. So here's some guys here. we're very closely aligned with what I do that are kind of in my field.

I could click on any one of these guys' resume to get a better idea of what I should be putting on my resume. What's working for them. Why are they like the top people popping up? Another thing you can do is go into actual jobs, going to actual jobs and look at what they're looking for, examine what the things that they're looking for in when they say they want you to have, what, what are they looking for experience with risk management framework.

And, and this is, this is my field, but you could be whatever your field is. And you're saying de de says, no, no experience previous experience. I have. a BA in criminology and have an ma in strategy and security administration. All right. So that's the reason why right there, you don't have any experience.

It's really hard to get a job with no experience. So what I would do if I were you, is I will type entry level it, entry level it. And I would start from here. I would start from looking at entry level it jobs. What you wanna do is get in at a, get in, at a low level and then start gathering as much. It's not gonna pay.

Well, all right. It might be shift work. It might be 30 miles farther than you want to drive, but you gotta think long term. So what I mean by that is where do you want to be in five years, in five years from now? What kind of career do you wanna have? What kind of career and what path. Are you trying to get into that's what you do.

Just like with your degree, you have a master's degree in strategy and security administration, which will help you, by the way, you have a bachelors D degree in criminology. What was going through your head when you got those degrees? You know, it's a, a four to six year degree, right? You had to plan it out.

It's the same thing with this career path, you gotta be like, okay, in four years, I wanna do, um, forensics that'll match great with my criminology stuff. Forensics is, is a great match for me. Where can I get my first entry level, position experience doing forensics? That's how you gotta think. So what you do is, okay, forensics entry level forensics, which who knows it might, I don't think we're gonna find it, but it's worth a try.

I can't even spell forensics entry level per forensics. Did I spell it right? I guess I did. Okay. So yeah, so here's some entry level positions, uh, cyber security analyst, entry level, uh, security analyst. So you have stuff here. Um, and I don't know that this is what you wanna be. Hopefully you're following along with me.

This is kind of what you wanna do. Entry level is only one keyword or key phrase that you could use to get in. Really. You want any kind of entry level position just to start. Once you get your foot in the door, you can then start putting that on your resume experience equals money experience equals stability.

All right. I can't stress. It enough. A lot of people who contact me, that's the same thing. It's the same story, Bruce. Um, I have no experience whatsoever. I've applied for a hundred jobs. I can't find a job experience is king experience is better than a D than a degree experience is better than a certification.

Um, everything else is just icing on the cake experience is everything. Um, I, I knew people who, who had no degree, no certifications, and because of their experience coming out of the military and they had done all they'd set up servers before they'd set up DNS servers, they'd secure systems on, you know, 500.

Uh, systems around the world. No, no degree, no certification, but they were brilliant. they were, and they had experience. They could do whatever task was given to them. And they would get a job from their connections and they were getting paid like crazy, the certifications and degrees, all that stuff for them came later.

I know a lot of guys like that, um, that, that happened to couple of my mentors, actually, neither a few of my top mentors had no degree, no certifications. Those, they were just extremely brilliant. Uh, and they , they just knew how to do stuff. It's crazy. Um, but that said they had experience. So the reason why they were able to figure out these problems is because they were thrown to the wolves.

They were a baby that was thrown to the wolves in the military. That's what they do. They just throw you in there and say, fix this, fix that. That's what they used to do. I don't know what they do now. It's been, it's been a while. experience, experience, experience. That's how you do it get experience. Um, and how do you probably think, how do I get experience volunteer?

Do you go to school? Do you still have an Alma mater? Do you still have a, a, are you still close to your college? See if you can volunteer at the school, try to experience is money. Okay. It's not money now. It's money in the future. Go volunteer at whatever community, um, thing that you do. You have you go to church volunteer there.

If you go to you have a high school volunteer there, volunteer to teach, volunteer, to help out set out, uh, set up a teacher's, uh, little network. If they have something there volunteer to be their assistant volunteer, to help out set up the, uh, the wireless volunteer, you know, and then do stuff on your own too.

Set up stuff in your own house to, to learn more. And spade says, uh, look into e-discovery. Is that like a training? Is that like a training session or something?

Okay. So I hope that helps out, uh, DD and also look into your own field. Like whatever field you're in, you might already have some experience, you know, a lot of times people say they have zero experience and especially if they're older people like kids don't have experience. You know what I mean? Like if you're just coming outta high school, you pro you really don't have any experience, but if you are, have been in the field for a while, like my man is doing, um, uh, administrative support that I'm sure he has experience.

I'm I'm certain he has it. He just doesn't know. Probably doesn't know what he has yet, but he, he has experience. All right, let me, there's some other questions here before I let you guys go. I've been on this for 48 minutes. I think I answered this one, but I do have some more stuff. Spade says it's like the practice.

And prep. It's like, it's like the practice and prep and preparing data and security controls for litigation. Some FARs work in it. Is that the kind of work that you've done? Oh, okay. E that's what e-discovery is. Oh, okay. I see what you're saying. And you in criminology, um, you might even wanna look into the FBI.

Um, I'm, you're probably laughing, but seriously, uh, because you sounds like you have, I don't know, you don't might wanna look into it. They have some really good, um, they have some really good programs in, in the federal government that, uh, where they'll teach you the federal, government's a different kind of beast.

Like basically they don't pay you a lot in the federal government. Like if you're a federal employee, I'm not talking about contractor, I'm not talking about like, I'm talking about U R E federal employee. What they'll do is they'll you sign up, right. And they'll give you all this training, but you have you're on like a contract.

I don't know if the FBI does this, but in the military though, you're on a contract, but they're going to give you so much training. The thing is, I know field agents have something similar to this and field agents get thousands and thousands of dollars in free training. And if you were to stay with them like a government agency for like three years, hell two years, you have, by the end of it, you have so much ex experience that, uh, you're so far ahead of most people in it field.

All right. Let me read some of these questions here. See if there's anything else? Um, let me see here. Somebody said, um, I don't have a secret clearance, but I have. I have a degree in it. Security I'm air force veteran, how can I get employment? So right here, all he, all this person has to do daily hip hop live.

If you, if you're watching this, you ever watch this. If you send me your resume, I might be able to help you out. Cuz if you have a it cybersecurity degree, if you were in the air force, um, yeah, I might be able to help you out if our, were you one option for you? I don't know how you feel about this, but one option that you have just from what I'm reading here is to become a us, um, a, a government, civilian government, civilian employee is one option for you and then just do it for a couple years.

And then after that, it also helps you to retain your total active federal service. So there there's that. So, yeah, that's, you're actually way ahead of, of most people, if you have these two things, so yeah. Send me your resume. I might be able to help you out.

Um, DEI says, thanks, Bruce. You are awesome. Thanks man. Appreciate that.

I mean, thanks, sir. Or ma'am uh, let me see. I'm reading more stuff here. I'm trying to find more questions. I might be able to answer right now before I go.

That's relevant to what we're seeing here. Okay. This one says

hi there, are there any sites that offer a free security com a free cyber security certification for free offers? A, a cyber security certificate for free, because I do not have the money. If there is a site that I hope you will put the link or tell me about it. Um, I don't know if there's any off the top of my head.

I don't know of any free ones. I know there's some that are pretty cheap. Like I tell used to be very cheap. I think right now that they're requiring that you take their they're requiring now that you take their training and I don't know how expensive their training is, but it's not free, um, free courses.

Let me see if I was kind of messing around looking for this online, and this is kind of what I found. One of 'em. I know that there's lots of free courses out there. One of which is my course, I got a couple free things and actually I've got a few other free things out there that you can try out. If you're trying to get into cyber security.

This is an entry level course right here. But then I've got some other stuff that's free. Some, some of my stuff that's actually paid, I'll have free things in that. So you might wanna still just go on there and check out free stuff, but there's other free courses online as well. There's some from Harvard, there's some from you'd be surprised.

So this is 15 best free online certifications, courses and training. Let's see what they're talking about here. There are several great sites that offer free online certifications among these sites are cor Sarah edx.com. allison.com code academy. TMY uh, U to me has some very cheap courses. Very, very cheap.

I don't know that they have free ones, but they might, um, general assembly and MIT open courseware to name a few. All right. So let's see what they're talking about here. So for programming. You've got a introduction to computer science at Harvard. You've got a Michigan university programming for everybody introduction for Python.

These are just courses by the way. Uh, you've got a, this is how you make iPhone apps. And I actually making apps, I learned to make apps from where was it, does a free couple free sites. And then some YouTube channels that I learned to actually code, uh, smartphone, um, apps with it's still, you know, I don't have a lot of experience with it.

I, I don't have a, I don't have a, a, uh, talent for it. but I was able, actually able to make one just from free courses online from YouTube and from just sites that walked me through it design. Okay. So they have some free design courses like Adobe certifications, I guess these are free certifications. For designing what though?

Um, it's cuz Adobe has okay here. It's it kind of mentions it here. Image manipulation, photo retouching, um, Adobe's tools, vector design, layout design. And I guess there's some, some actual certifications in, in that as well. Uh, graphic design specialization at Cal arts,

fundamental graphic design graphic artists can make money, even if they're independent

online marketing, let's see online. I know there's a lot of good stuff for online marketing. Google, I think has one. As a matter of fact, I believe is free diploma for web business development and marketing from Allison. There's marketing and digital world, university of Illinois getting started on Google analytics.

Yep. That's free. And I think you even get a certification off of this one and they also have one for ad sense. I think they got Google analytics, Google ad sense. And then they got some other stuff, learning a new language. This is kind of off the beaten path. I'm just gonna zip through this one, uh, entrepreneurship, new venture financing.

Okay. This is just business stuff. I'm looking for kind of technical this I'm writing, uh, communication, communicating strategically Purdue university. So yeah, there's, there's some stuff out there. I know that Google has some free courses. Amazon may have some free courses. , you know, I don't know that you'll, after you take those courses and those cert and you have that certification that you're gonna be able to just go out and get a job immediately or anything like that.

But to answer your question, yes, there's free training out there. So I'm gonna go ahead and leave this link for

I have, well, before I promote my own stuff, I'll just put, put this here. Here is some stuff, stuff I found

also Google and possibly,

possibly, where can I spell possibly? Um, Amazon might have some free, might have free certs and training. I also have free training.

You really need experience to get a job though?

Um, yeah, I don't even know how many of these are actually, I don't know if they're security, not sure if they are security related.

Hope that answers this question. Big, like big thumbs up. And somebody said D five D D D. If you, if you're a military veteran, uh, they're actually a few organizations that pay for your search. Yep. That's another thing. So this guy right here, I'm gonna go ahead and message him.

You may. So as a veteran, as a vet, you may have many opportunities,

opportunities, grants, and other stuff you can do to get more training and or positions.

I don't have a security clearance, but I have a degree in, I think he means associates, a master's degree, master's degree in it, security and I'm air force veteran. How can I get employed? Send your resume. And I will take a look, send my email address.

There it is right there.

Hey Al, how you doing? I'm just finishing this up, answering some questions that people have sent me. Um, but if you have any questions right now, I am. Free to open, uh, free to answer any questions at all right now, I got two job offers this past week from my dream companies. Your videos are the best. Thanks, Bruce.

Love to hear that. That's great news. Great news. There's there's lots of opportunities out there even now for it there, we just don't have enough people to do this work. Um, enough qualified people who are willing to put in the, have the patience to actually sit down and learn it. And that's why, like, most of our it's funny, like our, our nation, like is kind of like, not, doesn't seem appreciative of, uh, immigrants, but immigrants really are like something like 75% of the business is made here from immigrants.

I don't know if you guys knew that, but Google, Amazon, uh, name a company. Uh, they're probably made by either I an immigrant or the children of immigrants. Like I'm talking about, they were born, their parents are born in another country, came here, had they had kids and then their kids started Google. Yeah.

Larry look up, um, Larry Page in, uh, Sege Brin, at least one of them is from German is from Russia. I think Serge BRN is from Russia. His parents are from Russia. He was, uh, he may have been born here. Um, the dude who started, uh, uh, Yahoo was, uh, he's either a Chinese immigrant or his parents are a Chinese immigrant.

The, uh, the dude who started, uh, well actually Bezos fr uh, Jeff Bezos is, is, uh, his dad was from Cuba Bezos. Um, uh, who else? Uh, go down the list. Just go down the list. I mean, president Trump, himself, his. Great grandfathers from not from here. So yeah, I mean, immigrants, um, immigrants are like really a great part of, uh, this of the us.

And it's just unfortunate, more Americans don't take up engineering or mathematics, or I know stem, like we just, I don't know what's going on, but there's not enough Americans people born here, you know, that actually apply for these jobs. And so they're always, we're always wearing two, three hats. So I'm about to end this guys.

Um, I got more questions here. Um, some of these, I probably maybe I'll save 'em for next week and I appreciate all the compliments here. Great, great compliments. I'm glad this stuff. Some of this stuff is helping people. I appreciate everybody. Who's been watching me week after week. I'm gonna continue to put out more, more, um, content for everybody.

And, um, if you guys have time, check out my courses, it's at combo courses.com. I got a collection of, of stuff I'm building. I'm gonna do certifications, certifications take a lot longer to do, but there's free stuff out here. A lot of informative stuff I'm gonna, I've got more stuff coming real soon. Al says, uh, is because I don't have any certifications is because I don't have cert any certifications or anything.

I straight, straight cyber security for five years. Al do you mean that you don't, you, you haven't had a position or, or what, what was your, what was this? It seems like I, I caught this conversation in the middle of, of what you're saying here.

Is this a question you said it's because I don't have any certifications yet. Um, Cyber security for five years. Are you asking if, like, why can't you get a position or do you have a position or is, I'm not sure I understand your question.

So let me see if I can answer one more question before I cut outta here. Um,

our great says, just wanted to say, just wanted to say your interview tips and information has helped me to get an offer with a prominent government agency. As critical asset and vulnerability analyst. Thanks a lot. Yep. I've been doing this for a while, man. Um, this is just stuff that I've been doing and I've learned with trial and error and that's why this stuff works.

Um, it's just, this is honestly, I am in the industry currently. I'm currently in this industry and I'm just, I'm just saying what I've been through. I've I'm telling people how I've gotten to where I've gotten and the interview stuff. Yeah. That's just, it's just worked. It just worked over and over again.

So now I'm just passing it along to people who are willing to listen. So that's what this whole channel's about. That's what my combo courses.com is about. It's telling you literally what to do. Uh, let me see. Joe says, are cybersecurity labs enough experience to get a job? Um, I would say, uh, I would say yes.

And no reason why I say that is because is because, uh, it depends on the job. Number one. So if you're, if you're looking for a high level job, no, it's a lab is not enough. Uh, if you're looking for entry level job, and the lab allows you to a, the lab gets you in a place where you can either volunteer to get other experience, or you can get a certification, um, or you can get that, yes, that might get you to a place where you can get your foot in the door at an entry level position, doing something like help desk, junior level entry level help desk, or, or doing, uh, customer service where you're taking calls and helping people troubleshoot, uh, different issues like that.

If you, if you're looking in, if it's something like that, then maybe, maybe, um, but typically I can tell you. As a person who's actually done interviews on people. Um, them just, if I can't say it is not that we wouldn't hire somebody just off of their knowledge, cuz if they had really good knowledge, then maybe, but normally experiences what you're looking for.

Like the baseline is normally experience. And then the big question becomes, how do I get that experience? You're on the right track. If you have a lab in your house and you're training, or if you got the security plus or a plus certification, you're going on the right track. That's what you want to do.

You wanna crack those books? You want to get your hands dirty. You wanna set up labs in your house. You wanna tear computers apart, putting 'em back together. You wanna learn as much as you can. And then while you're trying to get your foot in the door in it, now that doesn't mean cold calling IBM necessarily.

Right? There's. Nowadays, you put your resume out there. You put what your experience is, but also if you happen to already have a job, you can get a lateral, uh, get lateral training or you can get a lateral move. You can, if you're already at a job, wherever it is, they have an it department go over to the it, it department and get friendly with them and start asking 'em questions.

Like man, I'm, I'm really trying to get into it. You'd be surprised how many geeks and nerds are there who want to talk your ear off about how to do it? Cuz we don't normally get those kinds of questions. We don't normally, I mean, I know me, I'm always anxious to, to train people.

View Details

See the video:

https://www.youtube.com/watch?v=ZATU40nemZg&t=2s

There are ways to get into cybersecurity and information technology. With little or no experience.

In this podcast, I explain how to do that. Some things I've learned along the way in my 20 plus years of experience. And we keep open topics. So we talking about a lot of different Now this one is from 2020. A lot of things were happening as you know, in 2020, the pandemic was happening with all these protests in America and all that stuff. I try not to talk about that stuff too much but it does come up from time to time i focus mainly on cyber security stuff so if you're interested in knowing how to get into it with little or no experience check out this podcast

Hope you enjoy this one. I I do weekly. I missed last week. Um, had some stuff going on, but here I am this week, and today we're gonna cover, we're gonna cover some questions that I recently got. So if you have any questions at, at any time throughout this, just feel free to ask and I will I'll cover it. But one of the common questions I I've been getting lately is how do I get into it with no little or no experience?

And so more than one person has been asking, for some reason questions go in sets like somebody will ask me and then like three other people ask me the same question. So I would like to cover that what, um, and give you some resources and stuff like that. But before we. I should let you, uh, I should, I just want to give condolences to, to, to the, all the people who have passed away, do the COVID 19, I'm still bunkered in still, um, uh, staying at home and stuff just like I'm supposed to do.

And hopefully you guys are staying safe as far as the job market is concerned. Uh, it's pretty much the same. It's kind of a freeze going on with hiring new people that said, I am still getting job offers, uh, and opportunities in my inbox. Just not as many, not nearly as many as I was before. And also, um, like the company I'm working for, they have kind of a hiring freeze, but they, they did hire some people like at the tail at the very beginning of this COVID 19.

So we actually do have new people, but they're kind of slowing it down. Cause we don't know financially. where the wind's blowing as far as the company and as far as clients and stuff like that. So that's kind of what's going on with COVID 19. And if you guys, uh, have any anecdotal, uh, personal experiences on what's going on in your wherever, you're from feel free to let us know.

Um, you guys are looking at the same data that I'm looking at, so that's, what's going on with it. And let's just go ahead and dive into this. Let me see if I could bring up the questions I've been getting. And, uh, yeah. So several people have been asking me this question right here. I dunno if you could see this, but I'm just gonna go ahead and read it and it says, um, Hey, what if you have zero experience and just got your security plus cert everyone seems to want new graduates or people with five years of experience.

Also, I don't have a security clearance. So I gotten this question several times, um, from several different people. From all over, uh, from, from LinkedIn, from my email box. Uh, and then there's a couple other people who have, who have asked that very question. So I'm gonna go ahead and answer it to the best of my ability.

And bef before I start on this, I should let you know that I actually have a course that talks about this very thing. So if you go to combo courses.com or you can go to security, compliance, dot, think.com, combo courses.com, easier to remember. You'll see some courses that I have, one of the free courses that I have that talks about my, my perspective on how do you get into it?

How do you get into cyber security with little or no experience? And I talk about it here. I break everything down. I talk about what I would do if I was in like, starting from scratch, knowing what I know now, what would I do? um, and this is from an insider's perspective, what would I do to get in? And so here's some of the topics that I cover.

And so very briefly, I'm gonna summarize some of the stuff that's in here, but if you're interested in this, it is free right now. Um, the reason why I made it free recently is because people are hurting. People are wanting to change and I can see the service industry and several other industries are destroyed.

I'm fine. My job's fine. Um, even if I lost my job right now, I'm certain I could get a job very quickly. It's because I'm in it. And I realize that I'm, you know, I'm a very privileged growing field. And so I encourage a lot of people who, who are looking for a stability to, to get into this field because it's, we definitely need people.

We need people with experience. We need people with, with patients. Um, and you might be surprised you might be in an industry that compliments getting into it. A lot of people I think are kind of shook by all the technical stuff you have to know. But to be honest with you, there's some aspects of our career field that are not very technical and I will talk about those things.

So there you go. There's a free course for you. If you want to jump on there and then I've got some other paid stuff that's also in there, sign up is free. The course is free and it's to help people out. So there you go. All right, what would I do? What would I do? And I got some stuff lined up to tell you like other people's perspective on it.

What, what I would do is number one, I would look at my current experience. Cause as I said, some experience that you may have in the service industry, in the medical industry, in banking, whatever you do it, may you be, might be surprised how much it could compliment getting into it. And I'll give you a couple examples.

In retail, let's say you work retail or your customer service. You're a front facing person who a customer comes up to and has to interact with the way this can help, can help you if you're getting into it, is that a lot of ITP professionals are not good with people. They're not, they're just not good at talking to me, myself included.

I'm I'm I mean, I'm now I'm damn near 50, so I, I know how to speak. I've been, I've done so many things. I've been baptized by fire so many times I've talked, you know, I've done briefings for generals. I've done briefing for, uh, C level execs. I so many times that now it's just, it feels natural to me. I still get nervous and stuff cuz it's just not my I'm not an extrovert.

Uh, so what I'm getting at is a lot of us, it professionals we're good at technical stuff, but not so good. Usually at face to face interaction. So if you're at a customers facing. Um, whether it's retail or if it's, uh, if you're working in, um, the front, your clerk store clerk, or even, uh, you work at McDonald's or anything like that, you have to interact with people on a regular basis.

You have to have a, you know, you have to be professional at all times. You have to approach things in a certain way, from the perspective of the company, you know, you have to maintain this face. That right there already is way above what a lot of it professionals. Skill sets entail. Um, a lot of us don't have it.

We just don't, we're just not very, we don't have a we're just not good at it. You know, so right there, you already have a skill set that is very useful for help desk for customer it customer service, believe it or not, there's an it customer service that is still alive and well in the United States. Not just in India, not just in the Philippines, not just in the us.

We have a lot of customer service representative spots. Um, and as, without naming any names without, without naming my clients or anything like that, I was. Few weeks ago, maybe a couple months ago I was, uh, at a client's location and one of our client was saying, yeah, we need, we need it. Security, not, we need it customer, uh, customer service people, and we just can't keep him.

And he was, he was this guy explaining like, man, we just really need, you know, so there is, there are jobs out there for customer service and sometimes some of the entry level positions will train you on the job and you have like a script, uh, and you'll have to interact with people, but they have a script and a walkthrough of how to fix certain things.

Um, so if I was to start now, if I starting off had no experience at all, what I would do is look at my own skills that I already have. So that's one, I just named one skillset that you probably already have. If you're a customer, uh, customer service representative, that's actually a very good skill to have.

Now you still have to learn the basics of it. You still have to learn. Uh, things like what's in the, at the, um, compt a plus certification which breaks down what, what goes in the hardware and software, how it all works together. You still have to have a basic understanding of that stuff. Um, if you're getting in the it, right.

Um, another skill set that you might have is if you've worked in a bank, so banks, their security and their terminology is different. They call assessments, auditing, you know, they, they are always looking for auditors. Somebody who's gonna look at comp. They kind of see the world from a, like a CPA's perspective, you know?

So it's, uh, different terminology, different frameworks, like security compliance frameworks that they have to meet, that banks have to meet a certain compliance. And then you might have to have compliance for PCI. Like that's the card readers. Um, there's Sarbanes Oxley that you might have to learn. There might be some things that you already know that I don't know, Haven never.

Work directly in a banking environment. You know, I've done assessments and stuff for different organizations, but not, I've never worked for a bank. You know, I've never been an employee there. So you may already have some skills. You may already know some terminology. You may have already taken security, basic security training that is very specialized for you as a teller or you as a loan officer or you working in a financial sector, you probably have some skills and some terminology that I, I don't even have with 20 plus years of, um, security and it experience.

So that's another one. Another one is he, the healthcare industry, healthcare industry has, uh, different frameworks and different practices that they use on a regular basis. That is very important in their field, which is like HIPAA is one of them and protecting, uh, the. Healthcare information. So there's a whole realm of things.

You've probably already gotten the training. If you work in the healthcare industry about what HIPAA is and how to protect, uh, electronic, uh, private healthcare information and all those things. So you already have some skills, some of that stuff you can actually literally put on your resume and it's legit.

If you, like I said, customer service, that's legit. Um, healthcare, if your healthcare industry, you know, HIPAA you've been to this or that class, you've done this or that training you've protect this or that per, uh, personnel's information that's you could put that on your resume. Um, what else did I mention banking?

Same thing. There's certain things that you already have certain skills you already have. You can literally put in a resume and it will, uh, help you now that said most people are not gonna, uh, hire you without any. information. If you don't have, um, a it certification, if you've never taken a class in it, if you don't have any it experience whatsoever, you gotta go out and get it.

So it's, that's the thing you gotta go out now, if it was me, what I would do is I would go volunteer. If I would work. If I work at Walmart, you know, I would, I would see if the, it guys at work in Walmart, there's it guys there. See if I can volunteer my time to work with them, knowing that that experience that I get from volunteering with them can be put on my resume.

You know, if you're, if you, or excuse me, if, if you're allowed to get in there and do it, then yeah, they're gonna, you can put that. On your resume. Um, if you go to church, like church might have an it, like they might want to hook up their wifi server there, you, you might volunteer to help 'em out, uh, wifi, uh, hotspots or whatever, you know, they have there, you might volunteer to help them out.

Um, so there's a lot of volunteer stuff that you can do. You gotta see what's on your resume. Put that stuff on your resume. Um, see what get, dive into it. Learn its another thing I would do. I would hit the books, get in there, start studying, uh, to learn how this stuff all works together. That's what I would do is in entry level is not gonna be overnight.

It's gonna take some hard work, but what I wanna do right now is look at some tips that some people have brought up here. This article right here brings up a couple of things from leader quest.com. Leader quest online.com is where I'm at. It says seven tips for getting into it. With zero experience. Let me see if there's any of this that I can agree with or stuff that I think you should know, um, reexamine and apply for your past experience in it industry.

Yep. That's what I just said. Um, and it's just to kind of read it real quickly, like a little part of it. It might be, it might seem like to you, like you have none, none of the skills that you need, but soft skills can be surprisingly important. Exactly. Soft skills are like non-technical skills because, uh, we need people who can talk to people.

You know what I mean? Customer service people are very good at talking to people. They, they have training and they, it says, for example, if you were looking into starting to help desk position, a common entry level, it role, uh, things like communication, customer service familiarity with Microsoft office.

Yeah, those skills are, you can put on your resume. So right there, you know, that's one, use your past skills, put those on your, find out and see that's the reason why you have to dive into it. Cuz you don't know anything about it. Once you start diving in, you'll start finding, well, I've done this before, put it on your resume.

If you've done it before in a professional. So you don't even know, you don't even realize how experienced you already have in it, or even it security. If you've ever, uh, done it, training in your company, if you, if you've ever been in any kind of company and they gave you access to a computer more than likely what they had to do is sit you down and say, okay, um, here's the things you don't do on our computer, right?

When you log into this computer, when we give you this count, here's the things you don't do. So you have to have some kind of standardized security awareness training. Um, some of that training that you've had to use. Like, whether it's you, uh, create, you had to have an account made, you had to, um, do anything with the computers.

You need to look at what you've done and put that on your resume. But as you dive into it, you'll be able to realize things like, okay, audit logs are super important. Logging in, in a, an account creation. Having an account is super important. Uh, training is super important. Policies are super important.

There's certain aspects like when you look at secur, normally from somebody from the outside, looking in, they look at a it person, all they think about is a person taking a computer apart, putting it back together, or a person staring at a computer and typing stuff into the computer. I don't even know what, what they're typing.

there's so many things that go into this field. It's so big. It goes into all often all these different, uh, categories and some of 'em are not even technical, to be honest with you. You're not even that tech one example of. Just kind of go off on a tangent here is, is called project management, proj, and also known as, uh, program manager or project, uh, project manager.

Those two basically are very needed in many different, um, it roles, uh, it units will use a program manager or a project manager to manage giant projects that are going on. They don't have to be technical. They have to know very little about it stuff, cuz they're not diving in the weeds. They don't have to know.

They have to know some of the terminology. They have to know how to work with people and stuff like that. And that's my wife right there. Gimme a second here. So yeah, they have to know certain things, uh, related to the project, but not, not super. They don't have to be super technical because they're not in the weeds.

All right. So let's keep going for, with this thing. Uh, get. It certifications. This is actually something a lot of people do when they contact me. They say, Hey Bruce, I got this a plus certification. How can I get a job? I've been applying for jobs and I can't get one. Um, it's actually a really good step forward because it's showing that you have the initiative it's showing that you have learned, you're learning a common body of knowledge.

Uh, and then you should start to, you'll start to realizing things you've actually done. Like if you actually take the, a plus certification, you actually take the security plus certification. Any of those certifications, you'll start to think. Well, you know, you'll be reading through it and studying and stuff and you'll be realize, damn, I've done this before.

And that's the kind of stuff you wanna put on your resume, you know? So there's so many different aspects of it. As you learn more, you'll, you'll start to realize what you've already done. So it kind of mentions a couple certifications here. So entry level certifications, like the I L certification compt security plus network plus security plus.

These are all good entry level certifications. And some people will hire you just off the strength of that, but they do want you to have some level of experience more times than not, but some entry level jobs. If you just have one those certifications, they will hire you. Um, said you have to apply for certain certifications.

You can't apply for a, uh, junior level cyber security, uh, position with a, just a security plus and no experience. It won't work. Um, it says junior, so you're like, oh it, well, it's a junior certification. No, listen. So there's different tiers here. All right. So, and I wish, let me see if I can show you like a visualization so you can get an idea of the tier system that you have.

I till kind of does a pretty good job of showing this. Let me see if I can find that I till is like, um, A library of different processes. It maps out different things that have to happen within an information technology, um, within the information technology and in any large organization, they have this great breakdown of the different tiers that you have.

And I'm looking for something there's like a lot of maps and stuff here. Here's what I'm, lemme just show you what I'm looking at here. They have this really good breakdown of the different levels that I'm, I'm thinking of right now. That is really good at showing you like where you, where you should really start because you can't start in the middle and with a, just a security plus or an a plus you gotta start from the beginning, think of your own career, you know, think of your own career.

Somebody can't just walk in off the streets and then suddenly be in the middle. You know what I mean? Um, let me see, this looks kind of like what I'm talking about. Yeah. This kind of looks like it. Let me see if I can get a better picture of this. This map is kind what I'm talking about. So here's ital and it breaks down different aspects of an organization that has it services.

Um, and that's, that's what it's all about. When you start off you're you're not starting in the middle. You're not starting here. You know what I mean? You're not starting. So a lot of jobs that you, that people say, Hey, I've been applying for all these jobs and I can't get in a job. They're applying for mid-tier positions.

Like they already know, okay, I'm not a manager, I'm not a middle manager, man. I'm not gonna be able to. But what they don't realize is that the job they're applying for a lot of times are middle. Level, you're gonna be on like a service desk type position. You're gonna start from the bottom. This is where most people start.

Even if you go on a program manager, which has, which has no technical, very little technical skills, I should say, cuz you do have to know like office when Microsoft office and the Gantt charts and stuff like that. But which you can learn very quickly, but even those jobs it's non-technical you still have to start from the bottom.

And so that's what this is kind of kind of showing here. The service desk has a many different layers on top of it. Even service desks gets extremely advanced all the way to management, you know, who answers directly to the CIO and, and higher management positions. But you gotta start from the bottom. And how do you find these positions?

Let me, let me show you. So if you go to just go to Google, like we don't have to get fancy. Let's just go to Google. If you type in entry level, um, project manager, let's say we were going for a project manager job, just Google. It's gonna go on your local, wherever you're from. It's gonna start from there.

And you'll have a bunch of entry level positions starting from where you're from. If you're willing, willing to move, you'll find way more positions. If you're willing to move. If you're, if you're flexible in, in location, then it'll, it'll be some of these project management jobs are actually, um, or actually, uh, work from home positions as well.

You can get, find these from, uh, work from home, but here's a couple of entry level project coordinator, project manager type positions. They're gonna tell you what they expect from you. And most of 'em are, look this one, one to two years. You know, you can apply for it, but they're saying, look, we expect you to have some experience.

We expect you to have this kind of bachelor's degree, you know? So there are still things that you caveats that you need to, to, to have. Um, so that, yeah, that's just to give you in a nutshell, like that's a couple things on the list of a person with no experience trying to get an it, let's just read a couple more here.

Your degree in another field may be a huge asset and this is true. Like a lot of positions in it will actually take science degrees. They'll take, uh, engineering degrees that are not necessarily computer based. And let me just read a little bit, says you may be tearing your hair out with regret, wondering why you used all your time in college to get a degree that isn't helping you and your quest for a long term career.

Many employers are more. Inclined to offer you a job because you have accomplished that feat and earning a degree, instead of focusing on how your degree may have cost you money and, and blah, blah, blah, um, uh, focus on ways your degree can help apply for moving for a degree moving forward in the it career field.

And this is, yeah, I would say this is true. Like, especially if you have a technical degree, not all degrees are gonna help you. You know what I mean? If you have a, if you have an, um, art degree, it's probably not. I mean, unless you're doing like a AutoCAD or something, or if you're doing engineering and you need to learn 3d modeling, then that might art might help you.

But if you're doing straight up it fixing computers, or if you're, you know, it it's science degrees might help you, engineering degrees might help you. just being completely honest. Not all degrees are gonna help you out, but they're saying here in this article, a philosophy major, I think this is a stretch philosophy major, uh, has a deep understanding of a logic and unique way of approaching challenges.

I, I guess I, you know, I don't know about that. I just tell you from my experience, normally, when companies are hiring people, they're looking for technical type degrees, philosophy degree. I don't know that it's gonna help you. So I, I kind of disagree with this portion, what you could do. If you have a major in philosophy, you have a master's degree in philosophy, it could help you to get an it degree, go back to college, get a minor in it.

And you, you know, you're doing less classes, but you're gonna, you're gonna still get, uh, your degree faster provided they, they accept your, your previous credits. Okay, so be open to start from the bottom. This is absolutely important. Um, you gotta start from the bottom, right? If you have zero experience, you gotta expect to come in and learn so super important.

Um, you can't start from the middle and think you're gonna get a job. You need to type in entry, go to Google type in our LinkedIn or wherever you're at type in entry level position and this entry level position. And that, um, especially the thing is if you have, if you were trying to get an entry level, position and network engineering or net, uh, uh, beginning in, uh, security, it's probably not gonna happen cuz once you get to networking or servers or if you get it's kind of a, the next step, it's another tier.

It's another support tier. That's very specialized. You have to start from the bottom first, which is help desk, customer service. you know, junior level help desk positions, uh, is the best way to get that experience, but you can also volunteer too. Okay. So don't forget the power of networking, talk to people, you know, if you happen to be at a job, um, and you, you know, there's an it department and you want to get experience, you are you're in a gold mine, especially if the company allows you to help out.

You can. Even, what I would do is if I was so hungry to get into this field is I was willing to work extra just to learn. Not to get paid, not over time just to learn cuz I realized the value experience and it's really paid off in the long run. It's a long term plan that I had and it worked teach yourself relevant technical skills also very important.

Absolutely. You gotta get in there and, and once you do that, you can actually use that to put some of that stuff that you've learned on your resume by saying familiar with this, familiar with that. Meaning. Yeah, I've never done. I've never used this thing before, but I'm familiar with it. I've read about it.

I have a lab at home that I worked on. I'm familiar with it. You know, you can even say that you have a lab in your house where you take care of a, uh, a Splunk system that's collecting logs on 45 different virtual systems. You know what I mean? Like you can, you can put stuff like that on your resume. Um, look for crossover positions.

Yep. This is what I was talking about. You happen to be in a field. They might have a, an it workers there that you can go and ask them or ask, see if you can laterally, move over there and start learning stuff. Some companies will allow you to do that. So a lot of the stuff that they talked about in here actually have talked about in this free course, it, if you happen to be in entry level and you have no experience, this is a great opportunity for you to, uh, dive into this.

It's about four hours. I think of video and, and, uh, slides, presentation and stuff like that. You can watch it at your leisure on all devices. Go ahead and go check it out and it's free. All right. So let me see, I'm gonna switch gears here. And there's some people been watching me. Thanks guys for watching.

Appreciate you guys. I got, uh, spades 93 says how can, how can anyone, how can one established. Uh, two to three years in administrative, how can one established a bit with two to three years in administrative support, get, uh, transitioned into cybersecurity position. I'll be taking my security plus exam in two weeks.

Okay. This is right up. What we're talking about. This is great. So this is exactly. If you're still watching this spade, this is for you. This is exactly what I'm talking about. So you're in a administrative supportive position. What I would do is number one, just like this is number, and this is what I'm talking about in this course.

This is why this course is IPO is, is, uh, important. Cuz I, this is exactly what I I'm saying. Okay. If you're a beginner, you have no zero experience. Here's where you start. If you were an it geek, meaning, meaning you don't, you've never held a position, but you do, you do stuff online at your house. You like to mess around and tinker around with things in your home.

I I'm saying like, here's how you evolve from that point. Cuz you need to go to the next level. If you're a beginner, you need to become an it geek. If you're an it geek, next level is a security. Plus get those courses in there, start volunteering places and become an it professional. And then once you're an it professional, you start to focus in on whatever field you can go into forensics.

You can go into cyber security, you can go into, uh, cyber and analyst, work, threat analysis work. There's so many different aspects and so many different places you can go once. You're an it professional and to, uh, hone in your skills and have one specialized skill. Not just cybersecurity by the way. So yeah, so exactly what I'm talking about is for you.

If you're an administrative support person, this is what I'm talking about. You already have soft skills that, um, That you can apply to your current resume. You probably, even as an administrative person, you may even have technical skills. You need to see the thing is, as you dive into security, plus, as you get into the a plus certification or whatever certification as you start cracking those books and start doing, looking at the common body of knowledge that goes in the it, you'll start to realize, man, I've done that before you wanna put that on your resume.

Like as an I'm trying to think of an, an administrative support person, like the kind of things that they might do is like personnel security. So personnel security, meaning you vet people who come into your, and I'm just guessing what your job is. So bear with me. So a person who, a new person, a person who's coming in off somewhere else, they're coming into your organization.

An administrative support person might be in charge of doing things like personnel security, meaning they conduct like a brief background check. They maybe they. Call their supervisor and call that's personnel security. That's something that you can legitimately put on your resume to say, yes, here's some security I've done.

What other kinds of administrative support stuff have, uh, that I could point to would be kind of like, um, uh, security awareness training. Everybody has to have that. I'm sure you've had some kind of cyber security awareness training, or if you've ever caught an email from a, from a, uh, fishing attack, that's another thing that you might have done.

Like there, a lot of times organizations will do their own fishing attacks or actual fishing attacks will come into your email box and you caught you spot one. Like this, this email looks weird. I'm gonna send this to the security support team. Guess what? You could put that on your resume. You know, that's one thing out, it's a small thing, but the thing is you put enough of those small things that you've done on your resume and it looks like.

They're, it's not that you're painting some fake picture, but you're saying here's the actual exposure that I've had in it. Another thing that you may have helped out is like, if you had to stay a while with the it department to help them to load patches or something, maybe they want you to stick around and, uh, reboot your system and they're, and you're, so you're actually coordinating and assisting them to, uh, put patches on a, on a system.

Uh, another thing like that, this article actually mentions and is also in my course, my free course is that get in the certifications does help. I do agree with that. It does help. It's not the end all be all. You definitely want. Don't wanna start there, stop me. You don't wanna stop there. Um, and starting from the bottom.

So all of these things help. Another thing is, um, using, they mentioned it in here. I think they said it was called. Teach yourself relevant skills. Yeah. We already know about that crossover positions. Yeah. This is a good one. So if you're in an administrative position, there's it guys you might wanna try to get in there, like the even volunteer, uh, a couple hours for free, like be like I'm off right now, but I wanna learn this so bad that you go in there coordinate a time.

Like you don't want to, you, you wanna be on their time. Right. So if there's like a swing shift and the it guys are there at get permission to legitimately go in there and learn from them. Or even do work with them that is even better. Cuz you can put that on your resume and, and every all experience equals money in it.

All right. So he says I've triage computer issues, uh, at my position as an AA. Exactly. So that's the kind of stuff you can put on your resume and that's really good stuff. That's the kind of stuff that you wanna put on your resume. Okay. I've got some other questions here. DD says, hi Bruce. I have been applying for jobs for over 15 and over 15 interviews and still no job offers, what am I doing wrong?

So DD, I would have to, if you tapping to still be on, um, I get this a lot from people saying I've applied for all these jobs and from my position. And I, I, I realize I have a kind of a, um, filtered position. It's kind of, um, through my eyes. There's so many job openings. I it's shocking when people say that, but I don't know your context.

Like, I don't know how much experience you have. I don't know what you're applying for. I don't. So what you want to do is you wanna match your skillset. Let me just see if I can bring up what I was looking at before you wanna match whatever skillset you have with positions that are out there. So in this example, right here are these jobs here.

I'll use this one. I just opened up here, right? This is for a junior project analyst. Sorry, a junior project engineer, right at Kelly services in Colorado Springs, Colorado. Excuse me. Now look at this job title. What we just read project engineer. They are looking for three to one to 2, 1, 2, 3 years of experience.

They're looking for a bachelor's degree, they're looking for necessary 3d modeling design. So here's what I do.

Here's my technique. What I do is I look for jobs that I have the skills for. Um, so for example, this says junior level one to two years of experience, one to three years of experience, right. As a project engineer. Okay. I make sure I have that education, uh, education level bachelor's degree in these items.

Right. I make sure I have that. I match myself up with that career path. No, you might be thinking well, Bruce, I don't have a year experience. I don't have 3d modeling. I don't have, are you telling me that I'm supposed to go get this job get three years? Where do I get the three years experience? Okay.

Listen to what I'm saying right here. Check this out. So you have to find a job that already matches the skills you already have, right? Not, not necessarily, if you're just kind of shooting around, if you're just like throwing resumes out there, that's not going to work as effectively as finding somebody you already match up with you already have these skills, find somebody who matches that same skill.

That's all I do. That's all I do. And now, nowadays you got tools like Google. This is cool. This is a cool little tool and everything, but the best tools are ones that have built in job search algorithms that are built specifically for that. Google's very good at search. Very good at research. Awesome way to, and I would definitely put that in your toolbox, but linked in is.

Incredible LinkedIn, you can do exactly what I'm telling you to do. Like, what you do is you fill out a LinkedIn profile, right? Fill it out in complete completely. Then what you now have a whole course about how to do it. What my exact techniques, in what keywords I use tools to find keywords, all that kind of stuff, go to convo courses.com.

You'll find it there, but let me just summarize some things that are very important for you right now for free. So what you do is you take your current skills and I'm assuming you're an it guy right now. If you're, if you're a NBE, that's totally different. That's what we were just talking about. That's entry level, that's volunteer work.

That's something else entirely. If you have it experience, take your resume. Match your resume. What skills you already have with something you find on LinkedIn on career jet on indy.com on dice.com on all these different algorithms, search engines, um, that are specialized in jobs. That's what I do. And it works.

So let me just give you another, let me just show you what I'm talking about here. I'm gonna find one of my real profiles out here on LinkedIn. Let me just, I just gotta sign in real quick. If I could sign in what's going on here, why is it lead me all these different directions? Okay, here we go. So check this out.

Here's my real LinkedIn profile, right? And I, I've not looked at this in a while, so, but here, I hope there's no surprises in here, but here's my real LinkedIn profile right here. And I feel it completely out. I don't even have that many connections. Here's the thing. Many people I know have way more connections than I do, but somehow I get all of these very targeted positions.

Why, why is that? Cause I feel this completely out from top to bottom. So once I do that, this, this tool linked in finds jobs for me, it lines me up and suggests certain jobs for me. When I do a search, if I was to type in, um, it security, it's gonna find jobs in my location. It'll find jobs that, um, that accept my degree, accept my certifications.

It's not blasting everything out. It's, it's looking for stuff that's within, uh, 30 miles from. So there's tons of stuff. And it also shows here's another little gym. It also shows other people with my similar skills, people resulting in it security like this guy, if I was a type click on this guy's resume, I'll see all the stuff that he does now.

This is the owner of black heels information. So he's not what I'm talking about. um, a better job description would be, uh, it securities too. Generic. I'll just say, okay, let's just, let's just go risk management framework. This is pretty specific, um, analyst or engineer. This is very specific to what I do.

It's a very, it's a very specific thing. Another thing I could have typed in is cybersecurity engineer, cyber security analysts. There's lots of different things I could have typed in it. Security is too broad. All right. So here's some guys here. we're very closely aligned with what I do that are kind of in my field.

I could click on any one of these guys' resume to get a better idea of what I should be putting on my resume. What's working for them. Why are they like the top people popping up? Another thing you can do is go into actual jobs, going to actual jobs and look at what they're looking for, examine what the things that they're looking for in when they say they want you to have, what, what are they looking for experience with risk management framework.

And, and this is, this is my field, but you could be whatever your field is. And you're saying de de says, no, no experience previous experience. I have. a BA in criminology and have an ma in strategy and security administration. All right. So that's the reason why right there, you don't have any experience.

It's really hard to get a job with no experience. So what I would do if I were you, is I will type entry level it, entry level it. And I would start from here. I would start from looking at entry level it jobs. What you wanna do is get in at a, get in, at a low level and then start gathering as much. It's not gonna pay.

Well, all right. It might be shift work. It might be 30 miles farther than you want to drive, but you gotta think long term. So what I mean by that is where do you want to be in five years, in five years from now? What kind of career do you wanna have? What kind of career and what path. Are you trying to get into that's what you do.

Just like with your degree, you have a master's degree in strategy and security administration, which will help you, by the way, you have a bachelors D degree in criminology. What was going through your head when you got those degrees? You know, it's a, a four to six year degree, right? You had to plan it out.

It's the same thing with this career path, you gotta be like, okay, in four years, I wanna do, um, forensics that'll match great with my criminology stuff. Forensics is, is a great match for me. Where can I get my first entry level, position experience doing forensics? That's how you gotta think. So what you do is, okay, forensics entry level forensics, which who knows it might, I don't think we're gonna find it, but it's worth a try.

I can't even spell forensics entry level per forensics. Did I spell it right? I guess I did. Okay. So yeah, so here's some entry level positions, uh, cyber security analyst, entry level, uh, security analyst. So you have stuff here. Um, and I don't know that this is what you wanna be. Hopefully you're following along with me.

This is kind of what you wanna do. Entry level is only one keyword or key phrase that you could use to get in. Really. You want any kind of entry level position just to start. Once you get your foot in the door, you can then start putting that on your resume experience equals money experience equals stability.

All right. I can't stress. It enough. A lot of people who contact me, that's the same thing. It's the same story, Bruce. Um, I have no experience whatsoever. I've applied for a hundred jobs. I can't find a job experience is king experience is better than a D than a degree experience is better than a certification.

Um, everything else is just icing on the cake experience is everything. Um, I, I knew people who, who had no degree, no certifications, and because of their experience coming out of the military and they had done all they'd set up servers before they'd set up DNS servers, they'd secure systems on, you know, 500.

Uh, systems around the world. No, no degree, no certification, but they were brilliant. they were, and they had experience. They could do whatever task was given to them. And they would get a job from their connections and they were getting paid like crazy, the certifications and degrees, all that stuff for them came later.

I know a lot of guys like that, um, that, that happened to couple of my mentors, actually, neither a few of my top mentors had no degree, no certifications. Those, they were just extremely brilliant. Uh, and they , they just knew how to do stuff. It's crazy. Um, but that said they had experience. So the reason why they were able to figure out these problems is because they were thrown to the wolves.

They were a baby that was thrown to the wolves in the military. That's what they do. They just throw you in there and say, fix this, fix that. That's what they used to do. I don't know what they do now. It's been, it's been a while. experience, experience, experience. That's how you do it get experience. Um, and how do you probably think, how do I get experience volunteer?

Do you go to school? Do you still have an Alma mater? Do you still have a, a, are you still close to your college? See if you can volunteer at the school, try to experience is money. Okay. It's not money now. It's money in the future. Go volunteer at whatever community, um, thing that you do. You have you go to church volunteer there.

If you go to you have a high school volunteer there, volunteer to teach, volunteer, to help out set out, uh, set up a teacher's, uh, little network. If they have something there volunteer to be their assistant volunteer, to help out set up the, uh, the wireless volunteer, you know, and then do stuff on your own too.

Set up stuff in your own house to, to learn more. And spade says, uh, look into e-discovery. Is that like a training? Is that like a training session or something?

Okay. So I hope that helps out, uh, DD and also look into your own field. Like whatever field you're in, you might already have some experience, you know, a lot of times people say they have zero experience and especially if they're older people like kids don't have experience. You know what I mean? Like if you're just coming outta high school, you pro you really don't have any experience, but if you are, have been in the field for a while, like my man is doing, um, uh, administrative support that I'm sure he has experience.

I'm I'm certain he has it. He just doesn't know. Probably doesn't know what he has yet, but he, he has experience. All right, let me, there's some other questions here before I let you guys go. I've been on this for 48 minutes. I think I answered this one, but I do have some more stuff. Spade says it's like the practice.

And prep. It's like, it's like the practice and prep and preparing data and security controls for litigation. Some FARs work in it. Is that the kind of work that you've done? Oh, okay. E that's what e-discovery is. Oh, okay. I see what you're saying. And you in criminology, um, you might even wanna look into the FBI.

Um, I'm, you're probably laughing, but seriously, uh, because you sounds like you have, I don't know, you don't might wanna look into it. They have some really good, um, they have some really good programs in, in the federal government that, uh, where they'll teach you the federal, government's a different kind of beast.

Like basically they don't pay you a lot in the federal government. Like if you're a federal employee, I'm not talking about contractor, I'm not talking about like, I'm talking about U R E federal employee. What they'll do is they'll you sign up, right. And they'll give you all this training, but you have you're on like a contract.

I don't know if the FBI does this, but in the military though, you're on a contract, but they're going to give you so much training. The thing is, I know field agents have something similar to this and field agents get thousands and thousands of dollars in free training. And if you were to stay with them like a government agency for like three years, hell two years, you have, by the end of it, you have so much ex experience that, uh, you're so far ahead of most people in it field.

All right. Let me read some of these questions here. See if there's anything else? Um, let me see here. Somebody said, um, I don't have a secret clearance, but I have. I have a degree in it. Security I'm air force veteran, how can I get employment? So right here, all he, all this person has to do daily hip hop live.

If you, if you're watching this, you ever watch this. If you send me your resume, I might be able to help you out. Cuz if you have a it cybersecurity degree, if you were in the air force, um, yeah, I might be able to help you out if our, were you one option for you? I don't know how you feel about this, but one option that you have just from what I'm reading here is to become a us, um, a, a government, civilian government, civilian employee is one option for you and then just do it for a couple years.

And then after that, it also helps you to retain your total active federal service. So there there's that. So, yeah, that's, you're actually way ahead of, of most people, if you have these two things, so yeah. Send me your resume. I might be able to help you out.

Um, DEI says, thanks, Bruce. You are awesome. Thanks man. Appreciate that.

I mean, thanks, sir. Or ma'am uh, let me see. I'm reading more stuff here. I'm trying to find more questions. I might be able to answer right now before I go.

That's relevant to what we're seeing here. Okay. This one says

hi there, are there any sites that offer a free security com a free cyber security certification for free offers? A, a cyber security certificate for free, because I do not have the money. If there is a site that I hope you will put the link or tell me about it. Um, I don't know if there's any off the top of my head.

I don't know of any free ones. I know there's some that are pretty cheap. Like I tell used to be very cheap. I think right now that they're requiring that you take their they're requiring now that you take their training and I don't know how expensive their training is, but it's not free, um, free courses.

Let me see if I was kind of messing around looking for this online, and this is kind of what I found. One of 'em. I know that there's lots of free courses out there. One of which is my course, I got a couple free things and actually I've got a few other free things out there that you can try out. If you're trying to get into cyber security.

This is an entry level course right here. But then I've got some other stuff that's free. Some, some of my stuff that's actually paid, I'll have free things in that. So you might wanna still just go on there and check out free stuff, but there's other free courses online as well. There's some from Harvard, there's some from you'd be surprised.

So this is 15 best free online certifications, courses and training. Let's see what they're talking about here. There are several great sites that offer free online certifications among these sites are cor Sarah edx.com. allison.com code academy. TMY uh, U to me has some very cheap courses. Very, very cheap.

I don't know that they have free ones, but they might, um, general assembly and MIT open courseware to name a few. All right. So let's see what they're talking about here. So for programming. You've got a introduction to computer science at Harvard. You've got a Michigan university programming for everybody introduction for Python.

These are just courses by the way. Uh, you've got a, this is how you make iPhone apps. And I actually making apps, I learned to make apps from where was it, does a free couple free sites. And then some YouTube channels that I learned to actually code, uh, smartphone, um, apps with it's still, you know, I don't have a lot of experience with it.

I, I don't have a, I don't have a, a, uh, talent for it. but I was able, actually able to make one just from free courses online from YouTube and from just sites that walked me through it design. Okay. So they have some free design courses like Adobe certifications, I guess these are free certifications. For designing what though?

Um, it's cuz Adobe has okay here. It's it kind of mentions it here. Image manipulation, photo retouching, um, Adobe's tools, vector design, layout design. And I guess there's some, some actual certifications in, in that as well. Uh, graphic design specialization at Cal arts,

fundamental graphic design graphic artists can make money, even if they're independent

online marketing, let's see online. I know there's a lot of good stuff for online marketing. Google, I think has one. As a matter of fact, I believe is free diploma for web business development and marketing from Allison. There's marketing and digital world, university of Illinois getting started on Google analytics.

Yep. That's free. And I think you even get a certification off of this one and they also have one for ad sense. I think they got Google analytics, Google ad sense. And then they got some other stuff, learning a new language. This is kind of off the beaten path. I'm just gonna zip through this one, uh, entrepreneurship, new venture financing.

Okay. This is just business stuff. I'm looking for kind of technical this I'm writing, uh, communication, communicating strategically Purdue university. So yeah, there's, there's some stuff out there. I know that Google has some free courses. Amazon may have some free courses. , you know, I don't know that you'll, after you take those courses and those cert and you have that certification that you're gonna be able to just go out and get a job immediately or anything like that.

But to answer your question, yes, there's free training out there. So I'm gonna go ahead and leave this link for

I have, well, before I promote my own stuff, I'll just put, put this here. Here is some stuff, stuff I found

also Google and possibly,

possibly, where can I spell possibly? Um, Amazon might have some free, might have free certs and training. I also have free training.

You really need experience to get a job though?

Um, yeah, I don't even know how many of these are actually, I don't know if they're security, not sure if they are security related.

Hope that answers this question. Big, like big thumbs up. And somebody said D five D D D. If you, if you're a military veteran, uh, they're actually a few organizations that pay for your search. Yep. That's another thing. So this guy right here, I'm gonna go ahead and message him.

You may. So as a veteran, as a vet, you may have many opportunities,

opportunities, grants, and other stuff you can do to get more training and or positions.

I don't have a security clearance, but I have a degree in, I think he means associates, a master's degree, master's degree in it, security and I'm air force veteran. How can I get employed? Send your resume. And I will take a look, send my email address.

There it is right there.

Hey Al, how you doing? I'm just finishing this up, answering some questions that people have sent me. Um, but if you have any questions right now, I am. Free to open, uh, free to answer any questions at all right now, I got two job offers this past week from my dream companies. Your videos are the best. Thanks, Bruce.

Love to hear that. That's great news. Great news. There's there's lots of opportunities out there even now for it there, we just don't have enough people to do this work. Um, enough qualified people who are willing to put in the, have the patience to actually sit down and learn it. And that's why, like, most of our it's funny, like our, our nation, like is kind of like, not, doesn't seem appreciative of, uh, immigrants, but immigrants really are like something like 75% of the business is made here from immigrants.

I don't know if you guys knew that, but Google, Amazon, uh, name a company. Uh, they're probably made by either I an immigrant or the children of immigrants. Like I'm talking about, they were born, their parents are born in another country, came here, had they had kids and then their kids started Google. Yeah.

Larry look up, um, Larry Page in, uh, Sege Brin, at least one of them is from German is from Russia. I think Serge BRN is from Russia. His parents are from Russia. He was, uh, he may have been born here. Um, the dude who started, uh, uh, Yahoo was, uh, he's either a Chinese immigrant or his parents are a Chinese immigrant.

The, uh, the dude who started, uh, well actually Bezos fr uh, Jeff Bezos is, is, uh, his dad was from Cuba Bezos. Um, uh, who else? Uh, go down the list. Just go down the list. I mean, president Trump, himself, his. Great grandfathers from not from here. So yeah, I mean, immigrants, um, immigrants are like really a great part of, uh, this of the us.

And it's just unfortunate, more Americans don't take up engineering or mathematics, or I know stem, like we just, I don't know what's going on, but there's not enough Americans people born here, you know, that actually apply for these jobs. And so they're always, we're always wearing two, three hats. So I'm about to end this guys.

Um, I got more questions here. Um, some of these, I probably maybe I'll save 'em for next week and I appreciate all the compliments here. Great, great compliments. I'm glad this stuff. Some of this stuff is helping people. I appreciate everybody. Who's been watching me week after week. I'm gonna continue to put out more, more, um, content for everybody.

And, um, if you guys have time, check out my courses, it's at combo courses.com. I got a collection of, of stuff I'm building. I'm gonna do certifications, certifications take a lot longer to do, but there's free stuff out here. A lot of informative stuff I'm gonna, I've got more stuff coming real soon. Al says, uh, is because I don't have any certifications is because I don't have cert any certifications or anything.

I straight, straight cyber security for five years. Al do you mean that you don't, you, you haven't had a position or, or what, what was your, what was this? It seems like I, I caught this conversation in the middle of, of what you're saying here.

Is this a question you said it's because I don't have any certifications yet. Um, Cyber security for five years. Are you asking if, like, why can't you get a position or do you have a position or is, I'm not sure I understand your question.

So let me see if I can answer one more question before I cut outta here. Um,

our great says, just wanted to say, just wanted to say your interview tips and information has helped me to get an offer with a prominent government agency. As critical asset and vulnerability analyst. Thanks a lot. Yep. I've been doing this for a while, man. Um, this is just stuff that I've been doing and I've learned with trial and error and that's why this stuff works.

Um, it's just, this is honestly, I am in the industry currently. I'm currently in this industry and I'm just, I'm just saying what I've been through. I've I'm telling people how I've gotten to where I've gotten and the interview stuff. Yeah. That's just, it's just worked. It just worked over and over again.

So now I'm just passing it along to people who are willing to listen. So that's what this whole channel's about. That's what my combo courses.com is about. It's telling you literally what to do. Uh, let me see. Joe says, are cybersecurity labs enough experience to get a job? Um, I would say, uh, I would say yes.

And no reason why I say that is because is because, uh, it depends on the job. Number one. So if you're, if you're looking for a high level job, no, it's a lab is not enough. Uh, if you're looking for entry level job, and the lab allows you to a, the lab gets you in a place where you can either volunteer to get other experience, or you can get a certification, um, or you can get that, yes, that might get you to a place where you can get your foot in the door at an entry level position, doing something like help desk, junior level entry level help desk, or, or doing, uh, customer service where you're taking calls and helping people troubleshoot, uh, different issues like that.

If you, if you're looking in, if it's something like that, then maybe, maybe, um, but typically I can tell you. As a person who's actually done interviews on people. Um, them just, if I can't say it is not that we wouldn't hire somebody just off of their knowledge, cuz if they had really good knowledge, then maybe, but normally experiences what you're looking for.

Like the baseline is normally experience. And then the big question becomes, how do I get that experience? You're on the right track. If you have a lab in your house and you're training, or if you got the security plus or a plus certification, you're going on the right track. That's what you want to do.

You wanna crack those books? You want to get your hands dirty. You wanna set up labs in your house. You wanna tear computers apart, putting 'em back together. You wanna learn as much as you can. And then while you're trying to get your foot in the door in it, now that doesn't mean cold calling IBM necessarily.

Right? There's. Nowadays, you put your resume out there. You put what your experience is, but also if you happen to already have a job, you can get a lateral, uh, get lateral training or you can get a lateral move. You can, if you're already at a job, wherever it is, they have an it department go over to the it, it department and get friendly with them and start asking 'em questions.

Like man, I'm, I'm really trying to get into it. You'd be surprised how many geeks and nerds are there who want to talk your ear off about how to do it? Cuz we don't normally get those kinds of questions. We don't normally, I mean, I know me, I'm always anxious to, to train people.

View Details

Check out convocourses.com

View Details

Check out convocourses.com

View Details

https://www.youtube.com/watch?v=KW7gaKX_H0Y

RMF ISSO Controls: https://www.amazon.com/dp/B0B6QKT8DR SCA Course (early release) https://securitycompliance.thinkific.... 0:00 start of convocourses 02:23 Security Controls Book and SCA courses (no longer 2 usd) 07:13 Prepare for a SCA Interview (CVE - Common Vulnerabilities and Exposures 23:10) 26:51 Security Controls Book on Amazon & SCA course 34:48 Cyber Security is a great career move 40:19 ITJobs part 1 How Match My Resume with Job I want to Market My self 53:04 ITJobs part 2 Get the Actual Security Experience you did on your resume 59:09 Master Degree in Cybersecurity still no job 1:01:08 GRC and 8140 cybersecurity certifications 1:07:57 The Security Control Assessment Courses has started 1:10:20 Information Security gives Robust Cybersecurity Experience 1:12:06 How to Do CPEs for ISC2 CAP 1:22:51 Cyber security assessor role 1:36:28 Cybersecurity Community on Tiktok & the NIST 800 control book

View Details

https://www.youtube.com/watch?v=KW7gaKX_H0Y

RMF ISSO Controls: https://www.amazon.com/dp/B0B6QKT8DR SCA Course (early release) https://securitycompliance.thinkific.... 0:00 start of convocourses 02:23 Security Controls Book and SCA courses (no longer 2 usd) 07:13 Prepare for a SCA Interview (CVE - Common Vulnerabilities and Exposures 23:10) 26:51 Security Controls Book on Amazon & SCA course 34:48 Cyber Security is a great career move 40:19 ITJobs part 1 How Match My Resume with Job I want to Market My self 53:04 ITJobs part 2 Get the Actual Security Experience you did on your resume 59:09 Master Degree in Cybersecurity still no job 1:01:08 GRC and 8140 cybersecurity certifications 1:07:57 The Security Control Assessment Courses has started 1:10:20 Information Security gives Robust Cybersecurity Experience 1:12:06 How to Do CPEs for ISC2 CAP 1:22:51 Cyber security assessor role 1:36:28 Cybersecurity Community on Tiktok & the NIST 800 control book

View Details

https://www.youtube.com/watch?v=z-OfA-_lU6Q&

We talk about #securityclearance a lot on this one. 0:00 Podcast 0:14 Cybersecurity Public or Private Sector 15:00 How Long Does it Take to Get a Security Clearance 20:47 How do I get a security clearance if I am eligible 29:53 The Value of Security Clearances in IT 33:39 What Security Clearance Can Help in Private Sector 35:51 Does Cybersecurity Job require a Security Clearance 43:44 My experience going through TS clearance 46:33 Finding Out Cybersecurity Salary 52:42 Master Degree in a Cybersecurity Role 1:03:17 Cybersecurity with ZERO experience 1:12:50 convocourses testimonial 1:16:54 Talking about colorado 1:24:58 I recommend Program Management

View Details

https://www.youtube.com/watch?v=z-OfA-_lU6Q&

We talk about #securityclearance a lot on this one. 0:00 Podcast 0:14 Cybersecurity Public or Private Sector 15:00 How Long Does it Take to Get a Security Clearance 20:47 How do I get a security clearance if I am eligible 29:53 The Value of Security Clearances in IT 33:39 What Security Clearance Can Help in Private Sector 35:51 Does Cybersecurity Job require a Security Clearance 43:44 My experience going through TS clearance 46:33 Finding Out Cybersecurity Salary 52:42 Master Degree in a Cybersecurity Role 1:03:17 Cybersecurity with ZERO experience 1:12:50 convocourses testimonial 1:16:54 Talking about colorado 1:24:58 I recommend Program Management

View Details

This was a 2020 Live on discord and youtube. https://www.youtube.com/watch?v=VzQesvI0T1E

View Details

This was a 2020 Live on discord and youtube. https://www.youtube.com/watch?v=VzQesvI0T1E

View Details

http://convocourses.com

See the video here:

https://www.youtube.com/watch?v=cStSGLLypyI

View Details

http://convocourses.com

See the video here:

https://www.youtube.com/watch?v=cStSGLLypyI

View Details

Full video. May 2020 was crazy.

https://www.youtube.com/watch?v=WnB2rdxQpwI&t=3s

Imagine cyber security and all our career paths being expanded into space as the space industry begins to expand. Imagine us having more opportunities in that. Industry. That's what we talk about a little bit on this podcast. We also go into details about CCIS. STIGs which is security, technical implementation guides and how those.

Interact with risk management framework, 800 and CIS controls. Now, this is an older podcast. Um, that I did in 2020, but a lot of it is still relevant. Hope you enjoy Test test audio, test audio test. All right. This is gonna be a short one. I think, welcome to convo courses. My name is Bruce, and, um, wanna start off by, um, addressing, you know, what's going on right now, as far as the coronavirus and stuff. Uh, but we're gonna dive into, we're gonna keep it, uh, to combo courses and cybersecurity stuff.

I know there's a lot of stuff, negative stuff happening right now. As far as the protests and, um, coronavirus, we're looking at a hundred thousand people, um, reported it as having died from coronavirus. We're looking at around the world, 6 million people infected millions, uh, million, at least in the us and all this stuff's going.

And I want to, first of all, I'll send condolences to, to, uh, the people who have passed away from the coronavirus and people are suffering with it now. And if, and if you happen to be out there protesting or anything like that, I mean, just man, stay safe. Um, and, uh, That's all I'll say about that. You know, it's is a pretty heavy subject and, uh, I don't normally address that kind of stuff on this channel, but I just want to address it and make sure every everybody's being mindful, stay safe out there.

You know, this coronavirus, stuff's still going on, take it serious. Um, at the very least try to protect other people. You know what I mean? Um, the people who are most vulnerable to this, to this. So, and that goes for, uh, our justice system too. Like, let's try to protect those who are vulnerable to, to the injustices and stuff like that.

Listen, let's jump right into it. There is positive stuff happening right now. And I wanna, uh, talk about that stuff. That's that's occurring right now. Namely, I don't know if you've been watching it, but the recent. Astronauts coming from a commercial aircraft, uh, commercial space vehicle flying all the way up to the international space station and then linking up with it.

And then this right here is, is really awesome because it opens up the private industry to start doing things like going to the moon, uh, or without the government. So that that's incredible bull. Uh, the reason why it's incredible for us, for it people, information system security people, especially is because that really expands our industry, the better the techno the technological field, the industries and technology do the, be the more opportunities for people like us, who are it?

People, people who are are nerds, you know, people who are geeks, it people, uh, we get more job opportunities. Um, Um, an increase of salary and, and the whole nine yards. So this is a really positive thing. And just to give you an idea of how positive this is, is that of, of, since I've been outta the military and actually in the military, I did some, some stuff for, uh, operations that are, that had to do with space.

But when I got out of the military, most of my jobs had to do with aerospace. Most of my jobs were with aerospace companies. So. It's a huge industry. And, um, and it needs, especially, it needs, uh, security compliance. Like they have to follow a very strict methodology. Right. And that's exactly what I do. And, and, and that's the stuff that I teach mostly, you know, and I, and I'll branch out to other things like certifications or more technical in the weeds type stuff.

But I just wanted to address, like the reason why this is such a positive. Is that the more commercialized, the more accessible space and aerospace low or, or orbits, or even on the moon or Mars, the, the bigger and larger that industry gets. The more mark my words, don't take my word for it. Just watch history.

Watch what happens as that, that industry expands and we are on the moon or we're on Mars, or we are on the wherever low earth or. They're gonna there more and more of these organizations are gonna crop up and more of them are gonna have to hire people like you and I, it people and security compliance people.

So that's, it's a super positive thing. I know my, my daughter had been up all night watching all the news about the, the protests and the riots and how in some cities it's going pretty bad. Uh, and she says, why are you watching this live feed of NASA? You know, instead of don't, you know, what's going on. I said, Hey, you know, this might give us a way to get off earth and she says, yeah, you know, you have a good point about that.

so, I mean, if you, if you wanna be pessimistic about it, then this is, this is an optimist spin. Is that this is a way eventually, well, just leave. Like you don't like it here. You can just go somewhere else. so, yeah, I just want to bring that up. It's it's um, something positive and, and that's why I see any kind of.

Of stuff about the, the expansion of us in the space humans and the space is a positive thing, cuz the industry is gonna grow and uh, the more the industry grows, the more opportunities there are for, for us, especially because it's, it's private, that's even more opportunities for us. All right. So somebody asking me a question and I wanna address that.

I don't wanna make this one too long, but one of the things I wanted to address. and I'll get to questions after this. I got somebody who just jumped on Alice. How you doing? She says, uh, hi. Um, can I send you my resume and for you to look at, please, may I have your email? So here's my email address. Um, let me see if I can find my contact information.

Let's just, oh, I see what happened. All right. Gimme. There it is right there. There is my email address. That's the best way to contact me. Let, just move this down a little bit, move it, move it down. Boom. Best way to contact me is right here. If you happen to be, have, uh, purchased one of my courses, then, um, I will definitely help you directly.

That's one of the perks of Purchas purchasing it directly from combo courses.com is that I will help. um, I don't have any kind of consulting or side things going on right now. I'm pretty new to this thing. So I, I haven't gotten into paid consulting or anything like that. So you have the benefit of catching me early when I'm doing it a lot, some stuff for free.

So yeah, you can send me your, your resume, particularly if you've bought one of my, uh, courses, uh, on combo courses.com. If you've done that, please send me your resume. I will check it. I sometimes I'll even rearrange it for you. I'll just make suggestions on the resume to say, here's what you should do. You know, here's some key words you should consider and things like that.

But if you're interested here, let me, let me just show you guys something real quick. I think this is a really good course, um, that I'm, that I made a while ago and I was super excited about it, cuz this concept is something that's really helped me out over the years. Here's my here's combo courses right here and I've, I've got many D.

stuff like how to get in from scratch from cybersecurity, um, and how to do risk management framework. I've got free stuff here. Uh, but the one that, that Alice is asking me about is this one right here, resume marketing. This one I'm excited about because this, the techniques that I use here is exactly what has made me, uh, be able to constantly.

Position, uh, positions and constantly get opportunities. And I still, even during the pandemic, even during an economic downturn, such as the one we're in now, and even in 2008, I was still continuously getting opportunities because of this, these techniques that I use here. So if you're considering getting into this and you want me to directly look at your resume, go ahead and check out the resume marketing for cyber security.

And it, I don't just talk about cyber security. And it can also apply to you if you're in, in different industry, really, it can apply to anyone cuz the techniques absolutely work. And if you want an idea of what I'm talking about, it's building a profile it's researching, it's finding key, creating the resume.

I walk you through all this stuff. And then I walk you through how, what tools I use online from career jet monster. And I also have something on interviewing and also. Uh, I will be adding more stuff to there that just like with all my courses, I add continuously add as, uh, as I find new things out or something comes up and I, and this is a, it is a really good thing for the course.

I'll add it to, to that course or, or, or any relevant course that I'm talking about. So go ahead and check that out. And, uh, let's get into control correlation identifier. Somebody's been asking me about. , this is the reason I have not talked about it because this is kind of, uh, this one is a bit of a, this one's very specific to D department of defense and dissa.

So, um, that's why it's kind of it's it's, it's it's out there. So, I mean, it's very specific, but what is it? Let's just talk about what this is real quick. Let me just get rid of this information here. give me a second and now we'll be addressing questions after this, by the way. So just keep the questions coming in the, in the, um, chat and I will I'll get, get to that.

All right. So a CCI or a control correlation identifier provides a standard identifier and description for each of the singular actionable statements. That comprise and information assurance, IA control or IA practice. IA is just another word for security control. That's what the department of defense calls it.

CCI or control. Correlation identifier bridges the gap between high level policy expression and low level technical implementation. All right. I can explain this and there's, there's a lot more here that it talks about here, but I can explain it in clear terms of what it means, what the CCI does is a code that identifies specific tasks that you have to do on Lennox systems on windows systems on servers, on database.

Very specific things you do on each one of these operating systems and it links these specific actions that you have to do to a risk management framework control, uh, to a security control. So I'll give you a specific, I'm gonna show you first off. Let me tell you what it is. And then I'm gonna show you, uh, in greater detail what it is.

And, uh, I don't know how deep we'll go, but it'll, it should be very. What a CCI is when we're done. All right. So first off a specific example would be audit controls, like let's say on you're on a windows 2010 workstation, and you have been tasked to turn, turn on auditing on that system. Meaning event logs.

It's gonna collect event logs for whenever somebody MIS authenticates, they, they type in their password wrong and it pops up as a Nope. This is not your. It will send an event, it'll record an event on the system and that's the control that we have to turn on. Right? Well, CCI would be assigned a specific number, like say CCI 0, 0 6 dash 5 53 or whatever that specific tag.

Uh, we'll be identifying a, a re a specific action, which is turning on audit logs and that specific action ties to AU control one and AU control dash two. So now that might not make any sense if you've never done this before, but I'm going to show you, uh, a more specific example, couple examples. um, let me, let me see if I can bring something up here.

Got a couple of examples that I was just looking at. So bear with me. So this is stuff I downloaded from the site. If you wanna learn more, I just, I am on cyber dot mill slash STIGs slash CCI. That's where I'm at right here. So if you wanna just Google it, you can just Google. CCI STS. And you'll, you'll find this, right?

So this is I'm on the dis is one of diss sites. That's why I'm I am. And I downloaded some of the stuff from here, which is, is not very helpful, to be honest with you. It's not very helpful. Um, uh, right now I'm looking for some examples that I actually had prepped. So just bear with me, give me a second and I will show you what I am talking about.

Okay. Here's one of them. So this is, this is. um, this is

a system that, uh, had a STIG viewer ran on it. And what I wanna show you here, the relevant portion is this right here. This is a CCI. This right here. Can you, can you guys see that? Let me make sure you can see that. Okay. Yeah, you can see it. I made it bigger. CCI 0 0 1 8 1 2. And what is that? Right? What's the re the reference tells us here, it's referring to a specific event that the STIG viewer and okay.

Context, a STIG is a security, technical implementation guide. What it does is it walks you through all the individual things that you have to do to secure a system. The department of defense, along with some other departments within the federal government and even some state organizations, they have this breakdown of everything that you need for best practice to secure a system, whether it's turn on audit logs, making sure you have multifactor authentication, making sure it's in a secure area and physical has certain physical security making sure it has a policy making sure, uh, you have GPOs turned on and you.

You have control over your shared files, networking file protocols, making sure you have certain encryption turned on and or updated though. Each one of those things and there's that mil, thousands and thousands of others, maybe millions of others that are individual tasks on windows, on red hat, on every operating system.

You can think. It has security controls. Right? And so what this department of defense does is they create these STIGs security, technical implementation guides that breaks down all the task and they made it so that it's, they made it easier for you to make like a, you can make a script that automatically goes through and fixes all that stuff for you.

And they actually have some scripts that you can use to actually fix that stuff automatically. But this is a you're looking. Some stuff from an actual STIG. And it's the rule title. The thing that it's trying to fix is on a windows, 10 guy, uh, system, and it's for a windows installer will always install with elevated privileges.

This must be disabled. So by default, a window system will automatically elevate privilege. to, uh, to, they're trying to make it easier, more user friendly whenever you, uh, install something. So it just automatically gives elevated privileges. But the problem is that's an that's something that can be exploited.

So the rule that the stick came up with best practice is to turn this off. So when you turn, when you turn the system on you installing it, it, you gotta go in there and turn it off. Okay. So discussion standard user accounts must not be granted elevated privileges. Because, and the reason for that is you want least privilege that what that means is, um, AC I'm not gonna remember C five.

I think it is it's either AC five or C six. And I don't, I don't remember which one it is, but it's the standard of least privilege. Meaning you, you only give users. Standard users, privileged users, operational users. You only give users what they need to do their job. You don't give them anymore. So windows by default and even Lennox does this will give extra privileges that you don't necessarily need for this specific environment.

Now, there may be instances where you, you can give more privileges. It just depends on the environment, but let's dive back into this. It says the standard user. Must not be granted elevated privileges, enable windows installer to elevate privileges. When installing applications can allow malicious persons or threat actors and applications to gain full control of the system.

So if this thing is turned on, somebody with mal with malicious intent might exploit it by, by granting, elevating their own privilege. Right. So we have to disable this thing. That's what they're telling us. And then they tell us specifically how to do it, where to go in the actual system to disable, always install elevated privileges.

And it's telling us to go to computer configuration, administrative F uh, template, windows, component, windows, installer, and then disable, always install with elevated privileges. And I hope that makes sense this right here, what everything I just read is a CCI. All right now, let's talk about how CCIS this specific task on a specific system links to N um, N uh, 800, uh, security compliance controls.

All right, here it is right here. This reference explains it. So at first of all, it has a, it's a, has a, a unique identifier. Every single CCI has a unique identifier. In this case, a CCI 0 0 1 8 1. And what is it telling like in one sentences explains what it is. The information system, prohibits user installation of software without explicit privileges, uh, privileged status.

That's what it does. And it links to, and the references, it tells you it links to this nest 853 rev four is going to rev five soon, cm, 11. so cm is, is dealing with configuration management. Configuration management is dealing with, does our organization control? Does the security posture of our, of our or environment in layman's terms, in layman's terms?

What I'm saying is a cm control is having a inventory of everything that's on your network. Like for example, in your own. you know, you already know you got three computers, right? Your kid has a computer. Everybody has a cell phone and you have a router down in the basement. That's it? Right. If you suddenly were doing a scan on your network and you saw 15 other systems on your network, that would give you grounds to freak the hell out.

Right. cause that you don't know what's going on. So in the same way, an organization needs to know everything that's going on on their environment. They need to know what networking devices are on their network, all the nodes, what their IPS are, what systems they have, what vulnerabilities they have. They need to know all the software that's in their environment.

Right. They need to know if there's wireless, if there's other connections coming into their. They need to know everything that's going on with their network. And that's where a cm control comes in. So cm is controlling your environment. That's all it is configuration management, managing my configuration of my organization's systems because we have very important stuff going on.

That's that's cm. And so they're saying that this CCI links to this cm 11. So if we go down the. Let me see if there's anything I else I can show. Okay. Here's here's what I'm gonna do. I'm gonna actually bring up a STIG. This is a STIG viewer right here. This is an application you can download for free. Go to DISA a DISA dot mail, uh, or just Google a St.

Viewer. And this is a automated it, it's basically a little app that will grab all of the security, uh, CCI. Everything you're supposed to do on a window system or on a Linnux system or a red hat, whatever system and says, okay, have you done these things? Right? So that's what we're looking at here. So I've already taken Liberty to downloading a windows 10, uh, security St.

And one of these days I'm gonna make a whole course outta how to, how to do this. This is something I've been doing a long time, so I know, I definitely know how to do it. So here we. Um, and I can explain, break all this stuff down. It's it's pretty involved, um, special if you're going through all these. So this right here, what you're looking at is windows.

Um, okay. This is not showing me, us everything. So I'm gonna make this a little smaller so you can see everything going on here. There you go. Hopefully that's clear to you. That's okay. There we go. Right there. So right here, we're looking at window. The last one I showed to you was an, was a screenshot. This is an actual STIG that I pulled down.

Um, not from a client of mine or anything like that. would not show that. So here's, so we're clear. This is just a random STIG that I downloaded from this dot mail. And then that's what we're looking at. This is generic. So, uh, what I wanna show you is. This first CCI, this is CCI 0 0 0. Here's where I'm getting the number from right here.

If you could see my cursor where my curse was pointing, right, right there. is CCI 0 0 0 360 6. Organization implements the security configuration. And what is it linked to? There's a few of them cm, six cm, uh, six do one, uh, and, uh, cm, six B what are we doing? What we're doing is looking at the domain. Joined systems.

Must use windows 10, uh, enterprise edition, 64 version. and it goes in a deeper discussion on what, what they're wanting want, what they're wanting as far as how to meet this particular, uh, STIG control and each one of these, the way they break it down. So, okay. Let's, let's do a little bit of a tour here.

There's a couple of numbers here that, that I think you should know. So let's look at this one right here. This vulnerability, I. Vulnerability ID identifies each individual potential weakness of a system. It's saying that specifically the weakness, uh, on this system is this is X, right? And, and the rule name is attached to a w N windows 10 dash.

right. And each, each one of these vulnerability IDs attached to a specific weakness that has been detect that, um, that needs to be addressed. Right. And so you can manually go through each one of these. So one of the things that you can do as an information system, security officer, one great tool you can use better than nothing is to run this stool, this run, this STIG viewer and have your system.

By your side, right? You have your system right here. You have your system here and you're looking at each individual item manually going through one by one by one to fix everything on your system. Another thing you can do is, is run a, a script that fixes all these things automatically. Right. And, and I believe there's tools.

I, I wanna say that there's, there's something called, um, uh, SCC or. Checker software that, that, uh, you can get from department of defense, that, that has something that will fix it. It'll scan your system. You, you load it on your, the affected system. Uh, and then you scan it'll scan and, and see what STS, what individual CCIS, what vulnerability IDs are not being met on your system.

And then you would go through manually and fix every, all those items. Now. There's a couple of different things here. How does this help you? Um, as an information system, security officer, if you don't happen to be actually installing these things, how it helps you is that if you have the report from this thing, you'll be able to know, okay.

When they did a scan, they found, let me just find that whole different CCI here, that we can talk about something that.

So let's say you're only doing documentation. You can take something like this, this scan, and you could, uh, this would be like an artifact or a bit of evidence stating that this rule has been met. And how's the rule been met, you could say, right, right in here. It says, uh, that first of all, it is a windows ink workspace.

Consider. Uh, uh, sorry. Uh, workstation ink works, windows, ink, workspace configured, but disallowed access, uh, above the lock. And it tells us how to secure it. Securing windows ink with, uh, which contains application and features oriented towards, uh, the pin towards pin comput. I, I have no idea what this is. I have no idea.

I have no idea what this is. This is some oh, pin, like the pin you E enter into the system. Okay. Okay. Okay. I'm just making more sense to me. So this is showing us how the scan, how, where it would be scanned at, like, what value is would you be looking for? So it's saying that you would go into the registry back into the system and then.

If this was turned on, and if you're doing a scan, it would check for this item in the registry keys. That's what it's saying. That's how I'm understanding it. And it's saying the fix action is disable the convenience pin, uh, sign in. So we don't want you to be able to sign in with a pin because that's too easy to exploit.

So here's how we fix that. That's that's what they're saying here. And it breaks it down exactly how you actually fix it. So. If you were doing the documentation for this, there's a couple things you could do. You could use this to explain what the weakness is. Let's say your organization didn't do it. You could use this to break down where we are not meeting specifically how, uh, what's going on.

Or if you wanted to prove that it, that it's been fixed, you could go through and do a screenshot of what, of, of this feature, or if you were doing a. you could run a scan and say, look, here it is right here. The windows 10 CC 0 0 0 3, 8 85 has been met. And that covers, uh, cm seven right there, CCM seven. So, and you could do that on many of these different items here that we have here and.

go from, they run the gamut from going this one, C, C uh, S I 16, you got some AC IA controls, you got different controls. So it's telling you here in the CC, uh, in this reference where these map to each one of the security controls, and that's why super helpful you as an information security officer. If you happen to be one you're looking for, how can I.

These security controls. How can, how does our organization meet this particular security control? So this is just one way. If you happen to have a window system or a Linux or whatever it is, right? Cause they have, they have these for every kind of system. All the main systems are, are, are covered by the STS.

You can use this information to figure out if you guys are meeting this particular control or if you're not meeting control and how to. So I hope that that makes sense. Um, I kind of, I feel like we, we kind of went overboard with it, but at, at some point, what I would like to do is actually take a system and secure the system, using the STIGs using the SCC tools and everything, but that'll be a whole course cuz that, that all that stuff takes a bit of time and set up and all that kind of stuff.

I'm actually setting up some stuff on the back end here, but um, it's gonna take me a while to set all that stuff up. if there's any questions we can address those, but while you guys are coming up with questions, I would like to show you something else real quick. Uh, another very useful thing with ma with having a matrix or having these individual vulnerability IDs and CC eyes and all these things, or how they all come together is beautiful because there's something else where these same control.

Map to, um, a more commercialized version of controls, which is CIS benchmark controls. These controls are used by a lot of private industry stuff, private industries, some banks, and some other industries actually use these controls rather than the nest controls.

View Details

Full video. May 2020 was crazy.

https://www.youtube.com/watch?v=WnB2rdxQpwI&t=3s

Imagine cyber security and all our career paths being expanded into space as the space industry begins to expand. Imagine us having more opportunities in that. Industry. That's what we talk about a little bit on this podcast. We also go into details about CCIS. STIGs which is security, technical implementation guides and how those.

Interact with risk management framework, 800 and CIS controls. Now, this is an older podcast. Um, that I did in 2020, but a lot of it is still relevant. Hope you enjoy Test test audio, test audio test. All right. This is gonna be a short one. I think, welcome to convo courses. My name is Bruce, and, um, wanna start off by, um, addressing, you know, what's going on right now, as far as the coronavirus and stuff. Uh, but we're gonna dive into, we're gonna keep it, uh, to combo courses and cybersecurity stuff.

I know there's a lot of stuff, negative stuff happening right now. As far as the protests and, um, coronavirus, we're looking at a hundred thousand people, um, reported it as having died from coronavirus. We're looking at around the world, 6 million people infected millions, uh, million, at least in the us and all this stuff's going.

And I want to, first of all, I'll send condolences to, to, uh, the people who have passed away from the coronavirus and people are suffering with it now. And if, and if you happen to be out there protesting or anything like that, I mean, just man, stay safe. Um, and, uh, That's all I'll say about that. You know, it's is a pretty heavy subject and, uh, I don't normally address that kind of stuff on this channel, but I just want to address it and make sure every everybody's being mindful, stay safe out there.

You know, this coronavirus, stuff's still going on, take it serious. Um, at the very least try to protect other people. You know what I mean? Um, the people who are most vulnerable to this, to this. So, and that goes for, uh, our justice system too. Like, let's try to protect those who are vulnerable to, to the injustices and stuff like that.

Listen, let's jump right into it. There is positive stuff happening right now. And I wanna, uh, talk about that stuff. That's that's occurring right now. Namely, I don't know if you've been watching it, but the recent. Astronauts coming from a commercial aircraft, uh, commercial space vehicle flying all the way up to the international space station and then linking up with it.

And then this right here is, is really awesome because it opens up the private industry to start doing things like going to the moon, uh, or without the government. So that that's incredible bull. Uh, the reason why it's incredible for us, for it people, information system security people, especially is because that really expands our industry, the better the techno the technological field, the industries and technology do the, be the more opportunities for people like us, who are it?

People, people who are are nerds, you know, people who are geeks, it people, uh, we get more job opportunities. Um, Um, an increase of salary and, and the whole nine yards. So this is a really positive thing. And just to give you an idea of how positive this is, is that of, of, since I've been outta the military and actually in the military, I did some, some stuff for, uh, operations that are, that had to do with space.

But when I got out of the military, most of my jobs had to do with aerospace. Most of my jobs were with aerospace companies. So. It's a huge industry. And, um, and it needs, especially, it needs, uh, security compliance. Like they have to follow a very strict methodology. Right. And that's exactly what I do. And, and, and that's the stuff that I teach mostly, you know, and I, and I'll branch out to other things like certifications or more technical in the weeds type stuff.

But I just wanted to address, like the reason why this is such a positive. Is that the more commercialized, the more accessible space and aerospace low or, or orbits, or even on the moon or Mars, the, the bigger and larger that industry gets. The more mark my words, don't take my word for it. Just watch history.

Watch what happens as that, that industry expands and we are on the moon or we're on Mars, or we are on the wherever low earth or. They're gonna there more and more of these organizations are gonna crop up and more of them are gonna have to hire people like you and I, it people and security compliance people.

So that's, it's a super positive thing. I know my, my daughter had been up all night watching all the news about the, the protests and the riots and how in some cities it's going pretty bad. Uh, and she says, why are you watching this live feed of NASA? You know, instead of don't, you know, what's going on. I said, Hey, you know, this might give us a way to get off earth and she says, yeah, you know, you have a good point about that.

so, I mean, if you, if you wanna be pessimistic about it, then this is, this is an optimist spin. Is that this is a way eventually, well, just leave. Like you don't like it here. You can just go somewhere else. so, yeah, I just want to bring that up. It's it's um, something positive and, and that's why I see any kind of.

Of stuff about the, the expansion of us in the space humans and the space is a positive thing, cuz the industry is gonna grow and uh, the more the industry grows, the more opportunities there are for, for us, especially because it's, it's private, that's even more opportunities for us. All right. So somebody asking me a question and I wanna address that.

I don't wanna make this one too long, but one of the things I wanted to address. and I'll get to questions after this. I got somebody who just jumped on Alice. How you doing? She says, uh, hi. Um, can I send you my resume and for you to look at, please, may I have your email? So here's my email address. Um, let me see if I can find my contact information.

Let's just, oh, I see what happened. All right. Gimme. There it is right there. There is my email address. That's the best way to contact me. Let, just move this down a little bit, move it, move it down. Boom. Best way to contact me is right here. If you happen to be, have, uh, purchased one of my courses, then, um, I will definitely help you directly.

That's one of the perks of Purchas purchasing it directly from combo courses.com is that I will help. um, I don't have any kind of consulting or side things going on right now. I'm pretty new to this thing. So I, I haven't gotten into paid consulting or anything like that. So you have the benefit of catching me early when I'm doing it a lot, some stuff for free.

So yeah, you can send me your, your resume, particularly if you've bought one of my, uh, courses, uh, on combo courses.com. If you've done that, please send me your resume. I will check it. I sometimes I'll even rearrange it for you. I'll just make suggestions on the resume to say, here's what you should do. You know, here's some key words you should consider and things like that.

But if you're interested here, let me, let me just show you guys something real quick. I think this is a really good course, um, that I'm, that I made a while ago and I was super excited about it, cuz this concept is something that's really helped me out over the years. Here's my here's combo courses right here and I've, I've got many D.

stuff like how to get in from scratch from cybersecurity, um, and how to do risk management framework. I've got free stuff here. Uh, but the one that, that Alice is asking me about is this one right here, resume marketing. This one I'm excited about because this, the techniques that I use here is exactly what has made me, uh, be able to constantly.

Position, uh, positions and constantly get opportunities. And I still, even during the pandemic, even during an economic downturn, such as the one we're in now, and even in 2008, I was still continuously getting opportunities because of this, these techniques that I use here. So if you're considering getting into this and you want me to directly look at your resume, go ahead and check out the resume marketing for cyber security.

And it, I don't just talk about cyber security. And it can also apply to you if you're in, in different industry, really, it can apply to anyone cuz the techniques absolutely work. And if you want an idea of what I'm talking about, it's building a profile it's researching, it's finding key, creating the resume.

I walk you through all this stuff. And then I walk you through how, what tools I use online from career jet monster. And I also have something on interviewing and also. Uh, I will be adding more stuff to there that just like with all my courses, I add continuously add as, uh, as I find new things out or something comes up and I, and this is a, it is a really good thing for the course.

I'll add it to, to that course or, or, or any relevant course that I'm talking about. So go ahead and check that out. And, uh, let's get into control correlation identifier. Somebody's been asking me about. , this is the reason I have not talked about it because this is kind of, uh, this one is a bit of a, this one's very specific to D department of defense and dissa.

So, um, that's why it's kind of it's it's, it's it's out there. So, I mean, it's very specific, but what is it? Let's just talk about what this is real quick. Let me just get rid of this information here. give me a second and now we'll be addressing questions after this, by the way. So just keep the questions coming in the, in the, um, chat and I will I'll get, get to that.

All right. So a CCI or a control correlation identifier provides a standard identifier and description for each of the singular actionable statements. That comprise and information assurance, IA control or IA practice. IA is just another word for security control. That's what the department of defense calls it.

CCI or control. Correlation identifier bridges the gap between high level policy expression and low level technical implementation. All right. I can explain this and there's, there's a lot more here that it talks about here, but I can explain it in clear terms of what it means, what the CCI does is a code that identifies specific tasks that you have to do on Lennox systems on windows systems on servers, on database.

Very specific things you do on each one of these operating systems and it links these specific actions that you have to do to a risk management framework control, uh, to a security control. So I'll give you a specific, I'm gonna show you first off. Let me tell you what it is. And then I'm gonna show you, uh, in greater detail what it is.

And, uh, I don't know how deep we'll go, but it'll, it should be very. What a CCI is when we're done. All right. So first off a specific example would be audit controls, like let's say on you're on a windows 2010 workstation, and you have been tasked to turn, turn on auditing on that system. Meaning event logs.

It's gonna collect event logs for whenever somebody MIS authenticates, they, they type in their password wrong and it pops up as a Nope. This is not your. It will send an event, it'll record an event on the system and that's the control that we have to turn on. Right? Well, CCI would be assigned a specific number, like say CCI 0, 0 6 dash 5 53 or whatever that specific tag.

Uh, we'll be identifying a, a re a specific action, which is turning on audit logs and that specific action ties to AU control one and AU control dash two. So now that might not make any sense if you've never done this before, but I'm going to show you, uh, a more specific example, couple examples. um, let me, let me see if I can bring something up here.

Got a couple of examples that I was just looking at. So bear with me. So this is stuff I downloaded from the site. If you wanna learn more, I just, I am on cyber dot mill slash STIGs slash CCI. That's where I'm at right here. So if you wanna just Google it, you can just Google. CCI STS. And you'll, you'll find this, right?

So this is I'm on the dis is one of diss sites. That's why I'm I am. And I downloaded some of the stuff from here, which is, is not very helpful, to be honest with you. It's not very helpful. Um, uh, right now I'm looking for some examples that I actually had prepped. So just bear with me, give me a second and I will show you what I am talking about.

Okay. Here's one of them. So this is, this is. um, this is

a system that, uh, had a STIG viewer ran on it. And what I wanna show you here, the relevant portion is this right here. This is a CCI. This right here. Can you, can you guys see that? Let me make sure you can see that. Okay. Yeah, you can see it. I made it bigger. CCI 0 0 1 8 1 2. And what is that? Right? What's the re the reference tells us here, it's referring to a specific event that the STIG viewer and okay.

Context, a STIG is a security, technical implementation guide. What it does is it walks you through all the individual things that you have to do to secure a system. The department of defense, along with some other departments within the federal government and even some state organizations, they have this breakdown of everything that you need for best practice to secure a system, whether it's turn on audit logs, making sure you have multifactor authentication, making sure it's in a secure area and physical has certain physical security making sure it has a policy making sure, uh, you have GPOs turned on and you.

You have control over your shared files, networking file protocols, making sure you have certain encryption turned on and or updated though. Each one of those things and there's that mil, thousands and thousands of others, maybe millions of others that are individual tasks on windows, on red hat, on every operating system.

You can think. It has security controls. Right? And so what this department of defense does is they create these STIGs security, technical implementation guides that breaks down all the task and they made it so that it's, they made it easier for you to make like a, you can make a script that automatically goes through and fixes all that stuff for you.

And they actually have some scripts that you can use to actually fix that stuff automatically. But this is a you're looking. Some stuff from an actual STIG. And it's the rule title. The thing that it's trying to fix is on a windows, 10 guy, uh, system, and it's for a windows installer will always install with elevated privileges.

This must be disabled. So by default, a window system will automatically elevate privilege. to, uh, to, they're trying to make it easier, more user friendly whenever you, uh, install something. So it just automatically gives elevated privileges. But the problem is that's an that's something that can be exploited.

So the rule that the stick came up with best practice is to turn this off. So when you turn, when you turn the system on you installing it, it, you gotta go in there and turn it off. Okay. So discussion standard user accounts must not be granted elevated privileges. Because, and the reason for that is you want least privilege that what that means is, um, AC I'm not gonna remember C five.

I think it is it's either AC five or C six. And I don't, I don't remember which one it is, but it's the standard of least privilege. Meaning you, you only give users. Standard users, privileged users, operational users. You only give users what they need to do their job. You don't give them anymore. So windows by default and even Lennox does this will give extra privileges that you don't necessarily need for this specific environment.

Now, there may be instances where you, you can give more privileges. It just depends on the environment, but let's dive back into this. It says the standard user. Must not be granted elevated privileges, enable windows installer to elevate privileges. When installing applications can allow malicious persons or threat actors and applications to gain full control of the system.

So if this thing is turned on, somebody with mal with malicious intent might exploit it by, by granting, elevating their own privilege. Right. So we have to disable this thing. That's what they're telling us. And then they tell us specifically how to do it, where to go in the actual system to disable, always install elevated privileges.

And it's telling us to go to computer configuration, administrative F uh, template, windows, component, windows, installer, and then disable, always install with elevated privileges. And I hope that makes sense this right here, what everything I just read is a CCI. All right now, let's talk about how CCIS this specific task on a specific system links to N um, N uh, 800, uh, security compliance controls.

All right, here it is right here. This reference explains it. So at first of all, it has a, it's a, has a, a unique identifier. Every single CCI has a unique identifier. In this case, a CCI 0 0 1 8 1. And what is it telling like in one sentences explains what it is. The information system, prohibits user installation of software without explicit privileges, uh, privileged status.

That's what it does. And it links to, and the references, it tells you it links to this nest 853 rev four is going to rev five soon, cm, 11. so cm is, is dealing with configuration management. Configuration management is dealing with, does our organization control? Does the security posture of our, of our or environment in layman's terms, in layman's terms?

What I'm saying is a cm control is having a inventory of everything that's on your network. Like for example, in your own. you know, you already know you got three computers, right? Your kid has a computer. Everybody has a cell phone and you have a router down in the basement. That's it? Right. If you suddenly were doing a scan on your network and you saw 15 other systems on your network, that would give you grounds to freak the hell out.

Right. cause that you don't know what's going on. So in the same way, an organization needs to know everything that's going on on their environment. They need to know what networking devices are on their network, all the nodes, what their IPS are, what systems they have, what vulnerabilities they have. They need to know all the software that's in their environment.

Right. They need to know if there's wireless, if there's other connections coming into their. They need to know everything that's going on with their network. And that's where a cm control comes in. So cm is controlling your environment. That's all it is configuration management, managing my configuration of my organization's systems because we have very important stuff going on.

That's that's cm. And so they're saying that this CCI links to this cm 11. So if we go down the. Let me see if there's anything I else I can show. Okay. Here's here's what I'm gonna do. I'm gonna actually bring up a STIG. This is a STIG viewer right here. This is an application you can download for free. Go to DISA a DISA dot mail, uh, or just Google a St.

Viewer. And this is a automated it, it's basically a little app that will grab all of the security, uh, CCI. Everything you're supposed to do on a window system or on a Linnux system or a red hat, whatever system and says, okay, have you done these things? Right? So that's what we're looking at here. So I've already taken Liberty to downloading a windows 10, uh, security St.

And one of these days I'm gonna make a whole course outta how to, how to do this. This is something I've been doing a long time, so I know, I definitely know how to do it. So here we. Um, and I can explain, break all this stuff down. It's it's pretty involved, um, special if you're going through all these. So this right here, what you're looking at is windows.

Um, okay. This is not showing me, us everything. So I'm gonna make this a little smaller so you can see everything going on here. There you go. Hopefully that's clear to you. That's okay. There we go. Right there. So right here, we're looking at window. The last one I showed to you was an, was a screenshot. This is an actual STIG that I pulled down.

Um, not from a client of mine or anything like that. would not show that. So here's, so we're clear. This is just a random STIG that I downloaded from this dot mail. And then that's what we're looking at. This is generic. So, uh, what I wanna show you is. This first CCI, this is CCI 0 0 0. Here's where I'm getting the number from right here.

If you could see my cursor where my curse was pointing, right, right there. is CCI 0 0 0 360 6. Organization implements the security configuration. And what is it linked to? There's a few of them cm, six cm, uh, six do one, uh, and, uh, cm, six B what are we doing? What we're doing is looking at the domain. Joined systems.

Must use windows 10, uh, enterprise edition, 64 version. and it goes in a deeper discussion on what, what they're wanting want, what they're wanting as far as how to meet this particular, uh, STIG control and each one of these, the way they break it down. So, okay. Let's, let's do a little bit of a tour here.

There's a couple of numbers here that, that I think you should know. So let's look at this one right here. This vulnerability, I. Vulnerability ID identifies each individual potential weakness of a system. It's saying that specifically the weakness, uh, on this system is this is X, right? And, and the rule name is attached to a w N windows 10 dash.

right. And each, each one of these vulnerability IDs attached to a specific weakness that has been detect that, um, that needs to be addressed. Right. And so you can manually go through each one of these. So one of the things that you can do as an information system, security officer, one great tool you can use better than nothing is to run this stool, this run, this STIG viewer and have your system.

By your side, right? You have your system right here. You have your system here and you're looking at each individual item manually going through one by one by one to fix everything on your system. Another thing you can do is, is run a, a script that fixes all these things automatically. Right. And, and I believe there's tools.

I, I wanna say that there's, there's something called, um, uh, SCC or. Checker software that, that, uh, you can get from department of defense, that, that has something that will fix it. It'll scan your system. You, you load it on your, the affected system. Uh, and then you scan it'll scan and, and see what STS, what individual CCIS, what vulnerability IDs are not being met on your system.

And then you would go through manually and fix every, all those items. Now. There's a couple of different things here. How does this help you? Um, as an information system, security officer, if you don't happen to be actually installing these things, how it helps you is that if you have the report from this thing, you'll be able to know, okay.

When they did a scan, they found, let me just find that whole different CCI here, that we can talk about something that.

So let's say you're only doing documentation. You can take something like this, this scan, and you could, uh, this would be like an artifact or a bit of evidence stating that this rule has been met. And how's the rule been met, you could say, right, right in here. It says, uh, that first of all, it is a windows ink workspace.

Consider. Uh, uh, sorry. Uh, workstation ink works, windows, ink, workspace configured, but disallowed access, uh, above the lock. And it tells us how to secure it. Securing windows ink with, uh, which contains application and features oriented towards, uh, the pin towards pin comput. I, I have no idea what this is. I have no idea.

I have no idea what this is. This is some oh, pin, like the pin you E enter into the system. Okay. Okay. Okay. I'm just making more sense to me. So this is showing us how the scan, how, where it would be scanned at, like, what value is would you be looking for? So it's saying that you would go into the registry back into the system and then.

If this was turned on, and if you're doing a scan, it would check for this item in the registry keys. That's what it's saying. That's how I'm understanding it. And it's saying the fix action is disable the convenience pin, uh, sign in. So we don't want you to be able to sign in with a pin because that's too easy to exploit.

