Skip to content
AppSec PodcastThe Application Security Podcast — home
44 min

Marc French — The AppSec CISO

With Marc French

Privacy and ComplianceCareers in AppSec

Is becoming a CISO the next technical promotion, or a fundamentally different job? Marc French joins Chris and Robert to discuss the role through the eyes of an application security leader.

Listen

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 16 chapters
  1. 00:00IntroductionAudio
  2. 02:09How Marc's AppSec CISO perspective developedAudio
  3. 05:30Running application security inside product managementAudio
  4. 08:59Balancing vulnerabilities and business commitmentsAudio
  5. 10:37Learning outside a security roleAudio

About this episode

Is becoming a CISO the next technical promotion, or a fundamentally different job? Marc French joins Chris and Robert to discuss the role through the eyes of an application security leader. Drawing on experience running both product and security functions, he explains how delivery commitments change the way risk decisions look. The conversation examines the CISO’s communication-heavy day, reporting relationships, alternative career paths, and the growing importance of application and product security as infrastructure becomes code. Marc offers practical advice for people pursuing leadership: understand the business, gain experience outside a narrow security role, and find mentors who will challenge your assumptions. He also discusses programming skills, developing future AppSec talent, and why a title alone is not a useful career plan.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Marc French:
LinkedIn

Resources
Boston Application Security Conference

Actionable

From this conversation

  1. Build security requirements into products

    What ended up happening is we recognized we need to start embedding security inside the products.

    2:48
  2. Gain business experience outside security

    Be a business person, because you're going to get that appreciation.

    10:37
  3. Plan your career across security disciplines

    You've got to plan that out and make sure that you're taking roles that are going to fill in the boxes of all the different functions of security.

    26:24
  4. Build a technical foundation before entering AppSec

    You have got to set your chops in technology before you can be an AppSec person.

    34:46
Transcript · 44 min conversation

0:00Chris RomeoMark French is a security person, firearms geek, scuba guy, lousy golfer, and an aspiring blacksmith. We met Mark in the hallway at the Boston Application Security Conference, and we ended up chatting the afternoon away. Mark has extensive experience as a CISO, but came from the world of AppSec to the executive suite, which is not the normal path. We discuss what is a CISO and what does a CISO actually do? the role of AppSec in the life of the CISO, and tips Mark has for those that wish to become a CISO someday. We hope you enjoy this conversation with Mark French. I want to take a moment to introduce you to Security Journey. At Security Journey, we believe security is every developer's job. We work with our customers to help them build long-term sustainable security culture amongst all their developers. Our approach is to provide security education that is conversational, quick, Hands-on and fun. We don't do lectures. Instead, we let the experts talk about what's important. The modules are quick, 10 to 20 minutes in length. We believe in hands-on experiments, builder and breaker style, that allow developers to put what they learned into action. And lastly, fun. Training doesn't have to be boring. We make it engaging and fun for the developers. Visit www.securityjourney.com to sign up for a free trial of the Security Dojo. The Application Security Podcast. Here we go. Hey folks, welcome to this episode of the Application Security Podcast. This is Chris Romeo, CEO of Security Journey and co-host of said podcast. I'm also joined by Robert Hurlbut. Hey Robert, how are you doing today?

2:05Robert HurlbutHey Chris. Yeah, this is Robert, Threat Modeling Architect. Good to be here.

2:09Chris RomeoAnd today we're gonna tackle a topic that is, I think, gonna be interesting for a lot of different people, Robert, because we're gonna talk about First of all, what is a CISO? Maybe even how to pronounce CISO. Is it CISO? Is it CISO? What is it and how can somebody from the world of application security get into this type of a role? And so, we're joined by Mark French, who has a lot of experience in this world of the CISO. But Mark, we always start this podcast off, which is going to be much more prevalent for this particular episode and much more important, with How did you get started in security?

2:48Marc FrenchI have an interesting meandering origin story. So I actually started my career as a police officer a long, long time ago. Decided that, you know, being a beat cop was not really what I wanted to do. Went off and got a computer science degree and then started as an engineer. really building Seawolf-class nuclear submarines, to be honest with you. So I was a CAD/CAM Fortran DB2 engineer, you know, back when you had those big radiation screens that kind of glowed green. And it's funny, that's where I actually started my security career. I did a little bit of RackF on the mainframe, for folks on the phone who might actually know what that is. Um, I did a little bit of user access control work on a 3390 mainframe, stepped away for a while, and then was really an engineer. I worked my way up through the engineering thing, did the heyday thing in the '90s, 5, 6 startups over the course of 4 years, about every 9 months cycling through a different startup as we burned through cash, and then really landed in product management. Surprisingly, so I was working at Iron Mountain here in the Boston area, running their digital product management group. And it was funny; we recognized at that point in time that you know being Iron Mountain and part of what they do is security. That's kind of the the shtick that they have. What ended up happening is we recognized we need to start embedding security inside the products. So I I built the application security. program at Iron Mountain inside the product management team.

4:34Chris RomeoWhat year is this, Mark, just to help us kind of set the stage?

4:37Marc FrenchRoughly, you know, I would say 2006. Okay, 2005, 2006. I got hooked on it, to be honest with you. So I started focusing more of my time on the security stuff, less of my time on delivering product, and then basically jumped into the deep end of the pool and became a security person. at that point in time, really with an initial focus on AppSec. And then he got a CISO job, kind of a group CISO job at EMC out in Silicon Valley, and then took a CISO job here in the Boston area, took another CISO job, took another CISO job. And now I'm kind of currently running what I'll call like a boutique AppSec consulting firm out here in Massachusetts. So, kind of an interesting ebb and flow, but historically just an AppSec developer.

5:30Chris RomeoYeah, so that's a number of interesting things I hear in your background here. I want to start by understanding a little bit more about this idea of building an AppSec team inside of product management. So, that's fascinating to me as somebody who's an AppSec practitioner, and AppSec normally starts either within the security team or maybe you have some collaboration with the development folks. But I've never heard of an AppSec program starting inside of product management. So can you tell us a little bit more about how that kind of worked?

6:02Marc FrenchIt was actually probably one of the best places to have it. You know, I know a lot of the other security folks are going to probably disagree with me on the phone, but I've always kind of tried to focus my teams inside the engineering teams because selfishly, it's where all the money is. I hate to say that. they're generally not viewed as a cost center, they're viewed as a revenue center. So when I needed resources, being inside the development teams spread amongst 1,000 engineers, when I needed extra money, it was actually easy to get. But really, the reason for product management was, if you think about it, a lot of what we do is driving requirements into the things that we deliver to customers. So who better to actually manage and drive requirements is product management. So when we looked at where to stand this up, we could have put it in the traditional security team. That team at Iron Mountain was really focused in on kind of compliance and vulnerability management, not really about driving security features into the products that we shipped. So when we look, step back and said, what our customers are actually asking for, they're looking for security features. How do I do resets? How do I do auth? How do I integrate with my own environments? We said, hey, that sounds like product management. You know, building features and prioritizing features for the products that we ship, that kind of sounds product management-y. And yeah, we're going to do some code reviews and we're going to do other things, but that's how we kind of settled on it being in product management. So I actually had a PM whose job it was to be the security PM.

7:39Chris RomeoAnd so you actually, you had additional, you had some engineering resources within your team in product management that were focused on security, or were the engineering folks in engineering and you were kind of dotted line or collaboratively working with them?

7:55Marc FrenchNo, I had engineers. So, I had folks that are going to turn the AppSec bits, right? So, folks running SAST and folks running DAST and doing code reviews and threat models. But then I also had product managers. And then we had a kind of a dotted line into the core security organization, but I actually worked for the head of the technology division.

8:18Chris RomeoYeah, that is definitely fascinating. And I agree with your idea of, hey, it's about requirements. At the end of the day, it's all about requirements, and product managers are always the keepers of the requirements. And so that's why I'm so fascinated by this idea. And I think it's— I agree with you. I think it's a good place to have your AppSec function because you're able to influence those requirements right at the source versus trying to lobby somebody who is going to give 10% or 20% of their thinking time to security. You embedded yourself right within where all those people were making those decisions. Yeah.

8:59Marc FrenchAnd I didn't have to deconflict because it was my team. So, I ran both functions. So, if I needed to focus, I could focus. Now, the one interesting thing I'll tell you though is it gives you a perspective that you may not get coming up through the security organization because, you know, my security folks would come to me and say, you know, this thing is the end-all be-all, there's a vulnerability, we need to fix it. And I would have to balance that with the fact that, hey, I've got a marketing campaign that's running on Tuesday and I absolutely have to ship. So it gave me a perspective that I think a lot of security folks don't get get exposure to early in their careers where I had to be right in the business side because I'm running the business side and I'm running the security side. And that conflict can be tough sometimes.

