Fast-Track Your Cybersecurity Career

SANS Institute · Advanced ·🎯 Management & AI-Era Leadership ·4y ago

Key Takeaways

The SANS Institute presentation covers various aspects of cybersecurity, including career development, diversity, risk management, and security architecture, highlighting the need for diverse thought and perspectives in the industry. It also provides resources for career growth and development, such as training and education, networking, and industry groups.

Full Transcript

So, um I want to start with how I got here because it was, you know, a it sounds traditional, but it really wasn't. Um, you know, I was a delivery leader in an IT basically running platform delivery. And I was known for taking broken programs and and fixing them and making them still running. And to be honest with you, I was tired of fixing the same problem, but not being in a position to be able to fix the root cause of that problem. And I was bored. So, I went out and to my network of of friends and peers and and colleagues and and started to talk about what's next for me. And what one woman in my network uh really wanted to hire me, didn't want me to leave the company, but didn't have anything for me. And then suddenly this opportunity to run vulnerability management fell into her lap, and she needed to hire somebody for that. And so, she looked at me. I have no experience running vulnerability management program. I'd never been in a cybersecurity group. Um, so, you know, I asked around and I thought, "Hmm, you know, do I do this or not?" And, you know, one person said, "Well, you thought people didn't like you now. Just you wait until you run that program." And I thought, "What do you mean people don't like me now?" But, I digress. One person said, "It is a complete dumpster fire. Everyone will hate you. Don't go near it." But, you know, I like a good dumpster fire. And for some reason, uncharacteristic of me, I said, "Yes." I took that risk. So, I found my tribe. It was the best thing I have ever done. It it's offered me so much. And I want you to have that experience as well. Whoa. And there I clicked way too much. Sorry about that. So, goals for today. I'm going to use the page down button from here on out cuz that mouse is too excited. I want you to have an overview of the industry and and take your first next step. I would have done this years ago if I had known that that this would be such a great fit for me. Um, I want you to be able to match your values, your talents, and your personality to a path. I want to provide resources for career changers. Hint. We need more people in cybersecurity, and we need more diversity. This is a team sport, folks. We we hear all the time that cybersecurity is everyone's job, and it is. But, we tend to only attract certain kinds of people. And and I want to change that. We need diverse experience and diverse perspectives. And and so, I I hope, if nothing else, that for those of you who look around the room and think, "Oh gosh, these people don't look like me." Don't let that bother you. We we have a place for you. And finally, I want to encourage the leaders in the room to hire for potential potential. Um I personally don't believe that we have all that much of a cybersecurity resource shortage. I think we have really poor hiring practices. And every time we hire we exclude somebody because they don't have some perfectly trainable technical skill, we're shortchanging that person, and we're shortchanging ourselves. I encourage you to look at the hiring practices in your own organization and help us all do better. So, there's my gauntlet. I'm throwing it down. So, you may have already asked this question in your mind. Why on earth would anyone hire somebody into a senior leadership role that has no experience in cyber cybersecurity? Well, as it turns out, you know, running a product and in a platform, you do start to get some of that experience. You know, I ran and it and I was successful at it. Um, program management turned out to be the thing that that twice failed initiative needed. Um and I ran one of the largest vulnerability management and application security programs in the world. But, here's the other thing. Is that I built a successful program around a diverse cast of people. You you know, my group sounded like the the entry of a bad joke. You know, I I had a Christian, a Muslim, a Hindu, you know, a white woman, LGBTQ, old, young. I had it all. And this position put me in a place where I could provide opportunities for lots of people. And by the way, most of these people also did not come from a cybersecurity background. So, why me and why them? Well, as it turns out, cybersecurity is everyone's job. And I and they had a lot of information security experience in in our previous roles. So, I was responsible for doing business impact analysis and disaster recovery. Was responsible for the application security and security architecture and vulnerability management on my platform. And it as I said, leadership, program management, customer service skills because dealing with a lot of people, my relationships in the company mattered. Um, all of the things that I brought to the table turn out to be as important as the technical skills. And for the people that I hired and for the people that I see in our community, they're curious, they're problem-solving, they're still start starting, they're humble. And I probably should have put that first. This is a big industry, and anybody that tells you that they know everything or, you know, we we do have a bit of of overconfidence sometimes. We don't know everything, and and we leverage one another. And that's one of the things I love about this community is that it really is a community. Uh, there are so many people that give back and are helpful and so many resources, and we'll talk about that in a bit. But, you know, it starts with having some humility and in working on a team. And finally, finding your place. I mean, what skills, preferences, personality traits do you have? And where do you match that and and a values match? So, I'm going to pause there. We often encounter sensitive things, and we're protecting sensitive data, and our ethical