{"id":3550,"date":"2024-05-14T09:00:00","date_gmt":"2024-05-14T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/there-is-no-cyber-labor-shortage"},"modified":"2024-05-14T09:00:00","modified_gmt":"2024-05-14T14:00:00","slug":"there-is-no-cyber-labor-shortage","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/14\/there-is-no-cyber-labor-shortage\/","title":{"rendered":"There Is No Cyber Labor Shortage"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt335a2d57784210db\/664367974f89291d778d64ad\/Hiring%281800%29_Bryan_Sikora_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/there-is-no-cyber-labor-shortage.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/there-is-no-cyber-labor-shortage.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The unfortunate truth is, if you&#8217;re looking for an entry-level position in the cybersecurity field, there aren&#8217;t many on-ramps. The wide-ranging <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-careers\/keys-to-hiring-cybersecurity-pros-when-certification-can-t-help\" rel=\"noopener\">security certification<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> bodies and training organizations that dominate the industry have convinced many \u2014 maybe even most \u2014 cybersecurity leaders that &#8220;number of certifications&#8221; or &#8220;years of formal training&#8221; are the only metrics by which potential job candidates should be judged. What&#8217;s more, the emergence of both undergraduate and graduate-level <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-careers\/the-wild-west-of-security-post-secondary-education\" rel=\"noopener\">cybersecurity degrees<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> has placed another arbitrary barrier between otherwise qualified individuals and the jobs they want. Don&#8217;t have the right degree? Too many organizations will tell you not to bother applying.&nbsp;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Unfortunately, the meaningless requirements and barriers we place in front of candidates are only likely to get more burdensome with time. Want an entry-level security operations center (SOC) position? Please arrive with a bachelor&#8217;s degree in cybersecurity, Security+ (CISSP preferred) training, and $30,000 worth of SANS courses. Oh, and be prepared to work third shift for a while.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yes, those credentials have value, but treating them as mandatory artificially raises the barrier to entry for new security professionals. Hiring managers often are hesitant to hire candidates perceived as undercredentialed when they believe there must be a &#8220;perfect&#8221; candidate out there somewhere. But the truth is, a perfect candidate probably isn&#8217;t interested in a third-shift SOC position \u2014 which means hiring managers need to reevaluate where they look for new employees and which qualifications matter most.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Solving the Shortage by Broadening the Candidate Pool\">Solving the Shortage by Broadening the Candidate Pool<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It isn&#8217;t just organizations themselves that fall into this trap \u2014 recruiters do, too. As effective as recruiters are at gathering candidates, they usually aren&#8217;t cybersecurity experts \u2014 which means they aren&#8217;t always capable of discerning between <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/5-failsafe-techniques-for-interviewing-security-candidates\" rel=\"noopener\">cybersecurity candidates<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> ready to deliver value and those who are simply good at marketing themselves. Understandably, they look for shorthand ways to help them narrow down candidates: Degrees, certifications, training, and other measurable factors obviously are attractive. They become de facto indicators of value, and their absence is treated as an indicator that a candidate is unqualified \u2014 or at least not a fit for a technical role.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The result is self-defeating. By narrowing down candidate pools based on a small number of arbitrary qualifications, organizations and recruiters end up self-selecting candidates who are good at acquiring credentials and taking tests \u2014 neither of which necessarily correlate to long-term success in the cybersecurity field. Prioritizing this small pool of candidates also means overlooking the many, many candidates with analytical potential, technical promise, and professional dedication who may not have gotten the right degree or attended the right training course. By tapping into these candidates, organizations will find that the &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/addressing-cybersecurity-talent-shortage-its-impact-on-cisos\" rel=\"noopener\">labor shortage<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8221; that has received so much attention isn&#8217;t such a hard problem to solve, after all.&nbsp;&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Solving the Problem Requires Adopting a New Approach&nbsp;\">Solving the Problem Requires Adopting a New Approach&nbsp;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Of course, recruiters and hiring managers aren&#8217;t the ones who suffer when they overlook potentially valuable candidates. Yes, the companies struggling to fill critical positions will continue to feel the impact of the&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/the-cybersecurity-talent-shortage-is-a-myth\" rel=\"noopener\">so-called labor shortage<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, but perhaps even worse is the fact that it cuts off a path to prosperity for countless individuals who fail to meet a list of arbitrary qualifications. Any security organization worth its salt should have a strong training program in place, and entry-level positions should be treated as just that. Candidates with the right traits and skills are qualified \u2014 whatever their r\u00e9sum\u00e9 may say. Helping them make the most of those skills is up to the organization.