{"id":186782,"date":"2026-02-12T13:00:00","date_gmt":"2026-02-12T18:00:00","guid":{"rendered":"https:\/\/testing.news-you-need.com\/index.php\/2026\/02\/12\/cybersecuritys-broken-hiring-process\/"},"modified":"2026-02-12T13:05:09","modified_gmt":"2026-02-12T18:05:09","slug":"cybersecuritys-broken-hiring-process","status":"publish","type":"post","link":"https:\/\/testing.news-you-need.com\/index.php\/2026\/02\/12\/cybersecuritys-broken-hiring-process\/","title":{"rendered":"Cybersecurity&#8217;s Broken Hiring Process"},"content":{"rendered":"<p><a href=\"https:\/\/www.linkedin.com\/pulse\/cybersecuritys-broken-hiring-process-cisoseries-5fzsc\">Cybersecurity&#8217;s Broken Hiring Process<\/a><\/p>\n<p><a href=\"https:\/\/www.linkedin.com\/pulse\/cybersecuritys-broken-hiring-process-cisoseries-5fzsc\">https:\/\/www.linkedin.com\/pulse\/cybersecuritys-broken-hiring-process-cisoseries-5fzsc<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-02-12 13:00:00<\/a><\/p>\n<p>Source Domain: <a href=\"www.linkedin.com\">www.linkedin.com<\/a><\/p>\n<p>Author: <a href=\"\"><\/a><\/p>\n<p> Using an unordered list, summarize the following article with between 4 and 8 key points. <\/p>\n<p>          Something is wrong with the math in the cybersecurity job market. If there are &#8220;millions&#8221; of unfilled jobs out there, why are so many job seekers struggling to even book an interview?<\/p>\n<p>          Check out this post by <\/p>\n<p>        Dr. Chase Cunningham<\/p>\n<p>  , CSO at<br \/>\n      Demo-Force.com<br \/>\n  , for the discussion that is the basis of our conversation on this week\u2019s episode, co-hosted by me, <\/p>\n<p>        David Spark<\/p>\n<p>  , the producer of CISO Series, and <\/p>\n<p>        Geoff Belknap<\/p>\n<p>  . Joining us is <\/p>\n<p>        Brett Conlon<\/p>\n<p>  , CISO,<br \/>\n      American Century Investments<br \/>\n  . Thanks to our podcast sponsor,<br \/>\n      Scanner<br \/>\n  .<\/p>\n<p>        The experience paradox<\/p>\n<p>          Getting into cybersecurity has become a problem that higher education seems unable to address. <\/p>\n<p>        Nick Chadwick<\/p>\n<p>   of<br \/>\n      NT Concepts<br \/>\n   described his own path: &#8220;I didn&#8217;t even get into cybersecurity roles until I was 5-8 years deep in enterprise and edge IT, and then they were just additional duties on my normal job.&#8221; That was 20 years ago. Today, he asked, &#8220;How can someone perform cybersecurity primary roles if they don&#8217;t have deep hands-on exposure to enterprise IT?&#8221; Hand wringing about talent shortages isn&#8217;t new, as <\/p>\n<p>        Rob Slade<\/p>\n<p>   of<br \/>\n      ISC2<br \/>\n   reminded, &#8220;Forty-five years ago, when I joined the IT job market, there were articles (from companies) bewailing the lack of IT talent. Forty years ago, when I joined the security job market, there were articles bewailing the lack of security talent.&#8221; For the last thirty years, while teaching IT and security talent, &#8220;there have never been recruiters beating down the doors. And yet, the articles bewailing the lack of talent have continued. Either the articles are lying, or this &#8216;supply and demand&#8217; thing that the economists seem to think is important, is, in fact, nonsense.&#8221;<\/p>\n<p>        Who benefits from the narrative?<\/p>\n<p>          The talent shortage story isn&#8217;t coming out of a vacuum. It serves specific institutional interests, hiding dysfunctional hiring practices. <\/p>\n<p>        Laura Kenner<\/p>\n<p>   of<br \/>\n      Bootstrap Cyber Community<br \/>\n   pointed to who profits from perpetuating the shortage narrative, saying, &#8220;It&#8217;s the colleges and certification programs perpetuating this lie because it adds to their bottom line.&#8221; Companies want someone with 10 years of experience, expect them to be a jack-of-all-trades, but pay entry-level wages. &#8220;Candidates are coming out of schools and cert programs in droves, ready to work,&#8221; she emphasized. &#8220;The next generation of cyber professionals will be built in the workplace!