@sp1icer@Infosec_Taylor@_mbanana Look at it like a Labrador Retriever: “Wow, look at all this fun stuff I get to do! I get to learn cloud and kick squirrels off the lawn and talk to developers and write reports! What will I get to do tomorrow? Ball? Ball!”
@DanielW_Kiwi@hmemcpy This is going to sound dumb but in some systems the save button really does need extra help, at least for me. Sometimes I need to know if it saves and leaves me on the record so I can keep editing or saves and takes me somewhere else. Ticketing systems, Agile work items, etc.
@DM3k_tech “Sorry, I’ve not worked with your app before - can you explain X like I’m a Labrador retriever?” is a relatively common question I ask since I have to work with a ton of different teams/apps.
@kvlly Allegedly I’m a “Principal Application Security Architect” and today I created epics and features in Azure DevOps and did only a little bit of architecture.
@DoomsdayGoth@caterpillar Not sure when you graduate, looks like our full time college grad roles for this year are filled but both IT (which houses the central cybersecurity team) and Digital (web/mobile app engineering division, we have a small appsec team) still have summer intern roles posted.
@DoomsdayGoth You come join the cool kids at @Caterpillar 😎. We have a decent tuition assistance program, although like most others it comes with a commitment. https://t.co/t6umU3RM5m
@VPNSteve@AccidentalCISO I’m familiar with pyramid of pain but I’m thinking more design and less threat detection (I’m not a CSIRT Labrador retriever anymore but I have yet to figure out what labbo I am now and “feral raccoon of security architecture” is also on the list of possibilities 😂)
Does anyone have an example of a threat model done really well so that I can understand if what I see happen is what is supposed to happen? CC: @AccidentalCISO because that’s the only way I can get visibility out of the algorithm 😂
@AccidentalCISO but the output I most often see is a tabletop vulnerability assessment complete with CVSS scores. It’s hard for me to feel like those add much to an already crowded conversation. But that’s why I want to talk to people, because maybe I just don’t understand. 2/2
@AccidentalCISO The reason I ask is that I think of a threat model as “determine the bad scenarios that might happen to my specific app and the likelihood of those scenarios occurring” (like scenario-based DR planning), 1/
@AccidentalCISO@xTiffVicious The bummer about weaponized anxiety is that cybersecurity requires us to assess likelihood and if we could do that we probably wouldn’t have anxiety 😂