Why is the majority of security management just unqualified bodies in a position of authority? The majority know nothing about info sec nor hold industry certifications. These people would be unable to get any type of information security job at other companies but we put them in leadership positions. We are talking people with accounting, Ad Services, and software Developer backgrounds who didn’t properly secure API’s etc. They have their more qualified analysts speaking for them and attending meetings because the manager is incapable of speaking to what occurs on their own team.
I’m waiting for the bonus before I bolt to Dell or VMWare for a leadership position.
Thanks for my 30k in certifications and training that now has other companies contacting me on the reg for more money.