&#8221; <\/p>\n<p>        Andrew Robinson FREC<\/p>\n<p>   of<br \/>\n      Securiti<br \/>\n   highlighted how internal processes compound the problem. He described a portfolio client whose pre-IPO hiring involved two or three interviews maximum with direct C-suite engagement. Once they reached $4 billion in revenue, &#8220;it was death by interview. 15+ wasn&#8217;t uncommon, and in the worst case, an 11-month process.&#8221; Companies try to reduce hiring costs, he noted, but many of their processes are broken and not fit for purpose.<\/p>\n<p>        Kitchen sink job postings<\/p>\n<p>          Market dynamics have given employers leeway to make unrealistic demands. &#8220;With thousands of highly experienced folks suddenly kicked to the curb, employers know they can ask for whatever they want under whatever title they want to use for their vacancy\u2014and pay less than they ever thought they could get away with paying,&#8221; said <\/p>\n<p>        Arun Acharya<\/p>\n<p>  . &#8220;Not so long ago, there was the phenomenon of the &#8216;kitchen sink&#8217; resume. Now there is the new phenomenon of &#8216;kitchen sink&#8217; job posting.&#8221; <\/p>\n<p>        Ronald Sweatland<\/p>\n<p>   of<br \/>\n      Orcannus Cyber Security<br \/>\n   emphasized that it&#8217;s not uncommon to see postings requiring a PhD in Cybersecurity along with every certification imaginable. &#8220;While these credentials may look impressive on paper, such expectations are often impractical,&#8221; he explained. &#8220;Organizations would benefit far more from professionals with hands-on experience and real-world problem-solving skills\u2014individuals who have faced and mitigated threats in live environments\u2014rather than those who have only accumulated theoretical knowledge and certifications.&#8221;<\/p>\n<p>        The aggregation problem<\/p>\n<p>          Part of this hiring story is that cybersecurity isn&#8217;t a one-size-fits-all industry. &#8220;I think there&#8217;s a disconnect here,&#8221; said <\/p>\n<p>        \ud83d\udc68\ud83d\udcbb Steve Pangborn<\/p>\n<p>   of<br \/>\n      Onsite Logic<br \/>\n  . &#8220;&#8216;Cybersecurity&#8217; isn&#8217;t a single discipline: it&#8217;s a whole ecosystem of roles: architecture, forensics, governance, detection, policy, data protection, and more. We often refer to a generic &#8216;cyber talent gap&#8217; as if one person could fill all of that.&#8221; The path forward requires specificity rather than broad generalizations. &#8220;The truth is, we need to start defining what kind of talent is missing, and where, before we can effectively address the issue,&#8221; he emphasized.<\/p>\n<p>          Please listen to the full episode on your favorite podcast app, or over on our blog, where you can read the full transcript. If you\u2019re not already subscribed to the Defense in Depth podcast, please go ahead and subscribe now. Listen to the full episode here.<\/p>\n<p>            Thanks to our podcast sponsor, Scanner<\/p>\n<p>            Subscribe to Defense in Depth podcast<\/p>\n<p>          Please subscribe via Apple Podcasts, Spotify, YouTube Music, Amazon Music, Pocket Casts, RSS, or just type &#8220;Defense in Depth&#8221; into your favorite podcast app.<\/p>\n<p>            Join us next week, Friday [02-20-26], for &#8220;Hacking the Future of Log Data&#8221;<\/p>\n<p>          Join us Friday, February 20, 2026, for\u00a0\u201cHacking the Future of Log Data: An hour of critical thinking about why your traditional SIEM is telling only a fraction of the story.\u201d<\/p>\n<p>          It all begins at 1 PM ET\/10 AM PT next Friday with guests <\/p>\n<p>        tim leehealey<\/p>\n<p>  , vp of corporate strategy and operations,<br \/>\n      Strike48<br \/>\n  , and <\/p>\n<p>        Nick Falzarano<\/p>\n<p>  , director, information security,<br \/>\n      TE Connectivity<br \/>\n  .