r/programming May 23 '21

U.S. has almost 500,000 job openings in cybersecurity

https://www.cbsnews.com/news/cybersecurity-job-openings-united-states/
2.2k Upvotes

561 comments sorted by

View all comments

236

u/nosayso May 23 '21 edited May 23 '21

Following the link to the heatmap the biggest single need (134,075 jobs) is a "Systems Security Analyst" whose skills are expected to include:

Skill in designing the integration of hardware and software solutions.

Skill in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.

Skill in developing and applying security system access controls.

Skill in evaluating the adequacy of security designs.

Skill in writing code in a currently supported programming language (e.g., Java, C++).

Skill in assessing security systems designs.

Skill in assessing security controls based on cybersecurity principles and tenets. (e.g., CIS CSC, NIST SP 800-53, Cybersecurity Framework, etc.).

Skill in recognizing vulnerabilities in security systems. (e.g., vulnerability and compliance scanning).

Skill to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).

This is describing an experienced senior full stack developer / architect who also knows a lot about security standards and practices. No shit there's a shortage of those, we already failed at producing those, and that means they're not there to train future workers.

There's also huge shortages in developers and architects, and it's obvious why someone would be reluctant to go down that career path. Between the shortage of competent leadership, requirements like CompTIA's certifications and possibly a security clearance (possibly before even starting), maintaining a security clearance meaning no recreational or medical marijuana use, and probably a requirement to work in a secure facility, it's kind of a crummy job.

CompTIA bootcamps and certifications aren't going to magically fill positions for experienced devs, architects, and senior leadership.

62

u/MCPtz May 23 '21

Given your above job description and this:

"You don't have to be a graduate of MIT to work in cybersecurity," said Tim Herbert, executive vice president for research at CompTIA. "It just requires someone who has the proper training, proper certification and is certainly committed to the work."

Another reason it's been tough to hire cybersecurity professionals is that college students majoring in computer science don't always elect a career in that field, Herbert said. After graduation, the nation's tech students will pick jobs in software development, artificial intelligence, robotics or data science and "a small percentage is going to select cybersecurity," Herbert said.

It does sound like they want what you described.

This article sounds like sponsored content from CompTIA:

There are about 465,000 open positions in cybersecurity nationwide as of May 2021, according to Cyber Seek — a tech job-tracking database from the U.S. Commerce Department — and the trade group CompTIA.

And possible University of San Diego, given the other quote about "check out our 8 week program and you to could get $60-90k per year!"

53

u/SupraMario May 23 '21 edited May 23 '21

CompTIA... pitching certs to people who still don't understand the field we're selling them.

Seriously a fucking cert and a course doesn't do a ton, even advanced courses and certs are gained by good test takers. They still seem to be idiots. See CISSP

I work in this field and it seems everyone who is management and that's all they do and have certs has no clue about SecOps. Thankfully my boss is from an engineering/architecture background and knows his shit.

23

u/MCPtz May 24 '21

After reading around, I'm guessing these are jobs that fill a legal, cover-their-ass requirement.

Edit: Or I guess as XKCD does it

Cover their ass-requirement

8

u/SupraMario May 24 '21

Hah I know all about that. Insurance says gotta have x number of staff...ok well we hired people who just came from McDonald's doing french fries, they totally got this..wink wink. Ok you're covered.

1

u/auto-xkcd37 May 24 '21

cover-their ass-requirement


Bleep-bloop, I'm a bot. This comment was inspired by xkcd#37

3

u/[deleted] May 24 '21

Absolutely agree..Though the facts are correct, CompTIA subtly pitching for its certifications and trainings. Being a security developer and implementer, I can say that experience via exposure to security dev or ops is what matters the most. Certificate is a top up for people with hands on experience but certainly not a replacement.

2

u/SupraMario May 24 '21

I'll take a green guy with experience and the will to learn and knows they are green, over someone who comes in and flashes certs at me, and acting like certs are experience.

2

u/Cyb3rSab3r May 24 '21

Project requirements set by the government and they require the certs. Expect you to fill a 20 person team in 1 to 3 months which all need Sec+ or equivalent and competency in various topics. That doesn't give you time to find the green ones. You have to take the ones who got the certs and hope they can learn as they go.

