Live data from Hacker News

U.S. has almost 500k job openings in cybersecurity

cbsnews.com

31–40 of 103 posts

Re: U.S. has almost 500k job openings in cybersecurity

#31
post #4

That sounds huge. 0.15 % of the entire us population just for cyber security? I hope you don't need garbage men and bakers.

> 0.15 % of the entire us population just for cyber security? Even better: 0.15% of the entire US population for unfilled jobs. I'm going to assume most of these aren't permanent positions but gigs.

[deleted]

Re: U.S. has almost 500k job openings in cybersecurity

#32
post #8

I believe this. Most of the "security" people i run into don't know jack. Incompetence is ripe and this sector will only grow. Last external IT audit I had to explain to the auditors what a password manager was. They'd never heard of it.

As a developer who used to work in cyber security that feeling is mutual on both sides. Unfortunately they are typically both right.

Re: U.S. has almost 500k job openings in cybersecurity

#33
I remember thinking circa 2009 that every company was going to eventually need a dedicated cyber security department or pay for equivalent services, and that investing in a portfolio of stocks that can provide software and services would be a windfall. I made a paper portfolio on Yahoo! Finance. Unfortunately it doesn't really track performance properly, but seems like I made a good call. I selected dedicated security vendors like Fortinet (+800%) as well as enterprise software vendors (MSFT +800%) and IT consultancy firms (Accenture +400%). I don't really have any convictions as strong in today's environment, although cyber security probably has a lot further to go.

Re: U.S. has almost 500k job openings in cybersecurity

#34

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

There are a few bespoke consulting firms that actually try to improve their clients security beyond checklist whack-a-mole and automated scanning. Annoyingly bunch of charlatan firms pretend to do this, but just toss an intern with a scanner at the customer and/or double book their staff so they don’t have time to think beyond the basics. This lets them always underbid the firms that do honest work.

The problem is that its hard to measure if someone had deep thoughts about the security of a system vs checked a box as it can take years before you notice they did nothing (eg: hired another firm the next time that found a pile of issues).

Disclaimer: I work for one of the rare non-checklist/scanner firms.

Re: U.S. has almost 500k job openings in cybersecurity

#35
post #19

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

Your impressions mirror mine, and is also why I chose to stick to software engineering. You can still apply your security knowledge. OSCP doesn't apply to most of that depending on what language you use (caveat: I haven't seen the new course) - OSWE does however. Generally companies won't pay extra for your security knowledge unless they're specifically looking for it, even if you've really found and fixed things in…

IMO, one of the problems with things like the OSCP is that they don't really mirror how real pentesting works.

I've never heard of a pentest that's done as a 24 hour thing where someone is watching you through a webcam and you can't collaborate with people, and then the report is written up the next day. Also (last time I looked at it anyway) it quite a few topics that whilst interesting again don't mirror day-to-day pentesting, and restrictions on using things like Metasploit are just weird.

Re: U.S. has almost 500k job openings in cybersecurity

#36

Earlier quoted context omitted.

US tech industry bis larger than people imagine. With the ongoing cyber attacks, every company > 10 employees who have a lot at stake needs to hire cyber security specialists. If we can have 500k police and private guards, we should have 500k cyber security specialists

Does every company > 10 employees have a security guard?

There's probably a point where insurance requires it.

Re: U.S. has almost 500k job openings in cybersecurity

#37

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

Yes at the end of the day your main job is it to either educate people about always the same security issues,

Fixing the same security issues,

Or singing of on procedures.

Re: U.S. has almost 500k job openings in cybersecurity

#38

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

There are a few bespoke consulting firms that actually try to improve their clients security beyond checklist whack-a-mole and automated scanning. Annoyingly bunch of charlatan firms pretend to do this, but just toss an intern with a scanner at the customer and/or double book their staff so they don’t have time to think beyond the basics. This lets them always underbid the firms that do honest work. The problem is th…

The pentesting industry has a big problem with being a good "market for lemons".

It's very hard for customers to differentiate the good and bad companies, without having their own internal expertise, and even then you need to go down the line of getting named testers and speaking to each one.

Another problem is with how many/most pentest companies report, which is by exception. There's no requirement to state all the tests they did, just the results, so it's hard to tell the difference between "we've got a good system and they didn't find much" and "they didn't do good work and missed things"

Re: U.S. has almost 500k job openings in cybersecurity

#39
post #23

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

It's IT via checklist. I can't imagine a more depressing way to go through my life. Talking to the cybersecurity people I know they all frame it like they're elite warriors who are locked in a titanic struggle with cunning adversaries. My take is...you followup on tickets generated by third party tools by filling out web forms. Yes you're getting 'probed' by Russia and China all the time but thats from botnets lookin…

It might be something similar as it is in software development.

At the end of the day it is a job.

But when you part of the 1% of the good people you have your team and more leaway and potentially get called for the more critical and more interesting things.

Re: U.S. has almost 500k job openings in cybersecurity

#40
post #8

I believe this. Most of the "security" people i run into don't know jack. Incompetence is ripe and this sector will only grow. Last external IT audit I had to explain to the auditors what a password manager was. They'd never heard of it.

I prepared so much for our audit and the only thing this guy cared for in a 5 developer company was the fact that I had root access on all environments.

He didn't care about Aws having 2fa configured about our vlan ipsec Tunnel, etc

I even took the liberty to fix the md5 Passwort shit with bcrypt just before the audit...

Post reply on HN