Douglas McKee is paid, essentially, to be a hacker. He’s the principal engineer and a senior security researcher at McAfee, and a member of the Advanced Threat Research (ATR) team in the office of the CTO — identifying vulnerabilities in various software and hardware platforms, and finding solutions to fix and prevent them with other cybersecurity engineers.
The difference between him and a hacker, however, is what he does with the information.
“We follow something called responsible disclosure,” McKee says, “which means that instead of releasing our research to the world, we take that research and contact the vendors, or we contact who created the piece of technology that we're looking at, and we tell them, you've got a problem here. We'll give them really in-depth details about what the problem is, and give them an idea of how they can fix this problem and work with them to kind of fix those issues.”
This helps bolster security for both organizations and users, McKee said. Finding these vulnerabilities — and the fixes for them — is his favorite part of the job. It both gives him the thrill of problem solving, while helping to make the world a better place.
“It creates an environment where we're still fixing problems, and we're fixing them before the bad guys can leverage them for malicious activity,” McKee said. “At the end of that process, we're bringing awareness to the issues, and that helps the industry learn and grow so that, hopefully, we have less of those issues as a whole.”
Problem solving is a large part of being a cybersecurity engineer, as well as fostering a sense of curiosity and desire to learn. The two best things young professionals can do in their path to becoming a cybersecurity engineer, McKee said, is to practice, and to fail often.
”Not being afraid to fail is extremely important,” he said. “You need to be able to take on something and have the patience and the mental fortitude to keep going. I might take a project and have a thousand things go wrong before I find the one right thing.”
That willingness to learn is also key to the role. McKee constantly has to think outside of the box in order to find the weak spots in a system.
“Being able to learn quickly and efficiently is one of the primary skills [I need to know],” McKee said. “I can't stress this enough, but in the job functions that I do, I have to be able to pick up something that I've never seen before and understand how software or a piece of hardware or a new IoT device works, and how it integrates into the larger ecosystem of cybersecurity.”
Getting into the mindset of a hacker is also key. Much of what McKee does when analyzing a new system is reverse engineering where a vulnerability stems from. He then finds out how to exploit that vulnerability in order to gain access.
“There’s really only one difference between what I do and what a bad guy does: what I do with the information I've learned. I go through the responsible disclosure process,” McKee said. “If that's the only difference, then that means I have to have the same thought process as the malicious actor. Being able to think like that is extremely important.”
As cybersecurity is becoming more important than ever, especially as big-profile breaches make headlines for organizations. McKee said there’s no predicting where technology can go — twenty years ago, using an entire gigabyte of data for storage seemed ludicrous. Nowadays, however, it’s not uncommon for an entire video to take up 1 GB on a laptop or a phone.
The key to staying ahead of this technology is remaining adaptable and curious, McKee said.
“You need to stay apprised of current research,” he said. “You have to be able to read and know what's going on in history and learn from other people, which leads to mentorship as well. I've really been fortunate to have some great mentors in my life that helped guide me and navigate those uncharted waters, if you will. That was really crucial to my development.”
Mentorships in particular have also played a major role in how McKee has developed his skill set. He recommends that young professionals find a mentor in their workspace by asking questions. They should seek advice from more experienced professionals, and continuing to develop that relationship over time.
Ultimately, a cybersecurity engineer needs to have a constant thirst for knowledge and a natural curiosity. Security goes beyond just protecting a system — it’s about knowing what to protect, how to protect it, the mindset of those trying to work their way around that protection, and asking the right questions in the process.
“It's about having that curiosity,” McKee said. “I have that natural curiosity to ask why. Asking questions is really important as well. And so being able to look at a problem and apply what I already know. And then having the self-awareness to know that, okay, this is something I do know, but over here is something that I really don't know, so this is something I should ask about. Put your pride aside for a second and ask for that help. It really helps develop relationships as you go.”
Comments