Comments
InformationWeek Radio: State of Information Security Salaries & Careers
Newest First  |  Oldest First  |  Threaded View
Joyce23501
50%
50%
Joyce23501,
User Rank: Apprentice
5/20/2014 | 10:00:51 AM
salaries are likely to rise
I worked in my company's IT Security department for many years.  The required skills are primarily those of network engineering: knowledge of Radius (authentication) servers,  enterprise firewall devices, IP routing, enterprise VPN servers, and intrusion detection devices.    These are all highly specialized areas that are very difficult to learn. 

By comparison, Web development skills are (by comparison) relatively easy to learn.  There is a huge number of people who know how to develop Websites.  This is why salaries for Web development are likely to decline, while salaries for security specialists are likely to keep rising.
Lorna Garey
50%
50%
Lorna Garey,
User Rank: Ninja
5/16/2014 | 1:19:03 PM
Re: salary bubble?
Is automation the wild card? If the really smart security people build tools that are usable by less skilled people to test for 75% +/- of potential problems, then you free skilled manhours in the same way that hiring LPNs and CNAs fre up RNs for more skilled work. 
Robert McDougal
50%
50%
Robert McDougal,
User Rank: Ninja
5/16/2014 | 11:59:56 AM
Re: salary bubble?
I believe the talent pool has remained small due to the skills required for information security.  For example, web application penetration testing requires in depth knowledge of HTML, HTTP, SQL, XML, LDAP, IMAP, SMTP, shell coding, and the knowledge of how to apply it.  Those skills span many different IT disciplines and it takes someone dedicated to be able to learn it.  Unlike other areas of IT you cannot give someone a step by step tutorial on information security, every situation is unique.

I don't see the required skillset of a qualified information security professional becomming easy to obtain in the near future.  As a result, I don't see a large talent pool either.
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
5/16/2014 | 9:10:09 AM
salary bubble?
Interesting question. The infosec community has enjoyed healthy salaries due to high demand and a smaller talent pool. But if indeed the search widens to other more available skillsets, could that burst the high-dollar salary bubble?


White House Cybersecurity Strategy at a Crossroads
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/17/2018
Lessons from My Strange Journey into InfoSec
Lysa Myers, Security Researcher, ESET,  7/12/2018
What's Cooking With Caleb Sima
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/12/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-14394
PUBLISHED: 2018-07-19
libavformat/movenc.c in FFmpeg before 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with a user crafted Waveform audio file.
CVE-2018-14395
PUBLISHED: 2018-07-19
libavformat/movenc.c in FFmpeg before 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with a user crafted audio file when converting to the MOV audio format.
CVE-2018-14399
PUBLISHED: 2018-07-19
libs\classes\attachment.class.php in PHPCMS 9.6.0 allows remote attackers to upload and execute arbitrary PHP code via a .txt?.php#.jpg URI in the SRC attribute of an IMG element within info[content] JSON data to the index.php?m=member&c=index&a=register URI.
CVE-2018-14401
PUBLISHED: 2018-07-19
CopyData in AxmlParser.c in AXML Parser through 2018-01-04 has an out-of-bounds read.
CVE-2018-14402
PUBLISHED: 2018-07-19
axmldec 1.2.0 has an out-of-bounds write in the jitana::axml_parser::parse_start_namespace function in lib/jitana/util/axml_parser.cpp.