The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/LevelUp Cyber
LevelUp Cyber artwork

Ep 115: The Non-Technical Side of Cyber with Susan Klement

LevelUp Cyber · 2024-11-26 · 32 min

0:00--:--

Key moments - from our scoring

Substance score

46 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality8 / 20
Guest Caliber11 / 20
Specificity & Evidence8 / 20
Conversational Craft10 / 20

Susan Klement, a leader at AT&T, argues that cybersecurity teams need both highly technical practitioners and non-technical connectors to function effectively. The episode unpacks the spectrum from deeply technical roles (like OSCP certification holders writing scripts and configuring tools) to entry-level positions in security awareness, compliance documentation, and project management where technical coding knowledge isn't required. Klement shares her own progression from programmer to project manager to security leader, highlighting how soft skills - organizing work, connecting people with complementary expertise, managing timelines against regulations, and communicating security decisions to business stakeholders - become more valuable as complexity grows. The conversation explores the emerging BISO role as a liaison between technical security teams and business units, emphasizing how non-technical professionals can translate technical requirements into business language for board-level decisions. For emerging professionals entering cybersecurity without deep technical backgrounds, Klement recommends starting in awareness training, compliance roles, or technical writing, then volunteering for security projects to build domain knowledge. The broader argument is that with AI, quantum computing, and increasing breach sophistication, the need for people who can explain why security measures matter - and how they impact revenue, COGS, and operations - will only grow more critical.

Key takeaways

  • →Non-technical cybersecurity roles like project management and BISO functions are essential for preventing technical teams from getting lost in rabbit holes and keeping security projects aligned with business deadlines and regulations.
  • →Entry-level pathways into cybersecurity without deep technical skills include security awareness training, compliance documentation, technical writing, and volunteering for security projects within your current organization.
  • →The ability to organize work, connect people across skill sets, and bridge communication between technical teams and business stakeholders is as valuable as coding or tool configuration skills.
  • →As cybersecurity becomes more complicated with AI and quantum computing, the demand for roles that translate complex security decisions into business impact (ROI, COGS, revenue) will intensify, especially for board-level communications.
  • →Finding middle ground between absolute security (which prevents all business operations) and unrestricted operations (which creates massive risk) requires non-technical voices who can frame security as a business enabler, not just a blocker.

Guests

Susan Klement

Topics in this episode

MetasploitSplunkAT&TCapture The Flag (CTF)BISO (Business Information Security Officer)OSCP (Offensive Security Certified Professional)Cyber awareness trainingCompliance documentation and regulationSecurity project managementTechnical writing for security

Questions this episode answers

What is a BISO and what do they do in a cybersecurity organization?

A BISO (Business Information Security Officer) is a liaison between technical security teams and business units who translates complex security requirements into business language, explains to stakeholders why security measures are necessary, and helps secure board-level funding and support for security investments.

What are good entry-level roles in cybersecurity for people without technical coding skills?

Entry-level non-technical roles include security awareness training delivery, compliance documentation and monitoring, technical writing, and project management positions - many of which can be accessed by volunteering for security projects within your current organization.

How do non-technical cybersecurity roles prevent technical teams from losing focus?

Non-technical project managers and leaders keep technical teams grounded by tracking deadlines, regulatory requirements, and business priorities, preventing engineers from getting distracted by new tools or techniques and ensuring projects solve immediate problems rather than exploring tangential features.

What skills from other career fields transfer most effectively to cybersecurity leadership roles?

Organization, stakeholder management, connecting people across different skill sets, clear communication, and documentation are the most transferable skills - Susan transitioned from programming to project management to security using these foundational capabilities.

Why is the BISO role becoming more important in 2024 and beyond?

As cybersecurity becomes more complex with AI and quantum computing, board-level governance requirements increase, and the cost of tools and security programs grows, organizations need people who can articulate security decisions in terms of business impact (revenue, COGS, profitability) to justify investments.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode offers some useful framing about non-technical cybersecurity roles (compliance, project management, BISO) and touches on legitimate career advice for entrants. However, much of the content consists of generic motivational statements, repetitive affirmations, and throat-clearing rather than densely packed, non-obvious insights. The core idea - that non-technical roles in security are valuable - is sound but not novel or deeply explored with concrete mechanisms or data.

technical folks on our team, they are very interested in solving a problem, They're very interested in what the technology can do for them, and they can kind of, you know, fall down a rabbit hole a little bit
by organizing a lot of this work and kind of pulling all that stuff together. I allow the technical people to focus on what they're doing

Originality

8 / 20

The episode rehashes well-worn cybersecurity tropes: security as a team sport (explicitly acknowledged as overplayed), the value of bridging technical and non-technical gaps, and the importance of soft skills in tech. The BISO role discussion is current but not deeply original thinking - it's already circulating in industry discourse. No contrarian takes, first-principles reasoning, or genuinely counterintuitive arguments emerge from the conversation.

I don't like the phrase of securities a team sport or whatever overplayed
we're trying to protect you. These are big issues that could come up

Guest Caliber

11 / 20

Susan Klement is a legitimate practitioner with real experience (programmer → project management → infrastructure → security, working at AT&T), which gives her credibility for discussing non-technical security roles. However, she is neither a famous industry figure nor notably senior (no title given beyond context clues). The host's framing as meeting her at local networking events suggests mid-level practitioner status rather than executive leadership. She has done the work at scale but isn't a marquee guest.

I started out a long time ago as a programmer and then moved over into project management
when I do cybersecurity for AT and T, I'm not just supporting AT and T customers, I'm supporting the country

Specificity & Evidence

8 / 20

The episode lacks concrete metrics, named case studies, or specific examples with dollar figures, timelines, or measurable outcomes. Susan mentions AT&T and utility companies as targets for state actors, and there's a brief allusion to a board simulation exercise involving cost-of-goods-sold impacts, but these are not unpacked with data. Most advice is abstract ('find someone doing what you want,' 'get certifications') without concrete implementation details or evidence of what works.

there's a lot of regulation around cybersecurity and what kind of protections you're putting in place, and you need to track are people doing that
you can lose a lot of data, you can lose money, you can lose time if something gets broken

Conversational Craft

10 / 20

The host asks reasonable open-ended questions and attempts follow-ups, but rarely pushes back, challenges claims, or digs into complexity. The conversation flows pleasantly but feels more like a friendly chat than rigorous inquiry. The host occasionally pivots topics broadly rather than drilling down. There's no moment where the host challenges Susan's framing or surfaces tension, and several softball questions lack follow-up depth.

So kudos to you and appreciate you
so to help kind of level set the expectation, because we're going to dive into that idea of technical versus not technical

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

technical49sure19somebody19trying18help15cybersecurity13security13cyber12project12feel11interested11role11back9different9management9roles9

Episode notes

Get ready for an exciting and insightful episode of the LevelUp Cyber show! Join host Tony Bryan, Executive Director of CyberUp, as he sits down with Special Guest Susan Klement, CISSP, PMP , Cybersecurity Lead at AT&T, for an engaging conversation titled: "The Non-Technical Side of Cyber" Discover the human, strategic, and leadership aspects of cybersecurity that are just as crucial as the technical ones.

Full transcript

32 min

Transcribed and scored by The B2B Podcast Index.

Good afternoon, and welcome to this week's episode of Level Up cyber My name is Tony Bryan, the executive director of Cyber Up and your host for the show. Really excited. I feel like I haven't recorded the show in a couple of weeks, had a little bit of time off, but excited to be back in the studio. I'm really looking forward today's conversations with Susan Clement with ATMT.

Susan, Welcome to the show. Hi, welcome, Thanks for having me. So Susan and I have met a couple of times a different events and just being in the networking Saint Louis cyber scene, but have had an opportunity to get to know over the last couple of years. And what I've met had come to grow as a passionate leader, a committed individual in the cybersecurity space.

