Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operations

12/1/2014
02:55 PM
Connect Directly
Twitter
RSS
E-Mail
100%
0%

How I Became a CISO: Jonathan Trull, Qualys

Technology was more of a hobby than a career choice for Jonathan Trull, but protecting people was always job number one.

Jonathan Trull, chief information security officer for Qualys, says he was always in the protection industry. Like many CISOs, Trull did not set out for a career in infosec, but rather stumbled into it in a happy accident. While some CISOs began their journeys as far afield as physics, law, auto repair, and liberal arts, Trull from the beginning was doing security -- just a rather different sort.

Trull got his Bachelor's degree in criminal justice (and later a Master's in public administration) and proceeded to become a correctional officer. He was an intelligence officer in the US Navy Reserves for eight years.

In his off-time, he was tinkering -- fiddling with client computers and servers, developing websites for friends and family, nerding out about Linux in open-source community groups. Yet he had always seen it as more of a hobby than a career.

Computer-based threats were becoming a bigger and bigger issue for the military, though, and Trull's role as lieutenant commander adapted accordingly.

In 2011, he took a position in the State of Colorado's Office of the State Auditor. Being an auditor satisfied Trull's interests in public service and IT risk. But there was something missing.

"I wanted to not just tell people" to institute security practices, he says. "I wanted to do it myself."

So, when Colorado's CISO job became available, Trull applied and landed the job, managing information security for a "cloud-first" state government with 2,500 servers, 26,000 employees, and nearly as many missions. A daunting challenge, especially if you consider the CISO role to be about more than flashing lights and whirring machines.

"Being a CISO in any company is much more than technology," says Trull. "You should have a very good breadth of the business you're in, because security touches everything."

Fortunately, Trull enjoys those softer aspects of security leadership -- like building relationships with other departments and educating users on subjects like cloud computing risks and rewards.

While at Colorado, however, he decided he wanted to be CISO for an innovative company, and says he found just that when he joined Qualys in May.

As CISO of a security company, he must exercise and maintain his techie know-how much more than he did in Colorado. His team gets to play a role in product development, and at Qualys he doesn't have to sell the concept of secure development, as his colleagues at other tech companies might.

"Our software developers [at Qualys] are well educated in secure coding, but that's not always the case."

Along the way, Trull has earned certifications for auditing (CISA), fraud examination (CFE), and offensive security (OCSP). "My philosophy is. I'm responsible for my education," whether an employer will pay for it or not.

Nevertheless, he doesn't think that those abbreviations tacked on the end of his name helped him get his CISO positions. Making connections with people, he says, is more important.

"I'm a huge proponent of social networking," says Trull. He has met people helpful to his career at conferences and through group conversations on LinkedIn. There's value in those conversations, he says, even if they're casual, and particularly if you volunteer yourself to collaborate with others: "Put yourself out there."

More critical even than meeting new peers, says Trull, is to find a mentor -- a CISO with the time and generosity to help you develop your skills, plot your path, and meet the right people.

If he wasn't a CISO, Trull suspects that he would work for a non-profit organization, perhaps as an international health aid worker.

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
12/3/2014 | 11:03:22 AM
Mentors
Good piece of advice from Jonathan about finding mentors. @SaraPeters, Did he  mention who mentored him and who he mentors in his current role?

Also curious to hear the experiences frm the Dark Reading community about being mentored or mentoring others. Have you found this worthwhile? Or even possible? Let's chat about it...

 
News
Former CISA Director Chris Krebs Discusses Risk Management & Threat Intel
Kelly Sheridan, Staff Editor, Dark Reading,  2/23/2021
Edge-DRsplash-10-edge-articles
Security + Fraud Protection: Your One-Two Punch Against Cyberattacks
Joshua Goldfarb, Director of Product Management at F5,  2/23/2021
News
Cybercrime Groups More Prolific, Focus on Healthcare in 2020
Robert Lemos, Contributing Writer,  2/22/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Building the SOC of the Future
Building the SOC of the Future
Digital transformation, cloud-focused attacks, and a worldwide pandemic. The past year has changed the way business works and the way security teams operate. There is no going back.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-21302
PUBLISHED: 2021-02-26
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed in 1.7.7.2
CVE-2021-21308
PUBLISHED: 2021-02-26
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout system is not complete and an attacker is able to foreign request and executes customer commands. The problem is fixed in 1.7.7.2
CVE-2021-21273
PUBLISHED: 2021-02-26
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, requests to user provided domains were not restricted to external IP addresses when calculating the key va...
CVE-2021-21274
PUBLISHED: 2021-02-26
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver could redirect requests to their .well-known file to a large file. This can lead to...
CVE-2021-23345
PUBLISHED: 2021-02-26
All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint when the src attribute of an HTML element refers to an internal system file, such as <iframe src='file:///etc/passwd'>.