I've reading about this "security professionals shortage" for quite some years, yet the reality is that there is no such shortage. And I think this is even expandable now to any IT field. People keep saying about shortage, but what I do see is exhausting hiring process most people just don't want to deal with.
"Shortage" is a synonym for "costs more than I'd like to pay for it".
U.S. has almost 500k job openings in cybersecurity
51–60 of 70 posts
Re: U.S. has almost 500k job openings in cybersecurity
#52Re: U.S. has almost 500k job openings in cybersecurity
#53Earlier quoted context omitted.
Security is always going to be a cost side of the business, to be minimized.
If I am reading the trend correctly, we will soon see Trust/Security/Assurance move into more of a GTM function for B2B product companies.
Re: U.S. has almost 500k job openings in cybersecurity
#54Re: U.S. has almost 500k job openings in cybersecurity
#55Earlier quoted context omitted.
If I am reading the trend correctly, we will soon see Trust/Security/Assurance move into more of a GTM function for B2B product companies.
how do you arrive at this conclusion?
Re: U.S. has almost 500k job openings in cybersecurity
#56How many of those job postings list a CISSP or 5 years for an entry-level job that pays $70k? This is stuff I see often. I have extensive experience in cloud security environments, have done IR, DR/BCP planning, passed SOC II audits, and have security cert(s). But I'd have a hard time finding a security engineering job that pays similarly to what I get paid currently as a support engineer for AWS's security services.…
The 70k thing... in Texas I think fresh college grads are getting that for risk analyst roles. Experienced security engineers seem to go for 120k-150k, more for appsec. I assume Silicon Valley is double that (for much more then double the cost of living).
The CISSP thing is definitely real but beginning to fade out, although asking for one for an entry level role is less ludicrous than it sounds. I legitimately had one before my first sec title. Practically everything counts as security experience... if you've ever worked on an Active Directory domain, that's IAM, for example. I don't actually think that much of the CISSP and I think it's a mistake for HR to value it so highly, but it's not insurmountable.
Re: U.S. has almost 500k job openings in cybersecurity
#57Certification? I don't think so, why would you even...
> Tim Herbert, executive vice president for research at CompTIA.
Ahhh... it's an advertisement for a bad certification program.
Re: U.S. has almost 500k job openings in cybersecurity
#58Earlier quoted context omitted.
"Shortage" is a synonym for "costs more than I'd like to pay for it".
Paying more just means you fill your vacancy at the expense of another firm who has their employee poached. The net effect is that one company is still vulnerable.
Also, employees are not some company's property. At-will employment goes two ways, and if you want to treat them as if they were property you may as well just turn off the lights now because it will not end well.
Re: U.S. has almost 500k job openings in cybersecurity
#59Earlier quoted context omitted.
Yeah, so.. I was in the same boat. Just fake your cv, it sounds really unethical but really if you’re a sr devops you’ll be able to handle all the work easily. You’ll only get in trouble if you can’t actually do it. Maybe do the oscp too.
Working in cybersecurity requires trust. Lying on your CV isn't a great way of demonstrating that.
Entry level with min 3-5 years of experience in cyber security, yeah, that's bullshit. Either they're outright lying, dramatically exaggerating about what they need, or dangerously incompetent.
When someone sets up fraudulent requirements for a job listing, they're priming the ground for dishonesty all around (they're being dishonest with the job listing to begin with), and they become partially responsible for the context.
If I put out a job listing for $250,000 / year and demand people have 3-5 years of experience at telepathy, I'm going to get a lot of candidates willing to lie on their application. The same principle comes into effect when you put out any manner of fraudulent requirements for jobs; to the extent your listing is fraudulent, is the extent to which it's going to cause problems one way or another.
Re: U.S. has almost 500k job openings in cybersecurity
#60Earlier quoted context omitted.
Working in cybersecurity requires trust. Lying on your CV isn't a great way of demonstrating that.
They're fake / fraudulent requirements, it's questionable which side is being more unethical. Entry level with min 3-5 years of experience in cyber security, yeah, that's bullshit. Either they're outright lying, dramatically exaggerating about what they need, or dangerously incompetent. When someone sets up fraudulent requirements for a job listing, they're priming the ground for dishonesty all around (they're being…