SlideShare a Scribd company logo
Analyst, Engineer or Consultant?
DOES IT EVEN MATTER?
Harry McLaren
• Alumnus of Napier University
• Managing Consultant at ECS [Security]
• Splunk Enablement Lead, Engineer & Architect
• Previous Roles:
• Security Engineer, SOC Analyst, IT Technician
@cyberharibu
Disclaimer
• I’m Dangerous
• [A little] knowledge is powerful right?
• I’m speaking for me, not my employer.
• These are thoughts, not facts.
Coming Up
• Starting Out in Cybersecurity
• Security Domains & Roles
• Personal Journey
• Foundational Knowledge & Skills
• Interviewing Tips
• Tips for ”Professionals”
• Resources
~35mins
Who’s Here?
Aspiring, Current, Former
Professional
Starting Out in Cybersecurity
Initial Career
•Degree
Education
•Collage
Education
•Other Routes
[Rare]
Career Move
•Business
Skills
•Soft[er]
Skills
•Formal
Education
IT Professional
•Transferable
Skills
•Transferable
Experience
•Formal
Education
Security Domains (ISC2 CBK)
•Security and
Risk
Management
•Asset Security
•Security
Engineering
•Communications
and Network
Security
•Identity and
Access
Management
•Security
Assessment and
Testing
•Security
Operations
•Software
Development
Security Primary Experience
Secondary Experience
Security Operations Roles
Tier 1/2
Support
Analyst
Security
Analyst
Expert
Security
Analyst
Tier 2/3
Incident
Investigator
Threat
Hunter
SOC
Consultant
Management
Shift Leader
Incident
Manager
SOC
Manager
Security Engineering Roles
Build
Associate Security
Engineer/Consultant
Security
Engineer/Consultant
Lead
Specialist Security
Engineer
Consulting Security
Engineer
Manage
Managing
Consultant
Principal Security
Engineer
Personal Journey
Consultant
Engineer
Analyst
• IT Technician (2006)
• Desktop Support (2011)
• Senior Security Analyst (2013)
• Security Engineer (2014)
• Security Consultant (2016)
• Senior Consultant (2017)
• Managing Consultant (2018)
Emotional Journey
In Denial /
Imposter
Terrified
Scared
Foundational Knowledge & Skills
Technical Competence/Experience
Communication Skills
Interpersonal Awareness
Interviewing Tips
• CV (2-3 Pages, Clear, Concise, Skills, Community, Basics)
• Preparation (Research, Interviewers, Arrival)
• Situation, Task, Action, Result (STAR for Competency Questions)
• During (Breathe, Vocalise, Water, Questions)
• After (Relax, Review, Repeat)
Embrace
Change
Manage
Expectations
Promote
[Safe] Failure
Share the
Fear
Tips for ”Professionals”
Resources
• Meetups
• Splunk User Group Edinburgh
• Security MeetUp Scotland
• Cyber Scotland Connect
• The Cyber Academy
• ENU Security Society at Edinburgh Napier
• Sigint Security Society at the University of Edinburgh
• ISC2 Scottish Chapter
• 2600 Edinburgh
• ISACA Scottish Chapter
• OWASP Scotland
OWASP - Analyst, Engineer or Consultant?

More Related Content

PDF
Most Important steps to become a hacker
PPTX
Information technology
PPTX
Tips to kick-start your Software Engineering Career - Ferdous Mahmud Shaon
PDF
Tips to Kick-start your Software Engineering Career
PDF
2016 Hour of Code
PPTX
Cyber Scotland Connect: Getting into Cybersecurity (Deck 2)
PDF
CNIT 160 4d Security Program Management (Part 4)
PPTX
Cyber Scotland Connect: What is Security Engineering?
Most Important steps to become a hacker
Information technology
Tips to kick-start your Software Engineering Career - Ferdous Mahmud Shaon
Tips to Kick-start your Software Engineering Career
2016 Hour of Code
Cyber Scotland Connect: Getting into Cybersecurity (Deck 2)
CNIT 160 4d Security Program Management (Part 4)
Cyber Scotland Connect: What is Security Engineering?

Similar to OWASP - Analyst, Engineer or Consultant? (20)

