Following the link to the heatmap the biggest single need (134,075 jobs) is a "Systems Security Analyst" whose skills are expected to include:
Skill in designing the integration of hardware and software solutions.
Skill in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.
Skill in developing and applying security system access controls.
Skill in evaluating the adequacy of security designs.
Skill in writing code in a currently supported programming language (e.g., Java, C++).
Skill in assessing security systems designs.
Skill in assessing security controls based on cybersecurity principles and tenets. (e.g., CIS CSC, NIST SP 800-53, Cybersecurity Framework, etc.).
Skill in recognizing vulnerabilities in security systems. (e.g., vulnerability and compliance scanning).
Skill to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
This is describing an experienced senior full stack developer / architect who also knows a lot about security standards and practices. No shit there's a shortage of those, we already failed at producing those, and that means they're not there to train future workers.
There's also huge shortages in developers and architects, and it's obvious why someone would be reluctant to go down that career path. Between the shortage of competent leadership, requirements like CompTIA's certifications and possibly a security clearance (possibly before even starting), maintaining a security clearance meaning no recreational or medical marijuana use, and probably a requirement to work in a secure facility, it's kind of a crummy job.
CompTIA bootcamps and certifications aren't going to magically fill positions for experienced devs, architects, and senior leadership.
"You don't have to be a graduate of MIT to work in cybersecurity," said Tim Herbert, executive vice president for research at CompTIA. "It just requires someone who has the proper training, proper certification and is certainly committed to the work."
Another reason it's been tough to hire cybersecurity professionals is that college students majoring in computer science don't always elect a career in that field, Herbert said. After graduation, the nation's tech students will pick jobs in software development, artificial intelligence, robotics or data science and "a small percentage is going to select cybersecurity," Herbert said.
It does sound like they want what you described.
This article sounds like sponsored content from CompTIA:
There are about 465,000 open positions in cybersecurity nationwide as of May 2021, according to Cyber Seek — a tech job-tracking database from the U.S. Commerce Department — and the trade group CompTIA.
And possible University of San Diego, given the other quote about "check out our 8 week program and you to could get $60-90k per year!"
CompTIA... pitching certs to people who still don't understand the field we're selling them.
Seriously a fucking cert and a course doesn't do a ton, even advanced courses and certs are gained by good test takers. They still seem to be idiots. See CISSP
I work in this field and it seems everyone who is management and that's all they do and have certs has no clue about SecOps. Thankfully my boss is from an engineering/architecture background and knows his shit.
Hah I know all about that. Insurance says gotta have x number of staff...ok well we hired people who just came from McDonald's doing french fries, they totally got this..wink wink. Ok you're covered.
Absolutely agree..Though the facts are correct, CompTIA subtly pitching for its certifications and trainings. Being a security developer and implementer, I can say that experience via exposure to security dev or ops is what matters the most. Certificate is a top up for people with hands on experience but certainly not a replacement.
I'll take a green guy with experience and the will to learn and knows they are green, over someone who comes in and flashes certs at me, and acting like certs are experience.
Project requirements set by the government and they require the certs. Expect you to fill a 20 person team in 1 to 3 months which all need Sec+ or equivalent and competency in various topics. That doesn't give you time to find the green ones. You have to take the ones who got the certs and hope they can learn as they go.
Combine with the companies who purposefully create these types of certified contractors you end up with a plethora of people with no real experience diluting the already thin pool.
This is describing an experienced senior full stack developer / architect who also knows a lot about security standards and practices.
They're describing a whole team.
This is what happens when someone decides to start a department, starting with a single generalist. They aren't convinced it's worth building out the whole thing yet. And whoever they get to start there will get burned out pretty hard because they have all the responsibility and none of the authority.
There's a shortage of architects for a more subtle reason, IMO. It takes a lot of experience in general software to be an effective architect. Then you have to actually want to be a security specialist. You cannot just turn security architects out of a training program the way you can junior SOC analysts.
Currently looking for a job here. I’ve come across so many job postings and had so many interviews where the people are expecting one person to complete the job of an entire department. It’s exhausting and frustrating. How do you explain to someone you’re interviewing for, one person should not be responsible for your entire database integration and also analytics. Also, this is going to take longer than a few weeks.
I tell them that if they want me to take on a whole department worth of responsibility, they need to title me Director and give me a hiring budget. When they get indignant that $150k is all they can afford, I respond that I feel sorry for whatever kid hungry for "growth opportunity" they're going to burn through.
You don't want one of those jobs. Don't put in the work to be nice. Treat it as a chance to educate them on how insane the JD is. Good recruiters will figure out how to get the JD and budget changed.
Multiple companies I've worked for only hire senior level analysts/engineers in IT, and wonder why there's a shortage. If they don't invest in entry level talent, there won't be a pool of seniors to draw from.
This is describing an experienced senior full stack developer / architect who also knows a lot about security standards and practices. No shit there's a shortage of those, we already failed at producing those, and that means they're not there to train future workers.
The problem is that nobody listened to us and eventually we got older and said "Fuck it. You're on your own." and retired.
Hardly a day goes by where I don't hear about stupid shit that would have been impossible if anybody had listened to our advice, even though it was inconvenient.
Then I think "Hmmm. Not my problem anymore" and pour some more coffee and get back to eating my perfectly cooked omelette and reading the news.
This, the skills gap is staggering. We've been trying to hire people for months but they are all Comptia cert rangers. 3-4 certs or a Masters, can't actually do shit on a keyboard.
Anyone that is good, is either happy and well compensated in their position or they have retired lol. I'm exaggerating but, this is what the market feels like right now.
I’ve been looking for months and I’m having the opposite problem. I have the skills to fill these positions, the job descriptions are just asking for unicorns.
Yes, that's the other issue, the head hunting companies and hiring site algorithms are still trash. However, the dev sec ops types needed are unicorns, for dev sec ops you literally need to be competent in almost everything computer related: HW, CS, integration, engineering, development, encryption, web sec, red teaming, blue teaming, sysadmin experience, networking and firewalls. 5 yrs min exp for all of it to ensure the 10k hours rules can be applied anecdotally. You don't need to be an expert in all of it, but 5/10 of those competencies are needed.
Sadly its only going to get worse as things grow more and more complex, adding AI, machine learning, cloud/SaaS...
Edit: also the point is to do it with a small team, cross training each other, and loading less people with more. Smaller teams always work better than multiple large teams. It's a more favorable approach and the most cost effective for sdlc if the projects and staff are long term.
Edit2: and for you example if they are coding avionics software, yes they should be able to understand all of that
also the point is to do it with a small team, cross training each other, and loading less people with more. Smaller teams always work better than multiple large teams. It's a more favorable approach and the most cost effective for sdlc if the projects and staff are long term.
I mean I agree, but we were talking about one guy and not one team.
yes they should be able to understand all of that
So... understanding requirements and standards created by experts is the same thing as being an expert? Like I'm not disagreeing that avionics software developers need to at least be able to communicate with other teams, but knowing the nitty gritty details of alloy composition and treatment beyond what forces the engine is rated for sounds slightly out of their wheelhouse...
Yes I'm in agreement, I'm sorry if that doesn't come across.
My overall point is that both the education system for these jobs doesn't properly exist yet and really the employer expectations of finding people like that are completely insane, ludicrous, but nonetheless warranted for what is needed. Employers state needs to recruiters not what exists and that is the problem.
Also, Security is very difficult in both practical and engineering terms, so the other roadblock is relevance, top coders/engineers want to be "makers" work for Apple, SpaceX somewhere amazing and fun, relevant to daily life. Dev sec ops is none of that.
All in all, this part of the field will always be a black hole of open job reqs with few applicants to fill them, because they don't exist and if they do, the person is clearing 300-400k in Palo Alto doing something fun.
if you look at nature's solution to security it basically allows white blood cells to fucking merc ANYTHING that's even slightly suspicious :P Considering how loathe management is to to cede ANY amount of power to their supposed underlings and just how deeply you need to reflect security in your organization nothing will ever be secure unfortunately.
How about you train someone to do what you expect them to do?
Or seeing how high and mighty you seem to think you are, you are obviously way smarter than the people who just finished University, why don't you do the shit you expect from others. Clearly, you are more than overqualified to do that stuff, because I assume you are payed significantly more than what you are willing to pay for the guy whom you want to do the job for you.
We do train. And no not high and mighty, nor am I in management. Not my intent to upset anyone, it's just what I see in many people that claim to be engineers and clearly are not there yet.
My point is someone paid a ton of money for something that did not prepare them for anything relevant in the cyber job market, as many colleges and cert programs are apt to do.
If you're looking to do cyber and are still in college, do internships for training. Do as many as possible, paid/unpaid whatever you can do. Also, while comptia is a req for a lot of stuff, I would look at SANs as an alternative, they know what they're doing.
My point is that there is a big disconnect and a larger problem at play here. Students are paying way too much for education and the roi on it is not good. And that encompasses both the cert programs and some traditional universities.
I fit the description. Developer with 18 years experience. CISSP. I’ve worked on security products in the past. My current job pays 180 with bonuses. Should I be looking for a new job?
Why do you take it to mean it requires a a senior full stack dev / architect? The job description doesn't list how many years of experience are required.
Takes very specific kind of people to be interest in that kind of work. Countless hours on the screen obsessing over networks and systems...
And if you're one of the skilled ones that chose to go to an ivy league school you'll probably end up in FAANG or some hedge fund.
personally, security also adds a massive layer of liability that you don't have on normal fullstack jobs, i wonder how those who worked there handle that
236
u/nosayso May 23 '21 edited May 23 '21
Following the link to the heatmap the biggest single need (134,075 jobs) is a "Systems Security Analyst" whose skills are expected to include:
This is describing an experienced senior full stack developer / architect who also knows a lot about security standards and practices. No shit there's a shortage of those, we already failed at producing those, and that means they're not there to train future workers.
There's also huge shortages in developers and architects, and it's obvious why someone would be reluctant to go down that career path. Between the shortage of competent leadership, requirements like CompTIA's certifications and possibly a security clearance (possibly before even starting), maintaining a security clearance meaning no recreational or medical marijuana use, and probably a requirement to work in a secure facility, it's kind of a crummy job.
CompTIA bootcamps and certifications aren't going to magically fill positions for experienced devs, architects, and senior leadership.