Startups

5 ways to attract top cybersecurity talent in a tight labor market

Comment

Image of a man looking through a magnifying glass at small statuettes to represent the hiring process.
Image Credits: Ivan balvan (opens in a new window) / Getty Images

George Gerchow

Contributor
George Gerchow is the chief security officer at Sumo Logic.

He graduated from a college I’d never heard of. He earned a master’s degree from Villanova, but it was in human resources development. He spent 16 years in the Marine Corps in various military and civilian roles, but none directly involved cybersecurity. His most recent job was as a project manager at a construction firm.

When I asked other senior executives at my company, Sumo Logic, to interview him for a security operations center (SOC) manager position, I initially was met with shoulder shrugs and eye rolls. “Why am I talking to this guy?” went the typical response. “He doesn’t seem a fit at all.”

What they didn’t know was that in my earlier interview with Roland Palmer, I concluded within a half-hour that the job was his. I was blown away by his intense desire to take on hard assignments and win. This ex-Marine had faced daunting challenges, such as planning communications operations in Afghanistan and helping evacuate hundreds of people from an area in Japan contaminated by a nuclear spill. Managing a SOC can be grueling, a constant barrage of crises and incident tickets, but Roland, despite the lack of security work on his resume, seemed born for it.

I told my colleagues, “I’d like for you to talk to him, but if you don’t, I’m hiring him anyway.” They ended up falling in love with Roland, too. He got the job.

That was three years ago. In 2020, Roland was promoted to senior SOC manager. The same year, he won our company’s highest award for employee achievement.

I’m telling this story because I think it says something about what companies and their cybersecurity organizations need to be doing to power over one of their highest hurdles: hiring great talent in an absurdly tight labor market.

“The cybersecurity skills crisis continues on a downward, multi-year trend of bad to worse and has impacted more than half (57%) of organizations,” said a recent report by the Information Systems Security Association and analyst firm Enterprise Strategy Group. There are now 3.5 million unfilled cybersecurity jobs – enough to fill 50 NFL stadiums – according to Cybersecurity Ventures.

At a time when ransomware attacks, data breaches and supply chain intrusions are skyrocketing — the volume of cyber intrusion activity globally soared 125% in the first half of 2021 compared with the same period last year, according to an Accenture study – what is a company supposed to do?

Today’s chief security officer (CSO) needs to start by not only accepting but embracing the talent hunt as a core part of the job. (I spend at least 10% of my week on it, often more.) Then they need to tear up old assumptions about where good security professionals come from and be open-minded and creative in their search.

Five pieces of advice:

Beware the warm body syndrome

Let’s be honest: It’s tempting to just grab anyone you can, not only because cybersecurity jobs need to be filled but due to additional pressures such as protecting headcount before any open positions are cut in a layoff after a bad quarter.

Don’t do it. Cybersecurity is too important to risk having team members who can’t (no pun intended) hack it. Wait to find the best people, no matter what.

Degrees, shmegrees

Graduating from a prestigious institution is a feather in someone’s cap, and I don’t at all mean to discount it, but it’s down my list of prerequisites. Drive, ambition, calm under pressure, team spirit and situational awareness are far more important.

In my first week at Sumo, in 2015, I attended an introductory meeting with several fellow executives who had graduated from schools like Stanford, UC-Berkeley and MIT. When it was my turn to share more about myself, I told everyone around the conference table about my alma mater: Regis University, a small Jesuit university in Denver.

I wasn’t embarrassed; I was proud. And in hiring others, I’ve maintained a philosophy of valuing skills and personal qualities over college backgrounds.

Resilience matters as much as or more than experience

Working in a cybersecurity organization is one of the world’s most stressful jobs, with burnout a constant concern. According to a report by the Chartered Institute of Information Security, 51% of security pros are kept up at night by work stress.

So while past security experience is a huge plus, an ability to handle or even relish the pressure matters as much. I always tell job candidates, “This job is going to be a grind, it’s going to be tough. But the mission is vital.” Some people’s eyes light up when they hear this – that’s who you want, regardless of what’s on their resume.

