Live data from Hacker News

U.S. has almost 500k job openings in cybersecurity

cbsnews.com

81–90 of 103 posts

Re: U.S. has almost 500k job openings in cybersecurity

#81

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

I'll add one more, the problem with compliance jobs is that it only really becomes important (to the bigwigs) when it goes wrong. Most of the time you are just a cost-center, a necessary nuisance. It's a lot harder to extract money / get promoted when your good work isn't immediately noticeable.

The cost center mentality is a huge part of the problem.

As a consultant I've been trying for years, with limited success, to persuade people to think in terms of business process integrity, since that more clearly ties the necessary work to the revenue output. It's an uphill slog though as prevailing culture is checklist compliance.

Doesn't help that major consulting and advising firms make more money on checklist mentalities.

Re: U.S. has almost 500k job openings in cybersecurity

#82
post #65

Earlier quoted context omitted.

Currently, IT checklists are security theater. Reducing liability vs improving security. How many orgs are transitioning to zero knowledge networks, encrypting all data at rest?

> encrypting all data at rest That’s a common checklist item. Implementing it is of course more work than just checking the box, but ensuring it’s actually done means it’s added to a lot of different checklists.

At the field and record level? Sufficient to guarantee privacy?

Never store PII as cleartext, akin to proper password storage.

Translucent Databases https://www.amazon.com/gp/product/1441421343

Encrypting databases, file systems, and backups remain necessary, but insufficient.

Re: U.S. has almost 500k job openings in cybersecurity

#83
post #7

That sounds huge. 0.15 % of the entire us population just for cyber security? I hope you don't need garbage men and bakers.

How many boot camp web devs are currently being churned out who don't know the first thing about the 1000 ways their service could be attacked?

Luckily there are now cyber security professional boot camps to fix this. Not kidding: https://bootcamp.umn.edu/cybersecurity/

Re: U.S. has almost 500k job openings in cybersecurity

#84

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

4. Most places you'll work will treat you as a cost center. Nobody wants to pay for security.

5. A lot of the "Cybersecurity" folks are closer to the sysadmin-cert-associate degree than the Engineering CS side of things.

Re: U.S. has almost 500k job openings in cybersecurity

#85
post #78
post #41

Earlier quoted context omitted.

A roommate studying for aerospace engineering described that field as "Everyone gets in because they want to work at Skunkworks and design the SR-71. In reality, 95% of graduates will spend the next 40 years optimizing the efficiency of a winglet on a 747." Security feels similar. The edge of the spear is fascinating, exciting, challenging work. Unfortunately, no one needs that work. What companies actually need is m…

Optimizing the wingtip on a 747 actually sounds interesting, and it's the sort of thing that could meaningfully affect the world. It might even prevent more wars than the SR-71 program in terms of lessening ecological and environmental pressures. A much worse career would be convincing regulators that new aircraft like the 737 MAX don't need any additional training. Maintaining lists of open exploits, and keeping the…

Would that task keep you interested for many years? A lot of the people I know in Aerospace end up working on a single component of a larger system for so long that they lose interest and burn out. It's a very high paying job for mostly very boring work. There are always exceptions though.

Re: U.S. has almost 500k job openings in cybersecurity

#86
post #28

I feel like cybersecurity is undergoing an AI/ML like buzz at the moment, where basically every company is going all in on it, but the value is really being provided by a small concentration of talented people who really know their stuff. I've found it frustrating being in the DevOps space, because the hype bleeds into other decisions and sometimes I swear people forget we're actually running a business and believe e…

By now I know more people who stopped working in security rather than people who kept working in the field.

Re: U.S. has almost 500k job openings in cybersecurity

#87
post #7

That sounds huge. 0.15 % of the entire us population just for cyber security? I hope you don't need garbage men and bakers.

How many boot camp web devs are currently being churned out who don't know the first thing about the 1000 ways their service could be attacked?

Many. Worked with a boot camp grad. She asked for help. Open the file and SQL injection literally dead center of the first page. Not a clue or sense of urgency to fix.

Re: U.S. has almost 500k job openings in cybersecurity

#88

From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…

The industry gets a bad rap, because it's full of ego maniacs, but the reality is that there are tons of interesting opportunities that fall outside conventional compliance/pen-testing roles. Research is actually a huge sector, because you can apply security research to so many emerging and existing industries. You can specialize is specific things as well. Take for example blockchain. !0 years ago there were no cryptocurrencies, today it's a multi-billion (trillion?) dollar industry. People with skills to audit smart contracts are in huge demand. What about all of the other emerging technologies? Criminals are always quick to exploit and abuse emerging tech and emerging markets, so there are always opportunities presenting themselves for technical & security minded folks. The world of cybersecurity goes beyond just pen testing or sitting in a SOC as an analyst.

Re: U.S. has almost 500k job openings in cybersecurity

#90
post #4

Earlier quoted context omitted.

> 0.15 % of the entire us population just for cyber security? Even better: 0.15% of the entire US population for unfilled jobs. I'm going to assume most of these aren't permanent positions but gigs.

I'm going to assume the number is for any tech job that has even the slightest but of security function, including any sysadmin, dbeng, webapp dev, etc It's just too big to be correct.

According to the primary source there are "319,720 additional openings requesting cybersecurity-related skills" included in that number.

https://www.cyberseek.org/index.html#aboutit

Post reply on HN