standards need to be top notch. And it I can tell you from personal experience, we can talk about that later in the Slack, not here in public, about how uncomfortable it is to be in an organization where your values don't match theirs. So, find that values match, and I'll say, you know, look at your values, look at what they publish, and start there. Okay. So, this eye chart started out as my organizing my thoughts to build a security program. And I don't expect you to read it. The reason why I put you put this on here is because each one of these colors and each one of these boxes represents a domain in cybersecurity that that you might be an expert in or become an expert in or a place to start. Um, I put this on here as a visual for quantity, not necessarily for for you to read it. And I want to point out that in the center of that it it says security program. But, really what that is and what we are all doing is managing risk. So, be thinking about that. Every one of these things is about managing and mitigating risk. And there is a specialty of risk management. So, there can't be a lot of risk without threats. And and I've made a list here which you can read. But, it's interesting that that often times when we think about cybersecurity risk, what we're thinking about is hackers and people breaking in. But, I just was a part of an incident through poor architecture and design in which the business and the um development group accidentally built an account takeover. Whoops. So, you know, risk can be intentional, they can be non-intentional. And the goal of the risk manager is to identify those risks and and help the organization figure out what to do about it. So, that could involve business impact analysis, which is, you know, how important are these things and and if one of these threats materializes, what happens? What's important, what's not? Business continuity. That would be when, you know, one of these threats materializes, and how do we continue to run the business? And then disaster recovery. One of these things happens, how do we recover the business? So, the kinds of people that risk management tends to attract are people who who are methodical thinkers. They're they're good at documentation, they're good at customer service. They have imagination because a lot of times people in these groups often have to design tabletops. And you need to be able to think about, you know, if this happens, what happens to my organization? And I talk about it as business, but it could be government, it could be nonprofit, it could be anything. Uh Lots of places that that do risk management, and that might be a good place for you. And it's it's not a bad place to start either as as an analyst because that's one of those places that you can bring your skills that you that you developed somewhere else. All right, asset management. So, this doesn't necessarily live in cybersecurity, but I put it here anyway because asset management in most organizations is a mess, and you can't secure what you can't protect. So, you know, I put it here because it's important, and maybe it lives in in cybersecurity, or maybe it lives in IT, and this is your jumping off point to get in. So, asset management, in my mind, involves the baselines, the security baselines, and the patching of the server assets, not just um you know, knowing where stuff is, but it's also about determining risk and value. Um data loss prevention could live here as well. And this attracts people who like to bring order and to chaos operations because it doesn't happen just once. I know organizations think they can just do an inventory every year and they're done, but doesn't really work that way. Uh they like cycles. Again, you're going to need your customer service skills because you're probably in this role going to have to deal with various aspects of the business. And of course, analyzing problems. All right, compliance and audit. Um what laws, regulations, certifications are we subject to? So, folks, this is more than does box A match box B. You have to have some discernment about what actions and evidence match the requirements and what rules apply. You might be asked to do a road map to get an organization into compliance, so some project management skills. Technical skills are can be helpful, but um they aren't necessarily required. And here's the thing, you can be an expert in a single regulation or law, or a framework, um or you can be broad-based. And this tends to attract people who like organizing, project management, and change adoption. So, I want to pause on that. Getting people to make change, it'd be a really important skill, and if you know how to do that in your current role, that would be a great thing to highlight as you as you move on. And I would also say that legal experience is in short supply, so you got to get that. That might be your entry point here. All right, program management, which is which is my bailiwick. In cybersecurity, it tends to be more about designing services. What does your cybersecurity group provide to the rest of the organization? An ITIL background can be helpful because service assurance, especially, is very, very similar. And telling a compelling story. So, the ability to say in plain English how something might happen, we'll say we'll say a cyber attack. You know, taking taking that minor framework and putting it into English so that people understand how this might happen in your organization, and then helping them to see why they need to make change and be more secure. So, this attracts people who like strategic thinking, risk assessment, prioritizing, setting objectives, and of course, leading people. Ah, security architecture and engineering. So, how controls are positioned. You'll note my picture here on the side, you might recognize it. It is the fortress at Agra. And one of the neat things about about visiting here, um which I did in 2018, is that it is a great physical example of how architecture can protect. So, it's got a moat, it's got a bridge, um you'll see there it's got a gate there, it's got tall walls with turrets, so if you get past any of those things, they can shoot down at you when you try to come in. And