the reality vs. expectation in cybersecurity.

Grant Collins
26 Jan 202410:17

Summary

TLDRIn this video, the influencer candidly discusses the reality versus expectations of a cybersecurity career. They challenge the notion of a 'skills shortage', suggesting instead a 'talent or experience gap', where entry-level jobs are scarce and competition is fierce. The script highlights organizational complexities and the cultural attitudes within companies that can hinder security efforts. It also touches on the daily grind and burnout faced by professionals, emphasizing the need for continuous learning in an ever-evolving field. The video serves as a realistic portrayal of the cybersecurity industry, urging viewers to consider both the challenges and rewards of a career in this domain.

Takeaways

  • 🚀 The video aims to contrast the expectations versus the realities of a cybersecurity career, highlighting the complexities and barriers faced in the industry.
  • 🎓 The speaker, a university student, initially had an idealized view of cybersecurity, expecting to read news and handle tickets, but found the reality to be more complex.
  • 🔒 The speaker feels disappointed with the organizational barriers in cybersecurity, which are not as apparent when you're just starting out in the field.
  • 🤔 Three main expectations versus realities are discussed in the video: the skills shortage gap, the challenge of adding value early in a career, and the daily grind of cybersecurity.
  • 📈 The cybersecurity industry is often portrayed as having a skills shortage, with many high-paying jobs available, but the reality is more about a talent or experience gap.
  • 💼 Entry-level cybersecurity jobs are competitive and not as readily available as expected, with recruiters seeking experienced professionals.
  • 🏢 The organizational culture and leadership's attitude towards security greatly impact the success of a security team and individual within an organization.
  • 🔄 Companies often underinvest in their security programs until they experience a breach, leading to a cycle of minimal effort followed by a ramp-up in security.
  • 📚 The constant need to learn and adapt to new technologies and techniques can lead to information overload and burnout in the cybersecurity field.
  • 🔄 The speaker emphasizes the repetitive nature of some entry-level tasks and the mental and emotional toll that the daily grind can take on professionals.
  • 🌟 Despite the challenges, the speaker still finds the cybersecurity career path rewarding and is committed to continuing in the industry.

Q & A

  • What is the main theme of the video script?

    -The main theme of the video script is the contrast between the expectations and realities of a career in cybersecurity, as experienced by a university student entering the field.

  • What misconception does the video creator address about the cybersecurity job market?

    -The video creator addresses the misconception that there is a significant skills shortage in cybersecurity, suggesting instead that it is more of a talent or experience gap, with many qualified individuals struggling to find jobs due to a preference for experienced professionals.

  • Why does the video creator feel disappointed when looking at the queue of tickets in real life?

    -The video creator feels disappointed because they realized there are many organizational barriers in cybersecurity that they did not anticipate, making the job more complex and challenging than expected.

  • What is the difference between expectation and reality regarding job opportunities for cybersecurity graduates?

    -The expectation is that cybersecurity graduates would have many high-paying job offers, but the reality is that the job market is very competitive, and entry-level positions are hard to come by due to the demand for experienced professionals.

  • How does the video script describe the organizational complexity in cybersecurity?

    -The script describes organizational complexity as a set of internal tools, processes, and company culture that a new cybersecurity professional must learn and navigate, which can be difficult and varies greatly between industries and sectors.

  • What is the impact of company culture on the success of a cybersecurity team?

    -Company culture and attitudes towards security, including leadership's awareness and risk tolerance, play a significant role in determining the success of a cybersecurity team within an organization.

  • Why do some companies only increase their security efforts after experiencing a breach?

    -Some companies may put minimal effort into their security program due to budget constraints or lack of awareness, and only after experiencing a breach do they ramp up their security budget and program, creating a cycle of underinvestment and reactive spending.

  • What does the video script suggest about the daily grind or burnout in cybersecurity careers?

    -The script suggests that the daily grind or burnout in cybersecurity careers is due to the constant need to learn and adapt to new technologies, attack techniques, and industry jargon, which can be overwhelming and exhausting.

  • How does the video creator feel about the repetitive tasks often associated with entry-level cybersecurity positions?

    -The video creator acknowledges that entry-level tasks can be repetitive, such as account provisioning or responding to low-level incidents, and that this can contribute to the feeling of burnout.

  • What advice does the video creator give to those considering a career in cybersecurity?

    -The video creator advises prospective cybersecurity professionals to be aware of the challenges and realities of the field, to maintain a balance between expectations and the actual demands of the job, and to take care of their mental, physical, and emotional well-being.

Outlines

00:00

🤔 Cybersecurity Career Expectations vs. Reality

The speaker begins by acknowledging the cliché of discussing cybersecurity career expectations versus reality, a common theme in influencer videos. They reflect on their own journey and the misconceptions they had as a university student about the field. Initially, they thought the role would involve reading security news and handling a manageable number of tasks. However, they discovered that organizational barriers and complexities are significant in the cybersecurity industry. The speaker expresses a sense of disappointment as they realized the reality of the job market and the gap between the skills learned in university and the experience demanded by employers. They challenge the notion of a skills shortage, suggesting it's more of an experience gap, with entry-level positions being scarce and competitive.

05:01

🏢 Navigating Organizational Challenges in Cybersecurity

In the second paragraph, the speaker delves into the organizational and cultural aspects of cybersecurity, emphasizing that company culture and leadership attitudes significantly impact the success of a security team. They discuss the difficulty of assessing these factors as an outsider and the complexity of internal tools and processes within an organization. The speaker also touches on the reactive nature of some companies' approach to security, often increasing efforts only after a breach occurs. This leads to a cycle of minimal investment followed by a sudden ramp-up, highlighting the intricacies of working in the cybersecurity field and the importance of understanding organizational dynamics.

10:01

🔥 The Grind and Burnout in Cybersecurity

The final paragraph addresses the personal toll of working in cybersecurity, focusing on the continuous learning required to stay current in the field. The speaker talks about the overwhelming amount of information and the pressure to keep up with evolving technologies and tactics. They describe the potential for burnout due to the repetitive nature of certain tasks, especially at the entry level. The speaker acknowledges the challenges but also the rewards of the career, urging others to consider their experiences and to approach the field with a balanced perspective, taking care of their mental, physical, and emotional well-being.

Mindmap

Keywords

💡Influencer Bandwagon

The term 'influencer bandwagon' refers to the trend of individuals joining popular social media trends or themes to gain attention or followers. In the context of the video, the speaker is acknowledging that they are participating in a common type of content, which is comparing 'reality versus expectation' in various scenarios, including cybersecurity careers.

💡Cybersecurity

Cybersecurity is the practice of protecting internet-connected systems, including hardware, software, and data, from attack, damage, or unauthorized access. The video discusses the realities and expectations of a career in cybersecurity, highlighting the complexities and challenges faced by professionals in this field.

💡Skills Shortage Gap

The 'skills shortage gap' refers to a situation where there is a lack of qualified individuals to fill available positions within a particular industry. The video script mentions this concept, suggesting that while there is a perceived need for cybersecurity professionals, the reality is that there may be more of a 'talent or experience gap' where companies seek experienced individuals rather than just those with the skills.

💡Triage

In the context of cybersecurity, 'triage' refers to the process of prioritizing and categorizing security incidents or tickets based on their severity and urgency. The video script uses this term to illustrate the day-to-day tasks that a cybersecurity professional might expect, which can be more complex and time-consuming than initially thought.

💡Organizational Barriers

Organizational barriers are internal obstacles within a company that can hinder the effectiveness of processes or initiatives, such as cybersecurity measures. The video discusses how these barriers can make the role of a cybersecurity professional more challenging, as they must navigate company culture, policies, and procedures.

💡Experience Gap

The 'experience gap' in the video refers to the difference between the number of job openings and the availability of professionals with the necessary work experience in cybersecurity. It suggests that while there is a demand for cybersecurity professionals, the industry may be overlooking potential talent due to a focus on experience rather than skills.

💡Company Culture

Company culture refers to the shared values, attitudes, and behaviors that characterize a particular organization. In the video, it is mentioned as a significant factor that can influence the success of a cybersecurity department, as it can affect the organization's approach to and investment in security measures.

💡Informational Overload

Informational overload occurs when an individual is exposed to more information than they can effectively process or manage. The video script discusses this concept in relation to the cybersecurity field, where professionals must continually learn about new threats, technologies, and industry trends to stay current.

💡Burnout

Burnout is a state of chronic stress and exhaustion, often resulting from prolonged high-intensity work. The video mentions 'daily burnout or grind' to describe the potential emotional and mental toll that a cybersecurity career can take on an individual, especially due to the demanding nature of the work and the constant need to learn and adapt.

💡Entry-Level Jobs

Entry-level jobs are positions that are designed for individuals who are new to a profession and typically require minimal prior experience. The video script discusses the challenges of finding entry-level cybersecurity jobs, noting that they may be scarce or竞争激烈, and that the reality of such positions may involve repetitive tasks and a steep learning curve.

Highlights

The video discusses the reality versus expectation of cybersecurity careers, aiming to provide a realistic perspective for newcomers.

The creator reflects on their third year in cybersecurity, realizing the complexity and barriers within the industry.

A common misconception is that cybersecurity has a skills shortage; instead, it's more of an experience gap.

Despite the high demand for cybersecurity professionals, entry-level jobs are competitive and hard to secure.

The reality of cybersecurity jobs is that they require not just technical skills but also the ability to navigate organizational complexities.

Company culture and leadership attitudes significantly impact the success of a security team within an organization.

The video points out the difficulty of assessing company culture as an outsider and the importance of internal company processes.

Cybersecurity professionals often face the challenge of informational overload and the need for continuous learning.

The video creator emphasizes the personal struggle with burnout due to the ever-evolving nature of cybersecurity.

Repetitive tasks and the daily grind can lead to a sense of burnout in cybersecurity roles.

The video encourages viewers to approach cybersecurity careers with a balanced view, acknowledging both challenges and rewards.

The creator shares their personal experience of feeling the pressure to constantly learn and adapt in the cybersecurity field.

The video serves as a cautionary tale for those considering a career in cybersecurity, highlighting the need for mental and emotional well-being.

A call to action for viewers to share their own experiences with cybersecurity careers in the comments section.

The video concludes with a reminder to maintain a holistic approach to well-being while pursuing a career in cybersecurity.

