SecurityMetrics Podcast | 27
The Myth of the Cybersecurity Workforce Shortage
“Is there really a shortage of skills in cybersecurity? Or are we just looking at it the wrong way?”
Director of Information Security and IT at BEEM Technologies, Naomi Buckwalter (CISSP, CISM) discovered hacking at Vanguard, where she joined a class and learned to hack from scratch. Her experiences as a software security architecture, security engineer, career advisor, mentor, and speaker have given her a broad spectrum of insight about the so-called cybersecurity “skills shortage.”
In this episode, Naomi Buckwalter talks with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) about why mythology and gatekeeping in cybersecurity are holding the industry back and creating an uncertain future.
Listen to learn:
- Why new professionals see barriers in cybersecurity and what industry veterans need to do to paint a better picture
- How improving emotional intelligence and culture in the cybersecurity community can help us better fight cybercrime
- Tips for people who want to get started in cybersecurity
Resources:
Download our Guide to PCI Compliance! - https://www.securitymetrics.com/lp/pci/pci-guide
Download our Guide to HIPAA Compliance! - https://www.securitymetrics.com/lp/hipaa/hipaa-guide
[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.
The Myth of the Cybersecurity Workforce Shortage Transcript
Hello, and welcome back to the Security Metrics podcast. I'm Jen Stone. I'm one of the principal security analysts here at Security Metrics. Super excited today to talk to our guest.
We have a topic of it's pretty timely. How hiring managers and security teams can make it easier to train up the next generation of cybersecurity professionals.
Common sense and practical tips for security teams and hiring managers. The reason I think this is important is I continually see, especially on LinkedIn, some of the other places where we have conversations, what do we do about these the so called myth of the, cybersecurity, shortage?
I think that that Naomi is going to have a lot to speak to us about today. Her her name is Naomi Buckwalter. I'm gonna read to you her bio because it's pretty amazing. So first of all, she has her CISSP, CISM, and holds two master's degrees from Villanova.
That's awesome. And bachelor's of engineering from Stevens Institute of Technology, director of information security and IT at Beam Technologies.
Over twenty years of experience in IT and security and has held roles in software engineering, security architecture, security engineering, and security leadership. Those are fantastic, broad array of things. If you're interested in going into cybersecurity, having a really broad understanding of how how IT works is going to to pave the path for you. Cybersecurity career advisor and mentor for people around the world. She's passionate about helping people, particularly women, get into cybersecurity.
She volunteers with the Philly Tech Sistas, a Philadelphia based nonprofit helping women of color prepare for a career in a in, IT and tech. In her spare time, she plays volleyball and stays active as the mother of two boys, And her love language is bacon, which I can totally relate to. Naomi Delicious.
Thank you for being on the show. Welcome. Did I miss anything? Did I get anything wrong? Were there any updates? I kind of stalked here, like, Facebook group.
Oh my gosh. No. You did it perfectly. Actually, this is a secret, but I love bacon, but I was a vegetarian for seven years. Oh my goodness. So apparently, that didn't work out. And now I'm just like meat all the time.
That's, that's bacon is for reals, the killer for me on on vegetarianism.
Yeah. So I I was a few weeks ago, I thought I need to get someone to come talk to me about the cybersecurity path. How do we bring more people in? What's the entry point for that?
Is there really a a shortage of skills or are we just looking at it the wrong way? And I started reading some of the things that you were posting about bringing people into cybersecurity, and I thought you have a very excellent perspective on this that I would love other people to hear about. So maybe we could start with, your your personal journey into a cybersecurity career. What propelled you into the industry, and how has it shaped your desire to help other people come into the industry as well?
Oh, I love that question. Thanks. Oh, well, I'll just say someone gave me a chance way back in the day. I think it was, like, when I was twenty seven, twenty eight. I was a software engineer at a company called Vanguard, and a great, great company. Learned a lot there. Huge, huge multi trillion dollar mutual fund giants.
