Top 5 reasons to be a Head of Information Security
Photo: Georgia Cowling

Top 5 reasons to be a Head of Information Security

I was speaking last week with Jacqui Loustau (founder of the AWSN and all-round fabulous security person) about the challenges of recruiting Heads of Information Security who have ‘done the role before’. We chatted about the pool of people who are willing to move into Heads-of roles and those who are experienced enough to meet the requirements of a hiring company. It got me thinking about one of my early blogs “an alternative path to security leadership” and the ‘what’s in it for me’ for those being encouraged into Heads-of positions. So, with consideration, here are 5 great reasons to take on a role as Head of Information Security (insert other senior security leadership role as you see fit…)

1.    Being a Head of Information Security can be a great stepping stone to a CISO role (and vice versa) or CIO position given your knowledge across all aspects of IT. You are likely to have been involved in IT operations as well as having built a strategy that crosses IT and the business – experiences that not all c-level candidates can exhibit. 

2.    Being a Head of Information Security is a great pitstop enroute to the Board having spent your days practicing good governance and being exposed to risk management, both technical and business.

3.    Travel. Need I say more. Experienced Heads of Information Security are highly sought after globally as up-and-coming CISO’s and subject matter experts. The opportunities for work in all corners of the globe in senior roles can definetly be realised (if you’re up for the challenges of expat life…but as always…that’s another blog for another day).

4.    Not only can you move countries but you can move industries. Skills needed by Heads of Information Security are transferrable across industry from banking to utilities to FMCG and digital. Security Leaders can soak in the risk profile of a new industry and surround themselves with subject matter experts in order to successfully protect a new-found area of interest.

5.    Finally, and possibly most importantly, you can leave a legacy by way of a groomed successor – having nurtured skills in your direct reports to help create experienced, seasoned Heads of Information (and Cyber) Security for the future. Mentoring and coaching the next generation of security professionals to be influential, communicate effectively and leverage the value of relationships is key to there being enough experienced future Heads-of to go around who have ‘done it before’.

With that said, there are many other benefits to leading a security function – including being able to work with some very talented people who are committed to the greater good. If you’re interested in a career as a Head of Information Security or indeed as a CISO, acquiring the skills needed to realise this dream can be a challenge. Most organisations will expect that you can build a strategy, influence demanding stakeholders and inspire the workforce to join the security journey – which is no mean feat. But despite the challenges, with this pivotal role offering so many benefits, who wouldn’t want to pursue the path to being a senior information security leader and beyond?

.

.

For more blogs, visit www.27lanterns.com

Joseph Schwerha

Professor & Entrepreneur

7y

Nice post. Hope all is well.

Like
Reply
Jarrod Loidl

Cybersecurity & Tech Risk Leader

7y

The titles are largely interchangeable for SMBs who may not want or require the role at the C-level where the title would be largely inflated, or where the function is relatively in it's infancy. There is a notable distinction at the enterprise level however, particular for publicly listed companies or those heavily regulated.

A great post Claire I hope this inspires more people to aim for these higher level roles in their career.

Yes not to forget the competitive business advantage you create to make the business more resillient..

Puneeta Chellaramani

Senior Executive | Cybersecurity and Risk | CISO and ministerial advisor | Business development leader ANZ, EMEA,SEA | Security Evangelist | Industry speaker and mentor

7y

Because its the need of the hour and shall remain the need for every subsequent hours to come .... The more sophisticated the technology becomes the more stringent the security has to be ! What better than to be in a field where you have the domain hold & passion to grow ! Anz offers it the best with great working culture :)

To view or add a comment, sign in

More articles by Claire Pales

  • Is your cyber security function an enabler…or an enabler?

    Is your cyber security function an enabler…or an enabler?

    For a while now, security leaders have been re-positioning the cyber security function as an enabler. The definition of…

    9 Comments
  • No longer the Secure CIO

    No longer the Secure CIO

    Why I’m no longer simply striving for a Secure CIO (from the author of ‘The Secure CIO’…) A few years back, I wrote a…

    5 Comments
  • How could you be more targeted in your career goals?

    How could you be more targeted in your career goals?

    My eldest son wants to be a professional soccer player. He lives and breathes soccer.

    1 Comment
  • The rise of the Security 2IC?

    The rise of the Security 2IC?

    It’s a common requirement of CIO’s to desire a security leader who can cover all bases. Someone who can truly lead…

    6 Comments
  • Values-based recruitment

    Values-based recruitment

    When was the last time you thought about the values of your organisation? Are they written on a wall you pass by every…

    3 Comments
  • Is it time to rethink your interview process?

    Is it time to rethink your interview process?

    Last week I was chatting to a friend about the new CISO role he is about to take on. He mentioned that he had been…

    2 Comments
  • Is your security leader on a tour of duty?

    Is your security leader on a tour of duty?

    We all know of people who take on a new role with a plan a mind. They know from day one what their 30-, 60-, and 90-day…

    2 Comments
  • Does your CISO know the role of the board?

    Does your CISO know the role of the board?

    I’ve spent the past week at the Australian Institute of Company Directors (AICD) learning about the ins and outs of…

    3 Comments
  • Are women the only answer to increased diversity?

    Are women the only answer to increased diversity?

    I have noticed that a lot of diversity talk in Australia centres around women. More women needed on Boards.

    18 Comments
  • SaaS is not RaaS (Risk-as-a-Service)

    SaaS is not RaaS (Risk-as-a-Service)

    Scenario: A manager in your organisation signs up for a software as a service (saas) offering. Confidential company and…

Insights from the community

Others also viewed

Explore topics