You're Gonna Be Popular: Why They're Getting a Callback and You're Not
Ruby Murphy (AVP · Hampton North), Clea Ostendorf (Co-founder, CEO · Wolf Pack Security)
BSidesSF 2026 · Day 2 · AMC Theatre 07
Overview
In an era defined by rapid technological shifts and economic uncertainties, the security job market has become an increasingly complex and often frustrating landscape for both job seekers and hiring managers. Ruby Murphy, AVP at Hampton North, and Clea Ostendorf, Co-founder and CEO of Wolf Pack Security, tackle this pervasive issue in their BSides SF talk, "You're Gonna Be Popular: Why They're Getting a Callback and You're Not." Their presentation serves as a candid and insightful exploration of the systemic breakdowns in the modern hiring process, particularly within the cybersecurity domain, and offers actionable strategies for candidates to navigate these challenges effectively.
Key moments
- 0:40 Talk purpose: giving tools to navigate the job market
- 2:10 Crucial takeaway: Hiring system is broken, not the candidate
- 3:00 Common frustrations: no feedback, self-doubt, market saturation
- 4:40 Four root causes: AI, outdated processes, high expectations, poor leadership
- 6:10 How AI-generated applications create vanilla, fake-looking candidates
You're Gonna Be Popular: Why They're Getting a Callback and You're Not
Speakers: Ruby Murphy, AVP, Hampton North; Clea Ostendorf, Co-founder, CEO, Wolf Pack Security
Conference: BSides SF
YouTube: https://www.youtube.com/watch?v=n3aJrz1KcOI
Overview
In an era defined by rapid technological shifts and economic uncertainties, the security job market has become an increasingly complex and often frustrating landscape for both job seekers and hiring managers. Ruby Murphy, AVP at Hampton North, and Clea Ostendorf, Co-founder and CEO of Wolf Pack Security, tackle this pervasive issue in their BSides SF talk, "You're Gonna Be Popular: Why They're Getting a Callback and You're Not." Their presentation serves as a candid and insightful exploration of the systemic breakdowns in the modern hiring process, particularly within the cybersecurity domain, and offers actionable strategies for candidates to navigate these challenges effectively.
The speakers dissect the common frustrations experienced by highly qualified security professionals who find themselves adrift in a market that feels inexplicably "broken." Far from laying blame on individuals, Murphy and Ostendorf meticulously outline the root causes of this dysfunction, ranging from the proliferation of AI-driven screening tools to outdated corporate hiring practices and a distinct lack of strategic leadership. Their core message emphasizes that while the traditional hiring system struggles to adapt, the human element—authenticity, emotional intelligence, and strategic networking—remains the most potent differentiator for success.
This talk is crucial for anyone involved in the security industry, whether actively seeking a new role, contemplating future career moves, or managing hiring within their organization. It provides not just a diagnosis of the problem but a practical toolkit for empowerment, urging attendees to re-evaluate their approach to personal branding, resume construction, and professional networking. By demystifying the recruiter's perspective and offering a clear roadmap for visibility and impact, Murphy and Ostendorf equip their audience with the knowledge to thrive in a competitive and evolving job market, underscoring that while the system may be flawed, individual agency and strategic effort can still pave the way to desired outcomes.
Background
▶ Watch: Talk purpose: giving tools to navigate the job market (0:40)
The premise of this discussion stems from a widely observed sentiment across the professional landscape, particularly amplified on platforms like LinkedIn: "hiring is broken." This perception is not merely anecdotal; it reflects a tangible reality where highly skilled individuals, previously accustomed to being recruited, now face radio silence after submitting numerous applications. The speakers highlight that while the system isn't entirely "broken," it is "extremely far behind and struggling to catch up" (02:00). This lag is exacerbated by recent economic shifts, including significant layoffs, which have flooded the market with talent, intensifying competition and fostering self-doubt among job seekers.
Historically, the traditional hiring system was engineered for scale, speed, and safety (02:00). However, the last two years have seen a critical element—humanity—eclipsed by these priorities. The speakers identify four primary root causes contributing to the current dysfunctional state of security hiring:
- AI Resumes Fighting AI Screeners: The advent of sophisticated AI tools allows candidates to generate "perfect" but ultimately "vanilla" applications, making them appear generic and, ironically, potentially "fake" in an environment rife with hiring fraud (06:00). This creates a "bot talking to a bot" scenario, where genuine qualifications can be overlooked.
- Outdated Processes: Many companies prioritize volume and data metrics over a genuine understanding of specific role requirements. This leads to generic job descriptions that fail to capture the nuanced skills needed, such as the stark difference between an "Application Security Engineer" who is a former developer versus one who tunes SAST tools (08:00).
- Higher Expectations: Automation has raised the bar, demanding more from candidates for less. The elusive "security generalist" role, often a first hire, exemplifies this, requiring individuals to manage everything from GRC to AppSec without a clear definition of what that entails or the realistic experience level required (10:00). Companies seek "short-term certainty" rather than investing in "long-term potential."
- Lack of Strategic Leadership: A prevalent approach has been to "throw AI on to something" (06:00) without a coherent strategy, leaving hiring managers and candidates to contend with the unforeseen consequences. Furthermore, recent layoffs disproportionately affected middle management, stripping organizations of experienced hiring educators and pushing the burden onto technical managers who often lack the training or time for effective recruitment (12:00).
Compounding these issues are external emotional and psychological factors stemming from global events, which cannot be separated from the economy and hiring trends. This confluence of technological, procedural, and human challenges has created a unique and demanding environment, necessitating a fundamental shift in how candidates approach their job search.
Key Findings
▶ Watch: Crucial takeaway: Hiring system is broken, not the candidate (2:10)
The talk distills several critical findings that illuminate the current state of the security job market and offer pathways to success:
- Hiring is Systemically Flawed, Not a Reflection of Candidate Worth: The most empowering finding is the assertion that the "hiring system is broken not because of you" (02:00). The current environment, characterized by a flood of applicants post-layoffs and an overreliance on automation, often overlooks highly qualified individuals, leading to self-doubt among candidates.
- The Erosion of Humanity in Hiring: While technology promises efficiency, the traditional hiring pipeline has "died" (06:00) due to a loss of the human element. AI-generated resumes and keyword-driven screening lead to "safe, very vanilla applications" that paradoxically make genuine candidates look inauthentic in an era of rampant hiring fraud.
- Generic Job Titles Obscure Specificity: Broad titles like "Application Security Engineer" can encompass vastly different skill sets. This ambiguity harms both candidates, who struggle to identify fitting roles, and hiring managers, who receive a deluge of mismatched applications. Clarity on specific organizational needs is paramount (08:00).
- The "Security Generalist" Trap: The demand for candidates who can "do everything" often stems from a lack of clear definition and a desire for "short-term certainty" over "long-term potential" (10:00). This leads to unrealistic expectations and job descriptions that are difficult to match.
- Hiring Managers Face Significant Constraints: Beyond candidate challenges, hiring managers contend with running businesses, fear of legal repercussions from honest feedback, and a lack of formal hiring education, especially after middle management cuts. This environment makes timely and constructive communication difficult (12:00).
- Emotional Intelligence and Authenticity are Core Differentiators: Despite the technical nature of security, the "humanity" (12:00) of a candidate—their personality, emotional intelligence, and ability to connect—is the ultimate leverage. This "20% selling yourself" combined with "80% actual talent" is crucial for passing modern screening barriers (14:00).
- Networking is the Sole Reliable Path: In a market where automated applications vanish into an "abyss" (16:00), networking is identified as the only reliable path to securing a job. This includes online platforms, conferences, and direct relationships with hiring professionals.
- Resumes Must Demonstrate Outcomes, Not Just Tasks: A critical shift in resume construction is required. Instead of listing responsibilities, candidates must highlight results and outcomes, quantifying their impact wherever possible. This demonstrates what they "changed" rather than merely "touched" (26:00).
- Continuous Interviewing and Mentorship are Imperative: Interviewing year-round, even when employed, helps candidates stay sharp, receive constructive feedback without desperation, and understand market shifts. Mentorship, particularly from those in hiring roles, provides invaluable shortcuts and honest guidance (28:00).
