logo
episode-header-image
Sep 2024
31m 46s

CISO vs. Security Engineer

Dr. Eric Cole
About this episode

In this episode of Life of a CISO, Dr. Eric Cole dives into the significant differences between security engineers and chief information security officers, a distinction many fail to recognize. He explains that merging these two roles into the same career track is one of the core issues plaguing the cybersecurity industry today. Security engineers are technical experts focused on identifying vulnerabilities and solving problems from a risk-based perspective, but a CISO's role is far more strategic. The CISO must bridge the gap between cybersecurity and business, speaking the language of the executives and aligning security initiatives with the company's overall growth and profitability goals. Many businesses struggle because their CISOs come from a deeply technical background without the necessary training in business, which causes a breakdown in communication between the executives and cybersecurity teams.

Dr. Cole stresses that the career paths of a security engineer and a CISO are not just different—they require distinct mindsets. While security engineers are problem finders, world-class CISOs are problem solvers, often accepting a level of risk that technical engineers might find unacceptable. This difference in approach is critical to the success of any organization's cybersecurity efforts. Dr. Cole emphasizes the importance of retraining the industry to understand that being a CISO is not a natural progression from a security engineer role, but a separate career path that requires a deep understanding of both business and security. He encourages aspiring CISOs to embrace this mindset shift and focus on communicating security in a way that drives business success.

 

Up next
Dec 2022
How do CISOs translate business language to board members?
In this episode of Life of a CISO, Dr. Eric Cole points out the key elements CISOs need to adapt to excel as a translator in the board rooms. The focal point to consider is learning how to communicate and listen. 
32m 25s
Oct 2022
How Do CISOs Make An Impact On Executives?
In this episode of Life of a CISO, Dr. Eric Cole educates us about the principles you must follow if you’re a brand new CISO making their way into this field. You must understand the business to make a lasting impact on the executives. How can you help with the business? What dif ... Show More
31m 10s
Aug 2022
CISOs Accept The Risks
In this episode of Life of a CISO, Dr. Eric Cole asks what are you focused on? Because ultimately that’s what you’re going to become. You will never score that high-level CISO position if you focus on not being good enough for it.  Watch this episode of Life of a CISO to understa ... Show More
29m 47s
Recommended Episodes
Oct 2024
Balancing Security with Usability in Cybersecurity
In this episode of Threat Vector, host David Moulton talks with guest speaker Brian Wrozek, Forrester Principal Analyst in Security & Risk, about the complexities of aligning security strategies across global teams. Brian draws on his extensive experience in cybersecurity, operat ... Show More
41m 41s
Oct 2024
Navigating NIST CSF 2.0: Guide to Frameworks and Governance
<p>In this episode, we sat down with Lukasz Gogolkiewicz, an Australia-based Cybersecurity Leader and former pentester, to explore his journey from offensive security into cybersecurity leadership. Lukasz, also a speaker coach at BlackHat USA, brings valuable insights into what i ... Show More
36m 29s
Nov 2024
3092: Infosec - The Future of Cybersecurity Training and Upskilling
<p>How can the cybersecurity industry bridge the gap in its staggering 4 million open roles? This episode dives into the critical need for workforce development and how unconventional paths into cybersecurity are reshaping the field.</p> <p>Joining us is Keatron Evans, VP of Port ... Show More
20m 9s
Aug 2024
Securing SMBs Serving Defense Industrial Base and U.S. Critical Infrastructure
<p>In this episode, <a href="https://ChrisPeterson,Co-FounderandCEOofRADICL" rel="noopener noreferrer" target="_blank">Chris Petersen, Co-Founder and CEO of RADICL</a>, and I discuss the challenges of securing the small and medium-sized businesses (SMBs) that serve the United Sta ... Show More
40m 59s
Nov 8
A Former Black Hat Hacker Advises Us On Security Weaknesses
Unveiling the Double-Edged Sword of AI in Cybersecurity with Brian Black In this episode of Cybersecurity Today, host Jim Love interviews Brian Black, the head of security engineering at Deep Instinct and a former black hat hacker. Brian shares his journey into hacking from a you ... Show More
55m 44s
Dec 2024
Behind the Scenes with Palo Alto Networks CIO and CISO Securing Business Success with Frictionless Cybersecurity
In this episode of Threat Vector, David Moulton speaks with Meerah Rajavel, CIO of Palo Alto Networks, and Niall Browne, CISO of the organization, about the importance of aligning IT strategy with cybersecurity.  Meerah and Niall discuss how frictionless security, AI integration ... Show More
39m 17s
Oct 2022
An IT security professional walks into an OT bar.
An assessment of port and terminal cybersecurity in the US. Tata Power discloses a cyberattack. The White House issues statements on cybersecurity. India’s power company collaborates on energy sector cybersecurity. Guests Special Agent in Charge, Tom Sobocinski, and Supervisory S ... Show More
37m 7s
Oct 11
The Role and Evolution of Virtual CISOs with Craig Taylor
In this episode of Cybersecurity Today, Jim hosts Craig Taylor, a seasoned virtual Chief Information Security Officer (vCISO) with over 25 years of experience. They discuss the evolution and significance of the vCISO role, Taylor's career path, and the founding of his company, Cy ... Show More
51m 54s
Jun 2025
Vibe Coding vs Low-Code/No-Code: Security Risks and CI/CD Pipeline Impacts for Citizen Developers
Explore the evolution from traditional coding to vibe coding and its relationship with low-code/no-code (LCNC) platforms. This comprehensive analysis examines how AI-assisted development and visual programming tools are creating a new generation of citizen developers, transformin ... Show More
9m 42s