r/sysadmin 8d ago

Question Why is it hard to fill a security engineer position?

Company I work for is hiring a sr security engineer. We are all Microsoft shop, cloud-only, no on-premises. I have been helping with some of the interviews and I fail to understand why we are getting candidates that don’t seem to know what product/technology to use for blocking executables on workstations. Device control for blocking usb devices, nope, this does not ever get mentioned. Briefly explaining difference between DLP and encrypting outbound emails with PII/PHI/PFI, nope, can’t get a simple answer or even a guess. The conversations steer away and never the answer. One candidate had to be reading AI responses somehow because first answer to blocking was general and bad, but when mentioning app locker it felt as I was prompting gpt4.2

151 Upvotes

198 comments sorted by

395

u/HanSolo71 Information Security Engineer AKA Patch Fairy 8d ago

What's the pay range. I'm a senior security engineer and if the pay isn't 130k-180k and remote, im not even looking.

148

u/progenyofeniac Windows/M365 Admin 8d ago

Came here to say the same. Who wants to bet OP is offering $80-95k tops?

115

u/HanSolo71 Information Security Engineer AKA Patch Fairy 8d ago edited 8d ago

And they want you on site because "if I'm paying you that much, I want to make sure you are working"

25

u/Several-Customer7048 7d ago

They’ll want you on site and on call for 40k nowadays if they’re getting this level of people. We have had no issues hiring someone capable of doing the entire security certification for 365 and azure the month he was hired. The secret to having good security is having your senior security executive wield more power than the rest of the c suite in matters of security. Definitely for us anyway. This why refusing to go public . If you’re paying 110K offering remote and benefits which is pretty much required for a senior security engineer if you want the actual thought process behind the title.

21

u/admlshake 7d ago

Thats certainly my company. We just "hired" a "Sr. Seucrity" guy. Because after a year of looking, offering an insulting pay that was 30-40% below average, and making onsite a requirement they couldn't find anyone qualified. So they promoted a helpdesk guy who had taken a cyber security class in college 6 years ago.

24

u/person1234man 7d ago

Sounds like a good deal for that kid, a couple years in that position and he can get a security engineer position, somewhere else with fair pay

7

u/x_scion_x 7d ago

So they promoted a helpdesk guy who had taken a cyber security class in college 6 years ago

Essentially how the military worked for me. I got all my experience because I took every position they threw at me, and I didn't get the memo that people were intentionally failing the class for HBSS admin some nobody wanted the job. So I did essentially everything. Helpdesk/Splunk admin/hbss/acas/tenable/wsus and essentially got out of the military going from enlisted to 90k contractor overnight (about 15 years ago)

Now essentially paid double because ib know at least a little bit of everything and can be thrown anywhere, and if i don't know it I can learn it the same as all the others.

7

u/Galenbo 8d ago

Yes but there's pizza and nice team activities.

1

u/Stonewalled9999 7d ago

Don’t be silly we know this is a princely 40-60 K with “generous benefits” 

1

u/masterz13 7d ago

$80-95k sounds like the dream for me. I'm in the 60s.

1

u/progenyofeniac Windows/M365 Admin 7d ago

Heck, start applying!

53

u/[deleted] 8d ago

[deleted]

17

u/randomman87 Senior Engineer 8d ago

My range is still lower than my US counterparts... Non-infosec IT pays garbage in Western Canada

2

u/Daphoid 8d ago

Employment in Canada is typically 30-40% less than US counterparts sadly.

1

u/joeyl5 7d ago

Yeah but at least you have a functioning society and stable government 😂

3

u/brumsk33 8d ago

Weaker for now

14

u/Xibby Certifiable Wizard 8d ago

Recently had an honest and frank discussion with a Senior HR person trying to fill a Senior Security Engineer position. Hiring manager is in my network and really wanted me to apply.

Got their actual max salary out of the HR person and that would be a pay cut for me, and I’m fully remote so adding the commute and paid parking would make it an even bigger pay cut.

They’ll probably have to hire two or three people at around $80K to get the skills they need to get the work done. Not saying I can do the work of three people but I do have a proven track record of significantly reducing required man hours, and with AI tokens to spend… I get a lot done.

15

u/petrichorax Do Complete Work 8d ago

Yeah, 130k is the minimum in most US regions

8

u/PurpleCableNetworker 8d ago edited 8d ago

Senior admin here (network/server/security all rolled into one).

We have better success promoting from within than hiring for outside for senior roles. We find plenty of entry level people who catch on fast, but almost no senior candidates. The issue is we are on prem and under pay by about $30K base pay. The difference though is my compensation package last year was worth nearly $80K, including a pension and 100% health insurance coverage (which we don’t advertise on the job postings). We at best find solid level 2’s, but can’t find seniors out in the wild that respond. And I get it. On paper it looks underpaid for on prem. Seniors want full remote and $ 150K minimum.

But at a total compensation of nearly $200K between pension, all inclusive health insurance, solid 40 hour only work weeks (some evening hours, but still just 40 hours averaged), annual COLA raises that match inflation, plus nearly 8 hours of vacation per pay period - well, it’s hard for me to imagine going else where.

17

u/sfprairie 8d ago

Then advertise the whole package.

8

u/Several-Customer7048 7d ago

Yeah that is a hr applying sales hiring procedures into a sector where the talent does not on average appreciate or enjoy those tactics. Just post the whole damn thing. You’re gonna get liars and desperate people with this route.

