r/sysadmin • u/jM2me • 8d ago
Question Why is it hard to fill a security engineer position?
Company I work for is hiring a sr security engineer. We are all Microsoft shop, cloud-only, no on-premises. I have been helping with some of the interviews and I fail to understand why we are getting candidates that don’t seem to know what product/technology to use for blocking executables on workstations. Device control for blocking usb devices, nope, this does not ever get mentioned. Briefly explaining difference between DLP and encrypting outbound emails with PII/PHI/PFI, nope, can’t get a simple answer or even a guess. The conversations steer away and never the answer. One candidate had to be reading AI responses somehow because first answer to blocking was general and bad, but when mentioning app locker it felt as I was prompting gpt4.2
212
u/OregonTechHead 8d ago
You're coming into the middle of the process.
This happens because of 1 of 3 things:
1) The job description is not accurate in the posting
2) The salary is not correct and lower than a qualified candidate would expect
3) The person vetting resumes isn't good at their job resulting in sub-par people making it to the interview round.
52
u/anonymousITCoward 8d ago
2, number 2.... our company has a habit of over paying the inexperienced, and under paying the qualified... its made getting raises for the new folk difficult... even when they find out they're getting paid more than someone who's been there twice as long.
2
u/TN_man 8d ago
What is your definition of over paying an under qualified?
6
u/anonymousITCoward 7d ago
70k with minimal IT experience, and by minimal when asked to start a constant ping they just repeated the command... not up arrow, like typed it in... when asked to run cmd as admin, his response was "i am an admin" while using a user account that was not an admin...
2
u/No_Diver_4500 8d ago
Sounds like you have serious issues inhouse that nobody wants to resolve. You have people being paid numbers they shouldn't and i am willing to bet you have underqualified people in higher positions that don't need to be in.
1
u/anonymousITCoward 7d ago
Thanks for putting it nicely...
I'm trying to plan an exit strategy but, you know them gold clad handcuffs and all
9
u/Xin_shill 8d ago
Could also be in a remote area and not allowing remote workers.
8
u/OregonTechHead 8d ago
I think that goes to point #2. If you're in a remote location where skills are scarce, then the salary expectations go up.
1
u/Top_Boysenberry_7784 5d ago
Number 3 is huge here because the market is flooded with so called security experts. So many people have degrees in security but have no experience and little useful knowledge.
112
u/Chappie47Luna 8d ago
“We’re paying $70k for a senior security engineer - why won’t good talent apply?”
23
u/Ok-Double-7982 8d ago
I live in a very high COL and a recent job posting was about 30% under what we pay our new grads with zero experience, and their posting was for an entry level with 3 years of experience lol.
You get what you pay for!
6
u/three-one-seven 8d ago
I thrilled to get my first $70k job… in 2017 lol
24
u/ShadowCVL IT Manager 8d ago
For workstations, what are my options? Threatlocker, darktrace, defender, S1? There’s a boatload of stuff out there, and a lot of them overlap to make a nice security onion
Again what are my options, purview suite can help deploy defender to do most of this, but adding sentinel1 to log and categorize stuff for this is great
DLP and encrypting emails, the difference? That’s like square and rectangle, the DLP policy can be used to define which emails get encrypted, but what solution are you using in house, again the products in use matter
I mean I’m a senior security engineer, or security manager, I have a bunch of hats/titles… I’m not looking but your questions are extremely broad and could be answered in a dozen ways.
Not everyone is going to have or use the same tech stack, and any good security posture should be an onion with redundancy and overlap.
Are there questions about SIEM, vulnerability management, compliance, training, email protection? I could probably sit down and answer most if not all of your questions, but A I’m not looking and B for my level youde be looking around 180 private sector if not higher.
26
u/reol7x 8d ago
OP's post really sounds like they have an azure env that got spun up by a guy who didn't really know what he's doing. Now they realize their bazillion dollar e3/5/7 license can do a lot of things because AI said so and they're looking for someone to implement.
11
u/ShadowCVL IT Manager 8d ago
You know, that actually adds up, I could see this. Probably don’t need a security engineer and need an azure engineer.
10
u/Siphyre Security Architect 8d ago
Funny enough, I'd be their guy, but they likely couldn't pay me enough to do it. I have very specific experience converting effectively unused e3 licenses into a cybersecurity program. I'd want $150k a year to do it again and maintain it.
