Live data from Hacker News

U.S. has almost 500k job openings in cybersecurity

cbsnews.com

41–50 of 70 posts

Re: U.S. has almost 500k job openings in cybersecurity

#41
post #29

Earlier quoted context omitted.

We don't put this financial burden-of-self-defense on any other industry though. Why is cybersecurity different than physical retailers? Walgreens isn't responsible for providing their own police force. Sure, they put locks on the doors, but the burden of protecting businesses is on the police, which they (and we) pay for via taxes. You could say "Oh, a business which can't defend itself against looting doesn't deser…

Walgreens - great example! That's a pharmacy. Pharmacies have to follow strict safety regulations and are constantly worried about both those and the threat of lawsuits for endangering customers. And there are also both internal and external threats to the business (drugs are a valuable, easily portable asset). Oversimplifying a lot, Walgreens has these well-paid, trained workers they call "pharmacists" to deal with…

You are trying to whatabout this, ignoring the actual point. Let's not do that.

The Pharmacists make only effort to prevent someone from breaking into the Pharmacy with a crowbar and stealing all the drugs + prescriptions. In fact, I would be shocked if Walgreens even _allowed_ staff to physically detain shoplifters -- that's a huge legal liability.

Defending those goods is the job of the police.

Re: U.S. has almost 500k job openings in cybersecurity

#42
post #40

Earlier quoted context omitted.

We don't put this financial burden-of-self-defense on any other industry though. Why is cybersecurity different than physical retailers? Walgreens isn't responsible for providing their own police force. Sure, they put locks on the doors, but the burden of protecting businesses is on the police, which they (and we) pay for via taxes. You could say "Oh, a business which can't defend itself against looting doesn't deser…

In San Francisco, Walgreens is responsible for providing their own security force, so they decided to stop operating there. Companies that can't secure their operations can hire others, like Shopify, Paypal, etc to conduct online operations for them. We've all heard the many stories of professionals making security recommendations and being overruled. If you don't want to invest in security, then don't have valuable…

Are you seriously arguing that Walgreens leaving SF over rampant shoplifting is natural, healthy outcome?

Literally every sane person agrees this is a symbol of utter dysfunction that should never happen in a functioning city.

Re: U.S. has almost 500k job openings in cybersecurity

#43
post #40

Earlier quoted context omitted.

In San Francisco, Walgreens is responsible for providing their own security force, so they decided to stop operating there. Companies that can't secure their operations can hire others, like Shopify, Paypal, etc to conduct online operations for them. We've all heard the many stories of professionals making security recommendations and being overruled. If you don't want to invest in security, then don't have valuable…

Are you seriously arguing that Walgreens leaving SF over rampant shoplifting is natural, healthy outcome? Literally every sane person agrees this is a symbol of utter dysfunction that should never happen in a functioning city.

Oh, no, it's terrible.

But government can't secure the Internet like they could physical space, so operating on the Internet is like operating in SF.

Re: U.S. has almost 500k job openings in cybersecurity

#44
I wish these supposed jobs existed when I finished my degree for going into cybersecurity, unfortunately EVERY "entry level" job required 3-5 years experience. It's probably exactly the same today. Now I work in electrical engineering, because the position requested (not required) a background in IT and my hobbyist experience was enough to satisfy the rest of the requirements.

Re: U.S. has almost 500k job openings in cybersecurity

#45
post #12

Earlier quoted context omitted.

"Shortage" is a synonym for "costs more than I'd like to pay for it".

Competing harder for the limited pool of competent security people might redistribute breaches away from your company onto others. From a local perspective this could be rational but as a society we want to be less vulnerable in aggregate. (Although there I think the IT operations side is vastly overblown and not nearly enough attention is paid to quality control on the most popular software packages. Want to make ev…

The pool is never truly limited though. Every industry was at one time tiny and had to train people to do the job.

But, training costs money, so they hope some other company will do it for them.

Re: U.S. has almost 500k job openings in cybersecurity

#46
post #28

I don't know any security professionals. Is this something that a mostly-self-taught software engineer could get a job in? What are interviews typically like?

Tom Aptek’s (security company founder) pitch a few years back was Get through ‘A Web Application Hacker’s Handbook’ and ‘Securing DevOps’ and his company would probably give you six figures and a brand new macbook. For an extra bonus you could work through their crypto challenges. https://cryptopals.com/sets/1 https://www.manning.com/books/securing-devops https://archive.org/details/TheWebApplicationHackersHandbook..…

That’s a company that hires based on actual knowledge and skill, rather than certificates and buzzwords.

Re: U.S. has almost 500k job openings in cybersecurity

#47

I am a Sr. devops engineer and have been looking to transition to a devsecops or even some sort of security ops role for a YEAR. I am willing to take a pay cut and move to a more junior role but I can never pass the HR filter of “prior security experience needed.”

Yeah, so.. I was in the same boat. Just fake your cv, it sounds really unethical but really if you’re a sr devops you’ll be able to handle all the work easily. You’ll only get in trouble if you can’t actually do it. Maybe do the oscp too.

Re: U.S. has almost 500k job openings in cybersecurity

#48

I am a Sr. devops engineer and have been looking to transition to a devsecops or even some sort of security ops role for a YEAR. I am willing to take a pay cut and move to a more junior role but I can never pass the HR filter of “prior security experience needed.”

Yeah, so.. I was in the same boat. Just fake your cv, it sounds really unethical but really if you’re a sr devops you’ll be able to handle all the work easily. You’ll only get in trouble if you can’t actually do it. Maybe do the oscp too.

Working in cybersecurity requires trust. Lying on your CV isn't a great way of demonstrating that.

Re: U.S. has almost 500k job openings in cybersecurity

#49
post #17

Earlier quoted context omitted.

Then they need to get off the Internet if they truly can't secure their systems. Or, goodness, so many people became unemployed during the pandemic, they could train them for the job they "need".

We don't put this financial burden-of-self-defense on any other industry though. Why is cybersecurity different than physical retailers? Walgreens isn't responsible for providing their own police force. Sure, they put locks on the doors, but the burden of protecting businesses is on the police, which they (and we) pay for via taxes. You could say "Oh, a business which can't defend itself against looting doesn't deser…

You pretty much have no clue what your talking about when it comes with the duty of the police. The police have no charge to protect you or your business, at all, whatsoever. This has been decided in the high courts in the US. Pretty much everything you stated is completely incorrect.

Re: U.S. has almost 500k job openings in cybersecurity

#50
post #40

Earlier quoted context omitted.

In San Francisco, Walgreens is responsible for providing their own security force, so they decided to stop operating there. Companies that can't secure their operations can hire others, like Shopify, Paypal, etc to conduct online operations for them. We've all heard the many stories of professionals making security recommendations and being overruled. If you don't want to invest in security, then don't have valuable…

Are you seriously arguing that Walgreens leaving SF over rampant shoplifting is natural, healthy outcome? Literally every sane person agrees this is a symbol of utter dysfunction that should never happen in a functioning city.

San Francisco neighborhoods did not want mall-like corporate chains at all, a few decades ago. The companies paid for the privelege and prevailed over time. Meanwhile economics changed and left a lot of people out of the benefits, wages for working people stayed even, and the pain-killer drugs and organized crime grew strong. Toxic cocktail to be sure, but SF has always been a cocktail town, from the early days. In some ways The City has reaped what it sowed, socially.
Post reply on HN