Startups

5 ways to attract top cybersecurity talent in a tight labor market

Comment

Image of a man looking through a magnifying glass at small statuettes to represent the hiring process.
Image Credits: Ivan balvan (opens in a new window) / Getty Images

George Gerchow

Contributor

George Gerchow is the chief security officer at Sumo Logic.

He graduated from a college I’d never heard of. He earned a master’s degree from Villanova, but it was in human resources development. He spent 16 years in the Marine Corps in various military and civilian roles, but none directly involved cybersecurity. His most recent job was as a project manager at a construction firm.

When I asked other senior executives at my company, Sumo Logic, to interview him for a security operations center (SOC) manager position, I initially was met with shoulder shrugs and eye rolls. “Why am I talking to this guy?” went the typical response. “He doesn’t seem a fit at all.”

What they didn’t know was that in my earlier interview with Roland Palmer, I concluded within a half-hour that the job was his. I was blown away by his intense desire to take on hard assignments and win. This ex-Marine had faced daunting challenges, such as planning communications operations in Afghanistan and helping evacuate hundreds of people from an area in Japan contaminated by a nuclear spill. Managing a SOC can be grueling, a constant barrage of crises and incident tickets, but Roland, despite the lack of security work on his resume, seemed born for it.

I told my colleagues, “I’d like for you to talk to him, but if you don’t, I’m hiring him anyway.” They ended up falling in love with Roland, too. He got the job.

That was three years ago. In 2020, Roland was promoted to senior SOC manager. The same year, he won our company’s highest award for employee achievement.

I’m telling this story because I think it says something about what companies and their cybersecurity organizations need to be doing to power over one of their highest hurdles: hiring great talent in an absurdly tight labor market.

“The cybersecurity skills crisis continues on a downward, multi-year trend of bad to worse and has impacted more than half (57%) of organizations,” said a recent report by the Information Systems Security Association and analyst firm Enterprise Strategy Group. There are now 3.5 million unfilled cybersecurity jobs – enough to fill 50 NFL stadiums – according to Cybersecurity Ventures.

At a time when ransomware attacks, data breaches and supply chain intrusions are skyrocketing — the volume of cyber intrusion activity globally soared 125% in the first half of 2021 compared with the same period last year, according to an Accenture study – what is a company supposed to do?

Today’s chief security officer (CSO) needs to start by not only accepting but embracing the talent hunt as a core part of the job. (I spend at least 10% of my week on it, often more.) Then they need to tear up old assumptions about where good security professionals come from and be open-minded and creative in their search.

Five pieces of advice:

Beware the warm body syndrome

Let’s be honest: It’s tempting to just grab anyone you can, not only because cybersecurity jobs need to be filled but due to additional pressures such as protecting headcount before any open positions are cut in a layoff after a bad quarter.

Don’t do it. Cybersecurity is too important to risk having team members who can’t (no pun intended) hack it. Wait to find the best people, no matter what.

Degrees, shmegrees

Graduating from a prestigious institution is a feather in someone’s cap, and I don’t at all mean to discount it, but it’s down my list of prerequisites. Drive, ambition, calm under pressure, team spirit and situational awareness are far more important.

In my first week at Sumo, in 2015, I attended an introductory meeting with several fellow executives who had graduated from schools like Stanford, UC-Berkeley and MIT. When it was my turn to share more about myself, I told everyone around the conference table about my alma mater: Regis University, a small Jesuit university in Denver.

I wasn’t embarrassed; I was proud. And in hiring others, I’ve maintained a philosophy of valuing skills and personal qualities over college backgrounds.

Resilience matters as much as or more than experience

Working in a cybersecurity organization is one of the world’s most stressful jobs, with burnout a constant concern. According to a report by the Chartered Institute of Information Security, 51% of security pros are kept up at night by work stress.

So while past security experience is a huge plus, an ability to handle or even relish the pressure matters as much. I always tell job candidates, “This job is going to be a grind, it’s going to be tough. But the mission is vital.” Some people’s eyes light up when they hear this – that’s who you want, regardless of what’s on their resume.