inside, it's got even even more walls and more segregation, and it really is a great example of of layered defense, which is a key feature of security architecture. You can do this in both the application and network space. So, if you're in a development group, for example, this would be possibly a a natural fit or enterprise architecture. This one does require uh it techno- technological skill, or at least an interest in it. Um the ability to manage abstractions because often times you're taking a picture, and people have to fit their their coding and their architectures within yours, um and translating business requirements into technical requirements would be a key skill in these kinds of roles. I'm going to highlight network security in here because again, this is the traditional place where where when we think about cybersecurity, it's here. Network security is changing, though. You know, it used to be about where do I put the cables and where do I plug things in, and securing my closets and all of that, but with the cloud, it's become a lot more virtual. And so, intrusion detection and prevention, firewalls are a bit more virtual as well. So, it's changing, but again, this may be a good place to get in. You know, it requires technical knowledge and certifications, yes, but there are a lot of free resources out there for those things. So, this attracts people who are detail-oriented and good problem solvers. And I'm going to point out that you need to have a thick skin when you're in this role. I say that with a bit of facetiousness, but not completely, because whenever something goes wrong, the network people are the first ones to blame. And you have to be able to shrug that off to be able to think clearly and work your way through a problem. All right, application security. So, you know, we talk a lot about network security, but I think that the field that is very overlooked is application security, and I think that's going to be the the really the next hot spot. And that's largely about, you know, what can people do within your application and in stealing credentials and in moving around in ways that you didn't necessarily think about when you designed it. I talked a minute ago about account takeover. I mean, that that was an accident. I mean, you know, basically, the app- in the short, the application wasn't doing enough um identification and authorization to be able to ensure that someone couldn't do something that they aren't supposed to do. So, for application security, product management, platform management, um application development experience is helpful. I added here experience deploying in the cloud. It seems like most of our models tend to lean towards on-premises uh deployment, and we're starting to see a lot of configuration issues in the cloud. So, so if you are you have a lot of cloud experience, this might be a natural segue. This attracts people who have an understanding of sound secure architecture, and good repeatable process, so enterprise architecture is a natural fit here. Um having an imagination about how one might break an application, curiosity about how applications work, and one that's probably the most overlooked is SDLC. A lot of the problems I was solving and part of why I was starting to get bored long time back in my role is that our biggest problem was with putting security to the to the left in the development cycle, and having a development cycle period. People were just doing things in an ad hoc way and making a mess. And it you know, we don't think about that necessarily in application security, but but that is one of the features. All right, security operations. So, this is a long list of places where where you too can start. Um the security operations center, threat intelligence, incident response, digital forensic forensics, vulnerability management, identity access management, things that require repeatable cadence typically fall into security operations. So, the SOC. This is sometimes called the heartbeat of our cybersecurity. Um what they do there is that's our operations center, they triage alerts and events and try to figure out what's important and what's not. This is a great place to start because it there are often entry-level positions, they they train you on what to look for. It's a great place to learn because you start to figure out what's important and what's not, and you know, a truly great SOC analyst understands what they're supporting and understands what's important, and they're able to tune those things and make their group more efficient. So, CTI, threat intelligence, is a more forward-thinking group. So, they they're looking out at threats and determining what's important. Now, this requires a lot of critical thinking skills. Bias is a is a problem for for everybody, right? We all have our prejudices and biases, but the ability to get out of that and look at the evidence and see where it leads you. So, these are the people who do the attribution about they about threat groups, or possibly organizations. But here's the other thing that they do. They're able to connect those things to a requirement. You know, we don't just go out and in and um Russia's attacking Ukraine, therefore we're all at risk. Um that's not what threat intelligence does. If they they look at the requirements of the organization, and they match those things, that evidence, to meet those requirements. So, it's if I want to know how Russia is a threat to my organization, that's different than just Russia is a threat to my organization. You see that nuance? And finally, vulnerability management on this page. So, this is another good entry point because again, it starts with a lot of checklists. It you may be running a scanner. Um things that are easy to learn and then you progress to the more analytical type activities. Is this a threat? Is this important? How do I manage all the data? What does my program look like? And then incident response. So, this here has technical and non-technical features to it. It can include threat hunting, which is looking through the ecosystem and determining whether somebody's in there that shouldn't be or it or it could include threat intelligence. Service