--- title: "Derek Fisher -- Hiring in Cyber/AppSec" url: https://appsecpodcast.com/derek-fisher-hiring-in-cyber-appsec/ date: 2024-07-16 duration_seconds: 3705 season: 11 episode: 18 guests: ["Derek Fisher"] topics: ["Careers in AppSec"] audio: https://www.buzzsprout.com/1730684/episodes/15421342-derek-fisher-hiring-in-cyber-appsec.mp3 video: https://www.youtube.com/watch?v=ifc5CMNLajM transcript: true --- # Derek Fisher -- Hiring in Cyber/AppSec *July 16, 2024 · 1 hr 2 min · Season 11, episode 18* with [Derek Fisher](https://appsecpodcast.com/guests/derek-fisher/) on [Careers in AppSec](https://appsecpodcast.com/topics/careers/) [Audio](https://www.buzzsprout.com/1730684/episodes/15421342-derek-fisher-hiring-in-cyber-appsec.mp3) · [Video](https://www.youtube.com/watch?v=ifc5CMNLajM) ## Show notes Derek Fisher, an expert in hardware, software, and cybersecurity with over 25 years of experience is back on the podcast. Derek shares his advice on cybersecurity hiring, specifically in application security, and dives into the challenges of entry-level roles in the industry. We discuss the value of certifications, the necessity of lifelong learning, and the importance of networking. Listen along for good advice on getting noticed in cybersecurity, resume tips, and the evolving landscape of AppSec careers. Mentioned in this episode: The Application Security Handbook by Derek Fisher Derek Fisher brings over 25 years of hardware, software, and cybersecurity expertise across multiple industries, including healthcare and finance. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey We provide application security training for not just your developers, but for all roles in your SDLC. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Derek Fisher: → [The Application Security Handbook by Derek Fisher](https://www.manning.com/books/application-security-program-handbook) → [Cyber for Builders by Ross Haleliuk](https://ventureinsecurity.net/p/cyber-for-builders) Mentioned in this episode: → [The Application Security Handbook by Derek Fisher](https://www.manning.com/books/application-security-program-handbook) → [Cyber for Builders by Ross Haleliuk](https://ventureinsecurity.net/p/cyber-for-builders) → [Effective Vulnerability Management by Chris Hughes](https://www.wiley.com/en-us/Effective+Vulnerability+Management%3A+Managing+Risk+in+the+Vulnerable+Digital+Ecosystem-p-9781394221219) → [With the Old Breed by E.B. Sledge](https://www.penguinrandomhouse.com/books/168399/with-the-old-breed-by-e-b-sledge/) → [Derek Fisher – The Application Security Handbook](https://youtu.be/DgmlHgNT-UM?list=PLFa4WU2IyiNrIRr84JpYFH4FL45ZFUMnv) → [WiCyS (Women in Cybersecurity)](https://www.wicys.org/) → [CISSP](https://www.isc2.org/certifications/cissp) → [BSides](https://bsides.org/) Chapters: 00:00 Meet Derek Fisher: Hiring in Cyber/AppSec 01:35 Yeah, we're joined by someone who's been on the podcast before 03:48 What's your favorite thing to grow 06:21 It's the, as you said, it's the therapeutic value of getting 11:05 Which to your point, mid to senior level people are 100% 13:15 With that in mind, I mean, how are people getting into 17:32 I mean, if anything, it's the patterns, kind of the try 20:03 Reminds me of something about Billy the Kid. Like, do you 21:58 You mentioned resume reviews. I'm always curious. I've never participated in 26:18 The last, you know, 5, 7 years, all the hiring I've 33:16 I would say, you know, that's one way to stand out 35:43 One of the we got to blame the hiring companies though 37:00 You can apply something, yourself to something. And so that, I 39:57 That, that I look back and say, I didn't necessarily use 47:59 By doing a pen testing class and doing a forensics class 52:17 All right. So yeah, 3 questions that we have. First of 55:34 Makes sense. So number 3, what's your Top book recommendation and 57:24 Yeah, he just wrote a new book on, yeah, it's the 58:49 Excellent. Derek, what about a key takeaway or a call to ## Transcript *11,058 words · assemblyai* **0:00 Chris Romeo:** Derek Fisher brings over 25 years of hardware, software, and cybersecurity expertise across multiple industries, including healthcare and finance. As an accomplished leader and educator, Derek has used his experience to help business partners defend software from malicious activity. His expertise encompasses cybersecurity strategy, risk management, and compliance. It has helped him lead incident response efforts while directing high-performing cybersecurity teams. and effectively communicating technical concepts to diverse audiences, including executive leadership and board members. Derek joins us to discuss hiring in cyber, more specifically in application security. We also cover what it takes to be noticed and to get a job, resume reviews, and the challenge of no entry-level application security roles. The Application Security Podcast is brought to you by Security Journey. We provide application security training for not just your developers, but for all roles in your SDLC. Learn more at securityjourney.com. Hey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo. I'm the CEO of DaVinci, also a general partner at Curve Ventures. And an AppSec aficionado. Joined as always by my good friend Robert. Hey, Robert. **1:25 Robert Hurlbut:** Hey, Chris. Yeah, Robert Hurlbut. I'm a principal application security architect and threat modeling lead at Acquia. And always, as always, glad to be here. **1:34 Chris Romeo:** Yeah, we're joined by someone who's been on the podcast before, Derek Fisher. Derek joined us first time in March 2023. when he was on the circuit, I guess, talking about his book, The Application Security Handbook, which is still part of my recommended reading list. So Derek, it's great to have you back again with us on the show. And because we've already heard your security origin story, we're going to go to our kind of our, our decision tree. We're going to go down the other path in the decision tree. And I'm going to ask you, what do you like to do that gets you away from computers and technology? **2:14 Derek Fisher:** Thanks for having me back on. I really appreciate it. Yeah. So for me, I, I do some gardening and in fact, usually my previous house, I had a, like a nice in-ground garden. I wasn't doing it for sustenance. It was more just therapeutic getting out there, weeding, seeing things grow. That was always cool. And the house I just recently moved into, there's some space for me to put one in ground, but it's not ideal. So I had to do kind of the raised beds on the deck. And so, you know, it's still, again, it's not quite the same thing, but it's getting out there and being able to check on the progress of how things are growing and how they're doing. It's always, you know, again, kind of therapeutic. I do run, I get outside. Try to get out for runs a couple times a week. I just did a trail run in Vermont about 2 weeks ago or 2 or 3 weeks ago. It was a 10-mile through the woods and it was, you know, a lot of fun. You know, it's, I'm getting older, so it hurts a little more and I'm not as fast as I probably should be, but it's still, it's good to just be able to get out and just see, you know, nature. So. That gets me away from the desk. But of course, as soon as I'm done, I, you know, I'm right back at my desk. So, but at least, at least I carve out that time to get out and, and do something different. So. **3:46 Robert Hurlbut:** Yeah. **3:47 Chris Romeo:** So what's your favorite thing to grow? **3:49 Derek Fisher:** Tomatoes are always an easy one to do. Squash is, is usually pretty easy. Strawberries are, are fun, but I don't have enough plants to really make a, a big difference. Like I might get a couple strawberries a day, which isn't, awful. But usually tomatoes, squash, peppers, hot peppers. Actually, lettuce is pretty easy too. Like any kind of leaf, you know, salad-type lettuce, that's pretty easy. Some things can be picky, you know, finicky and easy to kill. So, I try to avoid those things. So, I tried to grow corn once and that actually, you know, it, we ate it and then it was, it It was okay. It didn't look anything like the stuff you would get at the store, but it was edible. So. **4:34 