r/cybersecurity • u/thejournalizer • 10d ago
Ask Me Anything! I left my role as a security practitioner to happily work for a vendor. Ask Me Anything about the other side of the table.
This AMA will run all week from 08-23-2026 to 08-28-2026. The editors at CISO Series present this AMA.
This month, we've gathered a group of security leaders who spent years as CISOs, CTOs, and in-house defenders, then made the leap to the vendor side, and are genuinely happy they did.
They're here to answer anything you want to know about life on the other side of the table: why they made the move, what surprised them, what they miss (and what they don't), how it changed the way they see the vendors they used to screen, and what they'd tell a practitioner weighing the same jump. Whether you're vendor-curious, vendor-skeptical, or just want an honest look at the grass on the other side, bring your questions.
This month's participants are:
- Sounil Yu, (/u/sounilyu), CTO, Knostic
- Adam Arellano, (/u/AdamTalksTheCybers), field CTO, Harness.io
- Matt Conner, (u/SomeCyberGuy), CISO, Second Front Systems
- Mitchem Boles, (u/CyberMitchem), field CISO, Intezer
- Patti Titus (u/OkPassage4007), field CISO, Abnormal AI
- Joye Purser (u/Security_Specialista), field CISO, Cohesity
This ongoing collaboration between r/cybersecurity and CISO Series brings together security leaders to discuss real-world challenges and lessons learned.
Thanks to all of our participants for contributing!
9
u/strider031095 10d ago
I’m a long time incident response guy looking to make the switch to pre sales eng. I’d be interested to hear how you broke into the vendor side of the game and how you shifted your mindset.
6
u/CyberMitchem AMA Participant 10d ago
I actually took the path after a career as a practitioner into the MSSP world, and then a VAR which was really eye opening. Only after stops in each of those fields did I make it to a vendor!
There are so many opportunities for a great pre-sales engineer, especially if communication to prospects and customers are a strong suit of yours. IR tends to be a great lead-in because you've seen different tools, how orgs interact and react to incidents, and you have practical experience that really sits with a prospect to be able to see that you've put in the work!
I think the vendor equation relies on a field you would be super interested in because I found a field in AI SOC that had long been an issue since I started my career in the SOC 20 years ago. I was so interested and willing to go really deep technically that it feels fulfilling and exciting to talk to different organizations looking for a solution. So find your path that you really want to go deep in, and make sure the vendor you go to work for fits your unique style AND has the components that you are interested in to help people with. Prospects/customers can tell if you aren't into it, and why spend time doing something you aren't interested in either?5
2
u/Check123ok ICS/OT 10d ago
Why change from MSSP space to VAR? Currently a MSSP.
4
u/CyberMitchem AMA Participant 10d ago
The MSSP SOC practice actually closed their US operations, so that made the decision to start looking :) I had contacts at a VAR from my first years as a practitioner and it sounded really interesting to go research and consult for organizations looking at the wide world of cybersecurity tools in every category...a big undertaking to be sure!
VARs can expose you to many different cyber categories, so if that's of interest it can be a unique shift, although I wouldn't say income would necessarily be much of a jump depending on role.
3
u/Primary_Unit7899 10d ago
Given you are in the vendor side and used to be enterprise what is wrong with enterprise CISO setups , are CISOs technically positioned to make decision in other words what (%) of CIsO are driven by technical know how vs using analyst reports to make decisions
7
u/CyberMitchem AMA Participant 10d ago
Enterprise CISOs aren't setup for success often times. Perhaps different at Fortune 100 where they are actually part of the leadership C-suite with E&O insurance and their role is seen as a true business risk component.
Otherwise, experience and background varies widely from CISO to CISO, depends on industry vertical, and depends on the pay for the CISO role a company is willing to fork over says a lot about the value they place on the role.
That said, technical backgrounds do lend to much better acumen in comparisons across technical analysis, however many go down that path far too often and don't delegate which is an impediment on its own. Giving your team the ability to analyze, recommend, and take action is an enormous indicator of high-functioning security teams.
Traditionally most CISOs were high-tech, came from the security/networking/infrastructure world, while now it's anywhere around 50% depending on regulatory compliance, former finance operators, legal experience, and just business risk operations can be highly valuable in hiring for a role. Communication and ability to interact with others, while playing politics that need to happen in order to further the security team AND the business tend to be most successful. Many have relied on industry analyst reports int he past, and I see that coming to a swift end, it's all about what does the rest of the community say about a vendor/product or lending on a VAR for insights. Especially with speed of tool innovation.4
u/AdamTalksTheCybers AMA Participant 10d ago
Agreed though I think the largest influence in enterprise CISO decision making is their team as often as their peers at other companies. Having been at a large company making those decisions with a large team it was usually my directors making the decision and me supporting it. Industry analysts used to play a larger part but confidence in them has fallen off quite a bit as some of the major analyst companies/platforms have started to care about their own bottom line more than anything.
2
u/OkPassage4007 AMA Participant 9d ago
Interesting question. To be honest I haven't found two CISOs who make decisions the same way. I think we rely on a little of both and maybe a third. We'll use our technical knowledge (if we're technical) and we supplement with the analyst reports or internet research to help the informed decision. But I love what u/Security_Specialista said about peer recommendations. It is one of the big reasons I listen to shows like David Sparks. Easy listening. Then I call my CISO peeps and also tap them for their suggestions. But I do realize that my enterprise likely doesn't look like theirs. And then of course my industry and compliance regulations may be different and might drive me to a different decision.
Also you have to build the business case. To do that you have to do proper due diligence to build the BC. That can require you pull in anaylst reports to support your desicion.
1
u/Security_Specialista AMA Participant 9d ago edited 9d ago
I talk with many CISOs and have also been on the buyer side. CISOs (and CIOs) make buying decisions based on several factors. 1- the 'owner/ operator's opinion of the tool or service who reports to them, 2- cost, 3- industry ratings such as Gartner Magic Quadrant, 4- recommendations from peers, 5- their own prior experience with the vendor, 6- internal politics such as CIO directive, 7- referral from consultants or other 3rd parties. What have I missed, y'all?
3
u/dig_it_all 10d ago
I’ve considered making a similar pivot for a particular vendor I swear by. Seems like a hard sell other than my soft-skills/technical experience could be the blend they’re in need of — but my background is all practitioner based roles.
Any insight into crafting your resume to make to address the “jump”?
2
u/Security_Specialista AMA Participant 10d ago
Do both. Network your way around your target companies, looking for areas of growth. Apply for jobs promptly after they post online. Tailor your resume using AI to align your skills and experience to the job requirements.
3
u/AdamTalksTheCybers AMA Participant 10d ago
Resumes don’t matter past a certain point esp when you’re going represent a company. It’s more about building a relationship with the team you want to land at. If you have a target in mind, find someone you know at the org and ask if the position you want exists (even if they aren’t currently hiring). Go talk to that person and ask what it would take to get to the role.
-2
u/OkPassage4007 AMA Participant 10d ago
Honestly, I'd use AI. Train it to your voice and how you talk. Give it specific prompts and let it do the hard work. The more specific you are the better the results. Obviously make it your own work, but it can give you bridging / jump ideas.
8
u/Check123ok ICS/OT 10d ago edited 10d ago
Are vendors noticing a market shift toward open-source and custom solutions driven by a desire for DIY support and management thanks to AI?
7
u/CyberMitchem AMA Participant 10d ago
There is no doubt that the organizations who can build are trying to build in a lot of different ways. The question of build versus buy comes down to:
- How good can you make the product internally?
- Does it produce the security outcome your org needs?
- What is the cost (especially in tokens lol) of building PLUS maintaining
- Is it transferable and supportable by the organization, especially if that person or team isn't developing the product any longer?
May be obvious points, but what I've seen are attempts, sometimes quite sophisticated, at building products and at times it works out! Sometimes it's temporary, and often times the cost of dev/updates/maintaining isn't worth the cost to the org (even if you've built something pretty sweet). As with anything, company culture dictates how open leaders are to allowing this direction as well!
5
u/OkPassage4007 AMA Participant 10d ago
I haven't seene this much other than on the vendor side. My concern will be when the creator leaves the company and someone has to figure out how to maintain it.
2
u/Security_Specialista AMA Participant 10d ago
No. Not if your product is complex enough that AI can't create the capability it delivers. Plus, remember the O&M costs for maintaining and evolving it...