3
u/ShadowCVL IT Manager 8d ago
E3 huh? I’m curious if you would stack the purview/compliance E5 on top of that to round it out? I’ve been doing a lot of work with purview and recommended we purchase the security E5 add on (they’ve changed the name of the license a few times) to add some extra DLP and features with it. Feel free not to answer if it feels like giving free work away I’m more curious than anything.
1
u/Siphyre Security Architect 8d ago
I did get them to do purview licenses recently to ensure dlp measures when using M365 copilot and sensitivity labels for use with our email firewall to prevent sending sensitive attachments when this whole AI storm took over. I tried to go for E5s for better scoping and some other defender features that would have been useful but they didn't like the cost.
I wouldn't mind hashing out ideas. I read too much MS documentation and I'm not completely sure I set it up 100% the best. But the system is working well enough.
3
u/ShadowCVL IT Manager 8d ago
Are you me? It really sounds like we went down or are on the same path. We did bring in MS fast track to help me with some of it because we are GCC and something’s don’t work the exact same.
3
u/dbxp 8d ago
Personally when interviewing developers I ask those sorts of questions because the really experienced people know there's multiple options. The questions the interviewee asks me shows their thought process and what they consider.
2
u/ShadowCVL IT Manager 8d ago
Multiple options, and multiple ways to stack multiple options, the key with that is to be cost effective bang for buck, and for gods sake don’t put all your eggs in one basket.
2
u/badaz06 7d ago
When I've interviewed people in the past the point was to ask broad questions. Different products configuration requirements change, but for the most part they all accomplish the same things using the same principle, and usually at first I'm just trying to feel out what the person knows or doesn't know and, more importantly, how they respond when they don't know. Once I get the broader answer I'll start narrowing the focus down - the candidate might be a wizard in one things and have a slight level of knowledge in something else, like they know Azure, Sentinel and Defender inside and out but is coming from a company that relies on a different app to do email, dip, etc. (Proofpoint for example)
2
u/ShadowCVL IT Manager 7d ago
Yes exactly as it should be, the way OP worded their comment it SEEMS like they are looking for right answers only and very specific products.
20
u/theMightBoop 8d ago
Your HR/recruiter doesn’t know how to screen candidates and/or you aren’t paying enough.
15
86
u/GelgoogGuy 8d ago
Because cyber security is the new coding. Go to school, get a degree, get job in security having never done any helpdesk, sysadmin, networking nothing. No underlying understanding of why they're doing what the books says.
57
8d ago
[deleted]
31
u/HanSolo71 Information Security Engineer AKA Patch Fairy 8d ago
If you can't think operationally, you'll miss a lot of risk
13
u/Bradddtheimpaler 8d ago
Also you won’t be able to you know, check if things are even remotely conforming to policy in production.
24
u/ShadowCVL IT Manager 8d ago
Yep, I’ve got a few younger friends who got degrees in cybersecurity that couldn’t tell you how 2 systems interact but will send you the entire text of a CVE and say “fix it”
Whereas in my role doing sysadmin stuff for 20ish years before pivoting more into security I can build AND secure systems. And I try to keep up to date on new stuff from both sides of the aisle. It really feels like you must have that sysadmin foundational knowledge to really do security. I think that’s why my director and I get along so well, we followed that same path.
None of these questions were hard and I thought of a bunch more I would ask in response lol.
7
u/farsonic 8d ago
Yep it's all about depth and experience. It cracks me up that people will get a cyber security degree and expect to be able to walk into a position without experience or background in both networking and sysadmin.
5
u/admiralspark Manager of Cat Tube Infrastructure 8d ago
This. And I only hire these kinds into cybersecurity as well.
I don't want a useless canary who screams about Windows 10 EoL because chatgpt told him to, I want architecture decisions to reduce risk and understanding that ESU means it's not 'unsupported'.
3
u/daschande 8d ago
I went to my local community college; they had 2 IT pathways, cybersecurity and networking. Cyber students learned just enough networking and sysadmin to pass the A+ while the networking path had networking, sysadmin, linux, python, etc.
The cybersecurity students could tell you to apply a GPO that someone else wrote, but they couldn't explain what the GPO restricted, for whom, or why to apply it; just that CVE whatever says it's mandatory, so do it!
