Live data from Hacker News

U.S. has almost 500k job openings in cybersecurity

cbsnews.com

21–30 of 70 posts

Re: U.S. has almost 500k job openings in cybersecurity

#21
post #4

I've reading about this "security professionals shortage" for quite some years, yet the reality is that there is no such shortage. And I think this is even expandable now to any IT field. People keep saying about shortage, but what I do see is exhausting hiring process most people just don't want to deal with.

The security industry is unique in how much and how quickly it changes. There are two kinds of companies that hire infosec professionals in my experience: Those that understand that change and the resulting need to plug their employees into the industry training pipeline, invest in their active learning and those that don't. Those that don't more often than not have laughable or terribly unbalanced job descriptions where they're willing to pay decently well but demand a golden platypus riding a unicorn, and those types of hires might have a shortage indeed.

Re: U.S. has almost 500k job openings in cybersecurity

#22

How many of those job postings list a CISSP or 5 years for an entry-level job that pays $70k? This is stuff I see often. I have extensive experience in cloud security environments, have done IR, DR/BCP planning, passed SOC II audits, and have security cert(s). But I'd have a hard time finding a security engineering job that pays similarly to what I get paid currently as a support engineer for AWS's security services.…

Security is always going to be a cost side of the business, to be minimized.

Re: U.S. has almost 500k job openings in cybersecurity

#23
I am a Sr. devops engineer and have been looking to transition to a devsecops or even some sort of security ops role for a YEAR. I am willing to take a pay cut and move to a more junior role but I can never pass the HR filter of “prior security experience needed.”

Re: U.S. has almost 500k job openings in cybersecurity

#24
post #3

The salary they mentioned in the article is too low when the downside is millions in payout

I’ve noticed that Cyber Security at a lot of companies are still stuck in the sys admin days of yore. They continue to hold on the antiquated tooling that doesn’t scale or actually detect most issues. And the idea of learning or expanding into security automation beyond their toolset is frowned upon by a not significant number of member of the community doing the day to day work. This creates an atmosphere where they SecOps teams can’t articulate the positives they are bringing to the organization. And thus the market doesn’t pay them their worth.

Compare this to DevOps where the sale has been done well and the business is convinced that these highly paid automation engineers will help the business to improve and speed up software delivery providing more income to the company.

Until security is able to properly articulate how they are helping and improving the business, not just getting in everybody’s way. The field is going to struggle to raise salaries to comparable levels as these other disciplines.

Re: U.S. has almost 500k job openings in cybersecurity

#26
post #12
post #4

I've reading about this "security professionals shortage" for quite some years, yet the reality is that there is no such shortage. And I think this is even expandable now to any IT field. People keep saying about shortage, but what I do see is exhausting hiring process most people just don't want to deal with.

"Shortage" is a synonym for "costs more than I'd like to pay for it".

Competing harder for the limited pool of competent security people might redistribute breaches away from your company onto others. From a local perspective this could be rational but as a society we want to be less vulnerable in aggregate.

(Although there I think the IT operations side is vastly overblown and not nearly enough attention is paid to quality control on the most popular software packages. Want to make every business substantially more secure at once? Take a hard look at Windows Server, Exchange, etc).

Re: U.S. has almost 500k job openings in cybersecurity

#27

How many of those job postings list a CISSP or 5 years for an entry-level job that pays $70k? This is stuff I see often. I have extensive experience in cloud security environments, have done IR, DR/BCP planning, passed SOC II audits, and have security cert(s). But I'd have a hard time finding a security engineering job that pays similarly to what I get paid currently as a support engineer for AWS's security services.…

Security is always going to be a cost side of the business, to be minimized.

If I am reading the trend correctly, we will soon see Trust/Security/Assurance move into more of a GTM function for B2B product companies.

Re: U.S. has almost 500k job openings in cybersecurity

#28

I don't know any security professionals. Is this something that a mostly-self-taught software engineer could get a job in? What are interviews typically like?

Tom Aptek’s (security company founder) pitch a few years back was

Get through ‘A Web Application Hacker’s Handbook’ and ‘Securing DevOps’ and his company would probably give you six figures and a brand new macbook.

For an extra bonus you could work through their crypto challenges.

https://cryptopals.com/sets/1

https://www.manning.com/books/securing-devops

https://archive.org/details/TheWebApplicationHackersHandbook...

Re: U.S. has almost 500k job openings in cybersecurity

#29
post #17

Earlier quoted context omitted.

Then they need to get off the Internet if they truly can't secure their systems. Or, goodness, so many people became unemployed during the pandemic, they could train them for the job they "need".

We don't put this financial burden-of-self-defense on any other industry though. Why is cybersecurity different than physical retailers? Walgreens isn't responsible for providing their own police force. Sure, they put locks on the doors, but the burden of protecting businesses is on the police, which they (and we) pay for via taxes. You could say "Oh, a business which can't defend itself against looting doesn't deser…

Walgreens - great example! That's a pharmacy. Pharmacies have to follow strict safety regulations and are constantly worried about both those and the threat of lawsuits for endangering customers. And there are also both internal and external threats to the business (drugs are a valuable, easily portable asset).

Oversimplifying a lot, Walgreens has these well-paid, trained workers they call "pharmacists" to deal with it.

Re: U.S. has almost 500k job openings in cybersecurity

#30
post #12
post #4

I've reading about this "security professionals shortage" for quite some years, yet the reality is that there is no such shortage. And I think this is even expandable now to any IT field. People keep saying about shortage, but what I do see is exhausting hiring process most people just don't want to deal with.

"Shortage" is a synonym for "costs more than I'd like to pay for it".

Paying more just means you fill your vacancy at the expense of another firm who has their employee poached. The net effect is that one company is still vulnerable.
Post reply on HN