6 ms·
U.S. has almost 500k job openings in cybersecurity
- deleted 5y ago[deleted]
- hparadiz 5y agoThe salary they mentioned in the article is too low when the downside is millions in payout
- ENOTTY 5y agoThat's just an entry level salary
- hn8788 5y agoMost places where I've worked only had 1-2 security people that weren't entry level. The majority of people doing cybersecurity work are just going to be looking at automated alerts and automated scan reports, then they pass things up to the senior person to make sure it gets investigated and fixed.
- tootahe45 5y agoI imagine lot of these would be highly laborious analytical-type roles (staring at a dashboard all day) which don't lead to the high paying and glamorized hacker/pentester roles.
- Trisell 5y agoI’ve noticed that Cyber Security at a lot of companies are still stuck in the sys admin days of yore. They continue to hold on the antiquated tooling that doesn’t scale or actually detect most issues. And the idea of learning or expanding into security automation beyond their toolset is frowned upon by a not significant number of member of the community doing the day to day work. This creates an atmosphere where they SecOps teams can’t articulate the positives they are bringing to the organization. And thus the market doesn’t pay them their worth. Compare this to DevOps where the sale has been done well and the business is convinced that these highly paid automation engineers will help the business to improve and speed up software delivery providing more income to the company. Until security is able to properly articulate how they are helping and improving the business, not just getting in everybody’s way. The field is going to struggle to raise salaries to comparable levels as these other disciplines.
- iamAy0 5y agoI've reading about this "security professionals shortage" for quite some years, yet the reality is that there is no such shortage. And I think this is even expandable now to any IT field. People keep saying about shortage, but what I do see is exhausting hiring process most people just don't want to deal with.
- hn8788 5y agoThe hiring process is definitely an issue. Cybersecurity is new enough that HR has no idea what they want, so they require useless certifications like CEH, and a college degree in CS. There's also a wide variation in what Cybersecurity even means. Some college cybersecurity programs are all about policy and compliance, while some focus on offensive security and vulnerability analysis.
- isbvhodnvemrwvn 5y agoOften it's not HR that writes these job adverts, it's the managers. HR is just a middleman.
- hirundo 5y ago"Shortage" is a synonym for "costs more than I'd like to pay for it".
- closeparen 5y agoCompeting harder for the limited pool of competent security people might redistribute breaches away from your company onto others. From a local perspective this could be rational but as a society we want to be less vulnerable in aggregate. (Although there I think the IT operations side is vastly overblown and not nearly enough attention is paid to quality control on the most popular software packages. Want to make every business substantially more secure at once? Take a hard look at Windows Server, Exchange, etc).
- nitwit005 5y ago
- whoknew1122 5y agoHow many of those job postings list a CISSP or 5 years for an entry-level job that pays $70k? This is stuff I see often. I have extensive experience in cloud security environments, have done IR, DR/BCP planning, passed SOC II audits, and have security cert(s). But I'd have a hard time finding a security engineering job that pays similarly to what I get paid currently as a support engineer for AWS's security services. And that's largely because most security jobs I see are asking for unicorns willing to get paid substantially less than other IT disciplines.
- MattGaiser 5y ago> But I'd have a hard time finding a security engineering job that pays similarly to what I get paid currently as a support engineer for AWS's security services. I would assume that AWS would be near the top of compensation no matter what job when looking at American companies.
- whoknew1122 5y agoReally depends on what Org you're working for. I've had a lot of colleagues in support get pulled away to SaaS vendors to get paid more. I actually talked with a friend the other day who essentially offered me a job with 50% the workload and $30k+ more per year. While SDE/SDMs/etc. probably get paid the top of the compensation when looking across companies, support isn't the same. Also, most of that is likely tied up in RSUs. But I know for a fact L4 people in AWS's SOC get paid more than L5s in support. But AWS's SOC isn't a remote position, and I'm not in a position to move to where the SOC teams are located.
- killingtime74 5y agoWhat is SOC
- zentr1c 5y agoSecurity Operations center. Centralized logs,analyse and react on incidents.
- bpodgursky 5y agoMeta on the comments: While it's true that the salaries are unreasonably low, it doesn't mean that there are 500k Americans capable of doing cybersecurity work just waiting for the right paycheck. There can be _both_ a worker shortage and unreasonable salary expectations. A labor market will always have slack on both sides, but even at the extreme, there could be 10 cybersecurity experts, and you'd have people saying "Oh, you can find workers, you just have to be willing to pay $100mm/yr."
- MattGaiser 5y agoI wonder if it is like the rural doctor/nurse/cop shortages though. Those places don't want to pay, so don't care if the jobs are actually filled. How many of the 465,000 jobs do companies actually care get filled? Or do they just have them open just in case someone cheap walks through the door?
- bpodgursky 5y agoThe rural doctor shortage is probably a really good parallel, because as a society we in the abstract agree that it's Very Bad to let people die without reasonable access to healthcare, but poor rural communities simply can't support paying doctor or even nurses to be available. There's still a ton of society loss / deadweight because of the consequences of not having those services; the question is, how can we restructure the supply side of the argument to make it possible? For doctors+nurses, it's via government subsidies (income-based repayment, federal grants). ie, the cost of security breaches isn't to the companies being breached -- it's to the consumers who lose their PII/PHI to hackers. Or who lose access to a service they love using, because they can't keep running without a security expert.
