It has been a fairly common story, and part rumor, that intelligence agencies like to recruit young people active in the cyber criminal scene, and that the IT security industry also adapted this approach. They basically becomes part informer and part subject expert, especially since IT security expertise seems to be a difficult subject matter to teach in universities. When I studied IT security in university, about 1…
Those kids make good "experts" in thier narrow fields, but that doesnt last long. They are generally not effective leaders, thier usefullness drying up as the state of the art moves on. Some grow up and learn how to operate as leaders in a corporate or government environment, but most burn out once they meet the next generation of golden childs. That's actually ok in a military context. Most kids right out of highsch…
They sound like regular A/B-grade CS students: unproven new grads. Motivated and high-energy, yes, which is sensible for a junior low-trust role if they pass other basics like references and criminal checks. At our current company, we would not have hired several of them in our entry roles due to the obvious issues that our routine diligence would surface (in recent work history: associating with criminals & criminal orgs, repeat googleable public displays of racism, etc). And the rest, for likely not being at the level of top students applying to us, irrespective of evaluating on academics vs DIY. Their examples would need to be significantly more compelling to change the conversation.