The Register Home Page

back to article Wanted. Top infosec pros willing to defend Britain on shabby salaries

While the wages paid by governments seldom match those available in the private sector, it appears that the UK's intelligence, security and cyber agency is a long way short of being competitive in its quest for talent. In a recent job advert, the Government Communications Headquarters (GCHQ) sought a lead cyber security expert …

Page:

    1. Anonymous Coward
      Anonymous Coward

      I guess it depends on what exactly GCHQ require their "cyber" people to be doing.

      I doubt if its deploying your standard security toolset or running a SIEM/SOC or patching Windows servers or being able to quote PCI/ NIST frameworks to auditors from Deloittes - you know the typical cyber stuff that is the daily grind for most security professionals.

      I'd imagine their entire focus was more offensive or cryptography.

      More akin to working as security researchers for the types of orgs who hunt threats and look for new vulns - not something that banks in the city of London have much need for but more like the big boys in Google, Microsoft or Palo Alto etc play at. I'm not even sure if those orgs pay much to the guys and gals who do this sort of heavy technical lifting either, but I can't say I've ever seen one of those jobs advertised.

      1. 0laf

        Maybe you are right. There is an excess of cyber graduates coming out now that can talk tech about an attack but couldn't do a thing about it when faced with a room of beancounters. I've always thought that information security was 90% psychology and 10% technology.

        A grad that can pen test but not write a risk report or develop user polcies and standards to act as controls is no use to me. The tech skills I can buy in cheap when needed.

      2. Anonymous Coward
        Facepalm

        Infosec are mostly useless in corp land

        I've yet to meet any infosec people I'd trust to install a piece of AV software properly, let alone have even an ounce of securty knowledge above most quality admins. I know there must be some good infosec bods out there but all I've met so far from infosec are people who couldn't hack it as a proper Linux/Windows/DB admin job and so ended up doing infosec 'cos it was mostly just sitting around in meetings waving bits of paper with Rapid7 reports printed and moaning that no one take security seriously enough despite the constant rounds of patching admins do daily.

        Apologies to the good infosec bods but you have a lot of cowboys in your part of the IT crowd, you really need to sort your image out! ha ha!!

      3. FarnworthexPat

        Threat Researchers Salaries

        >>>I'm not even sure if those orgs pay much to the guys and gals who do this sort of heavy technical lifting either, but I can't say I've ever seen one of those jobs advertised.<<<

        A random search of Microsoft's career Web site. Senior threat researcher IC4 $117K to $229K, San Francisco area $153K to $250K. Level IC5 $137.6K to $267K, San Francisco $180K to $290K partial WFH, good medical benefits and discounted stock purchase, stock options and 401(k) partial matching.

  1. Mog_X

    "the chance to defend one’s country from the insides of Britain's cyber security hub"

    If you are unlucky you could end up defending it from the insides of a large gym bag that you somehow managed to do up and lock by yourself.....

  2. Longegg

    Well this explains the terrible security.....

    I don't think it takes a genius to work out why paying staff significantly less than the market rate is a terrible idea when hiring someone for a leading position in your cyber security organisation.

    First of all it makes it easy for foreign adversaries to get a foot in the door.

    Second, even if you employ someone who isn't working for a foreign state it is going to be far too tempting to the person you employ to sell sensitive data to the criminal underworld because of the value of that data compared to the wages being paid by the government.

    If you want the job done right then you have to be willing to pay for it.

    I eagerly await the next massive UK cyber security breach, it'll give me a good chuckle for a few minutes knowing how incompetent they are not just at the task of digital security but also just hiring a suitable person to fulfil that task.

    I feel sorry for those living in the United Kingdom, they're being protected by paper hat's and cardboard shields against a whole range of adversaries equipped with flamethrowers & petrol bombs.

    If you live in the UK it may be worth contacting your local government representative and asking them to raise this as a SERIOUS issue before it's too late and they employ a weazel or a complete & utter idiot.

