Preview Mode Links will not work in preview mode

Defense in Depth

May 27, 2021

All links and images for this episode can be found on CISO Series

Should you look for the ideal candidate that has all the security talent you want, or should you find the right person and train them with the security talent you want. And if the latter, what is the right person to work in security who doesn't have security experience?

Check out this post and this Twitter discussion for the basis for our conversation on this week’s episode which features me, David Spark (@dspark), producer of CISO Series, co-host, Geoff Belknap (@geoffbelknap), CISO, LinkedIn, and our guest Dev Akhawe (@frgx), CISO, Figma.

Thanks to our podcast sponsor, Sonatype


With security concerns around software supply chains ushered to center stage in recent months, organizations around the world are turning to Sonatype as trusted advisors. The company’s Nexus platform offers the only full-spectrum control of the cloud-native software development lifecycle including third-party open source code, first-party source code, infrastructure as code, and containerized code.

  • Is there a cyber talent shortage?
  • If so, does the shortage come from the hiring side?
  • The dangers of leaving positions open too long
  • The dangers of focusing on checklists vs. candidate potential