<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator><link href="https://seccomet.com/feed.xml" rel="self" type="application/atom+xml" /><link href="https://seccomet.com/" rel="alternate" type="text/html" /><updated>2026-05-30T22:38:35+00:00</updated><id>https://seccomet.com/feed.xml</id><title type="html">The Tales of SecComet</title><author><name>Jason H</name></author><entry><title type="html">Year in Industry - Worth more than 12 Months?</title><link href="https://seccomet.com/blog/Placements/" rel="alternate" type="text/html" title="Year in Industry - Worth more than 12 Months?" /><published>2020-08-20T00:00:00+00:00</published><updated>2020-08-20T00:00:00+00:00</updated><id>https://seccomet.com/blog/Placements</id><content type="html" xml:base="https://seccomet.com/blog/Placements/"><![CDATA[<p>Placement, internship, year in industry.  Whatever you call it, it’s just an excuse to avoid essay writing for a year, right? As someone who’s just recently completed a 12-month placement within the threat intel team of a cybersecurity firm, I disagree. I think anyone who has the opportunity to undertake a placement during their course should do it.</p>

<p>Hopefully, my tips and anecdotes will you to decide to spend time in the security industry and give you some advice to get the most of your time.</p>

<h2 id="to-placement-or-not-to-placement">To Placement or not To Placement</h2>

<p><img src="/assets/images/shakespeare.gif" alt="To be or not to be gif" title="To be or not to be gif" /></p>

<p>University is a very traditional method of learning, you learn theory, and you can learn an isolated skill in practical classes. But combining these learned skills &amp; theory with time constraints and other pressures of a corporate environment is something that only occurs in the workplace, meaning there will always be a learning curve when you first start working in the cybersecurity industry.</p>

<p>Doing a placement role will get you through that learning curve before graduating, as well as giving you 12 months experience over other graduates applying to the same roles as you. Placement experience could be the clincher between you and another candidate that didn’t do a placement.</p>

<p>You may have an area of interest in which you want to work, by doing a placement you get a test drive of what could be a future career, giving you a chance to make sure that area is somewhere you want to work in.</p>

<h2 id="finding--applying">Finding &amp; Applying</h2>

<p>Now that you’ve decided to do a placement, where do you look to find one? Some of the places I searched when finding placement opportunities are:</p>

<ul>
  <li>Usual graduate/job search sites (<a href="https://www.indeed.co.uk">Indeed</a>/<a href="https://www.glassdoor.co.uk">Glassdoor</a>/<a href="https://gradcracker.com">Gradcracker</a>)</li>
  <li>Networking with exibitors &amp; attendeed at conferences</li>
  <li>LinkedIn (if you don’t have a profile, make one now!)</li>
  <li>Speculative applications (applying to a business that’s not explicitly advertising)</li>
</ul>

<p>Remember that Glassdoor also has reviews of companies by people who’ve worked there, it’s worth checking them out for any listing you’re interested in.</p>

<h3 id="now-you-just-send-in-your-cv-right">Now you just send in your CV, right?</h3>

<p><img src="/assets/images/moss.jpg" alt="wrong, image" title="wrong, image" /></p>

<p>You could just yeet your CV to any recuitment email you find, but your chances of being successful are very low. Instead, read the job description and person specification and tailor your cover letter and CV to them. For example, if a listing mentions Python, be sure to point out a module you’ve completed in Python, or some other experience you’ve had with the language.</p>

<p>I can’t offer much advice on speculative applications, since I didn’t submit any during my hunt. But it would be beneficial to identify the team/role you’re interested in working with, and what skills you possess that you believe would be relevant. Also, make sure you send your application to the right person, use LinkedIn to identify the recruiter for your region or manager of the team you want to join and email your application to them.</p>

<h3 id="subject-to-change">Subject to Change</h3>

<p>Remember that not all companies recruit in the same fashion. The steps in the recruitment will vary as will the order in which you’ll undertake them. It’s ok to ask your contact at the company what the process will be, it shows your actively interested not just spamming applications, and will help you to prepare for the rest of the process.</p>

<p>You’ll need to be prepared for:</p>

<ul>
  <li>Telephone/video interviews (used just to confirm your eligility &amp; find out about you)</li>
  <li>Technical interviews (sometimes an computer based test or problem solving in front of an interviewer)</li>
  <li>Assessment Centres (these may include group assessments, technical tests, and face to face interviews)</li>
</ul>

<p>Interviews are a 2-way street, you get to ask your prospective employer questions too. Working for a company should benefit both you and the company. If it’s been more than say a fortnight without hearing about the next steps, follow up with your contact and find out what the situation is. If you’re unsuccessful, keep your head up and find a new listing to apply for, but don’t forget to ask for some feedback as to why you were removed.</p>

<p>My recruitment experience with my placement employer was mostly straightforward, except for having to follow up a couple of times before and after my initial interview. This was the only interview I had for this role, as some time later I got an offer. Before getting the offer, I was revising knowledge that was mentioned in the job spec for a possible technical test/interview.</p>

<h2 id="day-1-n---your-time-at-work">Day 1-n - Your time at work</h2>

<h3 id="nerves">NERVES</h3>

<p>When you first start your going to be nervous, that’s normal and you’ll soon settle in. Take the time to get to know your colleagues on your team and in your office, find out what their role is or ask about what they’re working on. You have a great opportunity to ask questions and learn from these people, so take advantage of them (a little bit).</p>

<h3 id="the-learning-curve">The Learning Curve</h3>

<p>If you have not worked in any cybersecurity role before, naturally there’s going to be a learning curve. Your boss should allow for this, and give you the time to understand and get the hang of what your learning before setting you loose on something live or Service Level Agreement (SLA) bound. As my boss told me in the first month “You’re here to learn as well as do, as long as you’re doing one of those then I’m happy”. I struggled to get the hang of one of the first processes I was learning as it involved using Curl in a way I wasn’t used to. I was given reassurance that this was ok and got some help along the way. Once I had mastered the process, I was able to complete live items successfully.</p>

<h3 id="get-your-hands-dirty">Get Your Hands Dirty</h3>

<p>Don’t be afraid to get involved in things, if you see a project that you’re interested in but haven’t been asked to contribute to, ask the person leading that project or your boss if you can get involved. I was able to contribute to 3 projects: a Capture The Flag (CTF) for training/skills development for the Security Operations Centre (SOC), an event that was organised to encourage local university students to apply for next years placement program, and a company contribution to a cyber skills competition.</p>

<h3 id="make-a-record">Make a Record</h3>

<p>The whole time that you’re working, be sure to keep track of what you’ve learned and things you’ve achieved, this will be a valuable resource for you to refer to in future as to what your time in this role can bring to a future graduate role, as well as to avoid a feeling of imposter syndrome during or after your placement. My university required me to keep a weekly log of things I had been doing, and while I initially thought this to be a waste of time, I’m now glad that I did it because otherwise, I’d have likely forgotten a lot of the things I’d done/achieved.</p>

<h3 id="training-training-training">Training Training Training</h3>

<p>Many teams will have a budget to be spent on training and development, don’t think that just because you’re a placement student that you’re exempt from this. If there’s a course or a certification that could benefit you, ask your manager about it. Often you’ll be able to use some time at work to study for it, and your employer may even pay for you to take the exam. Why not do it? It’s free knowledge!</p>

<p><img src="/assets/images/fre.gif" alt="It's free real estate" title="It's free real estate" /></p>

<h3 id="a-note-on-working-from-home">A Note on Working from Home</h3>

<p>Generally, placements don’t involve working from home, as most employers (along with your college/university) will want &amp; expect you to be in a supported learning environment during your placement. However, if you’re applying for placements around the time the post goes live then you’ll likely be working from home. I spent the final 4 months of my placement working from home after a lockdown was introduced in the UK, so here’s a few tips learnt during my time being productive from home.</p>

<p>Regarding equipment, if there’s things that you need such as a monitor, keyboard, or laptop dock mention it to your IT or HR team. You may be able to either expence the purchase of these items or get equipment issued to you by your employer. I was issued a monitor and a laptop dock from the office when we ‘evacuated’, and these were returned to the office when I left the company.</p>

