Pushing Boundaries: Journeys to the top of Security...
Lea Snyder, Devina Dhawan (Staff Security Engineer)
BSidesSF 2024 · Day 1
Overview
This talk, "Pushing Boundaries: Journeys to the top of Security...", delivered by Lea Snyder and Devina Dhawan at BSidesSF 2024, offers a candid and insightful exploration into the career paths of women in cybersecurity, particularly focusing on the challenges and strategies for reaching senior individual contributor (IC) roles. The speakers, both accomplished security engineers, share their personal experiences, highlight systemic issues, and provide actionable advice for navigating the complex landscape of a security career. The presentation delves into critical topics such as the retention crisis for women in technology, the distinction between mentorship and sponsorship, the importance of leadership skills in technical roles, and the necessity of building community to combat isolation.

Key moments
- 09:50 Deep technical skills, breadth, and leadership for IC ladder
- 11:50 Security's responsibility for 'rogue AI' and network shutdown
- 14:50 Eradicating two largest vulnerabilities through deep data dive
- 16:00 Challenging HashiCorp Vault implementation in Terraform
- 19:00 Failure of Octa OAG implementation due to lack of automation
- 26:00 Overview of the Individual Contributor (IC) career ladder
- 38:00 Taking on cloud security project with minimal prior experience
- 41:00 Recommendation of OWASP Juice Shop for CTF practice
Pushing Boundaries: Journeys to the top of Security...
Speakers: Lea Snyder, Devina Dhawan
Conference: BSidesSF 2024
YouTube: https://www.youtube.com/watch?v=RIjV3ifaxRc
Overview
This talk, "Pushing Boundaries: Journeys to the top of Security...", delivered by Lea Snyder and Devina Dhawan at BSidesSF 2024, offers a candid and insightful exploration into the career paths of women in cybersecurity, particularly focusing on the challenges and strategies for reaching senior individual contributor (IC) roles. The speakers, both accomplished security engineers, share their personal experiences, highlight systemic issues, and provide actionable advice for navigating the complex landscape of a security career. The presentation delves into critical topics such as the retention crisis for women in technology, the distinction between mentorship and sponsorship, the importance of leadership skills in technical roles, and the necessity of building community to combat isolation.
Lea Snyder, a Principal Security Engineer at Microsoft, and Devina Dhawan, a Staff Security Engineer and founder of Davy Labs, bring diverse backgrounds and perspectives to the stage. Their discussion is not merely a recounting of their professional journeys but a broader commentary on the state of diversity and inclusion in the cybersecurity industry. They emphasize that while pipeline issues (getting women into computer science) are often discussed, the more pressing concern is retention – ensuring women stay and thrive in their careers, especially as they advance to higher levels. The talk is particularly relevant given the high demand for senior security professionals and the observed drop-off of women in these advanced roles, making their insights invaluable for both aspiring and established security practitioners, as well as organizations committed to fostering a more inclusive and equitable tech environment.
Background
▶ Watch: Deep technical skills, breadth, and leadership for IC ladder (09:50)
The foundation of this talk is built upon a critical observation: despite efforts to increase the pipeline of women into computer science and engineering, a significant challenge remains in retaining them, particularly as they advance in their careers. Devina Dhawan highlighted her personal experience, graduating in 2014 with a Computer Science degree where only 1.5% of her class were women. While this number had risen to 7% by 2022, it still represents a stark underrepresentation. This issue extends beyond academia into the professional world, where a staggering 57% of women in Technology, Media, and Telecommunications (TMT) anticipate leaving their jobs, often due to a lack of perceived support.
This retention problem leads to a severe lack of diversity in cybersecurity teams. Both speakers shared experiences of being the "only woman in the room" or one of very few, a sentiment echoed by many in the audience. This isolation contributes to feelings of loneliness and insecurity, even for highly competent individuals. Lea Snyder presented a LinkedIn statistic showing a 45% increase in demand for Principal Security Engineer jobs, yet juxtaposed this with data indicating a significant drop-off of women in higher-level roles after the age of 39. This suggests that while there's a clear demand for senior talent, women are disproportionately not reaching or staying in these positions.
The speakers' own journeys exemplify both the challenges and the unconventional paths to success. Devina, despite her formal computer science education, spent eight years as the sole female on her security teams until joining Shopify. This experience underscored the need for proactive community building. Lea, on the other hand, came from an entirely self-taught background in tech, holding degrees in Economics and an MBA, and transitioning from traditional IT roles (help desk, desktop engineering, SRE) into application security without a formal coding background. Her pivot into security was driven by a desire to find a field with more women, a testament to the isolating environments often found in highly technical domains. Their diverse backgrounds highlight that there isn't one single path to a senior security role, but both encountered similar systemic barriers and personal struggles related to gender representation and career progression.
Key Findings
▶ Watch: Eradicating two largest vulnerabilities through deep data dive (14:50)
The talk unveiled several key findings and insights crucial for understanding and navigating a career in cybersecurity, particularly for women and gender non-conforming individuals:
- Retention is Paramount: While pipeline issues are often discussed, the more critical challenge is retaining women in technology and cybersecurity roles. Many women leave due to a lack of support, leading to a significant drop-off at higher career levels.
- Leadership Skills are Essential for IC Growth: To climb the security engineering ladder, deep technical skills and breadth are necessary, but leadership skills are equally vital. These can be developed through various avenues like volunteering, leading projects, or even starting a non-profit, without necessarily transitioning into management.
- The Power of Impactful Projects: Taking on "scary" and challenging projects, even those outside one's immediate expertise, is a primary driver for career acceleration and promotion. These projects offer opportunities for significant learning and demonstrate high impact.
- Failure as a Learning Tool: Projects that don't go as planned are not true failures but invaluable learning experiences. They teach crucial lessons about self-reflection, project management, and the importance of timely escalation to leadership.
- IC vs. Management Path: There's a persistent push for women to move into management roles. However, the Individual Contributor (IC) path, particularly at staff and principal levels, allows for significant technical growth and leadership without direct reports, offering a powerful alternative.
- Sponsorship Outweighs Mentorship: A critical distinction was drawn between mentorship (guidance and support) and sponsorship (active advocacy for promotions, raises, and opportunities). Women are often "over mentored and undersponsored," highlighting the need to cultivate sponsors, especially managers, and actively advocate for one's achievements.
- Community Building is Crucial: To combat the pervasive loneliness and isolation experienced by many women in tech, actively building and participating in communities (e.g., internal women in tech groups, external organizations) is essential for support, networking, and shared growth.
- Embrace Discomfort and Self-Advocacy: Both speakers emphasized the importance of signing up for projects and applying for jobs that are outside one's comfort zone, viewing them as opportunities for paid education and growth. This requires adopting a mindset of self-belief and not self-selecting out of opportunities.
- Responsible AI is a Security Mandate: The rise of AI presents both opportunities and significant security responsibilities. Security professionals must learn about AI, advocate for its responsible use, and prepare to be the "call of action" for potential rogue AI scenarios.
Technical Deep Dive
▶ Watch: Failure of Octa OAG implementation due to lack of automation (19:00)
The talk, while heavily focused on career development and personal journeys, provided several concrete examples of technical work and concepts that underscore the speakers' expertise and the nature of senior security engineering roles.
Devina Dhawan recounted a particularly challenging and impactful project involving the implementation of Vault Secrets Management by HashiCorp. She described it as "so hard man," highlighting the complexity of deploying such a critical tool in a production environment. Her task involved doing "everything in Terraform in such a production-ready way," a testament to the infrastructure-as-code paradigm prevalent in modern cloud environments. The project was further complicated by being a remote employee pre-pandemic, with infrastructure changes happening via "hallway conversations" at headquarters. Despite these hurdles, Devina successfully created a robust Vault system that could be handed over to another team for ongoing management after a single one-hour meeting. This project, which she undertook as a senior engineer, directly led to her promotion to security architect within a year and a half, demonstrating the profound impact of tackling complex, high-stakes technical challenges.
Lea Snyder shared her experience leading a large program at a former company focused on vulnerability eradication. She spent three months conducting a deep dive into data to understand why certain vulnerabilities were recurring. The core of the program involved root cause analysis, working directly with engineers to dissect and eliminate these persistent issues. This initiative successfully eradicated two of the largest vulnerabilities the company was facing within months, significantly easing the burden on developers. This project highlights the strategic and analytical aspects of a principal security engineer role, moving beyond individual vulnerability fixes to systemic problem-solving.
Both speakers touched upon the evolving nature of security domains. Lea's first security job was in application security (AppSec), despite her self-admitted lack of traditional coding background, showcasing that a strong technical aptitude and willingness to learn can bridge domain gaps. Devina's experience at Etsy involved becoming the de facto expert in cloud security with minimal prior experience (having only set up "one EC2 instance"). She quickly grasped and introduced cloud concepts to the company, eventually leading discussions on their migration to the cloud, demonstrating the rapid learning and adaptability required in the field.
The discussion also illuminated the Individual Contributor (IC) ladder in engineering, outlining typical progression from Junior Engineer to Engineer, Senior Engineer, and then diverging into Security Architect or Staff Engineer, eventually leading to Senior Staff and Principal roles. A key technical insight here is how the "scope changes" as one ascends this ladder. Lea, as a Principal Security Engineer, now focuses on "strategic work" across "all the security domains" of her team, including AppSec, incident response, GRC, detections, and threat. This contrasts with earlier career stages that might be "super hyperfocused on one thing," illustrating the need for broad technical understanding and the ability to connect disparate security functions at senior levels. Devina similarly described her staff engineer role as involving "creating design and infrastructure for the rest of the company to be on the same page when it comes to your security concept," which requires a blend of technical depth, architectural vision, and persuasive communication.
Finally, the speakers briefly touched upon the technical implications of Artificial Intelligence (AI). While acknowledging its potential for good (e.g., in education, as seen with Khan Academy), they stressed the critical role of security professionals in ensuring responsible AI development. They foresee a future where security teams will be the "call of action" for "rogue AI," needing to "turn the networks off" and mitigate large-scale issues, akin to past challenges with cloud systems. This underscores a future technical responsibility for security practitioners to understand and secure AI systems. For new graduates, Devina recommended exploring OWASP Juice Shop for practical, low-stakes capture-the-flag exercises, and for mid-career professionals, she suggested reviewing the CISSP (Certified Information Systems Security Professional) curriculum by ISC2 to understand the broad domains of security and identify areas of interest for transition.
Demo / Proof of Concept
▶ Watch: Overview of the Individual Contributor (IC) career ladder (26:00)
The conference talk "Pushing Boundaries: Journeys to the top of Security..." was primarily a discussion-based presentation focused on career development, personal experiences, and strategic advice for women and gender non-conforming individuals in cybersecurity. As such, it did not include a live technical demonstration or a proof of concept of any specific tool, vulnerability, or system. The speakers shared anecdotes and project examples, such as Devina's implementation of HashiCorp Vault and Lea's vulnerability eradication program, but these were described verbally rather than demonstrated visually or interactively.
Defensive Implications
▶ Watch: Recommendation of OWASP Juice Shop for CTF practice (41:00)
The insights shared by Lea Snyder and Devina Dhawan carry significant defensive implications for both organizations and individual security professionals aiming to build more resilient teams and secure systems.
For Organizations:
- Prioritize Retention and Support: Organizations must shift focus from solely pipeline issues to actively retaining women and gender non-conforming individuals in cybersecurity. This means providing robust support systems for significant life changes (e.g., maternity leave, family care) and fostering an inclusive culture that combats feelings of loneliness and isolation. The statistic that 57% of women in TMT anticipate leaving their jobs is a critical call to action for HR and leadership.
- Cultivate Diverse Teams: The pervasive issue of women being the "only one in the room" highlights a lack of diverse perspectives. Organizations should actively work to increase representation, as diverse teams bring varied mindsets, leading to more comprehensive security strategies and better problem-solving, as exemplified by the different perspectives a marketing person might bring to password management compared to an IT professional.
- Recognize and Reward IC Leadership: The tendency to push high-performing women into management roles can deplete the pool of senior technical talent. Organizations should clearly define and value the Individual Contributor (IC) ladder, providing opportunities for leadership development within technical roles. This allows individuals to drive strategic impact and mentor others without taking on direct reports, thereby retaining deep technical expertise.
- Implement Sponsorship Programs: Moving beyond traditional mentorship, organizations should actively foster sponsorship. Managers, in particular, should be trained and encouraged to act as sponsors for their team members, advocating for promotions, raises, and high-impact projects. This requires a cultural shift where managers actively champion their team's achievements.
- Invest in Challenging Growth Opportunities: Encourage and support employees, especially those from underrepresented groups, to take on "scary" projects that push their boundaries. These projects, like Devina's Vault implementation or Lea's vulnerability eradication program, are crucial for accelerated learning, skill development, and career advancement, ultimately leading to more capable security teams.
- Foster a Culture of Learning from Failure: Create an environment where project "failures" are viewed as learning opportunities rather than setbacks. This encourages experimentation, innovation, and open communication, including timely escalation of issues, which is vital for adapting to the rapidly changing threat landscape.
- Prepare for AI Security: Organizations must recognize that AI security will become a core defensive responsibility. This involves investing in training for security teams on AI systems, advocating for responsible AI development within the organization, and preparing incident response plans for potential "rogue AI" scenarios.
For Individual Security Professionals (especially women/GNC):
- Actively Seek Sponsorship: Understand that your manager is your primary sponsor. Proactively document your achievements, contributions, and impact, and regularly discuss these in one-on-one meetings to ensure your manager can effectively advocate for your career progression.
- Develop Leadership Skills in IC Roles: Don't wait for a management title to lead. Volunteer for conference roles, take ownership of projects, initiate internal communities, or even start a non-profit. These activities build crucial leadership, communication, and organizational skills that are essential for senior IC positions.
- Embrace Discomfort and Stretch Assignments: Actively seek out projects and roles that are outside your comfort zone or for which you don't feel 100% qualified. This "paid education" approach, as described by Lea, is a powerful way to accelerate learning and demonstrate adaptability, making you a more versatile and valuable defender.
