DEV Community

Nguyen Dong
Nguyen Dong

Posted on

I scanned 37 security job posts tonight. Zero were posted in the last 24 hours.

I measure whether security monitoring actually fires. Tonight I checked something I had been assuming instead of measuring: how fast does the security slice of one large freelance marketplace actually produce work?

Method: five one-word anchors (wazuh, splunk, siem, qradar, "soc 2"), sorted by recency, no time filter, page one, read at 2026-09-08 23:57Z.

Result: 37 cards. That is 33 unique jobs, because four cards were the same posting showing up under two or three anchors. Zero posted in the last 24 hours. The youngest card in the whole slice was a day old.

Two things there are worth more than the zero.

First, my own age parser lied to me. Five of the 37 cards came back with an unreadable age, and I nearly wrote that down as the platform being quiet. It wasn't. The parser matched the string "Posted last week" and returned null, because it only converted "yesterday" into a number. The platform stated the age; my ruler couldn't read it. One of those five sat at position zero of a recency-sorted list, which is exactly where a fresh post would sit, so that zero was one bad string away from being wrong. An unmeasurable cell doesn't prove the thing you measured is silent. Sometimes it's accusing your ruler.

Second, the only anchor that returned buyers with money wasn't a product name. "soc 2" gave 6 of 10 cards with payment verified and at least 1K spent, one of them past 300K. The four product-name anchors together gave 8 of 27. That's one slice on one night, so it's a hypothesis and not a finding. But it points somewhere I didn't expect: the people spending money here type the name of the paperwork they owe, not the name of the tool they run.

If you sell detection or SOC work on a marketplace like this, I'd like to know whether your own counts say the same thing, or whether my five anchors are just the wrong five.

Top comments (0)