Leadership & Executive Communication
,
Professional Certifications & Continuous Training
,
Training & Security Leadership
ISC2 CISO Jon France on Unrealistic Job Descriptions, Hiring for Attitude
According to ISC2’s latest report, job descriptions for entry-level cybersecurity roles tend to list qualifications that are out of reach for most new cyber professionals. Based on feedback from 929 hiring managers across six countries, the report says hiring managers need updated requirements and broader talent pipelines to build more resilient security teams.
See Also: OnDemand | Old-School Awareness Training Does Not Hack It Anymore
Jon France, CISO at ISC2, said many inflated job requirements – such as CISSP certifications or five years of experience for entry-level jobs – still dominate listings and discourage candidates.
“We’re still asking the profession for senior-level certifications or experiential requirements for entry level, partly because HR departments might write in a vacuum,” France said. “One of the recommendations we make is for the hiring manager, which hopefully would be in the cybersecurity team, to co-write and to vet those job descriptions and work with HR to get an appropriate descriptor language to come to the fore.”
Foundational certifications, hands-on learning and non-technical traits offer more realistic pathways into the profession, he said. “Hire for attitude, and train for aptitude,” he said.
In this video interview with Information Security Media Group, France also discussed:
France is an information security professional and CISO at ISC2 serving as advocate for security and risk management activities, skills development and awareness among all users of technology across the industry, as well as within ISC2.