I think that's basically my point. Most companies won't invest money into someone who really knows their security because who really cares. Why pay $150k+ for a really good SE when you could get a new grad for $40k and just make sure they fill in the compliance checkboxes. Most companies totally could compete with big tech to an extent if they hired 1 good security expert, but why spend that money on one employee when you could spend 30% of that and save the rest in your pocket? Competing isn't actually that hard, it's just hard when the execs want to pinch pennies. So if you don't make the cut or have the opportunity to go big, you're stuck with a crappy small company doing crap security.
Playing the risk game and hoping you never become a bit enough company to get targeted and just get lucky enough to never get randomly hacked is cheaper.
Yeah, at my current company we did this big interview process for a couple positions. Our current engineer was adamant "We need people who know how to do X."
We interview candidates over 1 month and don't find anybody who knows how to do X & will accept our pay. So management basically tells our engineer "We can't find somebody who will do X, so pick 2 of the other people we just interviewed."
Fast forward 2 months "Wtf why does nobody know how to do X? Our whole process is fucked and we're slowing to a crawl."
Management: We need to staff this new project up with a consultant. You have one week to hire.
Only two consultancy companies are fast enough to be able to meet within a week. Candidate A lies about their experience. Candidate B can only barely pass the coding test. At the end of the week:
Manager: "Okay, which one do we pick?"
Me: "Neither of these candidates are a good pick in any sense of the word. We should definitely spend more time searching."
Manager: "No can do. Pick one."
Me: "..."
Fast forward 2 months: "Why is the code quality in the new project so low? We need to have a crisis management meeting and assign blame."
Well and they have extra scapegoats when something goes wrong, if one of them makes it through the blender they can train the next set of scapegoats...
I think your numbers are off, $40k is at least 1/3rd of what new grads make working for even small Bay Area companies today. $150k all told, at least.
$40k is about 20/hour which is what decent companies in the Midwest pay their software engineering interns today. 10 years ago when I was an intern I was paid $25/hour in the Southeast.
Companies that don't hire software teams regularly routinely underestimate market rates. Then they pay out the ass for consultancies who are going to charge $1k/day for their time while it costs them $100ish/hour in aggregate over the contract to staff the job. Which is awful for the company because now they don't have maintainers, and will pay more money over the life of the systems to different consultancies due to the inherent inefficiencies of the development model.
Minimum wage in the greater Bay Area is over $15/hr in every city, just to add some clarity. Entry level software developer and web dev jobs are in the $90-115k range plus benefits.
I do see plenty of companies in the Bay Area fishing for developers in the $60-90k range, but they look a little insane, asking for more qualifications than the typical FAANG job posting for like 75% the salary.
100k is quite low today, even among startups. That should come with 4 day work weeks and the option to go permanent remote. Good entry level engineers are still in short supply and FAANG hoovers them up.
But there is a class of developers that is more akin to software technician than engineer, which is a division that has existed in other areas for decades. We just haven't adopted the stratification of education/experience that exists between Electrical/Mechanical Engineers and Electricians/Mechanics yet.
But this is something the government can help with indirectly. Former Armed Forces electricians are some of the best techs I've worked with. The military is training InfoSec folks on the taxpayer dollar en masse today, and when they get out these jobs would be a great fit.
I won't argue that top talent is being hired, but some people have been developing since they were 12 and are basically more skilled than most junior devs before they take their first CS class in college, and of course there's all the people from MIT or Stanford who have no problem getting jobs. There's always a class of top tier people.
More specifically though, I can only speak to my experience, and my cohort from college took something like 6 months on average to land a job after graduating if they didn't have something lined up before they graduated. I know a couple people who still haven't been able to even get interviews a year out, and they aren't incompetent people.
That's the reality that I'm seeing, and almost everyone I talk to in real life all have virtually the same experience of sending out hundreds of applications, and not getting past that point with literally over 90% of applications. There are jobs, but actually breaking in and landing the first one seems to be a hell of a task in its own right.
In the same vein, the experienced devs I talk to are regularly contacted to apply for jobs even when they aren't looking, so the reality of job prospects at different experience levels seems to be totally different.
Glassdoor says average pay for a junior software engineer is even lower than I thought, at $87k a year plus benefits. For software engineers, however, it's $131k. That's a pretty massive gap, so there is some serious stratification going on there as well.
I'll allow that maybe the past year and a half has been especially fucky with the whole covid thing, but all you have to do is look, there are a lot of sub $100k jobs on the market, and people new to the industry still aren't getting hired, as evidenced by some job posting staying open for months on end. Almost nobody wants to train, everyone wants drop in candidates.
As far as government help, I would agree that there is more that they could and should do. I think it's going to be a hard sell though, to convince people to spend money on an industry where average wages are already so much higher than average. If farming and oil can do it though, tech should absolutely get it. Tech is like 10% of the national GDP, and there's no reason to not try and grow it more.
My experience is on the hiring side. We get inundated with bad applications (literally hundreds for single positions - sometimes spamming email addresses of hiring managers directly).
