Conversations with CISOs and other important thought leaders offering advice for those wanting to enter the field, grow in the field of cybersecurity.
ThreatX surveyed 2,000 consumers in the US and UK about the cybersecurity skills gap – to get their thoughts on its causes and effects.
In this episode, Gene and ThreatX Field CISO Jeremy Ventura analyze the results, including:
62% reported that if they or their child had more education around cybersecurity in school, they would have considered entering the field.
90% reported that they are concerned about the future of cybersecurity if more isn’t done at an earlier stage to expose students to the field.
78% are under the impression that a college degree is necessary to pursue a career in cybersecurity, and 67% thought a career in cybersecurity should be achievable through certifications or apprenticeships versus a 4-year+ college degree.
52% say engaging students of all backgrounds earlier in STEM/cybersecurity courses it will help minimize the talent shortage among the cybersecurity industry.
Full survey results: https://info.threatx.com/hubfs/ug/ThreatX-global-2023-survey-cyber-talent-shortage.pdf
Jeremy Ventura on LinkedIn: linkedin.com/in/jeremy-ventura-36204676
What's the difference between working in fraud and working in cybersecurity? Nancy Schuehler, Director of Cyber Strategy and Program Execution at Verizon, has worked in both and breaks it down for our listeners.
She and Gene also dig into the pros and cons of working for a large enterprise, and of staying with one company for many years.
Nancy Schuehler on LinkedIn: https://www.linkedin.com/in/nancy-schuehler-87311610/
Verizon cyber recruiting: https://verizon.com/cybersecurity
No experience? No problem. In this episode, CISO Dane Jones explains how to build a resume that highlights a passion and aptitude for cybersecurity without any work experience in the field.
Dane Jones is CISO at HighRadius. He has been a security leader for many years, including at Lowe’s.
Dane Jones on LinkedIn: https://www.linkedin.com/in/daneejones/
Is a career in cybersecurity right for me? https://www.isc2.org/thank-you/is-a-career-in-cybersecurity-right-for-me
(ISC)² Cybersecurity Workforce Study: https://www.isc2.org/Research/Workforce-Study#
Cybersecurity is a great field because of the all the change, says Ted Julian. But to succeed, you have to be proactive about that change. Ted and Gene talk about how to keep up with the change, plus about his experience in the early days of cybersecurity, what it’s like to work in product management, and why joining an early-stage company is so beneficial.
Ted Julian has held leadership positions in several security companies, including Devo and Resilient. He is currently a Venture Partner at Glasswing Ventures.
Ted Julian on LinkedIn: https://www.linkedin.com/in/tedjulian/
Gene sits down with Stratejm CEO John Menezes to talk about working for an MSSP, plus gets John’s thoughts on hiring and nurturing the next generation of cybersecurity talent.
Stratejm: https://stratejm.com/
Success in cybersecurity is not about your technical skills, but your emotional intelligence, according to CISO Randy Raw. Randy and Gene talk about why he thinks this, plus his approach to hiring, why leaders need to be proactive in asking their reports how they want to be managed, why everyone needs both a coach and a sponsor, and more.
Randy Raw is the CISO at Veterans United Home Loans, where he has worked for almost 12 years. He is also a leadership coach at SABERS Coaching.
Randy Raw on LinkedIn: https://www.linkedin.com/in/randyraw/
Randy Raw’s blog: https://randyraw.com
Lowe’s CISO Marc Varner has had a long career in cybersecurity, including CISO roles at Yum Brands and McDonald’s. Why does he think cybersecurity is a good career choice? Because there is always a new challenge. “What was the last really cool discovery or change in math?” he jokes. There’s something new in cybersecurity just about every day.
Tune in to his podcast episode with Gene to hear more. They discuss his journey, keys to success in the field, skills from other experiences that are transferable to cyber, and what he is looking for in entry level candidates.
Why is the geopolitical landscape critical to cybersecurity strategy? CISO Mark Houpt breaks it down in this episode. Mark also shares his advice to the college and high school students he mentors, how to approach the ever-changing nature of cybersecurity, and how to think about a college education.
Mark Houpt is the CISO at DataBank. Previously he held senior security roles at organizations including State Farm, Lincoln Christian University, and Sallie Mae. Mark served in the US Navy from 1991 to 1999.
Mark Houpt on LinkedIn: https://www.linkedin.com/in/mark-houpt/
Mark’s recommended list of classes:
Microsoft CISO Workshop: https://learn.microsoft.com/en-us/security/ciso-workshop/ciso-workshop
Ascend Education: https://ascendeducation.com/monthly-subscription/
Amazon Cybersecurity Awareness Training: https://learnsecurity.amazon.com/en/index.html
Center for Development of Security Excellence: https://www.cdse.edu
ISC2 -Certified in Cybersecurity: https://www.isc2.org/1mcc
Cisco Networking Academy: https://skillsforall.com/course/introduction-to-cybersecurity
Cyberbit Remote Training: https://go.cyberbit.com/100k-worth-of-free-remote-cyber-range-training/?utm_source=nist_website&utm_medium=list&utm_campaign=free-remote-soc-team-training-nam
StationX - 12 Month Trial: https://www.cybersecurityjobs.com/csj-training-fund/
Cyber Training 365: https://www.cybertraining365.com/cybertraining/FreeClasses
Cyber Skyline Professional: https://cyberskyline.com/professional/purchase
Cybrary: https://www.cybrary.it
EC.Council: https://www.eccouncil.org/cybersecurity-exchange/free-cybersecurity-resources-2022/
Elastic: https://www.elastic.co/training/free
Evolve Academy: https://www.academy.evolvesecurity.com/cybersecurity-fundamentals
Federal Virtual Training: https://fedvte.usalearning.gov
How do you make the jump from ER nurse to SOC analyst? Alex Gatz did it, and he’s sharing his insights and tips with the eXecutive Security podcast audience. Don’t miss this fascinating discussion about making a bold career change, the power of LinkedIn, what a security researcher does, the benefits of working for a startup, and more.
Alex Gatz is a senior security researcher at ThreatX. Previously, he worked as a data analyst and ER nurse at MidMichigan Health.
Alex Gatz on LinkedIn: https://www.linkedin.com/in/alexgatz/
Stephen Semmelroth: https://www.linkedin.com/in/semmelroth/
We Hack Purple: https://www.linkedin.com/company/wehackpurple/
The job market has shifted dramatically in the past two years, and Mike Privette shares his thoughts on navigating it in this episode. He and Gene discuss things you can do TODAY to get your foot in the cybersecurity door. He also shares how his newsletter Secure the Job can help.
Mike Privette is the CISO, VP of Information & Cyber Security at Passport. He is also the founder of Return on Security, which publishes the Security, Funded and Secure the Job newsletters. Previously, he held cybersecurity leadership roles at various organizations, including Defiance Digital, Truist, MetLife, and Ally Financial.
Mike Privette on LinkedIn: https://www.linkedin.com/in/mikeprivette/
Secure the Job newsletter: https://jobs.returnonsecurity.com
Key to a successful tech career? Re-inventing yourself every three years, says Faisal Bhutto, SVP of Cloud and Cybersecurity at Calian. Don’t go into tech if you’re not ready to be constantly learning and re-inventing yourself, he says. Hear more tips and advice from Faisal in his episode, including why money and promotions can’t be your only motivation, why you shouldn’t network only to look for a job, and how to get into cybersecurity without a tech background.
Faisal Bhutto is SVP of Cloud and Cybersecurity at Calian IT & Cyber Solutions. Previously, he was the co-founder of and COO at ENETsolutions.
Faisal Bhutto on LinkedIn: https://www.linkedin.com/in/fbhutto/
Corey Nenno (aka That Cyber Guy) just transitioned out of the military and into the cybersecurity industry in 2021 – so this is an ideal episode for those currently in the military looking to soon enter the cybersecurity field. It’s also one of our most practical episodes, whether you’re in the military or not – it’s filled with tips and advice on what to put on your resume, how to pass the CISSP, how to find a mentor, and more.
Corey Nenno is a Senior Cyber Intelligence Analyst at Cargill. Previously, he spent 12 years in the US Army in Cyber and Information Technology fields.
VetSec: www.veteransec.org
Corey Nenno on LinkedIn: https://www.linkedin.com/in/coreynenno/
Cyber Mentor Dojo: https://cybermentordojo.com
Alfredo Hickman fought the war on terror in the early 2000s in the Marine Corps infantry in Iraq. He shares some intense stories from his military experiences overseas with Gene, as well as how he transitioned from the front lines to a cybersecurity executive. Alfredo is passionate about helping veterans and giving back, and this episode is valuable for anyone looking to enter this industry, military or not. He shares details about his life and journey, his thoughts on cybersecurity trends in 2023, how the SANS Institute has been a resource for him and can be for others, his thoughts on mentoring, and more.
Alfredo Hickman is Head of Information Security at Obsidian Security. He previously held security leadership positions at Rackspace. Alfredo served in the US Marine Corps from 2003 to 2011.
Alfredo Hickman on LinkedIn: https://www.linkedin.com/in/alfredohickman/
Obsidian Security: https://www.obsidiansecurity.com
SANS Institute: https://www.sans.org
David Cross’ advice for breaking into cybersecurity? Strategic use of gift cards. Get details on his networking through social media ideas in this episode. David transitioned out of the military into the world of high tech, where he has held numerous cybersecurity leadership roles. This episode is filled with practical tips and advice on demonstrating your skills to prospective employers, deciding what type of company to work for, transitioning military skills to the corporate world, networking, and more.
David Cross is the Senior Vice President, Chief Information Security Officer (CISO) of Oracle SaaS Cloud. Previously, he held senior leadership positions at numerous companies, including Google and Microsoft. David also served in the US Navy from 1991 to 1996.
David Cross on LinkedIn: linkedin.com/in/☢️-david-b-cross-b856657
Zenobia Godschalk has worked closely with many cybersecurity companies over the years as the founder of ZAG Communications, a PR and marketing firm serving technology companies, and is now SVP of Communications for Hedera. She also does a lot of philanthropic work in the technology space.
LinkedIn: https://www.linkedin.com/in/zenobiaaustingodschalk/
Dark Reading Article: https://www.darkreading.com/remote-workforce/senior-level-women-leaders-cybersecurity-nonprofit
Forte Group:https://forte-group.org/home-our-mission
Andreessen Horowitz:https://a16z.com
Brian Castagna is the CISO at Seven Bridges, a leading biomedical data company. He is an experienced and skilled information security leader who has held security leadership positions at several organizations including Acquia and Oracle.
LinkedIn: https://www.linkedin.com/in/brian-castagna-1890544/
Jenn Reed has more than 25 years of product management and engineering experience in cloud networking infrastructure, security, governance, risk, and compliance across both the private and public sectors. She is currently CISO at Aviatrix, a cloud networking and network security company. Jenn served her country in the U.S. Marine Corps from 1995-2000 and again in 2003 during the Iraq war.
LinkedIn: https://www.linkedin.com/in/jennsreed/
Ramachandra Hegde is a senior executive with over 24 years of experience, including 12 years in global CISO roles, including with a Fortune 300 manufacturing multinational and a global professional services firm. He is currently senior vice president and CISO at Genpact.
LinkedIn: https://www.linkedin.com/in/ramkhegde/
Dan Schiappa, the chief product officer at Arctic Wolf, has been a technology leader for many years at organizations including Sophos, RSA Security, and Microsoft.
LinkedIn: https://www.linkedin.com/in/daniel-schiappa-bbb1062/
University of Central Florida News: https://www.ucf.edu/news/cybersecurity-team-wins-4th-national-championship/
Arctic Wolf: https://arcticwolf.com/company/careers/
Richard Ford is an experienced cybersecurity and technology leader. Currently the Chief Technology Officer at Praetorian, he has held leadership positions at many organizations, including Cyren, Forcepoint, and Raytheon. Richard also has a Ph.D. in Physics from the University of Oxford.
Personal LinkedIn: https://www.linkedin.com/in/dr-ford/
Praetorian LinkedIn: https://www.linkedin.com/company/praetorian/
ISC2: https://www.isc2.org
BSides: https://bsideslv.org
Lauren is just starting her career in cybersecurity. She has a bachelor’s degree in cybersecurity from Champlain College and is a SOC Analyst at ThreatX.
LinkedIn: https://www.linkedin.com/in/laurencampanara/
Ray has more than 15 years of experience in the information security space and is currently CISO at Inspectiv. He has held leadership positions at numerous organizations including, Cobalt.io, Amazon, Proofpoint, and Cisco.
LinkedIn: https://www.linkedin.com/in/ray-espinoza-b399821/
Black Girls in Cyber: https://www.blackgirlsincyber.com
Maarten Van Horenbeeck, who is the chief information security officer at Zendesk, has more than 15 years of experience managing security organizations, which includes building the cybersecurity-threat intelligence team at Amazon, and working on the security teams at Google and Microsoft. He is also a former board member and Chairman of the Forum of Incident Response and Security Teams (FIRST).
