3 ms·
This is interesting, and not the first time I've seen this sentiment. I don't take immediate issue with the points made here, but I think the conclusion is not
by david_shaw 2y ago
This is interesting, and not the first time I've seen this sentiment.
I don't take immediate issue with the points made here, but I think the conclusion is not entirely correct. Security isn't full, it's just harder and more competitive than people think.
I'll explain: because of the hype described here, many, many people decided that security would be a great way to make a living. They were told that there was a severe need for security professionals, and that there would be high-paying jobs just waiting for them to apply.
So these people studied security in school, maybe took the Security+ or CEH certs, and applied for jobs. Those that got jobs got laid off (again, mentioned in the article) when times got tough, or never got a job in the first place. Why?
Security is a field of people who love what they do. Go to DEF CON -- or even better, small, regional infosec conferences -- and you'll find people who are extremely talented... some of whom don't even work in the industry. For people like this, there is a talent shortage.
I've been consistently hiring security people for the last 15 years. There is absolutely a talent shortage at high levels of the industry -- but it's really hard to get to that level. Learning the OWASP Top 10 and a few nmap flags isn't going to cut it.
My experience may not be universal, but this is what I've seen over the course of a lifetime in infosec.
- GuB-42 2y agoI don't work in cybersecurity, though I kind of considered it. Cybersecurity looks fun, I have seen a few DEFCON talks and if it wasn't in a different continent, maybe I would have been there. Finding vulnerabilities, cracking stuff, learning about all the incredibly clever attacks, defenses, and how to overcome them, CTF games, etc... All fun stuff. But the reality looks more like implementing the latest recommendations from whatever regulatory agency, checking boxes, writing reports. Being hated by everyone else because they are trying to do their job and you are in the way with all your restrictions, some of them you know are useless but you have to put them in place to check a box. Going through who knows how many reports full of false positives. Of course I guess there is some stressful moment when you are actually under attack, calls in the middle of the night and all that. Not for everyone (and not for me) but at least, that's exciting. But most of the job looks more like doing administrative paperwork in an office than the cool stuff you see at DEFCON.
- PenguinCoder 2y agoI was a Linux sysadmin that transitioned to cybersecurity a decade ago. I much prefer this type of work than the new cloud hotness. While there is a lot of check the box security at different companies, that's not what I see or do cybersecurity as. That's more compliance. Granted I am a blue team incident responder and I love the analysis, puzzle and problem solving, and achieving security that's outside the box of _install this tool, good_. I'm lucky that my current company sees our value in that and listens to our recommendations. All that to say, I like this field when it's being done right.
- Workaccount2 2y agoI remember years ago when working my way through certs by going to classes, it was abundantly clear who was there because they had a fiendish obsession with computers and who was there because they googled "highest paying jobs you can get without a college degree". The ratio was 1 to 10 respectively. Even with my first job, I remember being gleeful to be in a "computer nerd" environment, only to learn that my work mate didn't give shit about computers and was just here to do their job.