9:46Chris RomeoYeah, I've had a similar experience here in, you know, with what Security Journey does. We have our own cloud-based application that provides training. And so, you know, we've got our own DevOps build pipeline, we've got security tools built in, we're dealing with third-party dependency tracking and vulnerability management stuff. And so, I've gotten a whole new appreciation now for all the things that I've been saying for years, now that I'm in the trenches and I have to deal with them. And I have to think about sometimes, hey, I might have to specifically filter out a particular vulnerability just because I need to push a new version of code while there isn't yet a fix, for example, for a particular library. And so now I just, it just gives you a different perspective when you've walked a mile in the shoes of those that you're trying to influence, whether that's developers or product managers.

10:37Marc FrenchAnd I would say, and I know we're going to get to this in a bit, one of the things that I mentor a lot of folks that are kind of up-and-coming CISOs here in the Boston area. And one of the things I tell them is go get another job outside of security because, you know, as you get up to that level where you're an executive, there's going to be an expectation that you can walk on both sides of the street. and understand that business viewpoint. A lot of folks that come up through the technical ranks, to your point, Chris, don't have that appreciation. I think you need to go off and get that appreciation, even if it's go work in HR, go work in sales. I try to tell my mentees, get off for a year and don't be a security person, be a business person, because you're going to get that appreciation.

11:24Chris RomeoYeah, I think that's great advice. to really get that perspective. That's when, you know, as a startup CEO is kind of the role that I'm in right now. And even more than what I was talking about with developers, I have a whole different appreciation for running a business now. I can't just say we have to secure this thing like I might have 10 years ago in my career.

11:46Marc FrenchOkay.

11:46Chris RomeoNow I'm thinking about, well, what is it gonna cost? What are the ramifications for our customers? What is the amount of risk that's gonna be reduced? Like I'm asking things that, that are blowing my mind at this point.

11:55Marc FrenchAnd then you just answered what a CISO does, right? 'Cause the reality of it is, is you're that person now. When you get that role, you know, you have to be that person who's gonna guide the organization through the conversation you just said. You know, you're not, and this is gonna be controversial, you're not a technical person anymore as a CISO, really. You still dabble in it, and I'll be honest with you, I still do. I try to code once or twice a year just to make sure I still have some skills and convince myself I'm still technical, but that's not the job that you have in the organization. Your job is to facilitate that conversation you just had, Chris, the things you just said.

12:36Chris RomeoAnd that's a good segue here to kind of our next question of what is a CISO, however we want to say it here, and what do you actually do in that role? And so I know I kind of brushed around the edges of that perhaps and describing what I'm doing these days. But Mark, I'd love to get your take when you have to define it for somebody. What is a CISO and what do you actually do in that job?

13:01Marc FrenchSo we'll say CISO, that's what I generally call it. Some people say CISO, tomato, tomato, whatever word you wanna call it. You know, a day in the life is not what you would expect. You know, I think a lot of folks, Think it's a continuation of their technology career, when in reality it's not. You know, I joke with some of my mentees; it's not roses and candy at that level. I'll be honest with you: most of the time is spent in communications. So communicating across your stakeholders, so all of your business partners, in trying to talk to them about risk. and get them focused in on how to maintain an acceptable level of risk in the organization, and a tremendous amount of time of communicating up. So dealing with the CIO, dealing with the CEO of the organization, talking to the board of directors. So on a typical day, you will spend 6 hours in meetings, of which most of it is kind of alignment and discussion and risk conversations. So it's, you know, folks are coming in thinking that they're going to maintain and be that technical leader. I'm going to tell you, you probably have a false expectation of what the role is because it's really about comms and discussions and a lot less about tech.

14:24Chris RomeoAnd so in your experience and when you look across the industry right now, where do you see the CISO fitting into the organizational chart right now? Is there a direct relationship to the CEO? Is the CIO kind of in between? Are you reporting to someone else? Where do you fit in the org chart?

14:41Marc FrenchI think it kind of depends on the org. I think historically it's kind of reported into the CIO. I'll be honest with you, that's just a place I don't like to have it be because I think— don't get me wrong, again, controversial statements today— most CIOs are seen as cost centers. and must-haves, I prefer to actually be— if I had my druthers about it, I'd be in the CTO organization because that's where the innovation is happening. And I think security needs to be innovative in order to reduce risk for the organization. So if I had a choice, I'd actually kind of go into the CTO organization. And again, maybe this goes back to the fact that I kind of grew out of product management, but I think if the goal is to be innovative, that's the best place to be. Stay away from legal. That is a compliance function. Unless you really want to be the person who is seen as the beat cop of— use a bad analogy from my past— the beat cop of PCI, try to stay out of the legal department. It would be great if you can be reporting to the CEO. I have had 2 CISOs in my past that have had that, and that had not worked out very well. I think partially because they were still technologists and that wasn't the language that the CEO was speaking. Those guys, I'll be honest with you, flashed out fairly quickly, and then that role actually got tucked under the CIO afterwards. Again, if I had my choice, CTO all the way.

16:15Chris RomeoMark, I want to dig a little bit deeper into this, the technical nature of the CISO role, because I see so many folks that I meet in my travels and talk to. And they see the CISO as the role like, hey, that's what I want to get to. That's the pinnacle of my career. That's my big goal. And I don't think most people realize what you were saying about kind of the technical nature of this. So, when you're in this role and you have a giant architecture change that's happening and your team is building a whole new architecture, Are you involved in that process at all? Like, what level? Are you approving it? Are you even seeing it, or are you in other meetings?

16:57Marc FrenchSo I guess it kind of depends on the size of the organization, Chris. If it's, you know, let's, let's be honest, if you're a team of 3 or 4 and you're the CISO, you're the, you're the player coach. You're still kind of running the ball up and down the field, even though, you know, you've, you've got this responsibility to have communications. The converse of that is if you are the CISO of a large multinational, probably not so much. They may come to you and say, we are going to do a new enterprise architecture to satisfy this business requirement, but that is probably as technical as you are going to get with respect to that. I see this a lot. I mentored a friend of mine not too long ago who was at a director-level position very technical, thought that he needed to be a CISO. And the reality of it is, is, you know, my guidance to him is, why? You know, you really have passion for the technical aspects, and I'm going to tell you that you're going to take this role and you're going to hate it, to be honest with you, because it's not going to scratch that technical itch for you. And don't feel that your career is over because you've made director. There are other opportunities for you. CISO's probably not the right role for you because it's not gonna get you where you wanna be from kind of your visceral self. You know what I mean? It's not really what you wanna do. You think you need to get there because that's the pinnacle, but it's not really the pinnacle based on your skills and your desires.

18:26Chris RomeoWhat do you see as other opportunities that folks should be looking at other than the CISO role?

18:36Marc FrenchSo there's always the, you know, go to the larger company. So if you're an AppSec person, team of one, you know, go to a company where there's a team of 5 and you're the lead. You know, the challenge that we have in AppSec is big teams, there's not a lot of them. Let's be honest, Chris. I mean, the number of teams that have 100 people in AppSec, we could probably count on one hand across the world. So, you know, there is something to say that you can kind of still progress up through there. I'd also urge you guys to think about maybe going back into product management or going into engineering. To be honest with you, there's, there's opportunity over there. Take the skills that you've learned on the security side, maybe go to a security startup like you, you know what I mean? Go build a product. You've got the expertise in security. Get off and be an entrepreneur.

19:27Robert HurlbutYeah.

19:28Marc Frenchmaybe go do a startup, do consulting. There are other opportunities for you to do that where CISO isn't the role that you need to take.

19:36Chris RomeoYeah, you think about how many CISO jobs are there actually out there, and there's only one for every company. And so are you seeing like how small of companies are Actually declaring somebody the CISO at this point?

19:56Marc FrenchIt's actually— I'll call it going downmarket. You know, I think it used to be that they would have to be a certain size in order for them to have a CISO, but I'm seeing more and more organizations with one security person and them anointing a CISO at that point because there's this kind of mantra out there that every organization's got to have one. You know, whether you're truly a CISO or not is a different conversation. But the title seems to be getting down to smaller and smaller organizations.

20:24Robert HurlbutYeah.

20:25Marc FrenchYou know, how many— you're right, it's kind of the pinnacle position. So, you know, if you think about here in Boston, there's probably 50 CISO jobs, and it's the same deck chairs that get moved around and around. So I see a lot of my peers just moving from company to company because, you know, there's only 50 gigs to take. Maybe there will be a new one when a new company comes on, and you might add 2 or 3 a year, but the pipeline, it is just like the military, I guess, to use another analogy. There are only so many generals at the top. There are a lot of lieutenants and a lot of colonels, but a lot fewer generals.

21:03Chris RomeoWhen we think about who the buck stops with in the security organization, If you're a CISO, that's going to be you. And so how have you seen kind of the data breach climate that we're in now? How does that affect the longevity of a CISO working for a particular company?

21:26Marc FrenchYou know, I would say, to be honest with you, I don't think it's the breach that's causing the current longevity issue. I think it's their ability to influence and make change. So, you know, we hear about these things, people get breached and their CISO gets fired or their CEO gets fired, but that's a handful of folks, let's be honest. I think most people leave now because they don't think they can affect change in the organization they're in. So I see most of my peers, couple, 3 years they last, maybe 1 or 2 turns of a strategy, 18-month strategy, then they feel they've either done everything they can do, or they're not going to be able to achieve what they want to do, and they roll off and go somewhere else. So while I think there's a little bit of that breach failure, you know, get rid of the CISO. I think it's mostly the other 2 reasons that drive them out.

22:16Chris RomeoSo let's look closer at how application security fits in now to the life of the CISO. And so is application security like a function that reports to the CISO, or how does application security fit into this world?

22:33Marc FrenchYou know, it used to be that I call it the smallest group in the CISO's arsenal. So if you think about a typical, and I'll put it in air quotes, you can't see it, security organization, there's a whole bunch of GRC folks and a whole bunch of what I'll call infrastructure security folks, and then a tiny amount of AppSec people. You know, I've seen organizations that have 60 people in GRC, you know, 100 people in infrastructure security, and 2 people in AppSec. You know, What is interesting to me is that is evolving, because I am having conversations with my folks, both my peers and my staff. The reality of it is that infrastructure organization is going to go away, and again, back to controversial statements. People say, well, what do you mean, Mark? I said, well, if you think about where things are going with the cloud and infrastructure as code, The need for those, what I will call classic information security folks, people standing up firewalls and doing firewall rule reviews, it is becoming less and less. The need for people that can code and run automation and do code reviews and that kind of stuff is growing. There is going to be this point where that traditional infrastructure team gets diminished, and you are going to need a lot more AppSec people. on that side, because that is where the engineering organizations are going. I have worked at organizations where it is the same transformation that is happening in IT. IT is running the traditional data centers, and they have got blinky boxes in racks. Then the engineering teams, all in AWS, and everything is infrastructure as code, it is getting deployed through Puppet and Chef. It is all Docker containers, and that is all being run by engineering. So likewise, what's happening there, IT is diminishing, engineering is going up. I think you're going to see the same thing happen in the security space where that information, you know, that kind of traditional infrastructure security group is going to go down and you're going to see the rise of the application security team because they're going to have to follow along with the engineering team because that's what the engineering team is doing.

24:45Chris RomeoI just wrote that down, the rise of the AppSec team.

24:51Marc FrenchRise of the AppSec team.

24:52Chris RomeoSounds like it could be a science fiction movie.

24:54Marc FrenchRise of— I can't say the name of the movie.

24:57Robert HurlbutYeah.

25:00Marc FrenchI have the proper clearance to say it.

25:02Chris RomeoYeah. So that's helpful to understand how AppSec fits into the life of the CISO. Now, if we haven't dissuaded folks from wanting to go down this path, and I hope we have, and I hope if some folks Yes. Are really saying, hey, communication, collaboration, managing risk, dealing with folks at the highest level. I hope there are some folks that are like, that is what I want to do, because we definitely need more people that are focused on that. What are some tips then, Mark, that you would provide for somebody who wants to follow in your footsteps here, become a CISO, What do they do? Do you go to CISO school? Is there such a thing as CISO school?

25:51Marc FrenchThere's not such a thing as CISO school. So I guess I'll just ask a clarifying question. So these are folks coming up through AppSec, is that— or just in general, Chris?

26:03Chris RomeoLet's talk in general first, and then maybe we'll add a little AppSec spin on it after.

26:07Robert HurlbutYeah, and I'd also like to ask about students. I just recently was talking to some college students, and I Met a couple who said, I'd like to be a CISO one day. Okay.

26:17Marc FrenchOh boy. Okay. So let's start with Chris's first one.

26:22Chris RomeoKind of the general nature.

26:24Marc FrenchWe'll talk about the general nature of it. You know, I think you've got to— I always tell folks, take a job for the job after this job. So a lot of folks kind of take a gig looking at what they're going to provide and not thinking about the longer-term strategy. So everybody that I kind of mentor, I say, You're going to take this job. What job is that going to get you afterwards? So if you think about what a CISO— the breadth of what a CISO needs to understand, you've got to start positioning yourself and really put a plan together to say, all right, I'm in this space. I'm a GRC person, as an example, because I've started in information security and I've got a compliance focus. I really need to learn the other disciplines of of this practice. You don't have to be an expert in all of them. You need to be an expert in one, but you're going to have to have pretty deep knowledge in the other disciplines. So you need to go off and take a role that's going to get you that kind of infrastructure security space or get you some experience with engineering. Because when you get up to the CISO role, there's going to be an expectation that you have some knowledge, and I'll say a little, probably more than some, across all of these different disciplines. So you've got to kind of plan that out and make sure that you're taking roles that are going to kind of fill in the boxes of all the different functions of security. I'll be honest with you, I think the hardest one out there is when you get a converged role. So a lot— I see this a lot in technology companies— security, security, security. So you've got the CISO who's a tech person, and all of a sudden they say, oh, you're a head of security, you have physical security. And that's not really something that a lot of technology people do, and all of a sudden, you got to worry about what we call Triple G, gates, guards, and guns, and you are thrust into this world of badges and executive protection and the corporate jet and all this other stuff. Sometimes it is hard. There is a little shock and awe when that happens, but I have seen it a lot. How do you plan that out to make sure that you have at least some knowledge of that when you have been given the position to take those things over? So, you know, you really got to plan this through and think about this. So that's kind of my general answer, Chris.

28:33Robert HurlbutOkay.

28:35Marc FrenchNow, AppSec, you know, what I would tell you there is, you know, if you're an AppSec practitioner, if I were going to make the next move, I'd probably go into compliance. I hate to say that, but the reason is, is a lot of what gets driven from the top It's driven by the sales organization, and a lot of times what happens there is it gets driven by compliance initiatives. Hey, we're going to launch into the healthcare vertical. Well, now you've got to understand HIPAA and PHI here in the US. So, you know, it's also going to help you decide whether or not it's the role you want because it's going to be a very less technical role, and it's going to be more indicative of some of the things you're going to do at the CISO role. So if you're a practitioner, I'd almost say go off and do compliance as your next gig, because that transition to do kind of infrastructure security is going to be easier for you as a technologist. So do that jump after you do the compliance gig, because you want to know right away whether or not you're going to want to be a CISO. So doing the compliance stuff is going to be more like it. Make that gig your next gig, and if you like it, then do the infrastructure. Now you've kind of holistically got all of the checkboxes, and now you can start having the conversation about, you know, kind of evolving into the CISO.

29:51Chris RomeoYeah, when I think about the demand that we see right now in the AppSec space, I almost want to tell people, I want to always want to be like, if you're in AppSec now and you're growing your career and you're continuing to learn, there's going to be a lot of VP of AppSec. I'm almost thinking there could be a future here where there is a Chief Application Security Officer separate from the CISO.

30:18Marc FrenchI've seen that. I've seen Chief Product Security Officer. It's a very Silicon Valley thing right now, but I have seen organizations— a very good friend of mine, she took that role at an organization in, in the Valley, and she ended up becoming the CISO afterwards. I'd never seen the title before. She, she let me know, hey, I've got this role. I saw her popped up on LinkedIn because that's usually how it happens. And I'm like, wow, that's intriguing. So I honestly agree with you, Chris. I think it's going to evolve because the focus is different. And again, it's kind of how the organization is structured. If you've got the IT and CTO, you could almost see where the CISO is kind of that traditional person sitting inside the CIO organization, and the CPSO is sitting in the CTO's organization driving that innovation over there.

31:08Chris RomeoYeah. Yeah, because you still got to have somebody that is focused on, like you said, to your point earlier about the infrastructure, and then even the physical side, you still got to have. And it's almost like over the next few, maybe 5 to 10 years, there's going to become more and more is going to be falling on a chief product security officer, then there's going to be less and less things that would be kind of in that classic role.

31:36Marc FrenchYeah, there is going to be kind of the shift right, I guess. I'm trying to think left, right. Left is the DevOps thing, so we'll go right. So we're going to shift right a lot of what's happening in some of the traditional roles over into the product security roles. And I, I'll be honest with you, it worries me a little bit because I, I don't see a lot of folks thinking through that transition. And we're already challenged, you guys know this, of hiring AppSec folks.

32:01Robert HurlbutYeah.

32:01Marc FrenchAll of a sudden, if that transformation happens, where am I going to get all those people? Because we are already struggling on the infrastructure side, and AppSec is even smaller. And you guys know when you try to hire folks, it is very, very difficult to get AppSec people. What happens if I need 4 times as many of those folks to kind of drive this transition and transformation? Yikes.