LinkedIn: https://www.linkedin.com/in/maartenv/
Chaos Computer Club: https://en.wikipedia.org/wiki/Chaos_Computer_Club
NIST: https://www.nist.gov
MITRE: https://www.mitre.org
Rand Institute: https://www.rand.org
FIRST: https://www.first.org
Cloud Security Alliance: https://cloudsecurityalliance.org
Jim Routh has a long history in technology and cybersecurity as a leader and management consultant. He was formerly a cybersecurity leader for many large companies including MassMutual, CVS Health, Aetna, and JP Morgan Chase. He is also the former Board Chair for the Health Information Sharing & Analysis Center (H-ISAC) where he served for five years and former Board member for the Financial Services Information Sharing & Analysis Center (FS-ISAC). Jim currently sits on several Boards and acts as an advisor for several cybersecurity companies and venture funds. Jim brings to the boards a vast business and technology background and is considered a digital and cyber security industry expert and thought leader. Finally, Jim is an ICIT Fellow and an Adjunct Faculty member for NYU.
The Role of Cybersecurity Leaders as Educators: https://icitech.org/wp-content/uploads/2022/03/ICIT-Fellow-Perspective-The-Role-of-Cybersecurity-Leaders-as-Educators.pdf
LinkedIn: https://www.linkedin.com/in/jmrouth/
Jim Routh's Book List:
Cybersecurity and Cyberwar by Singer and Friedman
Dark Territory by Kaplan
The Perfect Weapon by Sanger
Sandworm by Greenberg
The Cuckoo’s Egg by Stoll
Spam Nation by Krebs
Future Crimes by Goodman
Data and Goliath by Schneier
Confront and Conceal by Sanger
The Fifth Domain by Clarke
America the Vulnerable by Brenner
The Code Book by Singh
Algorithms to Live By by Christian and Griffiths
Your Government Failed You by Clarke
Sting of the Drone by Clarke
Countdown to Zero Day by Zetter
Software Security: Building Security In by McGraw
@War by Harris
Fight Fire With Fire by Tarun
Kingpin by Poulsen
The Age of Surveillance Capitalism by Zuboff
The Internet in Everything by DeNardis
Senior Cyber by Schober
CISO Compass by Fitzgerald
This Is How They Tell Me the World Ends by Perlroth
Crimedotcom by White
Big Breaches by Daswani and Elbayadi
Innovating in a Secret World by Srivastava
Cyber Mayday by Lohrmann and Tan
Navigating the Cybersecurity Career Path by Patton
Tribe of Hackers by Carey and Jin
The PtaaS Book by Wong
CyberJutsu by McCarty
Cyber Defense Matrix by Yu
Shape by Ellenberg
So You Want to Talk About Race by Oluo
White Fragility by Diangelo
Hos to Be an Antiracist by Kendi
Ron is President at Gula Tech Adventures, which focuses on cyber technology, cyber policy and recruiting more people to the cyber workforce. Since 2017, GTA has invested in dozens of cyber start-ups and funds and supported multiple cyber nonprofits and projects. From 2002 to 2016, Ron was the co-founder and CEO of Tenable Network Security. He helped grow the company to 20,000 customers, raise $300m in venture capital and grow revenues to $100m, setting up the company for an IPO in 2018. Prior to Tenable, Ron was a cyber industry pioneer and developed one of the first commercial network intrusion detection systems called Dragon, ran risk mitigation for the first cloud company, was deploying network honeypots in the mid 90s for the DOD and was a penetration tester for the NSA and got to participate in some of the nation's first cyber exercises. Ron was also a captain in the Air Force.
LinkedIn: https://www.linkedin.com/in/rongula/
Gula Tech Adventures: https://www.gula.tech
Cybrary, Free Cybersecurity Training and Career Development: https://www.cybrary.it/
SANS Institute: https://www.sans.org
Bill Brown is an accomplished information technology and information security leader with experience leading M&A Security Due Diligence Response and Remediation, and leading global teams in start-up, mid-size, and Fortune 1000 companies. Currently he is CISO and CIO at Abacus Insights and an advisory board member to ThreatWarrior. He has also held security leadership positions in ClickSoftware, Houghton Mifflin Harcourt, Veracode, and Iron Mountain.
LinkedIn: https://www.linkedin.com/in/billbrownusa/
HIPPA: https://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act
Hiitrust: https://en.wikipedia.org/wiki/HITRUST
PII: https://www.techtarget.com/searchsecurity/definition/personally-identifiable-information-PII
Cyber Warrior: https://www.cyberwarrior.com/
Cloud Security Alliance: https://success.impartner.com/English/Customer/home.aspx
James Carder is an experienced Chief Security Officer, research and development leader, cyber security services expert, and go to market executive with over 26 years in both corporate security and consulting for public and private companies across various industries, the Fortune 500, and U.S. Government. Currently, he is the Chief Security Officer at iOffice + SpaceIQ. James also served in the Air Force.
