How to Build a More Diverse Cybersecurity Workforce

70 views
May 14, 2019
by
RSAC Cybersecurity
YouTube video player
How to Build a More Diverse Cybersecurity Workforce

TL;DR

Building a diverse cybersecurity workforce requires removing barriers to entry, reconsidering traditional qualifications, and showing candidates the field’s full range of roles. Degree programs and AI cannot solve talent shortages alone. Employers should offer internships, rotations, and visible career paths while combining experienced professionals’ knowledge with fresh, cross-generational perspectives.

Transcript

Hey. So our next speaker is fantastic. We're gonna have some continued energy. We're gonna continue to explore this diversity conversation. We're getting to a generational conversation now. So Hacking the Cyber Diversity Challenge: A Generational Perspective. Please join me in welcome, welcoming Dr. Christine Isikhuo, who's the Senior Manager of Gl... Read More

Key Insights

  • A single accessible experience can launch a cybersecurity career. Christine Izuakor discovered the field through one elective, which led to three security-related degrees and professional roles at United Airlines and as a part-time professor, despite having no cybersecurity role models when she began.
  • The next generation has greater access to cybersecurity knowledge through free online information and course materials. These resources can provide exposure to college-level curricula without college-level prices, allowing motivated people to develop relevant skills through routes that do not necessarily begin with a traditional degree program.
  • Inclusive talent development requires deliberate design. Cyber degree programs and AI are important, but they will reproduce existing STEM diversity patterns if organizations do not identify the distinct cultural, economic, isolated, and systemic barriers that prevent different groups from viewing cybersecurity as a realistic career path.
  • Years of formal experience do not determine a professional’s entire value. Historical knowledge and established expertise remain important, but fresh perspectives are also necessary in a rapidly changing field. Cross-generational collaboration can combine these strengths and help organizations respond differently to evolving security and workforce challenges.
  • Entry-level cybersecurity opportunities need realistic requirements and visible progression. Treating five to ten years of experience as necessary for every position restricts the talent pipeline, while internships, cybersecurity rotation programs, and a clear career line of sight give newcomers credible ways to enter and advance.
  • Traditional degree requirements can exclude capable candidates with relevant training and practical experience. A Year Up intern completed business and technical preparation and worked on a Fortune 100 cybersecurity team, yet recruiters did not take her seriously because she was not pursuing a degree.
  • Cybersecurity includes roles that do not require coding or highly technical expertise. Presenting the profession primarily through the image of hackers in hoodies obscures its breadth, discourages potential candidates, and prevents people with different interests and strengths from recognizing where they could contribute.
  • Visible cybersecurity professionals can help attract a more diverse workforce. People cannot imagine themselves in work they never see, so practitioners should discuss the field’s many responsibilities through media, educational partnerships, and public conversations while still preserving confidential or sensitive information.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can organizations build a more diverse cybersecurity workforce?

Organizations can build a more diverse cybersecurity workforce by identifying the barriers that prevent different groups from seeing the field as a viable career, then designing recruitment and development programs around those barriers. Useful approaches include internships, cybersecurity rotation programs, alternative training pathways, realistic entry-level requirements, visible career progression, university and corporate partnerships, and public communication about both technical and nontechnical security roles.

Q: Why are degree programs and AI insufficient to solve cybersecurity talent challenges?

Cybersecurity degree programs and AI are important, but they cannot solve talent challenges if access to their benefits is not inclusive by design. Without deliberate attention to barriers affecting minority groups, cybersecurity can reproduce the same lack of diversity seen across STEM. Organizations must understand why different communities may not recognize security as a possible career and help them overcome cultural, economic, isolated, or systemic obstacles.

Q: How can employers improve entry-level cybersecurity hiring?

Employers can improve entry-level hiring by reconsidering job descriptions that demand five to ten years of experience for positions intended to expand the talent pipeline. They should create structured points of entry through internships and cybersecurity rotation programs, explain how recruits can progress, and evaluate candidates according to their training, practical experience, perspective, and potential instead of relying exclusively on traditional degrees or lengthy employment histories.

Q: Do cybersecurity professionals need a college degree?

A college degree should not automatically be treated as the only valid qualification for cybersecurity work. The example of a Year Up intern shows that a candidate may complete business and technical training, gain cybersecurity experience within a Fortune 100 company, and demonstrate genuine passion while still being overlooked for not pursuing a degree. Employers should reassess whether conventional minimum degree requirements match the skills actually needed.

Q: Does every cybersecurity career require coding skills?

Not every cybersecurity opportunity requires coding or an intensely technical background. Some roles require technical experience, but the industry contains other forms of work and contribution that the familiar image of a hacker in a hoodie fails to represent. Communicating the field’s broader range through social media, mainstream media, and educational or corporate partnerships can help people with varied strengths recognize suitable career paths.

Q: Why is cross-generational collaboration valuable in cybersecurity?

Cross-generational collaboration combines experienced professionals’ historical knowledge with the fresh perspectives of newer entrants. Years of experience remain valuable, but they are not the sole measure of a person’s contribution, particularly in a field undergoing rapid change. Cybersecurity organizations are unlikely to address new developments by repeating established practices alone, so knowledge sharing across generations can strengthen both innovation and continuity.

Q: How can cybersecurity professionals discuss their work without exposing secrets?

Cybersecurity professionals can explain the purpose, variety, and impact of their work without revealing protected information. Confidentiality may restrict particular details, but it should not become a reason to avoid public discussion entirely. Practitioners can describe different career paths, responsibilities, and experiences through media, educational partnerships, and events, helping prospective candidates see the field while continuing to preserve sensitive organizational information.

Q: What makes the next generation important to cybersecurity recruitment?

The next generation is presented as more diverse and globally conscious, increasingly engaged in higher education, and skilled at using freely available online information to learn. Its members also see major breaches reported regularly and may feel a personal connection to security rather than viewing it only as a corporate issue. These characteristics create an opportunity to increase awareness and build a broader future talent pipeline.

Summary & Key Takeaways

  • A single cybersecurity elective redirected Christine Izuakor from optometry toward a bachelor’s degree in security management, a master’s degree in information system security, and a PhD in security engineering. Her experience illustrates how one accessible encounter with the field can reveal a meaningful career path to someone without role models in technology or corporate America.

  • The next generation is more diverse, globally conscious, connected to security incidents, and able to access educational resources online. These conditions give the cybersecurity industry an opportunity to increase awareness and develop a broader talent pipeline, but organizations must intentionally identify and address the cultural, economic, isolated, and systemic barriers facing different minority groups.

  • Employers should challenge assumptions that strong cybersecurity candidates always need degrees, extensive experience, coding expertise, or highly technical backgrounds. Internships, rotation programs, alternative training, inclusive recruitment, and cross-generational collaboration can open practical routes into the profession. Security professionals must also discuss their varied work publicly while continuing to protect sensitive information.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