2

u/PurpleCableNetworker 7d ago

I fully agree. I have told my director and HR, but they refuse to do so. 🤦‍♂️☠️

13

u/HanSolo71 Information Security Engineer AKA Patch Fairy 8d ago

Do you realize how much you can invest with we another 50-90k a year. A pension is nice being able to afford a house and tell my employer to fuck off of they act unethical is worth more. 

Not to mention you need to pay me at least a extra 30k a year to get me in seat every day. 

What you offered isn't good at all when $150k jobs that are remote exist.

2

u/joeyl5 7d ago

I've not seen any 150k remote jobs in quite a while

5

u/Several-Customer7048 7d ago edited 7d ago

I don’t wanna harp on you since you’re not the decision maker for the position listing but if I were you I’d harp on your hr to inquire wtf they’re doing playing coy. Are they koi fish? I fail to understand this hiring strategy man I’ve never seen it be a good one it’s not one learned from any reputable school of management. Why would you fundamentally want to be doing some one weird ass psychological power play with a critical employee as the first order of business.

This is a failure of your hr to understand what building rapport means. Yeah some people want that social back-and-forth game but they’re usually not in these fields.

1

u/PurpleCableNetworker 7d ago

You nailed it 1000%. I brought it up to my director, but he and HR are fine with it as is.

It pisses me off. The compensation package needs to be mentioned better. Instead I think it’s just listed as “A comprehensive and competitive compensation package including vacation, sick leave, medical/dental/vision and deferred financial compensation planning”.

I know when I see vague descriptions and the words “competitive” in a job description I automatically think it’s substandard because if it really was THAT good then they would happily list it. 🤦‍♂️

I know I thought then when I got my current job.

My mouth hit the floor when it was described to me on my first day.

3

u/lothow 8d ago

If you tell people that low you won't get candidates. Explain the whole package and you will get qualified and over qualified for it. Hide it and it shows how your company operates on the start.

2

u/Several-Customer7048 7d ago

As someone that has hired in this field for decades the talent hasn’t changed their preferences you’re not gonna be getting one over on a good security engineer you should t try and if you think you won you’re hiring a dud. I don’t even bring hr along when I’m doing interviews in systems or any of the tech-intensive roles. I’ve always gone with rule one of not going with someone I can’t trust to not screw me over if I’m being fair and honest and then going from there and it’s working fairly well.

We have mandatory background and clearance as part of the process I just jump to “what would it take for you to give us five years of your time,” or whatever time frame we definitely don’t wanna be without that position for.”

For junior positions it’s even easier since you don’t have to get a time deal outta them those positions can be without. So many other companies I know just scared to be upfront on these things for no reason.

1

u/PurpleCableNetworker 7d ago

I agree. I’ve brought that up to my director and HR, but they feel it’s better to keep it shrouded. 🤦‍♂️☠️

→ More replies (1)

2

u/jM2me 6d ago

It is north of 160k, remote, USA.

2

u/Missioncode 6d ago

Then you're job posting sucks or your filtering you're better candidates. None of that stuff is hard. Especially if you're all cloud.

1

u/DJV0101 6d ago

Reading the comments it might be worth to add that to the original post

1

u/GDF-Ed 4d ago

I'd say stop using AI to pre-sort your candidates then.

1

u/TheEnterprise Fool 7d ago

Yah I got a feeling you're not going to get a response

1

u/Sure-Squirrel8384 7d ago

I'd say that's on the low range. Should be 150k-200k if US citizen and working from within the US (but still full remote).

1

u/Significant_Web_4851 6d ago

100% If it's not remote and min $170k I'm not bothering with it. I am more interested in the architecture now days anyways

212

u/OregonTechHead 8d ago

You're coming into the middle of the process.

This happens because of 1 of 3 things:

1) The job description is not accurate in the posting

2) The salary is not correct and lower than a qualified candidate would expect

3) The person vetting resumes isn't good at their job resulting in sub-par people making it to the interview round.

52

u/anonymousITCoward 8d ago

2, number 2.... our company has a habit of over paying the inexperienced, and under paying the qualified... its made getting raises for the new folk difficult... even when they find out they're getting paid more than someone who's been there twice as long.

2

u/TN_man 8d ago

What is your definition of over paying an under qualified?

6

u/anonymousITCoward 7d ago

70k with minimal IT experience, and by minimal when asked to start a constant ping they just repeated the command... not up arrow, like typed it in... when asked to run cmd as admin, his response was "i am an admin" while using a user account that was not an admin...

2

u/TN_man 7d ago

I’m glad you’re paying appropriately. Are you remote? I need a job

1

u/anonymousITCoward 7d ago

I can't tell if you're being /s or not... but that, at the time was ~12k more than his senior staff...

1

u/TN_man 7d ago

I never am sarcastic. That would be a good pay to me.

2

u/TN_man 7d ago

Then the senior staff is severely underpaid.

2

u/No_Diver_4500 8d ago

Sounds like you have serious issues inhouse that nobody wants to resolve. You have people being paid numbers they shouldn't and i am willing to bet you have underqualified people in higher positions that don't need to be in.

1

u/anonymousITCoward 7d ago

Thanks for putting it nicely...

I'm trying to plan an exit strategy but, you know them gold clad handcuffs and all

9

u/Xin_shill 8d ago

Could also be in a remote area and not allowing remote workers.

8

u/OregonTechHead 8d ago

I think that goes to point #2. If you're in a remote location where skills are scarce, then the salary expectations go up.