And for that and Williams, roll over your sleeves and help others right, So kudos to you and appreciate you. Thank you for that. Thanks, So you know I know you, but I'd love to give everybody to have a chance to get to know you. So I'd love to hear your origin story.

How did you get into cyber how did you break in? And we'll get started there. Sure, I started out a long time ago as a programmer and then moved over into project management, did project management for software development for several years, and then moved over into hardware infrastructure and from there over into security because I've always been interested in and wanted to do it, and I was lucky enough that I had a former boss who had moved before and knew that I would be willing to kind of jump in and get into those details and push for security so while helping the teams that needed some organizations.

So that's how I got into cybersecurity. So as we get ready for today's show, and the topic of the day is the idea of being technical versus not technical, right, I think there's been a lot of, honestly misinformation because I feel like that's a bad word and it gives it a negative connotation. But I think there's definitely been a spectrum right out there of like what would be technical versus what isn't technical because there are so many different roles. Right, You've got your risking compliance, you've got some audity, and you could go even as basic as kind of awareness training, which there's zero need for technical skills behind, right, So to help kind of level set the expectation, because we're going to dive into that idea of technical versus not technical and how you could build a really successful career by not being the most technical person in the room.

But let's kind of set expectations. So in your mind, what would be super technical and what would be kind of on the front end of not technical. Right, So super technical in my mind, you're in the tools, You're configuring the scans, your writing scripts, You're basically doing more development work. And I feel like I saw myself a little short because when I say to like our architects and our developers that I'm not as technical, they often say, you're kind of technical, but I don't get into the details.

I know needs to happen, and I know who's really good at doing that, and I can pull them together to form a solution. But I'm not right in any programming. I'm not configuring tools things like that. Yeah, the thing that I kind of pops in my brain is just a quick kind of point of references, and I lean towards a certification OSCP.

Right was at offensive security, some kind of cybersecurity professional thereo. Yeah, what a twenty four hour certification where you're like, you're trying to solve technical problems to attain that certification. Right, Like, for me, that is the top end of technical. You're you're committing to understand all of those things.

And to your point, the bottom end of that is security awareness. Like there are front end sales people that do cybersecurity sales that are good relationship managers but not necessarily technical, and they're going to pass that person to and then house more technical person to walk them through those demos. Right, So that's just you. Can answer high level questions, but they pull someone in for the more detailed technical questions.

Right. I probably could talk enough in front of a room about concepts and ideas of the security. I feel like I have a solid understanding of the world and ins and outs and the lies. But for me, the how would fall apart?

Right. You put me on a keyboard and say here's a splunk or metasployd tool, go crazy and try to figure it out. Clueless and I and I've tried it a couple of times, and capture the flag events where you know you're doing that, you know I'm waving surrender flex, Come help me. I don't know what I'm doing.

Yeah, so you know, maybe that's another good. If you're out actively trying to find CTFs, you're probably a little bit more technical than so there would. If you're giving advice ay on how to remediate an issue. That's that seems more technical to me, you know, but that's something that we have on our teams.

I can point them in that direction, but I can't do it. So let's let's kind of unpack, you know, that a little bit more the idea of, you know, the importance of somebody who would be in a cybersecurity team that's on the more non technical side, right, you know what, what are what would you, in your opinion, be some advantages around kind of the technical versus non technical roles, right, because I think they're complementary to another. But from your perspective, well, wait.

This is something that comes up a lot. Like the technical folks on our team, they are very interested in solving a problem, They're very interested in what the technology can do for them, and they can kind of, you know, fall down a rabbit hole a little bit like, oh, this is a new technique that I haven't tried. Or a new feature of this tool that we could you know, maybe we can implement that. And you know, you need somebody that says, hey, we have a problem that we're solving right now, and we can mark that down and say later come back to it and maybe have a project where we look in these new features and techniques, but right now, we need to make sure we're solving this problem that we have in front of us.

And sometimes it's just helpful to have somebody that can pull pull that rain that in and get back to the problem. Keep an eye on the dates when we have to have something completed in order to either meet a regulation or meet a you know, just something that we told our customers are internal or external customers or clients that we would do. Somebody has to keep an eye on those technical details. And then you know, all the various parts of a project.

