After 3+ years at my current job (Cybersec Advisory), I'm entertaining some change.
As much as I understand that budget can be tight, some of the expectations companies have today are reaching a scary level.
Here are some positions I was approached for by recruiters and 3 key skills that I circled after the interview with the hiring manager :
- Cyber Risk Advisor : Cloud Architecture (AWS / O365 / Azure) - GRC (Specifically NIST, ISO 27001 and associated controls) - Extensive Intune Administration
- Cybersecurity Consultant : Multi-cloud Cloud as above - Advisory services background - Red / blue teaming
- Cloud Security Architect : Cloud Security (AWS / O365 / Azure / GCP) - Scripting / DevOps / Code review (Python, C#, Ruby...) - Security buffet (STRIDE, NIST / DISA, DAST, SAST, OAUTH, SAML)
Taking a step back, I can recognize that some of those skills definitely go together. However, we do have to admit that finding one competent person with all those skills at a production level is more than complicated. Each of these key skills takes years to somewhat master.
For position 1 and 2, I wasn't selected because I didn't have an advanced level in one of the key skills. But the trend is becoming dangerous that we are looking for either unrealistic unicorns (job requirements says 5+ years on average) or seniors that the business can't afford.
Just curious to know what everybody else is coming across either as a hiring manager or a candidate.