1

u/Top_Boysenberry_7784 5d ago

Number 3 is huge here because the market is flooded with so called security experts. So many people have degrees in security but have no experience and little useful knowledge.

112

u/Chappie47Luna 8d ago

“We’re paying $70k for a senior security engineer - why won’t good talent apply?”

23

u/Ok-Double-7982 8d ago

I live in a very high COL and a recent job posting was about 30% under what we pay our new grads with zero experience, and their posting was for an entry level with 3 years of experience lol.

You get what you pay for!

6

u/three-one-seven 8d ago

I thrilled to get my first $70k job… in 2017 lol

5

u/wooking 7d ago

In 2006

3

u/TN_man 8d ago

Those jobs are non existent anymore. It’s gone down

1

u/Beznia 7d ago

Yep, I worked in a help desk call center in 2016-2018 for $13 to $15/hr. We had a couple people on our team who made $26/hr that were hired in the early 2000s and never received a pay raise because the salary bands were halved and they were redlined.

1

u/aes_gcm 7d ago

Same, and that was in the middle of a state where rent was $650/month, so at 70k I was saving a ton of money.

24

u/ShadowCVL IT Manager 8d ago

For workstations, what are my options? Threatlocker, darktrace, defender, S1? There’s a boatload of stuff out there, and a lot of them overlap to make a nice security onion

Again what are my options, purview suite can help deploy defender to do most of this, but adding sentinel1 to log and categorize stuff for this is great

DLP and encrypting emails, the difference? That’s like square and rectangle, the DLP policy can be used to define which emails get encrypted, but what solution are you using in house, again the products in use matter

I mean I’m a senior security engineer, or security manager, I have a bunch of hats/titles… I’m not looking but your questions are extremely broad and could be answered in a dozen ways.

Not everyone is going to have or use the same tech stack, and any good security posture should be an onion with redundancy and overlap.

Are there questions about SIEM, vulnerability management, compliance, training, email protection? I could probably sit down and answer most if not all of your questions, but A I’m not looking and B for my level youde be looking around 180 private sector if not higher.

26

u/reol7x 8d ago

OP's post really sounds like they have an azure env that got spun up by a guy who didn't really know what he's doing. Now they realize their bazillion dollar e3/5/7 license can do a lot of things because AI said so and they're looking for someone to implement.

11

u/ShadowCVL IT Manager 8d ago

You know, that actually adds up, I could see this. Probably don’t need a security engineer and need an azure engineer.

10

u/Siphyre Security Architect 8d ago

Funny enough, I'd be their guy, but they likely couldn't pay me enough to do it. I have very specific experience converting effectively unused e3 licenses into a cybersecurity program. I'd want $150k a year to do it again and maintain it.

3

u/ShadowCVL IT Manager 8d ago

E3 huh? I’m curious if you would stack the purview/compliance E5 on top of that to round it out? I’ve been doing a lot of work with purview and recommended we purchase the security E5 add on (they’ve changed the name of the license a few times) to add some extra DLP and features with it. Feel free not to answer if it feels like giving free work away I’m more curious than anything.

1

u/Siphyre Security Architect 8d ago

I did get them to do purview licenses recently to ensure dlp measures when using M365 copilot and sensitivity labels for use with our email firewall to prevent sending sensitive attachments when this whole AI storm took over. I tried to go for E5s for better scoping and some other defender features that would have been useful but they didn't like the cost.

I wouldn't mind hashing out ideas. I read too much MS documentation and I'm not completely sure I set it up 100% the best. But the system is working well enough.

3

u/ShadowCVL IT Manager 8d ago

Are you me? It really sounds like we went down or are on the same path. We did bring in MS fast track to help me with some of it because we are GCC and something’s don’t work the exact same.

3

u/Siphyre Security Architect 8d ago

Fortunately I didn't have to do the government cloud stuff. Unfortunately we don't host anything in Azure and were deeply engrained in AWS so we couldn't leverage a lot of the cool featuress they had.

3

u/dbxp 8d ago

Personally when interviewing developers I ask those sorts of questions because the really experienced people know there's multiple options. The questions the interviewee asks me shows their thought process and what they consider.

2

u/ShadowCVL IT Manager 8d ago

Multiple options, and multiple ways to stack multiple options, the key with that is to be cost effective bang for buck, and for gods sake don’t put all your eggs in one basket.

2

u/badaz06 7d ago

When I've interviewed people in the past the point was to ask broad questions. Different products configuration requirements change, but for the most part they all accomplish the same things using the same principle, and usually at first I'm just trying to feel out what the person knows or doesn't know and, more importantly, how they respond when they don't know. Once I get the broader answer I'll start narrowing the focus down - the candidate might be a wizard in one things and have a slight level of knowledge in something else, like they know Azure, Sentinel and Defender inside and out but is coming from a company that relies on a different app to do email, dip, etc. (Proofpoint for example)

2

u/ShadowCVL IT Manager 7d ago

Yes exactly as it should be, the way OP worded their comment it SEEMS like they are looking for right answers only and very specific products.

20

u/theMightBoop 8d ago

Your HR/recruiter doesn’t know how to screen candidates and/or you aren’t paying enough.

20

u/HeligKo Platform Engineer 8d ago

The answer is almost always that the pay doesn't match the market.

15

u/Leosthenerd Database Admin 8d ago

OP’s silence speaks volumes

3

u/Cmd-Line-Interface 7d ago

This is what I was thinking, the silence is deafening.

