Home > Security News > Employers to seek more security talent in '07
Security News:
EMAIL THIS

Employers to seek more security talent in '07

By Krissi Danielsson, Contributor
15 Dec 2006 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Information security will never go out of style. As long as companies have computing infrastructure, security professionals will be needed to ward off dangers.
Businesses are looking for professionals that understand security fundamentals and are specialized in a particular area of technology such as Cisco or Microsoft or wireless security.
Ali Pabrai,
advisory committee member, CompTIA Security+

But like all other IT careers, the market demands wax and wane and the requirements change. Experts say spending on security will continue to rise – and specialization, compliance knowledge and documented work experience are in demand.

Compliance spending continues

Enterprises continue to pour money into compliance projects, resulting in a need for more security pros, said Ali Pabrai, CEO of ecfirst.com and a member of the advisory committee at CompTIA Security+, the largest developer of vendor-neutral IT certification exams..

"Financial, healthcare and government organizations are aligning their security initiatives with compliance priorities," he said.

Employers are looking for the right talent to specialize in a particular area, Pabrai said. Finding that niche may be key to landing the next big job.

"Businesses are looking for professionals that understand security fundamentals and are specialized in a particular area of technology, such as Cisco, Microsoft or wireless security," he said.
Security jobs:
Podcast: Security certifications pay could rebound in '07

Security clearance means more $$$

Outsourcing: Understanding the business risks

Better VoIP training needed, SANS director says

Information Security Quizzes

While the initial "compliance binge" has slowed down, professionals who are well-versed in remediation and audits are still needed, said Ed Tittel, a freelance writer, trainer and consultant based in the Austin, Texas area.

In addition to compliance skills, companies are looking for professionals with dual talents in development and security, as well as professionals with security clearances who can fulfill the specialized needs of government agencies and defense contractors, Tittel said.

Experts agree that security spending will continue to increase in 2007, but at a slower pace than in previous years. Tittel estimated that the industry would see a 12-15% growth in the coming year; during the past several years, security spending has increased at least 20% annually, he said.

VoIP, wireless security growth

New eras bring new risks. And as one might expect from the skyrocketing numbers, handheld and wireless devices pose an increasing threat to corporate security, said Neill Hopkins, vice president of skills development for CompTIA.

According to a survey by Fierce-Wireless-Bluefire Wireless Security, 87% of respondents had concerns about the security of email access to corporate server accounts and remote access to corporate networks, Hopkins said. Respondents also had concerns about wireless security and loss or theft of mobile and wireless devices.

Hopkins also warned that companies will be facing threats from increased use of voice-over-Internet Protocol (VoIP) telephony and related technologies that are delivered over converged networks.

"In the IP-based communications environment, the system's functionality resides on standard computing platforms, which are vulnerable to the same types of attacks – viruses, worms, Trojan horses – that plague the data environment," Hopkins said.

Companies adopting IP-based communications solutions should thoroughly re-evaluate security practices and strategies to reduce vulnerability, he said.

Certifications in demand

So what will best prepare would-be security pros for the demands of 2007?

According to Hopkins, the following are the most demanded certifications:

  • CompTIA Security+

  • Global Information Assurance Certification (GIAC) organization's set of credentials

  • Information Systems Audit and Control Association (ISACA)'s Certified Information Systems Auditor (CISA) and the Certified Information Security Manager (CISM)

  • (ISC) ² 's Systems Security Certified Practitioner (SSCP) and Certified Information Systems Security Professional (CISSP) certifications officer, chief security officer or senior security engineer.

  • Product vendor certifications such as Check Point, Cisco Systems and Microsoft

    But a certification isn't always enough to guarantee jobseekers a paycheck.

    For entry-level jobseekers, Tittel said that skills, knowledge and experience can be more important than certification. He advises network administrators and others hoping to enter the security market to document security-related aspects of their jobs, such as incidents handled, training delivered and audits undertaken, in addition to pursuing certifications.

    "Intermediate to advanced credentials like the mid-range SANS certs, CISSP, CISM and so forth represent the first significant stepping stones into a space where certification does register," he said. "But you're wise to recognize that three to five years of relevant, current information security job experience also factors into this equation."

    More and more, said Hopkins, employers are looking for candidates who have degrees in IT, ideally focused on information security, and proven on-the-job experience along with great versatility and a broad skill set.

    "Technical skills alone are no longer enough for most IT jobs," he said. "IT workers who understand how to use technology to meet business goals, and who can articulate this understanding, are golden in the eyes of employers."

    Tags: Information Security Jobs and TrainingCISSP CertificationSecurity Industry CertificationsVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Information Security Jobs and Training
    Despite recession, information security certification pay continues to climb
    Bruce Schneier on outsourcing, awareness training
    Creating a personal brand in information security
    Feds push cybersecurity jobs, PCI DSS changes ahead.
    Feds announce 1,000 new security jobs
    Some IT security certifications are overvalued, analyst says
    How to prepare for an information security job interview
    Security industry remains resilient to tough economy
    Top social networking sites to boost your information security career
    Q2 2009 data shows IT security certification pay still climbing

    CISSP Certification
    Some IT security certifications are overvalued, analyst says
    Q2 2009 data shows IT security certification pay still climbing
    Why doesn't the CISSP cover information assurance and DIACAP?
    IT security skills and certification pay
    Despite recession, pay climbs for top IT security certifications
    Information security book excerpts and reviews
    Security skills pay increases despite economic downturn
    How do I get CPE credits?
    Finding a security management job after an economic downturn
    What is the GISP certification and how does it compare to the CISSP certification?
    CISSP Certification Research

    Security Industry Certifications
    Despite recession, information security certification pay continues to climb
    Creating a personal brand in information security
    Some IT security certifications are overvalued, analyst says
    Q2 2009 data shows IT security certification pay still climbing
    An introduction to Information Security Career Advisor
    Security jobs survey finds fewer budget cuts, lower security salaries
    IT security skills and certification pay
    Despite recession, pay climbs for top IT security certifications
    How do I transition to a career in IT security?
    Security skills pay increases despite economic downturn

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Cisco Certified Security Professional (CCSP)  (SearchSecurity.com)
    CSO  (SearchSecurity.com)
    security clearance  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts