Live data from Hacker News

U.S. has almost 500k job openings in cybersecurity

cbsnews.com

51–60 of 70 posts

Re: U.S. has almost 500k job openings in cybersecurity

#51
post #12
post #4

I've reading about this "security professionals shortage" for quite some years, yet the reality is that there is no such shortage. And I think this is even expandable now to any IT field. People keep saying about shortage, but what I do see is exhausting hiring process most people just don't want to deal with.

"Shortage" is a synonym for "costs more than I'd like to pay for it".

I'd say "costs more than the median income" is closer. Adjust for legitimate training costs that are incurred by the workers, and it might be a pretty good definition.

Re: U.S. has almost 500k job openings in cybersecurity

#52

Earlier quoted context omitted.

Security is always going to be a cost side of the business, to be minimized.

If I am reading the trend correctly, we will soon see Trust/Security/Assurance move into more of a GTM function for B2B product companies.

^^^ This

Re: U.S. has almost 500k job openings in cybersecurity

#53

Earlier quoted context omitted.

Security is always going to be a cost side of the business, to be minimized.

If I am reading the trend correctly, we will soon see Trust/Security/Assurance move into more of a GTM function for B2B product companies.

how do you arrive at this conclusion?

Re: U.S. has almost 500k job openings in cybersecurity

#54

Earlier quoted context omitted.

Security is always going to be a cost side of the business, to be minimized.

If I am reading the trend correctly, we will soon see Trust/Security/Assurance move into more of a GTM function for B2B product companies.

GTM = Go To Market?

Re: U.S. has almost 500k job openings in cybersecurity

#55

Earlier quoted context omitted.

If I am reading the trend correctly, we will soon see Trust/Security/Assurance move into more of a GTM function for B2B product companies.

how do you arrive at this conclusion?

For every company that is not selling a security product, this is self evidently true.

Re: U.S. has almost 500k job openings in cybersecurity

#56

How many of those job postings list a CISSP or 5 years for an entry-level job that pays $70k? This is stuff I see often. I have extensive experience in cloud security environments, have done IR, DR/BCP planning, passed SOC II audits, and have security cert(s). But I'd have a hard time finding a security engineering job that pays similarly to what I get paid currently as a support engineer for AWS's security services.…

My experience having gone from Principal Systems Engineer to cybersecurity analyst to eventually pen test and then red team is that cybersecurity pays substantially more than most other IT disciplines, except maybe SE and Dev(Sec)Ops.

The 70k thing... in Texas I think fresh college grads are getting that for risk analyst roles. Experienced security engineers seem to go for 120k-150k, more for appsec. I assume Silicon Valley is double that (for much more then double the cost of living).

The CISSP thing is definitely real but beginning to fade out, although asking for one for an entry level role is less ludicrous than it sounds. I legitimately had one before my first sec title. Practically everything counts as security experience... if you've ever worked on an Active Directory domain, that's IAM, for example. I don't actually think that much of the CISSP and I think it's a mistake for HR to value it so highly, but it's not insurmountable.

Re: U.S. has almost 500k job openings in cybersecurity

#57
> "It just requires someone who has the proper training, proper certification

Certification? I don't think so, why would you even...

> Tim Herbert, executive vice president for research at CompTIA.

Ahhh... it's an advertisement for a bad certification program.

Re: U.S. has almost 500k job openings in cybersecurity

#58
post #12

Earlier quoted context omitted.

"Shortage" is a synonym for "costs more than I'd like to pay for it".

Paying more just means you fill your vacancy at the expense of another firm who has their employee poached. The net effect is that one company is still vulnerable.

There are at least one million people in the US who have more than enough experience for an entry-level cybersecurity position; all they need is a few weeks of training (to start) and an employer that isn't demanding twenty years of experience and a CISSP for $50k with crap healthcare and inadequate PTO.

Also, employees are not some company's property. At-will employment goes two ways, and if you want to treat them as if they were property you may as well just turn off the lights now because it will not end well.

Re: U.S. has almost 500k job openings in cybersecurity

#59
post #48

Earlier quoted context omitted.

Yeah, so.. I was in the same boat. Just fake your cv, it sounds really unethical but really if you’re a sr devops you’ll be able to handle all the work easily. You’ll only get in trouble if you can’t actually do it. Maybe do the oscp too.

Working in cybersecurity requires trust. Lying on your CV isn't a great way of demonstrating that.

They're fake / fraudulent requirements, it's questionable which side is being more unethical.

Entry level with min 3-5 years of experience in cyber security, yeah, that's bullshit. Either they're outright lying, dramatically exaggerating about what they need, or dangerously incompetent.

When someone sets up fraudulent requirements for a job listing, they're priming the ground for dishonesty all around (they're being dishonest with the job listing to begin with), and they become partially responsible for the context.

If I put out a job listing for $250,000 / year and demand people have 3-5 years of experience at telepathy, I'm going to get a lot of candidates willing to lie on their application. The same principle comes into effect when you put out any manner of fraudulent requirements for jobs; to the extent your listing is fraudulent, is the extent to which it's going to cause problems one way or another.

Re: U.S. has almost 500k job openings in cybersecurity

#60
post #48

Earlier quoted context omitted.

Working in cybersecurity requires trust. Lying on your CV isn't a great way of demonstrating that.

They're fake / fraudulent requirements, it's questionable which side is being more unethical. Entry level with min 3-5 years of experience in cyber security, yeah, that's bullshit. Either they're outright lying, dramatically exaggerating about what they need, or dangerously incompetent. When someone sets up fraudulent requirements for a job listing, they're priming the ground for dishonesty all around (they're being…

If I copied and pasted some boilerplate requirements to save time, I would look for the candidate whose attitude is, "I'm so strong in other areas you haven't considered that you're going to overlook your requirements and make an exception for me" rather than the candidate who thinks, "I take bullet points so seriously that I'm going to focus on deceiving you into thinking I meet them when I actually don't". You will eventually find an employer who doesn't bother fact checking but is that the kind of employer you want?
Post reply on HN