{"id":9479,"date":"2026-09-14T08:25:00","date_gmt":"2026-09-14T08:25:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9479"},"modified":"2026-09-14T08:25:00","modified_gmt":"2026-09-14T08:25:00","slug":"how-to-level-up-from-security-pro-to-security-leader","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9479","title":{"rendered":"How to level up from security pro to security leader"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">There comes a time in a cybersecurity professional\u2019s life when being a tech expert is no longer enough. The next step may lead to management or the C-suite, but the goal demands a different kind of expertise.<\/p>\n<p class=\"wp-block-paragraph\">Technical skills will continue to serve a new CISO well, but the role demands additional capabilities built on that foundation. That may mean prioritizing investments amid tight budgets or helping business leaders weigh the security tradeoffs behind a product launch.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe strongest CSOs and CISOs are the ones who can confidently translate technical risk to business priorities,\u201d says Chad LeMaire, CISO at ExtraHop. Without that ability, technical depth can become \u201ca career ceiling\u201d instead of a competitive advantage. \u201cPresenting solely as the most technically skilled person in the room may actually hold CISOs back,\u201d LeMaire adds.<\/p>\n<p class=\"wp-block-paragraph\">An <a href=\"https:\/\/www.sciencedirect.com\/science\/article\/abs\/pii\/S0167404825000525\">analysis of CISO job postings<\/a> found that employers value education in STEM or business fields and vendor-neutral certification, but they also want to see strong communication skills and knowledge of regulatory frameworks. In contrast, job listings placed little emphasis on mastery of particular security platforms, coding ability, or security clearances.<\/p>\n<p class=\"wp-block-paragraph\">The study also highlighted CISO responsibilities and requirements. Taken together, they portray the CISO as a <a href=\"https:\/\/www.csoonline.com\/article\/3626973\/cisos-embrace-rise-in-prominence-with-broader-business-authority.html\">business strategist and organizational leader<\/a>, not the person expected to handle day-to-day technical work.<\/p>\n<p class=\"wp-block-paragraph\">The CISOs must build trust, communicate clearly, and collaborate without slipping into the \u201cIT guy\u201d posture, says John Harbaugh, CISO at BlueVoyant.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIn my career, I\u2019ve been very successful with the following: have a positive attitude especially under stress, assume best intent from people you\u2019re engaging with, and always take the high road, especially when trying to collaborate on solutions,\u201d he says. \u201cCheesy, but I\u2019ve found it to be super effective across my super diverse business and mission career.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Other effective skills are knowing how to read the room, keeping an open mind, and finding a good mentor. All these can help aspiring CISOs navigate uncertainty and build trust.<\/p>\n<h2 class=\"wp-block-heading\">Show up like you deserve to be there<\/h2>\n<p class=\"wp-block-paragraph\">Aspiring CISOs must enter the room as leaders helping the business goals, not as obstacles standing in the way. \u201cShow up in every room like you deserve to be there,\u201d says LeMaire. \u201cThe more conversations you listen in to, the more you can ladder security goals to align with overall business objectives and also align with legal, business development, employee engagement, and other departments.\u201d<\/p>\n<p class=\"wp-block-paragraph\">That extra knowledge can also help a future CISO take ownership of problems and use their technology background to develop solutions. Then, they need to explain those solutions clearly, so others can accept them.<\/p>\n<p class=\"wp-block-paragraph\">\u201cYou want someone who looks professional and, most importantly, acts and speaks professionally,\u201d says Ira Winkler, CEO and program director of CruiseCon. \u201cPeople need to present confidently. They need to speak concisely.\u201d<\/p>\n<p class=\"wp-block-paragraph\">But while it\u2019s important to look professional, overdoing it can be a mistake. \u201cI was on shift work at NSA, and one entry-level analyst always wore a suit to work,\u201d Winkler says. \u201cHe was dressing for the role he wanted<em>.<\/em>\u201d Most managers, though, saw it as an attempt to curry favor, while his peers found it alienating.<\/p>\n<p class=\"wp-block-paragraph\">Colleagues and friends can help an aspiring CISO spot habits and blind spots. When Winkler tried to raise venture capital for his company, he had little experience with the process, so he listened closely to his advisors.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe investment banker I was working with told me that I need to stop using the filler word honestly,\u201d he said. \u201cIt sends people the subliminal impression that I was otherwise lying.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Be a good politician<\/h2>\n<p class=\"wp-block-paragraph\">\u201cCISOs need to be able to articulate security needs and investments in a way that will resonate with various leaders and audiences,\u201d LeMaire says. \u201cLeading CISOs will be the ones who explore how security and technical decisions are connected to business goals and objectives.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Harbaugh agrees. \u201cA CISO needs to know how to be both a good politician and a good business partner,\u201d he adds.<\/p>\n<p class=\"wp-block-paragraph\">Another skill is <a href=\"https:\/\/www.csoonline.com\/article\/3625745\/how-cisos-can-forge-the-best-relationships-for-cybersecurity-investment.html\">building relationships across departments<\/a>. CISOs depend on developers, operations teams, legal, finance, and business leaders to manage risk, so <a href=\"https:\/\/www.csoonline.com\/article\/4217607\/stop-playing-with-the-ciso-role-fix-cybersecurity-leadership.html\">influence often matters<\/a> as much as authority.