You know, there's the technical stuff, but you've got to communicate to your clients, and you've got to make sure that your documentation is updated and all all of those parts that you need to make sure happen in order for the full solution to not only be implemented, but be useful going forward. I always kind of look at the idea of like a project manager right pops in my head, and everything I've always been told is that technical it t folks, whether you be cyb or code oftentimes aren't the most manejerial right like or or you know, the very good at writing code, and those are kind of their skills set.

But there's always you know, that doesn't always translate into good people management or leader leader management project management. So I definitely could see where that's a huge role where somebody maybe with an I TILL or P and P could come in leads crumb discussions and really kind of facilitate everybody's like projects to get to an end goal and really track if I let's so, let's say I'm new, I just graduated college, or I just finished a program like cyber Up, and I'm trying to I'm listening today and I'm trying to figure out what I want to be when I grow up.

I don't feel super technical. Maybe that's a little bit of imposter synem or maybe it's just the truth. You know, what, where where should I start or where should I start looking to either gain some skills in this non technical background, or where are some kind of roles or functions that you would kind of push me to so I can start looking at where I would go. Yeah, you know, and I see a lot of when I see project managers that are in the cyber or security area, they start arted out usually they started out someboace else, either in software development or networking something like that, so they get kind of a feel for how these projects work.

And then they've seen issues come up and seeing how they had to be resolved, and so it's a it's a good way to move into saying okay, I'm interested in that, and then just volunteering. If you're at work and there's a project that you're working on and somebody's like, well, we need to make sure that you know the security organization is involved, to say hey, let me run interference there. Let me not run interference, run you know, do that connection and just get to know the people and you know, let people know that, hey, this is something I'm really interested in.

People. If you're interested in doing a job and you're actually interested in learning, people want people like that. They want you to come in and do stuff that you're you know, going to actually be interested in and you're actually going to work a little harder because you want to learn how this works, and they'll kind of include you on projects, and then when an opportunity comes up where you can move into that as well. You see a lot of that people move from other areas into cybersecurity.

For if you're just kind of wanting to start out in the security area, you can just look at, you know, kind of low level project manager jobs or technical writing jobs sometimes is a good way to do that. You don't have to know all the details, but you have to be able to, you know, work with other people to get that documentation correctly. Just kind of letting people know what you're interested in and continue to do training. You know, you can do the high level training as well.

It doesn't have to be I low Python. I don't know Python. I don't know. When I was a programmer, I did Cobol, so it's a very out of date in my programming languages.

So but just even having any of that experience is a good background to say, I know what you're what you're doing, what you need. So let's let's kind of take a step back and let's you know, back to the idea of a college student or a recent graduate of trying to break in. Where what are some things I should could look for as a way to maybe grow some non technical skills right or where would be some again back to the roles in which I would look from. I'm just trying to break in as an entry level person, and I've seen all, I've been told all the stuff.

But you know, where would be a good place for me to start looking for some of these non technical roles. You know, even some like training of cybersecurity awareness. If you're good at training people and taking them through you know, you've got materials. There's lots of materials out there about how to be a good online citizen and you know, how to avoid scams and just but some people need somebody to walk them through that and give them some practical exams examples.

So being able to do that kind of training, it's a relatively entry level job that you can find and work through that. Another good area is h I'm sorry, my brain to stuff work in for a moment. Another good thing to do is to look at kind of compliance stuff, you know, where you're kind of documenting what people are doing and if they're meeting the requirements. There's a lot of regulation around cybersecurity and what kind of protections you're putting in place, and you need to track are people doing that?

So that is something that you know you can get into without having a lot of technical you know, people will show you if they're doing it or not. You kind of go through and say, is this happening? Are these teams? Do they need support in helping to figure out how to do this work?