    1. Anonymous Coward
      Anonymous Coward

      Re: Well this explains the terrible security.....

      What is funny is that certain levels of HMG security clearance particularly look for whether the subject (or their family) is financially exposed.... ie being likely to take a bung from Moscow.

      They look for debts but they don't look for the bleedin' obvious which is that they pay badly!

    2. jgard

      Re: Well this explains the terrible security.....

      Eh? You eagerly await the next massive security breach? What are you talking about? It would serve us all better if you were worried about your issues in the land of the free. The US has an appalling record of cybersecurity failures, critically affecting many branches of government and revealing untold amounts of extremely sensitive personal and national security information. Take the 2020 breach as an example; it was bad, really, really bad, but unfortunately, I'm prevented from emphasising just how bad it was because much of it is classified. It's so bad that they won't even tell us how bad it was. That's freedom, y'all. Woo!

      What's even worse is that US companies are responsible for much of the West's critical infrastructure (Apple, Microsoft, Google, Cisco, AWS, Uber, etc.). This means breaches could lead to serious and deadly global problems. Still, despite the security experts earning salaries in the millions, they fuck it up constantly. The fact that the US govt does not oversee this situation better is reckless and irresponsible. Worse still, no matter how badly they fuck up, the US govt just gives these firms more secret data to protect. Look at the amount of security fuck ups Microsoft has made that have led to catastrophic outcomes. Yet, the US govt (with all these wonderful salaries you imply US govt security jobs pay) keeps trusting them with more of its critical national security information. IT'S NUTS.

      I work in this area in the UK, and at the risk of being impolite, you don't know what you're talking about. That said, like you, I feel sorry for those of us in the UK, but only because we must rely so much on US infrastructure, software, services, corporate governance structures and a substandard US government cybersecurity service that keeps making the same mistakes. Not to mention a guy who keeps nuclear records in his garage and tweets mission details whenever he fancies it.

      However, unlike you, I will not and never would have a good chuckle when the US has another breach. Why the hell would I? Only a dickhead would want to do that.

      1. amanfromMars 1 Silver badge

        Re: terrible cyber security..... @jgard

        A simple question for you, jgard, because you have real live practical virtual experience in this area in the UK ...... Is cyber security which prevents increasingly damaging leaks and exploitation of sensitive information and secret intelligence by foreign agents/hostile entities/Anons/unknown unknowns possible?

        Here it is realised to be impossible, but a great invisible export earner nevertheless, which is surely crazy whilst being just a figment of primitive imagination for 0day use/abuse/misuse/attack against daydreamers wherever and whenever such a surreal reality is presented/pimped/pumped and dumped.

  3. amb310

    Just asking...for a friend, of course

    Looking at how things could shake out here in Burgerland, you think they'd hire one of us USians?

    I'll...er...they'd work cheap just to GTFO if we get Trumped. They won't even care where they'd stick them. Anything is better than living through that again.

    1. Anonymous Coward
      Anonymous Coward

      Re: Just asking...for a friend, of course

      No, you'd not be allowed to have a job as you've already proven yourselves to be disloyal to The Crown ;-)

    2. Anonymous Coward
      Anonymous Coward

      Re: Just asking...for a friend, of course

      Surprises me to hear. I feel like a very small minority being left leaning in this part of the industry even in the UK. I hear a lot of not just right wing support, but even overt support of Trump!

      Such a minority to the point where I suspect even posting AC on this one piece of information will mean people know who I am.

      1. Anonymous Coward
        Anonymous Coward

        Re: Just asking...for a friend, of course

        I think we in the UK don't understand that Trump is in fact really quite popular in the old USofA.

        It may look implausible to us Eastpondians but then we just have to consider the degredation in quality of our own politicians. We're only a few political cycles away from having our own Trump (and Bojo was getting close anyway).