<p>Get yourself an ‘office’, it doesn’t necessarily need to be a room entirely to yourself, but try to place your computer at a desk or table that you aren’t using for any other purpose. And get yourself a decent desk chair, your back will thank you for it. While your at it, speak to those you live with to remind them that when you’re at your desk your ‘in the office’ and must not be disturbed. In my case, I took over the dining table in my flat.</p>

<p>Make use of comms, what platform is used to communicate in your firm, make use of it for both work-related communication and social chats. Create a ‘water cooler’ voice or text chat where you and others can chat casually when on your breaks or when there’s not much doing.</p>

<h3 id="when-the-end-comes">When the End Comes</h3>

<p>Finishing my placement during the Coronavirus situation was not a very high note, and I hope that the end of your placement will be better. Make sure to take time to celebrate your achievement. You’ve earned it!</p>

<p>Before you leave, give your contact details to either your boss or your recruiter along with your expected graduation date. You never know, you might have an opportunity to return and already having a relationship with other employees should give you a step up. Connect with co-workers on LinkedIn as well, even if they move on elsewhere, you’ll be able to find other jobs with their new employer.</p>

<h2 id="tldr---do-it">TL;DR - Do it</h2>

<p>Even if your university doesn’t offer a sandwich option as part of the course, you can easily take a year out to do a placement of your own volition, and I would recommend doing it. In my opinion, a 12-month placement is worth considerably more than 12 months of your time. If you’re able to do one, do it, you won’t regret it.</p>]]></content><author><name>Jason H</name></author><category term="Blog" /><category term="Placement" /><summary type="html"><![CDATA[Placement, internship, year in industry. Whatever you call it, it’s just an excuse to avoid essay writing for a year, right? As someone who’s just recently completed a 12-month placement within the threat intel team of a cybersecurity firm, I disagree. I think anyone who has the opportunity to undertake a placement during their course should do it. Hopefully, my tips and anecdotes will you to decide to spend time in the security industry and give you some advice to get the most of your time. To Placement or not To Placement University is a very traditional method of learning, you learn theory, and you can learn an isolated skill in practical classes. But combining these learned skills &amp; theory with time constraints and other pressures of a corporate environment is something that only occurs in the workplace, meaning there will always be a learning curve when you first start working in the cybersecurity industry. Doing a placement role will get you through that learning curve before graduating, as well as giving you 12 months experience over other graduates applying to the same roles as you. Placement experience could be the clincher between you and another candidate that didn’t do a placement. You may have an area of interest in which you want to work, by doing a placement you get a test drive of what could be a future career, giving you a chance to make sure that area is somewhere you want to work in. Finding &amp; Applying Now that you’ve decided to do a placement, where do you look to find one? Some of the places I searched when finding placement opportunities are: Usual graduate/job search sites (Indeed/Glassdoor/Gradcracker) Networking with exibitors &amp; attendeed at conferences LinkedIn (if you don’t have a profile, make one now!) Speculative applications (applying to a business that’s not explicitly advertising) Remember that Glassdoor also has reviews of companies by people who’ve worked there, it’s worth checking them out for any listing you’re interested in. Now you just send in your CV, right? You could just yeet your CV to any recuitment email you find, but your chances of being successful are very low. Instead, read the job description and person specification and tailor your cover letter and CV to them. For example, if a listing mentions Python, be sure to point out a module you’ve completed in Python, or some other experience you’ve had with the language. I can’t offer much advice on speculative applications, since I didn’t submit any during my hunt. But it would be beneficial to identify the team/role you’re interested in working with, and what skills you possess that you believe would be relevant. Also, make sure you send your application to the right person, use LinkedIn to identify the recruiter for your region or manager of the team you want to join and email your application to them. Subject to Change Remember that not all companies recruit in the same fashion. The steps in the recruitment will vary as will the order in which you’ll undertake them. It’s ok to ask your contact at the company what the process will be, it shows your actively interested not just spamming applications, and will help you to prepare for the rest of the process. You’ll need to be prepared for: Telephone/video interviews (used just to confirm your eligility &amp; find out about you) Technical interviews (sometimes an computer based test or problem solving in front of an interviewer) Assessment Centres (these may include group assessments, technical tests, and face to face interviews) Interviews are a 2-way street, you get to ask your prospective employer questions too. Working for a company should benefit both you and the company. If it’s been more than say a fortnight without hearing about the next steps, follow up with your contact and find out what the situation is. If you’re unsuccessful, keep your head up and find a new listing to apply for, but don’t forget to ask for some feedback as to why you were removed. My recruitment experience with my placement employer was mostly straightforward, except for having to follow up a couple of times before and after my initial interview. This was the only interview I had for this role, as some time later I got an offer. Before