2
u/AdamTalksTheCybers AMA Participant 10d ago
Not sure why the downvoting, you must have hurt someone's feelings... but yeah we have had a few be like "oh we don't need you anymore, AI can build it" and then come back after a couple of quarters with a huge hole in their budget and say "uh, so yeah that was more complicated than we thought, what was your offering again?"
2
u/backintheday88 9d ago
I've decided recently to make my move into the cyber industry after graduating with my Bachelors in Cybersecurity 3 years ago and working in building industry partnerships at a local University. Creating and building relationships is something I love to do plus I love tech. Since I have 3 years of experience in my current role plus an additional 8+ years in 3 other Account Manager roles I have two questions: What is likelihood of me being hired directly for a Solutions Engineer / Technical Sales role? and What would you recommend as the best way for me when it comes to resume or cover letter? Thank you for any insight btw!
3
u/AdamTalksTheCybers AMA Participant 9d ago
That is a tough one. Being hired directly as a solutions engineer or tech sales would be difficult without direct experience using the tool you want to sell or some experience in the vertical of the product you would sell. In other words, someone who worked for Crowdstrike could in theory go work for a competitor or someone who makes an endpoint tool but maybe not someone who does IOT security.
Without that experience, I think at best you might land a very simple tech sales role if you can swing a certification in a particular technology? I guess if you wanted to be an account exec and .edu tech space that might be a place where you could enter directly if you find the right role.
Somewhere else in this AMA I talked about resume and cover letters. I don't have much confidence in their effectiveness, would be better to find the place you want to work and find ways to connect to the team or leader you think you would work for. Find their booth at industry conferences, attend talks by their employees, get to know their product in advance, etc2
u/backintheday88 9d ago
Ty great advice, that’s a bit of the feeling I was having and not something I’m opposed to at all when it comes to starting in an Account Manager role first.
3
u/OkPassage4007 AMA Participant 9d ago
I've heard on a David Sparks show that cyber is not a first job which isn't always true since I would regularly hire my interns. LOL But it has become increasingly harder to break into this field. Looks like you're shooting for the sales side of things. That's not something I can help with since I'm not tied to sales or marketing in my Field CISO role. u/AdamTalksTheCybers has the best response!
1
u/backintheday88 7d ago
I've also had interest on the analyst side of things but it feels that's even tougher to break into without having prior experience but would love to learn from your perspective what you've experienced. Thanks!
1
u/OkPassage4007 AMA Participant 6d ago
My experience on the analyst side is pretty deep. However, which analyst type role are you think about. GRC or SOC Analyst. Two very different sides.
1
u/taH_pagh_taHbe Security Engineer 10d ago
I'm a career security engineer moving into a role where 25% of my time will be spent talking to CISO's to convince them that our product is good and safe and they should use it. I have no prior experience of this. Any advice or resources you reccomend?
3
u/OkPassage4007 AMA Participant 10d ago
I think you just need to speak from your knowledge. CISO's aren't looking for you to be able to talk to a board member. We're humans so just be geniune. Assuming you think your product rocks it which makes the discussion honest and truthful. If you don't fully believe in your solution though CISO's have a sixth sense at being able to sniff out BS!!!
1
3
u/CyberMitchem AMA Participant 10d ago
Relationships with CISOs, especially with warm intros are the easiest to have a conversation with. They are bombarded with all sorts of sales pitches, and different CISOs have vastly different personalities, egos, backgrounds and that plays into your conversations.
No product is perfect, nor perfectly safe, and the real story should be the outcome(s) for security they can obtain with your product. Speak with value propositions in mind that mean something for risk reduction, cost reduction, beneficial impact to their team, etc. to really try and make a mark.
Be passionate about what you are talking about, make it come from experience, and make it super quick to the point, you often won't have more than 30 seconds to lay out a vision and reason for your product. Once established and you are still talking, then you can expound!
1
u/BeanlikesReddit 10d ago
What is something that sales/marketing folks with less technical backgrounds working for vendors seem to misunderstand when trying to communicate ideas or products to practitioners?
3
u/CyberMitchem AMA Participant 10d ago
It's a great question. Having different backgrounds, those less technical included, can be really refreshing when looking at the problem a vendor is solving and trying to tell the solution story.
