The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/The Virtual CISO Moment
The Virtual CISO Moment artwork

S8E25 - From Help Desk to Enterprise Security with Travis Stein

The Virtual CISO Moment · 2026-06-30 · 32 min

0:00--:--

Key moments - from our scoring

Substance score

27 / 100

Five dimensions, 20 points each

Insight Density5 / 20
Originality4 / 20
Guest Caliber8 / 20
Specificity & Evidence4 / 20
Conversational Craft6 / 20

Travis Stein's career trajectory offers a masterclass in breaking into cybersecurity through persistence and strategic networking rather than traditional credentials alone. Beginning as an IT help desk technician in 2013, Stein endured eight years of burnout before pivoting to cybersecurity in 2021 by leveraging LinkedIn networking to secure a sales engineer role at Ahead - a foot-in-the-door approach that led to positions at CyberArk and Delinea managing privileged access management, cloud security, and zero trust architecture. The episode emphasizes how curiosity, troubleshooting skills, and an investigative mindset transfer directly from IT operations to security engineering. Stein's LinkedIn strategy - personalized connection requests citing specific posts, virtual coffee chats to understand roles, and consistent content sharing - demonstrates how networking beats cold applications by a wide margin. For operators building security teams solo or managing compliance efforts like SOC2 and ISO 27001, Stein advocates embracing the accountability and influence of single-person security departments, using peer networks for validation while maintaining decision-making authority. His mentorship philosophy centers on the "act as if" principle - taking leadership responsibilities before the title arrives.

Key takeaways

  • →Transition from IT to cybersecurity leverages the same analytical troubleshooting mindset; curiosity and willingness to research unknowns matter more than perfect technical knowledge.
  • →LinkedIn networking with personalized connection requests and virtual coffee chats yields measurably better job placement than cold applications (estimated 10-15% success rate).
  • →Leading a security program as a sole person or small team lets you shape policy, influence architecture decisions, and lead compliance audits (SOC2, ISO 27001) despite increased accountability.
  • →Security roles should enable business operations rather than slow them down; project-based work and long-term initiatives provide more satisfaction than endless IT help desk tickets.
  • →Aspiring security leaders should "act as if" by volunteering for leadership responsibilities, mentoring others, and demonstrating capability before receiving the formal title.

Guests

Travis Stein

Topics in this episode

Zero trust architectureLinkedIn networkingSales engineeringSoC2 complianceCloud securityISO 27001 compliancePrivileged access management (PAM)CyberArkDelineaAhead

Questions this episode answers

How do you transition from IT help desk to a cybersecurity career?

Network actively on LinkedIn using personalized connection requests (reference specific posts or work), request 20-minute virtual coffee chats to learn about roles, and show genuine interest in the person beyond job hunting. Stein landed his first cybersecurity role at Ahead through a LinkedIn contact who referred him for a sales engineer position after a coffee chat.

What skills from IT help desk work transfer to security engineering?

Analytical troubleshooting, critical thinking, the ability to research unknowns without panic, and an investigative mindset are directly applicable. Stein credits his 8-9 years in IT help desk and systems administration with building a well-rounded foundation for security work.

What's the best way to use LinkedIn for job hunting in cybersecurity?

Post content regularly, engage with others' posts, send personalized connection requests citing their work, schedule informal chats, and build relationships over time rather than pitching jobs immediately. Stein estimates a 10-15% success rate for cold applications versus significantly higher returns from networking.

How do you manage a security program as the only security person at a company?

Lean into the accountability and influence it provides - you shape policy, drive architecture decisions, and lead compliance audits (SOC2, ISO 27001). Even as a sole contributor, build relationships across the organization to validate decisions and bounce ideas off trusted peers.

How do you transition from individual contributor to a leadership role in security?

Apply the "act as if" principle by volunteering for leadership responsibilities, mentoring others, and demonstrating capability before receiving the formal title. This proves readiness and builds the track record needed for promotion.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

5 / 20

The episode is almost entirely generic career advice - be curious, network on LinkedIn, volunteer for projects, manage burnout - with no tactical frameworks, no operational specifics, and nothing a B2B security practitioner couldn't have guessed. The portion on running a solo security program, which had the most potential, stays entirely surface-level.

being analytical, you know, being willing to troubleshoot and being able to find out, find out the answer
having that curiosity is what drives me on, on a regular basis

Originality

4 / 20

Every idea in the episode is a well-worn career platitude: networking beats cold applying, curiosity is key, work-life balance matters, volunteer to show leadership. There is no contrarian argument, no first-principles reasoning, and no claim that would surprise any informed listener.

it's who you know, it is what you know still, but it's also who you know
the moment folks stop Learning is when it's time to retire, hang it up or change careers

Guest Caliber

8 / 20

Travis Stein is a genuine practitioner with real hands-on experience across PAM, SOC2, and ISO 27001, and his IT-to-security transition story is credible, but he is an individual-contributor-level engineer with no executive scope, and the transcript reveals no depth that only he could provide.

leading, you know, like ISO 27001 audits and SOC2 audits
I had never been like the sole guy at a company. I had always been part of a team, you know, of like five or 10, 15 folks

Specificity & Evidence

4 / 20

The episode is almost devoid of concrete data, named client outcomes, or verified metrics; the only numbers offered are casually estimated percentages with no sourcing, and company names are dropped without any substantive detail about what was actually done or achieved there.

cold applying, you know, probably has like a 1015 success rate, maybe the numbers are a pinch higher than that
send out 200 requests, hear back from 10 people. Out of those 10 people, maybe five can help you

Conversational Craft

6 / 20

The host asks topically reasonable questions but consistently accepts vague answers without follow-up, interjects with lengthy personal anecdotes that derail momentum, and closes the interview with an exchange about a company trip to Europe that has zero relevance to any B2B operator.

What, how do you do, how do you approach that? Let's just say you start a job and you are the only person there. Um, what do you start with first? What do you look for? How do you survive?
Well, two things I need to respond to that. A, I'm jealous. And B, those folks that work for VC Solutions Services. No, we're not going to Europe anytime soon.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A76%
  • Speaker B24%

Most-used words

security30folks26help20linkedin20cyber17cybersecurity14jobs13sometimes12team12sure11back11burnout11desk10field10different10first9

Episode notes

In this episode of The Virtual CISO Moment , Greg Schaffer welcomes Travis Stein, a security engineer whose journey from IT help desk to leading enterprise security programs offers valuable lessons for cybersecurity professionals at every stage of their careers. Travis shares how burnout led him to pursue cybersecurity, why a strong IT foundation remains invaluable, and how networking on LinkedIn opened doors that traditional job searching could not. The conversation also explores leading security as a team of one, transitioning from technical expert to leader, and practical strategies for avoiding burnout while building a rewarding career. Whether you're looking to break into cybersecurity or grow into a leadership role, this episode is packed with practical advice and real-world insights from someone who has successfully navigated both paths.

Full transcript

32 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Sa.

Speaker B: Hi M. I'm Greg Schaefer. Welcome to the Virtual CISO Moment. Travis Stein joins us today. He's a senior security engineer. He's taken an uncommon path through the industry, beginning in it, uh, at the help desk and systems admin, before moving into cloud security, privileged access management, zero trust architecture and security engineering roles with organizations including CyberArk, Galinia and Ahead. Along the way, he's helped organizations achieve SOC2 compliance and ISO 27001 compliance, while developing a practical philosophy that security must enable the business, not slow it down. He is passionate about mentoring others, entering cybersecurity and writing candidly about what it really takes to run security in a lean environment. Travis, welcome to the Virtual CISO Moment. Thank you so much for joining us today.

Speaker A: Hi Greg. Appreciate you having me on. It's an honor.

Speaker B: Well, it's an honor to have you sir, and would like to start as we always start off. I want to hear your story and uh, like how and why you got involved into this weird, really weird field sometimes it seems like, and just bring us through to where you're at.

