WealthForgeWsMS16

Is a SANS certification worth it?

At a startup, a $6,000 cybersecurity boot camp is a tough sell. I'm a fullstack dev and the devops at work, and securing the PII we have access to is the most important thing we do. My father does cybersecurity in DC, and is really pushing it as a thing I should do for both my job and myself. Is it worth cashing in political capital at work, or barring that: out-of-pocket for the appropriate SANS cert?

Microsoft Bad Hombre Jul 19, 2017

Never heard of it!

IBM 0xc0ff33 Jul 19, 2017

If you don't have experience, certifications are an option. Personally I wouldn't pay it. If you're serious about doing security full-time, it may be advisable but if your goal is to stay a dev, a full SANS bootcamp is probably not for you.

Bluebot BBio Jul 20, 2017

A sans boot camp is the best 5-6 days of security instruction you can buy. Highly respected by the industry. A great investment for an organization that has no cyber talent. Now that being said just because you go to a boot camp doesn't mean you learned anything.

New
gravos Jul 20, 2017

I wouldn't pay out of pocket for a sans class/cert. Get the company to pay or teach yourself from the numerous free resources online

Google Mooc Jul 20, 2017

You can't go wrong with SANS

Duo Security zSRV55 Jul 20, 2017

If you're looking to move into an entry-level security position, the SANS cert can be a good foothold at some companies (and there are other people who will say they view them neutrally or negatively). If you just want to learn security stuff, figure out which certification you'd find most valuable to your role, and use material found online, books, and cheaper trainings to get a good foundation. For example, many computer security conferences will offer cheap or free trainings to attendees. Attending computer security conferences and meetups can also be valuable. There is possibly a "citysec" Meetup near you, if you're in any kind of city with a tech scene (I don't know where you live).

Duo Security zSRV55 Jul 20, 2017

There is a Humble Bundle security books bundle available for the next ten days. Of the included books, for what you described, I would say the "Threat Modeling", "Web Application Hacker's Handbook", "Unauthorized Access", and "Cryptography Engineering" books would be most useful to you!