So here's how we fix that. That's that's what they're saying here. And it breaks it down exactly how you actually fix it. So. If you were doing the documentation for this, there's a couple things you could do. You could use this to explain what the weakness is. Let's say your organization didn't do it. You could use this to break down where we are not meeting specifically how, uh, what's going on.

Or if you wanted to prove that it, that it's been fixed, you could go through and do a screenshot of what, of, of this feature, or if you were doing a. you could run a scan and say, look, here it is right here. The windows 10 CC 0 0 0 3, 8 85 has been met. And that covers, uh, cm seven right there, CCM seven. So, and you could do that on many of these different items here that we have here and.

go from, they run the gamut from going this one, C, C uh, S I 16, you got some AC IA controls, you got different controls. So it's telling you here in the CC, uh, in this reference where these map to each one of the security controls, and that's why super helpful you as an information security officer. If you happen to be one you're looking for, how can I.

These security controls. How can, how does our organization meet this particular security control? So this is just one way. If you happen to have a window system or a Linux or whatever it is, right? Cause they have, they have these for every kind of system. All the main systems are, are, are covered by the STS.

You can use this information to figure out if you guys are meeting this particular control or if you're not meeting control and how to. So I hope that that makes sense. Um, I kind of, I feel like we, we kind of went overboard with it, but at, at some point, what I would like to do is actually take a system and secure the system, using the STIGs using the SCC tools and everything, but that'll be a whole course cuz that, that all that stuff takes a bit of time and set up and all that kind of stuff.

I'm actually setting up some stuff on the back end here, but um, it's gonna take me a while to set all that stuff up. if there's any questions we can address those, but while you guys are coming up with questions, I would like to show you something else real quick. Uh, another very useful thing with ma with having a matrix or having these individual vulnerability IDs and CC eyes and all these things, or how they all come together is beautiful because there's something else where these same control.

Map to, um, a more commercialized version of controls, which is CIS benchmark controls. These controls are used by a lot of private industry stuff, private industries, some banks, and some other industries actually use these controls rather than the nest controls.

View Details

Hey guys, this is Bruce, and welcome to combo courses, podcast. I'm doing an experiment where I'm doing daily is here. We'll see how this goes. I don't know if I'll keep this or maybe I'll do this twice a week or something like that because it hasn't been that bad. I got so many things. I can talk about so many questions to answer, but right now I wanted to focus my time on the categories of cybersecurity.

So a lot of times. Industry people think that cyber security is all about. And I think it's all about just hacking or something like that, something to that effect. And those are the things that are popular, just Hacking or pin testing or programming another one's for digital forensics.

People think that's all that there is, but in cyber security, not just I've been doing this for a very long time. I've done everything from the technical side where I'm actually configuring systems and installing systems and that kind of thing. But I've also done the, more of the management type side.

And I want to tell you that there's. So many different. Parts to cyber security. And when you see somebody talking about hacking or whatever it's very glamorous, but that's a tiny fraction of the whole spectrum of cyber security. It goes very deep. So if you're actually trying to get into this career path, cuz it pays very well and it does then I, what I wanna do is introduce you to some other categories of cyber security that you may.

Know about. And so one of there's an organization out there and it's from nonprofits and the government and a couple of private sector. They got together and they broke down the different categories of cyber security that need to be addressed. And it's not just. Cyber security by itself. Some of it is you can have a system administrator who does cyber security, that also accounts for this one.

And I'm gonna explain that in a second. If you stick with me, you'll understand this and you'll understand, especially if you, this is particularly for you. If you are trying to get into cyber security, if you're interested enough to want to be a part of cyber security in this field. And if you've been thinking about getting into it, I'm gonna show you the whole spectrum of cyber security.

Let me show you. A framework called it's called the workforce framework for cyber security. And if you didn't know about this is something the federal us federal government has been using for years now to figure out what categories to put people in and what kind of training that they need to do in order to be in these different categories.

And from a bird's eye view. Let me. Switch my screen over here on TikTok. Feel free to ask me any kind of questions. I'll be doing this for about 30 minutes if you're interested in this, but let me show you what I've got going on here. And I'm just so you know, I'm broadcasting on a podcast, but I'm also doing so I, I will explain what we're looking at here, but you can watch this on YouTube and Facebook eventually will put this on Facebook.

But here we have all the categories. Now there's seven different categories at the time of this recording. There's analyze. There's collect and operate. There's investigate. There is operate and maintain, overseeing, govern, protect, and defend and securely provision. And what I wanna do is give you an example of each one of these seven categories, cuz each one of these breaks out into specialty areas.

So for example, analyze breaks out into. What you call exploit analysis, language analysis, target analysis, and you'll see that some of these don't look like cyber security topics, but they, in fact they are now, if you happen to be dual bilingual, if you happen to know another language Very fluently.

You might actually be able to very quickly go into something called language analysis, which we'll briefly touch on in a second. But what I wanna keep this kind of high level right now, just to show you the different specialty areas. Now there's about, I don't know, 30 or 40 different specialty areas.

Each one of these categories of cyber security breaks out into these special specialty areas now in collect and operate, you'll see things like cyber, operational planning, you don't think that would have a lot of hands-on stuff and it actually doesn't. So let's keep going here.

And when I say hands-on, I mean like somebody who's actually configuring a server or setting up a network and stuff like that, cyber security is not all just about that. It's a very broad area. It's a very broad umbrella. So investigation is what you might expect is digital forensics, cyber investigations.

Threat hunting, things like that. And we'll cover that in a second operate and maintain. This is what people normally think about when they think about system administrators, data, administrators, network services, that's their network engineers, things like that. These guys are in.

Cyber security in that they have to do a lot of cyber security-type activities. They're not typically seen as cybersecurity people, but they have to do a lot of things in cybersecurity. As you might expect when they're installing patches or things like that. Overseeing govern. So this is what I do.

I can speak extensively on this, but this is a lot of management type stuff. Cyber security management. This is your C level execs and it even includes legal and program managers. This is something I would very much like to talk to you about because program management requires a certain level of emotional intelligence that a lot of it people do not.

Okay. And I, it's a very important a very critical piece of any kind of system engineering, any kind of major cyber security projects, anything the organization is doing that where they're spending a lot of time, money, and energy, and a lot of resources. They need a program manager. I'll get off my soapbox on that one, but it also pays very.

And that's something I talk about a lot on my site program management is a big one. Okay. Anyway, let's keep going. Let's keep it high level protect and defend. So protect and defend. Is dealing with a cyber defense analysis, just to name a few incident response. That's a huge one, vulnerability assessment and management.

Huge, but that's for protect and defend. So you see, this is not all just firewalls. This is not all hacking have I haven't even mentioned hacking yet. That's how big this field. And there's some things that are not even included on here. Like cryptography, you don't see cryptography on here, but cryptography is considered part of part of cyber security.

And I would argue that the cypherpunks, the guys who created The concept for Bitcoin and all that kind of stuff were also very good cybersecurity people anyway. So securely provision. Now this one has to do with risk management, software development, system architecture, that sort of thing. So you can see, what I wanna do is just show you.

The high level here. There's many different categories of cyber security and it's not all just hacking. It's not all just programming. Yes. Those are part of what we do. But in the major scheme of things, like when you look at the big picture for all of this it's a very big feel. And I wanna just explain to you why if you think about it, it really makes sense when you go to your bank and you are trying to send a wire transfer from one.

Using ACH to another bank, right? Or you wanna wire something overseas or whatever the case may be. The bank has a certain they have certain protocols and procedures and certain policies that they have to do in order to secure your information to make sure that the $1,000 you sent from one bank to another, or from, to your, whoever.

Wherever you're sending it. They have to make sure that information is protected. The rules and protocols and procedures and the legal system. All of the things that come together that is known as secure security compliance. Now the financial industry has a different set of laws, as you would imagine than say the healthcare.

The healthcare industry is protecting your healthcare information, your digital, if it's that information is digitized, they have to protect that information, right? So they have a whole different set of laws that are completely different because it has a different has a different, it has, it requires a bus different business solution than say a bank.

If you think about it like this, the government, the federal government, who's protecting your social security number. They're protecting your, I don't know. They're holding, making sure that things like the DMV, if you're talking about the state they have to protect your personal on for information as well.

and making sure that's, of course there's all kinds of leaks and all kinds of hacks and all that kind of stuff going on, but they have a whole different set of procedures and rule sets and laws that apply to the federal and state government. And that's also called security compliance.

Security compliance is in every industry. It's in every state, it's in every jurisdiction, it's in every county and it's in every country. Each country has their own set of laws that pertain to. And all of us, all of them have different solutions that they need for their particular situation. So one would imagine as you can probably imagine, there's a lot of security that has to be done for that.

And it's not all hacking. Like you can see how hacking is a tiny drip and a gigantic ocean that is cyber. Cybersecurity is a very huge field and that's why you have seven different categories. Now, what I wanna do is kinda give you a practical understanding of these seven categories. Now let's start from the top here.

I'm gonna give you a specific example of where you might have seen this on TV or in a movie, or relate it to something you can understand here on a practical way. So let's start with analyze the first category we see on the top here is analyze. Has these specialty areas right here. Now, if you break these down and if you wanna go to the site, by the way, if you happen to be watching me on YouTube I have a link to where you can actually follow along.

The actual site. Is there in the link now analyze, let me give you a practical understanding what analyze is now. When I was in the military, we had, when I was in a combat zone and we have we had languish analyst. Whenever we and the reason why we had these language analysts was because we can't understand, say if say a another country is attempting to hack our systems, like they'll put some code on our systems and that code has to be in Ukrainian or in Russian or whatever other language you need a language.

To actually figure out what is being said in that in that code. And that's why a lot of times they figure out, oh yeah this hat came from Russia. This hat came from Ukraine. This hat came from whatever country, because you have an language analyst who has they're multidiscipline in language languages, where they can figure out and decipher and figure out like what's going on.

They'll have like different tools. That'll help them to decipher what's going on with that, with whatever hack is going on. So this is actually a part of the analyze category. Let me give you another example, threat analysis. Now this is a big one. So a cyber threat analysis is something where what you're doing is.

You're trying to detect and figure out where a company might get hacked from an organization might get hacked from, and it sounds impossible. Sounds crazy. How can you figure out where threats are coming from? There's some ways to do it. So if you think about like this right now, somebody might be trying to hack, I don't know, I'm just pick something off the top of my head.

They might be trying to hack Walmart or something. Wal, what Walmart can do is they can have somebody scour the internet. Do search conduct searches or create a tool that goes out and. Does a web crawl of the internet to figure out okay, who is mentioning Walmart who is talking about it on social media?

Who's talking where are the communications that are in the public domain to figure out who is talking about us so we can figure out where those threats are coming from. Because a lot of times when these, before the attack even occurs, these criminal hackers are talking amongst each other on the dark web.

About how they're gonna attack or they even already had the attack. They already pulled the information from there and they're selling Walmart's emails. Now this is just an example. I just, so you know, I don't have a client with Walmart or anything like that. I don't have not interacted with Walmart's cyber security.

I was using them as an example and I'm unaware of any current tax or anything like that. Just, this is just an example, but that is what threat warning analysts do. And this is something I did at my last job, as a matter of fact, that was one of our jobs was to do threat analysis on companies to figure out what's going on.

And this also pertains to doing cyber looking at terrorist threats for whole countries, by the way. So that's analyze an analyze goes into analyzing information, analyzing targets, analyzing threats that might be coming to a cyber security through, to an organization. There is, there can be some hacking involved.

There can be times where you have to know a little code, but language analysts don't typically know code, and then all source analysis. This goes straight into just intelligence. This is normally what you'll see in like intelligence organizations where they're gathering actual, actionable intelligence from other.

From multiple sources, putting that information together to figure out, okay, we have a terrorist threat here. We have a terrorist threat there. We know that we have advanced persistent threats here and there. We have some, we have reason to believe we have human intelligence people on the ground where they've gathered this or that information to figure.

Who's gonna attack what, and a good example of this one would be that if you've ever watched a mission, impossible the ghost ghost recon, that one, they have, they talk about this type of job all the throughout that one. The as a matter of fact, they have one of the characters is an analyst, and this is the, what they're talking about.

This is somebody who. Who pulls information from different sources, different intelligence sources puts it together and figures out. Okay. We know that there's a credible, there's a probable attack. That's gonna happen over here, over there, based off of all the Intel that they've gathered in the field.

Okay. So we beat that one to death. Let's keep going here. So that is analyzed and that's in cybersecurity. Then we've. Collect and operate. Let's look at this one. So here's the specialty areas with collect and operate. Now, what are we talking about here? This is also dealing with a lot of intelligence, this, a lot of govern department of defense and some of the other three level organizations will have something like this cyber operations, where they're also looking at real time threats.

They're looking at foreign intelligence entities. So this one's very much related. To what we were talking about here analyze a lot of times we'll see these in security operation centers, a security operation center, especially the ones for that work for different governments.

They're very large, they have a large. Office where you have all these giant screens going on, you see these in movies, like when they were walking in and it's like, what's the threat and there's a, there's supposed to be a bomb here and they're trying to figure out like, what's going on. so a lot of times they're talking about a cyber.

Intel planner. These are the guys who put everything together. And if I could just read through some of this details here, it says, develops detailed intelligence plans to satisfy cyber operations requirements. So these are the guys that are managing all the information that's coming in and how we're gonna, what we're gonna do once we gather that information.

So that is collect and operates, dealing with a lot of Intel type stuff. And You see it in movies and stuff like that. That's, it's not like the movies to be honest with. It's pretty boring. But okay. Investigation. Now, this one, if you ever seen the show CSI, this is. It, the digital forensics, not necessarily the scientists scientific forensics where they're trying to figure out when a person was murdered, based off of the insects that are consuming the corpse or whatever, sorry to be so crude, but that's forensics, digital forensics is a little bit different.

This is the people who will take a computer. A lot of times they'll work with law enforcement and stuff because they're dealing with very heavy issues. I don't wanna get flagged for talking about some of the stuff that they find. But if you're talking about digital forensics, you're only talking about a few crimes major crimes that are gonna have to necessitate a digital forensics guy, major crime murders, and assaults that were caught on fi on, on digital media.

And somebody try to hide some. Illegal contraband on their computer and try to do some illegal transactions using cryptocurrency or something like that, and they have to trace back. Where the cryptocurrency wallet it's went to, or they have to figure out see if somebody was using some illegal pictures or images on their computer, but they try to erase it.

But with digital forensics, you can actually extract that from the ones and zeros on the hard drive. That is what we're talking about when we're talking about investigations. So they work a lot with the law, with law enforcement, they work a lot with with The with law they might have to do things like what you call it.

Chain of custody, where they have to make sure that the hard drive that they're investigating can get to trial and not be tampered with and things like that. So that's investigations then you have maintain and operate. So what is this one maintain and operate is this one's pretty self explanatory.

Once, once you see some of the job titles and stuff in here network services, that's like the people who install, configure, test operate, maintain the network, the firewalls. The switches, the hubs, they, they say hubs here, but not many people use hubs that much anymore. So that's funny, but system administrators, these are people who install, troubleshoot, maintain the servers and the configuration files and make sure that the config, the confidentiality, the integrity and the availability of the system is protected.

So yeah, that's that is maintain and operate. Then you've got overseeing governor. I could talk. My entire site is about this one specifically about cyber security management. Cause this is what I do. And this is when I, when we were talking about this in the beginning, we were talking about what exactly what I'm doing, which is.

This right here, information system, security manager, actually, I'm a my specialty is information system security operate officer, but management's something I do as well. So it's security. Doing cyber security for the whole organization, making sure that the cyber security of the organization is sound making sure the documentation is good, making sure that you've got all the system security controls are in place, things like that.

And you have to work a lot with the C level execs, high level security people within the organization. Doing a lot of coordination talking with the program managers, talking with the subject matter experts on the firewalls, on the networks, on all that kind of stuff, to make sure that we, as a team in the organization are doing what we're supposed to do, whether that's doing PCI compliance or HIPAA compliance or whatever industry standard we need to meet, that's what cyber security managers are doing.

And. COMSEC manager. These guys manage the cryptography, the crypto keys within an organization. So that is one, that's just one of the specialty areas that we're talking about for overseeing govern. This also goes into C level execs, your CIOs, your CIS OS with chief system security officers, or your chief information security officers, your C level execs, you're legal people.

You don't know often see legal people. Lumped into cyber security, but here it is right before your eyes. I'm telling you, the point I'm trying to make is that cyber security is not just programming. It's not just hacking stuff. It's also, it includes legal advocacy. Because the organization has to protect its reputation.

If somebody's defaming the organization, right? Their reputation is at stake. Who do they go to? You go to your legal team. Your legal team is, has to determine, okay, did these people defam? The, our organization are these, do we need to do a cease and desist order on this website? That's trying to. Do what's called typo squatting.

That's where you let's say google.com, but some somebody creates a site called Google, whether E and the L are transposed so that people, whenever they miss type Google, it goes to their site. And then they take you to a, some malware or something. Some other site. So are, do we have a legal case?

For the protection of our reputation or not, so legal is also where you would talk about, okay, we need to develop a privacy notification. We need to develop a a, something so that some, a non-disclosure agreement for all of our users who come in that's legal department. They, so they're very much involved with things like.

Privacy notifications that pop up on a website whenever you've gone to a website that privacy notification pops up, that's serious because the organization doesn't wanna be liable to, they don't wanna get sued because they released your information without you knowing about it without you, knowing what you were clicking on.

So they have to go to the legal department for that kind of stuff. Cyber security includes that kind of. So let's keep going here. I wanna show you a few more things and I'll keep it a little bit briefer on the next ones, what we do. So that's overseeing, govern. Let's go to the next one, which is protect and defend.

This is one of my favorite ones, cuz this one, excuse me. This one includes cyber defense analysis. In a past life. This is what I did. And this is, this one is really fun. I really love doing this one. This is people looking at logs. It looks like the matrix. Like they'll sit there and they're watching a screen full of logs go by and they're trying to figure out what is, if there's any kind of attacks going on in, on their, in their environment.

If there's some, if. Malware happening in the environment. Like it, it actual infiltrated the environment, or if there's somebody doing something they're not supposed to do, you could pick that stuff up in the logs. If you know what to look for. And they're looking for certain patterns of behavior inside the logs, that's reflected in what's going on.

Cyber defense analysis is where you would do that. It's picking up the IDs, intrusion detection, intrusion prevention, the firewall logs, the network, traffic logs, all that stuff. And it's making a determination. And these days you can do it a little bit with artificial intelligence to help you out, to help out the actual cyber defense analysts.

So that. What we're talking about with that's one of the things that we're talking about with protect and defend another huge one is incident response. That's a big one. And then vulnerability. These are like whole. Industries, by the way. This I'm briefly mentioning the names, but this is an entire industry in and of itself.

This one incident responses is own thing. And so it's vulnerability management. Okay. Let's go to securely provision. And this is the last one last, but not least this one's getting into risk management. This is something I do a lot. This is my whole job right here. Risk management. This is making sure that the organization is within a acceptable level of risk because every system that's out there, every single system, no matter what system it is, has some certain level of risk that they have to operate with.

And so risk management is just simply making sure that the risk is not too great for them to operate and not the risk. If a system has too much risk. It's too much exposure to their critical systems, then they can get, they're gonna get hacked at some point, they're gonna have a breach at some point, if your risk is too high.

So you need risk management as a specialty area, software development, whenever you develop software, you gotta make sure that software is developed securely so that you don't have any major breaches. A lot of the breaches that happen especially with zero. It's because of software issues, that software that wasn't secure and that's all in securely division securely provisioned rather.

So there's other things in here and the whole point I'm trying to make before I close this thing out and I'm almost done here is that cyber security is a huge, it's a huge field. It includes everything from manage. Program managers are very integral part to cybersecurity. It's a whole different discipline.

They do not have to have hands on stuff. They do need to, at some point, understand the organization's process on how software is developed, but not necessarily no Java or no C plus, or how to actually code or how to use the coding libraries and all that kind of stuff. They don't need to. They need to know the organization's process.

They need to know things like agile. They need to know things like what's the other one, scrum. And and things like that, processes that allow an organization to get to securely build the system securely build the software, develop the software, things like that. They need to know. So it, this includes C level executives.

This includes like we said, manage. It includes risk risk management, managing the risk effectively for an organization. It includes an, a lot of analysis. It includes all of these aspects. So whenever you think, whenever somebody says cyber security, just know it's a huge field, and it's not just one thing.

It's many different things. Okay. That's it for this one, guys. Thank you for watching me. I really appreciate it. I'm trying to do these lives. Daily. I'm I've got one on YouTube coming tomorrow. I'll try to put this on TikTok as well. I try to put on as many platforms as I can tomorrow. I do these at least once a week on Saturdays, one o'clock mountain standard time on YouTube.

I've got a podcast it's called pod combo courses dot pod, bean.com. And if you go to combo courses.com, there's tons of downloadables tons of free stuff. It's free to actually sign up there and I'm always giving out stuff like this where I don't expect you to pay me anything. I'm just giving you out information so we can get.

More people where they can take care of their family. To me, that's the name of the game you taking, being able to take care of yourself and being unable to take care of your family. That's the name of the game? That's why I teach people how to get into this field, how to make more money in this field and how to have security in this field.

Financial security. A career security so that they could take care of themselves and their family. All right, guys, that's it for this one. Thank you so much for watching. I really appreciate everybody. Who watched and I'm sorry, I couldn't get to your questions this time. Maybe next time.

We'll attack those questions. Peace.

View Details

Hey guys, this is Bruce, and welcome to combo courses, podcast. I'm doing an experiment where I'm doing daily is here. We'll see how this goes. I don't know if I'll keep this or maybe I'll do this twice a week or something like that because it hasn't been that bad. I got so many things. I can talk about so many questions to answer, but right now I wanted to focus my time on the categories of cybersecurity.

So a lot of times. Industry people think that cyber security is all about. And I think it's all about just hacking or something like that, something to that effect. And those are the things that are popular, just Hacking or pin testing or programming another one's for digital forensics.

People think that's all that there is, but in cyber security, not just I've been doing this for a very long time. I've done everything from the technical side where I'm actually configuring systems and installing systems and that kind of thing. But I've also done the, more of the management type side.

And I want to tell you that there's. So many different. Parts to cyber security. And when you see somebody talking about hacking or whatever it's very glamorous, but that's a tiny fraction of the whole spectrum of cyber security. It goes very deep. So if you're actually trying to get into this career path, cuz it pays very well and it does then I, what I wanna do is introduce you to some other categories of cyber security that you may.

Know about. And so one of there's an organization out there and it's from nonprofits and the government and a couple of private sector. They got together and they broke down the different categories of cyber security that need to be addressed. And it's not just. Cyber security by itself. Some of it is you can have a system administrator who does cyber security, that also accounts for this one.

And I'm gonna explain that in a second. If you stick with me, you'll understand this and you'll understand, especially if you, this is particularly for you. If you are trying to get into cyber security, if you're interested enough to want to be a part of cyber security in this field. And if you've been thinking about getting into it, I'm gonna show you the whole spectrum of cyber security.

Let me show you. A framework called it's called the workforce framework for cyber security. And if you didn't know about this is something the federal us federal government has been using for years now to figure out what categories to put people in and what kind of training that they need to do in order to be in these different categories.

And from a bird's eye view. Let me. Switch my screen over here on TikTok. Feel free to ask me any kind of questions. I'll be doing this for about 30 minutes if you're interested in this, but let me show you what I've got going on here. And I'm just so you know, I'm broadcasting on a podcast, but I'm also doing so I, I will explain what we're looking at here, but you can watch this on YouTube and Facebook eventually will put this on Facebook.

But here we have all the categories. Now there's seven different categories at the time of this recording. There's analyze. There's collect and operate. There's investigate. There is operate and maintain, overseeing, govern, protect, and defend and securely provision. And what I wanna do is give you an example of each one of these seven categories, cuz each one of these breaks out into specialty areas.

So for example, analyze breaks out into. What you call exploit analysis, language analysis, target analysis, and you'll see that some of these don't look like cyber security topics, but they, in fact they are now, if you happen to be dual bilingual, if you happen to know another language Very fluently.

You might actually be able to very quickly go into something called language analysis, which we'll briefly touch on in a second. But what I wanna keep this kind of high level right now, just to show you the different specialty areas. Now there's about, I don't know, 30 or 40 different specialty areas.

Each one of these categories of cyber security breaks out into these special specialty areas now in collect and operate, you'll see things like cyber, operational planning, you don't think that would have a lot of hands-on stuff and it actually doesn't. So let's keep going here.

And when I say hands-on, I mean like somebody who's actually configuring a server or setting up a network and stuff like that, cyber security is not all just about that. It's a very broad area. It's a very broad umbrella. So investigation is what you might expect is digital forensics, cyber investigations.

Threat hunting, things like that. And we'll cover that in a second operate and maintain. This is what people normally think about when they think about system administrators, data, administrators, network services, that's their network engineers, things like that. These guys are in.

Cyber security in that they have to do a lot of cyber security-type activities. They're not typically seen as cybersecurity people, but they have to do a lot of things in cybersecurity. As you might expect when they're installing patches or things like that. Overseeing govern. So this is what I do.

I can speak extensively on this, but this is a lot of management type stuff. Cyber security management. This is your C level execs and it even includes legal and program managers. This is something I would very much like to talk to you about because program management requires a certain level of emotional intelligence that a lot of it people do not.

Okay. And I, it's a very important a very critical piece of any kind of system engineering, any kind of major cyber security projects, anything the organization is doing that where they're spending a lot of time, money, and energy, and a lot of resources. They need a program manager. I'll get off my soapbox on that one, but it also pays very.

And that's something I talk about a lot on my site program management is a big one. Okay. Anyway, let's keep going. Let's keep it high level protect and defend. So protect and defend. Is dealing with a cyber defense analysis, just to name a few incident response. That's a huge one, vulnerability assessment and management.

Huge, but that's for protect and defend. So you see, this is not all just firewalls. This is not all hacking have I haven't even mentioned hacking yet. That's how big this field. And there's some things that are not even included on here. Like cryptography, you don't see cryptography on here, but cryptography is considered part of part of cyber security.

And I would argue that the cypherpunks, the guys who created The concept for Bitcoin and all that kind of stuff were also very good cybersecurity people anyway. So securely provision. Now this one has to do with risk management, software development, system architecture, that sort of thing. So you can see, what I wanna do is just show you.

The high level here. There's many different categories of cyber security and it's not all just hacking. It's not all just programming. Yes. Those are part of what we do. But in the major scheme of things, like when you look at the big picture for all of this it's a very big feel. And I wanna just explain to you why if you think about it, it really makes sense when you go to your bank and you are trying to send a wire transfer from one.

Using ACH to another bank, right? Or you wanna wire something overseas or whatever the case may be. The bank has a certain they have certain protocols and procedures and certain policies that they have to do in order to secure your information to make sure that the $1,000 you sent from one bank to another, or from, to your, whoever.

Wherever you're sending it. They have to make sure that information is protected. The rules and protocols and procedures and the legal system. All of the things that come together that is known as secure security compliance. Now the financial industry has a different set of laws, as you would imagine than say the healthcare.

The healthcare industry is protecting your healthcare information, your digital, if it's that information is digitized, they have to protect that information, right? So they have a whole different set of laws that are completely different because it has a different has a different, it has, it requires a bus different business solution than say a bank.

If you think about it like this, the government, the federal government, who's protecting your social security number. They're protecting your, I don't know. They're holding, making sure that things like the DMV, if you're talking about the state they have to protect your personal on for information as well.

and making sure that's, of course there's all kinds of leaks and all kinds of hacks and all that kind of stuff going on, but they have a whole different set of procedures and rule sets and laws that apply to the federal and state government. And that's also called security compliance.

Security compliance is in every industry. It's in every state, it's in every jurisdiction, it's in every county and it's in every country. Each country has their own set of laws that pertain to. And all of us, all of them have different solutions that they need for their particular situation. So one would imagine as you can probably imagine, there's a lot of security that has to be done for that.

And it's not all hacking. Like you can see how hacking is a tiny drip and a gigantic ocean that is cyber. Cybersecurity is a very huge field and that's why you have seven different categories. Now, what I wanna do is kinda give you a practical understanding of these seven categories. Now let's start from the top here.

I'm gonna give you a specific example of where you might have seen this on TV or in a movie, or relate it to something you can understand here on a practical way. So let's start with analyze the first category we see on the top here is analyze. Has these specialty areas right here. Now, if you break these down and if you wanna go to the site, by the way, if you happen to be watching me on YouTube I have a link to where you can actually follow along.

The actual site. Is there in the link now analyze, let me give you a practical understanding what analyze is now. When I was in the military, we had, when I was in a combat zone and we have we had languish analyst. Whenever we and the reason why we had these language analysts was because we can't understand, say if say a another country is attempting to hack our systems, like they'll put some code on our systems and that code has to be in Ukrainian or in Russian or whatever other language you need a language.

To actually figure out what is being said in that in that code. And that's why a lot of times they figure out, oh yeah this hat came from Russia. This hat came from Ukraine. This hat came from whatever country, because you have an language analyst who has they're multidiscipline in language languages, where they can figure out and decipher and figure out like what's going on.

They'll have like different tools. That'll help them to decipher what's going on with that, with whatever hack is going on. So this is actually a part of the analyze category. Let me give you another example, threat analysis. Now this is a big one. So a cyber threat analysis is something where what you're doing is.

You're trying to detect and figure out where a company might get hacked from an organization might get hacked from, and it sounds impossible. Sounds crazy. How can you figure out where threats are coming from? There's some ways to do it. So if you think about like this right now, somebody might be trying to hack, I don't know, I'm just pick something off the top of my head.

They might be trying to hack Walmart or something. Wal, what Walmart can do is they can have somebody scour the internet. Do search conduct searches or create a tool that goes out and. Does a web crawl of the internet to figure out okay, who is mentioning Walmart who is talking about it on social media?

Who's talking where are the communications that are in the public domain to figure out who is talking about us so we can figure out where those threats are coming from. Because a lot of times when these, before the attack even occurs, these criminal hackers are talking amongst each other on the dark web.

About how they're gonna attack or they even already had the attack. They already pulled the information from there and they're selling Walmart's emails. Now this is just an example. I just, so you know, I don't have a client with Walmart or anything like that. I don't have not interacted with Walmart's cyber security.

I was using them as an example and I'm unaware of any current tax or anything like that. Just, this is just an example, but that is what threat warning analysts do. And this is something I did at my last job, as a matter of fact, that was one of our jobs was to do threat analysis on companies to figure out what's going on.

And this also pertains to doing cyber looking at terrorist threats for whole countries, by the way. So that's analyze an analyze goes into analyzing information, analyzing targets, analyzing threats that might be coming to a cyber security through, to an organization. There is, there can be some hacking involved.

There can be times where you have to know a little code, but language analysts don't typically know code, and then all source analysis. This goes straight into just intelligence. This is normally what you'll see in like intelligence organizations where they're gathering actual, actionable intelligence from other.

From multiple sources, putting that information together to figure out, okay, we have a terrorist threat here. We have a terrorist threat there. We know that we have advanced persistent threats here and there. We have some, we have reason to believe we have human intelligence people on the ground where they've gathered this or that information to figure.

Who's gonna attack what, and a good example of this one would be that if you've ever watched a mission, impossible the ghost ghost recon, that one, they have, they talk about this type of job all the throughout that one. The as a matter of fact, they have one of the characters is an analyst, and this is the, what they're talking about.

This is somebody who. Who pulls information from different sources, different intelligence sources puts it together and figures out. Okay. We know that there's a credible, there's a probable attack. That's gonna happen over here, over there, based off of all the Intel that they've gathered in the field.

Okay. So we beat that one to death. Let's keep going here. So that is analyzed and that's in cybersecurity. Then we've. Collect and operate. Let's look at this one. So here's the specialty areas with collect and operate. Now, what are we talking about here? This is also dealing with a lot of intelligence, this, a lot of govern department of defense and some of the other three level organizations will have something like this cyber operations, where they're also looking at real time threats.

They're looking at foreign intelligence entities. So this one's very much related. To what we were talking about here analyze a lot of times we'll see these in security operation centers, a security operation center, especially the ones for that work for different governments.

They're very large, they have a large. Office where you have all these giant screens going on, you see these in movies, like when they were walking in and it's like, what's the threat and there's a, there's supposed to be a bomb here and they're trying to figure out like, what's going on. so a lot of times they're talking about a cyber.

Intel planner. These are the guys who put everything together. And if I could just read through some of this details here, it says, develops detailed intelligence plans to satisfy cyber operations requirements. So these are the guys that are managing all the information that's coming in and how we're gonna, what we're gonna do once we gather that information.

So that is collect and operates, dealing with a lot of Intel type stuff. And You see it in movies and stuff like that. That's, it's not like the movies to be honest with. It's pretty boring. But okay. Investigation. Now, this one, if you ever seen the show CSI, this is. It, the digital forensics, not necessarily the scientists scientific forensics where they're trying to figure out when a person was murdered, based off of the insects that are consuming the corpse or whatever, sorry to be so crude, but that's forensics, digital forensics is a little bit different.

This is the people who will take a computer. A lot of times they'll work with law enforcement and stuff because they're dealing with very heavy issues. I don't wanna get flagged for talking about some of the stuff that they find. But if you're talking about digital forensics, you're only talking about a few crimes major crimes that are gonna have to necessitate a digital forensics guy, major crime murders, and assaults that were caught on fi on, on digital media.

And somebody try to hide some. Illegal contraband on their computer and try to do some illegal transactions using cryptocurrency or something like that, and they have to trace back. Where the cryptocurrency wallet it's went to, or they have to figure out see if somebody was using some illegal pictures or images on their computer, but they try to erase it.

But with digital forensics, you can actually extract that from the ones and zeros on the hard drive. That is what we're talking about when we're talking about investigations. So they work a lot with the law, with law enforcement, they work a lot with with The with law they might have to do things like what you call it.

Chain of custody, where they have to make sure that the hard drive that they're investigating can get to trial and not be tampered with and things like that. So that's investigations then you have maintain and operate. So what is this one maintain and operate is this one's pretty self explanatory.

Once, once you see some of the job titles and stuff in here network services, that's like the people who install, configure, test operate, maintain the network, the firewalls. The switches, the hubs, they, they say hubs here, but not many people use hubs that much anymore. So that's funny, but system administrators, these are people who install, troubleshoot, maintain the servers and the configuration files and make sure that the config, the confidentiality, the integrity and the availability of the system is protected.

So yeah, that's that is maintain and operate. Then you've got overseeing governor. I could talk. My entire site is about this one specifically about cyber security management. Cause this is what I do. And this is when I, when we were talking about this in the beginning, we were talking about what exactly what I'm doing, which is.

This right here, information system, security manager, actually, I'm a my specialty is information system security operate officer, but management's something I do as well. So it's security. Doing cyber security for the whole organization, making sure that the cyber security of the organization is sound making sure the documentation is good, making sure that you've got all the system security controls are in place, things like that.

And you have to work a lot with the C level execs, high level security people within the organization. Doing a lot of coordination talking with the program managers, talking with the subject matter experts on the firewalls, on the networks, on all that kind of stuff, to make sure that we, as a team in the organization are doing what we're supposed to do, whether that's doing PCI compliance or HIPAA compliance or whatever industry standard we need to meet, that's what cyber security managers are doing.

And. COMSEC manager. These guys manage the cryptography, the crypto keys within an organization. So that is one, that's just one of the specialty areas that we're talking about for overseeing govern. This also goes into C level execs, your CIOs, your CIS OS with chief system security officers, or your chief information security officers, your C level execs, you're legal people.

You don't know often see legal people. Lumped into cyber security, but here it is right before your eyes. I'm telling you, the point I'm trying to make is that cyber security is not just programming. It's not just hacking stuff. It's also, it includes legal advocacy. Because the organization has to protect its reputation.

If somebody's defaming the organization, right? Their reputation is at stake. Who do they go to? You go to your legal team. Your legal team is, has to determine, okay, did these people defam? The, our organization are these, do we need to do a cease and desist order on this website? That's trying to. Do what's called typo squatting.

That's where you let's say google.com, but some somebody creates a site called Google, whether E and the L are transposed so that people, whenever they miss type Google, it goes to their site. And then they take you to a, some malware or something. Some other site. So are, do we have a legal case?

For the protection of our reputation or not, so legal is also where you would talk about, okay, we need to develop a privacy notification. We need to develop a a, something so that some, a non-disclosure agreement for all of our users who come in that's legal department. They, so they're very much involved with things like.

Privacy notifications that pop up on a website whenever you've gone to a website that privacy notification pops up, that's serious because the organization doesn't wanna be liable to, they don't wanna get sued because they released your information without you knowing about it without you, knowing what you were clicking on.

So they have to go to the legal department for that kind of stuff. Cyber security includes that kind of. So let's keep going here. I wanna show you a few more things and I'll keep it a little bit briefer on the next ones, what we do. So that's overseeing, govern. Let's go to the next one, which is protect and defend.

This is one of my favorite ones, cuz this one, excuse me. This one includes cyber defense analysis. In a past life. This is what I did. And this is, this one is really fun. I really love doing this one. This is people looking at logs. It looks like the matrix. Like they'll sit there and they're watching a screen full of logs go by and they're trying to figure out what is, if there's any kind of attacks going on in, on their, in their environment.

If there's some, if. Malware happening in the environment. Like it, it actual infiltrated the environment, or if there's somebody doing something they're not supposed to do, you could pick that stuff up in the logs. If you know what to look for. And they're looking for certain patterns of behavior inside the logs, that's reflected in what's going on.

Cyber defense analysis is where you would do that. It's picking up the IDs, intrusion detection, intrusion prevention, the firewall logs, the network, traffic logs, all that stuff. And it's making a determination. And these days you can do it a little bit with artificial intelligence to help you out, to help out the actual cyber defense analysts.

So that. What we're talking about with that's one of the things that we're talking about with protect and defend another huge one is incident response. That's a big one. And then vulnerability. These are like whole. Industries, by the way. This I'm briefly mentioning the names, but this is an entire industry in and of itself.

This one incident responses is own thing. And so it's vulnerability management. Okay. Let's go to securely provision. And this is the last one last, but not least this one's getting into risk management. This is something I do a lot. This is my whole job right here. Risk management. This is making sure that the organization is within a acceptable level of risk because every system that's out there, every single system, no matter what system it is, has some certain level of risk that they have to operate with.

And so risk management is just simply making sure that the risk is not too great for them to operate and not the risk. If a system has too much risk. It's too much exposure to their critical systems, then they can get, they're gonna get hacked at some point, they're gonna have a breach at some point, if your risk is too high.

So you need risk management as a specialty area, software development, whenever you develop software, you gotta make sure that software is developed securely so that you don't have any major breaches. A lot of the breaches that happen especially with zero. It's because of software issues, that software that wasn't secure and that's all in securely division securely provisioned rather.

So there's other things in here and the whole point I'm trying to make before I close this thing out and I'm almost done here is that cyber security is a huge, it's a huge field. It includes everything from manage. Program managers are very integral part to cybersecurity. It's a whole different discipline.

They do not have to have hands on stuff. They do need to, at some point, understand the organization's process on how software is developed, but not necessarily no Java or no C plus, or how to actually code or how to use the coding libraries and all that kind of stuff. They don't need to. They need to know the organization's process.

They need to know things like agile. They need to know things like what's the other one, scrum. And and things like that, processes that allow an organization to get to securely build the system securely build the software, develop the software, things like that. They need to know. So it, this includes C level executives.

This includes like we said, manage. It includes risk risk management, managing the risk effectively for an organization. It includes an, a lot of analysis. It includes all of these aspects. So whenever you think, whenever somebody says cyber security, just know it's a huge field, and it's not just one thing.

It's many different things. Okay. That's it for this one, guys. Thank you for watching me. I really appreciate it. I'm trying to do these lives. Daily. I'm I've got one on YouTube coming tomorrow. I'll try to put this on TikTok as well. I try to put on as many platforms as I can tomorrow. I do these at least once a week on Saturdays, one o'clock mountain standard time on YouTube.

I've got a podcast it's called pod combo courses dot pod, bean.com. And if you go to combo courses.com, there's tons of downloadables tons of free stuff. It's free to actually sign up there and I'm always giving out stuff like this where I don't expect you to pay me anything. I'm just giving you out information so we can get.

More people where they can take care of their family. To me, that's the name of the game you taking, being able to take care of yourself and being unable to take care of your family. That's the name of the game? That's why I teach people how to get into this field, how to make more money in this field and how to have security in this field.

Financial security. A career security so that they could take care of themselves and their family. All right, guys, that's it for this one. Thank you so much for watching. I really appreciate everybody. Who watched and I'm sorry, I couldn't get to your questions this time. Maybe next time.

We'll attack those questions. Peace.

View Details

http://convocourses.com

All right. I'm testing a new platform called stream yard, and this is convocourse's podcast. I'm gonna do about, I don't know, 20, 30 minutes to test this out and also to inform you guys of a career move I recently made. I haven't really talked about this. But about three months ago I was working as a cybersecurity consultant and that's much different from an information system, security officer.

So in the past, Three four months. I made a big Mo well, not really a big move. I I've, it's not a big move for me. I've done both jobs before, but all I want to do is compare the two kind of give you an idea of what the differences are between cyber security consultant.

And what I'm going to be doing with information system security officer work, and what's the daily life of both of those things. How do they compare and give you an idea of which one you should choose before I start, you should know that I own a site called combo courses where I teach cyber security compliance and how to get in this field as a cyber security person.

I've been doing this for 20 years, doing cyber security in all forms of security, as well as some it information technology stuff like being a system admin or network. Administrators, stuff like that. I've done a little bit of all that stuff. But my specialty is really in security compliance.

And so that's what I teach people to do. And. People ask me on YouTube, on, on TikTok questions. And I'll just go ahead and answer them and by the way, if you have any questions during this feel free to ask them and I’ll do my best to answer. them sometimes we have such a great community that they'll actually answer the questions on my behalf.

There’re things I don't know. So, somebody, some other subject matter expert will jump in and then answer those questions and. My favorite times on this, on convo courses, because that's what convo courses in my mind is all about is about the community and us coming together, figuring things out. Okay. So, I wanted to tell you recently I made a huge move.

I was working at a major telecommunications company that does cybersecurity on the side. They have a branch that does cybersecurity and I did it because it was a great opportunity. One of my former coworkers. Gave me a they referred me and brought me into the company. It was a great company.

They had great benefits. It was some of the best benefits I've had outside the military. It was decent pay and the only, probably bad thing was that there was a lot of travel and that eventually was the thing that got me out of there. And it was stressful too. And I was how having too many personal issues that happened at that at the time that I was working there, I worked for there for about two and a half, three years, and I was doing cyber security consulting for them.

So, what we would do is we would. We bring our expertise to smaller companies. We go to, and it's a lot of companies and banks and hospitals and healthcare industries that you probably use to be honest with you. that? I Some of I was surprised were like, damn, I use this. We're doing security compliance for them.

And the security compliance it wasn't just security compliance. It was basically, we would do a bunch of We would do a bunch of risk assessments and those risk assessments would be things like be we had 15… different risk assessments. So, 12, 12 to 15 different risk assessments, depending on what they chose.

So we would do things like physical security assessments we would do. Of course, network security assessments. There was like three of those. We did cloud-based security assessments. We did… We did wireless security assessments. We take all of those and we would give them an overall view of what their security looks like.

And then we would prioritize where their major risks were. And then we would talk to the sea level or director or upper-level management to say, hey, this is where you should focus your energy because this is where we see the most risk. And the purpose of that was to reduce their. Their security any kind of vulnerabilities they have, and they can focus all their time, money, and energy and resources to that highest level of risk in their organization.

That's what I was doing. And it wasn't too bad. I actually liked it. I fit right in over there. The only I, we would do these reports, which were really easy for me, the. Challenging thing I found was sometimes the clients were a bit difficult to work with and it wasn't that they didn't know what they were doing or something like that.

It was just very high strung because cybersecurity. It could be very stressful because you're dealing with you. If you have a vulnerability, a major vulnerability and you have to take that to the C CEO and say, Hey, we have. We have a bunch of legacy systems that are in this area here, there's a lot of stress because you don't want to be the person that to, to barer of bad news, and we'd find those things and we'd say, Hey.

You have this stuff going on. And there was just a lot of stress with that. That's probably the hardest part of the whole thing. The travel wouldn't have been a big deal if I hadn't had so many personal issues happening with my family, kids and everything that just all happened at once. So, I had to unfortunately had to leave because I actually really loved the people and everything.

What did my daily life look like? We were mostly going off east coast time for me, because that's where most of my clients were. They'd give us like two or three clients. And then you would work directly with them. So, most of your day was coordinating. The scans and the assessments that you'd have to do, if you had to go to their site, you'd have to coordinate that.

And they expect you to go do that on your own. It was very self-directed where it's you have the client, like you'd run the meetings with them. You'd coordinate when you're going to go there. You'd coordinate how many hours or how much time it would take to get there and who you're gonna meet and all of that stuff you'd have to do.

And then the scans, we had a, like a separate scan team. We'd work with the scan team. We'd work with the program. Managers we'd work with them and we'd put together this report to deliver. On a quarterly basis and sometimes annually, it depends on what kind of assessment it was. Because obviously you wouldn't do like a physical assessment every quarter.

Because I didn't, that wouldn't really make any sense because it stuff doesn't change. But anyway, so that's what we would do. It is mostly meetings and coordination and doing scans and reviewing the scans and then writing reports that's your, that was your whole day as a cybersecurity consultant at this organization.

I was with where. The main thing we did was deliver these reports and we would do really, most of it was risk assessment type stuff. And I was very familiar with that because in the department of defense, we do a lot of security assessments and stuff. So that's very different from where my main core specialties are, which is security compliance.

We would dabble a little bit in security compliance like every now and then. We I would help them do like a PCI compliant PCI audit or something like that or we'd say, okay here's how you, your system would fit into eight NIST 800 or here's how your system would fit into CIS controls.

You do a little bit of that, but that wasn't really what we're, that would, it was separate from what we were doing was mostly risk assessment type stuff. So seeing where their risks are and determining that. Now that brings us to the next thing, which is information system security officer. So information system security officer is more in compliance.

It, the compliance space, security compliance and security compliance is making sure an organization is lined up with regulations, laws, industry standards. That doesn't have to be the federal government, which is mostly what I work with. It can be with hospitals have a certain standard that they're supposed to meet.

One of which is called HIPAA, where they have to make sure that they're protecting their patient's healthcare information and their digital records for the healthcare and stuff like that. Another example of industry standards would be PCI compliance. That's protection of. Of credit cards. So whenever you are at a store and you're using your credit cards, they're supposed to have a separate network for those point of sale devices.

So that doesn't touch, say the wifi that's in the that's for the staff or for guest to log in. So that has to be a separate protected network so that the credit card data has its has, is protected. So separate from your. Other networks. That's just one of the things you have to do.

Another things you have to do for PCI compliance is have the adequate documentation for the security of the system. Like making sure that net, we have network diagrams and making sure you have asset and inventory of all the assets, things like that. Those are all the types of things that you would have to do for PCI.

And that's, those are just two examples, but you've got CIS compliance. You've got. ISO 27,001 compliance. You got many different countries have their own security compliance and different industries like have their own compliance. So my, my specialty is in NIST 800. Security compliance NIST 800 is what the federal government has created and adopted as the main source of security controls.

Sec security controls is a set of security features that protect the organization's. Primary assets. That means like your main server that has all the social security numbers on it. Your main server that has all the secret secret data on it, the main server that's holding all the maps of different parts of the world.

Those, that's what you call an asset. So those are just some of the examples of, and those are some of the difference. Now, one of the things that, what the daily, what it looks like from on a day to day basis for an is. Just to compare this versus versus the consulting I was doing.

So it's also a lot of meetings. Security is a lot of coordination. Cyber security is a lot of coordination with different organiz because you're having to meet. Different subject matter experts like you, you're not necessarily the person who's locking down the, those, that windows server.

That's gonna be a server type person. That's gonna be a person like a system admin who specializes in Linux, red hat, network, administration and windows 2019. Active directory servers so you are gonna coordinate with them. So in ISSO, that's what they do. They're coordinating with these different, the firewall guy, the the privacy person.

They're coordinating with all these different people to make sure that the organization has a certain level of. So it is a lot of meetings. It's a lot of meetings with a lot of different people, and that's probably the main difference between the meetings. Like an ISSO is gonna have a meeting with all kinds of people throughout the organization.

One organization, whereas a consultant is gonna have a meeting with just a few people at different organizations like me. I had three or four clients at a, any given time and I would have to coordinate with the there's like a main point of contact. I would talk to big two or three main points of contact and every now and then I'd meet like a C level exec, but I was talking to three or four different organizations.

Whereas an ISSO is talking maybe one organization and there might be other sub organizations, but they're all one you're talking about many people in that organization. So you're going really deep in, in all of the details and stuff and making sure that all the securities is is in place. Now it wasn't, it's not like an enforcement role.

Typically you are more like a news reporter. What I mean by that is a lot of people think that you're the police and you're gonna come and busting down doors and say, Hey, this, we gotta secure this server. That's not really your job. Like you might point things out, but the person who has to be the enforcer is gonna be the management, because they're the ones, things come down from management.

So they have to be the ones to enforce that stuff. Now if you happen to be the voice piece, the mouthpiece to tell them, Hey, the CEO just said. You're just a reporter. You're just reporting to them. Hey, this is what happened. We have to obey what is going on with this organization's policies.

Here's what we have to do. So that's the main differences between a security consultant and information system, security officer. The reason why I quit my job as. A consultant and went over to, and now I'm going to back to information to security officers has more to do with. Not the work per se. It was, it is more like the travel, like the organization I was at was paid really good, had great.

One of the best benefit packages I've ever had, but it was too much travel and I had too much stuff going on. And I had too many clients, it was getting a little stressful plus I had family stuff I had to deal with. So that's the reason why I transitioned over. And now I'm going to somewhere where it's a little bit more It's gonna be a better fit for me and my new family situation.

So that's what's going on. Okay. I've got some questions here. Let me see for Mike. Thanks Mike, for your question. I really appreciate that. And Mike says he says quick question the ISSM role coming from being an ISSO. What is what's your suggestion? Quick question is S. A ism role coming from, are you gonna be doing an ISSM role from being an is O I'm assuming that's what you mean?

So you were an ISSO and now you're about to be an ISS O sorry. You were an is O you're about to be an ISSM that's I'm trying to interpret your questionnaire. Any suggestions. Yeah. So the biggest difference between these two roles is that one is a manager information systems, creating manager.

You're gonna have more of you're gonna have even more meetings. I'm just gonna tell you like the differences. So an ISSO is more like they, they both have a lot of meetings, but an ISSOs has to be more in the weeds because ISSO has to be able to say, give an example of an issue. A vulnerability comes down the vulnerability.

Is let's make something up. A vulnerability is a zero day exploit on windows 2019 or something. And now the ISSO gets wind into this and that comes from the vulnerability team. Now they have to meet directly with the vulnerability team to figure out what's going on with this thing. And they might have to spend some time researching what the zero day exploit is.

What's the criticality of it. Like how quickly do we need to fix this thing? They have to be in the weed. So they have to go probably go to the CVE. CVEs and then figure out what type of what this affects. And they have to probably look at a list of every, all the systems that this is going to touch.

And how quickly can we fix this? So there. And if so is more in the weeds in that they have to know what is going on in a, on a technical level, they have to get more in the weeds and be more technical if you get what I mean. They might not have to touch the system. A lot of times, they're not the ones implementing the security controls, but they're coordinating with the people who have to implement those security controls.

Compared to that, to an information system, security manager, their meetings are more with upper level people. So they're dealing with stuff that's more broad and stuff. That's touching the entire organization and making sure you have enough making sure the security team has all the resources in that they need all the time and resources that they need to do their work.

So your. Gonna have the same amount of meetings or more, but they're gonna be with upper level management from. Fields like you're gonna be talking to the it manager, the information technology manager who, whom the network manager, the network engineering manager. You're gonna be talk, coordinate with them.

And you guys are gonna be talking about like resources. How many resources do we have to do this work? Okay. We just had this zero date on windows, 2019. Do you guys have the resources and time to do this? How much time do you guys need to actually get this? So you're talking about like on a broader scale, how do we manage the resources that our team needs to get this job done?

And can we get it done and effectively in a reasonable amount of time? And you're trying to, your main job is managing expectations to upper level management, the C level execs, the directors and all that stuff, managing their expectation. That is your main job, as well as taking care of the people who are.

You work for the ISSOs like your job is working for the, ISSOs managing the expectations of upper level management. So you're still in cyber security, but it's more of a management. You're not in the weeds. You're not having you. You'll never, you're not ever touching any technology. Whereas in ISSO they might have to touch something at some point like, and so they might have to touch the EMA system where they're inputting information there, they might have to mess around with creating.

They might have to create a security policy, might help create the security policy review, the security policy. They might look at audit logs. They might. Help enable audit logs. They might be the person who's doing threat detection and stuff. The managers, they're not doing that kind of stuff. They're working on resources for the information system, security officers.

So it's a great move because it is is SMS are ma are legit managers. And so they're paid typically paid a lot more. They're paid more. And if you. If you're a first time manager, you'll get, you should get a pay bump. But if you have been doing a management for a while, you get a significant pay bump, like if you've been doing it for a year or two, then you'll be able to like, if forever you move or.

Those are the guys who eventually become directors. That's the path directly to directors and see C level execs and things like that who gets paid a lot of money. So that's really good. That's a really good move. If that's the case, if that's what you're doing, then that's awesome, man.

And Mike says got it. ISSOs ISSO I worked with EAs and C C Sam and tenable. Yep. Tenable NEIS and all that kind of stuff. That's right. Exactly. You got it. They're more hands on and touching stuff. Whereas managers, they're not, they're gonna ask about, Hey, you have access to eMASS.

Okay, cool. Great. They might look in there since, okay. Let's make sure that the system security plan is there. All right. And any problems with the system security plan. Okay, good. There's no problems. Let's go or, Hey Does the new guy have access to EASs. Does the new guy have access to tenable?

Okay, cool. Or let me help out. Make sure that we have, let me coordinate with the person who controls access to tenable to make sure the new guy has it. Okay. The new guy we just have some people leave. Let's make sure that person is not, no longer has access to eMASS or tenable stuff like that.

That's the manager. They're not like putting things. Into EASs or running the scans necessarily. Sometimes I've been with some managers who did do that kind of stuff, but it was because they wanted to do it. And they were very sharp, very technical, and they wanted to do it and they, but they te they totally didn't have to.

And they had other things to do by the way. All right. Let me shift gears. If you guys have any questions, go ahead and feel free to, to ask me any questions. I'm testing out this new platform. That's why it all looks a little bit different. So if you want, have any questions whatsoever, feel free to ask me in the meantime, let me show you that I have a book out called R MF is O where walks you through it's a bird's eye view of what NIST 800 is all.

And it's very quick, and this is actually the audio version, which is only like one hour long. And then also I've got a deeper dive into the NIST 800 security controls, but I'm not hitting every single control. What I do is I hit the families and give you a practical understanding of what the families are and how you navigate those.

And interpretation of the families of controls. And I focus from an ISSOs perspective. What parts of that family do you really need to know? That's the kind of stuff that I'm focusing on. And another thing you guys should know, if you didn't know already is I have a podcast here. It is right here. The podcast is, I'm doing the podcast right now.

So this the type of stuff that you hear me talk about here is the kind of stuff that I actually is gonna be on the odd. But this, the difference is on a podcast, you could just be in your car, on your commute and listen to it, or when you're cleaning or something like that, you can actually just listen to it.

Listen to our conversation as we're, as you're doing your thing. So, that's the good thing about doing a podcast? I actually really like podcasts. I'm listening to one right now, learning a new language. And I really like it. Okay. Let me see. There's another question here from Mike. He says, can I book you for a consultant for my ISSO role ISSO role you know what I'm actually in the middle of a couple of other consultations, you can email me feel free to email me and I'll see if I can find some.

For you, I'm not saying no, but let me see what I can do. Here's my I'm gonna send you my contact. My contact is scrolling across the bottom. There is contact@convocourses.com. If you're interested in getting some kind of consulting and stuff like that, I'm I'm getting back into the work field.

I'm not gonna be able to do as much consulting as I was doing before. Because my hours are gonna get tapped, but Hey, who knows? Like maybe we can do it before I actually start my job right now. I'm going through the background. The background investigation process. Okay. I got another questions from.

Mr. Fernandez. He says, so I'm getting my bachelor's degree in, in cyber security in December, I'm currently working on physical in wor working in physical security for government contracting. So I'm dealing with classified documents and D O D things will. Will I be able to, okay, let me see the next rest of this question to get an entry level is ISS O I think you mean ISS O job in your opinion, yes or no.

Okay. So L Ludwig let me give you an example and I hope that my example can give you an idea. First of all, short answer is yes. Okay. I know this because I actually start off in physical security myself. So I was a. Security forces member in the air force. And basically what I was really, I was a weapon expert.

Like I don't even know if they have that, that it was called 3P0X1. That was my AFSC. It's a specialty code that they have had in the military at that time. I don't know if they I've been following it, but basically what I did was I was a weapon specialist and. I guarded planes. I guarded if the president came in to our base or whatever, I'd do that, I'd be on that detail.

Not much personnel security, to be honest, it was mostly garden resources. And then I also did some law enforcement. So I knew a lot about the UCMJ use of force, all that kind of weapons, training, combat training, all that work with the army and the Marines and all branches and different countries.

Security people, but it was mostly physical security and I trans we call it cross train. I cross trained from physical security to cyber security. There's a lot of crossover. I was surprised to, to learn that. Some I'll just tell you a few things that are gonna help you going from physical security over into cyber security into it in general.

Number one you are, you're gonna have a very sound understanding of security overall because it's not really that much. When you get into cyber security, it's just a lot of more layers and there's, it's more complex because you got defense in depth. Physical security still applies in cyber security, which is crazy.

But when you think about it's common sense, if anybody can touch a system, then they own it. You can own a system. You can take the hard drive out, put it in another device you can use password crackers you could use. Oh man, you, you could do forensics tools on it and then extract all the bits on it and figure out what people try to delete is that as a matter of fact, that's what forensics is all about.

And speaking of forensics some of the laws that pertain to, to you, like when you're talking about chain of custody, when you're talking about Making sure that things that, that things aren't tampered with during the investigations, all those things apply. So some of the laws still apply.

What else applies, man? Physical security checks, physical security assessments is it's. The concept is similar and actually is still used in cyber security. You has to still do physical security to make sure that the facility and the room that the information system resides in is protected so that all that stuff still applies.

So it is gonna help you out. And then the main thing is that if you dealt with classified documentation before, and if you have a security clearance, all of that will also help you. To get an entry level job in cyber security. And if specifically, in information to security officer, but any kind of entry level position, because you have a security clearance, if you have one that helps.

A lot of people confuse like security. They think that if you're in cyber security, you have to have a security clearance. No that's not the case. Two different things. The security, they should just call it a clearance. It's very confusing. A clearance just does a background check on you to make sure that you are trustworthy to make sure that you don't have any criminal background that might that might.

Cause a conflict of interest where you're working like a bank doesn't want somebody who robbed the bank. You know what I mean? It's stuff like that. A hospital probably doesn't want somebody who had malpractice it's stuff. Like they don't, there's certain criminal things that not to say that you if you had some kind of.

You had a case on you in the past that you couldn't work in cyber security? It's not what they're saying. It's basically, there's certain things that cause a conflict of interest. So I have to do a background check on you to make sure that there's nothing that might allow you to be exploited.

Or something that deems you as untrustworthy to do that particular job. So if you have a clearance that really helps out a lot if you've handled classified information before that actually helps you quite a bit as well, because some people don't have any experience with that and they don't know how that world works, but you knowing that, how that world works, that helps you quite a bit.

The main thing that you need to focus on now is technical. Because me going from physical security over to cyber security, that was the biggest challenge is learning all the terminology, learning information, technology, learning how computer works learning how Ram CPU and storage all works together.

Learning how to protect those components of information system. Those are the main things, all the layers and the minutia of learning networks, how to networks work how you protect those networks, stuff like that. Porch protocols, and services. Those are the things that you need to be really focusing your mind on the security stuff will come very naturally to you.

So the answer to your question is, yes, it will help you to get an entry level job when you get your, that bachelor's degree. Only thing I would recommend that you do while you're in school. And this is what I tell everybody is try to get experience. If you. Hands on technical experience, if you can. That means if you're whatever college you're going to, or if you happen to be in the military or wherever, whatever, wherever you're at, try to get hands on.

If you see the, we call them work group managers, fixing a computer, ask if you can help them out. If you can, if they will allow you to help them to fix that computer, whether it's update and virus, definitions, updating the security patches, whatever it is like even the simplest thing possible, even if it's putting the router in and plugging it in or whatever, you'll be able to put that on your resume.

And the experience is what they really wanna see a degree is great. Certifications are great, but the experience is what they really wanna see. Another thing is I would highly recommend that you, if you can, if you have the time, if you have the cycles to do it, some people do not is to get a certification while you're working on your degree.

Degree takes a pretty long time. And sometimes the degree helps you to get the degree. If they, if you're college or wherever you're going to has a degree, a certification program, I will go ahead and take it. It's not a waste of your time, especially if you get the comp Tia, any of the comp Tia ones. If you get any kind of cloud certification, if you get any kind of networking certifications, those are all gonna help you out a bit, a lot on your resume.

So I hope that answers your question. Okay. I've got another question here. It says Mr. Fernandez says and I'm a security plus certified I'm security plus certified, but I don't have the most experience with physical hardware. Okay. Yeah. Yeah, that's what I'm saying is go ahead and get as much.

Experiences you can with any aspect of information technology. And at this point, since you're new, anything will help you out. Like whether it's help desk type stuff, whether you're Updating, like I said, virus, signatures, whether I, the reason why I keep bringing those up, because those are the simplest things that kind of come up constantly over time.

Like you've probably done it before you just don't it's something we do often so often that we don't even think about it, but that is something you can literally put on your resume. You just need to know how to articul. Speaking of articulation, just to do a little transition here. I'm working on a book right now, a new book.

That's gonna tell you how to actually break down a resume. How to, I have a course on this already. So if you're interested I'm not trying to cram anything down anybody's throat or anything, but I'm working on a book. That's a lot cheaper that. It'll be about 20 bucks or something like that.

It'll have downloadable templates. It's essentially this right here. This course right here is something I've been using for a long time. And because of this, I haven't been without a job. I, this thing works like this process that I've been doing, basically, all I did was to say, okay, how am I getting all these jobs?

I literally get like 10 offers a day between LinkedIn. Messages on LinkedIn emails calls I'm literally getting anywhere from, it's not as much as it used to be before COVID and now we have some kind of a downturn in the economy. So it's not as many as it used to be, but it's at least six messages a day.

I get for different jobs and I'm just constantly getting undated with these opportunities. And so all I did was I condensed exactly how I'm able to do this into. Into a course. And I'm gonna make this into a book that tells you how to articulate your, any kind of. Security, cyber security experience into a workable template that is marketable to employers.

So that is what I'm doing and it's coming, I'm working on it. I actually finished the first draft. I'm getting it edited right now. As we speak the first, book's gonna be a three, the four books series where I'm gonna break down. Not only how to market your resume and not only how to create the resume, not only a template so that you can use my mys as a sample and other people's resume as a sample.

But I'm also what I'm gonna do is expand it out into other books that tells you how to get remote jobs. Because people ask me about that a lot and I'm gonna do one where it's talking about the different categories of cyber security, because that's something I've found. People, the questions that they ask, I can tell they don't really know that there's different aspects of cybersecurity.

So that is what I'm doing. Mike says, I bought this course from you. You need to update it. Oh, okay. Yes, updates are on the way. I'm working on a whole bunch of stuff right now. So that's when I'm not on these calls that's what I'm. Okay. If there's no more questions, guys, I'm going to, I'm gonna call it quits for the day and I'll see you guys next time.

See you on the next one. Thanks for thanks for jumping on this one. Thanks Mike. For all your questions. Appreciate it. Appreciate all the questions and and thanks, Mike. Thanks for the update, Mike. I will get on that. I appreciate you later.

View Details

http://convocourses.com

All right. I'm testing a new platform called stream yard, and this is convocourse's podcast. I'm gonna do about, I don't know, 20, 30 minutes to test this out and also to inform you guys of a career move I recently made. I haven't really talked about this. But about three months ago I was working as a cybersecurity consultant and that's much different from an information system, security officer.

So in the past, Three four months. I made a big Mo well, not really a big move. I I've, it's not a big move for me. I've done both jobs before, but all I want to do is compare the two kind of give you an idea of what the differences are between cyber security consultant.

And what I'm going to be doing with information system security officer work, and what's the daily life of both of those things. How do they compare and give you an idea of which one you should choose before I start, you should know that I own a site called combo courses where I teach cyber security compliance and how to get in this field as a cyber security person.

I've been doing this for 20 years, doing cyber security in all forms of security, as well as some it information technology stuff like being a system admin or network. Administrators, stuff like that. I've done a little bit of all that stuff. But my specialty is really in security compliance.

And so that's what I teach people to do. And. People ask me on YouTube, on, on TikTok questions. And I'll just go ahead and answer them and by the way, if you have any questions during this feel free to ask them and I’ll do my best to answer. them sometimes we have such a great community that they'll actually answer the questions on my behalf.

There’re things I don't know. So, somebody, some other subject matter expert will jump in and then answer those questions and. My favorite times on this, on convo courses, because that's what convo courses in my mind is all about is about the community and us coming together, figuring things out. Okay. So, I wanted to tell you recently I made a huge move.

I was working at a major telecommunications company that does cybersecurity on the side. They have a branch that does cybersecurity and I did it because it was a great opportunity. One of my former coworkers. Gave me a they referred me and brought me into the company. It was a great company.

They had great benefits. It was some of the best benefits I've had outside the military. It was decent pay and the only, probably bad thing was that there was a lot of travel and that eventually was the thing that got me out of there. And it was stressful too. And I was how having too many personal issues that happened at that at the time that I was working there, I worked for there for about two and a half, three years, and I was doing cyber security consulting for them.

So, what we would do is we would. We bring our expertise to smaller companies. We go to, and it's a lot of companies and banks and hospitals and healthcare industries that you probably use to be honest with you. that? I Some of I was surprised were like, damn, I use this. We're doing security compliance for them.

And the security compliance it wasn't just security compliance. It was basically, we would do a bunch of We would do a bunch of risk assessments and those risk assessments would be things like be we had 15… different risk assessments. So, 12, 12 to 15 different risk assessments, depending on what they chose.

So we would do things like physical security assessments we would do. Of course, network security assessments. There was like three of those. We did cloud-based security assessments. We did… We did wireless security assessments. We take all of those and we would give them an overall view of what their security looks like.

And then we would prioritize where their major risks were. And then we would talk to the sea level or director or upper-level management to say, hey, this is where you should focus your energy because this is where we see the most risk. And the purpose of that was to reduce their. Their security any kind of vulnerabilities they have, and they can focus all their time, money, and energy and resources to that highest level of risk in their organization.

That's what I was doing. And it wasn't too bad. I actually liked it. I fit right in over there. The only I, we would do these reports, which were really easy for me, the. Challenging thing I found was sometimes the clients were a bit difficult to work with and it wasn't that they didn't know what they were doing or something like that.

It was just very high strung because cybersecurity. It could be very stressful because you're dealing with you. If you have a vulnerability, a major vulnerability and you have to take that to the C CEO and say, Hey, we have. We have a bunch of legacy systems that are in this area here, there's a lot of stress because you don't want to be the person that to, to barer of bad news, and we'd find those things and we'd say, Hey.

You have this stuff going on. And there was just a lot of stress with that. That's probably the hardest part of the whole thing. The travel wouldn't have been a big deal if I hadn't had so many personal issues happening with my family, kids and everything that just all happened at once. So, I had to unfortunately had to leave because I actually really loved the people and everything.

What did my daily life look like? We were mostly going off east coast time for me, because that's where most of my clients were. They'd give us like two or three clients. And then you would work directly with them. So, most of your day was coordinating. The scans and the assessments that you'd have to do, if you had to go to their site, you'd have to coordinate that.

And they expect you to go do that on your own. It was very self-directed where it's you have the client, like you'd run the meetings with them. You'd coordinate when you're going to go there. You'd coordinate how many hours or how much time it would take to get there and who you're gonna meet and all of that stuff you'd have to do.

And then the scans, we had a, like a separate scan team. We'd work with the scan team. We'd work with the program. Managers we'd work with them and we'd put together this report to deliver. On a quarterly basis and sometimes annually, it depends on what kind of assessment it was. Because obviously you wouldn't do like a physical assessment every quarter.

Because I didn't, that wouldn't really make any sense because it stuff doesn't change. But anyway, so that's what we would do. It is mostly meetings and coordination and doing scans and reviewing the scans and then writing reports that's your, that was your whole day as a cybersecurity consultant at this organization.

I was with where. The main thing we did was deliver these reports and we would do really, most of it was risk assessment type stuff. And I was very familiar with that because in the department of defense, we do a lot of security assessments and stuff. So that's very different from where my main core specialties are, which is security compliance.

We would dabble a little bit in security compliance like every now and then. We I would help them do like a PCI compliant PCI audit or something like that or we'd say, okay here's how you, your system would fit into eight NIST 800 or here's how your system would fit into CIS controls.

You do a little bit of that, but that wasn't really what we're, that would, it was separate from what we were doing was mostly risk assessment type stuff. So seeing where their risks are and determining that. Now that brings us to the next thing, which is information system security officer. So information system security officer is more in compliance.

It, the compliance space, security compliance and security compliance is making sure an organization is lined up with regulations, laws, industry standards. That doesn't have to be the federal government, which is mostly what I work with. It can be with hospitals have a certain standard that they're supposed to meet.

One of which is called HIPAA, where they have to make sure that they're protecting their patient's healthcare information and their digital records for the healthcare and stuff like that. Another example of industry standards would be PCI compliance. That's protection of. Of credit cards. So whenever you are at a store and you're using your credit cards, they're supposed to have a separate network for those point of sale devices.

So that doesn't touch, say the wifi that's in the that's for the staff or for guest to log in. So that has to be a separate protected network so that the credit card data has its has, is protected. So separate from your. Other networks. That's just one of the things you have to do.

Another things you have to do for PCI compliance is have the adequate documentation for the security of the system. Like making sure that net, we have network diagrams and making sure you have asset and inventory of all the assets, things like that. Those are all the types of things that you would have to do for PCI.

And that's, those are just two examples, but you've got CIS compliance. You've got. ISO 27,001 compliance. You got many different countries have their own security compliance and different industries like have their own compliance. So my, my specialty is in NIST 800. Security compliance NIST 800 is what the federal government has created and adopted as the main source of security controls.

Sec security controls is a set of security features that protect the organization's. Primary assets. That means like your main server that has all the social security numbers on it. Your main server that has all the secret secret data on it, the main server that's holding all the maps of different parts of the world.

Those, that's what you call an asset. So those are just some of the examples of, and those are some of the difference. Now, one of the things that, what the daily, what it looks like from on a day to day basis for an is. Just to compare this versus versus the consulting I was doing.

So it's also a lot of meetings. Security is a lot of coordination. Cyber security is a lot of coordination with different organiz because you're having to meet. Different subject matter experts like you, you're not necessarily the person who's locking down the, those, that windows server.

That's gonna be a server type person. That's gonna be a person like a system admin who specializes in Linux, red hat, network, administration and windows 2019. Active directory servers so you are gonna coordinate with them. So in ISSO, that's what they do. They're coordinating with these different, the firewall guy, the the privacy person.

They're coordinating with all these different people to make sure that the organization has a certain level of. So it is a lot of meetings. It's a lot of meetings with a lot of different people, and that's probably the main difference between the meetings. Like an ISSO is gonna have a meeting with all kinds of people throughout the organization.

One organization, whereas a consultant is gonna have a meeting with just a few people at different organizations like me. I had three or four clients at a, any given time and I would have to coordinate with the there's like a main point of contact. I would talk to big two or three main points of contact and every now and then I'd meet like a C level exec, but I was talking to three or four different organizations.

Whereas an ISSO is talking maybe one organization and there might be other sub organizations, but they're all one you're talking about many people in that organization. So you're going really deep in, in all of the details and stuff and making sure that all the securities is is in place. Now it wasn't, it's not like an enforcement role.

Typically you are more like a news reporter. What I mean by that is a lot of people think that you're the police and you're gonna come and busting down doors and say, Hey, this, we gotta secure this server. That's not really your job. Like you might point things out, but the person who has to be the enforcer is gonna be the management, because they're the ones, things come down from management.

So they have to be the ones to enforce that stuff. Now if you happen to be the voice piece, the mouthpiece to tell them, Hey, the CEO just said. You're just a reporter. You're just reporting to them. Hey, this is what happened. We have to obey what is going on with this organization's policies.

Here's what we have to do. So that's the main differences between a security consultant and information system, security officer. The reason why I quit my job as. A consultant and went over to, and now I'm going to back to information to security officers has more to do with. Not the work per se. It was, it is more like the travel, like the organization I was at was paid really good, had great.

One of the best benefit packages I've ever had, but it was too much travel and I had too much stuff going on. And I had too many clients, it was getting a little stressful plus I had family stuff I had to deal with. So that's the reason why I transitioned over. And now I'm going to somewhere where it's a little bit more It's gonna be a better fit for me and my new family situation.

So that's what's going on. Okay. I've got some questions here. Let me see for Mike. Thanks Mike, for your question. I really appreciate that. And Mike says he says quick question the ISSM role coming from being an ISSO. What is what's your suggestion? Quick question is S. A ism role coming from, are you gonna be doing an ISSM role from being an is O I'm assuming that's what you mean?

So you were an ISSO and now you're about to be an ISS O sorry. You were an is O you're about to be an ISSM that's I'm trying to interpret your questionnaire. Any suggestions. Yeah. So the biggest difference between these two roles is that one is a manager information systems, creating manager.

You're gonna have more of you're gonna have even more meetings. I'm just gonna tell you like the differences. So an ISSO is more like they, they both have a lot of meetings, but an ISSOs has to be more in the weeds because ISSO has to be able to say, give an example of an issue. A vulnerability comes down the vulnerability.

Is let's make something up. A vulnerability is a zero day exploit on windows 2019 or something. And now the ISSO gets wind into this and that comes from the vulnerability team. Now they have to meet directly with the vulnerability team to figure out what's going on with this thing. And they might have to spend some time researching what the zero day exploit is.

What's the criticality of it. Like how quickly do we need to fix this thing? They have to be in the weed. So they have to go probably go to the CVE. CVEs and then figure out what type of what this affects. And they have to probably look at a list of every, all the systems that this is going to touch.

And how quickly can we fix this? So there. And if so is more in the weeds in that they have to know what is going on in a, on a technical level, they have to get more in the weeds and be more technical if you get what I mean. They might not have to touch the system. A lot of times, they're not the ones implementing the security controls, but they're coordinating with the people who have to implement those security controls.

Compared to that, to an information system, security manager, their meetings are more with upper level people. So they're dealing with stuff that's more broad and stuff. That's touching the entire organization and making sure you have enough making sure the security team has all the resources in that they need all the time and resources that they need to do their work.

So your. Gonna have the same amount of meetings or more, but they're gonna be with upper level management from. Fields like you're gonna be talking to the it manager, the information technology manager who, whom the network manager, the network engineering manager. You're gonna be talk, coordinate with them.

And you guys are gonna be talking about like resources. How many resources do we have to do this work? Okay. We just had this zero date on windows, 2019. Do you guys have the resources and time to do this? How much time do you guys need to actually get this? So you're talking about like on a broader scale, how do we manage the resources that our team needs to get this job done?

And can we get it done and effectively in a reasonable amount of time? And you're trying to, your main job is managing expectations to upper level management, the C level execs, the directors and all that stuff, managing their expectation. That is your main job, as well as taking care of the people who are.

You work for the ISSOs like your job is working for the, ISSOs managing the expectations of upper level management. So you're still in cyber security, but it's more of a management. You're not in the weeds. You're not having you. You'll never, you're not ever touching any technology. Whereas in ISSO they might have to touch something at some point like, and so they might have to touch the EMA system where they're inputting information there, they might have to mess around with creating.

They might have to create a security policy, might help create the security policy review, the security policy. They might look at audit logs. They might. Help enable audit logs. They might be the person who's doing threat detection and stuff. The managers, they're not doing that kind of stuff. They're working on resources for the information system, security officers.

So it's a great move because it is is SMS are ma are legit managers. And so they're paid typically paid a lot more. They're paid more. And if you. If you're a first time manager, you'll get, you should get a pay bump. But if you have been doing a management for a while, you get a significant pay bump, like if you've been doing it for a year or two, then you'll be able to like, if forever you move or.

Those are the guys who eventually become directors. That's the path directly to directors and see C level execs and things like that who gets paid a lot of money. So that's really good. That's a really good move. If that's the case, if that's what you're doing, then that's awesome, man.

And Mike says got it. ISSOs ISSO I worked with EAs and C C Sam and tenable. Yep. Tenable NEIS and all that kind of stuff. That's right. Exactly. You got it. They're more hands on and touching stuff. Whereas managers, they're not, they're gonna ask about, Hey, you have access to eMASS.

Okay, cool. Great. They might look in there since, okay. Let's make sure that the system security plan is there. All right. And any problems with the system security plan. Okay, good. There's no problems. Let's go or, Hey Does the new guy have access to EASs. Does the new guy have access to tenable?

Okay, cool. Or let me help out. Make sure that we have, let me coordinate with the person who controls access to tenable to make sure the new guy has it. Okay. The new guy we just have some people leave. Let's make sure that person is not, no longer has access to eMASS or tenable stuff like that.

That's the manager. They're not like putting things. Into EASs or running the scans necessarily. Sometimes I've been with some managers who did do that kind of stuff, but it was because they wanted to do it. And they were very sharp, very technical, and they wanted to do it and they, but they te they totally didn't have to.

And they had other things to do by the way. All right. Let me shift gears. If you guys have any questions, go ahead and feel free to, to ask me any questions. I'm testing out this new platform. That's why it all looks a little bit different. So if you want, have any questions whatsoever, feel free to ask me in the meantime, let me show you that I have a book out called R MF is O where walks you through it's a bird's eye view of what NIST 800 is all.

And it's very quick, and this is actually the audio version, which is only like one hour long. And then also I've got a deeper dive into the NIST 800 security controls, but I'm not hitting every single control. What I do is I hit the families and give you a practical understanding of what the families are and how you navigate those.

And interpretation of the families of controls. And I focus from an ISSOs perspective. What parts of that family do you really need to know? That's the kind of stuff that I'm focusing on. And another thing you guys should know, if you didn't know already is I have a podcast here. It is right here. The podcast is, I'm doing the podcast right now.

So this the type of stuff that you hear me talk about here is the kind of stuff that I actually is gonna be on the odd. But this, the difference is on a podcast, you could just be in your car, on your commute and listen to it, or when you're cleaning or something like that, you can actually just listen to it.

Listen to our conversation as we're, as you're doing your thing. So, that's the good thing about doing a podcast? I actually really like podcasts. I'm listening to one right now, learning a new language. And I really like it. Okay. Let me see. There's another question here from Mike. He says, can I book you for a consultant for my ISSO role ISSO role you know what I'm actually in the middle of a couple of other consultations, you can email me feel free to email me and I'll see if I can find some.

For you, I'm not saying no, but let me see what I can do. Here's my I'm gonna send you my contact. My contact is scrolling across the bottom. There is contact@convocourses.com. If you're interested in getting some kind of consulting and stuff like that, I'm I'm getting back into the work field.

I'm not gonna be able to do as much consulting as I was doing before. Because my hours are gonna get tapped, but Hey, who knows? Like maybe we can do it before I actually start my job right now. I'm going through the background. The background investigation process. Okay. I got another questions from.

Mr. Fernandez. He says, so I'm getting my bachelor's degree in, in cyber security in December, I'm currently working on physical in wor working in physical security for government contracting. So I'm dealing with classified documents and D O D things will. Will I be able to, okay, let me see the next rest of this question to get an entry level is ISS O I think you mean ISS O job in your opinion, yes or no.

Okay. So L Ludwig let me give you an example and I hope that my example can give you an idea. First of all, short answer is yes. Okay. I know this because I actually start off in physical security myself. So I was a. Security forces member in the air force. And basically what I was really, I was a weapon expert.

Like I don't even know if they have that, that it was called 3P0X1. That was my AFSC. It's a specialty code that they have had in the military at that time. I don't know if they I've been following it, but basically what I did was I was a weapon specialist and. I guarded planes. I guarded if the president came in to our base or whatever, I'd do that, I'd be on that detail.

Not much personnel security, to be honest, it was mostly garden resources. And then I also did some law enforcement. So I knew a lot about the UCMJ use of force, all that kind of weapons, training, combat training, all that work with the army and the Marines and all branches and different countries.

Security people, but it was mostly physical security and I trans we call it cross train. I cross trained from physical security to cyber security. There's a lot of crossover. I was surprised to, to learn that. Some I'll just tell you a few things that are gonna help you going from physical security over into cyber security into it in general.

Number one you are, you're gonna have a very sound understanding of security overall because it's not really that much. When you get into cyber security, it's just a lot of more layers and there's, it's more complex because you got defense in depth. Physical security still applies in cyber security, which is crazy.

But when you think about it's common sense, if anybody can touch a system, then they own it. You can own a system. You can take the hard drive out, put it in another device you can use password crackers you could use. Oh man, you, you could do forensics tools on it and then extract all the bits on it and figure out what people try to delete is that as a matter of fact, that's what forensics is all about.

And speaking of forensics some of the laws that pertain to, to you, like when you're talking about chain of custody, when you're talking about Making sure that things that, that things aren't tampered with during the investigations, all those things apply. So some of the laws still apply.

What else applies, man? Physical security checks, physical security assessments is it's. The concept is similar and actually is still used in cyber security. You has to still do physical security to make sure that the facility and the room that the information system resides in is protected so that all that stuff still applies.

So it is gonna help you out. And then the main thing is that if you dealt with classified documentation before, and if you have a security clearance, all of that will also help you. To get an entry level job in cyber security. And if specifically, in information to security officer, but any kind of entry level position, because you have a security clearance, if you have one that helps.

A lot of people confuse like security. They think that if you're in cyber security, you have to have a security clearance. No that's not the case. Two different things. The security, they should just call it a clearance. It's very confusing. A clearance just does a background check on you to make sure that you are trustworthy to make sure that you don't have any criminal background that might that might.

Cause a conflict of interest where you're working like a bank doesn't want somebody who robbed the bank. You know what I mean? It's stuff like that. A hospital probably doesn't want somebody who had malpractice it's stuff. Like they don't, there's certain criminal things that not to say that you if you had some kind of.

You had a case on you in the past that you couldn't work in cyber security? It's not what they're saying. It's basically, there's certain things that cause a conflict of interest. So I have to do a background check on you to make sure that there's nothing that might allow you to be exploited.

Or something that deems you as untrustworthy to do that particular job. So if you have a clearance that really helps out a lot if you've handled classified information before that actually helps you quite a bit as well, because some people don't have any experience with that and they don't know how that world works, but you knowing that, how that world works, that helps you quite a bit.

The main thing that you need to focus on now is technical. Because me going from physical security over to cyber security, that was the biggest challenge is learning all the terminology, learning information, technology, learning how computer works learning how Ram CPU and storage all works together.

Learning how to protect those components of information system. Those are the main things, all the layers and the minutia of learning networks, how to networks work how you protect those networks, stuff like that. Porch protocols, and services. Those are the things that you need to be really focusing your mind on the security stuff will come very naturally to you.

So the answer to your question is, yes, it will help you to get an entry level job when you get your, that bachelor's degree. Only thing I would recommend that you do while you're in school. And this is what I tell everybody is try to get experience. If you. Hands on technical experience, if you can. That means if you're whatever college you're going to, or if you happen to be in the military or wherever, whatever, wherever you're at, try to get hands on.

If you see the, we call them work group managers, fixing a computer, ask if you can help them out. If you can, if they will allow you to help them to fix that computer, whether it's update and virus, definitions, updating the security patches, whatever it is like even the simplest thing possible, even if it's putting the router in and plugging it in or whatever, you'll be able to put that on your resume.

And the experience is what they really wanna see a degree is great. Certifications are great, but the experience is what they really wanna see. Another thing is I would highly recommend that you, if you can, if you have the time, if you have the cycles to do it, some people do not is to get a certification while you're working on your degree.

Degree takes a pretty long time. And sometimes the degree helps you to get the degree. If they, if you're college or wherever you're going to has a degree, a certification program, I will go ahead and take it. It's not a waste of your time, especially if you get the comp Tia, any of the comp Tia ones. If you get any kind of cloud certification, if you get any kind of networking certifications, those are all gonna help you out a bit, a lot on your resume.

So I hope that answers your question. Okay. I've got another question here. It says Mr. Fernandez says and I'm a security plus certified I'm security plus certified, but I don't have the most experience with physical hardware. Okay. Yeah. Yeah, that's what I'm saying is go ahead and get as much.

Experiences you can with any aspect of information technology. And at this point, since you're new, anything will help you out. Like whether it's help desk type stuff, whether you're Updating, like I said, virus, signatures, whether I, the reason why I keep bringing those up, because those are the simplest things that kind of come up constantly over time.

Like you've probably done it before you just don't it's something we do often so often that we don't even think about it, but that is something you can literally put on your resume. You just need to know how to articul. Speaking of articulation, just to do a little transition here. I'm working on a book right now, a new book.

That's gonna tell you how to actually break down a resume. How to, I have a course on this already. So if you're interested I'm not trying to cram anything down anybody's throat or anything, but I'm working on a book. That's a lot cheaper that. It'll be about 20 bucks or something like that.

It'll have downloadable templates. It's essentially this right here. This course right here is something I've been using for a long time. And because of this, I haven't been without a job. I, this thing works like this process that I've been doing, basically, all I did was to say, okay, how am I getting all these jobs?

I literally get like 10 offers a day between LinkedIn. Messages on LinkedIn emails calls I'm literally getting anywhere from, it's not as much as it used to be before COVID and now we have some kind of a downturn in the economy. So it's not as many as it used to be, but it's at least six messages a day.

I get for different jobs and I'm just constantly getting undated with these opportunities. And so all I did was I condensed exactly how I'm able to do this into. Into a course. And I'm gonna make this into a book that tells you how to articulate your, any kind of. Security, cyber security experience into a workable template that is marketable to employers.

So that is what I'm doing and it's coming, I'm working on it. I actually finished the first draft. I'm getting it edited right now. As we speak the first, book's gonna be a three, the four books series where I'm gonna break down. Not only how to market your resume and not only how to create the resume, not only a template so that you can use my mys as a sample and other people's resume as a sample.

But I'm also what I'm gonna do is expand it out into other books that tells you how to get remote jobs. Because people ask me about that a lot and I'm gonna do one where it's talking about the different categories of cyber security, because that's something I've found. People, the questions that they ask, I can tell they don't really know that there's different aspects of cybersecurity.

So that is what I'm doing. Mike says, I bought this course from you. You need to update it. Oh, okay. Yes, updates are on the way. I'm working on a whole bunch of stuff right now. So that's when I'm not on these calls that's what I'm. Okay. If there's no more questions, guys, I'm going to, I'm gonna call it quits for the day and I'll see you guys next time.

See you on the next one. Thanks for thanks for jumping on this one. Thanks Mike. For all your questions. Appreciate it. Appreciate all the questions and and thanks, Mike. Thanks for the update, Mike. I will get on that. I appreciate you later.

View Details

http://convocourses.com

Full video on Youtube.com/convocourses

Hey guys, this is Bruce and welcome to convo courses, podcasts. Every week. What I do is I talk to you guys about cyber security, mainly speaking on security compliance. And I'm opening this things up to questions. So if you have any questions during the course of this live session, feel free to ask 'em.

This is the perfect time to interact with me. And if you didn't know, I'm the sole proprietor owner of convo courses.com where I got tons of free stuff. If you're interested in cyber security compliance in particular, lots of downloadables, lots of free stuff for you to check it out.

You might not even be interested in cyber security, but outta, unless you try you, you must been hearing about it. It's a hot career path and let's get right into this. So what I wanted to talk about today, If somebody on TikTok said just another guy selling a book and yes, I am selling a book, but I'm also selling courses.

I'm selling my time. But it, the thing is I've been doing this for years. , it's I've been putting free content out for years. My. Has something like 600 free videos where I'm putting people on how to get into cyber security, how to do cyber security compliance how to secure their system.

All things, cyber security I've been talking about for free and you can still get this stuff's all out there. So if you're interested in this. The best place to follow me. If I can't, if you wanna get stuff for free, you wanna try it out or whatever, or get information is to go to YouTube.

YouTube has hour long. Literally I do these every week. I've been doing hourly long videos for years, teaching people, just ask me questions and I'll just go ahead and speak for an hour straight about a topic. Yeah, I am I selling a book? Yes. On Amazon, I'm selling a risk management framework. I, this Audi, most of the people in this audience will not be interested in that book.

I'm selling to a very niche group of people who are interested in this is people who are in cyber security, trying to make big money. Not everybody is willing to do, take the time to to learn this trade. And to get into this and they want that quick money, but this is not quick money.

This is long term money that's gonna help you and your family for years. If you are interested in that, then you come to the right place, cuz I'm here to teach. And if you're here to learn then let's do this. Somebody said what up family? Somebody said any thoughts on IBM cybersecurity certificate on Corsera is really dope.

Corsera if I'm not mistaken they're also doing the Google support it certification. So Coursera is incredible. Another one I would recommend is you to me. I've taken TMY myself, actually, TMY is incredible because it has a lot of entry level courses and stuff. IBM cyber security certification.

My opinion on it is I really, this is the first time I've heard about it. That being said, one of the things that you wanna look into whenever you try to get a certification is how. How popular is that certification that matters to give you an example of why that matters is because there's a certification called the C and it's a certified ethical hacker cert certification.

And it's got a lot of attraction, like HR departments, companies know what exactly what it is and what it does. It's for people who do pen testing it's for people who are looking at cyber threats. Cyber threat analysis, things like that. Now in the hacker community, if you talk to most hackers, people have been doing this for a while.

People really know what they're doing. They hate that certification. The reason why is because the certification is a, not, I won't say it's a money grab, but it doesn't. It goes into a lot of the tools that you use for the trade, rather than the actual theory. And I having read through the books for C I would disagree with that.

They treat you a lot of the fundamentals that it takes to learn the basics of hacking and goes a little bit deeper. So I would say it was from basic to intermediate. Β But it's got a, an unfair shake in my opinion, from the hacker and the pen testing community, because it just doesn't go deep enough and they want it to be more hardcore.

If you want something more hardcore, you wanna go to the SC P O S C P or Cali Linux, stuff like that. Those certifications have more hacker respect. What the point I'm trying to get at is C is a very marketable certification. If you have that certifi. You're looking at and a little bit of experience under your belt.

You're looking at six figures, but that's because it's a popular certification. So IBM cyber security certification I'm saying is not super popular. I'm guessing, but let's take the guesswork out of it when I'm gonna do right now is I'm gonna go to, I'm gonna go to a. And I'm gonna show you what I'm talking about.

As far as marketability of certifications, you wanna look at the marketability of a certification. Let's go to indeed.com. One of my favorite sites to go to for job searches. And I'm gonna show you, let me show you my screen real quick while I'm doing this. Somebody ask me what search do I have?

I'll answer that in a second. While I'm doing this C I S P and Cap and a few other ones, but let me show you what I'm talking about. Oh man. You can not see that. Okay. I'll just walk you through it. Okay. So I've got a bunch of people watching, so I'm on indeed right here. And I'm gonna type in IBM what'd you say security certification.

You said cyber security certification cyber. And this is what you wanna do with any kind of certification that you are trying to pursue. You wanna see the marketability of it? Cyber security, certifi. You can just go to any kind of job aggregator such as LinkedIn, indeed monster and just type it in. So it says there's no searches, but that's because it's only searching in my area of Colorado.

Let's look at all the United States and let's see how many certifications how many people are looking for the certification. So I did a search here. And it's saying that there's 11 jobs looking for the IBM certification where that keyword came up and really it's not even it's keying in on certification security.

It's not really finding the IBM certification, but let's take an equivalent certification. Let's say equivalent of cyber security certification. Let's say it's a security plus. Now watch this. I type in security plus comp Tia. In fact let's narrow it down. Comp Tia security plus certification.

There are 9,000 jobs. That's what that says right there. Nine, 9,000 jobs for the comp Tia security plus, and look at the look at what they're paying. Now. This is for a junior ethical hacker, but that's not bad at. And it's getting you into ethical hacking, which is pretty good. It's I've.

So my opinion about the IBM certification is doesn't have traction just yet. A lot of these vendors will try to create their own, and this is coming from somebody who has vendor level certifications. I'll get into what kind of certifications I have in a second, but vendor level certifications, some of 'em don't take off some of 'em don't they lose traction.

And because it's the company, the organization doesn't market them effectively. And what they lack that some of the certification organizations have. A couple being ISACA, which has C I S a C I S M C risk and some of the others comp Tia, which has a plus certification network plus certification security plus certification and others.

And then you have is I C ISC two squared, which has CS S P and a couple of other big time certifications. What these guys do right? Is they market the certification. They know who to talk to, to get in on these lists, the government lists to say, Hey, these are approved set of certifications. They market it so that other people have to take the cert.

And then it becomes a requirement like they did with the C the marketing on C is incredible. Like they did a great job on the marketing aspect of it. So my opinion of the IBM cyber security certification, it doesn't have traction just. I would probably go for something like the sec security plus if you're trying to get in the field and make money.

So that's my opinion about it. I hope that answers your question. That's a question from TikTok, by the way. Here's another question that I have from Floris floes leak. And it says, what kind of certifications do you have? Certifications that I have. Okay. I've got the C I S P that certification singlehandedly changed my life as a professional level certification from ISD to squared.

I got it when it, not when it first came out, but shortly after it came out. So I have a pretty low number. They have a set of numbers. So I got mine in like 2006 or 2005 or something like that. And then I've got the ISC two cap, which is it's for a security compliance for N 800. I. I've had two different versions of the security plus one of which doesn't expire.

Cuz I got it. Like when it first came out, I used to teach security plus comp Tia. I had the original network plus the original, a plus, which was one certification now is two. I have Microsoft C I've got, I had the CCNA, but that expired. I don't like, I don't, my, that knowledge has left me. If you don't speak a language for a while it's gone.

I understand still the basics of, I, I could probably configure a router or something like that, but it will take me a minute. Then I've got a bunch of vendor level certifications. I've got one for arc site. I've got one for QS. I got one and I got a few other ones, and I'm not people call me a paper tiger or whatever, cuz I, I go out and get these certs and stuff.

I normally, I would get the cert based on the job I'm in. If there's a job I need to do. And they need me to do learn this particular, this a certain thing. Then I'll go out and learn that. So that's why I have so many certifications. I got 'em outta necessity. I didn't get 'em because I was trying to get a bunch of certifications.

It was all for me. It's outta necessity. I got other things to do with my time. , you know what I'm saying? Like the next certification I'm gonna get is probably gonna be a cloud based certification. Like I'll probably get that AWS. Cloud practitioner one coming up real soon because people keep asking me questions about cloud.

I'm like, damn, I don't really, I'm not really deep on cloud, so Β okay. Let me see. Jimmy says thanks for the breakdown, man. I really appreciate that. Hey man, no problem. No problem at all. Okay. So I wanted to take some have people call in, but I'm having, I don't have a lot of people joining me on YouTube, so I'll wait on.

In the meantime, what I can do is I could take more questions and I can actually teach some stuff on a N 837. Or, you know what I think a better thing to do is to speak a little bit more on certifications since I got a lot of people asking questions about it. Okay. So certifications, I would recommend let's talk about that certifications.

I would recommend I'm gonna talk about the Entry level intermediate to expert. Okay. Let's start with intermediate entry level certifications. So entry level certifications. I would highly recommend in this order. If you let's say you come in off the street, you get, you know anything about it or computers.

I would recommend a plus certification. That was the first one I took. It was, it's a great introduction into the common body of knowledge that you need to know in order to troubleshoot. Systems and how to secure them as well as the networking aspect of computers. A plus certification is one of the best ones from comp Tia.

So comp Tia, let me just show you what that site looks like. CompTIA. Another one I would recommend would be the Google support it certification. This is comp tier right here. It's one of the top certification. Organizations in the world, CompTIA, they got a plus they got network. Plus they've got cloud plus they've got a really good course curriculum that breaks down the basics of what you really need to know for this career field.

So it's a really good starting point. I would say. And then another one I would recommend would be the Google. It support it, which a lot of people are getting jobs off of that for some reason. And then the other one I would highly recommend for entry level. If you've already taken the a plus, if you've already taken security plus stuff like that, ISS.

Certification AWS cloud practitioner. This is this one's hot. Because Amazon, if you didn't know, owns a large percentage of the market share for cloud. So they're competing against Google. They're competing against, Oracles in there now, but the biggest competitors is Microsoft and Google.

Microsoft has Azure, their Azure product. And then Google has their own cloud based products and the go. Of the world are, and other companies are starting to use their cloud services, but the ones that they use the most is Amazon. I believe like Netflix, Netflix uses Amazon cloud services and then other like large organizations multi-billion dollar trillion dollar organizations are using, or either they already have their own cloud service or they're using Amazon Google or Microsoft Azure.

So those are the three entry level certifications that I would recommend. Intermediate let's say you're already an it person. You've got three years under your belt doing it. You, your work on help desk, you work as a customer support. What would I recommend? I would recommend for entry level or intermediate is to go for a professional level certification.

That's what I would recommend. That's a CIS S. Top one, especially if you're doing cyber security, I would recommend if you're networking, then you want to go with either a CCNA security or a CCNP security. I think they have a CCNP cloud and a CCMP video and all kind of other CCMP. These are not easy certifications, but CCMP is from Cisco.

It's one of the highest sought after certifications out there. It. It's gonna pay you a lot of money. That's why I'm saying that you should do it. And on top of that, you're gonna really know what you're doing because and then a, they, Cisco owns a lot of the market share for networking technology.

The only other one that comes close is like Huawei, which is in China and is banned in the us and parts of Europe. Their products are, and Juniper and I think Palo Alto or something like that, that even come close to their market share, but Cisco's the best. And so that's why we recommend that's one of the, one of the few vendor level certs out.

You could get by yourself. You can get that one cert by itself. And then that would be incredible. Like it would. It will butter your bread. It will. It's gonna pay your bills. Β it's and then expert low level certifica. Oh, another one for intermediate would be there's red hat certifications that if you happen to be a red hat person and then there's Microsoft, if you, so once you get intermediate.

Entry level is gonna be like basic stuff that you need to know. But once you get into intermediate territory or professional level territory, you have, you're going to drill down into one or two products. Like you're gonna be really good on one or two products. You're not gonna be a master of everything.

So once you get to that level you're gonna wanna get a professional level cert in that field that you're in. If you happen to do Microsoft, you're gonna get I don't know what they're calling it now. MCs. MCSE. Is that still valid? Β I haven't done Microsoft in a while, so I might be wrong.

Let me see CSE and correct me if I'm wrong, guys, if I'm okay. Cuz I know that they changed it recently. Yes. Still MCSE. Okay. They have different. Okay. It's definitely evolved quite a bit. MCSE and MCSA yeah, that's a professional level cert as well. And then Cisco has CCMP so you'd wanna go deeper into whatever product that, once you get to the professional level, then at the expert level.

That's very specialized typically. So an expert level cert would be would be a C, C I E. And a lot of people, most people don't have it. It's like the equivalent of a PhD. Not many people get those because they're super, super hard. And it takes a toll outta your life. It's serious.

So C I E if you're in, if you're in networking, another one would be. I think there's an there's one in hacking called the O S C E, which is super high level. I don't know much about it. I just know it's a high level expert level certification. And then there's GS E which also not many people have, cuz it's just super expensive and super hard to get.

So you've got entry level certifications, which are usually called like core CompTIA calls 'em core. They're. Entry level or associate, then you've got professional level certifications. They're called the usually professional level certifications or intermediate certifications. And then you got expert level certifications.

What do you think about the IBM certification on a program on KRS Coria? So I already answered this one, but your quick answer would be that I don't think it's a very popular certification. I'm not trying to hate on IBM certification. Now, if you, if it happens to be your first certification, it just add a caveat to it.

If it happens to be your first certification, go for it. If it's your first certification, you're trying to learn it and they're giving it out for free. It won't hurt to go ahead and try it. But as far as if you got the certification, would it be marketable? I don't know how marketable it's gonna be like a security plus will be way more marketable.

I'm just telling you guys honestly like a, that IBM certification is not on any, it's not on the D O D approved list. It's not, I just heard about it on TikTok. It must be. They're giving it out for free because more than one person has asked me about it. If you happen to be learning this, go for it.

If you're like learning this from scratch, go for it, do it. But if you wanna level up at some point, take that one and then do the security plus security. Plus once you get that certification under your belt, it's marketable. Like you could put it on your resume. And get a job. So I don't know if you can do the same with IBM cyber security.

I'm not trying to hate on it or anything, but go, I'm saying, go for it. IBM is dope. I just putting IBM actually IBM itself is a key word that you could put on your resume. So IBM itself would be good to put on your resume. IBM security program. I'm sure it, it would make you a little bit more marketable than you are.

If you don't already have it on there. That's my 2 cents on it. Cisco does have some free search too. I'm not sure if they're already covered. Oh, really? I didn't know that. Cisco has a C E N T, which is an entry level certification. I think that one's pretty good. And then.

Above the CC E and T you have a CCNA and then above CCNA, you have specializations of CCNA, and then you have a CC N P, which is a professional level cert, which goes pretty deep on different technologies. Yeah that's the whole thing then CC I E is like expert level, top tier type certification.

I've known a few people who have the C I E, but they're pretty rares. I've known a lot more people who have the CCMP or a CCNA as matter of fact, I've had a CCNA before. Okay. Let me see here. Let me see if I got any more questions or stuff I want to talk about. Okay. Here's one. I wanted to talk about the pros and cons of cybersecurity.

If you guys are interested in joining a call that I have right now on YouTube, feel free to jump on. This broadcast on YouTube on just go to YouTube type in combo courses. You'll see me there. And then I will a give you a link if you're interested in this. And if not, that's cool. Let me see, I'm gonna talk to you guys about the pros and cons of it.

