NetworkNewb wrote: » Ever tried doing bug bounties?? I'm genuinely curious if anyone on here has made decent money doing that as a full or part time job. I keep hearing people can make decent money but feel that is a lot market hype for people to try and sell their books and courses. Seems like it would be a decent thing to try if you know you are going to be moving around a lot though.
0b3lix wrote: » Working remotely for my current employer is unfortunately not an option due to the labour laws in two of the countries. Both my employer and me would've preferred that but unfortunately it wouldn't work legally.
0b3lix wrote: » CREST/CHECK won't be beneficiary as none of the countries is the UK.
0b3lix wrote: » I read up on PCI QSA cause it seemed like a really good idea as there's demand for PCI audits and accompanying pentests everywhere. Turns out though that there are multiple steps in the process of getting and remaining certified that require a primary point of contact in a PCI QSA accredited company. The process does not seem to allow for individuals that want to acquire and maintain their certification independently. Also the obligatory training is 3k USD (VAT not included)... If there was a way for an independent individual to acquire and maintain that status, though, I would actually go for it.
0b3lix wrote: » I had been contemplating the CEH and LPT shortly, but only very shortly. I know it helps with a few HR filters but fortunately wherever a CEH is required usually a CISSP is also accepted. And, though you may call me stupid for that....
0b3lix wrote: » Several posters mentioned that CISA wouldn't exactly help in my situation. Why do you guys think so?
paul78 wrote: » Yah - I was one of them. The CISA is a non-technical cert. It's typically held by auditors who have a risk, governance, and/or compliance background. These are folks generally doing audits like SSAE16/18 which are non-technical audits. ISACA has a version for security professionals called the CISM. But given your interest in pent testing and the fact that you already have a CISSP, I doubt that the CISA or CISM is probably not worthwhile. Unless you just want to do it for fun or you suffer from insomnia. Their material is a great cure for insomnia.