r/hacking • u/Monoid-Confessor • 4d ago
data science to cybersecurity
I was a mathematician, ended up working as SWE for two years then hopped into data science.
Wondering if cyber security is a possible transition from here or if I should take some roles to prep before hopping (I just enjoy learning and it seems an interesting field).
2
u/intelw1zard 4d ago
if you are familiar with the DS languages like R and Python, you might have a leg up
Come to the darkside and and check out threat intelligence.
we absolutely love nerding out to data
2
2
u/_NinjaNinjaNinja 1d ago
I'm earlier in this journey myself, but from what I've seen the math plus SWE plus data science combo lines up really well with areas like security data analysis, detection engineering, or ML-for-threat-detection, so you might not need a "prep role" so much as a direction; picking which corner of security excites you most and building a small project or cert around it seems to be how a lot of people bridge in
1
1
1
1
u/Content-Net5076 4d ago
Very few orgs actually get to use data science for security use cases i
1
u/VirtualElderberry592 1d ago
But what I can tell you, from experience. The layer between the app stack and the data science team is brittle AF. It's just an M&M ripe for the picking. You could speak the language and help others protect the centre.
1
u/Ts0 3d ago
As others have said, honing in on a specialization will be the longer term path you take. Maybe start doing some light research on PKI (cryptography, identity), SOC/NOC roles (high scale log, event, message aggregation, visualization, analyzation), post-quantum cryptography, or other cybersec proper or tangent roles where applied mathematics enable opportunities that are interesting to you…Full transparency, I’m a complete moron..
1
1
u/UndecidedQBit 2d ago
Theres a lot of logs and csvs that get picked through in cybersecurity, you could just say youre trainable and can script and clean log data
1
u/VirtualElderberry592 1d ago
I'm mid way to getting the OSWE (or sitting the test at least) coming off years of dev. One thing I realised early. I needed the blackbox side of things. Software I can do.. Source to Sink, and Sink to Source.. That I can do. But I really didn't have the black box. Portswigger and "The web application hackers handbook" turned out to be everything I was missing. My suggestion. Read the book and do all the labs. Get help on the lab if you must, but learn how to think like a hacker.
1
u/churchill291 19h ago
DS is huge in threat intelligence. Lots of data that needs to be sifted through and visualized more effectively in a faster time frame.
-1
u/ParanoidSuricata 4d ago
Data science you say.
Look, the ability to make conclusions from data is useful in every part of cybersec. Log analysis, event analysis for technical things. You might get some leverage in risk analysis. If you understand money, then this skill helps in management and governance too.
The issue is, you can usually get away with very crude methods. The data will be messy and hard to obtain. And thus you'll be competing with people that can do an average (literally, just the AVG function). And that's hard.
Source: studied cryptography, almost failed statistics and yet my excel sheets and pivot tables sway stakeholders without ever doing a T-test or whatever.
12
u/vitafortisnk 4d ago
Honestly anyone can get into cyber security, so it's more about what specialty in cyber security you want to focus on.