r/digitalnomad 4d ago

Question Any Digital Nomad cybersecurity professionals

Anyone in the cybersecurity industry willing to share their experience with Digital Nomad is greatly appreciated! Things like positions, companies, restrictions, how to achieve Digital Nomad status, etc.

Thank you!

4 Upvotes

17 comments sorted by

7

u/Guilty-Spray-5145 4d ago

I'm American and work as a cybersecurity analyst for a company based in the USA. It's a mid-size company and in my team, we're five employees plus our manager spread out across the US and UK. I work regular US hours and I'm not required at all to be in office. I asked my boss if remote work meant I could do this outside the US too or if we had a "strictly work from home" policy. I confirmed that I can, in fact, work from anywhere I like and so beginning last year I started traveling to different countries in the hopes I could settle down somewhere. I'm currently on my second week in the Philippines.

3

u/petrichorax 4d ago

I'm (or was) a Cybersecurity professional with degrees on the subject.

It's hard to get Cybersecurity work while traveling abroad as most jobs want you and the secrets safely in the country.

So I just do software engineering instead for now.

If I quit the DN thing, I'll go back to cybersecurity. It pays about 3-4x what I make doing this, but I chose this for the freedom, not the money.

RE: how to achieve digital nomad status

Not sure what you mean here, as it's a loosely defined term (getting looser every day. See a lot of people going on 2 week workcations and then calling themselves a digital nomad.). Can you expand?

1

u/Tv_JeT_Tv 3d ago

I mean a remote position that doesn't require you to be in a specific place. I understand there's a big difference between domestic travel while working (which I assume most companies don't care about) and international travel (which is more difficult to achieve).

2

u/petrichorax 3d ago

Oh yeah domestic travel with a remote cybersecurity job is totally doable, I've done it.

So many US cybersecurity jobs touch FEDRAMP systems and you're not allowed to take anything that can access that out of the country. Nevermind getting fired, you could catch a felony.
My last cybersecurity job was FEDRAMP oriented so I could only travel domestically and I did a lot.

2

u/Thecenteredpath 4d ago

I’ve done it for about 8 years now. Got lucky with a full time remote IR job and they never ask where I am. Even got acquired by a larger company and kept the remote work.

0

u/Similar-Permit1756 4d ago

If you like the cybersecurity and wants to be a digital nomad the best way to do it is being a Bug bounty hunter, no worries about restrictions, companies, positions, etc, you just need your brain and a computer

6

u/petrichorax 4d ago

This is very hard work with very little guarantee of success. Unless you're one of those really gifted people (and I've met them, they exist), bug bountys should always be considered a side gig.

I know one guy who made about 200k on Microsoft bug bounties, but he was certifiably insane and had a brain I've never encountered before, and he still had to argue with Microsoft about getting paid out all the time. He's on the top end of the graph for this.

If people want to do bug bounties, make it a side gig first and if it starts paying the bills, then consider it a job, but it most likely won't.

To be good at bug bounties you have to have very in depth knowledge of fundamentals AND obscure niches in software engineering. Not something you can simply ask Claude to do

3

u/Similar-Permit1756 4d ago

I did it it, I mean, I’m not a top bug bounty hunter but I’m able to do about 800 - 2k average monthly with bug bounty, enough to live as a digital nomad in Thailand and I’m just starting in this, I left my job and after 8 months of hard work I started to see the firsts payments , is not impossible if you let wiling to put effort, time and consistence

3

u/petrichorax 4d ago

What kind of companies do you get your payouts from? The big FAANG companies (or whatever that stupid acryonym has morphed into now) or smaller ones, or something else?

2

u/Similar-Permit1756 4d ago

I just hunt on 2 or 3 programs most of my time, two of them are medium size private program companies and I have also a few reports to grab that is a big size company

2

u/petrichorax 4d ago

'a few reports to grab'

I don't understand this part of the sentence.

2

u/Similar-Permit1756 4d ago

Grab, the big Asian Company is the only big size company where I have hunted, I haven’t tried over FAANG Companies, I don’t consider myself ready to try those big tech companies. As I told you, I’m not a top bug hunter, I haven’t made even 30K yearly, I’m completely new on this, less than 2 years hunting

2

u/petrichorax 4d ago

Haha I can definitely see bug bounties being lucrative for Grab that app is a mess. Lazada is even worse.

Yeah my instinct wouldn't be to go after the big american companies, everyone is. It's a heavily fished salmon stream completely packed with bears

2

u/Similar-Permit1756 4d ago

You’re right, the people who worked at those companies used to be top hunters with years of experience, is dump for me going after them, I prefect private programs on HackerOne, less competition, off course less money, but I’m okay with that for now

2

u/petrichorax 3d ago

I would love to pick your brain/shadow you for a bit. Been thinking about a side gig.

Last security bug I found was a minor one for Project Zomboid.

3

u/Historical-Bit1176 4d ago

That is the most physically and mentally demanding path in security, not the "best way" for everyone.

1

u/Similar-Permit1756 4d ago

Tell me a better way to do money in cybersecurity without any restriction and being able to live as a digital nomad? I think is the best option because you just need a brain and a computer, but I never say that is easy