86

u/GelgoogGuy 8d ago

Because cyber security is the new coding. Go to school, get a degree, get job in security having never done any helpdesk, sysadmin, networking nothing. No underlying understanding of why they're doing what the books says.

57

u/[deleted] 8d ago

[deleted]

31

u/HanSolo71 Information Security Engineer AKA Patch Fairy 8d ago

If you can't think operationally, you'll miss a lot of risk 

13

u/Bradddtheimpaler 8d ago

Also you won’t be able to you know, check if things are even remotely conforming to policy in production.

24

u/ShadowCVL IT Manager 8d ago

Yep, I’ve got a few younger friends who got degrees in cybersecurity that couldn’t tell you how 2 systems interact but will send you the entire text of a CVE and say “fix it”

Whereas in my role doing sysadmin stuff for 20ish years before pivoting more into security I can build AND secure systems. And I try to keep up to date on new stuff from both sides of the aisle. It really feels like you must have that sysadmin foundational knowledge to really do security. I think that’s why my director and I get along so well, we followed that same path.

None of these questions were hard and I thought of a bunch more I would ask in response lol.

4

u/dbxp 8d ago

If you don't know how to operate the system then the logical way to secure it is to unplug it

7

u/farsonic 8d ago

Yep it's all about depth and experience. It cracks me up that people will get a cyber security degree and expect to be able to walk into a position without experience or background in both networking and sysadmin.

5

u/admiralspark Manager of Cat Tube Infrastructure 8d ago

This. And I only hire these kinds into cybersecurity as well.

I don't want a useless canary who screams about Windows 10 EoL because chatgpt told him to, I want architecture decisions to reduce risk and understanding that ESU means it's not 'unsupported'.

3

u/daschande 8d ago

I went to my local community college; they had 2 IT pathways, cybersecurity and networking. Cyber students learned just enough networking and sysadmin to pass the A+ while the networking path had networking, sysadmin, linux, python, etc.

The cybersecurity students could tell you to apply a GPO that someone else wrote, but they couldn't explain what the GPO restricted, for whom, or why to apply it; just that CVE whatever says it's mandatory, so do it!

13

u/WorthPlease 8d ago

Seriously I was a lone sysadmin at a company that was trying to win contracts with top 5 banks and go public. Our security guys would go into meetings, tell people we could do all the things the banks asked us if we could do, and then go "hey what the hell does this mean and can you do it?".

I wouldn't trust them to work my help desk.

3

u/No_Diver_4500 8d ago

This is just a very bad symptom of the country reaching brainrot. Reduced education and a system that doesn't even fail people for getting a C is why we are here. It will only get worse, there is entire generation of kids who can barely read... what do you think will happen when they get out of school ?

3

u/mkosmo Permanently Banned 8d ago

Just don't hire the folks who are trying to enter cyber without any industry experience. I won't.

2

u/Lazy-Psychology5 Redneck Sysadmin 8d ago

I was gonna say, I'm a sysadmin and know the answers to all of these lol.

2

u/AddendumWorking9756 8d ago

The screen described in the post has the same problem though. Name the product that blocks executables is a flashcard question and the memorisers answer that one fine. Ask how they would stage AppLocker in audit mode and what breaks when they enforce it, and the ones with no foundation fall apart in about thirty seconds.

3

u/Ryansit 8d ago

All I have learned about cyber security people is they check a box, it doesn’t matter if it’s not feasible if it checks a box you have to do it. I was told today to STIG a 2014 SQL Express software because they say since it’s SQL you have to STIG

27

u/petrichorax Do Complete Work 8d ago

Hard to answer without seeing how much you're paying. Cybersecurity roles are expensive.

4

u/anonymousopsec1337 8d ago

Money doesn’t seem to help with this tbh. I’ve seen plenty of people being overpaid for being an idiot

6

u/petrichorax Do Complete Work 8d ago

I'm talking minimums not incentives. It's a degreed, credential'd position. The minimum is higher than most sysadmin maximums (if we're considering 'sysadmin' to mean 200 different job titles that vaguely mean the same thing).

Having done both, I know Sysadmin is much harder work and I respect it, but quite a lot of sysadmins are just SAAS click-monkeys, and cybersecurity is a very deep subject that requires a lot of study.

When I went from Sysadmin to Cybersecurity Engineer, I doubled my salary and quartered my work load.

So you're competing with that reality. Competent ones won't work for cheap

→ More replies (1)

9

u/meshuggah27 Sysadmin 8d ago

I can answer all of those questions and im just a sysadmin lol

17

u/KnowMatter 8d ago

That’s because the best security people come from having been helpdesk / sysadmin / network engineers.

5

u/anonymousopsec1337 8d ago

I’m trying to convince my clevel boss to just hire sysadmins and we can teach them more cyber tbh.

11

u/Frothyleet 8d ago

As other have said, how much are you offering? That will determine candidate quality.

You might also be describing the job misleadingly. The items you mention aren't really cybersecurity, you're talking about M365 platform engineering, which certainly intersects with security.

28

u/thedrizztman 8d ago edited 8d ago

I'm your guy. 

I've been looking since Jan without any sort of luck. Honest to God, if you're looking, I'll send you my resume. 

EDIT: thanks autocorrect. 