That kind that's a good way to get into it as well. That's great advice do as you've kind of leaned into this and you're you know, you've mapped out your own career right and you've had a great run, you know, leading teams, leading projects within a large organization, which is great, you know, and you've probably had many iterations there and I noticed, you know, just your background of writing and editing, I'm sure is a very transferable skill. What skills have you taken from past experiences and you think really help you on your day to day function to be a good kind of contributing project manager leader within those the very technical products right at that part of you know, what.

Organizing is is the big one, right you know, you make an organize, you make sure that you have a good list of everything that needs to be done and who's going to do it and how you're going to get that done and make sure that those things happen when they need to happen. That's useful anywhere. So you had that for a lot. The other big thing that I like is, you know, bringing people together to work together, like who have different skill sets.

Saying oh, I know a person who's really good in this coding area that could help us. That is. Very helpful and gets a lot of work done, honestly, because people don't always you know, sometimes and not always, but a lot of the technical folks, I know, they're busy, they're writing their code, you know, doing their configurations, whatever they're doing, and they don't necessarily know who else can help them, who else can give them ideas that will help them solve a problem. So being able to meet a lot of different people and know what they do and how they can help and how you can help them, you know, like maybe you know, I can find somebody else to help you, and then maybe next time you'll come over and help us with this problem is tremendously valuable.

I've always heard, you know, I mean the speculations nobody likes cybersecurity folks, right, Like, you're finding the bad things. I've always heard the horror stories of like walking down the hall and they know you're the cyber person, Like, oh no, right, Like, so there's this fear of the unknown because you're always trying to catch that person or you know, catch that person doing bad. And were the people that say, now and I've never seen that, right Like, And I'm sure it's happened, and there are people out there, but like the non technical aspect of this, I would assume it plays such a huge role, Like what what things have you found kind of with that example there that you've been able to bridge and maybe mend some of those relationships, And how have you done that, you know through non technical folks and maybe dispel the myth that all security people are bad and trying to you know, take away all of their fun toys that they can play.

Right right, Well, you know what I like to do is point out that we're trying to protect you. These are big issues that could come up. You know, you can lose a lot of data, you can lose money, you can lose time if something gets broken, and we want to protect you from that you know, we're looking at to support you, to make sure that all this work that you're doing is good and is out there and is helpful some people. I do feel like sometimes, especially on the security side, people do say, oh, no, we don't want you to do anything because that's unsafe, And obviously that's it's helpful to have somebody that's kind of in the middle to say, yeah, that's unsafe, but we have to let people do their work.

We have to let you know, there has to be a business to protect and then they have to do some things in order to have that. So kind of find that middle ground is helpful to say, Okay, I know if we were one hundred percent safe, no one would ever see anything that we wrote or any of our data. And then the people on the business side are saying, but then we can't we can't contact people, we can't sell them any thing. We don't know what they want because we have all their data locked up too tight, you know, So we're really protecting both sides.

You got to find that balance. Well, I think the hard part's always so you're trying to always protect everything, but also make sure you're not slowing down operations or other people need just to do business. So you know, there's a fine line of non technical talk to explain to people the reasons and the whys of some of this stuff and how it is an impact to what you just alluded to the risk that are associated with it, and then there's a technical stuff. But I think maybe some of those conversations to be harder when somebody's talking more about the ones and the twos and you know, the protocols and like what you have to do it, versus the kind of broad general explanation of like, hey, we're here to help you know.

I don't like the phrase of securities a team sport or whatever overplayed. Right, everything's a team sport technically, but I could definitely see where it's such an important part right to really be that I'm going to use a word as make a voice of reason, you know, to to to take very technical, difficult things and packaged in a way that is universally understood across most organizations and then try to be that bridge to have to foster good relationships within internal teams just to get jobs and work done right.

You realize, so we want to we want to make your we want to make your job. We don't want to make it harder if we can avoid it, but we have to make sure we protect the company and the data. Yeah, and I think even just that bridge of just helping people understand why some of the things that you do, I think is such an important part of right, Like why do I patch this stupid software in every single month? Oh?

