Skip to content

Comment on Bruce Schneier: On the Cybersecurity Jobs Shortage

Comments

Nit: it's not a jobs shortage, it's a talent shortage.

And as soon as you mention cyber security, there will be confusion over whether you're referring to front line SoC analysts, application security engineers, malware analysts, threat hunting, DFIR specialists, vulnerability researchers, security architects, etc. The skills, knowledge and barrier to entry are wildly different among various sub-domains.

The nature of skilled cyber security is that it requires a deep understanding of computer architecture and programming as a prerequisite. If you don't understand how computers work at a fairly low level, you're going to have a tough time truly understanding security enough to contribute.

There's also a huge industry around certification and compliance that adds almost no value. I've never known any experienced security professional who places any value in CISSP, CEH, etc. (In fact they're often a negative indicator of competence). They're the security equivalent of a 6-week coding bootcamp. Mostly just a cash grab.

Coincidentally, all the best security minds I know are mostly self taught when it comes to the security aspect, having pivoted into it from a dev background. The types of people who spend their free time reverse engineering anything they can get their hands on or practicing CTFs.

There's also a huge industry around certification and compliance that adds almost no value. I've never known any experienced security professional who places any value in CISSP, CEH, etc. (In fact they're often a negative indicator of competence). They're the security equivalent of a 6-week coding bootcamp. Mostly just a cash grab.

Preach. The number of times I have had to explain basic computer to a cissp is larger than I’d like to admit.

That’s because you’re misunderstanding the purpose of CISSP. It’s about risk mitigation and governance, not 0days and buffer overflows.

If you want that, hire a hacker.

I've never known any experienced security professional who places any value in CISSP, CEH, etc. (In fact they're often a negative indicator of competence)

You're tempting me to go on a very long rant about your comment right there. Those two certs are horrible but here are plenty of difficult certs with practical exams like offensive security certs and even SANS these days but damn shame on you if you use someone's certs as a negative indicator or an indicator of anything other than they or their employer paying a large sum of money to validate some knowledge or skill.

Coincidentally, all the best security minds I know are mostly self taught when it comes to the security aspect, having pivoted into it from a dev background. The types of people who spend their free time reverse engineering anything they can get their hands on or practicing CTFs.

Right, and you will accept github accounts and HTB accounts on a resume? How many company's HR will let you? How do you know people aren't buying those accounts to get a job? (Certs are proctored).

You can teach yourself a lot of things, I did. But there was a crapton of stuff I had to learn responding to incidents and trying to solve real world problems that you just can't learn sitting at home. I don't disagree with what you said about being self taught, but that only means they are motivated and have potential. Certs and experience is how you prove that potential enough to get an interview, it is the manager's job to grill them and make sure their cert isn't b.s. after that.

I have seen talented people with or without degrees and/or certs and with varying backgrounds from school teachers and geologists to masters degrees.

It's rare to have more than 100 applications for security jobs. So my take is that security managers themselves need to learn security well or hire people whose opinion they can rely on. And then use certs and experience to priorize the stack, do phone interviews and practical online tests to filter out applicants and do an extensive in person (or over zoom) technical interview to hire the right talent.

If I may add another perspective, the culture in the US is particilarly horrible. In certain other countries, they have tons of talented hackers who get paid shit (well, at least not as good as the US).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.