LinkedIn: https://www.linkedin.com/in/carderj/
Twitter: https://twitter.com/carderjames
ISSA: https://www.issa.org/
OWASP: https://owasp.org/
Cloud Security Alliance: https://cloudsecurityalliance.org/
BSides: https://bsideslv.org/
U Minnesota Certificate Program: https://bootcamp.umn.edu/cybersecurity/
Ian Amit is an executive manager in the security and software industry with vast experience in multiple fields - from enterprise security, through retail, to end-user software, large back-end systems, corporate security policy, regulatory compliance, and strategy. He has spoken at various customer-focused seminars such as DEFCON, RSA, BlackHat, BSides, and many more.
LinkedIn: https://www.linkedin.com/in/iamit/
DEFCON: https://defcon.org
BSides: https://bsideslv.org
Tanya Janca, also known as SheHacksPurple, is the author of ‘Alice and Bob Learn Application Security’. She is also the founder of We Hack Purple, an online learning academy, community and weekly podcast that revolves around teaching everyone to create secure software. Tanya has been coding and working in IT for over twenty years, won numerous awards, and has been everywhere from startups to public service to tech. She values diversity, inclusion, and kindness.
LinkedIn: https://www.linkedin.com/in/tanya-janca/
Jobs in InfoSec: https://shehackspurple.ca/2022/01/01/jobs-in-information-security-infosec/
We Hack Purple Community: https://community.wehackpurple.com/
Chris Wysopal is Co-Founder and Chief Technology Officer at Veracode, which pioneered the concept of using automated static binary analysis to discover vulnerabilities in software. In the 1990’s, Chris was one of the original vulnerability researchers at The L0pht, a hacker think tank, where he was one of the first to publicize the risks of insecure software. Chris started his career as software engineer that first built commercial software and then migrated to the specialty of testing software for vulnerabilities. He has led highly productive and innovative software development teams and has performed product strategy and product management roles.
Chris is a much sought-after expert on cybersecurity. He has been interviewed for most major technology and business publications, including New York Times, The Washington Post, WSJ, Forbes, Fortune, AP, Reuters, Newsweek, Dark Reading, MIT Tech Review, Wired, and many networks, including BBC, CNN, ABC, CBS, CNBC, PBS, Bloomberg, Fox News, and NPR. He has keynoted cybersecurity and technical conferences on 4 continents.
Link: Chris Wysopal LinkedIn
Link: Cult of the Dead Cow by Joseph Menn
David McLeod is the VP, Chief Information Security Officer at Cox Enterprises. He is an experienced Chief Information Security Officer who has demonstrated success across multiple industries. David has extensive skills in Privacy, Enterprise Risk Management, IT Strategy and Governance, and Information Risk Management.
David McLeod LinkedIn
Patti Titus is the Chief Privacy and Information Security Officer at Markel Corporation. She also serves on the Board of Directors for Black Kite and the Girl Scouts of the Commonwealth of Virginia. She was recognized as a 'Woman of Influence' by the Executive Women’s Forum in 2009 and the Silicon Valley Business Journal in 2013.
Patti has held numerous leadership positions in the cybersecurity industry, including at Freddie Mac, Symantec, Unisys Corporation and the Transportation Security Administration within the Department of Homeland Security.
Patricia's Linkedin
SANS Institute
Special thanks to Tom Quinn for joining us in this episode:
MomentumCyber: https://momentumcyber.com/
Girl Security: https://www.girlsecurity.org/
Hello and welcome to the eXecutive Security podcast where we talk to CISOs and other leaders in cybersecurity about a career in this industry, specifically how to get into it, and how to advance. My name is Gene Fay and I'm the CEO of ThreatX an API security company and the host of the eXecutive Security podcast.
I started this podcast because of my two passions, cybersecurity and helping people find jobs in cyber. Over the last 17 years, I've been blessed to meet so many amazing people within this industry. People who taught me not only about cybersecurity, but how to be a great leader. For a while I've been thinking about how I can give back to the cybersecurity industry, which has been so good to me.
Also, I've been thinking about what I've learned from great leaders in this space, and I can share this knowledge with a lot of people. So this [00:01:00] is how this podcast was started.
If you were just thinking about getting into cybersecurity and want to learn how to get started, or if you're in the field and aspire to be a manager, VP, or CISO, this podcast is for you.
I hope you enjoy it. If you have any suggestions on guests or topics you want us to cover in the future, please send me an email at genedotfayatthreatxdotcom. Thanks a lot and I hope you enjoy the podcast.