assurance here again can be helpful because incident management response and IT is very similar to what it what it is in security. So again, this attracts people who enjoy critical and methodical thinking um because again, checklists, runbooks, and so on need to be published as you get more experience and get more mature. Imagination again because you know, what's going on here? What could be causing X, Y, or Z? Process improvement, of course. And here's something. Um exhibiting calmness under pressure. Um I worked with a with a guy who was ahead of security operations and he was great. Good at process, good at imagination, methodical thinking. He was hysterical on calls. And you can't be screeching on at people on an incident management call. Um it raises everybody's blood pressure and then nobody can think. And it becomes very hard for people to methodically do a job. And also, when he's hysterical, he's not able to effectively run the call. And it ended up that he moved on um to do more more of a process kind of a role than than a security kind than an incident management kind of a role. But if you are somebody who is really good at staying calm and reacting to a crisis and being able to work through a problem, this might be a great space for you. And identity and access management. So, this used to require a lot of technical skill, but now with a lot of the modern tools, which pull out the the access and authorization for you, you may not need this. Now, what's interesting is that these days, there's a bit of a network security flavor in this because everything in the cloud is identity and policy. So, this suddenly requires again, more than does box A match box B, but a bit of imagination about what can I do and where can I go from here? So, this attracts people who can see patterns and solve puzzles. And if that's you, this might be a good place for you to start. So, other specializations. Internet of things. You know, we've got a bunch of stuff in our houses that need security. Um industrial systems. So, Rob and Lee, who was an instructor here at SANS, um he owns a company called Dragos and or founded a company called Dragos. They tend to hire people for who they are and they're happy to train on the industrial systems that they support because there's so few people who have any expertise in this. So, if industrial systems interest you or manufacturing and and critical infrastructure, study up on that. Great opportunities there. And data engineering. So, as we get better at collecting data and logging data and so on, now we have a bunch of disparate data that we have to do something with. And then there's AI and machine learning in there because again, there may be more data and information than human brains can manage. And these are great opportunities if you have an interest in either of those two things or maybe you're you're in a in a large data space doing something else, this would be a good place to enter in. So, how do I get in and where do I start, right? So, largely, we talk about what are what are my values. I think I talked about that earlier. Finding companies with those values, matching that up, ask your friends. Um what kind of a culture do I like? So, so I have some pictures here, you know, a dumpster fire is for me. But if you don't if you like a good dumpster fire, find yourself an immature organization that needs maturing. Now, again, I you want to find a dumpster fire and and put it out. You don't don't just want to keep it a dumpster fire. But if you like smooth sailing, then maybe a more mature organization is for you. Somebody who's got some repeatable process. If you like details, doing some of the more detailed work like a SOC analyst or vulnerability management or forensics. Project management, there's always a place for you. In security operations, we have to process and improve as well as in compliance. You know, putting together the pieces of the puzzle could be almost anywhere in in security. And then I am and of course, I mentioned big data. But again, think about what your temperament is and the kinds of things that you like to do. But here's what I'm also going to say. If you don't know, start somewhere. There's it's experience. It's all experience. There's no harm in trying. Oop. And I said I wasn't going to touch that scroll bar and I did. Okay, so training and reading. Again, I put together a fairly generic list here. Use these things to jump off of you. You'll have access to them after the presentation. I do want to point out a couple of them. We've got sans.org, our hosts here, and we know that they provide world-class training and I honestly, I would not be where I am today if I didn't take their training. Um they also have a reading room. They do webinars every day, sometimes multiples of them. Newsletters, definitely leverage that as a resource. Um LinkedIn learning, most of their cybersecurity classes are um in the paid version, but here's the thing. In major cities, most of your local libraries will get you access to that for free with your library card. And finally, down here a little bit, I've got ISC2. Um they are doing a new entry-level cert. I believe it's in the evaluation phase. I bet you that's going to be a good one and it would be smart. I I would go and and be a part of that evaluation. And finally, networking and industry groups. Okay. Again, a long list, a fairly generic group. Use it to jump off. I do want to point out a couple. Twitter is at the top because that is where a lot of security people tend to hang out. I think even more than LinkedIn. LinkedIn, of course, for anybody who's looking for a job, I I think that's, you know, table stakes. And I want to point out Meetup because a lot of your local security groups are going to post their things on Meetup and it may be a good way to meet people. So, connect with people, find a mentor. I think that's probably the best advice I can give you about starting. You'll get ideas, you'll get support, and possibly your next job. So, with that, I want to wrap up. Thank you all for for listening. Um I will be obviously in the in the Slack. And you know, feel free to ask questions and and I'll I'll hang out with you over there.