PDF
CNIT 160 4d Security Program Management (Part 4)
PDF
What type of training is required for cyber security.pdf
PDF
March 2014 B2B - Breaking into info sec
PDF
Rothke stimulating your career as an information security professional
PPTX
cybersecurity analyst.pptx
PPTX
Cyber Ranges: A New Approach to Security
PPTX
Career In Information security
PDF
WTF is Penetration Testing
PPTX
Cyber Security Full Course 2023
PDF
Careers in Cyber Security
PPTX
FIVE TOP CYBER SECURITY CERTIFICATION.pptx
PDF
Skill Set Needed to work successfully in a SOC
PDF
Professional and Technology Services
PPTX
Cyber Scotland Connect: Getting into Cybersecurity (Deck 1)
PPTX
2021 BSides Tampa Cyber Security Careers
PDF
InfosecTrain_Certified_Information_Systems_Auditor_CISA_Course_Content.pdf
PPTX
Cybersecurity and the future of work Securing Remote workforces in 2024 and b...
PDF
DevOpsDaysRiga 2018: Joep Piscaer - Reducing inertia with Public Cloud and Op...
PDF
Reducing inertia in organizations is the key to a successful DevOps transition
PPTX
How To Become An IT Security Risk Analyst
CNIT 160 4d Security Program Management (Part 4)
What type of training is required for cyber security.pdf
March 2014 B2B - Breaking into info sec
Rothke stimulating your career as an information security professional
cybersecurity analyst.pptx
Cyber Ranges: A New Approach to Security
Career In Information security
WTF is Penetration Testing
Cyber Security Full Course 2023
Careers in Cyber Security
FIVE TOP CYBER SECURITY CERTIFICATION.pptx
Skill Set Needed to work successfully in a SOC
Professional and Technology Services
Cyber Scotland Connect: Getting into Cybersecurity (Deck 1)
2021 BSides Tampa Cyber Security Careers
InfosecTrain_Certified_Information_Systems_Auditor_CISA_Course_Content.pdf
Cybersecurity and the future of work Securing Remote workforces in 2024 and b...
DevOpsDaysRiga 2018: Joep Piscaer - Reducing inertia with Public Cloud and Op...
Reducing inertia in organizations is the key to a successful DevOps transition
How To Become An IT Security Risk Analyst
Ad

More from Harry McLaren (20)

PPTX
Security Operations, MITRE ATT&CK, SOC Roles / Competencies
PPTX
Modern Security Operations & Common Roles/Competencies
PPTX
Becoming a Defender (Blue Teams FTW!)
PPTX
Virtual Splunk User Group - Phantom Workbook Automation & Threat Hunting with...
PPTX
SOC Fundamental Roles & Skills
PPTX
Hunting Hard & Failing Fast (ScotSoft 2019)
PPTX
Splunk Phantom, the Endpoint Data Model & Splunk Security Essentials App!
PPTX
Collecting AWS Logs & Introducing Splunk New S3 Compatible Storage (SmartStore)
PPTX
Using Metrics for Fun, Developing with the KV Store + Javascript & News from ...
PPTX
Splunk .conf18 Updates, Config Add-on, SplDevOps
PPTX
SplDevOps: Making Splunk Development a Breeze With a Deep Dive on DevOps' Con...
PPTX
Lessons on Human Vulnerability within InfoSec/Cyber
PPTX
Big Data For Threat Detection & Response
PPTX
TSTAS, the Life of a Splunk Trainer and using DevOps in Splunk Development
PPTX
Cyber Scotland Connect: Welcome & Purpose Statement
PPTX
Latest Updates to Splunk from .conf 2017 Announcements
PPTX
Securing the Enterprise/Cloud with Splunk at the Centre
PPTX
Security Meetup Scotland - August 2017 (Deconstructing SIEM)
PPTX
Deconstructing SIEM
PPTX
Supporting Splunk at Scale, Splunking at Home & Introduction to Enterprise Se...
Security Operations, MITRE ATT&CK, SOC Roles / Competencies
Modern Security Operations & Common Roles/Competencies
Becoming a Defender (Blue Teams FTW!)
Virtual Splunk User Group - Phantom Workbook Automation & Threat Hunting with...
SOC Fundamental Roles & Skills
Hunting Hard & Failing Fast (ScotSoft 2019)
Splunk Phantom, the Endpoint Data Model & Splunk Security Essentials App!
Collecting AWS Logs & Introducing Splunk New S3 Compatible Storage (SmartStore)
Using Metrics for Fun, Developing with the KV Store + Javascript & News from ...
Splunk .conf18 Updates, Config Add-on, SplDevOps
SplDevOps: Making Splunk Development a Breeze With a Deep Dive on DevOps' Con...
Lessons on Human Vulnerability within InfoSec/Cyber
Big Data For Threat Detection & Response
TSTAS, the Life of a Splunk Trainer and using DevOps in Splunk Development
Cyber Scotland Connect: Welcome & Purpose Statement
Latest Updates to Splunk from .conf 2017 Announcements
Securing the Enterprise/Cloud with Splunk at the Centre
Security Meetup Scotland - August 2017 (Deconstructing SIEM)
Deconstructing SIEM
Supporting Splunk at Scale, Splunking at Home & Introduction to Enterprise Se...
Ad

Recently uploaded (20)