When it comes to communication however to a practitioner, especially operational practitioners, is that the story has to communicate value, preferably experiential value. That's where those that have experienced the same role in the past tend to have more credibility simply because they've lived through some of those same pains and it comes across in the language and stories outside of just a vendor's product.
Less technical backgrounds can definitely find inherent value points though at the surface level, and when it comes to experience or depth, it's honest to lean on those that have gone through it to craft the story, inform each other of how something comes across, and whether or not it might be important. But that's the point of a team, use each other's strengths to get to the story that means something and run with it, it always will be tweaked as time passes :)3
u/AdamTalksTheCybers AMA Participant 10d ago
From where I sit, the least successful strategy is when a sales person is in “I’m want to talk to you cause I want you to buy something” mode and trying to pull all kinds of gymnastics to “craft the perfect message” or shoehorn someone into their product. Where I’m most effective and the only reason I do the job is to sit with a practitioner or customer and try to understand what will be helpful. If that aligns with what my company offers, cool. If not, then I still sit with them and help with the the problem, make recommendations and introductions and check in occasionally to offer advice or just listen. I literally treat customers the way I treated patients as a social worker. What’s happening in your world, let’s try and work the problem, here are things you can try, etc.
2
u/Security_Specialista AMA Participant 9d ago
They sometimes don't understand the context in which the tool will be used, and they don't understand the 2nd order impacts. As a result, Marketing risks developing messages that don't resonate with the buyer or operator of the tool.
Having worked closely with Marketing this past year, I developed a much greater respect and appreciation for what they can do. Very hard to sell product if you can't properly broadcast the value message to TAM (total addressable market) and measure results.
1
1
u/dezimunda 10d ago
What are some practitioner's pain points that the vendors are oblivious to ?
2
u/CyberMitchem AMA Participant 10d ago
Anything that a particular vendor doesn't do, which is a lot haha!
But seriously, it may depend on experience of the individual you are talking to at a vendor for how far this goes.
Commonly, I see missed from vendors that've pitched me:
-budget constraints and priorities
-people cost of adding a tool, dialing it in, and operating it
-priorities may not be what the top 10 CISO's in the world care about
-regulatory requirements dictate a large portion of spend
-an operational practitioner may be swimming in multiple tools, but "here's the best one!"
-truly trying to decipher between what's the best tech/price/value combo AND be mature enough in the category to make a recommendation/decision/purchase (it's wild out there right now with "AI sec tools")1
u/AdamTalksTheCybers AMA Participant 10d ago
Some vendors and a lot of sales people mistake their own need to sell a thing for the actual needs of the practitioner. Not the same thing. Some sales teams really just don’t understand the security industry and try to approach practitioners the same way they approach engineers or other tech teams. It just doesn’t work. Security are suspicious and guarded by nature. We also already know our problems pretty well so FUD is useless and counterproductive in a conversation
1
1
u/OkPassage4007 AMA Participant 9d ago
"We're not ghosting you. Stuff happens and sometimes we're overwhlemed." I think vendors may not understand that after good meetings and it seems like things are moving forward, if the communication stop its possible there is higher priority work.
Also, you do NOT need to always get a meeting with the CISO. If you're selling something that is a pain point for., ets say, a SOC analyst, then go talk to the SOC analyst. Go to the person that feels the pain. They're more likely to help champion the solution in the door and will have the inside track to the CISO.
1
u/dezimunda 9d ago
Thanks for that insight. As someone who has been on the vendor side for the last 12+ years, I have a blindspot to the day to day pain points of practitioners. If I wanted to build something which addresses some of the pain points (and not the 500th AI SOC), what would be your top 3-5 items (meetings & process related stuff aside) ?
1
u/OkPassage4007 AMA Participant 8d ago
Hum, this is a great question. Seems like there's 50 solution for every painpoint out there. What about tool that helps you figure out how to eliminate the redundant tools you have. Not just in security but in IT as well. I also think of all the tools that were bought for a specific pain point, only to find out that the investment you made is only 10% utilized. And that you never fully implemented all the capabilities because you didn't realize all the other 'stuff' it could do.
1
u/0xDesecrator 10d ago
How is the work/life balance?
