Special Coverage Series

Network Computing

Special Coverage Series


How To Hire The Right IT Security Pro

Want to hire the best security team for your company? Understand your security needs, focus on specific skills (including people skills), and don’t worry too much about certifications, advises security expert Michael Davis.

Recent reports show that demand for security staff is rising faster than the available supply of workers. At the same time, the No. 1 hiring priority for U.S. companies is beefing up the ranks of competent security staffers, according to a recent InformationWeek staffing survey.

Twenty-four percent of companies polled said they plan to increase the number of security staff positions during 2013, the report found.

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

But it won't be easy. 39% told InformationWeek that people with the right skillsets were difficult to find.

There are ways for hiring managers overcome a skewed demand/supply curve. The first thing to do is reconsider your requirements without lowering your standards, according to Michael A. Davis, CEO of security consulting firm Savid Technologies, who wrote the InformationWeek security hiring report.

"Most security teams fail for one of two reasons," he wrote. "A lack of proper funding and bad hires. Funding is becoming less of a concern...but making the right hire is always a concern."

The most important things are for your company to understand its specific security needs, and make sure the hiring budget matches the actual requirements, Davis wrote. Security plans often founder because a company hires only one security professional when three are required, or a company assumes that a person who only spends part of her time on security is just as effective as a full-time, dedicated hire.

Companies may also overlook qualified candidates because they think they need a "security ninja;" that is, someone who is expert in white-hat hacking, IT architecture, network engineering, policy administration, social engineering, training and every other potentially relevant skill.

Even companies desperate to overcome a serious shortage of infosec skills don't necessarily need to hire a person with mythic skills. "Usually when a company thinks it needs a ninja, we find it really just needs a plan and someone to execute it," Davis wrote.

[ Join us at Interop Las Vegas for access to 125+ IT sessions and 300+ exhibiting companies. Register today! ]

The first step, then is to identify the specific projects, tasks and roles a new security hire would fill during the first six to 12 months. "Specific," by the way, means something like "analyze and bring up to spec all firewall rules and anti-virus systems," not "stop all the hackers."

In addition to expertise, some organizations may require a security professional with softer qualifications, such as good people skills that will allow him or her to balance security demands with the productivity needs of business units.

Security pros with experience as a security evangelist should be able to act as a go-between and translator for IT and business units, making clear to business-unit managers and executives the importance of security and what that means to both their budgets and business procedures.

Finders, Keepers

It's one thing to want to fill a security position, but another thing to find someone to do it. Of the companies surveyed by InformationWeek, 21% said they prefer to retrain existing staff to fill new security roles. Only 16% said new skills would come exclusively from new hires or contractors. The other 63% planned to mix and match retraining, contracting and new hires in various combinations.

For new hires, the job description should be as detailed as the resumes you hope to review. Listing "Windows 2008 experience" as a requirement is not the same as "analysis of Windows 2008 event logs to determine if a login event was legitimate or not," Davis wrote.

Testing candidates in an interview is a fine technique, but whiteboarding a situation your company actually faces will also show more accurately how a candidate would approach the problem than inventing a theoretical problem, Davis wrote.

It's reasonable that companies would want to hire qualified candidates, including those with industry certifications. According to a report from Burning Glass, a developer of job-search and resume-parsing software, the number of job ads requiring security candidates hold a Certified Information Systems Security Professional (CISSP) certificate is 52% higher now than in 2011.

However, while potential employers may regard a security certification as a validation of a candidate's ability, organizations may not want to put too much stock into it. "We look at most security certifications as worthless," Davis wrote.

The problem with certifications is that they help recruiters identify candidates, but don't identify for hiring managers whether a candidate has a passion for security, or analytic problem-solving skills. Hiring managers have to go further to establish a candidate's bona fides, Davis maintained.

Davis' final hiring tip is to establish specific criteria and a consistent evaluation process before interviewing candidates. If more than one hiring manager interviews a candidate, it's more useful to have metrics against which to compare their impressions rather than the just gut feeling of each interviewer.

Hiring the right person takes time, but Davis says the time invested is worth it. If an organization cuts corners in the hiring process, it raises the odds that it will have to go through the whole rigamarole again in six months when a new hire isn't up to the job, or a good hire goes looking for another job with managers who might understand and appreciate their genuine skills.



Related Reading



Network Computing encourages readers to engage in spirited, healthy debate, including taking us to task. However, Network Computing moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Network Computing further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | Please read our commenting policy.
 

Editor's Choice

RESEARCH: 2013 Backup Technologies Survey

RESEARCH: 2013 Backup Technologies Survey

Think backups are boring? Not so, say more than 500 IT pros. Most, 60%, use two, three or even more different backup applications, and the percentage encrypting all media has jumped 15 points since 2011.
Get full survey results now! »

Digital Issue: The Standardization Debate

Digital Issue: The Standardization Debate

An IT infrastructure constructed from uniform blocks of hardware and software is easier to manage and secure, and new services can be rolled out fast. But giving business units carte blanche can deliver more flexibility, drive innovation and better meets employee needs. Two IT executives square off in this debate, and almost 400 survey respondents weigh in too.
Get the Digital Issue »

WEBCAST: Avoiding Downtime: How Virtualization Can Help In Times of Trouble

WEBCAST: Avoiding Downtime: How Virtualization Can Help In Times of Trouble

Server and storage virtualization can help keep systems alive even in the face of demand spikes, disasters and other troubles. Attend this webcast to learn how virtualization can maximize application availability, create business continuity options for critical apps, and improve disaster recovery.
Register Today »

Related Content

From Our Sponsor

Implementing Energy Efficient Data Centers

Implementing Energy Efficient Data Centers

Electrical power costs over the life of a data center may exceed the initial cost of the IT equipment. As described in this paper, recognizing the appropriate IT design architecture necessary and being able to quantify the potential electrical savings can significantly increase cost savings over time.

Creating Order from Chaos in Data Centers and Server Rooms

Creating Order from Chaos in Data Centers and Server Rooms

IT Professionals who are challenged with managing a chaotic data center - messy racks, sub-standard floor air distribution and cable sprawl - can now leverage innovative methods for dealing with and eliminating the root causes of disorder. This paper outlines the solutions available to help create an organized data center.

High-Efficiency AC Power Distribution for Green Data Centers

High-Efficiency AC Power Distribution for Green Data Centers

In order to create optimal electrical efficiency and simplified data centers, the use of 240 volt power distribution is highly recommended. This paper describes the various configurations for this distribution architecture as well as the quantified benefits. Note: Applicable to North America only.

Energy Efficient Cooling for Data Centers: A Close-Coupled Row Solution

Energy Efficient Cooling for Data Centers: A Close-Coupled Row Solution

The trend of increased heat densities in data centers has held consistent with advances in computing technology. As power density increased, the degree of difficulty in cooling these higher power loads was also increasing. This article discusses the efficiency benefits of row-based cooling compared to two other common cooling architectures.

Data Center Projects: Standardized Process

Data Center Projects: Standardized Process

As the design and deployment of data centers evolve into more complicated projects, the benefits of a standardized and predictable process are compelling. This paper presents an overview of a standardized, step-by-step process methodology that can be adapted and configured to suit individual requirements, thus reducing costs and eliminating waste.