Live data from Hacker News

U.S. has almost 500k job openings in cybersecurity

cbsnews.com

61–70 of 70 posts

Re: U.S. has almost 500k job openings in cybersecurity

#61

I wish these supposed jobs existed when I finished my degree for going into cybersecurity, unfortunately EVERY "entry level" job required 3-5 years experience. It's probably exactly the same today. Now I work in electrical engineering, because the position requested (not required) a background in IT and my hobbyist experience was enough to satisfy the rest of the requirements.

I was never entry level. First programming job was senior. Like really senior.

No idea why they hired someone brand for senior.

I guess for a while I explained it as “senior” and “junior” not necessarily being descriptive.

Now I think it’s that I had related experience (I had been a teacher, and training/mentoring is a big part of the job.)

Re: U.S. has almost 500k job openings in cybersecurity

#62
post #60

Earlier quoted context omitted.

They're fake / fraudulent requirements, it's questionable which side is being more unethical. Entry level with min 3-5 years of experience in cyber security, yeah, that's bullshit. Either they're outright lying, dramatically exaggerating about what they need, or dangerously incompetent. When someone sets up fraudulent requirements for a job listing, they're priming the ground for dishonesty all around (they're being…

If I copied and pasted some boilerplate requirements to save time, I would look for the candidate whose attitude is, "I'm so strong in other areas you haven't considered that you're going to overlook your requirements and make an exception for me" rather than the candidate who thinks, "I take bullet points so seriously that I'm going to focus on deceiving you into thinking I meet them when I actually don't". You will…

How many HR resume filters do you get past before you even get a chance to make that argument?

You could be referred personally to some hiring manager but you have to admit that situation is a minor occurrence compared to most job postings

Re: U.S. has almost 500k job openings in cybersecurity

#63

Earlier quoted context omitted.

> But I'd have a hard time finding a security engineering job that pays similarly to what I get paid currently as a support engineer for AWS's security services. I would assume that AWS would be near the top of compensation no matter what job when looking at American companies.

Really depends on what Org you're working for. I've had a lot of colleagues in support get pulled away to SaaS vendors to get paid more. I actually talked with a friend the other day who essentially offered me a job with 50% the workload and $30k+ more per year. While SDE/SDMs/etc. probably get paid the top of the compensation when looking across companies, support isn't the same. Also, most of that is likely tied up…

What is SOC

Re: U.S. has almost 500k job openings in cybersecurity

#65

Earlier quoted context omitted.

If I am reading the trend correctly, we will soon see Trust/Security/Assurance move into more of a GTM function for B2B product companies.

how do you arrive at this conclusion?

With the recent attacks, particularly supply-chain attacks, B2B buyers would be asking more security questions to their vendors.

Vendors will soon be competing on the quality and reputation of their security features.

Finally, I think regulation night be coming down in the area soon. My read is that this will be welcomed by big enterprises, and they go to market touting their "enterprise-grade security features". Eventually, all B2B teams will have a Trust/Assurance portion to their GTM playbook.

Re: U.S. has almost 500k job openings in cybersecurity

#66

Earlier quoted context omitted.

Really depends on what Org you're working for. I've had a lot of colleagues in support get pulled away to SaaS vendors to get paid more. I actually talked with a friend the other day who essentially offered me a job with 50% the workload and $30k+ more per year. While SDE/SDMs/etc. probably get paid the top of the compensation when looking across companies, support isn't the same. Also, most of that is likely tied up…

What is SOC

Security Operations center.

Centralized logs,analyse and react on incidents.

Re: U.S. has almost 500k job openings in cybersecurity

#67
post #37

Earlier quoted context omitted.

The rural doctor shortage is probably a really good parallel, because as a society we in the abstract agree that it's Very Bad to let people die without reasonable access to healthcare, but poor rural communities simply can't support paying doctor or even nurses to be available. There's still a ton of society loss / deadweight because of the consequences of not having those services; the question is, how can we restr…

The rural doctor shortage is caused by the American Medical Association cartel deliberately restricting the supply of doctors to keep prices high. When there isn't even enough supply to meet the needs of desirable urban areas, what chances does the middle of nowhere in the Midwest or Alaska have? I once dated an Indian-born MD who immigrated to the US. A Senator from Missouri went to bat personally (not one of his st…

Rural areas are understaffed in every skilled field, whether it be nursing, EMTs, firefighters, cops, engineers, etc. It is because the people there don't want to pay any taxes so they would rather do without.

Re: U.S. has almost 500k job openings in cybersecurity

#68

I wish these supposed jobs existed when I finished my degree for going into cybersecurity, unfortunately EVERY "entry level" job required 3-5 years experience. It's probably exactly the same today. Now I work in electrical engineering, because the position requested (not required) a background in IT and my hobbyist experience was enough to satisfy the rest of the requirements.

If 3-5 years is the baseline, you deduct 3-5 years from the experience numbers and apply to those job postings. I.e. 3-5 years entry level? Apply after college. 5-8 years senior position? Apply after 2-3 years.

Job position descriptions are wish lists, if they don't find a candidate they will hire somebody that doesn't fit the bill 100%. Which is usually the people that dared to apply anyway.

Re: U.S. has almost 500k job openings in cybersecurity

#69

Earlier quoted context omitted.

Paying more just means you fill your vacancy at the expense of another firm who has their employee poached. The net effect is that one company is still vulnerable.

There are at least one million people in the US who have more than enough experience for an entry-level cybersecurity position; all they need is a few weeks of training (to start) and an employer that isn't demanding twenty years of experience and a CISSP for $50k with crap healthcare and inadequate PTO. Also, employees are not some company's property. At-will employment goes two ways, and if you want to treat them a…

>There are at least one million people in the US who have more than enough experience for an entry-level cybersecurity position

What's the base requirement for these people?

Re: U.S. has almost 500k job openings in cybersecurity

#70

Earlier quoted context omitted.

how do you arrive at this conclusion?

With the recent attacks, particularly supply-chain attacks, B2B buyers would be asking more security questions to their vendors. Vendors will soon be competing on the quality and reputation of their security features. Finally, I think regulation night be coming down in the area soon. My read is that this will be welcomed by big enterprises, and they go to market touting their "enterprise-grade security features". Eve…

have you sold any security products?

infosec is basically QA with veto powers. It's mostly just checklists and passing the book. A cost center everyone wants to cut..until it's too late.

Post reply on HN