Exploit nontraditional sources

Roland Palmer is one example of how the best cybersecurity pros don’t necessarily come from the cybersecurity world. But there are many others.

For example, I’ve found software development organizations to be a fertile breeding ground for security talent. Agile development methods such as DevOps are taking development, operations and security out of their traditional silos. Everyone is now expected to work together to foster a fast, efficient, secure software pipeline.

This offers new opportunities for developers to stretch out into the security specialty and help drive the company’s software lifecycle in a different way while expanding their own horizons.

As I often tell developers, “If you join our team, you get to work on infrastructure in the cloud, you get to work on applications, and how APIs and microservices play together. And along the way, you’re developing a higher-level understanding of the software pipeline and helping drive a security-baked-in culture. And if you decide to return to engineering in the future, you’re better prepared to do so with broader experience and the security mindset that has become so crucial.”

I also look at folks with financial operations backgrounds because of their regulatory compliance orientation and attention to detail that is essential to security work.

Seek empathy

When I got started in security, I sensed other employees would hide from me when they saw me walking down the hall. They viewed me as the bad guy arriving to rap their knuckles over some security issue.

In today’s more collaborative culture, that no longer flies. Security pros need to be seen as trusted teammates to feel comfortable around. Therefore, a collaborative, empathetic personality is a trait I always look for in prospective hires.

Whether they like it or not, hiring top-notch people has become one of the most important and challenging facets of a CSO’s job, and that won’t change anytime soon. But with determination and some out-of-the-box thinking, they can answer the challenge.

More TechCrunch

Welcome back to TechCrunch’s Week in Review — TechCrunch’s newsletter recapping the week’s biggest news. Want it in your inbox every Saturday? Sign up here. OpenAI announced this week that…

Scarlett Johansson brought receipts to the OpenAI controversy

Accurate weather forecasts are critical to industries like agriculture, and they’re also important to help prevent and mitigate harm from inclement weather events or natural disasters. But getting forecasts right…

Deal Dive: Can blockchain make weather forecasts better? WeatherXM thinks so

pcTattletale’s website was briefly defaced and contained links containing files from the spyware maker’s servers, before going offline.

Spyware app pcTattletale was hacked and its website defaced

Featured Article

Synapse, backed by a16z, has collapsed, and 10 million consumers could be hurt

Synapse’s bankruptcy shows just how treacherous things are for the often-interdependent fintech world when one key player hits trouble. 

6 hours ago
Synapse, backed by a16z, has collapsed, and 10 million consumers could be hurt

Sarah Myers West, profiled as part of TechCrunch’s Women in AI series, is managing director at the AI Now institute.

Women in AI: Sarah Myers West says we should ask, ‘Why build AI at all?’

Keeping up with an industry as fast-moving as AI is a tall order. So until an AI can do it for you, here’s a handy roundup of recent stories in the world…

This Week in AI: OpenAI and publishers are partners of convenience

Evan, a high school sophomore from Houston, was stuck on a calculus problem. He pulled up Answer AI on his iPhone, snapped a photo of the problem from his Advanced…

AI tutors are quietly changing how kids in the US study, and the leading apps are from China

Welcome to Startups Weekly — Haje‘s weekly recap of everything you can’t miss from the world of startups. Sign up here to get it in your inbox every Friday. Well,…

Startups Weekly: Drama at Techstars. Drama in AI. Drama everywhere.

Last year’s investor dreams of a strong 2024 IPO pipeline have faded, if not fully disappeared, as we approach the halfway point of the year. 2024 delivered four venture-backed tech…

From Plaid to Figma, here are the startups that are likely — or definitely — not having IPOs this year

Federal safety regulators have discovered nine more incidents that raise questions about the safety of Waymo’s self-driving vehicles operating in Phoenix and San Francisco.  The National Highway Traffic Safety Administration…

Feds add nine more incidents to Waymo robotaxi investigation

Terra One’s pitch deck has a few wins, but also a few misses. Here’s how to fix that.

