Cybersecurity Is Full (2024)
cyberisfull.com
cyberisfull.com
Yet, all of the mentioned careers have (as the author rightly points out) something in common: there's no cheat code, there's no 6-week bootcamp and there are certainly no magic shortcuts. Cyber security jobs require specialists with experience, just like many other professions.
I don't take immediate issue with the points made here, but I think the conclusion is not entirely correct. Security isn't full, it's just harder and more competitive than people think.
I'll explain: because of the hype described here, many, many people decided that security would be a great way to make a living. They were told that there was a severe need for security professionals, and that there would be high-paying jobs just waiting for them to apply.
So these people studied security in school, maybe took the Security+ or CEH certs, and applied for jobs. Those that got jobs got laid off (again, mentioned in the article) when times got tough, or never got a job in the first place. Why?
Security is a field of people who love what they do. Go to DEF CON -- or even better, small, regional infosec conferences -- and you'll find people who are extremely talented... some of whom don't even work in the industry. For people like this, there is a talent shortage.
I've been consistently hiring security people for the last 15 years. There is absolutely a talent shortage at high levels of the industry -- but it's really hard to get to that level. Learning the OWASP Top 10 and a few nmap flags isn't going to cut it.
My experience may not be universal, but this is what I've seen over the course of a lifetime in infosec.
Even with my first job, I remember being gleeful to be in a "computer nerd" environment, only to learn that my work mate didn't give shit about computers and was just here to do their job.
Cybersecurity looks fun, I have seen a few DEFCON talks and if it wasn't in a different continent, maybe I would have been there. Finding vulnerabilities, cracking stuff, learning about all the incredibly clever attacks, defenses, and how to overcome them, CTF games, etc... All fun stuff.
But the reality looks more like implementing the latest recommendations from whatever regulatory agency, checking boxes, writing reports. Being hated by everyone else because they are trying to do their job and you are in the way with all your restrictions, some of them you know are useless but you have to put them in place to check a box. Going through who knows how many reports full of false positives.
Of course I guess there is some stressful moment when you are actually under attack, calls in the middle of the night and all that. Not for everyone (and not for me) but at least, that's exciting. But most of the job looks more like doing administrative paperwork in an office than the cool stuff you see at DEFCON.
With that said the points the author is making about recruiting and driving salaries down are endemic to other areas. In my undergrad, I had a law-related class and the professor took a class to talk through the issues with job placement in the legal system and encourage students fulfilling an undergrad before LSAT and future JD, etc. to consider things like public policy programs so they didn't end up with mountains of debt and a degree that was hard to actuate into a career.
Also, lol at 100k not being a lot of money
And the second argument about 100k not being a lot of money is mentioned by the author: there are many places (in the US and outside) where 100k will not cover rent and essentials. So yeah, in this way, 100k is not a lot of money, because it will not grant you any form of comfortable life in (Austin, Seattle, most of CA, etc.), which is where a large chunk of tech jobs are located.
I know more people than I can count that are doing just fine in places where rent costs a lot and none of them are making over 100k.
If tech salaries go down, those places will become more affordable.
You start including things like food, savings, a car and associated insurance… you don’t have a whole lot left with $100k/yr.
The people who live on less than that make significant compromises. Either roommates, living far away, long commute times, or make up the cost elsewhere. Or they bought property many many years ago and don’t have significant costs.
It’s not comfortable. Saying otherwise is missing the bigger picture.
AI isn't going to fix your security problems, in fact, it is the cause of security problems you will face in the future because your employees are using it and leaking data that should probably be confidential. I've got clients whose senior management is pushing AI in to their businesses without considering access control and security. I've already seen dozens of really bad practices (how about every employee can read a transcript of every meeting, including management ones where employee performance is discussed on an individual level and you can search for your name?) and that's just within the last year.
Cybersecurity is not full, and it's underfunded. Thank the tech gods that "certifications" (ISO, SOC, etc.) are seen as marketable and are causing funding increases in cybersecurity for some organizations.
Deeply buried, but highly insightful. This is what Cybersecurity startup founders and professionals must pay attention to before they commit to the field.