Live data from Hacker News

U.S. has almost 500k job openings in cybersecurity

cbsnews.com

11–20 of 70 posts

Re: U.S. has almost 500k job openings in cybersecurity

#11
post #4

I've reading about this "security professionals shortage" for quite some years, yet the reality is that there is no such shortage. And I think this is even expandable now to any IT field. People keep saying about shortage, but what I do see is exhausting hiring process most people just don't want to deal with.

The hiring process is definitely an issue. Cybersecurity is new enough that HR has no idea what they want, so they require useless certifications like CEH, and a college degree in CS. There's also a wide variation in what Cybersecurity even means. Some college cybersecurity programs are all about policy and compliance, while some focus on offensive security and vulnerability analysis.

Re: U.S. has almost 500k job openings in cybersecurity

#12
post #4

I've reading about this "security professionals shortage" for quite some years, yet the reality is that there is no such shortage. And I think this is even expandable now to any IT field. People keep saying about shortage, but what I do see is exhausting hiring process most people just don't want to deal with.

"Shortage" is a synonym for "costs more than I'd like to pay for it".

Re: U.S. has almost 500k job openings in cybersecurity

#14

How many of those job postings list a CISSP or 5 years for an entry-level job that pays $70k? This is stuff I see often. I have extensive experience in cloud security environments, have done IR, DR/BCP planning, passed SOC II audits, and have security cert(s). But I'd have a hard time finding a security engineering job that pays similarly to what I get paid currently as a support engineer for AWS's security services.…

> But I'd have a hard time finding a security engineering job that pays similarly to what I get paid currently as a support engineer for AWS's security services.

I would assume that AWS would be near the top of compensation no matter what job when looking at American companies.

Re: U.S. has almost 500k job openings in cybersecurity

#15

Meta on the comments: While it's true that the salaries are unreasonably low, it doesn't mean that there are 500k Americans capable of doing cybersecurity work just waiting for the right paycheck. There can be _both_ a worker shortage and unreasonable salary expectations. A labor market will always have slack on both sides, but even at the extreme, there could be 10 cybersecurity experts, and you'd have people saying…

I wonder if it is like the rural doctor/nurse/cop shortages though. Those places don't want to pay, so don't care if the jobs are actually filled. How many of the 465,000 jobs do companies actually care get filled? Or do they just have them open just in case someone cheap walks through the door?

The rural doctor shortage is probably a really good parallel, because as a society we in the abstract agree that it's Very Bad to let people die without reasonable access to healthcare, but poor rural communities simply can't support paying doctor or even nurses to be available.

There's still a ton of society loss / deadweight because of the consequences of not having those services; the question is, how can we restructure the supply side of the argument to make it possible? For doctors+nurses, it's via government subsidies (income-based repayment, federal grants).

ie, the cost of security breaches isn't to the companies being breached -- it's to the consumers who lose their PII/PHI to hackers. Or who lose access to a service they love using, because they can't keep running without a security expert.

Re: U.S. has almost 500k job openings in cybersecurity

#16

Meta on the comments: While it's true that the salaries are unreasonably low, it doesn't mean that there are 500k Americans capable of doing cybersecurity work just waiting for the right paycheck. There can be _both_ a worker shortage and unreasonable salary expectations. A labor market will always have slack on both sides, but even at the extreme, there could be 10 cybersecurity experts, and you'd have people saying…

> There can be _both_ a worker shortage and unreasonable salary expectations.

This is true, but unreasonable salary expectations exacerbates a worker shortage.

I can either try to find security work with reasonable expectations and salary, or I can take the skills I learned in security to learn IaaC, CI/CD, and Docker (which takes maybe a couple months?) and go do DevOps to make a lot more money. Sure I'm not passionate about DevOps, nor do I feel I'll be making more of a societal impact in DevOps. But I'll be materially better off and won't have to sift through hundreds of job postings to find a posting with reasonable expectations.

The end result? Another qualified, passionate person outside of the job pool.

Re: U.S. has almost 500k job openings in cybersecurity

#17

Meta on the comments: While it's true that the salaries are unreasonably low, it doesn't mean that there are 500k Americans capable of doing cybersecurity work just waiting for the right paycheck. There can be _both_ a worker shortage and unreasonable salary expectations. A labor market will always have slack on both sides, but even at the extreme, there could be 10 cybersecurity experts, and you'd have people saying…

Then they need to get off the Internet if they truly can't secure their systems.

Or, goodness, so many people became unemployed during the pandemic, they could train them for the job they "need".

Re: U.S. has almost 500k job openings in cybersecurity

#19

How many of those job postings list a CISSP or 5 years for an entry-level job that pays $70k? This is stuff I see often. I have extensive experience in cloud security environments, have done IR, DR/BCP planning, passed SOC II audits, and have security cert(s). But I'd have a hard time finding a security engineering job that pays similarly to what I get paid currently as a support engineer for AWS's security services.…

> But I'd have a hard time finding a security engineering job that pays similarly to what I get paid currently as a support engineer for AWS's security services. I would assume that AWS would be near the top of compensation no matter what job when looking at American companies.

Really depends on what Org you're working for. I've had a lot of colleagues in support get pulled away to SaaS vendors to get paid more. I actually talked with a friend the other day who essentially offered me a job with 50% the workload and $30k+ more per year.

While SDE/SDMs/etc. probably get paid the top of the compensation when looking across companies, support isn't the same. Also, most of that is likely tied up in RSUs.

But I know for a fact L4 people in AWS's SOC get paid more than L5s in support. But AWS's SOC isn't a remote position, and I'm not in a position to move to where the SOC teams are located.

Re: U.S. has almost 500k job openings in cybersecurity

#20
post #17

Meta on the comments: While it's true that the salaries are unreasonably low, it doesn't mean that there are 500k Americans capable of doing cybersecurity work just waiting for the right paycheck. There can be _both_ a worker shortage and unreasonable salary expectations. A labor market will always have slack on both sides, but even at the extreme, there could be 10 cybersecurity experts, and you'd have people saying…

Then they need to get off the Internet if they truly can't secure their systems. Or, goodness, so many people became unemployed during the pandemic, they could train them for the job they "need".

We don't put this financial burden-of-self-defense on any other industry though. Why is cybersecurity different than physical retailers?

Walgreens isn't responsible for providing their own police force. Sure, they put locks on the doors, but the burden of protecting businesses is on the police, which they (and we) pay for via taxes.

You could say "Oh, a business which can't defend itself against looting doesn't deserve to be in business", and maybe you end up with like 5 mega-Walmarts who can afford heavily armed guards, but this isn't actually a better society in the end than one with robust small businesses.

It's the same with cybersecurity -- you can take everyone except Google, Amazon, and Facebook off the internet, because only those three can hire top-of-the-line security professionals, but that's not actually a better internet than the one we have now.

Post reply on HN