<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Calling all Security Engineers in Career Discussions</title>
    <link>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8020#M649</link>
    <description>&lt;P&gt;I don't think there is such a thing as "an ideal day".&amp;nbsp; The first time you think you got one of those, a zero day hits you hard.&amp;nbsp; You think it was an ideal day and you've just been owned.&amp;nbsp; I've gotten to the point where I try to make things safer today than they were yesterday.&amp;nbsp; I try to learn something in the process or help someone else learn something.&amp;nbsp; Since there is no way to secure a network 100%.&amp;nbsp; I also trying to do packet captures and look for odd stuff.&amp;nbsp; Every now and then I will throw in odd stuff to see if anyone finds it.&amp;nbsp; It helps to keep them focused and it becomes a bit of a challenge.&amp;nbsp; When someone finds enough of the "odd traffic" I'll give them a day off.&amp;nbsp; Then they are telling me what they need to do the job better, they are trying to learn the software better and so on.&amp;nbsp; I'm not sure if that answers your question but I hope it helps.&lt;/P&gt;</description>
    <pubDate>Fri, 02 Mar 2018 04:54:33 GMT</pubDate>
    <dc:creator>Bertikus</dc:creator>
    <dc:date>2018-03-02T04:54:33Z</dc:date>
    <item>
      <title>Calling all Security Engineers</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8016#M647</link>
      <description>&lt;P&gt;Hey folks -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am looking to operationalize and mature our security group. We have some engineers that are fantastic, but a bit unfocused.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking for feedback on the ideal day for a Sec Engineer. This means a day where you have all the data you need and the ability to do your job to the optimal level. Some specifics:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's involved?&lt;/P&gt;&lt;P&gt;What do you have access to, and what is just provided?&lt;/P&gt;&lt;P&gt;What roadblocks that normally exist are no longer present?&lt;/P&gt;&lt;P&gt;How are you growing and developing daily, and longer-term?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Mar 2018 20:59:33 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8016#M647</guid>
      <dc:creator>Jslaughter</dc:creator>
      <dc:date>2018-03-01T20:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: Calling all Security Engineers</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8020#M649</link>
      <description>&lt;P&gt;I don't think there is such a thing as "an ideal day".&amp;nbsp; The first time you think you got one of those, a zero day hits you hard.&amp;nbsp; You think it was an ideal day and you've just been owned.&amp;nbsp; I've gotten to the point where I try to make things safer today than they were yesterday.&amp;nbsp; I try to learn something in the process or help someone else learn something.&amp;nbsp; Since there is no way to secure a network 100%.&amp;nbsp; I also trying to do packet captures and look for odd stuff.&amp;nbsp; Every now and then I will throw in odd stuff to see if anyone finds it.&amp;nbsp; It helps to keep them focused and it becomes a bit of a challenge.&amp;nbsp; When someone finds enough of the "odd traffic" I'll give them a day off.&amp;nbsp; Then they are telling me what they need to do the job better, they are trying to learn the software better and so on.&amp;nbsp; I'm not sure if that answers your question but I hope it helps.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 04:54:33 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8020#M649</guid>
      <dc:creator>Bertikus</dc:creator>
      <dc:date>2018-03-02T04:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: Calling all Security Engineers</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8024#M650</link>
      <description>&lt;P&gt;Information Technology&amp;nbsp;is continually evolving, vulnerabilities are being discovered,&amp;nbsp;&amp;amp; threats are emerging --- so&amp;nbsp;the 'ideal day' for a security engineer would be a holiday.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let's look at the answers to your questions in terms of what's expected, rather than typically encountered: -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) What's involved?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;The security of the&amp;nbsp;organization’s entire IT infrastructure, scoping ALL of its components and users.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) What do you have access to, and what is just provided?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Monitoring systems drawing real-time information from the IT infrastructure --- with the information properly analyzed and automated response mechanisms for alerts produced --- adequate visibility of operations, and a range of sources for vulnerability&amp;nbsp;alerts.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) What roadblocks that normally exist are no longer present?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;A lack of support from senior management and / or a lack of resources (people, processes &amp;amp; technology) to secure the organization.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4) How are you growing and developing daily, and longer-term?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Learning about, encountering and responding to new systems, threats &amp;amp; vulnerabilities.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the desired circumstances may not be present, the only time a security engineer might be able to avoid having to deal with&amp;nbsp;any inadequacies would be while on a holiday.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 08:00:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8024#M650</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2018-03-02T08:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: Calling all Security Engineers</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8039#M654</link>