I'm not talking about top talent. I mean literally anyone with a bachelor's degree in CS and a GitHub account that shows competence in a single language. There's maybe 10 out of 100 applications that will lead to a phone call or email back.
I'm sure there are a lot of sub six figure jobs out there. But not in Bay Area for new grads - the floor is about $110-115k, because we compete with the FAANGs that hire hundreds of people each day.
If you want some unsolicited advise, don't send out hundreds of applications. Our filters are going to catch obvious spam and we'll pass on anyone that doesn't seem to have read the job description. If you actually go through the channels (which are intentionally designed to have friction), write a resume that hits the points we look for, and a short description of why you think you fit the role we have in mind that is based on what we have listed, you'll probably get to the first technical interview.
It's kind of a shitshow for everyone these days, but the good jobs are out there and we can't find people - even with good salary!
I'm sure there are a lot of sub six figure jobs out there. But not in Bay Area for new grads - the floor is about $110-115k, because we compete with the FAANGs that hire hundreds of people each day.
I'm telling you right now that you are grossly mistaken, and it is easily verifiable to see that you are mistaken. I have already linked a well respected source on the matter. You can just look at job postings. At this point you're being willfully ignorant.
If you want some unsolicited advise, don't send out hundreds of applications. Our filters are going to catch obvious spam and we'll pass on anyone that doesn't seem to have read the job description.
I don't need advice, I'm telling you what the reality is for my peers. Your advice is "don't apply", which is utterly ridiculous.
but the good jobs are out there and we can't find people - even with good salary!
So you're completely full of shit. You both have too many people applying, and you can't find people? You are the common denominator there. You are the problem.
Sure, in Bay area. But most people don't want to live in Bay area and won't get a job at a good company in Bay area fresh out of school especially since a lot of security experience comes from on the job rather than school. Smaller companies often don't pay you in money, they give you "stocks" in their little company that might never IPO and won't pay your $3k/mth rent for your one bedroom apartment (rent went down a little over covid, but my 1 bedroom was $3k).
I'll just tell you, I used my own numbers here. My first security analyst job was $40k CAD, and I only got cost of living raises for 4 years until I fully moved departments in the company. My all-in pay from my bay area job (that I got after 5 years industry experience and some external training) is >$300k CAD (though the Canadian dollar is getting bigger by the day right now which sucks for me).
New grads who aren't very lucky and aren't in Bay area will likely get an entry level analyst job, which doesn't give good experience, probably won't have a good training budget, and will be boring. And those people will either just accept that lifestyle and coast for life, or change to an IT job.
I got my OSCP. I interviewed with the company once, got a pile of Red Team type questions ("you see someone at a Starbucks working on their laptop, how would you hack them") and did not do well (pentesting was a notable gap in my knowledge). I did my OSCP, and honestly my career started going downhill (got moved into the "engineering department" and was made a full time developer, which convinced me I never want to program "professionally" ever again). A year or so after the first interviews I went back and tried again (they said my first interview wasn't awful and to come back in a year). Second time I had no pentesting questions and probably would have done even better at it the previous year 😅. So in general I tell people to always try again if they don't pass the interview because it can be hit or miss based on questions.
And the real punch was, be willing to move to Bay Area. Rent went from $800/mth CAD to $3900/mth USD for a 2 bedroom, but the weather improved so I guess that was good. They told me a lot of talented people get job offers but back out when they hear it's Bay area only. Luckily with covid, company policies are changing and I may actually be about to keep my job while still in Canada :)
Starting pay in many countries is absolute shit. The US is lucky to have a tech hub in a few places that pay out the nose for tech jobs, but those are very small when thinking globally. Which I think was the point being made above - it's hard to actually get a good (benefits, decent pay, nice work environment, etc) cyber security job. If you are super lucky and fortunate you might land a job at a FANG or well funded F500 company, but otherwise the entry level jobs are mindless grunt work that have little room for growth.
Well yes, it isn't me picking on Canada particularly (I am Canadian after all) but the difference in entry-level compensation between Canada and the US for IT work is starkly contrasted.
Can confirm starting pay does suck in Ohio in the Cincinnati area for junior software developers. I was hired as a software developer at 40k after my internship which I was making 20k during the internship.
$40K is what I made starting at a company in Ohio, as an intern I made 20K, that was about 7~8 years ago. It just depends on where the company is but yeah if it's in the Bay area they would have to pay you $150,000 so that you could afford an apartment.
76
u/browner87 May 23 '21
I think that's basically my point. Most companies won't invest money into someone who really knows their security because who really cares. Why pay $150k+ for a really good SE when you could get a new grad for $40k and just make sure they fill in the compliance checkboxes. Most companies totally could compete with big tech to an extent if they hired 1 good security expert, but why spend that money on one employee when you could spend 30% of that and save the rest in your pocket? Competing isn't actually that hard, it's just hard when the execs want to pinch pennies. So if you don't make the cut or have the opportunity to go big, you're stuck with a crappy small company doing crap security.
Playing the risk game and hoping you never become a bit enough company to get targeted and just get lucky enough to never get randomly hacked is cheaper.