My current workplace is going through significant transformation. That reminded me I need to do strategic career check-up. “If you want peace – prepare for war”, as they say. This year I did the check-up in form of reading the “Navigating the Cyber Security Career Path” book by Helen Patton.
Here is my review of the book.

Helen has worked as a security professional in multiple industries for multiple years, so it was interesting to see her perspective on the topic. The book was an easy read. It is unpretentious and grounded. I appreciate when authors focus on readers instead of boosting their own authority via complex language.
I have found no life-changing truth or big “A-ha!” moments in the text. Just a lot of ground wisdom, which we all need to be reminded of. With my age and experience, it is hard to find anything new and outstanding in the industry (technology excluded).
One unusual thing, though, the book is aimed at multiple audiences – from complete security newbies to experienced security leaders. It was ambitious, but I think Helen has done a great job addressing all them. Common sense is common across all experience levels.
Here are a few highlights that resonated with me:
“One of the biggest causes of conflict and stress when working in security is when others misunderstand what security is or why security people make the decisions they make… If you’re going to be part of or lead a security team, you need to be very clear about why you do it, what value it brings, and how security is a good thing. If you don’t believe this with the core of your being, you will likely burn out well before you can be successful.”
As I mentioned in the Security Architect Role article – If we do our security job well – nothing happens. It is hard to show clear value in the security profession if nothing happens, so Helen is spot on. The whole “The Stress of Working in Security” chapter is excellent, I think.
“Advise Them, and Then Let Them Decide…Your value is to provide solid information and advice to others who can choose to take it — or not.”
That is moving away from policeman to adviser role – mature and constructive approach. I much prefer adult/equal communication to bossy “comply with my requirements”.
“Define where your job stops and starts and what you can personally own. Make sure you’re not taking responsibility for security stuff outside of your role”.
That is a recurring pain point, steaming from the lack of clear value or deliverables in cyber security. It is too easy for the job scope to creep into “everything security”. Security is everywhere, and we can’t do everything.
“Find out your Why”
Great strategy. I am fortunate to know my Whys, for other people struggling, she refers to works of Marcus Buckingham, Donald Clifton, and Simon Sinek’s. I am not familiar with these sources, but I did not like Sinek’s TED talk – he claimed he found the simple formula of Apple success, which sounded naive.
“Talk to your manager. Let them know you want to pursue a promotion and ask them for guidance”.
That is a non-intuitive tip I learned long time ago. Your best ally for career development (not necessarily in the same company) is your manager. Too often, people search for opportunities outside of the current organization, and then surprise the bosses with the letter of resignation. Your boss can help you find opportunities outside of your organisation too!
“One way to keep self-doubt at bay is to keep a list of the things that went right. The list doesn’t have to be Big Things like significant projects or solving world hunger. It can be a daily, weekly, or monthly list of positive interactions with peers, deadlines met, and new things learned.”
I took that advise seriously. I created a “list of achievements” – however big or small, direct or indirect. It helps a lot with the sense of fulfilment, performance review and prevention of burnout. I need to fill it more often. For some reason I think I need to do something earth-shattering, or it does not matter. Every bit matters.
“Find a manager or two and interview them about their jobs. “
I remember I wanted to become a manager, and there was a position opening in my company. I approached the current holder of the position, asked him why he wanted to leave. His answer was “I want to have life”. Needless to say – I did not apply for that role 🙂
One interesting insight from Helen was that middle manager position is the hardest one. She says “you will be evaluated both for your individual technical outcomes as well as the success of your team as a whole.”
“Know your manager: Explicitly ask how they like to communicate.”
On the first day of a job my manager asked me to do something. He was very polite, and his ask sounded like soft optional thing, rather than firm request. I said “no”, and he did not look happy 🙂 I have asked him to be always direct with me and tell things as they are, promised I’d do the same for him. He was happy, and it was the beginning of a very long, constructive relationship. I remember another stakeholder, which did not like my directness and perceived me as harsh, so I have adopted my communication style with them accordingly. Another successes story. Different people have different communication styles, better establish the communication preference early.
I also found “How Can I Know If It’s Time to Move On?” and “How to manage security strategically” chapters well-written.
So, would I recommend this book? Yes, I would, especially for people starting out in cyber security. For more mature professionals – it is full of things you’d probably already know, but it is good to be reminded.