Live data from Hacker News

U.S. has almost 500k job openings in cybersecurity

cbsnews.com

91–100 of 103 posts

Re: U.S. has almost 500k job openings in cybersecurity

#91

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

This is me. There's nothing more boring than those positions. (Or to me, unethical than working for the US government) I'd much rather create something that benefits the world. Maybe the partial solution is bug bounties? As much as I'd hate those positions, I actively poke around for holes in websites for fun. I love when I have to do business with a small poorly run website, seems you can always find something they…

> (Or to me, unethical than working for the US government) I'd much rather create something that benefits the world.

I’ll be a little more nuanced. I’m very appreciate of the hard work nist does posting best practices and guidelines on privacy, zero-trust, crypto, and other things. The SP series of publications are well respected and do lift the entire industry up to some minimum standard. In some cases they actually move things forward by a lot (like the AES competition)

Re: U.S. has almost 500k job openings in cybersecurity

#92
post #78
post #41

Earlier quoted context omitted.

A roommate studying for aerospace engineering described that field as "Everyone gets in because they want to work at Skunkworks and design the SR-71. In reality, 95% of graduates will spend the next 40 years optimizing the efficiency of a winglet on a 747." Security feels similar. The edge of the spear is fascinating, exciting, challenging work. Unfortunately, no one needs that work. What companies actually need is m…

Optimizing the wingtip on a 747 actually sounds interesting, and it's the sort of thing that could meaningfully affect the world. It might even prevent more wars than the SR-71 program in terms of lessening ecological and environmental pressures. A much worse career would be convincing regulators that new aircraft like the 737 MAX don't need any additional training. Maintaining lists of open exploits, and keeping the…

> Optimizing the wingtip on a 747 actually sounds interesting

That was my first thought as a software dev - I'd love to be able to spend time _optimizing_ something rather than breaking my "stories" down to one-to-two hour "tasks" and justifying my "estimates" every morning.

Re: U.S. has almost 500k job openings in cybersecurity

#93
post #23

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

It's IT via checklist. I can't imagine a more depressing way to go through my life. Talking to the cybersecurity people I know they all frame it like they're elite warriors who are locked in a titanic struggle with cunning adversaries. My take is...you followup on tickets generated by third party tools by filling out web forms. Yes you're getting 'probed' by Russia and China all the time but thats from botnets lookin…

[deleted]

Re: U.S. has almost 500k job openings in cybersecurity

#94
post #15

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

is hunting for bounties not viable?

As a primary source of income? Not really.

You could spend weeks looking for bugs and find nothing and not make a dime.

Re: U.S. has almost 500k job openings in cybersecurity

#95
post #43

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

I've worked in cybersecurity for ~7 years, and what you said is accurate. I'm actually switching to a government job and taking a big pay cut because the field is pretty miserable to work in for the most part. I think I've had one cybersecurity job that was actually enjoyable, and that was a Fortune 500 customer that saw the value in keeping their company safe, so their only limitations on our activity was no social…

I did it for 3.5 years and then I jumped ship back to just regular development. When I started, we were actually really great at discovering and solving actual issues. Our VP got replaced with someone who wanted us to only work on compliance checklists, and the joy I found in that job went from 100 to 0 in an instant.

Re: U.S. has almost 500k job openings in cybersecurity

#96
I get that the US government funded part of the research this article is based on, but I think substantial skepticism is warranted -- as with all 'IT shortage' articles.

Many US agencies are mis/guided/influenced/funded/run directly and/or indirectly by industry professionals, lobbyists, etc.

If there was any actual shortage of IT personnel in the US, it would not take experienced US-based IT professionals months or years of job searching to find work -- if at all.

There is no conspiracy theory necessary -- in this case, it's pretty clear-cut -- a training company needed some PR to drum up business, so they got their lobbyist to work with a group inside an agency in the government, got a report, pinged their contact at CBS, done.

But outside of that, it'd be nice to know how 500,000 alleged openings compares historically. It's obviously a number that is supposed to impress.

But how impressed should we be?

How fast is the number growing?

If the number is going up, why aren't all these unemployed IT professionals getting hired? Companies are willing to sustain IT attacks instead of hire and train an experienced IT professional?

Hiring remotely is easier than ever, but does that apply to security jobs? Are clearances necessary? Physical presence?

What is the appropriate number of job openings, per IT vertical (e.g. cybersecurity, networking, cloud, big data, SCADA, etc.), at any point in time, to provide proper 'slack'/fluidity of the labor force? Presumably this would be some number that the IT industry was roughly comfortable with, that industry analysts/economists thought was 'healthy', etc.

Is that 10,000 job openings? 100,000? 1,000,000?

Re: U.S. has almost 500k job openings in cybersecurity

#97
post #88

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

The industry gets a bad rap, because it's full of ego maniacs, but the reality is that there are tons of interesting opportunities that fall outside conventional compliance/pen-testing roles. Research is actually a huge sector, because you can apply security research to so many emerging and existing industries. You can specialize is specific things as well. Take for example blockchain. !0 years ago there were no cryp…

Security research fascinated me after reading a number of papers on really cool exploits, but it was quickly evident it wasn't something I'd ever be cut out for. Anyways, do you typically have to be highly credentialed to do it? How many people are getting hired as security researchers without prior [academic] research?

Re: U.S. has almost 500k job openings in cybersecurity

#99

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

There are a few bespoke consulting firms that actually try to improve their clients security beyond checklist whack-a-mole and automated scanning. Annoyingly bunch of charlatan firms pretend to do this, but just toss an intern with a scanner at the customer and/or double book their staff so they don’t have time to think beyond the basics. This lets them always underbid the firms that do honest work. The problem is th…

This is what I am working hard towards, moving to a firm like yours.

Re: U.S. has almost 500k job openings in cybersecurity

#100
post #58
post #23

Earlier quoted context omitted.

It's IT via checklist. I can't imagine a more depressing way to go through my life. Talking to the cybersecurity people I know they all frame it like they're elite warriors who are locked in a titanic struggle with cunning adversaries. My take is...you followup on tickets generated by third party tools by filling out web forms. Yes you're getting 'probed' by Russia and China all the time but thats from botnets lookin…

Don't be so hard on checklists :) the bigger problem is applying ill conceived checklists no?

On one hand, the security checklists are laughably insufficient, you can tick all the boxes and still have systems with as many holes as Swiss cheese.

On the other hand, so many real breaches have happened because very basic things weren't done, and a basic checklist would have shown that they aren't done. But of course, that checklist would not cause the organization to provide the resources and motivation to actually fix the issues.

The big problem with checklists is that organizations inherently don't really want to invest to fix these problems, they have other priorities, and if someone else forces a checklist on them, then they often will explicitly prioritize ticking off the boxes (with any caveats they can negotiate or hide) at the expense of actual security.

Post reply on HN