Live data from Hacker News

Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

cybersecurityventures.com

31–40 of 66 posts

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#31
post #13

Well, one role in this might be that a lot of cybersecurity jobs are complete bullshit, and or their certifications are. I won a free certification course as an EC-Council Certified Security Analyst, and it's the biggest joke I've ever seen. It's such a massive fucking joke that I decided to not even renew my certification for free because it would just have been a waste of time. Most of these "cybersecurity" jobs ar…

> I won a free certification course as an EC-Council Certified Security Analyst, and it's the biggest joke I've ever seen. It's such a massive fucking joke that I decided to not even renew my certification for free because it would just have been a waste of time. I've been in the field for a couple of years. I work for a global corporation with 10k+ employees and most of our team members in the security department ar…

>Care to explain why you think intrusion detection is bullshit?

If they're signature based they're not better than antivirus. I have zero faith in signature based systems.

For the stuff that uses machine learning, I have to admit, I have no idea how that stuff performs. But in general I wouldn't trust a machine learning model to not be fooled.

Edit: Add to that HTTPS, I don't buy any claim that they can spot malware traffic from malware that isn't dumb, and I don't think MITMing all traffic is an acceptable solution.

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#32
Worked with a security solution, spammed company’s distribution list specifically for this work with alerts. I ended up analyzed everything and found not just false positives but also wrong analysis from their analysts... this is to say the intention to selling security solution out could be good and genuine, but the values in return can be nothing. So why companies pay? 99% is “let the experts deal with the problem, if shit happens, we know who to blame, we have done our due diligence so one more thing to check off on auditor’s radar.”

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#33
post #23
post #13

Well, one role in this might be that a lot of cybersecurity jobs are complete bullshit, and or their certifications are. I won a free certification course as an EC-Council Certified Security Analyst, and it's the biggest joke I've ever seen. It's such a massive fucking joke that I decided to not even renew my certification for free because it would just have been a waste of time. Most of these "cybersecurity" jobs ar…

IT has a shortage of metasploit/burpscanner/nexpose/nessus jockeys and XYZ security appliance administrators at low salaries. The positions you're talking about are an incredibly difficult sell to companies. Top 10 companies have a few positions on hire at decent wages doing unique work but that's it. Some companies cyber defense strategy just involves buying a bunch of insurance. Plenty of pen testing mega-mart cons…

Buying insurance might be the most cost effective strategy. If insurance of $2MM would cover your liability, why incur 3MM expenditures and still only be reasonably secure?

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#36
post #13

Well, one role in this might be that a lot of cybersecurity jobs are complete bullshit, and or their certifications are. I won a free certification course as an EC-Council Certified Security Analyst, and it's the biggest joke I've ever seen. It's such a massive fucking joke that I decided to not even renew my certification for free because it would just have been a waste of time. Most of these "cybersecurity" jobs ar…

I have NEVER heard a useful description by a cybersecurity analyst (i.e. detecting intrusions and exfiltration) on how they do their work, despite being in a position where they should have been able to do so. Usually I just get shrugged shoulders.

I can't tell what this post is implying - that sec analysts are like... a fake job?

Can you please elaborate?

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#37

Ironically, going to https://www.cybersecurityventures.com in Firefox throws an SSL certificate error: SSL_ERROR_BAD_CERT_DOMAIN. This does not fill me with confidence regarding this company's security prowess.

Do you think there's much overlap between the people generating reports and the people in charge of hosting their domain/ managing certs?

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#38

Sounds great. But how would I (software engineer) go about moving into those sorts of jobs? Do bug bounties until I make it?

Talk with ops guys and have a security guy (that typically is on that team) assign you things to fix. It’s a bull shit job, as far as software development goes. Sure, you’ll learn a bunch of hacks and ways to fix them and maybe pass cissp cert if you really don’t want to code anymore.

[deleted]

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#39
post #13

Well, one role in this might be that a lot of cybersecurity jobs are complete bullshit, and or their certifications are. I won a free certification course as an EC-Council Certified Security Analyst, and it's the biggest joke I've ever seen. It's such a massive fucking joke that I decided to not even renew my certification for free because it would just have been a waste of time. Most of these "cybersecurity" jobs ar…

> I won a free certification course as an EC-Council Certified Security Analyst, and it's the biggest joke I've ever seen. It's such a massive fucking joke that I decided to not even renew my certification for free because it would just have been a waste of time. I've been in the field for a couple of years. I work for a global corporation with 10k+ employees and most of our team members in the security department ar…

I've worked with global retail banks, investment banks, nationwide insurance firms, stock exchanges, power grid operators, biglaw firms, payroll and benefits providers, and a giant global pharma. Not one of them demanded that I or anyone I worked with possess a certification of any sort. I'm confident there are firms that want to see a CISSP --- I'm guessing they're mostly mid-range regional firms --- but it's not a bigco thing.

I second the IDS and WAF bullshit argument.

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#40
post #31

Earlier quoted context omitted.

> I won a free certification course as an EC-Council Certified Security Analyst, and it's the biggest joke I've ever seen. It's such a massive fucking joke that I decided to not even renew my certification for free because it would just have been a waste of time. I've been in the field for a couple of years. I work for a global corporation with 10k+ employees and most of our team members in the security department ar…

>Care to explain why you think intrusion detection is bullshit? If they're signature based they're not better than antivirus. I have zero faith in signature based systems. For the stuff that uses machine learning, I have to admit, I have no idea how that stuff performs. But in general I wouldn't trust a machine learning model to not be fooled. Edit: Add to that HTTPS, I don't buy any claim that they can spot malware…

Anomaly detection doesn't do much better than signature systems do. It finds real stuff, but it "finds" so much garbage that the signal is swamped by it.
Post reply on HN