Are there other techniques or topics you think I missed? If so, please add them here to help people.
The purpose of the article is to help people who have been laid off to present themselves as well as possible and to find a new job.
Even though this information may not be completely new, I do still see a lot of the same mistakes being made, both in the applicants we see and the comments I read online. Sometimes just being reminded by a Hiring Manager and a Recruiter that these things really do matter can help.
Correct, that's my comment. When you submit a link to HN you it asks for a URL, Title, and Text. The text is automatically added to the posting as a comment.
This article dives deep to help you create the ideal resume, find a new position, do company research, set yourself apart from all the other applicants, and how to nail your interviews and get an offer.
The Highspot Security Team is hiring Security Engineers for ProdSec, AppSec, and CorpSec. We’re building a team that has all the best aspects of an agile consulting team (research, speaking and attending conferences, building tools, and delivering real results) with the best things of working at a well funded, rapidly growing, startup (funding, time to get things done and see your efforts make an impact).
We’re tackling fun challenges with great support and investment in our projects. If you want to learn more please reach out to me directly or apply with one of the links below.
Highspot is hiring Principal, Senior, and Security Engineers
Location: Seattle, WA. Remote Possible
We're hiring Security Engineers at all levels for our Product Security team at Highspot.
Highspot is a rapidly growing Pre-IPO startup that recently achieved "Unicorn" status in Seattle. We're building security solutions for our platform today with an eye on the company that we will be as we double every year.
Highspot may be growing quickly, but we haven’t lost our inclusive, respectful, and team focused culture. We’re looking for passionate people from all backgrounds who want to learn everything they can. Our team supports each other to achieve our best work. We leave the team and company competition or try harder thinking at the door.
We encourage our team to build tools, speak at and attend conferences, and publish research. We heavily use and rely on Open Source tools and software and we want to build and contribute back to those tools and to develop new techniques to help our security industry grow and improve together.
If this sounds exciting to you and you’re interested in learning more about our team and what it takes to be part of an exceptional, passionate, technical security engineering team, please reach out.
We use tools to make our lives easier, make us more effective, and to help us get better security coverage quickly, but manual assessment and vulnerability hunting is where we will make the most impact.
Whether you're a seasoned pro or relatively new to security I encourage you to check out Highspot. Our tech stack is fun (React, Ruby, Clojure) and modern (AI/ML, interesting and complex systems) and we service millions of users and are growing super-fast.
You'll find more information on the specific job postings. We're also hiring a ton of other positions that you can find on our Careers page: https://www.highspot.com/careers/
Highspot | (Senior) Security Engineer (and more!) | Seattle, WA
I'm hiring Security Engineers for my Product Security team, but there are many other incredible positions open at Highspot. Check out the Careers page for more info: https://www.highspot.com/careers/
Are you looking to join a rapidly growing team of security professionals in order to build an industry leading and bleeding edge security team?
Highspot may be growing quickly, but we haven’t lost our inclusive, respectful, and team focused culture. We’re looking for passionate people from all backgrounds who want to learn everything they can. Our team supports each other to achieve our best work leaving the intra-team or intra-company competition or try harder ethos at the door.
We encourage our team to build tools, speak at and attend conferences, and publish research. We heavily use and rely on Open Source tools and software and we want to build and contribute back to those tools and to develop new techniques to help our security industry grow and improve together.
If this sounds exciting to you and you’re interested in learning more about our team and what it takes to be part of an exceptional, passionate, technical security engineering team, please reach out.
We use tools to make our lives easier, make us more effective, and to help us get better security coverage quickly. We understand tools can make us better, but manual assessment and vulnerability hunting is where we will make the most impact.
Whether you're a seasoned pro or relatively new to security I encourage you to check out Highspot. Our tech stack is fun and modern and we service millions of users and are growing really fast.
I recently migrated from LastPass to 1Password. Honestly it's been great. The UI is better, sharing vaults is easier, they have integrations with haveibeenpwned.com, and integrations are seamless. There's no free tier, but the cost feels worth it to me. I was able to get my whole family on 1Password without too much hassle.
1.8 Billion Active Users on Facebook in Q3 of 2020
Every user in the US brings gives Facebook about $40 in advertising revenue every quarter
Facebook made $21 BILLION dollars in advertising, just in Q3 of 2020
Facebook has an effective tax rate of between 4% (in Q3 of 2020) and 20% in Q4 of 2019.
You’re worth a bit less than $160/year to Facebook in advertising revenue. They made 70 Billion dollars last year, and have made almost 60B this year already (82% of what they made in 19). They are taxed in the low double digits.
My questions to you:
- Did you get $160 worth of value out of Facebook?
- What’s your annual tax rate?
My guess is it’s No to the first question and a lot more than 4% to the second.
Thanks for reading my article. I agree this is overkill for this specific Coronavirus outbreak. The point of my article, though, was to show that with little outlay you can prepare yourself for a wide range of risks. In a city I think it’s important to prepare yourself for being able to stay in one place, without external resources, for some time, how much time is entirely up to you.
I see a lot of people here panicking and buying up all the toilet paper and hand sanitizer because they have never thought of this before. It’s best to be prepared, or at least thoughtful about your approach.
Absolutely, I should have made this clearer in the article. There have been many breaches in the past and the more places you put your sensitive data the more likely it is to be lost!
Yea, I'm glad it turned out to be nothing. I was pretty concerned to see my valid credentials in the subject line. The PDF was reasonably convincing, and very threatening. It got me thinking about things like "this can't be real, right? but what if it is? Should I just pay it to make it go away?" I figured if I was thinking those thoughts others might, so it was worth the investigation. Thanks for reading!!
My company uses join.me (a Logmein product) all the time for easy screen sharing. It's one of the few quick screen sharing apps out there that doesn't require a heavy download and is user friendly enough to be used by all of the people in our company and all of our client.
I've been using LastPass since 2011 and have been really happy with it (other than the slightly opaque UI and design from the 90's).
I'm hopeful about the acquisition, maybe logmein can give some UI/UX guidance to the LastPass team, while the LastPass team can help expand and grow to help more people to use a password manager.
If not, there are plenty of other password managers out there, I suppose.
I realize security probably not on the top of your feature list in 48 hours, but since I work for a security company doing security assessments it's is one of the first things I think about. I noticed an issue that will let me win without racing.
The reason I bring this up is not, in any way, to diminish your work, but to highlight that you don't get much security for free in these types of frameworks. So this isn't a big deal for this game, but in case somebody was using this for a more sensitive project they may want to be careful.
A Security Engineer and a Lead Security Manager. If you eat, sleep and breathe Software Security please apply! We've also setup a challenge website for you to test your skills on at: http://bit.ly/Hekjxe (email [email protected] for hints if you get stuck).
Lead Security Manager
Our Lead Security Manager will be tasked with delivering security assessments and managing a team of security engineers to deliver security assessments for Security Innovation's wide array of clients; from web, embedded, desktop, mobile and cloud based applications. This person should have some management experience and deep technical, security experience. Their day to day tasks include helping to scope application security projects, delivering the projects, leading and growing a team of security engineers and helping the local sales and marketing resources with proper messaging and understanding. Additionally this person will be expected to lead projects and interface directly with our clients. This person should have at least 3-5 years of manual application penetration testing experience, deep security knowledge, and 1-2 years of development experience.
Security Engineer
At Security Innovation Security Engineers are tasked with delivering security assessments for our wide array of clients on an even wider array of technologies and platforms. This person should have deep technical and security knowledge. This person will be tasked with performing manual Penetration Tests, Code Reviews, creating Threat Models, Design Reviews and more. Beyond their technical skill this person should have strong written and spoken communication skills. Additionally, this person should have 1-3 years of manual application assessment experience, deep security experience, and development experience would be a plus.
About Security Innovation
Security Innovation helps our clients to reduce their overall risk by providing application security services, education and standards. We assess the security of a wide range of applications and technologies to ensure they properly protect their sensitive data. Security Innovation is headquartered in Boston and has a branch office in Seattle, WA. This is an immensely challenging and rewarding company to work for, we have built a tight knit team of security experts who are well regarded as leaders in the field. As a reward for being the best in the industry we provide our engineers with 10% of their time for research, hefty hardware and research budgets, retirement, compensation and insurance packages. Oh, and we have unlimited vacation too.
Be a part of an awesome team of hackers with Security Innovation.
We find security issues in some incredibly interesting pieces of software, from web applications to embedded and mobile to desktop and server apps. If you think the world is a scary, insecure place and 0x41414141 makes you smile, please apply!
We encourage you to do your own security research and give you time and budget to pursue those topics. We want you to attend and speak at the conferences, write tools, white papers and blog posts on topics of your choosing. Beyond that we have an awesome perks package. You get a ton of freedom to be a rockstar.
We have developed or helped develop Blackmamba(http://rootfoo.org/blackmamba), Firesheep and other cool security tools.
We have four positions (and multiple openings) open:
- Security Engineer - the pen-testers that find vulns
- Lead Security Engineer - a seasoned security professional that can run our new Boston based security team
- Sales Engineer - a technical engineer that can help bridge the gap between sales and the engineers
- Linux System Engineer - Help build and design the most secure Kiosk system in the world based on some really cool tech.
Hey, submitter of the above link here. I had a hard time coming up with a non-spammy sounding title for this submission, but my company, Security Innovation, does a lot of application security work and has created some very cool eLearning.
If you're interested in learning about security this is a great (free) place to start. There are six courses that will be given away for free. I encourage you to check them out.
I'm looking to hire a couple awesome security professionals for our Boston office. We assess a wide range of really interesting technologies, from web apps to mobile to crypto. You have to have a true passion for security, most of the team does this on their off time and it's all we talk about. If you dream in hex, clickjack for breakfast, exploit XSS, SQLi and CSRF for lunch, Buffer Overflows and Format String Vulns for Dinner and some AuthN/AuthZ hijacking for a midnight snack you're our kind of candidate.
You'll have time and budget to do research, go to and speak at conferences, and build tools that will change the internet (We helped develop Firesheep, if you remember that).
You can e-mail me directly: jbasirico at securityinnovation dot com for more informaiton.
The purpose of the article is to help people who have been laid off to present themselves as well as possible and to find a new job.
Even though this information may not be completely new, I do still see a lot of the same mistakes being made, both in the applicants we see and the comments I read online. Sometimes just being reminded by a Hiring Manager and a Recruiter that these things really do matter can help.