Hosted by Staffing Security Positions How To Choose The Right Personnel Jeffrey Posluns, CISA, CISSP, SSCP, CCNP, GSEC SecuritySage Inc.

Slides:



Advertisements
Similar presentations
Reasons to Become CISSP Certified Keith A. Watson, CISSP CERIAS.
Advertisements

Degrees Certifications Experience Last Update Copyright Kenneth M. Chipps Ph.D. 1.
Security and Personnel
Network+ Guide to Networks, Fourth Edition
© 2013 The McGraw-Hill Companies, Inc. All rights reserved Mike Meyers’ CompTIA A+ ® Guide to 801: Managing and Troubleshooting PCs Fourth Edition (Exam.
Role of Vendor Technologies in the Development of Network Professionals Mak Sharma and Sharon Cox School of Computing, Telecommunications and Networks.
StanSource Inc. is Information Technology services and solutions providing organization engaged in providing a full range of solutions and services to.
UNCLASSIFIED 1 Enterprise Architecture Career Path Working Group Walt Okon Senior Architect Engineer Architecture & Infrastructure Directorate Office of.
Computer Security and Penetration Testing
© 2006 IBM Corporation Introduction to z/OS Security Lesson 9: Standards and Policies.
Network+ Guide to Networks, Fourth Edition Chapter 1 An Introduction to Networking.
Security Certification
© 2007 The McGraw-Hill Companies, Inc. All rights reserved The Path of the PC Tech Chapter 1.
Security Certifications
© 2010 The McGraw-Hill Companies, Inc. All rights reserved Mike Meyers’ CompTIA A+ ® Guide to Managing and Troubleshooting PCs Third Edition The Path of.
The Top Ten of Security. Ten best practices for securing your network. Ten best security web sites. Eight certifications.
Firewall Auditing Sean K. Lowder CISSP / MCSE / CCNA
Computers Are Your Future Eleventh Edition Chapter 10: Careers & Certification Copyright © 2011 Pearson Education, Inc. Publishing as Prentice Hall1.
Certification and Training Presented by Sam Jeyandran.
Chapter 8 Sport Management
Figure 1-2: Simple peer-to-peer network
Network+ Guide to Networks, Fourth Edition Chapter 1 An Introduction to Networking.
Computers Are Your Future Tenth Edition Chapter 10: Careers & Certification Copyright © 2009 Pearson Education, Inc. Publishing as Prentice Hall1.
1. 2 Why is the Core important? To set high expectations –for all students –for educators To attend to the learning needs of students To break through.
Test Organization and Management
Test Roles and Independence of Testing Telerik Software Academy Software Quality Assurance.
Cisco Networking Academy Program  Welcome & Syllabus  Cisco System Fact Sheet  Course Structure  Cisco Line of Certification – CCNA Exam Objectives.
Nata Raju Gurrapu Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips.
Professional Administrative Support for Adult Learning Pro- SAL PROJECT INFORMATION.
Ali Pabrai, CISSP, CSCS ecfirst, chairman & ceo Preparing for a HIPAA Security Audit.
© 2010 VMware Inc. All rights reserved vSphere 4.1: Install, Configure, Manage.
Ms. Amy Hubbard Career Counselor SENIOR PORTFOLIO The spotlights on YOU!
Chapter 2 Organisation and People. HD Location Centralised –Single physical location within an organisation Decentralised –Multiple support sites located.
Certifications (Animated Presentation)
Information and communication technology (ICT) careers  What are information technology careers?  Working with computers and/or communication technologies.
Course 2277: Implementing, Managing, and Maintaining a Microsoft ® Windows ® Server 2003 Network Infrastructure: Network Services.
Copyright 2012 John Wiley & Sons, Inc. Chapter 3 The Project Manager.
MT 340 Unit #7 Seminar Dr. Donald Wilson Agenda: Unit #7 Organization Culture Unit #8 HR Practices & Diversity Unit #8 Compiled Final Project Unit #9 The.
Information Security Principles and Practices by Mark Merkow and Jim Breithaupt Chapter 3: Certification Programs and the Common Body of Knowledge.
Carly Einstein Assistant Director of Graduate Career Services Office of Graduate Studies Resume Writing Workshop.
Job offer IT System & Software Specialist We are currently looking for an IT database administrator in order to respond to one key-account customer demand.
Job offer IT Infrastructure Specialist We are currently looking for an IT infrastructure specialist in order to respond to one key-account customer demand.
Module 2: IT Professionals in an Enterprise. IT Professional Roles IT Management and Processes Professional Development for IT Professionals.
Pass Cisco CCENT Certification Exam. Required Exam: The exam required to get this certification is: ICND1: Interconnecting Cisco Networking.
RESEARCH QUESTION “What does the term 'industry ready' mean and what are the generally accepted criteria for assessing whether or not an IT person is 'industry.
MANAGEMENT of INFORMATION SECURITY, Fifth Edition.
Cisco Professional Certifications Exam
IS4680 Security Auditing for Compliance
DoD Information Assurance Certification
Test Roles and Independence of Testing
Information Security Professional (CISSP Preparation)
Career Portfolios Building Your Own Personal Career Portfolio
The Path of the PC Tech Chapter 1.
Stretch Your Budget With Organizational Membership
Pass MCP Test MCSE: Messaging.
CMGT 445 Competitive Success/snaptutorial.com
2018 New CheckPoint Exam Dumps Killtest
CMGT 245 Education for Service-- snaptutorial.com.
CMGT 445 Education for Service/snaptutorial.com
CMGT 245 Teaching Effectively-- snaptutorial.com.
CMGT 445 Teaching Effectively-- snaptutorial.com.
CYBER TRAINING & EDUCATION CONFERENCE
Chapter 3 The Project Manager © 2012 John Wiley & Sons Inc.
Network+ Guide to Networks, Fourth Edition
CS 490/CIS 790 Information System Security
Stretch Your Budget With Organizational Membership
Security week 1 Introductions Class website Syllabus review
The Final – and Most Important – Step in the Hiring Process
Chapter 3 The Project Manager © 2012 John Wiley & Sons Inc.
APMP Professional Certification
Presentation transcript:

