Skip to content

Cybersecurity, Experience and the Risk of Age Bias

Cybersecurity values experience, but age bias in hiring may filter out veteran talent before recruiters ever see it.

Photo by Zulfugar Karimov / Unsplash

The recent articles in The Times and  BBC Womans Hour have put workplace ageism back into the conversation in the UK, particularly for people who find that a long and successful career can suddenly become a disadvantage when applying for their next role. 

Is this true of cybersecurity? Cybersecurity should, in theory, be one of the better places to grow older professionally. Experience matters when your job involves understanding risk, anticipating what can go wrong, navigating regulation and governance, or recognizing the significance of something you have seen before. 

But cybersecurity is also part of an industry obsessed with what comes next. In more technical roles, I wonder how quickly experience can become reframed as legacy experience, or whether an older candidate has to work harder to prove they can keep pace with cloud, automation, AI and whatever technology we collectively become excited about next.

Cybersecurity companies also employ for skills beyond the SOC. They need marketers, finance teams, HR professionals, salespeople, operations teams and many other functions where the value attached to experience may look very different. A security vendor can genuinely value the experience of a 50-year-old risk auditor while unconsciously questioning whether a 50-year-old marketing candidate still has the energy, digital skills or appetite to keep up.

Gen X knowledge workers are lifelong technology learners. We entered the workplace before smartphones, social media, cloud computing and generative AI existed, and we have spent our careers adapting to new technologies, new workflows and ever-changing possibilities.

Yet somewhere along the way, that experience of life-long learning and adaptation appears to have acquired an expiration date.

Age discrimination is illegal in the majority of leading economies, but age discrimination in the hiring process is impossible to prove. Nobody needs to say that somebody is too old when they can decide that person is probably overqualified, too expensive, unlikely to stay or perhaps not quite the right “cultural fit.” A casual read of personal stories across LinkedIn and beyond reveal a consistent pattern, one that reveals overlooked candidates are not lacking in skill, they are abundant in years.

Have we unwittingly built an infrastructure that supports outdated bias in recruiting?

For example, LinkedIn can work out exactly how old you are. LinkedIn Recruiter allows recruiters to filter out candidates based on graduation year. It serves all the information needed to fuel unconscious bias in experience, age, gender and race. The chronology and mandatory dates for each role highlight gaps. It wasn't that long ago when career breaks were considered a red flag to employability, reducing opportunities for women.

More from Lucy Millington:

Why The Cybersecurity Team Should Be The Marketers’ Best Friend
Cybersecurity and marketing share the same goal: trust. Learn why closer collaboration strengthens brands and reduces risk.
Internal Communications Overload Creates Security Risk
If you work in SecOps more noise equals more risk. The more alerts you have, the harder it is to find the ones that need immediate action. Yet in my experience, this idea of more noise being detrimental to understanding, does not stretch beyond the SOC into business communications.

What if LinkedIn kept exact employment dates private by default and displayed tenure instead? Four years as Communications VP at a cybersecurity firm tells a recruiter something useful about my experience without revealing whether those four years began in 2012 or 2022, or if they came after a career break. Neither of those are relevant to my ability to succeed in a role today. I can be transparent when I have the opportunity to talk to a recruiter about the role and why I would be a great fit.

LinkedIn, Indeed and other platforms could also introduce a bias-reduced first views to recruiters, initially hiding names, photographs, graduation years and exact employment dates. Recruiters could assess skills, achievements and experience before seeing information that can trigger assumptions about a candidate's “fit”.

People can be trained to recognize unconscious bias, but increasingly the volume of applicants means initial screening decisions are given to technology. If an AI tool learns from previous hires and current talent, does it also learn the age profile of those hires and create an unintentional echo chamber where 35 years old is a critical success factor? Requirements such as “recent experience” “zero career gaps” or "15 years experience" can sound perfectly neutral while potentially creating a very particular picture of the person an algorithm thinks should be interviewed.

Recruiters and hiring managers need to ask who AI is filtering out, and question if it is quietly teaching itself who not to see.

None of this would eliminate unintended bias in people or infrastructure, but it could help hiring managers and recruiters recognize and mitigate it by questioning why they are not reviewing resumes/CVs from people with 25 years experience when hiring for management roles.

This matters because there is a contradiction at the heart of the way we talk about longer working lives. We cannot tell people they must work longer, continually reskill and adapt to extraordinary technological change, while maintaining recruitment systems that make it remarkably easy to judge them by age before ability. 

Perhaps it is time that we stopped asking whether older workers can keep up with changing technology and practices, and shifted our assumptions about what elements of a resume/CV makes a great candidate.

Cybersecurity may look immune for the short-term but I would urge you to check that your tools and attitudes to hiring have kept up with the ageing highly experienced and available workforce.

HOU.SEC.CON CTA

Latest