Original Description

There is something for everyone in cybersecurity. You don't have to be technical. Our industry needs diverse thought, diverse perspectives, and diverse personalities. This presentation matches interests and personalities to the different domains of cybersecurity, and then provides resources for participants to explore their interests. Let's make our industry more accessible so we can attract smart, kind, talented people to fill the talent gap we're always hearing about! About the Speaker Carolann Jacobs is currently the Director of Cybersecurity Operations for LendingPoint. She has wide experience in Cybersecurity, Information Technology, and Leadership. Previous roles include VP of Security Operations for a top tier global media company, Head of Security for a bio-tech firm, and Delivery Lead for Hilton HHonors. Carolann is passionate about diversifying leadership and creating opportunities for the historically excluded. When not at work, you can find her hanging out with her partner, 3 dogs, and cat somewhere close to the US northern border. View upcoming Summits: http://www.sans.org/u/DuS Download the presentation slides (SANS account required) at https://www.sans.org/u/1iaE #New2yber #New2CyberSummit
Watch on YouTube ↗ (saves to browser)
Sign in to unlock AI tutor explanation · ⚡30

Playlist

Uploads from SANS Institute · SANS Institute · 0 of 60

← Previous Next →
1 SANS FOR610: Reverse Engineering Malware: Malware Analysis Tools & Techniques
SANS FOR610: Reverse Engineering Malware: Malware Analysis Tools & Techniques
SANS Institute
2 SANS Institute Cybersecurity Training Customer Stories
SANS Institute Cybersecurity Training Customer Stories
SANS Institute
3 SANS Institute UK Cyber Academy
SANS Institute UK Cyber Academy
SANS Institute
4 SANS Institute UK Cyber Academy
SANS Institute UK Cyber Academy
SANS Institute
5 CISSP® Prep Exam, MGT414, by SANS Institute
CISSP® Prep Exam, MGT414, by SANS Institute
SANS Institute
6 SANS Institute's Rob Lee Discusses The OPM.GOV Hack on CNN
SANS Institute's Rob Lee Discusses The OPM.GOV Hack on CNN
SANS Institute
7 Information Security Training from SANS Institute - Student Testimonials
Information Security Training from SANS Institute - Student Testimonials
SANS Institute
8 SANS NetWars
SANS NetWars
SANS Institute
9 SANS DFIR NetWars
SANS DFIR NetWars
SANS Institute
10 Hack The Drone - SANS Cyber Academy UK
Hack The Drone - SANS Cyber Academy UK
SANS Institute
11 SANS VetSuccess Immersion Academy
SANS VetSuccess Immersion Academy
SANS Institute
12 SANS Cybersecurity Training, Certifications & Placement for Veterans
SANS Cybersecurity Training, Certifications & Placement for Veterans
SANS Institute
13 The 2015 SANS Holiday Hack Challenge
The 2015 SANS Holiday Hack Challenge
SANS Institute
14 SANS VetSuccess Academy: Hands-on Skills
SANS VetSuccess Academy: Hands-on Skills
SANS Institute
15 SANS VetSuccess Academy Overview
SANS VetSuccess Academy Overview
SANS Institute
16 SANS ICS Security Summit & Training 2017
SANS ICS Security Summit & Training 2017
SANS Institute
17 Exploring the Unknown Industrial Control System Threat Landscape – SANS ICS Security Summit 2017
Exploring the Unknown Industrial Control System Threat Landscape – SANS ICS Security Summit 2017
SANS Institute
18 WannaCry recap, patches, and analysis