<\/p>\n<p class=\"wp-block-paragraph\">\u201cYou can be an exceptional security specialist, but if you cannot build trust with those groups, influence decisions, and create shared accountability, you will struggle in a CISO role,\u201d says Anant Adya, executive vice president and head of Americas delivery at Infosys.<\/p>\n<p class=\"wp-block-paragraph\">Owning mistakes and sharing the lessons learned can help build trust. \u201cThat combination of accountability, judgment, and business maturity can actually strengthen the candidacy,\u201d LeMaire says.<\/p>\n<p class=\"wp-block-paragraph\">In fact, he advises aspiring CISOs to avoid looking \u201ctoo perfect\u201d during an important conversation or the job interview. \u201cThere is no such thing as a perfect candidate and the strongest CISO candidates are often the ones who can clearly say what they got wrong,\u201d LeMaire says.<\/p>\n<h2 class=\"wp-block-heading\">Never forget the importance of the business<\/h2>\n<p class=\"wp-block-paragraph\">Security professionals with technical backgrounds can easily become absorbed in technical details, but the CISO role demands a broader perspective. They need to understand <a href=\"https:\/\/www.csoonline.com\/article\/4080670\/what-does-aligning-security-to-the-business-really-mean.html\">how the company really operates<\/a> and how cybersecurity decisions impact the business.<\/p>\n<p class=\"wp-block-paragraph\">\u201cI have become a major advocate of getting an MBA,\u201d Winkler says. \u201cPeople need to understand business. If they want to be a peer of the CFO, CIO, COO, etc., they should have the same educational base.\u201d<\/p>\n<p class=\"wp-block-paragraph\">An MBA is not the only option for becoming business-fluent. Security leaders can also build it by managing budgets, joining complex projects, or gaining experience in product, operations, and risk roles. What matters is understanding how the company makes money.<\/p>\n<h2 class=\"wp-block-heading\">Have an open mind and keep learning<\/h2>\n<p class=\"wp-block-paragraph\">Curiosity is not optional for aspiring CISOs. Technology is changing quickly, so they need to stay up to speed. \u201cAI agents, APIs, and machine identities are growing quickly inside enterprises,\u201d Adya says. \u201cKnowing how to govern what they can access and do will become a valuable skill for future security leaders.\u201d<\/p>\n<p class=\"wp-block-paragraph\">A great CISO has experience outside cybersecurity. \u201cSpend time in data, cloud, software engineering, or operations,\u201d Adya adds. \u201cIt may feel like a detour but understanding how technology is built and used will make you a stronger security leader.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Harbaugh seconds this. He advises aspiring CISOs to approach difficult problems without preconceived answers and to stay enthusiastic about learning new technologies and supporting the business. \u201cBring a passion, not just a here-for-the-paycheck mentality,\u201d he says.<\/p>\n<h2 class=\"wp-block-heading\">Find a mentor. Or two<\/h2>\n<p class=\"wp-block-paragraph\">More than three decades ago, at the start of his career, LeMaire was fortunate to meet two people who are still his mentors. \u201cOne of the biggest lessons I learned is that leaders develop leaders,\u201d he says. \u201cMy two mentors were leaders who taught me how to lead, expected me to lead, then expected me to teach others how to lead.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Because of their mentorship, he was able to have a career as well. \u201cI owe a debt of gratitude and can only hope I was able to do the same for others,\u201d he says.<\/p>\n<h2 class=\"wp-block-heading\">Draft a career plan, but don\u2019t obsess about it<\/h2>\n<p class=\"wp-block-paragraph\">Ambitious security experts can easily become preoccupied with promotions and future titles. But sometimes an excessive focus on what lies ahead can create unnecessary anxiety and distract from what truly drives success: continuous learning, resilience, adaptability, and delivering meaningful outcomes.<\/p>\n<p class=\"wp-block-paragraph\">\u201cTrue leadership growth comes not from meticulously scripting a long-term career path, but from excelling in the role you hold today,\u201d Adya says. \u201cI embraced this mindset and chose to focus on doing the right things, taking on challenges and creating impact wherever I was.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Focus on the work itself, rather than following a rigid career plan, and the right opportunity will follow. \u201cThis approach played a significant role in my growth trajectory and helped open doors to experiences and leadership opportunities I could not have planned for in advance,\u201d Adya adds.<\/p>\n<p class=\"wp-block-paragraph\"><strong>See also:<\/strong><\/p>\n<p><a href=\"https:\/\/www.csoonline.com\/article\/4208210\/what-the-ciso-role-will-look-like-in-2029.html\">What the CISO role will look like in 2029<\/a><\/p>\n<p><a href=\"https:\/\/www.csoonline.com\/article\/4159317\/cisos-reshape-their-roles-as-business-risk-strategists.html\">CISOs reshape their roles as business risk strategists<\/a><\/p>\n<p><a href=\"https:\/\/www.csoonline.com\/article\/4200382\/how-cisos-can-rise-to-the-business-resilience-challenge.html\">How CISOs can rise to the business resilience challenge<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>There comes a time in a cybersecurity professional\u2019s life when being a tech expert is no longer enough. The next step may lead to management or the C-suite, but the goal demands a different kind of expertise. Technical skills will continue to serve a new CISO well, but the role demands additional capabilities built on [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9480,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9479","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9479"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9479"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9479\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9480"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9479"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9479"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9479"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}