3 ms·
As someone else struggling to find a job, I understand. I would still have my last job if I was a little less transparent and made infosec a blackbox. I gave th
by technick 3y ago
As someone else struggling to find a job, I understand. I would still have my last job if I was a little less transparent and made infosec a blackbox. I gave this company almost 5 years of my time, only to be told "Your services are no longer needed" and given 6 weeks of severance, then forced to sell my private RSU's for 2 cents a piece.
Most companies I've applied at don't respond, the < 5% that do respond with a rejection, they send the rejection email during the weekends which makes me wonder if they have people in other countries reviewing resumes.
I'm not a spring chicken either, I've been doing tech since 1999. Started as a linux / unix admin which became devops between then and 2016. I was doing security work but didn't have a security title until 2016. A lot of DevOps includes security, just it's never called out. I've been in dedicated security roles since 2016, making it all the way to lead security engineer and leading a team of 2 other people. Still I can barely get an interview and when I do get an interview, it ends with "We like you but we're going with another candidate or we don't feel your senior enough. Let me briefly highlight some of the gold nuggets I remember from my recent interviews.
* I did a 30 minute interview for a security architect position at a media company. It was me and another guy talking over a network diagram and the questions that need to be asked. I got all but one, which was about the hardware (Network DVR) becoming sentient and threatening physical damage.
* Did 5 hrs of interviewing for a Senior Security Engineer (detection) only to be put paired with a python developer in the end and asked to write code well beyond what the position called for. I can script and I never claimed to be a developer. But let me show you this thing called Copilot and ChatGPT, or if I need something advanced, I'll ask someone who knows more than me to help out.
* Another interview for a security architect at the local water company. They asked why I want to be a security architect, I respond with, "I'm into making sure security is baked into platforms as it's being designed, it's more optimal that way over shoeing in security as an after thought.". Hiring manager replies with "We've been around for over 100 years, we don't design anything new."
* I interviewed at a major password management company (the biggest) and was talking about their recent breach. In the aftermath they claimed to be encrypting all fields going forward, interview confirmed they lied and are not doing it now. I complained about vendors lying as they lied to me during a vendor review at my previous job. HR let me know later that they "liked me but decided to go with another candidate", probably one that doesn't care.
* I've had two jobs basically ghost me, say they wanted to create a new job position that fits all of my skills then go radio silent.
* A place that rhymes with dox had me interview with someone who thought a WAF can stop malware / ransomware from spreading on a internal network. I didn't know if this was a test to see if I corrected him or not, and if I corrected him will that blow my chances. The recruiter brushed me off and didn't respond for over a month after the interview.
* A few other interviews have turned into dick measuring contests on who knows the most irrelevant crap.
I've applied at jobs that I check every single box on their job posting and they don't even give me the time of day for a conversation before receiving a rejection. I'm getting tired and frustrated with the screwed up practices we've allowed to grow in our industry.