      <description>&lt;P&gt;Let's try to focus your question a bit, shall we?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One way or another most of us have some type of tool set to do our jobs. With that note those tools may not be ideal for what we would like but tools can be very expensive to out right free. No excuses for blaming our lack of any tool to perform our tasks at hand.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A successful day starts with a full night's sleep, no phone calls the night before or first thing in the morning BEFORE I get to work. Second, no one waiting at the door for my arrival. This is not untypical. I have folks who start work before I get out of bed by practice, if not work ethic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I agree with the other posts concerning making things better than the day before but no amount of preparation and diligence will stop every bad actor, every day. We fight the good fight or wallow in delusion. The choice is up to you.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 15:42:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8039#M654</guid>
      <dc:creator>Beads</dc:creator>
      <dc:date>2018-03-02T15:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: Calling all Security Engineers</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8065#M660</link>
      <description>&lt;P&gt;Some very good answers above, so I'm enjoying this thread. I would just add that I think an ideal day might have these two elements:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-- A day where we can work on a more proactive basis. Not buried by governance sort of tasks or babysitting scans - but doing more work that justifies the word 'analyst' in a job title. A day that ends feeling like we maybe moved the needle even a little bit on the overall security maturity or posture of the place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-- A day where we make good headway on establishing or improving an important process - one that hopefully makes us more efficient and/or effective tomorrow.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Mar 2018 20:47:43 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8065#M660</guid>
      <dc:creator>jordanpw</dc:creator>
      <dc:date>2018-03-03T20:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: Calling all Security Engineers</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8115#M667</link>
      <description>&lt;P&gt;Jordan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the post. Good information here, for sure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You mention the idea of making a difference and moving the needle a little bit each day. For you, is there a specific area where you would say is the most fulfilling part of your day as a Security Engineer/Analyst?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you define as babysitting?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there reports you want to see, versus noise you could do without?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jonathan&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 15:26:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8115#M667</guid>
      <dc:creator>Jslaughter</dc:creator>
      <dc:date>2018-03-05T15:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Calling all Security Engineers</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8116#M668</link>
      <description>&lt;P&gt;Beads -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fair point. I get the reality of the daily threats for sure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for the start of the day - good sleep and no late night calls are a definite consensus.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you start your day, what do you immediately want to have at your finger tips? What type of Threat Intelligence should be provided to you to make your day the most effective once you sit down?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How much of your day would you say should be directly "fighting the good fight" versus personal/professional development and hitting the growth edge of your skills?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jonathan&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 15:29:56 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8116#M668</guid>
      <dc:creator>Jslaughter</dc:creator>
      <dc:date>2018-03-05T15:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: Calling all Security Engineers</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8118#M669</link>
      <description>&lt;P&gt;Shannon -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the details in your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I understand from your note is that a key component is the intelligence at your fingertips, and fully ready for use.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What does that ideal intelligence stack contain? Do you have a favorite set of applications or tools (i.e. Splunk, Guardacore, etc.)?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 15:32:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8118#M669</guid>
      <dc:creator>Jslaughter</dc:creator>
      <dc:date>2018-03-05T15:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: Calling all Security Engineers</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8128#M673</link>
      <description>&lt;P&gt;jslaughter&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a number of things that would fit into the 'most fulfilling part of the day' category - a few top of the head would be: being involved in hardening reviews and seeing hardening changes made as a result of those (so a little less chasing down same vulnerabilities caused by same installed apps/services); talking or working with application/system owners who get it, or are beginning to get it, in terms of thinking about security a little more - I had an application owner say to me today that rather than updating an app version he might just see about removing it "to make the attack surface smaller" - it's awesome hearing that phrase from an app owner; evaluating and recommending cool new tools, especially when it's just getting more out of free or built-in tools (eg Sysmon, Windows Event Log Forwarding); and learning. There's always so much to learn - about our own environment, and about ICS in general&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Babysitting - I was mainly thinking about just the volume of scans that need to be run, and sometimes kinda being a slave to getting them done and then having less time to really think on the results or the bigger picture.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Honestly, overall I enjoy my work, our work, tons. I go to work most every day pretty happy with what I need to get done, and enjoy reading, watching videos etc on work-related topics out of hours too. Having said that, shockingly I still manage to have a life as well - spend time with family, get out with the dog, play some sports etc.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 00:43:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8128#M673</guid>
      <dc:creator>jordanpw</dc:creator>
      <dc:date>2018-03-06T00:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: Calling all Security Engineers</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8136#M674</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To answer your&amp;nbsp;1st question, &lt;A href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1446087431" target="_self"&gt;&lt;SPAN class=""&gt;Jslaughter&lt;/SPAN&gt;&lt;/A&gt;, the ideal stack consists of at least 2 categories of information ---&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Norms &amp;amp; Baselines&lt;/STRONG&gt;&amp;nbsp;-&amp;nbsp;What's expected to happen. (What&amp;nbsp;should&amp;nbsp;be done, by whom, how, and when)&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Real-time information&lt;/STRONG&gt; - What's&amp;nbsp;actually happening. (What is being done, by whom, how and when)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A&amp;nbsp;SIEM / monitoring solution will give you the latter, but to effectively use this, you&amp;nbsp;must correlate it with the former&amp;nbsp;--- to&amp;nbsp;perceive&amp;nbsp;existing&amp;nbsp;threats &amp;amp; foresee potential ones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not in a position to answer your 2nd question,&amp;nbsp;as my&amp;nbsp;current role (Information Security Officer) has me dealing with security policies, enforcement, compliance and risk management, with little exposure&amp;nbsp;to the use of solutions, for which we have dedicated roles.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 06:31:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/8136#M674</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2018-03-06T06:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: Calling all Security Engineers</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/9644#M813</link>
      <description>&lt;P&gt;I can give you my view as a Mainframe Security Engineer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For my role in our company is defined as maintaining and managing risk for our platform in addition to providing direction for our ID ADMIN team.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My typical day consistent of vulnerability management, report generation, meetings (my leadership, IRM, IAM and Audit) and training.&amp;nbsp;&amp;nbsp; Being the only CISSP on our team as well as the team lead it falls to me to train others on my team as well as training to other engineers (not only security but our OS, Network and tower engineers)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I typically start by pulling all the latest vulnerability reports as well as IBM Alerts specific to mainframe.&amp;nbsp;&amp;nbsp; these are reviewed, logged, tracked until resolution.&amp;nbsp; Dashboard are prepared for leadership as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other aspects include scheduling of A&amp;amp;P test for our platform.&amp;nbsp;&amp;nbsp; While A&amp;amp;P test typically go in-eventful one item recognized for us is we have no down time.&amp;nbsp; Day is online processing and night is batch processing.&amp;nbsp; both of which run the company.&amp;nbsp;&amp;nbsp; an outage due to a scan is not acceptable so they are planned for least impact times and systems&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Project work is another area where IRM/IAM are making many changes and as the Security Engineer for our platform it falls to us to implement these items correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Training is usually handle via working sessions.