Speaker A: Yeah, sure. So my, my path through, through the industry, you know, started off with, I guess, you know, fairly humble origins and being IT help desk. To start out my career back in 2012, 2013, I got my first IT help desk job and you know, I got it just kind of cold applying off, off the uh, street back when cold applying was much more successful, you could say. And so um, you know, did IT help desk, system admin work for probably about eight or eight or nine years. Got a lot of um, you know, really, really good experience in, in that realm from about 2013 to 2021 and then kind of, you know, over the years, even though the experience was good, the burnout was, was pretty real for me, like with IT help desk and the whole like, you know, mental health deal that comes along with that, you know, with that burnout sometimes. And so back in like 2020, 2021, I was like, well, you know, I'm just kind of going to different jobs, but the burnout is the uh, same. I probably need, need something, something new, something different. And you know, cybersecurity was something that always really fascinated me. Like I got into it because I liked helping people and I got into cyber security because I like helping and, and um, protecting people from, you know, threats, the bad guys, all that, you know, kind of fun stuff. And so, you know, I went to. Back in 2021, I was, I was on LinkedIn networking with folks just uh, Talking to them for coffee, chats, kind of asking them about, like, hey, you know, I noticed you're in this position. You know, what do you like about it? Pros, cons, you know, do you have 20 minutes of time to talk with me and just kind of give me lay the land of different cybersecurity roles and areas out there. And I was networking with one person, uh, that turned out to be my future boss at the time. He's like, you know, hey, we might have a spot as a sales engineer at Ahead. And um, you're welcome to interview. You know, no guarantees, but, you know, you're welcome to kind of get an interview. I can get your. Get a foot in the door for you. And, um, you know, then it kind of came. The, uh, rest was what was history after that. You know, I stayed there for a little while and then, you know, went to a few other places like. Yeah, like Cyber Arc and Delinea, and then did a, uh, you know, most recent, uh, tour at Poly. And I'll be, uh, starting a new, new job soon, so stay tuned for details on that.

Speaker B: Well, congratulations about that. Um, it's certainly an interesting path. And I want to go back to the beginning there where you talked about, uh, being part of the IT help desk. And I'm wondering, is there anything from those days that has helped you now where you are in cyber security?

Speaker A: Yeah, sure. I think biggest thing is bringing that analytical mind, like a. A troubleshooting sort of, sort of mind to the equation because there are a lot of common skills, at least from it, that I think a lot of people, you know, could you can use in cybersecurity. And certainly I was able to take advantage of just having, you know, and a, uh, analytical mind, I should say, and just being able to, um, you know, troubleshoot well, being able to think critically through. Through issues, through problems. And sure, there's the, you know, there's the plethora of technical skills that's needed for site for most cyber security roles too. But, yeah, there's. There's some common ground there between, you know, when I started my IT career in 2013 and all the way up to 2021, that really, I think served me well. And yeah, being analytical, you know, being willing to troubleshoot and being able to find out, find out the answer. Like sometimes there's. There have been plenty of times in cyber security where I've been stumped. I didn't know the answer. I had to ask for help and look things up. So being able to research what you don't know. Being able to lean into what you don't know instead of, you know, some people can panic when they don't know something. But I always took it as a challenge too, to kind of grow and get better at my craft.

Speaker B: Oh, gosh. Yeah. I mean, uh, I, I kind of chuckled a little bit when you're saying, you know, ask questions. Don't know. I mean, uh, I've been, I've been in this industry for, uh, getting close to 40 years now, and it's like, uh, I still ask questions. I don't know. Sometimes I forget things and like, oh, yeah, that's right. I remember that now. And, and, and it's okay to ask questions. It's, it's worse to try to, to try to fool your way through it. I think it is.

Speaker A: And people, people pick up on that when you, I mean, there, there, there is, you know, a, you know, kind of fake it till you make it component to, to some jobs. But if, if it's 100% fake it till you make it, people, people pick up on it. But yeah, like, being able to, to ask questions. Like, most people are pretty willing to help as long as you're showing that willingness to be like, hey, this is what I tried first. And then people are pretty willing to help if there's like, you know, okay, so you've tried these three things. You're still stuck. Yeah, let me step in. And just showing that willingness to kind of do some research on your own first. And then it's like, hey, you know, questions are good. There's, there's no real dumb question in cybersecurity because we've, we've, we've all been there where we're like, I don't know what the answer to this problem is. I need to phone a friend.

