Showing posts with label Staffing. Show all posts
Showing posts with label Staffing. Show all posts

Wednesday, November 6, 2019

"A Teams" And Well Intentioned Mistakes In Cyber Security



Hiring an “A team” may seem like a difficult task to many cyber leaders. But retaining an entire team of As is even harder. 




We can begin with the common attribute of “A players” generally taking the initiative. Sometimes you’ll get great initiative and great results. Occasionally, you’ll get great initiative and poor judgment. Poor judgment that can lead to a mistake.


But, from a leadership perspective, a mistake made because of taking the initiative isn’t such a bad thing.

Friday, November 1, 2019

The Art Of Retaining Cyber Security Talent


The most important thing that we do as cyber security leaders is recruit high quality talent. The second most important thing that we do is work to retain that talent.




How does a leader retain talent in an often crazy market with a shortage of cyber security professionals?

  
To me, there are three fundamentals to success. Each is so fundamental that, in my mind, they can’t be prioritized into an order.

Saturday, October 19, 2019

Rarely Discussed Real Life Application Security Decisions


The cyber security industry often frames application security as a singular entity with a similar model, approach, and employee requirements across the full range of organizations. 



If only that were correct.

A key difference among application security models and approaches isn't the toolsets involved or the level of automation of those tools in the build pipeline, it's where the analysis of defects found by those tools takes place. The differences in each approach or model drive requirements for skillsets, resources, and scope with potential impacts outside of the cyber security team.  

Your organization will have some fundamental decisions to make. 

In some models, the development team performs the analysis of app security defects. The app security engineers tend to be tool focused. The output is simply passed to the development team. Application security engineers only need to have some familiarity with OWASP and other app security vulnerabilities as the analysis, prioritization, and severity of the defects is performed by the dev team.  The downside of this model is that (1) the dev team will need to be resourced to handle this analysis and (2) in many organizations, it’s the devs that have to process through the inevitable false positives and duplicates. 

In other models, an outsourced vendor performs the analysis of app security defects. They may also run the tools. From interviews, I’ve learned that some with the title, “application security engineer” actually represent the organization to manage the app security vendors. The downside here is (1) the potential cost of buy vs. build and (2) the organization may not be building longer term expertise, knowledge, and historical data around application security. 

In still other models, the application engineers perform the analysis of the defects. The upside of this model is that the app security team provides tangible value identifying false positives, removing duplicates, and often validating the automated classifications provided by the scanning tools. The downside is the depth of specific application development knowledge and experience required of the app security engineers.  In my team’s case, we focus on hiring previous developers and automated test engineers as we’ve rarely interviewed security engineers that have the ability to perform such tasks at a high level. 

So, when you are doing comparison between programs or listening to other senior cyber describe their application security program, there may be variances that don’t necessarily fit your organization’s goals, budget, or ability to resource. Some organizations can do great with a high percentage of app security interns because the work and the costs of detailed defect review are likely being borne elsewhere.  

You’ll also need to dig in during interviews to determine the fit of candidates. The title of “Application Security Engineer” can mean many things from “I throw the switch on tools” to “I manage a vendor” to “I look at defects and analyze them”. 

One size does not fit all in application security. As they say, “all models are wrong but some are useful.”

Hopefully, you find these useful. 

Follow me on Twitter for discussion and the latest blog updates: @Opinionatedsec1. Or, start your own discussion using #crazygoodcyberteams on twitter or Linkedin and I'll read it.

SEE ALSO





Thursday, October 17, 2019

Striving Towards Cyber Mediocrity


The best description I’ve heard of cyber security comes from a recent Forbes magazine article. That article describes cyber security as having to defend your house in a bad neighborhood without being able to lock the front door.



The cyber security industry provides us with a cornucopia of products and services upon which we spend tons of money and yet the house is still regularly robbed and often burned completely to the ground. And then we repeat the process expecting different results.

We are in a race towards mediocrity. Strangely, we may be striving for it.

Wednesday, October 16, 2019

Characteristics Of Great Cyber Practitioners


Great cyber security practitioners are not unicorns.  They are mentored, not born. If you meet what you consider to be a unicorn, someone in their past took the time to mentor them to where they are today.  Unfortunately, this may be why they are so few in number.