&amp;nbsp;&amp;nbsp;we identify an area we need work on then have a daily working session on it where we present the issue, work on how to solve it and then have one or more of our team implement it.&amp;nbsp;&amp;nbsp; we use these as training because most my team are not engineers, they are learning.&amp;nbsp; so they are being taught engineering principles in these sessions&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other training consist of topics like vulnerability management.&amp;nbsp; process management.&amp;nbsp;&amp;nbsp; out reach for our local users groups and attending training like our RACF users group which is our security product..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;right now we're working on STIG compliance and developing the skills and tools to provide that compliance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope some of that helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sandra&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 12:44:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/9644#M813</guid>
      <dc:creator>smgvbest</dc:creator>
      <dc:date>2018-04-23T12:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: Calling all Security Engineers</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/9668#M815</link>
      <description>&lt;P&gt;I have to say that my day as a Security Engineer is rarely scripted or even the same day to day.&amp;nbsp; I do seem to have more meetings than deemed healthy for sanity, but Project Managers seem to only exist within the context of a meeting or TSP report.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Frankly, my charter is to 1) Serve as the go between (aka Translator) between the IA and IT staffs; 2) Try to solve the technical problems&amp;nbsp;of conducting business and maintaining a reasonable security posture;&amp;nbsp;3) Talk the PMs off the ceiling whenever they hear that the cheapest solution still&amp;nbsp;has a cost; 4) Ensure that solutions are installed and configured correctly, and stay that way; 5) &amp;nbsp;Explain to engineers and developers why we cannot simply make the firewall any-any, set file permissions 777, use TELNET, RSH, etc..., or run CRON jobs as root. 6) Explain the same ideas to Windows SA's, but gentler so that I don't hurt their feelings. 7) Try to train the security staff to look for a solution, or at least talk to me, before saying No!; &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; Write justifications (ROIs) for my boss for any expenditures for tools; 9) Spend 2-3 times as much money and time as the tool would have cost&amp;nbsp;on labor and time trying to make the "same&amp;nbsp;thing but free" that some&amp;nbsp;budget manager heard about at his off-site team building&amp;nbsp;leadership retreat in the Poconos. 10) Review scan reports, mitigation reports, track action&amp;nbsp;items&amp;nbsp;to completion. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are a bunch of other things that go into my day. Many of them frustrating. Some of them rewarding. Rarely the same. But, I really like this job for the challenges it gives me every day. I look forward to coming in and trying to solve a problem. I don't mind staying late to make sure something is working as intended. I get to learn new things as well as teach. A good day for me is when I feel like I have accomplished something.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 18:30:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/9668#M815</guid>
      <dc:creator>Zonker</dc:creator>
      <dc:date>2018-04-23T18:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: Calling all Security Engineers</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/9737#M826</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's involved? Being in a security conscious culture helps or an environment that supports you actively working to increase the security posture.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you have access to, and what is just provided?&amp;nbsp; You have access to training material or able to travel to seek out unique training opportunities.&amp;nbsp; &amp;nbsp;Support from senior management and infrastructure teams is another bonus.&amp;nbsp; Visibility into operational procedures is another plus.&lt;/P&gt;&lt;P&gt;What roadblocks that normally exist are no longer present?&amp;nbsp; Visibility into systems or operational procedures may be the largest roadblock that is no longer present in our environment.&lt;/P&gt;&lt;P&gt;How are you growing and developing daily, and longer-term?&amp;nbsp; Working toward helping developers receive additional training quarterly as a mandate and delivering more training in-house.&amp;nbsp; When you can leverage your in-house security engineer talent to deliver training they feel valuable to the organization.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 16:15:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/9737#M826</guid>
      <dc:creator>canLG0501</dc:creator>
      <dc:date>2018-04-24T16:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: Calling all Security Engineers</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/9744#M828</link>
