Banks want to hire ethical hackers
Financial services firms are being plagued by hackers.
This week, the Nasdaq revealed that it's computer systems had been targeted by hackers who "appear just to have been looking around" and the London Stock Exchange says its new open source-base trading system was under "major cyberattack" last year.
But security concerns are by no means limited to major stock exchanges. As we highlighted recently, financial services firms are concerned about both internal and external threats to their IT systems.
"Financial sector companies are under increasing pressure to ensure that they are proactive around securing their often sensitive data from attacks," says Paul Hanley, director of information security at KPMG. "This means identifying what information is most at risk or sensitive to fraud, increasing encryption protection, beefing up controls and ensuring they have the ability to contain the situation should a breach take place."
From a recruitment perspective, this means that information security professionals and so-called ethical hackers are very desirable. We understand that Morgan Stanley, RBS, SocGen and Nomura are all hiring in this area currently.
Paul Winchester, managing director of IT recruiter Greythorn said: "As a result of the increased virulence of attacks against prominent financial institutions, the City has had to take IT security much more seriously. Penetration testers - ethical hackers - working in the financial sector have become hot property as the number of hires has increased."
But the salaries on offer for these roles are relatively diminutive, even from a technology perspective. Winchester says the average pay for a mid-level penetration tester comes in at 62k.
"In banking terms that may sound cheap, but it's a 13% increase over average salaries twelve months ago," he says.
Winchester says that competition is heating up for a relatively limited pool of talent in this area, but financial services firms are still likely to be incredibly careful with who they choose to employ in these roles.
"The biggest thing firms look for is integrity - if someone is an ex-hacker, or turns out to be a rogue individual, the risks are high as they could do an awful lot of damage," says Hanley. "But it's also important to have a broad range of technical know-how, to be very analytical and make sure you can keep abreast of developing technologies and their potential threats."