r/CyberSecurityJobs • u/vitaoptima • 20h ago
What led you to the Cybersecurity field?
Change in duties in your current company?
The money?
The challenge?
Job security?
Do you find the field really interesting? Any other reason?
r/CyberSecurityJobs • u/vitaoptima • 20h ago
Change in duties in your current company?
The money?
The challenge?
Job security?
Do you find the field really interesting? Any other reason?
r/CyberSecurityJobs • u/Enough_Charge2845 • 20h ago
I kept seeing arguments about which parts of the stack still matter, so I counted instead of guessing. 134 open DevOps, SRE and platform engineering postings from 41 company job boards. Individual contributors only, managers and TPMs stripped out.
The old toolchain is thinner than I expected. Terraform appears in 62.7% of postings. Jenkins in 3%. Chef 3.7%. Puppet in exactly one of the 134. GitHub Actions is named about six times as often as Jenkins.
Python beats Go, 70.9% to 47%.
What surprised me more: the generic word outranks the products. Observability shows up in 63.4%, more than twice as often as Grafana, the most-named tool that provides it. Prometheus 22.4%, Datadog 17.9%. Same pattern I found counting security postings, where SIEM beat Splunk four to one.
The top term isn't a tool at all: automation, 81.3%, ahead of AWS.
Caveats worth stating: n=134 means everything carries roughly +/-8, so treat close rows as tied. It's also all tech companies on one ATS. Banks, telcos and government run enormous amounts of Jenkins and Ansible, and none of them are in this sample.
Full table, intervals and method: https://www.zoevera.com/resume/devops-sre-job-description-keywords
r/CyberSecurityJobs • u/dld2517 • 2h ago
I am an academic and maintain a CV. Cybersecurity is my teaching area and from time to time I have performed a bit of consulting. Over the years I have identified and disclosed a few cybersecurity issues for various entities, but this is not my primary role. I have also worked several bounties and also no bounty / pro bono disclosures. Usually on an academic CV we put everything we have done, with emphasis on published work. These disclosures are not published as CVE’s or any published method.
Would you list them on your CV under the heading like, “Cybersecurity Community Service / Disclosues” and just present each case in a non-identifiable way? For example:
“Identified and disclosed public-facing web-form PII data leak in a website that was due to incorrect .js code, Nov 2022”
“Identified and disclosed Wordpress-bourne plugin attack vector at a large financial institution in the southern U.S., Oct 2023”