AI Resume Screening Barriers Push Young IT Talent Toward Cybercrime
Young specialists entering the Russian IT job market, particularly in information security and antifraud, face systemic barriers created by automated resume screening systems that prioritize candidates with existing commercial experience.
Entry-Level Challenges in IT Hiring
A recent graduate with a diploma, freelance background, and personal projects in antifraud systems applied to 50 positions on hh.ru and received only two interview calls, both ending in rejection. One explicit reason cited was insufficient experience. Despite widespread industry claims of talent shortages in cybersecurity, just 10-11% of IT vacancies in January 2026 were accessible to applicants without prior work history, according to SuperJob data reported by Expert magazine. Across the entire labor market the figure reached 37-38%.
Habr Careers statistics for the second half of 2025 further illustrate the imbalance: out of 10,820 published vacancies, only 870 targeted interns and juniors combined, while 6,463 positions were reserved exclusively for mid-level and senior specialists.
Link to Cybercrime Involvement
Russian judicial statistics from the Judicial Department at the Supreme Court of the Russian Federation show that 48.2% of individuals convicted for crimes involving computer information in 2022 were aged 18-24, with another 19.7% aged 25-29, totaling 67.9% under 30. Research on Article 272 of the Russian Criminal Code (unauthorized access to computer information) for 2018-2023 notes that young people facing unemployment and financial pressure become more susceptible to offers of quick illegal earnings, especially when they possess technical skills but hold only low-paid positions.
Foreign studies of active and former criminal hackers reveal that initial motivations often stem from technical curiosity and a desire for mastery rather than money. Several participants had originally sought legitimate cybersecurity roles but were blocked by educational or experience requirements. One individual who reported vulnerabilities received no response from affected organizations.
Effective Prevention Approaches
The National Crime Agency in the United Kingdom operates the Cyber Choices program, which redirects young people using technology illegally toward legal applications. Participants receive part-time work placements in cybersecurity companies. Evaluation of 1,041 referrals showed lower repeat offense rates compared to control groups.
Automated hiring systems, as examined in research by Harvard Business School and Accenture, frequently eliminate suitable candidates by enforcing rigid criteria such as minimum years of experience or exact keyword matches, even when applicants demonstrate relevant skills through personal projects or freelance work.
The core paradox remains: companies demand ready-made mid-level and senior professionals while offering few structured pathways for juniors to acquire the necessary commercial experience, potentially increasing the risk that technically skilled youth turn to illegal activities where formal credentials are not required.
Related articles
Merkle Tree Certificates Proposed to Enable Lightweight Post-Quantum HTTPS in Chrome
Google Chrome developers, together with industry partners and the IETF PLANTS working group, are introducing Merkle Tree Certificates (MTC) as the first HTTPS change designed to address performance challenges of post-quantum cryptography. The new format replaces parts of traditional X.509 certificate chains with compact inclusion proofs inside a Merkle tree whose root is signed by a certificate authority. This approach significantly reduces the size of authentication data exchanged during TLS handshakes while preserving strong post-quantum security properties. MTC also enforces Certificate Transparency by design, making it impossible to issue a public certificate without recording it in a publicly verifiable log. Performance evaluations are currently underway with Cloudflare, and initial public MTC logs operated by experienced CT log providers are planned for early 2027. A dedicated post-quantum Chrome Root Store supporting only MTC is scheduled for the third quarter of 2027 and will run in parallel with the existing root store.
Bill Gates Calls for Stronger External Oversight and Regulation of AI
Bill Gates stated in an NBC News interview that self-regulation by AI developers is no longer sufficient and urged Congress to pass binding laws on artificial intelligence. He warned that AI tools in the hands of malicious actors could trigger catastrophic events capable of causing up to a billion deaths, emphasizing the unprecedented power of combining bad intentions with modern AI systems. Gates advocated for mandatory rules, audits, and monitoring, particularly in critical sectors such as medicine, finance, and government infrastructure, while acknowledging that some added bureaucracy would be necessary. Leaders from Anthropic and OpenAI have similarly suggested slowing AI development, with former Anthropic employee Jacob Coxon publicly accusing companies of playing roulette with lives by pursuing self-improving superintelligence. House Speaker Mike Johnson prefers to wait for industry proposals, whereas Mark Zuckerberg opposes coordinated oversight and believes individual labs should decide on pace. Several U.S. states including California, Maryland, and New York have already begun launching their own AI regulatory initiatives and expert panels.
Implementing DevSecOps in Unprepared Teams: A Practical Three-Month Roadmap
Many development teams face resistance when security tools are introduced without proper process changes, leading to bypassed checks and unresolved findings. The article outlines a structured approach for small teams of five to eight developers without a dedicated security specialist, focusing on one service as a pilot. It emphasizes assigning clear roles including a Security Champion, selecting initial checks such as secret scanning with Gitleaks and dependency analysis, and converting scanner reports into actionable tasks with owners and deadlines. The plan covers the first eight weeks of setup, including baseline handling for legacy issues, automated blocking rules, and incident rehearsal exercises. Metrics recommended include time to first triage, age of open critical defects, and false positive rates, aligned with DORA indicators for release performance. The guidance draws on OWASP SAMM practices and stresses that security requirements must be integrated into daily workflows rather than added as extra gates.
Why Technically Strong CISOs Lose to Weaker Peers: The Hidden Role of Internal Politics
A new analysis from independent expert Andrey Biryukov explains why technically proficient CISOs frequently fail to secure budgets and executive support while less technical peers succeed. The core issue lies not in technical knowledge but in the ability to translate security risks into business language that resonates with CFOs, CEOs, and boards. Biryukov details how influence, rather than formal authority, determines whether security initiatives gain traction or stall in endless approvals. He emphasizes building coalitions in advance, crafting compelling narratives, and preparing concrete business cases that quantify revenue impact and regulatory exposure. The article also highlights common pitfalls such as relying on fear-based arguments or ignoring stakeholder KPIs. Ultimately, the piece argues that selling security internally is essential for any CISO who wants both resources and long-term survival in the role.