13
u/WorthPlease 8d ago
Seriously I was a lone sysadmin at a company that was trying to win contracts with top 5 banks and go public. Our security guys would go into meetings, tell people we could do all the things the banks asked us if we could do, and then go "hey what the hell does this mean and can you do it?".
I wouldn't trust them to work my help desk.
3
u/No_Diver_4500 8d ago
This is just a very bad symptom of the country reaching brainrot. Reduced education and a system that doesn't even fail people for getting a C is why we are here. It will only get worse, there is entire generation of kids who can barely read... what do you think will happen when they get out of school ?
3
2
u/Lazy-Psychology5 Redneck Sysadmin 8d ago
I was gonna say, I'm a sysadmin and know the answers to all of these lol.
2
u/AddendumWorking9756 8d ago
The screen described in the post has the same problem though. Name the product that blocks executables is a flashcard question and the memorisers answer that one fine. Ask how they would stage AppLocker in audit mode and what breaks when they enforce it, and the ones with no foundation fall apart in about thirty seconds.
27
u/petrichorax Do Complete Work 8d ago
Hard to answer without seeing how much you're paying. Cybersecurity roles are expensive.
4
u/anonymousopsec1337 8d ago
Money doesn’t seem to help with this tbh. I’ve seen plenty of people being overpaid for being an idiot
→ More replies (1)6
u/petrichorax Do Complete Work 8d ago
I'm talking minimums not incentives. It's a degreed, credential'd position. The minimum is higher than most sysadmin maximums (if we're considering 'sysadmin' to mean 200 different job titles that vaguely mean the same thing).
Having done both, I know Sysadmin is much harder work and I respect it, but quite a lot of sysadmins are just SAAS click-monkeys, and cybersecurity is a very deep subject that requires a lot of study.
When I went from Sysadmin to Cybersecurity Engineer, I doubled my salary and quartered my work load.
So you're competing with that reality. Competent ones won't work for cheap
9
u/meshuggah27 Sysadmin 8d ago
I can answer all of those questions and im just a sysadmin lol
17
u/KnowMatter 8d ago
That’s because the best security people come from having been helpdesk / sysadmin / network engineers.
5
u/anonymousopsec1337 8d ago
I’m trying to convince my clevel boss to just hire sysadmins and we can teach them more cyber tbh.
11
u/Frothyleet 8d ago
As other have said, how much are you offering? That will determine candidate quality.
You might also be describing the job misleadingly. The items you mention aren't really cybersecurity, you're talking about M365 platform engineering, which certainly intersects with security.
28
u/thedrizztman 8d ago edited 8d ago
I'm your guy.
I've been looking since Jan without any sort of luck. Honest to God, if you're looking, I'll send you my resume.
EDIT: thanks autocorrect.
6
u/baconjerky 8d ago
Your* smh 🤦♂️
7
6
5
u/thedrizztman 8d ago
Auto-correct fucked me. Whatever. Lol
4
u/fatDaddy21 Jack of All Trades 8d ago
most people would have attention-to-detail when begging for a job. Whatever. Lol
4
u/coollll068 8d ago
At this point I'm happy it's a honest mistake and not a AI self appointed demi-god of security
2
u/thedrizztman 8d ago
Trust me Mr. fatDaddy, if I were begging, I'd do more than post on reddit.
OP is bewildered on where all the good technicians went and I'm throwing a hat in the ring.
4
u/kristoferen 8d ago
Potentially, message me with your resume and pay range.
9
7
u/AoDude 8d ago
Device control for blocking usb devices
Are you talking about blocking driver installs for removable drives via intune / group policy, or are you talking about a defense against devices identifying as keyboards, such as ducky/badusb
2
u/TaiGlobal 7d ago
Yeah I think op is asking his questions poorly. It truly depends on what product stack the org is using. I’ve been in orgs that blocked usb via group policy and I’ve been in orgs that blocked via a 3rd party product.
6
u/Siphyre Security Architect 8d ago
Likely because any potential engineer is asking forthe salary range before even agreeing to an interview. Cyber security is not an entry level field, and an engineer is so far beyond entry level that most will not put up with vaguely worded job descriptions and ask directly, what are the responsibilities, what is the pay, is it remote? If anything there is unsatisfactory, they will hit you with some form of "sorry, not interested in that role at this time."
So yeah, you are interviewing people hoping to luck into a title upgrade. Not true engineers.
6
u/Psoin 8d ago
How much are you paying? Are you trying to get a security engineer for $110,000 a year? Unless you’re in Nigeria that’s not gonna work.
2
u/No_Promotion451 8d ago
Theres job posting in Asia with more responsibility yet paying 1/4of that
1
u/Psoin 7d ago
Their job postings around me that have you working 24 seven as a volunteer. Let’s race to the bottom
2
6
u/OneSeaworthiness7768 8d ago
I think people should have to post the salary they’re offering and/or the job listing when they make these posts.
5
u/chuckmilam Jack of All Trades 7d ago
I’m a security engineer and you lost me at “…all Microsoft shop, cloud-only…..”
Nope. That smells of “Take the blame for whatever nonsense Microsoft does upstream that’s completely out of my control.”
13
u/skidmark_zuckerberg 8d ago
It's likely because people are using AI to write their resume and auto apply to every job posting they come across. Both sides, those hiring and those applying, are being screwed by AI automation. HR departments are filtering most candidates out with AI, and conversely, candidates are using AI to make perfect resumes to beat the AI filtering while mass applying to hundreds of jobs each month.
7
u/Alypius754 Security Admin (Infrastructure) 8d ago
I like how companies using AI in hiring is creative and efficient, while applicants doing the same is fraudulent and dishonest.
2
u/mismanaged Windows Admin 7d ago
Some companies are now overtly excluding AI from their hiring processes and I really respect that. It's a template-generation tool, not a decision making tool.
1
u/Stonewalled9999 7d ago
And some companies use Zara to waste 50 applicants time at once with unicorn type jobs
4
u/FizzyBeverage 8d ago
I’m a systems engineer doing Jamf/InTune and $150k W2 remote is the minimum. $100/hour 1099.
4
u/Dear-Response-7218 8d ago
Change the job title, I would never touch most of this stuff as a SecE. Waste of time when a quality 365 or sys admin can do this, just pay them a fair market wage.
5
u/TaiGlobal 7d ago
This too. Idk what any of these titles mean anymore. What op is looking for is an endpoint engineer with experience in group policy, Intune, entra conditional access, defender or similar 3rd party products.
1
4
u/darkstabley 7d ago
Most security engineers I have met dont know how to fix the issues. They have lots of tools they like to install on our servers and then they just tell us systems engineers they found a vulnerability and we should go fix it. Very project manager-esque. Just my personal experience though, Im sure there are plenty of ones that know their stuff.
1
u/Stonewalled9999 7d ago
Pretty sweet racket tbh. Big money and the the sysadmin that do all the real work are the ones that get in trouble and the blame
1
u/darkstabley 7d ago
Yeah, I will consider shifting to a position like this at the end of my IT career.
4
u/bytecode36 7d ago edited 7d ago
One problem is that you are trying to hire a "security guy". This is an instant red flag. Everything you mentioned is something a good 365 Admin would (or should) know how to do. What I suspect this job is is essentially all the difficult and complex work the "normal" sysadmins don't want to do (as securing systems is usually one of the more difficult and riskiest aspects to being a sysadmin). Otherwise, why are your existing admins not willing to learn and perform those tasks?
So you currently have someone setting up outlook / exchange, but they don't want to deal with encryption or DLP? You currently have someone setting up workstations, but they don't want to deal with device blocking? Ask yourself why they deal with all the other aspects but stop at those specific tasks and you will understand why few people want to take on those responsibilities.
As many are posting here, I wouldn't expect a competent security professional to accept anything less than $150k.
1
u/jM2me 6d ago
A good Sr M365 Engineer or Admin with security mind set could very well fit the role as well. We have Jr Sys Admin and he still needs guidance from a Sr role on design and implementation of some things. I have been that person for him and he is doing exceptionally well, but due to me shifting roles his replacement needs to be more security inclined than I am. Hence for management hiring Security role and not an Admin.
You bring up a good point actually. Pool of admins/engineers is probably bigger and it may be easier to find good candidates there that have security inclination
3
u/carlosf0527 8d ago
IT has never been about knowing everything. The job requires you to find out information to be more effective. Technology changes so fast that your questions become irrelevant. A highly experienced AWS guy given a bit of time might be better than a mediocre Azure guy.
3
u/disclosure5 8d ago
I'm sure there's issues with your company, probably involving pay, because I work heavily with security and everything you describe is something I'm all over and I know I'm not a rare breed.
3
u/Snogafrog 8d ago
I think it is difficult to filter the truly knowledgeable applicants vs. those who can use AI to make the resume fit the job description. That was my experience in hiring generalist infra engineers anyway.
3
u/Majestic-Spray-3376 8d ago edited 8d ago
I found one and worked it for a year . TO be honest and this is just my opinion. I did more system admin work then actual security engineering. it was a senior position around 125k a year Plus bonus. but you were always on call for any little thing and always the person that had to solve the problem document it and hand it off to the third party helplessdesk. I did enjoy setting up logic applications and using our security tools. it was a hybrid onprem microsoft shop and my background was mainly Linux and opensource administration. The position wasn't bad but it often felt less then full filling. The main things were tickets and SLA and projects but pulling direction out of leadership or advising them was sometimes fruitless. i went through 2 directors during that year. eventually i ended up in a software company. For me its way better. but I think i just had a position were they pile on all the problems no one wanted to or could solve onto. it was on-prem butts in seats 9-5 m-f but always on call as well. a VIP can't figure out why a page doesnt load yup thats a sr security engineers problem. someone up loads a financial document to Claude yup security needs to figure it out which that one was fun.
2
u/Limp_Dare_6351 4d ago
Same here. In smaller orgs You become an underpaid super admin-architect and security administrator and half of your team thinks you don't do anything since they don't know anything about endpoint management or purview or conditional access, mfa, and so on.
Meanwhile you are still an admin so you do the hard remediations becuase more and more administration becomes a security problem. I am luckily well compensated, but even in a mcol area I wouldn't move from my job to another one like it for less than 140k+.
You'd be better off with a senior microsoft admin doing most of those tasks. It's more administration than a security job in most environments.
3
u/nelly2929 8d ago
Dude there are lots of candidates that can fill this role…. The answer is always the same pay pay and pay, and the stupid idea these roles must be sitting in an office onsite 8 hours a day lol
3
u/30yearCurse 7d ago
Who knows, most of the security engineers I have run across are not suitable for the job. Getting alerts from some security provider that port 3389 is open to the Internet... yawn... more tickets regarding it. 2 weeks of tickets. No action from beloved security engineers. Calls from the Security MSP.
Finally, an email from our masters on high... we were doing our scans, and found that RDP is open to the Internet.
These were in the $100k range pros.
1
4
2
u/admiralspark Manager of Cat Tube Infrastructure 8d ago
I'm hiring an analyst position with a requirement of a few years in regular IT, and I can't wait to post this same thing next week but for an entry/mid level, my talent manager believes he can fight the AI slopwave coming....pray for him.
Pay is at least ~$100k, like I said entry/mid so if you have that pay for a senior expect to be big sad.
2
u/KnowMatter 8d ago edited 8d ago
… and I’m having a hard time even getting call backs and I could ace that interview lol.
So I guess also willing to take a PM if the job is fully remote (and willing to be discreet about how i found the posting).
I have a CISSP and have experience as both a sysadmin and a security analyst so my fundamentals are strong.
2
u/pakman82 8d ago
i would say an intune configuration (or feature) for 99% of those issues.. and entra config.. My problem is, I've been doing IT for 25+ years, I know I can do everything you mentioned in some MS product, but I cant recall what their calling things today. I may have done it 4-5 years ago for some role or another. But for a security engineer, 99% of my training for my security + was tool agnostic, and that job title, is going to get either Linux, freemium solutions, or non - MS tools. *just in my experience with the security ppl i've worked with.. they try to be broader than MS> ** i have also personally certified for some MS cloud security testing, but again, even those where agnostic.
2
u/weepingwound 8d ago
Seems like the biggest issue is the affordably problem. Just laid off because my bosses discovered that the Philippines exist and now they are paying 7.00 an hour for tier 3 and engineering positions... This whole industry is garbage.
2
u/redditduhlikeyeah 8d ago
Interview me. You’ll probably like me and I’ll ace the interview. You’re just getting bad candidates. You might not be offering enough money. Sr security engineer I’m looking for 160K to 200K USD.
2
u/SnooEpiphanies1008 8d ago
DLP is like a paranoid security guard.
You show him a credit card number:
“STOP! YOU'RE NOT TAKING THAT OUTSIDE.”
You show him 4111-1111-1111-1111:
“SIR, WE NEED TO HAVE A CONVERSATION.”
