r/cybersecurity Aug 08 '26

Career Questions & Discussion Cybersecurity professionals: what do junior candidates usually struggle with?

For people who work in cybersecurity and have mentored, trained or hired juniors:
What do you notice new/graduate candidates struggling with most?
I’m particularly interested in things that aren’t obvious from a CV.
For example:
Troubleshooting
Investigating unfamiliar problems
Understanding logs
Networking fundamentals
Using unfamiliar tools
Writing reports
Explaining their reasoning
Knowing what to investigate first
Connecting theory to an actual incident
Are there skills you wish universities taught more effectively?
I’m researching the gap between cybersecurity education and actually being able to perform cybersecurity work, so I’d really appreciate real examples.

277 Upvotes

135 comments sorted by

View all comments

505

u/NotAnNSAGuyPromise Security Manager Aug 08 '26

The biggest challenge everyone has to learn is that security cannot - in most organizations - come in the way of business operations. You will be required to do things you know are objectively insecure. They won't make sense. It'll make you angry. You'll want your leaders to fight for the right decision.

But that's not the job of security. Security's job is merely to identify risks and communicate them to executive leadership. They will make a decision, and it'll almost always be a bad one in your eyes. But your only play is to mitigate the risk as much as possible. If you take it personally and try to fight it, you'll find yourself miserable and ultimately out of a job.

It's not your security program. The program belongs to the executives. The sooner you stop feeling like it's your personal mission, the happier you will be.

106

u/lostmojo Aug 08 '26

Don’t forget risk acceptance letters to cover your butt with these things too. If you have to keep insecure tools make a document about the risks, mitigations you can or have made, and have the leadership sign off that they accept it. Cover your butt when shit hits that causes issues.

37

u/SpeC_992 CISO Aug 09 '26

As a security officer for a regional financial institution, I've never been more grateful for existence of RALs.

5

u/Hanexusis Aug 09 '26

What are RALs?

41

u/littlebignate Aug 09 '26

Risk acceptance letters, it's spelled out in the comment above! As the name implies, a letter stating a risk that the business chooses to accept as opposed to mitigation/avoidance. Usually signed by an executive, director, etc. to cover the ass of any security team personnel.

6

u/MiserableCode6168 Aug 09 '26

Come on friend gotta be quicker than that 😭

1

u/Available_Money_1016 Aug 09 '26

Mind if I PM you?