getting the offer, I was revising knowledge that was mentioned in the job spec for a possible technical test/interview. Day 1-n - Your time at work NERVES When you first start your going to be nervous, that’s normal and you’ll soon settle in. Take the time to get to know your colleagues on your team and in your office, find out what their role is or ask about what they’re working on. You have a great opportunity to ask questions and learn from these people, so take advantage of them (a little bit). The Learning Curve If you have not worked in any cybersecurity role before, naturally there’s going to be a learning curve. Your boss should allow for this, and give you the time to understand and get the hang of what your learning before setting you loose on something live or Service Level Agreement (SLA) bound. As my boss told me in the first month “You’re here to learn as well as do, as long as you’re doing one of those then I’m happy”. I struggled to get the hang of one of the first processes I was learning as it involved using Curl in a way I wasn’t used to. I was given reassurance that this was ok and got some help along the way. Once I had mastered the process, I was able to complete live items successfully. Get Your Hands Dirty Don’t be afraid to get involved in things, if you see a project that you’re interested in but haven’t been asked to contribute to, ask the person leading that project or your boss if you can get involved. I was able to contribute to 3 projects: a Capture The Flag (CTF) for training/skills development for the Security Operations Centre (SOC), an event that was organised to encourage local university students to apply for next years placement program, and a company contribution to a cyber skills competition. Make a Record The whole time that you’re working, be sure to keep track of what you’ve learned and things you’ve achieved, this will be a valuable resource for you to refer to in future as to what your time in this role can bring to a future graduate role, as well as to avoid a feeling of imposter syndrome during or after your placement. My university required me to keep a weekly log of things I had been doing, and while I initially thought this to be a waste of time, I’m now glad that I did it because otherwise, I’d have likely forgotten a lot of the things I’d done/achieved. Training Training Training Many teams will have a budget to be spent on training and development, don’t think that just because you’re a placement student that you’re exempt from this. If there’s a course or a certification that could benefit you, ask your manager about it. Often you’ll be able to use some time at work to study for it, and your employer may even pay for you to take the exam. Why not do it? It’s free knowledge! A Note on Working from Home Generally, placements don’t involve working from home, as most employers (along with your college/university) will want &amp; expect you to be in a supported learning environment during your placement. However, if you’re applying for placements around the time the post goes live then you’ll likely be working from home. I spent the final 4 months of my placement working from home after a lockdown was introduced in the UK, so here’s a few tips learnt during my time being productive from home. Regarding equipment, if there’s things that you need such as a monitor, keyboard, or laptop dock mention it to your IT or HR team. You may be able to either expence the purchase of these items or get equipment issued to you by your employer. I was issued a monitor and a laptop dock from the office when we ‘evacuated’, and these were returned to the office when I left the company. Get yourself an ‘office’, it doesn’t necessarily need to be a room entirely to yourself, but try to place your computer at a desk or table that you aren’t using for any other purpose. And get yourself a decent desk chair, your back will thank you for it. While your at it, speak to those you live with to remind them that when you’re at your desk your ‘in the office’ and must not be disturbed. In my case, I took over the dining table in my flat. Make use of comms, what platform is used to communicate in your firm, make use of it for both work-related communication and social chats. Create a ‘water cooler’ voice or text chat where you and others can chat casually when on your breaks or when there’s not much doing. When the End Comes Finishing my placement during the Coronavirus situation was not a very high note, and I hope that the end of your placement will be better. Make sure to take time to celebrate your achievement. You’ve earned it! Before you leave, give your contact details to either your boss or your recruiter along with your expected graduation date. You never know, you might have an opportunity to return and already having a relationship with other employees should give you a step up. Connect with co-workers on LinkedIn as well, even if they move on elsewhere, you’ll be able to find other jobs with their new employer. TL;DR - Do it Even if your university doesn’t offer a sandwich option as part of the course, you can easily take a year out to do a placement of your own volition, and I would recommend doing it. In my opinion, a 12-month placement is worth considerably more than 12 months of your time. If you’re able to do one, do it, you won’t regret it.]]></summary></entry><entry><title type="html">2018 - It’s been Non-Stop</title><link href="https://seccomet.com/blog/2018-Recap/" rel="alternate" type="text/html" title="2018 - It’s been Non-Stop" /><published>2018-12-31T00:00:00+00:00</published><updated>2018-12-31T00:00:00+00:00</updated><id>https://seccomet.com/blog/2018-Recap</id><content type="html" xml:base="https://seccomet.com/blog/2018-Recap/"><![CDATA[<p>With the end of the year imminent, I’ve decided to start a blog of sorts. It seems only fair that I recap on what’s been an amazing, but busy time. At least since the start of my second year of university. The first half of 2018 may not have been a great time, but I’ve started a new journey now, not only studying cybersecurity, but joining the community that surrounds it.</p>