Chris Romeo:** Yeah, that's a great hobby though. It's something I'm getting into now as well. And I've done a little bit of gardening as well kind of throughout my life. And I love to grow tomatoes. My favorite story growing tomatoes though is I got a whole bunch of good dirt, put it on the side of our house, like really rich, not the red clay we're known for here in North Carolina, but the the really good black dirt that's got all those nutrients in it. And I didn't know how to plant. So it turns out I double planted from existing plants that I got at the store and they grew like crazy. And so I had like every day I had like multiple beautiful tomatoes that were ripe all throughout the summer. You could go out and pick 2 or 3 a day. **5:17 Derek Fisher:** Right. **5:17 Chris Romeo:** I'm like, and I thought I might've over— and apparently overplanting just happened to work for me. It didn't, They didn't fight for resources or anything. So I was, uh, but that's a great, I just, I enjoy the same thing that you're describing. Yeah. There's something therapeutic about like going outside, digging in the dirt, doing, just caring for things like that is, is just, I don't know. It's, it's different than what we do all day long to be able to like not be looking at a screen is such a great thing. **5:45 Derek Fisher:** I think it's good to just get some dirt on your hands and do something manual, you know, uh, feel like you're doing, you know, something beneficial there. So, but I always like the joke I've always heard was that, you know, you spend, you know, whatever, hundreds of dollars on, you know, building this garden to save yourself 50 cents at the, you know, the grocery store. It's like, look, I grew, I grew a tomato and it only cost me, you know, $100 or something, you know, for the, between the dirt and the, and the raised bed and the water. And you're, so you could have just went down to the grocery store and got one for you know, a dollar or something like that. But, you know, it's, that's not the point. So, yeah. **6:21 Chris Romeo:** It's the, as you said, it's the therapeutic value of getting outside and getting some fresh air and moving around. So, and not just sitting still, you know, like we do often too much in our day-to-day jobs. So I think the first place we want to go here, and there's a couple different threads in our conversation that we're going to, we're going to go after here. But I'm curious to get your take as a place to start on reasons why we can't fill the cybersecurity jobs that are out there. And I just want to preface this and get your take on this as well. It seems like there's 2 schools of thought in cybersecurity. There are those that say we have a 2 to 5 to 100 million, okay, I'm exaggerating, 2 to 5 million job deficiency. We just don't have the people to do this. And then there's this faction now on the other side of the equation saying, we got plenty of jobs. There's not, you know, we have plenty of people. That's not the problem. And so now we've got this tension and it's like, now who do we believe? Do we believe that there's a giant deficiency or do we believe that there isn't one? So let's start there. Like, what's your take on that as you look across our industry? **7:33 Derek Fisher:** Yeah. And I, you know, I think it's like, most things that are, I don't wanna say controversial, but where people have opinions, strong opinions, you can almost always find statistics or numbers that are gonna back up that opinion. And, you know, I, before, before the podcast, I was searching around for some statistics on this and where kind of the industry is, you know, and the US Labor Department says that there's gonna be, you know, 200,000 job openings, unfillable job openings in cybersecurity over the next, you know, 5, 10 years or something like that. And I know we've also heard those numbers of, you know, a million or 2 million, you know, open positions. And, you know, I think it really, again, it depends. I think you're going to be able to find metrics and numbers that are going to back up your opinion or your theory on this. And at the same time, there's 100%, uh, employment, meaning that there's people. And again, this was one of the statistics that I found where it said 100% employment, meaning that there are no, you know, anybody that wants to find it, anybody that, uh, that there, there's no unfilled roles, right? Or I'm sorry, that there's no roles that, um, that there aren't, aren't people for, right? Um, and so, but when you get out there and you talk to people, in this industry or trying to get into this industry, you'd see firsthand that it's not like that. I mean, there are a lot of people that are trying to get into these roles. I was at WiCyS back in May in Nashville, the Women in Cybersecurity Conference, and was— I volunteered there past 2 years and was doing resume reviews and just talking to people that were coming in and getting their experience on trying to find a job. And a lot of them have been just applying to a lot of positions and they think there's something wrong with their resume and they think there's something wrong with them because they keep hearing that there's tons of jobs out there, but they can't get in. Same thing, I was at SecureWorld here in Philadelphia, shortly after WSIS and was on a panel there talking about, talking about, you know, this, this exact topic and, and, you know, just hearing from some of the audience members about their experience as well. I mean, people that were, that have been in the industry and are still, and are still struggling to find jobs, as well as the people that are, you know, entry-level trying to get in. It's like, okay, well, if we have you know, all these open positions that can't be filled, uh, you know, or there's not enough people to, to fill them. Something doesn't add up, you know? And, and, um, yeah, it's definitely, uh, I was talking to somebody the other day about how, like, I, I don't envy people looking for work right now in cybersecurity, 'cause it's just, it's like, it's not, it's not an easy task. So. Yeah. **10:42 Chris Romeo:** And I think we need to, We need to stop talking about, or everybody across our industry, meaning all these people that write articles and do studies, they always come to a conclusion of like, there's this many deficient, this many open positions, but nobody ever breaks it down because a lot of those positions, if they are out there, are for mid to senior level people. **11:04 Derek Fisher:** Right. **11:04 Chris Romeo:** Which to your point, mid to senior level people are 100%. I'll even go further. Like, I can't think of anybody who doesn't have a job right now who wants one. in my network of people that I know. And I think you guys are probably, it seems like across our industry, but these are mid to senior level people. And so everybody always talks about, well, there's, you know, let's just say there's 500,000 unfilled positions. How many of those are mid to senior level though? **11:28 Derek Fisher:** Right. **11:28 Chris Romeo:** Because mid to senior level, we can't, the only way we can get more of those is we have to grow them. We can't just, you can't just say, poof, we now have more mid-level people that you have to take more entry-level people and you have to provide them a pathway to grow them, to mentor them so that they could become those mid to high-level roles. And I think that's part of the challenge in our industry right now is we just, we're so focused on mid to high level and we just don't focus enough on growing people up in our industry. **11:59 Derek Fisher:** And I'd also be curious about what those roles are. Um, are they in the information security space? Are they in GRC? Are they penetration testers? Are they SOC analysts? Are they AppSec people? You know, cloud security. I mean, they're, you know, that's the other question that I, that I get often is people say, I just want to get into cybersecurity. It's like, well, what, you know, it's cybersecurity is, it's like saying, I want to get into engineering. It's like, okay, where's your interest? You know, because there's a ton of different, you know, ways to be in engineering or be in cybersecurity. And so, you know, the, you don't often see that breakdown either of like the bulk of these roles that are going unfilled are in this, you know, category or this type of position. But I think you're absolutely right on in the sense that a lot of those roles are going to be, you know, or likely to be those mid to senior level positions that a lot of, and that kind of probably leads into what we'll talk about in a bit, but, you know, the need to get people that have a certain level of experience and knowledge and, you know, education and all that other stuff to fill in these roles. So. **13:15 Robert Hurlbut:** With that in mind, I mean, how are people getting into cyber and AppSec? And what are the earlier parts of their career path that maybe have led them to security? I know we, all have different stories of how we got here, but what are you seeing or what are your thoughts on that? **13:29 Derek Fisher:** You know, I think it, if you look at, I often try to look at parallel industries or parallel lines of work and same thing with software engineering. If you come out of college with a computer science degree, that doesn't necessarily guarantee you that you're going to turn around graduation day and have a job. Um, for some people that, that may work out that way. For some other people, it may not. You, you know, you may not get into a role right away. And I think that's another industry that's, you're seeing a lot of change in, uh, in, you know, software development, just the way that it's being done and, and the needs of the, uh, of, uh, those that are getting hired. So I think with, you know, cybersecurity, you have people that are coming out of out of, um, school, number one, there, it, there, now some colleges are changing this, but there is not a computer science security degree. You know, there's not a, there's not a security undergraduate degree. Um, there's programs that are integrated with computer science or with, you know, CIS or, or other types of technology degrees that kind of bolt on, you know, that security, like we're going to give you some, um, I teach at Temple University. The course I teach is software security. It is part, is an elective that is part of a, you know, a broader, uh, school. And so until we get to a point where, you know, security is a, you know, and I'm not advocating for this because that's, this is a whole nother topic, but. Until we get to a point where, you know, you're coming out of college with a cybersecurity degree, then, you know, even then you're still not guaranteed to get in, right? I think it comes down to having that experience and that experience can come in multiple, you know, multiple different ways. My way of getting into cybersecurity was I was a software engineer and then got into AppSec. You know, lot of other people, when you hear their origin story, it wasn't, I graduated college and landed a job as a security architect. It just doesn't happen, right? You know, you're working your way up usually as an analyst and then moving your way up the ranks, unless you come in from a different discipline that has some kind of technology background. So, you know, what I've been trying to talk to other people about in terms of getting into cybersecurity, it's take a job, right? Take, and I don't mean, I don't mean a job in security. I mean, if it's there, then take it, but take a help desk job, right? If you come out of, if you're coming out of school, uh, take a, take a help desk job, take some type of an IT, uh, position, or, you know, if you're getting into software engineering, if you're getting into network engineering, if you're getting the, you know, into any one of those parallel, um, uh, disciplines, you're going to get that background. You're going to be able to leverage your security knowledge that you, that you have to be able to build that and show in the company that you're in that, hey, you know, I do have this, uh, knowledge. And then that hopefully transfers, you know, into a full-time role. But I don't think anybody has like the blueprint. Right. I don't think any of us have like, here is your path to get into cyber. **17:03 Chris Romeo:** Guaranteed, the guaranteed path. **17:06 Derek Fisher:** Yeah. I mean, with, you know, again, I look at parallel, you know, types of disciplines, software engineering, there is kind of a blueprint for that, right? There's, you know, you, you, there's a blueprint for getting into a software engineering job. Um, you know, getting into an operational job, getting into IT, like it, it, there are kind of blueprints for that. that, that generally work. But they're— I'm not aware of one in security. So somebody can prove me wrong, but I'm not aware of one. **17:32 Chris Romeo:** I mean, if anything, it's the patterns, kind of the try to get to the SOC, right? And then if you can get— but that's like the help desk as well. But if you can get to the SOC, maybe you can then get to somewhere else in the cybersecurity department, because you'd be becoming a non-quantity. And it's funny, the example you shared, I had the same conversation with a A recent grad in just the last few months where I said the same thing. I said, just get in the door, outwork everybody around. Don't just go in and hang out and think this is a fun place to work. Get in the door doing whatever they'll let you in to do, whether it's help desk, whether it's IT, something IT related, whether it's working in the SOC as a level 1 analyst, you know, covering the, you know, 2 AM to 9 AM shift or whatever. But go in there, outwork everybody, and they will move you. You will, you will begin to make your way through the ranks. If you go in and just show up, then you're on your own. I can't help you if, if you're, if you're not motivated to, to be successful. But there is a pathway in. It's not as easy, no, as everybody, everybody seems to think. **18:41 Derek Fisher:** Yeah, there's not a, there's not a, you know, it's not pushing on an open door, right? It's, you, there's, You have to be creative, you have to be, um, ready to work and, and, and work hard and, and show that you, you know, you have the, the desire. I think, you know, a lot of security comes down to passion and desire. Like, you know, you have to want to do this. It's not, you know, it's not like something like, ah, I just wanna get into security because, you know, the money or it's cool or, or whatever the case is. Like, you have to, you have to kind of want to do this, you know, and, and it can't just be because you think this is where you want to be. **19:17 Chris Romeo:** Yeah. **19:17 Derek Fisher:** Um, which is, you know, oftentimes when I talk to people and they say, I just want to get into cyber, it's like, you know, that kind of, for me, that always puts the spidey sense up a little bit where it's like, okay, why? Like, what is your reason for getting into this? You know, is it because you've been coached, you know, by somebody that this is the way, the path to go? Um, you think there's, you know, glory and fame and all that stuff in it. Um, I don't know. But, you know, when somebody just says, there can be, you know, but, you know, it's, you know, it's again, the question of, I just want to get into cyber. It's like, okay, where's your interest? Why do you want to do this? You know, where do you need to answer those questions before you can really, you know, choose your, choose your adventure here? So. **20:03 Chris Romeo:** Reminds me of something about Billy the Kid. Like, do you want to be famous or do you want to be infamous? Yeah. **20:11 Derek Fisher:** Luckily you can do either one in security, right? You got— **20:14 Chris Romeo:** You can, you can. **20:15 Robert Hurlbut:** Yeah. **20:16 Chris Romeo:** And it's, I've had a, I had a similar conver— or I have a similar conversation path. My favorite question to ask people when they say, oh, I want to get into cyber. **20:24 Robert Hurlbut:** Oh yeah. **20:24 Chris Romeo:** Why, why do you want to do that? I've heard too many times, because you make a lot of money. I'm like, come on. Like you gotta, you have to, you have to think this through. Don't do anything because you make a lot of money