Live data from Hacker News

U.S. has almost 500k job openings in cybersecurity

cbsnews.com

21–30 of 103 posts

Re: U.S. has almost 500k job openings in cybersecurity

#21

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

I’ve been in the industry since the 90’s. It’s been taking a pretty hard pivot into ‘devsecops’ and related merging of a variety of software engineering and development practices and traditional security domain practices.

I still love it. There’s a lot of interesting challenges and equally interesting people to work with. I do agree there is a perception problem, however, most of which is self-inflicted by a small minority of the those that work in the domain.

Re: U.S. has almost 500k job openings in cybersecurity

#22

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

Yeah this is largely accurate but there are more options than that.

There's e.g. product security, which can be a bit less nihilistic. You take your security knowledge and use that to influence application design and implementation process so the result has fewer issues. At the tippity top end this can mean adding e2e, differential privacy, suppressing harmful features, OS security improvements - work that can meaningfully improve security or privacy for millions of people.

There's all sorts of forensics and IR, malware analysis and RE. Exploit dev, scanner monkeying, bug triage, just all sorts.

A lot of pentesters manage to not hate their lives by doing #3 and focusing on the interesting problems while not caring that the customer just wants a compliance input.

Suck levels vary a lot by firm. Just like dev jobs can be meaningful and intellectually fulfilling OR meaningless ticket punching.

Re: U.S. has almost 500k job openings in cybersecurity

#23

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

It's IT via checklist. I can't imagine a more depressing way to go through my life. Talking to the cybersecurity people I know they all frame it like they're elite warriors who are locked in a titanic struggle with cunning adversaries. My take is...you followup on tickets generated by third party tools by filling out web forms. Yes you're getting 'probed' by Russia and China all the time but thats from botnets looking for ancient vulnerabilities. You're not single handedly keeping the barbarians back from the gates. You're paper pushers.

Re: U.S. has almost 500k job openings in cybersecurity

#24

That sounds huge. 0.15 % of the entire us population just for cyber security? I hope you don't need garbage men and bakers.

US tech industry bis larger than people imagine. With the ongoing cyber attacks, every company > 10 employees who have a lot at stake needs to hire cyber security specialists. If we can have 500k police and private guards, we should have 500k cyber security specialists

Does every company > 10 employees have a security guard?

Re: U.S. has almost 500k job openings in cybersecurity

#25
post #15

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

is hunting for bounties not viable?

It’s a good side hustle and a fantastic way to develop your skills, but depending on it for income is extremely stressful and leads to an array of pathological behaviors that spoil it for you and those downstream of your efforts.

Re: U.S. has almost 500k job openings in cybersecurity

#27
post #8

I believe this. Most of the "security" people i run into don't know jack. Incompetence is ripe and this sector will only grow. Last external IT audit I had to explain to the auditors what a password manager was. They'd never heard of it.

Exactly. Its shocking how bad most audits are. The standards they're trying to enforce were obviously put in with the best intentions but instead of the spirit of the rules, the letter is being followed. When the letter of the law is being enforced by people that don't know anything about the industry or how the technology works, you get truly asinine decisions.

Re: U.S. has almost 500k job openings in cybersecurity

#28
I feel like cybersecurity is undergoing an AI/ML like buzz at the moment, where basically every company is going all in on it, but the value is really being provided by a small concentration of talented people who really know their stuff.

I've found it frustrating being in the DevOps space, because the hype bleeds into other decisions and sometimes I swear people forget we're actually running a business and believe everyone should really be focused on security over everything else.

Re: U.S. has almost 500k job openings in cybersecurity

#29
post #27
post #8

I believe this. Most of the "security" people i run into don't know jack. Incompetence is ripe and this sector will only grow. Last external IT audit I had to explain to the auditors what a password manager was. They'd never heard of it.

Exactly. Its shocking how bad most audits are. The standards they're trying to enforce were obviously put in with the best intentions but instead of the spirit of the rules, the letter is being followed. When the letter of the law is being enforced by people that don't know anything about the industry or how the technology works, you get truly asinine decisions.

It's an inevitable part of the way IT Audit is structured. Standards are necessarily abstract from specific systems (so don't always apply well) and updating standards is a slow process.

The auditors themselves are often tasked with reviewing a massively disparate group of systems, so there's no way they could be come subject matter experts in each one.

So the result is a checklist approach, especially as most compliance tasks are pass/fail.

Re: U.S. has almost 500k job openings in cybersecurity

#30
There’s been a massive push for people to enter jobs in cyber sec in the UK too. Our intelligence services offer pretty huge bursaries for university students on the condition they’ll go into security on graduation. Really seems like there’s an imbalance wrt supply and demand currently.
Post reply on HN