Home > Ask the Security Experts > Expert Archive: Security Management Questions & Answers > Strategies for landing a security management position
Ask The Security Expert: Questions & Answers
EMAIL THIS

Strategies for landing a security management position

Mike Rothman, past SearchSecurity.com expert EXPERT RESPONSE FROM: Mike Rothman, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 08 May 2007
I am a Certified Ethical Hacker (CEH), but cannot get a job as a security officer. I also have a Masters Computer Diploma. What strategy should I pursue to land a security management position? Should I get a CCNA or CCSA certificate?

>
Management is not a technical skill, so you might be moving in the wrong direction. Having technical competence is actually a small part of being a security officer. The role I call "CSO Next" requires a new set of skills -- presenting, selling and ultimately understanding the ramifications of security to your business.

Let's discuss each of these ideas in turn. The most important skill a senior security officer needs is the ability to work with their peers on the senior team, meaning they have to be more of a businessperson than a technologist. Security officers must assist the employees in charge of the operation in order to understand the impact a security risk can have on the business. This has been a major focus of my research, culminating in the publication of the Pragmatic CSO, which details a new approach for the business of security management.

Talking about hackers and crackers and other attack vectors will go over like a lead balloon. These folks are all about business and want to see what kind of security program is in the works. How do you define success? How are you going to get there? What milestones are you using to ensure progress is being made?

Every VP of operations or general manager runs his or her business according to a plan. They are accountable for all commitments and must frequently report progress in an understandable and meaningful manner.

As such, an ethical hacker certification is not sufficient. Although you know how to think like a hacker, you have little experience as a businessperson, which is imperative when planning a career in security management.

So I'm of the opinion that a certification like CCNA or CCSA won't be very useful in landing a role in security management. I would do a couple of things if I were you. First, I'd learn as much about my business as I could. A good way to do that is to try to find a mentor who understands the business, who can teach you how it works. Finding a well-placed mentor will also give you more visibility in the organization.

I'd make sure I was a clear and effective communicator and writer. Maybe that means joining ToastMasters and/or taking a writing course. Communication is one of the most important skills a CSO has, so invest in making sure you can do that effectively.

For more information:

  • Determine if your information security career is on the right track.
  • Security practitioners reveal what they believe those embarking on an information security career should know about the IT industry.


  • BROWSE BY TAG
    Expert Archive: Security Management,   Information Security Jobs and Training,   Information Security Careers, Training and Certifications,   Security Industry Certifications,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Expert Archive: Security Management
    What is the GISP certification and how does it compare to the CISSP certification?
    Using a QSA to write up a PCI DSS report on compliance (ROC)
    How can gap analysis be applied to the security SDLC?
    Comparing cheap security products and appliances to costly appliances
    What are some tips on protecting my security budget in a poor economy?
    What value do research firms provide to their subscribing enterprises?
    What certificate offers the best ROI for an IT project manager?
    Is insider activity or outsider activity a bigger enterprise threat?
    How does information security prevent fraud in the enterprise?
    Differences between an SAS 70 data center and a Tier III data center

    Information Security Jobs and Training
    Despite recession, information security certification pay continues to climb
    Bruce Schneier on outsourcing, awareness training
    Creating a personal brand in information security
    Feds push cybersecurity jobs, PCI DSS changes ahead.
    Feds announce 1,000 new security jobs
    Some IT security certifications are overvalued, analyst says
    How to prepare for an information security job interview
    Security industry remains resilient to tough economy
    Top social networking sites to boost your information security career
    Q2 2009 data shows IT security certification pay still climbing

    Security Industry Certifications
    Despite recession, information security certification pay continues to climb
    Creating a personal brand in information security
    Some IT security certifications are overvalued, analyst says
    Q2 2009 data shows IT security certification pay still climbing
    An introduction to Information Security Career Advisor
    Security jobs survey finds fewer budget cuts, lower security salaries
    IT security skills and certification pay
    Despite recession, pay climbs for top IT security certifications
    How do I transition to a career in IT security?
    Security skills pay increases despite economic downturn

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Cisco Certified Security Professional (CCSP)  (SearchSecurity.com)
    CSO  (SearchSecurity.com)
    security clearance  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts