3 ms·
Having been a CISO, I would also add that this really depends on the company. Some companies want to be technically secure (Google, Facebook, etc.), others wan
by _wldu 5y ago
Having been a CISO, I would also add that this really depends on the company.
Some companies want to be technically secure (Google, Facebook, etc.), others want to be compliant to regulations (do the basics, check the box and move on) and a few just want to have a figure head for IT security to fire when things go wrong. So finding the right company that fits you and understanding their culture is important.
If you are hardcore CS/ECE and very technical, you'll want to work for the first type of company. If you did business/management/audit then perhaps the second type of company. I would not encourage anyone to work for the third type.
Just my personal opinion. Hope it helps someone.
- Kalium 5y agoI've found that very few companies in the third category understand that they are. As a result, they are unable to admit it and a security person only finds out when a need to bid for resources arises. Then they learn that the company sincerely believed that hiring the security person is all the resources required.