R.I.P. Entry-Level Cybersecurity Jobs?
This is not the first or last time we will address the (alleged, purported, actual, imagined) demise of the entry-level job.
That newbie fresh-out-of-college or right-out-of-the-military cyber-defender that had all the certs and none of the savvy? You might kiss it goodbye.
But in reality you're kissing that position description goodbye, not the role.
In brief we at Pythia Cyber think the nature of entry-level cybersecurity work will change but not disappear. Like any change process, its trajectory of change is unknowable; 5 years from now we will have a new labor force that arose from pressures we have now.
Over at The Signal, Alex Banks is having all of the angst. These three nonconsecutive paragraphs tell his story:
Nobody learns their trade in their first year. If you’re honest about your own, what you actually learn is a collection of many small micro-experiences that compound into a long list of intangibles that can rarely be named yet can only be sharpened through the doing. These intangibles include reading a room, who to believe, how to ask thoughtful questions, how to respond to criticism, amongst other things. They’re all vital and innately human. And if I’m honest, they can be built regardless of profession, as long as there is human interaction where individuals are working toward a common goal.
The knowledge you get from a degree is codified, which means it can be written down, and that is precisely why a model can reproduce it. The knowledge you get from doing the job is tacit, intangible, built through practice and forged through judgement.
The routine work was never the point. It was the reason a junior was in the room, and being in the room was how they learnt everything that couldn’t be written down. Now the model does the routine work, so there’s no reason to have the junior in the room. But the veteran still has to come from somewhere. Companies are cutting off the supply of experience while paying more for it than ever, and the Dallas Fed’s own economist says as much: you can leave new hires off the ladder for a while, but not for long, because eventually there’s nobody left to climb it.
His analysis is fine but in our opinion again it's focused on the entry-level position description you're comfortable with going away, not the role. What to do?
Here are five lessons from best-in-class organizations we work with.
First, decide what cybersecurity business you're in. Are you a mature operation at the cutting edge of cyber? Are you a small operation with basic security? Do you have an always-on op tempo? There is no wrong answer here other than misunderstanding your SOC ops.
Second, do you have a current (i.e. revised this calendar year) strategy security implementation plan? If the answer is no, then you need to pause here and develop one.
Third, whatever the future of the entry-level job is, it won't be defined by academic coursework (read the rest of Banks' Substack). The cyber-defender pipeline will be talent-based, not certification-dependent. Start with the Pythia Cyber Cybersecurity Talent Stack assessment and integrate badges (likely, AI badges) as a continual development process. Learning on the clock is your only real option.
Fourth, mentoring is now part of performance management or, if that's too icky for your organization, it's part of the promotion process for mentors. It's 'What's In It For Me' and it's cynical; do it because it works.
Fifth and finally, you cannot predict your own career five years out so build resilience into your systems now. Career development, which has always been viewed by leaders with disdain, is now part of what we refer to as the four pillars of a successful cyber-defense team (talent, structure, engagement, development). It might be something you pay for on an ad hoc basis v. having a subscription to a static course offering...from 2022...because -- can't say this often enough -- the nature of cybersecurity has changed and so must your operations.
Entry-level jobs that you're used to are going away, and that's OK -- as long as you're intentional about leading the transition.
See you on the other side.
Ask us how you can create a robust entry-level talent pipeline.

Comments
Post a Comment