For, I get a lot of people who are contacting me, who are new to this and who want to get in this field. And I feel like one of the questions they should ask is what are the pros and cons of this, especially if they happen to. A nurse or a teacher or some other profession trying to get in this security field in this field as a cyber security person or it person, what are the pros and cons of this and the pros and cons of it really depends on, I think, on where you're coming from.

If you happen to be in the service based industry and you're dealing with a client, a lot of clients and you happen to not to hate to. Love dealing with people. You happen to be an extrovert. You love interacting with people, and it's just boring where you don't have anybody to talk to makes the day go by faster.

If you have somebody to talk to then one of the negative things about can be with it is that you sometimes you're isolated. Sometimes your. Sometimes a job makes it so that you're actually isolated to where, for example when I was a network engineer, we just, sometimes we'd be in the com closet, the computer, the communications closet hooking up wires all day.

And I wouldn't see a person. I wouldn't see a human for six hours a day, like four hours. I'd be in this computer room, this cold computer room. With no windows fixing a router, just trying to, trying to fix the iOS on a router and backing the router up and stuff like that. And it would take all day cuz it be something wrong with it.

For whatever reason, it's not connecting to the next rest of the network. I'm connecting a bunch of systems to it. Or I'm trying to figure out which wire's not working or. Or I'm trying to turn on port security on a bunch of ports or something on a switch. Like I'd just be messing tinkering with this thing for hours.

If you happen to be an extrovert, that can be a negative thing. If you really like interacting with people, that's one of the negative things about it, but. It really depends, cuz not all jobs are like that. It could be a positive thing if you happen to be an introvert, like you don't really want be in the industry, the service industry, for example, you just don't really want to talk to people you don't wanna really deal with this kind of stuff.

Then it's perfect for you cuz you'll be in locked in a closet programming or something all day long Β so it really depends on what you wanna do? Pros and cons of it. Let me think of some other pros and cons of it. And if you guys happen to be in it, I wanna ask you guys, what are the pros and cons of being in information technology?

What are the good things about in being in information technology and what are some of the bad things about being in information technology, please chime in. Feel free to talk to me about it. I'll read your comment on there, but another one good thing I would say. It is that it, it pays pretty good.

Like even if you start off entry level and you're not getting paid really good after about a year, if you put that stuff on your resume, you work your resume, you can very quickly escalate to another level. And a lot of career paths don't have that kind, that level of they don't have that kind of progression built into the structure.

Like I know that my I've got a few friends and family who were nurses. Who were doing nursing or they were CNAs or something like that. And I noticed their progression's a lot harder. Like it's really hard to go from say a certified nursing assistant to a nurse. There's a huge gap in pay and skillset.

And there's just this huge gap between those two things you would think it's close. It's not close at all. Like a certified nursing assistant. Is a huge gap. Whereas in it, you can quickly progress one like one skill at a time and make a little bit more money, little bit more money, little bit more money.

So that's one of the pros and DG five, one says remote working is a pro. Oh my Lord. That's a great one. That's a great point, man. Thank you for bringing that up. Remote work is one of the. Things about it, the it field in my personal opinion because a lot of people don't have that option.

I think if you're a nurse, you'd be a traveling nurse and you can have remote work and then, but you're still traveling. You're still going to site and stuff like that. But with it, you can truly be remote, and there's networking jobs that remote, there's Infrastructure jobs that are remote there's cyber security jobs that are remote there's computer consulting jobs that are remote.

I, that was my last position. There's cyber security that are remote risk assessments that are remote customer service, technical that are that's remote. There's so many remote positions and that's one of the great things about doing remote. Let me see. So somebody said somebody said, do you need computer science degree to start no.

To do in cyber security or in it? No you don't need you don't need to have a degree to get into. To get into it. So the caveat to that is that I'm gonna prove it to you. I'm gonna show you some I'm gonna actually prove to and show you what exactly what I'm saying is true. So do you need that kind of those kind of computer?

So first of all, let's break this down. A computer science degree. It typically the courses typically focus on software engineering. Okay. Computer science. I don't even have a computer science degree and I've been doing it for 20 years and I'm making six figures working from home. Okay. I have a bachelor's degree in information technology, but I know people who have a bachelor's degree in information systems.

I know people who had math degrees, actually I know people with double's that's a electrical engineer who are working in this field as cyber security. So typically. If there are, if they are looking for a degree, you don't even have to have a computer science degree or a cyber security degree. You just need something in stem, which is science, technology, engineering, and mathematics.

If you have that with a little bit of experience, you can get, you can get in there and make really good money. Now that being said, There are jobs that don't require a degree at all. Now let me qualify that. So they do expect you to either travel a lot or learn very quickly, or have a G E D high school equivalent or.

Be working on a degree or have a certification or have a certain skill set. They usually want you to have something without a degree. And it's probably not gonna pay as much. That being said, two of my mentors who taught me all kinds of stuff did not have a degree. And they were the highest paid guys in the room at any given time, but they were brilliant.

They were brilliant. They were coming outta the military with three, four years of experience. They were the main person everybody was relying on. So I'm just trying to qualify this, but now let me show you where jobs, where you don't need a degree working in it. So what I'm gonna do here is I'm gonna go to a, I'm gonna go to a

Job search engine. And I'm gonna show you how you can find these jobs where it doesn't need a degree. Now it does need you to know you gotta do the work. They're gonna expect you to know exactly what you're doing. Β So you gotta actually have some knowledge of it. I'm not saying you can just walk in off the street.

This is not sweeping floors. You know what I mean? Like you have to know some stuff to come in to do this. So if you wanna follow along, let me just explain to you what I'm doing. Cause I've got people listening in on this as well. So what I'm doing is I just went to indeed dot. Okay. And I do job search. I remove the state.

You gotta remove the state. Because sometimes it'll come up with your local state. If you happen, you can also do this on LinkedIn and go to the search results. And then what you're gonna type in is entry level entry level it, okay. That's all I'm typing in entry level it

and. It'll come up with a bunch of stuff. Now we've got all kinds. Okay. Here's one help desk technician. What you're gonna do is you're gonna go down this list and look for positions that don't require a degree. So you'll go to the requirements. You'll go to each one of these jobs. I clicked on one called help desk technician.

And it's in it's remote job in Missouri and there's, here's their requirements. They said proven experience with help desk and customer service role customer. Customer oriented in difficult situations. Tech savvy must be able to be a part of a team be able to speak proficiency in English communication skills and it's a 40,000 to 60,000 per year job.

They're not saying anything about a degree. This is the kind of stuff I'm talking about. And what all I did was typed in entry level. It that's, this is the kind of jobs you can get. You don't actually need a degree. And that's another positive thing about it is that you, it's. So in demand that a lot of times you don't actually need a degree, but you're gonna have to look for those jobs.

And in addition You you're gonna have to know what you're doing because you saw that what they wanted you to have was a proficiency in actually fixing the computers. And they're looking for you to already have one to two, two to three years. Actually they're saying here in a position that said, or one year experience.

For entry level positions, and there's all kinds of positions like this that you can find, but you gotta know what you're doing. You gotta do your due diligence. And that's why I always tell people, Hey, go for an a plus certification, cuz it's gonna break down the fundamentals of what you really need to get into this field, to get in an entry level position, just like this.

All right. I've got some people who are joining me on YouTube. Let me just read a couple of these questions here. Somebody said Tony said. Thanks Tony for the comment he says I work in cyber security and I have a criminal justice degree. I have a criminal justice degree. I have a C I S P.

That's awesome. That's incredible. Tony, you should are you actually working in the field right now? Do you have a job in information technology and what's the status of that? Is it doing pretty good? I would be really interested in this. When I was in the military, I worked as a.

As a security forces member, where I had associate's degree in criminal justice. And I was like, man, I don't wanna get out and be a police officer. This is, it was a tough job. Like it was not an easy job, mad respect to police officers, cuz that's a thankless job where your customers. Hate your guts.

and you're dealing with the worst parts of society. A lot of times you're going and you're going in an and. Talking to people on their worst day of their life. And so they're not usually in their best frame of mind. It's a hard, it's a hard job, I know all the stuff going on with police officers today, and I'm not at any, at all, trying to justify some of the bad police officers that are out there cuz there's there's like right now, this is the epidemic and the police department's defend these guys.

I'm not saying that stuff is good. Like with some of the stuff that's happening, it's good at all. When I was in, they, when I was in the military, they, if you slipped up at all, they weren't did not have your back. You were, they threw you right under the bus. Like you better you were held to a higher standard.

And that's how I think police officers, the whole industry should be, but it's not, that's not what's happening. That being said, mad respect to that profession because it's very difficult and not everybody can do that. And I wish they would stop putting people in those positions that don't, that shouldn't be police officers cuz that's what's happening.

Okay. Tony says I'm actually a cyber security manager at oh KPMG. That's one of the top big four. That's one of the big four, one of the top. If I'm not mistaken, that's one of the top accounting firms in the us. There's four there's de. There's ston young there's P KPMG. And then there's one more.

I can't remember what the other one is. If you guys can remember what it is, please chime in. He says he acts as a cyber security manager at the okay. That's awesome, man. I do. I work in GRC work. So what kind of things do you guys do? Do you guys. So that means you're in the financial sector.

Do you guys have a system security plan where is that a, it's a package where you put all the security controls into one package and then you get the system authorized. I'm sure you guys have risk assessments. You guys have things like continuous monitoring. You guys have things like, but do you guys have like a system security plan where it's.

All of the documentation for all the controls are put in one place in a database. And that's shared out to the organization for some sort of approval with your C level execs and for the agency to approve that system. I'm very curious that you got, if you guys have something like that, do you guys also use Sarbanes Oxley?

That's a, if you didn't know, that's a security compliance set of rules. That banks, financial institutions, investing institutions use to make sure that the organization's doing what they're supposed to do. I'm very curious about that, Tony. And while you're answering that one, let me see somebody else.

Ask me another question. They said anyone trying to get into cyber and it. Should get in the help desk. That's yeah. That's definitely a big step up. It's a great way to learn the foundation that you need to get ahead. Oh man. SS that's some great advice. Great advice. Okay. So while I'm waiting on Tony to respond, I think I'm gonna go to assess this comment.

So you work in KPMG. And then you said you work in GRC. Okay. I don't know if Tony's gonna respond. So let me just go to SS. So SS says anyone trying to get into cyber and it should get into help desk. It's a great way to learn foundations. It needed to get ahead. Absolutely. Another thing I would add to that is that if you do help desk for some time to help desk, okay.

So there's a lot of different names for help desk. You've got customer support, technical customer support. You've got field tech, one field tech two, you've got a lot of different names for a help desk person, but essentially it's the first line of defense. Outside the user themselves, the first line to defense in the organization, the first person somebody calls.

When their computer is not working properly or it needs to be updated and something went wrong or they need a backup, a quick backup of a desktop or a laptop or something like that. Or they need to reconfigure their laptop or re-image the laptop or something. That's the, when they call the number, it goes to help desk.

That's the first person that they're contacting. It really is great for your resume because it's gonna give you. Like one, two years of experience where you actually get exposure to networking, you get experience with a little bit of a little bit of cloud technology. If they have that in environ environment, you get a little bit of, you might even get to touch on servers, some net routers and cyber security, of course.

So you just gotta put all that stuff on your resume. So that after about a year of work with that, Being on the help desk being on the front lines of that organization, that you can go ahead and level up after about a year. So yeah, a help desk was my actual first position on the job training. It was.

That was incredible. Like that experience I don't take it for granted. Like when I was there, I was just wanting to jump into routers or do firewalls or something like that, something specialized, but that foundational knowledge and skillset that I got of troubleshooting. And trying to figure out basic problems on those computers in a production environment, that experience, and that exposure allowed me to get into things like do deeper dives into things like networking.

Cuz I did network engineering for a while. It allowed me to do deeper dives into. Learning to build a software in a real environment, like how to, how not to develop software Β in different environments, like webpages and stuff and web applications and things like that. We didn't have that many back then, but from time to time we had to touch those.

So those are some of the stuff that I learned on the help desk. I would SS I would definitely agree with you on. All right. I've been talking for a little bit. I really wanted to test out I'm on this new thing where I can actually have people call in. I'm gonna keep using this until I can get people to call in and add their 2 cents on.

On things like cyber security and security compliance, maybe next week, we'll do this again and then have people call in. But if you're interested in calling in at some point give me your email and then I'll let you call in and I'll let you speak. On all this stuff. And but for today, I think that's about it.

Thank you guys so much for your questions. Thank you for your comments. Thanks, SS. Thanks Tony. And all the people on TikTok. Wow. There's a lot of interaction on TikTok with just a very few people who've been follow me. So thank you guys for that, but I'm gonna close this thing out.

Thank you so much. Let's close out TikTok first in the live show. And then I was also live on the podcast that's over and thanks so much once again, as always. Thank you so much for joining me on YouTube. Thanks for your questions. I'm outta here.

View Details

http://convocourses.com

Full video on Youtube.com/convocourses

Hey guys, this is Bruce and welcome to convo courses, podcasts. Every week. What I do is I talk to you guys about cyber security, mainly speaking on security compliance. And I'm opening this things up to questions. So if you have any questions during the course of this live session, feel free to ask 'em.

This is the perfect time to interact with me. And if you didn't know, I'm the sole proprietor owner of convo courses.com where I got tons of free stuff. If you're interested in cyber security compliance in particular, lots of downloadables, lots of free stuff for you to check it out.

You might not even be interested in cyber security, but outta, unless you try you, you must been hearing about it. It's a hot career path and let's get right into this. So what I wanted to talk about today, If somebody on TikTok said just another guy selling a book and yes, I am selling a book, but I'm also selling courses.

I'm selling my time. But it, the thing is I've been doing this for years. , it's I've been putting free content out for years. My. Has something like 600 free videos where I'm putting people on how to get into cyber security, how to do cyber security compliance how to secure their system.

All things, cyber security I've been talking about for free and you can still get this stuff's all out there. So if you're interested in this. The best place to follow me. If I can't, if you wanna get stuff for free, you wanna try it out or whatever, or get information is to go to YouTube.

YouTube has hour long. Literally I do these every week. I've been doing hourly long videos for years, teaching people, just ask me questions and I'll just go ahead and speak for an hour straight about a topic. Yeah, I am I selling a book? Yes. On Amazon, I'm selling a risk management framework. I, this Audi, most of the people in this audience will not be interested in that book.

I'm selling to a very niche group of people who are interested in this is people who are in cyber security, trying to make big money. Not everybody is willing to do, take the time to to learn this trade. And to get into this and they want that quick money, but this is not quick money.

This is long term money that's gonna help you and your family for years. If you are interested in that, then you come to the right place, cuz I'm here to teach. And if you're here to learn then let's do this. Somebody said what up family? Somebody said any thoughts on IBM cybersecurity certificate on Corsera is really dope.

Corsera if I'm not mistaken they're also doing the Google support it certification. So Coursera is incredible. Another one I would recommend is you to me. I've taken TMY myself, actually, TMY is incredible because it has a lot of entry level courses and stuff. IBM cyber security certification.

My opinion on it is I really, this is the first time I've heard about it. That being said, one of the things that you wanna look into whenever you try to get a certification is how. How popular is that certification that matters to give you an example of why that matters is because there's a certification called the C and it's a certified ethical hacker cert certification.

And it's got a lot of attraction, like HR departments, companies know what exactly what it is and what it does. It's for people who do pen testing it's for people who are looking at cyber threats. Cyber threat analysis, things like that. Now in the hacker community, if you talk to most hackers, people have been doing this for a while.

People really know what they're doing. They hate that certification. The reason why is because the certification is a, not, I won't say it's a money grab, but it doesn't. It goes into a lot of the tools that you use for the trade, rather than the actual theory. And I having read through the books for C I would disagree with that.

They treat you a lot of the fundamentals that it takes to learn the basics of hacking and goes a little bit deeper. So I would say it was from basic to intermediate. Β But it's got a, an unfair shake in my opinion, from the hacker and the pen testing community, because it just doesn't go deep enough and they want it to be more hardcore.

If you want something more hardcore, you wanna go to the SC P O S C P or Cali Linux, stuff like that. Those certifications have more hacker respect. What the point I'm trying to get at is C is a very marketable certification. If you have that certifi. You're looking at and a little bit of experience under your belt.

You're looking at six figures, but that's because it's a popular certification. So IBM cyber security certification I'm saying is not super popular. I'm guessing, but let's take the guesswork out of it when I'm gonna do right now is I'm gonna go to, I'm gonna go to a. And I'm gonna show you what I'm talking about.

As far as marketability of certifications, you wanna look at the marketability of a certification. Let's go to indeed.com. One of my favorite sites to go to for job searches. And I'm gonna show you, let me show you my screen real quick while I'm doing this. Somebody ask me what search do I have?

I'll answer that in a second. While I'm doing this C I S P and Cap and a few other ones, but let me show you what I'm talking about. Oh man. You can not see that. Okay. I'll just walk you through it. Okay. So I've got a bunch of people watching, so I'm on indeed right here. And I'm gonna type in IBM what'd you say security certification.

You said cyber security certification cyber. And this is what you wanna do with any kind of certification that you are trying to pursue. You wanna see the marketability of it? Cyber security, certifi. You can just go to any kind of job aggregator such as LinkedIn, indeed monster and just type it in. So it says there's no searches, but that's because it's only searching in my area of Colorado.

Let's look at all the United States and let's see how many certifications how many people are looking for the certification. So I did a search here. And it's saying that there's 11 jobs looking for the IBM certification where that keyword came up and really it's not even it's keying in on certification security.

It's not really finding the IBM certification, but let's take an equivalent certification. Let's say equivalent of cyber security certification. Let's say it's a security plus. Now watch this. I type in security plus comp Tia. In fact let's narrow it down. Comp Tia security plus certification.

There are 9,000 jobs. That's what that says right there. Nine, 9,000 jobs for the comp Tia security plus, and look at the look at what they're paying. Now. This is for a junior ethical hacker, but that's not bad at. And it's getting you into ethical hacking, which is pretty good. It's I've.

So my opinion about the IBM certification is doesn't have traction just yet. A lot of these vendors will try to create their own, and this is coming from somebody who has vendor level certifications. I'll get into what kind of certifications I have in a second, but vendor level certifications, some of 'em don't take off some of 'em don't they lose traction.

And because it's the company, the organization doesn't market them effectively. And what they lack that some of the certification organizations have. A couple being ISACA, which has C I S a C I S M C risk and some of the others comp Tia, which has a plus certification network plus certification security plus certification and others.

And then you have is I C ISC two squared, which has CS S P and a couple of other big time certifications. What these guys do right? Is they market the certification. They know who to talk to, to get in on these lists, the government lists to say, Hey, these are approved set of certifications. They market it so that other people have to take the cert.

And then it becomes a requirement like they did with the C the marketing on C is incredible. Like they did a great job on the marketing aspect of it. So my opinion of the IBM cyber security certification, it doesn't have traction just. I would probably go for something like the sec security plus if you're trying to get in the field and make money.

So that's my opinion about it. I hope that answers your question. That's a question from TikTok, by the way. Here's another question that I have from Floris floes leak. And it says, what kind of certifications do you have? Certifications that I have. Okay. I've got the C I S P that certification singlehandedly changed my life as a professional level certification from ISD to squared.

I got it when it, not when it first came out, but shortly after it came out. So I have a pretty low number. They have a set of numbers. So I got mine in like 2006 or 2005 or something like that. And then I've got the ISC two cap, which is it's for a security compliance for N 800. I. I've had two different versions of the security plus one of which doesn't expire.

Cuz I got it. Like when it first came out, I used to teach security plus comp Tia. I had the original network plus the original, a plus, which was one certification now is two. I have Microsoft C I've got, I had the CCNA, but that expired. I don't like, I don't, my, that knowledge has left me. If you don't speak a language for a while it's gone.

I understand still the basics of, I, I could probably configure a router or something like that, but it will take me a minute. Then I've got a bunch of vendor level certifications. I've got one for arc site. I've got one for QS. I got one and I got a few other ones, and I'm not people call me a paper tiger or whatever, cuz I, I go out and get these certs and stuff.

I normally, I would get the cert based on the job I'm in. If there's a job I need to do. And they need me to do learn this particular, this a certain thing. Then I'll go out and learn that. So that's why I have so many certifications. I got 'em outta necessity. I didn't get 'em because I was trying to get a bunch of certifications.

It was all for me. It's outta necessity. I got other things to do with my time. , you know what I'm saying? Like the next certification I'm gonna get is probably gonna be a cloud based certification. Like I'll probably get that AWS. Cloud practitioner one coming up real soon because people keep asking me questions about cloud.

I'm like, damn, I don't really, I'm not really deep on cloud, so Β okay. Let me see. Jimmy says thanks for the breakdown, man. I really appreciate that. Hey man, no problem. No problem at all. Okay. So I wanted to take some have people call in, but I'm having, I don't have a lot of people joining me on YouTube, so I'll wait on.

In the meantime, what I can do is I could take more questions and I can actually teach some stuff on a N 837. Or, you know what I think a better thing to do is to speak a little bit more on certifications since I got a lot of people asking questions about it. Okay. So certifications, I would recommend let's talk about that certifications.

I would recommend I'm gonna talk about the Entry level intermediate to expert. Okay. Let's start with intermediate entry level certifications. So entry level certifications. I would highly recommend in this order. If you let's say you come in off the street, you get, you know anything about it or computers.

I would recommend a plus certification. That was the first one I took. It was, it's a great introduction into the common body of knowledge that you need to know in order to troubleshoot. Systems and how to secure them as well as the networking aspect of computers. A plus certification is one of the best ones from comp Tia.

So comp Tia, let me just show you what that site looks like. CompTIA. Another one I would recommend would be the Google support it certification. This is comp tier right here. It's one of the top certification. Organizations in the world, CompTIA, they got a plus they got network. Plus they've got cloud plus they've got a really good course curriculum that breaks down the basics of what you really need to know for this career field.

So it's a really good starting point. I would say. And then another one I would recommend would be the Google. It support it, which a lot of people are getting jobs off of that for some reason. And then the other one I would highly recommend for entry level. If you've already taken the a plus, if you've already taken security plus stuff like that, ISS.

Certification AWS cloud practitioner. This is this one's hot. Because Amazon, if you didn't know, owns a large percentage of the market share for cloud. So they're competing against Google. They're competing against, Oracles in there now, but the biggest competitors is Microsoft and Google.

Microsoft has Azure, their Azure product. And then Google has their own cloud based products and the go. Of the world are, and other companies are starting to use their cloud services, but the ones that they use the most is Amazon. I believe like Netflix, Netflix uses Amazon cloud services and then other like large organizations multi-billion dollar trillion dollar organizations are using, or either they already have their own cloud service or they're using Amazon Google or Microsoft Azure.

So those are the three entry level certifications that I would recommend. Intermediate let's say you're already an it person. You've got three years under your belt doing it. You, your work on help desk, you work as a customer support. What would I recommend? I would recommend for entry level or intermediate is to go for a professional level certification.

That's what I would recommend. That's a CIS S. Top one, especially if you're doing cyber security, I would recommend if you're networking, then you want to go with either a CCNA security or a CCNP security. I think they have a CCNP cloud and a CCMP video and all kind of other CCMP. These are not easy certifications, but CCMP is from Cisco.

It's one of the highest sought after certifications out there. It. It's gonna pay you a lot of money. That's why I'm saying that you should do it. And on top of that, you're gonna really know what you're doing because and then a, they, Cisco owns a lot of the market share for networking technology.

The only other one that comes close is like Huawei, which is in China and is banned in the us and parts of Europe. Their products are, and Juniper and I think Palo Alto or something like that, that even come close to their market share, but Cisco's the best. And so that's why we recommend that's one of the, one of the few vendor level certs out.

You could get by yourself. You can get that one cert by itself. And then that would be incredible. Like it would. It will butter your bread. It will. It's gonna pay your bills. Β it's and then expert low level certifica. Oh, another one for intermediate would be there's red hat certifications that if you happen to be a red hat person and then there's Microsoft, if you, so once you get intermediate.

Entry level is gonna be like basic stuff that you need to know. But once you get into intermediate territory or professional level territory, you have, you're going to drill down into one or two products. Like you're gonna be really good on one or two products. You're not gonna be a master of everything.

So once you get to that level you're gonna wanna get a professional level cert in that field that you're in. If you happen to do Microsoft, you're gonna get I don't know what they're calling it now. MCs. MCSE. Is that still valid? Β I haven't done Microsoft in a while, so I might be wrong.

Let me see CSE and correct me if I'm wrong, guys, if I'm okay. Cuz I know that they changed it recently. Yes. Still MCSE. Okay. They have different. Okay. It's definitely evolved quite a bit. MCSE and MCSA yeah, that's a professional level cert as well. And then Cisco has CCMP so you'd wanna go deeper into whatever product that, once you get to the professional level, then at the expert level.

That's very specialized typically. So an expert level cert would be would be a C, C I E. And a lot of people, most people don't have it. It's like the equivalent of a PhD. Not many people get those because they're super, super hard. And it takes a toll outta your life. It's serious.

So C I E if you're in, if you're in networking, another one would be. I think there's an there's one in hacking called the O S C E, which is super high level. I don't know much about it. I just know it's a high level expert level certification. And then there's GS E which also not many people have, cuz it's just super expensive and super hard to get.

So you've got entry level certifications, which are usually called like core CompTIA calls 'em core. They're. Entry level or associate, then you've got professional level certifications. They're called the usually professional level certifications or intermediate certifications. And then you got expert level certifications.

What do you think about the IBM certification on a program on KRS Coria? So I already answered this one, but your quick answer would be that I don't think it's a very popular certification. I'm not trying to hate on IBM certification. Now, if you, if it happens to be your first certification, it just add a caveat to it.

If it happens to be your first certification, go for it. If it's your first certification, you're trying to learn it and they're giving it out for free. It won't hurt to go ahead and try it. But as far as if you got the certification, would it be marketable? I don't know how marketable it's gonna be like a security plus will be way more marketable.

I'm just telling you guys honestly like a, that IBM certification is not on any, it's not on the D O D approved list. It's not, I just heard about it on TikTok. It must be. They're giving it out for free because more than one person has asked me about it. If you happen to be learning this, go for it.

If you're like learning this from scratch, go for it, do it. But if you wanna level up at some point, take that one and then do the security plus security. Plus once you get that certification under your belt, it's marketable. Like you could put it on your resume. And get a job. So I don't know if you can do the same with IBM cyber security.

I'm not trying to hate on it or anything, but go, I'm saying, go for it. IBM is dope. I just putting IBM actually IBM itself is a key word that you could put on your resume. So IBM itself would be good to put on your resume. IBM security program. I'm sure it, it would make you a little bit more marketable than you are.

If you don't already have it on there. That's my 2 cents on it. Cisco does have some free search too. I'm not sure if they're already covered. Oh, really? I didn't know that. Cisco has a C E N T, which is an entry level certification. I think that one's pretty good. And then.

Above the CC E and T you have a CCNA and then above CCNA, you have specializations of CCNA, and then you have a CC N P, which is a professional level cert, which goes pretty deep on different technologies. Yeah that's the whole thing then CC I E is like expert level, top tier type certification.

I've known a few people who have the C I E, but they're pretty rares. I've known a lot more people who have the CCMP or a CCNA as matter of fact, I've had a CCNA before. Okay. Let me see here. Let me see if I got any more questions or stuff I want to talk about. Okay. Here's one. I wanted to talk about the pros and cons of cybersecurity.

If you guys are interested in joining a call that I have right now on YouTube, feel free to jump on. This broadcast on YouTube on just go to YouTube type in combo courses. You'll see me there. And then I will a give you a link if you're interested in this. And if not, that's cool. Let me see, I'm gonna talk to you guys about the pros and cons of it.

For, I get a lot of people who are contacting me, who are new to this and who want to get in this field. And I feel like one of the questions they should ask is what are the pros and cons of this, especially if they happen to. A nurse or a teacher or some other profession trying to get in this security field in this field as a cyber security person or it person, what are the pros and cons of this and the pros and cons of it really depends on, I think, on where you're coming from.

If you happen to be in the service based industry and you're dealing with a client, a lot of clients and you happen to not to hate to. Love dealing with people. You happen to be an extrovert. You love interacting with people, and it's just boring where you don't have anybody to talk to makes the day go by faster.

If you have somebody to talk to then one of the negative things about can be with it is that you sometimes you're isolated. Sometimes your. Sometimes a job makes it so that you're actually isolated to where, for example when I was a network engineer, we just, sometimes we'd be in the com closet, the computer, the communications closet hooking up wires all day.

And I wouldn't see a person. I wouldn't see a human for six hours a day, like four hours. I'd be in this computer room, this cold computer room. With no windows fixing a router, just trying to, trying to fix the iOS on a router and backing the router up and stuff like that. And it would take all day cuz it be something wrong with it.

For whatever reason, it's not connecting to the next rest of the network. I'm connecting a bunch of systems to it. Or I'm trying to figure out which wire's not working or. Or I'm trying to turn on port security on a bunch of ports or something on a switch. Like I'd just be messing tinkering with this thing for hours.

If you happen to be an extrovert, that can be a negative thing. If you really like interacting with people, that's one of the negative things about it, but. It really depends, cuz not all jobs are like that. It could be a positive thing if you happen to be an introvert, like you don't really want be in the industry, the service industry, for example, you just don't really want to talk to people you don't wanna really deal with this kind of stuff.

Then it's perfect for you cuz you'll be in locked in a closet programming or something all day long Β so it really depends on what you wanna do? Pros and cons of it. Let me think of some other pros and cons of it. And if you guys happen to be in it, I wanna ask you guys, what are the pros and cons of being in information technology?

What are the good things about in being in information technology and what are some of the bad things about being in information technology, please chime in. Feel free to talk to me about it. I'll read your comment on there, but another one good thing I would say. It is that it, it pays pretty good.

Like even if you start off entry level and you're not getting paid really good after about a year, if you put that stuff on your resume, you work your resume, you can very quickly escalate to another level. And a lot of career paths don't have that kind, that level of they don't have that kind of progression built into the structure.

Like I know that my I've got a few friends and family who were nurses. Who were doing nursing or they were CNAs or something like that. And I noticed their progression's a lot harder. Like it's really hard to go from say a certified nursing assistant to a nurse. There's a huge gap in pay and skillset.

And there's just this huge gap between those two things you would think it's close. It's not close at all. Like a certified nursing assistant. Is a huge gap. Whereas in it, you can quickly progress one like one skill at a time and make a little bit more money, little bit more money, little bit more money.

So that's one of the pros and DG five, one says remote working is a pro. Oh my Lord. That's a great one. That's a great point, man. Thank you for bringing that up. Remote work is one of the. Things about it, the it field in my personal opinion because a lot of people don't have that option.

I think if you're a nurse, you'd be a traveling nurse and you can have remote work and then, but you're still traveling. You're still going to site and stuff like that. But with it, you can truly be remote, and there's networking jobs that remote, there's Infrastructure jobs that are remote there's cyber security jobs that are remote there's computer consulting jobs that are remote.

I, that was my last position. There's cyber security that are remote risk assessments that are remote customer service, technical that are that's remote. There's so many remote positions and that's one of the great things about doing remote. Let me see. So somebody said somebody said, do you need computer science degree to start no.

To do in cyber security or in it? No you don't need you don't need to have a degree to get into. To get into it. So the caveat to that is that I'm gonna prove it to you. I'm gonna show you some I'm gonna actually prove to and show you what exactly what I'm saying is true. So do you need that kind of those kind of computer?

So first of all, let's break this down. A computer science degree. It typically the courses typically focus on software engineering. Okay. Computer science. I don't even have a computer science degree and I've been doing it for 20 years and I'm making six figures working from home. Okay. I have a bachelor's degree in information technology, but I know people who have a bachelor's degree in information systems.

I know people who had math degrees, actually I know people with double's that's a electrical engineer who are working in this field as cyber security. So typically. If there are, if they are looking for a degree, you don't even have to have a computer science degree or a cyber security degree. You just need something in stem, which is science, technology, engineering, and mathematics.

If you have that with a little bit of experience, you can get, you can get in there and make really good money. Now that being said, There are jobs that don't require a degree at all. Now let me qualify that. So they do expect you to either travel a lot or learn very quickly, or have a G E D high school equivalent or.

Be working on a degree or have a certification or have a certain skill set. They usually want you to have something without a degree. And it's probably not gonna pay as much. That being said, two of my mentors who taught me all kinds of stuff did not have a degree. And they were the highest paid guys in the room at any given time, but they were brilliant.

They were brilliant. They were coming outta the military with three, four years of experience. They were the main person everybody was relying on. So I'm just trying to qualify this, but now let me show you where jobs, where you don't need a degree working in it. So what I'm gonna do here is I'm gonna go to a, I'm gonna go to a

Job search engine. And I'm gonna show you how you can find these jobs where it doesn't need a degree. Now it does need you to know you gotta do the work. They're gonna expect you to know exactly what you're doing. Β So you gotta actually have some knowledge of it. I'm not saying you can just walk in off the street.

This is not sweeping floors. You know what I mean? Like you have to know some stuff to come in to do this. So if you wanna follow along, let me just explain to you what I'm doing. Cause I've got people listening in on this as well. So what I'm doing is I just went to indeed dot. Okay. And I do job search. I remove the state.

You gotta remove the state. Because sometimes it'll come up with your local state. If you happen, you can also do this on LinkedIn and go to the search results. And then what you're gonna type in is entry level entry level it, okay. That's all I'm typing in entry level it

and. It'll come up with a bunch of stuff. Now we've got all kinds. Okay. Here's one help desk technician. What you're gonna do is you're gonna go down this list and look for positions that don't require a degree. So you'll go to the requirements. You'll go to each one of these jobs. I clicked on one called help desk technician.

And it's in it's remote job in Missouri and there's, here's their requirements. They said proven experience with help desk and customer service role customer. Customer oriented in difficult situations. Tech savvy must be able to be a part of a team be able to speak proficiency in English communication skills and it's a 40,000 to 60,000 per year job.

They're not saying anything about a degree. This is the kind of stuff I'm talking about. And what all I did was typed in entry level. It that's, this is the kind of jobs you can get. You don't actually need a degree. And that's another positive thing about it is that you, it's. So in demand that a lot of times you don't actually need a degree, but you're gonna have to look for those jobs.

And in addition You you're gonna have to know what you're doing because you saw that what they wanted you to have was a proficiency in actually fixing the computers. And they're looking for you to already have one to two, two to three years. Actually they're saying here in a position that said, or one year experience.

For entry level positions, and there's all kinds of positions like this that you can find, but you gotta know what you're doing. You gotta do your due diligence. And that's why I always tell people, Hey, go for an a plus certification, cuz it's gonna break down the fundamentals of what you really need to get into this field, to get in an entry level position, just like this.

All right. I've got some people who are joining me on YouTube. Let me just read a couple of these questions here. Somebody said Tony said. Thanks Tony for the comment he says I work in cyber security and I have a criminal justice degree. I have a criminal justice degree. I have a C I S P.

That's awesome. That's incredible. Tony, you should are you actually working in the field right now? Do you have a job in information technology and what's the status of that? Is it doing pretty good? I would be really interested in this. When I was in the military, I worked as a.

As a security forces member, where I had associate's degree in criminal justice. And I was like, man, I don't wanna get out and be a police officer. This is, it was a tough job. Like it was not an easy job, mad respect to police officers, cuz that's a thankless job where your customers. Hate your guts.

and you're dealing with the worst parts of society. A lot of times you're going and you're going in an and. Talking to people on their worst day of their life. And so they're not usually in their best frame of mind. It's a hard, it's a hard job, I know all the stuff going on with police officers today, and I'm not at any, at all, trying to justify some of the bad police officers that are out there cuz there's there's like right now, this is the epidemic and the police department's defend these guys.

I'm not saying that stuff is good. Like with some of the stuff that's happening, it's good at all. When I was in, they, when I was in the military, they, if you slipped up at all, they weren't did not have your back. You were, they threw you right under the bus. Like you better you were held to a higher standard.

And that's how I think police officers, the whole industry should be, but it's not, that's not what's happening. That being said, mad respect to that profession because it's very difficult and not everybody can do that. And I wish they would stop putting people in those positions that don't, that shouldn't be police officers cuz that's what's happening.

Okay. Tony says I'm actually a cyber security manager at oh KPMG. That's one of the top big four. That's one of the big four, one of the top. If I'm not mistaken, that's one of the top accounting firms in the us. There's four there's de. There's ston young there's P KPMG. And then there's one more.

I can't remember what the other one is. If you guys can remember what it is, please chime in. He says he acts as a cyber security manager at the okay. That's awesome, man. I do. I work in GRC work. So what kind of things do you guys do? Do you guys. So that means you're in the financial sector.

Do you guys have a system security plan where is that a, it's a package where you put all the security controls into one package and then you get the system authorized. I'm sure you guys have risk assessments. You guys have things like continuous monitoring. You guys have things like, but do you guys have like a system security plan where it's.

All of the documentation for all the controls are put in one place in a database. And that's shared out to the organization for some sort of approval with your C level execs and for the agency to approve that system. I'm very curious that you got, if you guys have something like that, do you guys also use Sarbanes Oxley?

That's a, if you didn't know, that's a security compliance set of rules. That banks, financial institutions, investing institutions use to make sure that the organization's doing what they're supposed to do. I'm very curious about that, Tony. And while you're answering that one, let me see somebody else.

Ask me another question. They said anyone trying to get into cyber and it. Should get in the help desk. That's yeah. That's definitely a big step up. It's a great way to learn the foundation that you need to get ahead. Oh man. SS that's some great advice. Great advice. Okay. So while I'm waiting on Tony to respond, I think I'm gonna go to assess this comment.

So you work in KPMG. And then you said you work in GRC. Okay. I don't know if Tony's gonna respond. So let me just go to SS. So SS says anyone trying to get into cyber and it should get into help desk. It's a great way to learn foundations. It needed to get ahead. Absolutely. Another thing I would add to that is that if you do help desk for some time to help desk, okay.

So there's a lot of different names for help desk. You've got customer support, technical customer support. You've got field tech, one field tech two, you've got a lot of different names for a help desk person, but essentially it's the first line of defense. Outside the user themselves, the first line to defense in the organization, the first person somebody calls.

When their computer is not working properly or it needs to be updated and something went wrong or they need a backup, a quick backup of a desktop or a laptop or something like that. Or they need to reconfigure their laptop or re-image the laptop or something. That's the, when they call the number, it goes to help desk.

That's the first person that they're contacting. It really is great for your resume because it's gonna give you. Like one, two years of experience where you actually get exposure to networking, you get experience with a little bit of a little bit of cloud technology. If they have that in environ environment, you get a little bit of, you might even get to touch on servers, some net routers and cyber security, of course.

So you just gotta put all that stuff on your resume. So that after about a year of work with that, Being on the help desk being on the front lines of that organization, that you can go ahead and level up after about a year. So yeah, a help desk was my actual first position on the job training. It was.

That was incredible. Like that experience I don't take it for granted. Like when I was there, I was just wanting to jump into routers or do firewalls or something like that, something specialized, but that foundational knowledge and skillset that I got of troubleshooting. And trying to figure out basic problems on those computers in a production environment, that experience, and that exposure allowed me to get into things like do deeper dives into things like networking.

Cuz I did network engineering for a while. It allowed me to do deeper dives into. Learning to build a software in a real environment, like how to, how not to develop software Β in different environments, like webpages and stuff and web applications and things like that. We didn't have that many back then, but from time to time we had to touch those.

So those are some of the stuff that I learned on the help desk. I would SS I would definitely agree with you on. All right. I've been talking for a little bit. I really wanted to test out I'm on this new thing where I can actually have people call in. I'm gonna keep using this until I can get people to call in and add their 2 cents on.

On things like cyber security and security compliance, maybe next week, we'll do this again and then have people call in. But if you're interested in calling in at some point give me your email and then I'll let you call in and I'll let you speak. On all this stuff. And but for today, I think that's about it.

Thank you guys so much for your questions. Thank you for your comments. Thanks, SS. Thanks Tony. And all the people on TikTok. Wow. There's a lot of interaction on TikTok with just a very few people who've been follow me. So thank you guys for that, but I'm gonna close this thing out.

Thank you so much. Let's close out TikTok first in the live show. And then I was also live on the podcast that's over and thanks so much once again, as always. Thank you so much for joining me on YouTube. Thanks for your questions. I'm outta here.

View Details

New podcast link: https://convocourses.podbean.com/

check out the new books on amazon and audible RMF ISSO Controls: https://www.amazon.com/dp/B0B6QKT8DR

SCA Course (early release) https://securitycompliance.thinkific.com/courses/rmf-isso-security-control-assessment

Audible book: https://www.audible.com/pd/B0B4PYJ9JV/?source_code=AUDFPWS0223189MWT-BK-ACX0-312685&ref=acx_bty_BK_ACX0_312685_rh_us

check out our courses at: discord: https://discord.gg/esJAz2enBW facebook: https://www.facebook.com/groups/719892952526379

Hey guys, this is Bruce and welcome to combo courses, podcast. This is gonna be a short one. I just wanted to talk to you guys about cyber security, it jobs, resume marketing. Now we talked about this the last time we did a live podcast, but I wanna talk about it again and go a little bit greater detail.

And my purpose here is to help people to know what to put on the resume to actually get a job in cyber security. Cuz a lot of people are asking me questions about like, Hey Bruce, you know, I'm, I'm in it. Like what, what do I, I'm trying to get a level up in my job. I'm trying to make more money. Like what do I do?

So I'm about to tell you exactly what I do on my resume. As matter of fact, I'm gonna go into pretty good detail about. And I'm gonna show you where you can get your own resources on how you can figure this stuff out. Now, this is what you're seeing here on the screen. If you happen to be watching me, if you happen to be listening, I'll explain everything.

I'm writing a book called cyber security jobs, resume marketing, and it's gonna be a series of books. That's gonna break down exactly how to target, what category of cyber security you want, cuz it's a pretty big field and it breaks down into all these different parts. And then it's gonna talk about how to actually market yourself, how to get the keywords, how to find those keywords in that targeted market, and then put those in your resume and then how to actually write an impact, an action statement bullet in your resume.

That's very powerful and it's been working for me for years. This is stuff I learned from the military when I was getting out and also just from experience, just like doing this stuff myself. So let me just get down to what I'm talking about. now what, what you should do if you have any it experience is you've gotta put what you've done on there.

As far as your cyber security, like what, and if you've done it more than likely you've done cyber security, you just didn't know it. And so I, I have evidence of that. Let me show you evidence of that. So what I do is security compliance and in security compliance, we have to know a lot of security controls are going into not only the information system, but the, the organization as a.

Meaning it's not just the actual system that you're locking down and putting, you know, very complex passwords or making sure it has audit logs or making sure there's a, a whole space firewall on it and stuff like that. And anti-virus, and all those are all security controls that you're probably familiar with.

If you've ever done any of those things, guess what you you've done cybersecurity, and you need to put it in your resume. So in this book, what I'm gonna do is tell you not only what keyword to put in there and where to find those keyword, but also how to word it, how to word it and explain how you, how you participated, how you conducted and enabled configurations for security controls.

In secure, in in security compliance, I'm very familiar with all of the rules and all the security controls and one of the actual compliance. frameworks that I use is N 800, but there's many others. There's HIPAA. There's PCI compliance. There's some of 'em are just laws that kind of briefly explain what you can and can't do.

Some of 'em are in very great detail, like N 801 of 'em is called a CIS security control. So I use that one as an example in my book, cuz it's just a perfect it's it's perfect for what I'm trying to show you because N 800 is just, has it has over a thousand controls so that one wouldn't be, it wouldn't be right for this particular book.

Like if I I'm writing a spec, a book about that one or I'm breaking it down differently. And I actually have written, written a book on that one already, but I'm, I'm writing another, a whole series of books just on this 800 and how you can use it practically. But for the purposes of getting your work experience in what I do is I tell you, okay, here's how you put it in.

Here's the format you use. That's going to help you. To get your resume in front of more people, it's called an ATS style resume. Here's how, here's how the date should look. Here's how it should look when you put your position in here's how all of that stuff's in here. But more importantly, what I do is, and there's some misspellings in here because I have, I've gotta edit it and I'm actually working on that now, but just kind of took a breather and, and took a break so I can show you guys what I'm doing here.

So what I wanna show you that's important is let me see, I'm getting down. Oh, here it is right here. So here, if you could see my screen, these are all the controls that, that are in the CIS security, critical security controls. This is also known as the sand. Sand's top best practice best security practices.

But these controls explain all the things that an organization needs to have in order to secure their system. If you've done any of these things as an it professional in your profession, any whatever profession you're in profession, you're in, you've done these things. You have done security and you need to put it on your resume.

You need to put it up front in your resume. So let me just go through a couple here to give you an example. So I'll pick a couple here. One is here's what's a good one. Let me see if you've done. Okay. Here's here's a good one. Here's a couple good ones. One is email. Well, we'll start with audit logs.

I like that one audit log management. If you've ever turn enabled audit logs, for example, if you've ever monitored audit logs, if you've ever. For EV any reason had to analyze the O audit logs. That's a security, that's a cybersecurity thing you gotta put on your resume. And audit logs. If you didn't know another name for it is event, event, viewer event logs, you know, different systems call it like slightly different names, but it's all, it means the same things.

It's the logs that are in the back end of the system. That's telling you if the system is shut down or if somebody is if somebody is attempted to log into the system, but it was logged in, in unsuccessfully or, or successfully or whatever those are logs, audit logs. Another thing we'll talk about is EV email and browser protections, email and browsers is probably one of the biggest threat vectors or biggest ways that, that attackers adversaries can actually infiltrate an organization.

Cuz email, think about it, fishing. Like when somebody sends a fake email with a clickable link and then, then somebody who doesn't know any better, they click on that link. And it takes into a malicious site that malicious site downloads something to their system. Yeah, that's, that's one of the main ways right now that's happening that that sites and organizations are getting infiltrated and web browser protection.

That's another one, everybody interfaces with the internet. Most of the 99% of their interactions with the internet is through a browser. So it's important that that browser is up to date. It's important that it has any extensions. Those are approved in extensions, things like that. Malware defense. That's another one.

This is like making sure you have anti-virus. So let me show you, how do you word these on your resume? How would you go about wording? So what I did was I broke each one of these sections down to explain how you word these on your resume. So let's go to the ones we just talked about. We'll go audit, audit, log, manage.

So what, first of all, explain what it is. Audit log management audit logs are gathered on servers, end user systems routers, and other systems to prevent to detect, prevent and understand possible security incidents on the enterprise. That's what they're for. It's not just for security. It's actually for maintenance as well.

So how could we word this? So one of the things we could say is that you ensured that audit logs were enabled in a mixed mode environment. Mixed mode means like you didn't have just windows, you had Mac and you had Linux or whatever. And you allowed detection of threats against assets against assets in cybersecurity.

Okay. This one, I, I have to reword this one. I did reword that one. So in my, my next draft, but let me, let me just give you another example. Conducted security, audit, log, an analysis to detect anomalies or. Abnormal events that might match adversarial tactics, techniques, and procedures that are in the Mir attack framework.

And the reason why I put these together, this, this sentence is, is very tactical because I put a whole bunch of keywords in here. They wanna see that, you know, the Mir attack framework. If you don't know what it is, go look it up. It's, it's really important to cyber threat intelligence. Whenever you do cyber threat intelligence, it's like a breakdown of different types of attacks.

And I'm sure most of these you'll be familiar with like, how do people infiltrate a, a network via a Trojan, a Trojan horse? How do they, how do they actually infiltrate? Mir talks about things like that. Mir talks about cross side scripting, Mir talks about escalation of privileges. It breaks all these things down and kind of gives, gives you an idea of the path that an attacker and adversary takes to get into a, a network.

And you use the terminology to, to. basically establish a pattern when, and this is really good for writing reports. It's really good for your resume. It's really good for articulating what kinds of threats and what kind of vulnerabilities you have to avoid within your organization? So this is a really good key word, and I see it all over things like if you're going for a cyber security analyst, Mighter you, you need to have that on your resume.

And then audit log analysis. This is another key word. So you can see that what I'm doing is I'm talking about, I'm given the action of what you did pertaining to cyber security. So if you've done it more than likely you you've done something with audit locks, you have to articulate that. So I give you several different examples here of how you can articulate and how you, how you can word your the, the bullets on your resume.

And I apologize for this. This is like a rough draft. I'm actually, I have another updated one that I I'm working on. On my other computer. So let me show you another one. And here's another one right here. This one doesn't even have bullets on it. This is showing you how I'm literally working on this as we speak.

So bear with me here. Let me just put some bullets on it. So it's clear to, to read. Okay. So this one is CI CIS control nine email and web browser protections. What is it? So it's protection of email and web browsers. And, and this has everything to do. What we talked about earlier, which is making sure that users are educated on things like social engineering.

What is it? How do you avoid suspicious emails and clicking and opening up things that you shouldn't open? Well, how do you put this on your resume? Cause more than likely you, if you've done it for some time, you have done something with this. Now keep in mind if you haven't done this before and you're trying to get into it.

If you're trying to get into cyber security, this is a great opportunity for you to. What you need to what experiences that you need to have, what things you need to study, because this is the kind of thing that employers are actually looking for. So let's just go through a couple of these. So one is updated signatures on enterprise antivirus software for proactive protection of 1500 endpoint devices and servers on the land.

So we've got a couple of really good keyword here. We're talking about anti-virus software, we're talking, we gave an, an impact. Now this is another thing you use numbers to establish the impact to your actions. Cuz it's one thing to have an action, but it's a whole another to actually show the impact of what you did so that the employer, when they're reading your resume, they're like, okay, this guy does know how to do antivirus, but wow.

They did 1500 InPoint devices. Okay, this person really knows what they're talking about. And another step you can do is actually name the actual software that you used. That's also a great tactic. Because a lot of times, like what I've noticed in right now, I'm, I'm actually interviewing for jobs and stuff and they keep asking me specifically, do you know semantic endpoint protection, because that was on my resume to keep asking about it and have I implemented it?

Have I maintained it? Have I configured it, all those kinds of questions. So you can name the actual anti-virus enterprise antivirus that you actually use, whether it's Soho or if it's semantic or, or, or AFF or whatever it is, you can name it. So that they'll know which one you're using. And that becomes a key word as well.

Let's see here set up DLP technologies like Proofpoint email. See this one. I'm I'm mentioning it. DLP and C a S B Microsoft information protection MI Microsoft security, suite defender. So I'm naming a whole bunch of, of, of, of tools here. Tools are also a are also a key word. So that's something that you should also mention on there.

Okay. Let's keep going. There's a couple of other ones here, but let's go to the last one here. Malware defense. Now this is most people who are in it have done this before. So if you've done this, you've gotta mention it on your resume. You've gotta put these security features. Anytime you've interacted with a security control, you have to put it on your resume.

Otherwise, the employer is not gonna know if what you've done. So, this is one of the main ones, and this is, most people have done this. If you've done it, you've put in, you've updated the antivirus software. You've, you've updated the signatures of the antivirus software. You've removed antivirus on there.

So you've gotta put it on your resume. And this one actually on my, I didn't actually put the, the breakdown of the, of bullets here, but it's on my, this will be in the book. So just stay tuned for this. I just, the reason why I decided to do this book, I took a, a kind of a respite from the risk management framework series because people kept asking me the same questions, the same questions over and over and over again about like, Hey Bruce, what do I put on my resume?

Like what, what do I, how can I get in? I've been doing this for 15 years. I'm working in a job. That's not, I'm not getting paid a lot, but I've been, I have 15 years of experience. And why am I not able to get six figures? Why am I not able to get a better. And then I look at their resume and they're not really talking about cyber security and I'm like, you wanna get a cyber security job, but you didn't mention cyber security on your resume.

And I'm like, you gotta put it on your resume. So they'll send me their resume. I'll take a look at it. And there's nothing on there that talks about cyber. So what I'll do is I'll just put it in some keyword and I'll say, look, this is the kind of stuff you have to do. And now I'm trying to put a book form where I can just give it, basically give it it away, cuz it's gonna be a pretty cheap book.

It's not gonna be expensive, but it's gonna help a lot of people out. So that's kind of what I'm going with this. And I'll I'll let me see if I can answer a couple questions here. I see a couple people join me. Thanks for watching. I appreciate you guys. I know this is not the normal time that I do this smooth virus says 1500 more like 150,000 yeah.

True. True. True. Okay. So let me, let me go to, I had some stuff open here. If it didn't crash on me. We have some questions. Let me see if I'll just answer like one or two. I won't to keep you guys too long here. And this'll, this'll actually be an audio file. If, if you didn't know, I have a, if you go to pod bean, right?

If you go to pod bean combo courses dot pod bean, that's where my actual podcast is, and I've been putting 'em out daily. So go ahead and check that out. There's a whole bunch of 'em that I, that I I hadn't released. So I've been releasing those ones in podcast. Let's see. Let me see if I can answer some relevant questions here.

Okay. Somebody saw, talked about the, the key challenge. I don't know if you guys knew this, but there's something's going on where people are stealing Kias using a USB cable Kia's in Hyundais, Hondas. I believe of a certain type it's called the Kia challenge. Look that up. It's pretty, especially if you have a Kia high Hyundai is what it is.

Kia or hi Hyundai. Let me see, see if I can answer some more questions here. It's mostly about the Kia challenge. Somebody asked me about my book. I probably need to respond to that one. Whoa. Okay. That should have been blocked. Okay. I'm gonna go to TikTok. Let's see if there's some questions here lately.

I've been getting a lot of questions on TikTok. And so I answer these one at a time directly usually, but let me see if I can answer at least one. Could I get into cyber security with just one year of help desk and one of these certs? Absolutely. You can. This is exactly what I'm talking about. So if you, if you have, if you've been on the help desk for a year, more than likely you have done cyber security.

So that's that's, this is exactly what I'm talking about. You have done cyber security before you just have to put it on your resume. If you put it on your resume you, you will. You will get hits. You will get people contacting you about this. And that's what this book is all about. Let me see if I can bring that up again.

Nine, which one? Which version? Okay. I've got so many. That's one. I write, I have a whole bunch of versions. I have a whole bunch of versions of my book where I'm, I'm constantly updating, updating the book and stuff. So let's see set up marketing. I tell you how to market. Once you create an awesome resume with loaded, with keywords and, and lots of action and impact statements, I show you how to market it.

And this is something that's been working for me for many, many years. I've been using the same thing. And what I didn't know that I was doing right is I was using the correct format for my resume. I didn't know until recently it's called ATS style resume, and it looks a little bit like this it's very plain.

It doesn't have any kind of, and that's the thing. My, I had a ugly resume. It's ugly and there's misspellings in my resume. somebody point I was in an interview and somebody pointed that out to me and said, Hey, you know that you have some misspellings here. And they were like, I don't care about that. But you, you know, you might want to fix that.

I was like, wow. And I still got that job by the way. It's crazy. Right. And it's because my resume's dope. My resume's really good. It's it's loader we keyword. It's it's highlighting all the security stuff I've done. This is what an ATS style resume looks like. It's just plain. It's just like, so this is what you'll do.

If you are help desk, you've been doing it for one year. You, you have to put ATS style, resume on your cyber security resume. And then you've gotta mention all the times you've done cyber security. You can't just talk about in uploading or installing windows. It's gotta be what security patches did you put on that windows device?

How did you help the organization reduce the risk? Stuff like that. And this is stuff that when you're in the weeds, when you're on the help desk, when you're, you're a system admin, when you are firewall, even firewall guys, sometimes they're not seeing the big picture of what's going on, which, which is making sure the security posture of the organization remains at a certain level, right?

They're not seeing the big picture, but you gotta put that big picture on your resume. And the way that you can pinpoint that is look at the actual security. Look at the actual security controls, the best practices, the CIS controls is one that's only one you could do PC. You could look at PCI, they have a breakdown of all the security controls, and they look very much, very, very similar to CIS N 800 is really exhaustive and it goes into super great detail and stuff.

You, you can also use those too. This one I found is like one of the best breakdowns, because it just gets right to the point there's only eight 18 controls, security controls in the CIS version eight. I think, I think version seven, the previous version has like 22 controls E either way. It's covering the same ground, all the best security practices.

And that's the stuff you gotta put in your resume. I'm gonna do another actual TikTok of this, where I break this down. And so, so we'll, we'll cover that in greater detail. Bark says I've got lots of work to do on my fed resume. Yeah, man, like this kind of stuff right here is what you wanna make sure you put on there, this kind of stuff right here, these things, if you've done any of these things, you gotta put it on your resume.

and my, my new book is gonna break down, like how you word it for each one of these controls. If you've done this before, give you an idea, like, okay, have I configured data recovery systems? Have I done that before? How do I word that in an, in an impactful way that shows that not only have I done it, but I impacted this organization, I helped them with their security bar says, by the way got your, your RMF book.

Was there a part one? There's a part one and a part two to the RMF books. So let me see if I can bring that up. The RMF book has a part one and a part two, and I'm actually working on a part three, but that's gonna, that, one's gonna take me a little longer, cuz it's, it's talking about SCA or security control assessments.

Let me show you. Okay. I'm gonna show you on two different platforms. I'm gonna show you on audible and then I'll also show you, cuz I've got an audible version of it. If you happen to be driving on your commute, you can actually just listen to it. Or if you happen to be jogging or something, listen to it.

If you wanna know more about risk management framework and the controls and how it's broken down and stuff like that. The other one is Amazon. Let me show you. So if you go to Amazon or you go to audible and you type in just R M F I I S S O and you will find my book, both books. R M F I S S O. Okay.

Let me just show you here. What I'm talking about here. It is an audible. You can listen to it right now. If you like. The one, the first one is very short. It's only like an hour long. It's a guide. It's an overview. Like if you were like wondering, like what is missed 800. If you are crazy enough to like, say, what is N 800?

Like this breaks it down in one hour, I break down like what, not only what is, is it is, but how do you actually implement it? How do you as an information system, security officer, I'm hidden it from that perspective, how you actually, how you actually implement it as a, a cyber security person. And then the next book goes into greater detail about the controls.

And what I do is I talk about like, here's, here's the controls and here's what you do in with each one of the control families. I don't, there's a thousand controls, so I don't go in all thousand controls. That'd be a super boring book. I also use practical. Things that have actually happened to me in each one of those families, not just happened to me, but happen to people.

I know things that are going, like I mentioned, the, the I don't know if you guys remember the, the colonial pipeline, where does that fit in with the risk management framework? Where does that fit in with security controls? I use real world example. So you can get an exam, a, an idea of what that control family really means.

So that that's the two books right there. One's four hours long. The second book is four hours long. So I, I think it's a really good, a really good book. I, I haven't seen anybody write it like that before. So where you are using practical stuff, and I'm kind of doing the same thing with the SCA book, the SSEA book, the SA book is going a lot deeper than I wanted.

I, it's kind of like when you write, sometimes the book goes in its own direction and that's kind of what's happening with SCA. It's just getting way longer than I thought I was gonna get. I'm trying to, I gotta chop it down a little bit. Let's see. Bruce helped me. Land a federal contract job in cyber security management, man, smooth, smooth virus.

I is, is the man. this person I know. I know personally. So the advice he gives you does work, man. It really, really does work. And I only, I only mention it because I've been doing it for years. It's, it's the same tactic I've been using for years. And I, I constantly get work. I'm never, I, I don't have to worry about not having a job because I use this technique and I'm con sometimes I gotta turn the tap off.

Right. I turn it on. And it's like a flood of all of these different opportunities. And I gotta turn it off. I gotta turn the taps off. So it stops. And right now I'm, I'm going through that process right now. And it's something else I'm not actually doing background checks and stuff with a job that I, that I got chosen for bar says, awesome.

I have a good state level. Experience, but but new to fed. Oh, okay. That's great, man. That fits right. That fits right into the state federal stuff. It it's kind of goes hand in hand with, I, I believe state uses N right. Well, some states use the, the N 800 framework. So you'll, if, if that's the case you'll fit, right, right.

In there, federal stuff does, does things a little bit different is a lot more details. I, and then smooth virus says I can't get them to stop emailing me. exactly. Exactly. It's crazy. It's crazy. You gotta make sure all of your like monsters, you gotta be turned off, like make the, make your resume invisible.

You've gotta turn off. But what happens is, so what happens? Smooth virus is that the, it works so effectively. He's talking about the, this, this method that I have, it works so effectively because, because when you, when you put the resume into their database, it stays there. it stays in their database for years.

I got people calling me from a resume that went into their database five years, literally five years ago. And they contact me and say, Hey, are you on the market? Like your resume fits this job that just opened up with Boeing or with, with whoever, right. All of these different companies. And they're calling me from five, my resume's five years old in their database.

And sometimes they're like, nah, that's my old resume. Like, here's my new one. Like, here's, here's an updated resume. It really works. Like this technique really, really works. So if you, if you're like really looking for a job you're really trying to level up, then then you should be looking out for this book cuz it's coming soon.

It's coming within the next 30 days for sure. And then I'll have a follow up book where I break down something called a nice cyber security workforce where I break down each category. If you're trying to level up from one. Category to another, or if you're from it and you want to target a specific genre of cyber security, cuz there's many different kinds, then, then that's gonna be the second book.

And that one, I should be able to knock out pretty fast. I hope. And then I'm thinking about a third book in that series where I'm talking about either remote work, cuz I've been able to remote work remotely for, for over six years now. And then I'm thinking about doing one for entry level, cuz I get a lot of questions on that one as well.

So those books are incoming. First book in the series is gonna be called cyber security jobs resume marketing, and that one's coming real soon and, and it really, really works. It's all about finding patterns, finding patterns and exploiting those patterns and putting that on your resume. It it's like you're hacking, it's like you're hacking the entire system to make sure that your stuff rises to the top every time.

And it's really, really been working for me. Okay. There's a conversation happening here. Let me see. He says, bar says he's, he's got he's in Virginia and he's got a CI S P with 18 years of experience. Holy crap, man. You're about to make some money. If you got the, the CI S P or golden. Absolutely.

That's true. Let me see. And he says yeah, I would, if I would, yeah, you'd get around 200,000 or more in, in in Virginia area. Virginia pays really good, especially if you've got a, if you've got Virginia, Maryland, DC, that area, the DMV area, DC, Virginia, Maryland, D D DC, Maryland, Virginia D DMV. Yeah. so much anyway, so that area pays really good.

There's so many jobs in that area pays, pays really, really well. and because there's just so much competition. They they're, they're the ones getting most of the government contracts and it's because there's three level, all the three letter agencies have their headquarters there. NSA, FBI, CIA, all of those.

And some, some other ones DIA and all, all these other ones have it's like the hub of everything. Then you've got the senates there. You know, the Congress is there. You've got the white house. Is there everything is there. So there's all these contractors and subcontractors and there's just this, so many cyber security jobs there.

So, so man, it's crazy. Okay. I got a lot of people. Wow. I got a lot of people watching me right now. Mike VI, how you doing bark? I've got a smooth virus. I've got. Lu Ludwig. Hey, thanks guys. Thanks for watching. I appreciate everybody. And if you guys didn't know if you're caught catching this late, what I'm doing is I'm talking about another book that I'm, that I'm putting out real soon, you're looking at like the rough draft, this isn't E doesn't even have the, the actual right name here, but it's gonna be cyber security jobs, resume marketing.

And this one is gonna break down how you can level up using these proven techniques I've been using for many, many years. And as a matter of fact, people there's people watching me right now who use this technique that I've directly told them how to do it, or they took my course and they did it. And now they're working remotely working where they wanna work, making the kind of money they wanna make.

And that's what I'm trying to help people to do to. Make a whole bunch of mini Bruces out there. So you can, you guys can reap the rewards and the benefits of cyber security that I have over all of these years and not have to worry about the recession or people saying the economy's gonna collapse or whatever, cuz no matter what happens, cyber security is necessary because all of us are relying more and more on information technology.

And the more we rely on it, the more heavily rely we rely on it. The more protection is needed for your, your personally identifiable information, your private information, more more protection on your social security numbers, your banking information, your healthcare information, you name it. Every industry needs cyber security.

So the, the right now, as a matter of fact, there's something like 700,000 jobs that are positions that are need be, need to be filled. That are in the government space alone. So yeah, I'm telling you like it, this is a hot, this is a perfect opportunity to strike while they really need more people.

There's been a huge vacuum of people that have retired gotten outta this career field. A lot of boomers are getting out because they're, you know, they're 60 plus they're kind of getting, getting out, going retiring and stuff. So now there's this huge vacuum of people who are come, who need to come in fresh blood is needed to, to make this system work.

Mike bill says I'm in school doing cyber security and cloud. That's awesome. Mike, I would, I would highly suggest getting a cloud certification. The AWS cloud practitioner is a really good one. I would come outta school with that. And then. As much as you can, Mike, if you can get some kind of experience under your belt while you're in school, that would be awesome.

Get some sort of experience so that when you, you are already starting to fix your resume up, right. And the things that you need to do, the kind of stuff they wanna see on your resume. I mentioned in this book I break it down like how they wanna, how they wanna see it and all that kind of stuff. It's these controls because the name of the game was cyber security.

It's all about it's all about implementation of cyber, of cyber security controls, and actually physical controls and management controls. It's actually quite a bit of different types of controls that you can, if you've ever done an example, like to, just to give you an umbrella of like what kind of controls that they wanna see, not just technical controls, not just firewalls, not just audit logs, but it's also physical.

If you've ever done a physical security control assessment, that's one. If you've ever done a wireless scan, that's one, if you've ever done inventory on a network and, and made sure that the organization has a baseline of, of all of their software and hardware, that's the first two right here. The first two are inventory.

You wouldn't think this is a security control, right? But if you've ever taken accountability of all the assets, assets, meaning their computers, their servers, their workstations, their laptops, their phones, and made an inventory, a list, and you've maintained it in a database or whatever, whatever have you.

If you've done that before, that's actually a cyber security controls. So you gotta put that on your resume. And before you get outta school outta school, Mike, if you can try to get work, I'm working in the college as a as a front desk. That's awesome. If you can get some cyber security under your belt, some kind of, if you help them to.

For example, update their viruses, definitions, like say you, you have a desktop right in front of you. You help 'em to upload their virus definitions, put that on your resume because you can literally name the school and say I updated, you know, X amount of systems with the, or I've I up updated a critical system with the most current signature for McAfee, antivirus, whatever.

Like you could put that on your resume, start building your resume before you even get outta school. Because the most important thing when you get out is gonna be your experience. Yeah. Your degree is great. Like you have a bachelor's degree, especially if you have cloud experience, another thing, build a cloud server before you get out and that's something you don't even need the school for.

You can build a cloud server and get ans practitioner cloud practitioner certification, and you put that on your resume. If you can help the school do any kind of cloud stuff, put that on your resume. I'm in the CCDC team. Yeah, man. That's awesome. What, what does that stand for? CCD C's team is that computer department?

What, what does that stand for? Okay. Somebody says, how can I work as an ISSO without a clearance? So O Omo. So there are jobs and back me up. If you guys know what I'm talking about here, there are some is so jobs without security clearances, but they're, they're rare. And I personally have worked a couple a job, actually, right now I'm interviewing for a job where I already interviewed for it.

I got the job. I'm just doing background check, but there's clearances that are not security clearances. I mean, not secret clearances or not Ts S E I clearances. There's one called the public trust. Public trust is like a lower level a lower level security clearance. So. You, you, you know, you, there are jobs where the is, so doesn't have to have a security clearance, but there's also jobs where the is.

So can have a public trust, which is not as high level as a, a secret clearance or a Ts S sci, and it's way cheaper for them to do that particular type of clearance where they'll bring you in and, and they'll give you that public trust clearance. That's another thing. Another thing is that when you get into those jobs, what they'll do is sometimes they'll pay for your, your SS B I, your background check.

And then you can take that background, check to the next job, your clearance to your next job, and then you get paid a little bit more. It's national collegiate cyber defense competition. That's awesome. Put that on your resume. Put that on your resume. Is do as much as you can, before you get out, you probably give a, get a job before you even get out.

If you start right now, Mike, if you, if you, let me tell you something right now, you can put, you can list the credits that you already have from your degree on your resume. Right? Then you can put that you're on the national collegiate cyber defense competition, and then the accomplished event that you guys have done any kind of any time, you've helped them with their help desk issues, troubleshooting, adding updating patches that kind of thing.

Put that on your resume. It's just a matter of wording it properly, put that on your resume and then put that resume up on LinkedIn. Now it's not gonna have a lot on it because you're just now getting into this field, but I guarantee you, if you put that on monster on dice on LinkedIn and at least 10 other sites, As you're building your resume, you will get contacted.

You could have a job before you even leave the college. You hell it might even be so good that you say, Hey, you know what? I'll come back to college. I'll finish this later. I'm and I'm being completely serious. You'll get offers if you actually do what I just told you. Let me see. Okay. Focusing on the third risk management jobs, I'm focusing on the third party risk management jobs since I have no clearance.

Okay. Is that pretty good? Sounds like that's pretty good money. Like risk management job, third party, risk management job. You could still get security security control assessment jobs, and those pay really good if you're doing like third party risk, risk assessments and stuff like that. That, that, that could do too really good.

Now, om old, if you don't mind me asking, why don't you have a clearance? Is it, are you not eligible to get a clearance? Are you not a citizen? Because I know that. In order to be eligible, to get certain clearances, you have to be a you have to be a us citizen for certain clearances. And I don't, I think public trust, you don't need a clearance, but I could be wrong.

I mean, you don't what I'm saying. So I think for public trust, you don't need to be eligible. You don't have to be a a, a us citizen, I believe, but I could be wrong about that. Let me see. Okay. And then smooth job, smooth virus, just, he confirmed what I said. I'm completing my bachelor's degree now.

I got the job, even though I'm not done yet. Exact. That's exactly what I'm saying. Like one time I give you another example, Mike, when I I got outta the military, I had experience doing the work, but I didn't have all the requirements. I had a degree, but I didn't have, I didn't have a I didn't have the CISs P yet, but because I had the experience.

they said, Hey, you know, I sat with, through the interview, they love me. And they're like, listen, we want to take you. But only thing is this job requires a CI SS. P can you get a CI S S P within a year? I said, I said, yeah. And they said, we'll, we'll, we're gonna send you to a bootcamp. So you can get this, this certification and we'll pay for the certification, but you gotta get it within a year.

I said, yes, I'll do it. So there's flexibility. Like, even while you're in school, if you start to build your resume and market yourself, like I just told you, you can start getting a job. You could actually get a part-time job, making really good money in it and cyber security while you're finishing your degree.

And actually the company, a lot of times, they want you to finish that degree cuz soon as you, you you're done with it. They'll be like, okay, you're a supervisor. Okay. We gotta pay you more. We're gonna put you over here. They'll do that from time to time because they really need people who, who know what they're doing.

They really need people who, who are willing to work and do this and level up. Let me see. Almost says I'm a citizen, man. Then what is happening? Why don't you Somo? Like if you're looking for security clearance then what you could do, one of the things you can do is especially if you live in the east, on the east coast, they have a lot of jobs that require security clearance.

If you have a skill set, you said you, you work as a risk management framework person, third party, but you don't have a clearance. You could get a job, even if it pays a little bit less, right? And, but they're willing to pay for your clearance. Listen, it will be worth your time to work there for about six months, work there for about six months, have them get your clearance take as long as it needs for them to get you a clearance and then bounce, roll out and go to another place and be like, Hey, I got my clearance.

And by the way, I'm a risk management framework person. They'll pay you more money. Like you'll. They'll pay you more my hell after you get the clearance, they might even, they might even update you. They might even pay you more. It says I'm doing things backwards too. I'm in the healthcare and got a security plus and plan on going to get my master's in cyber security.

That's awesome, man. Like healthcare has so many great so many great opportunities because there's just such a huge need for healthcare professionals. People who are well versed in the healthcare industry to be cyber security or it people right now. And I can just give you one example of what I'm talking about.

Like it's, it's so crazy right now. Let me just show you what I'm talking about. Here's my book right now. If you guys, my book's right there. If you guys are trying to learn risk management framework, it's those stuff it's blowing up. Let me see. So let me, let me just take you to this site. This is a DISA site.

I'm gonna take you into a DISA dot mill site. Now you might be wondering, like, what does that have to do with healthcare? I'm about to show you, this is how crazy healthcare is. So I just typed in DISA a dot mill at 81 40. So let me just show you to this site. So 81, 40 and 85 85 70 is like it's like a breakdown of all the approved certifications that the department of defense and by proxy, some of the federal government actually uses to say, okay, these are approved certifications.

So what I wanted to show you is this right here. See this right here. What's that say? You see that this is on the approved list. This is an IAM level two. I am level two means information assurance manager level two, which means it's it's, it's a fancy word for information security or Infor or cyber security for information security.

Manage management and it has H, C I S S C H C I S P P. And I don't know if you've ever heard of this certification, but let me, let me show you something here. So if you type in this particular certification, I happen to know that this one specifically for healthcare and it's coming from the ISC two squared ISC, two squared is the top organization, arguably the top organization for security certifications because they, these are the guys who do the C I S S P.

Now they have one called the H C I S P P, which is for healthcare security certifications. I mean, professionals. And it break. Let me show you the breakdown of this. Like, if you didn't know about this one, this is this, one's hot, this one's hot, especially if you're in the healthcare industry. So this is the kind of stuff that's on that they expect you to know as a H H C I S P P.

and it's H H C I S P P is ideal for information security professionals charged with guarding protecting healthcare information. P H I protected healthcare. He protected health information, including those in the following positions. So if you happen to be in a compliance officer, information, security, privacy, officer, risk analysis analysis analyst hi health information manager.

If you do any of these things, they're saying, Hey, this is good for you. And see, it's listed right up here with the, with all the big boys, all these CI S S P and the cap and all these other ones. I didn't know about that. Thanks for sharing. Yeah, this is a, this is a really, really good one. Now, recently, if you happen to be entry level, this might be for Mike right here.

Entry level, the CI the ISE two square recently created this one right here. This is exciting. I think this one's gonna be listed on that approved list. It's the entry level certification for cyber security people, which is, which is crazy. They're trying to compete with security plus I think, but yeah, anyway, back to our subject.

So we're talking about this one though. So this is CRA, this is crazy. So you just recently added this to that department of defenses, the list of certifications. That means this certification is about the blow up. A lot of that means a lot of contractors, a lot of recruiters, a lot of HR departments are gonna start listing this as a requirement at major healthcare facilities, so that you have this certification, you get this, something like this under your belt.

And the thing is if you've been doing this and the healthcare field for some time, You might, you might just blow this test out of the water and then they have a breakdown of topics. So you gotta, I think you have to give them your, your information. They'll send this to you and, and you'll have their newsletter or whatever, but they have a breakdown of the domains, which I'd be interested in to see this right here.

Oh, here it is right here. Okay. Sneak peek at the domains. Here's the chapters. Third party, risk management, introduction of healthcare industry governance, legal risk compliance. Yeah, really cool stuff. Really cool stuff. It's they're saying it's already ranking in 39th among security clearances. I don't know about that, but that came from certification magazine.

Okay.

Yeah. So that's, that's really good stuff. Exciting times if you happen to be in this field. It hasn't always been like this. It's it's really hot right now. There's so many, there's so many job opportunities. And I just want to show you guys this this little before I let you go. There's so many jobs that they're looking for recently.

This is from July 1st, 2021 of last year, all the way till now this is from July 29th. The white house is pushing to fill 700 700. This is real. They're pushing to fill 700,000 jobs in cyber security in the United States. And what they're doing to do this is they're getting with all kinds of all kinds of private and public and nonprofit organizations to, to teach this.

That's how they have a whole bunch of free courses out there. They've got a bunch of, of, of organizations that are trying to get entry level people in cyber security. Like I believe Booz Allen Hamilton did it. And they go really fast. Like as soon as they list that job, it just, they jobs just start going really fast.

So the 700,000 job thing is real. Yeah, this is real, man. This is, this is coming directly from the, the, the white house, like the white house at a summit lack last month where they said there's 700,000 cyber security jobs we wanna fill across. I think what they mean not is not just the federal government.

I was, I think I misspoke with that. I think they mean throughout the United States, there's 700,000 jobs. And the reason why is cuz there's heightened, there's a lot of stuff going on behind the scenes. Like governments are starting to attack each other. There's a huge cyber war going on right now. And so that's why you're hearing about all these leaks and all of these.

All of these hacks and stuff, because a lot of companies and a lot of banks and a lot of healthcare industry facilities and stuff, they don't really have appropriate. They don't have appropriate security measures and what's happening is they're, they're soft targets. And and they're going to these hackers.

There's there's criminal gangs. There's some that are backed by, by government state state governments. There's some that are backed by you name it, criminal organizations, just that you're just trying to get money, whatever it's a free for all right now. And there's, and we are, the us is the biggest target because they're the ones holding all the money right now.

So, you know, they'll go off to a bank cuz they know a they know what the healthcare industry will pay. Like if they get you, did you hear about the one in LA? Like the LA school district? Somebody tried good on LA school district. They, they were able to they were able to protect themselves, but yeah, some, some hacker group went after LA school district.

Let me see if I can find that one.

Let me see if I could find that one. This is crazy. So yeah, the, they, somebody went after hackers target Los Angeles school district with a ransomware attack. They tried to get 'em on a ransomware attack. This was recent. This was like yesterday or something. Yeah. Look at this. September 10th. Yeah. Okay. So four days ago, hackers target Los Angeles school district with ransomware attack.

And luckily the, the school district was prepared for it. This is kind, this is what's happening. This is what's happening across the board because we're, so we've got so many soft targets and It's just, it's, it's sad to see, but that's why there's so many job openings for cyber security. And the white house is pushing this huge initiative to you know, to get more people, cyber security analysts, information system, security officers even, even things like program managers.

They probably lump those, those people in there program managers are super critical to, to doing things like security and engineering. So they are part of our team. Let me see, basle says, I'm looking to get into this field. Can you let me know what I could study or brush up brush up with? Okay.

So here's, here's what I, here's one of the things that I show how to that I would suggest. Okay. And this is just my 2 cents. Like some, there's some gurus out there who are, will tell you something totally different. , this is the first certification that I got from CompTIA. CompTIA has one of the best curriculums out there.

Some people really hate this certification, but you know, the market doesn't, if you have the certification, you can get hired somewhere so people can hate on it all. They want just like ch people hate on ch, but you know what? That will pay you. And this one, if you're an entry level, this is where you can start.

And so one thing you should know is that certifications, you can't just get a certification and magically get a job. Okay? It's not, that's not how it works. Like you can't, if you've never done any it work before you gotta put the work in to learn the material. But what I'm saying to you is that even though these these, these certifications are made to validate the skillset and knowledge that you already know, or the experience you already have, you can use it as a curriculum to learn.

And, and that will get your foot in the door. Now don't focus on the prize so much as the process itself, the process of learning this material in such a way that you can level up and start to actually do this work and, and get yourself an entry level position that doesn't require all of these different high level requirements.

So you go through this and you go through the curriculum of this, and it's gonna show you things like hardware, operating systems, how they work, software troubleshooting, network, networking, troubleshooting, security, virtualization, a little bit about cloud stuff, mobile devices. Those are kinds of the things that you're gonna see on this test.

But bef like before you take the test, you want to actually go read the book, break it down. Learn about it, put it on your computer. You can use VMware to learn it on your own. Like you could have a virtual environment right here, right on your computer. You can set up networks in your house. What, what I did when I first started doing this, I would build computers.

I would, I would buy the components, build the computer, cuz it gets you exposure to the hardware and let you know how the software works with the hardware with hands on experience, nothing beats hands on hand on hands on experience. So if you can get virtual virtual networks from things like GNS three, that's another thing you can use once you get this certification.

Like what you wanna do is study there's. This is two tests. This is not an easy test by the way. Now, if you're not very proficient, if you're not very savvy on on computer stuff, what you can do is go comp tia.org and go to ITF ITF. Plus, if you wanna, this will tell you whether or not you should even take.

Any of this, like you, whether you not, you wanna do this, a lot of people chase that money, chase the stability of it. So you, you might not even wanna do this. You know what I mean? Like this right here kind of dips your toe in the waters of it. So when I keep you probably I think it, Bruce, I don't care about it.

I wanna do cyber security. I know, I know. I know. I understand. But I, cyber security is stands on the . You have to know it before you get into cybersecurity. I, it, cyber security. Is it information technology? All we're doing is it's. It's like one it's cybersecurity is multidisciplinary. All right. So for cybersecurity, You're you're expected to already know information technology that's basic computer stuff, hardware, software troubleshooting, things like that.

So this something like this is an entry level. That's gonna tell you the terminology, the basics of information technology, how it works before you get into the hardware hardcore stuff, which is a plus certification. A plus certification is, is actually no joke. It's it it's, especially if it's your first certification, it's not easy.

So it was my first one and it wasn't easy for me. So it was not easy cuz you have to learn all the terminology and they're just throwing all the stuff at you and stuff. So like now if I went back to it, I'd be like, okay, I know this. Yeah, I know this, I know this, but if you're coming on there cold, a plus is not an easy certification to take cold.

It's not easy to take cold. It's so much terminology that you have to learn. So. After you take, let's say you, you got, you went through all this curriculum. You listened to Bruce's live and you like, man, this guy knows what you're talking about. I'm gonna go ahead and study for a plus. You got a book, you broke down the book, you took notes on it.

You took the test, you passed it. Another thing you could do, I'm just gonna tell you three different search. You should do that. I recommend there's another one called Google. This is, if you don't know, if you don't have a degree, if you Mike is already getting his degree, he's already like he should, he could probably do go straight to professional level search if he wants, because he is about to get a degree he's in UND himself in this world and everything.

But if you happen to have no degree, you're doing us all from scratch. Here's another one you can do. And you can do this one. If you're in college too, it's no big deal, but here's one called the Google support. It certification. The reason why I would recommend this one is because a lot of people are taking this certification with no degree going in.

And, and making and making this kind of salary right here. This is what people are telling me. This is what my users. Now this is anecdotal information. I do not personally have experience with this. This is all new to me. In my experience. You, you can't get into these fields without experience, but I stand corrected cuz several people have contacted me and said, yes, I got this it support certificate and I'm making X amount of dollars.

So this is another one you can do. If you're trying to bypass the degree programs and stuff. I, this is no guarantee that you're gonna get anything. Okay. But I'm just telling you anecdotal information of people contacting me saying I took certification. I'm now making X amount of dollars, not a hundred thousand, but it's pretty good money.

And it's entry level. They're doing entry level work by the way, another certification. Here's the hottest. One of all this one, whether you're in, whether you are in a degree program, whether you are have five years of experience. Whether you have a CIS S P, whether you're coming in off the street, you used to be a sanitation engineer, and now you're doing this.

I recommend every person take this one. Every person, every man, woman, and child dogs, cats living together, all of everybody should take this one. Okay. It's called the eight. If I could type cloud certification practitioner. So there, and let me, I'll just explain why this is, this one's so important. Okay.

And I went to the wrong site here, went to the wrong site. I'm trying to go to actual TMY is a good, good place to actually learn this stuff. I don't teach cloud yet. So TMY is a good place to prac. But anyway, here it is right here. AWS cloud practitioner. This is why this one's so important. Everything is going to cloud.

If you use Google, any Google services you use in cloud, Gmail's using cloud YouTube's using cloud services. All streaming uses cloud Netflix uses cloud everything's on the cloud right now. Everything is on the cloud. And AWS, Amazon is the leader in this. So Amazon's the leader in this. Amazon is killing it.

Like Amazon owns something like 30% of the total market share for a cloud. They, they own most of the government stuff in cloud. They, they they're their only competition really that's that's close is Azure from, went from Microsoft and, and Google Google itself. So this, this certification is not hard and, and everybody should know at least this level of knowledge and here.

And here's the reason why I say this. I just had I'm in the process of getting a new job. Okay. And I, I. L literally hundreds of screeners contacted me and it's just annoying. And I need to turn that crap off. But out of those hundreds of screeners people calling me, you know, really quickly, like it's like a quick interview, not even in interview.

It's like let's see if you qualify for this. Anyway. So out of those hundreds of screeners, I had five interviews. I had five interviews. Two out of those five, I have two that are potential one and one I'm act. I actually, they gave me an offer. They gave me a job offer. I said, yes. And now I'm going through the background process.

I say all this to say, going back to the cloud thing is that out of those five interviews, four of them ask me about cloud. And some of them went pretty deep on. and you gotta know cloud. So if, if you happen to be in an environment where you can learn more cloud stuff, learn it. Because I, I regretful my last job.

They were trying to force cloud down my throat and I didn't wanna do it. And I just kept dragging my feet about, and I wish back looking back. I wish I would've just done it. I wish I just would've at least taken this AWS cloud because they were asking me a lot of cloud questions. And I really didn't know.

I'm really, I really didn't know 'em you gotta learn cloud. So I would. And another thing about this AWS practitioner is that look at this it's a hundred dollars is 90 minutes. How hard does this? This can't be hard is 65 questions, multiple choice. I mean, Pearson peer view. It's this has gotta be easy. And I I'm gonna take this test, period.

I, they, they ask me way too many questions about it. It's getting way too ridiculous. I need to know more about cloud stuff. I need to be able to speak on it. And I was not able to do that. And so four interviewers asked me about freaking cloud stuff and I, and I'm like, damn, like I really should have, got more information on this.

I don't even do cloud. I'm doing information system, security officer type stuff. That's the jobs I was going for. And they keep asking me about cloud. I'm like, damn, like, can you ask me risk man, refr more questions? Like why what's cloud? Like, I mean, I have some exposure to it, you know, like Fedra and stuff like that.

But they were asking me like, like, how do you set it up and stuff? I'm like, what? what, what's the difference between a P a, a S and a and a S a, a S I'm like, oh my what? That kind of stuff. Basic really basic stuff, you know, cloud, but I didn't know it. So so yeah, check this one out. Somebody asked me, do you have a resume template?

I do. So if you go to my site I'm, I'm working on breaking down. if you I'm working on having like a complete breakdown of several different resumes and resume samples and stuff and ATS format, but it's gonna take me a while to do I gotta get off this call so I can go do it. But if you go to my site combo courses.com and you go to all courses, here's some of my stuff, books, new stuff that I put out free stuff.

What you're gonna do is you're gonna go to resume marketing. I have a course on resume marketing, the stuff that I'm writing in a book. I already have a course for it. And it works really, really good, but if you want the template, I'm making it free for now. Okay. So if you happen to be watching this, you are, you are in luck because I'm, I'm telling you free stuff.

That's out there right now that I'm probably gonna make. Not free. So if you go to this right here, just sign up is free. Okay. So number one, you can sign up right now and it's free to sign up. When you sign up for free, there's a ton of free stuff. You can download, you gotta go search for it. There's like, see this free preview stuff like that.

You gotta go through there and it'll have free stuff. This, this one has a downloadable for, for my resume has an actual down here it is right here. See this right here. I don't know if you, I don't know if you can see this. So all you have to do is, is if you sign up, you'll get that one for free. You'll get that one for free.

That's the template. Not always gonna be free. Some of the stuff I'm gonna I'm I'm gonna make it. I'm gonna make it paid, but for now it's free. So yes, the answer is yes, I do have a resume template. I'm gonna make a lot more. They're gonna be linked from the book a pipe. I don't know if I'll make 'em free or not.

I'm not sure. Probably, maybe initially, I, I don't know, but stay tuned for that, but in the meantime, there's an ATS style resume that's out there. And thanks a lot smooth virus for your testimonial. I appreciate that. Okay. That's it guys for this one. Thanks for watching a lot. I got 15 people watching me here.

I'm knowing how many people watching me on Facebook, but thanks for watching. Anyway, I'm gonna make this into a podcast. So stay tuned for that one. If you wanna listen to this again or whatever, it'll be out there. If you didn't know, I've got a podcast site it's on convo courses, dot pod bean been, I gotta get used to saying this combo courses.podbean.com.

Here it is right here. Here's everything. Here's all my podcasts. If you're interested in just listening, I got more coming out. I've been trying to crank these out every day. Not easy to do but here. Somebody said I'm sorry, can you show me where to navigate? Okay. Go to con courses.com. Convo courses.com.

courses.com. I'm go. I'm working on making this its own separate link, but for now I'm I gotta focus on writing this book. Okay. So go to all courses and then go to the course where I talk about marketing, cyber security marketing that breaks down what you do on a resume. And on here, I have a free resume.

If you sign, you can sign up for free. You can sign up for free. Okay. This says $145, but you can sign up for free, totally free. And then what you're gonna do is go, if you sign up for free tons of downloadable, see this one. See, this is free. You'll see this free stuff happen. I mean popping up if you go to resume here, that's where it is right there.

ATS resume sample. I've got a whole bunch of other stuff coming, but I'm just I'm right now, currently working on it. Like, obviously I'm, I'm in this live right now, so I can't do that while I'm in this live. So I really gotta let you guys go. Thanks a lot for watching. I appreciate everybody. Tony long time.

No, see I'm outta here guys. Thanks everybody for your questions. Thanks for.

View Details

New podcast link: https://convocourses.podbean.com/

check out the new books on amazon and audible RMF ISSO Controls: https://www.amazon.com/dp/B0B6QKT8DR

SCA Course (early release) https://securitycompliance.thinkific.com/courses/rmf-isso-security-control-assessment

Audible book: https://www.audible.com/pd/B0B4PYJ9JV/?source_code=AUDFPWS0223189MWT-BK-ACX0-312685&ref=acx_bty_BK_ACX0_312685_rh_us

check out our courses at: discord: https://discord.gg/esJAz2enBW facebook: https://www.facebook.com/groups/719892952526379

Hey guys, this is Bruce and welcome to combo courses, podcast. This is gonna be a short one. I just wanted to talk to you guys about cyber security, it jobs, resume marketing. Now we talked about this the last time we did a live podcast, but I wanna talk about it again and go a little bit greater detail.

And my purpose here is to help people to know what to put on the resume to actually get a job in cyber security. Cuz a lot of people are asking me questions about like, Hey Bruce, you know, I'm, I'm in it. Like what, what do I, I'm trying to get a level up in my job. I'm trying to make more money. Like what do I do?

So I'm about to tell you exactly what I do on my resume. As matter of fact, I'm gonna go into pretty good detail about. And I'm gonna show you where you can get your own resources on how you can figure this stuff out. Now, this is what you're seeing here on the screen. If you happen to be watching me, if you happen to be listening, I'll explain everything.

I'm writing a book called cyber security jobs, resume marketing, and it's gonna be a series of books. That's gonna break down exactly how to target, what category of cyber security you want, cuz it's a pretty big field and it breaks down into all these different parts. And then it's gonna talk about how to actually market yourself, how to get the keywords, how to find those keywords in that targeted market, and then put those in your resume and then how to actually write an impact, an action statement bullet in your resume.

That's very powerful and it's been working for me for years. This is stuff I learned from the military when I was getting out and also just from experience, just like doing this stuff myself. So let me just get down to what I'm talking about. now what, what you should do if you have any it experience is you've gotta put what you've done on there.

As far as your cyber security, like what, and if you've done it more than likely you've done cyber security, you just didn't know it. And so I, I have evidence of that. Let me show you evidence of that. So what I do is security compliance and in security compliance, we have to know a lot of security controls are going into not only the information system, but the, the organization as a.

Meaning it's not just the actual system that you're locking down and putting, you know, very complex passwords or making sure it has audit logs or making sure there's a, a whole space firewall on it and stuff like that. And anti-virus, and all those are all security controls that you're probably familiar with.

If you've ever done any of those things, guess what you you've done cybersecurity, and you need to put it in your resume. So in this book, what I'm gonna do is tell you not only what keyword to put in there and where to find those keyword, but also how to word it, how to word it and explain how you, how you participated, how you conducted and enabled configurations for security controls.

In secure, in in security compliance, I'm very familiar with all of the rules and all the security controls and one of the actual compliance. frameworks that I use is N 800, but there's many others. There's HIPAA. There's PCI compliance. There's some of 'em are just laws that kind of briefly explain what you can and can't do.

Some of 'em are in very great detail, like N 801 of 'em is called a CIS security control. So I use that one as an example in my book, cuz it's just a perfect it's it's perfect for what I'm trying to show you because N 800 is just, has it has over a thousand controls so that one wouldn't be, it wouldn't be right for this particular book.

Like if I I'm writing a spec, a book about that one or I'm breaking it down differently. And I actually have written, written a book on that one already, but I'm, I'm writing another, a whole series of books just on this 800 and how you can use it practically. But for the purposes of getting your work experience in what I do is I tell you, okay, here's how you put it in.

Here's the format you use. That's going to help you. To get your resume in front of more people, it's called an ATS style resume. Here's how, here's how the date should look. Here's how it should look when you put your position in here's how all of that stuff's in here. But more importantly, what I do is, and there's some misspellings in here because I have, I've gotta edit it and I'm actually working on that now, but just kind of took a breather and, and took a break so I can show you guys what I'm doing here.

So what I wanna show you that's important is let me see, I'm getting down. Oh, here it is right here. So here, if you could see my screen, these are all the controls that, that are in the CIS security, critical security controls. This is also known as the sand. Sand's top best practice best security practices.

But these controls explain all the things that an organization needs to have in order to secure their system. If you've done any of these things as an it professional in your profession, any whatever profession you're in profession, you're in, you've done these things. You have done security and you need to put it on your resume.

You need to put it up front in your resume. So let me just go through a couple here to give you an example. So I'll pick a couple here. One is here's what's a good one. Let me see if you've done. Okay. Here's here's a good one. Here's a couple good ones. One is email. Well, we'll start with audit logs.

I like that one audit log management. If you've ever turn enabled audit logs, for example, if you've ever monitored audit logs, if you've ever. For EV any reason had to analyze the O audit logs. That's a security, that's a cybersecurity thing you gotta put on your resume. And audit logs. If you didn't know another name for it is event, event, viewer event logs, you know, different systems call it like slightly different names, but it's all, it means the same things.

It's the logs that are in the back end of the system. That's telling you if the system is shut down or if somebody is if somebody is attempted to log into the system, but it was logged in, in unsuccessfully or, or successfully or whatever those are logs, audit logs. Another thing we'll talk about is EV email and browser protections, email and browsers is probably one of the biggest threat vectors or biggest ways that, that attackers adversaries can actually infiltrate an organization.

Cuz email, think about it, fishing. Like when somebody sends a fake email with a clickable link and then, then somebody who doesn't know any better, they click on that link. And it takes into a malicious site that malicious site downloads something to their system. Yeah, that's, that's one of the main ways right now that's happening that that sites and organizations are getting infiltrated and web browser protection.

That's another one, everybody interfaces with the internet. Most of the 99% of their interactions with the internet is through a browser. So it's important that that browser is up to date. It's important that it has any extensions. Those are approved in extensions, things like that. Malware defense. That's another one.

This is like making sure you have anti-virus. So let me show you, how do you word these on your resume? How would you go about wording? So what I did was I broke each one of these sections down to explain how you word these on your resume. So let's go to the ones we just talked about. We'll go audit, audit, log, manage.

So what, first of all, explain what it is. Audit log management audit logs are gathered on servers, end user systems routers, and other systems to prevent to detect, prevent and understand possible security incidents on the enterprise. That's what they're for. It's not just for security. It's actually for maintenance as well.

So how could we word this? So one of the things we could say is that you ensured that audit logs were enabled in a mixed mode environment. Mixed mode means like you didn't have just windows, you had Mac and you had Linux or whatever. And you allowed detection of threats against assets against assets in cybersecurity.

Okay. This one, I, I have to reword this one. I did reword that one. So in my, my next draft, but let me, let me just give you another example. Conducted security, audit, log, an analysis to detect anomalies or. Abnormal events that might match adversarial tactics, techniques, and procedures that are in the Mir attack framework.

And the reason why I put these together, this, this sentence is, is very tactical because I put a whole bunch of keywords in here. They wanna see that, you know, the Mir attack framework. If you don't know what it is, go look it up. It's, it's really important to cyber threat intelligence. Whenever you do cyber threat intelligence, it's like a breakdown of different types of attacks.

And I'm sure most of these you'll be familiar with like, how do people infiltrate a, a network via a Trojan, a Trojan horse? How do they, how do they actually infiltrate? Mir talks about things like that. Mir talks about cross side scripting, Mir talks about escalation of privileges. It breaks all these things down and kind of gives, gives you an idea of the path that an attacker and adversary takes to get into a, a network.

And you use the terminology to, to. basically establish a pattern when, and this is really good for writing reports. It's really good for your resume. It's really good for articulating what kinds of threats and what kind of vulnerabilities you have to avoid within your organization? So this is a really good key word, and I see it all over things like if you're going for a cyber security analyst, Mighter you, you need to have that on your resume.

And then audit log analysis. This is another key word. So you can see that what I'm doing is I'm talking about, I'm given the action of what you did pertaining to cyber security. So if you've done it more than likely you you've done something with audit locks, you have to articulate that. So I give you several different examples here of how you can articulate and how you, how you can word your the, the bullets on your resume.

And I apologize for this. This is like a rough draft. I'm actually, I have another updated one that I I'm working on. On my other computer. So let me show you another one. And here's another one right here. This one doesn't even have bullets on it. This is showing you how I'm literally working on this as we speak.

So bear with me here. Let me just put some bullets on it. So it's clear to, to read. Okay. So this one is CI CIS control nine email and web browser protections. What is it? So it's protection of email and web browsers. And, and this has everything to do. What we talked about earlier, which is making sure that users are educated on things like social engineering.

What is it? How do you avoid suspicious emails and clicking and opening up things that you shouldn't open? Well, how do you put this on your resume? Cause more than likely you, if you've done it for some time, you have done something with this. Now keep in mind if you haven't done this before and you're trying to get into it.

If you're trying to get into cyber security, this is a great opportunity for you to. What you need to what experiences that you need to have, what things you need to study, because this is the kind of thing that employers are actually looking for. So let's just go through a couple of these. So one is updated signatures on enterprise antivirus software for proactive protection of 1500 endpoint devices and servers on the land.

So we've got a couple of really good keyword here. We're talking about anti-virus software, we're talking, we gave an, an impact. Now this is another thing you use numbers to establish the impact to your actions. Cuz it's one thing to have an action, but it's a whole another to actually show the impact of what you did so that the employer, when they're reading your resume, they're like, okay, this guy does know how to do antivirus, but wow.

They did 1500 InPoint devices. Okay, this person really knows what they're talking about. And another step you can do is actually name the actual software that you used. That's also a great tactic. Because a lot of times, like what I've noticed in right now, I'm, I'm actually interviewing for jobs and stuff and they keep asking me specifically, do you know semantic endpoint protection, because that was on my resume to keep asking about it and have I implemented it?

Have I maintained it? Have I configured it, all those kinds of questions. So you can name the actual anti-virus enterprise antivirus that you actually use, whether it's Soho or if it's semantic or, or, or AFF or whatever it is, you can name it. So that they'll know which one you're using. And that becomes a key word as well.

Let's see here set up DLP technologies like Proofpoint email. See this one. I'm I'm mentioning it. DLP and C a S B Microsoft information protection MI Microsoft security, suite defender. So I'm naming a whole bunch of, of, of, of tools here. Tools are also a are also a key word. So that's something that you should also mention on there.

Okay. Let's keep going. There's a couple of other ones here, but let's go to the last one here. Malware defense. Now this is most people who are in it have done this before. So if you've done this, you've gotta mention it on your resume. You've gotta put these security features. Anytime you've interacted with a security control, you have to put it on your resume.

Otherwise, the employer is not gonna know if what you've done. So, this is one of the main ones, and this is, most people have done this. If you've done it, you've put in, you've updated the antivirus software. You've, you've updated the signatures of the antivirus software. You've removed antivirus on there.

So you've gotta put it on your resume. And this one actually on my, I didn't actually put the, the breakdown of the, of bullets here, but it's on my, this will be in the book. So just stay tuned for this. I just, the reason why I decided to do this book, I took a, a kind of a respite from the risk management framework series because people kept asking me the same questions, the same questions over and over and over again about like, Hey Bruce, what do I put on my resume?

Like what, what do I, how can I get in? I've been doing this for 15 years. I'm working in a job. That's not, I'm not getting paid a lot, but I've been, I have 15 years of experience. And why am I not able to get six figures? Why am I not able to get a better. And then I look at their resume and they're not really talking about cyber security and I'm like, you wanna get a cyber security job, but you didn't mention cyber security on your resume.

And I'm like, you gotta put it on your resume. So they'll send me their resume. I'll take a look at it. And there's nothing on there that talks about cyber. So what I'll do is I'll just put it in some keyword and I'll say, look, this is the kind of stuff you have to do. And now I'm trying to put a book form where I can just give it, basically give it it away, cuz it's gonna be a pretty cheap book.

It's not gonna be expensive, but it's gonna help a lot of people out. So that's kind of what I'm going with this. And I'll I'll let me see if I can answer a couple questions here. I see a couple people join me. Thanks for watching. I appreciate you guys. I know this is not the normal time that I do this smooth virus says 1500 more like 150,000 yeah.

True. True. True. Okay. So let me, let me go to, I had some stuff open here. If it didn't crash on me. We have some questions. Let me see if I'll just answer like one or two. I won't to keep you guys too long here. And this'll, this'll actually be an audio file. If, if you didn't know, I have a, if you go to pod bean, right?

If you go to pod bean combo courses dot pod bean, that's where my actual podcast is, and I've been putting 'em out daily. So go ahead and check that out. There's a whole bunch of 'em that I, that I I hadn't released. So I've been releasing those ones in podcast. Let's see. Let me see if I can answer some relevant questions here.

Okay. Somebody saw, talked about the, the key challenge. I don't know if you guys knew this, but there's something's going on where people are stealing Kias using a USB cable Kia's in Hyundais, Hondas. I believe of a certain type it's called the Kia challenge. Look that up. It's pretty, especially if you have a Kia high Hyundai is what it is.

Kia or hi Hyundai. Let me see, see if I can answer some more questions here. It's mostly about the Kia challenge. Somebody asked me about my book. I probably need to respond to that one. Whoa. Okay. That should have been blocked. Okay. I'm gonna go to TikTok. Let's see if there's some questions here lately.

I've been getting a lot of questions on TikTok. And so I answer these one at a time directly usually, but let me see if I can answer at least one. Could I get into cyber security with just one year of help desk and one of these certs? Absolutely. You can. This is exactly what I'm talking about. So if you, if you have, if you've been on the help desk for a year, more than likely you have done cyber security.

So that's that's, this is exactly what I'm talking about. You have done cyber security before you just have to put it on your resume. If you put it on your resume you, you will. You will get hits. You will get people contacting you about this. And that's what this book is all about. Let me see if I can bring that up again.

Nine, which one? Which version? Okay. I've got so many. That's one. I write, I have a whole bunch of versions. I have a whole bunch of versions of my book where I'm, I'm constantly updating, updating the book and stuff. So let's see set up marketing. I tell you how to market. Once you create an awesome resume with loaded, with keywords and, and lots of action and impact statements, I show you how to market it.