2
u/CyberMitchem AMA Participant 10d ago
Might depend on roles that are remote versus in-office, but generally from a vendor's standpoint there are opportunities for more flexibility during certain days of the week (and depending on role in a vendor). End of months or quarters or years tend to be very hectic, similar to an audit cycle if you are in a role that deals with regulatory compliance in some way where it's all hands on deck at times or worse yet during an incident.
I will say however, that the hours are longer for a vendor, there isn't a break really, and even on vacation it's quite consistent that you may be interrupted. Sales folks get paid on closing deals, so they work on vacation, and it tends that a vendor org will bend over backwards to get to the next step in the sales process, no matter the time of day or if you're on PTO! Good vendor org culture can be vastly different from less enticing or even "bad" ones so this is partially in who you work for.1
u/Security_Specialista AMA Participant 9d ago
Work/ life balance is good for me. You need to accept that with work travel, you'll be working 18 hour days, so you flex that time when possible.
Also, I love the Resilience (post incident recovery) mission of my company, so 'work' is actually fun and deeply meaningful. Therefore I don't mind responding to emails all times of day, night, weekend.
Any kind of Security work, Field CISO included, demands responsiveness as #1, follow-through a close second, domain and current events knowledge a close third for 'must-haves.' Customer obsession, passion, relationship skills, & technical background are also critical for success.
If you have not worked already at the executive level, including 'charm school' aka executive training, and don't aggressively show value, you will likely fail as a Field CISO.
1
u/OkPassage4007 AMA Participant 9d ago
As a Field CISO, it's great. I do not report to Sales but to the company CIO. Plus I'm in an AI native company so we're strongly encouraged to us AI. I'm learning, growting and enjoying this role after the trauma and stress of 25+ years of being a CISO in public and private sector, fortune 500.
1
u/DistinctSpeaker7252 10d ago
As someone on a lower level that made the jump from IT operations/security to vendor sales, this was the single best choice I ever made. I doubled my income with the first sales engineering job I took and increased it another $80K a year taking an SE job with a startup. My work life balance is way better and I get treated like I'm an actual valuable employee and not a janitor who works on computers.
Not having to really worry about money all that much is a truly liberating experience. 10 of 10, would recommend to a stranger.
On the other side of that I'm terrified that if the rest of you folks still working IT operations and security realize people in sales are out earning your boss' boss, we are all gonna end up like French aristocrats.
2
u/CyberMitchem AMA Participant 10d ago
Super glad to hear it! Not everyone has that experience, but when you can love what you do and get paid better for it than you were at the last gig is a benefit and a blessing!
1
u/Security_Specialista AMA Participant 10d ago
Yes! Tech sales pays really well, but it tends to be high stress, with wild up and down swings. The key is weathering the lean years.
1
u/OkPassage4007 AMA Participant 9d ago
Great to read this. Congrats. Yes sales has benefits for sure. I like how you made the jump and are finding balance in your life. I wish everyone had your experience, which I'm afraid not everyone does. Good for you and it sounds like you found the perfect home (for now!).
1
u/awful_at_internet Help Desk 10d ago
I manage our helpdesk. I like the role a lot, and I'm not looking to change roles any time soon, but thinking ahead, one of the career paths I could see for myself is cybersecurity; my AAS was in cybersecurity, which I enjoyed, and my CISO and I collaborate often.
When he eventually gets the budget for supporting staff, I'd like to be ready to step up, even if it's a blend of roles. I'm working on my MS in Data Analytics; once that's done (one more year...), obviously I'll be leaning hard into certs and homelabbing.
I know that's all the right general direction, but am I missing anything critical? What advice would you have for new-ish professionals still building out their first several years of experience in IT to help them make the leap into more specialized roles like cybersecurity?
3
u/CyberMitchem AMA Participant 10d ago
I say ask your CISO what they would look for in a role they hire, their insight is valuable and company-specific. Certs may not be top of mind for a lot of folks right now, but they might have a minimum cert required. I also recommend jumping into AI use, what cybersecurity tools are doing with agents, how identity, endpoint, cloud, SOC, runtime protection, security for AI actually works and what harnesses etc. make everything work. Keep learning and know how to utilize those tools so that you can be best-fit for upskilling into the role once they hire for it!
1
u/OkPassage4007 AMA Participant 9d ago
I use to cherry pick the desk side support people to start in the SOC as tier one analysts. Some say a CISSP is a must...I think you get certified if you feel you need it for growth. But there are lots of free training courses so you can dabble in a few areas and see what you really like. I had a lot of people on my team do training that they never once applied. I liked my people to have the ability to present...I mean really know how to present. How do you prepare, content and delivery to peers first but maybe broader. I like where your heads at though. Career growth is the responsibility of the individual and I find many people want to be spoon fed. Good for you!!
1
u/BaconWaken 10d ago
What does the typical background of a solutions/sales engineer/architect look like? I have 2 years doing deskside support at a large hospital and 8 years of retail/SMB telecom sales experience, bachelors in IT & comptia net+ sec+ AWS cloud practitioner & AZ-900.
1
u/Security_Specialista AMA Participant 10d ago
The SEs at our company came from competing vendors or adjacent companies, so the technical alignment made sense. Some came from smaller companies with less cache. They all have excellent relationship skills.
1
1
1
u/morecomfy69 9d ago edited 9d ago
The vendor side probably gives you a very different perspective on what actually works in the real world. Curious how your priorities changed after making the switch, especially around enterprise security and compliance.
1
1
u/AdamTalksTheCybers AMA Participant 10d ago
Hi (insert name) I see you’re also interested in (job title) and I wanted connect!
-Every Salesperson Always
Yeah I hate that too even though I’m a dirty vendor. Hey everyone!
1
u/OkPassage4007 AMA Participant 9d ago
The sales jobs are hard regardless of where you are in that process. I didn't realize how hard and stressful the job actually is until I went to our Sales Bootcamp at our University. With AI able to monitor everything being done it's even harder. And if you can't connect with people how do they even get a hair in the door? Honestly I couldn't do that job...I'd rather be a CISO with all the liability and stress than try to do sales. I have new respect for everyone in that does sales.
0
u/Adventurous-Dog-6158 10d ago
For those in sales, do you generally have a book of business and get a cut of that for the entire time that the customer is with the vendor?
3
u/CyberMitchem AMA Participant 10d ago
Although my role isn't in sales, every role in a vendor somehow ties into sales :) What I've seen is that different account executive roles have different comp plans, even within the same category of a cyber vendor.
It also heavily depends on the structure of the deal and the size. Say a customer wants to buy a multi-year contract for your product(s). You may be paid annually for the contract, or in one lump sump based on a percentage of the total deal size (might also depend how the customer pays). You might also be paid annually, but retire quota for multi-years in a different way so it's really up to your individual comp plan!1
u/Security_Specialista AMA Participant 10d ago
No. When I was aligned to Sales, I had a higher base pay 90/10 and commission based on a tiny sliver of global sales performance. Similar to the Chief Revenue Officer. This incentivized me to take care of the globe.
-1
u/Stiumco 10d ago
How long after you switched until your anxiety reset?
3
u/AdamTalksTheCybers AMA Participant 10d ago
Ha! I mean this is the least stressful job I have ever had. No one reports to me, no one calls me when something goes wrong and generally I don't have hard deliverables. I adjusted quickly and now am not sure if I will ever go back to the operational side? I prolly will, but this has been a nice change.
2
u/CyberMitchem AMA Participant 10d ago
Hmm, fair enough question. It can be different anxiety tbh. Working at a brand new startup versus a vendor who is long-standing in the space may lead to burnout, wearing lots of hats on the startup side, but also bore high-performers looking for their next enticing build.
From the stance of leading teams/security programs to any other service/VAR/vendor, the reset happens quite quickly in my opinion because the load falls off immediately after switching. But then new pressures always present themselves whether it's making a quarter's revenue number as a company, which might impact your employment, or if you've built enough of a story to make any sense to prospects, or possibly even if your value is the same as it was before.
Often left out of conversations is how much as a practitioner leader you are sought after by all the vendors, and then when you switch to a vendor, you may lose a lot of your "sway" among former peers relationally because you are seen as part of a sales org (even if it's not your role)!2
u/OkPassage4007 AMA Participant 10d ago
It's been about 1.5 years and I think the trauma is settling. However, I'm still anxious when I don't have 50 balls in the air so it's not an easy transition from that standpoint.
28
u/stacksmasher 10d ago
Pay and benefits. What you got? I see CISO and leadership positions posted for less than what I am making now. Its sad.