Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Could human resources be the main problem for hiring the right people into security positions?

by The Gurus
September 10, 2020
in Opinions & Analysis
Share on FacebookShare on Twitter

Pre-requisite requirements for hiring by Human Resources may cause the best people not being considered for jobs in security.

Speaking to IT Security Guru, Cyber Security Challenge CEO Stephanie Daman said that there is often an issue where a company will have a hiring policy and if a person doesn’t fit with a qualifications minimum but has the right skill set, they may not be seen.
“The problem is two-fold: there are people with the underlying skills but HR does not recognise this as the people do not have the right qualifications and while they may have the right skills but not the qualifications that are specified,” she said.
“Also at every stage, there are people who do not understand the importance of particular skills and the youth of our profession. There has got to be a better approach as security people do not fit within a traditional way of education sometimes and once this is an older industry, the traditional ways of hiring will work.”
Amar Singh, chair of the UK Chapter security group of ISACA, said that he “100 per cent agreed”, and said that this issue is huge as job descriptions are written too objectively and they need to be more subjective.
“This is especially the case when you start off as HR has to know what you need for the job and they objectify it,” he said.
“HR has made it objective and the tough part is certificates are put in, but you never get the role filled. There needs to be a balance of subjectivity and objectivity and sometimes a job is senior level and it needs a narrative of it, reports to and from but managers don’t want to put it down as once it is written it is set in stone.”
James Lyne, SANS instructor and global head of security research at Sophos, said that the bigger issue is standardisation where people want skills and certifications and know what skills they need; but it is not a case of “one size fits all”.
“Many certifications are about proven knowledge and not experience, and the problem has been that employers require experience, but it should be on capability and should focus on educating people outside the organisation on what a security role looks like,” he said.
“There is a perception of security being a role rather than being multiple roles, and there is a challenge in managing roles and certifications. There are a lot of skills out there; the biggest thing that education requires is multiple paths for experience, capability and certifications. Employers need to use all three and being in a talent deficit, the functions in security don’t get this yet.”
Asked if this problem can be overcome, Damon said: “We are getting there. It is just an old process that is not helped by this sector moving too swiftly as universities try to keep up to speed with cyber security, which is going faster than any curriculum and businesses have to look at it that way too.
ShareTweet
Previous Post

Trustwave completes acquisition of Application Security

Next Post

US CERT issues warning about CryptoLocker

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol