From Hacking to C-Suite: Navigating the Labyrinth of Security Careers
BSidesSF 2024 · Day 1
Overview
This panel discussion, "From Hacking to C-Suite: Navigating the Labyrinth of Security Careers," offered a multifaceted exploration of career paths within the cybersecurity industry. Moderated by Nicole, who leads platform and application security at Roblox, the panel featured a diverse group of senior security leaders: Caroline Wong, Chief Strategy Officer at Cobalt; Swati Joshi, VP of SAS Cloud Security at Oracle; Anna Bellus, who leads security at Netflix; and Thuny, a Principal Engineer at Google. The discussion aimed to provide insights for individual contributors (ICs) considering pivots, managers contemplating executive roles, and anyone seeking to understand the non-linear nature of security careers.

Key moments
- 0:00 Panel introduction and audience participation, setting the stage for career discussions.
- 6:00 Thuny's intentional pivot to privacy, driven by evolving threat models and protecting users from companies.
- 8:00 Caroline's pivot from GRC to application and offensive security, and from policy to quantitative risk.
- 10:00 Swati's journey from generalist to specialist and back, highlighting the challenges and possibilities of career pivots.
- 11:00 Anna's experience moving into management, focusing on supporting others and allowing for failure.
- 17:00 Caroline discusses the difference between working for a security vendor versus an internal security team.
- 22:00 Panel discusses key soft skills (communication, influence, team building, context switching) essential for career growth.
- 42:00 Discussion on SEC rule changes and the CISO role on the board, addressing high-level governance and liability.
From Hacking to C-Suite: Navigating the Labyrinth of Security Careers
Speakers: Unknown
Conference: BSidesSF 2024
YouTube: https://www.youtube.com/watch?v=T6-cJ2N9vH4
Overview
This panel discussion, "From Hacking to C-Suite: Navigating the Labyrinth of Security Careers," offered a multifaceted exploration of career paths within the cybersecurity industry. Moderated by Nicole, who leads platform and application security at Roblox, the panel featured a diverse group of senior security leaders: Caroline Wong, Chief Strategy Officer at Cobalt; Swati Joshi, VP of SAS Cloud Security at Oracle; Anna Bellus, who leads security at Netflix; and Thuny, a Principal Engineer at Google. The discussion aimed to provide insights for individual contributors (ICs) considering pivots, managers contemplating executive roles, and anyone seeking to understand the non-linear nature of security careers.
The panelists shared their unique origin stories, detailing how they entered the security field—ranging from accidental entry during a state-sponsored attack to intentional academic pursuits in cryptography and self-taught expertise. A central theme was the concept of pivoting within security domains, between individual contributor and leadership roles, and across different types of organizations (in-house tech, consulting, security vendors). The conversation also delved into the critical soft skills essential for career advancement beyond technical prowess, such as communication, influence, and business acumen. Ultimately, the panel challenged the notion of the CISO role as the sole "pinnacle" of a security career, emphasizing impact and continuous growth as more meaningful measures of success. This discussion is crucial for anyone in the cybersecurity field looking to strategically plan their career trajectory, understand the evolving landscape of roles, and develop the necessary skills for long-term success.
Background
▶ Watch: Panel introduction and audience participation, setting the stage for career d... (0:00)
The panelists' diverse entry points into cybersecurity underscore the varied and often non-traditional paths individuals take to join the field. Nicole, for instance, began as a full-stack software engineer at Yahoo, finding herself thrust into security after experiencing a state-sponsored attack while working on identity. This accidental exposure solidified her commitment to the security domain. Caroline Wong's journey started with an engineering degree from UC Berkeley, leading to an internship at eBay and a career launch in GRC (Governance, Risk, and Compliance) shortly after the first version of PCI DSS (Payment Card Industry Data Security Standard) was released in 2005. Swati Joshi, in contrast, made a very intentional switch to security after a Bachelor's in Computer Science and a stint as a Java developer, pursuing a master's in security at an NSA-accredited university after encountering SASS and DAST (Static and Dynamic Application Security Testing) in her development work.
