CISO Recruiting is Broken
March 2, 2025
Nearly 2000 applications in 2 weeks to a single CISO role paying $200K-225K/yr. All that "demand" for cybersecurity talent we've been told about for years - wherever it is, it's not in the leadership echelon.
Granted, most recruiters - at least the ones posting real reqs as opposed to "ghost jobs" - agree that the vast majority of applications to desirable title roles tend to be unqualified. Sure, "Easy Apply-itis" and "aspirational application syndrome" count for a good portion of this chaff.
The larger issue is we really don't know how to hire for CISO roles. We know how to hire for CFO, CMO, CPO, CIO, and CEO roles. What's the measure of a "good CISO?"
- Didn't have any major breaches in the last 24 months (that they/we know of)?
- Spent a large budget on the latest shiniest vendor toys?
- Ran a team of X personnel?
- Got sponsored by vendors to speak at major conferences?
- Demonstrated alignment with business objectives? (my favorite)
- Didn't buck too much when fitted for the patsy suit when the SEC came calling about all those clean 10K/Q filings followed by a massive breach?
We write these job descriptions like some kind of abstract painting: a bright splash of technical skills, spots of leadership and management, strokes of compliance and incident response, a dash of communications skills and executive engagement, and whatever else the pallet holds just sprinkled around the canvas till it's sufficiently filled in.
Somehow, 25 years since the advent of the CISO title (RIP Steve Katz), we're still struggling to agree on what a CISO is actually supposed to be doing. Strange, isn't it?
hashtag#CISO hashtag#recruiting hashtag#jobsearch hashtag#cybersecurity hashtag#leadership hashtag#security