cyber security salary

jdchathuranga

Well-known member
  • May 4, 2009
    568
    1,348
    93
    37
    Colombo
    Mage opinion eka, lankawe cyber security kiyala karana job athatama cyber security newi. But intern gihin basic dewal tikak igena ganna puluwan.
    not really
    there are some companies that has dedicated security teams.
    example wso2, sysco labs… etc
    some of the wso2 products needs to be highly secure and they have dedicated security teams. (i have personally worked with some of the members in thir security team)
     

    tharakaf

    Well-known member
  • Oct 19, 2020
    34,960
    71,197
    113
    not really
    there are some companies that has dedicated security teams.
    example wso2, sysco labs… etc
    some of the wso2 products needs to be highly secure and they have dedicated security teams. (i have personally worked with some of the members in thir security team)
    Not all companies have. That is what I meant. If you are doing codign you need guys to do code reviews, PTs and shti. But in SL you don't invest in those. In SL cyber security means looking after firewalls/WAFs/proxies and shit :yes: :yes:
     
    • Like
    Reactions: jehantheexplorer

    jdchathuranga

    Well-known member
  • May 4, 2009
    568
    1,348
    93
    37
    Colombo
    Not all companies have. That is what I meant. If you are doing codign you need guys to do code reviews, PTs and shti. But in SL you don't invest in those. In SL cyber security means looking after firewalls/WAFs/proxies and shit :yes: :yes:
    first part is true,only a few companies that has actual security teams in SL

    though opportunities are less, there are companies that are investing in actual security

    also some of the audit companies has skilled security analysts, for an exmple KPMG has a team, they provide certification services like ISO27001 etc, during the process they conduct comprehensive cybersecurity analysis, with practical proofs/threat modeling etc

    firewalls/waf/proxies usually maintained by infrastructures/SRE teams, may be with guidance from security teams.
     

    jehantheexplorer

    Well-known member
  • Apr 25, 2023
    1,470
    1,136
    113
    Cybersec is not security analysis only, there're jobs like vul-research, exploit dev, sec eng and red teaming which require more skill and knowledge. I don't think so 99% of local techies have that kind of knowledge.
     
    Last edited:

    tharakaf

    Well-known member
  • Oct 19, 2020
    34,960
    71,197
    113
    first part is true,only a few companies that has actual security teams in SL

    though opportunities are less, there are companies that are investing in actual security

    also some of the audit companies has skilled security analysts, for an exmple KPMG has a team, they provide certification services like ISO27001 etc, during the process they conduct comprehensive cybersecurity analysis, with practical proofs/threat modeling etc

    firewalls/waf/proxies usually maintained by infrastructures/SRE teams, may be with guidance from security teams.
    Hmm yeah audit firms used to have "job roles" but the skills were questionable. ISO shit is just looking at a checklist and nothing else.

    Cybersec is not security analysis only, there're jobs like vul-research, exploit dev, sec eng and red teaming which require more skill and knowledge. I don't think so 99% of local techies have that kind of knowledge.
    Yeap exactly why I say in SL we don't have a proper field. People don't invest much (but way better than when I started back in 2012) so not a lot of opportunities. But fi you go to SG or mid east you can find a lot of good jobs.
     
    • Like
    Reactions: dirtybutterfly