U.S. has almost 500k job openings in cybersecurity
cbsnews.com
cbsnews.com
1. Working in a corporation, where the job is just compliance checklist whack-a-mole.
2. Working in government, which can be good (Mudge has done good work there) but the common policy I've seen elsewhere seems to be to maintain an arsenal of open exploits, thus making everyone in the world _less_ safe in the name of... security...?
3. Working in contract pentesting... for clients who really only care about compliance checklist whack-a-mole.
There is a fourth option, which is research, like what Christopher Domas does, but opportunities for that which don't end up falling into the government trap seem few and far between (and even fewer if you've developed your skills outside an MS/PhD program).
That said, I am not an industry insider. This is only my impression as someone who was once interested in the field and decided to stick with software engineering after getting a bad taste from what I saw from the industry.
Security feels similar. The edge of the spear is fascinating, exciting, challenging work.
Unfortunately, no one needs that work. What companies actually need is mind-bogglingly slow, comprehensive, steady progress and improvement of their postures.
A much worse career would be convincing regulators that new aircraft like the 737 MAX don't need any additional training. Maintaining lists of open exploits, and keeping them secret from vulnerable parties is that kind of job, where you're making the world less safe in a perversion of your ostensible goals.
That was my first thought as a software dev - I'd love to be able to spend time _optimizing_ something rather than breaking my "stories" down to one-to-two hour "tasks" and justifying my "estimates" every morning.
How many orgs are transitioning to zero knowledge networks, encrypting all data at rest?
That’s a common checklist item. Implementing it is of course more work than just checking the box, but ensuring it’s actually done means it’s added to a lot of different checklists.
Never store PII as cleartext, akin to proper password storage.
Translucent Databases https://www.amazon.com/gp/product/1441421343
Encrypting databases, file systems, and backups remain necessary, but insufficient.
Yes, Checklist in aviation and aerospace are crucial, but at the same time, you have to avoid checklist for checklist sake.
But they also do a lot of failure response testing, simulations where you walk through a failed checklist or incidient and how you would response. Cypersecurity does pen testing and phishing attempts, but how about dry runs where you act as if you are compromised and everyone runs a "fire drill" scenario?
On the other hand, so many real breaches have happened because very basic things weren't done, and a basic checklist would have shown that they aren't done. But of course, that checklist would not cause the organization to provide the resources and motivation to actually fix the issues.
The big problem with checklists is that organizations inherently don't really want to invest to fix these problems, they have other priorities, and if someone else forces a checklist on them, then they often will explicitly prioritize ticking off the boxes (with any caveats they can negotiate or hide) at the expense of actual security.
At the end of the day it is a job.
But when you part of the 1% of the good people you have your team and more leaway and potentially get called for the more critical and more interesting things.
The field is also full of people who switched careers to make more money, so they blow minor security issues out of proportion to try and justify their paycheck. It's really frustrating, because then management thinks you aren't doing anything if you don't do the same.
If you want to work in cybersecurity, I think your job as a software developer would actually be very valuable. The biggest problem we have, besides management thinking we're a waste of money, is having too much data, and no good way to go through it. Dedicated cybersecurity tools are pretty awful, and very expensive. If I had any professional experience in software development, that's what I'd be focused on. There's only a handful of automation tools used by most of the industry, and they are only used because they're the only option, not because they're particularly good.
I've considered making tools of my own for some things, but knowing what would actually be useful to people doing real work would be a good motivator.
Can you give a few examples of these?
There's e.g. product security, which can be a bit less nihilistic. You take your security knowledge and use that to influence application design and implementation process so the result has fewer issues. At the tippity top end this can mean adding e2e, differential privacy, suppressing harmful features, OS security improvements - work that can meaningfully improve security or privacy for millions of people.
There's all sorts of forensics and IR, malware analysis and RE. Exploit dev, scanner monkeying, bug triage, just all sorts.
A lot of pentesters manage to not hate their lives by doing #3 and focusing on the interesting problems while not caring that the customer just wants a compliance input.
Suck levels vary a lot by firm. Just like dev jobs can be meaningful and intellectually fulfilling OR meaningless ticket punching.
The problem is that its hard to measure if someone had deep thoughts about the security of a system vs checked a box as it can take years before you notice they did nothing (eg: hired another firm the next time that found a pile of issues).
Disclaimer: I work for one of the rare non-checklist/scanner firms.
A few of them have distinguished themselves, slightly, in the first year of a multi-year contract -- and then regressed to the mean in the rest.
Quoted prices vary by a factor of 4, approximately. Work done does not. Quality of work appears to be basically independent of price.
Arrogance scales with price, though.
Even if you are a non-checklist firm, I can't justify hiring you at a higher price because I can't differentiate you from the bloviators, and basically nothing you say other than "I am ptacek" can change that.
Scheduling in variety to try and prevent partial burnout is difficult if everyone in a vertical only wants to use the same person.
It's very hard for customers to differentiate the good and bad companies, without having their own internal expertise, and even then you need to go down the line of getting named testers and speaking to each one.
Another problem is with how many/most pentest companies report, which is by exception. There's no requirement to state all the tests they did, just the results, so it's hard to tell the difference between "we've got a good system and they didn't find much" and "they didn't do good work and missed things"
For slimmed down reports that are published/given to third parties (given to the customer’s customer) it’s extremely important that the scope of the test is detailed in that letter. The charlatan firms will be happy to omit the fact that they only tested the “about us” page while blind-folded.
So if you are reading a “letter of assessment” for something you are thinking of adopting, just look for the scope of the test, and if it sounds reasonable they potentially had a good test. If it’s missing, the test wasn’t worth the electrons in that letter.
5. A lot of the "Cybersecurity" folks are closer to the sysadmin-cert-associate degree than the Engineering CS side of things.
Most of the time you are just a cost-center, a necessary nuisance. It's a lot harder to extract money / get promoted when your good work isn't immediately noticeable.
As a consultant I've been trying for years, with limited success, to persuade people to think in terms of business process integrity, since that more clearly ties the necessary work to the revenue output. It's an uphill slog though as prevailing culture is checklist compliance.
Doesn't help that major consulting and advising firms make more money on checklist mentalities.
I also found some interviews in a similar format as developer interviews (hands on, timed), but with salaries that make it not really worth the trouble and stress (that's what OSCP was for!).
I've never heard of a pentest that's done as a 24 hour thing where someone is watching you through a webcam and you can't collaborate with people, and then the report is written up the next day. Also (last time I looked at it anyway) it quite a few topics that whilst interesting again don't mirror day-to-day pentesting, and restrictions on using things like Metasploit are just weird.
I still love it. There’s a lot of interesting challenges and equally interesting people to work with. I do agree there is a perception problem, however, most of which is self-inflicted by a small minority of the those that work in the domain.
obviously there are two sides to government, one side is the same as #1, checklist and say our site/solution is now secure, #2 is the side that has to do with generally attacking other governments but also handling dissident/criminal parts of their own society.
Fixing the same security issues,
Or singing of on procedures.
You could spend weeks looking for bugs and find nothing and not make a dime.
There's nothing more boring than those positions. (Or to me, unethical than working for the US government)
I'd much rather create something that benefits the world.
Maybe the partial solution is bug bounties? As much as I'd hate those positions, I actively poke around for holes in websites for fun. I love when I have to do business with a small poorly run website, seems you can always find something they don't want you to have access too. Most recently, no right click to save images, but chrome developer tools got me the high res version anyway!
I’ll be a little more nuanced. I’m very appreciate of the hard work nist does posting best practices and guidelines on privacy, zero-trust, crypto, and other things. The SP series of publications are well respected and do lift the entire industry up to some minimum standard. In some cases they actually move things forward by a lot (like the AES competition)
Last external IT audit I had to explain to the auditors what a password manager was. They'd never heard of it.
The auditors themselves are often tasked with reviewing a massively disparate group of systems, so there's no way they could be come subject matter experts in each one.
So the result is a checklist approach, especially as most compliance tasks are pass/fail.
https://www.crowdstrike.com/cybersecurity-101/cloud-security...
Cloud native tools such as Cilium that leverage eBPF to provide packet level visibility but I doubt 1% of enterprises use them!
https://cloud.google.com/blog/products/containers-kubernetes...
He didn't care about Aws having 2fa configured about our vlan ipsec Tunnel, etc
I even took the liberty to fix the md5 Passwort shit with bcrypt just before the audit...
