Black Hat 2018: Retaining and Promoting Women Cybersecurity Staffers

A great deal of time and effort is dedicated to trying to boost the number of women in cybersecurity, but not enough is placed on retaining and promoting the women already in the field, said Ashley Holtz, a forensic and security expert with NBCUniversal.
In her session "The Science of Hiring and Retaining Female Cybersecurity Engineers" at Black Hat 2018, Holtz boiled down the results of more than 100 reports conducted worldwide on the topic of women working in engineering and cybersecurity. She found, for the most part, that women want the same thing as men: job security, a chance to be promoted and fair pay. But there are other factors that come in to play, such as flexible work hours and feeling supported by the company.
However, the problem starts right out of the gate with the hiring process. Holtz said companies interested in increasing the number of women workers need to post job openings where women will see them and to ensure the description is not only gender neutral, but accurate.
“The job description language needs to be relevant to the role and inform an applicant how the company supports its workers,” said Holtz, formerly a services engineering manager at Crowdstrike.
Holtz noted that many job postings contain skill sets which are not really needed to do the job in question, which deters many qualified people from applying. In addition, to interest more women outside the field, it might be necessary to open up the experience requirements of applicants, she said.
Once the hiring process is completed, the next issue is retention.
“Seventy-four percent of women report loving their work, yet these women are leaving their careers at a staggering rate,” she said, noting that after 30 years on the job only 19 percent of women engineers are still in the field, compared to 39 percent of men.
Holtz did discount some of the usual excuses given for this, such as leaving to start families, saying studies show only about 20 percent of women leave the workforce entirely and most of those do not cite motherhood as the reason.
Some factors that help retain women are recognizing and rewarding their contributions equally with their male counterparts, equal pay, treating all employees the same after taking a leave of absence, training managers to notice harassment and unfair treatment, and empowering all workers to speak and advocate for themselves.
Once women are successfully retained, the next step is ensuring they are promoted up the ladder, Holtz said.
To accomplish this task, women must be actively sponsored and mentored by people who can help them reach their goals. Additionally, leadership goals should be advertised internally for all to see, and executives need to have the proper metrics to evaluate their female workers.
Finally, companies should not push women into non-technical admin and project lead roles, when they can instead be considered for technical lead roles.
Source: scmagazine

Latest Jobs
-
- Infrastructure (Network / Security) Engineer | West London commutable | Permanent
- London
- Apply today
-
Infrastructure (Network / Security) Engineer | West London commutable | Permanent This is an in house opportunity. Looking for someone that has on prem / data center experience MUST be a currently hands on config, Install, upgrade, troubleshooting experience Routing, Switching, Network Security (firewall, IDS etc), Microsoft Active Directory / 365. VMWare Scripting / automation experience wanted. Python, Powershell etc Must be commutable to West London twice a week. Visa sponsorship not available. Apply today for more information Book a call via this link https://calendly.com/d/crqf-t28-7tb
-
- Identity & Access Management Architect
- Edinburgh
- Upto £95000 plus bonus and benefits
-
Location: Edinburgh | Hybrid Working | Permanent Are you an experienced Identity & Access Management professional with a passion for designing and implementing cutting-edge security solutions? We are looking for a Lead Architect, where you’ll play a key role in helping clients enhance their IAM capabilities, protect critical data, and navigate complex security challenges. About the Role As a Lead Architect, you will be responsible for shaping and delivering IAM strategies, designing robust security solutions, and driving long-term digital transformation. You’ll leverage your expertise to provide strategic guidance on areas such as: Identity Governance & Administration (IGA) Privileged Access Management (PAM) Access Management (AM) Entitlement Management Directories & Authentication Solutions You will have the opportunity to work with innovative technologies and frameworks, ensuring that businesses can securely manage access to critical assets while enabling growth. What You’ll Be Doing Providing subject matter expertise in IAM and leading transformation projects for clients Developing IAM roadmaps, operating models, and governance frameworks Driving innovation by integrating IAM capabilities into wider digital transformation strategies Building and maintaining strong relationships with clients and stakeholders Designing and implementing scalable IAM solutions to meet business needs What We’re Looking For Proven experience in IAM strategy, solution architecture, or assurance Strong leadership skills with experience guiding technical teams Ability to work in a client-facing role, delivering clear communication and insights A technology-focused, innovative mindset with strong business acumen Willingness to work from our Edinburgh office 2-3 days per week
-
- Security Architect - Cloud - Consultancy London
- London
- N/A
-
Security Architect with a focus into Cloud (AWS, Azure or Google Cloud Platform) needed. You must have client facing consultancy experience. This mean you must have experience working with clients helping them to meet their security design needs. That could include working with existing internal teams to understand, review and mitigate / uplift existing Cloud Security designs, or perhaps helping clients set out / understand their current needs and deliver their cloud security strategy. (Or anything in between) Technical knowledge is of course essential but working with clients to understand and solve their Cloud Security design challenges is vital. You must obviously have a current history working as a cloud security architect. You will need to be commutable to London. Whilst a hybrid role the expectation is 3 days a week in the office / meeting clients. International relocation or Visa sponsorship isn’t available for this role. Apply on this page and arrange a call here https://calendly.com/d/crpz-m7j-wyx