Your goal as a cyber leader should include mentoring your team to greatness. Anyone can work hard and become a good cyber security practitioner. It's a leadership responsibility to mold the team from good to great.

If you are a cyber security individual contributor, you deserve to become great. Insist upon it.

Thursday, September 26, 2019

What Do You Want In A Cyber Security Program?


There is no “one size fits all” approach when building or re-building a high performance cyber security team.






The team that you build depends on the cyber program that you currently have, the industry that you are in, and the type of program that you want to build.  


The definition of success for a security team in a regulated industry may be very different and require a different set of skills than a security team in a less regulated industry.

Saturday, August 24, 2019

The Application Security Thought Process


I’m a believer in specialists.




Why? I know the principles behind flight but I couldn’t build an airplane, how internal combustion engines work but bring cars to mechanics, and share the same key board as prize winning novelists but couldn’t write one.


Specialists know something deeper than the tools and basic principles for their craft.


The difference that makes the difference in the value of the end product. 

Tuesday, August 20, 2019

The Cyber Recruiting Value-Add


Every scene in a good movie pushes the story forward. Adds value. Expands the narrative.   


The same is true with each member of the cyber security team. Each hire will define your program's story and value.

Building a top performing cyber security team is the most important thing that you can do as a cyber leader. Your choices or compromises in hiring will play a large role in making or breaking your career. 

Hire well. 

Know What Security Skills For Which You Are Hiring: Are you hiring for someone to look at a console all shift? Someone to capability build?  Do they need to engage with stakeholders? Write policies? Are they working from a playbook, compliance, or risk checklist? Security skills run a wide specrum and the candidate’s certifications won’t tell you how they fit in the range of roles that you might have to fill.  In addition to these, natural smarts and enough technical curiosity to understand what is happening behind the console screens are important to me.  I’ve “no hired” candidates for an incident response role with a masters in cybersecurity and candidates with 10 years of SOC experience because neither had the technical curiosity to understand key concepts about operating systems or malware as part of their very different experiences. You might feel differently.

Write Every Position Description For The Ideal Candidate: My bar for position descriptions is that the ideal candidate should immediately see themselves in the description. I can’t tell you the number of times that recruiting has said, “we will never find someone like that” and the perfect fit knocks on the door the next week. A lukewarm, warmed-over, bland position description just like all the others will only get you lukewarm, warmed over, and bland candidates just like all of the others. Be brave. Be different.

Be Participative Upstream With Recruiting: Review every resume and tell Recruiting what you like and don’t like about a resume…even the ones that aren’t the right fit. This will help them better understand how candidates fit and help them find you more ideal fits. 

Pass Prospective Candidates To Recruiting: I like to do my own candidate search and pass the Linkedin links to Recruiting to reach out. Not all of the prospects work out for various reasons and that's ok. Again, the value is that it brings clarity to the experiences that the ideal candidate might have.

Help Recruiters With A Few “Rough Cut” Phone Screen Questions: The questions will help recruiters see if the candidate knows the basics for that specific role. 

Phone Screen For Resume & Experience: Spend your time during phone screens on the resume and experience of the candidate. This will allow you to keep these to a minimum if you bring them in for an interview loop. You should be spending interview loop.

So you own pushing your security program’s story forward. Here’s your chance. You know the stakes. Write that script. Start adding value with each hire rather than just hiring.

It's your future. Don't compromise.


Follow me on Twitter for discussion and the latest blog updates: @Opinionatedsec1. Or, start your own discussion using #crazygoodcyberteams on twitter or Linkedin and I'll read it.

SEE ALSO



Friday, August 9, 2019

The Cyber Security Prioritization Mismatch

You’d think that all cyber professionals are cut from the same cloth. That they'd prioritize cyber security work in a similar way.






They don’t. That’s because there is no magic prioritization for cyber security. Risk management, defending the network, capability building, and regulatory requirements all need to be balanced and prioritized for a given organization.  


No single cloth to cut. Teams of unmatched fabric. 

Wednesday, August 7, 2019

The Training Conference Underestimation


Some underestimate the value of cyber security training as a key part of recruiting and retaining a high performing cyber team. 




It’s all on the internet.


We should be hiring for self learning.


Let them pay for training themselves. 


But, managed correctly, there is real value beyond the cost of training. How do you manage it?