By Katherine TeitlerAnyone who has spent any time in the information security/cybersecurity field is aware of the “talent gap,” meaning, there is greater demand for security practitioners than there are practitioners, themselves, to fill those roles. Various media outlets have claimed there will be staggering numbers of unfilled jobs by 20XX—often in the millions—leading to the type of fear, uncertainty, and doubt that plagues our profession on a regular basis. In its State of Cybersecurity Survey 2018, ISACA aims to level set and temper some of the industry FUD.It’s important to note that when referring to the state of the profession, the terms “talent gap” and “skills shortage” are often used interchangeably. However, there is (or should be) a distinction between not having enough people to fill open roles and not having enough appropriately skilled staff currently employed or in the pipeline of interviewing candidates. Per the ISACA report, both issues are problematic: the industry needs more people, and it needs people who possess appropriate skill sets to handle today’s cybersecurity challenges. According to the survey, 59% of enterprises report that they have open/unfilled security positions.What’s more, 30% of survey respondents report that “fewer than 25 percent of applicants are qualified” to fill open positions, and only 31% said that “between 25 to 50 percent of applicants are sufficiently qualified.” Though these data look discouraging on paper, 2018 showed slight improvement over 2017 in terms of enterprises receiving applications from what they consider to be qualified candidates.Unfortunately, these is no measure of “qualified” defined in this report, and more generally speaking, finding “the right skills” for a position can be somewhat subjective. Recruiters and HR professionals may judge a candidate’s or employee’s qualifications by the certifications that person has achieved. Hiring managers, on the contrary, are more likely to evaluate the types of projects and technologies with which an individual has hands-on experience. Peer-level coworkers, for their part, may have yet a different view of what’s required to add to the team’s capabilities.Still another angle presented by the ISACA report is that it’s possible organizations have shifted expectations over time, based either on what they think job seekers can bring to the table or what those people are expected to do once they land a role on the security team. Some of the shift could be attributed to the fact that machine learning and automation are becoming more integral parts of security operations, altering employee requirements.{tweetme}Interesting read on cybersecurity staffing. The talent gap is a real challenge for the industry. #InfoSecInsider #infosec{/tweetme}
Security Staff Acquisition & Development, Leadership
ISACA Workforce Development Report Highlights Need for More & More Qualified Security Employees
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