Are you serious?
What would be your suggestion then?
The solution is defense in depth. Have different accounts with separate access to various services. That way if an account is compromised they don’t have access to everything.
Most of your accounts should provide least access to what they need. Higher level accounts allowing greater control of your system should be rarely available for access and need to be part of regular access control audits.
But non the less with 5 people what audit system would be even available in which only one person has access.
All smart concepts cost either a lot of money or just don't work if you don't have enough people.
Should the only techlead have access to the audit system? Probably. Should the only techlead have access to VMs? Probably yes.
I made sure my systems are encrypted, 2fa wherever possible, no external systems besides the services.
I know this sounds mean but software developers are really embarrassingly bad at security, because security is inconvenient by design and developers strive for convenience.
This is a common statement from security people, and in my view, one of the reasons that security frequently fails.
To make an analogy, it's like a failing startup blaming the market for not adapting to their product. They're trying to solve this in a way the market doesn't want. Likewise, Security teams keep trying to ham-fistedly force everyone to do things in a way that's easy for them, and hard for everyone else.
Ops realized this a while ago, which is why we have so many tools for easily managing infrastructure abstractions. Where are the security abstraction tools? You want accounts to have the least privileges possible, so where are my tools to manage that? From what I've seen, those tools are few and far between.
I maintain that the way security is currently done is actively harmful. It incentivizes not talking to security, because if you do they're going to drop in, make a ton of demands (none of which they will actually help you accomplish), and your PM is going to be pissed the project is now late. Most of the meetings I've been in where security should have been there have involved someone saying "don't do that, because security will get involved".
Frankly, it happens because there is no alternative to using in house security. I can petition my higher ups to let me use AWS or GCP if I'm not happy with how the infrastructure is being managed; who do I petition to use if Security is holding us back?
For what it's worth, compliance departments often have the same issue. They know there's no one else you can use, so they have little incentive to make themselves easy to deal with.
Like some 4 eye system.
They both liked the idea very much that I might need to call them for access to systems I build :D
[1] https://www.bls.gov/emp/tables/emp-by-detailed-occupation.ht...
Many US agencies are mis/guided/influenced/funded/run directly and/or indirectly by industry professionals, lobbyists, etc.
If there was any actual shortage of IT personnel in the US, it would not take experienced US-based IT professionals months or years of job searching to find work -- if at all.
There is no conspiracy theory necessary -- in this case, it's pretty clear-cut -- a training company needed some PR to drum up business, so they got their lobbyist to work with a group inside an agency in the government, got a report, pinged their contact at CBS, done.
But outside of that, it'd be nice to know how 500,000 alleged openings compares historically. It's obviously a number that is supposed to impress.
But how impressed should we be?
How fast is the number growing?
If the number is going up, why aren't all these unemployed IT professionals getting hired? Companies are willing to sustain IT attacks instead of hire and train an experienced IT professional?
Hiring remotely is easier than ever, but does that apply to security jobs? Are clearances necessary? Physical presence?
What is the appropriate number of job openings, per IT vertical (e.g. cybersecurity, networking, cloud, big data, SCADA, etc.), at any point in time, to provide proper 'slack'/fluidity of the labor force? Presumably this would be some number that the IT industry was roughly comfortable with, that industry analysts/economists thought was 'healthy', etc.
Is that 10,000 job openings? 100,000? 1,000,000?
0.15 % of the entire us population just for cyber security?
I hope you don't need garbage men and bakers.
Even better: 0.15% of the entire US population for unfilled jobs.
I'm going to assume most of these aren't permanent positions but gigs.
It's just too big to be correct.
> An eight-week online course could help someone land an entry-level job as a "pen tester," a network security engineer or an incident response analyst, Moore said. Those jobs pay between $60,000 to $90,000 a year, she added
If we can have 500k police and private guards, we should have 500k cyber security specialists
- the building that rents them an office including a guard in the lobby
- the datacenter that rents them space including guards
- the cloud service taking care of their own datacenters
On the other hand, if you have your own building or rent in an unguarded building, deal with cash, have an actual storefront -- you'll probably be hiring security yourself.
I've found it frustrating being in the DevOps space, because the hype bleeds into other decisions and sometimes I swear people forget we're actually running a business and believe everyone should really be focused on security over everything else.