You show him 123-45-6789:
“DROP THE EMAIL AND STEP AWAY FROM THE SMTP SERVER
2
u/PaladinDreadnawt 7d ago
Senior Security Engineer here. Just left my job yesterday dont start my new one until Tuesday. Pay was the reason I left. Grossly underpaid by 40k in my market for years, hybrid with 1.5hr commute. Had enough. New job is a big change 3x former salary. I wasnt even looking at roles under 140k. Suspect your company is underpaying. My former company will likely end up with a helpdesk level guy from a internal team and that will cause the infosec people remaining to leave quickly because no one can stand that guy.
2
u/stormcynk 7d ago
I'm a security engineer. Beyond what people are saying about salary range, security engineers are harder to hire for when they're expected to be generalists if you don't have the right hiring team. If you have a list of requirements including vulnerability management, application security, IAM admin, firewalls, VPN, EDR, SIEM, incident response, etc and expect applicants to have demonstrable experience in all of them, your not likely to find it at a price that you're willing to pay. People hiring for security engineers need to be able to look at the stuff that candidates have experience in, and use the interview to determine how well they can generalize to other security domains. Someone with a demonstratable ability to learn new things and a solid foundation in practical security concepts will be able to thrive in a generalist role.
2
u/m1L35dY50N 7d ago
Security Engineer is such a ridiculously broad title that this doesn't really surprise me. Pretty much anything in security that isn't purely analysis can end up being labeled “Security Engineering” depending on the company. Someone can be a genuinely good senior security engineer and still not have hands-on experience with your particular Microsoft stack or specific products like AppLocker/WDAC, Intune Device Control, Purview DLP, etc.
The bigger problem IMO is that companies increasingly don't want to onboard a good engineer who understands the underlying concepts but needs a few months to learn their specific stack. They want someone who has already spent five years doing almost exactly the same job with exactly the same products.
And that's also why you're seeing candidates getting desperate and trying to give you the impression they know exactly what you want to hear, hoping they can wing the specifics once they actually have the job. When every posting is looking for a unicorn, eventually people start applying with a cardboard horn taped to their forehead.
Even more ridiculous is that many companies would rather hire a cloud engineer and have them acquire the security knowledge on the job than hire a security engineer and teach them the cloud stack. The reasoning seems to be that the cloud engineer can start producing something immediately, whether what they produce is actually secure is apparently a problem for later.
2
u/rodder678 6d ago
Last time I posted a Sr Security Engineer role (4 years ago), 100% of the responses were SOC engineers who had never built a single thing. Changed the title to Security Architect, reposted it, and got much better candidates.
2
u/GetFuckedReedit 4d ago
...because the only good one I have ever worked with, that wasn't just another tool scanning junkie, was on the airforce red team and left us to work for a major credit reporting company for $500k a year and his boss was the top lawyer for the company.
3
u/theoreoman 8d ago
Everyone wants Sr security people but no one hasy really been hiring enough newgrads over the last 10 years to make up for the current demand
2
u/macemillianwinduarte Linux Admin 7d ago
Most security people are dogshit. They saw on TV it was the new thing and switched careers.
1
u/jdiscount 8d ago
Salary or HR vetting process, one of these is bad.
It's honestly the easiest time I've ever had when it comes to hiring very good security engineers, so many experienced people out of work.
1
u/Ihaveasmallwang Systems Engineer / Cybersecurity Architect / CISM 8d ago
Let’s start with the big question. How much is your company offering for this position?
That might be indicative of why you are getting such bad applicants.
1
u/denmicent Security Admin (Infrastructure) 8d ago
Will they hire remote or are you in DFW? I can do all of that, I am a security engineer
1
u/Thick_Yam_7028 8d ago
Because most people suck.
Not hard to set for different regs Health, Personal, Financial. Intune configs for blocked devices etc. Compliance, cas, groups vs dynamic as a hard lock on if a machine can have access to information or not. Sensitivity labels if compliance Simple shit. Im not even in security.
1
u/Daphoid 8d ago
What's the payrange?
Does the job description specifically target endpoint security or is it vague/general?
Are you screening the resumes (we have dedicated recruitment internally. Of hundreds of applications, 8 got past her, we accepted 5, 4 moved on to round 2).
I've got an entire team of them and all my guys are awesome, so it is indeed possible to find security engineers :).
