News

4/26/2017
10:19 AM
Dawn Kawamoto
Dawn Kawamoto
Slideshows
50%
50%

6 Steps to Find Your Next Dozen Cloud Security Experts

There's stiff competition for cloud security experts, but finding yours may actually be easier than you think.
Previous
1 of 7
Next

Image Source: Robert Half 2016

Image Source: Robert Half 2016

With roughly 1 million-plus IT security jobs out there in the market, approximately 5% of them are cloud security positions, estimates Eddie Borrero, chief information security officer and enterprise information security and head of global customer support for recruiting firm Robert Half International.

And hiring for these cloud security positions is tough, especially when you consider the steep shortage of cybersecurity workers overall, Borrero notes. For example, cybersecurity training organization ISC2 forecasts a global shortfall of 1.8 million cybersecurity professionals by 2022.

"Traditional security needs to do an uptick in skills, as companies move their data and technologies to the cloud," he says.

In a 2016 Robert Half survey of UK CIOs, 51% of respondents listed cloud security as the No. 1 technical security skill that is in the most demand, yet 32% of survey respondents noted it was the most challenging to fill.

But as CISOs and hiring managers feel the pressure to find what they believe to be a need for a team of cloud security experts, Borrero offers a different perspective to address the problem and potentially create an easier workaround. Here are six actions he recommends.

 

Dawn Kawamoto is an Associate Editor for Dark Reading, where she covers cybersecurity news and trends. She is an award-winning journalist who has written and edited technology, management, leadership, career, finance, and innovation stories for such publications as CNET's ... View Full Bio

Previous
1 of 7
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
JeffM108
100%
0%
JeffM108,
User Rank: Apprentice
4/27/2017 | 10:07:44 AM
Editorial complaint
Does everything here really need to require six or more clicks to read? I've come to several posts here lately that require me to click to the next page, only to find two or three short paragraphs on each one. At some point, the benefit from the extra ad impressions you get are going to fall off. I'm already becoming reluctant to bite at a good headline from your site because I know I'll be needlessly clicking through to read the whole article. Some content lends itself to a multi-page format. But the deciding factor should be readability for users, not...whatever you're doing here.
RIP, 'IT Security'
Kevin Kurzawa, Senior Information Security Auditor,  11/13/2018
Understanding Evil Twin AP Attacks and How to Prevent Them
Ryan Orsi, Director of Product Management for Wi-Fi at WatchGuard Technologies,  11/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
Online Malware and Threats: A Profile of Today's Security Posture
Online Malware and Threats: A Profile of Today's Security Posture
This report offers insight on how security professionals plan to invest in cybersecurity, and how they are prioritizing their resources. Find out what your peers have planned today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-17906
PUBLISHED: 2018-11-19
Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within third party software may allow an attacker to compromise a component of the system.
CVE-2018-9209
PUBLISHED: 2018-11-19
Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2
CVE-2018-9207
PUBLISHED: 2018-11-19
Arbitrary file upload in jQuery Upload File <= 4.0.2
CVE-2018-15759
PUBLISHED: 2018-11-19
Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials. A remote unauthenticated malicious user may make many requests to the service broker with different credentials, allowing them to infer valid credentials and gain access to perfo...
CVE-2018-15761
PUBLISHED: 2018-11-19
Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a consent page to gain a token with arbitrary scopes that escalates their privileges...