Why is it so difficult to hire a qualified senior security engineer?

0
5
Asked By MellowCactus47 On

My company is hiring a senior security engineer for a fully cloud-based Microsoft environment with no on-premises infrastructure. I have been participating in interviews, but many candidates struggle with fairly practical questions: which technologies could block unauthorized executables on workstations, how to control or restrict USB devices, and how data loss prevention differs from simply encrypting outbound email containing sensitive information such as PII, PHI, or financial data. Some candidates avoid answering directly, while one seemed to become more convincing only after I mentioned AppLocker. Is the problem our interview process, the job description, the candidate pool, or something else?

4 Answers

Answered By QuartzLynx82 On

The first thing to check is compensation, work location, and the actual job description. A genuinely senior security engineer in the U.S. may expect roughly $150,000 or more, especially for a remote role. If the position is onsite, vaguely described, or combines endpoint engineering, Microsoft 365 administration, identity, DLP, incident response, and architecture into one job, many qualified people will skip it. The applicants who remain may be people hoping to stretch into a senior title.

CopperMeadow6 -

Also make the salary range and remote expectations visible before interviews. Otherwise experienced candidates often filter themselves out before you ever see them.

Answered By OrbitingPanda31 On

The work you describe sounds more like senior Microsoft 365 or endpoint security engineering than a generic security engineer role. Intune, Defender, Entra, Purview, Conditional Access, AppLocker or WDAC, and device-control policies are all reasonable solutions, but the exact answer depends on the organization's design and licensing. A strong candidate may not name your preferred product immediately but should explain the security goal, compare options, discuss deployment and auditing, and identify operational risks.

VelvetHarbor9 -

For example, instead of asking for the product that blocks executables, ask how they would introduce application control safely: audit mode, inventory, allow-list design, pilot groups, exceptions, rollback, and monitoring. That tests engineering judgment rather than product trivia.

Answered By NimbusRook24 On

There is a lot of résumé inflation in security, and automated applications make it worse. Many people have certifications or security titles without having built or operated infrastructure. Candidates with prior systems, network, endpoint, cloud, or development experience often make stronger security engineers because they understand how controls affect real systems. You can screen for that by asking them to design a rollout, troubleshoot a failure, explain tradeoffs, and describe a project they personally implemented rather than asking them to recall a product name.

SaffronCedar73 -

It is also worth considering internal promotion. A capable senior administrator or cloud engineer who understands the environment may learn the security-specific pieces faster than an applicant who has only managed security dashboards.

Answered By BrightOtter58 On

DLP and email encryption are related but not the same. DLP detects and governs sensitive information according to policy, such as preventing, warning about, quarantining, or auditing a transfer. Encryption protects the message while it is being transmitted or accessed. A DLP rule might trigger encryption, but encryption alone does not decide whether someone should be allowed to send the data or where it may go. The candidate should be able to explain that distinction even if they have used a different vendor's tools.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.