And this is something that's been working for me for many, many years. I've been using the same thing. And what I didn't know that I was doing right is I was using the correct format for my resume. I didn't know until recently it's called ATS style resume, and it looks a little bit like this it's very plain.

It doesn't have any kind of, and that's the thing. My, I had a ugly resume. It's ugly and there's misspellings in my resume. somebody point I was in an interview and somebody pointed that out to me and said, Hey, you know that you have some misspellings here. And they were like, I don't care about that. But you, you know, you might want to fix that.

I was like, wow. And I still got that job by the way. It's crazy. Right. And it's because my resume's dope. My resume's really good. It's it's loader we keyword. It's it's highlighting all the security stuff I've done. This is what an ATS style resume looks like. It's just plain. It's just like, so this is what you'll do.

If you are help desk, you've been doing it for one year. You, you have to put ATS style, resume on your cyber security resume. And then you've gotta mention all the times you've done cyber security. You can't just talk about in uploading or installing windows. It's gotta be what security patches did you put on that windows device?

How did you help the organization reduce the risk? Stuff like that. And this is stuff that when you're in the weeds, when you're on the help desk, when you're, you're a system admin, when you are firewall, even firewall guys, sometimes they're not seeing the big picture of what's going on, which, which is making sure the security posture of the organization remains at a certain level, right?

They're not seeing the big picture, but you gotta put that big picture on your resume. And the way that you can pinpoint that is look at the actual security. Look at the actual security controls, the best practices, the CIS controls is one that's only one you could do PC. You could look at PCI, they have a breakdown of all the security controls, and they look very much, very, very similar to CIS N 800 is really exhaustive and it goes into super great detail and stuff.

You, you can also use those too. This one I found is like one of the best breakdowns, because it just gets right to the point there's only eight 18 controls, security controls in the CIS version eight. I think, I think version seven, the previous version has like 22 controls E either way. It's covering the same ground, all the best security practices.

And that's the stuff you gotta put in your resume. I'm gonna do another actual TikTok of this, where I break this down. And so, so we'll, we'll cover that in greater detail. Bark says I've got lots of work to do on my fed resume. Yeah, man, like this kind of stuff right here is what you wanna make sure you put on there, this kind of stuff right here, these things, if you've done any of these things, you gotta put it on your resume.

and my, my new book is gonna break down, like how you word it for each one of these controls. If you've done this before, give you an idea, like, okay, have I configured data recovery systems? Have I done that before? How do I word that in an, in an impactful way that shows that not only have I done it, but I impacted this organization, I helped them with their security bar says, by the way got your, your RMF book.

Was there a part one? There's a part one and a part two to the RMF books. So let me see if I can bring that up. The RMF book has a part one and a part two, and I'm actually working on a part three, but that's gonna, that, one's gonna take me a little longer, cuz it's, it's talking about SCA or security control assessments.

Let me show you. Okay. I'm gonna show you on two different platforms. I'm gonna show you on audible and then I'll also show you, cuz I've got an audible version of it. If you happen to be driving on your commute, you can actually just listen to it. Or if you happen to be jogging or something, listen to it.

If you wanna know more about risk management framework and the controls and how it's broken down and stuff like that. The other one is Amazon. Let me show you. So if you go to Amazon or you go to audible and you type in just R M F I I S S O and you will find my book, both books. R M F I S S O. Okay.

Let me just show you here. What I'm talking about here. It is an audible. You can listen to it right now. If you like. The one, the first one is very short. It's only like an hour long. It's a guide. It's an overview. Like if you were like wondering, like what is missed 800. If you are crazy enough to like, say, what is N 800?

Like this breaks it down in one hour, I break down like what, not only what is, is it is, but how do you actually implement it? How do you as an information system, security officer, I'm hidden it from that perspective, how you actually, how you actually implement it as a, a cyber security person. And then the next book goes into greater detail about the controls.

And what I do is I talk about like, here's, here's the controls and here's what you do in with each one of the control families. I don't, there's a thousand controls, so I don't go in all thousand controls. That'd be a super boring book. I also use practical. Things that have actually happened to me in each one of those families, not just happened to me, but happen to people.

I know things that are going, like I mentioned, the, the I don't know if you guys remember the, the colonial pipeline, where does that fit in with the risk management framework? Where does that fit in with security controls? I use real world example. So you can get an exam, a, an idea of what that control family really means.

So that that's the two books right there. One's four hours long. The second book is four hours long. So I, I think it's a really good, a really good book. I, I haven't seen anybody write it like that before. So where you are using practical stuff, and I'm kind of doing the same thing with the SCA book, the SSEA book, the SA book is going a lot deeper than I wanted.

I, it's kind of like when you write, sometimes the book goes in its own direction and that's kind of what's happening with SCA. It's just getting way longer than I thought I was gonna get. I'm trying to, I gotta chop it down a little bit. Let's see. Bruce helped me. Land a federal contract job in cyber security management, man, smooth, smooth virus.

I is, is the man. this person I know. I know personally. So the advice he gives you does work, man. It really, really does work. And I only, I only mention it because I've been doing it for years. It's, it's the same tactic I've been using for years. And I, I constantly get work. I'm never, I, I don't have to worry about not having a job because I use this technique and I'm con sometimes I gotta turn the tap off.

Right. I turn it on. And it's like a flood of all of these different opportunities. And I gotta turn it off. I gotta turn the taps off. So it stops. And right now I'm, I'm going through that process right now. And it's something else I'm not actually doing background checks and stuff with a job that I, that I got chosen for bar says, awesome.

I have a good state level. Experience, but but new to fed. Oh, okay. That's great, man. That fits right. That fits right into the state federal stuff. It it's kind of goes hand in hand with, I, I believe state uses N right. Well, some states use the, the N 800 framework. So you'll, if, if that's the case you'll fit, right, right.

In there, federal stuff does, does things a little bit different is a lot more details. I, and then smooth virus says I can't get them to stop emailing me. exactly. Exactly. It's crazy. It's crazy. You gotta make sure all of your like monsters, you gotta be turned off, like make the, make your resume invisible.

You've gotta turn off. But what happens is, so what happens? Smooth virus is that the, it works so effectively. He's talking about the, this, this method that I have, it works so effectively because, because when you, when you put the resume into their database, it stays there. it stays in their database for years.

I got people calling me from a resume that went into their database five years, literally five years ago. And they contact me and say, Hey, are you on the market? Like your resume fits this job that just opened up with Boeing or with, with whoever, right. All of these different companies. And they're calling me from five, my resume's five years old in their database.

And sometimes they're like, nah, that's my old resume. Like, here's my new one. Like, here's, here's an updated resume. It really works. Like this technique really, really works. So if you, if you're like really looking for a job you're really trying to level up, then then you should be looking out for this book cuz it's coming soon.

It's coming within the next 30 days for sure. And then I'll have a follow up book where I break down something called a nice cyber security workforce where I break down each category. If you're trying to level up from one. Category to another, or if you're from it and you want to target a specific genre of cyber security, cuz there's many different kinds, then, then that's gonna be the second book.

And that one, I should be able to knock out pretty fast. I hope. And then I'm thinking about a third book in that series where I'm talking about either remote work, cuz I've been able to remote work remotely for, for over six years now. And then I'm thinking about doing one for entry level, cuz I get a lot of questions on that one as well.

So those books are incoming. First book in the series is gonna be called cyber security jobs resume marketing, and that one's coming real soon and, and it really, really works. It's all about finding patterns, finding patterns and exploiting those patterns and putting that on your resume. It it's like you're hacking, it's like you're hacking the entire system to make sure that your stuff rises to the top every time.

And it's really, really been working for me. Okay. There's a conversation happening here. Let me see. He says, bar says he's, he's got he's in Virginia and he's got a CI S P with 18 years of experience. Holy crap, man. You're about to make some money. If you got the, the CI S P or golden. Absolutely.

That's true. Let me see. And he says yeah, I would, if I would, yeah, you'd get around 200,000 or more in, in in Virginia area. Virginia pays really good, especially if you've got a, if you've got Virginia, Maryland, DC, that area, the DMV area, DC, Virginia, Maryland, D D DC, Maryland, Virginia D DMV. Yeah. so much anyway, so that area pays really good.

There's so many jobs in that area pays, pays really, really well. and because there's just so much competition. They they're, they're the ones getting most of the government contracts and it's because there's three level, all the three letter agencies have their headquarters there. NSA, FBI, CIA, all of those.

And some, some other ones DIA and all, all these other ones have it's like the hub of everything. Then you've got the senates there. You know, the Congress is there. You've got the white house. Is there everything is there. So there's all these contractors and subcontractors and there's just this, so many cyber security jobs there.

So, so man, it's crazy. Okay. I got a lot of people. Wow. I got a lot of people watching me right now. Mike VI, how you doing bark? I've got a smooth virus. I've got. Lu Ludwig. Hey, thanks guys. Thanks for watching. I appreciate everybody. And if you guys didn't know if you're caught catching this late, what I'm doing is I'm talking about another book that I'm, that I'm putting out real soon, you're looking at like the rough draft, this isn't E doesn't even have the, the actual right name here, but it's gonna be cyber security jobs, resume marketing.

And this one is gonna break down how you can level up using these proven techniques I've been using for many, many years. And as a matter of fact, people there's people watching me right now who use this technique that I've directly told them how to do it, or they took my course and they did it. And now they're working remotely working where they wanna work, making the kind of money they wanna make.

And that's what I'm trying to help people to do to. Make a whole bunch of mini Bruces out there. So you can, you guys can reap the rewards and the benefits of cyber security that I have over all of these years and not have to worry about the recession or people saying the economy's gonna collapse or whatever, cuz no matter what happens, cyber security is necessary because all of us are relying more and more on information technology.

And the more we rely on it, the more heavily rely we rely on it. The more protection is needed for your, your personally identifiable information, your private information, more more protection on your social security numbers, your banking information, your healthcare information, you name it. Every industry needs cyber security.

So the, the right now, as a matter of fact, there's something like 700,000 jobs that are positions that are need be, need to be filled. That are in the government space alone. So yeah, I'm telling you like it, this is a hot, this is a perfect opportunity to strike while they really need more people.

There's been a huge vacuum of people that have retired gotten outta this career field. A lot of boomers are getting out because they're, you know, they're 60 plus they're kind of getting, getting out, going retiring and stuff. So now there's this huge vacuum of people who are come, who need to come in fresh blood is needed to, to make this system work.

Mike bill says I'm in school doing cyber security and cloud. That's awesome. Mike, I would, I would highly suggest getting a cloud certification. The AWS cloud practitioner is a really good one. I would come outta school with that. And then. As much as you can, Mike, if you can get some kind of experience under your belt while you're in school, that would be awesome.

Get some sort of experience so that when you, you are already starting to fix your resume up, right. And the things that you need to do, the kind of stuff they wanna see on your resume. I mentioned in this book I break it down like how they wanna, how they wanna see it and all that kind of stuff. It's these controls because the name of the game was cyber security.

It's all about it's all about implementation of cyber, of cyber security controls, and actually physical controls and management controls. It's actually quite a bit of different types of controls that you can, if you've ever done an example, like to, just to give you an umbrella of like what kind of controls that they wanna see, not just technical controls, not just firewalls, not just audit logs, but it's also physical.

If you've ever done a physical security control assessment, that's one. If you've ever done a wireless scan, that's one, if you've ever done inventory on a network and, and made sure that the organization has a baseline of, of all of their software and hardware, that's the first two right here. The first two are inventory.

You wouldn't think this is a security control, right? But if you've ever taken accountability of all the assets, assets, meaning their computers, their servers, their workstations, their laptops, their phones, and made an inventory, a list, and you've maintained it in a database or whatever, whatever have you.

If you've done that before, that's actually a cyber security controls. So you gotta put that on your resume. And before you get outta school outta school, Mike, if you can try to get work, I'm working in the college as a as a front desk. That's awesome. If you can get some cyber security under your belt, some kind of, if you help them to.

For example, update their viruses, definitions, like say you, you have a desktop right in front of you. You help 'em to upload their virus definitions, put that on your resume because you can literally name the school and say I updated, you know, X amount of systems with the, or I've I up updated a critical system with the most current signature for McAfee, antivirus, whatever.

Like you could put that on your resume, start building your resume before you even get outta school. Because the most important thing when you get out is gonna be your experience. Yeah. Your degree is great. Like you have a bachelor's degree, especially if you have cloud experience, another thing, build a cloud server before you get out and that's something you don't even need the school for.

You can build a cloud server and get ans practitioner cloud practitioner certification, and you put that on your resume. If you can help the school do any kind of cloud stuff, put that on your resume. I'm in the CCDC team. Yeah, man. That's awesome. What, what does that stand for? CCD C's team is that computer department?

What, what does that stand for? Okay. Somebody says, how can I work as an ISSO without a clearance? So O Omo. So there are jobs and back me up. If you guys know what I'm talking about here, there are some is so jobs without security clearances, but they're, they're rare. And I personally have worked a couple a job, actually, right now I'm interviewing for a job where I already interviewed for it.

I got the job. I'm just doing background check, but there's clearances that are not security clearances. I mean, not secret clearances or not Ts S E I clearances. There's one called the public trust. Public trust is like a lower level a lower level security clearance. So. You, you, you know, you, there are jobs where the is, so doesn't have to have a security clearance, but there's also jobs where the is.

So can have a public trust, which is not as high level as a, a secret clearance or a Ts S sci, and it's way cheaper for them to do that particular type of clearance where they'll bring you in and, and they'll give you that public trust clearance. That's another thing. Another thing is that when you get into those jobs, what they'll do is sometimes they'll pay for your, your SS B I, your background check.

And then you can take that background, check to the next job, your clearance to your next job, and then you get paid a little bit more. It's national collegiate cyber defense competition. That's awesome. Put that on your resume. Put that on your resume. Is do as much as you can, before you get out, you probably give a, get a job before you even get out.

If you start right now, Mike, if you, if you, let me tell you something right now, you can put, you can list the credits that you already have from your degree on your resume. Right? Then you can put that you're on the national collegiate cyber defense competition, and then the accomplished event that you guys have done any kind of any time, you've helped them with their help desk issues, troubleshooting, adding updating patches that kind of thing.

Put that on your resume. It's just a matter of wording it properly, put that on your resume and then put that resume up on LinkedIn. Now it's not gonna have a lot on it because you're just now getting into this field, but I guarantee you, if you put that on monster on dice on LinkedIn and at least 10 other sites, As you're building your resume, you will get contacted.

You could have a job before you even leave the college. You hell it might even be so good that you say, Hey, you know what? I'll come back to college. I'll finish this later. I'm and I'm being completely serious. You'll get offers if you actually do what I just told you. Let me see. Okay. Focusing on the third risk management jobs, I'm focusing on the third party risk management jobs since I have no clearance.

Okay. Is that pretty good? Sounds like that's pretty good money. Like risk management job, third party, risk management job. You could still get security security control assessment jobs, and those pay really good if you're doing like third party risk, risk assessments and stuff like that. That, that, that could do too really good.

Now, om old, if you don't mind me asking, why don't you have a clearance? Is it, are you not eligible to get a clearance? Are you not a citizen? Because I know that. In order to be eligible, to get certain clearances, you have to be a you have to be a us citizen for certain clearances. And I don't, I think public trust, you don't need a clearance, but I could be wrong.

I mean, you don't what I'm saying. So I think for public trust, you don't need to be eligible. You don't have to be a a, a us citizen, I believe, but I could be wrong about that. Let me see. Okay. And then smooth job, smooth virus, just, he confirmed what I said. I'm completing my bachelor's degree now.

I got the job, even though I'm not done yet. Exact. That's exactly what I'm saying. Like one time I give you another example, Mike, when I I got outta the military, I had experience doing the work, but I didn't have all the requirements. I had a degree, but I didn't have, I didn't have a I didn't have the CISs P yet, but because I had the experience.

they said, Hey, you know, I sat with, through the interview, they love me. And they're like, listen, we want to take you. But only thing is this job requires a CI SS. P can you get a CI S S P within a year? I said, I said, yeah. And they said, we'll, we'll, we're gonna send you to a bootcamp. So you can get this, this certification and we'll pay for the certification, but you gotta get it within a year.

I said, yes, I'll do it. So there's flexibility. Like, even while you're in school, if you start to build your resume and market yourself, like I just told you, you can start getting a job. You could actually get a part-time job, making really good money in it and cyber security while you're finishing your degree.

And actually the company, a lot of times, they want you to finish that degree cuz soon as you, you you're done with it. They'll be like, okay, you're a supervisor. Okay. We gotta pay you more. We're gonna put you over here. They'll do that from time to time because they really need people who, who know what they're doing.

They really need people who, who are willing to work and do this and level up. Let me see. Almost says I'm a citizen, man. Then what is happening? Why don't you Somo? Like if you're looking for security clearance then what you could do, one of the things you can do is especially if you live in the east, on the east coast, they have a lot of jobs that require security clearance.

If you have a skill set, you said you, you work as a risk management framework person, third party, but you don't have a clearance. You could get a job, even if it pays a little bit less, right? And, but they're willing to pay for your clearance. Listen, it will be worth your time to work there for about six months, work there for about six months, have them get your clearance take as long as it needs for them to get you a clearance and then bounce, roll out and go to another place and be like, Hey, I got my clearance.

And by the way, I'm a risk management framework person. They'll pay you more money. Like you'll. They'll pay you more my hell after you get the clearance, they might even, they might even update you. They might even pay you more. It says I'm doing things backwards too. I'm in the healthcare and got a security plus and plan on going to get my master's in cyber security.

That's awesome, man. Like healthcare has so many great so many great opportunities because there's just such a huge need for healthcare professionals. People who are well versed in the healthcare industry to be cyber security or it people right now. And I can just give you one example of what I'm talking about.

Like it's, it's so crazy right now. Let me just show you what I'm talking about. Here's my book right now. If you guys, my book's right there. If you guys are trying to learn risk management framework, it's those stuff it's blowing up. Let me see. So let me, let me just take you to this site. This is a DISA site.

I'm gonna take you into a DISA dot mill site. Now you might be wondering, like, what does that have to do with healthcare? I'm about to show you, this is how crazy healthcare is. So I just typed in DISA a dot mill at 81 40. So let me just show you to this site. So 81, 40 and 85 85 70 is like it's like a breakdown of all the approved certifications that the department of defense and by proxy, some of the federal government actually uses to say, okay, these are approved certifications.

So what I wanted to show you is this right here. See this right here. What's that say? You see that this is on the approved list. This is an IAM level two. I am level two means information assurance manager level two, which means it's it's, it's a fancy word for information security or Infor or cyber security for information security.

Manage management and it has H, C I S S C H C I S P P. And I don't know if you've ever heard of this certification, but let me, let me show you something here. So if you type in this particular certification, I happen to know that this one specifically for healthcare and it's coming from the ISC two squared ISC, two squared is the top organization, arguably the top organization for security certifications because they, these are the guys who do the C I S S P.

Now they have one called the H C I S P P, which is for healthcare security certifications. I mean, professionals. And it break. Let me show you the breakdown of this. Like, if you didn't know about this one, this is this, one's hot, this one's hot, especially if you're in the healthcare industry. So this is the kind of stuff that's on that they expect you to know as a H H C I S P P.

and it's H H C I S P P is ideal for information security professionals charged with guarding protecting healthcare information. P H I protected healthcare. He protected health information, including those in the following positions. So if you happen to be in a compliance officer, information, security, privacy, officer, risk analysis analysis analyst hi health information manager.

If you do any of these things, they're saying, Hey, this is good for you. And see, it's listed right up here with the, with all the big boys, all these CI S S P and the cap and all these other ones. I didn't know about that. Thanks for sharing. Yeah, this is a, this is a really, really good one. Now, recently, if you happen to be entry level, this might be for Mike right here.

Entry level, the CI the ISE two square recently created this one right here. This is exciting. I think this one's gonna be listed on that approved list. It's the entry level certification for cyber security people, which is, which is crazy. They're trying to compete with security plus I think, but yeah, anyway, back to our subject.

So we're talking about this one though. So this is CRA, this is crazy. So you just recently added this to that department of defenses, the list of certifications. That means this certification is about the blow up. A lot of that means a lot of contractors, a lot of recruiters, a lot of HR departments are gonna start listing this as a requirement at major healthcare facilities, so that you have this certification, you get this, something like this under your belt.

And the thing is if you've been doing this and the healthcare field for some time, You might, you might just blow this test out of the water and then they have a breakdown of topics. So you gotta, I think you have to give them your, your information. They'll send this to you and, and you'll have their newsletter or whatever, but they have a breakdown of the domains, which I'd be interested in to see this right here.

Oh, here it is right here. Okay. Sneak peek at the domains. Here's the chapters. Third party, risk management, introduction of healthcare industry governance, legal risk compliance. Yeah, really cool stuff. Really cool stuff. It's they're saying it's already ranking in 39th among security clearances. I don't know about that, but that came from certification magazine.

Okay.

Yeah. So that's, that's really good stuff. Exciting times if you happen to be in this field. It hasn't always been like this. It's it's really hot right now. There's so many, there's so many job opportunities. And I just want to show you guys this this little before I let you go. There's so many jobs that they're looking for recently.

This is from July 1st, 2021 of last year, all the way till now this is from July 29th. The white house is pushing to fill 700 700. This is real. They're pushing to fill 700,000 jobs in cyber security in the United States. And what they're doing to do this is they're getting with all kinds of all kinds of private and public and nonprofit organizations to, to teach this.

That's how they have a whole bunch of free courses out there. They've got a bunch of, of, of organizations that are trying to get entry level people in cyber security. Like I believe Booz Allen Hamilton did it. And they go really fast. Like as soon as they list that job, it just, they jobs just start going really fast.

So the 700,000 job thing is real. Yeah, this is real, man. This is, this is coming directly from the, the, the white house, like the white house at a summit lack last month where they said there's 700,000 cyber security jobs we wanna fill across. I think what they mean not is not just the federal government.

I was, I think I misspoke with that. I think they mean throughout the United States, there's 700,000 jobs. And the reason why is cuz there's heightened, there's a lot of stuff going on behind the scenes. Like governments are starting to attack each other. There's a huge cyber war going on right now. And so that's why you're hearing about all these leaks and all of these.

All of these hacks and stuff, because a lot of companies and a lot of banks and a lot of healthcare industry facilities and stuff, they don't really have appropriate. They don't have appropriate security measures and what's happening is they're, they're soft targets. And and they're going to these hackers.

There's there's criminal gangs. There's some that are backed by, by government state state governments. There's some that are backed by you name it, criminal organizations, just that you're just trying to get money, whatever it's a free for all right now. And there's, and we are, the us is the biggest target because they're the ones holding all the money right now.

So, you know, they'll go off to a bank cuz they know a they know what the healthcare industry will pay. Like if they get you, did you hear about the one in LA? Like the LA school district? Somebody tried good on LA school district. They, they were able to they were able to protect themselves, but yeah, some, some hacker group went after LA school district.

Let me see if I can find that one.

Let me see if I could find that one. This is crazy. So yeah, the, they, somebody went after hackers target Los Angeles school district with a ransomware attack. They tried to get 'em on a ransomware attack. This was recent. This was like yesterday or something. Yeah. Look at this. September 10th. Yeah. Okay. So four days ago, hackers target Los Angeles school district with ransomware attack.

And luckily the, the school district was prepared for it. This is kind, this is what's happening. This is what's happening across the board because we're, so we've got so many soft targets and It's just, it's, it's sad to see, but that's why there's so many job openings for cyber security. And the white house is pushing this huge initiative to you know, to get more people, cyber security analysts, information system, security officers even, even things like program managers.

They probably lump those, those people in there program managers are super critical to, to doing things like security and engineering. So they are part of our team. Let me see, basle says, I'm looking to get into this field. Can you let me know what I could study or brush up brush up with? Okay.

So here's, here's what I, here's one of the things that I show how to that I would suggest. Okay. And this is just my 2 cents. Like some, there's some gurus out there who are, will tell you something totally different. , this is the first certification that I got from CompTIA. CompTIA has one of the best curriculums out there.

Some people really hate this certification, but you know, the market doesn't, if you have the certification, you can get hired somewhere so people can hate on it all. They want just like ch people hate on ch, but you know what? That will pay you. And this one, if you're an entry level, this is where you can start.

And so one thing you should know is that certifications, you can't just get a certification and magically get a job. Okay? It's not, that's not how it works. Like you can't, if you've never done any it work before you gotta put the work in to learn the material. But what I'm saying to you is that even though these these, these certifications are made to validate the skillset and knowledge that you already know, or the experience you already have, you can use it as a curriculum to learn.

And, and that will get your foot in the door. Now don't focus on the prize so much as the process itself, the process of learning this material in such a way that you can level up and start to actually do this work and, and get yourself an entry level position that doesn't require all of these different high level requirements.

So you go through this and you go through the curriculum of this, and it's gonna show you things like hardware, operating systems, how they work, software troubleshooting, network, networking, troubleshooting, security, virtualization, a little bit about cloud stuff, mobile devices. Those are kinds of the things that you're gonna see on this test.

But bef like before you take the test, you want to actually go read the book, break it down. Learn about it, put it on your computer. You can use VMware to learn it on your own. Like you could have a virtual environment right here, right on your computer. You can set up networks in your house. What, what I did when I first started doing this, I would build computers.

I would, I would buy the components, build the computer, cuz it gets you exposure to the hardware and let you know how the software works with the hardware with hands on experience, nothing beats hands on hand on hands on experience. So if you can get virtual virtual networks from things like GNS three, that's another thing you can use once you get this certification.

Like what you wanna do is study there's. This is two tests. This is not an easy test by the way. Now, if you're not very proficient, if you're not very savvy on on computer stuff, what you can do is go comp tia.org and go to ITF ITF. Plus, if you wanna, this will tell you whether or not you should even take.

Any of this, like you, whether you not, you wanna do this, a lot of people chase that money, chase the stability of it. So you, you might not even wanna do this. You know what I mean? Like this right here kind of dips your toe in the waters of it. So when I keep you probably I think it, Bruce, I don't care about it.

I wanna do cyber security. I know, I know. I know. I understand. But I, cyber security is stands on the . You have to know it before you get into cybersecurity. I, it, cyber security. Is it information technology? All we're doing is it's. It's like one it's cybersecurity is multidisciplinary. All right. So for cybersecurity, You're you're expected to already know information technology that's basic computer stuff, hardware, software troubleshooting, things like that.

So this something like this is an entry level. That's gonna tell you the terminology, the basics of information technology, how it works before you get into the hardware hardcore stuff, which is a plus certification. A plus certification is, is actually no joke. It's it it's, especially if it's your first certification, it's not easy.

So it was my first one and it wasn't easy for me. So it was not easy cuz you have to learn all the terminology and they're just throwing all the stuff at you and stuff. So like now if I went back to it, I'd be like, okay, I know this. Yeah, I know this, I know this, but if you're coming on there cold, a plus is not an easy certification to take cold.

It's not easy to take cold. It's so much terminology that you have to learn. So. After you take, let's say you, you got, you went through all this curriculum. You listened to Bruce's live and you like, man, this guy knows what you're talking about. I'm gonna go ahead and study for a plus. You got a book, you broke down the book, you took notes on it.

You took the test, you passed it. Another thing you could do, I'm just gonna tell you three different search. You should do that. I recommend there's another one called Google. This is, if you don't know, if you don't have a degree, if you Mike is already getting his degree, he's already like he should, he could probably do go straight to professional level search if he wants, because he is about to get a degree he's in UND himself in this world and everything.

But if you happen to have no degree, you're doing us all from scratch. Here's another one you can do. And you can do this one. If you're in college too, it's no big deal, but here's one called the Google support. It certification. The reason why I would recommend this one is because a lot of people are taking this certification with no degree going in.

And, and making and making this kind of salary right here. This is what people are telling me. This is what my users. Now this is anecdotal information. I do not personally have experience with this. This is all new to me. In my experience. You, you can't get into these fields without experience, but I stand corrected cuz several people have contacted me and said, yes, I got this it support certificate and I'm making X amount of dollars.

So this is another one you can do. If you're trying to bypass the degree programs and stuff. I, this is no guarantee that you're gonna get anything. Okay. But I'm just telling you anecdotal information of people contacting me saying I took certification. I'm now making X amount of dollars, not a hundred thousand, but it's pretty good money.

And it's entry level. They're doing entry level work by the way, another certification. Here's the hottest. One of all this one, whether you're in, whether you are in a degree program, whether you are have five years of experience. Whether you have a CIS S P, whether you're coming in off the street, you used to be a sanitation engineer, and now you're doing this.

I recommend every person take this one. Every person, every man, woman, and child dogs, cats living together, all of everybody should take this one. Okay. It's called the eight. If I could type cloud certification practitioner. So there, and let me, I'll just explain why this is, this one's so important. Okay.

And I went to the wrong site here, went to the wrong site. I'm trying to go to actual TMY is a good, good place to actually learn this stuff. I don't teach cloud yet. So TMY is a good place to prac. But anyway, here it is right here. AWS cloud practitioner. This is why this one's so important. Everything is going to cloud.

If you use Google, any Google services you use in cloud, Gmail's using cloud YouTube's using cloud services. All streaming uses cloud Netflix uses cloud everything's on the cloud right now. Everything is on the cloud. And AWS, Amazon is the leader in this. So Amazon's the leader in this. Amazon is killing it.

Like Amazon owns something like 30% of the total market share for a cloud. They, they own most of the government stuff in cloud. They, they they're their only competition really that's that's close is Azure from, went from Microsoft and, and Google Google itself. So this, this certification is not hard and, and everybody should know at least this level of knowledge and here.

And here's the reason why I say this. I just had I'm in the process of getting a new job. Okay. And I, I. L literally hundreds of screeners contacted me and it's just annoying. And I need to turn that crap off. But out of those hundreds of screeners people calling me, you know, really quickly, like it's like a quick interview, not even in interview.

It's like let's see if you qualify for this. Anyway. So out of those hundreds of screeners, I had five interviews. I had five interviews. Two out of those five, I have two that are potential one and one I'm act. I actually, they gave me an offer. They gave me a job offer. I said, yes. And now I'm going through the background process.

I say all this to say, going back to the cloud thing is that out of those five interviews, four of them ask me about cloud. And some of them went pretty deep on. and you gotta know cloud. So if, if you happen to be in an environment where you can learn more cloud stuff, learn it. Because I, I regretful my last job.

They were trying to force cloud down my throat and I didn't wanna do it. And I just kept dragging my feet about, and I wish back looking back. I wish I would've just done it. I wish I just would've at least taken this AWS cloud because they were asking me a lot of cloud questions. And I really didn't know.

I'm really, I really didn't know 'em you gotta learn cloud. So I would. And another thing about this AWS practitioner is that look at this it's a hundred dollars is 90 minutes. How hard does this? This can't be hard is 65 questions, multiple choice. I mean, Pearson peer view. It's this has gotta be easy. And I I'm gonna take this test, period.

I, they, they ask me way too many questions about it. It's getting way too ridiculous. I need to know more about cloud stuff. I need to be able to speak on it. And I was not able to do that. And so four interviewers asked me about freaking cloud stuff and I, and I'm like, damn, like I really should have, got more information on this.

I don't even do cloud. I'm doing information system, security officer type stuff. That's the jobs I was going for. And they keep asking me about cloud. I'm like, damn, like, can you ask me risk man, refr more questions? Like why what's cloud? Like, I mean, I have some exposure to it, you know, like Fedra and stuff like that.

But they were asking me like, like, how do you set it up and stuff? I'm like, what? what, what's the difference between a P a, a S and a and a S a, a S I'm like, oh my what? That kind of stuff. Basic really basic stuff, you know, cloud, but I didn't know it. So so yeah, check this one out. Somebody asked me, do you have a resume template?

I do. So if you go to my site I'm, I'm working on breaking down. if you I'm working on having like a complete breakdown of several different resumes and resume samples and stuff and ATS format, but it's gonna take me a while to do I gotta get off this call so I can go do it. But if you go to my site combo courses.com and you go to all courses, here's some of my stuff, books, new stuff that I put out free stuff.

What you're gonna do is you're gonna go to resume marketing. I have a course on resume marketing, the stuff that I'm writing in a book. I already have a course for it. And it works really, really good, but if you want the template, I'm making it free for now. Okay. So if you happen to be watching this, you are, you are in luck because I'm, I'm telling you free stuff.

That's out there right now that I'm probably gonna make. Not free. So if you go to this right here, just sign up is free. Okay. So number one, you can sign up right now and it's free to sign up. When you sign up for free, there's a ton of free stuff. You can download, you gotta go search for it. There's like, see this free preview stuff like that.

You gotta go through there and it'll have free stuff. This, this one has a downloadable for, for my resume has an actual down here it is right here. See this right here. I don't know if you, I don't know if you can see this. So all you have to do is, is if you sign up, you'll get that one for free. You'll get that one for free.

That's the template. Not always gonna be free. Some of the stuff I'm gonna I'm I'm gonna make it. I'm gonna make it paid, but for now it's free. So yes, the answer is yes, I do have a resume template. I'm gonna make a lot more. They're gonna be linked from the book a pipe. I don't know if I'll make 'em free or not.

I'm not sure. Probably, maybe initially, I, I don't know, but stay tuned for that, but in the meantime, there's an ATS style resume that's out there. And thanks a lot smooth virus for your testimonial. I appreciate that. Okay. That's it guys for this one. Thanks for watching a lot. I got 15 people watching me here.

I'm knowing how many people watching me on Facebook, but thanks for watching. Anyway, I'm gonna make this into a podcast. So stay tuned for that one. If you wanna listen to this again or whatever, it'll be out there. If you didn't know, I've got a podcast site it's on convo courses, dot pod bean been, I gotta get used to saying this combo courses.podbean.com.

Here it is right here. Here's everything. Here's all my podcasts. If you're interested in just listening, I got more coming out. I've been trying to crank these out every day. Not easy to do but here. Somebody said I'm sorry, can you show me where to navigate? Okay. Go to con courses.com. Convo courses.com.

courses.com. I'm go. I'm working on making this its own separate link, but for now I'm I gotta focus on writing this book. Okay. So go to all courses and then go to the course where I talk about marketing, cyber security marketing that breaks down what you do on a resume. And on here, I have a free resume.

If you sign, you can sign up for free. You can sign up for free. Okay. This says $145, but you can sign up for free, totally free. And then what you're gonna do is go, if you sign up for free tons of downloadable, see this one. See, this is free. You'll see this free stuff happen. I mean popping up if you go to resume here, that's where it is right there.

ATS resume sample. I've got a whole bunch of other stuff coming, but I'm just I'm right now, currently working on it. Like, obviously I'm, I'm in this live right now, so I can't do that while I'm in this live. So I really gotta let you guys go. Thanks a lot for watching. I appreciate everybody. Tony long time.

No, see I'm outta here guys. Thanks everybody for your questions. Thanks for.

View Details

check out: convocourses.com :

the cybersecurity jobs: resume marketing book is coming soon!

Hey guys, this is Bruce and welcome to another podcast of pot of convo courses, where I'm gonna be talking to you. How to get in cyber security and how to market yourself. If you're interested in getting into a career field, that's gonna grow in the next five years, probably double to what it is right now, where you have job security and I've, I've never had to worry about whether or not I'm gonna get a job.

If you are wanting more job security, then this is a great feel to get in. And you're talking to somebody who who's been doing this for 20 years, I'm speaking to you from inside the industry. All right. So if you have any questions on Facebook, on YouTube, on TikTok live on podcast, then this is a great question.

The time to ask any of your questions regarding it and cyber security. So let's keep it to that. I'm not interested in anything having to do. Anything except cyber security. So let's just keep it to cyber security questions. All right. That being said, let's get into this. If you didn't know, I am the owner and proprietor of combo courses.com.

It's a site where it teaches you how to do site, get into cybersecurity. And specifically my sub, where I'm the subject matter expert is something called security compliance, security compliance has to do with if you've ever gone to a bank, if you've ever used a retail, if you ever used a point of sale device, if you ever gotten a, a card from the DMV, like all of those things require something called.

security compliance that that's the rules and the regulations that go into an organization, cyber security. So not necessarily implementation of the cyber security, like firewalls or IPSS IDSS and all that kind of stuff. Not the technical implementation, but more like, how does this organization, whether it be a bank or your hospital, or your, or target or Walmart or whoever, how do they comply and keep security on their systems?

That's what I do. And that's what I teach people how to do. I've been doing this for a very long time, specifically for the government, the federal government, but I've also done it in the private sector and I've done it in for states. I've done it for a little bit for other countries when it pertained to the us.

So let's get into this. So we've got combo courses. I also wanted to tell you that I'm doing real steady podcasts on pod beam. If you're, if you wanna get some information on that just go to pod beam dot combo courses, dot pod beam.com. Enjoy me there. I'm doing lives every week. I'm putting out more content.

If, if if you prefer to listen to this, or if you're at your job and you wanna listen and learn and stuff, this is a great opportunity for you to do that. And I'm open to any kind of questions you have specifically to this to this genre, to this area of my area of expertise. And a lot of, one of the good things about this community is that if I don't know something, somebody in this community, isn't a subject matter expert on that thing.

And that's one of the things that I personally love about this community that we've been building. So let's get into this. I also wanna let you guys know, I have a book I'm gonna be breaking down and giving you a lot of the stuff that's in this book. Okay. So if you actually stay tuned for this, I'm gonna actually break down exactly how to mark yourself, how to get in this career path and how to level up if you happen to be an it person.

If you happen to be a, a cable jockey, a person who's laying cable for people doing internet stuff. If you happen to be in areas like healthcare, if you happen to be in stuff like banking, this is a really good opportunity for you to transition into a career field that pays better. That has more security and has a lot of opportunities for the next 20, 30 years to come because cyber security is not going anywhere.

Okay. And it's not all super technical. That's another MIS misconception about cyber security that I, that I like to dispel that myth. All right. So let's get into this. Let me show you guys what I've got going on. I've I'm writing a book right now that breaks down one of my main questions. So one of the main questions people ask me on TikTok on Facebook, on YouTube.

Everywhere is Bruce. How do I get into this career field? Like I've been trying for years, maybe I'm in it. Maybe I'm in the hospital. Maybe I'm I'm in healthcare, I'm in this other industry and I'm trying to get into break into cyber security. I'm trying to break into it. So what I'm doing, if I could actually switch this thing over, let me see.

So what I'm doing is a book where I'm gonna tell you how to get cyber security in it. This works also for any other career field as well, how to get into it. and how to market yourself in, in this field. This is something that I've been using for years. This is not something that this is not theory for me.

This is something I actually do in practice all the time. So it's gonna be a series where I'm gonna add lots and lots of value to you over the years as I released these books. But let me just get right into this. Okay. So here's the sections of the book. What I'm telling you is first of all, the expectations, what I've been able to do successfully, and then I break down all of the steps you're gonna take to actually put this stuff on your resume, particularly if you are in it, if you're in it, the good news is you can very quickly ramp up to cyber security by putting certain things in your resume.

So one of the things I talk about. How to do an ATS style, resume ATS style resume means applic application tracking software. This is what most employers are using these days. If you happen to be putting your resume out there and you're not getting any traction, then it might be because the resume style that you have is not correct.

And sometimes when you put your resume out there it's, if you make it harder on the employer to actually take your, the data in from your resume, you know, it's, they might look, look you over and look for somebody else. So I'm teaching you how to use in in fact, I'm just giving you a template. If you go to convo courses.com and look for my course, it actually has a free template you can download right now that has the template that I use.

That's been successful over over the years. But so that's what I do. I tell you, look, here are the tools that you need to set up for this. Here's the places we're gonna be posting this, this your resume. And one of the main key features that I. aside from the format and telling you how to do all that stuff is I actually show you how to do the keyword research.

How do you find what career path to do, cuz that's a really important thing. You need to know what path you're doing because here's the thing you can see. There's misspellings in this book. This is a first, this is a rough draft. Okay. what I do is I bang out the, I just write it as fast as I can. I take all the knowledge and I dump it into this book and then I go through it like two or three times and edit it myself.

Then I get it, give it to an editor. So that's why you're, you might see some misspellings. There's some errors in here. Just ignore that stuff. That's gonna be cleaned up. As I release this, it's gonna be released on Amazon, on my, on my personal site on, and then I I'm gonna advertise it everywhere. Anyway.

what I'm gonna show you, how to do is how to find a specific category of cyber security. Cuz this is one thing that some of the gurus out there and some of the subject matter experts and some of the pen testers and stuff, they don't talk about this. And one that's that this is a huge career field cyber security's huge.

So you don't have just pen tester. You would think that cybersecurity is just a bunch of people in a closet hacking stuff. And that is not a, could not be further from the truth. This is actually a huge career field and it's getting deeper and deeper. And just to give you an example, like in my book here, I'm, I'm breaking down some of the categories that's coming from the government, the government broke down this what they did was they had this initiative where they broke down all of the main career paths of cybersecurity.

It's called the national initiative. For cyber security, careers and studies. I know that's, that's a mouthful, but this is what they called it. Take that up, that issue up with the government of why they name stuff like this, but also known as nice, nice cyber cyber workforce. If you, if you Google that, you'll find this what I'm talking about right here.

So what I'm breaking doing is breaking this down in a practical way that you can use this. So it breaks down things like securely and provision. So what does that mean? That's like people who architect and design. Secure systems. And then you got overseeing govern. That's kind of what I do. That's making sure that the, the system is secure, making sure that we manage the security and manage the the risk associated with that system.

And it also goes into legal advice and then program management and all that kind of stuff. So as you, you could probably tell that that's not super technical or in the weeds or hands on type stuff. That's more like organizing, make sure the organization itself as a whole is doing what they're supposed to do.

So cyber security is a huge field. Another area that we talk about is the, the hacking and the defense and actual people who are on the system you know, on the actual firewall, doing the configuration, putting the rules in those guys do exist. You know, I'm not saying sitting here saying that they're irrelevant or they don't exist.

I'm saying this field is so huge that you've got people who are way in the weeds all the way down the mathematics. Right. Cause you've got people who do CR cyber they, they do cyber crime investigations, forensics. You also have people who are doing crypto cryptography. So that is also considered a part of cyber security by the way.

And this thing that breaks down all those different areas that you would find these different these different categories. And then it breaks it down even further into specializations. So what my book is doing is gonna do and what I'm gonna show you how to do like a practical way to do this for yourself right now is what they do is they break it all the way down to work roles.

And then once you figure out what work roles, the first thing you gotta do is figure out what part of cyber security you want go in. Cause it's not enough to say I want to go into cybersecurity. You gotta be like, I wanna go, I wanna be a pen tester. I wanna be, I wanna go into cryptography. I wanna go into forensics.

I want to go in. I wanna do what Bruce does. I wanna do information system, security officer work. I wanna do compliance. You gotta be down to that granularity. And the only way for you to get there is for you to do some study on your keyword. Right? So that's one of the things I break down in this book.

Now what I'm gonna do right now is show you exactly how I do this. So what I'm gonna do, like live right here right now. Let me just switch my screen here on TikTok. So what I'm gonna do right now is show you what I do. Okay. So there's three main sites in the us, okay. Three main sites. And, and this, this is different by the way, this is different for each country.

If you wanna work in another country, you have to find a whole nother set of a whole nother set of sites to go through in the us. There's a top 10 group of sites that work the best. And just off the top three is gonna be LinkedIn dice and monster. So those three sites are the best sites that you can go through, go to, but there's like 10 or 20 others that you should definitely apply to.

If you're trying to get a cyber security job, if you're trying to get really any job, cuz those are the top sites. Now, if you're in the nursing, if you are doing something completely different, like sanitation engineer, if you're doing something completely different, like civil engineering, there might be other sites and for your industry that are better for you, but you gotta do that research.

I'm talking about cyber security. I'm trying to get you prepped to get into this field in cyber security, by knowing not only the key words, but also the top sites. Now the top sites for that we're talking about is monster LinkedIn and dice. And you can actually, and indeed is another really good one, but these are the sites I'm gonna show you real quick.

So once you do your resume all, so once you, first of all, the first thing you need to do is figure out what keyword. Right. So let's say you did your research and you know, I want Bruce, I wanna go into forensics forensics. I'm gonna show you real quick, how you can find keywords for forensics. If you didn't, if you didn't know a lot about it, if you hadn't done research, if you're just starting out, you just go to the search engine and type in forensics.

Now this is a very broad field. Like forensics itself is super broad. If you ever watch that show CSI, I don't really talk about computers much. They talk about dead bodies and, and extracting the maggots from the bodies and stuff like that. I mean, that's kind of a crude thing, but that's exactly what the talk dog entomology and all that kind of stuff.

We're talking about computer science. So let's type in slip forensics computers. Now I happen to know that they call it digital forensics, but let's say you didn't know that. So you, I just typed in forensics and. See why? And it automatically came up with some keywords. This is how you do it. Now this works.

If you're doing, if you're doing this with cyber security analyst, if you're doing information security, officer information, system, security, period cloud security, anything you, any kind of subject matter, you wanna do this also works for any other field. You wanna be in you just type in a little bit.

And it starts to come up with some of the key words. So let's type, let's look at this one right here, computer forensics analysis. This is leading us down a rabbit hole of all the security keywords that we need for this particular career path. Now I'm gonna go ahead. I'm on monster.com, by the way. And now I'm searching for this career, but now where do we get the keyword?

Once these jobs come up, I'll show you. So, another thing to note is the salaries. Now, if you didn't know, this salary is for information security analyst and they don't always sell the name. You notice the names, none of these are saying forensics. That's because that's, that's how this works. Like if you go into whether you're doing cryptography, whether you're doing whatever, it doesn't always have the exact name of the title of the role, the work role that you want.

And that's why it's very important for you to do the research on your own to figure out what is in this career path. Okay. What are the key words? You can see a pattern already, information security analyst, information, security analysts cyber intrusion, detection, analysts. These are all analysts, right?

Let's look at this one. Cyber forensics analysts. So all of these jobs have analysts work in them. Okay. That's why it's all, these are coming up. The key words are gonna be in the responsibilities, the requirements and the skills, and sometimes they'll have, okay. Yeah. Desired certifications. Just off of this right here.

We can get the DNA. that's associated with this particular job role this work role, right? Just off of this one thing right here, we can, we can pull a lot of different gold out of this right here. Now let me, let me just show you what I'm talking about in the responsibilities. What you wanna do you wanna read like four or five of these to get an idea of what this job is all about?

First of all, cuz you might not even want to do it, right. You might have watched a CSI one too many times and you're like, oh, I wanna be a hacker. I wanna be, I wanna do forensic, like. It's the job is rarely what you think it is. You know what I mean? So you, you definitely wanna do your research and if you can talk to some, somebody like myself, who's been in this field for a while and ask their, ask them, like, how do you like it?

You've been doing this for 20 years. How do you like doing this job? Is this something that you think I should do? What are the pros and cons? Those are the kind of questions you really want to ask. Let's get back into keywords. So if we're looking at keywords here, I'm seeing a couple off the top of my dome right here.

If you see words like this, that you don't know what the hell it is, PCAP, that's a key right there. If you see there's a couple key tasks in here, stakeholders. There's a couple of key in here already, but you wanna read through responsibilities cuz you might, you might not even wanna do this job collects network, device, integrity, data and analyze signs of tampering and compromise.

Okay. So signs of tampering and compromise is one of the things you do as a. As a forensics guy. Now let's look at, let's get a little deeper into this desired skills. Look at this. Now this is a gold mine of all kinds of keyword. See all this stuff right there. These right here are tools. It says you need to be experienced and proficient with the following tools in case FTK sift.

These are all tools of the trade for a forensics guy. Very important. Like just like a plumber. Like if you are a plumber, there's certain tools that you need to know. Right? There's certain things that, that you basic things in that field that you need to know. If you don't know 'em you gotta get to know 'em right.

Especially if you're brand new at this, you gotta get to know what those things are. Now I'm talking to people who might have a little bit of it experience or something like that. For forensics, you, you probably have to know, at least the basics. In it very, very important. So now let's get back into this.

Let's get back into finding out key keyword here. So these are all key words right here. And now what you wanna do is take these. You got two things you can do from here. You could take this and put 'em into a copy of paste it into a, a blank text file. You can do that. Another thing you can do is put it into something called word art and word art.

What it'll do word word art does is it makes a visual representation of what of what you found. So let me just show you what that, what I'm talking about, that word, art.com and it's, it's just a tool to kind of help you to, to visualize what's going on. So here's word. All right here, you can create your own.

And it, it comes up with this site here and what you'll do is you'll input the words. You'll copy them and then import them in. So let's, let me just show you what I'm talking about. So we're gonna go to, I'm gonna go back here and I'm gonna copy and you wanna do this on two or three different jobs. I'm gonna copy this and we're gonna import what we just copied into word art.

We're gonna import it now. They, they take it right here. So I just copied it. Boom. I, I put it in here and I'm gonna import these words and now what it is, parsed out every word that's in the text that I just downloaded. So what I do, let me backtrack a little bit. So what I did was, what I'm doing is I'm going through two or three of these different websites, two or three of these different jobs, and I'm gonna copy and paste those into a one file.

One word document. Then I'm gonna take those and I'll put 'em into word art. And then we're gonna do get a visualization of what this looks like to see. What, what areas are the most important that we need to focus on tools. Look at this for so forensics, we can see that tools is mentioned a whole bunch of times out of this.

Now this is kind of a light list. Like it's only mentioned twice, but you wanna get like four or five different ones and dump 'em in there, but you kind of see the idea of what is happening here. And then the tools that are mentioned the most is in case now, in case it is a forensics tool, that's very expensive.

You might be able to get a free a free version of it, trial version to, to mess around with it. But this is not, this is not a cheap, this is one of the most expensive tools out there for forensics. So in case I'm very familiar with I'm familiar with that. It's used quite a bit in the government to.

What they'll do is if, if somebody's done a crime on a computer, I could tell you some crazy stuff for forensics that's happened is it's pretty dark. I mean, the stuff that they're, if you have a forensics guy in there, then whatever the hell's on my computer is pretty, it's pretty bad. Right? It's not something I could talk about without getting flagged by every, you can kind of come up with an idea of what it is, it's murder and it's, it's like stuff like that, right.

Or worse or worse, think of something worse than that. So, anyway, so that's, what's on people's computers. It's just bad, man. Anyway, so in case what it'll do, one of the things it does is it'll take a hard drive that people, somebody has tried to clean, that they try to delete stuff and in case can see all the stuff they.

The stuff's still on the computer after you delete it, by the way, even if you put it in the trash and then emptied the trash, it's still on the computer. And in case looks at the ones and zeros that were originally written on the disc, lifts those up, and then it can reconstruct those into files. Like if they had a image or a video or whatever, it can reconstruct those and give that to whoever's doing the investigation that they'll use for a court case or whatever.

FTC, I believe does the same thing. It's like an open source ver version of in case if I'm not mistaken. And then there's some other tools here, but yeah, this just gives you an idea of how you can pinpoint different keywords that are in any kind of genre and any kind of anything that you're trying to do.

So now that we know how to do keywords, the next thing we wanna do is put that in our resume. Now you don't wanna just put this in any resume. You wanna put it in a, at ATS style resume. Let me show you what I mean by that. So I have an example of that. In my book here. And I'm just gonna show you that real quick.

And if you want an example of this, there's a couple things you can do. You can go and Google how to find a ATS style, resume those exact words. Or you can go to my site combo courses.com and look for a cyber security marketing course. And that has a free downloadable of what I'm about to show you.

And it has the actual format that you can download it and use it for your own resume. ATS style resumes are so important because what the, and see I'm using word are here. I'm telling you how to do this. I'm walking you through it in this book. That's all the stuff that's gonna be in this book. That's coming here real soon.

So I'm looking for the actual resumes. It's I got a lot of stuff in here. It's breaking down everything, every aspect of what I'm telling you right now, but in greater detail I'm I skipped over a whole bunch of stuff that you should, that you should know. . So I'm trying to find my ATS style resume in here.

Man, where is it? Okay. ATS. It should be here. Okay. ATS style, resume all the sections. I'll give you an example of what that looks like. And then we go to there, here, here it is right here. All right. So here is example of a ATS style. Is this it? No, that's not it. Sorry about that. Yeah, this is it. This is it.

See how simple this is. This is an ATS style resume. It's very, very simple. It's it's not got a lot of stuff in it, so it'll have the person's name. It doesn't have any kind that's and fancy. It's nothing fancy going on with this. Now you can make a fancy ATS style resume, you know, and I'm, I'm not wasting my time with that for this.

I'm just telling you exactly how to do this. So you'll start off with the, the, a breakdown of what's going on a person, and then you'll put the your contact information and you'll put A breakdown of who you are. Another thing that I do in the summary by the way is I'll put, I'll put Hey, I wanna RO work remotely, cuz that's an opportunity for you to say that another thing you can do is say, Hey, I have a security clearance.

Like you wanna put the security clearance right up top, if you can. So you can put that in the summary. So you right here, you just put summary, this is ATS style resume. This is it right here. You put the name, you put the contact information. You put a summary, you put education up top, you know, in this style right here.

See how this is. And the reason why the format of this matters is because when your resume is when your resume is uploaded onto these sites, when if you put it on, indeed, that's another thing you need to do. You need to put it on. Indeed. You need to put it on monster dice. LinkedIn, you need to put it on as many sites.

If you don't have a job, your job should be to put this on as many resume as sites as possible. That's what you should be doing. Okay. Another thing I show you how to do is how to protect yourself because another one thing that's happening right now, lately is these freaking scammers are scamming people to get their social security number so they can do identity theft and all that kind of stuff.

So I've never felt fallen prey to that because the way that I do my resume, I don't put my real name. This is crazy. This is CRA I don't see anybody doing what I'm saying. I do not put my real name on the sites. Not I don't do that until I'm like on a screen, I'm talking to a screener, like maybe the second interview.

Then they know my real name. They do not know my real name till I'm on the second interview a lot of times. Right? Cause I'm screening them as they're screening me. Like I'm screening the organization. As I do not put my real phone number. I do not put my real, I might even put a different email address, like a fake throwaway email.

Like you can even do that. But I put a different name, an alias. I put an alias, something similar to my name, but it's not my actual name. I do not put my real phone number. I'll put like a, I'll use a Google voice. I tell you how to do all of this in this book. All right. All this is coming. Soon as I finish this, I've gotta do the first draft of this book.

You can see all kind of misspellings and stuff in here. I'll write the book really fast and then I'll go through it and then edit and stuff like that. So I just wanted to tell you guys, like, I just wanna inform you, this is how I do it. And it's been working for me. I've not been without a job. I mean, we've, you know, we've had several different collapses in the economy where we have recessions.

We've had like, that stuff does not affect me and I'm not trying. I mean, it affects me in like, okay, if I'm going to Walmart and the prices are higher or the gas is hot, jacked up or something. Yeah. That, that affects me obviously. But I'm talking about with a job. I'm good. Like I'm always employed. And the reason why is because I'm in cyber security, I'm one of the I'm in one of the fastest growing industries in the world.

And not only that, I stay ahead of the game by marketing myself. So I'm people are constantly contacting me about jobs and I'm not sent telling you this to two, my own horn. I'm telling you, you can do this two. You can do all the stuff I'm doing, too. Everything I just told you is what I do. Everything I just told you is what I do.

And that's how I'm able to stay ahead of the game. I put, I, I have a dope resume with all the keywords for the industry I'm searching for. It's all over my it's all over my resume. It's in the, it's in the it's in the, the summary it's in the, it's in the, the actions that I've done for an organization and my work experience.

It's in my skills. It's all throughout my resume. And then I put that out there. And here's another thing. If you are in it, If you are on a help desk, if you are laying cable for people, if you are in the hospital, if you are wherever you happen to be, if you've touched a computer before, okay, you have to put all the security stuff that you've done for that industry, you have to put all the stuff you've done, cuz that's really important.

A lot of times what people will do, whether what they won't do is they won't put the cybersecurity actions that they have taken and, and that's a, that's really bad. So that's another huge thing that you have to do. Okay. So let me keep going here. I'm gonna answer a few questions. I'm not gonna stay on here too long, but if you have any questions, feel free.

If you happen to be watching me feel free to ask me any questions that you have about getting in this industry about cybersecurity, about risk management framework, about security compliance, anything at all. I've been in this career field for a long time. I'm gonna tell you from the perspective of somebody who's been doing this for some time real world Examples, real world practical things that you can use to, to upload, to upgrade yourself.

All right. I'm answering some questions on YouTube as I do once a week. And if you didn't know, I'm all on TikTok, I'm, I'm answering questions there. Very one-on-one type questions. I'm answering questions on my email. I'm doing work for people like helping people with their resumes. I do all that kind of stuff.

If you're interested in that kind of thing, where I'm going way deeper and doing like a one on one, like just me and you corresponding, not like this kind of stuff you can text me at, you can email me at combo courses@contactcombocourses.com. Or you can go to con courses.com and find my contact information there.

I'm out there. Let me answer a couple of these questions. Somebody said, watch one of my videos and said, this is a gold mine. Wow. I appreciate that. Great compliment. This is when I was doing a video about help desk to cyber security and trying to helping people, helping people with that. Somebody said, how can I purchase this book?

Some old book that I wrote? If you didn't know, I've got some books out there on audio, on audible. So if you're interested in getting into, if you like, like listening to books, I listen to books quite a bit. And I just wanna tell you guys, I have a book out there. If you go to audible.com, if you happen to have it, if you don't have audible, actually you're in luck because they'll give you this.

They'll give you like a free trial. But you can go just type in R MF. ISSO. And these are two of the books that I have right now over over four hours worth of content to listen to, if you're interested in this. This will also help you with cap a little. If you happen to be doing a certification in cap, it'll help you a little bit in security plus, but it's like a small portion of security plus.

So it's not gonna help you that much, but cap, this helps you probably, this is 60% or more of the stuff that's on the test. It's not cater to you taking the test, but it will help you to understand like the practical implementation of risk management framework. So there's that if you're interested in listening to this, it's on audible, I'm also on Amazon, just type in, you can just type in Bruce Brown or you can type in NIST 800 control family.

My book is out there as well. And then you can also order it directly from me on combo courses.com. This is the site right here, tons of free stuff here, by the way. I, people are really upset about selling products and things, but a lot of the stuff that I have on here is actually free. And if you go to YouTube, if you follow me on YouTube, it's just so much free stuff on there.

Like a lot of the stuff I say on here, or that's on my website or that's in my books, it's there. You just gotta dig for it. You know, if you want a little bit deeper dive, then that's when you going to get the book or get the course itself. That's, you know, when you're serious about this, that's when you wanna start getting the book and, and getting in deeper in this and asking direct questions.

Okay. Somebody ask me if you want to be an ISSO, what certification do you need? That is a great question. Let me break this down to you. So if so, work is normally for the federal government and let me just put you on some game right here. So if so, work. The federal government goes by something called 81 40.

So 81 40 D O D 81 40 is a breakdown of what every contractor and government employee should have as far as certifications in order to get in this field faster. So what I'm doing right now is I'm actually showing you what 81 40 looks like, see this, what I'm like. And for those of you who are listening to me, I'll explain what you're seeing, what I'm, what we're seeing.

So this is 81 40 and essentially it's approved baseline of certifications. It changes from time to time lately, every about six months that've been updating this. So there's a couple things here that I'm, that I'm not seeing. That's been either removed or added. In fact, let me see if I can go to the newer version of this.

If you go to, oh, what is it? Dissa dot mill. Yeah. And you might see me. Okay, DISA dot mill. I think it is DISA dot mill, 81 40. They have the, one of the most up to date versions of this thing. I'm trying to look for 80. They used to call it eighty five seventy and it's a, it's all the approved certifications.

So if you go by this list right here that we're looking at, this is a list of approved baseline certifications. Let me explain what this what's going on with this thing. If you can see this, if you can, let me make it a little bit bigger here, but I'll also explain it. So they have, they have this broken up by technical and management architects, analysts, and auditors.

Okay. Those are the main categories. And let me just explain each one. So the the I a T means information assurance technical that just that's basic technical troubleshooting. It might be designing or configuring systems. These certifications are needed. If you're a level one, a level one is basically like a help desk person.

This is a person who has a, basically a one on one relationship to one customer at a time. They, somebody calls in and says, Hey, I have a trouble ticket. That means like something broken and they're, they're not connected to the internet. And they happen to be on the fourth floor. And then you, or you call 'em on online.

Maybe they're, you know, you're a remote worker or whatever, but this is a first line of defense for people fixing computers, help desk customer service, field technician, one, that kind of thing. They will. They're expecting you to have an, a plus certification as listed here, a CCNA security, which is, that's a very hard security.

That's a very hard certifi. I don't know why they put this here. I didn't make this. So keep that in mind. network plus C and D, which I don't even know what that is. S S C P one of those things. That's I a T level one. That's. And remember I a T level one is a help desk person. Now, if you happen to be upper level, like let's say, not only do you do help desk stuff, but you also do some networking stuff like you might have, you might be responsible for fixing the network on a whole floor.

This is like network engineers. This is like this is like people fixing a whole land, a local area network people who's responsible for a local area, a virtual local area network. So they're, they're kind of having to look at server issues as well as switching and networking problems locally, as well as like one on one customer support.

So what certifications does an I a T level two and information assurance, technical level two need so that's a CCNA security plus CSA plus a CI. So all of these things security plus is a big one. These, these are the ones that they're looking for. Okay. When we're gonna get to the information system security officer in a second here, I'm just building up here so you can kind of understand what's going on now.

I a T level three. So this is an enclave. Normally these guys are not only doing like one on they're kind of beyond the one on one type type of thing. Cuz their skill sets are so versatile that they're needed to do bigger things they're needed to do more like working with the architecture team, working directly with servers they're they're handling stuff.

That's like. Local area network to local area network. So these guys have professional level search. They're very, very in the weeds, but also high enough level to where they have to know, see the bigger picture of what's going on with the network. They're doing enclave to enclave. That's like one lo local area network to another local area network and possibly WANs, which is a wide area network.

And that's way more complex. So this is CCN P security. That's a very difficult certification, a professional level cer Cisco certification, a CSP, which is also a professional level cert that's no joke, a C S S P high level cyber security certification. And then some others G C I H, which is incident handling.

And I, they just added this one CCS P, which is, I think, a cloud, a cloud certification from ISE two squared. I think, I believe that's what it is. Okay. Now let's get into I ISO and the ISO, if you didn't know, is a information system security. So that is kind of what I do. And I can kind of give you in an, in a nutshell, like what an ISO, an information security person does.

So this job is typically your day looks like this. You're doing a lot of meetings. That's what your day looks like. It's a lot of meetings because you're, you're talking to other people within your organization, stakeholders, you're, you don't have to be a, a subject matter expert in say, firewalls, you don't have to be a subject matter expert in say networking or routers and stuff, but you do have to know enough to be dangerous.

Like you do have to know enough to communicate what is happening with the organization. Your responsibility, as an information system, security officer is to manage the risk is to help the organization to manage the risks of the organization so they can maintain their security posture. Now you might be like, Bruce, what the hell are you?

Are you talking about what are you? Let me spit it in layman's terms. That means. The, the organization has a certain level of security and they need to maintain that. And what does that mean? Like, think about it. Windows is constantly changing. It's constantly having upgrade to patches. There's constantly vulnerabilities coming out.

There's constantly new education that needs to happen with the users. There's all these new threats that are happening from day to day. Everything's constantly changing in it. Well, that's where an information system security officer comes in because our job is to make sure that no matter what changes happen, the organization stays compliant and stays secure at a certain level.

It's very challenging, especially if the organization has a lot of different technologies or also very large or organization with lots of stuff going on. So let's get back into what actual certifications does this information system security officer need. And I'm gonna show you here right now. So let's go back to the 81 40, so 81 40 up here is an is.

So is considered a, a manager type role. Okay. It's a manager type role because you're dealing with, you're not just doing in the weed stuff, fixing computers. You're not just working with firewall. They might have you do some stuff like that. But your time is mostly spent coordinating with the organization to make sure that the organization is doing what they're supposed to do.

I said organization. So you're, you're talking to C level execs. You're talking to upper level managers. You're talking to the, to the system, administrators, you're talking to users, you're talking to user reps. You might even be talking to the customer. So it's a lot of meeting. So if it's a manager type role, you gotta be able to communicate effectively.

So a cap, a cap is a, a certified authorization professional. So what they do is exactly what I'm talking about. They make sure that the organization can maintain a certain level of authorization so that the, so that all of their documentation is good, so that all the security compliance security controls on their system is good.

And let me break this down to you. So cap is a good one. Another one is CI while I'm topping here. Another one is a CI S S P CI SS P is a good one. Security plus is also a good one. Those three, I say, well, the top certifications that ISSO is typically typically has. Now this might evolve cap cap.

I notice comes up a lot. CS a comes up from time to time. But look at these, what I'm, what I just did was I logged into ISE two squared.org, and I'm showing you the different certifications now cap. This is the certified authorization certification. So security assessment and authorization certification.

So that's what it is. Certified authorization professional. That's what it's called. So this is one of the top. This specifically focuses on N 800. So N 800 is what the federal government and states and some other organization contracting organizations will use to ensure that you know what you're doing when you're talking about security.

For an organization. So these, let me just read a couple more here, a, a couple other ones that an ISSO is considered they're good for an ISSO is let me just name a few that I've seen in the industry, a cap, a cap, a C SM, a C S S P a G S GS, C L L C. And a recent add-on. These two right here is C, C I S O and a H C I S P P, which is normally for hospitals.

This is like HIPAA compliance and stuff that one's getting gaining ground right there. And this is listed on the dissa site. So this is that's a dot mill site. So that's, that's a big deal right there. So those are the main ones. I hope that answers your question. Let me keep going down questions. If you guys have any questions whatsoever, feel free to ask me, like, I've been doing this so long.

Just off the top of my head. I, I know this stuff. I've just been doing it so long. You know, I don't know if that's necessarily a good thing, cuz it's pretty much. All I know , you know what I mean? So let me see let me answer a couple questions here. Somebody said how do you get, how do you get this?

I'm looking for? Okay. What, what are you talking about here? A hundred. Oh, okay. I posted a job a job, a remote job where you're making a hundred K. And somebody says, how do you get this? I'm looking for this right now. I took a cyber security course, and now I'm studying for the interview questions.

I would like to know how you do this boss. Okay. So I do this, like in the beginning of this, of this session, I, I talked about it and I can just give you a brief rundown. The first thing I do is I make sure all the keywords are on my resume. So every, every category of cyber security. Has a different set of keywords.

For example, for example, at one time I was proficient at like two or three different parts of cyber security. I was, I was proficient. I'd done it before I'd had certifications, everything. Right. And those two were one, I was a seam engineer. That's a security information event manager, engineer. I could build them from scratch, set 'em up, create content for it.

And it could monitor all your logs. You know, I did that for like three years straight, so I just, I just knew it. And then another thing was, I was an information. I still am information system security officer. I know that means I like, I know how to allow an organization to be compliant with certain security standards.

And then another thing I was good at was cyber security analyst work. So those three things, those are three separate resumes. Okay. They have three separate keyword sets of keyword. . So what I did was I made a resume for each one of those. Each one has different certifications that are more relevant. I'd put those on top.

Each one has different. Some of 'em really require a security clearance. Like if so, and a cyber security analyst usually requires a security clearance, cuz you're working in like a, a, so a security operation center, which is, has classified information and blah, blah, blah. But the, the scene really didn't need a security clearance.

So I could even leave that off. And that was still good. My point is every single time you, whatever career path you're going in, it has this different set of, of keywords. And so what I do to make myself more marketable for this is I get keywords for each one of those work roles. Whatever it is. And to do that, you can, you can actually research it and figure it out.

Right? And I'm not telling you to lie on your resume. I don't recommend that a lot of people like lie on your resume. Why aren't you, why aren't you lying on your resume? Me personally, I say don't no, do not lie on your resume. Do not put your picture on your resume. Like put your picture on your, not resume, but, but unless you're on in, I guess EU does that, but put your picture on your profile.

Some people are like, nah, because I'm black. I don't want people to see that I can't get jobs. Nah. Why would you wanna work at an organization who doesn't want you? You need to put your picture there and if they don't wanna work with you, you shouldn't wanna work with them. That's how I feel about it. I don't wanna work somewhere.

They don't want me. So I put my black face on my profile. Go look at it. It's up there right now. So that's number one, like put your don't lie on your resume. The reason why I don't lie on my resume is because I don't want to get in there. And then they, I, they think I'm some, I'm freaking gonna walk on water and I don't not for that particular technology.

Not only that, but in the res in the actual interview, they will ask you these questions and then they will verify what you sold them. They will call your employer and ask, Hey, did Bruce do this X, Y, and Z. They'll do that. Especially as you go higher up in the echelons right now, if you wanna fudge some numbers of how long you work the place, and you know that it's not that big of a deal, but do not put certifications.

You don't have do not. Don't lie about your degree. They're gonna check that stuff, right? Don't like, this is some obvious things you shouldn't, you shouldn't lie about on your resume, cuz they will ask you I'm going through an interview process right now. You better believe they're investigating me.

They're looking at it. Every part of my life I'm having to put in there. Right? Because it, you can't, you can't just lie on your resume. So I don't recommend lying on your resume, put the real deal on your resume. But not only that put the key words for what you're doing on your resume. So that. when so that way, when you put the, when you upload this into LinkedIn into dice, into monster, and you need to put it on like 20 or 30 different job aggregators, okay.

You need to put on 20 or 30 different ones. And that's why I say you shouldn't use your real phone number or your real, you should use an alias because you're gonna get so many calls from all kinds of people and you don't wanna get scammed anyway. So that's what you do. That's what I do. And that's how I've been able to get all these offers for remote 100 K type jobs or more.

And, and that's how you do it. And I'm writing a book right now. If you're interested in this, if you're super deep into this, if you're very serious about this, I'm writing a book right now, it's gonna be out soon. And if you, if you, if you're interested in this, the very beginning of this podcast, I broke down exactly how, what I'm telling you.

I broke down. I showed you my like, how, how I picked these key out, how I find them. All that kind of stuff. If you're interested in this, a book is coming, that's gonna break all this down in great detail about how to get into cybersecurity in particular, but you can use these techniques for basically any, any job where you have to apply for a resume.

Any job you need a resume that you could use it for that. So let me see, I got a couple other questions that says on TikTok it says I just got a free ISO two course. And let me see. Cert is free when I'm done. Have you heard of this course? Yes, this is, this is great. Like thank you so much for asking that question.

So I've been, I've been telling everybody about this new certification that's coming out, like what's happening right now. If you guys didn't know, is that the government's hurting for cyber security positions, there's something. 700,000 careers that are empty slots. Like we in desperate need of, of people to get in here.

So what's happened is there's been this huge push from nonprofit organizations, corporations, and government entities to actually get people into this field as entry level. And so ISD two squared has this new certification. That's an entry level cybersecurity certification. And right now it's free. It will not be free forever because is ISD two squared.

I don't know if you knew this, but they don't, they don't mess. They don't mess around. They do not. These guys have the top cyber security certification in the world, arguably in the world's called C I S S P. I have this certification, this certification changed my life. It's a high level cyber security certification that talks about nothing and everything.

But it is so good at marketing me. Like, all I gotta do is put that on my resume. I could probably just have a blank page with just C I S S P on there, and I'd probably get hired. That's how powerful this resume. And it's the reason why this certification's so powerful is because they've done a great job of marketing it.

That being said, I'm saying this to tell you that they're now given this damn thing, this right here for free, this is an entry level for you to get into cyber security. This right, this right here, I'm showing you it's called certified in cyber security CC. Now, from here, you can build into other sec into other this is an entry level, but you can take this and build up to a higher level certification.

That's why this is so powerful. And these guys, this is not some fly by night, organiz. This is one of the top, if not the top and best cyber security certification organizations in the world on planet earth currently right now. So this is a great path. If you are actually looking into this, this is a great path for you to do, do this, doing it for free.

They're giving it away for free. This will not be free for long. I guarantee you because they're trying to compete directly with comp Tia security plus, that's what they're trying to do. And eventually this right here, this certification, I mark my words. This certification right here, this certified in cyber security will be on this sheet right here.

This is 81 40. This is 81 40. Also known as 85, 70 approved baseline for certifications. They will have CC on this. I bet you it'll be like right here. They'll put it right here alongside a plus certification, alongside C and D and all these other ones. And once this goes on here, It'll be way more marketable than it is right now.

Right now it's a free certifi it's it's brand new people don't really know about it. People are kind of figuring it out. Like they're kind trying to compete with this and the Google support it and the security plus, and those kind of certifications that are entry level because the government is making this huge push to get more and more people in this field.

This is a really, really exciting time to get into cyber security. This is, this is a rare opportunity where they're trying to open the doors, but you, this is not a field where you can just come in off the street and know nothing. You have to do some work. Like even if you come in and know nothing, you have to do work to understand the basics of information technology.

Right. That's all. I'm, that's what I'm saying. So this is a great opportunity. Let me see, I got a couple other questions that says, how does a civilian get a security clearance? Okay. So there's a couple ways. Just, just so you know, I've been doing this for some time and I've had security, all kinds of security clearances from public trust, all the way up to top secret type certification security clearances.

Another one misconception that you, that I wanna dispel is that you don't need a security clearance to get into cyber security. They're two separate things. Okay. A security clearance is just verifying that you are, are who you say you are. They're VE they're doing a, a, anywhere from a basic security background check to make sure you're not that you are trustworthy to work in their organization with secret information.

They're making sure you're not linked to any kind of terrorist organization or insurgents or militia organizations. You'd be surprised. You'd be surprised how many people are associated with it. because every time they ask me, I'm like, ha ha. That's ridiculous. I'm not, but no, there's really a lot of people who are associated with these organizations that wanna take down the government that don't feel like they have some kind of issues with the United States government, or they're tied to another government.

They actually happen to be working for another government. And they're trying to get in and infiltrate. You'd be surprised how many people this, this applies to anyway. So background check is just trying to see if you are who you say you are. If you don't have, make sure you don't have any crazy credit issues, that's gonna affect you to work on their job, making sure you're not like a, your a super predators killing people or something like that.

Yeah, they're trying to just do that. That's separate from cyber security. Okay. Cyber, a lot of cyber security jobs need a security background check. Because the nature of the information that you're gonna be having access to, and they wanna make sure that they can trust you to protect their systems, but they not, every, not every job requires a security background check.

Okay. Cyber security is their separate things. You can be a janitor and need a security clearance. Okay. So the question was, how does a civilian get a security clearance? There's a couple ways. Number one, work for an organization who will get you a security clearance. If you happen to work in the DMV area that's DC, Virginia, Maryland area.

There's so many jobs, not just cyber security you might have be a groundskeeper and mowing grass and have to have a clearance, some dead serious. You might be painting the inside walls of a, a skiff that need you need a clear. You might, there's all kind of clerical jobs secretarial jobs name something, janitors anything like can get you.

So you would, one way that you could get in is if you had a job, if you got a job at a place that required a clearance, a lot of times they will pay for you to get a clearance. They will pay for you to get the clearance because it costs money to get a clearance. Another thing is you can there's sites.

Somebody contacted me the other day. They were trying to get me a clearance. Like they didn't, they didn't know. I guess they would contact me and saying, Hey, we can get you a clearance and stuff. So there's, there's private organizations that can get you a clearance, but you're gonna have to pay for it.

It's not cheap. Just to give you an example, from what I heard a security, a secret background check is like $5,000. And then a Ts is like $10,000. That's what an organization has to pay to get you a clearance. And then a public trust. I don't know, public trust is like here. Secret clearance is here and then above that is top secret and all other white house, all this other stuff.

So, yeah, so you can, you can get into a position, a job that requires it and then they'll let the organization pay for it. That's probably the best way. The other way is to get it privately and pay for it yourself. That's another way. But then it has to remain active. I don't know how all that stuff works, but so those are the two ways that I personally know about how to do it.

So, and I could be wrong. Anybody else you guys know of another way to do it, please chime in and, and, and inform me what's going on. Let me see here. Somebody ask hope that ask your, answer your question, by the way. Somebody ask so I just signed up and I have to take an exam. Yes. So, so I believe that that, that I C two squared, they have a, they have a course.

All right. And I believe the course is free. If it's still free, they have a course that you can take that breaks down. What's gonna be on the test. And then you, you, you go to that course, you study for it. If it's still free, hopefully still free it. They were saying it was a value of one ninety nine, a hundred ninety $9.

But even if it costs $199, it's worth you investing in yourself. It's, it's, it's worth the risk. It's worth the risk. Anyway, if it's still free, cuz just last week, it was free. You take the, you go through the course that I believe is on course. Sarah it's either on course, Sarah or it's on their website.

Okay. Sign up for their website. They'll give you a breakdown of everything you need to do. And then from there you will take the test. Like once you study for it, you take the test. Somebody. no they're paying for it once you finish the course. There you go. Okay. Thank you for that. ODI says no, they're gonna pay for it once you take the course and there's only 1 million openings.

Okay. There you go. Okay. I stand corrected. So let me, let me correct myself. So what he's saying is once you, it was free for a while. It was, it has actually free like a, like a week ago or something I'm telling you. So now you're gonna have to take the, the, the course, and then once you take the course, I think was 1 99, then you you'll take the test, pass it, get your certification.

So let me see. You have to take a test. Yes. It's this is, yeah. There's there's hurdles. You have to take the test to get the certification, but it's worth your inve. If you are serious about this, it's worth your time. Okay. Let me see. I got a couple other questions. Somebody said I barely see a hundred percent remote opportunities.

Most people keep wanting people to be on site. That's true. And bro branding, I, I would add to that and say a lot of the security clearance, a lot of the cyber security jobs that require security clearances do require you to be on site at least like a hybrid on site. But I would say that there's a lot more remote jobs opportunities than than there were before.

COVID cuz it was, it used to be really hard to find them. Now they're everywhere and I could show you how to find them real quick. I'll show you let see if I could show you on LinkedIn, if you guys didn't know, I have a LinkedIn page you can search me out on Bruce Brown for the win. Let me show you on.

If you guys happen to be on LinkedIn here, here I am right here. If you type in Bruce, go to LinkedIn and type in Bruce. CIS S P RMF or something like that. You'll find me there. It is right there. There I am right there. And so join me. I'll definitely add you. I've got a, a lot of people wanting to add and I'm, I'm always open to, to add people or you can talk to me online, all that kind of stuff, but okay.

Let me show you how to find remote jobs. Okay. Let me see. Let's let's say you were looking for a cyber security analyst job, right? Cyber I'm just, just randomly pick one off out the air. So now check this out. First. You'll go jobs. And the reason why you wanna check pick jobs is because there it's gonna show you everything.

It's gonna show you companies, posts, schools, groups, people, all that you want jobs. Okay. So search jobs, then post a date. You don't want any time, cuz this goes back like a year or something. You want something within the, at least the last month. all right, so let's look for last month and then this one's up to you, they got internships, entry level, associate senior manager, whatever.

Right? You ch choose that. But if you don't really care, leave that blank and then remote, let's go to remote job. So here it is right here. You're gonna onsite versus remote. So you've got hybrid, you got remote and you got onsite. You just click on site. Now you notice it went from 17 K jobs down to three K jobs.

I'm on LinkedIn, by the way. So I just went to jobs stuff in the past month. And then I went to remote on site. This is a new feature, by the way, they didn't have, it needs to have all of this stuff. And now they have it on dice. They have it on monster. They have it on almost every site because remote jobs are so prevalent now after COVID.

So here you go. Here are some remote jobs for cyber security analysts, which I just typed in. And that's how you find remote jobs right there in five minutes. I just showed you how to do it. and you can do this with every site, with monster, with LinkedIn, with with da, with, with dice, all of these show you how to do remote jobs.

And if you go to dice, let me see if this one's ready. So here's, here's my profile on dice.com. I'm about to turn this thing off, man. I'm getting so many contacts with these guys, so there's a way to search for remote jobs. Let me just show you here. Let me I'll do the same thing. Cyber security. I'll just type in cyber security.

I didn't put a location in I'll hit search and check this out. It comes out with this page right here, taking a little bit of time and then look right at the top. Remote only if I hit remote only you notice it went down from 4,800 jobs to 600 jobs. So, yeah, there are less Brandon to, I, I could piggyback on what you're saying.

There are quite a bit less, but there are jobs there. I mean, look at this there's 600 jobs here. I mean, granted, I didn't search for, I said any dates, so that's, that's probably, what's adding to that. Let's do the last seven days. It's gonna be quite a few less. Oh, still 126 jobs. Look at that. These are all remote jobs.

And all I did was type in cybersecurity, look, 100% remote cyber security analyst, all of these are a hundred percent remote. Now you gotta double check. Cuz one of the things I noticed about these jobs is sometimes they'll say they're a hundred percent remote, but then when you do a, an interview with 'em, they're like, well, well it's a hundred percent, but we want you to come into the, I was like, Is this a hundred percent or not?

yeah. You gotta do an interview with 'em to make sure and ask them, is this a hundred percent remote? You know what I mean? Like you usually straighten that out with the, with the actual screener, once you, once you talk to them, ask them, and then sometimes it's, it is remote, but it's like 50% travel or something.

Like there's always some kind of catch sometimes with the judge. You just gotta make sure you, you weed out those gotchas with the remote jobs. I just went through this. That's why I know a lot about it. You know, , I've been, do working remotely for the past seven years now. Like I've been working remotely for a long time.

Crazy. It's crazy to me. Like I've been working. Yes. Seth's been seven years. I started in 2014 working remotely and I've been working remotely ever since. And I will never go back. I will never go back. all right. And that being said, if you guys are interested, I have a course on how to work remotely.

It's on combo courses. Go check it out on combo courses dot com, just work, find the remote jobs course. And then I have it out there and I I'm, I might even write a book about that one and break it down. So it's like a 20, $20 book or something like that. I might, I might do that cuz I I've gotten pretty good at getting remote jobs and winning those remote job positions.

Okay. Let me see link to the course. I'm assuming you're talking about the C the CC let me see if you're interested in this. We were just talking about this, this course right here, which is an entry level ISC two squared course, which they're given. I believe you have to pay for their training and then thinks 200 bucks for the training.

Now it was free like last week, unfortunately, no longer free. And then after. That you take the, the test and I think they give you the test for free. If I'm not mistaken, correct me if I'm wrong, TikTok somebody on TikTok, correct me on that one. I appreciate that. But yeah, here's the link right here. It's ISC two dot org slash configuration certifications and four slash CC.

Or you can go to Google and just type in ISE two square ISE, two space CC, and you'll find it. Let me see if I can give you the link in the chat. I, I don't have access to the chat right now. Yeah, and I always walk me through all this other stuff I gotta do to get link access to that. All right, guys, that's it for this one.

Thank you for watching. I really appreciate all the questions. Thanks a lot for, for all your kind words and stuff and all the donations. Appreciate that. Thank you so much. I've got a couple other questions on, on TikTok. Let me see if I can answer those real quick. Yes, it's still a self-paced exam.

Okay. We're still talking about the I C two CC. So I can get an entry level job with a CI S S P certification. Can you get a, okay. So with the CI SS P it requires like five years of experience. So somebody's either got a vouch for you having five years of experience, or so you're typically, if you have a C I S P you don't have, you're not an entry level person.

Now, if you happen to get, I think you can sit for the test, but you, they won't give you the cert until you hit all of these different requirements, but by the time you hit those requirements, you no longer entry level, if that makes any sense. So I don't know if I answer your question. Let me see. You said so I can get an entry level job with a C S S P cert.

You, once you have a C S P you don't have to get an entry level. You're not an, you're not an entry level person. If you have a CI S S P. So, so the, the certification we were talking about is called a, an ISC two. Let me just show you what we were talking about. We're not talking about CI SS P we're talking about a certified in cybersecurity certification.

That's from ISC two squared. It's this one right here. If this is an entry level certification, you don't need any requirements. Before you go into this. If you're talking about something like a CI S S P there's actual requirements, before you can even take the test before you even take the test. And even if they allow you to sit for the test, you have, somebody has to vouch for you that you have a certain level of experience before they'll give you the certification, something to that effect.

Okay. Let me see. Hey, Bruce, where would you start? If you had to start all over again, without any knowledge of cyber, I would start with cloud. or right now cloud's super hot, man. So I would, what I would do right now. If I was starting from scratch. That's a great question. I would, number one, I'd go to eight.

I'd go to, okay. There's a couple shirts I would get with no experience, know nothing starting from scratch. Knowing what I know now I would start with the AWS cloud certification, that one. And then there's no one from Google called Google, Google. Its, let me see if I can, let me just show you. I don't, I don't wanna be a liar here.

One, the one is called and let me, I'll explain to you why I would get these and you it'll blow your mind and you'll you'll follow exactly what I'm saying. It will blow your mind. So there's one called AWS certifications. If you wanna follow along with me, let me just show you what I'm saying. What I'm seeing right here.

Oh, wait we go back. Okay. There we go. Okay. So AWS certifications. I just typed it in. And skip all the ads, skip all the ads. We wanna go directly to amazon.com site. Okay. So I would take this right here. See this AWS certification so you can train on their site. I believe their training is free and he, they even have a whole path for you.

This one right here, this cloud practitioner is the one I would take. And the reason why I would take look at this it's 90 minutes long, it only costs a hundred dollars. I could take this right now. I could, I could literally I'm thinking about it. Actually. I'm gonna take this test. The reason why I would take this one, one of the first ones I would take is because in the last I just had five different interviews.

All right. I'm not even count counting the, the the screening interviews I had. I like probably 20 screening interviews or more, but I had about five interviews in, in four. Out of the five interviews. They all ask me about cloud. Now I'm an old head cloud is actually new for me. I have not dive dove into it.

I have a little bit of exposure to it, but not a lot. Right. I don't, I know some of the difference between a P a a S an versus a S a a S versus a I a, a S like, if you know what I'm talking about here, like different platforms of cloud, like platform. Cloud as a service versus software as a service versus whatever, as a service, like everything as a service planet earth, as a service, whatever the hell there, the terminologies, I'm an old head.

Like I, this is new to this crap is new to me right now. Virtualization's not new to me. That's been around, but cloud this and cloud that like everything's going to cloud. And the biggest cloud service right now is a Ws. They always ask me about that. And I had to be like, mm, I, that's not my, you know, but I can tell you this.

Here's what I know. You know, they all ask me about it. So if I was starting from scratch, I dos, if I really didn't know anything, nothing at all. And I was like a, like, starting from absolute scratch. I'll probably take the same one I did when I first started, which was a plus certification. Like if you know absolutely nothing about it, then probably the best thing to take would be an a plus certification, cuz that will get you.

At least knowledgeable on, on how computers work, cuz you really need to know, you need to know like the difference between Ram storage and and the CPU you need to know, kind of have an idea of how CPU work. You don't have to know like how the addresses are mathematically algorithm, the mathematical algorithm of how the CPU, you know, moves pixels from this side of the screen to another.

Like it's not even that deep, like it's just telling you, this is how the Ram works physical memory. Here's how it works with the storage versus the CPU. Here's how they all work to make a computer. You need to know what a computer is, how they work, how to troubleshoot 'em so a plus comp Tia, a plus certification.

One of the first ones I would take if I knew absolutely nothing, cuz that will give you after you take that certification, there's two different ones that you have to take in order to get the a plus once you know that you'd be able to troubleshoot computer, any computer, like you'd be able to troubleshoot.

A laptop, a server, your phone, they're all computers. They all use the same components essentially and different configurations. And then you'll have a solid understanding of how cloud works because it's also a computer. It's also a, it's a bunch of computers that are somewhere else over the internet.

That's, that's pretty much it. And then I would take that one and then another one that's pretty hot is Google support it. I would take that one. I would take a comp a plus. I'd learn everything I need to know about that one, take the test, pass it. I would learn. I would do Google support it. The basic one that they have out there, they got like two, I'd do the basic one.

And then I would do cloud AWS cloud practitioner. That's what I would do. And then after that, I, I put my resume out there and then I, I try to get some, I would do either internship or I'd do a a entry level. I do entry level making 15 bucks an hour to get my foot in the door to, and then I'd work there for like six months.

And then I would transition to another organization. That's what I would do. And then I would, I would take my, my experience from that place. I worked six months and then I would go work at another place and then ask for more money. That's what I would, that's what I would do. Another thing. This one dude on TikTok blew my mind.

So this dude had a brilliant strategy. And if you have the money to do this, this is the most brilliant strategy you could do. If you have the resources to do it. Now, this guy did, but he, he went to this college called. Oh, GWS governors, Western governors, university or somethings. So legitimate college, like the government when I was in the military, they were promoting it a lot.

GWS college college. Let me Western governors. G w G U. That's what it's called. So this, this, this dude, his name is Chris. He's one of the top cyber security guys out there. He went here to this college right here. He took a course in cyber security. I guess they have one here. He did it in six months.

It's not gonna be cheap. He did didn't undergraduate in, I think, six months then what he did WGU that's right. Then what he did, this is brilliant. So if you have the money to do this, this is, this will get you six figures super fast. He took this right. It took six months. It's not cheap. . Yeah. I mean, you know, relatively speaking, it's not cheap.

This is, this is not bad for a college, to be hoNIST with you. So he got an undergraduate in six months, accelerated course in it. Well, he did one of these and then I believe he took the it certification with it. One at, I, I believe he took one of these. If I'm not mistaken he took one of these, see this cloud one would be dope right here.

Look at all these certifications, you could take one of these certifications with it. That's what I would do. And then after you'd come out with a bachelor's degree or even a master's degree with one of these cloud certifications, and then you can, you can possibly make six figures after that. That's in that's within a year within one year.

I think what he did was he did something called the OS. C O S C P, which is super hard certification. I think he did this one right here. I believe he did something like this. And then he was able to get a six figures within a year, which is very impressive. And then he also took this dude. He's pretty impressive.

I mean, this, like, this's some people who are this hardcore and this talented to do this. I don't think this is for everybody, but he took this certification called O S C P penetration test. It's one of the, I heard it's a pretty hard test, but it's from offensive security and it's a practical test where you have to hack live for 24 hours or something.

And you got this certification. Look at this, look at this course, $1,400. So for all you guys complaining about my course being 200 damn dollars. Look, look at this, look at this Fe your eyes on this. This is how much a course costs baby. don't complain about no $200 to me. This is how much they cost right here.

All right guys, I'm out.

View Details

check out: convocourses.com :

the cybersecurity jobs: resume marketing book is coming soon!

Hey guys, this is Bruce and welcome to another podcast of pot of convo courses, where I'm gonna be talking to you. How to get in cyber security and how to market yourself. If you're interested in getting into a career field, that's gonna grow in the next five years, probably double to what it is right now, where you have job security and I've, I've never had to worry about whether or not I'm gonna get a job.

If you are wanting more job security, then this is a great feel to get in. And you're talking to somebody who who's been doing this for 20 years, I'm speaking to you from inside the industry. All right. So if you have any questions on Facebook, on YouTube, on TikTok live on podcast, then this is a great question.

The time to ask any of your questions regarding it and cyber security. So let's keep it to that. I'm not interested in anything having to do. Anything except cyber security. So let's just keep it to cyber security questions. All right. That being said, let's get into this. If you didn't know, I am the owner and proprietor of combo courses.com.

It's a site where it teaches you how to do site, get into cybersecurity. And specifically my sub, where I'm the subject matter expert is something called security compliance, security compliance has to do with if you've ever gone to a bank, if you've ever used a retail, if you ever used a point of sale device, if you ever gotten a, a card from the DMV, like all of those things require something called.

security compliance that that's the rules and the regulations that go into an organization, cyber security. So not necessarily implementation of the cyber security, like firewalls or IPSS IDSS and all that kind of stuff. Not the technical implementation, but more like, how does this organization, whether it be a bank or your hospital, or your, or target or Walmart or whoever, how do they comply and keep security on their systems?

That's what I do. And that's what I teach people how to do. I've been doing this for a very long time, specifically for the government, the federal government, but I've also done it in the private sector and I've done it in for states. I've done it for a little bit for other countries when it pertained to the us.

So let's get into this. So we've got combo courses. I also wanted to tell you that I'm doing real steady podcasts on pod beam. If you're, if you wanna get some information on that just go to pod beam dot combo courses, dot pod beam.com. Enjoy me there. I'm doing lives every week. I'm putting out more content.

If, if if you prefer to listen to this, or if you're at your job and you wanna listen and learn and stuff, this is a great opportunity for you to do that. And I'm open to any kind of questions you have specifically to this to this genre, to this area of my area of expertise. And a lot of, one of the good things about this community is that if I don't know something, somebody in this community, isn't a subject matter expert on that thing.

And that's one of the things that I personally love about this community that we've been building. So let's get into this. I also wanna let you guys know, I have a book I'm gonna be breaking down and giving you a lot of the stuff that's in this book. Okay. So if you actually stay tuned for this, I'm gonna actually break down exactly how to mark yourself, how to get in this career path and how to level up if you happen to be an it person.

If you happen to be a, a cable jockey, a person who's laying cable for people doing internet stuff. If you happen to be in areas like healthcare, if you happen to be in stuff like banking, this is a really good opportunity for you to transition into a career field that pays better. That has more security and has a lot of opportunities for the next 20, 30 years to come because cyber security is not going anywhere.

Okay. And it's not all super technical. That's another MIS misconception about cyber security that I, that I like to dispel that myth. All right. So let's get into this. Let me show you guys what I've got going on. I've I'm writing a book right now that breaks down one of my main questions. So one of the main questions people ask me on TikTok on Facebook, on YouTube.

Everywhere is Bruce. How do I get into this career field? Like I've been trying for years, maybe I'm in it. Maybe I'm in the hospital. Maybe I'm I'm in healthcare, I'm in this other industry and I'm trying to get into break into cyber security. I'm trying to break into it. So what I'm doing, if I could actually switch this thing over, let me see.

So what I'm doing is a book where I'm gonna tell you how to get cyber security in it. This works also for any other career field as well, how to get into it. and how to market yourself in, in this field. This is something that I've been using for years. This is not something that this is not theory for me.

This is something I actually do in practice all the time. So it's gonna be a series where I'm gonna add lots and lots of value to you over the years as I released these books. But let me just get right into this. Okay. So here's the sections of the book. What I'm telling you is first of all, the expectations, what I've been able to do successfully, and then I break down all of the steps you're gonna take to actually put this stuff on your resume, particularly if you are in it, if you're in it, the good news is you can very quickly ramp up to cyber security by putting certain things in your resume.

So one of the things I talk about. How to do an ATS style, resume ATS style resume means applic application tracking software. This is what most employers are using these days. If you happen to be putting your resume out there and you're not getting any traction, then it might be because the resume style that you have is not correct.

And sometimes when you put your resume out there it's, if you make it harder on the employer to actually take your, the data in from your resume, you know, it's, they might look, look you over and look for somebody else. So I'm teaching you how to use in in fact, I'm just giving you a template. If you go to convo courses.com and look for my course, it actually has a free template you can download right now that has the template that I use.

That's been successful over over the years. But so that's what I do. I tell you, look, here are the tools that you need to set up for this. Here's the places we're gonna be posting this, this your resume. And one of the main key features that I. aside from the format and telling you how to do all that stuff is I actually show you how to do the keyword research.

How do you find what career path to do, cuz that's a really important thing. You need to know what path you're doing because here's the thing you can see. There's misspellings in this book. This is a first, this is a rough draft. Okay. what I do is I bang out the, I just write it as fast as I can. I take all the knowledge and I dump it into this book and then I go through it like two or three times and edit it myself.

Then I get it, give it to an editor. So that's why you're, you might see some misspellings. There's some errors in here. Just ignore that stuff. That's gonna be cleaned up. As I release this, it's gonna be released on Amazon, on my, on my personal site on, and then I I'm gonna advertise it everywhere. Anyway.

what I'm gonna show you, how to do is how to find a specific category of cyber security. Cuz this is one thing that some of the gurus out there and some of the subject matter experts and some of the pen testers and stuff, they don't talk about this. And one that's that this is a huge career field cyber security's huge.

So you don't have just pen tester. You would think that cybersecurity is just a bunch of people in a closet hacking stuff. And that is not a, could not be further from the truth. This is actually a huge career field and it's getting deeper and deeper. And just to give you an example, like in my book here, I'm, I'm breaking down some of the categories that's coming from the government, the government broke down this what they did was they had this initiative where they broke down all of the main career paths of cybersecurity.

It's called the national initiative. For cyber security, careers and studies. I know that's, that's a mouthful, but this is what they called it. Take that up, that issue up with the government of why they name stuff like this, but also known as nice, nice cyber cyber workforce. If you, if you Google that, you'll find this what I'm talking about right here.

So what I'm breaking doing is breaking this down in a practical way that you can use this. So it breaks down things like securely and provision. So what does that mean? That's like people who architect and design. Secure systems. And then you got overseeing govern. That's kind of what I do. That's making sure that the, the system is secure, making sure that we manage the security and manage the the risk associated with that system.

And it also goes into legal advice and then program management and all that kind of stuff. So as you, you could probably tell that that's not super technical or in the weeds or hands on type stuff. That's more like organizing, make sure the organization itself as a whole is doing what they're supposed to do.

So cyber security is a huge field. Another area that we talk about is the, the hacking and the defense and actual people who are on the system you know, on the actual firewall, doing the configuration, putting the rules in those guys do exist. You know, I'm not saying sitting here saying that they're irrelevant or they don't exist.

I'm saying this field is so huge that you've got people who are way in the weeds all the way down the mathematics. Right. Cause you've got people who do CR cyber they, they do cyber crime investigations, forensics. You also have people who are doing crypto cryptography. So that is also considered a part of cyber security by the way.

And this thing that breaks down all those different areas that you would find these different these different categories. And then it breaks it down even further into specializations. So what my book is doing is gonna do and what I'm gonna show you how to do like a practical way to do this for yourself right now is what they do is they break it all the way down to work roles.

And then once you figure out what work roles, the first thing you gotta do is figure out what part of cyber security you want go in. Cause it's not enough to say I want to go into cybersecurity. You gotta be like, I wanna go, I wanna be a pen tester. I wanna be, I wanna go into cryptography. I wanna go into forensics.

I want to go in. I wanna do what Bruce does. I wanna do information system, security officer work. I wanna do compliance. You gotta be down to that granularity. And the only way for you to get there is for you to do some study on your keyword. Right? So that's one of the things I break down in this book.

Now what I'm gonna do right now is show you exactly how I do this. So what I'm gonna do, like live right here right now. Let me just switch my screen here on TikTok. So what I'm gonna do right now is show you what I do. Okay. So there's three main sites in the us, okay. Three main sites. And, and this, this is different by the way, this is different for each country.

If you wanna work in another country, you have to find a whole nother set of a whole nother set of sites to go through in the us. There's a top 10 group of sites that work the best. And just off the top three is gonna be LinkedIn dice and monster. So those three sites are the best sites that you can go through, go to, but there's like 10 or 20 others that you should definitely apply to.

If you're trying to get a cyber security job, if you're trying to get really any job, cuz those are the top sites. Now, if you're in the nursing, if you are doing something completely different, like sanitation engineer, if you're doing something completely different, like civil engineering, there might be other sites and for your industry that are better for you, but you gotta do that research.

I'm talking about cyber security. I'm trying to get you prepped to get into this field in cyber security, by knowing not only the key words, but also the top sites. Now the top sites for that we're talking about is monster LinkedIn and dice. And you can actually, and indeed is another really good one, but these are the sites I'm gonna show you real quick.

So once you do your resume all, so once you, first of all, the first thing you need to do is figure out what keyword. Right. So let's say you did your research and you know, I want Bruce, I wanna go into forensics forensics. I'm gonna show you real quick, how you can find keywords for forensics. If you didn't, if you didn't know a lot about it, if you hadn't done research, if you're just starting out, you just go to the search engine and type in forensics.

Now this is a very broad field. Like forensics itself is super broad. If you ever watch that show CSI, I don't really talk about computers much. They talk about dead bodies and, and extracting the maggots from the bodies and stuff like that. I mean, that's kind of a crude thing, but that's exactly what the talk dog entomology and all that kind of stuff.

We're talking about computer science. So let's type in slip forensics computers. Now I happen to know that they call it digital forensics, but let's say you didn't know that. So you, I just typed in forensics and. See why? And it automatically came up with some keywords. This is how you do it. Now this works.

If you're doing, if you're doing this with cyber security analyst, if you're doing information security, officer information, system, security, period cloud security, anything you, any kind of subject matter, you wanna do this also works for any other field. You wanna be in you just type in a little bit.

And it starts to come up with some of the key words. So let's type, let's look at this one right here, computer forensics analysis. This is leading us down a rabbit hole of all the security keywords that we need for this particular career path. Now I'm gonna go ahead. I'm on monster.com, by the way. And now I'm searching for this career, but now where do we get the keyword?

Once these jobs come up, I'll show you. So, another thing to note is the salaries. Now, if you didn't know, this salary is for information security analyst and they don't always sell the name. You notice the names, none of these are saying forensics. That's because that's, that's how this works. Like if you go into whether you're doing cryptography, whether you're doing whatever, it doesn't always have the exact name of the title of the role, the work role that you want.

And that's why it's very important for you to do the research on your own to figure out what is in this career path. Okay. What are the key words? You can see a pattern already, information security analyst, information, security analysts cyber intrusion, detection, analysts. These are all analysts, right?

Let's look at this one. Cyber forensics analysts. So all of these jobs have analysts work in them. Okay. That's why it's all, these are coming up. The key words are gonna be in the responsibilities, the requirements and the skills, and sometimes they'll have, okay. Yeah. Desired certifications. Just off of this right here.

We can get the DNA. that's associated with this particular job role this work role, right? Just off of this one thing right here, we can, we can pull a lot of different gold out of this right here. Now let me, let me just show you what I'm talking about in the responsibilities. What you wanna do you wanna read like four or five of these to get an idea of what this job is all about?

First of all, cuz you might not even want to do it, right. You might have watched a CSI one too many times and you're like, oh, I wanna be a hacker. I wanna be, I wanna do forensic, like. It's the job is rarely what you think it is. You know what I mean? So you, you definitely wanna do your research and if you can talk to some, somebody like myself, who's been in this field for a while and ask their, ask them, like, how do you like it?

You've been doing this for 20 years. How do you like doing this job? Is this something that you think I should do? What are the pros and cons? Those are the kind of questions you really want to ask. Let's get back into keywords. So if we're looking at keywords here, I'm seeing a couple off the top of my dome right here.

If you see words like this, that you don't know what the hell it is, PCAP, that's a key right there. If you see there's a couple key tasks in here, stakeholders. There's a couple of key in here already, but you wanna read through responsibilities cuz you might, you might not even wanna do this job collects network, device, integrity, data and analyze signs of tampering and compromise.

Okay. So signs of tampering and compromise is one of the things you do as a. As a forensics guy. Now let's look at, let's get a little deeper into this desired skills. Look at this. Now this is a gold mine of all kinds of keyword. See all this stuff right there. These right here are tools. It says you need to be experienced and proficient with the following tools in case FTK sift.

