Concern around the cybersecurity talent gap continues to ratchet up: The industry is short an estimated 4 million professionals and there are currently more than 572,000 open cybersecurity positions.
But that’s not to say that there isn’t interest.
In his role as chief security officer (CSO) at Hewlett Packard Enterprise (HPE), Bobby Ford said he is often contacted by people looking to get into the field, but they have “a barrier in front of them.” So, as he likes to say, the industry isn’t dealing with a talent shortage — but, rather, an experience shortage.
To break down these hurdles to entry, HPE last year launched its HPE Cybersecurity Career Reboot program, which seeks out talent in unlikely places. The initiative saw a surge of interest from the start, with the majority of participants going on to careers in cybersecurity, many at HPE.
“If we’re to make a dent on the cybersecurity talent gap, we must create talent, not just take
it from other organizations,” Ford, who helped conceive the program, told SDxCentral.
The initiative “recognizes that talent can come from a non-traditional path, and that formal degrees or prior cybersecurity experience aren’t always necessary.”
A win-win for both prospective talent and HPEHPE launched the reboot program “based on the belief that the greatest gift you can give someone is an opportunity,” said Ford, adding that he himself has been gifted with opportunities “that have changed the course of my life.”
Also, it could be a win-win: The initiative would provide HPE with a reliable worker pipeline.
Ford explained that the company focused its messaging on what candidates “did not need to have” (other than a desire to learn and a positive attitude).
“With this mindset, the talent pool becomes an ocean,” Ford said. “In the two years that we have been doing this, I can say confidently that we have discovered people with unique and valuable experience who would most certainly have been overlooked had we employed conventional hiring methodologies.”
Diverse backgrounds provide strong base for cybersecurityFifteen people have passed through the program over the last 18 months, coming from a diversity of previous careers including school bus driver, restaurant owner, respiratory therapist, nurse, military serviceperson and stay-at-home mom.
Ford noted that, “while there is of course much to learn in a new field, we have found many parallels between the skills formed in these careers and the ones needed to be successful in cybersecurity.”
Ford said that 80% of the first cohort have found jobs in cybersecurity and 60% of that same cohort are now working at HPE. One “rebooter” has since gone on to manage the initiative. Participants have landed jobs in areas such as cybersecurity compliance, cyber automation engineering and program management.
“This experience allowed me to not only learn an immense amount of information, but it gave me the gift of time and patience to absorb and apply all that I was learning,” Leah Dalton, a participant in the first cohort, told SDxCentral.
She explained that she has a background working with computers but has been out of the workforce for “quite some time.” She has since earned multiple certifications in the field and gained strong foundational knowledge of cybersecurity.
“This has been a pivotal program in my life because it opened the door for me to build the career I wanted, my way,” she said.
Hands-on training as well as theoretical learningHPE's Cybersecurity Career Reboot Program spans six months. Participants are placed in a team that aligns their interests and aspirations with HPE’s business needs. They tackle projects in areas including data analytics, security operations and compliance.
“This project-based work approach ensures that they get hands-on experience within various cybersecurity functions in addition to theoretical learning,” Ford explained.
HPE also funds industry certifications and provides mentoring from vendors and in-house experts in specialties such as cyberattack prevention and crisis management.
Furthermore, participants have the opportunity to engage in volunteering and activities “beyond the strict confines of cybersecurity training,” and they have access to employee resource groups.
Cherisse Lamb, a member of cohort two, was previously an English teacher, but decided to embark on a new career “driven primarily by the need to escape the grasp of teacher burnout,” she told SDxCentral.
Many of her family members work in the industry and they encouraged her to explore the field, she explained. She has since delved into product security and cloud security and has earned top certifications including Certified in Cybersecurity by ISC2, Security+ from CompTIA and the Certified Cloud Practitioner from AWS.
“This program has been a turning point in my life,” she said, “and will have a lasting impact for not just me, but my entire family.”
A ‘permanent and critical’ part of HPE’s cybersecurity strategyFor its first cohort, the program received 100-plus external applications, driven almost entirely through word of mouth.
“As it turns out, many of us know of someone who could benefit from an opportunity,” Ford noted.
The second cohort, meanwhile, was flooded with 750 applications for just 10 positions — and this within just two weeks of its announced enrollment.
Ford said the initiative is a “permanent and critical” part of HPE’s cybersecurity recruitment strategy. The company will bring in 10 more participants in its third cohort this winter, and there is opportunity to expand into additional geographies, different HPE functions and partnerships.
In two years, Ford’s goal is to have the programs scaled across the company and bringing in 10 times the participants.
Not act is too small; celebrate all winsUndoubtedly, HPE is a large enterprise with the resources to launch and manage such a program. Still, Ford noted that “there are so many other great ideas being executed out there.”
If security leaders are interested in exploring new avenues for talent recruitment, “just know that no act is too small,” he said.
It could be something as simple as looking at job descriptions and auditing for unreasonable expectations and bias. Or, explore opportunities for upskilling from within and sharing stories of employees’ non-traditional paths.
“Take small wins and use them as momentum,” Ford said..
Comments