logo
episode-header-image
Sep 2024
31m 46s

CISO vs. Security Engineer

Dr. Eric Cole
About this episode

In this episode of Life of a CISO, Dr. Eric Cole dives into the significant differences between security engineers and chief information security officers, a distinction many fail to recognize. He explains that merging these two roles into the same career track is one of the core issues plaguing the cybersecurity industry today. Security engineers are technical experts focused on identifying vulnerabilities and solving problems from a risk-based perspective, but a CISO's role is far more strategic. The CISO must bridge the gap between cybersecurity and business, speaking the language of the executives and aligning security initiatives with the company's overall growth and profitability goals. Many businesses struggle because their CISOs come from a deeply technical background without the necessary training in business, which causes a breakdown in communication between the executives and cybersecurity teams.

Dr. Cole stresses that the career paths of a security engineer and a CISO are not just different—they require distinct mindsets. While security engineers are problem finders, world-class CISOs are problem solvers, often accepting a level of risk that technical engineers might find unacceptable. This difference in approach is critical to the success of any organization's cybersecurity efforts. Dr. Cole emphasizes the importance of retraining the industry to understand that being a CISO is not a natural progression from a security engineer role, but a separate career path that requires a deep understanding of both business and security. He encourages aspiring CISOs to embrace this mindset shift and focus on communicating security in a way that drives business success.

 

Up next
Aug 21
Simplifying Cybersecurity, Time Management & Strategic Playbooks
In this episode of Life of a CISO, Dr. Eric Cole dives deep into simplicity, time management, and the foundations of being a world-class Chief Information Security Officer. He explains how rebooting your life and career—just like you reboot a slow computer—can help clear distract ... Show More
30m 47s
Aug 14
The #1 Skill CISOs Need for Career Acceleration (And How to Master It)
In this episode of Life of a CISO, Dr. Eric Cole dives deep into one of the most important yet often overlooked success principles for security leaders: simplicity. Drawing from decades of experience as one of the first CISOs before the title even existed, Dr. Cole explains why g ... Show More
32m 1s
Aug 7
Building Credibility Before the Crisis: Zachary Lewis on Frameworks & Board Trust
In this inspiring episode of Life of a CISO, Dr. Eric Cole sits down with Zachary Lewis, Chief Information Security Officer at the University of Health Sciences and Pharmacy in St. Louis. With over five years in the CISO seat and a career that spans startups, coal plants, and hig ... Show More
33m 23s
Recommended Episodes
Oct 2024
Balancing Security with Usability in Cybersecurity
In this episode of Threat Vector, host David Moulton talks with guest speaker Brian Wrozek, Forrester Principal Analyst in Security & Risk, about the complexities of aligning security strategies across global teams. Brian draws on his extensive experience in cybersecurity, operat ... Show More
41m 41s
Oct 2024
Navigating NIST CSF 2.0: Guide to Frameworks and Governance
In this episode, we sat down with Lukasz Gogolkiewicz, an Australia-based Cybersecurity Leader and former pentester, to explore his journey from offensive security into cybersecurity leadership. Lukasz, also a speaker coach at BlackHat USA, brings valuable insights into what it t ... Show More
36m 29s
Nov 2024
3092: Infosec - The Future of Cybersecurity Training and Upskilling
How can the cybersecurity industry bridge the gap in its staggering 4 million open roles? This episode dives into the critical need for workforce development and how unconventional paths into cybersecurity are reshaping the field. Joining us is Keatron Evans, VP of Portfolio and ... Show More
20m 9s
Aug 2024
Securing SMBs Serving Defense Industrial Base and U.S. Critical Infrastructure
In this episode, Chris Petersen, Co-Founder and CEO of RADICL, and I discuss the challenges of securing the small and medium-sized businesses (SMBs) that serve the United States defense industrial base (DIB) and critical infrastructure. These SMBs play a significant role in suppo ... Show More
40m 59s
Jun 14
The Secret CISO: Navigating the Human and Technical Challenges in Cybersecurity
In this episode of 'Cybersecurity Today,' hosts John Pinard and Jim Love introduce their unique show, 'The Secret CISO,' which aims to dive deep into the lives and thoughts of CISOs and similar roles, beyond the usual interview-style format. The guest for this episode is Priya Mo ... Show More
51m 57s
Jul 2024
2975: AI in Cybersecurity: Balancing Innovation and Risk
Are you prepared for the ever-evolving cybersecurity threats that challenge today's businesses? In this episode of Tech Talks Daily, we sit down with Dave Merkel, CEO of Expel, to delve into the dynamic world of cybersecurity. With threats becoming more sophisticated and frequent ... Show More
24m 29s
Apr 2025
Understanding SaaS Security: Insights, Challenges, and Best Practices
In this episode of Cybersecurity Today, host Jim Love delves into the topic of SaaS (Software as a Service) security. Sharing his early experiences promoting SaaS, Jim elaborates on its inevitable rise due to cost-effectiveness and shared development resources. The episode highli ... Show More
38m 5s
May 2024
Cybersecurity: The role of CISOs in today's business strategy
Text us your thoughts on this episodeIn this episode, PwC’s Global Cybersecurity & Privacy Leader, Sean Joyce and Deneen Defiore, Chief Information Security Officer at United Airlines dive into the world of cybersecurity and its growing importance in the C-suite.They explore how ... Show More
25m 59s
Apr 2025
When Hackers Hijack Your Factory Floor
In the future, hackers will have many new vulnerabilities to exploit, especially as industries move from legacy IT to state-of-the-art digital systems. BCG’s Vanessa Lyon looks at how cyber-attacks are likely to evolve over the next ten years, and what business leaders need to do ... Show More
29m 25s
Jun 2021
Role of Top Management in Cybersecurity Governance
The recent ransomware attacks on Colonial Pipeline and JBS are grave reminders that organizations at all levels must constantly be in a high state of cybersecurity readiness and alert. This is no easy task as the points of vulnerabilities are numerous, especially the probability ... Show More
29m 47s