What is the career path for a CISO in 2021? | How to start a career in Cybersecurity

preview_player
Показать описание
On this episode of Life of a CISO, I answer the question, how does one actually become a CISO? A mistake that many technical cybersecurity professionals make is thinking that by working hard enough and long enough on the technical path, you deserve to be a CISO. The CISO is just a different career path. There’s nothing wrong with being a world-class security expert, and you can get plenty of money and prestige from it, just like you can be the best airplane mechanic and get plenty of money and prestige from that, but it’s a different career path than being a pilot.

🔑 [FREE MASTERCLASS]
Discover How You Can Advance Your Career Through Cybersecurity

If you want to become a CISO, you need to have one foot in the executive world and one foot in the cybersecurity world. You can go to school for both of them separately, or you can hone your skills at one, get a good position in a company, and then reach out to some executives and ask them to mentor you. If you are willing to make the effort, perhaps pay for a dinner occasionally, and are willing to keep on asking after you’ve been told no by one or five people, you can find yourself on a fast track to being a CISO.

0:11 What is the career path for a CISO
0:33 A CISO needs 2 skills: A business and cybersecurity skillset
1:00 An example of these 2 skillsets
3:01 Switching hats
3:51 Notice the difference
4:36 Both sides are fighting, you’re a translator and marriage counselor
6:52 If you think a CISO doesn’t need to know it, you’re not cut out to be a CISO (right now)
8:23 You aren’t creating financials, you just need to understand them
9:12 You need to understand technical language and communicate it
9:41 The three categories of CISOs
11:40 A story about a C-Suite and the CISO
14:19 “What do the executives want to get out of that meeting?”
16:04 Do you really want to be a CISO?
19:54 Assuming you want to be a CISO, most people have a security background, not a business background
22:04 How to nail the interview
25:37 How to move up within your current company
26:45 Keep asking until you get a yes
28:23 Why ask people for advice in positions you don’t want to have?
29:03 First, honest assessment of where you are in business and security
29:40 The two options to go from one to another
30:01 Start within your own company
32:49 You can’t be afraid of the word “no”

About Dr Eric Cole
Eric Cole, PhD, is an industry-recognized security expert with over 20 years of hands-on experience in consulting, training, and public speaking. As the founder and CEO of Secure Anchor Consulting, Dr. Cole focuses on helping customers prevent security breaches, detect network intrusions, and respond to advanced threats. In addition, he is a sought-after expert witness and a 2014 inductee to the InfoSecurity Hall of Fame.

#LifeOfaCISO #Cybersecurity #Careerpath
Рекомендации по теме
Комментарии
Автор

As I transition from Regional Security Manager in Physical Security to a Business Continuity and Disaster Recovery Lead, I am eager to learn and grow. I consider your guidance invaluable as I strive towards my ultimate goal of becoming a Chief Information Security Officer (CISO). your supporter from the Philippines!

sphinxgru
Автор

This is phenomenal content. I’m surprised this doesn’t have 10x views. I definitely fall into the category of security engineer mindset, so it’s eye opening to me to see and understand what it takes to be a CISO — if I even want to be one. Love the content, production level, lighting, and your clear/concise way of speaking without the “um”s. Great information and presentation. Definitely subbed.

elliotalderson
Автор

31:00 that's exactly my scenario, lead noc engineer, studied / taken 2 CISSP courses, manager has known about my passion for security, our only security guy quit so he's giving me a shot i'm now doing his job, getting ready for my first audit, is nice to be able to put theory into practice.

SICKFREDO
Автор

Like your webmaster, just started.
Believe and I have been through alot of these items. Been doing CISO level work for 5 yrs, prior to having my first true CISO role 3 yrs ago.
Prior to both of those handling security engineering to security analytics for 12 yrs.
Learned through alot of hard knocks to exactly how you are evangelizing the CISO role, and how to be a better CISO.

toddluther
Автор

Really appreciate the content. Thank you sir

Lami_N
Автор

I like your perspective Eric, thanks for sharing it.

michaelflowerssr.
Автор

16:35 - the litmus test - how do you react in a cyber incident?

RWSunSets
Автор

very interesting, im researching and this is very useful and compelling to watch thanks Eric

GSF
Автор

great content ! i love the "you're not ciso material" 😂

ThisIsEduardo
Автор

So a business degree with cyber experience?

dma
Автор

Tom Brady doesn't want to be a running back; A security engineer may want to be a CISO. There's a difference.

Joshua_t_
Автор

So you have to break down tech, to be understandable to the lowest possible denominator but be able to lay down numbers that can impact and influence higher ups to make the decision you want.

franknoneofya