What hiring managers look for in a security professional

Opinion
Feb 6, 20083 mins

* (ISC)2 releases security hiring guide; launches online self-assessment tool for certification exam candidates

Today, we’ll review a couple of recent announcements from (ISC)2, the industry body that runs the highly-regarded and highly sought-after Certified Information Systems Security Professional (CISSP) certification. It has published a hiring guide that although is aimed at managers looking to recruit security specialists, the content could also be useful to IT pros interested in entering the security industry or for existing security personnel wanting an inside look at how they can better present themselves to potential new employers. The industry body also launched an online self-assessment tool that enables security pros to assess their knowledge of the (ISC)2 CBK taxonomy of information security topics – the foundation for all (ISC)2 certifications.

The hiring guide discusses the basics such as the type of job functions that exist, the ideal traits of an information security professional, a typical career path, and the certifications required (unsurprisingly this is the chapter where (ISC)2 plugs its range of certs for security pros).

The guide notes that gone are the days when employers hired a single ‘security engineer’ who worked with the IT department. Today, employers are more likely to seek specific roles such as forensic specialist, security architect, chief information security officer, information assurance manager, and compliance officer. Their role has also expanded to include identity and access management, vulnerability management and application security. As with most senior IT positions these days, employers want security pros with a good mixture of technical and business knowledge.

This leads to the ideal traits of a security pro, which (ISC)2 lists as having a keen understanding of technology and the ability to leverage that to implement effective security systems; an understanding of the employer’s industry and place in the market, in addition to its regulatory and legal requirements; and the ability to gain acceptance of security policies among all levels of workers in the company – something that is easier said than done.

(ISC)2 says there are two common career paths for security execs – as security technologists, or security manager/strategists. Don’t be fooled in thinking that security technologists can just sit in a darkened network operating center and monitor traffic for suspicious activity. Technologists require as much business knowledge, and communications and collaboration skills as the more people-facing roles. Security managers require broad understanding of multiple technologies, presentation skills, particular knowledge of a business line or product, and the desire to manage broader risk issues.

You can view the full guide here.

The association’s studISCope (pronounced “study scope”) online self-assessment tool provides a simulation of the (ISC)2 Certified Information Systems Security Professional and Systems Security Certified Practitioner (SSCP) certification exams. Questions used in this self-assessment are comprised of retired questions from previous versions of the actual certification exams and newer questions developed by (ISC)2-certified subject matter experts. At the conclusion of the simulation, the test taker receives his or her score based on the official algorithm used in the actual exam, helping them assess their overall exam readiness, according to (ISC)2.

StudISCope is available in three formats: as a one-of purchase by any individual, as a subsidized or voucher purchase where all the performance results are tracked for an organization separately for one year, and to corporations who purchase the assessment tool as part of a package including an education program or other services from (ISC)2.

The simulated exams can be purchased online in a variety of set combinations ranging in price from $99 to $219 for the CISSP and $49 to $109 for the SSCP, depending on the number of questions the candidate chooses.