Anna Bellus is a self-taught security professional, having started by "tinkering a lot with computers and technology as a child." Her career spanned various security disciplines, including offensive security, network security, product security, application security, and distributed botnet detection. Thuny, with a background in mathematics, discovered cryptography in her final year of undergrad, which led her to a master's program combining math and computer science. She then joined the Paranoids team at Yahoo focusing on web application security, later moving to Mozilla to secure the web platform and eventually pivoting to privacy, co-founding the W3C Privacy Community Group to build next-generation privacy-preserving APIs.
This array of origin stories highlights that there isn't a single, prescribed path into cybersecurity. The field accommodates individuals from various academic and professional backgrounds, whether through formal education, self-learning, or serendipitous events. The subsequent discussions on career pivots, the challenges of moving between individual contributor and management roles, and the differences in working for various company types all stem from this foundational diversity, illustrating the complex and often non-linear nature of career progression in security. The panel aimed to demystify this "labyrinth" by sharing personal experiences and offering practical advice on navigating its many turns.
Key Findings
▶ Watch: Caroline's pivot from GRC to application and offensive security, and from pol... (8:00)
The panel discussion yielded several key findings regarding career navigation in cybersecurity, emphasizing adaptability, continuous learning, and strategic skill development.
Firstly, pivoting is a fundamental aspect of career growth, though it is often challenging. Thuny intentionally shifted from security to privacy, driven by a changing threat model where technology companies themselves became a concern, not just external attackers. She noted the similar mindsets and skills required for both domains. Caroline transitioned from GRC and policy-focused roles at eBay and Zinga to application security and offensive security at Sigal and Cobalt, also moving from a policy view to a more quantitative testing approach within risk management. Swati described her journey as a "swing between generalist and specialist," initially struggling to find a specialized role after becoming a generalist, then intentionally specializing in defense operations at Mandiant and Netflix, only to later prove her generalist capabilities again for executive leadership at Oracle. This highlights that career paths are rarely linear and often require strategic shifts to acquire new skills or adapt to evolving industry needs.
Secondly, the distinction and transition between Individual Contributor (IC) and people leader/manager roles were thoroughly explored. Anna initially resisted management, feeling "corralled" into it, but ultimately "ended up loving it." She emphasized that moving into management requires a readiness to stop "doing the thing that you want to do every day" and instead support others, including letting them "fail in doing it without you stepping in." Thuny, a principal engineer, expressed gratitude for the existence of senior IC tracks (principal, distinguished, fellow engineer), which allowed her to wear multiple hats—diving deep into technical problems, shaping product strategy, and working cross-functionally—while also accommodating personal life choices. Swati's experience included moving from IC to manager and back to IC, driven by opportunities for more money and a desire to "round out [her] resume," before making a more intentional long-term switch back to management. This suggests that both paths offer significant growth and that trying both can be beneficial.
Thirdly, the panel highlighted the differences in working for various types of companies. Caroline contrasted working on an in-house security team (defending a specific company, reacting to incidents, integrating with business value) with working for a security vendor (solving problems for many customers, focusing on product management and strategy). She noted that vendor roles expand the universe of applicable skills beyond traditional risk management, including customer-facing roles like sales and marketing. Swati shared her experience in security consulting at Mandiant, which, despite personal costs like frequent travel, provided invaluable exposure to diverse industries (healthcare, oil and gas, tech), high-stress situations, and crucial skills in Stress Management and executive communication. She also noted the cultural adjustments required when moving from consulting to a tech company like Netflix (hallway conversations vs. formal agendas) and then to an enterprise company like Oracle, where different skills are needed for upward (explaining risk to executives), downward (technical leadership), and sideways (persuasion and influence with peers) communication.