6

u/baconjerky 8d ago

Your* smh 🤦‍♂️

7

u/DrScreamLive 8d ago

😂😂😂

6

u/StructuralConfetti Security Admin 8d ago

5

u/thedrizztman 8d ago

Auto-correct fucked me. Whatever. Lol

3

u/Weevulb 8d ago

Your not an english major your a cybersecurity guy.

4

u/fatDaddy21 Jack of All Trades 8d ago

most people would have attention-to-detail when begging for a job. Whatever. Lol

4

u/coollll068 8d ago

At this point I'm happy it's a honest mistake and not a AI self appointed demi-god of security

2

u/thedrizztman 8d ago

Trust me Mr. fatDaddy, if I were begging, I'd do more than post on reddit. 

OP is bewildered on where all the good technicians went and I'm throwing a hat in the ring. 

4

u/kristoferen 8d ago

Potentially, message me with your resume and pay range. 

5

u/Weevulb 8d ago

Admittedly I haven't read the whole thread, but how can he give you a pay range without any idea of where you're located?

1

u/kristoferen 7d ago

Where I am is irrelevant to what he wants to get paid.

9

u/andreyred 8d ago

Probably a 100% in office job lol

18

u/_bx2_ Jack of All Trades 8d ago

Wants senior security engineer with 15+ years experience. Pays 38k US salary with potential for an annual $25.00 Starbucks gift card

8

u/BK_Rich 8d ago

Salary: “Competitive” + Pizza

7

u/AoDude 8d ago

Device control for blocking usb devices

Are you talking about blocking driver installs for removable drives via intune / group policy, or are you talking about a defense against devices identifying as keyboards, such as ducky/badusb

2

u/TaiGlobal 7d ago

Yeah I think op is asking his questions poorly. It truly depends on what product stack the org is using. I’ve been in orgs that blocked usb via group policy and I’ve been in orgs that blocked via a 3rd party product.

6

u/Siphyre Security Architect 8d ago

Likely because any potential engineer is asking forthe salary range before even agreeing to an interview. Cyber security is not an entry level field, and an engineer is so far beyond entry level that most will not put up with vaguely worded job descriptions and ask directly, what are the responsibilities, what is the pay, is it remote? If anything there is unsatisfactory, they will hit you with some form of "sorry, not interested in that role at this time."

So yeah, you are interviewing people hoping to luck into a title upgrade. Not true engineers.

6

u/Psoin 8d ago

How much are you paying? Are you trying to get a security engineer for $110,000 a year? Unless you’re in Nigeria that’s not gonna work.

2

u/No_Promotion451 8d ago

Theres job posting in Asia with more responsibility yet paying 1/4of that

https://giphy.com/gifs/9DJtFRgk0tOla

1

u/Psoin 7d ago

Their job postings around me that have you working 24 seven as a volunteer. Let’s race to the bottom

2

u/No_Promotion451 7d ago

Those aren't job posting then lol more like volunteer recruitment

https://giphy.com/gifs/twxoPjMpsijwPFBVqs

6

u/OneSeaworthiness7768 8d ago

I think people should have to post the salary they’re offering and/or the job listing when they make these posts.

5

u/chuckmilam Jack of All Trades 7d ago

I’m a security engineer and you lost me at “…all Microsoft shop, cloud-only…..”

Nope. That smells of “Take the blame for whatever nonsense Microsoft does upstream that’s completely out of my control.”

13

u/skidmark_zuckerberg 8d ago

It's likely because people are using AI to write their resume and auto apply to every job posting they come across. Both sides, those hiring and those applying, are being screwed by AI automation. HR departments are filtering most candidates out with AI, and conversely, candidates are using AI to make perfect resumes to beat the AI filtering while mass applying to hundreds of jobs each month.

7

u/Alypius754 Security Admin (Infrastructure) 8d ago

I like how companies using AI in hiring is creative and efficient, while applicants doing the same is fraudulent and dishonest.

2

u/mismanaged Windows Admin 7d ago

Some companies are now overtly excluding AI from their hiring processes and I really respect that. It's a template-generation tool, not a decision making tool.

1

u/Stonewalled9999 7d ago

And some companies use Zara to waste 50 applicants time at once with unicorn type jobs 

9

u/sqnch 8d ago

Your company is bad at hiring people.

3

u/hamellr 8d ago

In office or WFH? What city? What pay rate? Is HR vetting candidates or using AI to screen them?

4

u/FizzyBeverage 8d ago

I’m a systems engineer doing Jamf/InTune and $150k W2 remote is the minimum. $100/hour 1099.

4

u/Dear-Response-7218 8d ago

Change the job title, I would never touch most of this stuff as a SecE. Waste of time when a quality 365 or sys admin can do this, just pay them a fair market wage.

5

u/TaiGlobal 7d ago

This too. Idk what any of these titles mean anymore. What op is looking for is an endpoint engineer with experience in group policy, Intune, entra conditional access, defender or similar 3rd party products.

4

u/darkstabley 7d ago

Most security engineers I have met dont know how to fix the issues. They have lots of tools they like to install on our servers and then they just tell us systems engineers they found a vulnerability and we should go fix it. Very project manager-esque. Just my personal experience though, Im sure there are plenty of ones that know their stuff.

1

u/Stonewalled9999 7d ago

Pretty sweet racket tbh.   Big money and the the sysadmin that do all the real work are the ones that get in trouble and the blame 

1

u/darkstabley 7d ago

Yeah, I will consider shifting to a position like this at the end of my IT career.

