Live data from Hacker News

U.S. has almost 500k job openings in cybersecurity

cbsnews.com

61–70 of 103 posts

Re: U.S. has almost 500k job openings in cybersecurity

#61
post #40

Earlier quoted context omitted.

I prepared so much for our audit and the only thing this guy cared for in a 5 developer company was the fact that I had root access on all environments. He didn't care about Aws having 2fa configured about our vlan ipsec Tunnel, etc I even took the liberty to fix the md5 Passwort shit with bcrypt just before the audit...

That guy is completely right. I wouldn’t look at anything else either as that is already the security worst case scenario.

On a small company with 5 people?

Are you serious?

What would be your suggestion then?

Re: U.S. has almost 500k job openings in cybersecurity

#62
post #48

Earlier quoted context omitted.

From the other side of the fence: I've been hiring companies to do external pen tests for fifteen years now. Some of them have been giant corporations with security divisions, some of them have been just past the startup stage, and some of them are recognizable big names in the industry. I've signed one year, two year and three year contracts. A few of them have distinguished themselves, slightly, in the first year o…

Security unfortunately is a creative process, which is hard to get consistent. I would love to use something like statistical product control, but I have yet to see a good way to apply it (or similar techniques) without forcing pen-tests to be “follow the checklist”.

I should add that burnout is a massive problem when it comes to quality. Even if you found a good consultant (or group of), for round #2, they could have just finished testing all of your competitors products and are now worn out.

Scheduling in variety to try and prevent partial burnout is difficult if everyone in a vertical only wants to use the same person.

Re: U.S. has almost 500k job openings in cybersecurity

#63
post #61

Earlier quoted context omitted.

That guy is completely right. I wouldn’t look at anything else either as that is already the security worst case scenario.

On a small company with 5 people? Are you serious? What would be your suggestion then?

Eliminate root access. If an intruder gets into your network they have unrestricted access to everything. Game over.

The solution is defense in depth. Have different accounts with separate access to various services. That way if an account is compromised they don’t have access to everything.

Most of your accounts should provide least access to what they need. Higher level accounts allowing greater control of your system should be rarely available for access and need to be part of regular access control audits.

Re: U.S. has almost 500k job openings in cybersecurity

#64
post #42
post #23

Earlier quoted context omitted.

It's IT via checklist. I can't imagine a more depressing way to go through my life. Talking to the cybersecurity people I know they all frame it like they're elite warriors who are locked in a titanic struggle with cunning adversaries. My take is...you followup on tickets generated by third party tools by filling out web forms. Yes you're getting 'probed' by Russia and China all the time but thats from botnets lookin…

Ask anyone in Aviation, checklists matter. Cybersecurity is often drudgery, but avoiding excitement is the entire point.

Currently, IT checklists are security theater. Reducing liability vs improving security.

How many orgs are transitioning to zero knowledge networks, encrypting all data at rest?

Re: U.S. has almost 500k job openings in cybersecurity

#65
post #42

Earlier quoted context omitted.

Ask anyone in Aviation, checklists matter. Cybersecurity is often drudgery, but avoiding excitement is the entire point.

Currently, IT checklists are security theater. Reducing liability vs improving security. How many orgs are transitioning to zero knowledge networks, encrypting all data at rest?

> encrypting all data at rest

That’s a common checklist item. Implementing it is of course more work than just checking the box, but ensuring it’s actually done means it’s added to a lot of different checklists.

Re: U.S. has almost 500k job openings in cybersecurity

#66

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

I'll add one more, the problem with compliance jobs is that it only really becomes important (to the bigwigs) when it goes wrong.

Most of the time you are just a cost-center, a necessary nuisance. It's a lot harder to extract money / get promoted when your good work isn't immediately noticeable.

Re: U.S. has almost 500k job openings in cybersecurity

#67
post #58
post #23

Earlier quoted context omitted.

It's IT via checklist. I can't imagine a more depressing way to go through my life. Talking to the cybersecurity people I know they all frame it like they're elite warriors who are locked in a titanic struggle with cunning adversaries. My take is...you followup on tickets generated by third party tools by filling out web forms. Yes you're getting 'probed' by Russia and China all the time but thats from botnets lookin…

Don't be so hard on checklists :) the bigger problem is applying ill conceived checklists no?

I suspect the underlying psychological tension is between "learn-design-create" versus "obey-follow playbooks-be reliable" People like me took decades to stop fighting the latter. Security is "for those that pay" in most cases, which also can set up some social tensions for those who consider larger social issues. make sense?

Re: U.S. has almost 500k job openings in cybersecurity

#68
post #61

Earlier quoted context omitted.

On a small company with 5 people? Are you serious? What would be your suggestion then?

Eliminate root access. If an intruder gets into your network they have unrestricted access to everything. Game over. The solution is defense in depth. Have different accounts with separate access to various services. That way if an account is compromised they don’t have access to everything. Most of your accounts should provide least access to what they need. Higher level accounts allowing greater control of your sys…

I'm not logging in as root directly.

But non the less with 5 people what audit system would be even available in which only one person has access.

All smart concepts cost either a lot of money or just don't work if you don't have enough people.

Should the only techlead have access to the audit system? Probably. Should the only techlead have access to VMs? Probably yes.

I made sure my systems are encrypted, 2fa wherever possible, no external systems besides the services.

Re: U.S. has almost 500k job openings in cybersecurity

#70
Serious question. 500k job openings is a lot. Where do go to find these job listings? Are they still spread out across lots of job listings sites like Monster, etc.? Are they doing a total of all listings across those sites? Is there a defacto site that everyone uses now? Just wondering if I’m doing something wrong.
Post reply on HN