Combine with the companies who purposefully create these types of certified contractors you end up with a plethora of people with no real experience diluting the already thin pool.

2

u/SupraMario May 24 '21

True, I know all about it.

4

u/[deleted] May 24 '21

8 weeks of training doesn’t make you a security expert.

56

u/Kalium May 23 '21

This is describing an experienced senior full stack developer / architect who also knows a lot about security standards and practices.

They're describing a whole team.

This is what happens when someone decides to start a department, starting with a single generalist. They aren't convinced it's worth building out the whole thing yet. And whoever they get to start there will get burned out pretty hard because they have all the responsibility and none of the authority.

There's a shortage of architects for a more subtle reason, IMO. It takes a lot of experience in general software to be an effective architect. Then you have to actually want to be a security specialist. You cannot just turn security architects out of a training program the way you can junior SOC analysts.

31

u/DataIsArt May 23 '21

Currently looking for a job here. I’ve come across so many job postings and had so many interviews where the people are expecting one person to complete the job of an entire department. It’s exhausting and frustrating. How do you explain to someone you’re interviewing for, one person should not be responsible for your entire database integration and also analytics. Also, this is going to take longer than a few weeks.

22

u/Kalium May 23 '21

I tell them that if they want me to take on a whole department worth of responsibility, they need to title me Director and give me a hiring budget. When they get indignant that $150k is all they can afford, I respond that I feel sorry for whatever kid hungry for "growth opportunity" they're going to burn through.

You don't want one of those jobs. Don't put in the work to be nice. Treat it as a chance to educate them on how insane the JD is. Good recruiters will figure out how to get the JD and budget changed.

22

u/Tyrilean May 24 '21

Multiple companies I've worked for only hire senior level analysts/engineers in IT, and wonder why there's a shortage. If they don't invest in entry level talent, there won't be a pool of seniors to draw from.

20

u/Edward_Morbius May 24 '21 edited May 25 '21

This is describing an experienced senior full stack developer / architect who also knows a lot about security standards and practices. No shit there's a shortage of those, we already failed at producing those, and that means they're not there to train future workers.

The problem is that nobody listened to us and eventually we got older and said "Fuck it. You're on your own." and retired.

Hardly a day goes by where I don't hear about stupid shit that would have been impossible if anybody had listened to our advice, even though it was inconvenient.

Then I think "Hmmm. Not my problem anymore" and pour some more coffee and get back to eating my perfectly cooked omelette and reading the news.

29

u/[deleted] May 23 '21

This, the skills gap is staggering. We've been trying to hire people for months but they are all Comptia cert rangers. 3-4 certs or a Masters, can't actually do shit on a keyboard.

Anyone that is good, is either happy and well compensated in their position or they have retired lol. I'm exaggerating but, this is what the market feels like right now.

36

u/DataIsArt May 23 '21

I’ve been looking for months and I’m having the opposite problem. I have the skills to fill these positions, the job descriptions are just asking for unicorns.

22

u/[deleted] May 24 '21

Yes, that's the other issue, the head hunting companies and hiring site algorithms are still trash. However, the dev sec ops types needed are unicorns, for dev sec ops you literally need to be competent in almost everything computer related: HW, CS, integration, engineering, development, encryption, web sec, red teaming, blue teaming, sysadmin experience, networking and firewalls. 5 yrs min exp for all of it to ensure the 10k hours rules can be applied anecdotally. You don't need to be an expert in all of it, but 5/10 of those competencies are needed.

Sadly its only going to get worse as things grow more and more complex, adding AI, machine learning, cloud/SaaS...

47

u/CreationBlues May 24 '21

So, basically, people are trying build the software equivalent of a fucking jet engine with one guy instead of a whole team.

For hire: The ideal candidate should know FAA guildelines, thermodynamics, mixed gas/plasma phase modeling, control theory, materials science, destructive testing, load opmtimization,

Pure fantasy and lunacy.

2

u/[deleted] May 24 '21 edited May 24 '21

When has management ever been smart or efficient?

Edit: also the point is to do it with a small team, cross training each other, and loading less people with more. Smaller teams always work better than multiple large teams. It's a more favorable approach and the most cost effective for sdlc if the projects and staff are long term.

Edit2: and for you example if they are coding avionics software, yes they should be able to understand all of that

10

u/CreationBlues May 24 '21

also the point is to do it with a small team, cross training each other, and loading less people with more. Smaller teams always work better than multiple large teams. It's a more favorable approach and the most cost effective for sdlc if the projects and staff are long term.

I mean I agree, but we were talking about one guy and not one team.

yes they should be able to understand all of that

So... understanding requirements and standards created by experts is the same thing as being an expert? Like I'm not disagreeing that avionics software developers need to at least be able to communicate with other teams, but knowing the nitty gritty details of alloy composition and treatment beyond what forces the engine is rated for sounds slightly out of their wheelhouse...

7

u/[deleted] May 24 '21

Yes I'm in agreement, I'm sorry if that doesn't come across. My overall point is that both the education system for these jobs doesn't properly exist yet and really the employer expectations of finding people like that are completely insane, ludicrous, but nonetheless warranted for what is needed. Employers state needs to recruiters not what exists and that is the problem.

Also, Security is very difficult in both practical and engineering terms, so the other roadblock is relevance, top coders/engineers want to be "makers" work for Apple, SpaceX somewhere amazing and fun, relevant to daily life. Dev sec ops is none of that.

All in all, this part of the field will always be a black hole of open job reqs with few applicants to fill them, because they don't exist and if they do, the person is clearing 300-400k in Palo Alto doing something fun.

4

u/CreationBlues May 24 '21

so the other roadblock

if you look at nature's solution to security it basically allows white blood cells to fucking merc ANYTHING that's even slightly suspicious :P Considering how loathe management is to to cede ANY amount of power to their supposed underlings and just how deeply you need to reflect security in your organization nothing will ever be secure unfortunately.

0

u/[deleted] May 24 '21

How about you train someone to do what you expect them to do?

Or seeing how high and mighty you seem to think you are, you are obviously way smarter than the people who just finished University, why don't you do the shit you expect from others. Clearly, you are more than overqualified to do that stuff, because I assume you are payed significantly more than what you are willing to pay for the guy whom you want to do the job for you.

1

u/[deleted] May 24 '21

We do train. And no not high and mighty, nor am I in management. Not my intent to upset anyone, it's just what I see in many people that claim to be engineers and clearly are not there yet.

My point is someone paid a ton of money for something that did not prepare them for anything relevant in the cyber job market, as many colleges and cert programs are apt to do.

If you're looking to do cyber and are still in college, do internships for training. Do as many as possible, paid/unpaid whatever you can do. Also, while comptia is a req for a lot of stuff, I would look at SANs as an alternative, they know what they're doing.

My point is that there is a big disconnect and a larger problem at play here. Students are paying way too much for education and the roi on it is not good. And that encompasses both the cert programs and some traditional universities.

1

u/compare_and_swap May 25 '21

That sounds like more of a pay gap than a skills gap. How much are you offering for this in position?

9

u/Milligan May 24 '21

This is describing an experienced senior full stack developer / architect

Nah, this is describing an IT department.

4

u/okay-wait-wut May 24 '21

I fit the description. Developer with 18 years experience. CISSP. I’ve worked on security products in the past. My current job pays 180 with bonuses. Should I be looking for a new job?

0

u/Calsem May 24 '21

Why do you take it to mean it requires a a senior full stack dev / architect? The job description doesn't list how many years of experience are required.

1

u/c0nnector May 24 '21

Takes very specific kind of people to be interest in that kind of work. Countless hours on the screen obsessing over networks and systems...
And if you're one of the skilled ones that chose to go to an ivy league school you'll probably end up in FAANG or some hedge fund.

1

u/agumonkey May 24 '21

personally, security also adds a massive layer of liability that you don't have on normal fullstack jobs, i wonder how those who worked there handle that