Recruiting Cybersecurity Professionals Audra Streetman Splunk
Audra Streetman, security strategist for Splunk, explains why organizations need to expand the size of the talent poll from which they are recruiting cybersecurity professionals.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Audra St.
Streetman, who is a security strategist for Splunk. And we're talking about, well, what to do about this persistent cybersecurity skills crisis that we find ourselves in. I think it's been around so long, we just accept it as a matter of fact.
But Audrey's got some thoughts about what to do about that. Audra, welcome to show. Yeah, thanks for having me.
I definitely have some thoughts about this. It's something that is personal for me as a career changer in cybersecurity. Uh, and it's something that I've been trying to convince as many hiring managers as I can that, that there is a way to hire for truly entry level jobs in, in cybersecurity.
'cause I think that's one of the main issues. When we talk about the skills gap, we're often referring to positions that go unfilled because hiring managers are searching for people that meet certain benchmarks, right? They have to have a certain number of years of experience or certain certifications for education requirements.
But I think that there needs to be a shift in how we approach this, especially when we look at more junior positions and the ability to take people on who have maybe zero cybersecurity experience, but they have an aptitude and potential to learn and, and learn on the job. And I think that that's something that hiring managers would actually benefit, uh, from taking on that point of view. Because when you look at some of the more junior positions in cybersecurity, my personal opinion is that people who are coming into this career path who are interested in cybersecurity and taking the initiative to learn on their own, they absolutely can handle the daily tasks required of say, a junior SOC analyst, for instance.
I really do believe that these companies are sometimes doing themselves a disservice by not, uh, opening up their, their job applications to a broader pool of applicants, especially people who might be career changers coming from a different background where they bring their own unique skill sets in with them to, to cybersecurity. Well, who came up with these crazy job recommendations and specifications in the first place? You would think that the HR hiring manager would be having a conversation with somebody.
Where does this all fall apart? I think it's twofold. I think the first is that it's easier when you have requirements to filter out applications because it can be quite a task to go through hundreds of applications to try to find the right candidates.
So when you're more specific about the benchmarks you're looking for, it can help narrow it down. But I do think that that actually excludes a lot of really great applicants sometimes because we're looking for the wrong things. And so that's one area where I think hiring managers can maybe benefit from shifting that point of view and, and looking more at people who have an interest, um, and, and a good work ethic.
I think those can go a long way as well instead of just those benchmarks. And then I also think it's, it's risk analysis because in cybersecurity that's a big component is analyzing risk and being able to assess risk. And sometimes I think it can appear risky to hire someone that doesn't have that experience yet.
But I think it's actually riskier to leave these positions unfilled, especially when you consider burnout in the industry and how it can affect a larger team to have multiple positions that go unfilled because there aren't people meeting the requirements who are applying. So I think that those are two examples of why these jobs go unfilled. Uh, and I think a good example is, is actually the job that I applied to at Splunk when I was changing careers.
'cause my background is actually in journalism. So I worked in local TV news for about a decade, decided I wanted to change careers, ultimately decided to pursue cybersecurity. And when I was applying, you know, I kept getting rejections left and right because I was cold applying for these jobs that required experience that I didn't have yet.
And it's that challenge of, well, how do you get the experience if no one will hire you? Right? And what I learned is that there are some jobs that are truly entry level.
Like the job that I applied to at Splunk was entry level. Um, and I was very fortunate that Splunk was actually looking to hire someone from a communications background for the position that I'm in. Uh, because they saw the benefit of communication skills and research and writing things like that, that can, that can come into play when you're doing research.
Um, and so that was, I was very fortunate in that sense. Um, but I think a lot of companies could benefit from, from looking at the same thing and trying to create job postings that are geared toward truly entry level applicants, um, who might have their own unique skill sets. So what should the job description actually look like?
I mean, I talked to some cybersecurity people and basically they're like, I just want somebody who's good at puzzles, but I don't know how to put that in a job description. Yeah, it definitely makes it more challenging, especially when you have a large pool of applicants to be able to filter on the qualities that really matter, like critical thinking and you know, an interest and aptitude, like I said earlier, I think a lot of times you wanna create a job posting that doesn't exclude anyone. You don't wanna give a person a reason not to apply.
I think it's really important to, to pay attention to the wording in a job posting, because there's often you'll look at job postings and say you have a, an applicant who's more humble, they might not apply if they don't meet every single one of those qualifications. And we've heard research before that women, for instance, have been found to be less likely to apply for a job if they don't meet all of the qualifications. Um, and so I think it's really important to, to, when you're putting these together, to not find a reason for someone to not apply.
So words are very powerful. I think finding language that's more inclusive than exclusive can actually benefit hiring managers when they're looking to bring in a more diverse applicant pool. Um, because I think a lot of companies I think understand the importance of diversity of thought and bringing in people onto your team from different backgrounds and how that can actually be a strength, uh, if you're able to, to do that and, and look for people from different backgrounds.
So I think that's one way to look at job postings. Uh, this is actually, actually a talk that I gave at RSA conference last year was about what hiring managers can do to create more inclusive job postings and what to look out for with language. What are some, you know, green flag words or versus red flag wordings that might turn people away or might be um, might have connotation to them, right?
Whether that be like an age connotation or a gender connotation or an experience or a culture connotation. You know, I think it's important to be mindful of that when you're drafting job postings. Uh, because a lot of people, they, it can be intimidating when you're applying for different jobs and if you're, if it's not a good fit, uh, that can definitely turn people away.
So I think that would be my recommendation for putting together a job posting. Are you at all worried that with the rise of ai, the definition of what an entry level job is changing and that's gonna have some impact on who we're trying to recruit because a lot of the entry level tasks are gonna be automated. So what is the definition of entry level gonna be?
Yeah, I think with generative ai, that's going to be a tool that can really help, especially for more junior analysts coming on. They can use generative AI to help with asking questions and and finding answers and checking some of their work. It can be a definitely a tool.
And I know a lot of, um, security teams are using it currently as a tool to help augment their operations. So I think that will actually help companies bring in more entry-level talent that can then use some of these tools to help as they learn as they go. Um, but I do think the one concern I have is that analysts don't rely on it too heavily so that it's a crutch, right?
Because critical thinking is such an important skill in cybersecurity that we don't wanna become too reliant on these tools 'cause it can actually take away from that analysis and those skills that you develop over time, Aren't we too obsessed with um, four year degrees? Because last time I checked the bad guys weren't exactly requiring the people that they hire to have a four year degree. So why do we need defenders with four year degrees?
Yeah, absolutely. I think that that's something that is changing. I've seen a number of government agencies, for instance, that are removing that requirement from their postings because they recognize that, that in cybersecurity we have certifications, we have ways that people can learn more incrementally that actually makes it a lot easier for career changers as well.
That was one of the reasons why cybersecurity was a more attractive field for me as a career changer, was I could work toward certifications one at a time and it seemed more doable than going back to school and and spending money on a four year degree for instance, or a master's degree program. So I do think that that's changing. I think that obviously you do have to have some knowledge in cybersecurity, right?
I mean there's a lot that people are constantly learning in this field. I always recommend to people if they're looking to break into learn networking concepts to start with and just get a really good foundational understanding of how the internet works, how computers work, and then build from there. And I think with certification, that's a great way to do that, is to start at a more foundational level and then work and become um, and pursue different paths in cybersecurity as well.
So I think that that's a really great way to do it. Um, and I think that a lot of job postings when they are more flexible in requirements about that, that can actually help as well. Instead of saying you have to have this very specific certification, you know, there are so many certifications out there that you can have various different ones that you look for to just have a baseline of, of where someone is with their knowledge in the field.
We also talk a lot about the turnover in this sector is high. A lot of that has to do with, um, it's, it is just a, a lot of burnout because in on certain levels it's tedious on other levels. It's like being in the military, it's long periods of boredom with a few minutes of sheer terror, but people eventually get stressed out and they change careers.
You've been at it for a while. Are there things that we can do to kind of help keep people in these jobs longer and make them feel like, you know, they're not gonna completely lose their mind? Yeah, absolutely.
I think burnout is a huge issue and it's something that a lot of, um, a lot of companies are, are struggling with how to, how to tackle this. Especially if you are struggling to fill positions, your team is short staffed, that adds extra pressure on the people who are, who are already doing the work. And I think, I think a lot of that is, is a management, um, issue when it comes to how do you address this among your team, right?
And I think a big, a big way that we can, we can address this is by first of all acknowledging the problem, right? And then also giving people time to like work-life balance, right? I think that's one area that that can be challenging with cybersecurity.
'cause there's this, this culture of constantly learning and constantly growing and keeping up with everything that's happening, which is great. But I think it's also important for managers to emphasize that if you, if you wanna, you know, take this day to, to go on vacation with your family, that's great. There's nothing wrong with that.
Or if you, you know, wanna take this weekend and, and not feel the need to be constantly studying and learning. 'cause I know that there is sometimes that pressure and I've definitely felt it myself of I've never caught up, right? I always have to keep learning.
I always have to get the next certification. So I think from a management point of view, it's really important to establish that culture of yes, it's really important to constantly learn. And that's a requirement in this industry is to constantly learn.
But also recognizing that in order to do that, in order to keep up with it, you have to be able to rest. Which can be counterintuitive, but it's also, I think if people feel like their management is encouraging in that way, it can make a huge difference. It's also important for management to remember to take people offline.
'cause there are people in the cybersecurity space who are highly committed, but, and they can go for years, but it's only a matter of time before they're gonna crack up like anybody. Yeah, exactly. And I think recognizing the signs among your team as well, if you have a, a coworker or if you're a manager, if you have an employee that you noticed is, um, someone that, that is extremely hardworking and has a hard time saying no or turning, turning down opportunities, I think that's really important to keep in in mind as well.
Because sometimes when you're approaching burnout, you don't even realize that until it's too late. So having people around you that can say, Hey, are you doing okay? Do you need, you know, do you need help or is there a way I can, I can help you with that I think is great as well.
Do we need to go where potential recruits are? I feel like a lot of the times organizations are, you know, they're waiting for somebody to apply, but should they be more proactive? And I don't know, going out to high schools or going into sectors where maybe there's more women or more minorities?
I mean, can we be more proactive about recruitment? Yeah, absolutely. I think beyond just recruitment, I think the biggest thing with bringing in people into this industry is mentorship.
I mean, that's really what inspired me to make a career change was just meeting someone who was already in this industry who was really encouraging and, and just provided me with a roadmap of how to do it. Because I think that's the most challenging part for people who are maybe interested in cybersecurity. It can be very daunting.
It can seem confusing of where do I even begin with this? How do I get my foot in the door? So I think having people who can provide that mentorship and that one-on-one conversation and guidance is incredibly important.
And then from a recruiting point of view, I think definitely reaching out to high schools is a great example. I've, I've, uh, actually taken part in a couple, uh, career fairs at different high schools. Being able to talk with students about their questions and what they're interested in and how that might turn into a potential career one day, I think is huge.
And then also, I just know that there are a lot of people out there who would be great at cybersecurity, they just don't even know it necessarily, right? Because there's, I think sometimes when, when people hear someone talking about something technical, their mind initially just doesn't wanna hear it, you know, it's kind of like, oh, that's too technical. That's not my area of expertise.
But I think a lot of that is starts with education and, and creating an environment for people where they, they don't have that reaction to, to technical information. It's more of like a, I can learn this if I apply myself. And it's not something that certain people are more, um, geared toward than others.
I think that's a misconception that you're either a technical person or you're not. 'cause that's absolutely not true. Anyone can be technical if they apply themselves.
It's just a matter of if you take the time to learn it. Uh, and I think that could be a misconception in the industry as well. So what do you know now that you wish you knew when you were trying to break into this ragged and, you know, would've made your life easier just at, at, at the early stages?
Yeah, absolutely. There's a few tips that I give people who are looking to break in. And my biggest one that I've seen the most success with is to reach out directly to hiring managers.
It actually helped me once with a position that I was really interested in. I found the CEO on LinkedIn and I sent a note and said, Hey, I'm really interested in this position. I'd love to learn more about what you're looking for in an applicant.
And with that job, I initially got a rejection from hr, uh, from the recruiter saying, you know, we, we aren't going to select you for an interview, which was disappointing, but not surprising because I didn't know anyone there. But then a couple days later I heard from the hiring manager saying, Hey, I noticed your name wasn't among this initial list of applicants. We'd like to invite you for an interview because I had reached out directly.
And so that's my biggest advice is if you can show that you're interested by reaching out and going beyond that, I think that can go a really long way. And actually getting a response and getting the opportunity to interview. And I was actually a finalist for that position that I was initially rejected for.
Um, and that the biggest difference was just showing my interest in the position. So that's my number one advice for applicants is, is to demonstrate that your interest in and take steps beyond just the application process to show that you're interested. Um, and then also, you know, following up, I I think that learning about the industry is, is super important to, to understand what the different areas of cybersecurity are and what you might be interested in, what certifications you might be interested in.
That's where mentorship, I think is really key, is finding someone who you can ask these questions, who can help guide you with, oh, are you interested in threat intelligence? Here's, you know, some resources you can learn about this. Or are you interested in pen testing?
Here's a really great book that I read on that. I think that that's really helpful to have someone to guide you in that way. And a lot of that starts with joining groups and associations.
That's a great way to connect with people in the industry. Attending conferences is another great option if you live somewhere and you can attend even, you know, black Hat or Defcon. Um, I remember I was actually able to attend Black Hat before I actually changed careers because I was on Twitter and I was following, uh, someone in the industry who was offering free passes to Black Cat for people looking to break into the industry.
And so I reached out to them on LinkedIn and then I got a free pass to Black Cat, right? So there are opportunities out there to, to reach out and, and to meet people and to network. So I think taking advantage of those is, is really important.
And what's your best advice to managers? And I asked the question because, um, a lot of them may be male and or older, and I think we all have unconscious biases. So how does that play out and how do you help them kind of recognize that in a way that, um, maybe isn't as threatening as it might otherwise be?
Yeah, I think when I was applying for jobs and when I was, uh, starting to change careers, I definitely encountered, uh, a lot of, uh, dismissive attitudes about my career change. For instance, saying I would never hire you. I got that several times from people because I was entry level and I don't know what other biases might have been there, but I did get a lot of dismissive comments or skepticism about my career change.
And I think the important thing in those situations is to just be steadfast in your desire to work in this industry and don't let anyone's opinion turn you away as, as easy as that is to say. I think it's so important to know that if someone ever has a dismissive attitude, uh, toward your ability to do a job, your initial response should be, well, they don't know me, right? Like, that's kind of been my attitude and it's really served me well to just ignore any negative, um, comments or attitudes about that and just be very firm in, in what I wanna do and, and, and how I wanna pursue this.
And so I did encounter that, but I, that really was my default response was, oh, this, this person clearly doesn't, doesn't know they've made an assumption, but it's incorrect. And I think that that's a really healthy way to approach that. All right, folks, you heard it here.
I think the most important lesson in all of this is you gotta remember, you gotta win the war with the army. You got not to win. You wish you had.
So make the best of what you got and fight the fight. Hey Andrew, thanks for being on the show. Yeah, thank you so much for having me.
All right. And back to you guys in the studio.