Operations // Careers & People

How to Solve the Security Skills Shortage

50%
50%

At RSA, security professionals weighed in on how to close the security skills gap -- if there is one -- and solve staffing problems.

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
KevinK-
50%
50%
KevinK-,
User Rank: Apprentice
4/1/2014 | 10:15:45 PM
BrightTalk and the skills shortage
I saw this from a LinkedIn security group I'm in. The presentation is from ESET company, which I have no interest in. ESET just happens to be the folks giving the presentation.

https://www.brighttalk.com/webcast/1718/106371
KevinK-
50%
50%
KevinK-,
User Rank: Apprentice
4/1/2014 | 4:18:06 PM
Re: Bringing in new perspectives
@SaraPeters. Hi Sara, I am an independent contractor, so I am paying for all my own training. I may have to wait until I finish my current VillanovaU training, and maybe pass either the CompTIA Security+ and/or Network+ exams, before getting 'in the door' on a job. I have more detail located here: http://myjourney2itsecurity.blogspot.com/2014/03/starting-point.html
Sara Peters
50%
50%
Sara Peters,
User Rank: Author
4/1/2014 | 10:45:35 AM
Re: Bringing in new perspectives
@tmccreight  Very, very cool. It's really great that you could get such value from someone who was just in an intern position.
Sara Peters
50%
50%
Sara Peters,
User Rank: Author
4/1/2014 | 10:42:58 AM
Re: Bringing in new perspectives
@KevinK  Good for you!  "I'm hoping with my work experience and training, that I can convince management of my desire to help make a difference."  Let us know how that goes!


Would you be willing to share a few more details? I'd love to know what kind of work you're volunteering for, what training you're taking, whether you're paying for that training yourself or if your company is paying for it, and how you plan to make your case to management to give you a job in security.
tmccreight
50%
50%
tmccreight,
User Rank: Apprentice
3/31/2014 | 12:02:30 PM
Re: Bringing in new perspectives
Keep at it, Kevin!  Forward thinking security managers will appreciate the skill sets you have as a BA, and taking additional security courses really shows your interest in the field.

If you get a chance to chat with the security management team, try focusing on the role a BA could play in their organization - linking the business drivers of different units in the organization to the role security plays by supporting business objectives and assessing risks. If you can make that link, most security managers will "get it" and want to chat further!
tmccreight
50%
50%
tmccreight,
User Rank: Apprentice
3/31/2014 | 11:59:57 AM
Re: Bringing in new perspectives
Hi Sara!  Thanks for the comment. 

The situation I was referring to involved an intern position we posted, and accepted a summer student who had a background in physical security (she was a security guard) but was working towards her certification in analytics.  We had a job opening for an intern in our security operations center and I gambled when I made the call to bring her on board. The job posting was structured to attract junior level candidates into the SOC and gauge their interest in the position.  We'd done this a few times and had some success, but these individuals were already in the infosec field.

It was worth the risk to hire someone outside of the typical infosec realm.  She came in with a fresh perspective and looked at the data we were collecting from a new angle.  She uncovered some very interesting patterns that lead to threats being blocked and some potential APT activity discovered in our network.
Sara Peters
50%
50%
Sara Peters,
User Rank: Author
3/31/2014 | 10:47:28 AM
Re: Bringing in new perspectives
@tmccreight  This is great to hear:  "we need to look outside the industry sometimes to find a different perspective.  I've made that judgement call, and was pleasantly surprised with the results.  I selected someone with a business and analytics background and trained them in InfoSec."  Was this someone you knew who already worked for the organization in a different capacity, or was this someone you hired from the outside? How did you structure the job posting to attract this person?
KevinK-
50%
50%
KevinK-,
User Rank: Apprentice
3/28/2014 | 7:18:10 PM
Re: Bringing in new perspectives
Absolutely, I like @tmccreight's creative thinking. I have been a Business Analyst in various forms, for 10 years. I have an interest in IT Security and I am taking a series of training classes. I plan to take some related certifications. I'm hoping with my work experience and training, that I can convince management of my desire to help make a difference.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
3/28/2014 | 2:24:17 PM
Re: Bringing in new perspectives
Would you go as far as embracing liberal arts as well as business a greate rfoccus on business topics? Dave Piscitello, VP Security, ICANN made that point in commentary on InformationWeek late last year. He wrote:

I work in InfoSec alongside respected colleagues who earned philosophy, physics, psychology, and political science degrees. I recently met former concert and improv flautists who are rock-solid privacy experts. STEM-centric education won't fill the short-horizon shortfall of cybersecurity talent -- and my head spins when I imagine the unintended consequences over the long term. For example, consider how critical trust and ethics are in cooperative society in general and InfoSec in particular. If you set yourselves on a course where only science matters, when and how do you teach ethics? If you must evangelize STEM, at the very least change the "T" to trust and "E" to ethics.

This makes a lot of sense to me. What do you think?

tmccreight
50%
50%
tmccreight,
User Rank: Apprentice
3/28/2014 | 1:58:48 PM
Re: Bringing in new perspectives
I think STEM is a great place to start, but I'd like to see business topics brought into the mix as well.  We've moved more to a risk-based, business focused approach with information security.  The IT Security professionals who can communicate in business terms and understand how business deals with risk bring new skills to the security work force.

 
Page 1 / 2   >   >>
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7298
Published: 2014-10-24
adsetgroups in Centrify Server Suite 2008 through 2014.1 and Centrify DirectControl 3.x through 4.2.0 on Linux and UNIX allows local users to read arbitrary files with root privileges by leveraging improperly protected setuid functionality.

CVE-2014-8346
Published: 2014-10-24
The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier for remote attackers to cause a denial of service (screen locking with an arbitrary code) by triggering unexpected Find My Mobile network traffic.

CVE-2014-0619
Published: 2014-10-23
Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.

CVE-2014-2230
Published: 2014-10-23
Open redirect vulnerability in the header function in adclick.php in OpenX 2.8.10 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) dest parameter to adclick.php or (2) _maxdest parameter to ck.php.

CVE-2014-7281
Published: 2014-10-23
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hijack the authentication of administrators for requests that reboot the device via a request to goform/SysToolReboot.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.