- Build and Leverage Community: Combat isolation by actively participating in or creating internal and external communities (e.g., women in tech ERGs, security collectives). These networks provide support, mentorship, and opportunities for shared learning and public speaking, fostering collective growth.
- Become AI Literate: Proactively learn about Artificial Intelligence, its underlying technologies, and its security implications. This will position you as a critical resource for your organization as AI adoption grows, enabling you to contribute to securing these new frontiers.
- Continuous Self-Advocacy: Do not self-select out of opportunities. Apply for jobs that excite you, even if you only meet a portion of the qualifications. Be confident in your abilities and potential for growth, mirroring the approach often taken by male counterparts.
- Strategic Career Planning: For new graduates, engage with practical tools like OWASP Juice Shop and participate in CTFs or bug bounties to gain hands-on experience. For mid-career professionals looking to transition into security, explore resources like the CISSP curriculum to understand the breadth of security domains and identify areas where existing technical skills can be leveraged.
By implementing these defensive implications, organizations can build stronger, more diverse, and more adaptable security teams, while individuals can strategically navigate their careers to achieve senior technical leadership roles and contribute more effectively to the overall security posture.
Key Takeaways
- Retention is as Critical as Pipeline: The cybersecurity industry must prioritize retaining women and gender non-conforming individuals, as many feel isolated and unsupported, leading to a significant drop-off in senior roles despite increasing demand.
- Leadership is for ICs Too: Advancing in individual contributor (IC) security roles requires strong leadership skills—such as project ownership, mentoring, and community building—which are distinct from, but as important as, deep technical expertise.
- Sponsorship Drives Advancement: Active sponsorship, where managers and senior colleagues advocate for promotions, raises, and high-impact projects, is more crucial for career progression than traditional mentorship, which often focuses on guidance without direct advocacy.
- Embrace Challenging Projects for Growth: Taking on "scary" or unfamiliar projects, even when not fully qualified, serves as a powerful catalyst for technical learning, skill development, and career acceleration, leading to significant impact and promotions.
- Community Combats Isolation: Building and actively participating in internal and external communities (e.g., women in tech groups, professional networks) is essential for combating loneliness, fostering support, and creating opportunities for shared growth and skill development.
- Security Professionals Must Lead on Responsible AI: As AI rapidly evolves, security professionals have a critical responsibility to understand its implications, advocate for responsible development, and prepare to be the frontline responders for potential AI-related security incidents.
About the Speaker(s)
Lea Snyder is a Principal Security Engineer at Microsoft, where she works within the Intra organization, focusing on identity and network access. Her career path is notably unconventional, having earned a degree in Economics and an MBA, and being entirely self-taught in technology. She began her tech journey in traditional IT roles, including help desk, desktop engineering, and Site Reliability Engineering (SRE), before transitioning into security. Her first security role was in application security, despite not considering herself a traditional coder. Lea has been recognized for her unique journey, having been interviewed by tldr sec and featured on the BlueHat podcast, an MSRC podcast, where she shared more about her background and experiences.
Devina Dhawan is a Staff Security Engineer based in Chicago, Illinois. She has a rich background working at prominent technology companies such as Etsy, Shopify, and Hulu, contributing to security aspects that impact a vast number of internet users. Devina is also the founder and CEO of Davy Labs, a non-profit organization dedicated to teaching women and gender non-conforming individuals how to code. She holds a degree in Computer Science with a minor in Math, graduating in 2014. Devina is a published author, having contributed a chapter to "The Security Path," a book featuring diverse career journeys in security, and has also been interviewed by tldr sec about her professional experiences and advice. She is passionate about mentoring and actively encourages others to connect with her on LinkedIn for career guidance.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
This talk, while not a deep technical dive into a zero-day, provides valuable insights into the career progression of senior Individual Contributors in security. The speakers share their personal journeys, highlighting the importance of deep technical skills, breadth, and leadership, alongside practical examples of impactful projects like HashiCorp Vault implementation and large-scale vulnerability eradication. They also offer candid advice on navigating challenges like being pushed into management and the critical distinction between mentorship and sponsorship.
Heather Calloway (CISO) — STRONG ACCEPT
This session effectively highlights critical talent pipeline and retention issues within the cybersecurity industry, particularly concerning women in senior Individual Contributor roles. The speakers provide valuable insights into the necessary blend of deep technical skills, broad understanding, and leadership capabilities required for advancement, illustrated through concrete project examples. Their candid discussion on the distinction between mentorship and sponsorship, and the institutional failures that lead to "over-mentored and under-sponsored" talent, offers a clear call to action for security leaders to re-evaluate their talent development strategies.