This podcast explores the challenges of trusting entry-level security professionals and how they can build trust and take on more responsibilities. It emphasizes the importance of mentorship, training, and institutionalized processes. The speakers also discuss the significance of self-thinking and problem-solving skills, as well as embracing imperfection and the value of entry-level employees.
Entry-level security professionals can gain trust by starting with predefined checklists and gradually increasing access as their maturity level improves.
Organizational leaders should invest in new talent, provide learning opportunities, and create an environment that fosters talent development and growth for entry-level cybersecurity professionals.
Deep dives
Building trust with entry-level security professionals
Entry-level security professionals face challenges in gaining trust within organizations. The need to balance providing access with minimizing unnecessary risks is a crucial concern. The podcast discusses strategies for building trust and allowing green professionals to grow in their roles. Mentoring and shadowing more experienced professionals can provide guidance and support. Starting with predefined checklists and gradually increasing access as their maturity level improves is an effective approach. Examples of entry-level tasks include vulnerability assessment with guidance from experienced colleagues.
Culture and roles in cybersecurity
The podcast explores the role of culture, security policies, and best practices in addressing the trust dilemma for entry-level cybersecurity professionals. It emphasizes having varying levels of responsibility and access based on institutional and domain knowledge, as well as experience. Organizational leaders are responsible for creating an environment that fosters talent development and growth. Guardrails and compensating controls play a vital role in allowing entry-level professionals to make decisions while minimizing negative consequences. Analogies are drawn to professions like nursing, the military, and pilot training, highlighting the importance of institutionalized learning and critical thinking skills.
Investing in talent and the role of experience
The podcast discusses the importance of investing in new talent and providing opportunities for learning and growth. Experience is seen as valuable, but the emphasis is on individuals who are motivated, willing to learn, and have a passion for cybersecurity. Entry-level roles, such as help desk and Tier 1 SOC analyst, are mentioned as good starting points for inexperienced professionals. The importance of mentorship, self-thinking, and creating an environment for safe failure is highlighted. The discussion acknowledges the need for institutionalized training in the cybersecurity field to ensure consistent and effective skill development.
All links and images for this episode can be found on CISO Series.
All experienced security professionals were at one time very green. Entry level status means risk to your organization. That's if you give them too much access. What can you trust an entry level security professional to do that won't impose unnecessary risk? And how can those green professionals build trust to allow them to do more?
Normalyze is a cloud data security platform that continuously discovers sensitive data and their access paths across your cloud environments. Normalyze provides the ability to analyze, prioritize and respond to data threats to prevent damaging data breaches.Discover, visualize, and secure your cloud data in minutes with Normalyze Freemium.
In this episode:
What can you trust an entry level security professional to do that won't impose unnecessary risk?
How can those green professionals build trust to allow them to do more?
What can they do with zero experience?
How can they graduate upwards?
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode