Live data from Hacker News

U.S. has almost 500k job openings in cybersecurity

cbsnews.com

41–50 of 103 posts

Re: U.S. has almost 500k job openings in cybersecurity

#41
post #23

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

It's IT via checklist. I can't imagine a more depressing way to go through my life. Talking to the cybersecurity people I know they all frame it like they're elite warriors who are locked in a titanic struggle with cunning adversaries. My take is...you followup on tickets generated by third party tools by filling out web forms. Yes you're getting 'probed' by Russia and China all the time but thats from botnets lookin…

A roommate studying for aerospace engineering described that field as "Everyone gets in because they want to work at Skunkworks and design the SR-71. In reality, 95% of graduates will spend the next 40 years optimizing the efficiency of a winglet on a 747."

Security feels similar. The edge of the spear is fascinating, exciting, challenging work.

Unfortunately, no one needs that work. What companies actually need is mind-bogglingly slow, comprehensive, steady progress and improvement of their postures.

Re: U.S. has almost 500k job openings in cybersecurity

#42
post #23

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

It's IT via checklist. I can't imagine a more depressing way to go through my life. Talking to the cybersecurity people I know they all frame it like they're elite warriors who are locked in a titanic struggle with cunning adversaries. My take is...you followup on tickets generated by third party tools by filling out web forms. Yes you're getting 'probed' by Russia and China all the time but thats from botnets lookin…

Ask anyone in Aviation, checklists matter. Cybersecurity is often drudgery, but avoiding excitement is the entire point.

Re: U.S. has almost 500k job openings in cybersecurity

#43

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

I've worked in cybersecurity for ~7 years, and what you said is accurate. I'm actually switching to a government job and taking a big pay cut because the field is pretty miserable to work in for the most part. I think I've had one cybersecurity job that was actually enjoyable, and that was a Fortune 500 customer that saw the value in keeping their company safe, so their only limitations on our activity was no social engineering, and don't break anything. They knew that real hackers won't follow checklists or a strict RoE, so they didn't want us to either.

The field is also full of people who switched careers to make more money, so they blow minor security issues out of proportion to try and justify their paycheck. It's really frustrating, because then management thinks you aren't doing anything if you don't do the same.

If you want to work in cybersecurity, I think your job as a software developer would actually be very valuable. The biggest problem we have, besides management thinking we're a waste of money, is having too much data, and no good way to go through it. Dedicated cybersecurity tools are pretty awful, and very expensive. If I had any professional experience in software development, that's what I'd be focused on. There's only a handful of automation tools used by most of the industry, and they are only used because they're the only option, not because they're particularly good.

Re: U.S. has almost 500k job openings in cybersecurity

#44
post #8

I believe this. Most of the "security" people i run into don't know jack. Incompetence is ripe and this sector will only grow. Last external IT audit I had to explain to the auditors what a password manager was. They'd never heard of it.

Virtually all cloud deploys are misconfigured ;)

https://www.crowdstrike.com/cybersecurity-101/cloud-security...

Cloud native tools such as Cilium that leverage eBPF to provide packet level visibility but I doubt 1% of enterprises use them!

https://cloud.google.com/blog/products/containers-kubernetes...

Re: U.S. has almost 500k job openings in cybersecurity

#45
post #4

Earlier quoted context omitted.

> 0.15 % of the entire us population just for cyber security? Even better: 0.15% of the entire US population for unfilled jobs. I'm going to assume most of these aren't permanent positions but gigs.

I'm going to assume the number is for any tech job that has even the slightest but of security function, including any sysadmin, dbeng, webapp dev, etc It's just too big to be correct.

You're probably right, any tech ad featuring the tag "security".

Re: U.S. has almost 500k job openings in cybersecurity

#46
post #40
post #8

I believe this. Most of the "security" people i run into don't know jack. Incompetence is ripe and this sector will only grow. Last external IT audit I had to explain to the auditors what a password manager was. They'd never heard of it.

I prepared so much for our audit and the only thing this guy cared for in a 5 developer company was the fact that I had root access on all environments. He didn't care about Aws having 2fa configured about our vlan ipsec Tunnel, etc I even took the liberty to fix the md5 Passwort shit with bcrypt just before the audit...

That guy is completely right. I wouldn’t look at anything else either as that is already the security worst case scenario.

Re: U.S. has almost 500k job openings in cybersecurity

#47
post #43

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

I've worked in cybersecurity for ~7 years, and what you said is accurate. I'm actually switching to a government job and taking a big pay cut because the field is pretty miserable to work in for the most part. I think I've had one cybersecurity job that was actually enjoyable, and that was a Fortune 500 customer that saw the value in keeping their company safe, so their only limitations on our activity was no social…

>Dedicated cybersecurity tools are pretty awful, and very expensive

Can you give a few examples of these?

Re: U.S. has almost 500k job openings in cybersecurity

#48

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

There are a few bespoke consulting firms that actually try to improve their clients security beyond checklist whack-a-mole and automated scanning. Annoyingly bunch of charlatan firms pretend to do this, but just toss an intern with a scanner at the customer and/or double book their staff so they don’t have time to think beyond the basics. This lets them always underbid the firms that do honest work. The problem is th…

From the other side of the fence: I've been hiring companies to do external pen tests for fifteen years now. Some of them have been giant corporations with security divisions, some of them have been just past the startup stage, and some of them are recognizable big names in the industry. I've signed one year, two year and three year contracts.

A few of them have distinguished themselves, slightly, in the first year of a multi-year contract -- and then regressed to the mean in the rest.

Quoted prices vary by a factor of 4, approximately. Work done does not. Quality of work appears to be basically independent of price.

Arrogance scales with price, though.

Even if you are a non-checklist firm, I can't justify hiring you at a higher price because I can't differentiate you from the bloviators, and basically nothing you say other than "I am ptacek" can change that.

Re: U.S. has almost 500k job openings in cybersecurity

#49
post #40
post #8

I believe this. Most of the "security" people i run into don't know jack. Incompetence is ripe and this sector will only grow. Last external IT audit I had to explain to the auditors what a password manager was. They'd never heard of it.

I prepared so much for our audit and the only thing this guy cared for in a 5 developer company was the fact that I had root access on all environments. He didn't care about Aws having 2fa configured about our vlan ipsec Tunnel, etc I even took the liberty to fix the md5 Passwort shit with bcrypt just before the audit...

What did he suggest as a mitigation? or isn't that part of an audit?

Re: U.S. has almost 500k job openings in cybersecurity

#50
post #36

Earlier quoted context omitted.

Does every company > 10 employees have a security guard?

There's probably a point where insurance requires it.

Lots of companies get physical security from:

- the building that rents them an office including a guard in the lobby

- the datacenter that rents them space including guards

- the cloud service taking care of their own datacenters

On the other hand, if you have your own building or rent in an unguarded building, deal with cash, have an actual storefront -- you'll probably be hiring security yourself.

Post reply on HN