Exploit nontraditional sources

Roland Palmer is one example of how the best cybersecurity pros don’t necessarily come from the cybersecurity world. But there are many others.

For example, I’ve found software development organizations to be a fertile breeding ground for security talent. Agile development methods such as DevOps are taking development, operations and security out of their traditional silos. Everyone is now expected to work together to foster a fast, efficient, secure software pipeline.

This offers new opportunities for developers to stretch out into the security specialty and help drive the company’s software lifecycle in a different way while expanding their own horizons.

As I often tell developers, “If you join our team, you get to work on infrastructure in the cloud, you get to work on applications, and how APIs and microservices play together. And along the way, you’re developing a higher-level understanding of the software pipeline and helping drive a security-baked-in culture. And if you decide to return to engineering in the future, you’re better prepared to do so with broader experience and the security mindset that has become so crucial.”

I also look at folks with financial operations backgrounds because of their regulatory compliance orientation and attention to detail that is essential to security work.

Seek empathy

When I got started in security, I sensed other employees would hide from me when they saw me walking down the hall. They viewed me as the bad guy arriving to rap their knuckles over some security issue.

In today’s more collaborative culture, that no longer flies. Security pros need to be seen as trusted teammates to feel comfortable around. Therefore, a collaborative, empathetic personality is a trait I always look for in prospective hires.

Whether they like it or not, hiring top-notch people has become one of the most important and challenging facets of a CSO’s job, and that won’t change anytime soon. But with determination and some out-of-the-box thinking, they can answer the challenge.

More TechCrunch

Featured Article

Bangladeshi police agents accused of selling citizens’ personal information on Telegram

Two senior police officials in Bangladesh are accused of collecting and selling citizens’ personal information to criminals on Telegram.

4 hours ago
Bangladeshi police agents accused of selling citizens’ personal information on Telegram

Carta, a once-high-flying Silicon Valley startup that loudly backed away from one of its businesses earlier this year, is working on a secondary sale that would value the company at…

Carta’s valuation to be cut by $6.5 billion in upcoming secondary sale

Boeing’s Starliner spacecraft has successfully delivered two astronauts to the International Space Station, a key milestone in the aerospace giant’s quest to certify the capsule for regular crewed missions.  Starliner…

Boeing’s Starliner overcomes leaks and engine trouble to dock with ‘the big city in the sky’

Rivian needs to sell its new revamped vehicles at a profit in order to sustain itself long enough to get to the cheaper mass market R2 SUV on the road.

Rivian’s path to survival is now remarkably clear

Featured Article

What to expect from WWDC 2024: iOS 18, macOS 15 and so much AI

Apple is hoping to make WWDC 2024 memorable as it finally spells out its generative AI plans.

10 hours ago
What to expect from WWDC 2024: iOS 18, macOS 15 and so much AI

In a research note, HSBC estimates that the Indian edtech giant Byju’s, once valued at $22 billion, is now worth nothing.

HSBC believes that $22 billion Byju’s is now worth zero

As WWDC 2024 nears, all sorts of rumors and leaks have emerged about what iOS 18 and its AI-powered apps and features have in store.

What to expect from Apple’s AI-powered iOS 18 at WWDC 2024

Apple’s annual list of what it considers the best and most innovative software available on its platform is turning its attention to the little guy.

Apple’s Design Awards highlight indies and startups

Meta launched its Meta Verified program today along with other features, such as the ability to call large businesses and custom messages.

Meta rolls out Meta Verified for WhatsApp Business users in Brazil, India, Indonesia and Colombia

Last year, during the Q3 2023 earnings call, Mark Zuckerberg talked about leveraging AI to have business accounts respond to customers for purchase and support queries. Today, Meta announced AI-powered…

Meta adds AI-powered features to WhatsApp Business app

TikTok is testing streaks that are similar to Snapchat’s in order to boost engagement, including how long people stay on the app.

TikTok is testing Snapchat-like streaks

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Your usual…

Inside Fisker’s collapse and robotaxis come to more US cities

New York-based Revel has made a lot of pivots since initially launching in 2018 as a dockless e-moped sharing service. The BlackRock-backed startup briefly stepped into the e-bike subscription business.…

Revel to lay off 1,000 staff ride-hail drivers, saying they’d rather be contractors anyway

Google says apps offering AI features will have to prevent the generation of restricted content.