PDF
Entrepreneurship PowerPoint for students
PDF
Understanding the Rhetorical Situation Presentation in Blue Orange Muted Il_2...
PPT
2- CELL INJURY L1 Medical (2) gggggggggg
PPTX
Prokaryotes v Eukaryotes PowerPoint.pptx
PPTX
1751884730-Visual Basic -Unitj CS B.pptx
PDF
CV of Architect Professor A F M Mohiuddin Akhand.pdf
PPTX
The Stock at arrangement the stock and product.pptx
PPTX
Condensed_Food_Science_Lecture1_Precised.pptx
DOC
field study for teachers graduating samplr
PDF
Blue-Modern-Elegant-Presentation (1).pdf
PPTX
OnePlus 13R – ⚡ All-Rounder King Performance: Snapdragon 8 Gen 3 – same as iQ...
PDF
Why Today’s Brands Need ORM & SEO Specialists More Than Ever.pdf
PPTX
chapter 3_bem.pptxKLJLKJLKJLKJKJKLJKJKJKHJH
PPT
BCH3201 (Enzymes and biocatalysis)-JEB (1).ppt
PDF
LSR CASEBOOK 2024-25.pdf. very nice casbook
PPTX
cse couse aefrfrqewrbqwrgbqgvq2w3vqbvq23rbgw3rnw345
PDF
313302 DBMS UNIT 1 PPT for diploma Computer Eng Unit 2
PDF
esg-supply-chain-webinar-nov2018hkhkkh.pdf
PPTX
Definition and Relation of Food Science( Lecture1).pptx
PPTX
Your Guide to a Winning Interview Aug 2025.
Entrepreneurship PowerPoint for students
Understanding the Rhetorical Situation Presentation in Blue Orange Muted Il_2...
2- CELL INJURY L1 Medical (2) gggggggggg
Prokaryotes v Eukaryotes PowerPoint.pptx
1751884730-Visual Basic -Unitj CS B.pptx
CV of Architect Professor A F M Mohiuddin Akhand.pdf
The Stock at arrangement the stock and product.pptx
Condensed_Food_Science_Lecture1_Precised.pptx
field study for teachers graduating samplr
Blue-Modern-Elegant-Presentation (1).pdf
OnePlus 13R – ⚡ All-Rounder King Performance: Snapdragon 8 Gen 3 – same as iQ...
Why Today’s Brands Need ORM & SEO Specialists More Than Ever.pdf
chapter 3_bem.pptxKLJLKJLKJLKJKJKLJKJKJKHJH
BCH3201 (Enzymes and biocatalysis)-JEB (1).ppt
LSR CASEBOOK 2024-25.pdf. very nice casbook
cse couse aefrfrqewrbqwrgbqgvq2w3vqbvq23rbgw3rnw345
313302 DBMS UNIT 1 PPT for diploma Computer Eng Unit 2
esg-supply-chain-webinar-nov2018hkhkkh.pdf
Definition and Relation of Food Science( Lecture1).pptx
Your Guide to a Winning Interview Aug 2025.

OWASP - Analyst, Engineer or Consultant?

  • 1. Analyst, Engineer or Consultant? DOES IT EVEN MATTER?
  • 2. Harry McLaren • Alumnus of Napier University • Managing Consultant at ECS [Security] • Splunk Enablement Lead, Engineer & Architect • Previous Roles: • Security Engineer, SOC Analyst, IT Technician @cyberharibu
  • 3. Disclaimer • I’m Dangerous • [A little] knowledge is powerful right? • I’m speaking for me, not my employer. • These are thoughts, not facts.
  • 4. Coming Up • Starting Out in Cybersecurity • Security Domains & Roles • Personal Journey • Foundational Knowledge & Skills • Interviewing Tips • Tips for ”Professionals” • Resources ~35mins
  • 5. Who’s Here? Aspiring, Current, Former Professional
  • 6. Starting Out in Cybersecurity Initial Career •Degree Education •Collage Education •Other Routes [Rare] Career Move •Business Skills •Soft[er] Skills •Formal Education IT Professional •Transferable Skills •Transferable Experience •Formal Education
  • 7. Security Domains (ISC2 CBK) •Security and Risk Management •Asset Security •Security Engineering •Communications and Network Security •Identity and Access Management •Security Assessment and Testing •Security Operations •Software Development Security Primary Experience Secondary Experience
  • 8. Security Operations Roles Tier 1/2 Support Analyst Security Analyst Expert Security Analyst Tier 2/3 Incident Investigator Threat Hunter SOC Consultant Management Shift Leader Incident Manager SOC Manager
  • 9. Security Engineering Roles Build Associate Security Engineer/Consultant Security Engineer/Consultant Lead Specialist Security Engineer Consulting Security Engineer Manage Managing Consultant Principal Security Engineer
  • 10. Personal Journey Consultant Engineer Analyst • IT Technician (2006) • Desktop Support (2011) • Senior Security Analyst (2013) • Security Engineer (2014) • Security Consultant (2016) • Senior Consultant (2017) • Managing Consultant (2018)
  • 11. Emotional Journey In Denial / Imposter Terrified Scared
  • 12. Foundational Knowledge & Skills Technical Competence/Experience Communication Skills Interpersonal Awareness
  • 13. Interviewing Tips • CV (2-3 Pages, Clear, Concise, Skills, Community, Basics) • Preparation (Research, Interviewers, Arrival) • Situation, Task, Action, Result (STAR for Competency Questions) • During (Breathe, Vocalise, Water, Questions) • After (Relax, Review, Repeat)
  • 15. Resources • Meetups • Splunk User Group Edinburgh • Security MeetUp Scotland • Cyber Scotland Connect • The Cyber Academy • ENU Security Society at Edinburgh Napier • Sigint Security Society at the University of Edinburgh • ISC2 Scottish Chapter • 2600 Edinburgh • ISACA Scottish Chapter • OWASP Scotland