- AI Fluency is a Non-Negotiable Skill: Candidates must communicate their AI fluency, showcasing how they use AI to "challenge" themselves and innovate, rather than merely for basic automation or "vibe coding." This demonstrates adaptability and a forward-thinking mindset crucial for avoiding obsolescence (30:00).
These findings collectively paint a picture of a job market in flux, where traditional methods are failing, and success hinges on strategic adaptation, personal visibility, and leveraging human connection.
Technical Deep Dive
▶ Watch: Common frustrations: no feedback, self-doubt, market saturation (3:00)
While the talk focuses on career strategy rather than specific cybersecurity vulnerabilities or protocols, it delves deeply into the technical mechanisms and operational realities of the modern hiring process, particularly as influenced by automation and digital platforms. The "technical deep dive" here refers to understanding the underlying systems and strategies that dictate how candidates are perceived and selected.
A central theme is the AI-versus-AI screening paradigm. On one side, candidates leverage tools like ChatGPT to craft "perfect" resumes and cover letters. While seemingly efficient, this often results in "vanilla applications" (06:00) that lack genuine personality or unique differentiation. Recruiters and hiring systems, on the other side, employ their own AI-powered Applicant Tracking Systems (ATS) and screening tools. These systems are designed to parse resumes for keywords, match against job descriptions, and flag anomalies. The problem, as Ruby Murphy points out, is that this often becomes a "bot talking to a bot" (04:00) scenario, where the human element is lost, and authentic talent can be inadvertently filtered out. This dynamic also plays into the broader issue of hiring fraud, as overly generic, AI-optimized profiles can be indistinguishable from legitimate ones, making recruiters wary of candidates who appear "too perfect" (06:00).
The speakers provide a crucial insight into the LinkedIn Recruiter backend, a proprietary tool that functions distinctly from the standard LinkedIn user interface or even LinkedIn Premium. When recruiters initiate searches, they don't see a candidate's full, detailed profile immediately. Instead, their initial view is highly condensed, displaying only the profile picture, headline, current title, and education (18:00). The resume itself is an "afterthought" in this initial screening phase. Recruiters use Boolean search queries with specific keywords to identify potential candidates. This means that a candidate's LinkedIn profile and headline must be meticulously optimized for these keyword searches. For instance, a recruiter looking for "Terraform" experience might miss a candidate whose profile only lists "infrastructure as code" if the search isn't broad enough, even if the candidate possesses the exact skills (20:00). This highlights a critical technical gap: the need for candidates to anticipate how non-technical recruiters might search for technical skills, requiring them to "treat your LinkedIn and your resume like you're talking to a 2-year-old, and like really start from scratch" (20:00) in terms of clarity and keyword inclusion.
Furthermore, the discussion touches upon the technical specificity required for job descriptions. Clea Ostendorf uses the example of an "Application Security Engineer," a title that can mean drastically different things (08:00). One hiring manager might seek a former developer proficient in reading, writing, and breaking code, with pen-testing and customer-facing experience. Another might prioritize someone skilled in Semgrep and tuning various SAST tools. Both are "AppSec Engineers" on paper, but their technical competencies and desired contributions are distinct. The lack of precise, technically informed job descriptions leads to a mismatch between candidate skills and organizational needs, perpetuating the "broken" hiring cycle. This mirrors the challenge faced by security teams drowning in alerts; just as security teams must define "what matters to us as an organization, where is our risk" (08:00), hiring managers must apply the same rigor to defining specific technical roles and their impact.
The talk implicitly argues for a more intelligent and human-centric integration of technology in hiring. While AI and automation are tools for scale, their current deployment often detracts from identifying genuine talent. The solution isn't to abandon technology but to use it more strategically, ensuring that keywords reflect a broad understanding of technical domains and that the initial screening process doesn't inadvertently filter out the "humanity" that ultimately drives successful team integration and problem-solving.
Demo / Proof of Concept
▶ Watch: Four root causes: AI, outdated processes, high expectations, poor leadership (4:40)
While "You're Gonna Be Popular" does not feature a traditional technical demonstration of code or exploitation, it effectively provides several practical "proofs of concept" in the form of actionable examples and recommended approaches for job seekers. These demonstrations illustrate how candidates can leverage the speakers' advice to enhance their visibility and appeal in the current market.
One key "demo" is the presentation of optimized LinkedIn profile elements. Ruby Murphy showcases her friend Tommy's LinkedIn introduction: "Tommy is a cloud-slinging, Terraform-wielding, spider-swatting infrastructure wizard" (20:00). This serves as a prime example of how to inject personality, humor, and technical prowess into a concise headline, making it memorable and engaging beyond generic keywords. Murphy contrasts this with typical, bland descriptions, emphasizing that such a hook immediately makes a recruiter "want to read more" and signals "emotional intelligence" (22:00). She also uses her own LinkedIn headline, "a tech recruiter that doesn't suck," as a self-deprecating yet effective example of a "1-second hook" that stands out (22:00).
Another crucial "proof of concept" is the structure of an effective resume. The speakers present an example resume template that, while simple in format, crucially highlights results and outcomes for each bullet point (26:00). Instead of merely listing responsibilities (e.g., "managed endpoints"), the example demonstrates how to quantify impact (e.g., "managed X endpoints, resulting in Y% reduction in Z incidents"). This directly addresses the hiring manager's desire to see "what you changed" rather than just "what you touched" (26:00). The visual example reinforces the idea that an outcome-driven resume is far more impactful than a task-oriented one, aligning with the perspective of discerning hiring managers.
Finally, the talk offers a "demo" of sorts for leveraging Generative AI for personal branding. Acknowledging the prevalence of tools like ChatGPT, the speakers suggest using it as a creative aid: "Just put yourself in and say, 'Tell me about myself in a fun way'" (23:00). This demonstrates how AI can be utilized not for rote content generation, but as a catalyst for injecting personality and uniqueness into one's professional narrative, helping candidates craft a compelling "skeleton" for their story without losing their "soul." These practical examples serve as concrete blueprints for candidates to apply the abstract concepts of authenticity, visibility, and outcome-driven communication.
Defensive Implications
▶ Watch: How AI-generated applications create vanilla, fake-looking candidates (6:10)
The insights shared by Ruby Murphy and Clea Ostendorf provide a robust framework of "defensive implications" for both security professionals navigating the job market and organizations striving for effective hiring. These implications are essentially strategies to "defend" against the current systemic failures and optimize for success.
For Security Professionals (Job Seekers):
- Proactive Digital Presence Optimization: Candidates must strategically optimize their LinkedIn profiles for recruiter searches, understanding that keywords in headlines, titles, and summaries are paramount. This involves not just listing skills but also using broader descriptive terms (e.g., "infrastructure as code" alongside "Terraform") to cater to both technical and non-technical recruiters. A verified, active LinkedIn profile is crucial, as it mitigates recruiter risk aversion stemming from past experiences with fake candidates (18:00).
- Outcome-Oriented Resume Crafting: Shift from listing responsibilities to detailing quantifiable results and outcomes. For every bullet point, ask: "What did I change? What was the impact?" (26:00). This demonstrates value and strategic thinking, distinguishing candidates from those merely listing tasks.
- Cultivate Emotional Intelligence and Authenticity: Inject personality and humor into professional communications (LinkedIn introductions, networking messages, interviews). As Ruby Murphy notes, "humor is definitely like an underrated weapon in hiring" (22:00). This human element fosters memorable connections and signals cultural fit, a critical factor in hiring decisions. However, maintain professionalism; "your persona is permanent" (22:00), and negative online behavior will be noted.
- Strategic Networking: Prioritize intentional networking over blind connections. Messages should clearly state the purpose of connection or follow-up, demonstrating genuine interest rather than generic requests (24:00). Building relationships with hiring managers and recruiters is "worth way more than 50 applications" (29:00).
- Continuous Interviewing Practice: Interview year-round, even when employed. This keeps skills sharp, provides invaluable feedback without the pressure of financial desperation, and helps individuals understand market expectations (28:00).
- Seek Mentorship: Actively find mentors, particularly those in hiring roles, who can offer honest, constructive criticism and strategic career guidance. A good mentor "will drive you and push you and tell you to work harder and tell you it's not good enough" (29:00).
- Develop and Communicate AI Fluency: Do not fear AI; instead, demonstrate how you use it to enhance your capabilities, challenge your thinking, and innovate (e.g., using it to build a threat model to break, rather than just generating code) (30:00). This positions candidates as forward-thinking and adaptable.
For Organizations and Hiring Managers:
- Define Roles with Granular Specificity: Move beyond generic job titles. Clearly articulate the specific technical skills, desired outcomes, and cultural contributions required for each role. This minimizes mismatches and attracts more relevant candidates (08:00).
- Invest in Hiring Education: Recognize that hiring is a distinct skill set. Provide training and resources for technical managers who are now burdened with recruitment responsibilities, especially following middle management cuts (12:00).
- Prioritize Long-Term Potential Over Short-Term Certainty: While immediate problem-solving is appealing, organizations should assess candidates for their growth potential and ability to adapt to evolving challenges. This fosters a more sustainable talent pipeline (10:00).
- Reintroduce Humanity into the Process: Balance automated screening with human review. Understand that AI-generated resumes can be misleading. Prioritize genuine engagement, constructive feedback (within legal bounds), and a personalized candidate experience to attract and retain top talent (02:00, 12:00).
- Standardize and Refine Keyword Strategies: Ensure that internal keyword searches and ATS configurations are comprehensive and account for various ways technical skills might be described, to avoid overlooking qualified candidates (20:00).
By adopting these defensive strategies, both individuals and organizations can better navigate the complexities of the modern security job market, moving beyond frustration towards more effective and fulfilling outcomes.
Key Takeaways
- The current security hiring system is outdated and struggling to adapt, leading to widespread frustration; candidates should remember that the problem lies with the system, not their inherent worth.
- Authenticity, emotional intelligence, and the ability to convey personality are crucial differentiators that help candidates stand out amidst AI-driven screening and generic applications.
- Optimize your online presence, especially LinkedIn, by crafting a compelling, keyword-rich headline and profile that catches a recruiter's eye in their initial, condensed view, anticipating how non-technical recruiters might search.
- Strategic networking, characterized by intentional connections and clear communication, is the most reliable path to securing opportunities in a market where automated applications often disappear into an "abyss."
- Resumes must focus on quantifiable results and outcomes, clearly demonstrating what you "changed" or "drove," rather than merely listing responsibilities or tasks.
- Embrace continuous professional development, including interviewing year-round, seeking mentors, and actively demonstrating AI fluency by using it to challenge and innovate, rather than just automate.
About the Speaker(s)
Ruby Murphy is an AVP with Hampton North, holding a "super fancy title for just saying I do everything." Her extensive experience spans security engineering, application security (AppSec), and disaster recovery (DNR), engaging with a diverse range of technical professionals. This talk marked her first time presenting at a conference, reflecting her deep practical understanding of the security industry and the intricacies of its hiring landscape.
Clea Ostendorf is the Co-founder and CEO of Wolf Pack Security, a boutique application security firm. She humorously describes herself as someone who "likes to cook, but I don't read recipes," signifying her ability to "read between the lines" and discern underlying meanings in conversations and market trends. Actively involved in hiring and the security community, Clea brings the perspective of a startup leader navigating the challenges of talent acquisition. This presentation also marked her debut as a conference speaker.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Competent, honest career-advice talk from two practitioners with legitimate hiring-side experience. Nothing groundbreaking, but the LinkedIn recruiter backend walkthrough and the ATS keyword-gap problem are grounded in real operational knowledge rather than LinkedIn-guru platitudes. Fills a BSides community slot fine — this crowd needs this content more than a DEF CON crowd would.
Heather Calloway (CISO) — WEAK
Competent career advice delivered by practitioners who clearly know the hiring market, but this is not a security conference talk in any meaningful sense — it's a job search workshop. The content is real, the problems diagnosed are genuine, and the advice is actionable for individuals, but it has no governance angle, no defender value, and no institutional relevance above the level of a single candidate's LinkedIn headline.