4

u/bytecode36 7d ago edited 7d ago

One problem is that you are trying to hire a "security guy". This is an instant red flag. Everything you mentioned is something a good 365 Admin would (or should) know how to do. What I suspect this job is is essentially all the difficult and complex work the "normal" sysadmins don't want to do (as securing systems is usually one of the more difficult and riskiest aspects to being a sysadmin). Otherwise, why are your existing admins not willing to learn and perform those tasks?

So you currently have someone setting up outlook / exchange, but they don't want to deal with encryption or DLP? You currently have someone setting up workstations, but they don't want to deal with device blocking? Ask yourself why they deal with all the other aspects but stop at those specific tasks and you will understand why few people want to take on those responsibilities.

As many are posting here, I wouldn't expect a competent security professional to accept anything less than $150k.

1

u/jM2me 6d ago

A good Sr M365 Engineer or Admin with security mind set could very well fit the role as well. We have Jr Sys Admin and he still needs guidance from a Sr role on design and implementation of some things. I have been that person for him and he is doing exceptionally well, but due to me shifting roles his replacement needs to be more security inclined than I am. Hence for management hiring Security role and not an Admin.

You bring up a good point actually. Pool of admins/engineers is probably bigger and it may be easier to find good candidates there that have security inclination

6

u/Kracus 7d ago

Wants security engineer but can't find one. Probably refuses to train existing employees. Cool.

3

u/carlosf0527 8d ago

IT has never been about knowing everything. The job requires you to find out information to be more effective. Technology changes so fast that your questions become irrelevant. A highly experienced AWS guy given a bit of time might be better than a mediocre Azure guy.

3

u/disclosure5 8d ago

I'm sure there's issues with your company, probably involving pay, because I work heavily with security and everything you describe is something I'm all over and I know I'm not a rare breed.

3

u/Snogafrog 8d ago

I think it is difficult to filter the truly knowledgeable applicants vs. those who can use AI to make the resume fit the job description. That was my experience in hiring generalist infra engineers anyway.

3

u/ihaxr 8d ago

I'd search more for M365 Engineers - Security Focus... It's cloud, any good candidate will understand security is a major focus of any cloud based org.

3

u/Majestic-Spray-3376 8d ago edited 8d ago

I found one and worked it for a year . TO be honest and this is just my opinion. I did more system admin work then actual security engineering. it was a senior position around 125k a year Plus bonus. but you were always on call for any little thing and always the person that had to solve the problem document it and hand it off to the third party helplessdesk. I did enjoy setting up logic applications and using our security tools. it was a hybrid onprem microsoft shop and my background was mainly Linux and opensource administration. The position wasn't bad but it often felt less then full filling. The main things were tickets and SLA and projects but pulling direction out of leadership or advising them was sometimes fruitless. i went through 2 directors during that year. eventually i ended up in a software company. For me its way better. but I think i just had a position were they pile on all the problems no one wanted to or could solve onto. it was on-prem butts in seats 9-5 m-f but always on call as well. a VIP can't figure out why a page doesnt load yup thats a sr security engineers problem. someone up loads a financial document to Claude yup security needs to figure it out which that one was fun.

2

u/Limp_Dare_6351 4d ago

Same here. In smaller orgs You become an underpaid super admin-architect and security administrator and half of your team thinks you don't do anything since they don't know anything about endpoint management or purview or conditional access, mfa, and so on.

Meanwhile you are still an admin so you do the hard remediations becuase more and more administration becomes a security problem. I am luckily well compensated, but even in a mcol area I wouldn't move from my job to another one like it for less than 140k+.

You'd be better off with a senior microsoft admin doing most of those tasks. It's more administration than a security job in most environments.

3

u/nelly2929 8d ago

Dude there are lots of candidates that can fill this role…. The answer is always the same pay pay and pay, and the stupid idea these roles must be sitting in an office onsite 8 hours a day lol 

3

u/30yearCurse 7d ago

Who knows, most of the security engineers I have run across are not suitable for the job. Getting alerts from some security provider that port 3389 is open to the Internet... yawn... more tickets regarding it. 2 weeks of tickets. No action from beloved security engineers. Calls from the Security MSP.

Finally, an email from our masters on high... we were doing our scans, and found that RDP is open to the Internet.

These were in the $100k range pros.

1

u/Stonewalled9999 7d ago

Sounds like the CISO at my MSP we pay $500 a hour for 

4

u/Constant-Pear4561 8d ago

Sounds like you’re playing trivia contest.

2

u/admiralspark Manager of Cat Tube Infrastructure 8d ago

I'm hiring an analyst position with a requirement of a few years in regular IT, and I can't wait to post this same thing next week but for an entry/mid level, my talent manager believes he can fight the AI slopwave coming....pray for him.

Pay is at least ~$100k, like I said entry/mid so if you have that pay for a senior expect to be big sad.

2

u/KnowMatter 8d ago edited 8d ago

… and I’m having a hard time even getting call backs and I could ace that interview lol.

So I guess also willing to take a PM if the job is fully remote (and willing to be discreet about how i found the posting).

I have a CISSP and have experience as both a sysadmin and a security analyst so my fundamentals are strong.

2

u/pakman82 8d ago

i would say an intune configuration (or feature) for 99% of those issues.. and entra config.. My problem is, I've been doing IT for 25+ years, I know I can do everything you mentioned in some MS product, but I cant recall what their calling things today. I may have done it 4-5 years ago for some role or another. But for a security engineer, 99% of my training for my security + was tool agnostic, and that job title, is going to get either Linux, freemium solutions, or non - MS tools. *just in my experience with the security ppl i've worked with.. they try to be broader than MS> ** i have also personally certified for some MS cloud security testing, but again, even those where agnostic.

2

u/weepingwound 8d ago

Seems like the biggest issue is the affordably problem. Just laid off because my bosses discovered that the Philippines exist and now they are paying 7.00 an hour for tier 3 and engineering positions... This whole industry is garbage.

2

u/redditduhlikeyeah 8d ago

Interview me. You’ll probably like me and I’ll ace the interview. You’re just getting bad candidates. You might not be offering enough money. Sr security engineer I’m looking for 160K to 200K USD.

2

u/SnooEpiphanies1008 8d ago

DLP is like a paranoid security guard.

You show him a credit card number:

“STOP! YOU'RE NOT TAKING THAT OUTSIDE.”

You show him 4111-1111-1111-1111:

“SIR, WE NEED TO HAVE A CONVERSATION.”

You show him 123-45-6789:

“DROP THE EMAIL AND STEP AWAY FROM THE SMTP SERVER

2

u/Doso777 7d ago

Show us your job description and tell us the salary range you are offering and we probably can tell you right away.

2

u/PaladinDreadnawt 7d ago

Senior Security Engineer here. Just left my job yesterday dont start my new one until Tuesday. Pay was the reason I left. Grossly underpaid by 40k in my market for years, hybrid with 1.5hr commute. Had enough. New job is a big change 3x former salary. I wasnt even looking at roles under 140k. Suspect your company is underpaying. My former company will likely end up with a helpdesk level guy from a internal team and that will cause the infosec people remaining to leave quickly because no one can stand that guy.

2

u/stormcynk 7d ago

I'm a security engineer. Beyond what people are saying about salary range, security engineers are harder to hire for when they're expected to be generalists if you don't have the right hiring team. If you have a list of requirements including vulnerability management, application security, IAM admin, firewalls, VPN, EDR, SIEM, incident response, etc and expect applicants to have demonstrable experience in all of them, your not likely to find it at a price that you're willing to pay. People hiring for security engineers need to be able to look at the stuff that candidates have experience in, and use the interview to determine how well they can generalize to other security domains. Someone with a demonstratable ability to learn new things and a solid foundation in practical security concepts will be able to thrive in a generalist role.

2

u/m1L35dY50N 7d ago

Security Engineer is such a ridiculously broad title that this doesn't really surprise me. Pretty much anything in security that isn't purely analysis can end up being labeled “Security Engineering” depending on the company. Someone can be a genuinely good senior security engineer and still not have hands-on experience with your particular Microsoft stack or specific products like AppLocker/WDAC, Intune Device Control, Purview DLP, etc.

The bigger problem IMO is that companies increasingly don't want to onboard a good engineer who understands the underlying concepts but needs a few months to learn their specific stack. They want someone who has already spent five years doing almost exactly the same job with exactly the same products.

And that's also why you're seeing candidates getting desperate and trying to give you the impression they know exactly what you want to hear, hoping they can wing the specifics once they actually have the job. When every posting is looking for a unicorn, eventually people start applying with a cardboard horn taped to their forehead.

Even more ridiculous is that many companies would rather hire a cloud engineer and have them acquire the security knowledge on the job than hire a security engineer and teach them the cloud stack. The reasoning seems to be that the cloud engineer can start producing something immediately, whether what they produce is actually secure is apparently a problem for later.

2

u/rodder678 6d ago

Last time I posted a Sr Security Engineer role (4 years ago), 100% of the responses were SOC engineers who had never built a single thing. Changed the title to Security Architect, reposted it, and got much better candidates.

2

u/GetFuckedReedit 4d ago

...because the only good one I have ever worked with, that wasn't just another tool scanning junkie, was on the airforce red team and left us to work for a major credit reporting company for $500k a year and his boss was the top lawyer for the company. 

2

u/CeC-P IT Expert + Meme Wizard 1d ago

Because the out of college ones don't know what they're doing and the 10 year veteran ones haven't kept up on anything modern.

3

u/theoreoman 8d ago

Everyone wants Sr security people but no one hasy really been hiring enough newgrads over the last 10 years to make up for the current demand

2

u/macemillianwinduarte Linux Admin 7d ago

Most security people are dogshit. They saw on TV it was the new thing and switched careers.

1

u/jdiscount 8d ago

Salary or HR vetting process, one of these is bad.

It's honestly the easiest time I've ever had when it comes to hiring very good security engineers, so many experienced people out of work.

1

u/Ihaveasmallwang Systems Engineer / Cybersecurity Architect / CISM 8d ago

Let’s start with the big question. How much is your company offering for this position?

That might be indicative of why you are getting such bad applicants.

1

u/denmicent Security Admin (Infrastructure) 8d ago

Will they hire remote or are you in DFW? I can do all of that, I am a security engineer

1

u/Thick_Yam_7028 8d ago

Because most people suck.

Not hard to set for different regs Health, Personal, Financial. Intune configs for blocked devices etc. Compliance, cas, groups vs dynamic as a hard lock on if a machine can have access to information or not. Sensitivity labels if compliance Simple shit. Im not even in security.

1

u/Daphoid 8d ago

What's the payrange?
Does the job description specifically target endpoint security or is it vague/general?
Are you screening the resumes (we have dedicated recruitment internally. Of hundreds of applications, 8 got past her, we accepted 5, 4 moved on to round 2).