<h2 id="i-finally-joined-enusec">I finally joined ENUSEC</h2>

<p>I finally bit the bug and signed up to ENUSEC, Edinburgh Napier University’s Security Society. And despite having very little security experience at the time, took part in the societies’ FreshersCTF.</p>

<p><img src="/assets/images/FreshersCTF.jpg" alt="Fully packed lab for FreshersCTF" title="Fully packed lab for FreshersCTF" /></p>

<p>You could say that I caught the CTF bug here and found myself a few days later at the beginner CTF organised by SigInt. Did I win either of these? No. But that’s not what mattered, what mattered was the experience and the learning, of which there was plenty. And besides, there was an even better opportunity to come.</p>

<h2 id="playing-with-the-big-guns">Playing with the big guns</h2>

<p>Despite not winning either of the two events I’d taken part in thus far, I was offered a place on the ENUSEC CTF team for upcoming competitions. First up was the Scottish Cybersecurity Challenge in Dundee, where I had the honour of leading the second ENUSEC team, comprised of students who are new to competitive CTFs, whilst we didn’t place the top 3, this was a great experience and one that I won’t forget in a hurry.</p>

<p><img src="/assets/images/DundeeCSC.jpg" alt="The competition was tough at Cybersecurity Challenge Scotland" title="The competition was tough at Cybersecurity Challenge Scotland" /></p>

<p>In addition to this, I was part of our team that competed to qualify for the Deloitte CTF finals in London. The good news was… we qualified, and soon flew down to London to compete in the final, where our team came fourth overall. It was great to get an insight into Deloitte’s cyber operations, and ‘get in the door’ when it comes to placement opportunities for next year.</p>

<p><img src="/assets/images/DeloitteCTF.jpg" alt="12 hours of hardcore flag catching" title="12 hours of flag capturing, I needed a beer after this" /></p>

<h2 id="meetups--omg">Meetups &amp; OMG…</h2>

<p>There’s plenty of meetups to bring together people in cybersecurity, industry &amp; students. This year I set about getting to as many as possible. I made it to several Security Scotland events, ENUSEC’s weekly meets, as well as Cyber Scotland Connect. Where…</p>

<p><img src="/assets/images/CSCTalk.jpg" alt="I was speaking at the meetup" title="I did my first talk at Cyber Scotland Connect" /></p>

<p>That’s right, I got to do my first actual talk. The open mike night at Cyber Scotland Connect gave me my first opportunity to speak at any sort of event, talking about my adventures taking part in FreshersCTF and ‘failing forward’ a term I’ll definitely use in the future. Public speaking is a skill that can set you apart from those who are only technically inclined, and I’d encourage anyone to try speaking, you’ll probably find you’re much better than you thought you were.</p>

