InfoSec and Security - not that glamorus of a field people - Wake up!
Just wanted to say something about the Info sec and the security field as it stands right now and from my observations from the recent threads and posts on this forum. Info-sec and IT Security is not that glamorous of a field - Wake up!
So many posts and threads recently about Info-sec and IT Security, people asking what certs to take, where to start, what materials to read, what tools to use some of these people are completely out of sync with reality, really and seriously! In my honest opinion Info-sec requires years of training and understanding of many different concepts along with a special ability and a nack of IT Security.
People read Info-sec and they see stars or dollar signs depending on the situation. They hear and read Info-sec articles and watch a few movies and their mind goes directly to the "grey hat", "white hat" hackers. They think info-sec is a hacker's competition of some sort.
Info-sec is not hacking people! In fact, you will probably not do any hacking for your company unless you work for a company specializing in pen testing, and even then you will have to write reports, documentations, resolutions and basically still require to write. In info-sec there are so many different job titles and positions all bundled into one word it is not even funny.
To describe the infosec word with an analogy, it is like college football or college basketball. Few make it to the NFL or NBA as players(true infosec people) the rest of us do other things, still relevant and still in info-sec. The lesson, always have a backup plan, don't go all in, many will not make their desired salary, position, title or fame.
It's always funny, when people ask me what my job is and i tell them, i work in IT Security, right away their response is "oh so you know how to hack stuff" and my answer is "No i don't, but even if i did, i wouldn't tell anyone" and then i finish with " Nah, I work on the governance side of IT security, I just look at reports" And then you see the disappointment on their face.
So seriously, wake up, info-sec is not all about testing code, patching vulnerabilities and responding to security incidents. Before you claim to want to get into info-sec do something else IT related, it probably falls within info-sec too.