These are all tools of the trade for a forensics guy. Very important. Like just like a plumber. Like if you are a plumber, there's certain tools that you need to know. Right? There's certain things that, that you basic things in that field that you need to know. If you don't know 'em you gotta get to know 'em right.

Especially if you're brand new at this, you gotta get to know what those things are. Now I'm talking to people who might have a little bit of it experience or something like that. For forensics, you, you probably have to know, at least the basics. In it very, very important. So now let's get back into this.

Let's get back into finding out key keyword here. So these are all key words right here. And now what you wanna do is take these. You got two things you can do from here. You could take this and put 'em into a copy of paste it into a, a blank text file. You can do that. Another thing you can do is put it into something called word art and word art.

What it'll do word word art does is it makes a visual representation of what of what you found. So let me just show you what that, what I'm talking about, that word, art.com and it's, it's just a tool to kind of help you to, to visualize what's going on. So here's word. All right here, you can create your own.

And it, it comes up with this site here and what you'll do is you'll input the words. You'll copy them and then import them in. So let's, let me just show you what I'm talking about. So we're gonna go to, I'm gonna go back here and I'm gonna copy and you wanna do this on two or three different jobs. I'm gonna copy this and we're gonna import what we just copied into word art.

We're gonna import it now. They, they take it right here. So I just copied it. Boom. I, I put it in here and I'm gonna import these words and now what it is, parsed out every word that's in the text that I just downloaded. So what I do, let me backtrack a little bit. So what I did was, what I'm doing is I'm going through two or three of these different websites, two or three of these different jobs, and I'm gonna copy and paste those into a one file.

One word document. Then I'm gonna take those and I'll put 'em into word art. And then we're gonna do get a visualization of what this looks like to see. What, what areas are the most important that we need to focus on tools. Look at this for so forensics, we can see that tools is mentioned a whole bunch of times out of this.

Now this is kind of a light list. Like it's only mentioned twice, but you wanna get like four or five different ones and dump 'em in there, but you kind of see the idea of what is happening here. And then the tools that are mentioned the most is in case now, in case it is a forensics tool, that's very expensive.

You might be able to get a free a free version of it, trial version to, to mess around with it. But this is not, this is not a cheap, this is one of the most expensive tools out there for forensics. So in case I'm very familiar with I'm familiar with that. It's used quite a bit in the government to.

What they'll do is if, if somebody's done a crime on a computer, I could tell you some crazy stuff for forensics that's happened is it's pretty dark. I mean, the stuff that they're, if you have a forensics guy in there, then whatever the hell's on my computer is pretty, it's pretty bad. Right? It's not something I could talk about without getting flagged by every, you can kind of come up with an idea of what it is, it's murder and it's, it's like stuff like that, right.

Or worse or worse, think of something worse than that. So, anyway, so that's, what's on people's computers. It's just bad, man. Anyway, so in case what it'll do, one of the things it does is it'll take a hard drive that people, somebody has tried to clean, that they try to delete stuff and in case can see all the stuff they.

The stuff's still on the computer after you delete it, by the way, even if you put it in the trash and then emptied the trash, it's still on the computer. And in case looks at the ones and zeros that were originally written on the disc, lifts those up, and then it can reconstruct those into files. Like if they had a image or a video or whatever, it can reconstruct those and give that to whoever's doing the investigation that they'll use for a court case or whatever.

FTC, I believe does the same thing. It's like an open source ver version of in case if I'm not mistaken. And then there's some other tools here, but yeah, this just gives you an idea of how you can pinpoint different keywords that are in any kind of genre and any kind of anything that you're trying to do.

So now that we know how to do keywords, the next thing we wanna do is put that in our resume. Now you don't wanna just put this in any resume. You wanna put it in a, at ATS style resume. Let me show you what I mean by that. So I have an example of that. In my book here. And I'm just gonna show you that real quick.

And if you want an example of this, there's a couple things you can do. You can go and Google how to find a ATS style, resume those exact words. Or you can go to my site combo courses.com and look for a cyber security marketing course. And that has a free downloadable of what I'm about to show you.

And it has the actual format that you can download it and use it for your own resume. ATS style resumes are so important because what the, and see I'm using word are here. I'm telling you how to do this. I'm walking you through it in this book. That's all the stuff that's gonna be in this book. That's coming here real soon.

So I'm looking for the actual resumes. It's I got a lot of stuff in here. It's breaking down everything, every aspect of what I'm telling you right now, but in greater detail I'm I skipped over a whole bunch of stuff that you should, that you should know. . So I'm trying to find my ATS style resume in here.

Man, where is it? Okay. ATS. It should be here. Okay. ATS style, resume all the sections. I'll give you an example of what that looks like. And then we go to there, here, here it is right here. All right. So here is example of a ATS style. Is this it? No, that's not it. Sorry about that. Yeah, this is it. This is it.

See how simple this is. This is an ATS style resume. It's very, very simple. It's it's not got a lot of stuff in it, so it'll have the person's name. It doesn't have any kind that's and fancy. It's nothing fancy going on with this. Now you can make a fancy ATS style resume, you know, and I'm, I'm not wasting my time with that for this.

I'm just telling you exactly how to do this. So you'll start off with the, the, a breakdown of what's going on a person, and then you'll put the your contact information and you'll put A breakdown of who you are. Another thing that I do in the summary by the way is I'll put, I'll put Hey, I wanna RO work remotely, cuz that's an opportunity for you to say that another thing you can do is say, Hey, I have a security clearance.

Like you wanna put the security clearance right up top, if you can. So you can put that in the summary. So you right here, you just put summary, this is ATS style resume. This is it right here. You put the name, you put the contact information. You put a summary, you put education up top, you know, in this style right here.

See how this is. And the reason why the format of this matters is because when your resume is when your resume is uploaded onto these sites, when if you put it on, indeed, that's another thing you need to do. You need to put it on. Indeed. You need to put it on monster dice. LinkedIn, you need to put it on as many sites.

If you don't have a job, your job should be to put this on as many resume as sites as possible. That's what you should be doing. Okay. Another thing I show you how to do is how to protect yourself because another one thing that's happening right now, lately is these freaking scammers are scamming people to get their social security number so they can do identity theft and all that kind of stuff.

So I've never felt fallen prey to that because the way that I do my resume, I don't put my real name. This is crazy. This is CRA I don't see anybody doing what I'm saying. I do not put my real name on the sites. Not I don't do that until I'm like on a screen, I'm talking to a screener, like maybe the second interview.

Then they know my real name. They do not know my real name till I'm on the second interview a lot of times. Right? Cause I'm screening them as they're screening me. Like I'm screening the organization. As I do not put my real phone number. I do not put my real, I might even put a different email address, like a fake throwaway email.

Like you can even do that. But I put a different name, an alias. I put an alias, something similar to my name, but it's not my actual name. I do not put my real phone number. I'll put like a, I'll use a Google voice. I tell you how to do all of this in this book. All right. All this is coming. Soon as I finish this, I've gotta do the first draft of this book.

You can see all kind of misspellings and stuff in here. I'll write the book really fast and then I'll go through it and then edit and stuff like that. So I just wanted to tell you guys, like, I just wanna inform you, this is how I do it. And it's been working for me. I've not been without a job. I mean, we've, you know, we've had several different collapses in the economy where we have recessions.

We've had like, that stuff does not affect me and I'm not trying. I mean, it affects me in like, okay, if I'm going to Walmart and the prices are higher or the gas is hot, jacked up or something. Yeah. That, that affects me obviously. But I'm talking about with a job. I'm good. Like I'm always employed. And the reason why is because I'm in cyber security, I'm one of the I'm in one of the fastest growing industries in the world.

And not only that, I stay ahead of the game by marketing myself. So I'm people are constantly contacting me about jobs and I'm not sent telling you this to two, my own horn. I'm telling you, you can do this two. You can do all the stuff I'm doing, too. Everything I just told you is what I do. Everything I just told you is what I do.

And that's how I'm able to stay ahead of the game. I put, I, I have a dope resume with all the keywords for the industry I'm searching for. It's all over my it's all over my resume. It's in the, it's in the it's in the, the summary it's in the, it's in the, the actions that I've done for an organization and my work experience.

It's in my skills. It's all throughout my resume. And then I put that out there. And here's another thing. If you are in it, If you are on a help desk, if you are laying cable for people, if you are in the hospital, if you are wherever you happen to be, if you've touched a computer before, okay, you have to put all the security stuff that you've done for that industry, you have to put all the stuff you've done, cuz that's really important.

A lot of times what people will do, whether what they won't do is they won't put the cybersecurity actions that they have taken and, and that's a, that's really bad. So that's another huge thing that you have to do. Okay. So let me keep going here. I'm gonna answer a few questions. I'm not gonna stay on here too long, but if you have any questions, feel free.

If you happen to be watching me feel free to ask me any questions that you have about getting in this industry about cybersecurity, about risk management framework, about security compliance, anything at all. I've been in this career field for a long time. I'm gonna tell you from the perspective of somebody who's been doing this for some time real world Examples, real world practical things that you can use to, to upload, to upgrade yourself.

All right. I'm answering some questions on YouTube as I do once a week. And if you didn't know, I'm all on TikTok, I'm, I'm answering questions there. Very one-on-one type questions. I'm answering questions on my email. I'm doing work for people like helping people with their resumes. I do all that kind of stuff.

If you're interested in that kind of thing, where I'm going way deeper and doing like a one on one, like just me and you corresponding, not like this kind of stuff you can text me at, you can email me at combo courses@contactcombocourses.com. Or you can go to con courses.com and find my contact information there.

I'm out there. Let me answer a couple of these questions. Somebody said, watch one of my videos and said, this is a gold mine. Wow. I appreciate that. Great compliment. This is when I was doing a video about help desk to cyber security and trying to helping people, helping people with that. Somebody said, how can I purchase this book?

Some old book that I wrote? If you didn't know, I've got some books out there on audio, on audible. So if you're interested in getting into, if you like, like listening to books, I listen to books quite a bit. And I just wanna tell you guys, I have a book out there. If you go to audible.com, if you happen to have it, if you don't have audible, actually you're in luck because they'll give you this.

They'll give you like a free trial. But you can go just type in R MF. ISSO. And these are two of the books that I have right now over over four hours worth of content to listen to, if you're interested in this. This will also help you with cap a little. If you happen to be doing a certification in cap, it'll help you a little bit in security plus, but it's like a small portion of security plus.

So it's not gonna help you that much, but cap, this helps you probably, this is 60% or more of the stuff that's on the test. It's not cater to you taking the test, but it will help you to understand like the practical implementation of risk management framework. So there's that if you're interested in listening to this, it's on audible, I'm also on Amazon, just type in, you can just type in Bruce Brown or you can type in NIST 800 control family.

My book is out there as well. And then you can also order it directly from me on combo courses.com. This is the site right here, tons of free stuff here, by the way. I, people are really upset about selling products and things, but a lot of the stuff that I have on here is actually free. And if you go to YouTube, if you follow me on YouTube, it's just so much free stuff on there.

Like a lot of the stuff I say on here, or that's on my website or that's in my books, it's there. You just gotta dig for it. You know, if you want a little bit deeper dive, then that's when you going to get the book or get the course itself. That's, you know, when you're serious about this, that's when you wanna start getting the book and, and getting in deeper in this and asking direct questions.

Okay. Somebody ask me if you want to be an ISSO, what certification do you need? That is a great question. Let me break this down to you. So if so, work is normally for the federal government and let me just put you on some game right here. So if so, work. The federal government goes by something called 81 40.

So 81 40 D O D 81 40 is a breakdown of what every contractor and government employee should have as far as certifications in order to get in this field faster. So what I'm doing right now is I'm actually showing you what 81 40 looks like, see this, what I'm like. And for those of you who are listening to me, I'll explain what you're seeing, what I'm, what we're seeing.

So this is 81 40 and essentially it's approved baseline of certifications. It changes from time to time lately, every about six months that've been updating this. So there's a couple things here that I'm, that I'm not seeing. That's been either removed or added. In fact, let me see if I can go to the newer version of this.

If you go to, oh, what is it? Dissa dot mill. Yeah. And you might see me. Okay, DISA dot mill. I think it is DISA dot mill, 81 40. They have the, one of the most up to date versions of this thing. I'm trying to look for 80. They used to call it eighty five seventy and it's a, it's all the approved certifications.

So if you go by this list right here that we're looking at, this is a list of approved baseline certifications. Let me explain what this what's going on with this thing. If you can see this, if you can, let me make it a little bit bigger here, but I'll also explain it. So they have, they have this broken up by technical and management architects, analysts, and auditors.

Okay. Those are the main categories. And let me just explain each one. So the the I a T means information assurance technical that just that's basic technical troubleshooting. It might be designing or configuring systems. These certifications are needed. If you're a level one, a level one is basically like a help desk person.

This is a person who has a, basically a one on one relationship to one customer at a time. They, somebody calls in and says, Hey, I have a trouble ticket. That means like something broken and they're, they're not connected to the internet. And they happen to be on the fourth floor. And then you, or you call 'em on online.

Maybe they're, you know, you're a remote worker or whatever, but this is a first line of defense for people fixing computers, help desk customer service, field technician, one, that kind of thing. They will. They're expecting you to have an, a plus certification as listed here, a CCNA security, which is, that's a very hard security.

That's a very hard certifi. I don't know why they put this here. I didn't make this. So keep that in mind. network plus C and D, which I don't even know what that is. S S C P one of those things. That's I a T level one. That's. And remember I a T level one is a help desk person. Now, if you happen to be upper level, like let's say, not only do you do help desk stuff, but you also do some networking stuff like you might have, you might be responsible for fixing the network on a whole floor.

This is like network engineers. This is like this is like people fixing a whole land, a local area network people who's responsible for a local area, a virtual local area network. So they're, they're kind of having to look at server issues as well as switching and networking problems locally, as well as like one on one customer support.

So what certifications does an I a T level two and information assurance, technical level two need so that's a CCNA security plus CSA plus a CI. So all of these things security plus is a big one. These, these are the ones that they're looking for. Okay. When we're gonna get to the information system security officer in a second here, I'm just building up here so you can kind of understand what's going on now.

I a T level three. So this is an enclave. Normally these guys are not only doing like one on they're kind of beyond the one on one type type of thing. Cuz their skill sets are so versatile that they're needed to do bigger things they're needed to do more like working with the architecture team, working directly with servers they're they're handling stuff.

That's like. Local area network to local area network. So these guys have professional level search. They're very, very in the weeds, but also high enough level to where they have to know, see the bigger picture of what's going on with the network. They're doing enclave to enclave. That's like one lo local area network to another local area network and possibly WANs, which is a wide area network.

And that's way more complex. So this is CCN P security. That's a very difficult certification, a professional level cer Cisco certification, a CSP, which is also a professional level cert that's no joke, a C S S P high level cyber security certification. And then some others G C I H, which is incident handling.

And I, they just added this one CCS P, which is, I think, a cloud, a cloud certification from ISE two squared. I think, I believe that's what it is. Okay. Now let's get into I ISO and the ISO, if you didn't know, is a information system security. So that is kind of what I do. And I can kind of give you in an, in a nutshell, like what an ISO, an information security person does.

So this job is typically your day looks like this. You're doing a lot of meetings. That's what your day looks like. It's a lot of meetings because you're, you're talking to other people within your organization, stakeholders, you're, you don't have to be a, a subject matter expert in say, firewalls, you don't have to be a subject matter expert in say networking or routers and stuff, but you do have to know enough to be dangerous.

Like you do have to know enough to communicate what is happening with the organization. Your responsibility, as an information system, security officer is to manage the risk is to help the organization to manage the risks of the organization so they can maintain their security posture. Now you might be like, Bruce, what the hell are you?

Are you talking about what are you? Let me spit it in layman's terms. That means. The, the organization has a certain level of security and they need to maintain that. And what does that mean? Like, think about it. Windows is constantly changing. It's constantly having upgrade to patches. There's constantly vulnerabilities coming out.

There's constantly new education that needs to happen with the users. There's all these new threats that are happening from day to day. Everything's constantly changing in it. Well, that's where an information system security officer comes in because our job is to make sure that no matter what changes happen, the organization stays compliant and stays secure at a certain level.

It's very challenging, especially if the organization has a lot of different technologies or also very large or organization with lots of stuff going on. So let's get back into what actual certifications does this information system security officer need. And I'm gonna show you here right now. So let's go back to the 81 40, so 81 40 up here is an is.

So is considered a, a manager type role. Okay. It's a manager type role because you're dealing with, you're not just doing in the weed stuff, fixing computers. You're not just working with firewall. They might have you do some stuff like that. But your time is mostly spent coordinating with the organization to make sure that the organization is doing what they're supposed to do.

I said organization. So you're, you're talking to C level execs. You're talking to upper level managers. You're talking to the, to the system, administrators, you're talking to users, you're talking to user reps. You might even be talking to the customer. So it's a lot of meeting. So if it's a manager type role, you gotta be able to communicate effectively.

So a cap, a cap is a, a certified authorization professional. So what they do is exactly what I'm talking about. They make sure that the organization can maintain a certain level of authorization so that the, so that all of their documentation is good, so that all the security compliance security controls on their system is good.

And let me break this down to you. So cap is a good one. Another one is CI while I'm topping here. Another one is a CI S S P CI SS P is a good one. Security plus is also a good one. Those three, I say, well, the top certifications that ISSO is typically typically has. Now this might evolve cap cap.

I notice comes up a lot. CS a comes up from time to time. But look at these, what I'm, what I just did was I logged into ISE two squared.org, and I'm showing you the different certifications now cap. This is the certified authorization certification. So security assessment and authorization certification.

So that's what it is. Certified authorization professional. That's what it's called. So this is one of the top. This specifically focuses on N 800. So N 800 is what the federal government and states and some other organization contracting organizations will use to ensure that you know what you're doing when you're talking about security.

For an organization. So these, let me just read a couple more here, a, a couple other ones that an ISSO is considered they're good for an ISSO is let me just name a few that I've seen in the industry, a cap, a cap, a C SM, a C S S P a G S GS, C L L C. And a recent add-on. These two right here is C, C I S O and a H C I S P P, which is normally for hospitals.

This is like HIPAA compliance and stuff that one's getting gaining ground right there. And this is listed on the dissa site. So this is that's a dot mill site. So that's, that's a big deal right there. So those are the main ones. I hope that answers your question. Let me keep going down questions. If you guys have any questions whatsoever, feel free to ask me, like, I've been doing this so long.

Just off the top of my head. I, I know this stuff. I've just been doing it so long. You know, I don't know if that's necessarily a good thing, cuz it's pretty much. All I know , you know what I mean? So let me see let me answer a couple questions here. Somebody said how do you get, how do you get this?

I'm looking for? Okay. What, what are you talking about here? A hundred. Oh, okay. I posted a job a job, a remote job where you're making a hundred K. And somebody says, how do you get this? I'm looking for this right now. I took a cyber security course, and now I'm studying for the interview questions.

I would like to know how you do this boss. Okay. So I do this, like in the beginning of this, of this session, I, I talked about it and I can just give you a brief rundown. The first thing I do is I make sure all the keywords are on my resume. So every, every category of cyber security. Has a different set of keywords.

For example, for example, at one time I was proficient at like two or three different parts of cyber security. I was, I was proficient. I'd done it before I'd had certifications, everything. Right. And those two were one, I was a seam engineer. That's a security information event manager, engineer. I could build them from scratch, set 'em up, create content for it.

And it could monitor all your logs. You know, I did that for like three years straight, so I just, I just knew it. And then another thing was, I was an information. I still am information system security officer. I know that means I like, I know how to allow an organization to be compliant with certain security standards.

And then another thing I was good at was cyber security analyst work. So those three things, those are three separate resumes. Okay. They have three separate keyword sets of keyword. . So what I did was I made a resume for each one of those. Each one has different certifications that are more relevant. I'd put those on top.

Each one has different. Some of 'em really require a security clearance. Like if so, and a cyber security analyst usually requires a security clearance, cuz you're working in like a, a, so a security operation center, which is, has classified information and blah, blah, blah. But the, the scene really didn't need a security clearance.

So I could even leave that off. And that was still good. My point is every single time you, whatever career path you're going in, it has this different set of, of keywords. And so what I do to make myself more marketable for this is I get keywords for each one of those work roles. Whatever it is. And to do that, you can, you can actually research it and figure it out.

Right? And I'm not telling you to lie on your resume. I don't recommend that a lot of people like lie on your resume. Why aren't you, why aren't you lying on your resume? Me personally, I say don't no, do not lie on your resume. Do not put your picture on your resume. Like put your picture on your, not resume, but, but unless you're on in, I guess EU does that, but put your picture on your profile.

Some people are like, nah, because I'm black. I don't want people to see that I can't get jobs. Nah. Why would you wanna work at an organization who doesn't want you? You need to put your picture there and if they don't wanna work with you, you shouldn't wanna work with them. That's how I feel about it. I don't wanna work somewhere.

They don't want me. So I put my black face on my profile. Go look at it. It's up there right now. So that's number one, like put your don't lie on your resume. The reason why I don't lie on my resume is because I don't want to get in there. And then they, I, they think I'm some, I'm freaking gonna walk on water and I don't not for that particular technology.

Not only that, but in the res in the actual interview, they will ask you these questions and then they will verify what you sold them. They will call your employer and ask, Hey, did Bruce do this X, Y, and Z. They'll do that. Especially as you go higher up in the echelons right now, if you wanna fudge some numbers of how long you work the place, and you know that it's not that big of a deal, but do not put certifications.

You don't have do not. Don't lie about your degree. They're gonna check that stuff, right? Don't like, this is some obvious things you shouldn't, you shouldn't lie about on your resume, cuz they will ask you I'm going through an interview process right now. You better believe they're investigating me.

They're looking at it. Every part of my life I'm having to put in there. Right? Because it, you can't, you can't just lie on your resume. So I don't recommend lying on your resume, put the real deal on your resume. But not only that put the key words for what you're doing on your resume. So that. when so that way, when you put the, when you upload this into LinkedIn into dice, into monster, and you need to put it on like 20 or 30 different job aggregators, okay.

You need to put on 20 or 30 different ones. And that's why I say you shouldn't use your real phone number or your real, you should use an alias because you're gonna get so many calls from all kinds of people and you don't wanna get scammed anyway. So that's what you do. That's what I do. And that's how I've been able to get all these offers for remote 100 K type jobs or more.

And, and that's how you do it. And I'm writing a book right now. If you're interested in this, if you're super deep into this, if you're very serious about this, I'm writing a book right now, it's gonna be out soon. And if you, if you, if you're interested in this, the very beginning of this podcast, I broke down exactly how, what I'm telling you.

I broke down. I showed you my like, how, how I picked these key out, how I find them. All that kind of stuff. If you're interested in this, a book is coming, that's gonna break all this down in great detail about how to get into cybersecurity in particular, but you can use these techniques for basically any, any job where you have to apply for a resume.

Any job you need a resume that you could use it for that. So let me see, I got a couple other questions that says on TikTok it says I just got a free ISO two course. And let me see. Cert is free when I'm done. Have you heard of this course? Yes, this is, this is great. Like thank you so much for asking that question.

So I've been, I've been telling everybody about this new certification that's coming out, like what's happening right now. If you guys didn't know, is that the government's hurting for cyber security positions, there's something. 700,000 careers that are empty slots. Like we in desperate need of, of people to get in here.

So what's happened is there's been this huge push from nonprofit organizations, corporations, and government entities to actually get people into this field as entry level. And so ISD two squared has this new certification. That's an entry level cybersecurity certification. And right now it's free. It will not be free forever because is ISD two squared.

I don't know if you knew this, but they don't, they don't mess. They don't mess around. They do not. These guys have the top cyber security certification in the world, arguably in the world's called C I S S P. I have this certification, this certification changed my life. It's a high level cyber security certification that talks about nothing and everything.

But it is so good at marketing me. Like, all I gotta do is put that on my resume. I could probably just have a blank page with just C I S S P on there, and I'd probably get hired. That's how powerful this resume. And it's the reason why this certification's so powerful is because they've done a great job of marketing it.

That being said, I'm saying this to tell you that they're now given this damn thing, this right here for free, this is an entry level for you to get into cyber security. This right, this right here, I'm showing you it's called certified in cyber security CC. Now, from here, you can build into other sec into other this is an entry level, but you can take this and build up to a higher level certification.

That's why this is so powerful. And these guys, this is not some fly by night, organiz. This is one of the top, if not the top and best cyber security certification organizations in the world on planet earth currently right now. So this is a great path. If you are actually looking into this, this is a great path for you to do, do this, doing it for free.

They're giving it away for free. This will not be free for long. I guarantee you because they're trying to compete directly with comp Tia security plus, that's what they're trying to do. And eventually this right here, this certification, I mark my words. This certification right here, this certified in cyber security will be on this sheet right here.

This is 81 40. This is 81 40. Also known as 85, 70 approved baseline for certifications. They will have CC on this. I bet you it'll be like right here. They'll put it right here alongside a plus certification, alongside C and D and all these other ones. And once this goes on here, It'll be way more marketable than it is right now.

Right now it's a free certifi it's it's brand new people don't really know about it. People are kind of figuring it out. Like they're kind trying to compete with this and the Google support it and the security plus, and those kind of certifications that are entry level because the government is making this huge push to get more and more people in this field.

This is a really, really exciting time to get into cyber security. This is, this is a rare opportunity where they're trying to open the doors, but you, this is not a field where you can just come in off the street and know nothing. You have to do some work. Like even if you come in and know nothing, you have to do work to understand the basics of information technology.

Right. That's all. I'm, that's what I'm saying. So this is a great opportunity. Let me see, I got a couple other questions that says, how does a civilian get a security clearance? Okay. So there's a couple ways. Just, just so you know, I've been doing this for some time and I've had security, all kinds of security clearances from public trust, all the way up to top secret type certification security clearances.

Another one misconception that you, that I wanna dispel is that you don't need a security clearance to get into cyber security. They're two separate things. Okay. A security clearance is just verifying that you are, are who you say you are. They're VE they're doing a, a, anywhere from a basic security background check to make sure you're not that you are trustworthy to work in their organization with secret information.

They're making sure you're not linked to any kind of terrorist organization or insurgents or militia organizations. You'd be surprised. You'd be surprised how many people are associated with it. because every time they ask me, I'm like, ha ha. That's ridiculous. I'm not, but no, there's really a lot of people who are associated with these organizations that wanna take down the government that don't feel like they have some kind of issues with the United States government, or they're tied to another government.

They actually happen to be working for another government. And they're trying to get in and infiltrate. You'd be surprised how many people this, this applies to anyway. So background check is just trying to see if you are who you say you are. If you don't have, make sure you don't have any crazy credit issues, that's gonna affect you to work on their job, making sure you're not like a, your a super predators killing people or something like that.

Yeah, they're trying to just do that. That's separate from cyber security. Okay. Cyber, a lot of cyber security jobs need a security background check. Because the nature of the information that you're gonna be having access to, and they wanna make sure that they can trust you to protect their systems, but they not, every, not every job requires a security background check.

Okay. Cyber security is their separate things. You can be a janitor and need a security clearance. Okay. So the question was, how does a civilian get a security clearance? There's a couple ways. Number one, work for an organization who will get you a security clearance. If you happen to work in the DMV area that's DC, Virginia, Maryland area.

There's so many jobs, not just cyber security you might have be a groundskeeper and mowing grass and have to have a clearance, some dead serious. You might be painting the inside walls of a, a skiff that need you need a clear. You might, there's all kind of clerical jobs secretarial jobs name something, janitors anything like can get you.

So you would, one way that you could get in is if you had a job, if you got a job at a place that required a clearance, a lot of times they will pay for you to get a clearance. They will pay for you to get the clearance because it costs money to get a clearance. Another thing is you can there's sites.

Somebody contacted me the other day. They were trying to get me a clearance. Like they didn't, they didn't know. I guess they would contact me and saying, Hey, we can get you a clearance and stuff. So there's, there's private organizations that can get you a clearance, but you're gonna have to pay for it.

It's not cheap. Just to give you an example, from what I heard a security, a secret background check is like $5,000. And then a Ts is like $10,000. That's what an organization has to pay to get you a clearance. And then a public trust. I don't know, public trust is like here. Secret clearance is here and then above that is top secret and all other white house, all this other stuff.

So, yeah, so you can, you can get into a position, a job that requires it and then they'll let the organization pay for it. That's probably the best way. The other way is to get it privately and pay for it yourself. That's another way. But then it has to remain active. I don't know how all that stuff works, but so those are the two ways that I personally know about how to do it.

So, and I could be wrong. Anybody else you guys know of another way to do it, please chime in and, and, and inform me what's going on. Let me see here. Somebody ask hope that ask your, answer your question, by the way. Somebody ask so I just signed up and I have to take an exam. Yes. So, so I believe that that, that I C two squared, they have a, they have a course.

All right. And I believe the course is free. If it's still free, they have a course that you can take that breaks down. What's gonna be on the test. And then you, you, you go to that course, you study for it. If it's still free, hopefully still free it. They were saying it was a value of one ninety nine, a hundred ninety $9.

But even if it costs $199, it's worth you investing in yourself. It's, it's, it's worth the risk. It's worth the risk. Anyway, if it's still free, cuz just last week, it was free. You take the, you go through the course that I believe is on course. Sarah it's either on course, Sarah or it's on their website.

Okay. Sign up for their website. They'll give you a breakdown of everything you need to do. And then from there you will take the test. Like once you study for it, you take the test. Somebody. no they're paying for it once you finish the course. There you go. Okay. Thank you for that. ODI says no, they're gonna pay for it once you take the course and there's only 1 million openings.

Okay. There you go. Okay. I stand corrected. So let me, let me correct myself. So what he's saying is once you, it was free for a while. It was, it has actually free like a, like a week ago or something I'm telling you. So now you're gonna have to take the, the, the course, and then once you take the course, I think was 1 99, then you you'll take the test, pass it, get your certification.

So let me see. You have to take a test. Yes. It's this is, yeah. There's there's hurdles. You have to take the test to get the certification, but it's worth your inve. If you are serious about this, it's worth your time. Okay. Let me see. I got a couple other questions. Somebody said I barely see a hundred percent remote opportunities.

Most people keep wanting people to be on site. That's true. And bro branding, I, I would add to that and say a lot of the security clearance, a lot of the cyber security jobs that require security clearances do require you to be on site at least like a hybrid on site. But I would say that there's a lot more remote jobs opportunities than than there were before.

COVID cuz it was, it used to be really hard to find them. Now they're everywhere and I could show you how to find them real quick. I'll show you let see if I could show you on LinkedIn, if you guys didn't know, I have a LinkedIn page you can search me out on Bruce Brown for the win. Let me show you on.

If you guys happen to be on LinkedIn here, here I am right here. If you type in Bruce, go to LinkedIn and type in Bruce. CIS S P RMF or something like that. You'll find me there. It is right there. There I am right there. And so join me. I'll definitely add you. I've got a, a lot of people wanting to add and I'm, I'm always open to, to add people or you can talk to me online, all that kind of stuff, but okay.

Let me show you how to find remote jobs. Okay. Let me see. Let's let's say you were looking for a cyber security analyst job, right? Cyber I'm just, just randomly pick one off out the air. So now check this out. First. You'll go jobs. And the reason why you wanna check pick jobs is because there it's gonna show you everything.

It's gonna show you companies, posts, schools, groups, people, all that you want jobs. Okay. So search jobs, then post a date. You don't want any time, cuz this goes back like a year or something. You want something within the, at least the last month. all right, so let's look for last month and then this one's up to you, they got internships, entry level, associate senior manager, whatever.

Right? You ch choose that. But if you don't really care, leave that blank and then remote, let's go to remote job. So here it is right here. You're gonna onsite versus remote. So you've got hybrid, you got remote and you got onsite. You just click on site. Now you notice it went from 17 K jobs down to three K jobs.

I'm on LinkedIn, by the way. So I just went to jobs stuff in the past month. And then I went to remote on site. This is a new feature, by the way, they didn't have, it needs to have all of this stuff. And now they have it on dice. They have it on monster. They have it on almost every site because remote jobs are so prevalent now after COVID.

So here you go. Here are some remote jobs for cyber security analysts, which I just typed in. And that's how you find remote jobs right there in five minutes. I just showed you how to do it. and you can do this with every site, with monster, with LinkedIn, with with da, with, with dice, all of these show you how to do remote jobs.

And if you go to dice, let me see if this one's ready. So here's, here's my profile on dice.com. I'm about to turn this thing off, man. I'm getting so many contacts with these guys, so there's a way to search for remote jobs. Let me just show you here. Let me I'll do the same thing. Cyber security. I'll just type in cyber security.

I didn't put a location in I'll hit search and check this out. It comes out with this page right here, taking a little bit of time and then look right at the top. Remote only if I hit remote only you notice it went down from 4,800 jobs to 600 jobs. So, yeah, there are less Brandon to, I, I could piggyback on what you're saying.

There are quite a bit less, but there are jobs there. I mean, look at this there's 600 jobs here. I mean, granted, I didn't search for, I said any dates, so that's, that's probably, what's adding to that. Let's do the last seven days. It's gonna be quite a few less. Oh, still 126 jobs. Look at that. These are all remote jobs.

And all I did was type in cybersecurity, look, 100% remote cyber security analyst, all of these are a hundred percent remote. Now you gotta double check. Cuz one of the things I noticed about these jobs is sometimes they'll say they're a hundred percent remote, but then when you do a, an interview with 'em, they're like, well, well it's a hundred percent, but we want you to come into the, I was like, Is this a hundred percent or not?

yeah. You gotta do an interview with 'em to make sure and ask them, is this a hundred percent remote? You know what I mean? Like you usually straighten that out with the, with the actual screener, once you, once you talk to them, ask them, and then sometimes it's, it is remote, but it's like 50% travel or something.

Like there's always some kind of catch sometimes with the judge. You just gotta make sure you, you weed out those gotchas with the remote jobs. I just went through this. That's why I know a lot about it. You know, , I've been, do working remotely for the past seven years now. Like I've been working remotely for a long time.

Crazy. It's crazy to me. Like I've been working. Yes. Seth's been seven years. I started in 2014 working remotely and I've been working remotely ever since. And I will never go back. I will never go back. all right. And that being said, if you guys are interested, I have a course on how to work remotely.

It's on combo courses. Go check it out on combo courses dot com, just work, find the remote jobs course. And then I have it out there and I I'm, I might even write a book about that one and break it down. So it's like a 20, $20 book or something like that. I might, I might do that cuz I I've gotten pretty good at getting remote jobs and winning those remote job positions.

Okay. Let me see link to the course. I'm assuming you're talking about the C the CC let me see if you're interested in this. We were just talking about this, this course right here, which is an entry level ISC two squared course, which they're given. I believe you have to pay for their training and then thinks 200 bucks for the training.

Now it was free like last week, unfortunately, no longer free. And then after. That you take the, the test and I think they give you the test for free. If I'm not mistaken, correct me if I'm wrong, TikTok somebody on TikTok, correct me on that one. I appreciate that. But yeah, here's the link right here. It's ISC two dot org slash configuration certifications and four slash CC.

Or you can go to Google and just type in ISE two square ISE, two space CC, and you'll find it. Let me see if I can give you the link in the chat. I, I don't have access to the chat right now. Yeah, and I always walk me through all this other stuff I gotta do to get link access to that. All right, guys, that's it for this one.

Thank you for watching. I really appreciate all the questions. Thanks a lot for, for all your kind words and stuff and all the donations. Appreciate that. Thank you so much. I've got a couple other questions on, on TikTok. Let me see if I can answer those real quick. Yes, it's still a self-paced exam.

Okay. We're still talking about the I C two CC. So I can get an entry level job with a CI S S P certification. Can you get a, okay. So with the CI SS P it requires like five years of experience. So somebody's either got a vouch for you having five years of experience, or so you're typically, if you have a C I S P you don't have, you're not an entry level person.

Now, if you happen to get, I think you can sit for the test, but you, they won't give you the cert until you hit all of these different requirements, but by the time you hit those requirements, you no longer entry level, if that makes any sense. So I don't know if I answer your question. Let me see. You said so I can get an entry level job with a C S S P cert.

You, once you have a C S P you don't have to get an entry level. You're not an, you're not an entry level person. If you have a CI S S P. So, so the, the certification we were talking about is called a, an ISC two. Let me just show you what we were talking about. We're not talking about CI SS P we're talking about a certified in cybersecurity certification.

That's from ISC two squared. It's this one right here. If this is an entry level certification, you don't need any requirements. Before you go into this. If you're talking about something like a CI S S P there's actual requirements, before you can even take the test before you even take the test. And even if they allow you to sit for the test, you have, somebody has to vouch for you that you have a certain level of experience before they'll give you the certification, something to that effect.

Okay. Let me see. Hey, Bruce, where would you start? If you had to start all over again, without any knowledge of cyber, I would start with cloud. or right now cloud's super hot, man. So I would, what I would do right now. If I was starting from scratch. That's a great question. I would, number one, I'd go to eight.

I'd go to, okay. There's a couple shirts I would get with no experience, know nothing starting from scratch. Knowing what I know now I would start with the AWS cloud certification, that one. And then there's no one from Google called Google, Google. Its, let me see if I can, let me just show you. I don't, I don't wanna be a liar here.

One, the one is called and let me, I'll explain to you why I would get these and you it'll blow your mind and you'll you'll follow exactly what I'm saying. It will blow your mind. So there's one called AWS certifications. If you wanna follow along with me, let me just show you what I'm saying. What I'm seeing right here.

Oh, wait we go back. Okay. There we go. Okay. So AWS certifications. I just typed it in. And skip all the ads, skip all the ads. We wanna go directly to amazon.com site. Okay. So I would take this right here. See this AWS certification so you can train on their site. I believe their training is free and he, they even have a whole path for you.

This one right here, this cloud practitioner is the one I would take. And the reason why I would take look at this it's 90 minutes long, it only costs a hundred dollars. I could take this right now. I could, I could literally I'm thinking about it. Actually. I'm gonna take this test. The reason why I would take this one, one of the first ones I would take is because in the last I just had five different interviews.

All right. I'm not even count counting the, the the screening interviews I had. I like probably 20 screening interviews or more, but I had about five interviews in, in four. Out of the five interviews. They all ask me about cloud. Now I'm an old head cloud is actually new for me. I have not dive dove into it.

I have a little bit of exposure to it, but not a lot. Right. I don't, I know some of the difference between a P a a S an versus a S a a S versus a I a, a S like, if you know what I'm talking about here, like different platforms of cloud, like platform. Cloud as a service versus software as a service versus whatever, as a service, like everything as a service planet earth, as a service, whatever the hell there, the terminologies, I'm an old head.

Like I, this is new to this crap is new to me right now. Virtualization's not new to me. That's been around, but cloud this and cloud that like everything's going to cloud. And the biggest cloud service right now is a Ws. They always ask me about that. And I had to be like, mm, I, that's not my, you know, but I can tell you this.

Here's what I know. You know, they all ask me about it. So if I was starting from scratch, I dos, if I really didn't know anything, nothing at all. And I was like a, like, starting from absolute scratch. I'll probably take the same one I did when I first started, which was a plus certification. Like if you know absolutely nothing about it, then probably the best thing to take would be an a plus certification, cuz that will get you.

At least knowledgeable on, on how computers work, cuz you really need to know, you need to know like the difference between Ram storage and and the CPU you need to know, kind of have an idea of how CPU work. You don't have to know like how the addresses are mathematically algorithm, the mathematical algorithm of how the CPU, you know, moves pixels from this side of the screen to another.

Like it's not even that deep, like it's just telling you, this is how the Ram works physical memory. Here's how it works with the storage versus the CPU. Here's how they all work to make a computer. You need to know what a computer is, how they work, how to troubleshoot 'em so a plus comp Tia, a plus certification.

One of the first ones I would take if I knew absolutely nothing, cuz that will give you after you take that certification, there's two different ones that you have to take in order to get the a plus once you know that you'd be able to troubleshoot computer, any computer, like you'd be able to troubleshoot.

A laptop, a server, your phone, they're all computers. They all use the same components essentially and different configurations. And then you'll have a solid understanding of how cloud works because it's also a computer. It's also a, it's a bunch of computers that are somewhere else over the internet.

That's, that's pretty much it. And then I would take that one and then another one that's pretty hot is Google support it. I would take that one. I would take a comp a plus. I'd learn everything I need to know about that one, take the test, pass it. I would learn. I would do Google support it. The basic one that they have out there, they got like two, I'd do the basic one.

And then I would do cloud AWS cloud practitioner. That's what I would do. And then after that, I, I put my resume out there and then I, I try to get some, I would do either internship or I'd do a a entry level. I do entry level making 15 bucks an hour to get my foot in the door to, and then I'd work there for like six months.

And then I would transition to another organization. That's what I would do. And then I would, I would take my, my experience from that place. I worked six months and then I would go work at another place and then ask for more money. That's what I would, that's what I would do. Another thing. This one dude on TikTok blew my mind.

So this dude had a brilliant strategy. And if you have the money to do this, this is the most brilliant strategy you could do. If you have the resources to do it. Now, this guy did, but he, he went to this college called. Oh, GWS governors, Western governors, university or somethings. So legitimate college, like the government when I was in the military, they were promoting it a lot.

GWS college college. Let me Western governors. G w G U. That's what it's called. So this, this, this dude, his name is Chris. He's one of the top cyber security guys out there. He went here to this college right here. He took a course in cyber security. I guess they have one here. He did it in six months.

It's not gonna be cheap. He did didn't undergraduate in, I think, six months then what he did WGU that's right. Then what he did, this is brilliant. So if you have the money to do this, this is, this will get you six figures super fast. He took this right. It took six months. It's not cheap. . Yeah. I mean, you know, relatively speaking, it's not cheap.

This is, this is not bad for a college, to be hoNIST with you. So he got an undergraduate in six months, accelerated course in it. Well, he did one of these and then I believe he took the it certification with it. One at, I, I believe he took one of these. If I'm not mistaken he took one of these, see this cloud one would be dope right here.

Look at all these certifications, you could take one of these certifications with it. That's what I would do. And then after you'd come out with a bachelor's degree or even a master's degree with one of these cloud certifications, and then you can, you can possibly make six figures after that. That's in that's within a year within one year.

I think what he did was he did something called the OS. C O S C P, which is super hard certification. I think he did this one right here. I believe he did something like this. And then he was able to get a six figures within a year, which is very impressive. And then he also took this dude. He's pretty impressive.

I mean, this, like, this's some people who are this hardcore and this talented to do this. I don't think this is for everybody, but he took this certification called O S C P penetration test. It's one of the, I heard it's a pretty hard test, but it's from offensive security and it's a practical test where you have to hack live for 24 hours or something.

And you got this certification. Look at this, look at this course, $1,400. So for all you guys complaining about my course being 200 damn dollars. Look, look at this, look at this Fe your eyes on this. This is how much a course costs baby. don't complain about no $200 to me. This is how much they cost right here.

All right guys, I'm out.

View Details

We talk about the cybersecurity workforce

dod 8140

View Details

We talk about the cybersecurity workforce

dod 8140

View Details

Some one doing social work wanted to get into cybersecurity.

View Details

Some one doing social work wanted to get into cybersecurity.

View Details

In this episode, we talk about privacy.Β 

View Details

In this episode, we talk about privacy.Β 

View Details

It is important to have emotional intelligence in cybersecurity.

View Details

It is important to have emotional intelligence in cybersecurity.

View Details

get the xls spreadsheet here:

https://securitycompliance.thinkific.com/courses/cis-control-maps

Hey guys, this is Bruce and welcome to a convo course podcast. And today I want to talk about one thing in particular, and that is the CIS and how it maps to the ISO 27,000. And one, if you didn't know, both of these are security compliance frameworks that are used in the public sector and private sector, as well as international organizations.

So pretty much a little slice of everybody use. One are the two of these particular security frameworks. CIS is typically used for the private sector. That means like retail stores or banking or community centers or those kind of organizations that are private Lee own organization. And sometimes nonprofits.

I'll also say that in having worked in the public sector from time to time, we'll actually use CIS controls as well. It, just depends on what kind of what we're doing. Like we use the CIS benchmarks. I've seen those used within the government within like department of defense, cuz it's just a great tool to use.

And if you're interested in finding this, just go to Google or being or Yahoo or your favorite search engine and just type in CIS controls and. Right now you have a mapping from the CIS controls version 7.1 to ISEL 27,001. Now right now, CIS controls are on version eight. I'm not, I don't think that one's out yet, but right now we are focusing on.

Version 7.1, but we will revisit this once we get version eight. Okay. So that being said, I sell 27,001 is an international standard for information security management. And they both, do the same thing. It's for an organization to have a guidance on how to actually. Proceed as far as securing their entire network, not even just the software and hardware devices that are connected to the network, but also things like physical security, maintenance.

All aspects of protecting the actual security of the system. Whether it's outside of the system whether who's touching the system who has access to the system, all those things let's start from the top. So what we're gonna do is just focus on the main security controls, like CIS control, one that is inventory and control of hardware assets.

And you'll see that the IO 27,001 has something similar in and it's called a.eight.one.one. So inventory of assets, right? They kind of group 'em all together. They don't break 'em apart in individual things for ISO 27,001. Whereas I CIS controls, they break it up into do different things. CIS control one is hardware.

Whereas CIS two is inventory of security controls. I inventory of security sorry, inventory and control of software assets. That is not broken apart by ISO 27,001. They keep those together as a dot eight, do one.one. Let's keep going here. We're gonna go to the next control, which is CIS control three, which is vulnerability management, continuous vulnerability management, every single security compliance.

Framework does have some sort of vulnerability management, our continuous monitoring and vulnerability management they're hand in hand. And this one is no different, so I sold 27,001, let me see let's see if they have it here. They have more of a risk rating response. That's continuously done.

management of technical vulnerabilities. Yeah. So they have a dot 12, do six.one that matches to CIS control three, 3.7, to be precise. Let's go on, keep moving here to CIS control four. And that covers controlled use of administrative privileges. And that's really important because you don't wanna give your admin accounts to everyone.

That's one. One of the things that some organizations do is they'll just give admin rights to everyone, anyone who needs it, they'll just put it on individual laptops and think it's okay. And it's really not okay. Because if you have an administrative privilege on that system, you can pretty much do what you want with that particular system.

And it might even allow you to escalate privileges on other systems. So you gotta be really careful with that. So that's why you have CIS control for. Controlled use of admin privileges and let's see what ISO 27,001 has. So ISO 27,001 does have this and they've broken it into parts and have it as password management systems as a dot nine dot four dot three.

They also have managed privileged access rights. There you go right there. So that matches directly to CIS four controlled use. Admin privileges. Let's keep it high. So far, I've gone through a bio, probably about 50 different controls. If you break it into the sub controls, it's probably 50. We just hit, but we'll just keep it high level and just focus on the main security controls.

Now let's move on to CIS five and this one deals with secure. Secure configuration and hardware software. This means like whenever you have a, laptop, a hard a laptop, a workstation, a server, there's a hardening process. Meaning we're gonna take this system and we're gonna make sure it doesn't have default passwords.

Make sure it has it's locked down. The WiFi's not just open and, attaching to anything. Maybe the wifi is off. We have some sort of secure configuration that we put on all hardware and software for mobile devices, laptop. Workstations and servers. This is a common, this is a, best practice. That's using most security frameworks.

So the ISO 27,001 does have this and they have it broken into two parts ex acceptable use of an asset where you would actually secure that system. And then also secure system engineering principles. Let's keep going to maintenance, monitoring, and analysis of audit. So the reason why audit logs in CIS control six is merged with maintenance is because audit logs are used not only for making sure that the incidents if you find any incidents, you can find them through the audit logs, but also for maintenance because every now and then a system goes down and you could put that in the log.

So it goes directly to a server. So you can, your maintenance people can go in and say, okay, let's look at the logs and see where this thing crash. So CIS six actually covers this and it maps directly to two different security controls in ISO 27,001 mainly event logging and clock synchronization. The reason why clock synchronization is important is because if you need a timestamp for all logs, otherwise if, you see that the system went.

You need to know what time it went down. So the actual clock synchronization is super important to event logs at the, and if the time is off, you don't know when an incident happened. You don't know when the system went down or whatever the log is telling you. All right. Let's keep going to CIS seven, which covers email and web browser.

Protections and these just so you know, these are not that much different from CIS controls eight. This is the same one that's so far, these are all the same ones that are in CIS version eight. So anyway, let's keep going here. We wanna know if this maps to ISO 27,001 and it does. So it goes into susceptible use of assets, just like we seen on the, in the previous section.

And then also it goes to restrictions on. Installations and that's what you have for protecting the email and browser protections. Another thing it has is network controls, making sure that the network traffic isn't going all over the place, making sure that we, making sure that the internal, our internal users are not allowed to go to.

Sites that they're not supposed to go to another one that's broken up into in ISEL 27,001 is control against malware. And that's your anti-virus stuff. E electronic messages that is making sure that you have secure messaging going back and forth, making sure that you don't have like email spoofing, things like that.

So it's broken up into several different parts, but let's keep going here to the next section to C I S eight and that's malware defense. This goes really deep into malware defenses for CIS controls those in everything from centralized management of, manage of anti malware software as, as well as ensuring that anti malware software signatures are updated and things like that.

And we do have this on ISO 27,001 name. And the control against malware is where we would find that in ISO 27,001, but there's several other breakdowns in ISO 27,001 that also link to our malware protection. All right, let's keep going to CIS nine. And this goes to limitations and control of network, ports, protocols, and services.

This is a common best practice that you'll find in this 800 you'll find in all of the different frameworks in some way, shape or form, do cover this on how to actually focus in. And use the, law of least functionality is what it's called the nest 800. But anyway let's, go into this one. So we're talking about associating, active ports and services with two asset inventories.

So we need to know is if port 23 is on which systems are using port 23. And ensuring the next one is ensuring only approved ports and protocols are used are running like what we only use in what we need. And you'll find the same thing in ISO 27,000 in one with security of network services and segregation of networks.

And then also network controls. Let's keep going here and see how we can map the next one, which is C I. control 10, which is data recovery capabilities. So this one does map to ISO 27,001, namely in information backups that those two map directly to the CIS data recovery. And this is just what you might think is ensuring that you have regular automated backups making sure that you can recover from those backup.

And, making sure that you protect those backups. All right, let's go to the next one. And we don't have that many more to go here. But this should give you an idea of what's in CIS controls and also what's in ISO 27,001 as well. So let's keep going. CIS control 11. So this is secure configuration of net for network devices, such as firewalls routers and switch.

And if I'm not mistaken, this one might be a little bit different in the CIS eight. It's not the same. The content's the same. They just shifted things around a little bit. So this one is, dealing with maintaining a standard for security configurations for network devices. That's their switches.

That's your routers, that's your firewalls and things like that. And let's see if there's a comparable. Control on ISO 27,001. Yeah, we have change management. This is where you would control the actual iOS security on a system and making sure that you have change management. But the, also the another one that they have here on ISO 27,001 is segregation of networks.

That one is lined up with what you have in CIS controls as well. All right. Let's keep going. C I S 12, and that is boundary defense. Now this is also in N 800. All the stuff that I've read so far is also in missed 800, maybe going forward, we will cover how CIS maps to N 800 because it does it all maps up.

And if one, that's why I say in some of my other courses and in my other videos is if one, you know them. There's a little bit of change of terminology. The control names are different, but if one, you know them all, okay. So this one is dealing with boundary defense, and this is maintaining an inventory of what is in your network.

What you need to know what's in your network. And to do this, you do things like scanning. You do things like denying certain communications from going to certain IPS. You have to control your boundary. In depth is used quite a bit with this one, but boundary defense and this one maps directly to network control.

That's in the ISO 27,001. Okay. Let's keep going here. Let's keep keeping it high level. There's a lot of things that we're going over, cuz we want to keep this high level. Okay. N the CIS control, 13 data protection. What does this one deal with? This is maintaining an inventory of sensitive information removing sensitive data or systems not regularly accessed by the organization.

Anything you don't need, we're gonna get rid of it. And making sure the sense of, data's not floating around out there, which is how a lot of data gets. and ISO 27,001 has addresses this in several different controls. One is classification of information. Another one is network controls, another one's electronic messaging.

And another one is mobile device policies. And there's a few others, but we are gonna keep going. All right. So C I S 14, this one deals with controlled access controlled access. On on the need to know. And so this one is segmenting the network based on sensitivity, enable fi enabling firewall filtering for between VLANs.

And this sounds a lot like PCI compliance. So PCI compliance also maps to the CIS. PCI I'm, talking about PCI DSS, that's protection of credit cards and the credit card industries and retail retailers and hotels use this quite a bit. So they have to actually go through an audit and assessments and stuff for all of their card readers.

So for this one, you have the same thing. ISO 27,001 has segmentation of network. Network control. You can see them, them using the same ones. Theirs is just broken up differently. So they group a lot of, the controls together. Let's keep going here. We don't have that many more to go.

We're on 15 CIS control 15, which is wireless access control. So this one, as you would suspect it, it's disabling access points that are not used if they're not required detecting wireless access points. That are connected to the wired network and, taking an inventory of all your wireless stuff.

And so this is covered in ISO 27,001 in the inventory of assets and the network controls and the acceptable use of AC of, assets. Let's keep going here to the CIS 16. And I think we only have two or three left here, but CIS controls 16. Account monitoring and control. So in, in N 800, And in this 800, you have this one is AC two, a C one C three.

When you're doing account control and account management and things like that, this one is in CIS control 16. So how does this map? Two 27,001. Control. In the inventory of assets, that's where they control it in ISO 27,001. They also cover it in policy on the use of crypto cryptographic controls and control network controls and user registration.

And deregistration so you can see it's just broken up. They're covering the same topics, but it's broken up into different parts. Now let's keep going to CI. Control 17. And I wanna say this is the last one. Let me see. 18, 19 20. Okay. There's only three more left. All right. 17 we'll just quickly go through these implementation of security awareness training.

Self-explanatory you do have the same thing on ISO 27,001. It's literally called information security awareness, education and, training. Same. Okay, so we're gonna go to 18 and 18 is application software security. That's making sure that you're, whenever you're developing software is developed securely and is, establishing secure coding practices.

And you have the same thing over ISO ISO 27001, which is a secure development policy. Whenever you're developing the actual software, you have to develop it securely. Okay. Then we go into 19, which is incident response. This is a big one. This is also in IR in the IR controls, IR 1, 2, 3, and 4 in the NIST 800.

But how does this map over to ISO 27001? They have something called responsibilities and procedures. And they have reporting information, security events, and con contacting authorities. All right. Onto pen testing. So this is CIS control 20. This is penetration testing and red team exercises. And this one, I don't know, this one actually doesn't have a comparable ISO 27001 control, which is.

Very shocking and that pretty much covers all the maps between CIS controls and ISO 27,001. And we also mentioned a couple of N 800 controls and I'll catch you guys on the next podcast.

If you want to download your free copy of the CIS To ISO 27001. Then go ahead and go to https://securitycompliance.thinkific.com/courses/cis-control-maps

View Details

get the xls spreadsheet here:

https://securitycompliance.thinkific.com/courses/cis-control-maps

Hey guys, this is Bruce and welcome to a convo course podcast. And today I want to talk about one thing in particular, and that is the CIS and how it maps to the ISO 27,000. And one, if you didn't know, both of these are security compliance frameworks that are used in the public sector and private sector, as well as international organizations.

So pretty much a little slice of everybody use. One are the two of these particular security frameworks. CIS is typically used for the private sector. That means like retail stores or banking or community centers or those kind of organizations that are private Lee own organization. And sometimes nonprofits.

I'll also say that in having worked in the public sector from time to time, we'll actually use CIS controls as well. It, just depends on what kind of what we're doing. Like we use the CIS benchmarks. I've seen those used within the government within like department of defense, cuz it's just a great tool to use.

And if you're interested in finding this, just go to Google or being or Yahoo or your favorite search engine and just type in CIS controls and. Right now you have a mapping from the CIS controls version 7.1 to ISEL 27,001. Now right now, CIS controls are on version eight. I'm not, I don't think that one's out yet, but right now we are focusing on.

Version 7.1, but we will revisit this once we get version eight. Okay. So that being said, I sell 27,001 is an international standard for information security management. And they both, do the same thing. It's for an organization to have a guidance on how to actually. Proceed as far as securing their entire network, not even just the software and hardware devices that are connected to the network, but also things like physical security, maintenance.

All aspects of protecting the actual security of the system. Whether it's outside of the system whether who's touching the system who has access to the system, all those things let's start from the top. So what we're gonna do is just focus on the main security controls, like CIS control, one that is inventory and control of hardware assets.

And you'll see that the IO 27,001 has something similar in and it's called a.eight.one.one. So inventory of assets, right? They kind of group 'em all together. They don't break 'em apart in individual things for ISO 27,001. Whereas I CIS controls, they break it up into do different things. CIS control one is hardware.

Whereas CIS two is inventory of security controls. I inventory of security sorry, inventory and control of software assets. That is not broken apart by ISO 27,001. They keep those together as a dot eight, do one.one. Let's keep going here. We're gonna go to the next control, which is CIS control three, which is vulnerability management, continuous vulnerability management, every single security compliance.

Framework does have some sort of vulnerability management, our continuous monitoring and vulnerability management they're hand in hand. And this one is no different, so I sold 27,001, let me see let's see if they have it here. They have more of a risk rating response. That's continuously done.

management of technical vulnerabilities. Yeah. So they have a dot 12, do six.one that matches to CIS control three, 3.7, to be precise. Let's go on, keep moving here to CIS control four. And that covers controlled use of administrative privileges. And that's really important because you don't wanna give your admin accounts to everyone.

That's one. One of the things that some organizations do is they'll just give admin rights to everyone, anyone who needs it, they'll just put it on individual laptops and think it's okay. And it's really not okay. Because if you have an administrative privilege on that system, you can pretty much do what you want with that particular system.

And it might even allow you to escalate privileges on other systems. So you gotta be really careful with that. So that's why you have CIS control for. Controlled use of admin privileges and let's see what ISO 27,001 has. So ISO 27,001 does have this and they've broken it into parts and have it as password management systems as a dot nine dot four dot three.

They also have managed privileged access rights. There you go right there. So that matches directly to CIS four controlled use. Admin privileges. Let's keep it high. So far, I've gone through a bio, probably about 50 different controls. If you break it into the sub controls, it's probably 50. We just hit, but we'll just keep it high level and just focus on the main security controls.

Now let's move on to CIS five and this one deals with secure. Secure configuration and hardware software. This means like whenever you have a, laptop, a hard a laptop, a workstation, a server, there's a hardening process. Meaning we're gonna take this system and we're gonna make sure it doesn't have default passwords.

Make sure it has it's locked down. The WiFi's not just open and, attaching to anything. Maybe the wifi is off. We have some sort of secure configuration that we put on all hardware and software for mobile devices, laptop. Workstations and servers. This is a common, this is a, best practice. That's using most security frameworks.

So the ISO 27,001 does have this and they have it broken into two parts ex acceptable use of an asset where you would actually secure that system. And then also secure system engineering principles. Let's keep going to maintenance, monitoring, and analysis of audit. So the reason why audit logs in CIS control six is merged with maintenance is because audit logs are used not only for making sure that the incidents if you find any incidents, you can find them through the audit logs, but also for maintenance because every now and then a system goes down and you could put that in the log.

So it goes directly to a server. So you can, your maintenance people can go in and say, okay, let's look at the logs and see where this thing crash. So CIS six actually covers this and it maps directly to two different security controls in ISO 27,001 mainly event logging and clock synchronization. The reason why clock synchronization is important is because if you need a timestamp for all logs, otherwise if, you see that the system went.

You need to know what time it went down. So the actual clock synchronization is super important to event logs at the, and if the time is off, you don't know when an incident happened. You don't know when the system went down or whatever the log is telling you. All right. Let's keep going to CIS seven, which covers email and web browser.

Protections and these just so you know, these are not that much different from CIS controls eight. This is the same one that's so far, these are all the same ones that are in CIS version eight. So anyway, let's keep going here. We wanna know if this maps to ISO 27,001 and it does. So it goes into susceptible use of assets, just like we seen on the, in the previous section.

And then also it goes to restrictions on. Installations and that's what you have for protecting the email and browser protections. Another thing it has is network controls, making sure that the network traffic isn't going all over the place, making sure that we, making sure that the internal, our internal users are not allowed to go to.

Sites that they're not supposed to go to another one that's broken up into in ISEL 27,001 is control against malware. And that's your anti-virus stuff. E electronic messages that is making sure that you have secure messaging going back and forth, making sure that you don't have like email spoofing, things like that.

So it's broken up into several different parts, but let's keep going here to the next section to C I S eight and that's malware defense. This goes really deep into malware defenses for CIS controls those in everything from centralized management of, manage of anti malware software as, as well as ensuring that anti malware software signatures are updated and things like that.

And we do have this on ISO 27,001 name. And the control against malware is where we would find that in ISO 27,001, but there's several other breakdowns in ISO 27,001 that also link to our malware protection. All right, let's keep going to CIS nine. And this goes to limitations and control of network, ports, protocols, and services.

This is a common best practice that you'll find in this 800 you'll find in all of the different frameworks in some way, shape or form, do cover this on how to actually focus in. And use the, law of least functionality is what it's called the nest 800. But anyway let's, go into this one. So we're talking about associating, active ports and services with two asset inventories.

So we need to know is if port 23 is on which systems are using port 23. And ensuring the next one is ensuring only approved ports and protocols are used are running like what we only use in what we need. And you'll find the same thing in ISO 27,000 in one with security of network services and segregation of networks.

And then also network controls. Let's keep going here and see how we can map the next one, which is C I. control 10, which is data recovery capabilities. So this one does map to ISO 27,001, namely in information backups that those two map directly to the CIS data recovery. And this is just what you might think is ensuring that you have regular automated backups making sure that you can recover from those backup.

And, making sure that you protect those backups. All right, let's go to the next one. And we don't have that many more to go here. But this should give you an idea of what's in CIS controls and also what's in ISO 27,001 as well. So let's keep going. CIS control 11. So this is secure configuration of net for network devices, such as firewalls routers and switch.

And if I'm not mistaken, this one might be a little bit different in the CIS eight. It's not the same. The content's the same. They just shifted things around a little bit. So this one is, dealing with maintaining a standard for security configurations for network devices. That's their switches.

That's your routers, that's your firewalls and things like that. And let's see if there's a comparable. Control on ISO 27,001. Yeah, we have change management. This is where you would control the actual iOS security on a system and making sure that you have change management. But the, also the another one that they have here on ISO 27,001 is segregation of networks.

That one is lined up with what you have in CIS controls as well. All right. Let's keep going. C I S 12, and that is boundary defense. Now this is also in N 800. All the stuff that I've read so far is also in missed 800, maybe going forward, we will cover how CIS maps to N 800 because it does it all maps up.

And if one, that's why I say in some of my other courses and in my other videos is if one, you know them. There's a little bit of change of terminology. The control names are different, but if one, you know them all, okay. So this one is dealing with boundary defense, and this is maintaining an inventory of what is in your network.

What you need to know what's in your network. And to do this, you do things like scanning. You do things like denying certain communications from going to certain IPS. You have to control your boundary. In depth is used quite a bit with this one, but boundary defense and this one maps directly to network control.

That's in the ISO 27,001. Okay. Let's keep going here. Let's keep keeping it high level. There's a lot of things that we're going over, cuz we want to keep this high level. Okay. N the CIS control, 13 data protection. What does this one deal with? This is maintaining an inventory of sensitive information removing sensitive data or systems not regularly accessed by the organization.

Anything you don't need, we're gonna get rid of it. And making sure the sense of, data's not floating around out there, which is how a lot of data gets. and ISO 27,001 has addresses this in several different controls. One is classification of information. Another one is network controls, another one's electronic messaging.

And another one is mobile device policies. And there's a few others, but we are gonna keep going. All right. So C I S 14, this one deals with controlled access controlled access. On on the need to know. And so this one is segmenting the network based on sensitivity, enable fi enabling firewall filtering for between VLANs.

And this sounds a lot like PCI compliance. So PCI compliance also maps to the CIS. PCI I'm, talking about PCI DSS, that's protection of credit cards and the credit card industries and retail retailers and hotels use this quite a bit. So they have to actually go through an audit and assessments and stuff for all of their card readers.

So for this one, you have the same thing. ISO 27,001 has segmentation of network. Network control. You can see them, them using the same ones. Theirs is just broken up differently. So they group a lot of, the controls together. Let's keep going here. We don't have that many more to go.

We're on 15 CIS control 15, which is wireless access control. So this one, as you would suspect it, it's disabling access points that are not used if they're not required detecting wireless access points. That are connected to the wired network and, taking an inventory of all your wireless stuff.

And so this is covered in ISO 27,001 in the inventory of assets and the network controls and the acceptable use of AC of, assets. Let's keep going here to the CIS 16. And I think we only have two or three left here, but CIS controls 16. Account monitoring and control. So in, in N 800, And in this 800, you have this one is AC two, a C one C three.

When you're doing account control and account management and things like that, this one is in CIS control 16. So how does this map? Two 27,001. Control. In the inventory of assets, that's where they control it in ISO 27,001. They also cover it in policy on the use of crypto cryptographic controls and control network controls and user registration.

And deregistration so you can see it's just broken up. They're covering the same topics, but it's broken up into different parts. Now let's keep going to CI. Control 17. And I wanna say this is the last one. Let me see. 18, 19 20. Okay. There's only three more left. All right. 17 we'll just quickly go through these implementation of security awareness training.

Self-explanatory you do have the same thing on ISO 27,001. It's literally called information security awareness, education and, training. Same. Okay, so we're gonna go to 18 and 18 is application software security. That's making sure that you're, whenever you're developing software is developed securely and is, establishing secure coding practices.

And you have the same thing over ISO ISO 27001, which is a secure development policy. Whenever you're developing the actual software, you have to develop it securely. Okay. Then we go into 19, which is incident response. This is a big one. This is also in IR in the IR controls, IR 1, 2, 3, and 4 in the NIST 800.

But how does this map over to ISO 27001? They have something called responsibilities and procedures. And they have reporting information, security events, and con contacting authorities. All right. Onto pen testing. So this is CIS control 20. This is penetration testing and red team exercises. And this one, I don't know, this one actually doesn't have a comparable ISO 27001 control, which is.

Very shocking and that pretty much covers all the maps between CIS controls and ISO 27,001. And we also mentioned a couple of N 800 controls and I'll catch you guys on the next podcast.

If you want to download your free copy of the CIS To ISO 27001. Then go ahead and go to https://securitycompliance.thinkific.com/courses/cis-control-maps

View Details

Hey guys, this is Bruce and welcome to another convo course of this podcast. And today I want to talk to you guys about what's been going on in the last few months. I've been able to actually travel while I was between jobs and because I have a high-paying cyber security job, I had one anyway. I was able to quit.

My job. I had some family issues like I had to take care of. And my, job was, it was a very high level high stress job. So I was a consultant for all these different organizations and it was just, it was really stressful. And I had all these severe family issues that I needed to take care of. And the, actually the corporation that I worked for was really, kind.

And my boss was, took me aside and said, Hey man, if whatever you need we'll, let you. Had to let check a sabbatical and all that kind of stuff, which was very kind, very sweet very good company actually. But the, problem was I had so much travel and I was, I'm a remote worker there, but it was just too much travel.

So I couldn't make that match what I was doing with my home life. So I, went ahead and just, I had to leave, but in between I knew I was gonna get another job. Actually, my. Side hustles have been doing so good. I thought maybe that I could just live off of that for some time, but the medical stuff was too high to the medical here in the us is really bad if you didn't know.

Anyway, so neither here nor there. I couldn't afford to actually live off of my. My businesses and my all my income streams and stuff. So I'm processing, as in processing stuff, I've did a whole bunch of interviews and everything. I learned quite a bit more about the current state of getting jobs in cyber security.

But I was able to get one pretty fast and it was, I was able to get something I really wanted. So a hundred percent remote position making the kind of money I wanna make. And for, and just to give you guys some social proof. what I've been doing. These, if you go to TikTok, a lot of the stuff I posted on TikTok was there's a lot of these videos that I did directly from my travels.

Here's let me show you one. Here's one right here where I'm on. I'm in Manila beach, I think so. Yeah. That's Manila beach right there. That's the embassy behind me in Manila. So yeah just did a whole bunch of videos. I was gonna. I was gonna go to all these other sites. I was gonna go to Bali and go to Singapore and, places like that.

But I, I just didn't, we had some issues with the flights. So I was just, I just ended up staying in the Philippines the whole time, but I just wanted to let you guys know, like what's possible because I was I'm working this high level job was able to save some money and able to go. Actually take a break for three months.

I've been off of work for three months and I could afford it because I just had, I had money and savings. I had all these other resources that I created. And so that's why I, was able to do it, but now I'm going back to work and everything. And I'm not sad about it, but I, would've been a lot happier if my business would've been able to support me and sustain my family for that whole time.

But unfortunately unfortunately not . So yeah, thanks everybody for watching me doing this live once again on, on the podcast. And I wanted to talk to you guys about a few things, show you my, new podcast and where that stuff is at. I'm gonna show you the new book that I have. That's coming out to show you to do exactly what I've been doing.

It's gonna break all that stuff down and give you a preview of what that's all. and and then I'll just answer some questions. We'll just, we'll keep it loose on this one. Let me show you another picture. This is me. I, was on a rooftop hotels, like a resort. It was really nice.

And I'm just telling, talking about showing like me actually doing it and. I've been able to do it by marketing myself. So that's what this video's all about. The video just shows me on the rooftop, jumping in a pool having a good life I wanna show other people how to do it.

Exactly what I did. It really works, but let me show you gonna be a book about marketing yourself in cyber security, how to create a resume in cyber security in particular, but it, you can also use it for it or whatever field you're in. Really like the techniques will work in any field, but I want to focus on cyber security cuz that's where that's what I've been doing for the last 20 years.

So cyber security and it jobs resume marketing. I'm gonna put this on Amazon. I'm gonna put this on my own personal website and I'll, there'll be two different versions and I'll have an audio version of this book. And what I'm gonna talk about is essentially how to get a path, how create a path in cyber security, cuz there's many cyber security is a huge field.

So whenever somebody says, oh, I'm want to get in cybersecurity. It's okay what, exactly do you wanna do in cyber security? Cuz there's forensics. There's incident responders, there's cyber security analysts, there's security compliance people. There's information to security officers.

There's engineers, architects, there's CIO, CSOs. There's all different kinds of roles and different kinds of fields within. Within cyber security, crypto cryptography is also a part of considered a part of cyber security as well. So it's just a huge field and it depends on what you're doing.

Yeah, here's the book it's gonna talk about, like the format you should use. I'm basically showing everything I've been doing and it's really been world. You wanna be spoon fed that stuff and ask me questions directly. Then that's the course expected results. All I do is talk about what, I'm experiencing.

Like I get calls all the time. I can name my price. If I want to go. If I'm willing to travel, I can name my price. I, tell you how to create a profile, how to put yourself out on all these sites and then how to get all the continuous calls. And not only that, but how to. Get the actual format that you need.

That's gonna sell yourself. That's gonna be able to be digestible by all these organizations and employers who want you. They're looking for people right now. Cyber security is a huge field and we really don't have enough people doing it. Unfortunately, it's getting so crazy that they're even taking in a lot more entry level people than before.

There's lots of opportunities if you've been watching my, my, if you watched my last podcast, I talked about how those out there. And here, they are right here so far. If you want this directly from the site, go, if you happen to be watching me on YouTube, you can click on the link description below, and then it'll go to this site right here, but it's combo courses dot podcast, pod bean.com.

And, you'll find it there. All right. Let me see, what else do I need to talk about? What else do I need to talk about? Oh yeah. So that book that I'm writing a cyber security book. That's gonna tell you exactly what I've been doing to market myself and get a lot of different opportunities to get into cyber security and information technology in general.

So I'm constantly getting emails, messages, text calls all day long. Maybe I'll probably get an average of. with everything probably six or seven on average a day. Sometimes it's way more. It's actually quite annoying. And now that I actually chose a job, I have to turn all that stuff off. It's just so many opportunities.

It's a good problem to have to constantly be sorting through all of these different jobs and stuff. And out of those tons of jobs out of a hundred jobs they're, probably about 30 of them or not 13 of them that I'm. Or yeah, this is a good one. I'm gonna do an interview with this, with these guys so that's what I'm gonna show you guys how to do, but the second book, it's gonna be a two book series.

The second book is gonna be based off of this. What you see here on the screen. If you happen to be listening to me, this is the nice framework. So this is an organization called the national initiative for cyber security, careers and studies. These guys have been around for quite some time and what they did.

Brilliant. They broke down all the main categories of cyber security in the cyber security workforce. And these categories include there's seven of them and analyze, collect and operate, investigate, operate, and maintain, oversee, and govern, protect, and defend. And then securely provision. And let me just show you like what this is all about.

Like you might be like what, does this have to do with your book? Let me just explain to you, so what I'm gonna do is I'm gonna break this down and make it so that it's understandable to, to everybody, like I'm gonna relate this directly to your, you getting a job, because like I said, cyber security is a huge field.

What these guys did was they broke it all down. If you go to this site, it's like a huge database. and they have specialty areas in each category, right? So what I'll do I take you to my category? So my category is called oversee and govern. And so this is where a lot of managers, cyber security management, executive cyber cyber leaders are at legal advice, policy procedures, things like that, education, all that kind of stuff, because.

It's not usually hands on type stuff. It's more of you're overseeing what's going on. You're making sure everything is being going in the right direction. So my specialty is really this one right here, which is security information system, security managers, and then they have different work roles that, that breaks this breaks in further down into work roles.

And so it has abilities knowledge, skills, tasks. And, other things that you need to know, if you're trying to get into this actual work role and it, furthermore, what you can do is, and what I'll do in my book is I break this down into even relate it to directly, to like LinkedIn and indeed and all that stuff.

So you can see direct correlation between the categories. That they've broken down here. And actually the categories that are in all cyber security that's cuz that's what they did. They just took seven categories and said, okay, this is how cyber security breaks up. And then they broke that down further into specialized skills.

And then they broke those into work roles. so I'm gonna take this stuff and relate it directly to how you can take stuff from indeed stuff from LinkedIn and find your niche that you can actually get into in cyber security. And then once you find your niche, once okay, I wanna be in information security officer.

I want to be an information security. I wanna be a COMSEC manager. Then what I'll do is I'll show you how to find. What exact degree you need, if you need one, cause some, don't even need a degree, bro. Some don't even need a degree. Some like just need specific skills, but it'll tell you exactly what skills you need.

Exactly what keywords to use on your resume. Exactly. What everything time you can check out this site is, that. Let me see if I can give you guys the link here. If you go to actually, if you go to Google and just type in cyber security workforce, nice. In N I C E, that right there will guide you to this site that I'm showing that I'm, that you see here.

It's pretty robust. There's a lot of things going on with this site, cuz these guys are very, active and the department of defense. As well as DHS and all these different agencies use these guys as a reference to know exactly what skills and tasks that are needed to do cyber security. Federal government relies on this, what you see here very heavily.

So that's why I decide to make a book about it, to boil it down its stuff, practical knowledge that you can use for your career. Two book series gonna tell you how to market and then how to get the proper career path of what, you want in this field. All right. Let's get into some questions.

This was not gonna be too long of a podcast. I'm going to go to, I've got a lot of questions popping up in TikTok. Shockingly enough. I did not expect this, but I've got about 2000 followers there so far and. A bunch very, active a lot of questions here, but let me see if I can answer a couple before I leave.

Lemme see here, if you're interested in following me on TikTok, just go to combo courses, go to TikTok and then search combo courses. Okay. So it says, somebody asked me I'm in the healthcare field and I'm. Trying to go with the security plus and the H C I S P which is like a healthcare cyber security certification from ISD two squared to stay relevant.

Any tips? Yeah. So this is great. Like this, is an awesome, and I'm gonna make another video about this specifically on TikTok, but I wanted to speak to this on with the podcast. For this as you're going to security, plus, as you're going to H C I S P I would actually do some labs in your house.

One of the best things, one of the most, one of the best ways to go deeper. And into this subject is actually have a lab in your house lab. That means get a separate computer, or you can actually do it on your computer that you use, get your laptop, your whatever workstation you use in your house. And you can use something called VMware and you can put different operating systems on that computer.

Or you can just buy a whole nother computer, build it from scratch, and then put the security features on that. That's a little bit more expensive with VMware. It allows you to I, don't think it's more in about 200 bucks VMware itself the software sounds, and that sounds pretty expensive, but you're investing in yourself.

So just think of it like that. You're investing in yourself, VMware. It works, but for now, I'm just gonna go to the site just to show you how you can create a lab, on your computer. So VMware is a virtual manager and it will, it's an application that sits on. system on your computer, and then you can upload like Linux on it.

You can have different versions of windows. You can have Mac all on the same computer, and then you can network 'em together. And it's really cool. It's a really great way to learn how to do whole space firewalls. You can actually, I think you can even put like different firewalls on it. You can put a NAS on it, a firewall.

You can have whole little tiny network. If you wanna do this for free. If you like, especially if you're in a networking, there's another thing you can do called GNS three. This is something I used to use to, to practice for CCNA G I used to have a CCNA. I used to be huge into network. it's been a while.

So G N S three. So GNS three is actually is free. The only thing that's gonna cost you is your time to figure it out because it's, like a open, last time I checked it, it was an open source simulator. That simulates network environments. Really, cool. It's actually free. Oh, is it not free anymore software that empowers it free download.

It's not free. It looks like it's not free. It. Why is this site all fancy now? Oh man. they do this. They put it out for free for a while. Wire shark used to be free too. I think I wanna say NEIS it was even free at one time. Yeah. Look, how many people use this? Anyway, so you download GNS three and it's a virtualized network and you can literally set up a little it's so cool.

Like it's this is one of another, one I like to do like a demonstration of it's really, cool. It allows you to configure log in and configure routers and switches and. Messing around with routing protocols and all kinds of stuff is really cool. So yeah, I would, that would be my advice to you is if you're going for a security plus a H C I S P and you're trying to get into this field, especially if you don't have experience, create a lab, put it on your laptop, start messing around with it.

So you can then start to understand the inner workings of it. All right. Next question. Dru says, Bruce, in your opinion, what is the most, what is a acceptable salary range for a new is SM or is O so it really depends. That's a great question. By the way, it really depends on where you're at in the United States.

And here's why I say that because if we type in ISO pay scale ISO pay scale, watch. It's gonna it's they have a price range, but it really depends. What you'll notice is it depends on what area you're in and it also depends on what, clearance you have, what's the organization. What you're seeing here is, typical of somebody with experience one 30 and these are in Colorado, California, and cer and I think this is Connecticut.

What I wanna see is the actual pay scale. Here it is. So the national average is over a hundred thousand dollars, $56 an hour. That's the national average. Now what this doesn't factor in, I don't think is how many years of experience the person has or if they have other additional certifications or things like that.

National average, that's pretty good for a national average. If you think about it, cuz that takes into account. All the way, the high, the highest level of pay down to the lowest levels of pay. Let me see, if I can find some more. Okay. The national average in Colorado, where I'm at the average is about one twenty three, a hundred twenty 3000.

And that's about right. That's about right. And independent on how much more experience you have. It'll be more. And I could tell you that if you're in the Virginia area, this is low, like 100. Is low, but I, would say it's around this. This is about right. For somebody starting off from scratch, you might come in lower.

If you've, if you have zero experience with it and you're coming in off like maybe you had some experience in the military or something like that. I, could tell you my first job outside the military as an ISSO I had a bachelor's degree, but I didn't have the required certifications.

They required a CI S P at the time. And I didn't have one. So what they did was they just brought me in and said, look, you have X amount of time to get a, cert this certification. Can you do it? I said, yes. So they hired me at 60, 60,000, 62,000, something like that, but which was very low. And, but keep in mind that this was how many years.

Damn. It's been a long time. 10, 15 years ago. It was like 15 years ago. So 10 years ago that's quite a bit of wild that's dang, 2004, 2006. Damn. That was a long time ago. 14 years ago. Wow, man. Time flies, anyway. Yeah, that was like 14 years ago. It's obviously the price has gone up so 70 between, okay.

Let me give you a range. If you are a new, is. A new information system, security manager or information security officer will say, officer first, cuz manager is different. Manager's a whole different range. Let's say an information system, security officer. The range is between, I wanna say depends on where you are in the United States, but I wanna say it's gonna be between about 70 and a hundred.

That's about right. For a new person. Now keep in mind. They know your value, especially once you start getting those certifications. So what you wanna do is no matter what they're paying you, when you get in, get a certification, a security plus a, CI S P a CI S a C risk get some sort of I would highly recommend a professional level security, cert like a CASP, a CI S P a C risk, a CIS, a one of those.

Not easy search by the way. And they do cost you, but once you get that, yeah you'll, be over. You'll be able to switch to another position, new job, somewhere as an ISSO that, or they'll pay you to stay and you'll be able to make over 115, at least 115 or, more. So that should answer that question.

Now you also ask a question about CI SM, which is a different position. CI SMS are usually the supervisors of a CI. C I S O a is SS O man I'm slipping. So an is SM is usually a manager of an is S O so let me show you what I'm talking about here. Managers are usually gonna make a little bit more cuz they're managers, but let's see if I'm not lying to you.

See if I can find the average of a okay. It's not coming up here. I don't know why. Oh, is he trying to search just in Colorado? What is up with that? Okay, let me go back one to see if I could find the average okay. Keeps wanting to search in Colorado USA or what I'm doing is I'm on zip recruiters and I'm looking at their, they've got a, like a little breakdown.

of this. So actually let's let's get outta this. Let's go, back to Google and find another management position. I, guess it's lumping it right in with ISS O okay. And actually the saying is lower for some reason that's inconsistent. Oh, okay. The No, This is saying it's a little bit lower.

That's weird. Which I don't think is correct because a ISSM is a manager, typically, especially in the federal government they, have two different positions. Like one is ISS, M will usually be over ISS OS and they'll usually be the person who signs for the, is S O and manages the ISO's work. So they usually make more, it's usually like a management type.

so that is that's incorrect. I would say is probably in more in the range of one 20 to one 40 and on up. So for an ISSM man glass door is even saying it's lower. That's not been my experience. Oh, okay. No glass door saying the average. For an ISSM is one 20. Yep. So there you go. That, was my guess would be more like one 20.

It is up the scale goes up like 10,000, something like that, just cuz you can see here that they're saying that the, average low on the low end is about 67 to 80. And all the way up to $290,000 is insanity. But yeah, so that's about right. 1, 1 20 is what I was saying. ISSM is gonna make, okay. Let me see if there's any other questions here.

I got some folks watching the stream here, watching the podcast, listening to the podcast. VMware GNS three are, golden for learning. Yeah. Apple work. Yeah, for sure. Okay, let me see if there's other questions. I have so many questions popping up on TikTok. It's very, active for questions. Somebody called me a scam.

It's free stuff. I give away, man. I don't know what people are thinking to be honest with you. Which is the best path for an at home job jobs only. Okay. So somebody asked me, I've had this question before, what are the best jobs? For at home jobs, remote work, what are the best, I guess it jobs, information, system, security, officer jobs.

Information security, cyber security type jobs, or it jobs for work from home these days after COVID I would've had a different a different thing to say about this, but these days mostly. Let me put it to you this way. I can tell you what jobs are, not compatible with remote work.

Let me start from there because nowadays you can do so many jobs, remotely and, more organizations and employers are now more open to remote work, which is I've been doing this before. COVID so it was a lot harder to get remote work before this. Anyway Jobs that are not conducive to remote work would be classified positions.

In my opinion, in my experience if, you're in a classified environment, if you're trying to get work at a especially if it's secret and above it's, harder to have a hundred percent remote. Normally what they'll do at, the most they'll have a a flex position. flex hours are flex.

I can't remember what they call it, but basically it's like a hybrid That's what they call it. So they'll say, okay, two days out of a week, you can be at home. And then the other three days out the week work of the work week, you have to be at the site or two days are vice versa, like two days on the site and then three days off site.

So they'll do stuff like that. But see, the thing is you have to. There, you have to be on site a lot of times to do the site, the security stuff the, classified stuff. But that being said there's, actually some people like a friend of mine, really good friend of mine. He was telling me about how there's this innovative new technology where you can actually do even classified work from home jobs.

So even that is gonna be work from home more and more and I'm talking about all the way up to Ts and he, once he explained to me how that's done I was, my mind was blown. I was like, holy crap. That makes sense. But anyway, most of those jobs right now are normally you can't do those remotely.

Another one that's deceptive are jobs where you have to travel a lot. The problem with those is they'll say, oh, it's a hundred percent remote, but. You're traveling so much that doesn't even matter, like some of the consulting and some of the professional services jobs, they require you to go on site.

If, they, if it's over, I'll put it to you like this. If the travel is over, if it's over 50%, then you're gonna be traveling a lot because you gotta factor in. Probably add another 20% for the travel days. Yeah. So if it's over, if it's 50 if it's even close to 50%, that is CR that is a lot of travel.

Like you, I, cuz I did a job like that and I was constantly on the road and the only time. I think mine was 60 to 75% travel. I was never home. I was never home. would come home for the weekend and then I was off again, like I'd have a three day weekend and I'd be traveling for the rest of the week. So it was brutal, man.

It was work from home, but I just, I was traveling all the time. So if it's any of those jobs and normally the other one I would say, okay, so we talked about classified jobs. Normally those are on site or some kind of a hybrid. Those are changing, but most of the jobs are you're gonna have to go on site.

The other one would be consulting where you're traveling a lot, cuz you have to go to all these different places. And then the other one would be if they really want you to have FaceTime with the customer. And that usually requires being on site, those off the top of my head, the ones that out of all the ones I've been offered that I've worked at personally, that's been my experience.

But if you guys can name any other places where it's pretty much, you have to be on site field text. That's another one that one's not gonna be well it's it says it is gonna, it can be remote, but you're traveling so much that it might as well not be remote cuz you're never home. Yeah.

Hope that answers your questions. Most jobs off the top of my head. Cyber, a lot of cybersecurity jobs can be done remotely. Remote administration, you can do system administrator jobs, a lot of those remotely. You can do networking a lot of those networking jobs, remotely configuring firewalls, monitoring traffic.

A lot of those you can do remotely. Just name something. Most of 'em you can do remotely. It really depends on the organization. So just keep that in mind. Okay. Let me keep going. okay. Somebody said it is back on the topic here. Somebody said it is difficult to to impossible to get a fully remote. There is zero chance that I would work and take the added risk of doing classified work remotely.

Yeah. So the technology that was in place was it was like a virtual machine, nothing stored on your computer, basically. It's you're seeing, it's like you're seeing images. Like your whole desktop and everything is just images that you're seeing. But the, risk for me is that if you're in your house, you've got things like you've got other what if your daughter is on the phone over here?

And they have their phone they're on speaker phone and you happen to be doing a you're on a secure line on. System and you're doing classified work and then they can hear what you're saying, so there's a possibility of a security incident because it got leaked to somebody. I don't know.

There's just I'd be nervous about it myself to be honest with you Dru says after C or it travel jobs still plentiful. Yes. I know the go. in the government for the government. It has slowed down quite a bit. Yet there's still a lot of travel jobs, but you're right. There's a lot of customers and clients.

And the last job I worked at without giving too much away last job I worked at I I was a, consultant. I was a cyber security consultant and we would, our biggest part of, one of the biggest part of our jobs is that we would have, we'd have all these assessments and we would. To a site.

We, we would go to the site and we'd do physical assessments and we'd do wireless assessments. You have to be on the site for those. So we would go there and sit down with the facility manager and ask them, que interview them and then walk around the facility and all this kind of stuff. And then you'd do a report like you say, okay you're good here.

Good. Here you have a checklist, all that kind of stuff. But a lot of clients were like, nah, you can't come to our site or you can come to this site, but you can't come to this site. So you have a point because of COVID travel has been. Restricted, but there is, it's starting to open up quite a bit lately.

Like right before I left, they were opening things up. Like it, it was opening up like crazy because Mo most places in the us are opening up with the exception of there's a few places. Like we had some overseas places that were still pretty, pretty locked down, pretty tight.

Exactly skiffs are skiffs for a reason. yeah. Okay. Let me see if I can answer if there's any other questions here. Tons of questions and interactions on TikTok. I'm really surprised about TikTok. Somebody asked me, okay, this is a good question. Couple questions that are related. Somebody asked me if they can do cyber security at age 30 and another person asked me if they could do it at age 45.

And I would say. As a matter of fact, cybersecurity lends itself to a more mature minded person. Because you have to do a lot of interaction. As a matter of fact, like this career field is pretty old. I don't say so myself, but the last place I worked at I wasn't the youngest guy, but I I'm pushing 50 man.

Like I, I, wasn't the youngest guy there and. so I was not the youngest or the oldest guy there. So it, this career path needs more mature people because you're dealing with pretty heavy, issues. And you're having to talk to, you have to have the maturity, the emotional intelligence to talk to high level, cyber security CISOs and C level execs and stuff.

And then you gotta be able to switch gears and then talk to a technical. and because of that, it lends itself to a more mature type of person who can handle, stress and not freak out. And who've been around the block enough to know, okay. Yep. Don't worry. Like we got this and not panic.

So you need somebody with a cool hand. And a lot of times even me, I've been doing this for 20 years, but August school, like the last place I worked at, there were, so there were people there who were masters at this and I'm like, I man, these guys were running circles around me. I thought I was pretty good at presentations and stuff, man they were killers.

They just like something bad would happen. Something horrible in cyber security. So many bad things could happen that we're in the business of preventing bad things from happening to your assets. Something would happen and the client would lose their damn minds and they'd be a younger.

Who can't handle any kind of pressure and they freak out and they they'd freak out and then have another person, like my mentor, who was at that job, that person would just be calm and just calm them down. Just talk 'em off the ledge, negotiate with them. And then next thing you know, they're no longer holding hostages like they were.

So good at speaking to cus clients and customers, and that level of maturity is, really necessary. Yeah, 45, like as long as you can get the concepts down, as a matter of fact if you don't wanna do another two years of if you don't want to sit down and do two years of learning all this new it, you could actually do something like a program.

Project manager is actually a really great position for an older person. Project manager is. Compliance the stuff I'm doing something like that. Something where you're not super like in the weeds, technically, because there's a lot going on with like firewalls are constantly evolving and changing.

And like a web technology is constantly evolving, changing, and man, to keep up with the server technology it's constantly going constantly moving constantly and you're having to constantly hit the books and stuff. So that could be. As you get older, you have all this other stuff going on in your life.

Whereas youngsters they're just now coming in and taking on new responsibilities. So the work is everything for them. They don't have maybe they have one kid or something, but they don't have necessarily grandkids or five kids or whatever, so they have, they can devote more of their time to this learning this new technology and stuff.

But if you, I would highly recommend especially if you're older, you already have done two or three different career paths and you're doing this so you can retire and, live a simpler life. Man I would recommend project management get P and, also it really needs more mature people like people who can handle pressure and not freak out people who are calm as a cucumber, this calm, this, and they can just work in any environment because they've, seen some. So they got that, that thousand yard stairs. We used to call it in the military. They've seen some shit so older people like, yeah, I, it is, you could definitely do this as an older person. All right. I think that's it guys.

Thanks for watching. I've been talking for about 30 minutes. I'm gonna try to do more like one offs like this, instead of just doing 'em once a week more Podcast. And if you're interested in hearing a lot more, cuz I actually post more stuff on on audio go to combo courses.podbean.com or checking the link description below and you'll have more access to all the stuff that I put out.

In some old podcasts I've been posting. All right guys, that's it for this one. Thank you so much. De truth. Thank you. S V T. Thanks for all the questions on TikTok.

View Details

Hey guys, this is Bruce and welcome to another convo course of this podcast. And today I want to talk to you guys about what's been going on in the last few months. I've been able to actually travel while I was between jobs and because I have a high-paying cyber security job, I had one anyway. I was able to quit.

My job. I had some family issues like I had to take care of. And my, job was, it was a very high level high stress job. So I was a consultant for all these different organizations and it was just, it was really stressful. And I had all these severe family issues that I needed to take care of. And the, actually the corporation that I worked for was really, kind.

And my boss was, took me aside and said, Hey man, if whatever you need we'll, let you. Had to let check a sabbatical and all that kind of stuff, which was very kind, very sweet very good company actually. But the, problem was I had so much travel and I was, I'm a remote worker there, but it was just too much travel.

So I couldn't make that match what I was doing with my home life. So I, went ahead and just, I had to leave, but in between I knew I was gonna get another job. Actually, my. Side hustles have been doing so good. I thought maybe that I could just live off of that for some time, but the medical stuff was too high to the medical here in the us is really bad if you didn't know.

Anyway, so neither here nor there. I couldn't afford to actually live off of my. My businesses and my all my income streams and stuff. So I'm processing, as in processing stuff, I've did a whole bunch of interviews and everything. I learned quite a bit more about the current state of getting jobs in cyber security.

But I was able to get one pretty fast and it was, I was able to get something I really wanted. So a hundred percent remote position making the kind of money I wanna make. And for, and just to give you guys some social proof. what I've been doing. These, if you go to TikTok, a lot of the stuff I posted on TikTok was there's a lot of these videos that I did directly from my travels.

Here's let me show you one. Here's one right here where I'm on. I'm in Manila beach, I think so. Yeah. That's Manila beach right there. That's the embassy behind me in Manila. So yeah just did a whole bunch of videos. I was gonna. I was gonna go to all these other sites. I was gonna go to Bali and go to Singapore and, places like that.

But I, I just didn't, we had some issues with the flights. So I was just, I just ended up staying in the Philippines the whole time, but I just wanted to let you guys know, like what's possible because I was I'm working this high level job was able to save some money and able to go. Actually take a break for three months.

I've been off of work for three months and I could afford it because I just had, I had money and savings. I had all these other resources that I created. And so that's why I, was able to do it, but now I'm going back to work and everything. And I'm not sad about it, but I, would've been a lot happier if my business would've been able to support me and sustain my family for that whole time.

But unfortunately unfortunately not . So yeah, thanks everybody for watching me doing this live once again on, on the podcast. And I wanted to talk to you guys about a few things, show you my, new podcast and where that stuff is at. I'm gonna show you the new book that I have. That's coming out to show you to do exactly what I've been doing.

It's gonna break all that stuff down and give you a preview of what that's all. and and then I'll just answer some questions. We'll just, we'll keep it loose on this one. Let me show you another picture. This is me. I, was on a rooftop hotels, like a resort. It was really nice.

And I'm just telling, talking about showing like me actually doing it and. I've been able to do it by marketing myself. So that's what this video's all about. The video just shows me on the rooftop, jumping in a pool having a good life I wanna show other people how to do it.

Exactly what I did. It really works, but let me show you gonna be a book about marketing yourself in cyber security, how to create a resume in cyber security in particular, but it, you can also use it for it or whatever field you're in. Really like the techniques will work in any field, but I want to focus on cyber security cuz that's where that's what I've been doing for the last 20 years.

So cyber security and it jobs resume marketing. I'm gonna put this on Amazon. I'm gonna put this on my own personal website and I'll, there'll be two different versions and I'll have an audio version of this book. And what I'm gonna talk about is essentially how to get a path, how create a path in cyber security, cuz there's many cyber security is a huge field.

So whenever somebody says, oh, I'm want to get in cybersecurity. It's okay what, exactly do you wanna do in cyber security? Cuz there's forensics. There's incident responders, there's cyber security analysts, there's security compliance people. There's information to security officers.

There's engineers, architects, there's CIO, CSOs. There's all different kinds of roles and different kinds of fields within. Within cyber security, crypto cryptography is also a part of considered a part of cyber security as well. So it's just a huge field and it depends on what you're doing.

Yeah, here's the book it's gonna talk about, like the format you should use. I'm basically showing everything I've been doing and it's really been world. You wanna be spoon fed that stuff and ask me questions directly. Then that's the course expected results. All I do is talk about what, I'm experiencing.

Like I get calls all the time. I can name my price. If I want to go. If I'm willing to travel, I can name my price. I, tell you how to create a profile, how to put yourself out on all these sites and then how to get all the continuous calls. And not only that, but how to. Get the actual format that you need.

That's gonna sell yourself. That's gonna be able to be digestible by all these organizations and employers who want you. They're looking for people right now. Cyber security is a huge field and we really don't have enough people doing it. Unfortunately, it's getting so crazy that they're even taking in a lot more entry level people than before.

There's lots of opportunities if you've been watching my, my, if you watched my last podcast, I talked about how those out there. And here, they are right here so far. If you want this directly from the site, go, if you happen to be watching me on YouTube, you can click on the link description below, and then it'll go to this site right here, but it's combo courses dot podcast, pod bean.com.

And, you'll find it there. All right. Let me see, what else do I need to talk about? What else do I need to talk about? Oh yeah. So that book that I'm writing a cyber security book. That's gonna tell you exactly what I've been doing to market myself and get a lot of different opportunities to get into cyber security and information technology in general.

So I'm constantly getting emails, messages, text calls all day long. Maybe I'll probably get an average of. with everything probably six or seven on average a day. Sometimes it's way more. It's actually quite annoying. And now that I actually chose a job, I have to turn all that stuff off. It's just so many opportunities.

It's a good problem to have to constantly be sorting through all of these different jobs and stuff. And out of those tons of jobs out of a hundred jobs they're, probably about 30 of them or not 13 of them that I'm. Or yeah, this is a good one. I'm gonna do an interview with this, with these guys so that's what I'm gonna show you guys how to do, but the second book, it's gonna be a two book series.

The second book is gonna be based off of this. What you see here on the screen. If you happen to be listening to me, this is the nice framework. So this is an organization called the national initiative for cyber security, careers and studies. These guys have been around for quite some time and what they did.

Brilliant. They broke down all the main categories of cyber security in the cyber security workforce. And these categories include there's seven of them and analyze, collect and operate, investigate, operate, and maintain, oversee, and govern, protect, and defend. And then securely provision. And let me just show you like what this is all about.

Like you might be like what, does this have to do with your book? Let me just explain to you, so what I'm gonna do is I'm gonna break this down and make it so that it's understandable to, to everybody, like I'm gonna relate this directly to your, you getting a job, because like I said, cyber security is a huge field.

What these guys did was they broke it all down. If you go to this site, it's like a huge database. and they have specialty areas in each category, right? So what I'll do I take you to my category? So my category is called oversee and govern. And so this is where a lot of managers, cyber security management, executive cyber cyber leaders are at legal advice, policy procedures, things like that, education, all that kind of stuff, because.

It's not usually hands on type stuff. It's more of you're overseeing what's going on. You're making sure everything is being going in the right direction. So my specialty is really this one right here, which is security information system, security managers, and then they have different work roles that, that breaks this breaks in further down into work roles.

And so it has abilities knowledge, skills, tasks. And, other things that you need to know, if you're trying to get into this actual work role and it, furthermore, what you can do is, and what I'll do in my book is I break this down into even relate it to directly, to like LinkedIn and indeed and all that stuff.

So you can see direct correlation between the categories. That they've broken down here. And actually the categories that are in all cyber security that's cuz that's what they did. They just took seven categories and said, okay, this is how cyber security breaks up. And then they broke that down further into specialized skills.

And then they broke those into work roles. so I'm gonna take this stuff and relate it directly to how you can take stuff from indeed stuff from LinkedIn and find your niche that you can actually get into in cyber security. And then once you find your niche, once okay, I wanna be in information security officer.

I want to be an information security. I wanna be a COMSEC manager. Then what I'll do is I'll show you how to find. What exact degree you need, if you need one, cause some, don't even need a degree, bro. Some don't even need a degree. Some like just need specific skills, but it'll tell you exactly what skills you need.

Exactly what keywords to use on your resume. Exactly. What everything time you can check out this site is, that. Let me see if I can give you guys the link here. If you go to actually, if you go to Google and just type in cyber security workforce, nice. In N I C E, that right there will guide you to this site that I'm showing that I'm, that you see here.

It's pretty robust. There's a lot of things going on with this site, cuz these guys are very, active and the department of defense. As well as DHS and all these different agencies use these guys as a reference to know exactly what skills and tasks that are needed to do cyber security. Federal government relies on this, what you see here very heavily.

So that's why I decide to make a book about it, to boil it down its stuff, practical knowledge that you can use for your career. Two book series gonna tell you how to market and then how to get the proper career path of what, you want in this field. All right. Let's get into some questions.

This was not gonna be too long of a podcast. I'm going to go to, I've got a lot of questions popping up in TikTok. Shockingly enough. I did not expect this, but I've got about 2000 followers there so far and. A bunch very, active a lot of questions here, but let me see if I can answer a couple before I leave.

Lemme see here, if you're interested in following me on TikTok, just go to combo courses, go to TikTok and then search combo courses. Okay. So it says, somebody asked me I'm in the healthcare field and I'm. Trying to go with the security plus and the H C I S P which is like a healthcare cyber security certification from ISD two squared to stay relevant.

Any tips? Yeah. So this is great. Like this, is an awesome, and I'm gonna make another video about this specifically on TikTok, but I wanted to speak to this on with the podcast. For this as you're going to security, plus, as you're going to H C I S P I would actually do some labs in your house.

One of the best things, one of the most, one of the best ways to go deeper. And into this subject is actually have a lab in your house lab. That means get a separate computer, or you can actually do it on your computer that you use, get your laptop, your whatever workstation you use in your house. And you can use something called VMware and you can put different operating systems on that computer.

Or you can just buy a whole nother computer, build it from scratch, and then put the security features on that. That's a little bit more expensive with VMware. It allows you to I, don't think it's more in about 200 bucks VMware itself the software sounds, and that sounds pretty expensive, but you're investing in yourself.

So just think of it like that. You're investing in yourself, VMware. It works, but for now, I'm just gonna go to the site just to show you how you can create a lab, on your computer. So VMware is a virtual manager and it will, it's an application that sits on. system on your computer, and then you can upload like Linux on it.

You can have different versions of windows. You can have Mac all on the same computer, and then you can network 'em together. And it's really cool. It's a really great way to learn how to do whole space firewalls. You can actually, I think you can even put like different firewalls on it. You can put a NAS on it, a firewall.

You can have whole little tiny network. If you wanna do this for free. If you like, especially if you're in a networking, there's another thing you can do called GNS three. This is something I used to use to, to practice for CCNA G I used to have a CCNA. I used to be huge into network. it's been a while.

So G N S three. So GNS three is actually is free. The only thing that's gonna cost you is your time to figure it out because it's, like a open, last time I checked it, it was an open source simulator. That simulates network environments. Really, cool. It's actually free. Oh, is it not free anymore software that empowers it free download.

