How to Improve Diversity in Cybersecurity Hiring

141 views
•
July 11, 2018
by
RSAC Cybersecurity
YouTube video player
How to Improve Diversity in Cybersecurity Hiring

TL;DR

Cybersecurity teams can address talent shortages by hiring for curiosity, ethics, collaboration, and growth potential, then training candidates in technical skills. Recruiting from nontraditional pathways and building teams with complementary strengths can expand the pipeline, while greater inclusion helps people from underrepresented groups see cybersecurity as a field where they can belong and thrive.

Transcript

My name is Caroline. Thank you so much for joining us today. Um, I can't tell you how honored I am to share the stage with these three amazing individuals. Uh, and I also can't tell you how thrilled I am to see this many people in the audience. You know, to be able to see people who are interested in hearing about this topic at a show like this, uh... Read More

Key Insights

  • Cybersecurity faces both a severe diversity problem and a substantial talent gap. Caroline Wong proposes that expanding access for underrepresented candidates could help address workforce shortages while creating a field that better reflects a wider range of people and experiences.
  • The survey received 313 responses from people who self-identified as women working in security. Its purpose was to complement reports about underrepresentation, inadequate pay, and workplace challenges by documenting another valid story: many women are building successful and rewarding cybersecurity careers.
  • Visible success stories are an important part of strengthening the cybersecurity pipeline. If girls and young women encounter only descriptions of an exclusionary culture, they may conclude that successful women are exceptions and decide that the profession does not offer a place for them.
  • Technical skills are trainable, while curiosity, ethics, and collaborative behavior are harder to teach. Robin Stuart prioritizes candidates who work well with others, remain dependable during stressful incident-response situations, and bring the personal qualities needed for effective security work.
  • Nonlinear career paths can provide cybersecurity teams with valuable raw talent. Recruiting through organizations serving high school students, prospective college students, and community-college participants expands the candidate pool beyond the conventional practice of targeting graduates from established information systems programs.
  • A candidate does not need to match every listed job requirement to merit consideration. Suzan Nascimento ideally seeks about 70 percent alignment but may accept 50 percent when the person demonstrates sufficient passion, hunger, and capacity to learn the remaining responsibilities.
  • A strong team is well-rounded even when its individual members are not. Hiring managers can examine existing personality patterns and capabilities, then recruit people who add missing qualities such as relationship building, influence, extroversion, strategic thinking, or execution.
  • Inclusion should create a shared benefit rather than replace one exclusive group with another. Suzan argues that diversity efforts can feel like a win-lose contest when focused on quotas, while listening to experiences across differences can support a more inclusive approach.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can cybersecurity hiring help solve the talent pipeline problem?

Cybersecurity employers can expand the pipeline by considering candidates from underrepresented and nontraditional backgrounds instead of recruiting only from familiar graduate programs. Hiring managers can identify raw talent, accept candidates who meet only part of a technical specification, and provide training for the rest. Curiosity, ethics, reliability, collaboration, passion, and willingness to learn can indicate that a candidate will grow into the role.

Q: What qualities should cybersecurity hiring managers prioritize?

Cybersecurity hiring managers should prioritize curiosity, ethics, teamwork, dependability, humor under pressure, and the ability to collaborate during stressful situations. Robin Stuart emphasizes that employers can teach practical abilities such as reading packets, but personal qualities are much harder to teach. Candidates must be people whom colleagues can trust when incident response becomes difficult and the team is working under significant pressure.

Q: Do cybersecurity candidates need to meet every job requirement?

Cybersecurity candidates do not need to satisfy every requirement before receiving serious consideration. Suzan Nascimento describes 70 percent competency alignment as an ideal target, while noting that she may consider candidates at approximately 50 percent. The remaining gap can be addressed through teaching when the applicant demonstrates passion, hunger, appropriate strengths, and a genuine commitment to developing the capabilities required by the position.

Q: How should managers build a well-rounded cybersecurity team?

Managers should seek complementary strengths across the team instead of expecting every employee to be individually well-rounded. A group with many introverts may benefit from an extroverted colleague, while strong strategic thinkers and executors may need teammates who build relationships and influence others. The hiring objective is to add people who differ productively from the existing team and help overlooked contributions receive attention.

Q: Why do positive stories about women in cybersecurity matter?

Positive stories show girls and young women that women can belong and thrive in cybersecurity. Reports focused only on underrepresentation, poor treatment, inadequate pay, or an exclusionary culture may make successful women appear to be unusual exceptions. Sharing varied professional experiences does not dismiss real problems. It adds evidence that rewarding careers are possible and provides visible examples for potential entrants to the field.

Q: What did the survey of women in security examine?

The survey invited people who identified as women working in cybersecurity to describe their experiences. Caroline Wong posted it on social media for two weeks, hoped to receive 100 responses, and received 313. The resulting report sought to present experiences that often receive less attention, particularly the fact that women are thriving in security alongside documented concerns about representation, treatment, and compensation.

Q: How can employers recruit cybersecurity talent from nontraditional pathways?

Employers can look beyond conventional sources such as graduate information systems programs and seek candidates through internship-based organizations serving high school students, people preparing for college, and participants connected with community colleges. Robin Stuart supports this approach because her own career followed a nonlinear route. The central principle is to evaluate raw talent and personal potential instead of treating one educational sequence as mandatory.

Q: Why should cybersecurity diversity efforts focus on inclusion?

An inclusion-centered approach aims to make workforce progress beneficial to everyone rather than turning representation into competition between groups. Suzan Nascimento warns that a transition from a perceived boys club to a girls club can still feel like a win-lose arrangement. She favors greater attention to inclusion and to exercises in which people listen directly to experiences shaped by differences in age, race, or gender.

Summary & Key Takeaways

  • Cybersecurity has both a severe diversity problem and a large talent gap, creating an opportunity to address two workforce challenges together. Caroline Wong gathered responses from 313 self-identified women in security to highlight not only underrepresentation and workplace difficulties, but also the experiences of women who are thriving in the profession.

  • Negative accounts of cybersecurity culture may discourage girls and young women from entering the field, especially when successful women appear to be rare exceptions. Sharing a wider range of professional stories can demonstrate that women belong in cybersecurity and provide visible examples of careers built through both conventional and nonlinear paths.

  • Effective hiring evaluates more than complete technical readiness. The panelists look for partial competency, curiosity, ethics, reliability under stress, passion for learning, and the ability to collaborate. They also recruit from underrepresented pathways and seek complementary personalities and strengths so the overall team, rather than every individual, is well-rounded.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