32:20Chris RomeoYeah. So to come back around to Robert's question here, he was mentioning that a few students have asked him that question or have said, hey, this is what I want to do with my career. What do you have for the student out there, Mark?

32:35Marc FrenchSo, we have this interesting challenge now because, you know, you guys see it. You know, HR will come back at you and say you need 5 years' experience in order to get your entry-level position. So, how do you get your entry-level position if you don't have 5 years of experience? But what I would tell you is You know, folks that are being trained, and again, this is my bias, be an engineer for a while or be a QA analyst for a while. You know, set your technical chops. You know, then you can dive into learning more about security once you get that technical foundation built, or even go be a sysadmin. You know, one of the challenges that I've seen is there's a lot more folks out there going through the cybersecurity programs They come out, they want to be a red team member, they want to be a SOC analyst. There's not a lot of those roles, and I don't— I'll be honest with you, I don't see many red teamers getting up to be CISOs. It's not really where they end up landing. I'd almost say stick to your guns and be an engineer for a while. Get that technical acumen or run the sysadmin or be a Linux admin for 2 or 3 years. then make the transition over into the security practice. That way you can ensure that your foundation is set in technology before you go off and learn the new security discipline.

33:57Chris RomeoAnd that's— that'll serve you so well. Like, I'll completely second what you just said here. I got my start in the world of technology as a sysadmin, and some of the things that I learned back in the mid-'90s are the foundation for what allows me to understand new technology that somebody sets in front of me. Because I understand, and I was forced to learn how TCP/IP actually works at the different layers and what's kind of happening behind the scenes and forced to understand how Linux works. It just changes your whole view when somebody brings something new to you. You're like, oh yeah, yeah, I understand. You know, tell me the 5% that I don't understand. I already have the 95%. That's, that's the kind of background or foundational stuff that gets you to the 5% of the cool new thing.

34:46Marc FrenchAnd I'll be honest with you, Chris, you know, as I look at career ladders that I put together for AppSec folks in the past, I don't have a junior level in there. You know, if you think 6 career ladders— junior, regular AppSec, senior— I don't actually have the first 2 levels in my career ladders because I am always a firm believer that you have got to set your chops in technology before you can actually be an AppSec person. So if you are not coming in with solid foundations in engineering practice, you really don't— you are really not going to be a successful AppSec person. So I don't— my career ladder starts at level 3. There is no level 1 and 2 for AppSec, where that is not true for my GRC folks and for my infrastructure folks.

35:32Chris RomeoYeah, I mean, I'll even take it a step further and say, as an AppSec person, you gotta know at least one language, for example. It's kind of a core skill that you bring to the table here. And it's— some people have made statements like that. Back to your controversial statements, I'll throw one of my own out there. I've heard some people say that everybody in security should know how to code. Which, I don't know, what's your take on that, Mark?

36:01Marc FrenchI would say for GRC-focused people, maybe not. But for infrastructure people, you better start learning. Because the reality of it is, is that is all transitioning from blinky boxes to infrastructure as code. And the way that gets going to— the way that's going to get deployed and managed going forward is going to be through automation. So if you don't know how to code Python or some other thing like that, you are going to be at a big disadvantage in the way things are going to go forward. So, you know, for GRC folks, maybe not. For guys that are working the physical security desk, maybe not so much. But if you're in that kind of traditional infrastructure security role, you better learn how to code fairly quickly because your job is going to require it if it already doesn't. And I think For AppSec people, absolutely, sir. You gotta know how to code. Most of the time I'll require most of my folks to know at least 2 languages. Right now they tend to be like JSON and some variant of a mobile app, or I hate to say it, Java.

37:06Chris RomeoNo, I mean, you know, Java, we hate on Java a lot, but one of the things I like about Java as a starting point is You have to understand object orientation for any language these days. And wherever you get that from, I find Java to be a good place to start to learn about object orientation because you can learn it. I feel like with JavaScript and some of the other languages, you can quickly get caught up in the language and the web kind of front end of what you're trying to do. Whereas in Java, you can really pull back and have to deal with, you know, what does it mean to have an object? and to have methods and constructors and all these type of things. That I find is things that— that's a foundational thing we want people to understand. Once you understand that, you can read code in almost any language when you've got that foundation.

37:59Marc FrenchYeah, and I'll even go back to way back in my history. One of the best jobs I've ever had, I was a C++ kernel developer. Talk about getting the foundational aspects of If you can code C++ at the kernel level, you can pretty much code anything. Let's be honest. I'm kidding. It's been a long time, but that served me well as a foundation for my programming practice.

