Live data from Hacker News

Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

cybersecurityventures.com

41–50 of 66 posts

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#41
post #23

Earlier quoted context omitted.

IT has a shortage of metasploit/burpscanner/nexpose/nessus jockeys and XYZ security appliance administrators at low salaries. The positions you're talking about are an incredibly difficult sell to companies. Top 10 companies have a few positions on hire at decent wages doing unique work but that's it. Some companies cyber defense strategy just involves buying a bunch of insurance. Plenty of pen testing mega-mart cons…

This is the correct answer. An "unfilled" job is a misnomer. There is a market-clearing price for everything.

If refineries shut down and the price of gas goes to $10/gallon is that not a "real shortage" because there is still a market clearing price and I can still buy gas? I disagree.

I think the fact that software engineers get offered $120k+ out of school to fiddle with js frameworks indicates a real shortage personally.

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#42
post #13

Well, one role in this might be that a lot of cybersecurity jobs are complete bullshit, and or their certifications are. I won a free certification course as an EC-Council Certified Security Analyst, and it's the biggest joke I've ever seen. It's such a massive fucking joke that I decided to not even renew my certification for free because it would just have been a waste of time. Most of these "cybersecurity" jobs ar…

I have NEVER heard a useful description by a cybersecurity analyst (i.e. detecting intrusions and exfiltration) on how they do their work, despite being in a position where they should have been able to do so. Usually I just get shrugged shoulders.

I have no trouble conjuring a job description for a "cybersecurity analyst"; I assume their job consists of:

1. Staffing an event management system (probably something with a pretty console that is 1/5th as powerful as an ELK deployment but that costs 10x as much because Security) and investigating alerts.

2. Kicking off routine scanning processes and reviewing the results generated by them.

3. Responding to requests to let this application or that host through some perimeter firewall.

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#43
post #23

Earlier quoted context omitted.

IT has a shortage of metasploit/burpscanner/nexpose/nessus jockeys and XYZ security appliance administrators at low salaries. The positions you're talking about are an incredibly difficult sell to companies. Top 10 companies have a few positions on hire at decent wages doing unique work but that's it. Some companies cyber defense strategy just involves buying a bunch of insurance. Plenty of pen testing mega-mart cons…

This is the correct answer. An "unfilled" job is a misnomer. There is a market-clearing price for everything.

I don't think so. There really are not 3 million jobs in cybersecurity.

There is not much demand for people who can run a scanner or set up a firewall. Not to mention that a setup is a single day of work, it's not even close to a full time job.

Maybe they are counting every guy who ever plugged a broadband modem as a security specialist.

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#44

Ironically, going to https://www.cybersecurityventures.com in Firefox throws an SSL certificate error: SSL_ERROR_BAD_CERT_DOMAIN. This does not fill me with confidence regarding this company's security prowess.

Do you think there's much overlap between the people generating reports and the people in charge of hosting their domain/ managing certs?

I'm just making more of a general comment re. the website/company, not the specific post this HN thread covers. Granted, it's a minor detail, and most people probably won't hit the www version of the site, but for whatever reason it's the version of their site that my search engine surfaced, so FWIW I just found it ironic.

Peace.

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#45
post #41

Earlier quoted context omitted.

This is the correct answer. An "unfilled" job is a misnomer. There is a market-clearing price for everything.

If refineries shut down and the price of gas goes to $10/gallon is that not a "real shortage" because there is still a market clearing price and I can still buy gas? I disagree. I think the fact that software engineers get offered $120k+ out of school to fiddle with js frameworks indicates a real shortage personally.

>>> I think the fact that software engineers get offered $120k+ out of school to fiddle with js frameworks indicates a real shortage personally.

Software engineers from a top school, who passed the most hardcore interviews in the most selective firms in the world, to live in the most expensive city on the planet where a single bedroom flat is $4k a month.

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#46
post #40
post #31

Earlier quoted context omitted.

>Care to explain why you think intrusion detection is bullshit? If they're signature based they're not better than antivirus. I have zero faith in signature based systems. For the stuff that uses machine learning, I have to admit, I have no idea how that stuff performs. But in general I wouldn't trust a machine learning model to not be fooled. Edit: Add to that HTTPS, I don't buy any claim that they can spot malware…

Anomaly detection doesn't do much better than signature systems do. It finds real stuff, but it "finds" so much garbage that the signal is swamped by it.

I don't know about network detection systems but antivirus heuristics used to be terrific.

You can assign 100 students to develop a trojan for a week. At the end of the week, more than 90% of the software are detected as generic trojan by the antivirus.

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#47
post #40

Earlier quoted context omitted.

Anomaly detection doesn't do much better than signature systems do. It finds real stuff, but it "finds" so much garbage that the signal is swamped by it.

I don't know about network detection systems but antivirus heuristics used to be terrific. You can assign 100 students to develop a trojan for a week. At the end of the week, more than 90% of the software are detected as generic trojan by the antivirus.

> You can assign 100 students to develop a trojan for a week. At the end of the week, more than 90% of the software are detected as generic trojan by the antivirus.

Probably because 90 of these 100 students have no idea how AV heuristics work and what the trivial tricks are to completely stomp them.

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#49
post #33
post #23

Earlier quoted context omitted.

IT has a shortage of metasploit/burpscanner/nexpose/nessus jockeys and XYZ security appliance administrators at low salaries. The positions you're talking about are an incredibly difficult sell to companies. Top 10 companies have a few positions on hire at decent wages doing unique work but that's it. Some companies cyber defense strategy just involves buying a bunch of insurance. Plenty of pen testing mega-mart cons…

Buying insurance might be the most cost effective strategy. If insurance of $2MM would cover your liability, why incur 3MM expenditures and still only be reasonably secure?

Cyber security insurance has liability caps, relatively low for the premiums. Standard boilerplate demands to hold such insurance in the US is around $1M liability coverage for small shops, usually gets quoted around $50K annual premiums. If you can even get underwritten at all. I have been able to negotiate those clauses away so far.

Everyone is already trying to pass the buck (quite literally) on information security risk via insurance, and the insurance industry is pushing back. One possibility that might develop out of the standoff is customers pushing the liability onto Cloud vendors and washing their hands of the concern.

What no one outside of information security wants to admit much less promulgate is development and IT teams must grow larger, or security continues as an expensive as hell fat tail risk. The cheap hedge is hiring additional staff; businesses have grown so accustomed to living outside the fat tail that the accumulated technical debt presents the illusion that status quo is normal. The new normal is ever-more expensive attacks.

I wish POSIX would offer a standard way to elide certain parts of a the command string that shows up in a process list. There are piles of legacy programs that won’t get retrofitted to use a file to read a password anytime soon. There are sins aplenty in our fields when it comes to security.

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#50
post #47

Earlier quoted context omitted.

I don't know about network detection systems but antivirus heuristics used to be terrific. You can assign 100 students to develop a trojan for a week. At the end of the week, more than 90% of the software are detected as generic trojan by the antivirus.

> You can assign 100 students to develop a trojan for a week. At the end of the week, more than 90% of the software are detected as generic trojan by the antivirus. Probably because 90 of these 100 students have no idea how AV heuristics work and what the trivial tricks are to completely stomp them.

Some of them quickly realize that the AV is flagging all their binaries and they try to evade it. They will soon discover that it is far from trivial.

Don't underestimate the students and don't underestimate the AV. The world is full of surprises.

Post reply on HN