Google Play cracks down on AI apps after circulation of apps for making deepfake nudes

The British retailers association also takes aim at Amazon’s “Buy Box,” claiming that Amazon manipulated which retailers were selected for the coveted placement.

UK retailers file a £1.1B collective action against Amazon over claims of data misuse

Featured Article

Rivian overhauled the R1S and R1T to entice new buyers ahead of cheaper R2 launch

Rivian has changed 600 parts on its R1S SUV and R1T pickup truck in a bid to drive down manufacturing costs, while improving performance of its flagship vehicles.  The end goal, which will play out over the coming year, is an existential one. Rivian lost about $38,784 on every vehicle…

14 hours ago
Rivian overhauled the R1S and R1T to entice new buyers ahead of cheaper R2 launch

Twitch has come up with a solution for the ongoing copyright issues that DJs encounter on the platform. The company announced Thursday a new program that enables DJs to stream…

Twitch DJs will now have to pay music labels to play songs in livestreams

Google said today it is partnering with RapidSOS, a platform for emergency first responders, to enable users to contact 911 through RCS (Rich Messaging Service).

Google partners with RapidSOS to enable 911 contact through RCS

Long before product-led growth became a buzzword, Atlassian offered free tiers for virtually all of its productivity and developer tools. Today, that mostly means free access for up to 10…

Atlassian now gives startups a year of free access

Featured Article

A social app for creatives, Cara grew from 40k to 650k users in a week because artists are fed up with Meta’s AI policies

Artists have finally had enough with Meta’s predatory AI policies, but Meta’s loss is Cara’s gain. An artist-run, anti-AI social platform, Cara has grown from 40,000 to 650,000 users within the last week, catapulting it to the top of the App Store charts. Instagram is a necessity for many artists,…

14 hours ago
A social app for creatives, Cara grew from 40k to 650k users in a week because artists are fed up with Meta’s AI policies

Google has developed a new AI tool to help marine biologists better understand coral reef ecosystems and their health, which can aid in conversation efforts. The tool, SurfPerch, created with…

Google looks to AI to help save the coral reefs

Only a few years ago, one of the hottest topics in enterprise software was ‘robotic process automation’ (RPA). It doesn’t feel like those services, which tried to automate a lot…

Tektonic AI raises $10M to build GenAI agents for automating business operations

SpaceX achieved a key milestone in its Starship flight test campaign: returning the booster and the upper stage back to Earth.

SpaceX launches mammoth Starship rocket and brings it back for the first time

There’s a lot of buzz about generative AI and what impact it might have on businesses. But look beyond the hype and high-profile deals like the one between OpenAI and…

Sirion, now valued around $1B, acquires Eigen as consolidation comes to enterprise AI tooling

Carlo Kobe and Scott Smith believed so strongly in the need for a debit card product designed specifically for Gen Zers that they dropped out of Harvard and Cornell at…

Kleiner Perkins leads $14.4M seed round into Fizz, a credit-building debit card aimed at Gen Z college students

A new app called MyGlimpact is intended not only to help people understand their environmental footprint, but why they shouldn’t feel guilty about it.

How many Earths does your lifestyle require?

Prolific Machines believes it has a way of transitioning away from molecules to something better: light.

Prolific Machines, with a $55M Series B, shines ‘light’ on a better way to grow lab proteins for food and medicine

It’s been 20 years since Shira Yevin, the lead singer of punk band Shiragirl drove a pink RV into the Vans Warped Tour grounds, the now-defunct punk rock festival notorious…

Punk singer Shira Yevin pushes for fair pay with InPink, a women-focused job marketplace

While the transport industry does use legacy software, many of these platforms are from an earlier era. Qargo hopes its newer technologies can help it leapfrog the competition.

Qargo raises $14M to digitize and decarbonize the trucking industry

When you look at how generative AI is being implemented across developer tools, the focus for the most part has been on generating code, as with GitHub Copilot. Greptile, an…

Greptile raises $4M to build an AI-fueled code base expert