top of page
Search

I Hire the Fry Cook Over the Resume Every Time

Aug 8
2 min read

Some of the best people I have ever brought into security started with zero IT background, and plenty of the others walked in fresh out of school with a cyber degree and no bad habits yet. That second part matters. I almost always hire green and train from the ground up, because I have found that people with years of experience usually arrive having learned the wrong way to do things. What I am really looking for is raw material I can shape. And more often than not, the best raw material has a service job on the resume. They worked the line. They bartended. They waited tables, ran the host stand, closed the place at midnight and opened it again six hours later. Degree or no degree, that is the resume that gets my attention.


Here is why. Cyber is not really about tools. It is about staying calm when everything is on fire, reading people, catching the one thing that is off, and juggling ten problems at once without dropping a plate. That is a Friday night dinner rush. Working the service industry teaches you how to handle customers, manage clients, and read a person fast, and that is a skill I have seldom found in people who had everything handed to them. You cannot teach that. You can absolutely teach them the tech.


Now look at how we actually hire. A friend put it perfectly. The posting wants a college grad, major in cyber and networking, five years experience, eight years of AI, for eighty to ninety grand. AI has not existed in any real form for eight years, but never mind. The resume goes into an AI screen that hunts for the right keywords. Miss them and you are gone before a single human looks. Then it lands with HR, who have no idea what the role actually does. Then it reaches a hiring manager who already had a friend’s kid lined up, someone with none of those credentials, and only opened the rec to prove they tried. Somewhere along the way cyber became a nepotistic little corner of business. We are certainly not the meritocracy we pretend to be.


Two years later the firm gets breached and everyone stands around looking confused. We still do not take this seriously. It has become a line item, and everyone leans on cyber insurance that I promise will find a reason not to pay the moment they see the state of your environment. Then we wash and repeat.


The stakes are not banking records anymore. We are sitting on top of AI now, and the blast radius is bigger than it has ever been. We hire keywords, certa and nepotism, this will be seen when the lawyers walk in.


So ask yourself honestly. Are you hiring the cert the friend of the family, or are you hiring the person?


 
 

Recent Posts

See All
Reconnaissance Is Not an Incident

Every statement out of the water sector this week says the same thing. Contained. Water is safe. Operators handled it. That is an after action report written by the wrong side. Twelve states now. More

 
 

Timcke Risk Management, LLC

660 Massachusetts Ave

6th Floor, Boston, MA 02118

 

© 2025 by Timcke Risk Management, LLC

 

bottom of page