WannaCry recap, patches, and analysis
SANS Institute
19 If We’re Doing So Well at Cyber Security, Why Are We Still Doing So Poorly?
If We’re Doing So Well at Cyber Security, Why Are We Still Doing So Poorly?
SANS Institute
20 Graduation Day - SANS HM Gov Cyber Retraining Academy
Graduation Day - SANS HM Gov Cyber Retraining Academy
SANS Institute
21 Incentivizing ICS Security: The Case for Cyber Insurance – SANS ICS Security Summit 2017
Incentivizing ICS Security: The Case for Cyber Insurance – SANS ICS Security Summit 2017
SANS Institute
22 SANS Data Breach Summit & Training 2017
SANS Data Breach Summit & Training 2017
SANS Institute
23 SANS Secure DevOps Summit & Training 2017
SANS Secure DevOps Summit & Training 2017
SANS Institute
24 How Threats Are Slipping In the Back Door - SANS ICS Security Summit 2017
How Threats Are Slipping In the Back Door - SANS ICS Security Summit 2017
SANS Institute
25 SANS Webcast – Continuous Opportunity: DevOps & Security
SANS Webcast – Continuous Opportunity: DevOps & Security
SANS Institute
26 SANS Cybersecurity Programs for the Department of Defense
SANS Cybersecurity Programs for the Department of Defense
SANS Institute
27 SANS Pen Test HackFest Summit & Training 2017
SANS Pen Test HackFest Summit & Training 2017
SANS Institute
28 SANS SIEM & Tactical Analytics Summit & Training
SANS SIEM & Tactical Analytics Summit & Training
SANS Institute
29 If We’re Doing So Well, Why Are We Still Doing So Poorly? – SANS ICS Security Summit 2017
If We’re Doing So Well, Why Are We Still Doing So Poorly? – SANS ICS Security Summit 2017
SANS Institute
30 SANS Institute
SANS Institute
SANS Institute
31 ICS515: ICS Active Defense and Incident Response
ICS515: ICS Active Defense and Incident Response
SANS Institute
32 SANS Institute
SANS Institute
SANS Institute
33 Introducing the NEW SANS Pen Test Poster
Introducing the NEW SANS Pen Test Poster
SANS Institute
34 SANS Institute - An Inside Look at the Newly Updated ICS515 Course
SANS Institute - An Inside Look at the Newly Updated ICS515 Course
SANS Institute
35 SANS ICS Security Training, Munich, Germany
SANS ICS Security Training, Munich, Germany
SANS Institute
36 SANS Automotive Summit Webcast
SANS Automotive Summit Webcast
SANS Institute
37 Privesc Playground - SANS Pen Test HackFest Summit 2017
Privesc Playground - SANS Pen Test HackFest Summit 2017
SANS Institute
38 Introduction to Reverse Engineering for Penetration Testers – SANS Pen Test HackFest Summit 2017
Introduction to Reverse Engineering for Penetration Testers – SANS Pen Test HackFest Summit 2017
SANS Institute
39 Honey, Please Don’t Burn Down Your Office: Fun with Smart Home Automation
Honey, Please Don’t Burn Down Your Office: Fun with Smart Home Automation
SANS Institute
40 SANS Security Operations Summit & Training 2018
SANS Security Operations Summit & Training 2018
SANS Institute
41 Sh*t Happens!  (But You Still Need to Drink the Water) – SANS ICS Summit 2018
Sh*t Happens! (But You Still Need to Drink the Water) – SANS ICS Summit 2018
SANS Institute
42 ICS Threat Intelligence: Moving from the Unknowns to a Defended Landscape – SANS ICS Summit 2018
ICS Threat Intelligence: Moving from the Unknowns to a Defended Landscape – SANS ICS Summit 2018
SANS Institute
43 You’re Probably Not Red Teaming (And Usually I’m Not, Either) – SANS ICS Summit 2018
