Want A Career In Cybersecurity?

With a growing cyber threat landscape and an estimated 1 million unfilled cybersecurity jobs worldwide, the field is wide open for both recent graduates and people looking to make a career change.

Job postings in the cybersecurity field have gone up 74% over the past five years, and US News and World Report ranked a career in information security analysis fifth on its list of best technology jobs. Average salaries nationally are $88,890, and significantly higher in cities such as San Francisco and New York.

"The job prospects are excellent," says Deborah Hurley, a professor for Brown University's executive master in cybersecurity program, "the demand far outstrips the supply."

Here are 10 different job options to explore in the cybersecurity field, with job description information from CyberDegrees.org.

1. Security Consultant
"A security consultant is the IT equivalent of Obi-Wan, advisor, guide and all-round security guru," according to CyberDegrees.org. People in this role design and implement the strongest possible security solutions based on the needs and threats facing an individual company, and day-to-day tasks may vary widely. 
A security consultant might determine the most effective way to protect computers, networks, software, data, and information systems against attacks, perform vulnerability testing and risk analyses, test security solutions, respond to any incidents, and update security systems as needed, depending on the terms of their contract. 
2. Chief Information Security Officer
The chief information security officer (CISO) is the leader of all security initiatives in a company. While these tech professionals were traditionally seen as security enforcers, they are now often considered strategists helping the enterprise avoid cyber-crime. 
CISOs typically appoint and guide a team of security experts, create a strategic plan for the deployment of information security technologies and programs, develop corporate security policies, and monitor security vulnerabilities, among a number of other tasks. 
3. Security Engineer
Security engineers are intermediate-level positions that build and maintain IT security solutions for a company. These professionals develop security for the organisation's systems and projects, and also handle any technical problems that arise. 
Security engineers are often responsible for configuring and installing firewalls and intrusion detection systems, performing vulnerability testing, developing automation scripts to track incidents, and testing security solutions.
4. Security Architect
The senior-level security architect position involves designing, building, and overseeing the implementation of network and computer security for a company. 
Security architects must plan, research, and design strong security architectures for all IT projects, perform security assessments, respond to incidents, develop requirements for LANs, WANs, VPNs, routers, firewalls, and other network devices, as well as design PKIs, among other tasks. 
5. Incident Responder
An incident responder (sometimes called a computer security incident response team engineer or an intrusion analyst) is essentially a cyber firefighter, and must rapidly address security threats and incidents within a company. "In your role as a first responder, you will be using a host of forensics tools to find the root cause of a problem, limit the damage and see that it never happens again," according to CyberDegrees.org. "Like a firefighter, part of your job will also involve education and prevention." 
This involves actively monitoring systems and networks for attacks, identifying security vulnerabilities, performing malware analysis and reverse engineering, and establishing protocols for communication within an organisation and with law enforcement during a security incident.
6. Computer Forensics Expert
A computer forensics expert acts as a digital detective, accessing and analysing evidence from computers, networks, and data storage devices. 
On a day-to-day basis, this role involves conducting security incident investigations, recovering and examining data from devices, compiling evidence for legal cases, and advising law enforcement on the credibility of acquired data. 
These experts often work for large corporations, law enforcement agencies, legal firms, private consulting firms, and the government. 
7. Penetration Tester
Penetration testers, also known as ethical hackers, are responsible for legally hacking into an organisation's applications, networks, and systems to discover and later patch security vulnerabilities. 
This role involves creating and performing formal penetration tests, conducting physical security assessments of servers, systems, and network devices, using social engineering to discover security flaws, and incorporating business considerations into security strategies.
8. Security Analyst
A security analyst detects and prevents cyber-threats for a company. 
This might involve planning, implementing, and upgrading security measures and controls, performing risk analyses, conducting internal and external security audits, managing network, intrusion detection, and prevention systems, and coordinating security plans with third party vendors.
9. Security Software Developer
These tech professionals develop security software and integrate security into applications software during the design and development process. 
Depending on the specific position and company, a security software developer might oversee a team of developers in the creation of secure software tools, develop a company-wide software security strategy, participate in the lifecycle development of software systems, support software deployments to customers, and test their work for vulnerabilities. 
10. Security Auditor
A security auditor is a mid-level role responsible for examining the safety and effectiveness of company computer systems and their security components, and then issuing a detailed report outlining the success of the system and any changes or improvements that could be made. These professionals plan, execute, and lead security audits across a company, evaluate the efficiency, effectiveness, and compliance of operational processes with corporate security policies and any government regulations, and develop and administer risk-focused exams for IT systems.

TechRepublic:

You Might Also Read:

GCHQ Approved: Ten Cyber Degree Courses:

Who Needs A Computer Science Degree Anyway?:

Cybersecurity Threats Are Changing Recruitment:

 

 

« Intelligence-Led Policing Gets Automated
Cybersecurity Is A Bigger Issue Than Brexit »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall And Why Does It Matter

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall And Why Does It Matter

See how to use next-generation firewalls (NGFWs) and how they boost your security posture.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Help Net Security

Help Net Security

Help Net Security has been a prime resource for information security news and insight since 1998.

IMS Networks

IMS Networks

IMS Networks specializes in the design and management of high criticality networks and telecoms services including network security and Managed Security Services.

Center for Strategic Cyberspace & International Studies (CSCIS)

Center for Strategic Cyberspace & International Studies (CSCIS)

CSCIS seeks to advance global cyberspace security and prosperity by providing strategic insights for cyberspace and policy solutions to decision makers.

Wallarm

Wallarm

Wallarm offers an adaptive security platform including an integrated Web vulnerability scanner and NG-WAF solution with automatically generated security rules based on AI.

Secarma

Secarma

Secarma provides penetration testing, security assessments, consultancy, and training services to ensure your digital infrastructure is secure from cybersecurity threats.

Neupart

Neupart

Neupart provides Information Security Management System, Secure ISMS, allowing organisations to automate IT Governance, Risk and Compliance management.

LATRO Services

LATRO Services

LATRO Services is a complete solution provider to discover, locate, and eliminate telecom fraud.

National Centre for Cyber Security (NCCS) - Pakistan

National Centre for Cyber Security (NCCS) - Pakistan

National Centre for Cyber Security (NCCS) undertakes cyber security research and plays a leading role in securing Pakistan’s Cyberspace.

Caveonix

Caveonix

Caveonix’s RiskForesight TM solution is an automated, proactive risk and compliance platform designed for hybrid and multi-cloud.

The Citadel Department of Defense Cyber Institute (CDCI)

The Citadel Department of Defense Cyber Institute (CDCI)

CDCI is established to address the critical national security needed for a skilled cybersecurity workforce.

Perygee

Perygee

Perygee is a fully integrated platform for operational security. Companies depend on Perygee to identify and streamline the most important security practices for their operations.

Capital Network Solutions

Capital Network Solutions

Capital Network Solutions are a highly accredited managed IT services and consultancy provider, specialising in cyber security, infrastructure and communications.

Harvey Nash

Harvey Nash

Harvey Nash is a leading global provider of talent and technology solutions.

Encova Insurance

Encova Insurance

Encova’s cyber liability coverage protects you and your customers in case of a security breach in your company's data.

Bastion Networks

Bastion Networks

Bastion are a security-focussed managed solution provider and consultancy. We work with advanced cyber security vendors to produce managed security solutions to protect from online threats.

CyberXpert

CyberXpert

CyberXpert is your cybersecurity partner for the public and private sector in Belgium.