Pros
I was at HALOCK for about a year when I realized that all of my clients had been genuinely interested in improving their security. I had peers in other firms whose clients were more interested in just getting past compliance markers. I asked a couple clients - mid-engagement - why they selected HALOCK over our competition. They said that it was because other consultancies offered to get them over a finish line no muss, no fuss. HALOCK, on the other hand, set a high bar and said, "I think you can get here." I loved my job up to that point. But I began to identify with my job after that revelation. If you want to recognize the difference between a security firm that does security badly and a security firm that does security well ask what it's like to work there. If consultants are bored because they keep doing the same thing over and over, and keep writing the same reports over and over, then they are probably bad at security. If they are expected to improve analysis methods, stay educated, improve skills, innovate, and be flexible for each client environment, then they might be great at security ... because the hackers have to meet all of those challenges too! As in every good consultancy the SMEs have developed some advanced knowledge, skills, and processes, but then they share that knowledge with newcomers. The SMEs are expert, but they have enough sense of team achievement to share those skills with their colleagues, and to encourage others to show them a better way. People congratulate each other a lot here. Credit for victories is shared. I seldom hear people give credit to themselves when a significant achievement is made. This tone is set at the top. Partners are sincerely thankful for their colleagues' contributions to victories, and are openly accountable for their occasional errors. Senior management is humble and always points out the superior skills of the people on their team. Each member of the team seems to really believe that their achievements are possible because they are part of a functioning team. Team play is collaborative, and not competitive. If a colleague has a better way to do something, we learn from it. There is a lot of laughing here. Team members and senior management are really funny and genuinely kind to each other. Significant others are strongly encouraged to join us at holiday and summer events. Compensation appears to be good across the board, but I don't have enough insight into salaries to say for sure. Our engineers, hackers, and consultants all know our stuff, but as a group characteristic we always feel we need to be better. We need to be better than our competition, better than the hackers, better tomorrow than we are today. I have spoken with highly accomplished engineers and consultants who earnestly focus on what they are weak on. That's so rare. I know too many "experts" in our field who confuse confidence in what they know with confidence in what they don't know. That's a bad combination in this field, and we don't see that here. Keep that in mind if you want to work here or anywhere. "I don't know for sure, but this is how I'll find out" is a sign of a righteous security pro.
Cons
Because demand on consultants' time is so high, SMEs are not able to spend as much time as they would like with up-and-comers. There are good processes in place to allow professionals at all levels to do their jobs well, but many positions require consultants to create their own value, and to be resourceful as they work within projects. HALOCK's reputation for excellence is strong, so professionals need to be able to operate comfortably with those expectations.