Like it just seems like a waste of time. I don't know, Like they're usually patches are good, right, And there's reasons why you're going to go do those things. So definitely like the idea do as you kind of look ahead to your own And I recently learned about a role was new to me at a recent conference to be SOO the business information security officer, Right, so you know, let's let's impact that when your and your brain or your kind of your words, what you know, what is a BISTO and what is that kind of role serve for you?

Yeah, you know, that's a big one that is really becoming very popular right now. And it kind of encompasses a lot of what I've been saying in that it it is kind of that liaison between the business and the tech side and to try to make that you know, be the voice of the customer over on the tech side and to let the customer know, hey, these are things we have to do and and here's why, so to kind of keep that smooth. It's it's actually a very interesting role. I like it.

I mean, I've I mean I've heard a couple of different like some bows or market specific, some be so or industry or kind of segment specific. So I feel like it's a pretty universal role with the intent is to help bridge the technical stuff to the non technical stuff and really explain the reason behind it. Do you think you know so biso's new. I feel like that timing is pretty much in line with legislature changes nationally to create more transparency and more involvement of board of directors for for profits, where I think a lot of this stuff right opens up apertures for non technical people because there's going to be a need as this continues to grow.

What do you think excites you the most over the next five to ten years for this type of function, you know, for still cyber roles, but less technical cyber roles, and what impact do you think they have on the kind of business forward. That's an excellent point because the cybersecurity landscape is not going to get any less complicated. In fact, it's going to get significantly more complicated. With AI and quantum computing coming up that have you know, are going to break kind of a lot of the stuff that we've already done, and it's going to impact everyone.

We're seeing, you know, you see it all the time, more data being stolen, more breaches. I don't know how many. I could probably have five or six or seven monitoring systems from breaches that have gotten into data that I've had recently, and that's probably only going to get worse. And like I said, more complicated is the tools that people are using are going to get more complicated.

So while everybody is seeing it a lot more and things are getting complicated, the role for somebody who can kind of go in between is just going to get more and more crucial because we're going to need to make sure that there's probably going to be more impacts on the business about what they're going to have to do as they're doing their day to day work and developing their regular business, but also having that protection in place, and you know, somebody that can explain, hey, this is why we need to do it, and also here are the exact steps that you need to take, because you know, not everybody has time learn all of the details about the security information, but like they may have to do something.

So if we've got somebody that can kind of walk them through that, that's you don't have to understand all the details to say, hey, you know, we've got this file that you need to install or whatever, you know, whatever the steps are that the solution has come up with it to kind of help them make sure that they're protecting their business, you know, all the data in the company while you know, trying to do their regular jobs. Uh. Well, the washing program I did a couple of years ago.

We did a lot of simulations around like our goal. We were ceesos and trying to make recommendations to our board of directors for investments that was through you know, security awareness. I was buying software like what's some strategy. And it was an interesting simulation because it showed the impact rights like we chose this thing, and there was you know, there was a you know, our cost went up and our cost you know, our cost of goods went down.

So like all those things that you wouldn't think through, right, I think that the general people would think like, oh, well, it's just I'm gonna buy this tool. Okay, Well there's a trickle down aspect of this, and specifically for the board of directors. So you're trying to get this funding from you've got to be able to package that in a way that it makes sense and focuses on what they're worried about. Right, dollars cents, revenue profits ebit of earnings before income taxes.

Right, cost a good sold So every time you're adding a tool, you're costing good solds go up. So it is all are consideration. At least, tools are not cheap. Whether you develop, whether you purchase them or develop them in house or some hybrid, they cost money.

So you need to make sure that you're doing the most effective for the I say, least amount of money possible. But that's not going to be a small amount of money. Yeah, well I was, you know, like I've I've kind of kicked back in my head over the last couple you know, especially twenty twenty four. It's been a weird market, right, I think teams that kind of sice and shrunk, you know, So it's been a weird a weird time.

And I don't know if it's a combo of just cautiousness to the economy, if it's advances in AI that we're kind of minimizing rules. I don't necessarily feel that strongly that's necessarily the case. I think it's more a conservative mindset of what they're trying to like spending wise, not you know, conservative what they want to spend and just trying to stack the coffers of cash to make sure if something really bad ready. But it's really hard to make decisions right because you're trying if you're focusing on that.

