Capítulo 1
The Digital Guardians: Inside the World of Ethical Hacking
In a world where our most sensitive data is just a hack away from exposure, a new breed of professionals has emerged as our digital guardians. They're the ethical hackers-cybersecurity experts who use hacker techniques to protect rather than exploit. Gary Rivlin's "Becoming an Ethical Hacker" offers a fascinating glimpse into this rapidly growing field where demand far outstrips supply. The book has become required reading in cybersecurity programs nationwide, with tech luminaries like Elon Musk recommending it to aspiring security professionals. As cybercrime damages soared past $3 trillion in 2015 (projected to double by 2021), this once-niche specialty has transformed into one of the most crucial and lucrative career paths in technology, with an estimated 3.5 million unfilled positions globally by 2021. Through intimate portraits of six diverse professionals, Rivlin reveals not just how to enter this field, but why it matters more than ever in our increasingly vulnerable digital world.
Capítulo 2
The Cyber ER: Life as an Incident Responder
Angela Gunn sits in Seattle's Bedlam cafe, juggling multiple cybersecurity emergencies simultaneously. It's peak attack season-hackers strike when guards are down during holidays-and she's running on fumes. Between urgent Slack messages and encrypted emails, she monitors five different security incidents across three time zones. As an incident response consultant, Gunn describes her role as "somewhere between a firefighter and dental hygienist," rushing into digital infernos while also performing preventative maintenance during quieter periods.
Despite finding her way to information security in her forties after a winding career in tech journalism, Gunn thrives on the adrenaline and unpredictability of incident response. She compares the work to an emergency room, where professionals make "a terrible day only a bad one or a bad day not so bad." The stakes are high, with average data breach costs reaching $4.35 million in 2022, but so is the compensation-entry-level positions command around $99,000 for incident analysts and $85,000 for forensic investigators. The field faces a severe talent shortage, with over 700,000 unfilled cybersecurity positions in the United States alone.
Gunn's baptism by fire came six weeks into her job at Microsoft in 2010, when she faced Stuxnet, the sophisticated worm that physically damaged Iranian nuclear facilities. The response involved grueling multi-day sessions in Microsoft's "ssirp room" (Software Security Incident Response Process), coordinating communications about the breach. The team worked around the clock, analyzing malware signatures, tracking infection vectors, and managing public relations. Despite meetings with screaming participants that lasted for hours and sleep-deprived nights fueled by energy drinks, Gunn found crisis management exhilarating.
After Microsoft, Gunn moved to Hewlett-Packard's Zero Day Initiative, managing communications and publishing research while enjoying better work-life balance. She oversaw the disclosure of hundreds of vulnerabilities and coordinated with researchers worldwide. Yet she missed the heroic role of incident response and eventually joined BAE Systems Applied Intelligence. There, she handles cases like a recent one involving a "rogue employee" at a financial institution who had sent sensitive documents to her personal computer. The case required digital forensics, employee interviews, and careful documentation for potential legal proceedings.
What makes incident response unique is the constant learning curve. No two security breaches are identical, and responders must adapt to novel attack vectors while working under intense pressure. Recent challenges include ransomware attacks targeting healthcare facilities, sophisticated nation-state campaigns, and supply chain compromises. Teams must master an ever-expanding toolkit: network monitoring, malware analysis, memory forensics, and threat hunting. As Gunn puts it, "It's not a job you can get bored at. If you get bored, you're doing something wrong." This combination of intellectual challenge, adrenaline rush, and exceptional compensation makes incident response an attractive entry point for many cybersecurity professionals-though the burnout rate remains high due to the stress and unpredictable hours. Industry surveys suggest that 65% of incident responders have considered quitting due to workplace stress.
Capítulo 3
The Master of Deception: Physical Penetration Testing
Mark Seiden doesn't look like your typical hacker. Yet this former music prodigy who attended Columbia at sixteen has become one of the most respected penetration testers in the cybersecurity world, combining technical prowess with social engineering to expose vulnerabilities before malicious actors can exploit them.
When a top-five global bank hired Seiden, they tasked him with stealing their most precious documents-client identities and fee structures. Given standard contractor access, he first probed digital defenses before switching to physical infiltration. Working mostly at night, he broke into the facilities manager's cabinet using a paperclip, stealing keys and copying floor plans. He also took unencrypted backup tapes and located passwords to the company's voicemail system. Through clever social engineering, he obtained the code names for major deals and their corresponding client identities.
When presenting his findings to shocked executives, Seiden returned all stolen materials and highlighted security vulnerabilities-including the facilities manager who had secretly replaced the stolen keys without reporting them missing. This comprehensive approach demonstrates why Seiden stands apart from typical penetration testers who focus solely on digital vulnerabilities.
His closet contains disguises ranging from delivery uniforms to hard hats, and he infiltrates facilities by blending with crews during breaks. This theatrical element of his work traces back to his unconventional background. During 1968 campus protests at Columbia, Seiden made keys to underground tunnels to avoid police-an early demonstration of his hacking mindset.
After decades in the field, Seiden's career evolved from programming at IBM to specialized security work. By the mid-2000s, penetration testing comprised 80% of his work, leading to a position with Yahoo's security team, the "Paranoids." There, he and colleague George Neville-Neil tested co-location centers worldwide, exposing alarming vulnerabilities: picking elevator locks in Hong Kong, interrupting magnetic door circuits, and short-circuiting electronic readers.
Now in his later career, Seiden rarely takes pen-testing assignments, noting the field has transformed since the 1990s. Large accounting firms and security companies now dominate what was once the domain of independent contractors. He recommends companies spend their security budgets on design reviews rather than penetration tests, though he believes organizations that have never done penetration testing raise red flags about their security mindset.
What makes Seiden's story compelling is how it illustrates that cybersecurity isn't just about technical skills-it's about creative thinking and understanding human psychology. The most sophisticated firewall can be rendered useless by a convincing impostor with a clipboard and the right uniform.
Capítulo 4
The Security Princess: Transforming Google from Within
When Parisa Tabriz created her unconventional "Security Princess" business card title in 2011, she wasn't just being whimsical-she was making a statement about breaking stereotypes in a male-dominated field. Despite not being "stereotypically princessy," the title serves as an effective conversation starter while reflecting her somewhat rebellious approach to security leadership.
Unlike many in her field, Tabriz showed no early affinity for computers. Growing up in Chicago suburbs with Iranian and Polish-American parents in medicine, she attended the University of Illinois at Urbana-Champaign for computer engineering almost by default, initially not even understanding the difference between browsers and AOL. Her security journey began when her personal website was hacked, sparking curiosity about vulnerabilities. She joined campus security clubs, attended the infamous DEF CON hacker conference, and eventually earned both bachelor's and master's degrees in computer science.
After joining Google in 2006, Tabriz found her calling finding vulnerabilities in Google products-work she loved for its creative problem-solving aspects. She developed "think like an attacker" classes to teach Google developers security principles, even creating a deliberately vulnerable application called "Gruyere" for training purposes. This educational approach would become a hallmark of her career.
By 2014, Tabriz had made Forbes' 30 Under 30 list while balancing speaking engagements, mountain climbing, and international security competitions. When she took over Chrome's security team, she expanded it beyond traditional security experts to include designers, psychologists, and other diverse backgrounds-emphasizing that understanding human behavior is as crucial as technical expertise in cybersecurity.
As Chrome's Browser Boss, Tabriz now oversees 200 engineers while championing diversity in security. She organized the OURSA conference to counter the male-dominated RSA event, mentors female engineers, and implements user-friendly security features like automated protections and clear warning messages. Her philosophy centers on making security accessible rather than intimidating-a significant shift from the gatekeeping mentality that once dominated the field.
Tabriz's story illustrates how cybersecurity leadership is evolving beyond technical expertise to include communication skills, empathy, and design thinking. Her success demonstrates that the field needs diverse perspectives to create security solutions that work for everyone, not just technical experts. As she puts it, "Security is a team sport"-one that requires players from all backgrounds to effectively protect billions of users.
Capítulo 5
The Reluctant Manager: From Gaming to Android Security
Dave Weinstein's journey into cybersecurity defies the stereotype of the lifelong computer prodigy. This burly, bearded manager in Google's Android security group took a circuitous path that included dropping out of college, twelve years in the gaming industry developing titles like Tom Clancy's Rainbow Six, and only pivoting to security in his mid-thirties.
Weinstein's transition came from burnout in gaming and a desire for a more temperate climate than the Southeast. Despite having no security experience, he found the industry desperate for talent-unlike the oversaturated gaming world where "thousands of talented people would give everything to break in-so they can get underpaid and overworked." At Microsoft, he created security tools using fuzz testing and trained developers, including those in Xbox who claimed they were "special snowflakes."
After eight years at Microsoft and a stint at Hewlett-Packard working on their Zero Day Initiative bug bounty program, Weinstein joined Google in 2016. Though he had sworn off management after a negative experience at Red Storm Entertainment, he eventually self-nominated for a leadership position at Google. As engineering manager of Android Security Assurance, he now leads a twelve-person team analyzing security issues, releasing monthly patches, and managing long-term projects.
What makes Weinstein's management philosophy distinctive is his focus on coaching rather than micromanaging. "Everything is ultimately about people," he explains-keeping them happy and productive while solving technical problems. This human-centered approach informs his hiring practices as well.
At DefendCon 2018, Weinstein challenged common security hiring fallacies. He rejected notions that entry-level hiring isn't viable, that security mindset is inborn rather than teachable, and that technical excellence requires an early start. Rather than seeking "perfect unicorns," he advocates finding people genuinely interested in solving problems. "If you cannot teach something, you don't really understand it," he explained. Technical skill matters less than being non-toxic to colleagues: "If you want to solve anything meaningful, you need to work with people."
For those entering information security, Weinstein advises maintaining emotional distance from inevitable failures. "You have to care about solving problems, but for survival's sake, recognize that things happen." He explains the defender's dilemma-attackers need breach only one entry point while defenders must protect all vulnerabilities across billions of Android devices. "If you put yourself in a position where you must be perfect, you will break."
Weinstein's story demonstrates that cybersecurity needs more than just technical wizards-it requires thoughtful leaders who understand both technology and human psychology. His gaming background gives him unique insight into user experience and team dynamics, proving that diverse career paths can strengthen rather than hinder security expertise.
Capítulo 6
The Mac Maverick: Finding Vulnerabilities Apple Missed
Patrick Wardle's discovery of the Fruitfly malware-which had been secretly compromising Mac computers for over a decade-exemplifies his unique position in the cybersecurity ecosystem. As one of the few researchers focused on macOS security, Wardle has built a career finding vulnerabilities in Apple's "walled garden" that the company itself often overlooks or downplays.
Unlike many in his field, Wardle grew up in a deeply religious household without technology in rural Pennsylvania. His life changed dramatically after moving to Connecticut for public school, where growing religious differences with his family led him to move out at fifteen. By sixteen, he was living independently with just $500 from his parents-an experience he now views as a gift that forced him to mature quickly. Despite hardships like living on food stamps and working multiple jobs to survive, he excelled academically, graduating in the top 5% of his class and earning scholarships to attend the University of Hawaii.
Wardle's security career began at the NSA, where he joined the elite Tailored Access Operations team after graduating in 2005. The agency proved a dream job with amazing perks, including their "20/20 program" that paid him a full salary while working part-time and attending graduate school at Johns Hopkins. Despite the fulfilling work, bureaucratic frustrations led him to leave in 2008 after nearly four years.
After co-founding Vulnerability Research Labs and later selling it to Computer Sciences Corporation, Wardle embraced a lifestyle in Hawaii valuing health and happiness over materialism. This Maui mindset influenced his approach to work, allowing him to surf, practice yoga, travel, and select projects based on interest rather than just financial gain.
As an ethical hacker and security researcher, Wardle has built a multi-faceted career as a speaker, tool developer, entrepreneur, and media expert. His notable discoveries include a Mac vulnerability giving full system control and revealing that the Shazam app's microphone remains active even when supposedly turned off. In 2015, he created Objective-See, offering completely free Mac security tools without ads or premium versions. This altruistic approach unexpectedly generated significant revenue through voluntary user donations-over a thousand people contributing $6,000 monthly by fall 2018.
Wardle's relationship with Apple has been complex. While Microsoft has embraced security researchers, Apple has historically been resistant to acknowledging vulnerabilities in their ecosystem. This tension actually benefited Wardle's career, as his focus on Mac security made his presentations stand out in a field dominated by Windows research. Over time, the relationship has improved, though tensions remain regarding Apple's limited bug bounty program.
After amicably separating from his wife in 2015, Wardle continues traveling globally for security conferences, often extending trips for personal adventures like scuba diving. His security expertise led to television appearances, including an HBO Vice News segment where he demonstrated hacking their producer in Moscow by creating a fake hotel network.
Wardle enthusiastically endorses ethical hacking as a career that offers financial security, flexibility, intellectual challenge, and the satisfaction of helping others-"an incredible career that's fulfilling, challenging, pays the bills, and you're helping other people."
Capítulo 7
The Wunderkind: From NASA to Startup Founder
Allison Wong's cybersecurity journey began earlier than most. After encountering computers in third grade-a life-changing experience-she was programming on DOS-based machines by sixth grade. In 1991, her family got an internet-connected Apple computer, unusual for that time. As a teenager, Wong immersed herself in online bulletin boards under the handle "ChinaWhite," built her own Linux computer by age fourteen, and worked tech support for an internet service provider while still in high school.
Despite missing out on a Lockheed Martin scholarship after high school, Wong received a consolation prize that proved more valuable-a job at NASA's Johnson Space Center in Houston. As a system administrator for the space shuttle program, the newly graduated teenager earned $40,000 annually while working on critical systems for shuttle launches. This early professional experience put her on an accelerated career path that would eventually lead to entrepreneurship.
After about a year at NASA, Wong took a position as a network administrator at an ISP, managing software upgrades and system maintenance while carrying a pager for emergency calls, often leaving classes to address server issues. School increasingly interfered with her earning potential and offered little relevant to her work. Instead, she taught herself programming languages like Perl and Python from O'Reilly books and learned security fundamentals by installing firewalls and testing her own network.
Wong's career accelerated when she joined a Dallas security firm as an international consultant at age twenty. Traveling globally to install firewalls and security measures for a major client, she earned a six-figure salary and enjoyed the itinerant lifestyle until 9/11 prompted her return to the US. Her subsequent career included positions at Citadel Security Software (working with Department of Defense clients), McAfee, Symantec (where she served as a security architect for clients like Google, eBay, and Visa), Websense (later acquired by Raytheon and renamed Forcepoint), and FireEye's Mandiant division, where she gained experience in incident response.
In 2018, Wong and her husband Afonso Infante launched Suavei, focusing on Internet of Things security. Their company addresses the vulnerability of internet-connected devices like webcams, smart doorbells, and industrial equipment that typically lack endpoint security protections. Wong serves as CEO while raising funds and promoting the company through speaking engagements worldwide.
Despite the challenges of balancing entrepreneurship with new motherhood, Wong appreciates the field's flexibility and lucrative compensation-her corporate security positions paid around $300,000 annually plus stock options. As she tells students considering cybersecurity, "It's hard to come up with a better career path."
Wong's story illustrates how early exposure to technology can launch an exceptional career trajectory. However, it also demonstrates that formal education isn't always necessary-self-teaching, hands-on experience, and problem-solving abilities often matter more in cybersecurity than traditional credentials.
Capítulo 8
Breaking Barriers: Diversity Challenges in Cybersecurity
Despite the success stories of women like Angela Gunn, Parisa Tabriz, and Allison Wong, the cybersecurity field remains predominantly male. Women hold less than 20 percent of tech jobs in the United States, with cybersecurity showing even worse representation-only 11 to 14 percent of the cybersecurity workforce was female as of 2018, according to Women in Cybersecurity. The field also suffers from racial underrepresentation, with Google's own diversity report showing only 2.5 percent of its workforce was black in 2018 and 3.6 percent Latino, with even lower percentages in technical roles.