Fourthly, the panelists converged on the paramount importance of soft skills for career advancement. Communication was universally cited as key, particularly the ability to tailor messages to different audiences and understand their value systems (Thuny). Anna emphasized learning communication in non-profits, where wearing many hats forces rapid learning. Thuny also highlighted passion and influence as crucial for motivating others. Caroline identified team building and Performance Management as vital for leaders, aiming for a "1+1=10" impact. Swati underscored her reliance on Technical Program Manager (TPM) skill sets for organizing groups around projects and outcomes, and the critical ability of context switching to juggle multiple priorities, from talent retention to incident response and resource allocation.
Finally, the panel directly addressed the question of whether the CISO role is the "pinnacle" of a security career. The consensus was a resounding "no." Caroline stated it's "not a job I want to have personally," preferring roles that maximize her positive impact on the world. Swati viewed limiting growth to one title as "very limiting," emphasizing that "career is not linear." Thuny focused on making "privacy pivots in the industry" and driving change as her personal pinnacle, rather than a specific title. Anna echoed this, stating that titles feel "limiting" and that success is "all about where you can find the most impact." This collective perspective reframes career success around influence, impact, and continuous personal and professional growth, rather than a singular executive title.
Technical Deep Dive
▶ Watch: Anna's experience moving into management, focusing on supporting others and a... (11:00)
While the panel primarily focused on career development and soft skills, the discussion implicitly touched upon various technical domains and the evolving landscape of cybersecurity. The panelists' backgrounds and current roles illustrate the breadth of technical expertise required in the industry.
Nicole's role at Roblox, leading platform and application security, highlights the proactive security measures necessary to protect large-scale online platforms. Her origin story at Yahoo, dealing with a state-sponsored attack on identity systems, points to the critical importance of robust identity and access management (IAM) and incident response capabilities.
Caroline Wong's career trajectory from GRC and PCI DSS compliance at eBay and Zinga to application security and offensive security at Cobalt demonstrates a shift towards more hands-on, proactive security testing. Her current role at Cobalt, an offensive security company, implies deep engagement with methodologies like penetration testing and vulnerability assessment, aiming to identify weaknesses before malicious actors exploit them.
Swati Joshi's experience as a Java developer exposed her to SASS and DAST, foundational tools for identifying security vulnerabilities in code during development and runtime. Her subsequent roles in incident response consulting at Mandiant and leading detection and response at Netflix underscore the technical demands of identifying, analyzing, and mitigating active threats. Her current position as VP of SAS Cloud Security at Oracle involves securing complex cloud applications, requiring expertise in cloud security architectures, data protection, and continuous monitoring. She explicitly mentioned her team needing to be "very technically savvy," knowing about ethical hacking, red teaming, GRC, and detection engineering.
Anna Bellus, being self-taught, accumulated experience across a wide array of technical areas, including offensive security, network security, product security, application security, and distributed botnet detection. Her work in botnet detection, in particular, requires sophisticated understanding of network traffic analysis, anomaly detection, and large-scale data processing.
Thuny's academic background in cryptography and web security formed the basis of her early career at Yahoo's Paranoids team, focusing on web application security. Her pivot to privacy at Mozilla, where she co-founded the W3C Privacy Community Group, involved developing privacy-preserving APIs for the web. This work is highly technical, requiring deep knowledge of web standards, browser architecture, and privacy-enhancing technologies to protect user data from tracking and profiling. Her current role at Google in privacy, security, and policy in search continues this focus, integrating technical solutions with broader policy considerations.
The discussion also touched upon security metrics, with Swati highlighting the importance of tracking incident health, application/product security (e.g., security faults, security by design, mitigation rates), and compliance to communicate effectively with executives and boards. This implies the need for robust data collection, analysis, and reporting frameworks within security operations.
Finally, the mention of SEC rule changes regarding CISO liability and the discussion about CISOs on boards points to the increasing legal and regulatory scrutiny on cybersecurity, which has direct implications for how technical security programs are structured, measured, and reported at the highest levels of an organization. While not a technical deep dive in the traditional sense of code or exploit analysis, the panel's insights reveal the diverse and evolving technical skill sets that underpin successful careers in cybersecurity, from offensive techniques and cloud security to privacy engineering and large-scale threat detection.
Demo / Proof of Concept
▶ Watch: Caroline discusses the difference between working for a security vendor versu... (17:00)
This panel discussion was a conversational session focused on career advice and personal experiences, rather than a technical presentation. As such, there was no live demonstration or proof of concept presented by any of the panelists. The format was entirely Q&A and shared insights.
Defensive Implications
▶ Watch: Discussion on SEC rule changes and the CISO role on the board, addressing hig... (42:00)
While this panel focused on career navigation rather than specific technical vulnerabilities, the insights shared have significant "defensive implications" for individuals and organizations looking to build resilient security teams and careers. These implications can be framed as proactive strategies for career development and organizational security posture.
For Individuals (Career Defense):
- Strategic Pivoting: Recognize that career growth is non-linear. Be open to intentional pivots across security domains (e.g., GRC to offensive security, web security to privacy) or between IC and management roles. This adaptability is a defense against stagnation and ensures continuous skill development.
- Cultivate Soft Skills: Prioritize developing strong communication, influence, and persuasion skills. These are critical for securing buy-in for security initiatives, managing teams, and navigating complex organizational dynamics. Understanding your audience's value system and tailoring your message is a powerful tool for advocacy.
- Develop Business Acumen: Understand your organization's core business, read its 10K reports, and know its key business metrics. This allows security professionals to tie security initiatives directly to business value, making a stronger case for resources and prioritization. This is a defense against security being perceived as a cost center.
- Embrace Continuous Learning: The complexity and rapid evolution of the security space (e.g., cloud security, new privacy regulations) demand constant learning. Viewing this as an exciting challenge rather than a burden is crucial for long-term career viability.
- Build a Diverse Network: Engage with professionals across different industries and company types (tech, consulting, security vendors). This broadens perspectives, offers new opportunities, and provides insights into varied security challenges and solutions.
- Manage Stress and Context Switching: Develop coping mechanisms for high-stress situations (e.g., incident response) and hone the ability to context switch effectively. These are essential for senior roles that demand juggling multiple critical priorities.
For Organizations (Security Program Defense):
- Foster Internal Mobility: Make it easier for employees to pivot internally. This leverages existing institutional knowledge, reduces hiring costs, and provides growth opportunities that retain talent.
- Support Diverse Career Paths: Create clear growth paths for both senior individual contributors (e.g., principal, distinguished engineer) and managers. This acknowledges different strengths and motivations, preventing talent loss due to a perceived lack of advancement options outside of management.
- Invest in Leadership Training: Train managers to effectively coach their teams, including the ability to "let people fail" in a controlled manner, fostering learning and resilience. This builds stronger, more autonomous teams.
- Improve Security Communication: Implement processes for clear, audience-tailored communication of security risks and initiatives, especially to executive leadership and the board. This ensures that critical vulnerabilities are understood and prioritized, and that security investments are justified.
- Establish Robust Processes for Critical Incidents: Ensure clear roles, responsibilities, and escalation paths for critical vulnerabilities or incidents, especially outside of business hours. This prevents confusion and ensures rapid response, rather than relying on individual "convincing."
- Measure and Communicate Impact: Develop and utilize meaningful security metrics (incident health, product security integration, compliance) that resonate with business objectives. This demonstrates the value of security investments and helps prioritize future efforts.
- Promote a Culture of Risk-Taking and Learning: Normalize the idea that "taking risks and having a little failure is okay" within a framework of retractable decisions. This encourages innovation and problem-solving without fear of catastrophic repercussions.
By applying these "defensive implications," both individuals can build robust, adaptable careers, and organizations can cultivate more effective, resilient, and strategically aligned security programs.
Key Takeaways
- Career paths in security are non-linear and require intentional pivoting. Professionals should be prepared to shift between technical domains (e.g., GRC to offensive security, web security to privacy), and between individual contributor and management roles, often driven by evolving threat models or personal growth objectives.
- Soft skills are as critical as technical expertise for advancement. Effective communication, the ability to influence and persuade, understanding an audience's value system, and strong business acumen are essential for securing buy-in, leading teams, and navigating complex organizational structures.
- Both Individual Contributor (IC) and management tracks offer significant growth opportunities. Senior IC roles (e.g., Principal Engineer) provide diverse impact through deep technical problem-solving, product strategy, and cross-functional leadership, while management focuses on team building and enabling others' success.
- Working for different company types provides unique experiences and skill development. In-house security teams focus on defending a specific company, while security vendors concentrate on solving problems for many customers. Consulting offers broad industry exposure, high-stress management experience, and rapid skill acquisition, albeit sometimes at a personal cost.
- The CISO role is not the sole "pinnacle" of a security career. Panelists emphasized that career fulfillment and success are best measured by the positive impact one makes on the world, continuous personal growth, and the ability to drive change, rather than by a specific title or position.
- Effective security leadership requires a blend of technical depth, business understanding, and people skills. Leaders must be able to communicate complex risks to executives, motivate technical teams, manage diverse priorities through context switching, and foster a culture of learning and resilience.
About the Speaker(s)
Nicole (Moderator): Currently leads platform and application security at ROBLOX, focusing on proactive security. Her entry into security was accidental, stemming from her experience as a full-stack software engineer at Yahoo during a state-sponsored attack on identity systems.
Caroline Wong: Serves as the Chief Strategy Officer at Cobalt, an offensive security company. She began her security career in GRC at eBay, where she was responsible for information security policy and PCI compliance. She later wrote the first information security policy for Zinga to help take the company public. Her career also includes management consulting at Sigal, particularly as a Bim practice lead, before joining Cobalt. She studied Electrical Engineering and Computer Sciences at UC Berkeley and is the author of "Security Metrics: A Beginner's Guide."
Swati Joshi: Is the VP of SAS Cloud Security at Oracle, overseeing the security of Oracle applications in the cloud. Prior to Oracle, she led the detection and response team at Netflix and was an incident response consultant with Mandiant. Swati made an intentional switch to security after graduating with a Bachelor's in Computer Science and working as a Java developer, pursuing a master's in security at an NSA-accredited university.
Anna Bellus: Leads security at Netflix. She is self-taught, having started by tinkering with computers as a child. Her diverse experience spans offensive security, network security, product security, application security, and distributed botnet detection.
Thuny: A Principal Engineer at Google, focusing on privacy, security, and policy in search. She studied mathematics in undergrad, where she discovered cryptography, leading her to a master's program in math and computer science. Her career began on the Paranoids team at Yahoo working on web application security. She then moved to Mozilla to secure the web platform, where she pivoted to privacy and co-founded the W3C Privacy Community Group to develop privacy-preserving APIs for the web.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
This panel discusses career paths in security, including pivots between individual contributor and management roles, and different industry contexts. While the speakers are experienced leaders, the content lacks technical depth or novel research, focusing instead on soft skills and career navigation. It's an 'awareness' session for career development, not a deep dive into security vulnerabilities, defensive innovations, or offensive techniques.
Heather Calloway (CISO) — MUST SEE
This panel provides valuable insights into navigating security careers, from individual contributor roles to executive leadership. The discussion on strategic pivots, the challenges of management, and the critical soft skills required for senior roles offers actionable guidance for security professionals and leaders. The panel also touches on the evolving role of the CISO and the implications of SEC regulations, directly addressing key governance and accountability concerns.