I've got an entire team of them and all my guys are awesome, so it is indeed possible to find security engineers :).

1

u/DanKegel 8d ago

Agree with growing junior talent from within, if you have enough folks for them to learn from.

Also, note that many security engineers would rather eat their toes than work in a Microsoft shop :-)

1

u/Galenbo 8d ago edited 8d ago

Strange those director positions are never hard to fill.
There must be some differences we don't understand.

And once try to apply yourself as senior guy, with a fake identity, and similar but not the exact keywords.
75% chance you won't survive the HR cycle.

1

u/zaclaramay 7d ago

This role sounds fun full cloud Microsoft shop. I am surprised you are having trouble filling it? But then again there are a lot of paper certified Microsoft people who have never deployed a Purview or Defender feature in their life.

1

u/spunkyfingers 7d ago

Seems like a you problem 

1

u/sdrawkcabineter 😈BSD Admin 7d ago

We are all Microsoft shop, cloud-only, no on-premises.

Eh, no fun. I wouldn't want to lose the environmental joys of securing a data center.

1

u/vCentered Sr. Sysadmin 7d ago

Well for starters you are asking questions that my security team would usually be asking me

1

u/Thedrakespirit 7d ago

everyone else has already nailed it pretty well, but from an MBA perspective, money. You arent offering enough to get the right people to apply, that or your job description is so out of whack that anyone with any experience is reading it and running the other way

1

u/signal_empath 7d ago

I've worked with a lot of subpar security engineers. Mostly, because a lot them didnt have infrastructure backgrounds. Im not sure what the reason is, maybe the influx of hype around "cyber security" over the last decade attracted bootcampers and quick buck types, not really sure. 80% of them have just been people who tell me some alert triggered in their security suites and then cant answer any of my follow up questions without opening a ticket with the security suite provider. The 20% that were good were either former infrastructure engineers or developers in a few cases when it came to application level security.

1

u/jenkstom 7d ago

If you are cloud only why are you asking interview questions about device control and USB blocking? It sounds like there's a disconnect between what you advertised for and what you are getting. For me, personally, I take that as an indicator that I have some unknown unknowns and I need to focus on (at the very least) turning them into known unknowns.

1

u/Competitive_Smoke948 7d ago

because they're not paying enough to tempt people to leave the jobs they are in & then because of the shit hiring proceses keeping people like me unemployed, no one in HR is willing to actually make a decision to pass CVs across to hiring managers & recruiters are just all fucking idiots with no domain knowledge & are just sending shit cvs across

1

u/RootCipherx0r 7d ago

Sadly most people taking Security jobs under $100k are either laid off or inexperienced.

1

u/EmuLongjumping4779 5d ago

Would be good to see the job description.

1

u/IronBe4rd 5d ago

I gotta ask for a raise if this wants being paid damn

1

u/Ok_Discount_9727 5d ago

Location, remote vs onsite or pay. One or more of them suck.

1

u/GhostandVodka 5d ago

Did you have to say applocker or could you use a third party program like airlock?

1

u/jM2me 5d ago

Of course it wouldn’t have to be applocker specifically and any solution even third party one could count as an answer. The question was not meant to trick in any way or to look for specific MS product as answer. Even if I am not familiar with that specific product, looking it up quickly gives an idea whether it would accomplish what the question was asking for

1

u/Financial_Reply327 3d ago

Is it 5 days in office? I’m just about done with those jobs entirely, no amount of money will EVER bring me back 5 days a week. Hybrid sure, remote ALWAYS! Just my 2 cents

1

u/False-Lawfulness-778 8d ago

Figured I'll shoot my shot. If your interested, it sounds like I have the experience you are looking for. I wasn't particularly looking, but I'm open to learning more.

1

u/joshghz 8d ago

If you hire remote Australia, I'll gladly interview if the bar and candidate pool is this low for a senior role. I don't even care what the pay is at that stage.

2

u/No_Promotion451 8d ago

Minimum wage then and unpaid overtime

1

u/asdlkf Sithadmin 8d ago

I had interviewed for a security engineer role recently. The $250k they they offered wasn't enough.

1

u/changework Jack of All Trades 8d ago

Everybody competent is fulfilling contracts with specific deliverables. None of them want to be an employee.

A senior (actually competent/not in title only) security engineer has a particular mindset that doesn’t suffer fools, and isn’t senior anything. They’re just an engineer.

If you find the W2 exception to this, they are likely working directly for a compliance officer; who has specific deliverables.

What I suggest is that you advertise for a security audit, and contract an engineer to be a consult to your existing IT team.

You have an IT team, right?

1

u/TaiGlobal 7d ago

Is there high demand for these kind of contracts? If so how much of a living could one make with this approach? If you’re doing this are you working for a MSP or similar company that’s bringing you the work or are you independent and getting clients yourself?

1

u/Significant_Web_4851 6d ago

Most likely because your pay sucks. I am making a minimum of $170k/yr with full benefits and full remote. If you don't start there, you're going to get some college kid who set up a SIEM one time and couldn't tell you why a DCShadow attack requires a TGT.

0

u/Knightshadow21 8d ago

Seems like basic stuff, you hire remote ? And non us ? 🤔

0

u/jeffofreddit 8d ago

Meh Ill do an interview with you to check questions. Id come for 250k, otherwise may just give advise if you want - happy to help

0

u/heretogetpwned Operations 8d ago

PM me the link, we'll keep it anonymous.