These statistics reveal a troubling disconnect: while cybersecurity desperately needs talent, with hundreds of thousands of unfilled positions, it's failing to tap into diverse talent pools. The reasons are complex, involving everything from early educational disparities to workplace culture issues that can make underrepresented groups feel unwelcome or isolated.
Organizations like Women in Cybersecurity (WiCyS) and Black Girls Code are working to address these gaps by providing mentorship, training, and community support. Companies like Google have also implemented initiatives to improve diversity, though progress remains slow. Parisa Tabriz's OURSA conference represents one approach to highlighting diverse voices in security that might otherwise be overlooked at traditional industry events.
The diversity challenge isn't just about fairness-it's about effectiveness. Security solutions designed by homogeneous teams often fail to account for diverse user experiences and threat models. As security becomes increasingly important to everyone's digital lives, the field needs perspectives that reflect the full spectrum of users it aims to protect.
Despite these challenges, cybersecurity offers diverse career paths for various personality types. The field demands passion, persistence, and puzzle-solving abilities. Many professionals describe a "security mindset" that either clicks or doesn't-a tendency to look at systems and immediately think about how they might be broken.
While formal education in cybersecurity is increasingly available, hands-on experience remains crucial. As Charlie Miller advises, "Don't just read. The most important thing is to actually do it." The field has no gatekeepers or mandatory certifications-as Dave Weinstein puts it, "All you have to do is want it."
This accessibility, combined with exceptional compensation and job security, makes cybersecurity an attractive option for career changers and new graduates alike. For those willing to develop the necessary skills and mindset, few fields offer better opportunities to make a meaningful impact while enjoying financial stability and intellectual challenge.
Capítulo 9
The Path Forward: Resources for Aspiring Ethical Hackers
For those inspired to explore ethical hacking, the journey follows a "Read. Learn. Do." framework. Begin with seminal works like "The Conscience of a Hacker" (the "Hacker Manifesto") and Eric Raymond's "How to Become a Hacker" to understand the philosophical underpinnings of hacker culture. Narratives like "The Cuckoo's Egg" by Clifford Stoll about tracking down a KGB hacker, and Kevin Mitnick's memoir "Ghost in the Wires" provide engaging entry points to security concepts.
Technical learning requires both theoretical understanding and practical application. "The Hacker Playbook" series offers step-by-step guides to penetration testing, while specialized texts on malware analysis, network security, and cryptography build deeper expertise. Formal education options have expanded dramatically, with cybersecurity degree programs available at many universities and community colleges. For self-directed learners, platforms like Cybrary offer free online training, while security news sites like Motherboard and Krebs on Security keep practitioners current on emerging threats.
The "Do" component is perhaps most crucial. Conferences like Black Hat and DEF CON provide opportunities to learn from industry leaders and network with potential employers. Local security meetups offer more accessible entry points to the community. Practice environments like Hack This Site, Capture the Flag competitions, and bug bounty programs allow aspiring hackers to develop and demonstrate skills in controlled settings.
Open-source contributions represent another valuable path. Security tools like Metasploit, Wireshark, and OWASP ZAP welcome contributions from developers at all levels. Contributing to these projects builds both technical skills and professional connections.
The cybersecurity community, while competitive, generally welcomes newcomers who demonstrate genuine interest and willingness to learn. Mentorship relationships often develop organically through community participation, with experienced professionals guiding newcomers through technical challenges and career decisions.
As Patrick Wardle emphasizes, ethical hacking offers "an incredible career that's fulfilling, challenging, pays the bills, and you're helping other people." In a world increasingly dependent on digital systems, few careers offer greater opportunity to make a positive impact while enjoying intellectual stimulation and financial security.
The path isn't always straightforward-as the diverse backgrounds of the professionals profiled in this book demonstrate-but for those with curiosity, persistence, and a security mindset, ethical hacking represents one of the most promising career frontiers of the digital age.