Live data from Hacker News

U.S. has almost 500k job openings in cybersecurity

cbsnews.com

31–40 of 70 posts

Re: U.S. has almost 500k job openings in cybersecurity

#32
post #12

Earlier quoted context omitted.

"Shortage" is a synonym for "costs more than I'd like to pay for it".

Paying more just means you fill your vacancy at the expense of another firm who has their employee poached. The net effect is that one company is still vulnerable.

It also creates supply, e.g. software developers in a related field deciding to switch careers.

Re: U.S. has almost 500k job openings in cybersecurity

#33
post #11
post #4

I've reading about this "security professionals shortage" for quite some years, yet the reality is that there is no such shortage. And I think this is even expandable now to any IT field. People keep saying about shortage, but what I do see is exhausting hiring process most people just don't want to deal with.

The hiring process is definitely an issue. Cybersecurity is new enough that HR has no idea what they want, so they require useless certifications like CEH, and a college degree in CS. There's also a wide variation in what Cybersecurity even means. Some college cybersecurity programs are all about policy and compliance, while some focus on offensive security and vulnerability analysis.

Often it's not HR that writes these job adverts, it's the managers. HR is just a middleman.

Re: U.S. has almost 500k job openings in cybersecurity

#34
post #17

Earlier quoted context omitted.

Then they need to get off the Internet if they truly can't secure their systems. Or, goodness, so many people became unemployed during the pandemic, they could train them for the job they "need".

We don't put this financial burden-of-self-defense on any other industry though. Why is cybersecurity different than physical retailers? Walgreens isn't responsible for providing their own police force. Sure, they put locks on the doors, but the burden of protecting businesses is on the police, which they (and we) pay for via taxes. You could say "Oh, a business which can't defend itself against looting doesn't deser…

Cybersecurity drastically varies depending on the actions of a business in a way which physical security doesn't, short of the business failing to lock its doors at night. And if the business does fail to lock its doors, the business is directly hurt, giving businesses incentives to treat security properly, while security breaches often hurt the customers, but not the company.

Also, you don't generally see the police demanding that retailers have windows that are easy to break because the police might want to rob them themselves someday, but the equivalent is routine with the government and cybersecurity.

Re: U.S. has almost 500k job openings in cybersecurity

#35
post #12

Earlier quoted context omitted.

"Shortage" is a synonym for "costs more than I'd like to pay for it".

Paying more just means you fill your vacancy at the expense of another firm who has their employee poached. The net effect is that one company is still vulnerable.

Or another country or another industry or encourages others to join the field.

Re: U.S. has almost 500k job openings in cybersecurity

#36
Well, since ultimately this involves codewords dancing around the "don't want to pay proper wage", America's companies should instead hand their security over to outsourcing firms like they do with everything else that is IT related?

What could go wrong? Make sure to diversify to China, Russia, Eastern Europe, Malaysia, Israel etc.

Oh does that sound like a bad idea? The fact is as soon as the main systems development is outsourced, you might as well have outsourced the security too.

Probably why most enterprise security is a bunch of people buying Cisco appliances and formulating checklists and policies and don't even know specific vulnerabilities or the safety degree of various algorithms.

And of course, their main job, making powerpoints for upper management and occupying seats/budget such that when leaks or failures occur upper management has plausible deniability.

Re: U.S. has almost 500k job openings in cybersecurity

#37

Earlier quoted context omitted.

I wonder if it is like the rural doctor/nurse/cop shortages though. Those places don't want to pay, so don't care if the jobs are actually filled. How many of the 465,000 jobs do companies actually care get filled? Or do they just have them open just in case someone cheap walks through the door?

The rural doctor shortage is probably a really good parallel, because as a society we in the abstract agree that it's Very Bad to let people die without reasonable access to healthcare, but poor rural communities simply can't support paying doctor or even nurses to be available. There's still a ton of society loss / deadweight because of the consequences of not having those services; the question is, how can we restr…

The rural doctor shortage is caused by the American Medical Association cartel deliberately restricting the supply of doctors to keep prices high. When there isn't even enough supply to meet the needs of desirable urban areas, what chances does the middle of nowhere in the Midwest or Alaska have?

I once dated an Indian-born MD who immigrated to the US. A Senator from Missouri went to bat personally (not one of his staff) to get her a green card under the proviso she would settle in rural Missouri, because he understood that's what it takes (she moved to Maryland after a few years).

Re: U.S. has almost 500k job openings in cybersecurity

#38
post #17

Earlier quoted context omitted.

Then they need to get off the Internet if they truly can't secure their systems. Or, goodness, so many people became unemployed during the pandemic, they could train them for the job they "need".

We don't put this financial burden-of-self-defense on any other industry though. Why is cybersecurity different than physical retailers? Walgreens isn't responsible for providing their own police force. Sure, they put locks on the doors, but the burden of protecting businesses is on the police, which they (and we) pay for via taxes. You could say "Oh, a business which can't defend itself against looting doesn't deser…

Well, that's one of the drivers for companies migrating their apps to the cloud.

Re: U.S. has almost 500k job openings in cybersecurity

#39
post #12

Earlier quoted context omitted.

"Shortage" is a synonym for "costs more than I'd like to pay for it".

Paying more just means you fill your vacancy at the expense of another firm who has their employee poached. The net effect is that one company is still vulnerable.

They are all in this together? Paying more means you fill your vacancy.

Edit: The cheapskate can follow suit and maybe that convinces one person to undertake the 8-week cert. No more shortage. Or maybe they don't pay more and are DDoS'd out of business. Again, no more shortage.

Re: U.S. has almost 500k job openings in cybersecurity

#40
post #17

Earlier quoted context omitted.

Then they need to get off the Internet if they truly can't secure their systems. Or, goodness, so many people became unemployed during the pandemic, they could train them for the job they "need".

We don't put this financial burden-of-self-defense on any other industry though. Why is cybersecurity different than physical retailers? Walgreens isn't responsible for providing their own police force. Sure, they put locks on the doors, but the burden of protecting businesses is on the police, which they (and we) pay for via taxes. You could say "Oh, a business which can't defend itself against looting doesn't deser…

In San Francisco, Walgreens is responsible for providing their own security force, so they decided to stop operating there.

Companies that can't secure their operations can hire others, like Shopify, Paypal, etc to conduct online operations for them. We've all heard the many stories of professionals making security recommendations and being overruled. If you don't want to invest in security, then don't have valuable data in computers connected to the Internet. Experian exposed our data and faced basically zero consequences, so I don't have any sympathy.

Post reply on HN