Startups

5 ways to attract top cybersecurity talent in a tight labor market

Comment

Image of a man looking through a magnifying glass at small statuettes to represent the hiring process.
Image Credits: Ivan balvan (opens in a new window) / Getty Images

George Gerchow

Contributor
George Gerchow is the chief security officer at Sumo Logic.

He graduated from a college I’d never heard of. He earned a master’s degree from Villanova, but it was in human resources development. He spent 16 years in the Marine Corps in various military and civilian roles, but none directly involved cybersecurity. His most recent job was as a project manager at a construction firm.

When I asked other senior executives at my company, Sumo Logic, to interview him for a security operations center (SOC) manager position, I initially was met with shoulder shrugs and eye rolls. “Why am I talking to this guy?” went the typical response. “He doesn’t seem a fit at all.”

What they didn’t know was that in my earlier interview with Roland Palmer, I concluded within a half-hour that the job was his. I was blown away by his intense desire to take on hard assignments and win. This ex-Marine had faced daunting challenges, such as planning communications operations in Afghanistan and helping evacuate hundreds of people from an area in Japan contaminated by a nuclear spill. Managing a SOC can be grueling, a constant barrage of crises and incident tickets, but Roland, despite the lack of security work on his resume, seemed born for it.

I told my colleagues, “I’d like for you to talk to him, but if you don’t, I’m hiring him anyway.” They ended up falling in love with Roland, too. He got the job.

That was three years ago. In 2020, Roland was promoted to senior SOC manager. The same year, he won our company’s highest award for employee achievement.

I’m telling this story because I think it says something about what companies and their cybersecurity organizations need to be doing to power over one of their highest hurdles: hiring great talent in an absurdly tight labor market.

“The cybersecurity skills crisis continues on a downward, multi-year trend of bad to worse and has impacted more than half (57%) of organizations,” said a recent report by the Information Systems Security Association and analyst firm Enterprise Strategy Group. There are now 3.5 million unfilled cybersecurity jobs – enough to fill 50 NFL stadiums – according to Cybersecurity Ventures.

At a time when ransomware attacks, data breaches and supply chain intrusions are skyrocketing — the volume of cyber intrusion activity globally soared 125% in the first half of 2021 compared with the same period last year, according to an Accenture study – what is a company supposed to do?

Today’s chief security officer (CSO) needs to start by not only accepting but embracing the talent hunt as a core part of the job. (I spend at least 10% of my week on it, often more.) Then they need to tear up old assumptions about where good security professionals come from and be open-minded and creative in their search.

Five pieces of advice:

Beware the warm body syndrome

Let’s be honest: It’s tempting to just grab anyone you can, not only because cybersecurity jobs need to be filled but due to additional pressures such as protecting headcount before any open positions are cut in a layoff after a bad quarter.

Don’t do it. Cybersecurity is too important to risk having team members who can’t (no pun intended) hack it. Wait to find the best people, no matter what.

Degrees, shmegrees

Graduating from a prestigious institution is a feather in someone’s cap, and I don’t at all mean to discount it, but it’s down my list of prerequisites. Drive, ambition, calm under pressure, team spirit and situational awareness are far more important.

In my first week at Sumo, in 2015, I attended an introductory meeting with several fellow executives who had graduated from schools like Stanford, UC-Berkeley and MIT. When it was my turn to share more about myself, I told everyone around the conference table about my alma mater: Regis University, a small Jesuit university in Denver.

I wasn’t embarrassed; I was proud. And in hiring others, I’ve maintained a philosophy of valuing skills and personal qualities over college backgrounds.

Resilience matters as much as or more than experience

Working in a cybersecurity organization is one of the world’s most stressful jobs, with burnout a constant concern. According to a report by the Chartered Institute of Information Security, 51% of security pros are kept up at night by work stress.

So while past security experience is a huge plus, an ability to handle or even relish the pressure matters as much. I always tell job candidates, “This job is going to be a grind, it’s going to be tough. But the mission is vital.” Some people’s eyes light up when they hear this – that’s who you want, regardless of what’s on their resume.