It's not free. It looks like it's not free. It. Why is this site all fancy now? Oh man. they do this. They put it out for free for a while. Wire shark used to be free too. I think I wanna say NEIS it was even free at one time. Yeah. Look, how many people use this? Anyway, so you download GNS three and it's a virtualized network and you can literally set up a little it's so cool.

Like it's this is one of another, one I like to do like a demonstration of it's really, cool. It allows you to configure log in and configure routers and switches and. Messing around with routing protocols and all kinds of stuff is really cool. So yeah, I would, that would be my advice to you is if you're going for a security plus a H C I S P and you're trying to get into this field, especially if you don't have experience, create a lab, put it on your laptop, start messing around with it.

So you can then start to understand the inner workings of it. All right. Next question. Dru says, Bruce, in your opinion, what is the most, what is a acceptable salary range for a new is SM or is O so it really depends. That's a great question. By the way, it really depends on where you're at in the United States.

And here's why I say that because if we type in ISO pay scale ISO pay scale, watch. It's gonna it's they have a price range, but it really depends. What you'll notice is it depends on what area you're in and it also depends on what, clearance you have, what's the organization. What you're seeing here is, typical of somebody with experience one 30 and these are in Colorado, California, and cer and I think this is Connecticut.

What I wanna see is the actual pay scale. Here it is. So the national average is over a hundred thousand dollars, $56 an hour. That's the national average. Now what this doesn't factor in, I don't think is how many years of experience the person has or if they have other additional certifications or things like that.

National average, that's pretty good for a national average. If you think about it, cuz that takes into account. All the way, the high, the highest level of pay down to the lowest levels of pay. Let me see, if I can find some more. Okay. The national average in Colorado, where I'm at the average is about one twenty three, a hundred twenty 3000.

And that's about right. That's about right. And independent on how much more experience you have. It'll be more. And I could tell you that if you're in the Virginia area, this is low, like 100. Is low, but I, would say it's around this. This is about right. For somebody starting off from scratch, you might come in lower.

If you've, if you have zero experience with it and you're coming in off like maybe you had some experience in the military or something like that. I, could tell you my first job outside the military as an ISSO I had a bachelor's degree, but I didn't have the required certifications.

They required a CI S P at the time. And I didn't have one. So what they did was they just brought me in and said, look, you have X amount of time to get a, cert this certification. Can you do it? I said, yes. So they hired me at 60, 60,000, 62,000, something like that, but which was very low. And, but keep in mind that this was how many years.

Damn. It's been a long time. 10, 15 years ago. It was like 15 years ago. So 10 years ago that's quite a bit of wild that's dang, 2004, 2006. Damn. That was a long time ago. 14 years ago. Wow, man. Time flies, anyway. Yeah, that was like 14 years ago. It's obviously the price has gone up so 70 between, okay.

Let me give you a range. If you are a new, is. A new information system, security manager or information security officer will say, officer first, cuz manager is different. Manager's a whole different range. Let's say an information system, security officer. The range is between, I wanna say depends on where you are in the United States, but I wanna say it's gonna be between about 70 and a hundred.

That's about right. For a new person. Now keep in mind. They know your value, especially once you start getting those certifications. So what you wanna do is no matter what they're paying you, when you get in, get a certification, a security plus a, CI S P a CI S a C risk get some sort of I would highly recommend a professional level security, cert like a CASP, a CI S P a C risk, a CIS, a one of those.

Not easy search by the way. And they do cost you, but once you get that, yeah you'll, be over. You'll be able to switch to another position, new job, somewhere as an ISSO that, or they'll pay you to stay and you'll be able to make over 115, at least 115 or, more. So that should answer that question.

Now you also ask a question about CI SM, which is a different position. CI SMS are usually the supervisors of a CI. C I S O a is SS O man I'm slipping. So an is SM is usually a manager of an is S O so let me show you what I'm talking about here. Managers are usually gonna make a little bit more cuz they're managers, but let's see if I'm not lying to you.

See if I can find the average of a okay. It's not coming up here. I don't know why. Oh, is he trying to search just in Colorado? What is up with that? Okay, let me go back one to see if I could find the average okay. Keeps wanting to search in Colorado USA or what I'm doing is I'm on zip recruiters and I'm looking at their, they've got a, like a little breakdown.

of this. So actually let's let's get outta this. Let's go, back to Google and find another management position. I, guess it's lumping it right in with ISS O okay. And actually the saying is lower for some reason that's inconsistent. Oh, okay. The No, This is saying it's a little bit lower.

That's weird. Which I don't think is correct because a ISSM is a manager, typically, especially in the federal government they, have two different positions. Like one is ISS, M will usually be over ISS OS and they'll usually be the person who signs for the, is S O and manages the ISO's work. So they usually make more, it's usually like a management type.

so that is that's incorrect. I would say is probably in more in the range of one 20 to one 40 and on up. So for an ISSM man glass door is even saying it's lower. That's not been my experience. Oh, okay. No glass door saying the average. For an ISSM is one 20. Yep. So there you go. That, was my guess would be more like one 20.

It is up the scale goes up like 10,000, something like that, just cuz you can see here that they're saying that the, average low on the low end is about 67 to 80. And all the way up to $290,000 is insanity. But yeah, so that's about right. 1, 1 20 is what I was saying. ISSM is gonna make, okay. Let me see if there's any other questions here.

I got some folks watching the stream here, watching the podcast, listening to the podcast. VMware GNS three are, golden for learning. Yeah. Apple work. Yeah, for sure. Okay, let me see if there's other questions. I have so many questions popping up on TikTok. It's very, active for questions. Somebody called me a scam.

It's free stuff. I give away, man. I don't know what people are thinking to be honest with you. Which is the best path for an at home job jobs only. Okay. So somebody asked me, I've had this question before, what are the best jobs? For at home jobs, remote work, what are the best, I guess it jobs, information, system, security, officer jobs.

Information security, cyber security type jobs, or it jobs for work from home these days after COVID I would've had a different a different thing to say about this, but these days mostly. Let me put it to you this way. I can tell you what jobs are, not compatible with remote work.

Let me start from there because nowadays you can do so many jobs, remotely and, more organizations and employers are now more open to remote work, which is I've been doing this before. COVID so it was a lot harder to get remote work before this. Anyway Jobs that are not conducive to remote work would be classified positions.

In my opinion, in my experience if, you're in a classified environment, if you're trying to get work at a especially if it's secret and above it's, harder to have a hundred percent remote. Normally what they'll do at, the most they'll have a a flex position. flex hours are flex.

I can't remember what they call it, but basically it's like a hybrid That's what they call it. So they'll say, okay, two days out of a week, you can be at home. And then the other three days out the week work of the work week, you have to be at the site or two days are vice versa, like two days on the site and then three days off site.

So they'll do stuff like that. But see, the thing is you have to. There, you have to be on site a lot of times to do the site, the security stuff the, classified stuff. But that being said there's, actually some people like a friend of mine, really good friend of mine. He was telling me about how there's this innovative new technology where you can actually do even classified work from home jobs.

So even that is gonna be work from home more and more and I'm talking about all the way up to Ts and he, once he explained to me how that's done I was, my mind was blown. I was like, holy crap. That makes sense. But anyway, most of those jobs right now are normally you can't do those remotely.

Another one that's deceptive are jobs where you have to travel a lot. The problem with those is they'll say, oh, it's a hundred percent remote, but. You're traveling so much that doesn't even matter, like some of the consulting and some of the professional services jobs, they require you to go on site.

If, they, if it's over, I'll put it to you like this. If the travel is over, if it's over 50%, then you're gonna be traveling a lot because you gotta factor in. Probably add another 20% for the travel days. Yeah. So if it's over, if it's 50 if it's even close to 50%, that is CR that is a lot of travel.

Like you, I, cuz I did a job like that and I was constantly on the road and the only time. I think mine was 60 to 75% travel. I was never home. I was never home. would come home for the weekend and then I was off again, like I'd have a three day weekend and I'd be traveling for the rest of the week. So it was brutal, man.

It was work from home, but I just, I was traveling all the time. So if it's any of those jobs and normally the other one I would say, okay, so we talked about classified jobs. Normally those are on site or some kind of a hybrid. Those are changing, but most of the jobs are you're gonna have to go on site.

The other one would be consulting where you're traveling a lot, cuz you have to go to all these different places. And then the other one would be if they really want you to have FaceTime with the customer. And that usually requires being on site, those off the top of my head, the ones that out of all the ones I've been offered that I've worked at personally, that's been my experience.

But if you guys can name any other places where it's pretty much, you have to be on site field text. That's another one that one's not gonna be well it's it says it is gonna, it can be remote, but you're traveling so much that it might as well not be remote cuz you're never home. Yeah.

Hope that answers your questions. Most jobs off the top of my head. Cyber, a lot of cybersecurity jobs can be done remotely. Remote administration, you can do system administrator jobs, a lot of those remotely. You can do networking a lot of those networking jobs, remotely configuring firewalls, monitoring traffic.

A lot of those you can do remotely. Just name something. Most of 'em you can do remotely. It really depends on the organization. So just keep that in mind. Okay. Let me keep going. okay. Somebody said it is back on the topic here. Somebody said it is difficult to to impossible to get a fully remote. There is zero chance that I would work and take the added risk of doing classified work remotely.

Yeah. So the technology that was in place was it was like a virtual machine, nothing stored on your computer, basically. It's you're seeing, it's like you're seeing images. Like your whole desktop and everything is just images that you're seeing. But the, risk for me is that if you're in your house, you've got things like you've got other what if your daughter is on the phone over here?

And they have their phone they're on speaker phone and you happen to be doing a you're on a secure line on. System and you're doing classified work and then they can hear what you're saying, so there's a possibility of a security incident because it got leaked to somebody. I don't know.

There's just I'd be nervous about it myself to be honest with you Dru says after C or it travel jobs still plentiful. Yes. I know the go. in the government for the government. It has slowed down quite a bit. Yet there's still a lot of travel jobs, but you're right. There's a lot of customers and clients.

And the last job I worked at without giving too much away last job I worked at I I was a, consultant. I was a cyber security consultant and we would, our biggest part of, one of the biggest part of our jobs is that we would have, we'd have all these assessments and we would. To a site.

We, we would go to the site and we'd do physical assessments and we'd do wireless assessments. You have to be on the site for those. So we would go there and sit down with the facility manager and ask them, que interview them and then walk around the facility and all this kind of stuff. And then you'd do a report like you say, okay you're good here.

Good. Here you have a checklist, all that kind of stuff. But a lot of clients were like, nah, you can't come to our site or you can come to this site, but you can't come to this site. So you have a point because of COVID travel has been. Restricted, but there is, it's starting to open up quite a bit lately.

Like right before I left, they were opening things up. Like it, it was opening up like crazy because Mo most places in the us are opening up with the exception of there's a few places. Like we had some overseas places that were still pretty, pretty locked down, pretty tight.

Exactly skiffs are skiffs for a reason. yeah. Okay. Let me see if I can answer if there's any other questions here. Tons of questions and interactions on TikTok. I'm really surprised about TikTok. Somebody asked me, okay, this is a good question. Couple questions that are related. Somebody asked me if they can do cyber security at age 30 and another person asked me if they could do it at age 45.

And I would say. As a matter of fact, cybersecurity lends itself to a more mature minded person. Because you have to do a lot of interaction. As a matter of fact, like this career field is pretty old. I don't say so myself, but the last place I worked at I wasn't the youngest guy, but I I'm pushing 50 man.

Like I, I, wasn't the youngest guy there and. so I was not the youngest or the oldest guy there. So it, this career path needs more mature people because you're dealing with pretty heavy, issues. And you're having to talk to, you have to have the maturity, the emotional intelligence to talk to high level, cyber security CISOs and C level execs and stuff.

And then you gotta be able to switch gears and then talk to a technical. and because of that, it lends itself to a more mature type of person who can handle, stress and not freak out. And who've been around the block enough to know, okay. Yep. Don't worry. Like we got this and not panic.

So you need somebody with a cool hand. And a lot of times even me, I've been doing this for 20 years, but August school, like the last place I worked at, there were, so there were people there who were masters at this and I'm like, I man, these guys were running circles around me. I thought I was pretty good at presentations and stuff, man they were killers.

They just like something bad would happen. Something horrible in cyber security. So many bad things could happen that we're in the business of preventing bad things from happening to your assets. Something would happen and the client would lose their damn minds and they'd be a younger.

Who can't handle any kind of pressure and they freak out and they they'd freak out and then have another person, like my mentor, who was at that job, that person would just be calm and just calm them down. Just talk 'em off the ledge, negotiate with them. And then next thing you know, they're no longer holding hostages like they were.

So good at speaking to cus clients and customers, and that level of maturity is, really necessary. Yeah, 45, like as long as you can get the concepts down, as a matter of fact if you don't wanna do another two years of if you don't want to sit down and do two years of learning all this new it, you could actually do something like a program.

Project manager is actually a really great position for an older person. Project manager is. Compliance the stuff I'm doing something like that. Something where you're not super like in the weeds, technically, because there's a lot going on with like firewalls are constantly evolving and changing.

And like a web technology is constantly evolving, changing, and man, to keep up with the server technology it's constantly going constantly moving constantly and you're having to constantly hit the books and stuff. So that could be. As you get older, you have all this other stuff going on in your life.

Whereas youngsters they're just now coming in and taking on new responsibilities. So the work is everything for them. They don't have maybe they have one kid or something, but they don't have necessarily grandkids or five kids or whatever, so they have, they can devote more of their time to this learning this new technology and stuff.

But if you, I would highly recommend especially if you're older, you already have done two or three different career paths and you're doing this so you can retire and, live a simpler life. Man I would recommend project management get P and, also it really needs more mature people like people who can handle pressure and not freak out people who are calm as a cucumber, this calm, this, and they can just work in any environment because they've, seen some. So they got that, that thousand yard stairs. We used to call it in the military. They've seen some shit so older people like, yeah, I, it is, you could definitely do this as an older person. All right. I think that's it guys.

Thanks for watching. I've been talking for about 30 minutes. I'm gonna try to do more like one offs like this, instead of just doing 'em once a week more Podcast. And if you're interested in hearing a lot more, cuz I actually post more stuff on on audio go to combo courses.podbean.com or checking the link description below and you'll have more access to all the stuff that I put out.

In some old podcasts I've been posting. All right guys, that's it for this one. Thank you so much. De truth. Thank you. S V T. Thanks for all the questions on TikTok.

View Details

http://convocourses.com

Hey, happy new year, everybody. This is a podcast for combo courses, and today we're gonna be talking about we got some, a few questions that, that have been asked of me. I've got a resume to go through. And I wanna talk to you guys about 20, 21 and what what I'm gonna be studying this year as a focus for like certifications or just sharpening my skill and some things that I would recommend that you look at too.

Cause I think it's looking forward five years ahead. What I think is gonna happen as far as our industry is concerned, cyber security or data analysis and things like that. And so let's get started. So the first thing I wanna talk to you guys about is some of the things that I'm gonna study in 2021, the things that I think that are gonna be relevant going forward in the future.

And let me just switch my screen here to show you the very first thing. that I wanna show you is blockchain technology. This is something I think that's gonna be more and more re relevant. If you've been watching the news, you've been seeing cryptocurrency going off the rails lately. And a lot of this technology the money is based on blockchain.

And I don't think that this technology's going away. It has all the hallmarks of what I saw with cloud computing many years ago, and everybody kept talking about it and it just kept coming up over and over again. It's really the same trends I'm seeing where all these gigantic companies and all these giant organizations are really dipping their toe in a blockchain technology and very quickly what it is a basically it's a digital ledger.

It's a distributed digital ledger that allows you to basic you, you can essentially you. , you don't have to have a middleman. It allows you to not have a middleman because there's something there's a, normally, if you like a, with a bank, for example, a bank is a middleman to your money. Your money is there.

You have to go to the bank to get your money, but with a digital ledger, basically, essentially your money is out there on the web and distribute. It's all over the place it's distributed and encrypted so that you can access it. And it has it's a cure. It allows you to be anonymous and and it's something, it validates it so that you can't, you people can't say that they didn't make that a payment or could, or didn't get a payment.

It's immutable. That's what that means. So the technology is emerging slowly but surely and not just cryptocurrency by the way, but also for things like logistics. And even voting can be done with the blockchain, many other things that we use every day can be used with blockchain technology.

And so that's why I'm gonna be studying more on this the actual technology behind it as opposed to just cryptocurrency for the sake of making money and investments and things, that's a whole separate issue. Blockchain itself does much more than just money and essentially, like what, another thing that you should know about blockchain technology is that let me see Oracle starting to use it.

Walmart is starting to use it and many different other organizations and governments are start. Dip their toe in this technology. And it looks a lot like what cloud technology was looking like about 10 years ago. All right. Another thing I'm gonna be studying very heavily is cyber threat intelligence.

This is becoming much more important to anybody who does cyber security and what this is from a high level is it's. If you have a customer or if you have an org you're in an organization, either one and you're protecting someone's assets, their laptops, their servers, their information, their personnel, you're protecting their assets.

Cyber threat intelligence is where you do recon to see if anyone is. Looking into trying to break into those assets and the way you would, one of the ways that you could do it is to have a cyber threat intelligence cyber threat intelligence system that goes out and checks the dark web checks the internet to see who's talking about your organization.

Does anybody have your, the IPS of your organization or is anybody scanning your organization? So you're looking for where people are trying to get into your organization, a preemptive you're. You're doing preemptive checks to see if there's anyone trying to get into your systems.

This is gonna be really more and more important as technology becomes even more important in our, in all of our lives. If you looked at the recent gigantic hacks that are going on, state sponsored hacks are happening. And the one of the ways to. to have some kind of defense against the state funded state sponsored actors is to actually do cyber threat intelligence.

See if anybody has been CA casing the joint, scanning your network scanning and see if you have any vulnerabilities out there. So cyber threat intelligence is something I'm gonna really dive into this year, and that's gonna start off with with things like ethical hacking, and then I'm gonna get into cyber threat intelligence, cuz you gotta know a little bit about ethical hacking and stuff to actually know a deep, have a deeper understanding of what threat intelligence is.

And another thing I'm gonna dive into this year and I've put it off way too long is cloud computing technology. And this is something I talk about a lot on this channel and it is just getting more and more important. Like it's not going away. It's just. it's really become a centerpiece of all of our lives whether you know it or not.

If you've, if you watch Netflix, if you use Gmail, if you use Hotmail , if you, whatever you use, like most of these gigantic technologies are using cloud technologies on the back end. So it's just becoming more and more important. And me as a cyber security person, I need to know have a deeper understanding of what that is all about.

So those are the things that I'm gonna study this year for 2021, and possibly get certifications in some of these technologies and actually it's become a required couple. Two of those things on that list that I just mentioned to you are, have become a requirement for the job that I work at, that I have to actually get a certification in 'em.

So this is something that, that I'm definitely gonna do. And I think. These tell those three things are gonna become more and more important in the next five to 10 years. All right. Let me see if I got anything else. I see a few people watching me. If you guys have any questions, let me know.

I'll give you guys time here. If anybody wants to chime in, I've got a few people who've asked me questions and a few people who've asked me to actually look at their resume. So I'm gonna actually do that. Let me see if I can find a good one to look at here. The first one I'm gonna look at is going to be from the, I changed the names, just so you know, change the names and the addresses and everything on there.

So there's no need to worry about that. I'm gonna look at this resume right here. And what I like to do is I will. get, put my suggestions in there sometimes the resumes are so good. I don't really have much to say about it, but it's just like little tweaks and stuff of what I've done on my own personal resume to give them some, to give them some extra juice, some Google juice on that resume and my mindset is that I market myself.

And so I encourage anybody, any of my students, anybody who follows me to do the same thing, you gotta market yourself. It's very important in this day and age, there's just so many people. And there's so many competitors out there for you. There's so many other eyeballs on other different resumes that you gotta put yourself.

You gotta set yourself apart by advertising yourself, marketing yourself. Okay. So this is coming from Mike and he's in the DMV area and he is a senior assessment and authorization engineer. Okay. All right. I've never heard that. Title before, but that's good. If just one suggestion I would make here is if you're Mar if you're looking for a different job, I would, one of the things that I do is I put some more more common, a more common name out there.

So this to me sounds like it's and I could be wrong here, but one of the things that he could do is say, he's a security, and I'm gonna read through the resume. This might change. I would suggest I'll just say suggestion is to have the title of this, be a security control assessor. And the reason why I would say that is because the security control assessor is a more common name for this type of work.

But then I, this might be something I've not. I'm not familiar with authorization engineer, but it is just not something I've heard people use in my industry. So that's why I I would recommend they do this now. This is good. They put active top secret clearance. That's really, that's excellent.

You, do you definitely wanna put any kind of clearances that you have here? Up top, because that's a very marketable thing to have that immediately eliminates 80% of the people who are gonna compete against you. So that's a very good thing to put on a resume. Let me see, I'm gonna read the top part of this qualification profile.

This is pretty good to have, like whenever you're marketing yourself because places like LinkedIn will have an area where you can put stuff like this, but what I normally do is I take advantage of it by putting as many keyword as possible inside of this profile. You don't want it to just be flowery and sound good.

You want it to hit 'em right in their teeth. You know what I mean? You want 'em to grab their attention immediately with a bunch of keywords. So they said concept and execution con concept to execution focus, systematic profe. I would not put any of this stuff in here. Okay. I'm just gonna, I'm just gonna suggest some things here.

I'm just gonna suggest some stuff I'm gonna say. Now I'll have to read the, what I'll do is I'll read through the resume. I'll come back and fix this up, but it's just way too flowery for me. Like I would not, if I was reading this, I would just skip right by it cuz I want to know what they can do core competencies.

These are good. But another thing that I do personally is I take this and I put it at the end, any kind of listing stuff like that. I put it at the end.

Cuz it will get picked up by the search engines. That's the reason why I do it. But when I'm reading through it, I want to very quickly know know what their education is, cuz that's normally a show stopper or a show it gets the show on the road if they know, okay, this guy has a bachelor's degree.

That's one of the requirements. He has a C I SM certification. That's one of our requirements. So you wanna very quickly have all the main things up here. Now this dude's actually got a great resume here. He's got some great set of skills. So another thing I do is I would put your top certification right up top, like this C S M I would say, is this top certification?

I would say I would put it right up here. Not trying to brag or anything, but I am a CI SM. And maybe you put the number in there cuz this is gonna be. Guaranteed a requirement. That's gonna this certification right here can replace things like C I S P and some other large level high, sorry, large high level security certifications that that he has.

And then the cast is also a really good one. But I think the C I SM is a better, has a, is better, is a higher level. It's more, no more people know about the C I S M I should say. Okay. So he's got a ethical hacker certification. That's also a good one. I would, that's another one you might wanna put up here as well.

That's a very marketable certification, a lot of pen testers and hackers really look down upon the C, but I'm telling you it's very marketable cuz the corporations have not gotten the memo, the government and the corporations have not gotten the memo on, on how bad this certification is. So it's very, still very marketable.

Yeah, I would put that on top. Let's see security plus. Okay. And some other stuff. All right. Let's keep going here. Scott. Cyber security professionals, Maryland. Oh, okay. Affiliation. I'll put this at the bottom. We wanna get to the meat. The meat is the actual experience. So I'm gonna take this, I'm gonna put this at the bottom.

This is a great resume, by the way this is right at this point, all I'm doing is putting my own suggestions in here which he can take it with a grain of salt. Like I, it, this, he could leave it just how it is and it would still be fine cuz he's got so much good stuff in here. The only thing I would highly recommend changing is.

this right here. Cause you want this to have impact. And this to me, expert at administering desktop printers, and this is not a good impact. This is not tip in my mind if I was reading this and I was trying to hire this guy, I'd be like, eh, whatever next I'm not trying to be mean or anything, but just keeping it real with you guys so that you guys don't do the same kind of stuff on your resume.

No flowers, just straight facts keywords, stuff like that. Okay. Let's see. So job was at K force to current. All right. Top secret clearance. Let's see a C Splunk. Okay. This is actually really good stuff. Support all activities on as outlined in this 837, 1 37. Okay. All right. Not seeing a lot of impact.

But I'm seeing lots of great keyword, so that's good support all outlined in. Okay. Review and analyze a and a as assessment and authorization. Security controls missed overlays experienced using administrative administration of EAs. Okay. So this guy, it sounds like he's like a is O but I'm not really sure what, cuz he names himself as a senior assessment authorization engineer.

That sounds like an ISSO. So another suggestion I would make is to possibly or use IFSO

information system security officer. and then I'll just tell 'em here. That senior, what I'm trying to get at is it's a senior assessment and authorization engineer is uncommon, is an uncommon title is an UN uncommon title. That's all I'm trying to say. So you wanna use like a common ti, if you're gonna put a title up here, it should be a title that people know about.

And that also fuels your your Google juice, your keyword cuz the, and the thing, the reason why I emphasize on my courses and whenever I do these resume suggestions, these are my suggestions. I'm sure other people have way better ideas than me, but these are just my suggestions.

The reason why I focus so much on keywords is because that's really what a lot of employers and a. Technical recruiters use as keywords re technical recruiters and the HR department. Who's looking for jobs and stuff. Typically they're not a technical person in your field every now and then a organization has the resources to cut some technical guys loose and say, Hey, go look through all these resumes and screen some people and have 'em come in.

But typically what happens is your resources. is your guys on the ground. You need them to actually do work. You don't want them to go looking through a hundred resumes. You want them to be working on cloud stuff. You want them to be analyzing data. You want them to be doing their job.

You're gonna have. So that's why, what organizations do is they have people who are not low level workers. It's not the right term, but. HR a screener from a whole, a third party organization, a third party company, they say, okay, look, here's our requirements. Please look through these hundreds and hundreds of different resumes and see if you can find us some good picks, just we gotta make sure that they have us and CSM.

They have to be in information system, security officer and see the thing is when they say we want a system security officer, they're not gonna know what a senior assessment and authorization engineer is is that, does that make sense? So you wanna use the same language that people are using if everybody is using cyber security.

The thing is I've been through a few iterations of this. So first iteration, when I went into security, Everybody called the information assurance, like if you were doing risk management framework, if you were doing certification and accreditation, that's what they called it. We were called either certification and accreditation engineers, or we were called information assurance officers, or we were called like this, just it's just an odd, that was like information AUR.

What is that? What they meant was security. You're security guy who does paperwork essentially you're a compliance guy that would make more sense, but then it evolved from information assurance to what did they start calling it? It was information system security, then information assurance, and then they start calling cyber sec, cyber security engineer information.

Change. And now the do D I think they are calling it like cyber surety or something like that. I don't, they keep changing the terminology, but you wanna keep up with the terminology people are using in this industry. So that way what words to use for those HR guys or those screeners who are who's, who are looking for all these resumes.

And they're looking for that one keyword, they don't know what an information system security officer is. All they know is that the employer said, Hey, we want an information system. And if so make sure that's you get this person. And so you gotta use those keywords. Okay. I'm gonna get off my get off my soapbox here and I'm gonna continue going through some of these.

Yeah. Tony, I see your message here. Let me just finish this. Getting through this resume. This resume does not look bad by the way. I've seen some really bad resumes. If you've been watching these for a while. I've been through a couple who were, that were really bad. This one's actually pretty good.

It's got great keywords. My only main suggestion would be, I'd be really surprised if this doesn't get tons of offers. My only change would be to change this whole, this right here. This is just this just too much fluff. Just get to the what. Okay. Let me just give you an example of what I would write here.

What I would do is I would say something like, cuz this guy has so much awesome skills. Let me just read through what he's done before. Let me see. And now analyze vulnerability data, multiple sources using a cast and Splunk. Okay. Here's what I would do.

I don't know how many years of experience this person has, but I would start off with my years of experience. I would say it looks like he has years of experience. Look as a security analyst. Good Lord. Jesus. Why? What are you doing here? What I would I'm sorry guys. I'm just, I'm a little frustrated.

Okay. I would say X years of cyber security analyst work using tools such as is Splunk. NEIS I don't know how to spell NEIS so he is gonna do a spell check NEIS.

He said a castle that's NSUs you wanna use? NSUs that's a real good tool to have. And let's see, EMA wait and a grasp of

No, not grasp, but we wanna emphasize how much skills this guy has. Cybersecurity analyst work using tools such as eight years of experience or whatever years, experience analyst work, using tools such as Splunk S with, okay. And okay, here we go. We'll say, and NEIS with a with solid experience.

Implementing

Risk management framework.

And we want to get that keyword in there. RMF, I'm gonna say N 800 also key phrases with solid. Okay. Yeah. See, I would start off. I wanted someone hit 'em right in their mouth. I don't want them when they see my resume. They're gonna stop reading all other resumes when I'm done. That's your goal.

You want them to stop on your resume and not read another resume? Okay. He, this dude got so much experience, like why is he saying all this fluff? That doesn't oh my God. Okay. So yeah, I would just hit him right in their mouth. Like I, okay. Then he wants to say. Have I have a active security clearance now you might be thinking, Bruce, why are you saying clearance over?

He says it here already because we're using a different keyword. So up here, he said, active top secret clearance right here. We're saying active security clearance. It's a, there's a difference. And we gotta spell it by the way, there's a difference because it's a different key word. So somebody's looking for security clearance and they want you to have a they want you to have a security, a secret clearance instead of top secret clearance.

They'll still see that you have a clearance period. They'll go, they'll be looking for a secret clearance. And they find a guy with an active top secret clearance. You know what I mean? So we wanna make the net as broad as possible. This dude's got so much incredible experience. That there's a lot to choose from here.

I would put something like this in here. Okay. Okay. Watch this. So we wanna put more about his in information security officer experience. So we wanna put ISSO with years of experience.

See how I can't spell. see. It's very important to do a spell check all right. Experience. If so with years of experience getting authorization to operate and with, for, and for multiple information systems.

So I got a bunch of keyword in here. I got cybersecurity analyst. That's a keyword key phrase. We got Splunk. We got NEIS, we've got risk management framework. We've got N 800. We've got a O we just want to hit all the buttons. We don't want fluff. We don't. Oh, bilingual. This is a good one too.

This is really good. And oh, by the way, I'm bilingual. Yeah. Super powerful. Bilingual opens up a ton more jobs for you. If more than one language, any language it's gonna open up other jobs for you. So that's just something that to keep in mind. All right. So that's it with that one. I I hope that that's helpful to, whoever's watching this the idea behind this is to get yourself in line with the market.

that's the whole thing. And you need to do that. You need to tell people who you are. You gotta show people, Hey, here I am. That's what marketing is all about. So you wanna market yourself. That's the whole, that's my whole thought process. Okay. Tony says, Hey bro, I have about seven years of compliance experience and I'm bored to say the least

I want to move into security engineering and architect roles. How do do you suggest I proceed? Wow. Tony that's I had the same experience. Like I, I had been doing it for I don't know, 12 years or something, and I just got so bored with it. It wasn't a challenge anymore for me, and I know that sounds ridiculous if you're getting paid and you're, you got a secure job, but you need some kind of a stimulation. I got into it cuz I love technology, and so I was doing this for like years and years compliance and I found myself losing my technical cuz I had technical skills and I started losing that because all I was doing was compliance stuff.

So I know how you feel. So what I did was I I just jumped off a cliff man. Like I, and I don't recommend this to anybody, but this is what I did. I took a job doing something that I was really excited about. I was looking for another position I was in between jobs and I was looking for another position and somebody off had a job overseas.

to do. They actually, it was risk management framework. I applied for that and I applied for another position they had for a system security analyst. I applied for the system security analyst and I didn't I of read about it. And it was talking about using Sims and talked about using tools like.

McAfee EPO and IDSS and IPS. And I was excited. I'm like, oh man, this is so cool. I've never even some of the stuff I never even touched before. So I was really wanting to get into it. So what I did was I applied for that job, as well as the risk management frame, I was fully expecting them to look at my resume for risk management and be like, okay, this is our risk management guy.

They didn't do that. They chose me for cyber security. They looked at all of my old technical skills and they were like, okay, this guy right here we really need somebody to do this work for cyber security analyst work. And they picked me up and they picked me up as a, like a junior cybersecurity analyst where I was learning I wasn't like the guy, the main guy on the floor.

Doing everything. I was like, one of the people like learning different technologies and actually staring at a monitor, looking at the data, coming in, out of a network and analyzing, they taught me arc site. They taught me, which is a SIM kind of like Splunk, a little bit of Splunk. They taught us all these different tools, man.

I had a blast, I'm learned so much stuff, but I had to learn, like I was like, I was fresh outta college. had to swallow my pride and I had to take, which I have no problem with, but I know that some older guys, especially if you've been in it for cyber security or it for a while some of us we've seen war zones and stuff, so it's like, why is this kid telling me what to do? But I didn't feel that way. I was like a kid. I was like a little kid learning like a wide-eyed little kid oh yeah. Really getting into it and. and then my work ethic kicked in and I learned everything. I could, I absorbed as much information like a sponge.

And so I would, so that's what what you could do. You don't have to go to another country or anything. Like I did jump off a cliff or anything, but what you could do is just apply for a junior level security engineering and architect role to get your beak wet to get started but keep in mind, if you have seven years experience you can't come in the door with the chip on your shoulder oh yeah.

I already know that I've done it for 15 years and throw your weight around or no, you gotta be like a little kid, and that's what I love about it is that I'm learning so many things like you can like right now, if somebody, if I went to a firewall role, even though I've touched them before I know how they work and stuff, I don't know how to configure a fire.

I can't do that from scratch. Somebody would have to sit down and teach. Like from, they'd have to teach me from the ground up. Now I'd learn very quickly cuz I have all this experience and all these other tools and stuff, but you I'd have to be open minded and learn what they're teaching me and not come in there.

Like I know everything and not knowing I have to come in there, like I'm an intern fresh outta college and I'm willing to learn from this Pierce person. Who's more than likely younger than me, so yeah, that's what I would do, Tony. I know how you feel. I felt the same thing many years ago, that path right there for the in terms of my career was a great move because now I have so many other doors and opportunities that have opened up over the years. And because I have this plethora of different experience that I can pick from I'm now a consultant. Like I can consult on all these different things.

I've touched so many different technologies before, and I don't have to actually be an expert on each one, but I know the concept so well that I'm able to say, okay, I know how this works with this. And I can look at data and say, okay, this is what I'm seeing here but yeah what I would do if I was you Tony, and actually that's what I did in the past.

And I know how you feel. All right. I got some other questions here that some folks have contacted me about and I'm gonna answer them. So let me show you guys what I'm seeing here. Let me show you what I am seeing all. So I've got a question. From my man. So Solomon H and he says I received a contingent offer for wait wait for security control assessor position.

And I'm proc I'm in the process of getting my clearance. I don't have a background in risk management framework or any cyber security compliance. What advice can you give me? I'm relatively new in cyber security and only have one to two years experience as a system administrator. I know that my job will focus on security and privacy controls.

As I look over the, as I look over the next 853 documentation. I've enrolled in your course. And so I can better understand an overview of how risk management framework works. Is there anything else that you can help me with or give me any kind of guidance? Yeah, actually I really can help with this.

I would say that if you happen to be watching this, Sawman as a system administrator, if you guys out there are system administrators, you should know. And especially if you're trying to go into cyber security, you should know that actually you have many years of security experience.

So if you have set up a server before and had to put the patches on that server, that security experience, if you've ever had to do some documentation on the system that you set up where you had to draw out a diagram, put that together and shop that around to the rest of the. The guys on on the staff you've, that's cyber security.

That's a little taste of all of these different things are taste of cyber security. If you've ever had to help the compliance guys out and those guys that contact you and say, Hey, could you give me, could you give me a blurb or some documentation about what this security feature of the system is?

Guess what that's, you've actually assisted with cyber security compliance. If you've ever put a secured software on the system, you put the software on there and then you had to update it. That's also cyber security, cuz you're updating the patches that could have been exploited by a threat actor so if you've ever put signatures on a system for anti-virus, that's also cyber security. If you've ever. Hard in a system like where, okay. Let's say that the, there is a password protection on there, but it doesn't have upper and lowercase and it doesn't have, it doesn't have password complexity, but you had to go on the back end of the server and ensure that the whole organization is enforcing password complexity or enforcing multifactor authentication or enforcing audit logs to be enabled for anybody who's failed, a failed login attempts or anything.

All of those things. If you are a system, administrator are things that you could put on your, you should put on your resume as a cyber security person, cuz you have done cyber security. In fact, you have, I would argue you have done more cyber security than some. Have quote or quote unquote in cybersecurity who have not done any technical stuff.

And all they do is policy. You've done more than them because you're go, you're now be able to go deep in policy and deep in technical, the technical side, your skills are very much needed in this field. Now you said that you're going into security control assessments. So this is security control assessors from my interactions with them and having done this myself.

We, the, you need a team of people who can assess different aspects of an organization. Systems. What I mean by that is you're not just looking at documentation. You're not just looking at their security policy and saying, okay, looks like you've got you've guys have a policy in place, and it's been updated on this and that date.

You're not just doing that. You're also ensuring that the organization is complying with their own security policies. And that means that you have to run things, do things like run scans, so you might have to Polish up on your ability to run a necess scan or a, I don't know, name, a name, a scanner.

And you might have to know a little bit more about that, but I'm sure you'll pick that up pretty fast being a system administrator. So that's one thing yeah, learning the nest 800. 37 I would say is another place to look. But if you're taking my course that's gonna walk, that's gonna really touch on what you need to know for N 853 and N 837.

It's gonna really touch on those things. And there's perspective of an information system, security officer. That course is actually really good for for se, especially if you're new to that work. Yeah, I hope that helps. That's a little bit of guidance for you if you're taking the course.

If you happen to see this this video, Sawman any questions you have whatsoever, I actually are currently doing assessments for different organizations, so I can help you out with that. Okay. I've got another question here. And somebody said oh wait. Spade says do you offer any mentoring opportunities?

Can you remind us of how. we could work with you concerning career guidance and resumes if possible. Yes. So spades, I get this questions like weekly now. I do not do mentoring because I have a full time job and I really enjoy what I'm doing with teaching online, or I really am getting into it.

I'm starting to meet other people. I'm learning stuff from other instructors. I'm really excited about it. So I wanna spend my time doing that. But what I can do if you're interested is I've got a bunch of courses. Let me just show you what I'm talking about here. I've got a bunch of courses that you can sign up for.

Some of this stuff is actually free. So what I do is I put out a course and I give a portion. a portion of it free, and some are just completely free. Some from scratch. If you're learning this from the beginning and you want to get into cyber security, then this is a free course for you to shows you what to actually focus on.

It's six hours along, by the way. It's not, it didn't start off free but I felt like it's time to help more people out that really need it to get into this market. I've got something on resume marketing, like how I have been able to have a job since I got outta the military I've got so many opportunities all the time because of this meth method that I use, some of which I teach for free on YouTube, by the way, some of the stuff I tell you guys is in this course, but it's a breakdown.

Let me just show you how extensive this is, this many hours of content and shows you, and you can use it as a reference. You don't have to go through line by line on all this stuff, but shows you what I do to. Have so much success in my career and continuously have offers from all different kinds of organizations and different industries related to cybersecurity.

And then I've got a walkthrough of the risk management framework process from the perspective of an information system, security officer. I've got a deeper dive into that, of how to actually do the documentation piece and downloadable templates that you can use. And I'm sharing essentially my experience in this field so that you're not lost and you know where to go and how to upgrade yourself and how to make more income.

Let's keep it real. This is about taking care of your family and taking care of your being, having some stability, financial stability. I'm talking about how I've been able to secure my life and my family using this career field. So that's what I'm talking about in there. And tons of it's free.

So you should, at least you should sign up. Check out the free stuff. If you like it. Now, if you do sign up, I do answer any of your questions. You I'm gonna set up communities there. There's lots more to come in 20 21, 20 22, 20 23 plan to be in around for a long time and offering as much help as possible for people.

My wife's calling me. Sorry, let me just turn that off real quick. Okay. So yeah. So yeah, I do not do mentoring just yet. Maybe I have a full time job. I love my job. I love, I know that's a weird thing to say, but I'm really having fun, like learning different things. And my, when I'm at work, I'm like really at work I don't have time to do anything else.

I'm really doing stuff. And I'm doing, I'm just learning so much. I do have a discord channel if you have, if. Anytime you want to question have que, especially if you happen to be a member of the site, if you happen to be a paying member of the site, I'm gonna go outta my way to help you out in, in very deep ways stuff that I, we wouldn't be able to share on here, obviously if it's more personal or if it's more related to specific things at your job, then of course I'm not gonna make a video about that.

So that's the kind of stuff that I do offer, and those are things that I can do on the weekends, like when I'm off work and things like that, and there might be a time when I'm on lunch or something, or just after work or whatever, I'm on, I'm off that day and I can call and we can have a I've talked to my students before on the phone, like we're just back and forth talking about stuff that's tailored to their life.

But as far as mentoring on a regular basis, I would take it extremely seriously. And I just, I'm not ready. I don't have the time and the day to, to dedicate to that. To that. So yeah, so that's where we're at with that. Let me see thank you guys for watching. Appreciate everybody. I got another question that someone asked me.

They said, let me switch this screen here so you can see what I'm seeing. They said, hello, Bruce. I'm interested in becoming an information system, security officer and was interested in your course and what guidance you can provide on what courses on your site I should start with. I was using Darrell Gibson, but I think he's a real popular security plus trainer, but I know the 5 0 1 expires on July 21st, 2021.

What books should I get for the risk management framework for the cap? Okay. So first of all, I am. Developing a cap course. But that's not gonna be out for a while now, if you wanna know what book that I would use right now for the cap course, I can share that with you. I'm gonna bring that up real quick.

The one that I think is a really good one, it's not cheap. And it's so expensive. I wanna apologize for how expensive it is. but there's no real op alternatives to this book that I've seen. There's there's just not a lot on the cap and that's why a lot of people follow me cuz there's, that's not a lot of people talking about risk management framework.

And this is one of the few books that that are out there that I think are worth your time. I have this book and it's, and I'm reading through it and it's really good. As far as taking the cap, it's really good. I don't believe it's super practical. But I think it's a good book for the actual test.

When I say practical, there's a difference between if you're an it guy this there's a difference between actually taking the test. There's a difference between taking the test and doing the work. And they're just two separate things. So that book right there is really good for the official guide to the cap.

Common body of knowledge is a good book for taking the test. Cuz they're hitting all the objectives line by line, they're hitting objectives. So that's what you want in a good certification book. Objectives, if you didn't know, typically. What certifications I used to teach certifications. So what certifications do is they have different domains, right?

Each domain has a different category, a broad category, like for example, C I S P has, I don't know, seven categories. I don't know if this should changed. I took it a long time ago, so I apologize for my ignorance. in advance. Yeah. And I'm a CI S P but the, it has say crypto crypto cryptography domain.

And it has another one that's related to security compliance. Let's just use those as examples. So the cryptography one is gonna have different objectives that it's gonna hit. Like it's gonna have different things that they expect you to know. And those objectives will be different.

From the security compliance domain, which will have its own objectives that go deeper into the details of the concepts behind that domain. And when you take the test, what they do is they stick to those objectives. So if you know the objectives very well, you should be able to pass the test. And if you don't pass the test, you should be able to take it the second time and pass it.

So yeah, that's a good book. And and what was your other question part of your question? That's the book that I would recommend for the cap, and then you said, was interested in your course and guidance. Okay. So for the course, for my course, I would recommend if you're trying to get, become an ISSO, the book is not gonna be enough to become an ISSO.

And this is the reason why I did, I started doing this online stuff is because. Nobody's really teaching this. It's just, I guess if you pay 3000 to somebody come out to your job and actually show you that way. Yeah. But no, there's just not a lot of courses that tell you, give your practical guidance on this stuff.

If you are going into it for the first time, I would highly recommend risk management framework, information, security officer foundations, which tells you what you need to know. For the course. Not for cap, it's not focused on cap, but for the actual work for ISSO work. So if you want a free preview to see if this is worth your time, worth your money, then just go ahead and log in.

And this first part is free. So there you go. And then there's just. Lots and lots of stuff on each one of the categories of the risk management framework process. So yeah it's good for somebody who's just starting out who wants to learn this for the first time and maybe you're an it person, but you're trying to get into risk management, but you are like, man, this I'm reading through the nest 837.

It just doesn't make any sense. I'm speaking to you in plain English and translating by the time you're done with the course. When you read through 853, when you read through risk management framework, 37, you're gonna understand what they're saying. They just use a certain language that is just very cumbersome.

I, myself, after years of this have to reread, sometimes I gotta read it over and over again. Cuz the language is not, they're not using every day speak like we're talking right now. It's just, they use all this different, these different words that you don't normally see. And so you're having to reread it.

yeah. Okay. Answered those two questions and I got a few people talking to me. Let me see, let me read a few of those and somebody's messaging me. Let me just make sure that this is not something important real quick. Okay. All right. So it looks like I'm gonna have to end this session pretty soon. I got a honey do list to attend to.

Okay. I'm gonna read through these as fast as I can. As fast as my dyslexic brain can allow me to process this information. okay. Says spade says I'm maybe five months into my first industry position as a tier one. Oh yeah. Tier one security operation center analyst. I guess I'm not exactly entry level, but I'm looking to make more, some more money.

Yeah, I would. So one of the things that I did looking for a junior security analyst role. Oh, okay. So one of the things that I did that immediately made me more valuable and is there's certain certifications. Now, one of my courses actually talks about this, but I can mention a couple right now, the certain certifications that lend themselves to making more money, like just off the top of my head, a CIS S P certification.

And then there's certain skills certain skills. Actually let me name a couple other certifications, any kind of professional level certification is going to get you more money. CI S P the CASP CI SM C I S a CCNP. Those are our professional level certifications, entry level security certifications would be like security plus and there's a few other ones, but okay, so those are certifications.

And then for skills, if you're in a sock that would be seam, if Splunk, if arch site's not as hot anymore, but Splunk is super hot. If some of the IDSS on IPSS if you're deep in the firewalls if you can configure them hot if you're Palo, Alto's a hot one.

But if you're it's security analyst works. So you're looking at more stuff. That's looking at logs. McAfee products NEIS is a good one. But the top ones right now is still on fire would be Splunk. Yeah, Splunk. And then another hot one, like it's getting more hot, I would say, would be cyber security.

Cyber security, threat intelligence stuff is getting pretty hot. Cloud computing. If you know that one, like more and more organizations are using it. So they need people who know some of the vulnerabilities of cloud technology. What kind of gotchas that organizations fall into is another good thing to know.

So those skill sets are immediately get you in another bracket of pay. I have to warn you though. Once you get to another bracket of pay, you gotta deal with the IRS, but that's a whole nother conversation. Okay. JJ says I got hit up for a cyber security risk management framework engineer, long term remote W2 contract position.

I have no experience with the risk management framework. I'm guessing I got hit up because of my cyber security experience, clearance tips, and tricks. Do I have any tips and tricks for this? You okay. Do you said I have no risk management framework. Okay. So if you ha don't have any experience in it yeah, that's gonna be, I if you want the job I would talk to 'em about taking you on as a, as somebody who's learning it.

Just be honest with them and say, no, I don't have experience with this, but I do have risk. I do have cybersecurity knowledge and I have read through the risk management framework, 853, I've read through 837. I'm familiar with it. I've worked with Compliance officers before I've worked with information system security officers before I've worked with security assessors before whichever one of those is true for you.

If none of 'em are true, of course don't say that, but , if you, so the thing is if you have experienced from cyber security, you have an advantage in that the basic concept of security, which is to protect the CIA protect the confidentiality, integrity, and availability. You can just tell them you have a very strong foundation, explain to them that you have a very found strong foundation in your respective cyber security role, and then build from there.

So if you have a solid skill set in cyber security, even if you're a system administrator, just what you need to do is dig into your archives of all the times you've done. Implementation of security features on a system. I guarantee you have a solid set of skills, right? So with those skills, you wanna tell them, Hey, I know how to secure systems.

I know what to look for. And by the way, I know the risk management framework process. I've not done it before, but I know it now, if you don't know it, go learn it. I have a course that you can go through, check that out that you can add, to be honest with you, you can probably just Google it and read through the risk management framework, 837.

I would highly recommend my course because I'm telling you exactly what you're gonna see and what they're gonna say to you and what they're expecting. And I'd be willing to help you out. So just keep those kind of things in mind, tips and tricks. Number one. Build on what you already know as a cyber security person confidentiality, integrity, availability, you've secured systems of before, more than likely you've worked with assessors and auditors before, more than likely you've worked with compliance people before you've done documentation before you wanna highlight all of those skills that you already have, and then tell 'em Hey, another tip is to learn the risk management framework process.

Learn it by my course. Go ahead and learn, read through it. Watch all the videos. You'll get a solid understanding of what the foundations of risk management framework are. Okay. I'm gonna move on to the next thing. I'm paid member at the first as a first timer. How do I get a job? Because most of the jobs are looking for five years of experience.

So one of the things that I would highly recommend Cobi is to. Look for entry level positions. Okay. Entry level positions, you gotta start somewhere and that start is entry level. Okay. So let me just show you what I mean by that. It's very simple. If you go, if you could follow along with me, if you want go tod.com, this is just one site, by the way, I use this one all the time, cuz it's just so vanilla.

It's so vanilla and so easy to understand and so straightforward that it's feel like it's a really good teaching tool. Okay. So first off here I am in indeed, indeed.com. You're gonna follow along with me. Okay. Put your location wherever you're from wherever you're from. Put that in there. Next thing put there's a couple things you can do here.

You can put ISSO there's a ton of key words you can use for this job. ISSO entry level,

none in this area. Okay. Let me search somewhere all over the United States. Wow. It's just really going to town here. All right. So look at this information system, security officer work, most of the jobs, if you happen to be on the east coast, you should know that you guys have all the jobs you guys have 70% of all the risk management framework jobs.

I'm not even messing around with you, but yeah. So you notice how all of these are Virginia. You can find a job, especially if you have a clearance. There's a couple of things that you have. You may have an advantage. If you happen to live on the east coast, you have an advantage. If you happen to have a security clearance, watch this.

If I put security clearance, if you have a security clearance, you have an advantage. Cause sometimes they're looking for a person with a security clearance and they're they just get desperate, cuz there's just not that many people who have it. So they'll actually pull you in and teach you if you have this.

Now, if you don't have a security clearance, another thing is you got, you could be eligible. For a security clearance. Eligible means you are a a us citizen BLE. I cannot spell what the damn eligible. my first and only language and I can't spell eligible. Yeah. Now all I did was type in eligible and and they, it immediately knows I'm looking for eligible active.

Oh wait, no, I'm looking for eligible. Security eligible for security clearance is what I'm looking for, but it's coming up with active duty okay. But a bunch of, so stuff came up eligible security clearance is what I'm looking for. Eligible security officer. Now these are physical security roles.

Okay. Here we go. Principle means like you're a boss, so you don't want that. information security specialists in an airport. That's physical security. Okay. This is mixing a bunch of stuff up here. Eligible security clearance.

Yeah, here we go. So if you're eligible for security clearance, if this is another another thing that's gonna make it so that you have a better chance of getting a job, the best thing you can have, of course, I'm not even gonna, I'm not gonna BSU is experience. There's no replacement for it, but how do you get experience if you don't have it?

So you gotta go to entry level positions. Now, if you have zero. if you have no it experience that is different. If you have some, listen, let me just be very Frank with you. If you have some it experience, meaning you are a system administrator, you worked on databases, you worked on cryptography, you worked on, you have some it experience.

You worked on workstations, whatever you have a very good chance of getting in, into risk management framework. Okay. You have a very good chance. If you have zero, it experience, meaning you've never held a role at a company or a university or a private or a government or anywhere that is different.

That is different. And the reason why is because risk management framework and security is typically not entry level. It's not like literally walking the door and start flipping burgers. Okay. That's not that this is not that kind of a job. there's too much stuff at stake. There's too much trust that's involved.

There's just, you're gonna be trusted with other people's information and assets. You're gonna be entrusted to know the secrets of that organization where the vulnerabilities are. You're gonna know where they are. They have to trust you. So for that, they need a professional who has something to lose.

All right. That's why cyber security is typically not an entry level position. I'm sure somebody out there right now is watching this saying, Bruce, what are you talking about? I'm an entry level. I'm walking off the street and I'm a cyber security person. Okay. That's fine. But I'm just telling you typically, it's not something you walk off the street and you can do this.

That's don't lose hope. Okay. If you don't have it experience, if you don't, if you've never done any of this stuff before, there's a couple things you can do. People contact me all the time and what the last time I did a couple weeks ago, somebody an educator contacted me and she said, Hey, Bruce I really wanna get into it.

I want to be getting a risk management framework. I like what you're saying. It sounds cool to me. I wanna do it. She's an educator. She had a master's degree in education. She has very little or no it skills. And I said, Hey, you might wanna consider becoming a program manager, okay. Program managers work with it.

They, and in some cases they have to know our, they gotta know what we're talking about. They have to know some of our jargon. They don't have to know how to configure a server. They don't have, they don't have to know how to stand up a Linux box. They don't have to know how to reduce threats on a. on a weapon system, they don't have to do all that, but what they do have to do is they have to have a certain level of maturity to manage a project and they have to have a certain level of technical know how with things like office so those are some of the things that you would, what I would suggest if you were trying to get in a high paying, very high, skilled, high paying job in it.

One of the things you can do is get a parallel job, which is a project manager position. It pays six figures by the way. Okay. It's not a joke. It's no joke. Program management is no joke. You can actually, even without an it experience, you can get in there and you can make upwards of six figures.

Look it up. Look it up. It's a damn good job. So yeah, number one, if you don't have any it experience at all, you gotta get it experience. You got, you have to, whether you're volunteering at your church, volunteering at your job. If let's say you're a system administrator you're a non system administrator.

You're HR, you're in the HR department, right? You work with people's w two S and stuff. You wanna get an it, but you don't know what to do. You don't wanna do a program management work. You don't wanna do that. You wanna do it. Okay. Then you gotta start from the bottom. Imagine somebody walking in your job in your profession, off the streets, not knowing anything and wanting the keys to the castle.

Okay. With cyber security. That's what we're talking about. You gotta, you, if you have no experience, you gotta get it. That means you gotta become, go to help desk entry level position is what I would suggest if you have zero it experience, but you wanna get technical. Yes. Go into, try to entry level positions, volunteer, do it for free.

Cause that work that you're gonna put in for free fixing somebody's laptops at some corporation is not indentured servitude. It's. That you're building up experience. It's experience. You're slowly building up and putting on your resume, building up experience, putting it on your resume. Then that'll allow you to level up to another job, a higher level it job.

You do that by the way, while you're working on your security. Plus, while you're working on your a plus certification, a entry level position with an entry level certification, then once you have those things, now we're talking about months and years worth of work. This is hard work. This is not something you walk off the street and then suddenly you do it.

People are gonna entrust think, imagine your bank. Okay. LIS if you don't think it's fair, just imagine your bank, whatever, wherever you bank in the back, they have a security person who D who a cybersecurity person who has no experience, but they know where all the SU they know where all the vulnerabilities of the bank are.

They know. Where the threats, they don't even know what threats are. They don't know what threats are, but they know there's vulnerabilities. They ran the scan. Do you want that person at your bank as a cyber security person who doesn't know what they're doing, who has no experience with it? No, you don't.

So I, when you're talking about cyber security, you're talking about somebody who's entrusted with the keys to the castle. They have to have something at stake. And that means you have to put in the work as an it for me to you. If you're an it professional, if you are trying to get cyber security, like we ha we are entrusted with something, with a lot of information so you have to have something, you have to have some skin in the game.

That means time. That means you, you invested your own time and money to get to the skill set and the skill level that you're at. And you're not willing to risk it by making a mistake or doing something stupid. And I everybody makes mistakes, but. As you get to learn how to troubleshoot as you get to learn how these systems work, how to do backups you begin to learn how to manage your own risk for your own profession.

You manage the risk to yourself and ran, manage the risk to your organization and the risk to the organization's information. I hope that makes sense to everybody out there listening. Let me see. And I'm gonna, I gotta do a couple guys. I gotta get going here. I apologize for cutting this one short, but let me see.

Can you get a ISSO job with a green card as a green card holder? That is a good question. Yes, you, you can, however There. Not, maybe not an it's gonna be harder to get an so job. Okay. But let me show you, let me show you my screen here. Let me show you how you can get a compliance job, a security compliance job with a green card.

So there are security, cybersecurity jobs that have a public trust clearance. It's a type of clearance, public trust clearance. It's a type of clearance that doesn't require you to be a us citizen. If I'm not mistaken. Yeah, let me see, let me try this one here. And usually they'll say, Hey, you must be a us citizen.

They'll tell you right on there. This one might not be, and it's not giving me that information. So this is a public trust. I think. but it's not okay. How about this? Let's do this. Let's just be straightforward here. Let's just say, watch this cyber security green card. They usually put GC as a green card, by the way.

Let's see cloud strike. Let's look at this one. It will say in here. Yep. There you go. Right there. See this that's the keyword right there. See it says green card for clearance, us citizen or green card for clearance. There you go. That's what you wanna look for when you're looking for positions now, do they do this for ISLs?

Let's see, let's just type in ISL. I don't, I've not seen a lot of green card holders be ISLs, but I could be wrong. Senior chemist, see that see is so usually in ISSOs working for a high level government agency and they require that you be a us citizen. So that's why you, I just don't I off the top of my head, I don't know if any ISSOs, but I know that there's actually, I take that back.

So there's some corporations there's some corporations who do ISSO work and they will hire a green card holder. But what I would do if I were you, is I would just

senior associate cyber risk.

See I'm currently working in an organization that we have people from all over the world working with us. So I know for sure you can do cyber security, cyber risk in the us without being a us citizen. I know several people who that work on our team who are in that exact position, but are they ISSOs we're not doing those kinds of, we're not doing D O D type stuff.

So let me see here. I'm looking for, did I just pass it? Yeah, it's in here must be a us citizen or green car holder. And most of these are gonna be, must be a us citizen, an our green car holder jobs. Yeah. We couldn't find an ISSO position. That's green card, but you can find. All right, guys. I have to go.

I gotta get going here. Thank you so much for watching me. If you have any other questions, if you look in the description below, there'll be a place where you can actually join me all times of the day on holidays and weekends and stuff on discord, you have any kind of questions. I'll answer. 'em when I can also you can always email me.

It's, cyberware 2020 gmail.com and we can talk about any kind, and I'll actually make a video sometimes about people ask me really great questions that I think could help many people. And you'd be surprised sometimes people ask me a question, but several other people ask me that exact same question.

So I know it's something that is relevant and I know it's something that needs to be addressed. So then I'll just go ahead and make a whole video about it. All right, guys. Thank you for all your questions. Thanks a lot. Copy. If I didn't answer your question, please answer, ask me on discord in the linked description below spades.

Thank you so much for that. I hope that's how you pronounce your name. Marcus, thank you for your comments. I did not get to your comments, but let, what I'll do is I will copy this and use this for another time. Another video. Thank you guys so much for watching. Join me on discord. If you have any, if you have a pressing question and we will talk.

View Details

http://convocourses.com

Hey, happy new year, everybody. This is a podcast for combo courses, and today we're gonna be talking about we got some, a few questions that, that have been asked of me. I've got a resume to go through. And I wanna talk to you guys about 20, 21 and what what I'm gonna be studying this year as a focus for like certifications or just sharpening my skill and some things that I would recommend that you look at too.

Cause I think it's looking forward five years ahead. What I think is gonna happen as far as our industry is concerned, cyber security or data analysis and things like that. And so let's get started. So the first thing I wanna talk to you guys about is some of the things that I'm gonna study in 2021, the things that I think that are gonna be relevant going forward in the future.

And let me just switch my screen here to show you the very first thing. that I wanna show you is blockchain technology. This is something I think that's gonna be more and more re relevant. If you've been watching the news, you've been seeing cryptocurrency going off the rails lately. And a lot of this technology the money is based on blockchain.

And I don't think that this technology's going away. It has all the hallmarks of what I saw with cloud computing many years ago, and everybody kept talking about it and it just kept coming up over and over again. It's really the same trends I'm seeing where all these gigantic companies and all these giant organizations are really dipping their toe in a blockchain technology and very quickly what it is a basically it's a digital ledger.

It's a distributed digital ledger that allows you to basic you, you can essentially you. , you don't have to have a middleman. It allows you to not have a middleman because there's something there's a, normally, if you like a, with a bank, for example, a bank is a middleman to your money. Your money is there.

You have to go to the bank to get your money, but with a digital ledger, basically, essentially your money is out there on the web and distribute. It's all over the place it's distributed and encrypted so that you can access it. And it has it's a cure. It allows you to be anonymous and and it's something, it validates it so that you can't, you people can't say that they didn't make that a payment or could, or didn't get a payment.

It's immutable. That's what that means. So the technology is emerging slowly but surely and not just cryptocurrency by the way, but also for things like logistics. And even voting can be done with the blockchain, many other things that we use every day can be used with blockchain technology.

And so that's why I'm gonna be studying more on this the actual technology behind it as opposed to just cryptocurrency for the sake of making money and investments and things, that's a whole separate issue. Blockchain itself does much more than just money and essentially, like what, another thing that you should know about blockchain technology is that let me see Oracle starting to use it.

Walmart is starting to use it and many different other organizations and governments are start. Dip their toe in this technology. And it looks a lot like what cloud technology was looking like about 10 years ago. All right. Another thing I'm gonna be studying very heavily is cyber threat intelligence.

This is becoming much more important to anybody who does cyber security and what this is from a high level is it's. If you have a customer or if you have an org you're in an organization, either one and you're protecting someone's assets, their laptops, their servers, their information, their personnel, you're protecting their assets.

Cyber threat intelligence is where you do recon to see if anyone is. Looking into trying to break into those assets and the way you would, one of the ways that you could do it is to have a cyber threat intelligence cyber threat intelligence system that goes out and checks the dark web checks the internet to see who's talking about your organization.

Does anybody have your, the IPS of your organization or is anybody scanning your organization? So you're looking for where people are trying to get into your organization, a preemptive you're. You're doing preemptive checks to see if there's anyone trying to get into your systems.

This is gonna be really more and more important as technology becomes even more important in our, in all of our lives. If you looked at the recent gigantic hacks that are going on, state sponsored hacks are happening. And the one of the ways to. to have some kind of defense against the state funded state sponsored actors is to actually do cyber threat intelligence.

See if anybody has been CA casing the joint, scanning your network scanning and see if you have any vulnerabilities out there. So cyber threat intelligence is something I'm gonna really dive into this year, and that's gonna start off with with things like ethical hacking, and then I'm gonna get into cyber threat intelligence, cuz you gotta know a little bit about ethical hacking and stuff to actually know a deep, have a deeper understanding of what threat intelligence is.

And another thing I'm gonna dive into this year and I've put it off way too long is cloud computing technology. And this is something I talk about a lot on this channel and it is just getting more and more important. Like it's not going away. It's just. it's really become a centerpiece of all of our lives whether you know it or not.

If you've, if you watch Netflix, if you use Gmail, if you use Hotmail , if you, whatever you use, like most of these gigantic technologies are using cloud technologies on the back end. So it's just becoming more and more important. And me as a cyber security person, I need to know have a deeper understanding of what that is all about.

So those are the things that I'm gonna study this year for 2021, and possibly get certifications in some of these technologies and actually it's become a required couple. Two of those things on that list that I just mentioned to you are, have become a requirement for the job that I work at, that I have to actually get a certification in 'em.

So this is something that, that I'm definitely gonna do. And I think. These tell those three things are gonna become more and more important in the next five to 10 years. All right. Let me see if I got anything else. I see a few people watching me. If you guys have any questions, let me know.

I'll give you guys time here. If anybody wants to chime in, I've got a few people who've asked me questions and a few people who've asked me to actually look at their resume. So I'm gonna actually do that. Let me see if I can find a good one to look at here. The first one I'm gonna look at is going to be from the, I changed the names, just so you know, change the names and the addresses and everything on there.

So there's no need to worry about that. I'm gonna look at this resume right here. And what I like to do is I will. get, put my suggestions in there sometimes the resumes are so good. I don't really have much to say about it, but it's just like little tweaks and stuff of what I've done on my own personal resume to give them some, to give them some extra juice, some Google juice on that resume and my mindset is that I market myself.

And so I encourage anybody, any of my students, anybody who follows me to do the same thing, you gotta market yourself. It's very important in this day and age, there's just so many people. And there's so many competitors out there for you. There's so many other eyeballs on other different resumes that you gotta put yourself.

You gotta set yourself apart by advertising yourself, marketing yourself. Okay. So this is coming from Mike and he's in the DMV area and he is a senior assessment and authorization engineer. Okay. All right. I've never heard that. Title before, but that's good. If just one suggestion I would make here is if you're Mar if you're looking for a different job, I would, one of the things that I do is I put some more more common, a more common name out there.

So this to me sounds like it's and I could be wrong here, but one of the things that he could do is say, he's a security, and I'm gonna read through the resume. This might change. I would suggest I'll just say suggestion is to have the title of this, be a security control assessor. And the reason why I would say that is because the security control assessor is a more common name for this type of work.

But then I, this might be something I've not. I'm not familiar with authorization engineer, but it is just not something I've heard people use in my industry. So that's why I I would recommend they do this now. This is good. They put active top secret clearance. That's really, that's excellent.

You, do you definitely wanna put any kind of clearances that you have here? Up top, because that's a very marketable thing to have that immediately eliminates 80% of the people who are gonna compete against you. So that's a very good thing to put on a resume. Let me see, I'm gonna read the top part of this qualification profile.

This is pretty good to have, like whenever you're marketing yourself because places like LinkedIn will have an area where you can put stuff like this, but what I normally do is I take advantage of it by putting as many keyword as possible inside of this profile. You don't want it to just be flowery and sound good.

You want it to hit 'em right in their teeth. You know what I mean? You want 'em to grab their attention immediately with a bunch of keywords. So they said concept and execution con concept to execution focus, systematic profe. I would not put any of this stuff in here. Okay. I'm just gonna, I'm just gonna suggest some things here.

I'm just gonna suggest some stuff I'm gonna say. Now I'll have to read the, what I'll do is I'll read through the resume. I'll come back and fix this up, but it's just way too flowery for me. Like I would not, if I was reading this, I would just skip right by it cuz I want to know what they can do core competencies.

These are good. But another thing that I do personally is I take this and I put it at the end, any kind of listing stuff like that. I put it at the end.

Cuz it will get picked up by the search engines. That's the reason why I do it. But when I'm reading through it, I want to very quickly know know what their education is, cuz that's normally a show stopper or a show it gets the show on the road if they know, okay, this guy has a bachelor's degree.

That's one of the requirements. He has a C I SM certification. That's one of our requirements. So you wanna very quickly have all the main things up here. Now this dude's actually got a great resume here. He's got some great set of skills. So another thing I do is I would put your top certification right up top, like this C S M I would say, is this top certification?

I would say I would put it right up here. Not trying to brag or anything, but I am a CI SM. And maybe you put the number in there cuz this is gonna be. Guaranteed a requirement. That's gonna this certification right here can replace things like C I S P and some other large level high, sorry, large high level security certifications that that he has.

And then the cast is also a really good one. But I think the C I SM is a better, has a, is better, is a higher level. It's more, no more people know about the C I S M I should say. Okay. So he's got a ethical hacker certification. That's also a good one. I would, that's another one you might wanna put up here as well.

That's a very marketable certification, a lot of pen testers and hackers really look down upon the C, but I'm telling you it's very marketable cuz the corporations have not gotten the memo, the government and the corporations have not gotten the memo on, on how bad this certification is. So it's very, still very marketable.

Yeah, I would put that on top. Let's see security plus. Okay. And some other stuff. All right. Let's keep going here. Scott. Cyber security professionals, Maryland. Oh, okay. Affiliation. I'll put this at the bottom. We wanna get to the meat. The meat is the actual experience. So I'm gonna take this, I'm gonna put this at the bottom.

This is a great resume, by the way this is right at this point, all I'm doing is putting my own suggestions in here which he can take it with a grain of salt. Like I, it, this, he could leave it just how it is and it would still be fine cuz he's got so much good stuff in here. The only thing I would highly recommend changing is.

this right here. Cause you want this to have impact. And this to me, expert at administering desktop printers, and this is not a good impact. This is not tip in my mind if I was reading this and I was trying to hire this guy, I'd be like, eh, whatever next I'm not trying to be mean or anything, but just keeping it real with you guys so that you guys don't do the same kind of stuff on your resume.

No flowers, just straight facts keywords, stuff like that. Okay. Let's see. So job was at K force to current. All right. Top secret clearance. Let's see a C Splunk. Okay. This is actually really good stuff. Support all activities on as outlined in this 837, 1 37. Okay. All right. Not seeing a lot of impact.

But I'm seeing lots of great keyword, so that's good support all outlined in. Okay. Review and analyze a and a as assessment and authorization. Security controls missed overlays experienced using administrative administration of EAs. Okay. So this guy, it sounds like he's like a is O but I'm not really sure what, cuz he names himself as a senior assessment authorization engineer.

That sounds like an ISSO. So another suggestion I would make is to possibly or use IFSO

information system security officer. and then I'll just tell 'em here. That senior, what I'm trying to get at is it's a senior assessment and authorization engineer is uncommon, is an uncommon title is an UN uncommon title. That's all I'm trying to say. So you wanna use like a common ti, if you're gonna put a title up here, it should be a title that people know about.

And that also fuels your your Google juice, your keyword cuz the, and the thing, the reason why I emphasize on my courses and whenever I do these resume suggestions, these are my suggestions. I'm sure other people have way better ideas than me, but these are just my suggestions.

The reason why I focus so much on keywords is because that's really what a lot of employers and a. Technical recruiters use as keywords re technical recruiters and the HR department. Who's looking for jobs and stuff. Typically they're not a technical person in your field every now and then a organization has the resources to cut some technical guys loose and say, Hey, go look through all these resumes and screen some people and have 'em come in.

But typically what happens is your resources. is your guys on the ground. You need them to actually do work. You don't want them to go looking through a hundred resumes. You want them to be working on cloud stuff. You want them to be analyzing data. You want them to be doing their job.

You're gonna have. So that's why, what organizations do is they have people who are not low level workers. It's not the right term, but. HR a screener from a whole, a third party organization, a third party company, they say, okay, look, here's our requirements. Please look through these hundreds and hundreds of different resumes and see if you can find us some good picks, just we gotta make sure that they have us and CSM.

They have to be in information system, security officer and see the thing is when they say we want a system security officer, they're not gonna know what a senior assessment and authorization engineer is is that, does that make sense? So you wanna use the same language that people are using if everybody is using cyber security.

The thing is I've been through a few iterations of this. So first iteration, when I went into security, Everybody called the information assurance, like if you were doing risk management framework, if you were doing certification and accreditation, that's what they called it. We were called either certification and accreditation engineers, or we were called information assurance officers, or we were called like this, just it's just an odd, that was like information AUR.

What is that? What they meant was security. You're security guy who does paperwork essentially you're a compliance guy that would make more sense, but then it evolved from information assurance to what did they start calling it? It was information system security, then information assurance, and then they start calling cyber sec, cyber security engineer information.

Change. And now the do D I think they are calling it like cyber surety or something like that. I don't, they keep changing the terminology, but you wanna keep up with the terminology people are using in this industry. So that way what words to use for those HR guys or those screeners who are who's, who are looking for all these resumes.

And they're looking for that one keyword, they don't know what an information system security officer is. All they know is that the employer said, Hey, we want an information system. And if so make sure that's you get this person. And so you gotta use those keywords. Okay. I'm gonna get off my get off my soapbox here and I'm gonna continue going through some of these.

Yeah. Tony, I see your message here. Let me just finish this. Getting through this resume. This resume does not look bad by the way. I've seen some really bad resumes. If you've been watching these for a while. I've been through a couple who were, that were really bad. This one's actually pretty good.

It's got great keywords. My only main suggestion would be, I'd be really surprised if this doesn't get tons of offers. My only change would be to change this whole, this right here. This is just this just too much fluff. Just get to the what. Okay. Let me just give you an example of what I would write here.

What I would do is I would say something like, cuz this guy has so much awesome skills. Let me just read through what he's done before. Let me see. And now analyze vulnerability data, multiple sources using a cast and Splunk. Okay. Here's what I would do.

I don't know how many years of experience this person has, but I would start off with my years of experience. I would say it looks like he has years of experience. Look as a security analyst. Good Lord. Jesus. Why? What are you doing here? What I would I'm sorry guys. I'm just, I'm a little frustrated.

Okay. I would say X years of cyber security analyst work using tools such as is Splunk. NEIS I don't know how to spell NEIS so he is gonna do a spell check NEIS.

He said a castle that's NSUs you wanna use? NSUs that's a real good tool to have. And let's see, EMA wait and a grasp of

No, not grasp, but we wanna emphasize how much skills this guy has. Cybersecurity analyst work using tools such as eight years of experience or whatever years, experience analyst work, using tools such as Splunk S with, okay. And okay, here we go. We'll say, and NEIS with a with solid experience.

Implementing

Risk management framework.

And we want to get that keyword in there. RMF, I'm gonna say N 800 also key phrases with solid. Okay. Yeah. See, I would start off. I wanted someone hit 'em right in their mouth. I don't want them when they see my resume. They're gonna stop reading all other resumes when I'm done. That's your goal.

You want them to stop on your resume and not read another resume? Okay. He, this dude got so much experience, like why is he saying all this fluff? That doesn't oh my God. Okay. So yeah, I would just hit him right in their mouth. Like I, okay. Then he wants to say. Have I have a active security clearance now you might be thinking, Bruce, why are you saying clearance over?

He says it here already because we're using a different keyword. So up here, he said, active top secret clearance right here. We're saying active security clearance. It's a, there's a difference. And we gotta spell it by the way, there's a difference because it's a different key word. So somebody's looking for security clearance and they want you to have a they want you to have a security, a secret clearance instead of top secret clearance.

They'll still see that you have a clearance period. They'll go, they'll be looking for a secret clearance. And they find a guy with an active top secret clearance. You know what I mean? So we wanna make the net as broad as possible. This dude's got so much incredible experience. That there's a lot to choose from here.

I would put something like this in here. Okay. Okay. Watch this. So we wanna put more about his in information security officer experience. So we wanna put ISSO with years of experience.

See how I can't spell. see. It's very important to do a spell check all right. Experience. If so with years of experience getting authorization to operate and with, for, and for multiple information systems.

So I got a bunch of keyword in here. I got cybersecurity analyst. That's a keyword key phrase. We got Splunk. We got NEIS, we've got risk management framework. We've got N 800. We've got a O we just want to hit all the buttons. We don't want fluff. We don't. Oh, bilingual. This is a good one too.

This is really good. And oh, by the way, I'm bilingual. Yeah. Super powerful. Bilingual opens up a ton more jobs for you. If more than one language, any language it's gonna open up other jobs for you. So that's just something that to keep in mind. All right. So that's it with that one. I I hope that that's helpful to, whoever's watching this the idea behind this is to get yourself in line with the market.

that's the whole thing. And you need to do that. You need to tell people who you are. You gotta show people, Hey, here I am. That's what marketing is all about. So you wanna market yourself. That's the whole, that's my whole thought process. Okay. Tony says, Hey bro, I have about seven years of compliance experience and I'm bored to say the least

I want to move into security engineering and architect roles. How do do you suggest I proceed? Wow. Tony that's I had the same experience. Like I, I had been doing it for I don't know, 12 years or something, and I just got so bored with it. It wasn't a challenge anymore for me, and I know that sounds ridiculous if you're getting paid and you're, you got a secure job, but you need some kind of a stimulation. I got into it cuz I love technology, and so I was doing this for like years and years compliance and I found myself losing my technical cuz I had technical skills and I started losing that because all I was doing was compliance stuff.

So I know how you feel. So what I did was I I just jumped off a cliff man. Like I, and I don't recommend this to anybody, but this is what I did. I took a job doing something that I was really excited about. I was looking for another position I was in between jobs and I was looking for another position and somebody off had a job overseas.

to do. They actually, it was risk management framework. I applied for that and I applied for another position they had for a system security analyst. I applied for the system security analyst and I didn't I of read about it. And it was talking about using Sims and talked about using tools like.

McAfee EPO and IDSS and IPS. And I was excited. I'm like, oh man, this is so cool. I've never even some of the stuff I never even touched before. So I was really wanting to get into it. So what I did was I applied for that job, as well as the risk management frame, I was fully expecting them to look at my resume for risk management and be like, okay, this is our risk management guy.

They didn't do that. They chose me for cyber security. They looked at all of my old technical skills and they were like, okay, this guy right here we really need somebody to do this work for cyber security analyst work. And they picked me up and they picked me up as a, like a junior cybersecurity analyst where I was learning I wasn't like the guy, the main guy on the floor.

Doing everything. I was like, one of the people like learning different technologies and actually staring at a monitor, looking at the data, coming in, out of a network and analyzing, they taught me arc site. They taught me, which is a SIM kind of like Splunk, a little bit of Splunk. They taught us all these different tools, man.

I had a blast, I'm learned so much stuff, but I had to learn, like I was like, I was fresh outta college. had to swallow my pride and I had to take, which I have no problem with, but I know that some older guys, especially if you've been in it for cyber security or it for a while some of us we've seen war zones and stuff, so it's like, why is this kid telling me what to do? But I didn't feel that way. I was like a kid. I was like a little kid learning like a wide-eyed little kid oh yeah. Really getting into it and. and then my work ethic kicked in and I learned everything. I could, I absorbed as much information like a sponge.

And so I would, so that's what what you could do. You don't have to go to another country or anything. Like I did jump off a cliff or anything, but what you could do is just apply for a junior level security engineering and architect role to get your beak wet to get started but keep in mind, if you have seven years experience you can't come in the door with the chip on your shoulder oh yeah.

I already know that I've done it for 15 years and throw your weight around or no, you gotta be like a little kid, and that's what I love about it is that I'm learning so many things like you can like right now, if somebody, if I went to a firewall role, even though I've touched them before I know how they work and stuff, I don't know how to configure a fire.

I can't do that from scratch. Somebody would have to sit down and teach. Like from, they'd have to teach me from the ground up. Now I'd learn very quickly cuz I have all this experience and all these other tools and stuff, but you I'd have to be open minded and learn what they're teaching me and not come in there.

Like I know everything and not knowing I have to come in there, like I'm an intern fresh outta college and I'm willing to learn from this Pierce person. Who's more than likely younger than me, so yeah, that's what I would do, Tony. I know how you feel. I felt the same thing many years ago, that path right there for the in terms of my career was a great move because now I have so many other doors and opportunities that have opened up over the years. And because I have this plethora of different experience that I can pick from I'm now a consultant. Like I can consult on all these different things.

I've touched so many different technologies before, and I don't have to actually be an expert on each one, but I know the concept so well that I'm able to say, okay, I know how this works with this. And I can look at data and say, okay, this is what I'm seeing here but yeah what I would do if I was you Tony, and actually that's what I did in the past.

And I know how you feel. All right. I got some other questions here that some folks have contacted me about and I'm gonna answer them. So let me show you guys what I'm seeing here. Let me show you what I am seeing all. So I've got a question. From my man. So Solomon H and he says I received a contingent offer for wait wait for security control assessor position.

And I'm proc I'm in the process of getting my clearance. I don't have a background in risk management framework or any cyber security compliance. What advice can you give me? I'm relatively new in cyber security and only have one to two years experience as a system administrator. I know that my job will focus on security and privacy controls.

As I look over the, as I look over the next 853 documentation. I've enrolled in your course. And so I can better understand an overview of how risk management framework works. Is there anything else that you can help me with or give me any kind of guidance? Yeah, actually I really can help with this.

I would say that if you happen to be watching this, Sawman as a system administrator, if you guys out there are system administrators, you should know. And especially if you're trying to go into cyber security, you should know that actually you have many years of security experience.

So if you have set up a server before and had to put the patches on that server, that security experience, if you've ever had to do some documentation on the system that you set up where you had to draw out a diagram, put that together and shop that around to the rest of the. The guys on on the staff you've, that's cyber security.

That's a little taste of all of these different things are taste of cyber security. If you've ever had to help the compliance guys out and those guys that contact you and say, Hey, could you give me, could you give me a blurb or some documentation about what this security feature of the system is?

Guess what that's, you've actually assisted with cyber security compliance. If you've ever put a secured software on the system, you put the software on there and then you had to update it. That's also cyber security, cuz you're updating the patches that could have been exploited by a threat actor so if you've ever put signatures on a system for anti-virus, that's also cyber security. If you've ever. Hard in a system like where, okay. Let's say that the, there is a password protection on there, but it doesn't have upper and lowercase and it doesn't have, it doesn't have password complexity, but you had to go on the back end of the server and ensure that the whole organization is enforcing password complexity or enforcing multifactor authentication or enforcing audit logs to be enabled for anybody who's failed, a failed login attempts or anything.

All of those things. If you are a system, administrator are things that you could put on your, you should put on your resume as a cyber security person, cuz you have done cyber security. In fact, you have, I would argue you have done more cyber security than some. Have quote or quote unquote in cybersecurity who have not done any technical stuff.

And all they do is policy. You've done more than them because you're go, you're now be able to go deep in policy and deep in technical, the technical side, your skills are very much needed in this field. Now you said that you're going into security control assessments. So this is security control assessors from my interactions with them and having done this myself.

We, the, you need a team of people who can assess different aspects of an organization. Systems. What I mean by that is you're not just looking at documentation. You're not just looking at their security policy and saying, okay, looks like you've got you've guys have a policy in place, and it's been updated on this and that date.

You're not just doing that. You're also ensuring that the organization is complying with their own security policies. And that means that you have to run things, do things like run scans, so you might have to Polish up on your ability to run a necess scan or a, I don't know, name, a name, a scanner.

And you might have to know a little bit more about that, but I'm sure you'll pick that up pretty fast being a system administrator. So that's one thing yeah, learning the nest 800. 37 I would say is another place to look. But if you're taking my course that's gonna walk, that's gonna really touch on what you need to know for N 853 and N 837.

It's gonna really touch on those things. And there's perspective of an information system, security officer. That course is actually really good for for se, especially if you're new to that work. Yeah, I hope that helps. That's a little bit of guidance for you if you're taking the course.

If you happen to see this this video, Sawman any questions you have whatsoever, I actually are currently doing assessments for different organizations, so I can help you out with that. Okay. I've got another question here. And somebody said oh wait. Spade says do you offer any mentoring opportunities?

Can you remind us of how. we could work with you concerning career guidance and resumes if possible. Yes. So spades, I get this questions like weekly now. I do not do mentoring because I have a full time job and I really enjoy what I'm doing with teaching online, or I really am getting into it.

I'm starting to meet other people. I'm learning stuff from other instructors. I'm really excited about it. So I wanna spend my time doing that. But what I can do if you're interested is I've got a bunch of courses. Let me just show you what I'm talking about here. I've got a bunch of courses that you can sign up for.

Some of this stuff is actually free. So what I do is I put out a course and I give a portion. a portion of it free, and some are just completely free. Some from scratch. If you're learning this from the beginning and you want to get into cyber security, then this is a free course for you to shows you what to actually focus on.

It's six hours along, by the way. It's not, it didn't start off free but I felt like it's time to help more people out that really need it to get into this market. I've got something on resume marketing, like how I have been able to have a job since I got outta the military I've got so many opportunities all the time because of this meth method that I use, some of which I teach for free on YouTube, by the way, some of the stuff I tell you guys is in this course, but it's a breakdown.

Let me just show you how extensive this is, this many hours of content and shows you, and you can use it as a reference. You don't have to go through line by line on all this stuff, but shows you what I do to. Have so much success in my career and continuously have offers from all different kinds of organizations and different industries related to cybersecurity.

And then I've got a walkthrough of the risk management framework process from the perspective of an information system, security officer. I've got a deeper dive into that, of how to actually do the documentation piece and downloadable templates that you can use. And I'm sharing essentially my experience in this field so that you're not lost and you know where to go and how to upgrade yourself and how to make more income.

Let's keep it real. This is about taking care of your family and taking care of your being, having some stability, financial stability. I'm talking about how I've been able to secure my life and my family using this career field. So that's what I'm talking about in there. And tons of it's free.

So you should, at least you should sign up. Check out the free stuff. If you like it. Now, if you do sign up, I do answer any of your questions. You I'm gonna set up communities there. There's lots more to come in 20 21, 20 22, 20 23 plan to be in around for a long time and offering as much help as possible for people.

My wife's calling me. Sorry, let me just turn that off real quick. Okay. So yeah. So yeah, I do not do mentoring just yet. Maybe I have a full time job. I love my job. I love, I know that's a weird thing to say, but I'm really having fun, like learning different things. And my, when I'm at work, I'm like really at work I don't have time to do anything else.

I'm really doing stuff. And I'm doing, I'm just learning so much. I do have a discord channel if you have, if. Anytime you want to question have que, especially if you happen to be a member of the site, if you happen to be a paying member of the site, I'm gonna go outta my way to help you out in, in very deep ways stuff that I, we wouldn't be able to share on here, obviously if it's more personal or if it's more related to specific things at your job, then of course I'm not gonna make a video about that.

So that's the kind of stuff that I do offer, and those are things that I can do on the weekends, like when I'm off work and things like that, and there might be a time when I'm on lunch or something, or just after work or whatever, I'm on, I'm off that day and I can call and we can have a I've talked to my students before on the phone, like we're just back and forth talking about stuff that's tailored to their life.

But as far as mentoring on a regular basis, I would take it extremely seriously. And I just, I'm not ready. I don't have the time and the day to, to dedicate to that. To that. So yeah, so that's where we're at with that. Let me see thank you guys for watching. Appreciate everybody. I got another question that someone asked me.

They said, let me switch this screen here so you can see what I'm seeing. They said, hello, Bruce. I'm interested in becoming an information system, security officer and was interested in your course and what guidance you can provide on what courses on your site I should start with. I was using Darrell Gibson, but I think he's a real popular security plus trainer, but I know the 5 0 1 expires on July 21st, 2021.

What books should I get for the risk management framework for the cap? Okay. So first of all, I am. Developing a cap course. But that's not gonna be out for a while now, if you wanna know what book that I would use right now for the cap course, I can share that with you. I'm gonna bring that up real quick.

The one that I think is a really good one, it's not cheap. And it's so expensive. I wanna apologize for how expensive it is. but there's no real op alternatives to this book that I've seen. There's there's just not a lot on the cap and that's why a lot of people follow me cuz there's, that's not a lot of people talking about risk management framework.

And this is one of the few books that that are out there that I think are worth your time. I have this book and it's, and I'm reading through it and it's really good. As far as taking the cap, it's really good. I don't believe it's super practical. But I think it's a good book for the actual test.

When I say practical, there's a difference between if you're an it guy this there's a difference between actually taking the test. There's a difference between taking the test and doing the work. And they're just two separate things. So that book right there is really good for the official guide to the cap.

Common body of knowledge is a good book for taking the test. Cuz they're hitting all the objectives line by line, they're hitting objectives. So that's what you want in a good certification book. Objectives, if you didn't know, typically. What certifications I used to teach certifications. So what certifications do is they have different domains, right?

Each domain has a different category, a broad category, like for example, C I S P has, I don't know, seven categories. I don't know if this should changed. I took it a long time ago, so I apologize for my ignorance. in advance. Yeah. And I'm a CI S P but the, it has say crypto crypto cryptography domain.

And it has another one that's related to security compliance. Let's just use those as examples. So the cryptography one is gonna have different objectives that it's gonna hit. Like it's gonna have different things that they expect you to know. And those objectives will be different.

From the security compliance domain, which will have its own objectives that go deeper into the details of the concepts behind that domain. And when you take the test, what they do is they stick to those objectives. So if you know the objectives very well, you should be able to pass the test. And if you don't pass the test, you should be able to take it the second time and pass it.

So yeah, that's a good book. And and what was your other question part of your question? That's the book that I would recommend for the cap, and then you said, was interested in your course and guidance. Okay. So for the course, for my course, I would recommend if you're trying to get, become an ISSO, the book is not gonna be enough to become an ISSO.

And this is the reason why I did, I started doing this online stuff is because. Nobody's really teaching this. It's just, I guess if you pay 3000 to somebody come out to your job and actually show you that way. Yeah. But no, there's just not a lot of courses that tell you, give your practical guidance on this stuff.

If you are going into it for the first time, I would highly recommend risk management framework, information, security officer foundations, which tells you what you need to know. For the course. Not for cap, it's not focused on cap, but for the actual work for ISSO work. So if you want a free preview to see if this is worth your time, worth your money, then just go ahead and log in.

And this first part is free. So there you go. And then there's just. Lots and lots of stuff on each one of the categories of the risk management framework process. So yeah it's good for somebody who's just starting out who wants to learn this for the first time and maybe you're an it person, but you're trying to get into risk management, but you are like, man, this I'm reading through the nest 837.

It just doesn't make any sense. I'm speaking to you in plain English and translating by the time you're done with the course. When you read through 853, when you read through risk management framework, 37, you're gonna understand what they're saying. They just use a certain language that is just very cumbersome.

I, myself, after years of this have to reread, sometimes I gotta read it over and over again. Cuz the language is not, they're not using every day speak like we're talking right now. It's just, they use all this different, these different words that you don't normally see. And so you're having to reread it.

yeah. Okay. Answered those two questions and I got a few people talking to me. Let me see, let me read a few of those and somebody's messaging me. Let me just make sure that this is not something important real quick. Okay. All right. So it looks like I'm gonna have to end this session pretty soon. I got a honey do list to attend to.

Okay. I'm gonna read through these as fast as I can. As fast as my dyslexic brain can allow me to process this information. okay. Says spade says I'm maybe five months into my first industry position as a tier one. Oh yeah. Tier one security operation center analyst. I guess I'm not exactly entry level, but I'm looking to make more, some more money.

Yeah, I would. So one of the things that I did looking for a junior security analyst role. Oh, okay. So one of the things that I did that immediately made me more valuable and is there's certain certifications. Now, one of my courses actually talks about this, but I can mention a couple right now, the certain certifications that lend themselves to making more money, like just off the top of my head, a CIS S P certification.

And then there's certain skills certain skills. Actually let me name a couple other certifications, any kind of professional level certification is going to get you more money. CI S P the CASP CI SM C I S a CCNP. Those are our professional level certifications, entry level security certifications would be like security plus and there's a few other ones, but okay, so those are certifications.

And then for skills, if you're in a sock that would be seam, if Splunk, if arch site's not as hot anymore, but Splunk is super hot. If some of the IDSS on IPSS if you're deep in the firewalls if you can configure them hot if you're Palo, Alto's a hot one.

But if you're it's security analyst works. So you're looking at more stuff. That's looking at logs. McAfee products NEIS is a good one. But the top ones right now is still on fire would be Splunk. Yeah, Splunk. And then another hot one, like it's getting more hot, I would say, would be cyber security.

Cyber security, threat intelligence stuff is getting pretty hot. Cloud computing. If you know that one, like more and more organizations are using it. So they need people who know some of the vulnerabilities of cloud technology. What kind of gotchas that organizations fall into is another good thing to know.

So those skill sets are immediately get you in another bracket of pay. I have to warn you though. Once you get to another bracket of pay, you gotta deal with the IRS, but that's a whole nother conversation. Okay. JJ says I got hit up for a cyber security risk management framework engineer, long term remote W2 contract position.

I have no experience with the risk management framework. I'm guessing I got hit up because of my cyber security experience, clearance tips, and tricks. Do I have any tips and tricks for this? You okay. Do you said I have no risk management framework. Okay. So if you ha don't have any experience in it yeah, that's gonna be, I if you want the job I would talk to 'em about taking you on as a, as somebody who's learning it.

Just be honest with them and say, no, I don't have experience with this, but I do have risk. I do have cybersecurity knowledge and I have read through the risk management framework, 853, I've read through 837. I'm familiar with it. I've worked with Compliance officers before I've worked with information system security officers before I've worked with security assessors before whichever one of those is true for you.

If none of 'em are true, of course don't say that, but , if you, so the thing is if you have experienced from cyber security, you have an advantage in that the basic concept of security, which is to protect the CIA protect the confidentiality, integrity, and availability. You can just tell them you have a very strong foundation, explain to them that you have a very found strong foundation in your respective cyber security role, and then build from there.

So if you have a solid skill set in cyber security, even if you're a system administrator, just what you need to do is dig into your archives of all the times you've done. Implementation of security features on a system. I guarantee you have a solid set of skills, right? So with those skills, you wanna tell them, Hey, I know how to secure systems.

I know what to look for. And by the way, I know the risk management framework process. I've not done it before, but I know it now, if you don't know it, go learn it. I have a course that you can go through, check that out that you can add, to be honest with you, you can probably just Google it and read through the risk management framework, 837.

I would highly recommend my course because I'm telling you exactly what you're gonna see and what they're gonna say to you and what they're expecting. And I'd be willing to help you out. So just keep those kind of things in mind, tips and tricks. Number one. Build on what you already know as a cyber security person confidentiality, integrity, availability, you've secured systems of before, more than likely you've worked with assessors and auditors before, more than likely you've worked with compliance people before you've done documentation before you wanna highlight all of those skills that you already have, and then tell 'em Hey, another tip is to learn the risk management framework process.

Learn it by my course. Go ahead and learn, read through it. Watch all the videos. You'll get a solid understanding of what the foundations of risk management framework are. Okay. I'm gonna move on to the next thing. I'm paid member at the first as a first timer. How do I get a job? Because most of the jobs are looking for five years of experience.

So one of the things that I would highly recommend Cobi is to. Look for entry level positions. Okay. Entry level positions, you gotta start somewhere and that start is entry level. Okay. So let me just show you what I mean by that. It's very simple. If you go, if you could follow along with me, if you want go tod.com, this is just one site, by the way, I use this one all the time, cuz it's just so vanilla.

It's so vanilla and so easy to understand and so straightforward that it's feel like it's a really good teaching tool. Okay. So first off here I am in indeed, indeed.com. You're gonna follow along with me. Okay. Put your location wherever you're from wherever you're from. Put that in there. Next thing put there's a couple things you can do here.

You can put ISSO there's a ton of key words you can use for this job. ISSO entry level,

none in this area. Okay. Let me search somewhere all over the United States. Wow. It's just really going to town here. All right. So look at this information system, security officer work, most of the jobs, if you happen to be on the east coast, you should know that you guys have all the jobs you guys have 70% of all the risk management framework jobs.

I'm not even messing around with you, but yeah. So you notice how all of these are Virginia. You can find a job, especially if you have a clearance. There's a couple of things that you have. You may have an advantage. If you happen to live on the east coast, you have an advantage. If you happen to have a security clearance, watch this.

If I put security clearance, if you have a security clearance, you have an advantage. Cause sometimes they're looking for a person with a security clearance and they're they just get desperate, cuz there's just not that many people who have it. So they'll actually pull you in and teach you if you have this.

Now, if you don't have a security clearance, another thing is you got, you could be eligible. For a security clearance. Eligible means you are a a us citizen BLE. I cannot spell what the damn eligible. my first and only language and I can't spell eligible. Yeah. Now all I did was type in eligible and and they, it immediately knows I'm looking for eligible active.

Oh wait, no, I'm looking for eligible. Security eligible for security clearance is what I'm looking for, but it's coming up with active duty okay. But a bunch of, so stuff came up eligible security clearance is what I'm looking for. Eligible security officer. Now these are physical security roles.

Okay. Here we go. Principle means like you're a boss, so you don't want that. information security specialists in an airport. That's physical security. Okay. This is mixing a bunch of stuff up here. Eligible security clearance.

Yeah, here we go. So if you're eligible for security clearance, if this is another another thing that's gonna make it so that you have a better chance of getting a job, the best thing you can have, of course, I'm not even gonna, I'm not gonna BSU is experience. There's no replacement for it, but how do you get experience if you don't have it?

So you gotta go to entry level positions. Now, if you have zero. if you have no it experience that is different. If you have some, listen, let me just be very Frank with you. If you have some it experience, meaning you are a system administrator, you worked on databases, you worked on cryptography, you worked on, you have some it experience.

You worked on workstations, whatever you have a very good chance of getting in, into risk management framework. Okay. You have a very good chance. If you have zero, it experience, meaning you've never held a role at a company or a university or a private or a government or anywhere that is different.

That is different. And the reason why is because risk management framework and security is typically not entry level. It's not like literally walking the door and start flipping burgers. Okay. That's not that this is not that kind of a job. there's too much stuff at stake. There's too much trust that's involved.

There's just, you're gonna be trusted with other people's information and assets. You're gonna be entrusted to know the secrets of that organization where the vulnerabilities are. You're gonna know where they are. They have to trust you. So for that, they need a professional who has something to lose.

All right. That's why cyber security is typically not an entry level position. I'm sure somebody out there right now is watching this saying, Bruce, what are you talking about? I'm an entry level. I'm walking off the street and I'm a cyber security person. Okay. That's fine. But I'm just telling you typically, it's not something you walk off the street and you can do this.

That's don't lose hope. Okay. If you don't have it experience, if you don't, if you've never done any of this stuff before, there's a couple things you can do. People contact me all the time and what the last time I did a couple weeks ago, somebody an educator contacted me and she said, Hey, Bruce I really wanna get into it.

I want to be getting a risk management framework. I like what you're saying. It sounds cool to me. I wanna do it. She's an educator. She had a master's degree in education. She has very little or no it skills. And I said, Hey, you might wanna consider becoming a program manager, okay. Program managers work with it.

They, and in some cases they have to know our, they gotta know what we're talking about. They have to know some of our jargon. They don't have to know how to configure a server. They don't have, they don't have to know how to stand up a Linux box. They don't have to know how to reduce threats on a. on a weapon system, they don't have to do all that, but what they do have to do is they have to have a certain level of maturity to manage a project and they have to have a certain level of technical know how with things like office so those are some of the things that you would, what I would suggest if you were trying to get in a high paying, very high, skilled, high paying job in it.

One of the things you can do is get a parallel job, which is a project manager position. It pays six figures by the way. Okay. It's not a joke. It's no joke. Program management is no joke. You can actually, even without an it experience, you can get in there and you can make upwards of six figures.

Look it up. Look it up. It's a damn good job. So yeah, number one, if you don't have any it experience at all, you gotta get it experience. You got, you have to, whether you're volunteering at your church, volunteering at your job. If let's say you're a system administrator you're a non system administrator.

You're HR, you're in the HR department, right? You work with people's w two S and stuff. You wanna get an it, but you don't know what to do. You don't wanna do a program management work. You don't wanna do that. You wanna do it. Okay. Then you gotta start from the bottom. Imagine somebody walking in your job in your profession, off the streets, not knowing anything and wanting the keys to the castle.

Okay. With cyber security. That's what we're talking about. You gotta, you, if you have no experience, you gotta get it. That means you gotta become, go to help desk entry level position is what I would suggest if you have zero it experience, but you wanna get technical. Yes. Go into, try to entry level positions, volunteer, do it for free.

Cause that work that you're gonna put in for free fixing somebody's laptops at some corporation is not indentured servitude. It's. That you're building up experience. It's experience. You're slowly building up and putting on your resume, building up experience, putting it on your resume. Then that'll allow you to level up to another job, a higher level it job.

You do that by the way, while you're working on your security. Plus, while you're working on your a plus certification, a entry level position with an entry level certification, then once you have those things, now we're talking about months and years worth of work. This is hard work. This is not something you walk off the street and then suddenly you do it.

People are gonna entrust think, imagine your bank. Okay. LIS if you don't think it's fair, just imagine your bank, whatever, wherever you bank in the back, they have a security person who D who a cybersecurity person who has no experience, but they know where all the SU they know where all the vulnerabilities of the bank are.

They know. Where the threats, they don't even know what threats are. They don't know what threats are, but they know there's vulnerabilities. They ran the scan. Do you want that person at your bank as a cyber security person who doesn't know what they're doing, who has no experience with it? No, you don't.

So I, when you're talking about cyber security, you're talking about somebody who's entrusted with the keys to the castle. They have to have something at stake. And that means you have to put in the work as an it for me to you. If you're an it professional, if you are trying to get cyber security, like we ha we are entrusted with something, with a lot of information so you have to have something, you have to have some skin in the game.

That means time. That means you, you invested your own time and money to get to the skill set and the skill level that you're at. And you're not willing to risk it by making a mistake or doing something stupid. And I everybody makes mistakes, but. As you get to learn how to troubleshoot as you get to learn how these systems work, how to do backups you begin to learn how to manage your own risk for your own profession.

You manage the risk to yourself and ran, manage the risk to your organization and the risk to the organization's information. I hope that makes sense to everybody out there listening. Let me see. And I'm gonna, I gotta do a couple guys. I gotta get going here. I apologize for cutting this one short, but let me see.

Can you get a ISSO job with a green card as a green card holder? That is a good question. Yes, you, you can, however There. Not, maybe not an it's gonna be harder to get an so job. Okay. But let me show you, let me show you my screen here. Let me show you how you can get a compliance job, a security compliance job with a green card.

So there are security, cybersecurity jobs that have a public trust clearance. It's a type of clearance, public trust clearance. It's a type of clearance that doesn't require you to be a us citizen. If I'm not mistaken. Yeah, let me see, let me try this one here. And usually they'll say, Hey, you must be a us citizen.

They'll tell you right on there. This one might not be, and it's not giving me that information. So this is a public trust. I think. but it's not okay. How about this? Let's do this. Let's just be straightforward here. Let's just say, watch this cyber security green card. They usually put GC as a green card, by the way.

Let's see cloud strike. Let's look at this one. It will say in here. Yep. There you go. Right there. See this that's the keyword right there. See it says green card for clearance, us citizen or green card for clearance. There you go. That's what you wanna look for when you're looking for positions now, do they do this for ISLs?

Let's see, let's just type in ISL. I don't, I've not seen a lot of green card holders be ISLs, but I could be wrong. Senior chemist, see that see is so usually in ISSOs working for a high level government agency and they require that you be a us citizen. So that's why you, I just don't I off the top of my head, I don't know if any ISSOs, but I know that there's actually, I take that back.

So there's some corporations there's some corporations who do ISSO work and they will hire a green card holder. But what I would do if I were you, is I would just

senior associate cyber risk.

See I'm currently working in an organization that we have people from all over the world working with us. So I know for sure you can do cyber security, cyber risk in the us without being a us citizen. I know several people who that work on our team who are in that exact position, but are they ISSOs we're not doing those kinds of, we're not doing D O D type stuff.

So let me see here. I'm looking for, did I just pass it? Yeah, it's in here must be a us citizen or green car holder. And most of these are gonna be, must be a us citizen, an our green car holder jobs. Yeah. We couldn't find an ISSO position. That's green card, but you can find. All right, guys. I have to go.

I gotta get going here. Thank you so much for watching me. If you have any other questions, if you look in the description below, there'll be a place where you can actually join me all times of the day on holidays and weekends and stuff on discord, you have any kind of questions. I'll answer. 'em when I can also you can always email me.