Pitch Deck Teardown: Terra One’s $7.5M Seed deck

Chinasa T. Okolo researches AI policy and governance in the Global South.

Women in AI: Chinasa T. Okolo researches AI’s impact on the Global South

TechCrunch Disrupt takes place on October 28–30 in San Francisco. While the event is a few months away, the deadline to secure your early-bird tickets and save up to $800…

Disrupt 2024 early-bird tickets fly away next Friday

Another week, and another round of crazy cash injections and valuations emerged from the AI realm. DeepL, an AI language translation startup, raised $300 million on a $2 billion valuation;…

Big tech companies are plowing money into AI startups, which could help them dodge antitrust concerns

If raised, this new fund, the firm’s third, would be its largest to date.

Harlem Capital is raising a $150 million fund

About half a million patients have been notified so far, but the number of affected individuals is likely far higher.

US pharma giant Cencora says Americans’ health information stolen in data breach

Attention, tech enthusiasts and startup supporters! The final countdown is here: Today is the last day to cast your vote for the TechCrunch Disrupt 2024 Audience Choice program. Voting closes…

Last day to vote for TC Disrupt 2024 Audience Choice program

Featured Article

Signal’s Meredith Whittaker on the Telegram security clash and the ‘edge lords’ at OpenAI 

Among other things, Whittaker is concerned about the concentration of power in the five main social media platforms.

1 day ago
Signal’s Meredith Whittaker on the Telegram security clash and the ‘edge lords’ at OpenAI 

Lucid Motors is laying off about 400 employees, or roughly 6% of its workforce, as part of a restructuring ahead of the launch of its first electric SUV later this…

Lucid Motors slashes 400 jobs ahead of crucial SUV launch

Google is investing nearly $350 million in Flipkart, becoming the latest high-profile name to back the Walmart-owned Indian e-commerce startup. The Android-maker will also provide Flipkart with cloud offerings as…

Google invests $350 million in Indian e-commerce giant Flipkart

A Jio Financial unit plans to purchase customer premises equipment and telecom gear worth $4.32 billion from Reliance Retail.

Jio Financial unit to buy $4.32B of telecom gear from Reliance Retail

Foursquare, the location-focused outfit that in 2020 merged with Factual, another location-focused outfit, is joining the parade of companies to make cuts to one of its biggest cost centers –…

Foursquare just laid off 105 employees

“Running with scissors is a cardio exercise that can increase your heart rate and require concentration and focus,” says Google’s new AI search feature. “Some say it can also improve…

Using memes, social media users have become red teams for half-baked AI features

The European Space Agency selected two companies on Wednesday to advance designs of a cargo spacecraft that could establish the continent’s first sovereign access to space.  The two awardees, major…

ESA prepares for the post-ISS era, selects The Exploration Company, Thales Alenia to develop cargo spacecraft

Expressable is a platform that offers one-on-one virtual sessions with speech language pathologists.

Expressable brings speech therapy into the home

The French Secretary of State for the Digital Economy as of this year, Marina Ferrari, revealed this year’s laureates during VivaTech week in Paris. According to its promoters, this fifth…

The biggest French startups in 2024 according to the French government

Spotify is notifying customers who purchased its Car Thing product that the devices will stop working after December 9, 2024. The company discontinued the device back in July 2022, but…

Spotify to shut off Car Thing for good, leading users to demand refunds

Elon Musk’s X is preparing to make “likes” private on the social network, in a change that could potentially confuse users over the difference between something they’ve favorited and something…

X should bring back stars, not hide ‘likes’

The FCC has proposed a $6 million fine for the scammer who used voice-cloning tech to impersonate President Biden in a series of illegal robocalls during a New Hampshire primary…

$6M fine for robocaller who used AI to clone Biden’s voice

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Is it…

Tesla lobbies for Elon and Kia taps into the GenAI hype