Live data from Hacker News

U.S. has almost 500k job openings in cybersecurity

cbsnews.com

71–80 of 103 posts

Re: U.S. has almost 500k job openings in cybersecurity

#71
post #68

Earlier quoted context omitted.

Eliminate root access. If an intruder gets into your network they have unrestricted access to everything. Game over. The solution is defense in depth. Have different accounts with separate access to various services. That way if an account is compromised they don’t have access to everything. Most of your accounts should provide least access to what they need. Higher level accounts allowing greater control of your sys…

I'm not logging in as root directly. But non the less with 5 people what audit system would be even available in which only one person has access. All smart concepts cost either a lot of money or just don't work if you don't have enough people. Should the only techlead have access to the audit system? Probably. Should the only techlead have access to VMs? Probably yes. I made sure my systems are encrypted, 2fa wherev…

Security is hard. As a business owner that is a risk you accept.

I know this sounds mean but software developers are really embarrassingly bad at security, because security is inconvenient by design and developers strive for convenience.

Re: U.S. has almost 500k job openings in cybersecurity

#72

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

The stereotype I heard was that security is under appreciated, so you get less respect at work while simultaneously getting paid less. I don’t know first hand, is this true?

Re: U.S. has almost 500k job openings in cybersecurity

#73

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

I'm convinced that if you are doing cyber sec at any large company you spend most of your time in Excel and not a shell - whack-a-mole is the best way to look at it.

Re: U.S. has almost 500k job openings in cybersecurity

#75
post #42
post #23

Earlier quoted context omitted.

It's IT via checklist. I can't imagine a more depressing way to go through my life. Talking to the cybersecurity people I know they all frame it like they're elite warriors who are locked in a titanic struggle with cunning adversaries. My take is...you followup on tickets generated by third party tools by filling out web forms. Yes you're getting 'probed' by Russia and China all the time but thats from botnets lookin…

Ask anyone in Aviation, checklists matter. Cybersecurity is often drudgery, but avoiding excitement is the entire point.

http://atulgawande.com/book/the-checklist-manifesto/

Yes, Checklist in aviation and aerospace are crucial, but at the same time, you have to avoid checklist for checklist sake.

But they also do a lot of failure response testing, simulations where you walk through a failed checklist or incidient and how you would response. Cypersecurity does pen testing and phishing attempts, but how about dry runs where you act as if you are compromised and everyone runs a "fire drill" scenario?

Re: U.S. has almost 500k job openings in cybersecurity

#76
post #41
post #23

Earlier quoted context omitted.

It's IT via checklist. I can't imagine a more depressing way to go through my life. Talking to the cybersecurity people I know they all frame it like they're elite warriors who are locked in a titanic struggle with cunning adversaries. My take is...you followup on tickets generated by third party tools by filling out web forms. Yes you're getting 'probed' by Russia and China all the time but thats from botnets lookin…

A roommate studying for aerospace engineering described that field as "Everyone gets in because they want to work at Skunkworks and design the SR-71. In reality, 95% of graduates will spend the next 40 years optimizing the efficiency of a winglet on a 747." Security feels similar. The edge of the spear is fascinating, exciting, challenging work. Unfortunately, no one needs that work. What companies actually need is m…

Its so true, was very depressing when working at my first aero job

Re: U.S. has almost 500k job openings in cybersecurity

#77
post #65

Earlier quoted context omitted.

Currently, IT checklists are security theater. Reducing liability vs improving security. How many orgs are transitioning to zero knowledge networks, encrypting all data at rest?

> encrypting all data at rest That’s a common checklist item. Implementing it is of course more work than just checking the box, but ensuring it’s actually done means it’s added to a lot of different checklists.

checkmate

Re: U.S. has almost 500k job openings in cybersecurity

#78
post #41
post #23

Earlier quoted context omitted.

It's IT via checklist. I can't imagine a more depressing way to go through my life. Talking to the cybersecurity people I know they all frame it like they're elite warriors who are locked in a titanic struggle with cunning adversaries. My take is...you followup on tickets generated by third party tools by filling out web forms. Yes you're getting 'probed' by Russia and China all the time but thats from botnets lookin…

A roommate studying for aerospace engineering described that field as "Everyone gets in because they want to work at Skunkworks and design the SR-71. In reality, 95% of graduates will spend the next 40 years optimizing the efficiency of a winglet on a 747." Security feels similar. The edge of the spear is fascinating, exciting, challenging work. Unfortunately, no one needs that work. What companies actually need is m…

Optimizing the wingtip on a 747 actually sounds interesting, and it's the sort of thing that could meaningfully affect the world. It might even prevent more wars than the SR-71 program in terms of lessening ecological and environmental pressures.

A much worse career would be convincing regulators that new aircraft like the 737 MAX don't need any additional training. Maintaining lists of open exploits, and keeping them secret from vulnerable parties is that kind of job, where you're making the world less safe in a perversion of your ostensible goals.

Re: U.S. has almost 500k job openings in cybersecurity

#79
post #42

Earlier quoted context omitted.

Ask anyone in Aviation, checklists matter. Cybersecurity is often drudgery, but avoiding excitement is the entire point.

Currently, IT checklists are security theater. Reducing liability vs improving security. How many orgs are transitioning to zero knowledge networks, encrypting all data at rest?

Encrypting data at rest at least is getting better if only because more systems do it by default as time goes on.
Post reply on HN