Live data from Hacker News

U.S. has almost 500k job openings in cybersecurity

cbsnews.com

51–60 of 103 posts

Re: U.S. has almost 500k job openings in cybersecurity

#51
post #43

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

I've worked in cybersecurity for ~7 years, and what you said is accurate. I'm actually switching to a government job and taking a big pay cut because the field is pretty miserable to work in for the most part. I think I've had one cybersecurity job that was actually enjoyable, and that was a Fortune 500 customer that saw the value in keeping their company safe, so their only limitations on our activity was no social…

Is there somewhere already extant I can read about the shortcomings of the available tools, or would I need to do some networking with people to find that information?

I've considered making tools of my own for some things, but knowing what would actually be useful to people doing real work would be a good motivator.

Re: U.S. has almost 500k job openings in cybersecurity

#52

Earlier quoted context omitted.

There are a few bespoke consulting firms that actually try to improve their clients security beyond checklist whack-a-mole and automated scanning. Annoyingly bunch of charlatan firms pretend to do this, but just toss an intern with a scanner at the customer and/or double book their staff so they don’t have time to think beyond the basics. This lets them always underbid the firms that do honest work. The problem is th…

The pentesting industry has a big problem with being a good "market for lemons". It's very hard for customers to differentiate the good and bad companies, without having their own internal expertise, and even then you need to go down the line of getting named testers and speaking to each one. Another problem is with how many/most pentest companies report, which is by exception. There's no requirement to state all the…

Our reports always have a section on things we looked at or for. Doing so takes a majority of the time it takes to write the report. Since it adds to the cost, firms that don’t do this can underbid the ones that do.

For slimmed down reports that are published/given to third parties (given to the customer’s customer) it’s extremely important that the scope of the test is detailed in that letter. The charlatan firms will be happy to omit the fact that they only tested the “about us” page while blind-folded.

So if you are reading a “letter of assessment” for something you are thinking of adopting, just look for the scope of the test, and if it sounds reasonable they potentially had a good test. If it’s missing, the test wasn’t worth the electrons in that letter.

Re: U.S. has almost 500k job openings in cybersecurity

#53
post #23

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

It's IT via checklist. I can't imagine a more depressing way to go through my life. Talking to the cybersecurity people I know they all frame it like they're elite warriors who are locked in a titanic struggle with cunning adversaries. My take is...you followup on tickets generated by third party tools by filling out web forms. Yes you're getting 'probed' by Russia and China all the time but thats from botnets lookin…

If you're looking for a career with literally no bureaucratic overhead--no checklists, no tickets, no paper pushing, then IT is not the field for you. Every IT field has bureaucratic overhead. Yes, beginners rely on checklists more than experienced people do, but that's the same for any field.

Re: U.S. has almost 500k job openings in cybersecurity

#54
post #4

Earlier quoted context omitted.

> 0.15 % of the entire us population just for cyber security? Even better: 0.15% of the entire US population for unfilled jobs. I'm going to assume most of these aren't permanent positions but gigs.

I'm going to assume the number is for any tech job that has even the slightest but of security function, including any sysadmin, dbeng, webapp dev, etc It's just too big to be correct.

Probably non-dev jobs too, managers, tech writers, HR, office assistants, etc.

Re: U.S. has almost 500k job openings in cybersecurity

#55
post #48

Earlier quoted context omitted.

There are a few bespoke consulting firms that actually try to improve their clients security beyond checklist whack-a-mole and automated scanning. Annoyingly bunch of charlatan firms pretend to do this, but just toss an intern with a scanner at the customer and/or double book their staff so they don’t have time to think beyond the basics. This lets them always underbid the firms that do honest work. The problem is th…

From the other side of the fence: I've been hiring companies to do external pen tests for fifteen years now. Some of them have been giant corporations with security divisions, some of them have been just past the startup stage, and some of them are recognizable big names in the industry. I've signed one year, two year and three year contracts. A few of them have distinguished themselves, slightly, in the first year o…

This is a good perspective. I pushed for a higher priced pen test firm in our last engagement due their name/reputation (i was sick of nessus scan outputs) but ultimately their price was just SO MUCH cheaper than the prestigious named one. I couldn't provide a justification to leadership outside of "they have these awesome writeups in their research division". Asking to see a sample report to prospective firm turns out to be a crapshoot as well (but seems to be one of the few things to go off of). Can you provide any insight on how you evaluate?

Re: U.S. has almost 500k job openings in cybersecurity

#57

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

4. Software development within cybersecurity. Ie. developing the tools of the trade. See [0] for an example of an opensource tool. I would say this is pretty interesting work.

[0] https://www.zaproxy.org/

Re: U.S. has almost 500k job openings in cybersecurity

#58
post #23

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

It's IT via checklist. I can't imagine a more depressing way to go through my life. Talking to the cybersecurity people I know they all frame it like they're elite warriors who are locked in a titanic struggle with cunning adversaries. My take is...you followup on tickets generated by third party tools by filling out web forms. Yes you're getting 'probed' by Russia and China all the time but thats from botnets lookin…

Don't be so hard on checklists :) the bigger problem is applying ill conceived checklists no?

Re: U.S. has almost 500k job openings in cybersecurity

#59
post #48

Earlier quoted context omitted.

There are a few bespoke consulting firms that actually try to improve their clients security beyond checklist whack-a-mole and automated scanning. Annoyingly bunch of charlatan firms pretend to do this, but just toss an intern with a scanner at the customer and/or double book their staff so they don’t have time to think beyond the basics. This lets them always underbid the firms that do honest work. The problem is th…

From the other side of the fence: I've been hiring companies to do external pen tests for fifteen years now. Some of them have been giant corporations with security divisions, some of them have been just past the startup stage, and some of them are recognizable big names in the industry. I've signed one year, two year and three year contracts. A few of them have distinguished themselves, slightly, in the first year o…

Security unfortunately is a creative process, which is hard to get consistent. I would love to use something like statistical product control, but I have yet to see a good way to apply it (or similar techniques) without forcing pen-tests to be “follow the checklist”.

Re: U.S. has almost 500k job openings in cybersecurity

#60
post #49
post #40

Earlier quoted context omitted.

I prepared so much for our audit and the only thing this guy cared for in a 5 developer company was the fact that I had root access on all environments. He didn't care about Aws having 2fa configured about our vlan ipsec Tunnel, etc I even took the liberty to fix the md5 Passwort shit with bcrypt just before the audit...

What did he suggest as a mitigation? or isn't that part of an audit?

He suggested that my CEO or CTO would be needed to be called if I needed root access.

Like some 4 eye system.

They both liked the idea very much that I might need to call them for access to systems I build :D

Post reply on HN