My Security Leadership Journey So Far
Sep 18, 2019
I have been fortunate enough to have been building and running the Information Security Program at Hulu for almost three years and I felt it would be appropriate and hopefully educational that I shared my experience and journey so far. There are plenty of articles out there for what a newly minted CISO should do or what experienced CISOs should do during their first 90 days.
While the guides are extremely helpful by providing some sort of structure, everyone’s journey is different and that is perfectly fine. Sharing my experience will hopefully illustrate how different one’s journey can be and that you can still survive even if you are taking your own path or steps along the way.

Congratulations! You’ve been hired to run an Information Security program
It’s exciting times! If you have just accepted an offer to become a CISO of an organization that has a small/no program or you’re a newly minted CISO for an organization that has somewhat of a program and you’re panicking right now, we’ve all been there. The panic is real and the thoughts of whether or not you’re good enough for it will kick in and will not stop for a while (if ever).
What worked for me during my initial days at Hulu was to get to meet with different teams and people (at different levels). Getting to learn the organization and hearing perspectives from both individual contributors to leadership was great. Getting that full context is beneficial as it only enables you to come up with complete proposals or understanding of where things are. A lot of times the perspectives between leadership and from those with boots on the ground are completely different.
Don’t judge and only ask why to help you understand. It’s very easy to come into an organization with a set of experiences and expectations that may be at a higher level of maturity than your new organization. Ask why to help you understand but don’t ask why by assuming the decisions made were not the right ones. Learn the context and restrictions that lead to the decisions being made. For example, when joining an organization that is carrying a lot of tech debt, you are not helping anyone by questioning decisions. Everyone knows the baggage, work with them on helping them reduce the debt.
Empathy goes a long way. When learning the levels of risk of the organization and inherently the appetite towards those, show some empathy particularly with those leaders and members of teams of the areas where the most risks are introduced. Put yourself in their shoes and understand their limitations. Ask them how current status looks compared to desired and dig in from there. Throughout my career I have yet to meet someone who has decided to introduce risk and shown little to no care about it.
Build trust by focusing on quick wins. Identify low hanging fruit items or items of critical risk that must be addressed and you’re confident your non-existent or small team can accomplish. Solve for those then move on. This gains you confidence (self) but also trust from within your peers and leadership. For example, at Hulu, I quickly identified that social engineering attacks were high and very successful. We quickly implemented an email security solution that not only reduced the risk but also benefitted everyone by reducing the amount of spam people were receiving.
Find yourself some allies. During the early days of my tenure, I quickly realized that there was no way my team could solve security concerns by ourselves. Benefiting from the conversations with stakeholders and feedback from my team, I learned that there were huge operational resiliency concerns. Identifying this, allowed me to gain some allies but combining the benefits of security to operations and resiliency. At Hulu, using resiliency allowed us to tie software security metrics with QA (functional) metrics. Combining security and functionality into the overall quality picture helped us bridge gaps between engineering, software testing, and security. Don’t try to fight the fight alone, I’ve found that people are always generally interested in helping out. When that’s not the case, I imagine it’s because there is no reason to.

Now that you have a program running, what do you do?
Once a security team, security processes, partnerships are established focus on getting the organization to drive small but continuous improvements. As Mike Johnson, a very talented CISO who I have the privilege of knowing and sharing ideas with (You can listen to his knowledge sharing here), says
Do not let perfect get in the way of better
Design your security organization in a way that it becomes a business enabler. When it comes to organizational design, I’m a believer of optimizing for processes and communication. To me that meant that I had to learn what Hulu, as a business, was asking from its security program. Understanding this allowed me to design an organization that met each aspect of the business with processes and products that support those intake of requests.
Hire good leaders. Once your organizational design is done, find good leaders for each of those newly formed teams. What I look for in my leaders are people who share the same leadership philosophy and the approach of how to build and grow teams. Bring leaders who can scale but also be mindful that these leaders are not operating at a level where there’s a large gap between their present and that of your organization. Empower them with trust and authority. Share your vision and enable them to execute.
Build products that scale. The sooner you realize that your teams are there to deliver security products (these can be technical or procedural), the better. At the end of the day, security is a customer service function. Design and deliver products that solve actual problems and continue improving upon them so that your efficiency is scaling alongside the rest of the business. But please make sure that you are first solving the basics before moving on to next generation things.
Trust your teams. To me, this is the most important and critical aspect of running a security program. I have learned with experience that if you set the tone with your teams that they are allowed to take risks and independently decide on how the vision must be accomplished, your teams will innovate. Jointly celebrate wins and allow the teams to fail fast. Allow your teams to try to touch the stars and celebrate if they are able to touch the moon. At the end of the day, any step towards improvement, is a huge leap when it comes to solving security problems at scale for an organization.
Empathy. Empathy. Empathy. Cannot stress this enough. Work with your leadership, peers, and stakeholders. Understand that you depend on them as much as they depend on you and your teams to deliver. Security is the job of everyone. If you turn it into a battle, you’ll be alone in the battlefield with sword in hand while watching everyone else move on.
Rinse and repeat. We must love this job and industry for us to be in it. Getting an organization to be secure should not be an end goal as it is not a static state. Risk management initiatives, that get us to a secure state of mind, is a path. As your organization continues to move down its strategic goals (and hopefully with growth), this path will take different directions. Security is about repeating that mindset of improvement. Don’t give up when things fail, use those as learning opportunities. Don’t give up if you find yourself doing things again and again as long as every time the organization has taken one more step at ‘being secure’.

Trust me, you are not alone in this journey
Security is constantly trying to solve problems that have no static solution. With a technology world that is continuously innovating at an unprecedented fast pace, there is no way that all security questions are answered. In fact, most of the times even doing the basics is difficult or almost impossible. One thing that always keeps me in check (and satisfies any sign of imposter syndrome) is by talking to peers. I have been lucky to surround myself with some of the best security professionals out there. Especially because those who I communicate quite often with, also believe in empathy and recognize they have been there before.
Surround yourself with knowledge and trust. Learn from others, regardless of how experienced they are (or lack of). Keep an open mind to new concept and approaches. I always operate with a mindset of ‘I could be wrong’. This has allowed me to expect to not be the smartest person in the room and actually embrace it and find synergies in ideas and concepts given to me by others.