&nbsp;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This is why the White House&#8217;s&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.whitehouse.gov\/oncd\/briefing-room\/2023\/11\/03\/answering-the-call-to-build-the-nations-cyber-workforce\/\" rel=\"noopener\">cyber workforce workshops<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;\u2014 well-intentioned though they may be \u2014 are misplaced. Fueled by a limited understanding of the true indicators of success for a cybersecurity career and an inability (or unwillingness) to tackle the root cause of the labor shortage, these workshops have only served to exacerbate the problem. The workshops invite schools and certification bodies to brainstorm ways to improve access to education and training \u2014 without stopping to consider that an overreliance on education and training benchmarks is a core part of the issue at hand. Education and training programs are great, but they scale poorly and continuing to treat them as the gold standard only serves to gatekeep opportunities in our industry. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/federalnewsnetwork.com\/hiring-retention\/2024\/04\/wh-aims-to-transition-nearly-100k-federal-it-jobs-to-skills-based-hiring\/\" rel=\"noopener\">The recent announcement from the White House<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;that candidates for IT positions should be evaluated based on skills rather than degrees is a step in the right direction, but it doesn&#8217;t go far enough to encourage emerging talent.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Where, then, can organizations find qualified individuals to fill their SOCs and run their vulnerability management programs? The answer is simple: They can be found in all walks of life, and from virtually every background. They can be found graduating high school, unconvinced by the merits of higher education and ready and eager to join the workforce. They can be found in fields ranging from closely related IT roles to those a bit further afield in biotech, retail, physical security, and other industries. They can be found in virtually every geographic region and in every imaginable demographic combination. Hiring managers simply require the willingness to organize their teams with the space and time to develop emerging talent. Countless other industries already do this \u2014 and (despite what many security professionals like to think) cybersecurity isn&#8217;t exceptional. There&#8217;s nothing unique about this industry that prevents it from approaching talent acquisition the same way.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Cybersecurity Labor Shortage Is a Lie\">The Cybersecurity Labor Shortage Is a Lie<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">None of this is meant to imply that succeeding as a security analyst is easy. It isn&#8217;t. It takes a strong analytic mind, a willingness to explore and grow, and a level of comfort with new and evolving technology. Perhaps most importantly, it requires a hiring manager willing to invest in a potentially unproven candidate. But the pool of individuals with the characteristics needed to succeed is far larger than many organizations and recruiters often believe \u2014 they just need to look in the right places. The sooner the industry recognizes how artificial many of the most common barriers to entry are, the sooner security organizations can realize that the so-called &#8220;labor shortage&#8221; is a lie \u2014 one that&#8217;s been told for far too long.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/there-is-no-cyber-labor-shortage\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY The unfortunate truth is, if you&#8217;re looking for an<\/p>\n","protected":false},"author":12,"featured_media":3551,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3550","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/there-is-no-cyber-labor-shortage.jpg?fit=1818%2C1057&ssl=1",1818,1057,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/there-is-no-cyber-labor-shortage.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/there-is-no-cyber-labor-shortage.jpg?fit=300%2C174&ssl=1",300,174,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/there-is-no-cyber-labor-shortage.jpg?fit=640%2C373&ssl=1",640,373,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/there-is-no-cyber-labor-shortage.jpg?fit=640%2C372&ssl=1",640,372,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/there-is-no-cyber-labor-shortage.jpg?fit=1536%2C893&ssl=1",1536,893,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/there-is-no-cyber-labor-shortage.jpg?fit=1818%2C1057&ssl=1",1818,1057,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/there-is-no-cyber-labor-shortage.jpg?fit=1024%2C595&ssl=1",1024,595,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/there-is-no-cyber-labor-shortage.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/there-is-no-cyber-labor-shortage.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/there-is-no-cyber-labor-shortage.jpg?fit=1818%2C1057&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3550","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3550"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3550\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3551"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3550"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3550"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3550"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}