Skip to content

Comment on Bruce Schneier: On the Cybersecurity Jobs Shortage

Comments

I have 25 years of experience in security, encompassing both product and I.T. security in technically focused IC roles.

I find it incredibly unrewarding.

On the front lines, most situations tend to be adversarial or highly stressful. This is the case even when your primary intention is to provide teams with the time and resources they need to address problems effectively - it can be an exhausting process to establish trust and camaraderie with your non-security peers given preconceptions about security in many organizations.

Engaging with the business and executive levels is even more challenging. I often wish that all managers were mandated to earn a CISSP. And while I respect the role of the CFO, as they ultimately shoulder all the risk, I just wish CPA’s would stay away from CISO positions, they’re not helping.

My experience is similar. I got drawn into the I. T. security field in the early 1990s Internet era due to my technical background and experience. It was fun and rewarding at first. But by the late 2000s the huge burden of responsibility, general business hostility towards security, expensive credentialisation, a lack of corresponding compensation, and limited career options, led me stop doing it. Programming is still fun and way less stressful.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.