How Do I Find a Job in Information Security?
Information security has evolved over the last few years into a topic that repeatedly pushes its way into our everyday lives – sometimes in the form of display boards failing due to cryptotrojans, sometimes as a flood of emails with which panicking companies try to obtain our consent for data processing just a day before new data protection regulations come into force. Through security incidents and legislative activity, awareness of the value of information and the dangers it is exposed to in an increasingly networked society is slowly rising for both private individuals and companies, and with it the awareness of the necessity to protect the confidentiality, availability, and integrity of information. This creates ideal conditions for anyone who would like to professionally deal with security-conscious system administration, penetration testing, or IT forensics. Good news regarding salary as well: specialized personnel are in high demand, and sound, well-founded advice is often highly compensated if it promises to save companies from the dreaded GDPR penalties.
But what does the educational path look like for someone aspiring to a superhero career in White Hat Hacking? Or as someone put it on gutefrage.de in 2016: Where do hackers learn to hack?
Classical Educational Paths: Work in Progress
There is no single answer to this. Since the subject matter, at the intersection of information technology and informational self-determination, still has the character of new territory in many respects, the design of special curricula and degrees at many educational institutions is not yet complete. Until now, information security consulting has been carried out mainly by experts from IT and computer science who acquired most of their subject-specific skills and experience „on the job”; for them, numerous lessons were undoubtedly associated with sweat and tears. A search on ZEITCampus in „Germany's most comprehensive degree course database”, which includes both university and technical college degrees, yielded only eight Master's and ten Bachelor's degree programs. For comparison: searching for IT security, a subfield of information security, increases the number of results to 79, while business informatics results in as many as 3,937.
Among the degree programs that have been established, most are located in the department of computer science. In Saarbrücken, Darmstadt, and Karlsruhe, students benefit from the proximity to the local competence and research centers for IT security: CISPA, CRISP, and KASTEL.
More Than a Degree
Given this situation, it is in many cases difficult to prove one's qualifications by presenting a relevant university degree, as is the case in other fields of work. But this doesn't have to be a disadvantage: employers are aware of the educational situation and are therefore tendentially more open to applications with colorful or unconventional resumes: a different degree, a discontinued degree, or no degree at all – as long as there is a solid knowledge base to work with and the right attitude, one should definitely try their luck and apply.
But what is it then that convinces potential employers?
It is the many small achievements that one has worked for because at some point they refused to simply accept the standard configurations of their own devices. It is the simple Python programs they built to handle a tedious everyday task, trying out different Linux distributions more out of curiosity than necessity, playing with web developer tools to peek behind the HTML curtain of the internet. It is the participation in Crypto and Keysigning parties and the standard use of pgp out of the awareness that „But I have nothing to hide!” misses the point. It is the commitment in the local hackspace or makerspace and the pleasure-driven occupation with technology in one's own free time, which creates an understanding of technical contexts in places where university education does not reach.
Conclusion
Everyone who finds themselves in this description (even if not in detail) has long since proven that they possess the curiosity, the creativity, and the comprehension skills that are the key to competence in all areas of information security, a field that is constantly evolving. Attentive employers will grasp this with a glance.
Anyone who is now inspired and would like to apply directly to aramido is welcome to choose a desired position in the job advertisements section and send us the application in a pgp-encrypted email. We look forward to tech-enthusiastic and security-conscious newcomers for our team!
On 03.04.2019 in the category aramido published.

