Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Careers & People

11/4/2016
07:30 AM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

How Businesses, Employees Can Navigate The Security Hiring Process

At Black Hat Europe 2016, security experts weigh in on how companies can build strong security teams, and how employees can educate themselves to meet business needs.

Businesses face complex and dangerous threats in the evolving world of cybersecurity, but one of their greatest obstacles is hiring the right talent to fight them.

At Black Hat Europe 2016, experts discussed how organizations can manage the skills gap through best hiring practices and education. On the other side of the interview chair, security pros can be more effective by learning industry-specific skills and how to talk with the business.

A 2016 survey of Black Hat USA attendees revealed organizations acutely feel the security skills gap. When 250 respondents were asked why their security efforts fail, 37% cited "a shortage of qualified people and skills," and noted a lack in staffing, budget, and training.

More than two-thirds (67%) of survey respondents felt they did not have enough training and skills necessary to perform all of the tasks required of them. Nearly 75% felt they didn't have enough staff to defend their organizations against modern threats.

There are a few ways security pros can effectively improve their knowledge, skills, and capabilities, said Bob Lewis of the Information Systems Security Association (ISSA).

An annual report from ISSA and the Enterprise Strategy Group (ESG) discovered the most popular options for security education included attending specific security training courses (58%), participating in professional organizations (53%), and on-the-job mentoring from a more experienced security pro (37%).

Education may be part of the solution, but it's also part of the problem. Trained security professionals are in higher demand, Lewis noted, and often tough for businesses to keep.

"The average lifespan of a CISO is two to four years," he explained. "There's a lot of churn, it's essentially a seller's market," and it's easy for skilled pros to find lucrative job offers. Nearly half (46%) of ISSA/ESG survey respondents were contacted by recruiters at least once a week.

Current and aspiring security professionals also struggle to establish career paths in the evolving industry, Lewis continued. Factors including the diversity among focus areas, lack of well-defined career road maps, and rapid industry changes which mean cybersecurity pros are not only undertrained, but unsure about what they need to learn.

So which skills are most critical for security pros navigating the job market?

"We need someone to explain technology in business terms," said Floris van den Dool, Accenture's managing director for security services in Europe, Africa, and Latin America. "Can we make our technical issues, our technical findings relevant to the business? That's what I'm looking for when I recruit people."

Van den Dool also noted a growth in demand for industry-specific technical skills. For example, someone applying to a cybersecurity position at a bank or telco network should possess skills relevant to their desired industry.

"There's a big shortage of skills like that," he said. "I think that's where the next wave of security will take us." 

Owanate Bestman, information security contract consultant at Barclay Simpson, cautioned against overloading your resume with too many certifications. While some, like CISSP, withstand the fluctuation in security trends, certifications don't convey excellence in softer skills that security pros also need.

"Communication, curiosity, etc. don't come with a certification, they come with the individual," he said.

Both experts stressed curiosity and experience as important factors for current and aspiring security pros. Applicants should be able to discuss their project experience and how their work influenced the business.

"The main thing in security is you have to be curious, you don't have to be afraid of technology, and you have to understand the business you want to secure," said van den Dool. "Learn, have technical curiosity, and think 'What can do wrong and how can I prevent it?'"

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Unreasonable Security Best Practices vs. Good Risk Management
Jack Freund, Director, Risk Science at RiskLens,  11/13/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19012
PUBLISHED: 2019-11-17
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or ...
CVE-2019-19022
PUBLISHED: 2019-11-17
iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which might allow remote attackers to obtain sensitive information, as demonstrated by searching for the NoSyncSearchHistory string in .plist files within public Git r...
CVE-2019-19035
PUBLISHED: 2019-11-17
jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSections and process_SOFn in jpgfile.c. The attack vector is: Open a specially crafted JPEG file.
CVE-2019-19011
PUBLISHED: 2019-11-17
MiniUPnP ngiflib 0.4 has a NULL pointer dereference in GifIndexToTrueColor in ngiflib.c via a file that lacks a palette.
CVE-2019-19010
PUBLISHED: 2019-11-16
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.