Showing posts with label security jobs. Show all posts
Showing posts with label security jobs. Show all posts

Monday, July 6, 2009

EDUCAUSE: The Career of the IT Security Officer in Higher Education

A paper titled "The Career of the IT Security Officer in Higher Education" by Marilu Goodyear, Gail Salaway, Mark R. Nelson, Rodney J. Petersen, and Shannon Portillo was released on July 1st. The paper details research and results of surveys and interviews with higher education security officers, reviews of job postings, and other data. Of note, over 300 individuals responded to the survey from a total of 1685 institutions, resulting in a large sample group.

Details include the reporting lines of the security officers, their previous employment and skillsets, as well as their education and certification levels. Over 90% of the security officers have at least a bachelor's degree, with over 40% having an advanced degree. CISSPs have the greatest showing, which makes sense for a management position, but GIAC and CISM and CISA certifications also make a strong showing.

Those interested in the field will also find the salary table on page 18 of the report noteworthy, with a median range of $70-90,000 across the full range of schools, and a maximum in the $170-190,000 range.

The paper is well worth a read even if you're not in higher education - the challenges described and the training that these security officers want are the same challenges and training that are needed across the board.

Wednesday, February 13, 2008

Reformed Lawyer Loves Information Security

David says I need to introduce myself if I want to post here. Since I want to post, here goes. I am a reformed lawyer now working in information security in higher education. My focus is primarily on policy development, although once in a while "they" let me out of my cell and I get to participate in a risk assessment or a special project related to information security and "the law." I truly enjoy the ability to meld my lawyer skills within the constantly changing, always evolving, never still discipline of information security. Without further ado (or with much ado about nothing), here goes...

-------------
I love Google Web Alerts. It proves to be a handy reconnaissance tool for gathering intel on coworkers, friends, family and the like. It also is helpful for assessing your own internet popularity presence (or notoriety as the case may be). Thus, it is with great anticipation that I scan my own weekly Google Web Alert to see if I have "popped up" someplace unexpected.

Today I did. Today's report showed that an article that I wrote back in 2004 has been included in a web-based bibliography. What is notable is the article is from my first career as an attorney, and the article discusses resources that all good general practitioners should have in their legal toolkit.

These days I talk about what a person needs in their security toolkit; IT resource acceptable use policies; and how to navigate the various federal, state, and local laws related specifically to technology and information security. Not only am I a quasi-geek, but I am also a information security policy wonk.

The story of the journey from general practitioner to information security policy writer is not terribly exciting. What is interesting though is that many of the skills, tools, and talents that are useful for the law are also useful for information security. Problem solving, the ability to critically analyze materials in front of you, and an unending desire to know your topic in depth (and always "be right" about the knowledge) are invaluable.

Lawyers working on a case need to know by rote the facts particular to a client, as well as the constraints that the law imposes on those facts. We need to be able to point out from a legal, business, and practical standpoint why a client's desired course of action may have an undesired result (jail, fines, and interaction with additional lawyers are nearly always undesired). Similarly, information security professionals need to know how information systems work, and how their clients and employers intend to use that system. Then the fun begins, pointing out the legitimate business trade offs between data security, business efficiency, and sometimes, plain old common sense.

Since I write policy, I get the best of all worlds (much like being a general practitioner attorney). Sort of a "jack of all trades, master of none" role. For short periods of time (usually spanning months), I get to develop some kind of subject matter expertise in a particular information security area while a policy is being created. I meet with the security professionals who know their areas inside and out, I meet with the administrators who know the business side of an organization cold, and I get to try to facilitate the development of a policy that balances information security and business efficiency in a way that makes sense for my organization. Like a law practice, sometimes it is frustrating, sometimes it is exhilarating. It is never dull.

Most readers of this blog are already information security professionals. For those that are not, I can offer the following tidbits that helped me as I entered this field:

1. Study up and don't be afraid to ask questions. This is not a field where you can bluff your way through complex projects with a "fake it till you make it" attitude. Study for certifications and then continue to study after that. Get to know professionals in the field and turn to them for advice frequently. Some day you will be able to return the favor.

2. Know your strengths/find your niche. I like to write formal documents and found a good match with my attorney training in contracts and information security policy writing. My role blends these strengths perfectly and I enjoy the challenge of looking for loopholes.

3. Don't stand still or get complacent. The information security area is always changing. For instance, new federal and state laws are really starting to grasp that information security, data security, electronic information stores, identity information, medical information, and digital forensics are areas ripe for legislation. Learn about what such legislation means for you as an information security professional.

I am really enjoying "phase two" of my professional career. One sign that it might be a good move: My Google Web Alerts for information security topics are at least as many as my alerts for lawyer topics!

Thursday, August 23, 2007

So you want an IT job?

Readers here know that Richard Bejtlich's Taosecurity is a favorite read for me. On Tuesday, he posted "What Hackers Learn that the Rest of Us Don't", and included a bit of commentary about his views for hiring IT staff.

I've had the pleasure of working with IT staff from a variety of backgrounds, from the computer lab IT guy who was a fine arts major, to the gifted Windows admin with a marketing background. They have taught me that a CS degree or an MIS degree frequently isn't the best indicator of suitability to the job. One infamous quote from a CS major undergrad that I knew was "I don't care how the computer works, I just program for it!". That's the same as "I don't care about edge cases, it works most of the time!", or other quotes that scare security folks every time we hear them.

As Bejtlich points out, native curiosity and interest - paying attention to the edge cases and the little details are some of the things that can make a hacker successful. The same goes for hiring an IT professional. During the past few years, I've developed a short list of things that I look for when hiring:

  • Curiosity - if I mention a new technology, technique, or other area of interest, does the candidate ask questions, and do they absorb knowledge?
  • Passion - not everybody can go home and play with things for the entire night, but do they actively enjoy doing what they do? Do they want to do it? I tend to ask candidates what their home network looks like, and how they're securing it. I ask what they'd like to play with, and what opportunities they've had and what they've enjoyed.
  • Laziness - not the bad kind, but the right kind. I look for someone who does it right once, rather than badly over and over again.
  • Active learning - are they expanding their knowledge, either formally via courses and training, or informally by tinkering?
  • Active pursuit of knowledge. Far too many candidates come in who read a security magazine once a month to stay in touch. That's not a useful way of staying up to date in the modern security world. Ask your candidate what they read to stay up to date, and what mailing lists they're subscribed to. I look for depth and breadth of knowledge seeking.
  • Personality - can they make and take a joke? Can they deal with users? How do they come across?
So, what do you look for in an IT candidate? And how does a security professional differ?