So that's where these bisos, this this rules that are coming down from Senate in Congress, like we need to increase this because like at the end of the day, there's a lot of risks and things that come up. Right when I think if AT and T or you know that has a ton of data or whatever, you know, bad things happen. There's a pretty big impact that kind of trickles down across the board for everybody. So right, and there's I mean so many different people that are coming after companies.

You know, there's just you know, common thieves that just want to steal and get some money. And there's state actors that are you know, like at AT and T we support communication system. You know, that's that's a big deal. Any kind of utility is going to have those bigger state band nation state actors that are that are trying to break things down.

You got to. So as you look. You know, so let's say I'm in high school, We're even gonna take a further back. Were tough college graphs.

We talk boot camp. So I'm at high school, I'm listening to this, like, man, I kind of want to do cyber when I get older. You know, what advice would you give to those kids that are aspiring to like, you know, they're not the ones and twos coders, but they like the idea of I think the other part, and I'm going to tangent here, I think what attracts me to cyber is it's mission oriented. That's the military that I think likes the mission and the purpose, and I think it's a much broader perspective.

I think in life most people want purpose. This is a role and function that you have the ability to have that every single day, right, So, I think is why it's such an attractive draw all individuals. So I'm in high school, I'm meeting the Susans of the world, and I'm asking questions about what I want to be when I grow up? Right, So, what advice do you give to these young folks that are maybe listening to this today and maybe have reservations to going into a career like this because they're out of their own fear of kind of the technical side of it.

You know, what advice would you give to them of where they would maybe go to learn these things, or of how to get to how to become you? Yeah, you know, I think what you really need to do is make sure that you're thinking about why you want to do it, because that makes a big difference. Like you say, I also really think this is important work that supports everyday people. When I do cybersecurity for AT and T, I'm not just supporting AT and T customers, I'm supporting the country, which I love.

So, you know, once you have that why, and then you say, well, what can I do if you're interested in learning more? There are you know, like there I belonged to a woman in cybersecurity group, for instance, but there are other kind of groups like that that you can go to go out on LinkedIn. Even if you're in high school, you can go on LinkedIn and kind of look around and see people that are doing what you want to do and just kind of ask them, you know, questions or just read and follow up.

Find people that are you know, doing a BES role, doing a project management role, a program management role, that are organizing the work and you know, reach out to I would love it if somebody reached out to me from high school and said, I want to do this and how did you do this? And what what do you like about it? And where did you go? I do think that there's still value and doing a college career and maybe doing like my degree was in computer information systems.

It was I did do a lot of programming, but it was other than that, it wasn't super technical. It was a business degree, so that was helpful. But also, like you know, apprenticeship programs like cyber updaes, those are are very helpful as well because you can get some hands on get into the details work and meet people from around the area that are that are doing this work, and get out into businesses and really see what the work is like because you're doing it, you know. I you know, I don't.

I've never trashed anybody's choice of how they gain skills, right like, their colleges college is a great option, We're a great option, right like. And I find it's just you know, find what's going to work best for you and give you the best opportunity successful life. And I don't think that's there's not one right path for every single person, but I do think there's a right approach. And how you're interacting with the people that are around you and how you break into it, I think.

Great, Yeah, if you're interested and you're curious and you want to learn, people will notice that and want to interact back with you and want to help you. The degree that piece of paper oftentimes is a check the box or a formality you would need to do or qualify for something, right like, it's the determinant of somebody's success, especially in this job. I think, for sure, great advice, And I would also say be careful jazz for right like, there are a lot of over caps. Career Professional Studies is a great program for high school students.

They've got an IT entrepreneurship program for juniors and seniors. Great model where you can go into business communities and technical professionals and start to ask questions obviously your career. Technical education is a great way for high school students to start to learn this stuff and be introduced to industry professionals. So, like, you know, there's a lot of opportunities, some more in other states and then some other at all school districts cred equally, but there's a lot of good options where somebody could go and find out.