\u00a0We&#8217;ll have fun conversation and games, plus at the end of the hour we&#8217;ll do our meetup.<\/p>\n<p>            Thanks to our Super Cyber Friday sponsor, Strike48<\/p>\n<p>            PREVIEW: CISO Series Podcast LIVE in Orlando, FL 3-6-26<\/p>\n<p>          CISO Series Podcast will be making like snowbirds to Orlando, Florida, recording an episode at Zero Trust World 2026. <\/p>\n<p>        Michelle Wilson<\/p>\n<p>  , CISO,<br \/>\n      Movement Mortgage<br \/>\n  , and <\/p>\n<p>        Rob Allen<\/p>\n<p>  , chief product officer,<br \/>\n      ThreatLocker<br \/>\n   will be joining us on stage for the recording.<\/p>\n<p>          Register to attend here, and use coupon code ZTWCISOSERIES26 to get $200 off your ticket.<\/p>\n<p>            Thanks to our sponsor, ThreatLocker<\/p>\n<p>            Cybersecurity Headlines &#8211; Department of Know<\/p>\n<p>          Our LIVE stream of The Department of Know happens every Monday at 4 PM ET \/ 1 PM PT with CISO Series producer <\/p>\n<p>        Richard Stroffolino<\/p>\n<p>   , and a panel of security pros. Each week, we bring you the cybersecurity stories that actually matter, and the conversations you\u2019ll be having at work all week long.<\/p>\n<p>          Monday\u2019s episode featured<br \/>\n      Chris R.<br \/>\n  , field CTO,<br \/>\n      GigaOm<br \/>\n  , and <\/p>\n<p>        Nick Ryan<\/p>\n<p>  , former BISO. Missed it? Watch the replay on YouTube and catch up on what\u2019s shaping the week in security.<\/p>\n<p>            Thanks to our Cybersecurity Headlines sponsor, ThreatLocker<\/p>\n<p>          Join CISO Series Podcast live at ThreatLocker&#8217;s Zero Trust World 2026, March 4-6th, 2026 in Orlando, FL. Use coupon code ZTWCISOSERIES26 to get $200 off your ticket.<\/p>\n<p>            Jump in on these conversations<\/p>\n<p>    \u201cNotepad++ Hijacked by State-Sponsored Hackers\u201d (More here)<br \/>\n    \u201cWaPo Raid Is a Frightening Reminder: Turn Off Your Phone\u2019s Biometrics Now\u201d\u00a0(More here)<br \/>\n    \u201cRussian hackers exploit recently patched Microsoft Office bug in attacks\u201d\u00a0(More here)<\/p>\n<p>            Thank you for supporting CISO Series and all our programming<\/p>\n<p>          We love all kinds of support: listening, watching, contributions, What&#8217;s Worse?! scenarios, telling your friends, sharing in social media, and most of all we love our sponsors!<\/p>\n<p>          Everything is available at\u00a0cisoseries.com.<\/p>\n<p>          Interested in sponsorship,\u00a0contact me,\u00a0David Spark.<\/p>\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity&#8217;s Broken Hiring Process https:\/\/www.linkedin.com\/pulse\/cybersecuritys-broken-hiring-process-cisoseries-5fzsc Publish Date: 2026-02-12 13:00:00 Source Domain: www.linkedin.com Author: Using an&#8230;<\/p>\n","protected":false},"author":1,"featured_media":186783,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/media.licdn.com\/dms\/image\/v2\/D5612AQFAaTm3PFzmHg\/article-cover_image-shrink_720_1280\/B56ZwwUh7JHYAI-\/0\/1770337217059?e=2147483647&v=beta&t=ieBjeu9xbT3NVXDkLUFLxGJ2H_zWMi4Ls_4cdpG2yJQ","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,31],"class_list":["post-186782","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-exploit"],"_links":{"self":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/186782"}],"collection":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=186782"}],"version-history":[{"count":1,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/186782\/revisions"}],"predecessor-version":[{"id":186784,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/186782\/revisions\/186784"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/186783"}],"wp:attachment":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=186782"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=186782"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=186782"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}