because you will hate your life. The people that go to law school or they go to medical school because, well, these jobs make a lot of money. And then these are the stories you hear about somebody who spends one week working in the law and goes, I hate this. And then they owe $220 billion to some university somewhere because they ran up a bunch of debt to take on something that they don't even really love to do. And so that's why, that's my ultimate career counseling thing that I tell people is like, what do you, what do you, what would you do if money didn't matter? **21:12 Derek Fisher:** Right? **21:12 Chris Romeo:** Like what if you didn't, if you didn't need money, what would you do with your, your, your hours every day? What would you go do? And that's where you find your passion and that's where you start to unlock what you should be doing. Don't do anything for the money. Yes, we need money to eat. We need money to, to live in our society, 100%. But if you make your life plan based on something you think is going to make the most money, I hate to break it to you, but you're not going to be very happy. You're going to be part of the, you know, oh gosh, it's Monday. Thank you. It's Friday, right? **21:45 Derek Fisher:** Right. **21:45 Chris Romeo:** Like, that's going to be your mindset and it's just a terrible place to live. Like, life is way too interesting to be caught in something that you hate. **21:54 Derek Fisher:** Doing. So, yeah, absolutely. All right. **21:58 Chris Romeo:** You mentioned resume reviews. I'm always curious. I've never participated in a resume review, but I love to read resumes. I love to analyze them in the hiring process. And so what do you see? What have you had? What have you seen in these experiences from people of like, what are they doing wrong? How do you recommend they fix them? Like, give us some ideas about some of the stuff you see. **22:22 Derek Fisher:** I don't know. You know, and I mean, I was thinking about this recently. I don't know what the answer is here because there's— I see resumes that when these early entry-level people come up and they say, here's my, you know, here's my resume, tell me what's wrong with it. And I look at it and it's like, it's a template, you know, and It has all the things you would expect to see for an entry-level person. And it shows, you know, the, the cert, you know, certificates that you took, the, the projects that you worked on, what you did in school, maybe some, you know, volunteer work and things like that. I mean, and I'm talking about entry-level resumes. And in those cases, It's like, I don't know. Like, I don't know what the right answer is here because you have people that are trying to beat a system, right? They're trying because now you have these, you know, we, if you ever go out on LinkedIn, you see a job that just opened 2 hours ago and there's 400 applicants to it. You're like, what the hell? Like, there can't be, there's no way that there's that, you know? And it's always some kind of niche position. Not all, I'm making it up here, but I mean, that is actually the case. But I mean, it could be a niche position where you're like, there's no way there's 400 people in this area that's qualified for this role. So you have this on the one side, you have these positions that are opening up and they get flooded with applicants. And then on the other side, you have the applicants that are trying to not be weeded out by the automation. So the questions that I often get about the resumes are, I mean, I've had this question bluntly asked, how do I beat the automation with this resume? I don't know. If I, I don't know, if I knew that, I'd create a class for that because apparently that's what everyone's trying to do. Um, so, but oftentimes, you know, the advice that I do try to give people is you need to really Tell, and it's hard to do this on a resume, but you need to tell a story. And I'll never forget when I was at WESAS back in May, one of the women that sat down gave me her resume and she, you know, I said, okay, you know, as I'm looking through it, I said, you know, tell me who you are, tell me about your background. She had a phenomenal background and experience. And I mean, just listening to her talk was like, how could you possibly be struggling to get a job? Like, and I even told her, I said, I would like to work for you because what she had accomplished in her time and the different work that she had been involved in, Was just stunning to me, and and but at the same time, it's like that doesn't come across. You know, and I'm just I'm highlighting this because I think the hiring companies are really doing a disservice by not being able to really get to those people. But I get the pain of you open up a position and you're getting flooded with you know hundreds of applicants. It's like you can't possibly. Go through all those resumes and profiles. You have to add some type of automation to that. And so I see why we're in this arms race. But, you know, I bring up that example because it really shows how we're missing out on some extremely talented people who can't seem to get through, you know, those, those, you know, those The automated systems. Yeah. **26:17 Chris Romeo:** The last, you know, 5, 7 years, all the hiring I've done has been for my various startups. And so smaller scale, but I guess I still used a little bit of filtering though, even within the tools to try to find, try to help me, you know, if I had 20 resumes, I still read all 20 though, just because I like the, I like the personal touch of reading people's resumes and trying to see, is there something I see here that maybe they're just not great at communicating what they did, but there's some cool things I want to know more about? **26:52 Derek Fisher:** Right. **26:53 Chris Romeo:** I think the, you know, when I think about advice I've given people over the years about resumes, I think one of the most important things is please be truthful about the things that you've done. Don't lie because I'll sniff it out. Like, I'm a trained investigator. I spent a few years working with a bunch of ex-FBI people in a computer crime unit back in the late '90s. They taught us computer nerds how to investigate. And like, as soon as I get, as soon as I look at your resume, I'm asking questions. Sometimes I don't even know what the thing is, but I'm going to ask you a question about it because I want to know if it's real and what you, if you can explain it to me. **27:30 Derek Fisher:** Right. **27:31 Chris Romeo:** But, and I remember one, one time I caught somebody, this is a long time ago. Guy had everything on his resume. You can imagine it was a kitchen sink resume. Like, there's no way everybody knows all of these things. Like, so I just started asking him questions about it, about various things. And he just started to like stammer and not be able to get anything out. And like, this guy, it just filled out a resume with every buzzword that existed in the industry to try to get through. And so there's danger in trying to beat the system by modifying your resume for what you think this system wants if you can't back it up. **28:10 Derek Fisher:** Right. **28:10 Chris Romeo:** It's about backing it up. **28:12 Robert Hurlbut:** Yeah. Adding every keyword, everything that you could find just to make sure you get in front. But then if you can't, yeah, like you said, that's, that's not the way to do it necessarily. **28:23 Derek Fisher:** Yeah. **28:23 Robert Hurlbut:** It gets you to just so far. It gets you just so far. **28:26 Derek Fisher:** Right. **28:28 Chris Romeo:** Makes you realize we need a better system. **28:30 Robert Hurlbut:** Yeah. **28:30 Chris Romeo:** System that we have now is broken. That's what you just led me to, Derek. **28:34 Derek Fisher:** You know, and, and I mean, I, I think about this often, you know, because it's, I, I feel like, you know, for, for us that have been in this space for, for a while, you know, we, we, you know, and I, I've been a hiring manager. Um, I've gone through like resumes for positions and stuff like that. And, and, you know, of course doing the resume reviews and talking to, you know, students and trying to help them. And I, I think, I think we do kind of owe it to the ones coming in to help shepherd them into this, right? Because we do need help, right? We do need to get people, more people into this space. And so I do think about this problem often and it's broke. I hate to say it, but I think it's broke. I mean, just the fact that Once you get locked into one of the, you know, as I keep saying, the arms race, once you get locked into that, that's really hard to unravel because you're creating these learned behaviors on the applicant side saying, I have to try to write my resume. To your point, Chris, I have to write my resume, you know, with these words because that's what's going to get somebody's attention. And then hopefully, you know, they'll read my resume and then hopefully I'll get to an interview. Um, and then, you know, again, on the other side where it's just like, there's no way I can go through hundreds of, you know, resumes. I mean, as a hiring manager in an organization, HR, you know, there's so many levels of, of gates before it actually even gets to, you know, my desk where, you know, there's automation that cuts out, let's say, and I'm making these numbers up, but let's say it cuts out 80%, then it gets to, you know, HR and they cut out maybe you know, 80% of that and then you end up with 5 to 10 resumes on your desk, right? Well, what happens to the other, you know, 200 that didn't make it through? Um, yeah, I never see those. **30:31 Chris Romeo:** So, you know, I'll, I'll, I wanna put a plug in here just for folks listening that might be looking for a job. There's a lot of value in the referral network. **30:43 Robert Hurlbut:** Yeah. **30:43 Chris Romeo:** And so when I think about all the people I've hired in the last, 10 years, I don't know, maybe half of them were by way of referral from other people. **30:56 Derek Fisher:** Yeah. **30:56 Chris Romeo:** Other people that I trusted that sent me somebody and said, hey, you should take a look at this person. Either they weren't a good fit for what I was looking for, or there's somebody I know that I know from this meetup or whatever. And so I know going to these meetups and trying to be a part of the community can be a really difficult thing in the beginning. Because you don't know anybody and you're like, God, nobody wants to talk to me. But being in those communities, getting to know people is one of the ways you circumvent the auto parsing system of resume reviews that try to cut people out. Because if you have a connection to somebody, if you have a connection, like if you're trying to get a job in a company in the team that I'm running, if you know somebody who knows me and they put a word in. Now I can say as somebody on the other side of that, like I'm very careful with who I will vouch for. Like I don't vouch for people I don't know. And because my reputation is attached to the candidate. **31:53 Derek Fisher:** Exactly. **31:53 Chris Romeo:** But I've recommended people in the past as well. And so just a plug for, there is value in getting into the community, being a part of the community, getting to the meetups, being involved and just getting to know people. Because you never know how an opportunity may be presented and somebody may think of you because they know you. I know this person from this meetup that I see them, I see like them once a month. They're always really enthusiastic about this topic. We should talk to them about that. **32:23 Derek Fisher:** Right. **32:23 Chris Romeo:** That happens more than you would imagine. Just, it never gets publicized because everybody knows about the resume challenge of trying to get through the automated system. We don't talk very often about the referral and the connection networks. That, that open up a lot of doors for folks. **32:38 Derek Fisher:** Yeah, absolutely. I, I mean, I think, you know, it's building that network of people who then know people who then know people. You know, you're just, you're creating that, you know, uh, what is it, the 7 degrees of Kevin Bacon or whatever. **32:52 Chris Romeo:** Kevin Bacon. **32:53 Derek Fisher:** Yeah. So it's like, you know, when you have people that, like you said, can vouch for you or, you know, they know something's coming up and they just had a, you know, conversation with you or, or You know, those things, those things do matter. And I think that's a way to get around the automation, right? If you, if you know somebody that can, that can connect you to somebody, that, that's, yeah, that's, that's worth it. It's gold, you know, weight in gold. **33:16 Robert Hurlbut:** So I would say, you know, that's one way to stand out, I think, for a candidate, but are there some other ways for candidates to stand out? **33:25 Derek Fisher:** So I think I'll go down this, you know, the dirty certificate word here. Um, you know, certification, you know, I think when you see a lot of these entry-level positions that just have acronyms, acronym soup on it, you know, and, and for certifications. And to me, like, I, I often called, uh, and this is gonna sound really bad, but, you know, I often call BS on it cuz it's like, Okay. Um, if you don't have any experience, but you have 6 certifications, you know, in the past 6 months, like that's, you know, that's good for you. Um, but I don't, you know, I, I think it, I'm not poo-pooing certifications, right? I think, you know, they, they definitely show that you have some knowledge and, and, you know, basic understanding of, of the material that, you know, that the certification pertains to, but it doesn't prove that you have experience. And it often, I think many applicants feel like I just need these certifications in order to get that job. And I think this does kind of come back to, you know, those keywords in that automation that's like going to say, hey, if you're looking for, you know, this, if you're looking for a SOC analyst role, you need, you know, these 2, you know, certifications or what whatever the case is, if you're going into an AppSec role, they want you to have a CSSLP or something, whatever. There's going to be job requirements, and that's a whole nother topic on how we build out these job descriptions and requirements. But I think we have these requirements around these roles. We say that, well, this role requires XYZ, And so the entry-level individuals that are trying to get into those roles say, well, it says I need these, you know, I'm seeing a pattern that says I need these certifications, so I'm going to go get them. I don't think that that really does anybody a service. You know, it's often costly to chase those certifications, and it doesn't really prove much of anything, to be honest. Oil. **35:42 Chris Romeo:** One of the we got to blame the hiring companies though, right? Because if you see a job post that says that you should have a CISSP and ten years experience to become a level one stock analyst, the inflation of requirements is the fault of all of the companies across our industry that are doing that. And I'm gonna I'm gonna offer a counterpoint on the certification side. And it's funny because I've been debating whether I'm gonna. relinquish my CISSP and CSSLP at this point in my career. One thing that I do like when I have a candidate for an entry-level role that has a certification, because for me that tells, that gives me a bit of a, some assurance that a candidate has chased a goal, driven through, executed, and done it. Same thing with a bachelor's degree in something. I don't even really care as much if it's in computer science versus something else versus music versus whatever. Like what, what does a bachelor's degree really give us? It gives you hopefully a well-rounded perspective on a number of different topics, but it also shows you can show up, take tests, and do something for 4 years in a row. **36:58 Derek Fisher:** Right? Yeah. That you can apply yourself to something. **37:00 Chris Romeo:** You can apply something, yourself to something. And so that, I think of the same thing, like certification. I like, I like, I don't, I'm not super happy to see, or, or I, nor do I think it's necessary for an entry-level candidate to have 6 certifications in different things. But I like to see some step forward because one of the things I'm looking for in a candidate at any level is, are they a lifelong learner? My favorite question to ask in interviews, what's the last book you read? Or what's the book you're reading right now? And you are not going to be shocked how many times I've heard people say, I don't like to read. I don't read books. I read a book 10 years ago in school. **37:41 Derek Fisher:** Okay. **37:42 Chris Romeo:** In my mind, the interview's now over because you're like, you're somebody who's going to require too much of my attention. I don't want people, I don't want to hire people that need all my attention. That's why I'm hiring you to go do this job. I need you to be able to research and figure it out. Sure, you can come to me later in the process if you're like, okay, I've tried everything I can think of here. Give me an idea of something to shake this loose. But you can't come back to me and ask me about something I read in a book because you didn't want to go do the research to it. And so that's, I don't know, that's, I guess the life, the world according to Chris, what just happened here. That was a new segment. **38:15 Derek Fisher:** But have you ever made a decision based on somebody having or not having a certificate? or certification in something? **38:22 Chris Romeo:** No, I've never had, I've never made certifications a criteria of any of the places. And I hired some people at Cisco years and years ago. I hired a lot of people and I hired 30 in my first startup and a few in my second startup. So certification for me, it's never been a criteria. It's never been like a cutoff point. And I never, I never would make it. I wouldn't recommend making it a cutoff point where you're like, oh, if you don't have CISSP, you can't do this job. **38:50 Derek Fisher:** Right. **38:51 Chris Romeo:** I don't think that's the truth. **38:52 Derek Fisher:** Yeah. And, you know, that's the reason I asked that question because I mean, I never, I couldn't tell you the last, you know, half dozen people that I hired. I couldn't tell you whether they had certification or not. Right. Because I didn't, it's not, I don't, I'm not basing my decision on that. Right. I mean, if you got it, great. You know, that, that's great. You know, to your point, it proves that you can, you know, you can focus on something, you know, for a period of time and get it done. Um, it's not, I don't think it's, I don't think it's a game changer in the sense that you're gonna come in a superstar because you have this certification or that certification. **39:30 Robert Hurlbut:** Yeah. **39:30 Derek Fisher:** Um, no, getting my CISSP didn't fundamentally change what I knew and how I, how I worked. Didn't, didn't change much. Right. It just, it just showed that I got it. **39:43 Chris Romeo:** For me now, granted, I got mine in 1999. a long time ago. It was a, it was a good foundational set of knowledge at the time. **39:56 Derek Fisher:** Yep. **39:57 Chris Romeo:** That, that I look back and say, I didn't necessarily use it all, but there were foundational pieces of that that, that allowed me to be ready to take the next steps in my career so that I wasn't completely clueless when more, more senior security people started talking about something. I knew some of the basics that I could at least follow the conversation, right? **40:19 Robert Hurlbut:** Right. **40:20 Chris Romeo:** So, but yeah, I mean, it was, I wouldn't, it shouldn't be something that's mandatory. And because people can come from different levels of experience, you can get experience, you know, someone with 10 years experience doing a job versus somebody with a certification. I mean, we know which way we're going to land if we have to choose between those 2 candidates. You know, 1 year experience in a CISSP versus 10 years experience. **40:44 Robert Hurlbut:** Right. **40:45 Chris Romeo:** That's a pretty easy, uh, pretty easy answer to take. So, right. Uh, let's see, Derek, let's do one, one more question here. And I'm curious because I know you're, you're, you teach in the academic world. And, uh, so what's the value from your perspective of a cybersecurity bachelor's? And I know we talked about it a little bit already. Um, I'm just curious, like, do you see that as Do you see job requirements that, that have a cybersecurity bachelor requirement, that specific discipline? **41:15 Derek Fisher:** I haven't seen that. Um, and like I said, I, I think there's, there's been graduate-level cybersecurity, you know, uh, programs that have been out there. I, I mean, I, and I could be totally way off here, but I, I have not seen a bachelor's, you know, an undergraduate one. Maybe they do exist. I just haven't looked at it. I, but again, I know that there's, I mean, I have a master's in cybersecurity, but it's, you know, it's basically a series of courses that are, you know, geared to help you understand, to basically to prepare you for the CISSP, right? It's a broad set of topics that are going to get you, you know, a mile wide, but an inch deep in, in most of it, you know, but you'll, you'll go deep on some things. But so, and I, just to kind of go back to the, to the entry-level, uh, question here to, to, to, uh, kind of highlight this is that a lot of students, when they come out of, you know, school with their, let's say it's computer science, they get a couple certs, they say they still can't land a job. So they go to get a graduate degree in cybersecurity. And it's like, man, that's, you know, that, and again, you're still, you're gonna come out now with a graduate degree, couple certs, and still no, no experience. And so, um, I, you know, I, I really, I hope that as an industry that we start to take a look at the way, you know, the requirements that we have around these positions. Um, there's plenty of people, and we know, we know this to be a fact, there are plenty of people out there that have zero education, you know, not education, but you know what I mean, like zero, uh, traditional bachelor's or graduate degrees that are superstars when it comes to security. **43:13 Chris Romeo:** Yep. **43:14 Derek Fisher:** Um, and, you know, just getting through that Same thing with getting a computer science degree doesn't, isn't gonna make you a superstar software engineer, right? You're, you know, you could suck at it. And so I think we put a lot of requirements around what we think we need because, you know, to be honest, like, as a hiring manager, Now, if I was, if I was hiring for my own company, it'd be a little different. But, you know, when you're a hiring manager in an enterprise, you're given a template. Here's the job description. What are you looking for? You're looking for this individual. Well, here's, you know, the pay range. Here's the type of people that we're looking for. Your organization may actually have requirements around, well, they have to have an edu— you know, they have to have a bachelor's degree. Anybody coming into the door, you know, for a technical role has to have a, you know, a bachelor's degree. Um, and you're already, you know, you're already starting from that platform. Um, but we know that in cybersecurity, you, you know, your background or your day-to-day experience, although we are technical and a lot of the things we work with is technical, but you have to, you have to think outside the box, right? You have to think about things that, you know, you have to think how the system's going to break. You have to think about how somebody's going to try to break it. Yes, that requires some technical ability, but that also requires some creativity, right? And that isn't often, in fact, I would argue that that's rarely ever taught, you know, in school anymore, especially in a technical degree. You're taught, here's how you do XYZ, you know, here's how you execute, you know, this and You're really confined to like the framework that, you know, for that particular discipline. So I, as much as I think that getting more people exposed to cybersecurity and making that as part of these degree programs is helpful, Um, I, I really think it comes down to the requirements that we make around these positions that say, here are the things that we, you know, again, it's all a template. You need an entry-level SOC analyst. Well, here's the certifications that we need. Here's the, you know, you need a bachelor's degree, you need this, you need that. Um, you know, there's plenty of jokes out there too about people that, um, you know, you require X amount of years experience in this language. know, 5 years experience in this language and the language has only existed for 2 years. You know, that's just indicative of, of how we create these requirements where it's like, yeah, it just, there's not a whole lot of thought into it. You know, I think— **46:08 Chris Romeo:** That's just lazy, lazy work behind the scenes is what that is. And that, that, yeah, I remember seeing one of those examples and, and it was pretty well publicized, but, and not, and, and the funny thing is I think the, the original story, it was the author of the framework. I was interviewing for the job. **46:26 Derek Fisher:** Yep. **46:27 Chris Romeo:** And they're like, I don't have 5 years of experience. **46:29 Robert Hurlbut:** I don't have the experience for the thing I built. **46:32 Derek Fisher:** Yeah. **46:32 Chris Romeo:** I built it from scratch, but it's only existed for 3 and a half years, not 5 years. So nobody can have 5. **46:38 Robert Hurlbut:** I'm disqualified from working on it. **46:41 Chris Romeo:** Yeah. So 2 thoughts that, Derek, I want to react to, uh, or answer one of the things I think, or a point about one of the things you said. I think one of the challenges, like we've constantly tried to layer, to make a cybersecurity degree by throwing a bunch of stuff into a pot and just stirring it up. Nobody's ever, that I'm aware of, gone back to the drawing board and said, let's build a cybersecurity degree from scratch with no constraints on computer science, on CIS, on IT-related things, on certifications. Let's just throw, it's like Tesla, when Tesla made their first car, they threw out away everything that people knew about cars and said, we're going to build a new car from scratch. And we're not going to use any of the old designs. We're going to start from scratch. I feel like that's what needs to happen with a cybersecurity university degree. Throw everything away, go to a whiteboard and create something from scratch that's based on the skills that people like us as practitioners know you need to have to be successful in various tracks, whether it's IT governance, whether it's AppSec, whether it's pen testing, whether it's forensics, incident response, like we could layer all of those things and say practical skills for each of these stacks. And then how do you get a well-rounded view of all of those stacks in a cybersecurity degree? **47:58 Derek Fisher:** Yeah. **47:58 Chris Romeo:** By doing a pen testing class and doing a forensics class that has incident response and then doing 2 classes on AppSec and secure coding and threat modeling classes, because we have to throw that in this curriculum. And, you know, just, but everybody just says, well, what can we add to our CS degree to make it feel like it has a cybersecurity t-shirt that it can wear out in public? And then the other thing on the graduate degree, I've had this conversation with a couple of different young folks that I've worked with and also just tried to advise. And everybody wants to go get a graduate degree. And a lot of them want to do it right out of— they want to go right from their bachelor's degree to their master's degree. And my problem with this is you don't know anything yet. And I don't mean to be mean, but you just know a bunch of book facts. And one of the things is I went back and got a master's later in life after working for a number of years. But I think what people would be able to do is you'd be able to interpret what the teacher's saying if you have real-world experience. Because then when the teacher says, well, this is how it is, you can raise your hand and you're like, uh, actually, I work at a company and it's not like that at all. That's something that they said that used to be 20 years ago. Things were like that. But when you go from, uh, directly from finishing your bachelor's directly into your master's degree, you don't have any life experience to know what I should believe and what I shouldn't believe. from what these folks are saying. So I don't know, we got to solve this university problem somehow. So somebody start a working committee or subgroup or something, and Robert and Derek and I'll show up and just pontificate for a whole hour or two. **49:46 Derek Fisher:** Yeah, I mean, I do like the idea of, you know, the way, at least for Temple University where I teach, you know, they, it's an elective. The software security course is an elective for CIS and CS students. Um, you know, that's, I wish that was not an elective, first of all, like that it was fully integrated with the program. Like it's required for you to know data structures and how to secure that, you know, the code you're writing. **50:21 Chris Romeo:** Derek. You're going to put us out of business, man. We're not going to have any AppSec work to do anymore. If you get this dream— **50:26 Derek Fisher:** I'm sure that we'll probably have plenty of AppSec work going forward. I don't think the problems are going away anytime soon. So, but you know, I think we, this comes down to how we kind of make cybersecurity very mysterious and we make it sound like we're wizards and we're in the ivory towers and we're, you know, and I know that's not the reality for a lot of us. You know, we are, we're in the trenches, we're in the dirt, we're doing, you know, the work. Um, but I think there's, you know, there, there can be a perception that there's engineering and then there's cybersecurity and they're 2 different things. And sometimes they, you know, uh, work together and sometimes they don't. And when we integrate those into blurring the lines, right? Like we talk about DevSecOps, you know, blurring the lines and all that stuff. Then I think it really starts clicking with people that like, okay, it's not just like building my application for resiliency and things like that. I mean, those aren't things that I, that's not handled by the resiliency, you know, team, that's handled by the development team, right? So I think, you know, as we start, hopefully as we go along, you know, uh, here that, you know, we'll, we'll get more security integrated into, um, into the, you know, undergraduate, uh, programs as like a requirement. Like you, you need to at least learn these things, you know, even if it's just basic stuff, just you need to learn that these things are problems that need to be solved. **52:02 Robert Hurlbut:** Yeah. **52:04 Chris Romeo:** All right. Well, I think we could literally spend hours discussing the issues that, that we went through here. But it's now time for us to transition into the lightning round. Robert, take it away. **52:17 Robert Hurlbut:** All right. So yeah, 3 questions that we have. First of all, what's your most controversial opinion on application security? And why do you hold that view? **52:26 Derek Fisher:** That we have too many tools in AppSec. I think there's too many tools, too many vendors. You know, every time you turn around, there's a new vendor solving the same problem. And, you know, I think there's definitely different areas in AppSec where we have, we don't have enough coverage, but certainly in some spaces in AppSec, there's just, yeah, you can, There's, there's too many vendors. And, you know, I remember reading recently about how— and I mean, we know this from experience as well— is that when you're bringing in a tool, I mean, you're not, you're not buying it as a security, you know, organization, you're not buying a tool and then turning it on tomorrow, and then it's running perfectly, right? It, you know, it takes a year, right? I know that some of the tools that I brought in, Um, when I was running, uh, prodsec, uh, at, uh, FastNet, we, you know, I remember having conversations like in my first week or two on the job with vendors and not even integrating that tool for like 