In fact, the founder invented a mute the mutual fund. So Jack Bogle, founder of Vanguard Group. So I started off as a software engineer there. I learned IT basically from scratch.
After a few years there, I took a class in hacking. And the moment I sat down and started taking this class, the heavens opened up. You know, the angels started singing and this was, this is my thing. This is what I was gonna do.
I just had this revelation and I was gonna be in security. And so I went up to the security manager. At the time, he had a position open for a senior level application security engineer, and I said, hey. I need to be on your team.
What will it take? And he said, who are you? Go away.
Stop annoying me.
And I didn't. I did not go away. I kept asking him pretty much like every other week. So, do you have an opening now?
You know? I just kept going back to him. So, how about now? You know? Eventually, he got so sick of me that he gave me a job.
And that is a true story. His name is Anthony Kaneki. He's since retired, so, I think he retired maybe a few years ago. But, yeah, he gave me a chance and I've been doing security pretty much ever since.
I took like a little sabbatical to learn about the business, about mutual funds. But, for a good fifteen years now, I've been doing technology and security.
Straight, but overall twenty years I would say, including all my internships and previous jobs in technology. So it's been a lot of fun. And to your second question, what makes me what drives me into helping others into cybersecurity? So Jen, I'll just tell you, I turn forty in a couple weeks, and I will say I would love to retire.
So my whole goal now is to retire and not have to worry about my data and my privacy and all the things that keep me secure, because I don't want to have to worry about the next generation of cybersecurity professionals not being there Mhmm.
After my generation leaves. And so if you know, like there's a there's a whole set of problems with our industry. There's a lot of unfilled positions, and most of those positions are for mid senior and above. Right?
There's not a lot of openings for entry level cybersecurity professionals. A lot of the openings are for people with experience. And so to me that's a problem. If we don't have people filling those positions, we won't have them, not just now, we won't have them in five or ten years or twenty.
When I'm ready to retire, there's not gonna be another generation backfilling for the work that needs to be done, and I think that is a huge problem. So recently, just within the past pandemic, this most recent pandemic, I have been, just trying to to to say kind of things that have always been on my mind. Like, why is it so hard to get into cybersecurity? I don't really think it's that difficult to learn.
I think there are things that junior level folks can do. So I was just saying a couple of these things, it kind of just snowballed into this this thing where I'm like, now this is all I ever want to talk about. Right? And trying to get people into cybersecurity.
So, yeah, it's been quite a a wild ride, I would say. And now I'm here talking to you, Jen.
Well and like you just said, there are a lot of people who think it's hard. There are a lot of people who who who hear cybersecurity and they think this is something I can't do or there's some barrier to entry for me. And so they don't even set a foot in you know, towards that path. What do you think we can do to help them understand, the the steps towards it that it's not as hard as maybe the mythology would want us to think.
Yeah. I mean, why do we do that? Right? I always wonder, like, is it because we're we just wanna seem important? Right? Like, our jobs are so mysterious.
And, like, you know, we're fighting against hackers, and they're wearing these black hoodies, and nation state actors, and oh my.
I don't know. It could just be one of those self preservation things where we wanna seem more important. I get that. That's a human thing where we just wanna be, like, you know, people ask you what you do.
Oh, I'm in cybersecurity. Right. Oh, you know, you want to seem impressive. But I think I think we're hurting ourselves this way.
Like, if we say it's really difficult, people are gonna probably be like, okay, yeah, then you handle it. Right? So how is that actually working out for us? Because what I see is a lot of burnout, a lot of stress, a lot of overworked cybersecurity professionals.
And as you know, Jen, I think the average tenure for a cybersecurity professional is literally like two years or less. I think the last time I saw this statistic, it was like every CISO changes a job every eighteen months or sixteen months, something like that. Where to me I'm like, that's totally true. I that happened to me a few times.
Like, so, you know, it's just because you get a little bit burned down or a little, you know, a little over it because one, you don't really get the support of the leadership Mhmm. In your company. Two, your your teams are so small, you're doing all the things.
And, you know, you're just worked to the bone and and you're ready for a change. So I get that. So we're only hurting ourselves, and this kind of gets back to my original point. We're only hurting ourselves when when we don't let people in, and we just try to do it all ourselves. And so we are burning out, we are overworking ourselves. And I think that another statistic here, I think about seventy percent of us self medicate on alcohol or drugs and or drugs.
You know, I wouldn't be surprised because I I talk to when I go to conferences, and this is a topic we have not raised yet on this on this podcast, but mental health issues among security professionals and the use of alcohol and, illicit drugs, it is a problem in the industry. And I've seen it shift, over time. It used to be the IT, like the sysadmins that were the superheroes keeping everything afloat. It's shifted now.
That's gone into the security realm. And I think you're right. It is that feeling of I wanna feel important, but also the the issues of overwork and the, turning to to negative behaviors, in order to, support that, lack of sleep, the lack of, time, the the, the feeling that you can never get caught up, that has shifted now a lot into the security side of things. Now, I don't have reports in front of me to to demonstrate that that is true.
But just in speaking with, colleagues, it seems to be that that is the shift that's happened. And I wonder how much of that is, an anxiety that we put on ourselves bay that that is related to, well, I need to be the king of this castle. I need to be the one who's who's saving everyone.
And how much of it is it's a a new and growing, sector of business that's important to the business.
But maybe the business doesn't understand it well enough to support it properly, and maybe people in security don't understand the business side of things well enough to, integrate in a mature way.
Oh, yeah. I hear you. And I absolutely agree. I think it is a burden that we've created for ourselves. And again, it's just trying to be important, trying to be needed, and I get that. But it would be so much better and easier if the business or your organization or whatever you're working in, your nonprofit, if everyone shares the load. And there is so many different levels of cybersecurity.
And I like to say cybersecurity is like a foreign language. Like anyone can learn one as long as you have enough time, resources, and you put in some effort. You can start with really simple words. Everyone can learn a couple words in pretty much every language, except for maybe the ones where you can't rule your r's. Like I can't do r's. Like Spanish r's.
I can't do that either.
Yeah. It's like, okay. I can't do those. Got it. But there are so many different things you can learn.
You can start with phrases, then sentences. Now you can, have conversations. Like, there's levels. Just like cybersecurity, you can start with very basic hygiene.
And then you move on towards like, hey, a little bit more technical, a little bit more like savvy kind of stuff. Right? Like, installing a VPN or whatever, using a VPN or, you know, things like that where anyone can really do it, they just have to learn. And by the time you get to IT or you're out of college and now you're working, you have already built up this language and this common understanding of cybersecurity.
And imagine now, Jen, if the entire world was like that, I can see us actually winning this war on cybercrime. Because, yes, this is a war, but we are so disjointed. We are so disconnected from one another. We are so mistrustful of new people trying to get into cybersecurity that we are fighting a war alone. We are not together. And if you know anything about cyber criminals, like, they are so coordinated. Like, they are so organized.
And they win. They're winning. The last survey I saw, the Verizon data breach report investigations, what is it? Data breach investigations report.
I think something like, you know, three point five billion dollars was lost to cybercrime in twenty nineteen, and then, like, according to the FBI, thirteen hundred cybercrimes were, reported every day. And again, that's just the number that were reported.
Like, who knows how many people don't actually report Sure.
Whenever their stuff is hacked. So it's it's real money. Like these Yeah. These poor people.
Like, I know several victims who just their entire life just gets ruined for for a good few months while they try to figure things out. So we are losing and I think a lot of the reason is why because cybersecurity professionals act as gatekeepers and we're afraid to let people in. And to me, that just makes no sense. I think it is quite easy to learn as long as you're starting small.
You're not gonna throw everything at them. You don't have to give all of the x number of domains, however CISSP decides on this year, how many domains you're gonna have this year. Six or eight. Just choose one, guys.
Like there there are things that you can learn, and you can continue to scale and continue to to mature. And it's just like in an organization, you start small, you teach, and here's the thing, I like to teach. So as cybersecurity professionals, we are guides and mentors and teachers of what good information security looks like. And so by the time you leave or you retire or you go on to a better place, like, the the the company that you just left should be a better place.
Like, you should have taught enough people where they can now do security activities without you. And that is our goal. Yeah. We wanna build a little army.
Yeah.
I love that. That's and it I've seen that in action. So some of the organizations that I work with that are doing it well, they use most of them have to adhere to a certain standard or a certain set of regulations. And somewhere in those standards and regulations, they always talk about training, security awareness, security training. And the companies that are doing it well, they are teaching the set the security concepts to the individuals that are applicable to that individual.
Starting with instead of, well, you know, here's what you have to know about hip HIPAA or here's what you have to know about PCI. And then either throwing the kitchen sink at them or just telling them it's something that that they have to follow and they should just read policies. But the ones that are that are doing it well look at what is the individual's potential impact to the security of the organization.
If their security is potentially impacted by their password and whether they use multifactor authentication or not, then you stick the training to that and then expand from there. But if their potential impact is they are a, an application developer and they need to understand what the cyber kill chain is through their application to the data, then they need a lot more training. And so, developers are uniquely situated to learn more about cybersecurity.
But that doesn't mean that the front desk person answering the phone shouldn't also be trained. They should there should be thought behind it to to, give them knowledge specifically for their job. And then, like you said, build on it from there so that cybersecurity isn't this big, opaque thing that we don't understand, but but there are pieces that we build on and build on so that over time, it becomes more ingrained into the whole population. Here's what we do and here's how we do it.
Yeah. You're you're preaching the sermon. How do I subscribe to your newsletter? That was perfectly stated.
Okay. But then there's the negative ones that you were mentioning as well, which is, sometimes security professionals are extremely disdainful of their users. Right? The and user's a perfectly fine name. But I a lot of times when you say, oh, the user doesn't know, it the disdain that comes from your users are the ones that are gonna cause you a problem and they can't learn anything and they're the ones that that and I'm sorry, but SolarWinds is doing this to the intern with the bad password. There are so many other points at which security could have happened that to try and blame one person for a bad password means that your entire program lacked cohesiveness.
It lacked a full risk assessment and it lacked what it needed in order to stop an attack at many points in that. And so it takes thought and it takes not disdain for your people, but sympathy for what they know and an understanding of what they can learn from there.
Oh, yeah. That is our I think our number one issue. Thanks for saying that. It's only because we have such a low level across the board, emotional intelligence.
I'll just say, like, we are not good at making friends. We are just so like, no one likes us. I will just say, like, no one likes us. So it's it's funny how also this is how I know we have low emotional intelligence.
We do this to ourselves. Like, imagine any take any data breach, like SolarWinds, the Microsoft Exchange pack that's happening right now, the Equifax. Like, take any one of those and think of the immediate reaction of the cybersecurity community. What was our immediate reaction?
Was it like, oh, yeah.
I know exactly what you're going to do.
Everyone piled on.
Exactly. It is a a pile on a pile. Like, it it is a football game with the, the audience, you know, who is watching also, tackling. Like, it is everybody on the field and plus the people in the stands.
So it's it's just a a total problem that I see in the industry. We lack emotional intelligence, and it it it's quite obvious why we can't get the seat at the table that we're always looking for or for the support of our executive team. It's because nobody likes us. You know?
Like, so it's not that hard to make that assumption not not the assumption, the correlation now between why we are overworked, why we are stressed, and the amount of breaches that we are currently still get every single day. It's like, come on. Don't you see this, like, immense obvious pattern that's going on? It's been going on.
Yeah. Pretty big disconnect. So now that we have discouraged everyone listening sorry. Glad you stayed with us.
Let's let's talk about let's stop talking about being the Spanish inquisition and start talking about what can we do about it. What are the positive things that we can and so one of the things that I really wanted to talk to you about was, as a leader in cybersecurity, what practical advice can you offer other leaders who are hiring cybersecurity team members, who are trying to fill those, slots? How do you look past the certifications? How do you look past the years in in in cybersecurity and bring in people who can help us start solving these problems?
Yeah. So I always say this, but you just have to take a little bit of risk here and and hire someone for their potential. You don't wanna hire them for the experience that you might want. You know, build the person that you want instead of just purchasing them.
So someone gave you a chance. People in our generation, Jen, that you and I are, like, kinda in the older generation now. We we were given a chance. We didn't have the resources or the training or the certifications that the folks have now.
They're doing all the work. Yeah. They're doing all the self learning, but we didn't have any of that. We were just given a chance because obviously that was the only thing that could be done.
Yeah. But we are now in this position of, like, we owe you have to bring all the learning on your own, we're not gonna teach you anything, and you have to hit the ground running. And that's very apparent when you see the number of job openings, it's all in the mid senior to senior range, and you don't see a lot of those entry level, true entry level positions. I did some research here, Jen.
I analyzed a thousand random LinkedIn LinkedIn job postings, and I saw that forty three percent of them, entry level positions require a five year experience or a CISSP and a college degree, like, the combination of those three things. Forty three percent.
An entry level position should not require five years. Entry level means you're just getting started. Right?
And so some people yeah. Some people argue, like, it's they're like, there's no such thing as an entry level cybersecurity job. And I wanna argue, actually, there is. Like, think of anything that you do on any given day and you tell me what do you do that requires five years of experience?
What do you do that actually requires you to have a CISSP or a cyber security degree? None of that. Literally none of that. I am right now filling in a spreadsheet that follows a NIST CSF.
I'm literally going down the list and, you know, checking things off. I'm like, do we do this great? Do we do not do this? Okay.
Let's, you know, fill it. So there is so much that's already built for me. I don't have to create anything from scratch. I am standing on the shoulders of giants because there are plenty of things that the community has already made through decades and decades of research and postmortems and lessons learned that we are now just using because it's already there.
All the resources are there. And what I'm saying is, the cybersecurity professionals of the next generation are struggling to get in and we are only hurting ourselves. So you said practical tips. My practical tip number one, hire someone for their potential because you were also hired for your potential.
Give them the little grunt work that you don't wanna do. There's plenty of stuff like that. Asset management, filling out a security questionnaire. There's so much stuff that you know you don't wanna do and you would rather do strategy.
Right? Everyone would rather do your strategy. Give them the tack the tactical stuff because I know you don't wanna do that. That stuff is boring.
Or if you wanna still stay technical, that's fine. Maybe you shouldn't be a security leader. Security leaders should be highly strategic, not tactical. I'll just leave that with that.
But I have plenty of other tips.
No. I love that. You know, and I may have told this story before on this podcast, but I don't I don't remember.
I was working as an executive assistant when I got my first IT job because there was an opening on the help desk and I said, I want that job. And so I went to the CEO that I was working for and said, hey, I would like this job. And he said, do you have education in this? No.
Oh, do you have experience? No. He said, oh, well, we'll give you a shot.
Like and people have said to me, recently, well, that was a different time. You know, that was back in that when things were first getting started. No. Actually, it was harder to gain the knowledge that I needed to know to be functional because it wasn't readily available. You can still hire somebody who just wants to do the job, toss them in, see how they do. Give them a little support. Give them access to information.
Give them the support. And I've and this is my next point here. Have you heard of the protege effect?
It's this really cool little thing, but essentially the teacher who is teaching the student actually ends up learning as well.
Ah, yes.
So imagine when you are teaching all the little things you have to know about the topic. You have to know all the little pieces and the ins and outs of any part so when as you're teaching this, you are now reinforcing the facts within your own mind. And so now you can explain it in an easier way. Awesome.
The teacher is also learning. So it's called the protege effect. I think everyone can benefit from having an entry level person just through the simple fact of like, hey, expand my team. Sure.
Share the burden. Teach somebody. You can also learn. The best way to learn is to teach.
I think I've heard that phrase too. I I agree.
There's so many arguments for hiring entry level people, and I don't know why we don't do it.
So that brings us to the job seekers. I know a lot of times, I try to help men and women, but a lot of the people who come to me and ask me for help in getting into work, I happen to be women. The one thing that I've see a lot of them do is they're not willing to apply for the job unless they one hundred percent can do everything described in the job. My answer to them is some hiring manager put this together on a on a quickly jotted down list of things that the person who needed a headcount, gave them, not even knowing if these are the actual things the person's going to do in the job. If the job feels like it's kinda if you think you can kinda do a lot of these things or learn them, why not apply? But but what would you tell people, you know, that especially when when people are faced with, oh, you have to have an a CISSP and five years experience in order to do this job. What would you tell job seekers when it seems like such a monumental hill to climb?
How do they get in past that?
Yeah. So this is this is an interesting one. Like, it is kinda hard to get past those applicant tracking systems, you know, the automated HR software that's now parsing resumes.
So you almost have to be a little creative. You you kind of want to be like, hey, as you're looking for this senior level person, is there any way that I can just step in as an intern and do the little small things while you are trying to find the right person? Can I just come in, I'll be the best worker, you can pay me twenty five dollars an hour, whatever it is? And then just sell yourself and be like, I am willing to help.
And as you're looking for your next full time cyber security professional, why don't you just hire me for part time just to do part time? So there's like that little trick. I'm sure hiring managers would be up for it. I'd cert I certainly would.
I'm doing it right now.
Like, because like hiring managers know they're probably not gonna find someone who fits that entire thing. Or if they do, they're gonna be costing a lot of money. So the, the gap, you know, that temporary person to help fill in like the immediate need for some of the more tactical things, I would absolutely hire an intern. And the the good news is most executive teams would approve that.
Sure. In, like, literally five seconds. They'd be like, oh, part time, no additional benefits, no, you know, you know, vacation time. Okay.
You're hired. Yeah.
And then it gives you the time to demonstrate that you've got the skills, either that you can learn them, which is I'll be honest. There are a lot of people who have the right passion and the right learning ability, but some people don't. But when you know that you do or that you can, gotta show it, and people will absolutely hire somebody who's willing to show that.
Yeah. I am I would too. And I can tell when someone's really, really passionate about it is when they're reading on their off time or they're building a home lab or they're writing articles or blogs, or they're coming on a podcast, or they're joining an event, or they're volunteering at a cybersecurity working group, or or contributing. Just, putting their voice out there. And I can really tell when someone spends their their extra time and contribute back to the industry. And I can I really love that?
It it makes a difference.
And, also, I think writing, just like teaching, is a way to formulate your thoughts about a thing, you know, to to have a more logical, understanding of what it is that you're what talking about. Right? So so speaking about things and writing about things that can actually make you better in your knowledge and your skills, in that thing.
Yeah. It almost works as, like, a twofer because you are learning and you're growing. And then at the same time, you're putting your information out there and all your insights, and now people can find you. And so I will say, like, I've gotten a couple of jobs now because I just post my thoughts online.
I'm like, this is how I think security leadership should be. I don't think it should be the cart leading the horse. I think security should be a business enabler. Like, very obvious things Mhmm.
That I've just learned in my travels. But once I started posting my thoughts online, a lot of recruiters just started reaching out and be like, Hey, would you like to, apply? You know, and you know like once those recruiters really, or you get on the radar of those recruiters, you actually skip ahead. You skip past that screening phase.
You get straight to the interview phase. I call it the hidden job, market. There's like a hidden job market you don't really know about. But the recruiters reach out to you.
You're right away put on the top of the interviewing list. Like, you don't have to go through that whole screening thing.
So let's say you're a leader. You've taken a chance. You found someone who has all of the the kind of personality things that you want. How do you then help them be successful?
So me as a security leader, I love teaching. So I give my entry level folks just, their own project. Like, I want them to own something. So start small.
So I am hiring an intern. We are going through the the project phase right now. But the the intern will be owning a process. So I'm gonna have them do a little technical writing to begin with and see how they go with it.
But, you know, we need some incident response playbooks. Why don't you create some? And really, it just requires, some good communication skills and the ability to find information and digest it into, infra like a resource that other people can now consume. So it is not very difficult to find ideas and projects for them to work on, but you will have to have them own something, and then guide them throughout it.
So you point them to their resources and be like, hey this is how I would do it. Or hey let's review kind of what you have, let's see what we've learned so far. So you are as a te you are their teacher. You are actually guiding them into what you want to see, and you let them make a little bit of mistakes.
You don't want to like keep them away from all mistakes. Like, you know, have them struggle just enough where they are learning how to do this correctly. Because honestly, when you do make mistakes, you learn a lot faster. You're like, oh, so I shouldn't do it that way.
But make it a safe environment, not not like that poor SolarWinds intern.
I know.
By the way, I thought what that CEO did was just the worst. Like the worst thing that could possibly happen. So don't do that. But you want to give the intern a safe space so that they, she or he, can make mistakes but not have, like, super impactful repercussions.
Yep. That is that's perfect.
Thank you so much for for, talking to me about this today. Is it are there any other aspects of, bringing people into cybersecurity that you want to cover before we wrap up?
Oh, we covered so much, I would say. Like but if you are listening and you are hoping to get a cyber security job, you know, the one thing we didn't talk about is really networking. So a lot of the questions I get is how do I start networking? You're like, how do I even do this?
So there's like a couple of great ways, within your own company I'm assuming you you have a job, but if you are in a company and you're not doing tech, you really want to get on the radar of the technical team. So, I this happened a couple of times, but you know, within the company that I'm in, people are just going up to their own managers and raising their hand. There's like, hey. I don't wanna be doing this anymore that I'm currently on your team.
I wanna join the IT team or I wanna join the security team. How can I get a conversation with the technology team or with the security team? And so what their manager will do then be like, hey. I know the manager of the security team.
Her name's Naomi. Let's set you up with a meeting. And so this happens all the time where all you have to do in your current role is just say, hey. I really don't like my job.
You know, you have to be a little bit brave. Be like, I don't wanna do this forever. Is there any way? I'm more interested in doing tech or security.
And if that company is anything that supports their employees, like, they will at least try to get a conversation going.
Right.
You know, you might not move laterally completely, but you know, who knows? Maybe you can intern there for three months or whatever. There's ways of doing things within your company and that's the easiest way. And you start building this network of people who will go to bat for you when there is an opening or when there's a job where the the person now knows somebody else and be like, hey.
Do you have somebody that you know who would be interested? And be like, yeah. Actually, I had a conversation with a person in a different department. Then they're looking to break into cybersecurity.
I think they'd be awesome. I think they'd be the perfect fit or however it is. You want that network, that trusted network, to believe in you and to go to bat for you. And so as long as you are now building trust and relationships, and those people have confidence in your skills, and you really want to be able to show the the your abilities, you know, like, day in and day out.
You don't wanna be, like, weird or anything like that. You you will be fine. You just have to start making those connections and be brave a little bit.
That's excellent advice. Thank you so much for for sharing that.
We'll, if people wanna connect with you, what's the best way for them to do it?
Oh, so I'm on I'm on LinkedIn.
Naomi dash Buckwalter, and I'm on Twitter too. So at I need more cyber. I only post, like, once a day, not even. So, yeah, just find me on there. I sometimes post about random things, highly political also, so watch out for that. But, for LinkedIn, it's mostly cybersecurity for sure.
Terrific. Well, thank you so much, and I appreciate your time today. Thanks, Jen. Thank you for joining us. I hope you enjoyed this episode of the Security Metrics podcast. And if you did, if you'd like to hear more like this, give us a like. Give us a follow.
See you next time.
Thanks for watching. To watch more episodes of Security Metrics podcast, click on the box on the left. If you prefer to listen to this podcast, it's available on all your favorite podcast platforms. See you on the slopes.
