Live data from Hacker News

U.S. has almost 500k job openings in cybersecurity

cbsnews.com

11–20 of 103 posts

Re: U.S. has almost 500k job openings in cybersecurity

#11
The US government's official numbers for 2019 [1] only show 131k jobs for "information security analysts" and they project 171k by 2029. The total for computer, network and database administrators is only around 500k.

[1] https://www.bls.gov/emp/tables/emp-by-detailed-occupation.ht...

Re: U.S. has almost 500k job openings in cybersecurity

#12
From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for:

1. Working in a corporation, where the job is just compliance checklist whack-a-mole.

2. Working in government, which can be good (Mudge has done good work there) but the common policy I've seen elsewhere seems to be to maintain an arsenal of open exploits, thus making everyone in the world _less_ safe in the name of... security...?

3. Working in contract pentesting... for clients who really only care about compliance checklist whack-a-mole.

There is a fourth option, which is research, like what Christopher Domas does, but opportunities for that which don't end up falling into the government trap seem few and far between (and even fewer if you've developed your skills outside an MS/PhD program).

That said, I am not an industry insider. This is only my impression as someone who was once interested in the field and decided to stick with software engineering after getting a bad taste from what I saw from the industry.

Re: U.S. has almost 500k job openings in cybersecurity

#13
post #7

Earlier quoted context omitted.

How many boot camp web devs are currently being churned out who don't know the first thing about the 1000 ways their service could be attacked?

While this is probably true for boot camp web devs, it is also a very real problem for recent college grads who learn about fancy algorithms in their CS degrees, but have no idea what angles of attack exist.

The closest thing to security I learned in university was RSA and why we didn't need to worry unless quantum computing succeeded.

Re: U.S. has almost 500k job openings in cybersecurity

#14

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

This is me.

There's nothing more boring than those positions. (Or to me, unethical than working for the US government)

I'd much rather create something that benefits the world.

Maybe the partial solution is bug bounties? As much as I'd hate those positions, I actively poke around for holes in websites for fun. I love when I have to do business with a small poorly run website, seems you can always find something they don't want you to have access too. Most recently, no right click to save images, but chrome developer tools got me the high res version anyway!

Re: U.S. has almost 500k job openings in cybersecurity

#15

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

is hunting for bounties not viable?

Re: U.S. has almost 500k job openings in cybersecurity

#16

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

I echo this. I was also interested in cybersecurity through CTFs. I also do a bit of bug bounties in my spare time. But i've sort of come to the conclusion that cybersecurity as a career isn't that great in general, most roles are just administrative or compliance types from what I've seen. But then I again I have seen opportunities with sort of smaller boutique security firms that mainly focus on exploit research, but for those it feels like they're looking for more specialist knowledge.

Re: U.S. has almost 500k job openings in cybersecurity

#17

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

The majority of work in government is on the defensive side, not the offensive side. But that would still be what you call whack-a-mole most of the time.

Re: U.S. has almost 500k job openings in cybersecurity

#18
post #4

That sounds huge. 0.15 % of the entire us population just for cyber security? I hope you don't need garbage men and bakers.

> 0.15 % of the entire us population just for cyber security? Even better: 0.15% of the entire US population for unfilled jobs. I'm going to assume most of these aren't permanent positions but gigs.

I'm going to assume the number is for any tech job that has even the slightest but of security function, including any sysadmin, dbeng, webapp dev, etc

It's just too big to be correct.

Re: U.S. has almost 500k job openings in cybersecurity

#19

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

Your impressions mirror mine, and is also why I chose to stick to software engineering. You can still apply your security knowledge. OSCP doesn't apply to most of that depending on what language you use (caveat: I haven't seen the new course) - OSWE does however. Generally companies won't pay extra for your security knowledge unless they're specifically looking for it, even if you've really found and fixed things in code proactively.

I also found some interviews in a similar format as developer interviews (hands on, timed), but with salaries that make it not really worth the trouble and stress (that's what OSCP was for!).

Re: U.S. has almost 500k job openings in cybersecurity

#20

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

>2. Working in government,

obviously there are two sides to government, one side is the same as #1, checklist and say our site/solution is now secure, #2 is the side that has to do with generally attacking other governments but also handling dissident/criminal parts of their own society.

Post reply on HN