Exploit nontraditional sources

Roland Palmer is one example of how the best cybersecurity pros don’t necessarily come from the cybersecurity world. But there are many others.

For example, I’ve found software development organizations to be a fertile breeding ground for security talent. Agile development methods such as DevOps are taking development, operations and security out of their traditional silos. Everyone is now expected to work together to foster a fast, efficient, secure software pipeline.

This offers new opportunities for developers to stretch out into the security specialty and help drive the company’s software lifecycle in a different way while expanding their own horizons.

As I often tell developers, “If you join our team, you get to work on infrastructure in the cloud, you get to work on applications, and how APIs and microservices play together. And along the way, you’re developing a higher-level understanding of the software pipeline and helping drive a security-baked-in culture. And if you decide to return to engineering in the future, you’re better prepared to do so with broader experience and the security mindset that has become so crucial.”

I also look at folks with financial operations backgrounds because of their regulatory compliance orientation and attention to detail that is essential to security work.

Seek empathy

When I got started in security, I sensed other employees would hide from me when they saw me walking down the hall. They viewed me as the bad guy arriving to rap their knuckles over some security issue.

In today’s more collaborative culture, that no longer flies. Security pros need to be seen as trusted teammates to feel comfortable around. Therefore, a collaborative, empathetic personality is a trait I always look for in prospective hires.

Whether they like it or not, hiring top-notch people has become one of the most important and challenging facets of a CSO’s job, and that won’t change anytime soon. But with determination and some out-of-the-box thinking, they can answer the challenge.

More TechCrunch

When Jordan Nathan launched his DTC nontoxic cookware company, Caraway, in 2019, he knew he was not the only founder trying to sell a new brand of pots and pans…

Why being the last company to launch in a category can pay off

Out of an abundance of caution, the car took two minutes to turn a corner.

This humanoid robot can drive cars — sort of

There has been a silly amount of drama in the run-up to Tesla‘s annual shareholder meeting on Thursday. The company is set to hold a vote on “re-ratifying” the $56…

Ahead of Tesla’s big shareholder vote, let’s re-read the judge’s opinion that got us here

To give users more control over the contacts an app can and cannot access, the permissions screen has two stages.

iOS 18 cracks down on apps asking for full address book access

The push to produce a robotic intelligence that can fully leverage the wide breadth of movements opened up by bipedal humanoid design has been a key topic for researchers.

Generative AI takes robots a step closer to general purpose

A TechCrunch review of LinkedIn data found that Ford has built this team up to around 300 employees over the last year.

Ford’s secretive, low-cost EV team is growing with talent from Rivian, Tesla and Apple

The most critical systems of our modern world rely on GPS, from aviation and road networks to emergency and disaster response, from precision farming and power grids to weather forecasting…

Tern AI wants to reduce reliance on GPS with low-cost navigation alternative 

Since fintech startup Brex’s inception in 2017, its two co-founders Henrique Dubugras and Pedro Franceschi have run the company as co-CEOs. But starting today, the pair told TechCrunch in an…

Fintech Brex abandons co-CEO model, talks IPO, cash burn and plans for a secondary sale

Hiya, folks, and welcome to TechCrunch’s regular AI newsletter. This week in AI, Apple stole the spotlight. At the company’s Worldwide Developers Conference (WWDC) in Cupertino, Apple unveiled Apple Intelligence,…

This Week in AI: Apple won’t say how the sausage gets made

India’s largest wealth manager focused on ultra-high-net-worth individuals, 360 One WAM, has agreed to acquire popular Indian mutual fund investment app ET Money for about $44 million. Earlier called IIFL…

India’s 360 One acquires mutual fund app ET Money for $44M

Helen Toner, a former OpenAI board member and the director of strategy at Georgetown’s Center for Security and Emerging Technology, is worried Congress might react in a “knee-jerk” way where…

Helen Toner worries ‘not super functional’ Congress will flub AI policy

Layoffs are tough. This year alone, we’ve already seen 60,000 job cuts across 254 companies according to layoffs.fyi. Looking for ways to grow your network can be even harder during…

