Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Careers & People

7/8/2017
10:46 AM
Connect Directly
Twitter
RSS
E-Mail
100%
0%

Desperately Seeking Security: 6 Skills Most In Demand

When people say there's a security skills gap, this is what they really mean.
Previous
1 of 7
Next


Image Source: Adobe Stock

Image Source: Adobe Stock

The last several years have seen a slew of reports coming out lamenting the typical enterprise's ability to recruit and retain quality cybersecurity talent.

Earlier this year, ISACA's Cybersecurity Nexus survey found that more than one in four organizations take six months or longer to fill priority cybersecurity positions. Respondents to the survey said that 40% of organizations report receiving fewer than five applications for cybersecurity positions. And if things keep going the way they're already headed, the problem is only going to get worse. According to the 2017 (ISC)2 Global Information Security Workforce Study conducted by Frost & Sullivan, by 2022 there will be a global shortfall of cybersecurity workers of 1.8 million people.

At the same time, the pain is not necessarily a singular problem; a lot of the issue comes down to the fact that there aren't enough candidates with the right combination of specialized skills to fight the security problem at any given moment. It's a moving target that changes day-by-day.

"There’s definitely a talent shortage of quality information security professionals who are capable of solving emerging problems," says Lee Kushner, president of cybersecurity recruiting firm LJ Kushner & Associates. "It’s not a shortage of general skill or average skill, it’s a shortage of skills that can help companies solve their problems."

As the industry starts to look at the problem, it'd best start putting a finer point on the types of skills most in demand rather than fixating on one overarching security deficiency.

"The problem is more granular than 'look at all the open jobs,'" says Mike Viscuso, CTO and co-founder of Carbon Black.

According to the most recent research, the following specialties and skills are the ones that hiring managers are having the hardest time plugging into their teams.

 

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Previous
1 of 7
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RetiredUser
50%
50%
RetiredUser,
User Rank: Ninja
7/31/2017 | 2:24:10 PM
Re: I don't buy young and cheap
To humbly disagree, "old and expensive" is a different skill set than "young and cheap".  Those who define and manage process still need those who can tear that process to the ground and force you to refine and release to stay on top of current trends.  Spend some time on the bug bounty sites and read how much detail goes into some of these bug reports written by the "young" who often take these bounties for the challenge alone; it's a crime how little some of the bounties are, yet still these young and cheap hackers are dancing circles around the over-paid CISOs who sometimes have no place on a security team.
TomC764
100%
0%
TomC764,
User Rank: Apprentice
7/19/2017 | 3:21:52 PM
I don't buy young and cheap
I am old and expensive. The main reason that I get gigs is business knowledge. Youngg and cheap are focused on buying more toys. My focus is on cost effective solutions that don't kill the profit of various business. I mostly doo risk assessments and rdidk management not CISSP type work. Those people are young aand cheap AND easily replaceable.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
7/14/2017 | 3:03:10 PM
Forgetting a couple
A couple items were missing from the slideshow.

"Young" and "cheap".

That's the real "talent shortage" in InfoSec and the tech sector right there, IMHO, based upon what I'm seeing.
mulhearnf
67%
33%
mulhearnf,
User Rank: Apprentice
7/13/2017 | 5:36:42 AM
The lack of skilled people, and the retention thereof.
As long as executives, continue to spend more money on coffee machines, than on security, the problem will continue, and get worse.

To get skilled people, you need to pay them enough, and treat them well.
afarngalo221
100%
0%
afarngalo221,
User Rank: Apprentice
7/11/2017 | 1:59:10 PM
Very good article
This is a very good article and it does highlight the overarching issues with the skills and experiences in the cyber security space.

 

As a recruiter for Navy Federal Credit Union, check out www.navyfederal.org.

 

Thanks,

Agatha
The Mainframe Is Seeing a Resurgence. Is Security Keeping Pace?
Ray Overby, Co-Founder & President at Key Resources, Inc.,  8/15/2019
The Flaw in Vulnerability Management: It's Time to Get Real
Jim Souders, Chief Executive Officer at Adaptiva,  8/15/2019
Tough Love: Debunking Myths about DevOps & Security
Jeff Williams, CTO, Contrast Security,  8/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-5638
PUBLISHED: 2019-08-21
Rapid7 Nexpose versions 6.5.50 and prior suffer from insufficient session expiration when an administrator performs a security relevant edit on an existing, logged on user. For example, if a user's password is changed by an administrator due to an otherwise unrelated credential leak, that user accou...
CVE-2019-6177
PUBLISHED: 2019-08-21
A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log files to be written to non-standard locations, potentially leading to privilege escalation. Lenovo ended support for Lenovo Solution Center and recommended that customers migrate to Le...
CVE-2019-10687
PUBLISHED: 2019-08-21
KBPublisher 6.0.2.1 has SQL Injection via the admin/index.php?module=report entry_id[0] parameter, the admin/index.php?module=log id parameter, or an index.php?View=print&id[]= request.
CVE-2019-11601
PUBLISHED: 2019-08-21
A directory traversal vulnerability in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to write or delete files at any location.
CVE-2019-11602
PUBLISHED: 2019-08-21
Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to gather information about the file system structure.