Discover your dream Career
For Recruiters

IT security jobs are both bulletproof and more lucrative

In the current climate, only roles that banks can justifiably claim to be essential are likely to receive sign off from the powers that be. Step forward the role of the information security professional.

In September, it was reported that Goldman Sachs was the victim of a hacking attack, when Lloyd Blankfein's (and 80 other employees') personal details were posted on the Pastebin website by anti-capitalist protestors. This follows attacks on Citigroup and the IMF earlier this year.

This year, it's become apparent just how susceptible banks are to cyber-attacks, and the result, even now, is a steady stream of recruitment for information security professionals within banks.

"Recruitment for information security experts is reasonably bulletproof, even in the current depressed financial recruitment market," says Brent Harris, UK Sales Director for Permanent Recruitment at Aston Carter. "We're seeing a steady demand for permanent recruitment and the contract space also remains relatively active."."

It's still relatively difficult to find people for these roles - recruiters tell us that there are just 500 people qualified to undertake these roles in the City. Handy qualifications for this sector include the CCSA NGX Certification and the CCSE for more experienced security professionals.

Pay can be relatively lucrative, with average salaries now at 125k for a head of information security thanks to increased demand pushing up pay.

Demand doesn't look set to fall any time soon. A recent report by Ernst & Young pointed to the fact that cyber attacks on financial services firms are becoming increasing frequent and more complex; often targeting not just systems but trying to exploit specific human behaviour. The result is that defences against these attacks have to become ever-more sophisticated.

UBS is currently recruiting an IT security architect for its investment bank, while Morgan Stanley and SocGen are also hiring, according to recruitment sources. There's also the fact that some banks are parachuting in external consultants to test the robustness of their IT security and strategies for improvement. The likes of KPMG and Ernst & Young are therefore hiring.

There are, however, some questions about just how worthwhile all this investment is. Computershare, a US-based firm which keeps records of registered shareholders of large corporations, has recently accused a former employee - Kathyann Pace - of illegally downloading its data on to two USB devices.

This is despite the fact, as Securities Technology Monitor points out, that Computershare was a huge investor in IT security. This, of course, also follows the high profile cases of Sergey Aleynikov at Goldman Sachs and Samarth Agrawal at SocGen, both of whom received jail sentences for stealing code from their former employers.

But financial services firms are also investing more into technical controls to identify when a data breach takes place internally, as well as being more vigilant about the consequences of data theft in employees' contracts.

author-card-avatar
AUTHORPaul Clarke

Sign up to Morning Coffee!

Coffee mug

The essential daily roundup of news and analysis read by everyone from senior bankers and traders to new recruits.

Sign up to Morning Coffee!

Coffee mug

The essential daily roundup of news and analysis read by everyone from senior bankers and traders to new recruits.