Yeah, that's all about how you learn or how you want to do it. That whichever way is best works best for you and gets you the skills and gets you into that people that you want to meet, that's the best way to do it, right, So if you work better an apprenticeships mode, that's there's a lot just I like that idea. I kind of wish i'd known about it when I was younger. Maybe there was because it is you get to actually because you know, and when I learn good stuff in college, but like it's different when you're actually in the workforce.

You know, the workforce is bigger, there's a lot more information out there. So having that that apprenticeship that and somebody to kind of walk you through that is also I think a very valuable thing. I pushed it. Anybody, regardless of skill path, benefits from a one year structured onboarding system with the mentor, with additional certifications and support right period.

I don't care if you're eighteen years old or eighteen. Every person's going to be better off in the end with all those support systems. And yeah, and I like certifications. They're good.

They're very useful. You learn a lot while you're studying for them and then and it's really helpful to kind of focus you. So I agree with that for sure. So everybody gets the last same question.

We're at time. It always goes fast. I told you four or five the next team. Yeah, what advice would you give to somebody looking to level up their cybersecurity career?

Yeah, find somebody who is doing what you want to do, and you know, with respectfully for their time. Ask them, you know, how did you get here and what do you recommend? Like we just said, I like the certification route because that's how I think. So you can see what certifications would be helpful, you know, just look around and see.

The one other thing that I would add is just it doesn't have to be the same thing that you've been doing I moved into program management. I was already doing project and program management. But you can look around and say, hey, I want to do a be SOROL for instance, you know, or whatever, it's something slightly different, and see how the skills that you already have apply to a slightly different job and see how you can move into that as well. Because you know, I think as long as you're learning stuff, it's it's interesting to do.

So that's my advice. Learn and grow. I'm a big fan of that Lifetime Lifetime grower. So well, Susan, thank you so much for your time today.

I really appreciated the insight and the topic, right. I think it's as people transition into it and they're really trying to find their kind of their space in this land. I think it's a good reminder that you don't always have to have be the best coder or the best hacker to feel like you have to get the job right, Like, there are opportunities and roles that you can do that without being the most technically proficient. And they're needed, they're needed roles.

Like. The one last thing I'd add is that by organizing a lot of this work and kind of pulling all that stuff together. I allow the technical people to focus on what they're doing. You know, they can focus on solving their problems, not figuring out how to make everything else.

Okay, yeah, that's awesome. Well, thank you so much to you Susan for join us. Thank you to everybody for listening. Always enjoyed these shows.

I hope everybody has a great end of their year and a great holiday. If we don't see you, so thank you.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • How Kubernetes Audit Logging Causes etcd Performance DegradationDevOps Daily with Fexingo · on Splunk91 / 100
  • Cyber Ranges, Attack Simulations & AI: Proving Cyber Readiness | Interview with Lee RosseySecure & Simple · on Splunk86 / 100
  • Modernizing your threat huntTalos Takes · on Splunk86 / 100
  • Security Data Pipelines: How to Cut SIEM Costs and Noise with Dina KamalCyber Sentries: AI Insight to Cloud Security · on Splunk85 / 100
  • Mythos is not the AI ApocalypseThreat Talks · on Capture The Flag (CTF)80 / 100
  • How to Navigate Complex B2B Sales Qualification in Global MarketsStart Global Insights · on Splunk80 / 100

More from LevelUp Cyber

All episodes →
  • Ep 118: A Dive into Multi-Factor Authentication with Sairam Durgaraju49 / 100
  • Ep 117: LinkedIn Best Practices with Jessica Cassidy68 / 100
  • Ep 116: Ask a CISO with Steve Zalewski79 / 100
  • Ep 114: Top 5 Cybersecurity Best Practices with James Bierly77 / 100
  • Ep 113: Trucker to Senior Cyber Leader with Travis Nichols71 / 100
Explore the best B2B Engineering & DevTools podcasts →
All LevelUp Cyber episodes →