38:25Chris RomeoYeah, one bug there and you're basically blue screening in the Windows world or causing a kernel panic and restarting the whole system. So you get a whole new appreciation.

38:37Marc FrenchYou get a whole new appreciation for buffer overflows at that point.

38:41Robert HurlbutAnd I think that's good advice about certainly about programming. I mean, I, you know, that's where I came from as well. Longtime programmer switched into security. But even, you know, the college students I was talking to, they were doing Java or they're learning Java rather in their college programs. And they said, why am I having to learn this? You know, this is— I'm going to focus on you know, cybersecurity and be a CISO? I'm like, well, no. You know, it's good background. And so I think that really is good advice even for students as well to consider.

39:15Chris RomeoI think of everything through the crawl, walk, run approach. And so I think about learning Java, that's part of the crawl approach to becoming an AppSec person or becoming a security executive. And there's going to be other steps along the way, but you definitely have Crawl. You know, when you have a new baby, they don't just all of a sudden stand up and sprint across the room as fast as an NFL football player. They crawl, they walk, and then they run along the way.

39:40Marc FrenchAll right. So, I'm going to ask you, what do you consider run, my friend?

39:43Chris RomeoRun from what perspective? Now, you got to qualify the question a little bit more.

39:48Marc FrenchSo, you said that you consider Java the crawl part. So, what would you consider the run part?

39:54Chris RomeoI would say that the run part is going to be— it's going to be a lot of secure coding. knowledge and ability to implement. It's going to fit into that. Secure code review from a position of knowledge is also going to be a big part of the run from my perspective when I'm thinking specifically AppSec.

40:14Marc FrenchYeah, I would agree. If you can sit down with a set of crypto implementation code and do a thoughtful code review, you're probably running at that point.

40:26Chris RomeoYou're probably past running if you're able to play at that level of code review and understand what's actually happening with crypto primitives and all that type of stuff.

40:37Marc FrenchSo, you know, education, I would say for those students, I'll be honest with you, it doesn't really matter what degree you get. I hate to say that, and that's probably gonna run afoul of many of the programs that are set out there for cyber. I'll be honest with you, some of the best folks I've ever hired in AppSec didn't have a technology degree. You know, they had a music degree or a philosophy degree. It's really about attitude and aptitude for it. So don't feel that you need to get stuck taking a hardcore computer engineering degree. I think if you got the right attitude about learning and you got the aptitude to do it, you can be an AppSec person. So don't get yourself wound around the fact that you need a tech degree to do that.

41:21Chris RomeoAnd you mentioned, Mark, a few different times that you mentor various people, and Robert and I are both big believers in that idea of mentoring the next generation of security professionals. And I know a lot of folks across the industry are of that same perspective as well. Any advice you would offer for folks As far as how they best connect with a mentor or how they find somebody to help them in this journey?

41:49Marc FrenchSo your, your network is probably your best bet. And don't be afraid to reach out. I know a lot of folks, sometimes they see the title of CISO and they don't want to reach out to folks. I don't want to bother that person. But you'd be surprised, most of my peers are more than willing to help folks that ask. So don't be shy, you know, if you see something. And you guys can reach out to me, I'll just put it out there. So I've got a Twitter handle, @AppSecDude. If you have any questions or thinking about stuff, just reach out on my Twitter account. I'm pretty good about responding back. Um, it's part of what we all need to do in order to drive this practice. Just don't be afraid to ask.

42:33Chris RomeoAnd Mark, thank you for joining us today and sharing your experience as a security executive and all of your experience in AppSec. I got— this is actually an area that I didn't have a lot of knowledge and experience of what actually goes into being a CISO. And so it's been very beneficial for me to get this perspective from you as a practitioner who's been there. So thank you for sharing this with our audience, and we'll definitely have you back again in the future. some time to talk about something else related to AppSec.

43:04Marc FrenchThanks, Chris.

43:06Chris RomeoThanks for listening to the Application Security Podcast. Our intro music is 8-Bit Kung Fu by Born and TJ, and our outro music is Southern Delight by Stefan Cartenberg. You'll find the show on Twitter @AppSecPodcast or on the web at www.securityjourney.com/application-security-podcast. You can also find Chris on Twitter @edgeroute and Robert @roberthurlbut. Remember, security is a journey, not a destination.

7,770 words · transcript by assemblyai

More on Careers in AppSec

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.