Cybersecurity Recruiting: Still Broken

October 23, 2024

Continuing with the cybersecurity "recruiting" theme, another entry in the neverending parade of thousands applying for every CISO opening out there. I say "recruiting" because it's doubtful any one prospective employer can legitimately process 2750 applicants to a single role, especially when the firm itself barely has 1500 employees.

Even considering the fact that at least 40% are unqualified based on current job level alone (entry level, manager, director), that still leaves more candidates than employees. Maybe they can give each employee a resume to review.

Once again, I ask - I implore - someone to explain why anyone at entry or junior level would apply to an actual CISO role. What do they expect, that by some fluke they luck out and get it, booking the title on their CV to then monkeybranch from to the next one before being fired or after the first breach, whichever comes first?

You don't see junior accountants either calling themselves CFOs or applying to corporate roles with that title, do you? Your IT helpdesk analyst hoping to land their first CIO gig as the next role, eh?

Then why is CISO the one "C-suite" title prone to this nonsense?

Is it the fact that we still don't have a consistent model for measuring CISO performance and thus a method for hiring true strategic leaders instead of glorified technology managers? Or is it the fact that despite now decades of trying to convince actual business leaders that "we are your partners" and that "CISOs belong in the C-suite," we've only managed to convince ourselves of our supposed "value?"

Maybe we've just been drinking our own kool-aid this entire time? Maybe the cyber hiring slowdown isn't just a reflection of the overall tech industry trends, but a matter of our long-grazing, extra-thick chickens finally coming home to roost?

You know, the ones that look like fat and happy unicorns, with platinum beaks and no sense of business value?

Looks like it'll be a bumpy ride out there for a while.

hashtag#cybersecurity hashtag#hiring hashtag#workforce hashtag#leadership