Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Analytics

Security Skills Shortage Creates Opportunities For Enterprises, Professionals

Security pros look to cash in on heavy demand for skills; enterprises need to cast a wider net, experts say

PHILADELPHIA, PENN. -- (ISC)2 World Congress 2012 and ASIS International 2012 -- A growing shortage in security staffing and skills is creating a seller's market for security professionals -- and could drive new thinking in hiring, experts say.

Here at the Career Pavilion at the co-resident annual conferences of two of the world's largest security professionals' associations, job hunters are finding a target-rich environment for workers with advanced skills. The industry will need to add nearly 2 million jobs during the next three years in order to keep up with demand, according to industry figures.

The growing gap between supply and demand is creating problems for many enterprises and may cause some to cast a wider net in search of talent, speakers at the event say.

"As more advanced technology is deployed -- technologies like cloud and bring-your-own device -- there's a demand not only for more skills, but for different kinds of skills," says Hord Tipton, executive director of (ISC)2. "Once you get your arms around one thing, there's something else you need to be ready for."

"There aren't enough good people out there," says Brent Conran, CSO of McAfee, who previously served as CIO for the U.S. House of Representatives. "In a lot of cases, you're in a position where you have to take a kid out of college and get them ramped up very quickly."

In its 2011 (ISC)2 Global Information Security Workforce Study, Frost & Sullivan researchers projected that there will be 4.24 million security professionals in the global workforce by 2015. The current figure is approximately 2.6 million.

The "skills gap" is being driven by a variety of factors, including increasing volume and sophistication of attacks, greater compliance requirements, and a shortage of professional training, experts say. While the global security workforce has grown by an estimated more than 600,000 in the past two years, there still are more positions open than there are trained people to fill them, experts say.

Many companies are still struggling with how to hire security professionals, Tipton observes. "It often falls to human resources people, but they don't always know what questions to ask," he observes. "They need to understand what tools that the candidate has used, what specialized areas they have experience in, and what certifications they have. Hiring security people is not always an easy process."

Other speakers at the conference took that idea one step further.

"The problem is not that we have a shortage of security people -- the problem is that the people who do the hiring are too binary in their thinking," says Winn Schwartau, chairman of MAD Security, who gave a presentation on security hiring practices at the conference on Monday.

Schwartau suggested that companies are too reliant on finding employees who have degrees and certifications, fit a certain age bracket, or even a certain type of hair and dress code.

"All people are not created equal," Schwartau. "Security is a creative pursuit, whether it's on the offensive side or on the defensive side, and it's not always done by people who work 9 to 5. It's not about fitting in, but the CEOs and the lawyers and the HR people make it that way."

For now, however, organizations are looking for ways to differentiate between candidates who know their craft and those who don't -- and certification is one way to do that, Tipton observes. Companies requiring a certification such as CISSP are up 34 percent this year, he says, and the average CISSP-certified employee makes an average of $97,000 a year, about $20,000 more than noncertified professionals.

Have a comment on this story? Please click "Add a Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
SDiver
50%
50%
SDiver,
User Rank: Strategist
12/17/2012 | 5:36:58 PM
re: Security Skills Shortage Creates Opportunities For Enterprises, Professionals
Forgive me but I have my doubts about the accuracy of this article.- I also realize that I may be the one who is wrong and the author (Tim Wilson) may be correct.

I am looking to change security careers and know other people who are as well but many of us have been rejected by potential clients for some of the most ridiculous reasons.- I'm willing to relocate anywhere in the US at my own expense and potential clients are still afraid to talk to me, thinking that I may not be sincere.

I realize that my information is anecdotal so it should be taken with a grain of salt but there are good people out there who are looking.
toonces
50%
50%
toonces,
User Rank: Apprentice
9/17/2012 | 10:16:29 PM
re: Security Skills Shortage Creates Opportunities For Enterprises, Professionals
I guess HR doesn't have any real criteria to draw on when choosing security staff but, really: CISSP? They may as well scout for people who've memorized all of the answers in Trivial Pursuit. IMO.

P.S. Yes, guys, I'm just jealous because the only cert I hold is OPSA 2.0 - from ISECOM, not Texas A&M :-D
Sodinokibi Ransomware: Where Attackers' Money Goes
Kelly Sheridan, Staff Editor, Dark Reading,  10/15/2019
Data Privacy Protections for the Most Vulnerable -- Children
Dimitri Sirota, Founder & CEO of BigID,  10/17/2019
State of SMB Insecurity by the Numbers
Ericka Chickowski, Contributing Writer,  10/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-16966
PUBLISHED: 2019-10-21
An issue was discovered in Contactmanager 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 for FreePBX 14.0.10.3. In the Contactmanager class (html\admin\modules\contactmanager\Contactmanager.class.php), an unsanitized group variable coming from the URL is reflected in HTML on...
CVE-2019-9491
PUBLISHED: 2019-10-21
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed.
CVE-2019-16964
PUBLISHED: 2019-10-21
app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated attackers (with at least the permission call_center_queue_add or call_center_queue_edit) to execute any comma...
CVE-2019-16965
PUBLISHED: 2019-10-21
resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute any commands on the host as www-data.
CVE-2019-18203
PUBLISHED: 2019-10-21
On the RICOH MP 501 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn and KeyDisplay parameter to /web/entry/en/address/adrsSetUserWizard.cgi.