It's, cyberware 2020 gmail.com and we can talk about any kind, and I'll actually make a video sometimes about people ask me really great questions that I think could help many people. And you'd be surprised sometimes people ask me a question, but several other people ask me that exact same question.

So I know it's something that is relevant and I know it's something that needs to be addressed. So then I'll just go ahead and make a whole video about it. All right, guys. Thank you for all your questions. Thanks a lot. Copy. If I didn't answer your question, please answer, ask me on discord in the linked description below spades.

Thank you so much for that. I hope that's how you pronounce your name. Marcus, thank you for your comments. I did not get to your comments, but let, what I'll do is I will copy this and use this for another time. Another video. Thank you guys so much for watching. Join me on discord. If you have any, if you have a pressing question and we will talk.

View Details

http://convocourses.com

from Oct 11, 2020

View Details

http://convocourses.com

from Oct 11, 2020

View Details

http://convocourses.com

check out the video: https://youtu.be/TGrw5yT6sSY

Hey guys, this is Bruce and welcome to combo course podcast. And today we're gonna be talking about a few things. One of the things I wanna talk to you guys about is process versus prize or system over goals. And this really applies to everything in life, but we're gonna specifically talk about cyber security.

Another thing I'm gonna show you as a new book I'm working on. It's not, it's gonna be out. I don't know, probably within the next month and a half, I gotta get it edited and all that kind of stuff. I'm actually still writing it, but it's gonna come out soon. So that's. Something we're talk about, then I'm gonna open it up to any kind of questions you have about getting into this space in cyber security.

And in the it, I got a lot of people contacting me about how to get in this field. That's growing really fast or how to upgrade themselves and all that kind of stuff. I've been doing this for over 20 years. I'm a subject matter expert specifically in cyber security compliance. That's, what I've been doing for most of this time that I've been in this space.

And so if you have any questions about that, how to get in it, how to, what to do like specific questions even I can answer 'em on this live. All right. Let's get into this. First of all, I want to tell you guys that I have a site called combo courses.com where I sell lots of stuff. A bunch of courses, also books, and a ton of stuff for free.

If you are interested. So if you're interested in that, go check out convo courses.com. Like, I said, lots of free stuff. It's free to sign up lots of training downloadables if you happen to be in this space I'm constantly giving out free stuff. I'm trying to build a community. And that's why, if you have question, why I'm giving out anything for free, that's the reason why cuz I'm building a community I'm, thinking bigger.

I'm thinking about making a community that helps itself and Built one of these before in a whole different genre. And it, works really well. So that's what I'm doing. If you're interested in joining that community, join me on, YouTube. Join me on discord. Join me on TikTok. Join me everywhere.

Combo courses, just type to combo courses. You'll find us out there where have a growing community of people that's coming together to learn this to, level up together to, get more to, make that money really. That's what it comes down to for take take, care of our families and take care of ourselves.

Okay. So what I'm gonna talk to you today about the first topic of discussion will be about will be about process versus the prize. A lot of people contact me about trying to get to certifications or degrees and which ones should they get and all that kind of stuff. and it's really the wrong question and I don't fault anybody for it.

Because I was, I had the same kind of questions when I first started. You should be focused more on the process and this, really goes on everything in life. Your focus should be not on the prize, not on how many likes you get, not on how many people are watching you, not on how many people or how many degrees you're gonna get or, courses or any one thing.

It should be on the process itself. And we're gonna specifically talk about cyber security, cuz that's my profession, but this really applies to anything in life. Let me specify what I mean by using this an example. Lately people have been asking me about the a plus comp Tia certification and how do you get it?

Where, do you get it from? How do you know all this kind of, what kind of job can you get if you actually do that, all that kind of all those kinds of questions and is there's nothing wrong going for that certification or any other certifications. Absolutely nothing wrong with that. And I would encourage you to get it if this is your first time getting in, into cyber security, into it in general it's a good thing to get.

But what I wanna say is that the most important thing that you should focus on is the process of learning this the common body of knowledge that goes into it. And the reason why I say that is because if you focus on the common body of knowledge, if you focus on actually learning what you have to do in to get that certification, to get that it certification.

If you focus on that, you'll have all the knowledge that you need to go ahead and take the Google support it certification. You'll have the knowledge that you need to actually go ahead and take the in network plus certification. You'll, have all the knowledge you need to actually spend your, whole your, whole resume.

If you actually learn the stuff that's in the comp tier a plus certification, right? It's just one thing. If you focus if you focus on just that thing, just that one prize, you'll get that prize, and there's nothing wrong with that, but I'm telling you to focus on the whole orchard. I'm telling you to focus on the seeds.

That's gonna get you like not just one certification, not just a little bit of experience, but expand your whole horizon and get you way more knowledge, way more certification, way more experiences and, actually get more from the fruits of your labor. To do that. You gotta focus on the actual labor, not the prize.

The prize is cool. I'm not telling you like not to get it. I'm saying expand like what you are, what you're doing by focusing on the work, focusing on the process itself, of learning the process of learning all the curriculum that's in CompTIA. And let me give you a specific example of what I'm talking about.

Let's go to CompTIA. Let's we're gonna use CompTIA a plus certification as an example of what I'm talking about. This is my, this was my first certification and this is why I promoted so much because after I learned that certification, I knew enough about computers to where I could get in this field.

And I was working helped desk for a while and I learned enough about troubleshooting and all that kind of stuff to where it, was able to expand my entire career. Eventually get me to working, making six figures and being able to take all these vacations and all kinds of stuff. But here's the curriculum right here.

And if you're listening to me right now, it's, I'll read it. There's nine skills that you have to master to validate your CompTIA, a plus certification, hardware, operating systems, software troubleshooting, network troubleshooting mobile devices, virtualization, cloud operational procedures, these, all of these things.

And these section, if you actually buy the book, these are the sections, some of the sections that'll mainly be broken into. And of course, it'll go more detail in each one of these areas. If you actually learn this stuff and not just go ahead and take the test and pass, cuz that's, actually the easy part taking the test and passing it you can actually go.

and take a bunch of just retake the test over and over again. And eventually you'll pass the test. I'm telling you to study the common body of knowledge and know and understand what's actually happening. Do go beyond just taking the test, go beyond just taking the questions and passing the test, go into actually setting up a lab in your house, figuring out how to put all that stuff together, figuring out your own network, figuring out how firewalls, whole space firewalls work, how's that different from network, firewalls, learning, all that stuff by maybe even actually doing it in your own home.

Maybe actually helping your community out. If there's an opportunity for you to do that, actually getting hands on to where you literally understand it, building your own computer, things like that, to where you understand it. So fully that the comp Tia a plus certification, when you get it is not a big.

It's your first certification. So obviously you're gonna be patting yourself on the back, but what I'm saying is if you expand your base and you understand this stuff, like you really deeply understand it, you can go then and go take other certifications, entry level certifications, easily like a plus certifications, the natural next step in your evolution.

And then the next thing you could probably take is a com is a Google support it certification, which will probably be easy for you, cuz you have gone so deep in the rabbit hole for a plus certification. I'm telling you to learn the common body of knowledge and learn the process, put the, put that work in and that will give you all your other, everything else.

You'll get all kinds of other prizes, not just the certification, right? And you might even inspire you to go get a degree. If you choose to go that path, you don't have to, but you could the process over the prize. This is book I read. A really good book. I encourage you to go out and get it. It's called atomic habits and it's really, it's a really good book.

And he, one of the things he said in the book was don't focus on the goal, focus on the system, creating a system to get that goal. And that's what I'm talking about. So if you focus on the process, that'll get you to that certification. You can get a whole bunch of other certifications and experience. If you actually understand how to build computers, how to build a network, if you actually have a hands on that you can do in your house nowadays.

So that's what I'm trying to encourage you to do super important. The next question should be how do I, get developed a discipline to focus on the work rather than just the prize? Because it's easy to work, focus on the prize. Like you're thinking about, okay, if I make this $65,000 a year after I get the certification, or if I can, if I, maybe I focus on getting I'll be able to get six figures.

If I get this professional level certification, and now I'm not telling you not to get six figures, I'm not telling you not to get a professional level cert. I'm not telling you not to get agreed. None of that. I'm not telling you that's the fruits of your labor. What I'm trying to tell you is if you focus on the actual process, if you work, if you focus on the discipline in that process, you can have any damn thing you want.

And what happens, what I've noticed is what happens is like when you focus on that discipline in this career path, all the people who I know who, are at this super high echelon is super high level. All these guys are highly accomplished because that's exactly what they did. They're more focused on like actually knowing and understanding how to do this stuff.

and because of that, all these other certifications are within their grasp. They have all these other opportunities and all of these other success factors that come in because they actually know the material. So well, that's where I want you to focus on. If you focus on the discipline of doing the process, then everything else you'll not only have the certification, you'll have several other opportunities to take other certifications, cuz you'll understand it so effectively.

And then after a while you notice a plus certifications is not that big of a deal at all. You'll notice that the does any certification is not that big of a deal. One of the things that I've learned on this path of just having the discipline to to, really go deep in this and become a professional level, subject matter expert in this field is that.

whenever I go to a new organization, they're always pat me on the back. I get all these certifications. I get all these awards I should say. And and I'm not telling you that to like brag or anything like that, cuz it's not bragging rights for me. It's bragging rights is that I was able to take care of my family.

It's bragging rights is I was able to take my family to Hawaii. That was dope. I do this for my family. I do this for to do better than just survive. And for me that's the greatest reward that I could ever receive because of that. I don't care that some giant company gave me an award, gave me extra a little bit extra cash because I, accomplished something within their organization.

When you I'm focused on the process of allowing us to have a roof over our head and to eat good. That's what I'm focused on. The process that it takes to do that means me studying sometimes late at night means me waking up a little bit earlier. Sometimes means me putting in the work that I need to do beyond motivation.

Cuz sometimes I'm not motivated. Sometimes I'm sick to my stomach and I don't feel like doing nothing. And I don't feel like getting out of bed. I, all I wanna do is watch YouTube all day and watch stupid videos. That's why , but what do, but I know that the discipline has to take precedence over bad habits, so once you get that in your head, once you start to develop this muscle of just having the discipline to get outta bed and go stay up late or do other things you need to do to make these things work. It, changes everything in your whole life. And I'm not just talking about cyber security.

I'm talking about everything in your life. . If you focus on the process and the discipline that it takes to do that process, you can do anything you want to do in this life, but it takes motor. It takes discipline beyond motivation. Motivation's not enough. You gotta have the discipline to do it. And that, and cyber security is no different.

So that's all I want to say about that. It's just something that I noticed about my own life. Anything that I've done in my life that was successful, but it came because I had the discipline to put, I put in the discipline to do it. If you go out and the discipline takes you to another level because, if I fail a certification, you only fell.

If you quit, I'll just keep taking it until I pass it. That's what I'll do. I won't. I do. I will not quit. I'll just keep taking it until I pass it. Once you get that discipline in you, nothing is gonna stop you. You're just gonna keep doing it. Okay. Anyway, let me tell you guys about Couple things here.

So if you didn't know, my name is Bruce. I run a site called combo courses. I'm building a community of like-minded cyber security, people who wanna teach each other, learn from one another. I call it combo courses, cuz it's a conversation between me and the community between us, the, between the community and itself.

I'm, building a community. I've got 10,000 followers on YouTube. I've got a few followers on on Facebook. I've got a few followers on my Facebook group on, discord, on and starting to build a community on TikTok where we're just helping each other out, learning from one another and building up and that's the, ultimate goal to this whole.

If you're interested in learning more, you wanna follow me go to YouTube and then go to combo course type in combo courses. You'll find me there where I talk about all things related to cyber security. Talk about how to get into this field. I talk about how to do risk management framework, which is my specialty and, security compliance.

That's what I mainly focus on. If you're interested in getting more out of this, I've got a book out there. That's related to my actual specialty, which is risk management framework, where I talk about the security controls that go into N 800 risk management framework. I've got one that's foundational and I've got one that like foundational, meaning you don't have to know anything.

You just listen to the book. I got it on audio by the way. Or, you can read the book and and, learn a little bit more about that. And it's so popular that people are literally copying my book like this dude copied my book and is selling it. He copied my book and selling it as his own anyway.

So it must be good if that's the case. I've got two books out there. I'm building more than just a book. I'm building a entire community. I'm building a a, an entire something where you can talk to me directly. You could talk to me directly and ask me specific questions about how to do this. And I think that's why a lot of people have been following, because I answer questions that they ask me.

So if you have any questions whatsoever, feel free to con to call up to email me, or you could actually ask me a question right now. If it's related to cyber security, I'll do my best to help you out. And, that goes for everybody in this community. I really appreciate all the people who've been following me.

I appreciate all the questions. I appreciate all the accolades, all the. Great comments that I've gotten on my book. It's, really been a great, a very rewarding thing to see people actually commenting and, leaving positive comments on my books and stuff. So that's really good. If you didn't know, go to amazon.com type in risk management framework or Bruce Brown.

You'll see my book there. And I also have a site called combo courses. I have a podcast I'm doing at least once a week. I've got I'm on YouTube doing combo courses. So follow me if you're interested in this kind of content, if you're interested in getting the it or a risk management framework then, follow me.

All right. And I'm gonna show you guys a glimpse of the book then I'm writing right now is how to improve your resume and, be able to get people to contact you. Cuz that's what I've been doing in the last few years. Reason why I've been able to get all these jobs quickly. Okay. Deru has a question on YouTube.

He says, Hey Bruce, what resources would you recommend for keeping in tune with the latest. And updates in cyber security. And I would say de truth. That's a good question. By the way, I would say that really depends on what categori category, sorry that you have in cyber security because there's many different cat cyber security is a huge category.

It's huge. Like it's a huge field. It's a huge umbrella. You've got everything from risk management framework to you've got cyber threat intelligence which, does threat hunting. You've got you've got Intel, which is considered a part of cyber security cyber Intel. You've got forensics, you've got all kinds of different branches of cyber security.

So it really depends on the branch. Now, if you want an overall of all cyber security, I could tell you, I could tell you some of my resources. And then what I'll do is I'll break it down into different genres of, cyber security, the ones that I know. All right. So first the first really good resource would probably be the CIS A's website.

CISA is a government site not, the actual certifications from Isak. I'm talking about csa.gov. And so CS a is cyber security infrastructure and security agency. This is one of the most one of the best resources. Let me just switch my camera here for TikTok, for those who wanna watch. So this is SI this isa.gov csa.gov.

And these guys are one of the best resources for things that are going on mostly to the whole United States, like federal government, state governments. If there's a huge hack, you'll see 'em here. Pop up here. You'll also see different vulnerabilities that come out like the big ones, different malware.

Like right now here they have 20, 21 top malware strains. And then they've got a blog here with the newsroom. Let's just go to, let's go to this one. This is dated August 31st, and this is SAFECOM publishes 2022 SAFECOM strategic plan. This is all like federal type stuff. So if you are in the federal space, this is one of your best resources.

Let me see what other resources are there? Other places you can go if you happen to be in vulnerability management are the people who like manage they manage let me see if I could switch. Oh, you switch it like that. Huh? Oh, that's cool. So messing around with TikTok , that's what I'm doing in the background.

So vulnerability management, that's people who take care of their organization's vulner patches, right? PA there's patches that are always coming in. And they have to update 'em. So one of the best resources for that is probably CVEs is a huge database of all the vulnerabilities that are popping up throughout the industry.

That's through a vendor it's all vendors. So it's not any one specific vendor that being said, vendor. If, you have say Microsoft patches, then the best resource is Microsoft for, their most recent vulnerabilities in how to fix 'em. And then if it, if you have a Cisco device, it's Cisco.

That's the best place for the most current things going on with Cisco. And if you have an apple product, same thing, like if you have a Macintosh, you go to the vendor, but this CVE site is really good because it has a huge database. That's constantly being updated to inform you of what is going on for vulnerabilities.

Let me see if I can find a really good breakdown of this. Let me see, where do you normally I find the individual CVEs from the, from Google. Let me see CVE resources. Okay. Just trying to find like a specific CBE that I could show you here. So yeah, CBEs are good for for, actual vulnerabilities and then there's Like I said different branches of cyber security.

So each branch has its own like group of resources. Government has C I S a everybody in a lot, everybody in the government goes to C S a site. And they have the most recent APTs advanced, persistent threats, most recent vulnerabilities, all that kind of stuff. What's what the government's doing.

Like what, where we should be focusing our energy. What it's, really good resource. And CVEs, this is like a huge database of, all the places you want to go for vulnerabilities. And I'm look, I'm still looking for the actual database of the actual vulnerabilities. Let me just, okay. See CVE I'm on Google right now, typing in CVE.

Let me see a specific one would be iOS CBE for I iOS. They have a vulnerability data database that has every single vulnerability you could think of. So this one's for iOS 15.6 and at this is going straight to apple site for 15.6, a recent kernel update and web kit update that they have. And it's for CVE 2022 3, 2 8, 9 3.

You might be familiar with this one, but I'm gonna type that one into Google. And it goes straight to the CVE site that I was just on. And then it'll have a breakdown of, how it affects other things. So this is one of the best resources that I, was, we were using a lot in almost every place I've gone to.

We use the same thing, private sector and. Public sector uses this one. Now, if you're in the department of defense, let me show you like department. See, it really depends on where you're at, but department of defenses, best resources is called dissa. D I S a DISA do mail. Okay. So D the DISA mill website has some of the best resources as far as how to fix your system.

They have the STIGs the, security test security, technical implementation guides, one of the best resources on the internet even, the private sector uses it. That's how good it is, but this is a really good resource for department of defense and actual federal government. And it's so good.

Recently it's gotten so good that even, the private sector start using the STIGs. So yeah here, it is right here. Here's the news that they're always releasing different stuff. That's related to department of defense, mostly. But. Their STIGs are incredible. Their training is ridiculous. It's one of the best resources.

It really depends on what branch and what area of cyber security that you're going in. But so I, hope that answers your question de truth. Specifically, what area, if you tell me, what area of cyber security you're in, we could find like a really good resource for it. Okay. I've got a question or comment on, TikTok.

They say, Hey, hi, Bruce. How difficult is it to travel with a security clearance with, or without a job? This is a great question. Okay. The question is how difficult is it to travel with or without a security clearance? It's not difficult at all to travel with a security clearance. It just takes a little bit of research on your part.

It depends on the, on your clearance. So Deru thank you so much for that 19 bucks. I appreciate you. So let me, this is a really good, this is a great question. I'm glad, so glad you asked me this question. So let's answer this now. I'm speaking from a person who's had a public trust, which I have right now.

I've had a sec, a secret clearance, and I've had a Ts S E I clearance. And I've known people who have a higher clearance than me. And I could tell you there's there is a difference. Alright, how difficult is it to travel? It's not difficult. You can travel anywhere you want. However

I'll start from the highest and go to the lowest. Okay. So a friend of mine and I won't name names, I won't tell how, what kind of clearance he had. I'll just say it was a hi, his clearance was higher than sci this. If you wanna Google what that is, then just research it for yourself. Just go to Google and type in high clearances.

High top secret clearances. He had one of those. He had something above that, and this dude could barely talk about what he did. He was very guarded. He said that they tapped his phone. Like they knew where he was at all times. It's it is the most ridiculous thing I've ever heard. It's preposterous. I said I would never work for an agency that does that.

They openly told him, Hey, by the way, we are tracking you we know where you're going. Here's and then they told him there's places you cannot go. It's, there's places you couldn't. And then when he named the places, I thought he was gonna say oh, I can't go to obvious places. Like I can't go anywhere near Iran.

I can't go to there's certain places in some, countries in Africa, you can't go there's certain places in. But then he said he couldn't go to certain parts of the Philippines. I was like, what? There's certain parts of the Philippines. He couldn't go because there was terrorist activity there.

And I was shocked. I'm like, I never heard of nothing like that. I didn't for a second. I didn't even believe him. Then he started breaking it all down. Cuz there's like some kind of terrorist threat and some part of mening now I'm like, are you for real? And then there was, they even questioned people.

He talked to whenever he would go overseas. So they weren't. And then a lot of times they weren't saying you can't go, but if you go overseas, you gotta tell us where you're going. You gotta tell us who you're talking to. That's the kind of clearance he had. All right. I don't like, I don't know much about that.

I can just, all this is hearsay and bullshit. Okay. So do your own research on that one. I'm just telling you what this dude told me. Let me tell you about something. I know about the clearance. Like I had to tell top secret S sci I had a secret clearance and I had a, public sector. I'm gonna tell you about those three.

All right. So in my experience, number one, there's no, they're not restricting me to. To most countries, the countries that I'm restricted to go to are obvious, and most, Americans should not go to these places. North Korea. Don't go to North Korea. Just don't. If you wanna know why just Google it, just do your own research.

Don't go. It's just stupid. It's just dumb. Don't don't do it. just don't especially if you used to be in the military, just don't do it. I don't, I just, anyway, I'm saying that because people have done it, you probably might be thinking like, why would nobody goes to North Korea?

People don't do it. Iran. Don't just, don't go. The us. And unfortunately it's unfortunate that our countries cuz it's a, it's an amazing place with amazing. amazing human history is happening there. And it's a shame that our governments can't work things out to where human beings can't go to certain parts of the world.

To me, it's just dumb, but if you have a clearance yeah, they monitor that there's certain countries you really will lose your clearance over. There's certain places in there's certain countries in Africa that you can't go certain countries in Africa. Can't go, cuz there's too many. There's a list.

Normally when you go to an organization, they'll have a list of places that you, they recommend you do not go. And so when you're, when you have your clearance, you're at this organization, one of the first things you should do is figure out what those countries are and what the policy is for your organization that you're working for.

What policy do they have that says, okay, you cannot go to these places. And here's why, and the reason why that you can't is because of this thing called I a R. And so I a R is. Oh Lord. What is the acronym? I a it's like international. If you guys know what it is, please let me know. I can't remember off the top of my head.

I a R is international trade arms. It's okay. Here it is right here. International traffic, and arms regulations. It, doesn't like this, the name of it doesn't fit. What it does. That's why it's confusing because it's not just arms that they're tracking. It's like all kinds of techn technical goods and, certain technologies.

And I of understand why they do it because if you look at a country like China, China steals a lot of in an LA. This is not, cap. This is not conspiracy. This is real China. And other countries will steal certain technologies from us companies. They do this on a regular basis. It's a pretty smart move.

I think they steal your, their, I. They've done it to Google. They did it to Google's search algorithm. They did it to Cisco. They did it to they stole the, that what's that jet. Oh my gosh. The joint strike fighter, they stole all the, they've done it to multiple successful organizations.

And not just in the, to the United States. China's just one example. All countries do this, all countries do this to one another, they still intellectual property. And then they either implement it or do something in their own country so that they can get a leg up. But a lot of people do this to the United States cuz of the United States, regardless of weight, how you might.

About the United States. It has some of the greatest innovations on planet earth. And it's because we're living in some sort of golden age where all this stuff is coming out. Like eventually this is gonna die out. Eventually all the ideas are gonna shift to another part of the world, probably China or something.

But right now us is in this place where all these inventions are happening. Mostly from even TikTok, TikTok used to be vine. You know what I mean? Like this idea of TikTok was taken from vine. They looked at vine and said, wow, that's successful. And then they reengineered it, made it better. And, then absorbed musically.

And then now you have TikTok, vine started in the us and I don't know, like what's going on in the us. Why there's so much innovation, why there's so many, I think it's because the, in my mind I I know it sounds. stupid conspiracy theory, but, or some kind of stupid faith patriotism, but it's because we're, there's freedom here.

There's freedom to think what you want and do what you and make mistakes. And that's why there's so many innovations here, I think. But if and if you, travel the world, like what's weird, what's crazy. When you travel, speaking of traveling, you see how much influence the us has on other countries.

You see how just going like Philippines. I was in the Philippines like last two weeks ago, three weeks ago. And everybody's wearing Fu boo shirts. Fu boo is a us brand from diamond. What's his face? Not yeah. Diamond that billionaire the, billionaire on on shark tank, that dude came up with that brand and that thing's all over the Philippines.

One of the most popular brands in the Philippines, you're walking through the mall and. I'm just saying like the influence that the us has is crazy. So one of the things that they, that country like different companies will have you do is Don not do not take our intellectual property to these countries.

They'll have a list. Don't go to those places. If you value your career, look at what their policy is and adhere to it, if they're saying, do not go to these countries, don't do it. So that's what I'll say about that. It doesn't. So to answer, go back to the question. went off on the tangent, the que original question from, to was how difficult is it to travel with the security clearance with, or without a job?

How difficult is it? It's not difficult. You can go wherever the hell you want. The problem is there's certain countries. If you go to go there, if you have a high enough clearance, you can lose your clearance. And they'll have a bunch of questions at the very least. They'll have a bunch of questions when you get back and they'll know where you went.

What you can do is before you go, is you tell them I'm going here and then they'll have a list of things that, that they will, that they'll say for you to do or not to do. Is it difficult? No. Can you go, yes. Can you jeopardize your job? Depends. If you, violated that, that organization's policies and yes, that you can lose not only your clearance, but your job as well.

So just keep that in mind. Somebody on TikTok said, Hey, yeah, they they're incredible at reverse engineering facts, Then in the Chinese, like in my mind, Chinese are the smartest human beings on earth. The Chi the Chinese are ha they're you say what you want, but man, they're in a they're I don't know, like it's so smart to steal.

Like this is the smartest thing. You can do steal a billion dollars worth of research, take it to your country. And then boom, you have by. You have WeChat, you have TikTok. How smart is that? That's brilliant. I am a lamp seeker says you might end up with a polygraph. Oh yeah. A polygraph test.

So one of the things that will happen is that you come back from your trip overseas and then they'll give you, you a polygraph test where they'll ask you a bunch of questions. Have you talked to any foreigners? Did, any foreign person come up to you and, ask you questions? This is just what I've heard from the, my, a friend of mine who has a high enough clearance to where they ask those kinds of que that's of what happens if you have a high enough clearance.

So do your own research. If you happen to be at an organization that has clearances and stuff, and you're dealing with sensitive information, look into their policies, look into I a R, which is international traffic in arms regulation. It's, not as bad as you think norm normally it's gonna be obvious places that you shouldn't go anyway, as an American citizen, it's just, you're jeopardizing yourself.

know, I'm just being real with you. Don't, there's certain places you shouldn't go. If you want to know what that list is, you can probably go to they have a list of them on us embassy. The, state department has a list of places that they recommend. You don't go. If you have a clearance, you should probably listen to that list.

Especially if you have a high enough clearance. All right. Let me ask, answer another, read some more comments here. Deru thank you so much, sir, for that, that 20 bucks, I really appreciate you. It says, I appreciate all you do. Your courses have helped me tremendously to learn risk management framework for my everyday duties.

Thank you. And please keep up the great work and teaching people, man. Thank you Deru I really appreciate you, man. I appreciate this community. Thank you guys for watching me for all these years. Much appreciate it. All right. Let's keep going. I'm gonna answer a couple more questions. I'm not gonna be on here that long on this one.

Feel like I said what I needed to say, but if you guys have any questions, I'll stay as long as we have questions. Let me see I'm going on YouTube right now and answering some questions from there. Have a very lively, active community on YouTube. If you're interested in getting diving into this. But I have one, a couple comments on, TikTok says I agree with you.

you have to have some permission to go to some certain countries. You might get a polygraph. Wow. Yeah. He, this guy knows what he's talking about. So speaking back on, on this security clearance issue, not enough, really people really talk about this. And that's why I think I get so much traction on, YouTube and social media when I talk about this kind of stuff.

But he says he says, he, when I was, what I was saying is if you travel with a security clearance, you should get permission. The right thing to do is to talk to the organization. Okay. That's the safest and right thing for you to do. If you have a clearance, if you have anything I say above a secret, if you happen to work for, even if you don't have no clearance and you're working for a, an organization who deals with sensitive information, especially if you're trying to work from those countries, like you should really think about doing this, talk to the organization first and say, Hey, next month, I'm going to Thailand next month.

I'm going to Indonesia. I'm going to Columbia, wherever the case may be. Just let 'em know. And what'll happen is because I've done this before the HR department will say here's a pamphlet of places. You shouldn't go in colo while you're in Columbia or you shit, you can't go to Cuba you, can't go there.

Here's why. And you might not agree with it. You might think it's stupid and maybe it is. But the point is, if you try to go, you could lose your clearance and your job in certain places that you go to. And then he lamp seeker says they might do a polygraph test on you. Like when you get what he means is I think this is what he means.

This never happened to me. When you get back, they might ask you some questions and hook you up to a polygraph test to see if you're lying. I'm not that's isn't that crazy? That's never happened to me, but a couple friends of mines that happened to that have a high enough clearance that, that happened to I'm like, wow, really?

Yeah. So just be mindful of that. You can go. But the right thing to do is to talk to your organization before you go and do your own research too, look at their policies, right? If you don't wanna say anything, you want your own privacy, whatever, do your own research, because they'll have a policy that tells you flat out, Hey, look at the HR departments travel.

They have a travel guide for you. Look at their read that thing, especially in the foreign country, foreign travel, read that, and they'll have a list of do not fly. Like you cannot go to these places. And here's why I a R whatever the case may be. Here's why you can't go. Or they'll say you can go there, but avoid these places, or you can go there, but.

Don't talk to you gotta avoid talking to just any random people coming up to you to asking you questions. And the reason why I say that is because one of the tactics that organizations from a foreign organizations will do is they'll have a casual, fine looking young lady. Come sit next to you at a bar and start asking you a bunch of questions and get real, real intimate with you and ask you a whole bunch of questions to get more and more information off you and try to date you.

If it's really serious, they'll date you like a damn spy and get even more information while they're dating you. Right now, you have a long distance relationship with a person who works for the CCP or something. If you think that this is crazy talk and spy talk, this actually happened to a couple Canadians, happens to Canadians and Americans.

You don't believe me. Look it. Like they work for the government or they work for a high level organization or just an organization. All these innovations they'll get really close to you. Then they'll start asking a bunch of questions. Just be careful. All right. Lamp seeker says, keep up what you're doing.

Thank you, sir. I appreciate that. It says even a secret that you have you have to get permission at least 30 days. Oh Oh. you're saying if you have a secret clearance. Okay. Okay. Listen to this. Here's some insider information right here. If you have a secret clearance, you have to get permission at least 30 days ahead, and some require 45 days or more.

So the right thing to do, and he says I'm an ISSO, but I was in industrial security for 15 years. Oh, here you go. Right here. So these guys put me on a game, like people like this is combo courses right here. This is what I'm. This is why I do this. People like this dude right here who come and educate me.

This is a great opportunity. A teaching moment. So I didn't know this. So listen to this. If you have a secret clearance, especially if you work in cyber security, right? Regardless it, if you could work in the hospital, sweeping floors, if you have a secret clearance, he's saying some organizations require you to let them know 30 to 45 days in advance.

And he's saying he's an ISSO, but he used to work in industrial security for 15 years. Industrial security are the guys who are really, deep into things like I a R really, deep into things like personnel security. So this guy knows what he's talking about. When one time I was doing it live and I was like, I don't know, I've never had a polygraph test and I don't know how it works and this dude just schooled me on it.

And I was able to, we were able to push that information out. So other people know information about a polygraph test. So I really appreciate that. Thank you, lamp seeker, great information. And he says, especially if you didn't get permission yeah. You gotta get, you should get permit. That's the right thing to do that's the right thing to do.

All right. Let me answer some questions on YouTube. And in Deru adds to that conversation, he says, always talk to the FSO of your company. And that's a correct me if I'm wrong, but facility security, officer functional security officer functional FSO is like a security person. Who, does secur personnel security.

Like they, they make sure that you, if you're gonna travel somewhere you're read up on any kind of issues that going on in that country. If there happen to be any things like that you, have to have situational awareness. You should know what you're just getting yourself into. If you do go to another country.

And that's something that I've been really good about, I travel quite a bit and I've been traveling even when I was in the military, I would travel. And you it's really important to know situational awareness. And let me just give you a couple stories, cuz I've been traveling since I've had up to top secret clearance and I've traveled extensively.

I've been to 15 different countries. And while I had clearances while I was working in the private public sector and I, know a little bit of something about this and I'm, gonna tell you a story. So when I I was in I used, I was stationed in, Korea. I was stationed in South Korea and this was in year 19.

I'm dating myself, but it was in 1,998 to, the year 2000 yeah I'm, a little older than I looked. Yeah, I was stationed there and I would just go off base. I would just roll. I would just roll off base. I was in Kusan and Osan that area. And I would I was actually in working in security.

I was a, I was physical security at the time. I was a security force member in the mil, in the military. That means I was military police as probably the thing. Everybody understand really. I was weapon specialist. I was high level security guard anyway, so I would just go on. I learned Korean onion, AHI come, Sony die.

I learned some Korean and then I'd get in the car. And the taxi, and then just go, and so the problem with that is that there's certain places in Korea that people don't really didn't at the time and probably same hated Americans at the time. There was a bunch of colleges that how colleges are, right.

There's just a lot of younger people and influenced by a, like a rebellious mindset. And they, it, bottom line is they hated Americans and they blamed the us for dividing the north and South Korea. And the reason why I know this for sure is cuz that's the red Eric. They were saying when they were out there protesting at the colleges and also that's what some of the gate guards, I would have to work with Korean.

The Royal the Republic of Korea army and air force, I would walk, I would talk to 'em. Some of 'em were really cool and taught me Korean and, I would talk to 'em about English and hip hop and stuff like that were really cool, but some of them hated me and they would not say three words to you.

And I would still talk to those guys and they would flat out telling me I don't like Americans and I'm. and a little bit in Korean, why don't you like us? And they would tell me you guys divided the us government divided our country in half. And you guys are the reason why north and south are no longer speaking to one another it's you are the reason if you guys left, we'd be able to unite Korea and I'd be like, what?

I'm like, that's not what I was told, and I was like, then I thinking are both of us being fed propaganda for our go from our governments? I was just thinking about all this stuff long. Okay. Let me get back on track. So I'm off base and people are super cool with me. I'm some black dude in, South Korea in the middle of nowhere.

Nobody can speak English. I'm speaking, my broken ass Korean and people are super cool, but it's the older people who are. Younger people hated Americans. And so at certain places that you would go get back to base and I was cool, right? I just met a couple. I had this great experience in Korea and everything.

I was just like, happy but I get back to base and they said, Hey there was a dude who got killed. There was an army dude who was in the wrong place at the wrong time. And this mob of Koreans killed him because they were having a protest. And I don't know what this dude was thinking, but he was walking by college and this mob killed this dude.

And they were saying, do not go to these places. Here's the this area here, and this area here, if you are an American, do not go here, period, you are not allowed to go there. And they told us why they, killed more than one soldier who would happen to be near those. You might, they might have had a girlfriend there.

So I don't know, but these dudes were killed and I was like, damn. Luckily there were no not big colleges where I was at, but just situational awareness. You gotta know what's going on. So whenever you go off base, whenever maybe you have nothing to do with the military, you just traveling abroad or whatever, just know what's going on.

I'm not telling, I'm not trying to scare you from going abroad, man. You should definitely use leave the United States and go experience the world. Experience, humanity, experience other cultures, man, it's gonna open up your eyes to a whole different I'm different, man. I'm, I've been to several countries.

I've seen extreme poverty. I've seen extreme wealth. I've seen I know that the us lacks heavily in certain areas that we shouldn't lack in, but I know that we, that the us is so successful in or other areas. The U. The world is not what you think it's, way beyond what you believe or watch on TV or whatever.

Like you gotta go there though. I'm not trying to scare you into not going, but I'm just saying have situational awareness. One of the things that military taught me is you gotta know what's going on for your own safety and security. Read the news that's going on in that country at that time. See what's going on with that country.

I'll give you another story about situational awareness. Not too long ago, like maybe five years ago, I went to Thailand and I was in Thailand, me and my, wife at the time we were chilling. We had a great time. We I'd been there like four or five times or something. I've been there total four or five times love Thailand.

I've been to two different cities there and stuff. I just, the people are great, man. The the, monasteries I went to the monastery seen that sleeping monk. There's this giant like sleeping monk a sleeping Buddha ah, man, this is just amazing. I went to old Siam, which is now called a Utah. A beautiful place, man.

The people are so nice. I man, anybody who's never been there, man should try. It is check is so amazing, such an amazing place. Anyway, me and my wife at the time we were there, we're hanging out with chilling and we had a great time. We go to leave. We get on the plane and we're leaving. We are on the plane leaving.

And then as we are in the air as it's taken off, we learn that the, country just had a coup and they shut down the airport. So we, might have missed that coup by about 15 minutes, cuz we were already boarded and flying and they shut the airport down and nobody could leave. I had no idea this stuff was going on.

I was just there as a tourist. I didn't see any protests where I was at. I didn't see any of that stuff, but a little bit of situational awareness for me. Would've let me know. Hey, there's something going on? I had no idea. And a lot of times, as a foreigner going to another country, you're totally clueless on this stuff.

Always have situational awareness, no matter what, whether you have a clearance or not, whether you work at a company that has sensitive information or not always know what's going on in that country, what's hot. What's going on, where not to go, where to go. You could find all this information on the internet a great resources would be the, embassy website.

They have, they usually like a breakdown of alerts and warnings of places and what's going on. They sometimes they're kidnapping Americans there. You know what I'm saying? Depending on where you go, this certain, it's like any places you go it's if, somebody flew to the us, like the first thing you wanna know is like where, right?

So they could be going to Hawaii and having the time of their life, or they could be going to Detroit and about to get get got in certain places in Detroit, not saying all of Detroit's bad, but certain parts are not so good. Like you probably don't wanna go to Chicago O block on the south side, not a good look, not a good place to go.

And even people on O block in south Chicago will be like, no, don't come here. Do not, this is not a vacation spot.

all right. Let me see. Somebody said please, do you think that you can use that? I can use my PMP certification to get a job in cyber security cyber security space in the us. Are you not in the us right now? If you happen to be watching me right now, I got a question on TikTok. They're asking me do I think that they can use their PMP certification to get a job in the United States?

So it depend like you gotta gimme more information. Okay. So if you have a PMP, so first of all, congrat congratulations, PMP is an awesome certification. I know several Several cyber security. People who have a PMP who have a PMP who they got it because it's a lucrative certification. So congrats on that.

Can you get a job? Yes. The answer is yes. You, can if you're not in the United States, it's probably gonna take a little bit longer because you gotta have to get a remote job possibly I'm I don't know your situation, but the answer is yes, regardless of the situation, it might not be the job you want.

It might not be the money you want, but let me just let, I'm gonna demonstrate this to you right now live. Okay. What I'm gonna do is go to a common us website. It's called indeed in the us. You've got every country has top search engines that you gotta go to. If, you're trying to get a job in UK, the UK job search sites are not the same.

Are not gonna be the same as the ones in the United States are not gonna be same in India. Not gonna be the same and pick a country. They're all different. So the first, one of the first things you gotta do and whatever country you're going to is find out what are the top search engine. And I'm typing while I'm doing this.

What are the top search engines that I need to go to in order to find a job in the us? One of the top ones is called indeed.com, but there's several other ones in LinkedIn, monster.com, dice.com. Career builder.com, clearance jobs.com. Those are all us, but if you go to, if you were finding another country then it would be different.

Okay. So let me show you guys what I got going on here. If you happen to be watching me still on on TikTok or Facebook or YouTube, what I'm doing is I'm on indeed.com and I just typed in PMP certified. Project manager and, watch, let's see what results we get. I put fine jobs. You can do this on any search aggregator, by the way any, job search site.

So what you would probably wanna look at here, it depends on your situation. If you're not in the United States, you probably want to get this first one here. That's a remote position. And then look at the requirements. So they have qualification this one's 30 days old. So this is probably gone. See, one of the things you wanna do is search by posted date, but for now, like you probably wanna do it within 14 days, but for now, let's just look at this one as an example for, to get this, due a job.

So I, what I would do is I would go to indy.com, which was one of the top search engines in, this country. And we found one here is technical project support manager, and luckily project support PMP. Lends itself to remote positions. So that's why I say yes, you can find a job here. This is, this one has a salary of a hundred thousand a year.

That's pretty good. It's a full-time position. They require a bachelor's degree. In addition to your PMP, preferred bachelor's preferred. So you don't have to have one five years preferred. This is really good. If you happen, have a P and P you might wanna check this one out. If you don't make a hundred thousand, but I think this one might be gone because it's over 30 days already.

So let me actually, lemme switch the screen. So people on YouTube can see. All right. So what I'm reading, I'll read this. If you happen to be listening to me. So we already said that this stuff was preferred. Now let's get into the, if there's any caveats, meaning can you do this from another country?

So one of the questions I would ask if I was living in another country or abroad or something like that, or if I wanted to work remotely from a country like Bali not country in Indonesia in Bali. So I would wanna know do do they have restrictions on where I can work from that would be the next question.

So the answer is yes, you could find a job in the us is hot market. A lot of people say, oh, I can't find a job, man. It is booming, man. There's no problem in it. Finding jobs. Here's one right here. As a matter of fact, yeah, they got health plan. They probably have requirements cuz this is a government.

So government positions, just so you know, usually they'll say remote, but you have to be in the United States. And then another thing to look out for, if you happen to be not, if you're not a us citizen, another thing you probably wanna look out for is whether or not you have to be eligible for, a certain clearance security clearance, because eligibility means that you are a us citizen.

Or a naturalized citizen or something like that. So the answer is yes, you can get a PMP in the United States. You just have to look at the requirements of it and and, check out the site for that. And then the, other thing I didn't do on here is look at you. One of the things you have to do is look at jobs, posted and look at it from the last 14 days, rather than last 30 days.

Cuz it's gonna be a little bit different and look this one right, away. It says you have to be a us citizen or a car green card. This is exactly what I was talking about. This one's specifically saying you should have to be a green card holder or a green card holder. Let me show you here.

This is exactly what I was talking about. So yes, you can do it, but look, it is remote by the way, but they want you to have a PMP certification, but you have to be either a us citizen or a green car holder and they tell you right away. That's what you wanna look for. And then if they don't tell you on the job description, you have to do you, have to call 'em like call 'em and figure that out.

Hey, I want to know, can I work there? I'm living in another state. I'm living in another country. Is that a problem? Is there any travel whatsoever? Is it a problem that I'm not a green car holder? You got to ask 'em all these kinds of questions. PMP is an incredible certification by the way.

Really, good certification. A lot of technical guys, I know got one because it's it, pays like PMP actually pays, good money. Let me see it got some other questions here. I'll stick with Italy and Japan. okay. Let me see here. I have some other YouTube questions. I'm gonna answer real quick.

If I can, did it just log me out. Oh man. Come on drew. Come on, dude. It just logged me out. Wow. I don't know why I did that. I can see myself live. Oh, wow. Okay. I don't know what's going on. I don't know why it logged me out, but I'm about at an hour. So I'm gonna cut this short here real quick.

Thank you guys so much for watching me. I really appreciate everybody who's watching. I re really appreciate my community. If you guys are interested in getting more, the show doesn't stop. You can always catch me on. You can email me. You can catch me on discord. You can catch me on TikTok. I'm always posting a new content, any kind of questions that you have, feel free to a ask me.

Most of my content comes from people asking questions. So I'll actually make a video about it. And if it's a really, good question that I'll be asked over and over again, I'll make an entire course out of it and spend weeks and months doing that. That's it for this one, guys. Thank you so much for watching.

Thank you for listening to me on podcast. If you guys didn't know, I have a podcast that I do regularly. That's another place you can catch this stream. It's on pod bean.com. Check that out or in Lincoln description below.

View Details

http://convocourses.com

check out the video: https://youtu.be/TGrw5yT6sSY

Hey guys, this is Bruce and welcome to combo course podcast. And today we're gonna be talking about a few things. One of the things I wanna talk to you guys about is process versus prize or system over goals. And this really applies to everything in life, but we're gonna specifically talk about cyber security.

Another thing I'm gonna show you as a new book I'm working on. It's not, it's gonna be out. I don't know, probably within the next month and a half, I gotta get it edited and all that kind of stuff. I'm actually still writing it, but it's gonna come out soon. So that's. Something we're talk about, then I'm gonna open it up to any kind of questions you have about getting into this space in cyber security.

And in the it, I got a lot of people contacting me about how to get in this field. That's growing really fast or how to upgrade themselves and all that kind of stuff. I've been doing this for over 20 years. I'm a subject matter expert specifically in cyber security compliance. That's, what I've been doing for most of this time that I've been in this space.

And so if you have any questions about that, how to get in it, how to, what to do like specific questions even I can answer 'em on this live. All right. Let's get into this. First of all, I want to tell you guys that I have a site called combo courses.com where I sell lots of stuff. A bunch of courses, also books, and a ton of stuff for free.

If you are interested. So if you're interested in that, go check out convo courses.com. Like, I said, lots of free stuff. It's free to sign up lots of training downloadables if you happen to be in this space I'm constantly giving out free stuff. I'm trying to build a community. And that's why, if you have question, why I'm giving out anything for free, that's the reason why cuz I'm building a community I'm, thinking bigger.

I'm thinking about making a community that helps itself and Built one of these before in a whole different genre. And it, works really well. So that's what I'm doing. If you're interested in joining that community, join me on, YouTube. Join me on discord. Join me on TikTok. Join me everywhere.

Combo courses, just type to combo courses. You'll find us out there where have a growing community of people that's coming together to learn this to, level up together to, get more to, make that money really. That's what it comes down to for take take, care of our families and take care of ourselves.

Okay. So what I'm gonna talk to you today about the first topic of discussion will be about will be about process versus the prize. A lot of people contact me about trying to get to certifications or degrees and which ones should they get and all that kind of stuff. and it's really the wrong question and I don't fault anybody for it.

Because I was, I had the same kind of questions when I first started. You should be focused more on the process and this, really goes on everything in life. Your focus should be not on the prize, not on how many likes you get, not on how many people are watching you, not on how many people or how many degrees you're gonna get or, courses or any one thing.

It should be on the process itself. And we're gonna specifically talk about cyber security, cuz that's my profession, but this really applies to anything in life. Let me specify what I mean by using this an example. Lately people have been asking me about the a plus comp Tia certification and how do you get it?

Where, do you get it from? How do you know all this kind of, what kind of job can you get if you actually do that, all that kind of all those kinds of questions and is there's nothing wrong going for that certification or any other certifications. Absolutely nothing wrong with that. And I would encourage you to get it if this is your first time getting in, into cyber security, into it in general it's a good thing to get.

But what I wanna say is that the most important thing that you should focus on is the process of learning this the common body of knowledge that goes into it. And the reason why I say that is because if you focus on the common body of knowledge, if you focus on actually learning what you have to do in to get that certification, to get that it certification.

If you focus on that, you'll have all the knowledge that you need to go ahead and take the Google support it certification. You'll have the knowledge that you need to actually go ahead and take the in network plus certification. You'll, have all the knowledge you need to actually spend your, whole your, whole resume.

If you actually learn the stuff that's in the comp tier a plus certification, right? It's just one thing. If you focus if you focus on just that thing, just that one prize, you'll get that prize, and there's nothing wrong with that, but I'm telling you to focus on the whole orchard. I'm telling you to focus on the seeds.

That's gonna get you like not just one certification, not just a little bit of experience, but expand your whole horizon and get you way more knowledge, way more certification, way more experiences and, actually get more from the fruits of your labor. To do that. You gotta focus on the actual labor, not the prize.

The prize is cool. I'm not telling you like not to get it. I'm saying expand like what you are, what you're doing by focusing on the work, focusing on the process itself, of learning the process of learning all the curriculum that's in CompTIA. And let me give you a specific example of what I'm talking about.

Let's go to CompTIA. Let's we're gonna use CompTIA a plus certification as an example of what I'm talking about. This is my, this was my first certification and this is why I promoted so much because after I learned that certification, I knew enough about computers to where I could get in this field.

And I was working helped desk for a while and I learned enough about troubleshooting and all that kind of stuff to where it, was able to expand my entire career. Eventually get me to working, making six figures and being able to take all these vacations and all kinds of stuff. But here's the curriculum right here.

And if you're listening to me right now, it's, I'll read it. There's nine skills that you have to master to validate your CompTIA, a plus certification, hardware, operating systems, software troubleshooting, network troubleshooting mobile devices, virtualization, cloud operational procedures, these, all of these things.

And these section, if you actually buy the book, these are the sections, some of the sections that'll mainly be broken into. And of course, it'll go more detail in each one of these areas. If you actually learn this stuff and not just go ahead and take the test and pass, cuz that's, actually the easy part taking the test and passing it you can actually go.

and take a bunch of just retake the test over and over again. And eventually you'll pass the test. I'm telling you to study the common body of knowledge and know and understand what's actually happening. Do go beyond just taking the test, go beyond just taking the questions and passing the test, go into actually setting up a lab in your house, figuring out how to put all that stuff together, figuring out your own network, figuring out how firewalls, whole space firewalls work, how's that different from network, firewalls, learning, all that stuff by maybe even actually doing it in your own home.

Maybe actually helping your community out. If there's an opportunity for you to do that, actually getting hands on to where you literally understand it, building your own computer, things like that, to where you understand it. So fully that the comp Tia a plus certification, when you get it is not a big.

It's your first certification. So obviously you're gonna be patting yourself on the back, but what I'm saying is if you expand your base and you understand this stuff, like you really deeply understand it, you can go then and go take other certifications, entry level certifications, easily like a plus certifications, the natural next step in your evolution.

And then the next thing you could probably take is a com is a Google support it certification, which will probably be easy for you, cuz you have gone so deep in the rabbit hole for a plus certification. I'm telling you to learn the common body of knowledge and learn the process, put the, put that work in and that will give you all your other, everything else.

You'll get all kinds of other prizes, not just the certification, right? And you might even inspire you to go get a degree. If you choose to go that path, you don't have to, but you could the process over the prize. This is book I read. A really good book. I encourage you to go out and get it. It's called atomic habits and it's really, it's a really good book.

And he, one of the things he said in the book was don't focus on the goal, focus on the system, creating a system to get that goal. And that's what I'm talking about. So if you focus on the process, that'll get you to that certification. You can get a whole bunch of other certifications and experience. If you actually understand how to build computers, how to build a network, if you actually have a hands on that you can do in your house nowadays.

So that's what I'm trying to encourage you to do super important. The next question should be how do I, get developed a discipline to focus on the work rather than just the prize? Because it's easy to work, focus on the prize. Like you're thinking about, okay, if I make this $65,000 a year after I get the certification, or if I can, if I, maybe I focus on getting I'll be able to get six figures.

If I get this professional level certification, and now I'm not telling you not to get six figures, I'm not telling you not to get a professional level cert. I'm not telling you not to get agreed. None of that. I'm not telling you that's the fruits of your labor. What I'm trying to tell you is if you focus on the actual process, if you work, if you focus on the discipline in that process, you can have any damn thing you want.

And what happens, what I've noticed is what happens is like when you focus on that discipline in this career path, all the people who I know who, are at this super high echelon is super high level. All these guys are highly accomplished because that's exactly what they did. They're more focused on like actually knowing and understanding how to do this stuff.

and because of that, all these other certifications are within their grasp. They have all these other opportunities and all of these other success factors that come in because they actually know the material. So well, that's where I want you to focus on. If you focus on the discipline of doing the process, then everything else you'll not only have the certification, you'll have several other opportunities to take other certifications, cuz you'll understand it so effectively.

And then after a while you notice a plus certifications is not that big of a deal at all. You'll notice that the does any certification is not that big of a deal. One of the things that I've learned on this path of just having the discipline to to, really go deep in this and become a professional level, subject matter expert in this field is that.

whenever I go to a new organization, they're always pat me on the back. I get all these certifications. I get all these awards I should say. And and I'm not telling you that to like brag or anything like that, cuz it's not bragging rights for me. It's bragging rights is that I was able to take care of my family.

It's bragging rights is I was able to take my family to Hawaii. That was dope. I do this for my family. I do this for to do better than just survive. And for me that's the greatest reward that I could ever receive because of that. I don't care that some giant company gave me an award, gave me extra a little bit extra cash because I, accomplished something within their organization.

When you I'm focused on the process of allowing us to have a roof over our head and to eat good. That's what I'm focused on. The process that it takes to do that means me studying sometimes late at night means me waking up a little bit earlier. Sometimes means me putting in the work that I need to do beyond motivation.

Cuz sometimes I'm not motivated. Sometimes I'm sick to my stomach and I don't feel like doing nothing. And I don't feel like getting out of bed. I, all I wanna do is watch YouTube all day and watch stupid videos. That's why , but what do, but I know that the discipline has to take precedence over bad habits, so once you get that in your head, once you start to develop this muscle of just having the discipline to get outta bed and go stay up late or do other things you need to do to make these things work. It, changes everything in your whole life. And I'm not just talking about cyber security.

I'm talking about everything in your life. . If you focus on the process and the discipline that it takes to do that process, you can do anything you want to do in this life, but it takes motor. It takes discipline beyond motivation. Motivation's not enough. You gotta have the discipline to do it. And that, and cyber security is no different.

So that's all I want to say about that. It's just something that I noticed about my own life. Anything that I've done in my life that was successful, but it came because I had the discipline to put, I put in the discipline to do it. If you go out and the discipline takes you to another level because, if I fail a certification, you only fell.

If you quit, I'll just keep taking it until I pass it. That's what I'll do. I won't. I do. I will not quit. I'll just keep taking it until I pass it. Once you get that discipline in you, nothing is gonna stop you. You're just gonna keep doing it. Okay. Anyway, let me tell you guys about Couple things here.

So if you didn't know, my name is Bruce. I run a site called combo courses. I'm building a community of like-minded cyber security, people who wanna teach each other, learn from one another. I call it combo courses, cuz it's a conversation between me and the community between us, the, between the community and itself.

I'm, building a community. I've got 10,000 followers on YouTube. I've got a few followers on on Facebook. I've got a few followers on my Facebook group on, discord, on and starting to build a community on TikTok where we're just helping each other out, learning from one another and building up and that's the, ultimate goal to this whole.

If you're interested in learning more, you wanna follow me go to YouTube and then go to combo course type in combo courses. You'll find me there where I talk about all things related to cyber security. Talk about how to get into this field. I talk about how to do risk management framework, which is my specialty and, security compliance.

That's what I mainly focus on. If you're interested in getting more out of this, I've got a book out there. That's related to my actual specialty, which is risk management framework, where I talk about the security controls that go into N 800 risk management framework. I've got one that's foundational and I've got one that like foundational, meaning you don't have to know anything.

You just listen to the book. I got it on audio by the way. Or, you can read the book and and, learn a little bit more about that. And it's so popular that people are literally copying my book like this dude copied my book and is selling it. He copied my book and selling it as his own anyway.

So it must be good if that's the case. I've got two books out there. I'm building more than just a book. I'm building a entire community. I'm building a a, an entire something where you can talk to me directly. You could talk to me directly and ask me specific questions about how to do this. And I think that's why a lot of people have been following, because I answer questions that they ask me.

So if you have any questions whatsoever, feel free to con to call up to email me, or you could actually ask me a question right now. If it's related to cyber security, I'll do my best to help you out. And, that goes for everybody in this community. I really appreciate all the people who've been following me.

I appreciate all the questions. I appreciate all the accolades, all the. Great comments that I've gotten on my book. It's, really been a great, a very rewarding thing to see people actually commenting and, leaving positive comments on my books and stuff. So that's really good. If you didn't know, go to amazon.com type in risk management framework or Bruce Brown.

You'll see my book there. And I also have a site called combo courses. I have a podcast I'm doing at least once a week. I've got I'm on YouTube doing combo courses. So follow me if you're interested in this kind of content, if you're interested in getting the it or a risk management framework then, follow me.

All right. And I'm gonna show you guys a glimpse of the book then I'm writing right now is how to improve your resume and, be able to get people to contact you. Cuz that's what I've been doing in the last few years. Reason why I've been able to get all these jobs quickly. Okay. Deru has a question on YouTube.

He says, Hey Bruce, what resources would you recommend for keeping in tune with the latest. And updates in cyber security. And I would say de truth. That's a good question. By the way, I would say that really depends on what categori category, sorry that you have in cyber security because there's many different cat cyber security is a huge category.

It's huge. Like it's a huge field. It's a huge umbrella. You've got everything from risk management framework to you've got cyber threat intelligence which, does threat hunting. You've got you've got Intel, which is considered a part of cyber security cyber Intel. You've got forensics, you've got all kinds of different branches of cyber security.

So it really depends on the branch. Now, if you want an overall of all cyber security, I could tell you, I could tell you some of my resources. And then what I'll do is I'll break it down into different genres of, cyber security, the ones that I know. All right. So first the first really good resource would probably be the CIS A's website.

CISA is a government site not, the actual certifications from Isak. I'm talking about csa.gov. And so CS a is cyber security infrastructure and security agency. This is one of the most one of the best resources. Let me just switch my camera here for TikTok, for those who wanna watch. So this is SI this isa.gov csa.gov.

And these guys are one of the best resources for things that are going on mostly to the whole United States, like federal government, state governments. If there's a huge hack, you'll see 'em here. Pop up here. You'll also see different vulnerabilities that come out like the big ones, different malware.

Like right now here they have 20, 21 top malware strains. And then they've got a blog here with the newsroom. Let's just go to, let's go to this one. This is dated August 31st, and this is SAFECOM publishes 2022 SAFECOM strategic plan. This is all like federal type stuff. So if you are in the federal space, this is one of your best resources.

Let me see what other resources are there? Other places you can go if you happen to be in vulnerability management are the people who like manage they manage let me see if I could switch. Oh, you switch it like that. Huh? Oh, that's cool. So messing around with TikTok , that's what I'm doing in the background.

So vulnerability management, that's people who take care of their organization's vulner patches, right? PA there's patches that are always coming in. And they have to update 'em. So one of the best resources for that is probably CVEs is a huge database of all the vulnerabilities that are popping up throughout the industry.

That's through a vendor it's all vendors. So it's not any one specific vendor that being said, vendor. If, you have say Microsoft patches, then the best resource is Microsoft for, their most recent vulnerabilities in how to fix 'em. And then if it, if you have a Cisco device, it's Cisco.

That's the best place for the most current things going on with Cisco. And if you have an apple product, same thing, like if you have a Macintosh, you go to the vendor, but this CVE site is really good because it has a huge database. That's constantly being updated to inform you of what is going on for vulnerabilities.

Let me see if I can find a really good breakdown of this. Let me see, where do you normally I find the individual CVEs from the, from Google. Let me see CVE resources. Okay. Just trying to find like a specific CBE that I could show you here. So yeah, CBEs are good for for, actual vulnerabilities and then there's Like I said different branches of cyber security.

So each branch has its own like group of resources. Government has C I S a everybody in a lot, everybody in the government goes to C S a site. And they have the most recent APTs advanced, persistent threats, most recent vulnerabilities, all that kind of stuff. What's what the government's doing.

Like what, where we should be focusing our energy. What it's, really good resource. And CVEs, this is like a huge database of, all the places you want to go for vulnerabilities. And I'm look, I'm still looking for the actual database of the actual vulnerabilities. Let me just, okay. See CVE I'm on Google right now, typing in CVE.

Let me see a specific one would be iOS CBE for I iOS. They have a vulnerability data database that has every single vulnerability you could think of. So this one's for iOS 15.6 and at this is going straight to apple site for 15.6, a recent kernel update and web kit update that they have. And it's for CVE 2022 3, 2 8, 9 3.

You might be familiar with this one, but I'm gonna type that one into Google. And it goes straight to the CVE site that I was just on. And then it'll have a breakdown of, how it affects other things. So this is one of the best resources that I, was, we were using a lot in almost every place I've gone to.

We use the same thing, private sector and. Public sector uses this one. Now, if you're in the department of defense, let me show you like department. See, it really depends on where you're at, but department of defenses, best resources is called dissa. D I S a DISA do mail. Okay. So D the DISA mill website has some of the best resources as far as how to fix your system.

They have the STIGs the, security test security, technical implementation guides, one of the best resources on the internet even, the private sector uses it. That's how good it is, but this is a really good resource for department of defense and actual federal government. And it's so good.

Recently it's gotten so good that even, the private sector start using the STIGs. So yeah here, it is right here. Here's the news that they're always releasing different stuff. That's related to department of defense, mostly. But. Their STIGs are incredible. Their training is ridiculous. It's one of the best resources.

It really depends on what branch and what area of cyber security that you're going in. But so I, hope that answers your question de truth. Specifically, what area, if you tell me, what area of cyber security you're in, we could find like a really good resource for it. Okay. I've got a question or comment on, TikTok.

They say, Hey, hi, Bruce. How difficult is it to travel with a security clearance with, or without a job? This is a great question. Okay. The question is how difficult is it to travel with or without a security clearance? It's not difficult at all to travel with a security clearance. It just takes a little bit of research on your part.

It depends on the, on your clearance. So Deru thank you so much for that 19 bucks. I appreciate you. So let me, this is a really good, this is a great question. I'm glad, so glad you asked me this question. So let's answer this now. I'm speaking from a person who's had a public trust, which I have right now.

I've had a sec, a secret clearance, and I've had a Ts S E I clearance. And I've known people who have a higher clearance than me. And I could tell you there's there is a difference. Alright, how difficult is it to travel? It's not difficult. You can travel anywhere you want. However

I'll start from the highest and go to the lowest. Okay. So a friend of mine and I won't name names, I won't tell how, what kind of clearance he had. I'll just say it was a hi, his clearance was higher than sci this. If you wanna Google what that is, then just research it for yourself. Just go to Google and type in high clearances.

High top secret clearances. He had one of those. He had something above that, and this dude could barely talk about what he did. He was very guarded. He said that they tapped his phone. Like they knew where he was at all times. It's it is the most ridiculous thing I've ever heard. It's preposterous. I said I would never work for an agency that does that.

They openly told him, Hey, by the way, we are tracking you we know where you're going. Here's and then they told him there's places you cannot go. It's, there's places you couldn't. And then when he named the places, I thought he was gonna say oh, I can't go to obvious places. Like I can't go anywhere near Iran.

I can't go to there's certain places in some, countries in Africa, you can't go there's certain places in. But then he said he couldn't go to certain parts of the Philippines. I was like, what? There's certain parts of the Philippines. He couldn't go because there was terrorist activity there.

And I was shocked. I'm like, I never heard of nothing like that. I didn't for a second. I didn't even believe him. Then he started breaking it all down. Cuz there's like some kind of terrorist threat and some part of mening now I'm like, are you for real? And then there was, they even questioned people.

He talked to whenever he would go overseas. So they weren't. And then a lot of times they weren't saying you can't go, but if you go overseas, you gotta tell us where you're going. You gotta tell us who you're talking to. That's the kind of clearance he had. All right. I don't like, I don't know much about that.

I can just, all this is hearsay and bullshit. Okay. So do your own research on that one. I'm just telling you what this dude told me. Let me tell you about something. I know about the clearance. Like I had to tell top secret S sci I had a secret clearance and I had a, public sector. I'm gonna tell you about those three.

All right. So in my experience, number one, there's no, they're not restricting me to. To most countries, the countries that I'm restricted to go to are obvious, and most, Americans should not go to these places. North Korea. Don't go to North Korea. Just don't. If you wanna know why just Google it, just do your own research.

Don't go. It's just stupid. It's just dumb. Don't don't do it. just don't especially if you used to be in the military, just don't do it. I don't, I just, anyway, I'm saying that because people have done it, you probably might be thinking like, why would nobody goes to North Korea?

People don't do it. Iran. Don't just, don't go. The us. And unfortunately it's unfortunate that our countries cuz it's a, it's an amazing place with amazing. amazing human history is happening there. And it's a shame that our governments can't work things out to where human beings can't go to certain parts of the world.

To me, it's just dumb, but if you have a clearance yeah, they monitor that there's certain countries you really will lose your clearance over. There's certain places in there's certain countries in Africa that you can't go certain countries in Africa. Can't go, cuz there's too many. There's a list.

Normally when you go to an organization, they'll have a list of places that you, they recommend you do not go. And so when you're, when you have your clearance, you're at this organization, one of the first things you should do is figure out what those countries are and what the policy is for your organization that you're working for.

What policy do they have that says, okay, you cannot go to these places. And here's why, and the reason why that you can't is because of this thing called I a R. And so I a R is. Oh Lord. What is the acronym? I a it's like international. If you guys know what it is, please let me know. I can't remember off the top of my head.

I a R is international trade arms. It's okay. Here it is right here. International traffic, and arms regulations. It, doesn't like this, the name of it doesn't fit. What it does. That's why it's confusing because it's not just arms that they're tracking. It's like all kinds of techn technical goods and, certain technologies.

And I of understand why they do it because if you look at a country like China, China steals a lot of in an LA. This is not, cap. This is not conspiracy. This is real China. And other countries will steal certain technologies from us companies. They do this on a regular basis. It's a pretty smart move.

I think they steal your, their, I. They've done it to Google. They did it to Google's search algorithm. They did it to Cisco. They did it to they stole the, that what's that jet. Oh my gosh. The joint strike fighter, they stole all the, they've done it to multiple successful organizations.

And not just in the, to the United States. China's just one example. All countries do this, all countries do this to one another, they still intellectual property. And then they either implement it or do something in their own country so that they can get a leg up. But a lot of people do this to the United States cuz of the United States, regardless of weight, how you might.

About the United States. It has some of the greatest innovations on planet earth. And it's because we're living in some sort of golden age where all this stuff is coming out. Like eventually this is gonna die out. Eventually all the ideas are gonna shift to another part of the world, probably China or something.

But right now us is in this place where all these inventions are happening. Mostly from even TikTok, TikTok used to be vine. You know what I mean? Like this idea of TikTok was taken from vine. They looked at vine and said, wow, that's successful. And then they reengineered it, made it better. And, then absorbed musically.

And then now you have TikTok, vine started in the us and I don't know, like what's going on in the us. Why there's so much innovation, why there's so many, I think it's because the, in my mind I I know it sounds. stupid conspiracy theory, but, or some kind of stupid faith patriotism, but it's because we're, there's freedom here.

There's freedom to think what you want and do what you and make mistakes. And that's why there's so many innovations here, I think. But if and if you, travel the world, like what's weird, what's crazy. When you travel, speaking of traveling, you see how much influence the us has on other countries.

You see how just going like Philippines. I was in the Philippines like last two weeks ago, three weeks ago. And everybody's wearing Fu boo shirts. Fu boo is a us brand from diamond. What's his face? Not yeah. Diamond that billionaire the, billionaire on on shark tank, that dude came up with that brand and that thing's all over the Philippines.

One of the most popular brands in the Philippines, you're walking through the mall and. I'm just saying like the influence that the us has is crazy. So one of the things that they, that country like different companies will have you do is Don not do not take our intellectual property to these countries.

They'll have a list. Don't go to those places. If you value your career, look at what their policy is and adhere to it, if they're saying, do not go to these countries, don't do it. So that's what I'll say about that. It doesn't. So to answer, go back to the question. went off on the tangent, the que original question from, to was how difficult is it to travel with the security clearance with, or without a job?

How difficult is it? It's not difficult. You can go wherever the hell you want. The problem is there's certain countries. If you go to go there, if you have a high enough clearance, you can lose your clearance. And they'll have a bunch of questions at the very least. They'll have a bunch of questions when you get back and they'll know where you went.

What you can do is before you go, is you tell them I'm going here and then they'll have a list of things that, that they will, that they'll say for you to do or not to do. Is it difficult? No. Can you go, yes. Can you jeopardize your job? Depends. If you, violated that, that organization's policies and yes, that you can lose not only your clearance, but your job as well.

So just keep that in mind. Somebody on TikTok said, Hey, yeah, they they're incredible at reverse engineering facts, Then in the Chinese, like in my mind, Chinese are the smartest human beings on earth. The Chi the Chinese are ha they're you say what you want, but man, they're in a they're I don't know, like it's so smart to steal.

Like this is the smartest thing. You can do steal a billion dollars worth of research, take it to your country. And then boom, you have by. You have WeChat, you have TikTok. How smart is that? That's brilliant. I am a lamp seeker says you might end up with a polygraph. Oh yeah. A polygraph test.

So one of the things that will happen is that you come back from your trip overseas and then they'll give you, you a polygraph test where they'll ask you a bunch of questions. Have you talked to any foreigners? Did, any foreign person come up to you and, ask you questions? This is just what I've heard from the, my, a friend of mine who has a high enough clearance to where they ask those kinds of que that's of what happens if you have a high enough clearance.

So do your own research. If you happen to be at an organization that has clearances and stuff, and you're dealing with sensitive information, look into their policies, look into I a R, which is international traffic in arms regulation. It's, not as bad as you think norm normally it's gonna be obvious places that you shouldn't go anyway, as an American citizen, it's just, you're jeopardizing yourself.

know, I'm just being real with you. Don't, there's certain places you shouldn't go. If you want to know what that list is, you can probably go to they have a list of them on us embassy. The, state department has a list of places that they recommend. You don't go. If you have a clearance, you should probably listen to that list.

Especially if you have a high enough clearance. All right. Let me ask, answer another, read some more comments here. Deru thank you so much, sir, for that, that 20 bucks, I really appreciate you. It says, I appreciate all you do. Your courses have helped me tremendously to learn risk management framework for my everyday duties.

Thank you. And please keep up the great work and teaching people, man. Thank you Deru I really appreciate you, man. I appreciate this community. Thank you guys for watching me for all these years. Much appreciate it. All right. Let's keep going. I'm gonna answer a couple more questions. I'm not gonna be on here that long on this one.

Feel like I said what I needed to say, but if you guys have any questions, I'll stay as long as we have questions. Let me see I'm going on YouTube right now and answering some questions from there. Have a very lively, active community on YouTube. If you're interested in getting diving into this. But I have one, a couple comments on, TikTok says I agree with you.

you have to have some permission to go to some certain countries. You might get a polygraph. Wow. Yeah. He, this guy knows what he's talking about. So speaking back on, on this security clearance issue, not enough, really people really talk about this. And that's why I think I get so much traction on, YouTube and social media when I talk about this kind of stuff.

But he says he says, he, when I was, what I was saying is if you travel with a security clearance, you should get permission. The right thing to do is to talk to the organization. Okay. That's the safest and right thing for you to do. If you have a clearance, if you have anything I say above a secret, if you happen to work for, even if you don't have no clearance and you're working for a, an organization who deals with sensitive information, especially if you're trying to work from those countries, like you should really think about doing this, talk to the organization first and say, Hey, next month, I'm going to Thailand next month.

I'm going to Indonesia. I'm going to Columbia, wherever the case may be. Just let 'em know. And what'll happen is because I've done this before the HR department will say here's a pamphlet of places. You shouldn't go in colo while you're in Columbia or you shit, you can't go to Cuba you, can't go there.

Here's why. And you might not agree with it. You might think it's stupid and maybe it is. But the point is, if you try to go, you could lose your clearance and your job in certain places that you go to. And then he lamp seeker says they might do a polygraph test on you. Like when you get what he means is I think this is what he means.

This never happened to me. When you get back, they might ask you some questions and hook you up to a polygraph test to see if you're lying. I'm not that's isn't that crazy? That's never happened to me, but a couple friends of mines that happened to that have a high enough clearance that, that happened to I'm like, wow, really?

Yeah. So just be mindful of that. You can go. But the right thing to do is to talk to your organization before you go and do your own research too, look at their policies, right? If you don't wanna say anything, you want your own privacy, whatever, do your own research, because they'll have a policy that tells you flat out, Hey, look at the HR departments travel.

They have a travel guide for you. Look at their read that thing, especially in the foreign country, foreign travel, read that, and they'll have a list of do not fly. Like you cannot go to these places. And here's why I a R whatever the case may be. Here's why you can't go. Or they'll say you can go there, but avoid these places, or you can go there, but.

Don't talk to you gotta avoid talking to just any random people coming up to you to asking you questions. And the reason why I say that is because one of the tactics that organizations from a foreign organizations will do is they'll have a casual, fine looking young lady. Come sit next to you at a bar and start asking you a bunch of questions and get real, real intimate with you and ask you a whole bunch of questions to get more and more information off you and try to date you.

If it's really serious, they'll date you like a damn spy and get even more information while they're dating you. Right now, you have a long distance relationship with a person who works for the CCP or something. If you think that this is crazy talk and spy talk, this actually happened to a couple Canadians, happens to Canadians and Americans.

You don't believe me. Look it. Like they work for the government or they work for a high level organization or just an organization. All these innovations they'll get really close to you. Then they'll start asking a bunch of questions. Just be careful. All right. Lamp seeker says, keep up what you're doing.

Thank you, sir. I appreciate that. It says even a secret that you have you have to get permission at least 30 days. Oh Oh. you're saying if you have a secret clearance. Okay. Okay. Listen to this. Here's some insider information right here. If you have a secret clearance, you have to get permission at least 30 days ahead, and some require 45 days or more.

So the right thing to do, and he says I'm an ISSO, but I was in industrial security for 15 years. Oh, here you go. Right here. So these guys put me on a game, like people like this is combo courses right here. This is what I'm. This is why I do this. People like this dude right here who come and educate me.

This is a great opportunity. A teaching moment. So I didn't know this. So listen to this. If you have a secret clearance, especially if you work in cyber security, right? Regardless it, if you could work in the hospital, sweeping floors, if you have a secret clearance, he's saying some organizations require you to let them know 30 to 45 days in advance.

And he's saying he's an ISSO, but he used to work in industrial security for 15 years. Industrial security are the guys who are really, deep into things like I a R really, deep into things like personnel security. So this guy knows what he's talking about. When one time I was doing it live and I was like, I don't know, I've never had a polygraph test and I don't know how it works and this dude just schooled me on it.

And I was able to, we were able to push that information out. So other people know information about a polygraph test. So I really appreciate that. Thank you, lamp seeker, great information. And he says, especially if you didn't get permission yeah. You gotta get, you should get permit. That's the right thing to do that's the right thing to do.

All right. Let me answer some questions on YouTube. And in Deru adds to that conversation, he says, always talk to the FSO of your company. And that's a correct me if I'm wrong, but facility security, officer functional security officer functional FSO is like a security person. Who, does secur personnel security.

Like they, they make sure that you, if you're gonna travel somewhere you're read up on any kind of issues that going on in that country. If there happen to be any things like that you, have to have situational awareness. You should know what you're just getting yourself into. If you do go to another country.

And that's something that I've been really good about, I travel quite a bit and I've been traveling even when I was in the military, I would travel. And you it's really important to know situational awareness. And let me just give you a couple stories, cuz I've been traveling since I've had up to top secret clearance and I've traveled extensively.

I've been to 15 different countries. And while I had clearances while I was working in the private public sector and I, know a little bit of something about this and I'm, gonna tell you a story. So when I I was in I used, I was stationed in, Korea. I was stationed in South Korea and this was in year 19.

I'm dating myself, but it was in 1,998 to, the year 2000 yeah I'm, a little older than I looked. Yeah, I was stationed there and I would just go off base. I would just roll. I would just roll off base. I was in Kusan and Osan that area. And I would I was actually in working in security.

I was a, I was physical security at the time. I was a security force member in the mil, in the military. That means I was military police as probably the thing. Everybody understand really. I was weapon specialist. I was high level security guard anyway, so I would just go on. I learned Korean onion, AHI come, Sony die.

I learned some Korean and then I'd get in the car. And the taxi, and then just go, and so the problem with that is that there's certain places in Korea that people don't really didn't at the time and probably same hated Americans at the time. There was a bunch of colleges that how colleges are, right.

There's just a lot of younger people and influenced by a, like a rebellious mindset. And they, it, bottom line is they hated Americans and they blamed the us for dividing the north and South Korea. And the reason why I know this for sure is cuz that's the red Eric. They were saying when they were out there protesting at the colleges and also that's what some of the gate guards, I would have to work with Korean.

The Royal the Republic of Korea army and air force, I would walk, I would talk to 'em. Some of 'em were really cool and taught me Korean and, I would talk to 'em about English and hip hop and stuff like that were really cool, but some of them hated me and they would not say three words to you.

And I would still talk to those guys and they would flat out telling me I don't like Americans and I'm. and a little bit in Korean, why don't you like us? And they would tell me you guys divided the us government divided our country in half. And you guys are the reason why north and south are no longer speaking to one another it's you are the reason if you guys left, we'd be able to unite Korea and I'd be like, what?

I'm like, that's not what I was told, and I was like, then I thinking are both of us being fed propaganda for our go from our governments? I was just thinking about all this stuff long. Okay. Let me get back on track. So I'm off base and people are super cool with me. I'm some black dude in, South Korea in the middle of nowhere.

Nobody can speak English. I'm speaking, my broken ass Korean and people are super cool, but it's the older people who are. Younger people hated Americans. And so at certain places that you would go get back to base and I was cool, right? I just met a couple. I had this great experience in Korea and everything.

I was just like, happy but I get back to base and they said, Hey there was a dude who got killed. There was an army dude who was in the wrong place at the wrong time. And this mob of Koreans killed him because they were having a protest. And I don't know what this dude was thinking, but he was walking by college and this mob killed this dude.

And they were saying, do not go to these places. Here's the this area here, and this area here, if you are an American, do not go here, period, you are not allowed to go there. And they told us why they, killed more than one soldier who would happen to be near those. You might, they might have had a girlfriend there.

So I don't know, but these dudes were killed and I was like, damn. Luckily there were no not big colleges where I was at, but just situational awareness. You gotta know what's going on. So whenever you go off base, whenever maybe you have nothing to do with the military, you just traveling abroad or whatever, just know what's going on.

I'm not telling, I'm not trying to scare you from going abroad, man. You should definitely use leave the United States and go experience the world. Experience, humanity, experience other cultures, man, it's gonna open up your eyes to a whole different I'm different, man. I'm, I've been to several countries.

I've seen extreme poverty. I've seen extreme wealth. I've seen I know that the us lacks heavily in certain areas that we shouldn't lack in, but I know that we, that the us is so successful in or other areas. The U. The world is not what you think it's, way beyond what you believe or watch on TV or whatever.

Like you gotta go there though. I'm not trying to scare you into not going, but I'm just saying have situational awareness. One of the things that military taught me is you gotta know what's going on for your own safety and security. Read the news that's going on in that country at that time. See what's going on with that country.

I'll give you another story about situational awareness. Not too long ago, like maybe five years ago, I went to Thailand and I was in Thailand, me and my, wife at the time we were chilling. We had a great time. We I'd been there like four or five times or something. I've been there total four or five times love Thailand.

I've been to two different cities there and stuff. I just, the people are great, man. The the, monasteries I went to the monastery seen that sleeping monk. There's this giant like sleeping monk a sleeping Buddha ah, man, this is just amazing. I went to old Siam, which is now called a Utah. A beautiful place, man.

The people are so nice. I man, anybody who's never been there, man should try. It is check is so amazing, such an amazing place. Anyway, me and my wife at the time we were there, we're hanging out with chilling and we had a great time. We go to leave. We get on the plane and we're leaving. We are on the plane leaving.

And then as we are in the air as it's taken off, we learn that the, country just had a coup and they shut down the airport. So we, might have missed that coup by about 15 minutes, cuz we were already boarded and flying and they shut the airport down and nobody could leave. I had no idea this stuff was going on.

I was just there as a tourist. I didn't see any protests where I was at. I didn't see any of that stuff, but a little bit of situational awareness for me. Would've let me know. Hey, there's something going on? I had no idea. And a lot of times, as a foreigner going to another country, you're totally clueless on this stuff.

Always have situational awareness, no matter what, whether you have a clearance or not, whether you work at a company that has sensitive information or not always know what's going on in that country, what's hot. What's going on, where not to go, where to go. You could find all this information on the internet a great resources would be the, embassy website.

They have, they usually like a breakdown of alerts and warnings of places and what's going on. They sometimes they're kidnapping Americans there. You know what I'm saying? Depending on where you go, this certain, it's like any places you go it's if, somebody flew to the us, like the first thing you wanna know is like where, right?

So they could be going to Hawaii and having the time of their life, or they could be going to Detroit and about to get get got in certain places in Detroit, not saying all of Detroit's bad, but certain parts are not so good. Like you probably don't wanna go to Chicago O block on the south side, not a good look, not a good place to go.

And even people on O block in south Chicago will be like, no, don't come here. Do not, this is not a vacation spot.

all right. Let me see. Somebody said please, do you think that you can use that? I can use my PMP certification to get a job in cyber security cyber security space in the us. Are you not in the us right now? If you happen to be watching me right now, I got a question on TikTok. They're asking me do I think that they can use their PMP certification to get a job in the United States?

So it depend like you gotta gimme more information. Okay. So if you have a PMP, so first of all, congrat congratulations, PMP is an awesome certification. I know several Several cyber security. People who have a PMP who have a PMP who they got it because it's a lucrative certification. So congrats on that.

Can you get a job? Yes. The answer is yes. You, can if you're not in the United States, it's probably gonna take a little bit longer because you gotta have to get a remote job possibly I'm I don't know your situation, but the answer is yes, regardless of the situation, it might not be the job you want.

It might not be the money you want, but let me just let, I'm gonna demonstrate this to you right now live. Okay. What I'm gonna do is go to a common us website. It's called indeed in the us. You've got every country has top search engines that you gotta go to. If, you're trying to get a job in UK, the UK job search sites are not the same.

Are not gonna be the same as the ones in the United States are not gonna be same in India. Not gonna be the same and pick a country. They're all different. So the first, one of the first things you gotta do and whatever country you're going to is find out what are the top search engine. And I'm typing while I'm doing this.

What are the top search engines that I need to go to in order to find a job in the us? One of the top ones is called indeed.com, but there's several other ones in LinkedIn, monster.com, dice.com. Career builder.com, clearance jobs.com. Those are all us, but if you go to, if you were finding another country then it would be different.

Okay. So let me show you guys what I got going on here. If you happen to be watching me still on on TikTok or Facebook or YouTube, what I'm doing is I'm on indeed.com and I just typed in PMP certified. Project manager and, watch, let's see what results we get. I put fine jobs. You can do this on any search aggregator, by the way any, job search site.

So what you would probably wanna look at here, it depends on your situation. If you're not in the United States, you probably want to get this first one here. That's a remote position. And then look at the requirements. So they have qualification this one's 30 days old. So this is probably gone. See, one of the things you wanna do is search by posted date, but for now, like you probably wanna do it within 14 days, but for now, let's just look at this one as an example for, to get this, due a job.

So I, what I would do is I would go to indy.com, which was one of the top search engines in, this country. And we found one here is technical project support manager, and luckily project support PMP. Lends itself to remote positions. So that's why I say yes, you can find a job here. This is, this one has a salary of a hundred thousand a year.

That's pretty good. It's a full-time position. They require a bachelor's degree. In addition to your PMP, preferred bachelor's preferred. So you don't have to have one five years preferred. This is really good. If you happen, have a P and P you might wanna check this one out. If you don't make a hundred thousand, but I think this one might be gone because it's over 30 days already.

So let me actually, lemme switch the screen. So people on YouTube can see. All right. So what I'm reading, I'll read this. If you happen to be listening to me. So we already said that this stuff was preferred. Now let's get into the, if there's any caveats, meaning can you do this from another country?

So one of the questions I would ask if I was living in another country or abroad or something like that, or if I wanted to work remotely from a country like Bali not country in Indonesia in Bali. So I would wanna know do do they have restrictions on where I can work from that would be the next question.

So the answer is yes, you could find a job in the us is hot market. A lot of people say, oh, I can't find a job, man. It is booming, man. There's no problem in it. Finding jobs. Here's one right here. As a matter of fact, yeah, they got health plan. They probably have requirements cuz this is a government.

So government positions, just so you know, usually they'll say remote, but you have to be in the United States. And then another thing to look out for, if you happen to be not, if you're not a us citizen, another thing you probably wanna look out for is whether or not you have to be eligible for, a certain clearance security clearance, because eligibility means that you are a us citizen.

Or a naturalized citizen or something like that. So the answer is yes, you can get a PMP in the United States. You just have to look at the requirements of it and and, check out the site for that. And then the, other thing I didn't do on here is look at you. One of the things you have to do is look at jobs, posted and look at it from the last 14 days, rather than last 30 days.

Cuz it's gonna be a little bit different and look this one right, away. It says you have to be a us citizen or a car green card. This is exactly what I was talking about. This one's specifically saying you should have to be a green card holder or a green card holder. Let me show you here.

This is exactly what I was talking about. So yes, you can do it, but look, it is remote by the way, but they want you to have a PMP certification, but you have to be either a us citizen or a green car holder and they tell you right away. That's what you wanna look for. And then if they don't tell you on the job description, you have to do you, have to call 'em like call 'em and figure that out.

Hey, I want to know, can I work there? I'm living in another state. I'm living in another country. Is that a problem? Is there any travel whatsoever? Is it a problem that I'm not a green car holder? You got to ask 'em all these kinds of questions. PMP is an incredible certification by the way.

Really, good certification. A lot of technical guys, I know got one because it's it, pays like PMP actually pays, good money. Let me see it got some other questions here. I'll stick with Italy and Japan. okay. Let me see here. I have some other YouTube questions. I'm gonna answer real quick.

If I can, did it just log me out. Oh man. Come on drew. Come on, dude. It just logged me out. Wow. I don't know why I did that. I can see myself live. Oh, wow. Okay. I don't know what's going on. I don't know why it logged me out, but I'm about at an hour. So I'm gonna cut this short here real quick.

Thank you guys so much for watching me. I really appreciate everybody who's watching. I re really appreciate my community. If you guys are interested in getting more, the show doesn't stop. You can always catch me on. You can email me. You can catch me on discord. You can catch me on TikTok. I'm always posting a new content, any kind of questions that you have, feel free to a ask me.

Most of my content comes from people asking questions. So I'll actually make a video about it. And if it's a really, good question that I'll be asked over and over again, I'll make an entire course out of it and spend weeks and months doing that. That's it for this one, guys. Thank you so much for watching.

Thank you for listening to me on podcast. If you guys didn't know, I have a podcast that I do regularly. That's another place you can catch this stream. It's on pod bean.com. Check that out or in Lincoln description below.

View Details

Get links here:

https://securitycompliance.thinkific.com/courses/cybersecurity

https://www.whitehouse.gov/briefing-room/statements-releases/2022/07/21/fact-sheet-national-cyber-workforce-and-education-summit/

Two one and we are live. Okay. I've got some urgent stuff to let you guys know about. That's why I decided to just go ahead, go live. So I'm on live. This is a podcast combo course podcast. First of all, my name is Bruce and I do this once a week. At least lately. I've been doing these a little bit more and I wanted to tell you guys about this national cyber workforce and education summit that happened on July last month.

And it's a bunch of free training for entry level cyber security people. And I thought that this was important enough that I should let you guys know what's going on. So if you guys did know my name is Bruce, what I do is cyber security training and also help people to get into this career. If you're interested in this, follow me on YouTube, tons of free information, tons of free stuff out there.

All of this is not paid. I'm just trying to help people out. That's the name of the game for me? I'm good. My life is good. I'm just trying to help y'all other people out. And that's what this is all about. So what this is gonna be is a breakdown of some of the free training that's out there.

Right now. For you guys the, a couple of these things are really exciting. A couple of 'em are really amazing and let's just get right into this. All right. So this is all coming from a summit that happened. so let me back up a little bit. So the white house is pushing some sort of initiative to fill a bunch of slots.

There's a huge shortage of cyber security people. There's something like seven over 700,000 cyber security positions that are open. And it's due to a lot of things it's due to people retiring it's due to people getting out of this career path. And they just can't retain people and there's a huge need for cyber security.

So they put together this initiative to pull more people in teach people and they pulled in all these other organizations to do that. So you've got everything from the private sector to different departments within the department of defense that are promoting this. and all of the stuff I'm about to tell you is coming directly from the white house dot coms white house, white house.gov.

I'm sorry, not white.com white house dot govs briefing that they did in July. So this is a bunch of free training, a bunch of job jobs and all kinds of opportunities. If you're interested. like I said, a lot of this is free. Let's start off with department of labor and commerce. So department of labor and commerce is doing 120 day cyber security apprenticeship.

And this is already started. So if you are interested in this, you gotta go to this. now you can either Google this right now, or you can go to combo courses.com where I have put all this slide deck with all of these links that I'm about to show you are on my site. So if you're interested in that, just go to combo courses, or you can just go to Google and type, and then Google what I'm saying, but if you're interested, you just go to convo courses.com and this is free to sign up and then you'll just download.

You'll download the slide deck from here, and then it'll have all of the, all the stuff that I put together on this thing. And alternatively, you can just type in national cyber workforce education summit, and then all the actual stuff is there minus the links, because I did extra research to get these.

All right. Let's start off with us department of labor and commerce. They have 120 day apprenticeship. So if you're trying to get your foot in the door with cyber security, this is one of the ways that you can do it. This is a golden opportunity. If you're actually an it person, you, or actually you might even be able to switch from another occupation to get into cyber security with an apprenticeship.

Yeah. So this is getting you actual experience. Now you've gotta go to the site and register. They've so far have 714 registered apprenticeship programs and they're accepting people and for a little bit, so go ahead and sign up for that. This is a part of a huge initiative from the us government to actually get more people trained up and get people in these positions that they really need.

So that's, what's happening right now with this So that's the us department of commerce. And like I said, if you want this slide deck that I have, if you wanna see all this stuff, you can download this on combo courses.com. Actually, if you are watching me on YouTube, it's in the link in the description below.

If you are watching if you're listening to this on podcasts, go to combo courses.com. Look for Look for convo courses online. It's a bunch of free stuff that I post out there. Downloadables all my slides are there. Look for that slide deck. This slide deck that I'm showing right now, but let me, let's go to the next one other opportunities out there.

This is the apprenticeship apprenticeship.gov. If you happen to be following along type in apprent. Apprentice ship.gov. And that'll show you the countdown of days. They're saying there's 77 days as of this recording and 14 hours left for people to sign up for this apprenticeship. If you're interested in getting into cyber security and being trained in the next 120 days with the department of labor and the department of commerce, that's where this is coming from.

All right. So let's keep going to the next. Next one. Okay. Now this one right here is incredible. If you happen to be watching, listening to me right now this is not gonna last. This is not gonna last. So ISC squared. Okay. Let me explain. This is really important. ISC squared are the guys who do one of the top.

They do the top cyber security certification known as CI S S P. So these are the CI S P. So they just recently released a new certification, an entry level cyber security certification called certified in cyber. This is unprecedented because these are the top guys in the field. They're competing directly with security.

Plus with this one, what they're doing right now is they're giving this away for, they are given free training. This is a $200 training. This will not be free for long. This is a $200 training that you can take. I believe after you take the training, you can go ahead and take their test, here is the site right here. It's on ISE, two.org/certifications/cc. Or you can go to Google and type in certified in cyber security, ISC two, and then you'll find their certification this right here. Let me see if I got another slide on that. Yeah. They're saying. Okay. So first of all, this is the world's largest nonprofit association of certified cybersecurity professionals.

That's a fact. So they have the leading certification. In the world, which is the CI S P and they also have the the cap and several other large certifications, but those are probably the two top ones. This is huge. They are giving free training for this. And then you can go ahead and take this certification.

It's an entry level certification is brand new. Marketability. I'm not sure how marketable it is since it's totally new and people don't know what it is, but people will know what it is because ISC two is the biggest cyber security certification. The most world renowned cyber cert security certification organization in the world.

So if you get their certifications they have, they are just everybody respects 'em because they don't do shady stuff. Like some other organizations that I won't name. Okay. And I have certifications from them. Cert, I've got multiple certifications from them and I've been I get jobs very easily because of that.

Alright, so let's see. Let's keep going here. Okay, Accenture I don't know if I'm pronouncing this right, but they have a bunch of entry level professional certifications. If you are interested in that They here's the site right here. Here's what it looks like. But if you go to Accenture I believe it's accenture.com.

That's a C E N T U R E. For those who are listening on the podcast you'll see their entry level professional certifications. And they've because of this initiative, this push forward to actually advertise. Getting more people into cyber security. They said that they're committed to creating access to new roles in cyber security cloud and technical areas through apprenticeship and upscale programs.

So if you're interested in that, go ahead and check it out. Let's keep going here. We've got a ton of other ones. We've got an Institute for cyber security studies. These guys are offering. A bunch of training for executive education programs. If you're interested in that, I'll keep going. If you're interested in getting the links, I've got links to each one of these training courses.

So this is not necessarily entry level, this one's for executives and board of directors and stuff. So that doesn't really apply to the people I'm talking to. So let's keep going with this. Okay. So Auburn universities. They have a program as well. That's has an in they're helping with this initiative to get more people into cyber security.

So you can check that one out. There's the link right there. If you're interested in that, go to combo courses.com and you can find that in in this slide deck that I'm showing right here, all of the links are there. There's lots and lots of details there. That's why I'm just gonna go ahead and give you the links and.

And find all this information that I'm showing you here, but this is where the link is at. You go to convo courses.com four slash courses, four slash cybersecurity, and you'll find it here. Alternatively, you can go to the actual site where all this stuff is at it, it won't have all my research.

I did extra research to show you like where all the news feeds are, where the actual sites are where where you can sign up for this stuff. You won't have that you'll have to do your own research, but if you go to if you go type, go to Google and type in national cyber workforce and education summit, you'll find everything that I'm talking about here.

That's where I got all this information from. Okay. Let's keep. We talked about ISE squared. We talked about Centura. We talked about a couple of universities. Let's keep going. Let's go to Cisco. So Cisco is also ha also has this initiative where they're pushing they're given a bunch of training to college and co colleges, including 107 historically black colleges and universities, the H HBCUs.

They're doing a huge push. Here's a, an image of their site. Trying to get more people into cyber security workforce, cuz as there's 700,000 vacancies in cyber and I can vouch for this I'm in this field and I'm telling you, they try to put four and five hats on us and we're having to do all this extra work cuz there's not enough people to do this work.

It's really a huge problem. And so there, I'm glad that. That they're actually trying to pull more people in, but now Ciscos in on it, they're trying to pull more people in. They're trying to get more education out there and get more people in the workforce. So let's keep going here. Comp Tia. So comp Tia has a partnership with connect wise.

And if you go to their site right now, if you go to their news feed, you'll see this right up top, where they're trying to get more people into this field by merging with ConnectWise and getting an it apprenticeship out there. Some of these things that I'm gonna show you by the way are in the works, they haven't actually started yet, but some of 'em are like already ongoing.

You can literally sign up right. And and apply for these and get into the apprenticeships. If this is, if I were you like, if the position that I'm seeing. Is, if you happen to be a help desk person, if you happen to be in a field where you do a little bit of tech, but you're trying to level up, this is actually perfect for you.

This is absolutely perfect for you. Now, if you happen to be in a completely other field, some of this may help you out the ISC two squared, I think is a huge one to, to try to do in these are entry level cyber securities thing. This is unprecedented. This is amazing. I'm glad that there.

This push for this field because it really needs it. But if you are brand new to cybersecurity, if you trying to get into this field, like people keep asking me over and over again on TikTok, on YouTube, on Instagram, everybody all over the place, trying to get from where they're at to cyber security. This right here, this certification, this ISE two squared certified in cybersecurity.

If you go to IC two square.org I actually it's is. two.org. You go there. You will see this assert a new certification called CC. And this is for entry level cyber security people. Let's keep going. Where were we let's see scrolling down, going to CompTIA. Okay. We just talked about CompTIA Lincoln description below.

If you happen to be watching me on YouTube, if you happen to be watching, listening to this on podcast a little bit later or live, then you can actually download all this stuff I'm talking about on my site com convo courses.com go to that site, and you will see that in in. What is it? Combo courses.com/courses/cybersecurity.

And then there's a downloadable that has all the links that I'm showing you here. It's called national cyber workforce and education summit. This is from all from a summit that happened on the, on July in July, just last month. All right, let's keep going. We already talked about compt. Image of the comp Tia newsroom.

If you go to comp tia.org and check out their press release, you will see exactly what I'm talking about here. So I just gave you several links that you can either go to Google and type it. You can go directly to the site such as comp tia.org, and look at the news feed and then find this find this right here.

This initiative, there's a push towards getting people apprenticeships with ConnectWise. Okay, let's keep going here. There's a couple other good ones here. I'm gonna just go straight to the good ones. You've got several organizations that are pushing towards this several universities as well, that are pumping lots of money and initiatives into getting more and more people into cyber security, such as Dakota state university they're highlighted.

90 million investment for cyber research and initiatives to support multi-party public private partnerships funding to get more people into cyber security and their goal is to get more people in cyber sciences over the next five years. Okay. So there's that initiative? IBM has a push towards getting is announcing that the education initiative.

That's gonna help the vet department of building and affairs. Couple of other organization and HB cus to provide no cost, zero cost stem training. For us military veterans, newer divergent learn learners and university students from underrepresented communities. So this is really impressive that they're actually reaching out and trying to pull more people in from all over the whole spectrum of the United States.

That's really cool. Okay. So Linox foundation had a good one as well. Now you gotta check this one out. This is one of the better ones. I don't know that I have many left that are as good as this one, but check this out. So Lennox foundation, they actually. And I think this is for a limited time only they have 15 hours of free software, secure software training programs.

Here is the link right here. If you wanna get that link, I already told you where the link is. If you happen to be watching me on YouTube, you can actually click the link. It'll take you directly to where you can download this slide, presentation that you're looking at right now that I'm describing on this podcast.

And you can download or get this, download this, and then click this link and it'll take you to this free. Developing secure software or alternatively go to Google. If you're lazy, go to Google type in Lenox foundations space, free secure software training, and I'm sure it'll lead you there, cuz this is active right now.

Look at this. This says enroll today. Cost zero. All of these are not gonna be zero for long, right? That's why I decided to do this live because. This stuff is limited. Like CC. ISC two is limited. I don't think that course is gonna be free forever. And then this one develops secure software is not gonna be free forever.

It's gonna go up to 200 or 100. Whatever the price is gonna be on this thing. Okay. So let's see night dragon is also doing some initiative. I already checked on this one. This one's not out yet. I don't think they have announcements and stuff, but I didn't see, I seen where you can sign up for it.

I didn't see a place where it's actually active yet, but I could be wrong. So go ahead and check that one out. This one's active in power will offer skill development courses and free it training and credentials to military connected individuals, as well as young adults from underserved and underrepresented communities.

That means if you are from a socioeconomic poor place. Like myself, this is gonna help you out. So you can literally apply here. Here's a little bit more news here for it. If you are happen to be listening to me, just go to Google type in power.org. And you'll find it. You'll find that site.

And I think that's it. The last thing I wanted to talk to you guys about is Booz Allen Hamilton. Now, I don't know if this is in direct relation to the, this push to get more cyber security people in this, but. It's matching what we're talking about. And right here, it's just saying that Booz Allen Hamilton starts entry level cyber security staffers at $150,000.

This is entry entry level, cyber security staffers, up to $150,000. Now, if you happen to be in it right now, if you happen to have a security. Hell. If you don't have any certifications and you happen to be an it person, this is something I would definitely look into. Now. I gave you some links here, or if you happen to be listened to me, go to Booz Allen Hamilton, just type in Google, go to Booz Allen Hamilton, go to their career section and put your resume right in their.

and then look for these cyber security jobs. I would just put your resume right in their site, because sometimes they'll reach out to you. If you do that. If, and if you happen to be watching this on YouTube, you can actually look in the link description below, sign up for free, and then go to Booz Allen Hamilton careers.

And the link is here. And then go ahead and sign up for this. That's all I wanted to say guys. That's it for this. I just wanted to, this was urgent because some of these things are gonna expire soon. Like some of these free items are gonna actually expire soon. Like this Lennox foundations, this one's really, this is a good one.

If you happen to be into doing development of code and you want to jump into this this is absolutely free. And then the other one that I'm the most exciting one to me, cuz I know this is this. This could possibly compete directly with security plus, I don't know. It depends on they market it and stuff, but this certified and cyber security entry level secur cyber security certification.

This is, this has a potential to be really good to where they'll add it to things like the DODs 81 40. They could probably add it there and compete directly with the security plus, we'll see how this goes, but I would, if it's free it's right now, it's free. Go to ISC two.org and look for this certification.

It's called a CC certification. I would go ahead and try it. If you're entry level. All right, I'm gonna take a few questions and then I'm gonna end this thing. I just wanted to, that was the main thing I wanted to talk about. So if you have any questions on I've got some, I might have some questions on TikTok or have some questions on YouTube.

Let me see. I've got one question here. Let me see. Moncho says we will need to know basic it will we need to know basic it. Cover a plus or can anyone just go in it and get training and learn? This is actually a really good question. So it depends on the thing that I have, all this lists I'm seeing here, there's a couple that are completely like, you can come in cold.

Yeah. This one right here. So this one right here is fast pace free. This one's designed specifically for people who are just, who are absolutely brand new. Let's check it out. Let's check it out. I don't wanna lie to you. So I'm gonna go to ISD two square live, and we're gonna, we're gonna go through this one together.

And for those who are just listening, I'll explain what we're looking at. So mantra asked me if this ISE two square. CC certification is for anyone like, can somebody who's coming in from nursing. Could they actually jump into this one and just start, let's see, they said it's entry level.

So that's what they're, it's not only entry level, but it's tailored towards people who are brand new in this thing. So let me see. So right now I'm on the SC ISC two.org certification CC site. So that's what we're looking at. And we're looking through it. Let's see introduc introducing the ultimate starting point for an, let me see for an exciting career certified in cyber security.

So they're doing their little. Spiel here to get us to get in here, take the first step in reward in a rewarding career to get your, and get your certified cyber security for ISC two square. The world's leading cyber security. Okay. They're promoting themselves. Let's get to the meat of this. Like what does the candidate need becoming an ISC two candidate.

Did you know that you can now join ISC two squared and become fully certified? Okay. Now we know we. We have recently launched a candidate. Okay. Which allows anyone studying for a certification or interested in a career in cyber security to join association. So this doesn't have any prerequisites. It looks like to me, that's what it looks like to me.

So qualifi, a qualifications, Pathfinder. Okay. Here it is right here. Unsure. If CC is right for you. Let's. let's see, we're gonna look at their Pathfinder that basically breaks down the path that they expect you to have to get this to get this. Let's see what is the best cyber security qualifications for you?

Anyone cyber security journey or career journey is everyone's cyber ski. If I could read is. And it could, it can be difficult to navigate through all the certifications opportunities which, okay. So you're still not telling me they want us to sign up. I bet. Okay. Pathfinder, we make it easy to discover.

You should go to the site yourself. If you're interested in this, you should go to as follow along with me, ISC two.org/certifications slash. Qualification Pathfinder right now they say, start your journey. And I believe they're gonna take me to a form. Okay. Nope. All right. Let's see. Are you interested in pursuing a cyber security certification for your team?

It's asking me some interactive questions to see, to determine if this is for me, I'm interested in pursuing a certification myself. So what I'm gonna do is I'm gonna answer this, like I'm brand new, like I'm coming out of a whole nother career. Which of the following best describes your current cyber security goals?