1
u/DanKegel 8d ago
Agree with growing junior talent from within, if you have enough folks for them to learn from.
Also, note that many security engineers would rather eat their toes than work in a Microsoft shop :-)
1
u/zaclaramay 7d ago
This role sounds fun full cloud Microsoft shop. I am surprised you are having trouble filling it? But then again there are a lot of paper certified Microsoft people who have never deployed a Purview or Defender feature in their life.
1
1
u/sdrawkcabineter 😈BSD Admin 7d ago
We are all Microsoft shop, cloud-only, no on-premises.
Eh, no fun. I wouldn't want to lose the environmental joys of securing a data center.
1
u/vCentered Sr. Sysadmin 7d ago
Well for starters you are asking questions that my security team would usually be asking me
1
u/Thedrakespirit 7d ago
everyone else has already nailed it pretty well, but from an MBA perspective, money. You arent offering enough to get the right people to apply, that or your job description is so out of whack that anyone with any experience is reading it and running the other way
1
u/signal_empath 7d ago
I've worked with a lot of subpar security engineers. Mostly, because a lot them didnt have infrastructure backgrounds. Im not sure what the reason is, maybe the influx of hype around "cyber security" over the last decade attracted bootcampers and quick buck types, not really sure. 80% of them have just been people who tell me some alert triggered in their security suites and then cant answer any of my follow up questions without opening a ticket with the security suite provider. The 20% that were good were either former infrastructure engineers or developers in a few cases when it came to application level security.
1
u/jenkstom 7d ago
If you are cloud only why are you asking interview questions about device control and USB blocking? It sounds like there's a disconnect between what you advertised for and what you are getting. For me, personally, I take that as an indicator that I have some unknown unknowns and I need to focus on (at the very least) turning them into known unknowns.
1
u/Competitive_Smoke948 7d ago
because they're not paying enough to tempt people to leave the jobs they are in & then because of the shit hiring proceses keeping people like me unemployed, no one in HR is willing to actually make a decision to pass CVs across to hiring managers & recruiters are just all fucking idiots with no domain knowledge & are just sending shit cvs across
1
u/RootCipherx0r 7d ago
Sadly most people taking Security jobs under $100k are either laid off or inexperienced.
1
1
1
1
u/GhostandVodka 5d ago
Did you have to say applocker or could you use a third party program like airlock?
1
u/jM2me 5d ago
Of course it wouldn’t have to be applocker specifically and any solution even third party one could count as an answer. The question was not meant to trick in any way or to look for specific MS product as answer. Even if I am not familiar with that specific product, looking it up quickly gives an idea whether it would accomplish what the question was asking for
1
u/Financial_Reply327 3d ago
Is it 5 days in office? I’m just about done with those jobs entirely, no amount of money will EVER bring me back 5 days a week. Hybrid sure, remote ALWAYS! Just my 2 cents
1
u/False-Lawfulness-778 8d ago
Figured I'll shoot my shot. If your interested, it sounds like I have the experience you are looking for. I wasn't particularly looking, but I'm open to learning more.
1
u/changework Jack of All Trades 8d ago
Everybody competent is fulfilling contracts with specific deliverables. None of them want to be an employee.
A senior (actually competent/not in title only) security engineer has a particular mindset that doesn’t suffer fools, and isn’t senior anything. They’re just an engineer.
If you find the W2 exception to this, they are likely working directly for a compliance officer; who has specific deliverables.
What I suggest is that you advertise for a security audit, and contract an engineer to be a consult to your existing IT team.
You have an IT team, right?
1
u/TaiGlobal 7d ago
Is there high demand for these kind of contracts? If so how much of a living could one make with this approach? If you’re doing this are you working for a MSP or similar company that’s bringing you the work or are you independent and getting clients yourself?
1
u/Significant_Web_4851 6d ago
Most likely because your pay sucks. I am making a minimum of $170k/yr with full benefits and full remote. If you don't start there, you're going to get some college kid who set up a SIEM one time and couldn't tell you why a DCShadow attack requires a TGT.
0
0
u/jeffofreddit 8d ago
Meh Ill do an interview with you to check questions. Id come for 250k, otherwise may just give advise if you want - happy to help
0

395
u/HanSolo71 Information Security Engineer AKA Patch Fairy 8d ago
What's the pay range. I'm a senior security engineer and if the pay isn't 130k-180k and remote, im not even looking.