      <description>&lt;P&gt;&amp;gt; We have some engineers that are fantastic, but a bit unfocused.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;nbsp;Looking for feedback on the ideal day for a Sec Engineer.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Have you taken a look at any project management frameworks or tools?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please don't take&amp;nbsp;any of the following as a negative or a criticism of you; this is not personal -- my replies are process motivated only.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The first thing I would generically suggest is not to be passive/reactive about this, be active.&amp;nbsp; Meaning, if your staff needs focus, if you need to know an ideal day, define it first and then plug the resources into it.&amp;nbsp; Generally, service providers, and you are one, don't have a template day -- that's production speak.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you've ever read any of the Situational Leadership stuff, recall three basic things about human behavior:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1.&amp;nbsp; All people are motivated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2.&amp;nbsp; All people are motivated for their own reasons (yes, even slackers are motivated -- see #1).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3.&amp;nbsp; No matter how hard one tries, you can never ultimately motivate people for your OWN reasons.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;That, is also, the difference between leadership and management... but I digress.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;One way to align a group of high performing but unfocused staff is through team building and accountability.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have two thoughts for you off hand that are cheap to implement and pay big dividends.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt; As another disclaimer, I understand some of what I'm going to write isn't trivial.&amp;nbsp; Services organizations seem to have more challenges in the areas you mention than production organizations.&amp;nbsp; But if one really looks at the situation without preconceived notions, they&amp;nbsp;can see where parts of frameworks&amp;nbsp;are applicable to their business&amp;nbsp;processes and in turn leverage the cool stuff!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1.&amp;nbsp; One technique you could use is document the work in kanban.&amp;nbsp; It's basically a board which says what work is upcoming, which work is in progress, and which work is completed.&amp;nbsp; Make the board public.&amp;nbsp; Make the team accountable for it -- at all levels.&amp;nbsp; The team should operate as a team and not a hierarchy&amp;nbsp;of pay grades and job titles from a basic service provision perspective.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In kanban, if you have an unfocused employee -- there's no excuse for that anymore; they see the work they need to do (it's publicly&amp;nbsp;posted), their teammates do too, and as staff progresses tasks from in-work to completed, they'll eventually&amp;nbsp;get into the habit going to the upcoming work side of the board and starting a task on their own.&amp;nbsp; They'll do that without team lead intervention and they'll have a lot of pride about it because&amp;nbsp;they are executing autonomously (which is going to free you up for other things too).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;An additional benefit is the team sees the work, the entire process is transparent.&amp;nbsp; They will all own it.&amp;nbsp; That's a very powerful motivator.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2.&amp;nbsp; Have you looked at any SCRUM methods?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Implement a morning stand up, no more than 15 minutes and&amp;nbsp;with all team members.&amp;nbsp; During this stand-up, go around the circle and have each team member publicly talk to the team about what they accomplished yesterday, what they plan on doing today, and to escalate any barriers.&amp;nbsp; This is a very powerful tool --&amp;nbsp;few people want to be a slacker in such an environment where they bring nothing to the stand-up while all their teammates are voicing their accomplishments.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I hope this helps.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 18:39:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/9744#M828</guid>
      <dc:creator>mgoblue93</dc:creator>
      <dc:date>2018-04-24T18:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: Calling all Security Engineers</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/9804#M838</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/783078713"&gt;@Shannon&lt;/a&gt;;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good call.&amp;nbsp; I'd have to second your response:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Norms &amp;amp; Baselines&lt;/STRONG&gt;&amp;nbsp;-&amp;nbsp;What's expected to happen. (What&amp;nbsp;should&amp;nbsp;be done, by whom, how, and when)&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Real-time information&lt;/STRONG&gt; - What's&amp;nbsp;actually happening. (What is being done, by whom, how and when)&lt;/LI&gt;&lt;/OL&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;In my experience, the "tools" are the team that you interact with.&amp;nbsp; If you're conflating "Engineering" with all of the operational tasks like configuration management, auditing, monitoring, and incident response - even longer term analysis, then you're probably not doing the essence of engineering.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Apr 2018 20:22:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Calling-all-Security-Engineers/m-p/9804#M838</guid>
      <dc:creator>Baechle</dc:creator>
      <dc:date>2018-04-25T20:22:38Z</dc:date>
    </item>
  </channel>
</rss>