Transcripts

play00:00

all right so I'm hopping on the typical

play00:01

influencer bandwagon with dumb video

play00:04

ideas like reality versus expectation

play00:07

but in today's video I thought you know

play00:09

as I enter into my third year and I've

play00:12

had these conceptions of cyber security

play00:14

careers I thought that I would create

play00:17

this video as bandwagon as it is uh to

play00:21

talk about cyber security realities

play00:24

versus the expectation and uh as I grow

play00:27

into this career I realized that there's

play00:29

lots of things that I don't know as a

play00:31

university student entering into cyber

play00:34

security I had a picture of what the

play00:36

ideal day-to-day would look like maybe

play00:38

you read some security news triage some

play00:40

tickets and maybe call it a day uh but

play00:43

what I found is that there is a lot of

play00:45

complexity and barriers when you are in

play00:48

an organization and approaching security

play00:52

with people and As I Grew into this role

play00:55

I felt like disappointed as I looked at

play00:58

a queue of tickets in real realize that

play01:01

there's a lot of organizational barriers

play01:03

that cyber security has that you

play01:05

otherwise wouldn't have so in today's

play01:07

video I'm going to be talking about

play01:09

three expectations versus the realities

play01:12

and this is subject to change as I

play01:16

continue to learn new things but as a

play01:19

university student or as maybe a

play01:22

perspective individual looking into this

play01:25

industry these are three realities or

play01:28

expectations that I would just keep in m

play01:30

in the back of your head now these may

play01:32

seem like kind of overly negative and

play01:33

I'm not trying to be a negative

play01:35

individual here I think that there are

play01:38

super positive things about this career

play01:40

so starting out with expectation versus

play01:42

reality 1 it's it's really the skills

play01:44

shortage Gap we know that cyber security

play01:48

marketing uh circles around the skills

play01:51

shortage Gap and how many unopened six

play01:54

figure jobs there are within this

play01:57

industry you look at universities

play02:00

marketing programs uh or boot camps and

play02:04

courses and they'll tell you hey there

play02:06

are 4 and a half million opening jobs

play02:10

projected by

play02:11

2030 and you think okay this is the

play02:14

career I can get into uh and then you

play02:18

start to learn the curriculum perhaps

play02:20

pursue some certifications or maybe get

play02:23

a University degree like I did myself

play02:25

and you realize that um it's a lot

play02:29

harder than actually looks uh well it's

play02:31

an illusion so as a university student I

play02:35

had the expectation that I would be able

play02:39

to have job opportunities coming out of

play02:42

school and when I applied online to

play02:47

online job search engine websites I

play02:50

realized it's a lot harder than it looks

play02:53

I expected I had this relatively easy

play02:55

time I had this resume I had a

play02:58

University degree maybe a few

play02:59

certifications which I had at the time

play03:01

and I thought that I would be a decent

play03:04

candidate but what a lot of recruiters

play03:06

are looking for is experienced

play03:10

professionals and this is where kind of

play03:11

my controversial opinion comes in is

play03:14

that cyber security really doesn't have

play03:15

a skills shortage Gap or maybe that's

play03:18

the wrong phrasing um it's more of a

play03:22

talent or experience Gap that uh cyber

play03:26

security has there are lots of students

play03:29

and individuals which may possess the

play03:32

skills or the potential with their

play03:34

skills to go out and add value to an

play03:37

Enterprise but what you find is that

play03:40

recruiters cyber security managers and

play03:43

companies in general are looking for

play03:45

people who have already tenure with it

play03:48

and specifically cyber security and

play03:51

they're pretty stringent on their

play03:53

requirements depending on which types of

play03:55

company or sector you're looking into uh

play03:58

so I think that that there's this

play04:00

reality versus expectation where the

play04:03

expectation is you'll have multiple

play04:05

high-paying job offers but the reality

play04:07

is it's very competitive for those

play04:10

high-paying jobs you have to have and

play04:12

possess the skills and potential and

play04:14

ultimately um the realities are cyber

play04:17

security jobs entry-level cybercity jobs

play04:20

they may not exist or they may depending

play04:22

on who you ask and they're hard to get

play04:25

and I am not going to minimize that

play04:27

within any of my videos they are are

play04:30

difficult they're not impossible but

play04:31

they're difficult this transitions me

play04:33

into expectation versus reality which is

play04:36

adding value day one or even adding

play04:40

value year one um so when you look at

play04:43

cyber security it's as much of an

play04:46

organizational or cultural issue as it

play04:49

is an actual technical tooling

play04:52

implementation type thing um you know

play04:55

company culture and attitudes towards

play04:57

security ultimately will determine how

play05:00

your department your security team and

play05:03

you are successful within the

play05:05

organization leaderships General

play05:07

awareness and risk tolerance towards

play05:10

security often shape how it's going to

play05:14

look within your industry and this can

play05:16

be really hard to assess as an outside

play05:19

candidate unless you have maybe some

play05:21

contacts inside who can tell you the

play05:23

company culture um so as an individual

play05:27

when you get into your organization

play05:30

what you'll find is that not only is the

play05:33

attitude important but it's also this

play05:35

organizational complexity where you have

play05:38

these internal tools that you're trying

play05:40

to learn from a company how they uh deal

play05:44

with processes in general and just their

play05:48

overall approach to security and um

play05:53

again depending on the industry or

play05:54

sector you're in some of them some of

play05:56

them are going to be more more risk

play05:58

tolerant than others and more aware um

play06:01

often times and we've seen this time and

play06:03

time again it's basically a company puts

play06:07

maybe minimal effort into their security

play06:09

program with in terms of budgeting uh

play06:12

personnel and training and then they get

play06:15

hit by ransomware they get breached and

play06:17

then they upramp the entire budget or

play06:20

the security program and that cycle kind

play06:23

of continues over and over again uh so

play06:25

there's this level of complexity that I

play06:28

didn't really realize going in is that

play06:30

it's not

play06:31

necessarily how can I write this bash

play06:34

script to automate this really cool

play06:37

configuration it's like that's cool but

play06:40

unfortunately there's a lot of

play06:41

organizational red tape and barriers in

play06:44

Enterprises and that's just inherent to

play06:47

working with people it's difficult and

play06:50

complex and then finally for expectation

play06:53

reality 3 I created a video recently

play06:57

about this and I've been really feeling

play06:59

this this year and that is just the

play07:02

daily burnout or grind you know you look

play07:05

at a lot of YouTubers marketing you know

play07:08

they're sitting there on their cool

play07:09

computers they're you know typing away

play07:12

cool awesome things and it just seems so

play07:16

trendy and cool to be a hacker or to be

play07:19

an information security professional but

play07:22

what you realize very quickly is just

play07:25

the amount of information that you have

play07:28

to continue to learn you know including

play07:31

just like the advanced attack techniques

play07:34

procedures defenses new technology and

play07:36

navigating all the different buzzwords

play07:38

you're going to have defense in depth or

play07:40

zero trust or you're going to have all

play07:42

these different buzzwords that you don't

play07:44

really need to know but you kind of need

play07:46

to know it's it's tough and the

play07:49

informational overload and complexity

play07:53

can consume you uh for me personally I

play07:57

feel in my life is that if I'm not

play08:00

learning or if I'm not doing something

play08:02

industry cyber security related I'm not

play08:05

growing and not only that but I'm

play08:06

falling behind uh and then that's a

play08:09

personal uh issue that I have to deal

play08:11

with but I think a lot of individuals

play08:13

feel that to some extent in themselves

play08:16

one must continue to learn in this ever

play08:19

evolving industry and not only that but

play08:22

the tasks that you're doing especially

play08:24

from an entry level perspective

play08:26

depending on where you're at with in

play08:27

security can be very repetitive you know

play08:30

it could be account provisioning or

play08:32

responding to lowlevel incidents in a

play08:35

sock there's a lot of different nuances

play08:39

with entrylevel security careers but

play08:42

ultimately you're going to have this

play08:43

Daily Grind or burnout and it just it

play08:47

eats your soul eventually and I I think

play08:49

I haven't really felt that until about

play08:52

year or two in this industry and and now

play08:55

I'm kind of kind of thinking like what

play08:57

how do I actually approach this because

play09:00

this is my career I don't regret getting

play09:03

into it but it's it's just something you

play09:05

have to deal with so you know the

play09:07

ultimately the moral story is you know

play09:09

don't trust or look at individuals on

play09:12

YouTube with a little bit of a lens uh

play09:14

including myself right I think everyone

play09:16

has to feed the YouTube algorithm but

play09:19

you you have to make sure that you are

play09:21

going into this perspective of yeah

play09:25

there's a lot of challenges and there's

play09:26

a lot of good things and it's just a

play09:28

balance between what you are looking for

play09:31

so yeah that's my generic bandwagon

play09:34

video on the reality versus expectations

play09:36

this is subject to change as I learn and

play09:41

grow in new ways in this industry and I

play09:44

think that everyone has their own unique

play09:47

experience so what is your experience

play09:50

with cyber security careers are you

play09:52

trying to get into it are you a student

play09:53

are you an industry professional leave a

play09:55

comment in the description or in the

play09:57

comment section below this security

play09:59

industry ultimately is a very rewarding

play10:01

career path and um I I do think that

play10:04

ultimately it's still the career I want

play10:07

to be in um so make sure to take care of

play10:10

yourself mentally physically emotionally

play10:13

and well yeah until the next time have a

play10:16

good day

Rate This

5.0 / 5 (0 votes)

Related Tags
CybersecurityCareer AdviceReality CheckSkills GapJob MarketIndustry InsightsEducational GapOrganizational BarriersCareer GrowthProfessional Burnout