<h2 id="doing-my-bit">Doing my Bit</h2>

<p>During this semester at university, I took up duties as a demonstrator for a first-year module, using my own experiences to help other students to understand topics in time for their upcoming exam. I’ve also worked for The Cyber Academy at several events, including the Data in Health &amp; Care conference, and manning the Cyber Academy stand at the GDPR Summit Scotland, where I found a new profile picture.</p>

<p><img src="/assets/images/GDPRSummit.jpg" alt="'working hard' at the GDPR summit" title="Representing the school of computing &amp; The Cyber Academy… and having a photoshoot while I’m at it " /></p>

<p>And on top of doing all these cool things, I had to manage completing three new modules in Python, Databases, and Systems &amp; Services. Fortunately, stresses over exams and coursework are over (for now) and I’ve got time to rest and reflect.</p>

<h2 id="what-about-next-year">What About next Year?</h2>

<p>Conferences will be coming around soon, and I intend to attend as many as possible, furthering my knowledge &amp; getting to know as many people in this industry as possible. And this will of course include ENUSEC’s own Le Tour Du Hack 2019. And of course, I’m searching for a yearlong placement opportunity.</p>]]></content><author><name>Jason H</name></author><category term="Blog" /><category term="Recap" /><summary type="html"><![CDATA[With the end of the year imminent, I’ve decided to start a blog of sorts. It seems only fair that I recap on what’s been an amazing, but busy time. At least since the start of my second year of university. The first half of 2018 may not have been a great time, but I’ve started a new journey now, not only studying cybersecurity, but joining the community that surrounds it. I finally joined ENUSEC I finally bit the bug and signed up to ENUSEC, Edinburgh Napier University’s Security Society. And despite having very little security experience at the time, took part in the societies’ FreshersCTF. You could say that I caught the CTF bug here and found myself a few days later at the beginner CTF organised by SigInt. Did I win either of these? No. But that’s not what mattered, what mattered was the experience and the learning, of which there was plenty. And besides, there was an even better opportunity to come. Playing with the big guns Despite not winning either of the two events I’d taken part in thus far, I was offered a place on the ENUSEC CTF team for upcoming competitions. First up was the Scottish Cybersecurity Challenge in Dundee, where I had the honour of leading the second ENUSEC team, comprised of students who are new to competitive CTFs, whilst we didn’t place the top 3, this was a great experience and one that I won’t forget in a hurry. In addition to this, I was part of our team that competed to qualify for the Deloitte CTF finals in London. The good news was… we qualified, and soon flew down to London to compete in the final, where our team came fourth overall. It was great to get an insight into Deloitte’s cyber operations, and ‘get in the door’ when it comes to placement opportunities for next year. Meetups &amp; OMG… There’s plenty of meetups to bring together people in cybersecurity, industry &amp; students. This year I set about getting to as many as possible. I made it to several Security Scotland events, ENUSEC’s weekly meets, as well as Cyber Scotland Connect. Where… That’s right, I got to do my first actual talk. The open mike night at Cyber Scotland Connect gave me my first opportunity to speak at any sort of event, talking about my adventures taking part in FreshersCTF and ‘failing forward’ a term I’ll definitely use in the future. Public speaking is a skill that can set you apart from those who are only technically inclined, and I’d encourage anyone to try speaking, you’ll probably find you’re much better than you thought you were. Doing my Bit During this semester at university, I took up duties as a demonstrator for a first-year module, using my own experiences to help other students to understand topics in time for their upcoming exam. I’ve also worked for The Cyber Academy at several events, including the Data in Health &amp; Care conference, and manning the Cyber Academy stand at the GDPR Summit Scotland, where I found a new profile picture. And on top of doing all these cool things, I had to manage completing three new modules in Python, Databases, and Systems &amp; Services. Fortunately, stresses over exams and coursework are over (for now) and I’ve got time to rest and reflect. What About next Year? Conferences will be coming around soon, and I intend to attend as many as possible, furthering my knowledge &amp; getting to know as many people in this industry as possible. And this will of course include ENUSEC’s own Le Tour Du Hack 2019. And of course, I’m searching for a yearlong placement opportunity.]]></summary></entry></feed>