12 to 16 months. And, and that's not, you know, unusual. Um, it just, it's such a long lead time to get, uh, security tools in. So the idea that you're going to switch to a different tool, um, is, you know, that's, that's painful. You know, there's, there's a very high switching cost when it comes to, uh, security. So, so I think, yeah, I don't know whether that's controversial or not, but, uh, you know, at least my opinion is that we got too many, too many stinking tools in AppSec. So. **54:06 Chris Romeo:** It seems like it is controversial. So you can also write to Derek at PO Box 142. **54:12 Robert Hurlbut:** Yeah. **54:14 Derek Fisher:** Let's keep saying, hit up my LinkedIn inbox. That always works. **54:17 Chris Romeo:** There you go. **54:20 Derek Fisher:** All right. **54:20 Robert Hurlbut:** Well, second question is, if you could display a single message on a billboard at the RSA or Black Hat conference, what would it say? **54:28 Derek Fisher:** Man, I, you know, I was sitting there thinking about this the whole time too. I was trying to figure out what it— I don't know. Touch grass. You know, I think we're, we're so— I think we're all, you know, we were talking about this earlier. I mean, I think we're all We're so deep into the, into the technology and, and, and to be honest, like the rat race of, of just being in this industry where it's a constant, you know, firestorm and, and you're just, you're always, there's always something going on. You know, I, I know that there's, there's just days, like I, like I said earlier, I, I, I go out running and it's just, you know, to just go outside and, you know, just I run with music, you know, I, I have friends that are like, I can't listen to music while I'm running, but like, you know, just to put some music on, get out and see the scenery, you know, and just unplug for a while. I think we all, you know, for mental health reasons, for the, the burnout that a lot of us see, I mean, it, it's just, you gotta, you gotta unplug once in a while. So. **55:33 Robert Hurlbut:** Makes sense. So number 3, what's your Top book recommendation and why do you find it valuable? **55:40 Derek Fisher:** Is this an interview? Is this a Chris Romeo interview? You're going to ask me what I'm currently reading? No, I, so I do read, you know, I, in fact, I have like 3 different books I'm reading right now and I just kind of, it depends on what's, what the mood is, you know, and I mean, I'm actually reading, um, uh, um, uh, With the Old Breed. It's about, uh, it's a World War II, uh, just, um, it's not light reading, you know, but it, but it's just stunning to see, I think, some of the things that that generation went through, you know, and, and to know that these were kids, you know, doing the things, you know, it's, If anybody knows the book or doesn't, it's written by a gentleman that was in the Pacific theater in Okinawa and some other islands. And just the firsthand view of what that looks like. And it's like, you know, every time I pick it up and read through it, it's like, this guy was 17 or, you know, 18 at the time. It's like, that's just, it's insane to think about, you know, that. But Technology-wise, I am reading Cyber for Cyber for for builders. That's a pretty good one by Ross. Can't remember his last name. Ross. Anyway, Cyber for Builders by Ross. **57:20 Chris Romeo:** It's like Hubalek or something. **57:21 Derek Fisher:** Yeah, it's H. It's H something. **57:24 Chris Romeo:** Yeah, he just wrote a new book on, yeah, it's the new book. You're talking about the new one on like cyber startups, right? **57:29 Derek Fisher:** Yep. Yeah, I think it came out, uh, maybe last year. Um, but yeah, it is somewhat recent and that's pretty good. Um, that, that's a good, if you're, even if you're not looking into getting into, you know, doing a startup, um, there's a lot of good takeaways there just from people that are working in cybersecurity. Um, you know, that what I mentioned earlier about the whole lead time to get, you know, a product in the door, uh, was something that was in that book. Um, you know, about how it, it's a very different world, uh, when it comes to cybersecurity tools versus your typical IT tool. Um, and so, but anyway, there's a lot of good, a lot of good tidbits in there. It's not just for people that are looking for, you know, starting, uh, starting a business or anything like that in cyber. It's, it's, you know, it's a very, Um, there's a lot of, uh, information in there that, that's, that's very, uh, very good. So the other thing I do have on my— I haven't said anything yet about this because I, I haven't cracked it open yet, but, uh, Chris Hughes, uh, his, uh, book on, uh, effective vulnerability management, I have it sitting on my desk. I, I pre-ordered it and came in, uh, a little while ago. I, I haven't, like I said, cracked it open yet, but, um, but I, I do plan on, uh, getting through it at some point here. So. **58:48 Chris Romeo:** Excellent. Derek, what about a key takeaway or a call to action for our listeners? **58:56 Derek Fisher:** So, you know, I think talking about hiring this whole time, I think again, the, the, my recommendation for people that are trying to get into this industry is that, you know, there is no blueprint, there is no fairy dust or magic, you know, that, that'll get you in the door. It's going to take hard work, it's going to you know, take networking, go to the industry events, go to your local events if you have, if you're lucky enough to have like something like a BSides near you, those are always good to go to. You don't have to go to the big ones. You don't have to go to, you know, Black Hat and DEF CON and RSA and all that stuff because one, you know, RSA is extremely expensive and, you know, travel costs and all that other stuff for people that are trying to get into the business, that's hard. But, you know, I'm in the Philadelphia area. There's a ton of security stuff, you know, that happens in this area. There's plenty of you know meetups. There's plenty of events. You know you just need to be able to find them and go to them. Start networking. Get you know some people that you can rely on and set up conversations with. A lot of times I get pinged to just have a conversation with somebody that's trying to get into the into the industry, and you know that. to me is, um, I think helpful. You know, I, I'm not, um, you know, Chris, to your earlier point, I mean, I'm not hiring, uh, right now, but, you know, for those people that are, that are having those conversations with me, now I can put a name, you know, a face to a name. I can put a story, you know, behind that. If something comes up that I know that somebody is hiring, then I can, you know, make a warm handoff there. **1:00:34 Chris Romeo:** So those relationships and, and, and really Well, Derek, thank you for visiting the show a second time. And you didn't bring a book that you authored this time, but maybe for the third time around, you'll have a new book that you'll be— **1:00:56 Derek Fisher:** I don't know if I have enough time for that, but I have been thinking about it. It's just, yeah, it's a lot of work. So yeah. **1:01:03 Chris Romeo:** I hear that. Everybody that's written a book, that's same, uh, the same conclusion that they come with. But we always appreciate your, uh, your insights and, uh, you know, the, all the stuff that you're doing to help move our industry forward. Uh, keep it up. And, uh, thanks for, thanks for all you do. Thanks for sharing your insights with our, our audience here. And we look forward to another visit at some point in the future. **1:01:24 Derek Fisher:** Yeah. And same to you, Chris. I mean, uh, you know, a lot of the stuff that, you know, you guys, you and Robert are doing, I mean, there's, you know, we, Again, this is what helps people, I think, get into the, uh, industry is when we're sharing knowledge, you know, and sharing our experience. I think that helps people really get some insight into it and then hopefully, you know, helps people get in. **1:01:43 Robert Hurlbut:** So. **1:01:43 Chris Romeo:** Yeah. Excellent. --- Source: https://appsecpodcast.com/derek-fisher-hiring-in-cyber-appsec/