Information Security Jobs
Home > Ask the Security Experts > Security Management Questions & Answers > Strategies for landing a security management position
Ask The Security Expert: Questions & Answers
EMAIL THIS

Strategies for landing a security management position

Mike Rothman EXPERT RESPONSE FROM: Mike Rothman

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 08 May 2007
I am a Certified Ethical Hacker (CEH), but cannot get a job as a security officer. I also have a Masters Computer Diploma. What strategy should I pursue to land a security management position? Should I get a CCNA or CCSA certificate?

>
EXPERT RESPONSE
Management is not a technical skill, so you might be moving in the wrong direction. Having technical competence is actually a small part of being a security officer. The role I call "CSO Next" requires a new set of skills -- presenting, selling and ultimately understanding the ramifications of security to your business.

Let's discuss each of these ideas in turn. The most important skill a senior security officer needs is the ability to work with their peers on the senior team, meaning they have to be more of a businessperson than a technologist. Security officers must assist the employees in charge of the operation in order to understand the impact a security risk can have on the business. This has been a major focus of my research, culminating in the publication of the Pragmatic CSO, which details a new approach for the business of security management.

Talking about hackers and crackers and other attack vectors will go over like a lead balloon. These folks are all about business and want to see what kind of security program is in the works. How do you define success? How are you going to get there? What milestones are you using to ensure progress is being made?

Every VP of operations or general manager runs his or her business according to a plan. They are accountable for all commitments and must frequently report progress in an understandable and meaningful manner.

As such, an ethical hacker certification is not sufficient. Although you know how to think like a hacker, you have little experience as a businessperson, which is imperative when planning a career in security management.

So I'm of the opinion that a certification like CCNA or CCSA won't be very useful in landing a role in security management. I would do a couple of things if I were you. First, I'd learn as much about my business as I could. A good way to do that is to try to find a mentor who understands the business, who can teach you how it works. Finding a well-placed mentor will also give you more visibility in the organization.

I'd make sure I was a clear and effective communicator and writer. Maybe that means joining ToastMasters and/or taking a writing course. Communication is one of the most important skills a CSO has, so invest in making sure you can do that effectively.

For more information:

  • Determine if your information security career is on the right track.
  • Security practitioners reveal what they believe those embarking on an information security career should know about the IT industry.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Security Management
    Is it against HIPAA regulations to permanently store sensitive information?
    Two-tier distributed systems vs. three-tier distributed systems
    How to prevent software piracy
    How would you define the responsibilities of a data custodian in a bank?
    How do ISO 17799 and SAS 70 differ?
    Has FFIEC made any VoIP-specific mandates?
    Finding lost notebooks with 'LoJack for laptops'
    What controls can compensate when segregation of duties isn't economically feasible?
    What can be done to block adult images in search engine results?
    What are the security job prospects for someone without a certification?

    Information Security Jobs
    CISOs adapt as compliance requires strategic thinking
    CISOs Must Innovate to Enable Business
    RSA 2008: Financial industry security challenges
    How would you define the responsibilities of a data custodian in a bank?
    What are the security job prospects for someone without a certification?
    The road from network administrator to information security professional
    Will a Security+ certification be useful for aspiring security analysts?
    Getting started on a career in penetration testing
    What Web security initiatives can be taken on a college campus?
    Getting your career in infrastructure security started

    Information Security Certifications
    Face-Off
    Logoff

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    CSO  (SearchSecurity.com)
    security clearance  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts