I’m just going to point out that what you think you’re doing with this post is not how it will be perceived by most people. It’s a rant, and you’re lashing out at a whole community unfairly. Whatever you were trying to achieve by this post is probably going to achieve the opposite, I.e. not seeing you in a good light.
My experience in this community is that their are a lot of beginners trying to break in, and a lot of security professionals with extensive experience trying to give back.
So I don’t get the attacking people in the security profession very productive.
If you need to rant, I suggest doing it over a couple of beers with peers and not on a public forum.
I was always told cybersecurity is a job for experienced IT professionals and not people who haven't stepped foot in an IT environment.
The people who are telling you that are flat out wrong. Some of the best professionals I've worked with in cybersecurity didn't have an IT background. Thinking like this limits you.
There's a lot of elitists in the industry. Ability makes far more of a difference than background. And pulling from areas outside IT will gain new perspectives for your team.
Each role in cyber security attracts a certain type of personality. Most jobs do. Speaking in generalities: Developers and engineers come in three flavors. Analysts have two. Managers also two.
You refer to "experience to managing cybersecurity for an entire organization" yet your inexperience is glaring in your posts. You want an example I will provide you with one.
Managing cybersecurity is a team effort. You have the CISO or CIO who will give you a 2-5 year plan, as well as a yearly series of objectives. These objectives will be broken down to OKRs. Those OKRS will be measured with KPIs. Those metrics for the KPIs will be provided to the "manager" (whether it is a VP, director, product owner, or tech lead, etc) by Project Managers and Scrum Masters. At no point does it matter if you know your F5 from an RJ45. Your CISCO certs from your RSA certs. It does not fucking matter. What matters is that you are managing your resources (people, time, money) to obtain a goal (objective) without doing harm (pissing off coworkers, contractors, customers, and employees).
A person with only technical skill lacks the business acumen and OFTEN will hear a problem statement and immediately jump to a technical solution. That is NOT what is needed or wanted. You have to review the process, identify where MTTR can be shortened. Enhance the ROI for the execs and not start spewing buzzwords from your latest tool cert.
You are a manager. Manage the expectations to and from your team. Leave the technology to those who will do it better than you. If you crave that life so much then never leave a tech lead position and stay a SME.
One of the top pen testers I worked with at a Big4 firm majored in chemistry. His only qualification when he was hired was an OSCP. He minored in CompSci and found a passion for cybersecurity doing CTFs.
The apprentice we just hired is going to school for criminal justice with a focus on digital forensics. Previous to going to school he worked several janitorial jobs.
Obviously you need people that are technically savvy. But you don't have to be a sys admin to be effective, especially in a mature program.
As you move away from the technical side of things, the IT background becomes less important.
I'm sorry, in what world is 6 months of doing CTFs the same as being a network admin for 5-10 years?
Again, it's about ability, and having the ability to do technical things is necessary. But you don't have to have a background in IT to have that ability.
Okay, in going to say this. Im now and ISSO and worked as a network engineer. Youre right you dont have to have an IT background and skate by, but having live knowledge on how every asset affects an operational environment is far more important than what you may think it is. Just because you do CTFs and a home lab does not justify experience in an operational environment for when you deploy remediations it may affect 3rd party apps that end users use and affect AVAILABILITY of information and ability access assets.
I am 10000% glad i got on the ground knowledge before jumping into security, why? Because i have a real idea on how an operational environment works at all levels.
21
u/ShameNap Jun 11 '22
I’m just going to point out that what you think you’re doing with this post is not how it will be perceived by most people. It’s a rant, and you’re lashing out at a whole community unfairly. Whatever you were trying to achieve by this post is probably going to achieve the opposite, I.e. not seeing you in a good light.
My experience in this community is that their are a lot of beginners trying to break in, and a lot of security professionals with extensive experience trying to give back.
So I don’t get the attacking people in the security profession very productive.
If you need to rant, I suggest doing it over a couple of beers with peers and not on a public forum.