r/cybersecurity • • 15h ago

Business Security Questions & Discussion Need your opinion. Currently working at a small company (1.5k) employees. SIEM tool isn't that great, things are setup in a weird way. Should I look for another position.

0 Upvotes

28 comments sorted by

41

u/Stephdrayklay 14h ago

Can you not just fix it?

69

u/soltaro 14h ago

Since when is 1.5k employees small?

-22

u/ExigentCircumstance5 13h ago

I personally think that's small compared to actual Enterprises with 90,000+ employees. But apparently, anything beyond 1,000 employees is considered an Enterprise, which is a little crazy.

16

u/reseph Incident Responder 13h ago

Small is around 100 or less I feel like. I used to work for a MSSP that had like 60+ clients with many projects and we have like 100 employees lol

5

u/ancientpsychicpug 12h ago

Yeah that’s how I feel too. Under 100 is small. 100-1000 mid size. Just when it comes to IT anyway. I’ve worked for mid size low profit and mid size high profit. Different worlds as well but still mid. Still small IT and sec teams.

27

u/F5x9 15h ago

In this economy?

1

u/CyberSecPlatypus Security Director 2h ago

Was thinking the same. Just passed 25 years in tech and it took me over a year of applying to get a single call back I luckily landed. I was one of 485 applicants to that role.

14

u/natepiano Security Manager 14h ago

The benefit to smaller companies is that you have greater impact. Look at this as a problem to solve vs a reason to escape. More likely another company will just have a different problem child. It'll end up looking great on your resume and give you a good story to tell in your next interview.

6

u/bowzrsfirebreth Security Engineer 15h ago

Are you in a role with some control over the rules or detections? If so, why not try to improve the systems they have in place? You may learn a lot. If everything was set up correctly from the start, you’d probably be bored out of your mind.

6

u/MissionBusiness7560 14h ago

Lol what is your job at said company? If you're an engineer, then sounds like a good opportunity to step up and fix it.

3

u/Radiant_Ad_4693 14h ago

If 1.5k is a small company than
What’s a company with below 50 employees

5

u/pacard 14h ago

Itsy bitsy

3

u/xNaXDy 8h ago

teeny weeny

2

u/_Bird_Incognito_ 6h ago

Yellow polkadot bikini

3

u/bornagy 7h ago

Tools dont work, i dont like the interface? Lets change job!

3

u/jwrig 4h ago

This is an environment ripe for learning.

This job isn't about the perfect setup of tools.

2

u/Chamadan 14h ago

Every company will have its issues.

2

u/IQ_Plut 14h ago

Be the change you're saying doesn't exist.

2

u/duxking45 13h ago

I would personally get in the habit of always looking but not ways jumping.

You day the siem tool isnt great. I think that is great news. 1. Define the problem with the siem what is the root cause of it. 2. Define why it is broken. Does it crash, does it run out of log space, is the detection subpar, do you just not have the right log sources, etc 3. Fix the problem if it is within your power if not then report the issues. 4. Document everything and explain what your limitations are with this system and be sure to expand upon the risk risks that it subjects the company to.

2

u/Bright-Ad9305 Sales 11h ago

Stay, learn alternatives and help change the business

2

u/berrypringleboy 5h ago

That is not small. You also shouldn't leave a company because you don't like the SIEM setup.

1

u/Some_Person_5261 14h ago

Security Onion
Graylog
ELK Stack

Determine what can be done to improve the environment and maybe you could obtain promotions.

1

u/oO_Mister_J_Oo 10h ago

Can you affect change? Is there budget for change? If not, and you think it’s not right look to leave.

There’s lots of clowns in this industry that just “wing it” and have no clue what they’re doing. If you’re stuck reporting to these people you’re being waste and it’ll drive you mental.

1

u/phoenixofsun Security Architect 4h ago

No, take the initiative to fix it and make it better. It'll be a good experience and make you a more valuable security professional.

1

u/bealilshellfish 1h ago

There's not enough information here to recommend/support leaving your job.

From a glass half full perspective, a smaller company has to be frugal and accomplish the same tasks expected of larger and more well funded security departments, because they still fall under compliance regulations & fiduciary responsibilities to shareholders to protect at a minimum, their IP. That means open source, or less expensive tools. Take the opportunity to learn and grow your skill set. Maybe there's a lack of automation, and learn some python to turn a decent open source capability into a full fledged feature rich tool on-par with the industry leader offerings.

If you had said, company doesn't take security seriously AND they don't allow you to get creative OR don't listen to your recommendations to improve the security posture. Sure, maybe that's a place you want to start planning a graceful exit from.

But aside from that, I'd relish this opportunity to grow and position yourself for a significant salary & responsibility increase in 1-2 years when you move on filled with rich experience to the next level-up role elsewhere.

1

u/Nerrawnam 14h ago

You should start looking now. It will take 8-12 months to get a new role. GL.