U.S. has almost 500k job openings in cybersecurity
31–40 of 70 posts
Re: U.S. has almost 500k job openings in cybersecurity
#32Earlier quoted context omitted.
"Shortage" is a synonym for "costs more than I'd like to pay for it".
Paying more just means you fill your vacancy at the expense of another firm who has their employee poached. The net effect is that one company is still vulnerable.
Re: U.S. has almost 500k job openings in cybersecurity
#33I've reading about this "security professionals shortage" for quite some years, yet the reality is that there is no such shortage. And I think this is even expandable now to any IT field. People keep saying about shortage, but what I do see is exhausting hiring process most people just don't want to deal with.
The hiring process is definitely an issue. Cybersecurity is new enough that HR has no idea what they want, so they require useless certifications like CEH, and a college degree in CS. There's also a wide variation in what Cybersecurity even means. Some college cybersecurity programs are all about policy and compliance, while some focus on offensive security and vulnerability analysis.
Re: U.S. has almost 500k job openings in cybersecurity
#34Earlier quoted context omitted.
Then they need to get off the Internet if they truly can't secure their systems. Or, goodness, so many people became unemployed during the pandemic, they could train them for the job they "need".
We don't put this financial burden-of-self-defense on any other industry though. Why is cybersecurity different than physical retailers? Walgreens isn't responsible for providing their own police force. Sure, they put locks on the doors, but the burden of protecting businesses is on the police, which they (and we) pay for via taxes. You could say "Oh, a business which can't defend itself against looting doesn't deser…
Also, you don't generally see the police demanding that retailers have windows that are easy to break because the police might want to rob them themselves someday, but the equivalent is routine with the government and cybersecurity.
Re: U.S. has almost 500k job openings in cybersecurity
#35Earlier quoted context omitted.
"Shortage" is a synonym for "costs more than I'd like to pay for it".
Paying more just means you fill your vacancy at the expense of another firm who has their employee poached. The net effect is that one company is still vulnerable.
Re: U.S. has almost 500k job openings in cybersecurity
#36What could go wrong? Make sure to diversify to China, Russia, Eastern Europe, Malaysia, Israel etc.
Oh does that sound like a bad idea? The fact is as soon as the main systems development is outsourced, you might as well have outsourced the security too.
Probably why most enterprise security is a bunch of people buying Cisco appliances and formulating checklists and policies and don't even know specific vulnerabilities or the safety degree of various algorithms.
And of course, their main job, making powerpoints for upper management and occupying seats/budget such that when leaks or failures occur upper management has plausible deniability.
Re: U.S. has almost 500k job openings in cybersecurity
#37Earlier quoted context omitted.
I wonder if it is like the rural doctor/nurse/cop shortages though. Those places don't want to pay, so don't care if the jobs are actually filled. How many of the 465,000 jobs do companies actually care get filled? Or do they just have them open just in case someone cheap walks through the door?
The rural doctor shortage is probably a really good parallel, because as a society we in the abstract agree that it's Very Bad to let people die without reasonable access to healthcare, but poor rural communities simply can't support paying doctor or even nurses to be available. There's still a ton of society loss / deadweight because of the consequences of not having those services; the question is, how can we restr…
I once dated an Indian-born MD who immigrated to the US. A Senator from Missouri went to bat personally (not one of his staff) to get her a green card under the proviso she would settle in rural Missouri, because he understood that's what it takes (she moved to Maryland after a few years).
Re: U.S. has almost 500k job openings in cybersecurity
#38Earlier quoted context omitted.
Then they need to get off the Internet if they truly can't secure their systems. Or, goodness, so many people became unemployed during the pandemic, they could train them for the job they "need".
We don't put this financial burden-of-self-defense on any other industry though. Why is cybersecurity different than physical retailers? Walgreens isn't responsible for providing their own police force. Sure, they put locks on the doors, but the burden of protecting businesses is on the police, which they (and we) pay for via taxes. You could say "Oh, a business which can't defend itself against looting doesn't deser…
Re: U.S. has almost 500k job openings in cybersecurity
#39Earlier quoted context omitted.
"Shortage" is a synonym for "costs more than I'd like to pay for it".
Paying more just means you fill your vacancy at the expense of another firm who has their employee poached. The net effect is that one company is still vulnerable.
Edit: The cheapskate can follow suit and maybe that convinces one person to undertake the 8-week cert. No more shortage. Or maybe they don't pay more and are DDoS'd out of business. Again, no more shortage.
Re: U.S. has almost 500k job openings in cybersecurity
#40Earlier quoted context omitted.
Then they need to get off the Internet if they truly can't secure their systems. Or, goodness, so many people became unemployed during the pandemic, they could train them for the job they "need".
We don't put this financial burden-of-self-defense on any other industry though. Why is cybersecurity different than physical retailers? Walgreens isn't responsible for providing their own police force. Sure, they put locks on the doors, but the burden of protecting businesses is on the police, which they (and we) pay for via taxes. You could say "Oh, a business which can't defend itself against looting doesn't deser…
Companies that can't secure their operations can hire others, like Shopify, Paypal, etc to conduct online operations for them. We've all heard the many stories of professionals making security recommendations and being overruled. If you don't want to invest in security, then don't have valuable data in computers connected to the Internet. Experian exposed our data and faced basically zero consequences, so I don't have any sympathy.