Okay. I would like to start in cyber security career, but unsure where to start. I'm currently working in it with security responsibilities. Okay. Nope. That's not us. I currently work in cyber security. Nope. I'm interested in specializing. Nope. I work in a note that's security role or a, it. I would like to demonstrate my knowledge of various risk frameworks, not what the hell I would I work for and pursuing cyber security job in the government, which or with contractor requirements, specific specifications, I work with healthcare industry in which to pursue cybersecurity.

Okay. This might be it right here. This might be it right. Let me see. I currently work in cybersecurity. Okay. This one, right? This one is for somebody going from healthcare industry. And this one is I would like to start cybersecurity career, but I'm sure where to start. Let's just get this one that's general enough.

Okay. Next one is saying, looking to start cyber security career, but unsure where to. , you're not alone. Many people are interested in cyber security, but they are unsure where to begin their journey. Okay. Select the option that describes you. I have worked in it. No, that's not me. I am a student studying computer science.

Nope. I would like to start cyber cybersecurity career, but have no or very little security or it experience. This is us. Okay. Now let's see if it says, get the hell outta here. This is not for you. Let's. Get certified in it. Okay. Lacking work experience is not a problem. Look at this. See, moncho this answers your question.

Lacking it. Lacking work experience is not a problem. The new certified and cybersecurity entry level certification is perfect for you. The certification is a pilot is a pilot form at this time, and it is an ideal next. For those interested in this field, like you learn more now this, I think this is where it's gonna ask me my name and social security number and firstborn child and all that kind of stuff.

Nope, it didn't okay. If I want more information, I'm gonna have to look at this free train. Look at this is what I'm talking about. Free training right here. Get free training for a limited time. Since this is new, they're trying to promote it by giving it to letting people use it for free. But it's, they're saying it's a $200 value.

That means it's probably gonna go up to $200 once day. And these courses are not cheap. All right. So if I want to download a breakdown of what's on the test and everything and how to train for it and everything you, I think this is where I would have to give them my email address and they put you on like a mailing list and stuff like this.

It's pretty in unintrusive. You know how some of these mailing lists are very like aggressive. I see two squares, not like that. But anyway, you would sign this stuff and then it would give you a breakdown of what domains are on the test and. More details about the actual test itself. This is a really good, I'm really glad that they did this.

This is a really smart move. I really hope the certification does well. It really depends on how much traction it gets. And so that's why I think they're giving the training away for free. So moncho, I hope that answers your question about this one. It looks like if you have no experience at.

They're doing an entry level certification. They're trying to compete with comp Tia, cuz comp Tia is right now, the premier it entry level certifications that you, that people are using. And it's the, if you get a help desk job, a lot of times they'll ask you, Hey, do you have a plus certification?

If you have no degree or whatever, or sometimes when you have a degree, it doesn't matter. They were like, Hey, do you have an a plus certificate? Cuz it's just that marketable. But now they're trying to compete with that. and then they're trying to get in that space where Google support it. Certifications are starting to become real popular as well.

So now ISE two, that's a really smart move, I think. All right guys, that's it for me. Thank you for listening. Thank you for watching. I really appreciate it. I'm gonna be restream this stuff on my podcast is on it's on pod beam dot convo courses. Now convo courses dot pod beam.com. If you happen to be li watching me on YouTube it's there I'm live streaming it right now, but I'm gonna re-release it for those who might have missed this one.

And that's it. Thank you so much for listening. Thanks for your questions. Thanks for watching. I will talk to you guys later. Pace.

View Details

Get links here:

https://securitycompliance.thinkific.com/courses/cybersecurity

https://www.whitehouse.gov/briefing-room/statements-releases/2022/07/21/fact-sheet-national-cyber-workforce-and-education-summit/

Two one and we are live. Okay. I've got some urgent stuff to let you guys know about. That's why I decided to just go ahead, go live. So I'm on live. This is a podcast combo course podcast. First of all, my name is Bruce and I do this once a week. At least lately. I've been doing these a little bit more and I wanted to tell you guys about this national cyber workforce and education summit that happened on July last month.

And it's a bunch of free training for entry level cyber security people. And I thought that this was important enough that I should let you guys know what's going on. So if you guys did know my name is Bruce, what I do is cyber security training and also help people to get into this career. If you're interested in this, follow me on YouTube, tons of free information, tons of free stuff out there.

All of this is not paid. I'm just trying to help people out. That's the name of the game for me? I'm good. My life is good. I'm just trying to help y'all other people out. And that's what this is all about. So what this is gonna be is a breakdown of some of the free training that's out there.

Right now. For you guys the, a couple of these things are really exciting. A couple of 'em are really amazing and let's just get right into this. All right. So this is all coming from a summit that happened. so let me back up a little bit. So the white house is pushing some sort of initiative to fill a bunch of slots.

There's a huge shortage of cyber security people. There's something like seven over 700,000 cyber security positions that are open. And it's due to a lot of things it's due to people retiring it's due to people getting out of this career path. And they just can't retain people and there's a huge need for cyber security.

So they put together this initiative to pull more people in teach people and they pulled in all these other organizations to do that. So you've got everything from the private sector to different departments within the department of defense that are promoting this. and all of the stuff I'm about to tell you is coming directly from the white house dot coms white house, white house.gov.

I'm sorry, not white.com white house dot govs briefing that they did in July. So this is a bunch of free training, a bunch of job jobs and all kinds of opportunities. If you're interested. like I said, a lot of this is free. Let's start off with department of labor and commerce. So department of labor and commerce is doing 120 day cyber security apprenticeship.

And this is already started. So if you are interested in this, you gotta go to this. now you can either Google this right now, or you can go to combo courses.com where I have put all this slide deck with all of these links that I'm about to show you are on my site. So if you're interested in that, just go to combo courses, or you can just go to Google and type, and then Google what I'm saying, but if you're interested, you just go to convo courses.com and this is free to sign up and then you'll just download.

You'll download the slide deck from here, and then it'll have all of the, all the stuff that I put together on this thing. And alternatively, you can just type in national cyber workforce education summit, and then all the actual stuff is there minus the links, because I did extra research to get these.

All right. Let's start off with us department of labor and commerce. They have 120 day apprenticeship. So if you're trying to get your foot in the door with cyber security, this is one of the ways that you can do it. This is a golden opportunity. If you're actually an it person, you, or actually you might even be able to switch from another occupation to get into cyber security with an apprenticeship.

Yeah. So this is getting you actual experience. Now you've gotta go to the site and register. They've so far have 714 registered apprenticeship programs and they're accepting people and for a little bit, so go ahead and sign up for that. This is a part of a huge initiative from the us government to actually get more people trained up and get people in these positions that they really need.

So that's, what's happening right now with this So that's the us department of commerce. And like I said, if you want this slide deck that I have, if you wanna see all this stuff, you can download this on combo courses.com. Actually, if you are watching me on YouTube, it's in the link in the description below.

If you are watching if you're listening to this on podcasts, go to combo courses.com. Look for Look for convo courses online. It's a bunch of free stuff that I post out there. Downloadables all my slides are there. Look for that slide deck. This slide deck that I'm showing right now, but let me, let's go to the next one other opportunities out there.

This is the apprenticeship apprenticeship.gov. If you happen to be following along type in apprent. Apprentice ship.gov. And that'll show you the countdown of days. They're saying there's 77 days as of this recording and 14 hours left for people to sign up for this apprenticeship. If you're interested in getting into cyber security and being trained in the next 120 days with the department of labor and the department of commerce, that's where this is coming from.

All right. So let's keep going to the next. Next one. Okay. Now this one right here is incredible. If you happen to be watching, listening to me right now this is not gonna last. This is not gonna last. So ISC squared. Okay. Let me explain. This is really important. ISC squared are the guys who do one of the top.

They do the top cyber security certification known as CI S S P. So these are the CI S P. So they just recently released a new certification, an entry level cyber security certification called certified in cyber. This is unprecedented because these are the top guys in the field. They're competing directly with security.

Plus with this one, what they're doing right now is they're giving this away for, they are given free training. This is a $200 training. This will not be free for long. This is a $200 training that you can take. I believe after you take the training, you can go ahead and take their test, here is the site right here. It's on ISE, two.org/certifications/cc. Or you can go to Google and type in certified in cyber security, ISC two, and then you'll find their certification this right here. Let me see if I got another slide on that. Yeah. They're saying. Okay. So first of all, this is the world's largest nonprofit association of certified cybersecurity professionals.

That's a fact. So they have the leading certification. In the world, which is the CI S P and they also have the the cap and several other large certifications, but those are probably the two top ones. This is huge. They are giving free training for this. And then you can go ahead and take this certification.

It's an entry level certification is brand new. Marketability. I'm not sure how marketable it is since it's totally new and people don't know what it is, but people will know what it is because ISC two is the biggest cyber security certification. The most world renowned cyber cert security certification organization in the world.

So if you get their certifications they have, they are just everybody respects 'em because they don't do shady stuff. Like some other organizations that I won't name. Okay. And I have certifications from them. Cert, I've got multiple certifications from them and I've been I get jobs very easily because of that.

Alright, so let's see. Let's keep going here. Okay, Accenture I don't know if I'm pronouncing this right, but they have a bunch of entry level professional certifications. If you are interested in that They here's the site right here. Here's what it looks like. But if you go to Accenture I believe it's accenture.com.

That's a C E N T U R E. For those who are listening on the podcast you'll see their entry level professional certifications. And they've because of this initiative, this push forward to actually advertise. Getting more people into cyber security. They said that they're committed to creating access to new roles in cyber security cloud and technical areas through apprenticeship and upscale programs.

So if you're interested in that, go ahead and check it out. Let's keep going here. We've got a ton of other ones. We've got an Institute for cyber security studies. These guys are offering. A bunch of training for executive education programs. If you're interested in that, I'll keep going. If you're interested in getting the links, I've got links to each one of these training courses.

So this is not necessarily entry level, this one's for executives and board of directors and stuff. So that doesn't really apply to the people I'm talking to. So let's keep going with this. Okay. So Auburn universities. They have a program as well. That's has an in they're helping with this initiative to get more people into cyber security.

So you can check that one out. There's the link right there. If you're interested in that, go to combo courses.com and you can find that in in this slide deck that I'm showing right here, all of the links are there. There's lots and lots of details there. That's why I'm just gonna go ahead and give you the links and.

And find all this information that I'm showing you here, but this is where the link is at. You go to convo courses.com four slash courses, four slash cybersecurity, and you'll find it here. Alternatively, you can go to the actual site where all this stuff is at it, it won't have all my research.

I did extra research to show you like where all the news feeds are, where the actual sites are where where you can sign up for this stuff. You won't have that you'll have to do your own research, but if you go to if you go type, go to Google and type in national cyber workforce and education summit, you'll find everything that I'm talking about here.

That's where I got all this information from. Okay. Let's keep. We talked about ISE squared. We talked about Centura. We talked about a couple of universities. Let's keep going. Let's go to Cisco. So Cisco is also ha also has this initiative where they're pushing they're given a bunch of training to college and co colleges, including 107 historically black colleges and universities, the H HBCUs.

They're doing a huge push. Here's a, an image of their site. Trying to get more people into cyber security workforce, cuz as there's 700,000 vacancies in cyber and I can vouch for this I'm in this field and I'm telling you, they try to put four and five hats on us and we're having to do all this extra work cuz there's not enough people to do this work.

It's really a huge problem. And so there, I'm glad that. That they're actually trying to pull more people in, but now Ciscos in on it, they're trying to pull more people in. They're trying to get more education out there and get more people in the workforce. So let's keep going here. Comp Tia. So comp Tia has a partnership with connect wise.

And if you go to their site right now, if you go to their news feed, you'll see this right up top, where they're trying to get more people into this field by merging with ConnectWise and getting an it apprenticeship out there. Some of these things that I'm gonna show you by the way are in the works, they haven't actually started yet, but some of 'em are like already ongoing.

You can literally sign up right. And and apply for these and get into the apprenticeships. If this is, if I were you like, if the position that I'm seeing. Is, if you happen to be a help desk person, if you happen to be in a field where you do a little bit of tech, but you're trying to level up, this is actually perfect for you.

This is absolutely perfect for you. Now, if you happen to be in a completely other field, some of this may help you out the ISC two squared, I think is a huge one to, to try to do in these are entry level cyber securities thing. This is unprecedented. This is amazing. I'm glad that there.

This push for this field because it really needs it. But if you are brand new to cybersecurity, if you trying to get into this field, like people keep asking me over and over again on TikTok, on YouTube, on Instagram, everybody all over the place, trying to get from where they're at to cyber security. This right here, this certification, this ISE two squared certified in cybersecurity.

If you go to IC two square.org I actually it's is. two.org. You go there. You will see this assert a new certification called CC. And this is for entry level cyber security people. Let's keep going. Where were we let's see scrolling down, going to CompTIA. Okay. We just talked about CompTIA Lincoln description below.

If you happen to be watching me on YouTube, if you happen to be watching, listening to this on podcast a little bit later or live, then you can actually download all this stuff I'm talking about on my site com convo courses.com go to that site, and you will see that in in. What is it? Combo courses.com/courses/cybersecurity.

And then there's a downloadable that has all the links that I'm showing you here. It's called national cyber workforce and education summit. This is from all from a summit that happened on the, on July in July, just last month. All right, let's keep going. We already talked about compt. Image of the comp Tia newsroom.

If you go to comp tia.org and check out their press release, you will see exactly what I'm talking about here. So I just gave you several links that you can either go to Google and type it. You can go directly to the site such as comp tia.org, and look at the news feed and then find this find this right here.

This initiative, there's a push towards getting people apprenticeships with ConnectWise. Okay, let's keep going here. There's a couple other good ones here. I'm gonna just go straight to the good ones. You've got several organizations that are pushing towards this several universities as well, that are pumping lots of money and initiatives into getting more and more people into cyber security, such as Dakota state university they're highlighted.

90 million investment for cyber research and initiatives to support multi-party public private partnerships funding to get more people into cyber security and their goal is to get more people in cyber sciences over the next five years. Okay. So there's that initiative? IBM has a push towards getting is announcing that the education initiative.

That's gonna help the vet department of building and affairs. Couple of other organization and HB cus to provide no cost, zero cost stem training. For us military veterans, newer divergent learn learners and university students from underrepresented communities. So this is really impressive that they're actually reaching out and trying to pull more people in from all over the whole spectrum of the United States.

That's really cool. Okay. So Linox foundation had a good one as well. Now you gotta check this one out. This is one of the better ones. I don't know that I have many left that are as good as this one, but check this out. So Lennox foundation, they actually. And I think this is for a limited time only they have 15 hours of free software, secure software training programs.

Here is the link right here. If you wanna get that link, I already told you where the link is. If you happen to be watching me on YouTube, you can actually click the link. It'll take you directly to where you can download this slide, presentation that you're looking at right now that I'm describing on this podcast.

And you can download or get this, download this, and then click this link and it'll take you to this free. Developing secure software or alternatively go to Google. If you're lazy, go to Google type in Lenox foundations space, free secure software training, and I'm sure it'll lead you there, cuz this is active right now.

Look at this. This says enroll today. Cost zero. All of these are not gonna be zero for long, right? That's why I decided to do this live because. This stuff is limited. Like CC. ISC two is limited. I don't think that course is gonna be free forever. And then this one develops secure software is not gonna be free forever.

It's gonna go up to 200 or 100. Whatever the price is gonna be on this thing. Okay. So let's see night dragon is also doing some initiative. I already checked on this one. This one's not out yet. I don't think they have announcements and stuff, but I didn't see, I seen where you can sign up for it.

I didn't see a place where it's actually active yet, but I could be wrong. So go ahead and check that one out. This one's active in power will offer skill development courses and free it training and credentials to military connected individuals, as well as young adults from underserved and underrepresented communities.

That means if you are from a socioeconomic poor place. Like myself, this is gonna help you out. So you can literally apply here. Here's a little bit more news here for it. If you are happen to be listening to me, just go to Google type in power.org. And you'll find it. You'll find that site.

And I think that's it. The last thing I wanted to talk to you guys about is Booz Allen Hamilton. Now, I don't know if this is in direct relation to the, this push to get more cyber security people in this, but. It's matching what we're talking about. And right here, it's just saying that Booz Allen Hamilton starts entry level cyber security staffers at $150,000.

This is entry entry level, cyber security staffers, up to $150,000. Now, if you happen to be in it right now, if you happen to have a security. Hell. If you don't have any certifications and you happen to be an it person, this is something I would definitely look into. Now. I gave you some links here, or if you happen to be listened to me, go to Booz Allen Hamilton, just type in Google, go to Booz Allen Hamilton, go to their career section and put your resume right in their.

and then look for these cyber security jobs. I would just put your resume right in their site, because sometimes they'll reach out to you. If you do that. If, and if you happen to be watching this on YouTube, you can actually look in the link description below, sign up for free, and then go to Booz Allen Hamilton careers.

And the link is here. And then go ahead and sign up for this. That's all I wanted to say guys. That's it for this. I just wanted to, this was urgent because some of these things are gonna expire soon. Like some of these free items are gonna actually expire soon. Like this Lennox foundations, this one's really, this is a good one.

If you happen to be into doing development of code and you want to jump into this this is absolutely free. And then the other one that I'm the most exciting one to me, cuz I know this is this. This could possibly compete directly with security plus, I don't know. It depends on they market it and stuff, but this certified and cyber security entry level secur cyber security certification.

This is, this has a potential to be really good to where they'll add it to things like the DODs 81 40. They could probably add it there and compete directly with the security plus, we'll see how this goes, but I would, if it's free it's right now, it's free. Go to ISC two.org and look for this certification.

It's called a CC certification. I would go ahead and try it. If you're entry level. All right, I'm gonna take a few questions and then I'm gonna end this thing. I just wanted to, that was the main thing I wanted to talk about. So if you have any questions on I've got some, I might have some questions on TikTok or have some questions on YouTube.

Let me see. I've got one question here. Let me see. Moncho says we will need to know basic it will we need to know basic it. Cover a plus or can anyone just go in it and get training and learn? This is actually a really good question. So it depends on the thing that I have, all this lists I'm seeing here, there's a couple that are completely like, you can come in cold.

Yeah. This one right here. So this one right here is fast pace free. This one's designed specifically for people who are just, who are absolutely brand new. Let's check it out. Let's check it out. I don't wanna lie to you. So I'm gonna go to ISD two square live, and we're gonna, we're gonna go through this one together.

And for those who are just listening, I'll explain what we're looking at. So mantra asked me if this ISE two square. CC certification is for anyone like, can somebody who's coming in from nursing. Could they actually jump into this one and just start, let's see, they said it's entry level.

So that's what they're, it's not only entry level, but it's tailored towards people who are brand new in this thing. So let me see. So right now I'm on the SC ISC two.org certification CC site. So that's what we're looking at. And we're looking through it. Let's see introduc introducing the ultimate starting point for an, let me see for an exciting career certified in cyber security.

So they're doing their little. Spiel here to get us to get in here, take the first step in reward in a rewarding career to get your, and get your certified cyber security for ISC two square. The world's leading cyber security. Okay. They're promoting themselves. Let's get to the meat of this. Like what does the candidate need becoming an ISC two candidate.

Did you know that you can now join ISC two squared and become fully certified? Okay. Now we know we. We have recently launched a candidate. Okay. Which allows anyone studying for a certification or interested in a career in cyber security to join association. So this doesn't have any prerequisites. It looks like to me, that's what it looks like to me.

So qualifi, a qualifications, Pathfinder. Okay. Here it is right here. Unsure. If CC is right for you. Let's. let's see, we're gonna look at their Pathfinder that basically breaks down the path that they expect you to have to get this to get this. Let's see what is the best cyber security qualifications for you?

Anyone cyber security journey or career journey is everyone's cyber ski. If I could read is. And it could, it can be difficult to navigate through all the certifications opportunities which, okay. So you're still not telling me they want us to sign up. I bet. Okay. Pathfinder, we make it easy to discover.

You should go to the site yourself. If you're interested in this, you should go to as follow along with me, ISC two.org/certifications slash. Qualification Pathfinder right now they say, start your journey. And I believe they're gonna take me to a form. Okay. Nope. All right. Let's see. Are you interested in pursuing a cyber security certification for your team?

It's asking me some interactive questions to see, to determine if this is for me, I'm interested in pursuing a certification myself. So what I'm gonna do is I'm gonna answer this, like I'm brand new, like I'm coming out of a whole nother career. Which of the following best describes your current cyber security goals?

Okay. I would like to start in cyber security career, but unsure where to start. I'm currently working in it with security responsibilities. Okay. Nope. That's not us. I currently work in cyber security. Nope. I'm interested in specializing. Nope. I work in a note that's security role or a, it. I would like to demonstrate my knowledge of various risk frameworks, not what the hell I would I work for and pursuing cyber security job in the government, which or with contractor requirements, specific specifications, I work with healthcare industry in which to pursue cybersecurity.

Okay. This might be it right here. This might be it right. Let me see. I currently work in cybersecurity. Okay. This one, right? This one is for somebody going from healthcare industry. And this one is I would like to start cybersecurity career, but I'm sure where to start. Let's just get this one that's general enough.

Okay. Next one is saying, looking to start cyber security career, but unsure where to. , you're not alone. Many people are interested in cyber security, but they are unsure where to begin their journey. Okay. Select the option that describes you. I have worked in it. No, that's not me. I am a student studying computer science.

Nope. I would like to start cyber cybersecurity career, but have no or very little security or it experience. This is us. Okay. Now let's see if it says, get the hell outta here. This is not for you. Let's. Get certified in it. Okay. Lacking work experience is not a problem. Look at this. See, moncho this answers your question.

Lacking it. Lacking work experience is not a problem. The new certified and cybersecurity entry level certification is perfect for you. The certification is a pilot is a pilot form at this time, and it is an ideal next. For those interested in this field, like you learn more now this, I think this is where it's gonna ask me my name and social security number and firstborn child and all that kind of stuff.

Nope, it didn't okay. If I want more information, I'm gonna have to look at this free train. Look at this is what I'm talking about. Free training right here. Get free training for a limited time. Since this is new, they're trying to promote it by giving it to letting people use it for free. But it's, they're saying it's a $200 value.

That means it's probably gonna go up to $200 once day. And these courses are not cheap. All right. So if I want to download a breakdown of what's on the test and everything and how to train for it and everything you, I think this is where I would have to give them my email address and they put you on like a mailing list and stuff like this.

It's pretty in unintrusive. You know how some of these mailing lists are very like aggressive. I see two squares, not like that. But anyway, you would sign this stuff and then it would give you a breakdown of what domains are on the test and. More details about the actual test itself. This is a really good, I'm really glad that they did this.

This is a really smart move. I really hope the certification does well. It really depends on how much traction it gets. And so that's why I think they're giving the training away for free. So moncho, I hope that answers your question about this one. It looks like if you have no experience at.

They're doing an entry level certification. They're trying to compete with comp Tia, cuz comp Tia is right now, the premier it entry level certifications that you, that people are using. And it's the, if you get a help desk job, a lot of times they'll ask you, Hey, do you have a plus certification?

If you have no degree or whatever, or sometimes when you have a degree, it doesn't matter. They were like, Hey, do you have an a plus certificate? Cuz it's just that marketable. But now they're trying to compete with that. and then they're trying to get in that space where Google support it. Certifications are starting to become real popular as well.

So now ISE two, that's a really smart move, I think. All right guys, that's it for me. Thank you for listening. Thank you for watching. I really appreciate it. I'm gonna be restream this stuff on my podcast is on it's on pod beam dot convo courses. Now convo courses dot pod beam.com. If you happen to be li watching me on YouTube it's there I'm live streaming it right now, but I'm gonna re-release it for those who might have missed this one.

And that's it. Thank you so much for listening. Thanks for your questions. Thanks for watching. I will talk to you guys later. Pace.

View Details

Checkout - http://convocourses.com

See the video of this podcast here: https://www.youtube.com/watch?v=0gA0vnflsUs

Join DiscOrd: https://discord.gg/WE2QFFf7ct

Question: CyberSecurity Jobs in Mexico - Charles

"Hello,

I really enjoy your videos, I wanted to know if there are

any cyber security jobs in Mexico or if you can work

remote jobs while being in Mexico?"

We go through how to find IT jobs in Mexico using job aggregators that are popular there.

View Details

Checkout - http://convocourses.com

See the video of this podcast here: https://www.youtube.com/watch?v=0gA0vnflsUs

Join DiscOrd: https://discord.gg/WE2QFFf7ct

Question: CyberSecurity Jobs in Mexico - Charles

"Hello,

I really enjoy your videos, I wanted to know if there are

any cyber security jobs in Mexico or if you can work

remote jobs while being in Mexico?"

We go through how to find IT jobs in Mexico using job aggregators that are popular there.

View Details

Main topics:

  • Challenge of working remotely in other countries
  • The ATS style resume for IT and cybersecurity

For more check out: www.Convocourses.com

https://www.youtube.com/convocourses

fb: https://www.facebook.com/convocourses

https://www.tiktok.com/@convocourses

Amazon books: https://www.amazon.com/dp/B0B6PWGXJZ?searchxofy=true&binding=kindle_edition&ref_=dbs_s_aps_series_rwt_tkin&qid=1661986519&sr=8-1

Audible:

https://www.amazon.com/gp/product/B0B98WG2HX?notRedirectToSDP=1&ref_=dbs_m_mng_rwt_calw_taud_tkin&storeType=ebooks&qid=1661986519&sr=8-1

Welcome to convo courses. My name is Bruce, and this is gonna be kind of a different format podcast. If you happen to watch my old ones, normally I put 'em on YouTube immediately. Um, right now I'm kind of on the go and I'm in my hotel. But I'm able to knock out these podcasts and there's a couple things we're gonna talk about on this one.

And I'm trying to just help you guys out with everything that I've learned over the years, doing cyber security and doing specifically security compliance, um, and how to get into the cyber security and it space. um, and, and things I've learned along the way I've been doing this for 20 years. Uh, I've been doing this since two, the year 2000.

I actually was in the military for eight years. Um, I, I ended where I was working as a physical security guy. I was a security forces member, protecting resources and assets, and then doing law enforcement, things like that. So I very familiar with security, physical security controls, but then I, I cross train into cyber security.

Well, actually I crossed into it and we call it computer operators, but I did all things, uh, related to it, including cyber security, where, and that's where I got into security compliance. So. What I'm gonna talk about in this one is gonna be, um, something I learned about resumes. I realized why my resume's been doing so well.

And it's because it's ATS or application tracking system compliant. Let explain what that is. And, uh, kind of walk you through how to do it, and I'll try to be as audio as possible, knowing that some people only watch only listen to these, uh, podcasts. Uh, but that being said, if you happen to watch this on YouTube, then I'll have, uh, some examples for you as I'm talking through it.

Another thing I'm gonna talk about since I happened to be remote. Is working remotely and some of the pros and cons and, um, got some notes here, pros and cons of working remotely, some of the benefits of it and some of the countries that, uh, a lot of Americans are going to and why. All right, let's start off with the actual remote work.

I'm gonna take you guys here outside for a second here, outside of my room. It's gonna be a little bit of a change of audio. So just bear with me, but you'll still be able to hear me well, all right, here we go. All right. So I'm not able to do this live. Normally I do these, I do these live and, uh, um, but I, the.

It's not good enough here. And so that's one of the things I talked about in the previous videos and previous, um, podcasts where you, whenever you go to a place it's about noise. Pollution is a factor. Sometimes. Anyway, that being said, let's get into this. I want to show you guys where I'm at. So I'm at a resort here in Manila, Philippines, and I've been here for, I've been in the Philippines for about a month.

Uh, I've been off for about two. At the end of that, and I'm actually looking for a job right now, learn some new things about the job market, which we'll talk about. Okay. So what I'm looking at, if you happen to be watching and listening to this on audio is it's just a group of hotels with a bunch of pools below it's.

It's beautiful. It's kind of a rainy, kind of a rainy day here in Manila. There's a freeway that's not too far from here. That's what you can kind of hear that far away. There's an airport, not too far from here. And then you can hear. Below that are in a pool and stuff. So that's, that's where I'm at. I'm like on a balcony of a hotel resort, pretty nice.

It's called the urban residence, urban residence. Crazy that I've gone to so many hotels. I forgot the name of this place. And even, even those places. Nice. Anyway. Okay. Let's talk about the benefits of remote work. You hear a lot of people talking about remote work and you probably wondering, like, why did everybody talk about this?

Why is this so popular? Why is what's going on with it? Well, there's a few reasons and everybody has their own reasons, but I'm going to name some of the most popular that come to mind. One of the biggest ones is, uh, when you're working remotely, especially in other countries, is that it's cheaper to live in other countries.

A great example is Manila is one of the most popular places that Americans will go and move to and work from because it's just, it's just cheaper to live here. The food is cheaper. Uh, for us, um, the cost of living here for Filipinos is, is not great. There are problems here. I've been here long enough to see some of the, the freight edges of, of a country.

And that's the thing. When you go to a country it's not all sunshine and rainbows, like you, you find there's issues in every country, just like in the us. So don't a lot of people just talk up on a country, but you gotta look at all sides of it whenever you travel. Anyway, one of the biggest benefits that Americans will come here in, in some other C.

That it's cheaper for us cheaper for us cost of living wise with food, much cheaper with your medical is much, much cheaper. It's cheaper to fly here or do medical, uh, and dental than it is to do it in the us. It's ridiculous in the us. It's cheaper for rentals are cheaper. Like these rentals here. Um, this, these are kind of an exception because these are, this is a private residence that are in a, a resort.

So this is gonna be a little bit more pricey. Um, but this, this place I. Which is, which is incredible, which has pools. It has has a clubhouse that right over there that, that dome looking building that donate, donate shaped dome looking building is a, is a clubhouse that has, it has food. It has amenities such as the gym.

It has all kinds of stuff there. And it's three levels, but this place I'm at is $45 a day for this resort. There's, there's like four pools here. There's an Olympic size swimming pool over there. This place is. It's it's, it's absolutely ridiculous. Um, not the best service I've had in the Philippines.

Philippines has some of the best service in the world. This place is kind of, so, so I don't know why it's the, management's not as way here, but this place is incredible. A place like this will run you probably $300 a day in the us. No joke, cuz this is like a five star resort. Um, here it's $45 and I found some of these places that you I'm looking at at hundreds of different.

Across from me and these units, some of 'em are only $27 a day. You could literally live here for $27 a day, $27 a day. It's like a thousand a month in a resort. Think about that. Living in a resort for thousand dollars a month or $30 a day. Yeah. About what, $30 a day. It's for 30 days, $900 a month. So that's still cheaper, like living in a place like this has a kitchen, it has internet, it has, uh, you know, um, Full bathroom.

Like you could, there's a laundry service downstairs. Like you could live here in this resort for $900 a month. There's a, there's a, uh, mall not too far from here. It's walking distance with a grocery store. Uh, everything you need is here and $900 a month, a place like this cost you $900 in the us. So that's one of the main reasons that people will travel and live in another place.

Some places that people consider besides. Would be that are cheap to live for us for American citizens is include Portugal, um, Thailand, Vietnam, Mexico, um, and Columbia. And there's a few other ones that are, that are comfortable for us to live and a Dominican Republic. That's another one comfortable for us to live much cheaper living standard and just your, your life is gonna be completely different there.

You. To really retire in some of these places. And this is 900 a month is, is, is crazy here. That's a crazy price. Um, you can get something that's not as doesn't have as many amenities for about $200 a month, $300 a month. A very, a pretty good place for about $300 a month. So, and then the food is, is cheaper.

It's uh, the transportation is fairly cheap. Um, here much, much cheaper than the us. It's all around. Like your whole living expense is gonna be different. So that said you don't need a hundred K job. You don't need a six figure job to live in a place like this. You have a six figure job here. You are living like a freaking king here, you know?

So that's one of the main reasons that people will go and live remotely. So, um, it's worth your time to look into everything's cheaper medical, uh, your dental, your food. Rentals your transportation, your whole living, your whole life is much, much, much cheaper in these countries that I named. Now, one thing you should know is that there's some countries that you probably sh can't go to, or don't necessarily want to go to, cuz you would not be able to work in an American or Canadian or some other countries going, you can't work from the following countries doing remote work.

I'm just gonna name a. Top of my head that are gonna be much, much harder for you to do remote from. And, uh, those, especially for American companies, cuz there's like an embargo. Anytime there's a country with an embargo, it's gonna be a lot harder for you to, to live there. And one of off the top of my head, one is Iran.

Um, Iran has some kind of sanctions, you know, and it's not that us American citizens agree with this stuff, but that's neither here nor there. If you're trying to work from. Cheaper location and you're trying to live there and stuff like that. It's just, you know, we are not necessarily the ones making the policies or controlling what's going on.

Right. So it it's fun. It's funny because the politically, we don't necessarily align with what the government is doing with the sanctions and stuff, but it it's a reality that we have to deal with. So one of those is Iran. Iran has all these sanctions. There's most American country companies that are paying you big money.

Will not be able to work from there. You can get there it's even gonna be hard for you to get there as an American. Another place is gonna be of course, uh, North Korea. obviously, it's funny because it's so obvious. It's so crazy. It's gotten, the relationship has been so bad between the us and North Korea.

They just did not even a question anymore. You go there, especially if you're ex-military or something you're gonna be end up in prison somehow, you know? So unless you're Dennis Rodman or something, I don't know. Um, it it's, it's just not a place that you're gonna be able to go. That that being said South Korea.

Um, it is probably a place you could live, but it's, it's a lot more expensive in South Korea. So, um, it it's, a lot of people don't go there because of that reason, unless they have family or friends or, or, or their family fiance or spouse, is there or something like that. Um, another place that you probably are gonna have some issues with is gonna be VE.

And it's just unfortunate, cuz it's such a beautiful place with beautiful people, beautiful culture and all that stuff. It's just sad. But Venezuela, I know people are going there but to work from there, um, cause the what's happening with the economy. Cause there's, you don't know like the, the embargo thing is kind of flaky with the us.

Every time there's a new president, they put some kind of stuff against Venezuela. Venezuela is probably not a place you could work remotely. Uh, another place is Cub. Another one that's really unfortunate because it's such a beautiful place. It's so amazing. It's so close. It just makes sense to live there.

And it's just like, because of all this stupid stuff going on between our governments, we as Americans gonna have a hard time getting in and out of there, especially if you're working from there on, on, uh, anything with any kind of government information, it's just gonna be harder for you to work there.

And then all this political stuff happening now with, with. Don't know if you've heard, but like Russia and, and some other countries that are going and, and making bases and stuff and having relationships with it's just gonna go outta control here real soon. So it's not a place I would recommend that you, even if you have the ability to do it, to work there for an American company and, and go there.

So those are the three that I was, I'm sure there's many other ones. Maybe I'll make another, uh, video where I explain some other countries that are, that are not good to go to, to work. Um, and, uh, that's, that's about it for those ones. Um, let me see if there's any other things I wanted to talk to you about with remote work.

I think that's it for remote work. I want to talk to you guys a little bit about something I've discovered something I was, I've been doing right for many, many years. I'm gonna actually change locations here so that we can get a better sound change up the ambiance a little bit. Okay. Here we go. Going inside.

Room

are you on? Okay, sorry. Uh, okay. Sorry. I, my partner's, uh, doing some work there, so I'm gonna stay in. I'm stay out here. oh, this is, uh, podcast. So that's what you get real life stuff going on. So anyway, um, I wanted to talk to you guys about a Ts. So what I discovered is all these years I've been doing something very right with.

My resume. If you didn't know, whenever I put my resume out there, I market my resume. It does really, really well on LinkedIn, on dice, on monster and all the other job sites. It does really well. And the reason why I discover is cuz I keep it simple. It's just a plain, it's not fancy. It doesn't have tables.

It doesn't have pictures. It doesn't have anything, any kind of overlays, nothing like that. It's just a plain document. White paper, white. With my name on the top contact information, and then job exper work experience. It has, um, certifications. It has education. It has that's about it. It's pretty simple.

Like I think I recently added skills, but it's pretty basic. And I normally put it in dot doc, turns out all that stuff is what you're supposed to do so that it is ATS compliant. Now, what is ATS? ATS? A application tracking software. It's basically like a database or software or a server that fortune many fortune 500 companies use to, uh, pull in the resumes and track, um, and, um, monitor and do analysis and do artificial intelligence analysis on resumes.

It pulls them in if it has the correct format. If, if the correct format is. It'll reject your it'll reject your, um, your applica your resume, right? And if you, you wanna know what I'm talking about, whenever you sign up for a job, think of this, have you noticed they always have you do an application? The reason why is cuz your resume is not compatible.

Normally people's resume is not compatible with the system that they, that company has internally. They have an internal database that pulls in all the information. It has. It has a database. Name, uh, where you've worked in the past, all your experience, your skills, your education, all that pulls, all that stuff in, and it compares you to other candidates and it, and once you're in their database, they have this big pool of people, um, that they can pull from and, and put into different positions.

And it allows 'em to put you quickly into those different positions and then call you con if you contact information's there, they'll contact you with via. Or via phone and say, Hey, Bruce, uh, we've got this position for you. Are you available on this day? We noticed that you have all the skills that we need for this position.

That is an ATS. It allows 'em to very quickly get you in their system. And if you have a resume, what they'll too, if your resume is right, is they'll pull all that information from LinkedIn or from dice or from monster or from other search sites. And. Put that into their database, just instantaneously, but that's only if your resume is out there in the correct format with all the correct information.

And that's why you have to fill out your complete profile. It has to be accurate and then upload your ATS compliant resume. That means a plain blank resume with the headers. All that stuff is in correct order. And one of the things that I noticed that my, my resume didn't get right, was the dates of work.

It's a work we're a little off, cuz there's a certain format that they want you to have in there. So ATS, uh, just having a simplified resume has helped me to get all these jobs and all these offers and all these opportunities over the years. And then now, recently I fine tuned it. I've I've gotten back into my resume, ripped it apart, rewrote it.

And now I'm like really getting into the weeds on the each one of the key words that they wanna see. And the format tightened it up. So it's perfect so that whenever they pull in those resumes, mine is gonna just come in and with no problems. So that is what ATS is. And, um, that is, that's something that that's really helped me out to get jobs and stuff.

Um, I would like to, at some point what I'm gonna do for you guys that watch me on YouTube is I'm gonna walk you through how I actually apply using my ATS. May, um, and how you can, um, maximize your opportunities, uh, to get these different jobs, high paying jobs, by the way, that's about it guys. Um, I'm got about three days left here.

I'm a little bit sad about it. Um, I've gotta go back into the workforce here real soon. , uh, it's been a great vacation here in Manila and I, I actually travel to, uh, different parts of the Philippines. Um, this Philippines, the reason why I come here so often is because it's been like a second home to me.

Um, I have over the years of these high paying jobs, I've been able to buy some condos here. Um, kind of got in early on some condos and, um, got some, uh, friends and family and stuff here. And that's, that's why I come here. And I know where things are, kind of have a better feel for this particular country.

Next country. I'm. To I've been here so many times. It's time for me to, to move to another place. I'm probably gonna go to like Indonesia. I'm gonna try that. At some point, I would like to go to Europe and, uh, countries in Africa. And, uh, those are things that are gonna be in the future for me. I would love to go there and, and visit.

But right now, this going to places, I know that I, that I'm familiar with that can go by myself and feel, and, and feel familiar enough to where I feel safe. So that's, that's why I. Year. And that's why I come here so often. Um, if I would, I get a job here, I noticed somebody asked me a question. They said, Hey, Bruce, like, would you get a, a job here?

And they said, Hey, I'm looking for a job in the Philippines. Could I do it? You totally could do it here. If I was doing that, I've got my kids and stuff are in the us. I'm not, I'm not doing it myself here. And it's a bit too crowded personally for me to live here. Uh, maybe in the far future, you know, and buy some.

Somewhere and then go live there or something, or have my spouse, by the way, you gotta be a Filipino citizen in order to buy land. Or anyway, what I would do if I wanted to get a job here is I would, first of all, tighten up my resume, right. Uh, tighten up my resume and I would look for either a job in Metro Manila or in Sibu I'd open myself up to those I'd look at all the job sites for Sibu and.

Metro Manila, cuz those are like the biggest cities here I'd apply for those jobs. Put my re, get my resume, right? Put it out there. And I noticed just kind of glancing at it that there's a lot of banks that need the kind of work that I provide. So I would apply for all of those, but my biggest play would be on remote work.

I would look for remote work in the us cuz it's a job. It's a hot job market right now for it. And cyber security. I would look for remote jobs. Would allow me to actually work from home and then I would fly here and work from here. That's what I would do. Um, if I was, if I was so inclined to actually work here and at one point I really considered it, I would actually consider bringing my kids here and like living here like three months out of a year or something like that, it didn't work out.

So now here I am by myself. Um, just enjoying my vacation here and. I think maybe in the future, what I'll do is I'll, uh, I'll look for some other country that I could live in. Uh, it probably won't be, like I said, Philippines, a little too crowded, but I'm looking, I'm kind of head hunting for, for different countries that I could live in.

Um, for a while. I like to like live in a country for like a year and, uh, and just to see how it, how it feels to actually be a resident of that country. So I would look for a. That will allow me to stay there for some time. And, but just off the top of my head, Portugal keeps coming up. Portugal is one that I would look into.

Um, maybe, maybe Thailand. I really love Thailand so much. Um, Indonesia's one. I want to check out. Those are what like that are, um, within my price range and I feel more comfortable in those places. Um, cuz I've been to Southeast Asia. So. Times that I kind of know what to expect. And then I would like to learn the language and stuff like that.

So I'd be pretty serious about it if I did do it. Um, I think that that's about it for this particular podcast. Guys, let me just, uh, end this on, uh, letting you get for those you, this is where I'm at. It's pretty nice. Um, got a few more days here. It's been great. Um, just enjoying the culture, enjoying the, the atmosphere and, uh, the humidity.

I love. Back in Colorado. We don't really have that. Um, it's, it's very, very dry mountainous and stuff, which is beautiful, has its own, you know, amazing beauty, but it's not the Philippines. You know what I mean? , we're not too far from the ocean here. Um, feels so amazing here. And, um, I'm gonna miss it once again.

I'm gonna miss this place and um, next time I'll gonna go to another country and hopefully I'll be able to do some podcast. There too. All right. Talk to you guys.

View Details

Main topics:

  • Challenge of working remotely in other countries
  • The ATS style resume for IT and cybersecurity

For more check out: www.Convocourses.com

https://www.youtube.com/convocourses

fb: https://www.facebook.com/convocourses

https://www.tiktok.com/@convocourses

Amazon books: https://www.amazon.com/dp/B0B6PWGXJZ?searchxofy=true&binding=kindle_edition&ref_=dbs_s_aps_series_rwt_tkin&qid=1661986519&sr=8-1

Audible:

https://www.amazon.com/gp/product/B0B98WG2HX?notRedirectToSDP=1&ref_=dbs_m_mng_rwt_calw_taud_tkin&storeType=ebooks&qid=1661986519&sr=8-1

Welcome to convo courses. My name is Bruce, and this is gonna be kind of a different format podcast. If you happen to watch my old ones, normally I put 'em on YouTube immediately. Um, right now I'm kind of on the go and I'm in my hotel. But I'm able to knock out these podcasts and there's a couple things we're gonna talk about on this one.

And I'm trying to just help you guys out with everything that I've learned over the years, doing cyber security and doing specifically security compliance, um, and how to get into the cyber security and it space. um, and, and things I've learned along the way I've been doing this for 20 years. Uh, I've been doing this since two, the year 2000.

I actually was in the military for eight years. Um, I, I ended where I was working as a physical security guy. I was a security forces member, protecting resources and assets, and then doing law enforcement, things like that. So I very familiar with security, physical security controls, but then I, I cross train into cyber security.

Well, actually I crossed into it and we call it computer operators, but I did all things, uh, related to it, including cyber security, where, and that's where I got into security compliance. So. What I'm gonna talk about in this one is gonna be, um, something I learned about resumes. I realized why my resume's been doing so well.

And it's because it's ATS or application tracking system compliant. Let explain what that is. And, uh, kind of walk you through how to do it, and I'll try to be as audio as possible, knowing that some people only watch only listen to these, uh, podcasts. Uh, but that being said, if you happen to watch this on YouTube, then I'll have, uh, some examples for you as I'm talking through it.

Another thing I'm gonna talk about since I happened to be remote. Is working remotely and some of the pros and cons and, um, got some notes here, pros and cons of working remotely, some of the benefits of it and some of the countries that, uh, a lot of Americans are going to and why. All right, let's start off with the actual remote work.

I'm gonna take you guys here outside for a second here, outside of my room. It's gonna be a little bit of a change of audio. So just bear with me, but you'll still be able to hear me well, all right, here we go. All right. So I'm not able to do this live. Normally I do these, I do these live and, uh, um, but I, the.

It's not good enough here. And so that's one of the things I talked about in the previous videos and previous, um, podcasts where you, whenever you go to a place it's about noise. Pollution is a factor. Sometimes. Anyway, that being said, let's get into this. I want to show you guys where I'm at. So I'm at a resort here in Manila, Philippines, and I've been here for, I've been in the Philippines for about a month.

Uh, I've been off for about two. At the end of that, and I'm actually looking for a job right now, learn some new things about the job market, which we'll talk about. Okay. So what I'm looking at, if you happen to be watching and listening to this on audio is it's just a group of hotels with a bunch of pools below it's.

It's beautiful. It's kind of a rainy, kind of a rainy day here in Manila. There's a freeway that's not too far from here. That's what you can kind of hear that far away. There's an airport, not too far from here. And then you can hear. Below that are in a pool and stuff. So that's, that's where I'm at. I'm like on a balcony of a hotel resort, pretty nice.

It's called the urban residence, urban residence. Crazy that I've gone to so many hotels. I forgot the name of this place. And even, even those places. Nice. Anyway. Okay. Let's talk about the benefits of remote work. You hear a lot of people talking about remote work and you probably wondering, like, why did everybody talk about this?

Why is this so popular? Why is what's going on with it? Well, there's a few reasons and everybody has their own reasons, but I'm going to name some of the most popular that come to mind. One of the biggest ones is, uh, when you're working remotely, especially in other countries, is that it's cheaper to live in other countries.

A great example is Manila is one of the most popular places that Americans will go and move to and work from because it's just, it's just cheaper to live here. The food is cheaper. Uh, for us, um, the cost of living here for Filipinos is, is not great. There are problems here. I've been here long enough to see some of the, the freight edges of, of a country.

And that's the thing. When you go to a country it's not all sunshine and rainbows, like you, you find there's issues in every country, just like in the us. So don't a lot of people just talk up on a country, but you gotta look at all sides of it whenever you travel. Anyway, one of the biggest benefits that Americans will come here in, in some other C.

That it's cheaper for us cheaper for us cost of living wise with food, much cheaper with your medical is much, much cheaper. It's cheaper to fly here or do medical, uh, and dental than it is to do it in the us. It's ridiculous in the us. It's cheaper for rentals are cheaper. Like these rentals here. Um, this, these are kind of an exception because these are, this is a private residence that are in a, a resort.

So this is gonna be a little bit more pricey. Um, but this, this place I. Which is, which is incredible, which has pools. It has has a clubhouse that right over there that, that dome looking building that donate, donate shaped dome looking building is a, is a clubhouse that has, it has food. It has amenities such as the gym.

It has all kinds of stuff there. And it's three levels, but this place I'm at is $45 a day for this resort. There's, there's like four pools here. There's an Olympic size swimming pool over there. This place is. It's it's, it's absolutely ridiculous. Um, not the best service I've had in the Philippines.

Philippines has some of the best service in the world. This place is kind of, so, so I don't know why it's the, management's not as way here, but this place is incredible. A place like this will run you probably $300 a day in the us. No joke, cuz this is like a five star resort. Um, here it's $45 and I found some of these places that you I'm looking at at hundreds of different.

Across from me and these units, some of 'em are only $27 a day. You could literally live here for $27 a day, $27 a day. It's like a thousand a month in a resort. Think about that. Living in a resort for thousand dollars a month or $30 a day. Yeah. About what, $30 a day. It's for 30 days, $900 a month. So that's still cheaper, like living in a place like this has a kitchen, it has internet, it has, uh, you know, um, Full bathroom.

Like you could, there's a laundry service downstairs. Like you could live here in this resort for $900 a month. There's a, there's a, uh, mall not too far from here. It's walking distance with a grocery store. Uh, everything you need is here and $900 a month, a place like this cost you $900 in the us. So that's one of the main reasons that people will travel and live in another place.

Some places that people consider besides. Would be that are cheap to live for us for American citizens is include Portugal, um, Thailand, Vietnam, Mexico, um, and Columbia. And there's a few other ones that are, that are comfortable for us to live and a Dominican Republic. That's another one comfortable for us to live much cheaper living standard and just your, your life is gonna be completely different there.

You. To really retire in some of these places. And this is 900 a month is, is, is crazy here. That's a crazy price. Um, you can get something that's not as doesn't have as many amenities for about $200 a month, $300 a month. A very, a pretty good place for about $300 a month. So, and then the food is, is cheaper.

It's uh, the transportation is fairly cheap. Um, here much, much cheaper than the us. It's all around. Like your whole living expense is gonna be different. So that said you don't need a hundred K job. You don't need a six figure job to live in a place like this. You have a six figure job here. You are living like a freaking king here, you know?

So that's one of the main reasons that people will go and live remotely. So, um, it's worth your time to look into everything's cheaper medical, uh, your dental, your food. Rentals your transportation, your whole living, your whole life is much, much, much cheaper in these countries that I named. Now, one thing you should know is that there's some countries that you probably sh can't go to, or don't necessarily want to go to, cuz you would not be able to work in an American or Canadian or some other countries going, you can't work from the following countries doing remote work.

I'm just gonna name a. Top of my head that are gonna be much, much harder for you to do remote from. And, uh, those, especially for American companies, cuz there's like an embargo. Anytime there's a country with an embargo, it's gonna be a lot harder for you to, to live there. And one of off the top of my head, one is Iran.

Um, Iran has some kind of sanctions, you know, and it's not that us American citizens agree with this stuff, but that's neither here nor there. If you're trying to work from. Cheaper location and you're trying to live there and stuff like that. It's just, you know, we are not necessarily the ones making the policies or controlling what's going on.

Right. So it it's fun. It's funny because the politically, we don't necessarily align with what the government is doing with the sanctions and stuff, but it it's a reality that we have to deal with. So one of those is Iran. Iran has all these sanctions. There's most American country companies that are paying you big money.

Will not be able to work from there. You can get there it's even gonna be hard for you to get there as an American. Another place is gonna be of course, uh, North Korea. obviously, it's funny because it's so obvious. It's so crazy. It's gotten, the relationship has been so bad between the us and North Korea.

They just did not even a question anymore. You go there, especially if you're ex-military or something you're gonna be end up in prison somehow, you know? So unless you're Dennis Rodman or something, I don't know. Um, it it's, it's just not a place that you're gonna be able to go. That that being said South Korea.

Um, it is probably a place you could live, but it's, it's a lot more expensive in South Korea. So, um, it it's, a lot of people don't go there because of that reason, unless they have family or friends or, or, or their family fiance or spouse, is there or something like that. Um, another place that you probably are gonna have some issues with is gonna be VE.

And it's just unfortunate, cuz it's such a beautiful place with beautiful people, beautiful culture and all that stuff. It's just sad. But Venezuela, I know people are going there but to work from there, um, cause the what's happening with the economy. Cause there's, you don't know like the, the embargo thing is kind of flaky with the us.

Every time there's a new president, they put some kind of stuff against Venezuela. Venezuela is probably not a place you could work remotely. Uh, another place is Cub. Another one that's really unfortunate because it's such a beautiful place. It's so amazing. It's so close. It just makes sense to live there.

And it's just like, because of all this stupid stuff going on between our governments, we as Americans gonna have a hard time getting in and out of there, especially if you're working from there on, on, uh, anything with any kind of government information, it's just gonna be harder for you to work there.

And then all this political stuff happening now with, with. Don't know if you've heard, but like Russia and, and some other countries that are going and, and making bases and stuff and having relationships with it's just gonna go outta control here real soon. So it's not a place I would recommend that you, even if you have the ability to do it, to work there for an American company and, and go there.

So those are the three that I was, I'm sure there's many other ones. Maybe I'll make another, uh, video where I explain some other countries that are, that are not good to go to, to work. Um, and, uh, that's, that's about it for those ones. Um, let me see if there's any other things I wanted to talk to you about with remote work.

I think that's it for remote work. I want to talk to you guys a little bit about something I've discovered something I was, I've been doing right for many, many years. I'm gonna actually change locations here so that we can get a better sound change up the ambiance a little bit. Okay. Here we go. Going inside.

Room

are you on? Okay, sorry. Uh, okay. Sorry. I, my partner's, uh, doing some work there, so I'm gonna stay in. I'm stay out here. oh, this is, uh, podcast. So that's what you get real life stuff going on. So anyway, um, I wanted to talk to you guys about a Ts. So what I discovered is all these years I've been doing something very right with.

My resume. If you didn't know, whenever I put my resume out there, I market my resume. It does really, really well on LinkedIn, on dice, on monster and all the other job sites. It does really well. And the reason why I discover is cuz I keep it simple. It's just a plain, it's not fancy. It doesn't have tables.

It doesn't have pictures. It doesn't have anything, any kind of overlays, nothing like that. It's just a plain document. White paper, white. With my name on the top contact information, and then job exper work experience. It has, um, certifications. It has education. It has that's about it. It's pretty simple.

Like I think I recently added skills, but it's pretty basic. And I normally put it in dot doc, turns out all that stuff is what you're supposed to do so that it is ATS compliant. Now, what is ATS? ATS? A application tracking software. It's basically like a database or software or a server that fortune many fortune 500 companies use to, uh, pull in the resumes and track, um, and, um, monitor and do analysis and do artificial intelligence analysis on resumes.

It pulls them in if it has the correct format. If, if the correct format is. It'll reject your it'll reject your, um, your applica your resume, right? And if you, you wanna know what I'm talking about, whenever you sign up for a job, think of this, have you noticed they always have you do an application? The reason why is cuz your resume is not compatible.

Normally people's resume is not compatible with the system that they, that company has internally. They have an internal database that pulls in all the information. It has. It has a database. Name, uh, where you've worked in the past, all your experience, your skills, your education, all that pulls, all that stuff in, and it compares you to other candidates and it, and once you're in their database, they have this big pool of people, um, that they can pull from and, and put into different positions.

And it allows 'em to put you quickly into those different positions and then call you con if you contact information's there, they'll contact you with via. Or via phone and say, Hey, Bruce, uh, we've got this position for you. Are you available on this day? We noticed that you have all the skills that we need for this position.

That is an ATS. It allows 'em to very quickly get you in their system. And if you have a resume, what they'll too, if your resume is right, is they'll pull all that information from LinkedIn or from dice or from monster or from other search sites. And. Put that into their database, just instantaneously, but that's only if your resume is out there in the correct format with all the correct information.

And that's why you have to fill out your complete profile. It has to be accurate and then upload your ATS compliant resume. That means a plain blank resume with the headers. All that stuff is in correct order. And one of the things that I noticed that my, my resume didn't get right, was the dates of work.

It's a work we're a little off, cuz there's a certain format that they want you to have in there. So ATS, uh, just having a simplified resume has helped me to get all these jobs and all these offers and all these opportunities over the years. And then now, recently I fine tuned it. I've I've gotten back into my resume, ripped it apart, rewrote it.

And now I'm like really getting into the weeds on the each one of the key words that they wanna see. And the format tightened it up. So it's perfect so that whenever they pull in those resumes, mine is gonna just come in and with no problems. So that is what ATS is. And, um, that is, that's something that that's really helped me out to get jobs and stuff.

Um, I would like to, at some point what I'm gonna do for you guys that watch me on YouTube is I'm gonna walk you through how I actually apply using my ATS. May, um, and how you can, um, maximize your opportunities, uh, to get these different jobs, high paying jobs, by the way, that's about it guys. Um, I'm got about three days left here.

I'm a little bit sad about it. Um, I've gotta go back into the workforce here real soon. , uh, it's been a great vacation here in Manila and I, I actually travel to, uh, different parts of the Philippines. Um, this Philippines, the reason why I come here so often is because it's been like a second home to me.

Um, I have over the years of these high paying jobs, I've been able to buy some condos here. Um, kind of got in early on some condos and, um, got some, uh, friends and family and stuff here. And that's, that's why I come here. And I know where things are, kind of have a better feel for this particular country.

Next country. I'm. To I've been here so many times. It's time for me to, to move to another place. I'm probably gonna go to like Indonesia. I'm gonna try that. At some point, I would like to go to Europe and, uh, countries in Africa. And, uh, those are things that are gonna be in the future for me. I would love to go there and, and visit.

But right now, this going to places, I know that I, that I'm familiar with that can go by myself and feel, and, and feel familiar enough to where I feel safe. So that's, that's why I. Year. And that's why I come here so often. Um, if I would, I get a job here, I noticed somebody asked me a question. They said, Hey, Bruce, like, would you get a, a job here?

And they said, Hey, I'm looking for a job in the Philippines. Could I do it? You totally could do it here. If I was doing that, I've got my kids and stuff are in the us. I'm not, I'm not doing it myself here. And it's a bit too crowded personally for me to live here. Uh, maybe in the far future, you know, and buy some.

Somewhere and then go live there or something, or have my spouse, by the way, you gotta be a Filipino citizen in order to buy land. Or anyway, what I would do if I wanted to get a job here is I would, first of all, tighten up my resume, right. Uh, tighten up my resume and I would look for either a job in Metro Manila or in Sibu I'd open myself up to those I'd look at all the job sites for Sibu and.

Metro Manila, cuz those are like the biggest cities here I'd apply for those jobs. Put my re, get my resume, right? Put it out there. And I noticed just kind of glancing at it that there's a lot of banks that need the kind of work that I provide. So I would apply for all of those, but my biggest play would be on remote work.

I would look for remote work in the us cuz it's a job. It's a hot job market right now for it. And cyber security. I would look for remote jobs. Would allow me to actually work from home and then I would fly here and work from here. That's what I would do. Um, if I was, if I was so inclined to actually work here and at one point I really considered it, I would actually consider bringing my kids here and like living here like three months out of a year or something like that, it didn't work out.

So now here I am by myself. Um, just enjoying my vacation here and. I think maybe in the future, what I'll do is I'll, uh, I'll look for some other country that I could live in. Uh, it probably won't be, like I said, Philippines, a little too crowded, but I'm looking, I'm kind of head hunting for, for different countries that I could live in.

Um, for a while. I like to like live in a country for like a year and, uh, and just to see how it, how it feels to actually be a resident of that country. So I would look for a. That will allow me to stay there for some time. And, but just off the top of my head, Portugal keeps coming up. Portugal is one that I would look into.

Um, maybe, maybe Thailand. I really love Thailand so much. Um, Indonesia's one. I want to check out. Those are what like that are, um, within my price range and I feel more comfortable in those places. Um, cuz I've been to Southeast Asia. So. Times that I kind of know what to expect. And then I would like to learn the language and stuff like that.

So I'd be pretty serious about it if I did do it. Um, I think that that's about it for this particular podcast. Guys, let me just, uh, end this on, uh, letting you get for those you, this is where I'm at. It's pretty nice. Um, got a few more days here. It's been great. Um, just enjoying the culture, enjoying the, the atmosphere and, uh, the humidity.

I love. Back in Colorado. We don't really have that. Um, it's, it's very, very dry mountainous and stuff, which is beautiful, has its own, you know, amazing beauty, but it's not the Philippines. You know what I mean? , we're not too far from the ocean here. Um, feels so amazing here. And, um, I'm gonna miss it once again.

I'm gonna miss this place and um, next time I'll gonna go to another country and hopefully I'll be able to do some podcast. There too. All right. Talk to you guys.

View Details

I was in the Philippines from June to part of August.

We talk about:

  • Remote Working
  • Countries I have worked in
  • ITAR and the countries you cannot work in
  • the new book about NIST 800-53 controls: https://securitycompliance.thinkific.com/courses/rmf-isso-controls-audiobook

Hey guys, this is Bruce, and welcome to concourses. I'm gonna be talking to you about my travels. I'm actually still abroad. I'm still in the Philippines and I actually going back home real soon. So you can expect regular podcasts like we've been doing before, but I wanted to go ahead and start doing these more often.

And I wanna start off by letting you guys know. I just released a few more products out there. So if you go to combo courses.com. I am writing a book about getting jobs in, um, in information technology and in cyber security and marketing those, uh, resumes that you put out, I'm gonna teach you how to create the resume from scratch and then how to promote the hell outta that resume.

So that is incoming. I'm doing that right now as we speak right in it. But if you want to get in early on this book, there it is right there. Uh, and that as soon as the. Is out I'll, I'll release it to you so you can actually pre-order it. Now I also am selling the audio version of the last two books that I wrote on my website, but you can also get 'em on audible as well.

And yeah. So speaking of that, The audible version of the NIST 800-53. If you prefer to use audible, if you have credits on audible, whatever, if you actually want to get a free trial on Audible, you can actually get this book for free on audible. So go ahead and check those things out and I'll be releasing a lot more and creating a lot more content for you guys.

But let's get into this one. I wanted to talk a little bit about this. And how you can do this. And just trying to tell you my experience. So you can get some idea of if, if, whether or not you actually wanna do this. I've first of all, I've been working remotely for, uh, past six years now, um, with different jobs.

Like I, this is my third, my last job was my third job that I did remotely. I worked for NASA remotely with a company, and then I, I worked, um, at Ball Aero. For a while remotely and, and then recently worked with Verizon remotely. And, um, there's a lot nowadays, there's a lot more remote jobs out there. So if you want the opportunity to actually do what I'm doing, it's much easier to do this now.

Um, my experience with RO work and remotely has been incredible. I've really enjoyed. Um, it's given me more time to spend with people who I love, um, I'm at home, so I can actually interact with them and figure out problems together with them and have more family time and things like that. Um, so those are the pros with it.

Some of the cons is if you have small kids, it's much harder to do remote work when you have small kids, or if you have somebody who's very needy it because it's hard to actually do your work with that. Um, and I've been in that situation where. Actually difficult. I had a remote job when my kids were really small and they, as soon as they see me, they wanna play, you know, so it wasn't the ideal, uh, situation when my kids were small, but now they're older, so they understand, Hey, dad's gotta work.

You know, and I have a, a place in my house where I can go and stuff like that. Um, another thing is that I have to actually have more discipline on stopping my work. Like you might think it. It is the opposite that you, it's hard to actually get to work for me. It's the opposite. It's hard to stop working.

I tend to just continuously work when I work from home and I gotta actually stop myself and have the discipline to say, okay, that's it. This project, the rest of this project and work till, wait till tomorrow. I'll I'll get to it then. Having that discipline is really important. Um, the self-discipline to actually not only do the work, but also stop yourself and have a schedule where you.

Force yourself to, um, not overwork. Um, so that that's some of the pros and cons of working remotely. Now, as far as what I'm doing now, what I'm doing right now is I'm actually in between jobs. I'm not working remotely, I'm working remotely on my own stuff, on my own business and I'm writing and stuff like that.

So you could include that as work remotely, but what we're talking about specifically is working for an employer. , you know, whether it's the government or private sector or whatever bank, whatever you're working for. Um, I'm not doing that right now. Right now. I'm abroad and I'm having a vacation and I do any work I'm doing is all, uh, business related.

But I, I have been here before in the Philippines and worked in other countries, Thailand and Vietnam and other countries worked actually working for an employer remote. and there are some challenges to this. If, if this is something that you, you aspire to do, there are some challenges that you should know about.

Um, number one I would say is just because your employer is allowing you, it, it, it has it on the dockets to work remotely. Doesn't mean they allow you to work in another. And what I mean by that is there's laws. There's rules. One is called I a R, which will pro will restrict you from taking their laptop and their information outside of a country.

And in sometimes in some cases they have a policy where you can't even take the, their. Do equipment out of the state and they don't expect you to work outside of the state, but country is a lot more, um, happens a lot more often where they don't allow you to work outside of the state. I mean, I'm sorry, out of the country.

And, and in sometimes it's just, it's not that they don't want you to work outside of the country. It's more like there's certain countries they don't allow you to and you've gotta make sure whatever. you you've gotta use strategy. Like if you're trying to live in say the Philippines and you know, you want to get a USA job or a job in Canada or wherever the case may be, you know, this is what you wanna do.

You have to think about it. Um, will this job allow me to work in another country? Okay. What countries can I work in the way that I've done it? Is whenever I get into a company, right? I'm I'm looking at their rules. I'm looking at what are their rules for remote work? Do they even allow, is it flex time where they want you to come in?

Once a week or something, is there travel? Is there, I'm looking at all the avenues of what I can do and what kind of information that we're gonna be processing. Cause that's another important feature when you're first looking at a remote job, uh, because if they're doing classified or any kind of super sensitive information, uh, more than likely it's, you're not gonna even be able to leave the, the state or the area.

Uh, and you have to, it'll be flex work, meaning you'll work from home, but then they want you to come in the office. If you're doing some kind of sensitive, really, really sensitive information. So that's one thing. Another thing I'll look at is, is the environment. Um, some organizations, especially private organizations are a little bit more, um, open about remote work.

They'll actually have like the last place I worked. We had people working in Japan. Like we had one guy working in Japan, doing work on for our clients and stuff like that. And we had another person who was working overseas in south America. uh, who we had clients in south America. We had clients, we had people in Europe doing work with those clients.

We had people in Australia, we had people all over the world doing it. So the job lended itself to working internationally, cuz we had people who were actually working internationally. So that was that. Wasn't another thing I look at, like what's the environment. A lot of, uh, government jobs. They're very stable.

They allow remote work, but they're usually like flex jobs. They want you to still come in and stuff like that once a week or something. And then they have like a little bit of travel. So you gotta watch that private companies a little bit more flexible. So you wanna look at the environment. . Um, so those are some of the things that I, that I normally look at when I'm trying to think about strategy of what do I want, what country do I want to live in, will this organization that I'm applying for allow that those are the things you gotta now, once you get in, let's say you get a remote job, you're there.

Um, it's a great job. They're paying you. Good. All that kind of stuff. Now you're like, Hmm, can I travel? Uh, Venezuela Brazil, wherever Cambodia, wherever it is. Can I go there now? It's a matter of their policy right now. You know, that they're remote and all that stuff. You know that they're, it's okay. Maybe to travel, uh, internationally.

They haven't restricted you from that. Um, you've got your VPN, you got your protection on your system, all that kind of stuff. Now you're like, okay, the next question should be what other. because some organizations will not allow you to go to certain countries and that's, it's tied to something called I a R and it's I don't remember what the actual acronym is.

It's and let me actually, let me look it up while I'm talking to you, you gotta look at the actual policies because that is super important. Um, you don't want to get caught, uh, traveling to some country you're not actually supposed to go to. And the, the company is obligated not to go to those countries.

Like legally you're not supposed to here. It's called it a international traffic in arms regulations, like arms you're thinking like guns and stuff like that. But, um, they're also talking about certain technologies that are wrapped into this, uh, into this. That the government has certain things that they do not allow com us companies to go to certain countries.

The reason why is because they, that that country might steal their, the intellectual property of that organization. A good example of this would be, um, companies like Lockheed Martin, who. military, um, different military components. There's certain components that are proprietary and owned by the government.

That if it, you go to that other country and that country is spying or actively stealing anything on and off their network, uh, That's really bad encrypted or not they'll they can steal it and encrypted for later or something like that. Um, and that actually does happen quite a bit. Um, especially with the bigger countries, like China's doing that a lot.

And I, I don't doubt that us is doing that China and Russia is doing, they're doing all these major powers or doing that to one another. The point is though, from our perspective as workers, we just wanna make sure that we are. Gonna get caught, violating these laws and, and worse, uh, leak some information from clients and jeopardize our entire career based off some international, uh, incident, you know, like you don't want to be that guy it's just too risky.

So we talked a little bit about knowing the environment for that remote company, uh, knowing the policies is another thing that's huge and. um, also making sure you don't violate any kind of laws that that company has. And that's normally tied into the policies. Now, one of the things that I did at the last place I worked at was I just asked, I said, Hey, are there any, what can you send me the laws of travel?

Like I wanna, I'm trying to travel. I didn't even go into details of that. I just say, Hey, can you send me the laws I read 'em myself. I'm not gonna ask permission and then get denied. Right? I'm just gonna. and make sure I don't violate any major laws and then ask forgiveness. If they're like, Hey, you're you're in another time zone.

They won't even know I'm in another time zone, cuz I'm not gonna let them, I'm gonna be on the same. I'm not gonna violate any of their policies. I'm not gonna violate any kind of international laws are unit us national laws or anything like that. Um, so all of that stuff is good, but what I'll. is make sure that I don't violate their, you know, I'm still on Eastern standard time or whatever the timeframe is.

So they don't even know I'm gone. Like I, I even travel sometimes I'll take, leave enough to travel to that other country. And then on Monday, Tuesday, when I'm supposed to go back to work, I'm bright and early working my nine to five. You. So that's some of the stuff I do. Um, I'm, I'm risk averse. Um, I manage my risk very effectively when I'm working for, for an organization.

I do not violate their rules. I do not. I just feel like the risk is too great for me. And that's kind of the mindset that you should have. I've not I've yet to be in trouble for traveling or anything. They don't even know I'm gone. I'm I'm doing everything I'm supposed to do now. Another. That you should think about when you're travel, when you're doing remote work and you're traveling, even if it's a staycation in another state, nevermind another country.

One of the things you should keep in mind is there's a few things. You, you need a place that's quiet. Uh, like right now I'm in this room here. It's, it's very quiet. It's very, um, there. I, I don't hear a lot of noise going on outside, but I've been in some places, especially in Southeast Asia where the noise level is super loud.

Like I was in Vietnam, the noise level was so loud. Like it, it, privacy was fine. I could just go inside of my room or whatever and, and shut the door, lock the door, whatever. Right. And had encryption, all that kind of stuff. But man, the noise pollution outside was seeping into the room. So you wanna have a place where you.

it's closed. You have privacy because especially if you're dealing with secret in not secret information, if you're dealing with, um, sensitive information from a client like vulnerabilities or IPS, you have to have privacy and you're talking on the phone, right? I'll get to the encryption and all that kind of stuff in a second.

But I'm talking about privacy. Like you're on the phone talking to somebody, talking to your boss, talking to peers, talking to the client, the customer, whatever. And you might be talking about some sensitive information on the phone. So you want privacy, a room where it's not leaked the information not leaking out, but also that room gives you quiet where you can actually speak to them and, and have a conversation cuz conversation, you know, The communication is huge.

That's a big deal, uh, in cyber security. So you need a, a private space, the other thing, and that's pretty obvious, but the other thing is security. Um, whatever system you're on, you need to ha make sure you have firewalls in place, antivirus in place, and a VPN virtual private network either built in from the organization.

Preferably. So that it's their level of encryption and you don't have to worry about, uh, some private organization's encryption getting, getting compromised or something, which does happen by the way. Um, you you're using their VPN and, and all the information is protected on their system. And preferably it's encrypted when it's stored, not just when it's sent, like, normally we were thinking, oh, when I send this data on email or me.

It's encrypted end to end, whatever, blah, blah, blah. But also it needs to be stored, encrypted that way. If the laptop something happens, it gets stolen. God forbid, something like that happens, lost whatever. Even if they get the hard drive out, they pull the hard, the hard drive out the computer, and they're trying to get that information it's encrypted so that it's gonna be super hard for them to get that information.

So stored encrypt. Uh, data at rest encrypted data in transit encrypted. That's the level of security that you want if you're traveling, especially if you're traveling abroad. So we talked about privacy and being in a closed environment, but also the encrypt, the security of the actual system itself super important.

Um, those are some of the things you wanna really think. When, if you're talking about traveling abroad, because those things are super important. Another thing is if you do go out, um, you don't want to do your work in public areas. Like this seems obvious, but it's very tempting to be in these beautiful locations and do your work as a cybersecurity person, especially if you're signing, even if you're an administrator and you're signing into a server remotely.

Uh, you, you really gotta be mindful of your environment because you never know who's watching over your shoulder. You never know who's shoulder surfing. You never know who's, who's, uh, monitoring the traffic in, in the, in a public environment, cuz it's legal to do that, to monitor the traffic, any kind of data going, uh, in, on a wifi network and stuff.

Don't do that stuff in public at all. Forget about that. Don't do. So that's just some of the stuff I wanted to talk to you guys about. I mean, other than that, I could tell you about how my trip is going. Right, right now, let me see if I can set up some pictures and stuff. I could sh that I had set up here to show you guys of my trip here and how it's gone.

It's it's been going pretty good. I'm actually already in the works of doing, of getting back into work. Um, I've been doing some interviews here, and this is me, um, uh, with my partner here, we're just walking in this place called, uh, what is it called? Azure. I'm that's where I'm at right now. This is what you're seeing.

It's called Azure, um, Azure residence. It's got like a, a manmade beach area in a like five, three or four pools and, and, uh, it's right by a mall and stuff. It's just a. You know, this job in cybersecurity is very stressful. So right now I'm in between jobs in between work. And, um, I just decided to take some time before myself, before I go back to another job.

Um, one of the things that a lot of people don't talk about. um, they talk about how great it is to be in cyber security and they talk about, you know, but it, it, it's a very, it's a stressful job, especially if you're taking on. Um, if you're taking on very, if you're taking on a high level job, there's a reason why it's high level.

Right. Um, I was doing consulting for about three years and, um, it, it was, it was pretty stressful. Um, on top of that. I had some personal issues and you know, the show must go on. So I was doing, dealing my own personal issues and dealing with work and I have a side hustles and stuff. It just got too much.

And I decided to, to quit now, the job, they offered me a sabbatical. It's really hard to. High level, cyber security people. So they were trying to keep me, and I said, you know, I don't know if I return because I, this there's a lot of travel here. You know, there's a lot of travel and I don't know that my issues are gonna be resolved and I, it's not compatible with, with my new life situation.

So I told him. Opt it out. And they said, well, if you ever wanna come back, you know, just to let us know. And I said, you know, I, I told me, well, thank you. I appreciate the offering. But in my mind, I'm like, I don't think I'll be back because there's too much travel and stuff. I'm, I'm hoping that me telling you guys my situation maybe will help you, you know, and whatever endeavors you have, whatever you decide to do with your, with your life and your situation and stuff like that.

So you have an idea of how this stuff. uh, one of the great things about, about the position I've put myself in by marketing myself and continuously growing in this field is that I is that I, um, I always have job opportunities, so I I'm, I feel okay with this situation that I'm in right now, I was. Save up some, some cash and, um, and, um, I'm not worried about getting a job.

I, I, I know I can get one, so I'm not, I'm not stressed out right now. You know, I'm, I'm on my, my third or fourth interview and, um, and I'm okay because I have so many options and it's a, it is a great feeling to know. I have enough options to where, to where I, you know, I know I'm gonna get a job is just a matter of, of time.

And, and there's nothing for me to stress about. And that's just because I, I have, I've built up certain. I have certain certifications. I position myself with my experience. I'll have my resume constantly being marketed it's out there. So I have people contacting me on Monday through Friday, I'm doing interviews, doing screen.

And stuff like that. So that's kind of where I'm at. That's what I'm doing here. I got about four or five more days left, and then I'm going back, going back to, um, let me see if I could find another video for, for those people who are watching this video. Um, yeah, I'm going back to go back to work here real soon.

Um, am I excited about it? I've been doing this for 20 years. You know, my excitement for. For this is, is not what it used to be. You know what I mean? Like it would take a lot for me to be excited about a new position at this point in my career. Um, maybe I'll find something that I'm excited about. There's been a couple that I'm like, Hmm, this seems interesting.

There's been a couple, you know, that I'm like, I hope I get this job. And so I, yeah, there's, it depends on the job, but there's a couple positions. I'm like, oh man, I don't know if I want this. That happens from time to time. I know I can do it. I know I'm qualified for this job, but I'm, I'm like, damn, I don't know if I want this.

I don't know if I want it. So, uh, there's about three companies right now that I'm in the works that I might, that, um, that I might get one of, either one of these positions right here that. that I might get. I, I don't know yet, you know, but they're all risk management framework type positions. I've decided to get back into that.

I had a few options. I could probably go into either seeing technology or I can go into cyber security, uh, analyst work again, which was fun, but I kind of, kind of want to get back into my roots was just information system, security officer work. So that's kind of what I'm where I'm at right now and what I'm doing.

and, um, I should have a job I'm expecting to have something lined up by, by the time I, uh, get home, I should have something lined up. So probably when within another week I'll have something, um, something that I can do. But, like I said, I'm not even if it, if I can't get one within the next, I'm trying to find another video here while we're talking, even if I can't find another video within the next.

Um, so another video , even if I can't find another job within the next, um, Couple few weeks. I'll be, I'll be okay. You know? So the way I position myself, I'm, I'll be fine. Right. My me and my family will be fine. The, the one thing that, that really hit me hard is that seems have gotten much, much worse, has been the medical.

I, I don't have good medical insurance. So my insurance at my last job was really, really good. And now I'm like having to just. Use this second hand individual insurance that barely covers anything. And I am spending probably a, a, a cool $1,500 a month pull with everything and I have insurance. It's ridiculous.

I had no idea how broken this system is in the us. It's it's very broken. It's so bad that me coming here spending all the money. I. And getting medical insurance here getting medical coverage. And like my, I check in my eyes check and stuff. It's cheaper than me doing anything in the us. Um, it, it, it's, it's just sad.

Like what the state of the us is, um, situation is, is actually is it's quite, um, alarming how bad it is and, and there's no intention. There's no intention to do anything about it. so yeah, insurance is, is it's it's, it's a disaster, man. If there's anything that's driving me to get this job faster, it's that?

Because the I've got two kids and you know, they're in and out of, in and out of medical, you know how Calvin kids is. I don't know if you know, if you have kids, you know, I'm talking about it, stuff happens. So they're in and out of getting treat, getting checked out and stuff like that. So, and it's not cheap at all.

So, yeah, that's what I'm doing. Just kind of giving you guys an update on what's going on with me. Um, I'm doing right. Um, still helping as many people as I can, as far as getting work and stuff. Um, I'm gonna end this one here real soon. I'm gonna put out much more information on, on podcasts, much more podcasts.

I just have to set up the right site for it. I think maybe if I put 'em on the site that my, my normal blog site, maybe, I don't know. We'll figure it out. Thanks. Thanks for watching guys. Thanks for listening. I appreciate everybody. If you have any questions, comments, or concerns, please hit me up on YouTube.

Uh, comment, email me, whatever there are topics we can always cover, but I will catch you guys on the next one.

View Details

I was in the Philippines from June to part of August.

We talk about:

  • Remote Working
  • Countries I have worked in
  • ITAR and the countries you cannot work in
  • the new book about NIST 800-53 controls: https://securitycompliance.thinkific.com/courses/rmf-isso-controls-audiobook

Hey guys, this is Bruce, and welcome to concourses. I'm gonna be talking to you about my travels. I'm actually still abroad. I'm still in the Philippines and I actually going back home real soon. So you can expect regular podcasts like we've been doing before, but I wanted to go ahead and start doing these more often.

And I wanna start off by letting you guys know. I just released a few more products out there. So if you go to combo courses.com. I am writing a book about getting jobs in, um, in information technology and in cyber security and marketing those, uh, resumes that you put out, I'm gonna teach you how to create the resume from scratch and then how to promote the hell outta that resume.

So that is incoming. I'm doing that right now as we speak right in it. But if you want to get in early on this book, there it is right there. Uh, and that as soon as the. Is out I'll, I'll release it to you so you can actually pre-order it. Now I also am selling the audio version of the last two books that I wrote on my website, but you can also get 'em on audible as well.

And yeah. So speaking of that, The audible version of the NIST 800-53. If you prefer to use audible, if you have credits on audible, whatever, if you actually want to get a free trial on Audible, you can actually get this book for free on audible. So go ahead and check those things out and I'll be releasing a lot more and creating a lot more content for you guys.

But let's get into this one. I wanted to talk a little bit about this. And how you can do this. And just trying to tell you my experience. So you can get some idea of if, if, whether or not you actually wanna do this. I've first of all, I've been working remotely for, uh, past six years now, um, with different jobs.

Like I, this is my third, my last job was my third job that I did remotely. I worked for NASA remotely with a company, and then I, I worked, um, at Ball Aero. For a while remotely and, and then recently worked with Verizon remotely. And, um, there's a lot nowadays, there's a lot more remote jobs out there. So if you want the opportunity to actually do what I'm doing, it's much easier to do this now.

Um, my experience with RO work and remotely has been incredible. I've really enjoyed. Um, it's given me more time to spend with people who I love, um, I'm at home, so I can actually interact with them and figure out problems together with them and have more family time and things like that. Um, so those are the pros with it.

Some of the cons is if you have small kids, it's much harder to do remote work when you have small kids, or if you have somebody who's very needy it because it's hard to actually do your work with that. Um, and I've been in that situation where. Actually difficult. I had a remote job when my kids were really small and they, as soon as they see me, they wanna play, you know, so it wasn't the ideal, uh, situation when my kids were small, but now they're older, so they understand, Hey, dad's gotta work.

You know, and I have a, a place in my house where I can go and stuff like that. Um, another thing is that I have to actually have more discipline on stopping my work. Like you might think it. It is the opposite that you, it's hard to actually get to work for me. It's the opposite. It's hard to stop working.

I tend to just continuously work when I work from home and I gotta actually stop myself and have the discipline to say, okay, that's it. This project, the rest of this project and work till, wait till tomorrow. I'll I'll get to it then. Having that discipline is really important. Um, the self-discipline to actually not only do the work, but also stop yourself and have a schedule where you.

Force yourself to, um, not overwork. Um, so that that's some of the pros and cons of working remotely. Now, as far as what I'm doing now, what I'm doing right now is I'm actually in between jobs. I'm not working remotely, I'm working remotely on my own stuff, on my own business and I'm writing and stuff like that.

So you could include that as work remotely, but what we're talking about specifically is working for an employer. , you know, whether it's the government or private sector or whatever bank, whatever you're working for. Um, I'm not doing that right now. Right now. I'm abroad and I'm having a vacation and I do any work I'm doing is all, uh, business related.

But I, I have been here before in the Philippines and worked in other countries, Thailand and Vietnam and other countries worked actually working for an employer remote. and there are some challenges to this. If, if this is something that you, you aspire to do, there are some challenges that you should know about.

Um, number one I would say is just because your employer is allowing you, it, it, it has it on the dockets to work remotely. Doesn't mean they allow you to work in another. And what I mean by that is there's laws. There's rules. One is called I a R, which will pro will restrict you from taking their laptop and their information outside of a country.

And in sometimes in some cases they have a policy where you can't even take the, their. Do equipment out of the state and they don't expect you to work outside of the state, but country is a lot more, um, happens a lot more often where they don't allow you to work outside of the state. I mean, I'm sorry, out of the country.

And, and in sometimes it's just, it's not that they don't want you to work outside of the country. It's more like there's certain countries they don't allow you to and you've gotta make sure whatever. you you've gotta use strategy. Like if you're trying to live in say the Philippines and you know, you want to get a USA job or a job in Canada or wherever the case may be, you know, this is what you wanna do.

You have to think about it. Um, will this job allow me to work in another country? Okay. What countries can I work in the way that I've done it? Is whenever I get into a company, right? I'm I'm looking at their rules. I'm looking at what are their rules for remote work? Do they even allow, is it flex time where they want you to come in?

Once a week or something, is there travel? Is there, I'm looking at all the avenues of what I can do and what kind of information that we're gonna be processing. Cause that's another important feature when you're first looking at a remote job, uh, because if they're doing classified or any kind of super sensitive information, uh, more than likely it's, you're not gonna even be able to leave the, the state or the area.

Uh, and you have to, it'll be flex work, meaning you'll work from home, but then they want you to come in the office. If you're doing some kind of sensitive, really, really sensitive information. So that's one thing. Another thing I'll look at is, is the environment. Um, some organizations, especially private organizations are a little bit more, um, open about remote work.

They'll actually have like the last place I worked. We had people working in Japan. Like we had one guy working in Japan, doing work on for our clients and stuff like that. And we had another person who was working overseas in south America. uh, who we had clients in south America. We had clients, we had people in Europe doing work with those clients.

We had people in Australia, we had people all over the world doing it. So the job lended itself to working internationally, cuz we had people who were actually working internationally. So that was that. Wasn't another thing I look at, like what's the environment. A lot of, uh, government jobs. They're very stable.

They allow remote work, but they're usually like flex jobs. They want you to still come in and stuff like that once a week or something. And then they have like a little bit of travel. So you gotta watch that private companies a little bit more flexible. So you wanna look at the environment. . Um, so those are some of the things that I, that I normally look at when I'm trying to think about strategy of what do I want, what country do I want to live in, will this organization that I'm applying for allow that those are the things you gotta now, once you get in, let's say you get a remote job, you're there.

Um, it's a great job. They're paying you. Good. All that kind of stuff. Now you're like, Hmm, can I travel? Uh, Venezuela Brazil, wherever Cambodia, wherever it is. Can I go there now? It's a matter of their policy right now. You know, that they're remote and all that stuff. You know that they're, it's okay. Maybe to travel, uh, internationally.

They haven't restricted you from that. Um, you've got your VPN, you got your protection on your system, all that kind of stuff. Now you're like, okay, the next question should be what other. because some organizations will not allow you to go to certain countries and that's, it's tied to something called I a R and it's I don't remember what the actual acronym is.

It's and let me actually, let me look it up while I'm talking to you, you gotta look at the actual policies because that is super important. Um, you don't want to get caught, uh, traveling to some country you're not actually supposed to go to. And the, the company is obligated not to go to those countries.

Like legally you're not supposed to here. It's called it a international traffic in arms regulations, like arms you're thinking like guns and stuff like that. But, um, they're also talking about certain technologies that are wrapped into this, uh, into this. That the government has certain things that they do not allow com us companies to go to certain countries.

The reason why is because they, that that country might steal their, the intellectual property of that organization. A good example of this would be, um, companies like Lockheed Martin, who. military, um, different military components. There's certain components that are proprietary and owned by the government.

That if it, you go to that other country and that country is spying or actively stealing anything on and off their network, uh, That's really bad encrypted or not they'll they can steal it and encrypted for later or something like that. Um, and that actually does happen quite a bit. Um, especially with the bigger countries, like China's doing that a lot.

And I, I don't doubt that us is doing that China and Russia is doing, they're doing all these major powers or doing that to one another. The point is though, from our perspective as workers, we just wanna make sure that we are. Gonna get caught, violating these laws and, and worse, uh, leak some information from clients and jeopardize our entire career based off some international, uh, incident, you know, like you don't want to be that guy it's just too risky.

So we talked a little bit about knowing the environment for that remote company, uh, knowing the policies is another thing that's huge and. um, also making sure you don't violate any kind of laws that that company has. And that's normally tied into the policies. Now, one of the things that I did at the last place I worked at was I just asked, I said, Hey, are there any, what can you send me the laws of travel?

Like I wanna, I'm trying to travel. I didn't even go into details of that. I just say, Hey, can you send me the laws I read 'em myself. I'm not gonna ask permission and then get denied. Right? I'm just gonna. and make sure I don't violate any major laws and then ask forgiveness. If they're like, Hey, you're you're in another time zone.

They won't even know I'm in another time zone, cuz I'm not gonna let them, I'm gonna be on the same. I'm not gonna violate any of their policies. I'm not gonna violate any kind of international laws are unit us national laws or anything like that. Um, so all of that stuff is good, but what I'll. is make sure that I don't violate their, you know, I'm still on Eastern standard time or whatever the timeframe is.

So they don't even know I'm gone. Like I, I even travel sometimes I'll take, leave enough to travel to that other country. And then on Monday, Tuesday, when I'm supposed to go back to work, I'm bright and early working my nine to five. You. So that's some of the stuff I do. Um, I'm, I'm risk averse. Um, I manage my risk very effectively when I'm working for, for an organization.

I do not violate their rules. I do not. I just feel like the risk is too great for me. And that's kind of the mindset that you should have. I've not I've yet to be in trouble for traveling or anything. They don't even know I'm gone. I'm I'm doing everything I'm supposed to do now. Another. That you should think about when you're travel, when you're doing remote work and you're traveling, even if it's a staycation in another state, nevermind another country.

One of the things you should keep in mind is there's a few things. You, you need a place that's quiet. Uh, like right now I'm in this room here. It's, it's very quiet. It's very, um, there. I, I don't hear a lot of noise going on outside, but I've been in some places, especially in Southeast Asia where the noise level is super loud.

Like I was in Vietnam, the noise level was so loud. Like it, it, privacy was fine. I could just go inside of my room or whatever and, and shut the door, lock the door, whatever. Right. And had encryption, all that kind of stuff. But man, the noise pollution outside was seeping into the room. So you wanna have a place where you.

it's closed. You have privacy because especially if you're dealing with secret in not secret information, if you're dealing with, um, sensitive information from a client like vulnerabilities or IPS, you have to have privacy and you're talking on the phone, right? I'll get to the encryption and all that kind of stuff in a second.

But I'm talking about privacy. Like you're on the phone talking to somebody, talking to your boss, talking to peers, talking to the client, the customer, whatever. And you might be talking about some sensitive information on the phone. So you want privacy, a room where it's not leaked the information not leaking out, but also that room gives you quiet where you can actually speak to them and, and have a conversation cuz conversation, you know, The communication is huge.

That's a big deal, uh, in cyber security. So you need a, a private space, the other thing, and that's pretty obvious, but the other thing is security. Um, whatever system you're on, you need to ha make sure you have firewalls in place, antivirus in place, and a VPN virtual private network either built in from the organization.

Preferably. So that it's their level of encryption and you don't have to worry about, uh, some private organization's encryption getting, getting compromised or something, which does happen by the way. Um, you you're using their VPN and, and all the information is protected on their system. And preferably it's encrypted when it's stored, not just when it's sent, like, normally we were thinking, oh, when I send this data on email or me.

It's encrypted end to end, whatever, blah, blah, blah. But also it needs to be stored, encrypted that way. If the laptop something happens, it gets stolen. God forbid, something like that happens, lost whatever. Even if they get the hard drive out, they pull the hard, the hard drive out the computer, and they're trying to get that information it's encrypted so that it's gonna be super hard for them to get that information.

So stored encrypt. Uh, data at rest encrypted data in transit encrypted. That's the level of security that you want if you're traveling, especially if you're traveling abroad. So we talked about privacy and being in a closed environment, but also the encrypt, the security of the actual system itself super important.

Um, those are some of the things you wanna really think. When, if you're talking about traveling abroad, because those things are super important. Another thing is if you do go out, um, you don't want to do your work in public areas. Like this seems obvious, but it's very tempting to be in these beautiful locations and do your work as a cybersecurity person, especially if you're signing, even if you're an administrator and you're signing into a server remotely.

Uh, you, you really gotta be mindful of your environment because you never know who's watching over your shoulder. You never know who's shoulder surfing. You never know who's, who's, uh, monitoring the traffic in, in the, in a public environment, cuz it's legal to do that, to monitor the traffic, any kind of data going, uh, in, on a wifi network and stuff.

Don't do that stuff in public at all. Forget about that. Don't do. So that's just some of the stuff I wanted to talk to you guys about. I mean, other than that, I could tell you about how my trip is going. Right, right now, let me see if I can set up some pictures and stuff. I could sh that I had set up here to show you guys of my trip here and how it's gone.

It's it's been going pretty good. I'm actually already in the works of doing, of getting back into work. Um, I've been doing some interviews here, and this is me, um, uh, with my partner here, we're just walking in this place called, uh, what is it called? Azure. I'm that's where I'm at right now. This is what you're seeing.

It's called Azure, um, Azure residence. It's got like a, a manmade beach area in a like five, three or four pools and, and, uh, it's right by a mall and stuff. It's just a. You know, this job in cybersecurity is very stressful. So right now I'm in between jobs in between work. And, um, I just decided to take some time before myself, before I go back to another job.

Um, one of the things that a lot of people don't talk about. um, they talk about how great it is to be in cyber security and they talk about, you know, but it, it, it's a very, it's a stressful job, especially if you're taking on. Um, if you're taking on very, if you're taking on a high level job, there's a reason why it's high level.

Right. Um, I was doing consulting for about three years and, um, it, it was, it was pretty stressful. Um, on top of that. I had some personal issues and you know, the show must go on. So I was doing, dealing my own personal issues and dealing with work and I have a side hustles and stuff. It just got too much.

And I decided to, to quit now, the job, they offered me a sabbatical. It's really hard to. High level, cyber security people. So they were trying to keep me, and I said, you know, I don't know if I return because I, this there's a lot of travel here. You know, there's a lot of travel and I don't know that my issues are gonna be resolved and I, it's not compatible with, with my new life situation.

So I told him. Opt it out. And they said, well, if you ever wanna come back, you know, just to let us know. And I said, you know, I, I told me, well, thank you. I appreciate the offering. But in my mind, I'm like, I don't think I'll be back because there's too much travel and stuff. I'm, I'm hoping that me telling you guys my situation maybe will help you, you know, and whatever endeavors you have, whatever you decide to do with your, with your life and your situation and stuff like that.

So you have an idea of how this stuff. uh, one of the great things about, about the position I've put myself in by marketing myself and continuously growing in this field is that I is that I, um, I always have job opportunities, so I I'm, I feel okay with this situation that I'm in right now, I was. Save up some, some cash and, um, and, um, I'm not worried about getting a job.

I, I, I know I can get one, so I'm not, I'm not stressed out right now. You know, I'm, I'm on my, my third or fourth interview and, um, and I'm okay because I have so many options and it's a, it is a great feeling to know. I have enough options to where, to where I, you know, I know I'm gonna get a job is just a matter of, of time.

And, and there's nothing for me to stress about. And that's just because I, I have, I've built up certain. I have certain certifications. I position myself with my experience. I'll have my resume constantly being marketed it's out there. So I have people contacting me on Monday through Friday, I'm doing interviews, doing screen.

And stuff like that. So that's kind of where I'm at. That's what I'm doing here. I got about four or five more days left, and then I'm going back, going back to, um, let me see if I could find another video for, for those people who are watching this video. Um, yeah, I'm going back to go back to work here real soon.

Um, am I excited about it? I've been doing this for 20 years. You know, my excitement for. For this is, is not what it used to be. You know what I mean? Like it would take a lot for me to be excited about a new position at this point in my career. Um, maybe I'll find something that I'm excited about. There's been a couple that I'm like, Hmm, this seems interesting.

There's been a couple, you know, that I'm like, I hope I get this job. And so I, yeah, there's, it depends on the job, but there's a couple positions. I'm like, oh man, I don't know if I want this. That happens from time to time. I know I can do it. I know I'm qualified for this job, but I'm, I'm like, damn, I don't know if I want this.

I don't know if I want it. So, uh, there's about three companies right now that I'm in the works that I might, that, um, that I might get one of, either one of these positions right here that. that I might get. I, I don't know yet, you know, but they're all risk management framework type positions. I've decided to get back into that.

I had a few options. I could probably go into either seeing technology or I can go into cyber security, uh, analyst work again, which was fun, but I kind of, kind of want to get back into my roots was just information system, security officer work. So that's kind of what I'm where I'm at right now and what I'm doing.

and, um, I should have a job I'm expecting to have something lined up by, by the time I, uh, get home, I should have something lined up. So probably when within another week I'll have something, um, something that I can do. But, like I said, I'm not even if it, if I can't get one within the next, I'm trying to find another video here while we're talking, even if I can't find another video within the next.

Um, so another video , even if I can't find another job within the next, um, Couple few weeks. I'll be, I'll be okay. You know? So the way I position myself, I'm, I'll be fine. Right. My me and my family will be fine. The, the one thing that, that really hit me hard is that seems have gotten much, much worse, has been the medical.

I, I don't have good medical insurance. So my insurance at my last job was really, really good. And now I'm like having to just. Use this second hand individual insurance that barely covers anything. And I am spending probably a, a, a cool $1,500 a month pull with everything and I have insurance. It's ridiculous.

I had no idea how broken this system is in the us. It's it's very broken. It's so bad that me coming here spending all the money. I. And getting medical insurance here getting medical coverage. And like my, I check in my eyes check and stuff. It's cheaper than me doing anything in the us. Um, it, it, it's, it's just sad.

Like what the state of the us is, um, situation is, is actually is it's quite, um, alarming how bad it is and, and there's no intention. There's no intention to do anything about it. so yeah, insurance is, is it's it's, it's a disaster, man. If there's anything that's driving me to get this job faster, it's that?

Because the I've got two kids and you know, they're in and out of, in and out of medical, you know how Calvin kids is. I don't know if you know, if you have kids, you know, I'm talking about it, stuff happens. So they're in and out of getting treat, getting checked out and stuff like that. So, and it's not cheap at all.

So, yeah, that's what I'm doing. Just kind of giving you guys an update on what's going on with me. Um, I'm doing right. Um, still helping as many people as I can, as far as getting work and stuff. Um, I'm gonna end this one here real soon. I'm gonna put out much more information on, on podcasts, much more podcasts.

I just have to set up the right site for it. I think maybe if I put 'em on the site that my, my normal blog site, maybe, I don't know. We'll figure it out. Thanks. Thanks for watching guys. Thanks for listening. I appreciate everybody. If you have any questions, comments, or concerns, please hit me up on YouTube.

Uh, comment, email me, whatever there are topics we can always cover, but I will catch you guys on the next one.

View Details

Sign up for free courses! http://convocourses.com

This is a live podcast from my travels in the Philippines. I answer some questions that I go on TikTok.

0:00 - Differences between NOC and SOC 10:40 - Go From NOC to a SOC 11:52 - How to Tailor Security Controls in NIST 800 24:36 - Certification should Match your Role 26:28 - Cybersecurity is about taking care of others 32:00 - Being Underpaid in information security 34:57 - Cybersecurity guys have crazy hustle 43:29 - Skills you gain as an ISSO 47:47 - When to Add Skills to Your Resume 53:18 - Asking for a raise as a cyber security 57:00 - information security and my remote opportunity 59:07 - cybersecurity tools and information security 01:02:49 - GRC tools xacta emass archer 01:06:16 - Helping cybersecurity people and risk assessments Check us out here: http://www.nist80037rmf.com/ http://instagram.com/convocourses https://www.facebook.com/ConvoCourses... https://www.linkedin.com/in/convocour... Podcasts / downloadable mp3: http://www.nist80037rmf.com/convocour... https://podcasts.apple.com/us/podcast... http://www.nist80037rmf.com/category/... #convocourses #cybersecurity #isso #nistrmf #rmf #usajobs #itjobs

View Details

Sign up for free courses! http://convocourses.com

This is a live podcast from my travels in the Philippines. I answer some questions that I go on TikTok.

0:00 - Differences between NOC and SOC 10:40 - Go From NOC to a SOC 11:52 - How to Tailor Security Controls in NIST 800 24:36 - Certification should Match your Role 26:28 - Cybersecurity is about taking care of others 32:00 - Being Underpaid in information security 34:57 - Cybersecurity guys have crazy hustle 43:29 - Skills you gain as an ISSO 47:47 - When to Add Skills to Your Resume 53:18 - Asking for a raise as a cyber security 57:00 - information security and my remote opportunity 59:07 - cybersecurity tools and information security 01:02:49 - GRC tools xacta emass archer 01:06:16 - Helping cybersecurity people and risk assessments Check us out here: http://www.nist80037rmf.com/ http://instagram.com/convocourses https://www.facebook.com/ConvoCourses... https://www.linkedin.com/in/convocour... Podcasts / downloadable mp3: http://www.nist80037rmf.com/convocour... https://podcasts.apple.com/us/podcast... http://www.nist80037rmf.com/category/... #convocourses #cybersecurity #isso #nistrmf #rmf #usajobs #itjobs

View Details

0:00 Convocourses page 0:59 Start of Convocourses podcast 2:47 Every ISSO Needs to Know this 37:06 Entry Level Cybersecurity What You Should Know 47:00 Types of IT Jobs for Remote Work 51:35 Military ISSO to Civilian ISSO 01:04:05 Videos about SCA work 01:08:40 PCI DSS work my opinion 01:15:34 States to find ISSO RMF jobs […]

View Details

RMF ISSO Assignment https://securitycompliance.thinkific.com/courses/rmf-isso-assignments-101 https://securitycompliance.thinkific.com/courses/cybersecurity check out our courses at: http://convocourses.com 0:00 Convocourses screen 4:29 Convocoures Big Thank you 6:11 Free Training on NIST 800-37 on Convocourses 8:11 New to the ISSO no technical background Where do I get training 19:11 CISSO vs ISSO RMF convoCourses 31:49 Have I Ever Resubmitted a Resume I have […]

View Details

check out: http://convocourses.com​ 0:00​ ISSO Therapy Session 14:38​ Things to read for Risk Management Framework 23:37​ How to Get a Security Clearance? 33:01​ Do I Need a Prestigious University for Cybersecurity? 43:24​ Why I don’t take calls as a mentor? 44:57​ Advice for a new SCA (Security Control Assessor) 49:31​ Cybersecurity Resume Tips for Security […]

View Details

There are privacy controls within the NIST RMF 800: NIST Privacy Controls:

View Details

Sign up for free courses! http://convocourses.com 0:00 Start Page Convocourses 0:55 Earn CEUs CPEs on ConvoCourses 9:43 Failed the ISC2 CAP 22:25 Continous Monitoring in the Course 29:57 College Lab work on Resume 34:44 Separation of Duties with one person (ISSO) 40:08 Implementation of security controls resources (part 1) 49:33 Implementation of security controls resources […]

View Details

There are some updates to the RMF Courses and many more to come. 0:00​ blank intro 0:40​ Start of convocourse podcast 1:43​ Helping with Master Degree on Nist RMF 2:38​ Complete Course of NIST RMF 5:45​ RMF NIST Course as an Audio file 7:40​ RMF NIST Security Control Interpretation 11:40​ ISSO lean to Support the […]

View Details

I often get questions from other professionals on how they can get into Cybersecurity. There are a few things that you can do to start. For one thing, start where you are. If you work in a company ask the resident IT guy what the career is like. Another thing to consider is IT adjacent […]

View Details

On this podcast we discuss the following: 0:00 blank intro 0:40 Start of convocourse podcast 1:43 Helping with Master Degree on Nist RMF 2:38 Complete Course of NIST RMF 5:45 RMF NIST Course as an Audio file 7:40 RMF NIST Security Control Interpretation 11:40 ISSO lean to Support the team 15:52 Cannot get an ISSO […]

View Details

In this podcast we address what needs to go into a resume if you are trying to transition from your current career field to IT and/or cybersecurity. https://youtu.be/Fjc18455ygI