News |
Career and Management Advice to Improve Diversity From 21 Leading Women in Cybersecurity
This post was originally posted on IBM Security.
Women in cybersecurity now represent 20 percent of the workforce, according to Cybersecurity Ventures. Thereâs still a long way to go in closing the industry gender gap, especially when you consider that women make up over half the U.S. workforce. However, the security industry has also made progress, and thatâs something to be proud of. In 2013, women were just 11 percent of the cyber workforce.
Continuing to move the needle toward equity is about more than filling empty cyber seats â though there are more than 4 million unfilled infosec jobs currently, according to (ISC)2. Itâs about creating more diverse teams who are better prepared to solve challenging problems. Itâs about creating unbiased artificial intelligence (AI) and higher-quality ideation.
Itâs about better representation, but itâs also about the entire picture of women and diversity in cyber. Itâs time to talk about increasing opportunities and creating pay equity. Leaders need to think about how to retain and promote women and other individuals who are underrepresented in cyber leadership roles.
The diversity problem is too big for any individual or organization to tackle alone. Creating an inclusive industry is going to require collaboration and radically different approaches. Luckily, 21 women in cyber have offered some advice on how to create better equity in hiring, management and retention efforts, as well as advice for women starting out their cybersecurity careers.
Cybersecurity Career Advice to Accelerate Your Growth
1. Donât Be Afraid
A significant amount of women are interested in making the transition to cybersecurity. âDonât be afraid,â advises Kara Federow, security analyst at Sucuri.
âWhere would we all be if women like Admiral Grace Hopper, Ada Lovelace and Katherine Johnson had all decided that they were too afraid to do what they did? You are valuable, you have things to contribute. Surround yourself with supportive people, and donât be afraid to be awesome.â
2. Find Your Fit and Be Patient
Thereâs an emerging number of specializations within cybersecurity. Now more than ever, motivated women in cyber have an opportunity to find a niche where they can flourish.
âCybersecurity encompasses so many different things â risk managementand response, policy and laws related to information security. [Plus,] social engineering and psychology,â says Mimi Zohar, senior software engineer with IBM Research. Thereâs also âapplication, network, cloud, IoTâ and more.
Remember that âsuccess will require a lot of time, patience and perseverance. Anything worthwhile normally does.â Zohar also advises women in cyber to consider culture before accepting a job offer: âChoose to work with nice, talented people.â
3. Catalog Your Accomplishments
Elaine Palmer, senior technical staff member at IBM Research, believes women in cybersecurity should pursue every possible opportunity for growth.
âGet as many academic and professional credentials after your name as you can â MBA, PhD, CISSP â and always use them in your signature,â says Palmer. âKeep your knowledge and skills up to date by joining professional organizations like ACM or IEEE. Take advantage of their free online libraries and cyber training courses. Keep a running log of your accomplishments and keep your resume up-to-date. When making career decisions, get fully informed, but trust your intuition.â
4. Increase Exposure
âThere isnât a step-by-step guide or specific track to success in cybersecurity, which makes it a great field for women to create their own paths,â says Carrie Bowers, director of Managed Detection & Response at Agio. âIf youâre just beginning in this field, start looking for opportunities to increase exposure like project management and technical writing [or] editing.â
âBuilding a career in cybersecurity starts with self-awareness and knowing what keeps you challenged. Stay curious.â
5. Master Interpersonal Skills
âHaving a technical aptitude is a valuable cybersecurity skill,â says Michelle Alvarez, manager, Threat Intelligence Production Team for IBM X-Force IRIS. Still, she believes âmastering interpersonal or soft skills, like being able to effectively communicate with peers, reports and clients, is essential.â
Alvarez relies heavily on soft skills for problem-solving, resolving conflicts and communicating. Her interpersonal skills also come into play when sheâs managing large projects, such as the annual X-Force Threat Intelligence Index.
âInvesting in the development of your interpersonal skills the way you might invest in technical skills will open up more cybersecurity opportunities,â says Alvarez.
6. Go Out and Meet People
Keren Elazari is a cybersecurity researcher, co-founder of Leading Cyber Ladies and co-founder of BSides TLV (Tel Aviv). She believes the best way for women to grow in their cybersecurity careers is to go out and meet people.
âThere are hundreds of events, meetups [and] conferences. Sadly, we often donât see many women participating as attendees, speakers and organizers. Iâve made some of my best connections and learned some of my most important technical and professional lessons by ⌠attending, volunteering, speaking and organizing events,â says Elazari.
7. Find Your Voice
âWhile listening and observing are important, donât be afraid to find your voice to speak up and engage,â says Anne Jobmann, manager on the Malware Reverse Engineering Team for IBM X-Force Incident Response and Intelligence Services (IRIS). âBe prepared to bring new ideas or solutions others might not have thought of yet. Donât be afraid to ask questions.â
8. Learn From Your Mistakes
âResilience is how fast you can recover from ⌠setbacks and push your career forward. In the long run, learning from mistakes is what makes you stronger,â says Glenda Lopez, director of IT Governance and Global Information Security at the Henry M. Jackson Foundation.
9. Prepare for Pay Equity Pushback
âBuild your reputation,â says Lauren Hasson, senior software and infosec engineer and founder of DevelopHer. âPeople who influence your career need to know you, and they need to know the great work that you do.â
In addition to building your influence, build your negotiation skills and start early. Lauren is a passionate advocate for tech pay equity. She recommends that women approach salary negotiation with a firm grounding in data based on research from multiple salary data sources. Also, prepare for pushback.
âYou can handle that pushback with confidence by asking your hiring manager a key question like, âWhere did you get your numbers?’â says Hasson. âSince your salary negotiation numbers are grounded in actual data ⌠youâll be able to have a conversation with professionalism that will impress your employer and set you up for success.â
10. Lead by Influence
âManagers need to be leaders, but you donât have to have direct reports to be a leader,â says Kim Wachtel, VP of Growth Engineering and UX at JumpCloud. She believes cyber women have an opportunity to lead by example at any stage in their career.
âThis thought process was a huge part of my career growth and journey,â says Wachtel. âWhen I stepped into a technical product management role, it was the first time I had to figure out how to lead by influence and really help engineers feel inspired ⌠without having any management authority over them.â
11. Donât Hold Yourself Back
âDonât hold (yourself) back if there is a job you want or a problem you see where you feel that you can make a difference,â says Beth Dunphy, director, deputy business information security officer (BISO) and privacy leader at IBM Security. âToo often, us women take ourselves out of the running for an opportunity due to a belief that somehow we are lacking a skill or experience or are not a perfect fit for the role, when objectively we actually may be the best candidate or have the right expertise to solve the problem at hand.â
12. Be Aware of Opportunity
âThe first thing I start with, particularly with younger women professionals, is educating them on the opportunity that the security industry presents,â says Catherine Frame, director, North America Technical Sales and Client Success with IBM Security.
âSecurity risks and threats have become more pervasive, which has then opened up a whole new industry for employment, skills and jobs. The opportunity that presents itself today for new professionals is the ability to enjoy the industry â if itâs something that excites you â for an entire career.â
Advice for Cybersecurity Management to Retain Diverse Teams
1. Support Security Conferences
Networking and conference attendance can be a gamechanger for diverse cybersecurity talent looking to find mentors and uncover new opportunities. Gina Yacone, cybersecurity consultant at Agio, believes âwe have a responsibility to younger generations of women to learn what barriers are preventing them from attending, like money, opportunity and insecurity.â
âWe have to help break those barriers,â says Yacone. âWe must pay it forward by sharing and offering scholarships to big events or covering dues for organization memberships.â
2. Hold Conferences Accountable
âWhen invited to speak at a conference, ask about how they are encouraging women and diverse candidates to speak,â recommends Kirstin McIntosh, Head of Partnerships at CyRise.
Kirstin is also a proponent of accountability in personnel management, supporting technology that enables more inclusive hiring and better retention efforts. âTextio [is] a bias-free language tool for job adverts,â says McIntosh. And, âApplied.com is a gender-neutral online recruitment tool.â
3. Think in Terms of Team Chemistry
âWe need to move away from the single âheroâ paradigm to a more healthy, creative, collaborative environment,â says Mimi Zohar. âDr. Margaret Heffernan gave the keynote at LINUXCON 2016 titled âBeyond Measure: The True Power and Skill of Collaboration,â on what makes a team repeatedly successful. The answer was not IQ or individual brilliance. Instead, it was empathy, helpfulness, trust and diversity.â
4. Support the Needs of Neurodiverse Talent
âIn cybersecurity, it is well-known that those who are neurodiverse, [such as] those who are autistic, have ADHD or other neurodiverse conditions, are well suited to careers in the industry,â says Lisa Ventura, CEO and founder of the UK Cyber Security Association. âHaving a diverse team doesnât just make your company look good, it goes a long way in promoting an environment of innovation and out-of-the-box thinking.â
âIf I go to a conference, or Iâm on a panel or speaking or something, I build in a day or two afterward, so I can just have some time. Those kinds of events can be really overwhelming to me,â says Ventura. She hopes conferences and leaders will consider inclusive management techniques such as âquiet zones where people like myself can go to get away from all the noise in the background.â
5. Create Networks of Support
Thereâs an opportunity to support âwomen and minorities in this field by [creating] relationships with universities [and] womenâs organizations like the Executive Womenâs Forum and Minorities in Cyber,â says Catherine Allen, chairman and CEO of Shared Assessments. In addition, Allen believes organizations should create internal networks of support, such as âAccenture and KPMG.â
âMentoring is critical,â says Allen. So is âseeing âsomeone like meâ in leadership.â
6. Make Retention a Priority
âWhat I have seen work well is a cultural change that starts with HR and sweeps through the entire hiring process. That process begins with how job descriptions are worded and goes on to having diversity on the interviewing team,â says Limor Kessem, executive security advisor with IBM X-Force IRIS.
âBut hiring is not enough. Retaining talent is a challenge. What I have seen work well is recognition, inclusion and psychological safety at work. Another major [retention] factor is flexibility in work hours and locations.â
7. Adopt Collaborative Tools
Lisa Forte, partner at Red Goat Cyber Security, once worked for a manager who was into âamateur dramatics.â This team used a performing arts technique for tech collaboration.
âThe rule was when someone put forward an idea, you could only start discussing it if you started your sentence with âyes, and ⌒â According to Forte, the improvisation tactic was really effective for inclusive collaboration. âFirstly, it stopped people just shutting down other peopleâs ideas,â says Forte. âSecondly, we developed some hugely creative ideas out of it because you had to think about how to get it to work instead of just saying no.â
8. Support Industry Events
âReach out to community events in your region [and] seek recruitment candidates there,â says Keren Elazari.
âSupport such events [and] host them at your offices. Give your team members the choice and support of travel and time to participate in their choice of professional and community events. Managers so often invest vast amounts of money in new tech, whereas the investment in talent is a fractional percent of that.â
9. Hire Critical Thinkers
âAs organizations are discovering more and more, cybersecurity talent is not about technical skills,â says Debbie Gordon, CEO of Cloud Range Cyber. âThe most important skill is critical thinking. Cybersecurity skills can be learned, but someone who is a critical thinker has a high likelihood of being successful versus someone with a bunch of certifications.â
10. Remove Bias From Hiring and Promotion
âWe need employers to be more creative about fostering gender equality and ending double standards during the interview process,â says Gina Yacone.
âAll business leaders should undergo bias training to minimize the impact of favoritism in the hiring and promotion processes. [One] method companies should consider includes ensuring the same questions are asked of all interviewees, regardless of their age [or] gender. Studies have shown that group interviews help curtail bias during interviews as well.â
11. Be Deliberate About Diversity
âThe cybersecurity industry continues to have lower diversity representation than the IT industry overall,â says Sonya Miller, HR director with IBM Security and Enterprise & Technology Security. Miller recently testified in front of Congress in favor of developing the cybersecurity workforce.
âEnsure that diversity is made a priority in hiring. Deploy programs to ensure diverse talent is given equal opportunity to develop and gain appropriate exposure for progression,â says Miller.
âBuilding and retaining a diverse workforce must be deliberate. The returns on business performance and innovation will follow.â
12. Stay Attentive to Bias
âIt is proven that a diverse workplace contributes to the overall satisfaction of employees and, consequently, to the business results,â says Vanessa Pugliese, Latin America Marketing Leader at IBM Security.
âYou want to make sure you are promoting a healthy, diverse and non-intimidating workplace. Be attentive to comments and attitudes that may sound inoffensive but can trigger a negative emotion â unconscious bias is far more common than conscious, explicit prejudice. Always make use of empathy and, should you identify [biased] behavior in your team, address it immediately.â
13. Revise Team Structures
âIf you want to hire and retain diverse teams, then how you hire and structure the roles has to change,â says Beth Dunphy. âIf we continue to recruit, interview and operate in the same way as we always have, then we are less likely to build diversity in our teams. Through initiatives like New Collar Worker, PTECH and Veterans hiring programs, IBM is diversifying our security teams to fill critical skills shortages and bring new perspectives.â
The Future of Cyber Is Female and Diverse
Women in cybersecurity and individuals who aspire to security careers can grow from this advice. Nothing good comes easy, including a well-paid, intellectually satisfying infosec job, but rest assured there is more than one path to that goal.
Leaders have a responsibility to create better career opportunities for women, minorities and individuals who bring a diversity of thought, experience and viewpoints to cyber teams. Itâs time to fill seats with empathetic, hard-working, critical thinkers by casting a wider net for talent and creating a more level playing field to retain diverse talent