2023 Cyber Security Career Roadmap: How to Get Started and Become a CISO, vCISO, or Director

preview_player
Показать описание
If you want to level up fast in Cyber Security, know a little about a lot, not a lot about a little.

I like to tell people "I'm a Jack of some trades, but a master of none". I can't even say that I'm a Jack of all

Truth is, I like learning new things. I learn, then move on and learn something else completely unrelated. I have always avoided going too deep down rabbit holes with narrow vision. I also have a plethora of useless information in my brain.

I can talk to you about bouncing a small 5 watt portable HAM radio signal off of a satellite in space to talk across the world, but you can only do it for a few minutes a couple times a day because of the earth's rotation.

I'm a pilot and can talk to you about classes of airspace (A,B,C,D and E) all day long.

I'm a scuba instructor and can talk to you about how slow you have to ascend from a dive so that you don't get decompression sickness, also known as "the bends".

I can have a full conversation with you about how to lower the bounce rate on your website and how it will affect your SEO (Search Engine Optimization).

I am not a master of any of these above, but I can have a full conversation with you about any of these topics, as well as much other useless information.

This is the approach that I took in my Cyber Security journey.

I learned things, and then learned something else, completely unrelated. For example, I learned about packet analysis, which is how to inspect and analyze TCP/IP packets so that I can tear them apart and decipher what communication is happening. After that I studied PCI compliance. Wordpress always interested me, so I learned how to build websites for companies. Afterward, I heard of this Nmap program so I bought a book and learned it. Wireless technology always intrigued me, so I figured out how to shoot wireless 50 miles across the sky with Ubiquiti equipment.

Over many years, I used my knowledge to land a job in defensive security doing intrusion detection. Learning the offensive side came after that, which led me to penetration testing and vulnerability management. I then found myself advising clients on PCI because I understood many of the controls, which then led to becoming a PCI QSA for awhile.

Eventually, I was able to take everything I learned over the years to start working vCISO contracts to help companies align their security posture with the business.

Absolutely none of this came from me being an expert at anything. I have no degree, and have only had a couple certs over the years (that were useless). However, my process helped me become well rounded.

If you want to be a leader, go down rabbit holes, but limit how deep you dig. Fill your knowledge bucket by exploring all of the rabbit holes stead of getting lost in one.

Learn a little about a lot, not a lot about a little.

#cybersecurity #informationsecurity #infosec #leadership
Рекомендации по теме
Комментарии
Автор

Never have I ever met a a higher level jack of all trades. A real life Jack. Brilliant inspiration, mate. Thanks for being you and going after it.

MRGUITARONFIRE
Автор

I am happy to see you here. I have been following you on X for some time now. I am subscribing to your channel outrightly.

peterillah
Автор

I’m so grateful I came across this video. I felt everything you said. “Jack of many. Master of none”. I just started my IT career journey 2months ago. Narrowed it down to Threat Detection/IR. It’s a long road but looking forward to becoming a CISO some day. Thanks for the advice Mike!

jamarengineers
Автор

This is exactly how I am but I’ve always seen it as something to overcome rather than a strength. So, its so awesome to see the same qualities be used in the opposite way to see so much success and growth!

Breanna_Unmasked
Автор

Basically how I see this is that your niche becomes the vCISO (advisory) aspect of it and not a specific area like pen-testing. Again the hardest part is finding what your specific niche is. For someone else that might just be the best pen-tester in the world because thats what they like to do.

aq
Автор

Great journey Mike.
Is it really required to have experience with both defensive and offensive side of security to become CISO or VCISO?

browingodfrey