Hosted by Staffing Security Positions How To Choose The Right Personnel Jeffrey Posluns, CISA, CISSP, SSCP, CCNP, GSEC SecuritySage Inc.

Hosted by Identifying Positions Management IT Security CSO / CIO Technical Implementation Administration Documentation Active vs. Passive Security Physical Monitoring Incident Response Communications

Hosted by Understanding Skills IT System Installation System Administration Patch Systems Monitor System Logs Backup Systems Follow Security Rules Systems Documentation Security Security Configuration Security Administration Understand Patches Monitor Security Logs Ensure Backup Security Ensure Rules Are Followed Security Documentation

Hosted by Understanding Skills (2) Most IT & Security Personnel Have Experience In Both Areas! Determining Where A Particular Person Can Best Fit In Can Be Difficult!

Hosted by Certifications ( Product ) MCSE ( Microsoft Certified Systems Engineer) Microsoft - Specific Information About A Product CCNA ( Cisco Certified Networking Associate ) Cisco - Specific Information About A Series Of Products CCSA ( Check Point Certified Security Administrator ) Checkpoint - Specific Information About A Product

Hosted by Certifications ( Technical ) SANS GIAC SANS - Specific Security Topic For Each Certification ( There Are A Few ) SSCP (Systems Security Certified Practitioner) ISC Broad Range Of Security Topics ( Similar To SANS GSEC )

Hosted by Certifications ( Management ) CISSP (Certified Information Systems Security Professional) ISC Broad Range Of Security Topics CISM (Certified Information Security Manager) ISACA - Security Management Specific

Hosted by Certifications ( Issues ) Learning To Pass A Test? vs. Knowing & Understanding The Materials? Someone With A Certification? vs. Someone With Years Of Experience?

Hosted by What You Want In A… Security Technologist Specific understanding of multiple technologies Technical expertise Communication skills (speaking and writing) Documentation skills Ability to work in a team The desire to improve one’s self and learn more Security Manager Broad understanding of multiple technologies Management techniques Communication skills (speaking and writing) Documentation skills Ability to direct a team Ability to distinguish between technical skills

Hosted by Security Career Paths Progression System Administrator Security Administrator Security Manager Certification Product Certifications Technical Certifications Management Certifications Why would someone NOT get a certification? Attitude / “certifications just mean you can pass a test” Apathy / Lack of understanding of how it can benefit them

Hosted by Evaluating A Resume ( Beyond the norm ) Past jobs IT specific with security functions Security specific job description Team leader or team member Communications skills Publications or papers written Memberships & Affiliations Affiliated with any public security forums? Contributions to open projects?

Hosted by In The Interview Communications Skills Explain a concept to both a technical and a non- technical person (simultaneously) Write a sample paragraph describing a security issue (~200 words) Your Thoughts Will this person’s skills grow from technical to management? Will this person want to move into management, or will he/she be happy as a senior tech?

Hosted by Summary Skills and requirements What is on paper vs. what’s in their head Growing as an individual within the company The resume vs. the person

Hosted by QUESTIONS? Thank you! Jeffrey Posluns, CISA, CISSP, SSCP, CCNP, GSEC SecuritySage Inc.