You’re Probably Not Red Teaming (And Usually I’m Not, Either) – SANS ICS Summit 2018
SANS Institute
44 A Sneak Peak at the New ICS410
A Sneak Peak at the New ICS410
SANS Institute
45 Jumping Air Gaps – SANS ICS Summit 2018
Jumping Air Gaps – SANS ICS Summit 2018
SANS Institute
46 Introduction to Linux
Introduction to Linux
SANS Institute
47 Introduction to Malware Analysis
Introduction to Malware Analysis
SANS Institute
48 You’re Probably Not Red Teaming (And Usually I’m Not, Either) Webcast by Deviant Ollam
You’re Probably Not Red Teaming (And Usually I’m Not, Either) Webcast by Deviant Ollam
SANS Institute
49 Hacking your SOEL: SOC Automation and Orchestration – SANS Security Operations Summit 2018
Hacking your SOEL: SOC Automation and Orchestration – SANS Security Operations Summit 2018
SANS Institute
50 Hunting for Post-Exploitation Stage Attacks with Elastic Stack and the MITRE ATT&CK Framework
Hunting for Post-Exploitation Stage Attacks with Elastic Stack and the MITRE ATT&CK Framework
SANS Institute
51 Apples and Oranges?:  A CompariSIEM – SANS Security Operations Summit 2018
Apples and Oranges?: A CompariSIEM – SANS Security Operations Summit 2018
SANS Institute
52 SANS Webcast - Perimeter Security and Why it is Obsolete
SANS Webcast - Perimeter Security and Why it is Obsolete
SANS Institute
53 SANS Webcast - Trust No One: Introducing SEC530: Defensible Security Architecture
SANS Webcast - Trust No One: Introducing SEC530: Defensible Security Architecture
SANS Institute
54 The Science of Security: The Psychological Impacts of Security Awareness Programs
The Science of Security: The Psychological Impacts of Security Awareness Programs
SANS Institute
55 How I Pulled Off an Edgy Security Campaign – SANS Security Awareness Summit 2018
How I Pulled Off an Edgy Security Campaign – SANS Security Awareness Summit 2018
SANS Institute
56 Practical Advice for Submitting to Speak at a Cybersecurity Conference
Practical Advice for Submitting to Speak at a Cybersecurity Conference
SANS Institute
57 SANS Webcast - Consuming OSINT: Watching You Eat, Drink, and Sleep
SANS Webcast - Consuming OSINT: Watching You Eat, Drink, and Sleep
SANS Institute
58 SANS Webcast - Zero Trust Architecture
SANS Webcast - Zero Trust Architecture
SANS Institute
59 SANS STX Cyber Range
SANS STX Cyber Range
SANS Institute
60 Part 1 – SANS Institute and Tenable talk about cloud security
Part 1 – SANS Institute and Tenable talk about cloud security
SANS Institute

The presentation provides an overview of the cybersecurity industry, highlighting the need for diversity and the various career paths available. It also covers key concepts such as risk management, security architecture, and incident response, and provides resources for career growth and development.

Key Takeaways
  1. Build a security program
  2. Provide opportunities for diverse people
  3. Manage risk
  4. Identify threats
  5. Conduct business impact analysis
  6. Pursue training and education
  7. Network with industry professionals
💡 The cybersecurity industry needs diverse thought and perspectives to address the complex security challenges, and there are various career paths available for individuals with different skills and interests.

Related Reads

Up next
Leadership Insight | Governing AI at UNPAD
Google for Education
Watch →