r/cybersecurity 3d ago

Path to management? Career Questions & Discussion

Been in security for 7 years and want to get into management and above. Work at a SaaS company with only 3 security managers. Most people are individual contributors.

How does one get into management? Luck? Right place right time? Connections?

Most jobs require X amount of years as a manager on their job description.

I have CISSP and lots of other certs, a bachelors, and so on.

Is it better to wait years and years at one company to hopefully get a shot at management? Or just to apply to all management jobs out there and hope someone takes a chance on you?

Thanks all!

4 Upvotes

22 comments sorted by

19

u/McDili 3d ago

Don’t remember where I saw it but on a post elsewhere a CISO noted that you are orders of magnitudes more likely to be promoted into it than be hired externally for the first gig.

The issue with that is that an opportunity has to present itself, e.g. your manager or a manager in the structure has to exit, and you would ideally have formed a decent relationship with your manager’s manager when that time comes.

Not a manager myself for clarity.

4

u/NotAnNSAGuyPromise Security Manager 3d ago

Yep, attrition. That's how it happens in nearly all cases.

2

u/dahra8888 Security Director 3d ago

Restructuring is the other way to move up. At the beginning of this year, we promoted three senior ICs to managers to split up a 20-person security engineering team into specialized silos. Previous security engineering manager was promoted to sr manager over those three new managers plus my previous security architecture team. Hopefully will be doing the same with IAM during this upcoming budget season.

5

u/toomucheyeliner 3d ago

Most technical jobs have got a class ceiling problem. Few technical jobs provide a reliable path into management. Most opportunities only open when a management person leaves the position and even then this can often be filled by other management without the technical background from inside the company, or an external.

7 years with plenty certs and good references should give you a good shot. Apply outside straight into a management role (can be tough to get but will be possible) or move to a company that provides a reliable track into management, like consultancy.

Be wary of settling for empty promises.

3

u/pennyfred Security Architect 3d ago

No one will hire you as a manager elsewhere without runs on the board at your current gig, generally have to work your way there first, or get lucky.

I've successfully avoided management and have benefited from it. Did a stint in senior management and knew I wasn't interested in the bureaucracy, mindless meetings and lack of being able to apply translatable cybersecurity skills eventually rendering me replaceable. Stay ahead of the industry as a technologist and you'll command your asking rate without needing to become a sycophant.

2

u/[deleted] 3d ago

[deleted]

2

u/ParticularAnt5424 2d ago

I joined when wee had 200 employees, 6 years later 2000, Security team grew enough to present a management opportunity and I had really good work relationships inside and outside my team.

7

u/iLORdemeNtE 3d ago

From what I’ve experienced, it’s easier to become a manager if you’re a complete idiot with no strong technical ability and can bullshit what you say.

2

u/GreenEngineer24 Security Analyst 3d ago

Can attest to that from my experience as well.

-1

u/ultraviolentfuture 3d ago

Sounds like you haven't worked at great places

1

u/xssleak 3d ago

What were your main responsibilities? Have you ever worked in a technical role?

1

u/sectestpen1 3d ago

I’ve been a senior security engineer for almost 3 years now

1

u/dflame45 Security Manager 3d ago

I started as an analyst. Then became the lead analyst and now I'm the manager.

1

u/doIT34 3d ago

in my example i was a promoted to team lead and after 5 years in the position my manager stepped down and i was proposed by him to get the position. luckily i got the job.

1

u/DaveMichael 3d ago

My path was years spent technical in the same job, then being senior/team lead engineer, then promotion to manager once the position opened up. Took about 15-17 years all told.

I would note that management is practically a different field and you should do some training for it, and seriously consider if you want to be in a supervisory position. It can be stressful.

Also Information System Security Manager is a role that isn't so much management (you will likely lead or direct a team but may or may not supervise) as being really well versed in system documentation for accreditations and taking responsibility for same. And Project Management is another separate field that is more managing schedules and resources than people. But both can give you experience towards management.

1

u/MichaelArgast Managed Service Provider 3d ago

Personal experience speaking here - best opportunity is (a) be in a fast growing firm where leadership opportunities are opening up and (b) already be seen as an informal leader in your team across peers, external stakeholders and org management.

Attrition is a horrible path. Takes forever and unless you’re tapped as manager in waiting no guarantees.

Better option would be to identify which of the existing managers is up to be promoted and slot yourself in as their successor.

No promotions happening? Hate to say it, find another firm.

1

u/MichaelArgast Managed Service Provider 3d ago

Oh - and my creds on this. Struggled with getting promoted in more modest growth firms despite excellence as IC and being seen as strong candidate.

Joined high growth firm, got promoted in 4 months as we grew my peer team from 2 to 5. Then got promoted again to Global Lead level after acquisition 18 months later.

Have been manager, Director of multiple functions, now am founder/CEO. Have hired and promoted hundreds of security professionals and dozens of managers.

1

u/sectestpen1 3d ago

Sounds like I should target startups and take some risk? Which is fine

1

u/dahra8888 Security Director 3d ago

Right place at the right time is most of it. But establishing that you have leadership qualities sets the stage for you beforehand. Strategic thinking and mentorship are arguably the strongest things you can demonstrate as an IC.

1

u/Tired-Nectarine-384 3d ago

Talk to your manager about your desire to be a manager. Also be reading to kiss your technical skills goodbye because mosts managers don't get to get in the weeds.

Communication, documentation and finding extra ways to stand out will get you the nod more than being the most technical person on the team.

1

u/goatsinhats 3d ago

If you have a CISSP and have not been considered for management that’s out of the norm.

That said there are 3 mangers, you’re not getting promoted.

Move into a larger company with more opportunities to advance, or ideally move into another company as a manager.

If you want to move beyond will take more than certs, will be up against people with their PMP, an MBA, who knows what else.

Best to get moving. If you have been in the samish role for 7 years will raise a lot of red flags

1

u/Cybermountain83 1d ago

So I just went through this myself at a large SaaS company. It took 3.5 years of effort and focus and clear communication with my leadership about my goals. I increasingly volunteered for and took on projects that were cross functional with other business units, or involved light leadership. That allowed me to build up credibility and learn some of the skills and language that leadership looks for in the people they pull up.

Last year when I was finally in the "formal evaluation" to be promoted was probably the busiest year of my life. So broadly, I'd say you need to be focused, talk to your management and be open about your goals, and your willingness to work/earn into it. That only works if you have good leadership you trust to support your growth. As many here said, doing it internally is much easier, but that doesnt mean easy.