Speaker B: Yeah. And, uh, I often, I have a difficulty remembering between red and blue teaming, which one is offensive and which one is defensive. And probably most folks that are newer in the field, including you, you're like, well, gee, Greg, that sounds kind of stupid. It's obvious. But I have to remind folks, it's like I come from an era where we didn't have red team or blue team or anything like that. We just, we just called it troubleshooting. So sometimes you have to take into account the background of the person. And as you said. Yeah, I don't think that there's really ever a stupid question. It's all about continuous learning.

Speaker A: That's the biggest thing I would say is like, if the moment folks stop Learning is when it's time to retire, hang it up or change careers because like that curiosity will go a long way whether it's an IT field, cyber security related field or job. Like having that curiosity is what drives me on, on a regular basis. It's, you know, one of the big reasons I moved into cybersecurity because I was just naturally curious about more things in cyber security than I was in it. And you know, of course the, you know, IT help desk, you know, grind probably didn't help the cause for, you know, so many years either. But I don't regret that time because it, it gave me a good like basis to enter cyber security. Like I had a lot of fairly well rounded skills when, when I came in. And so yeah, I mean being, being, being curious though is something that will serve a lot of people well, whether they're a nurse, a lawyer, a doctor, IT cybersecurity engineer. Like, it's, it's a good transferable skill to, to have for sure.

Speaker B: Yeah. I like to call it the investigative mindset. I think that everybody needs to have that. I think I, I like that because it's just, it sounds like wordy or it makes me sound smarter when I say something like that. But you touched on something that I think is very interesting as well too and you touched on burnout. And um, I know that, that, that, that can be, you know, a problem in IT and also in cybersecurity. It's just really how, I think there's some commonalities between how it builds and then how we deal with it. But um, did you notice any signs before as you were getting more and more burned out or did it just sort of happen? Um, I'm curious about that.

Speaker A: Yeah. You know, one of the biggest thing I noticed in those eight or nine years that I was doing it and you know, help desk and system admin work was that I would change jobs every, you know, couple of years and, but the feeling was still kind of the same. I was like, well this is a lot on a regular basis. You know, the tickets are endless to a degree I'm sure. You know, a lot of folks, if they're in IT help desk listening to this, they can probably nod along with, with us too. But like, yeah, yeah, we had a

Speaker B: lot of ID 10T errors. So it's like that got to be frustrating.

Speaker A: So you know, and it's interesting because I, I, I genuinely like helping people. But like I, I've, I found out that I have some limits like with cyber security, like the uh, there's still tickets. You, you, you never get away from tickets, right? And so like, but it's more project work, you know, long term work. It's not like, hey, let me fix a, a printer issue or let me troubleshoot an active directory user account or you know, some, some identity access management principle or something. Like it's, it's a, uh, a different kind of beast. But it's, it's also like, you know, I think more, more enjoyable too. And I think over the years I noticed like switching jobs, the satisfaction would kind of come back and then it would fade. Come back and fade. And it just kind of repeated that cycle until I was like, well, I think I need to do something else because like, you know, not only is the job hopping not looking super great on like a reserve to prospective employers, but like I'm, I wasn't at my core like all that happy with, with you know, my career direction because it was just a lot of burnout and you know, talking through with, you know, my support network and family and friends and they're like, yeah, you know, it's, you're probably right, it's time for a change. And then so like late 2020, early 2021, before I, you know, got to, got to Hartree Partners for my first real cyber. But um, you know, it was just time for a change and like the job satisfaction would always kind of fade over the course of like one to two years like clockwork. And that's how I knew I was like, well, I've been interested in cyber for a while and then I'm like, it's probably time for a change.

Speaker B: Yeah. And you mentioned that you leveraged LinkedIn and I uh, think LinkedIn is like one of those tools that you get more um, out of it the more you put into it. And one of the things that I find disappointing sometimes is when I get contacts on LinkedIn from people that the only time when they get on LinkedIn is when they're looking for something. Usually like looking for a job and all of that. And I'm kind of of the um, mindset that you should be constantly participating to keep your network active. I'm curious to hear from you if you have any LinkedIn, um, uh, nuggets of advice because uh, you, you, you mentioned something very important where it led to that foot in the door. Because once we get the foot in the door of a job, then now we're in control. But before that it's like we're at the mercy of the HR ats and, and, and whatever other stuff is out there, the, the bots out there, the fake, um, uh, job applications. I mean, as you said, it's a different world. You can't just pick up an ad right now and apply and be in there. But anyway, back to the original question. Uh, any LinkedIn tips or tricks that worked for you?

Speaker A: Yeah, that's probably one of the areas that I like to think I excel at the, uh, most, maybe even more so than my actual job sometimes is the art of kind of LinkedIn. And yeah, I created my first LinkedIn account when I got my IT career going in 2013, but I never really understood the value of LinkedIn until probably years later when I actually started posting on the platform a little more, sharing what I knew with folks, um, and just kind of noticing trends and patterns of like, hey, a lot of people are getting jobs on LinkedIn, a lot of people are talking about networking. What's this all about? You know, should I kind of, you know, do this for, uh, my own career? And so, you know, that was something that kind of developed over the years and I think it's, it's really important because, you know, LinkedIn has its pros and cons certainly, but it's still one of the most like, influential professional, you know, social media platforms out there. And I've gotten probably two, at least two or three jobs from LinkedIn Networking. And you just never know like, who you're going to meet on there, who you're who might be in a position of influence to help your own career out and things like that. And so I always encourage people, you know, sure, it's important to have a resume, it's important to have a good resume, it's important to, you know, do home labs, have projects, have some certs from time to time. Um, but really where a lot of the jobs are isn't so much, you know, like the job postings because sometimes those are just resume farms for employers and they can decide maybe months down the line they may or want to hire someone, may not. But networking with people gives you that, that advantage because it kind of takes out the bs, I guess you could say, of like trying to find a job because then you get to talk to actual people. And you know, what I started doing probably back in, yeah, 2020, 2021 was really getting serious about LinkedIn. I noticed people were getting jobs. So being able to, you know, ask people just basic things like, you know, hey, would you be willing to have like a 20 minute virtual coffee chat with me? Tell me about your, you, uh, know, a day in the life of you as, uh, you know, insert different positions here, but like, you know, an analyst or security engineer or sales engineer, and a lot of folks were fairly willing to help, like in one. One thing I noticed too, and you know, this is kind of like a personal pet peeve of mine too, is that when I connect with folks, I try to, you know, LinkedIn only gives you some. So many personalized invites, but when I connect with folks, like, I try to pick out something from their profile like, or like a, uh, post and like, hey, I noticed you posted on AI Governance, you know, uh, a week ago. I really liked what you had to say. Would you be willing to chat more with me sometime or, you know, kind of show. Take the time to show people that you're, you're paying attention to, um, to them to a degree. It's, it's that personal touch and it leads to more replies too, as a, as a bonus. Because people might get, you know, I'm sure you, you probably get as well, you know, dozens, hundreds of requests per week. And it's a way to kind of sift through the people that just want to ping folks strictly for jobs versus folks that are, you know, also pinging for jobs, but they're genuinely curious about the other person as well. And that goes a long way with folks. And it's certainly like, it's, it's a really good tool when used well. And sometimes it's definitely playing the long game too because you might, um, send out 200 requests, hear back from 10 people. Out of those 10 people, maybe five can help you. But, you know, as long as you're making the effort, the rewards will eventually come.

Speaker B: Yeah, and, and that mirrors a lot of my philosophy with LinkedIn. Uh, one of the things that, that, that I'm constant about telling folks that I don't like is like, don't. Don't hit me up with a dm, like selling me something immediately upon contact. If I don't, if I, I will accept requests for, from folks that I don't know in the real world if I think that, you know, they, we have some sort of an alignment and all that. But that's not an invitation first off, to like, start asking for stuff. Let's build that relationship a little bit. Because for me, you, um, mentioned jobs, um, when I'm looking for consultants to fill roles for virtual CISO engagements, I don't, I don't advertise that. I don't put it out like on, indeed or anything like that, I will put up, I will put a LinkedIn post out to my network because there are so many folks on my network that now I've gotten to know and I can vet them better. And then when I get responses too, one of the first things that I look for is like, okay, so how active have you been on the platform? Have you been helping others? That's what I'm really looking for when I do the networking on LinkedIn. And I think it behooves other folks to understand that side of the coin because that's. To your point, most of the jobs out there are not advertised. They're through that sort of word of mouth networking.

Speaker A: Yeah, exactly. Yeah. And you know, I think the word of mouth is so powerful because cold applying, you know, probably has like a 1015 success rate, maybe the numbers are a pinch higher than that, but it's not like a 90 success rate or anything, you know, crazy like that. And you know, the value really is in networking. And you know, my advice to a lot of folks that network is that, you know, sure, we, if, if you're networking, you're trying to break into cyber security, you probably want a job in cyber, right? Like that, there's, there's no secret about that, but it's the way you can kind of go about it to folks, you know, that personalized touch, taking some time to get to know the other person and then people are generally more willing to help. And like you said to your point, like, you know, one thing I check when you know people, you know, want me to mentor them or you know, look over a resume or give some advice is like, you know, how active have you been on LinkedIn? What have you tried so far? Do you post any, any kind of, you know, like content portfolio content, you know, home lab, stuff you're working on. And you know, that that's, that's a big part of it too is, you know, really utilizing LinkedIn as a, um, as a main platform. And you know, it's, it's, it's powerful when, when done, done well. And I don't, you know, it used to almost be like a secret like, oh, to network gets you a better chance at maybe landing a job or you know, breaking into the field. But it really is true these days that like, it's, it's who you know, it is what you know still, but it's also who you know and you know, just being able to get that foot in the door because once you're in cybersecurity, it's a lot easier to stay in cybersecurity. And so it's, it's one of those things where it's like, you know, once you land, it's not like you get like a 40 year career guaranteed in cybersecurity, but at the same time it definitely helps the cause because then you can put on your resume like, hey, I've been like a SOC analyst or I've been a security analyst or a cybersecurity engineer. And then each subsequent job becomes a little easier to land because you're actually, you've arrived in the field.

Speaker B: Well, and one of those things landing is like sometimes I'm going to draw from your past where you've landed and you find yourself like basically the security program. And so you've got to figure out all sorts of aspects of the security program. Uh, for someone who's a single person security department. What, how do you do, how do you approach that? Let's just say you start a job and you are the only person there. Um, what do you start with first? What do you look for? How do you survive?

Speaker A: You know, prior to you know, being at poly before, you know, taking this uh, new, new opportunity soon is that I had never been like the sole guy at a company. I had always been part of a team, you know, of like five or 10, 15 folks. And you know, at ah, you know my, my, my last job, it was just my, my boss and I, I guess we were a team of one and a, uh, third people because he was over three different teams including security. And then I was the sole security engineer. And then going into this next opportunity too, I'll also be one of the, the sole, you know, security analyst engineers at that, at this particular place. And you know, it's, it's interesting being this going from kind of a team mindset. I mean you, you always have a team mindset but like going from being like part of a bigger group to having to make the buck, you know, stops, stops there with, with, with you. You know, when, when you become the sole person at a company to lead a security team. And so probably, you know, there's, and there's, there's pros and cons. You know, cons are like, you really have to trust yourself because it's like if you make the um, you know, a decision that you know goes awry or you, you do a decision that you know, isn't fully, you know, like doesn't work out, you know, it's on you and it's not like, oh, hey, you know, the team lead came up with this. You can, you know, blame it on them, but, you know, you're, you're the, the sole point of accountability and, but it's something I've really relished in the last, you know, couple of years as I've had that lead experience. Because one of the things that I really love about being the, like a sole person on the security team is that I get to really influence like policy and really shape security programs and like leading, you know, like ISO 27001 audits and SOC2 audits. And you know, it's. I, I thought, you know, at first being the, the, you know, man, so the main man, so to speak, wouldn't be too fun, but it's actually quite a bit of fun. And like, you know, I, most of the, of the places that I've been so far where I've been the sole, you know, analyst or engineer, like, you're not completely on, on an island. You know, sure you, you know, a lot of the security decisions lie, lie with me, but at the same time, like, there's folks to ping, you know, bounce ideas off of. So even, you know, if folks find themselves, uh, owning a security program by themselves for their next, next role, you know, really lean into it and I would say embrace it too, because it's, it's a lot of fun. To be able to like, be at the forefront of things versus like individual contributor is certainly, you know, awesome. Like, you know, nobody starts probably being the sole person right off the bat very often. But if you ever, if folks get the opportunity, you know, it's something I would definitely encourage.

Speaker B: So putting on your mentor hat, now you got somebody who's a technical specialist and they want to go into a leadership type position. Um, like you were just talking about, what advice would you give them?

Speaker A: Yes, if they want to make, make the jump from being a more, you know, technical specialist or practitioner to a leadership role, I would say it's. Yep. It's always the like act as if principle like, you know, being able to take. If you're on like an individual team and you want that team lead role or you want like a managerial role some, you know, someday in the near future, like acting as if like trying to take, you know, trying to tackle things potentially by yourself before, like, you know, asking for help or showing that initiative that like you, you can lead projects, for example, because if you show leadership skills for like maybe a project that perhaps nobody wants to do and you're the one to tackle it and Take it on and really lead it from, you know, beginning to end. That goes a long way towards showing, I think, leadership skills and, you know, being able to. Yeah, being able to kind of, um, volunteer. Sorry. Uh, you know, being able to volunteer for different things and different projects, I would say, is really, you know, one of those keys and just, you know, showing that willingness to learn, the willingness to like, adapt and be able to tackle sometimes the tough projects and that. And you know, certainly in cybersecurity, you know, this is one of the things that, you know, I'm currently working on too. But working on like the cissp, for example, that's a really good. You know, it's obviously not necessarily like a year one kind of cert. You need some experience to sit for the exam and so on. But if you've got some cybersecurity experience and you want to move to a leadership role, that's a big checkbox too. It's not an easy checkbox, you know, for, for hr, but it's certainly one of the, um, a big one too. In addition to just volunteering for things and showing that those leadership qualities early on, because you don't even necessarily need a certification to prove that you're ready to lead a team. It's absolutely right.

Speaker B: Yeah. Well, but all of this can come with more stress though, and, uh, which is okay because I, uh, mean, we love our field and we know that there's going to be stress, but we have to, we have to channel that stress out and not let it overtake us. Otherwise could lead to, as we were talking about before, burnout, Um, I encourage folks to channel that stress in a positive manner, to decompress in a positive manner. What's one of the things that you do to, um, manage your stress in this wonderful field?

Speaker A: Yeah, so there's a couple of things, and some of these were lessons that I took from. It helped us to, you know, being able to just. And especially working predominantly from home for the past four or five, maybe even beyond five years. Like, it's a different kind of perspective for decompression. Like I being like, this office is the same is in, in my, My, My home. And there's no separation except for the office door behind me between my house and work. Like, it's. It can be a little, you know, tricky sometimes. And so I try to just keep it simple with the decompression and that, you know, I'll go outside for 10, 15 minutes on the patio, maybe, you know, bring my laptop with me. And even just that Is like somewhat refreshing, relaxing kind of, kind of thing for me. And um, you know, I've got a two year old son at home, so I like to go out the door and you know, play with him for 5, 10 minutes, come back to work and you know, you don't need a kid to do that necessarily. If you have a dog or a cat, that'll, that'll work just fine too. But uh, you know, just literally the proverbial kind of remembering to touch grass, so to speak, like, you know, getting outside, getting out of the house, you know, for me is really big. Certainly, you know, exercise and you know, I feel like I've also got a, um, much better support network than I had when I was doing it. Help desk. Like I've got, you know, doctors, a wife, you know, and kid and uh, friends and family and like, I've really, you know, built those networks up over, over the years to, to help with, with burnout. And there's still, you know, sure, there's still burnout in cyber security. I think a lot of folks will tell you it's like, you know, hey, he's talking about it. Burnout. What about cyber security burnout? Yeah, you know, and so, but it's been less. I mean, sure, there, there are some days where I'm like, you know, I don't know how I got through that day. It was such a, such a crazy day. But like, I have more days where I'm not burnt out than I do having burnout, um, you know, when I was doing it and maybe that's just learning how to handle things better because in it I would kind of work myself to the bone and like, I had to, you know, close all the, all the uh, tickets because I'm a fairly competitive person. So I was like, I'm not going to stop work until I close like three more tickets. And it just became like that thing that kind of, you know, bit me in the butt a little bit towards the end because I was like, you know, I'm so burnt out. Like I'm trying to close all these tickets and it just, you know, I need it to come up with more techniques and you know, being able to have like decent like mental health support too. Like, I think that's kind of an underrated thing. You know, whether that's a good family member or friend, your, your spouse, a therapist, you know, any, anything like that, like having those people in your corner, whether that's it, cyber being in any particular field, like it's really important to keep, keep those things up because, like, work can always be stressful, you know, no matter where, what, what area, um, what walk of life you. You come from. And so, you know, having some techniques, you know, even if it's like stretching for five minutes, you know, just walking outside for a handful of minutes, just a re. Kind of a reminder that, like, there's a whole world out there outside of work, and it's not the end all, be all. Like, I used to get really wrapped up in work as, like, my sole source of. And now it's a little more balanced. There's a family man component. There's a friend, a father, a son kind of role that I. I play. And it. It definitely helps me a lot. Like, I couldn't have probably made it into cyber security without a decent support network along the way. And particularly for folks that are searching for jobs, you know, some people with the market how it is and the field being kind of saturated from, you know, tech layoffs, you might be looking for a while. And so it's really important to have a steady, you know, mental health game and have a good support network as well.

Speaker B: Absolutely. Work to live, don't live to work.

Speaker A: Exactly.

Speaker B: Um, so future, uh, plans talking about living to work or working to live. I know you said that you're transitioning into another position, so that's cool. Um, what other. What other plans you got going on?

Speaker A: Let's see.

Speaker B: Yeah. Is that the main thing that right now?

Speaker A: That is more or less, yeah. The. The, uh, big, big ticket item is. Yeah, starting a new job in a couple weeks here. And let's see what else. We've got a trip planned to Dominican Republic in a couple of months. And then I hear the new job is potentially taking us somewhere in Europe for their anniversary. So, uh, that's never a bad thing to join a company. And they get taken on a company trip to Europe like a month or two later. That's always a good thing. I. I highly encourage people to join companies where they're doing that.

Speaker B: Well, two things I need to respond to that. A, I'm jealous. And B, those folks that work for VC Solutions Services. No, we're not going to Europe anytime soon. Well, listen, Travis, wonderful conversation. Appreciate you spending some time to chat with us. Uh, it's been a. It's been a very interesting conversation.

Speaker A: I learned a lot.

Speaker B: And, um, good luck on your new position. Sounds exciting.

Speaker A: Thank you so much, Greg. I really appreciate the opportunity to come on. It's. It's truly an honor.

Speaker B: And everybody stay secure. Sa.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Mythos And The Disappearing Patch WindowAI Proving Ground Podcast · on Zero trust architecture96 / 100
  • How GTT Rebuilt Global Security For The AI EraWhat's Up with Tech? · on Zero trust architecture91 / 100
  • Still Getting Cloud Wrong. Here’s what to Fix. With Simon VernonCyber Leaders · on Cloud security89 / 100
  • Data, AI, and Knowing When to Let Go - with Tommy CotterDefinitely, Maybe Agile · on SoC2 compliance81 / 100
  • An AI Just Out-Hacked 2 Million Humans. She Decides What Happens Next | Nidhi Aggarwal, CPO HackerOneCXO Spotlight · on Zero trust architecture80 / 100
  • Think Like an Attacker: Microsoft Security Exposure Management with Uros Babic [MVP-MCT]M365.FM · on Zero trust architecture78 / 100

More from The Virtual CISO Moment

All episodes →
  • S8E24 - Andrew Kalat: What Cybersecurity Can Learn from Aviation
  • S8E23 - Bruno Lecoq on AI, CMMC, and SMB Security
  • S8E22- Alan Clinard Discusses Building Security Programs That Actually Work
  • S8E21 - Cy Sturdivant on Community Banking, Risk, and Cyber Leadership
  • S8E20 - Becky MacDonald on Building Security Beyond Compliance
Explore the best B2B Ops podcasts →
All The Virtual CISO Moment episodes →