Layoffs Got You Down? Get a Half-Price Expo+ Pass at Disrupt 2024

YouTube announced this week the rollout of “Thumbnail Test & Compare,” a new tool for creators to see which thumbnail performs the best. The feature first launched to select creators…

YouTube creators can now test multiple video thumbnails

Waymo has voluntarily issued a software recall to all 672 of its Jaguar I-Pace robotaxis after one of them collided with a telephone pole. This is Waymo’s second recall. The…

Waymo issues second recall after robotaxi hit telephone pole

The hotel guest management technology company’s platform digitizes the hotel guest journey from post-booking through checkout.

Insight Partners backs Canary Technologies’ mission to elevate hotel guest experiences

The TechCrunch team runs down all of the biggest news from the Apple WWDC 2024 keynote in an easy-to-skim digest.

Here’s everything Apple announced at the WWDC 2024 keynote, including Apple Intelligence, Siri makeover

InScope leverages machine learning and large language models to provide financial reporting and auditing processes for mid-market and enterprises.

Lightspeed Venture Partners leads $4.3M seed in automated financial reporting fintech InScope

Venture fundraising has been a slog over the last few years, even for firms with a strong track record. That’s Foresite Capital’s experience. Despite having 47 IPOs, 28 M&As and…

Foresite Capital raises $900M sixth fund for investing in life sciences companies

A year ago, Databricks acquired MosaicML for $1.3 billion. Now rebranded as Mosaic AI, the platform has become integral to Databricks’ AI solutions. Today, at the company’s Data + AI…

Databricks expands Mosaic AI to help enterprises build with LLMs

RetailReady targets the $40 billion compliance market to help reduce the number of retail compliance losses that shippers incur annually due to incorrectly shipped packages.

YC grad RetailReady raises $3.3M for an AI warehouse app that hopes to save brands billions

Since its launch in 2013, Databricks has relied on its ecosystem of partners, such as Fivetran, Rudderstack, and dbt, to provide tools for data preparation and loading. But now, at…

Databricks launches LakeFlow to help its customers build their data pipelines

A big shoutout to the early-stage founders who missed the application window for the Startup Battlefield 200 (SB 200) at TechCrunch Disrupt. We have exciting news just for you! You…

Bonus: An extra week to apply to Startup Battlefield 200

When one of the co-creators of the popular open source stream-processing framework Apache Flink launches a new startup, it’s worth paying attention. Stephan Ewen was among the founding team of…

Restate raises $7M for its lightweight workflows-as-code platform

With most residential solar panels installed by smaller companies, customer experience can be a mixed bag. To try to address the quality and consistency problem, Civic Renewables is buying small…

Civic Renewables is rolling up residential solar installers to improve quality and grow the market

Small VC firms require deep trust, mutual support and long-term commitment among the partners — a kinship that, in many ways, resembles a family dynamic. Colin Anderson (Palantir’s ex-CFO and…

Friends & Family Capital, a fund founded by ex-Palantir CFO and son of IVP’s founder, unveils third $118M fund

Fisker is issuing the first recall for its all-electric Ocean SUV because of problems with the warning lights, according to new information published by the National Highway Traffic Safety Administration…

Fisker’s troubled Ocean SUV gets its first recall

Gorilla, a Belgian company that serves the energy sector with real-time data and analytics for pricing and forecasting, has raised €23 million ($25 million) in a Series B round led…

Gorilla, a Belgian startup that helps energy providers crunch big data, raises $25M

South Korea’s fabless AI chip industry saw a slew of fundraising events over the last couple of years as demand for hardware to power AI applications skyrocketed, and it seems…

Fabless AI chip makers Rebellions and Sapeon to merge as competition heats up in global AI hardware industry

Here’s a list of third-party apps that were Sherlocked by Apple at this year’s WWDC.

The apps that Apple sherlocked at WWDC 2024

Black Semiconductor, which is developing a chip-connecting technology based on graphene, has raised $273M in a combination of private and public funding. 

Black Semiconductor nabs $273M in Germany to supercharge how chips work together