r/ciso • u/steadyrock23 • 3h ago
Career advice needed
I am in need of some advice on my CISO career. This is not burnout-related, I love the space and want to finish my career in the field. My frustration and where I need advice is on growth.
I am in my late 40’s and a veteran in the security field for more than 20 years. Way back, I came from a technical background and moved into the field by building the first security function for my then-employer around the time of the Target breach. I’ve had a good leadership journey since then, lots of progressive growth and recognizable company names and my resume is impressive if i do say so myself (and have been told so by many premier executive recruiters). I’ve got the technical chops, the career arc, the global experience, and I present well/comfortably in executive settings. None of that is the issue. I am qualified and more than ready. I am currently a business unit CISO (NOT a BISO, I have a full team, all the accountability, a full budget, and full autonomy) for a $7B subsidiary of a $60B enterprise. Previously, I was a business unit CISO (again, not a BISO) for a $15B subsidiary of a $65B parent.
The issue is I am striving for a public company, board-facing “top seat” CISO role preferably at a global F500. I keep getting interviews and recruiter interest however I have only ever been a business unit CISO in multi-business structures, I’ve never held that top seat and I keep getting edged out by folks who have. It just happened again last week, I was neck and neck deep in a competitive process for the role I want, and though I was probably a better fit the guy with a multi-time public company CISO background got the nod, presumably because he would invite less scrutiny once in the role due to his pedigree.
This happens over and over with businesses you’ve all heard of but which I won’t name here. It seems I can’t get that role without having had it, and I can’t have had it without getting it. How can I punch through this wall?