        Prior to Trump being elected I had a friend that regularly worked in Huston, we were talking about the US election of that time when in the UK the idea of Trump beating Hillary seemed farcical and was rather fearfully telling me that I just didn't get how popular Trump actually was and that he might well win. I don't know if he had a bet on but he should have.

  4. This post has been deleted by its author

  5. Anonymous Coward
    Anonymous Coward

    Stranger than fiction

    So, I was once a contractor in said haunt of Alan Turing's ghost. I tell you, working in there is an absolute blast. Attack ships on fire off the belt of Orion doesn't begin to colour walking in Mr. Turing's footprints. You just need a little patience with the bureaucrats, is all. One of my gov employee colleagues had been a minor dot-com and contractor, but sold up and joined the place for the lulz. Then Crapita grabbed the contract so I retired early.

    Since then the world has changed. gov.uk now recruits on a so strictly level playing field that you start out anonymous. Your CV must contain no hint of who, where or what you are, just why you can do the job. Even a dopey old seventy-something pensioner, firing on so few cylinders they are reduced to 3 days a week, stands as much chance as anybody else of getting that interview. And the official workplace ethic is equally laid back. There is even compulsory "Active Bystander" training, in which you learn how to safely intervene in workplace abuse - best training course I ever did. So yeah, now I am a Civil Servant working part-time at the old skills, and still having a blast - though not in GCHQ this time - and I even get a packet of peanuts to supplement my pension!

    It's a weird world, o my masters.

    1. Yet Another Anonymous coward Silver badge

      Re: Stranger than fiction

      >Your CV must contain no hint of who, where or what you are, just why you can do the job

      But presumably does list where you went to school, which college you were at and what sport you played there.

      1. Anonymous Coward
        Anonymous Coward

        Re: Stranger than fiction

        No, absolutely not. Nothing that could be matched to Big Data to de-anonymise you. How the Aunt Sally do you think I got though it? <;o)

    2. amanfromMars 1 Silver badge

      Re: It's a weird world, o my masters. .... @Anonymous Coward

      And quickly getting considerably weirder with every effective unfolding 0day, AC.

      Makes for an exceedingly rich-pickings playing field though, whenever one knows what one should be doing ..... and how to both master and do what needs to be done ..... and what others will do as a result of guaranteed future programmed events.

  6. vulture65537

    My pension record shows salary £42,750 in April 2005.

    And nobody ever took any notice of my reports and advice - even managers with no first hand knowledge denying my own observations.

    1. Yet Another Anonymous coward Silver badge

      Congratulations - you achieved civil service nirvana

  7. DanUK

    The government is used to hiring people with PhDs and Masters for peanuts and can't quite believe that IT people who may not even have degrees are demanding six digit salaries! They managed to get Turing for probably a very modest salary after all

  8. Anonymous Coward
    Anonymous Coward

    Was a civil servant in the late 90s / early 2000s.

    Positives:

    * Graduate training is very good.

    * Retire at 60

    * Very Very Very hard to sack to sack someone (usually move positions)

    * Skills bonus makes you competitive-ish with private sector

    Negatives:

    * Every ~10 years, beancounters decide to do away with the skills bonus - so we mark time. Then, after ~5 years after that, management realise people are leaving in droves and not getting new recruits in. So skills bonus is brought in again.

    * Rubbish pay

    * Hard to change jobs as a specialist

    * Very Very Very hard to sack to sack someone (usually move positions)

    Ho hum.

  9. Anonymous Coward
    Anonymous Coward

    I want a new job

    I was looking on their website recently interested in a change of career (already in Defence/Software) but the salaries offered are embarrassing.

    They also weren't the 'proper jobs', not sure if these exist in the UK or if we a completely reliant on the US for the clever stuff.

    Without an internal referee I'm not sure an unsolicited CV even with details of current credentials would open the hidden doors!

  10. Anonymous Coward
    Anonymous Coward

    £41,935 ? LOL

    Are they expected to beg for handouts on the street in their spare time?

Page:

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like