
Ben Todd at Dynatrace explains how observability and automation are the magic ingredients needed to attract and win security talent
With a global shortage of 3.4 million cyber-security professionals, it’s no surprise that the competition between firms to capture and retain security talent is more fierce than ever.
One of the most important ways organisations can distinguish themselves to prospective hires is by offering meaningful, stimulating, and strategic work – but for many that’s easier said than done.
In most organisations, security professionals still find themselves saddled with manual and repetitive processes to obtain information needed to keep their applications secure. For example, only 25% of security teams can access comprehensive, accurate, and continuous reports of applications and code in production – forcing them to manually request and compile this information.
To attract and win security talent, organisations must escape from this trap so their teams can be freed up to do interesting, innovative, and strategic work.
Traditionally, the task of security teams when it came to applications was twofold: to harden software, and to develop and execute rapid response plans in the event of an attack or breach. In effect, security was treated as a late-stage process in the software assembly line, or as an emergency function.
However, it’s now widely recognised that treating security this way is incompatible with modern software environments and development practices.
In recent years the software development lifecycle has become more iterative. That means more releases with shorter review windows for security teams, all while the complexity of these releases has exploded. This pushes the traditional approach to security to the limit and significantly increases the risk of teams missing vulnerabilities at multiple levels, such as in the software supply chain or within their own code.
It also means security teams will need to repetitively review, revise, and document their response plans far more frequently, or risk them becoming obsolete very quickly. Even then, many sophisticated threats today often outpace the response times of even the most competent and well-drilled security teams. As a result, organisations face an increase in friction between all parties which results in a slowdown in releases and greater security risks for code in production.
There’s also the fact that this way of working relies on manual ticketing between DevOps and security teams. This creates the risk that poorly formatted or unclearly structured tickets and correspondence could cause miscommunications about which team is responsible for taking ownership, leading to issues being missed or left unresolved.
For security teams to flourish in a modern development environment, organisations must reassess their day-to-day role as something other than a late-stage process in the software lifecycle.
First, organisations need to encourage security teams to embrace automation, freeing them up from manual information-gathering tasks. Observability solutions can be invaluable in this effort, giving security teams real-time situational awareness over their environment along with a comprehensive overview of all apps and code running in production.
Observability solutions can review, analyse, and report changes in system resource use, incoming and outcoming traffic, and vulnerabilities in the software development lifecycle. Critically, they can help security teams assess the urgency of any issues and provide them with the insights needed to triage and remediate them.
The automation of many traditional tasks around observability and insight-gathering can also be used to break down information silos between DevOps and security teams. This eliminates many cases where security has to request information from DevOps, or where DevOps requires teams to request an intervention from security. Security teams can then assign vulnerabilities to the most appropriate people for resolution.
Continued advances in AI technologies, and efforts to integrate observability, analytics, and security into a single platform are opening the door to automatic resolution of many common challenges in keeping software secure. AI platforms can take accurate, rapid, and continuous insights from observability solutions, and then proceed to automatically action a workflow or runbook that executes simple tasks such as patching vulnerable packages or making minor code-level changes.
This shifts the day-to-day role of security teams away from actively policing the end-stage of software development. Instead, security teams can be continuously present throughout the software lifecycle, with constant data and insights empowering them to act as soon as issues arise.
Many organisations are going a step further with this transition, and are working to embed security practitioners within development teams. In these cases observability solutions are often critical, as they can free up security specialists to focus on the architectural side of security and take a proactive role in development decisions.
In the absence of observability this wouldn’t be possible, with security practitioners forced to spend much of their time gathering and analysing low-level data.
The global security professional shortage isn’t going to subside any time soon, which means that organisations cannot afford to ignore modernising processes for these teams.
Security teams rightly want to be able to work in environments that allow them to perform at their best, solve interesting problems, and learn and develop. That’s not possible in organisations that silo security teams and relegate them to manual and repetitive data-gathering, ticketing, and patching tasks.
When considering an organisation’s performance in the race for security talent, one of the first things IT leaders should ask is what they’ve been doing to help security teams do the best job that they can.
In today’s fast-paced digital world, that means helping break down the silos around security and empowering teams with comprehensive and real-time insights into their threat landscape.
Ben Todd is EMEA Security Sales RVP at Dynatrace.
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543