- fmajid 5y agoThe rural doctor shortage is caused by the American Medical Association cartel deliberately restricting the supply of doctors to keep prices high. When there isn't even enough supply to meet the needs of desirable urban areas, what chances does the middle of nowhere in the Midwest or Alaska have? I once dated an Indian-born MD who immigrated to the US. A Senator from Missouri went to bat personally (not one of his staff) to get her a green card under the proviso she would settle in rural Missouri, because he understood that's what it takes (she moved to Maryland after a few years).
- etaioinshrdlu 5y agoI don't know any security professionals. Is this something that a mostly-self-taught software engineer could get a job in? What are interviews typically like?
- codyb 5y agoTom Aptek’s (security company founder) pitch a few years back was Get through ‘A Web Application Hacker’s Handbook’ and ‘Securing DevOps’ and his company would probably give you six figures and a brand new macbook. For an extra bonus you could work through their crypto challenges. https://cryptopals.com/sets/1 https://cryptopals.com/sets/1 https://www.manning.com/books/securing-devops https://www.manning.com/books/securing-devops https://archive.org/details/TheWebApplicationHackersHandbook2ndEdition https://archive.org/details/TheWebApplicationHackersHandbook...
- mr_toad 5y agoThat’s a company that hires based on actual knowledge and skill, rather than certificates and buzzwords.
- merricksb 5y agoDiscussed 3 days ago: https://news.ycombinator.com/item?id=27219156 https://news.ycombinator.com/item?id=27219156 (88 points/94 comments)
- shiftpgdn 5y agoI am a Sr. devops engineer and have been looking to transition to a devsecops or even some sort of security ops role for a YEAR. I am willing to take a pay cut and move to a more junior role but I can never pass the HR filter of “prior security experience needed.”
- cyberpunk 5y agoYeah, so.. I was in the same boat. Just fake your cv, it sounds really unethical but really if you’re a sr devops you’ll be able to handle all the work easily. You’ll only get in trouble if you can’t actually do it. Maybe do the oscp too.
- jart 5y agoWorking in cybersecurity requires trust. Lying on your CV isn't a great way of demonstrating that.
- adventured 5y agoThey're fake / fraudulent requirements, it's questionable which side is being more unethical. Entry level with min 3-5 years of experience in cyber security, yeah, that's bullshit. Either they're outright lying, dramatically exaggerating about what they need, or dangerously incompetent. When someone sets up fraudulent requirements for a job listing, they're priming the ground for dishonesty all around (they're being dishonest with the job listing to begin with), and they become partially responsible for the context. If I put out a job listing for $250,000 / year and demand people have 3-5 years of experience at telepathy, I'm going to get a lot of candidates willing to lie on their application. The same principle comes into effect when you put out any manner of fraudulent requirements for jobs; to the extent your listing is fraudulent, is the extent to which it's going to cause problems one way or another.
- jart 5y agoIf I copied and pasted some boilerplate requirements to save time, I would look for the candidate whose attitude is, "I'm so strong in other areas you haven't considered that you're going to overlook your requirements and make an exception for me" rather than the candidate who thinks, "I take bullet points so seriously that I'm going to focus on deceiving you into thinking I meet them when I actually don't". You will eventually find an employer who doesn't bother fact checking but is that the kind of employer you want?
- a3n 5y agoWell that oughta get all those waiters and cashiers off unemployment.
- fullshark 5y agoNo one wants to pay big money to improve the talent in a cost center.
- AtlasBarfed 5y agoWell, since ultimately this involves codewords dancing around the "don't want to pay proper wage", America's companies should instead hand their security over to outsourcing firms like they do with everything else that is IT related? What could go wrong? Make sure to diversify to China, Russia, Eastern Europe, Malaysia, Israel etc. Oh does that sound like a bad idea? The fact is as soon as the main systems development is outsourced, you might as well have outsourced the security too. Probably why most enterprise security is a bunch of people buying Cisco appliances and formulating checklists and policies and don't even know specific vulnerabilities or the safety degree of various algorithms. And of course, their main job, making powerpoints for upper management and occupying seats/budget such that when leaks or failures occur upper management has plausible deniability.
- DigitallyFidget 5y agoI wish these supposed jobs existed when I finished my degree for going into cybersecurity, unfortunately EVERY "entry level" job required 3-5 years experience. It's probably exactly the same today. Now I work in electrical engineering, because the position requested (not required) a background in IT and my hobbyist experience was enough to satisfy the rest of the requirements.
- pyuser583 5y agoI was never entry level. First programming job was senior. Like really senior. No idea why they hired someone brand for senior. I guess for a while I explained it as “senior” and “junior” not necessarily being descriptive. Now I think it’s that I had related experience (I had been a teacher, and training/mentoring is a big part of the job.)
- carlmr 5y agoIf 3-5 years is the baseline, you deduct 3-5 years from the experience numbers and apply to those job postings. I.e. 3-5 years entry level? Apply after college. 5-8 years senior position? Apply after 2-3 years. Job position descriptions are wish lists, if they don't find a candidate they will hire somebody that doesn't fit the bill 100%. Which is usually the people that dared to apply anyway.
- anothernewdude 5y ago> "It just requires someone who has the proper training, proper certification Certification? I don't think so, why would you even... > Tim Herbert, executive vice president for research at CompTIA. Ahhh... it's an advertisement for a bad certification program.