How to become a cybersecurity analyst
This article will explore some interesting details from an episode of Infosec’s information security career podcast, Cyber Work. This episode, with guest Jonathan Butler, covers how to become a cybersecurity analyst.
Jonathan is the professional services and security analytics manager at Distil Networks. He takes us through his journey into information security and discusses how he got his start in security, a little about the day-to-day responsibilities of the role, what someone should enjoy doing if they plan on becoming a cybersecurity analyst and the future of the role.
How did you get your start? Were you always interested in tech?
Jonathan came from a rural upbringing with bad internet service. He attended the University of Virginia and pursued a mathematics degree which required that he take a computer science course, sparking his passion for computers. Another course Jonathan took piqued his interest in programming; this one required a project to recreate Angry Birds that Jonathan found fascinating for how physics were baked into the code.
When he was in school, the internet was still not quite as ever-present as it is today. Jonathan described it as being the age of the flip phone. Despite this, others around him had a better knack and general understanding of the internet because they were exposed to it much more than Jonathan, making him feel like he was always playing catch-up compared to others. A formative moment came in one class where he decided he would not make excuses and would sit down and learn the material.
What were some of the steps on your path to becoming a senior cybersecurity analyst?
According to Jonathan, he did not plan out the future. Instead, he put his nose to the proverbial grindstone and then let the universe lead him from there. He worked in a software development firm which led to a role in data science (which was a data consulting for the automotive space), where he decided that he wanted to become a database administrator.
While he was preparing for a database certification, Jonathan changed his mind and decided to enter the private sector. Here, he got involved in enterprise with companies that included Audi and Volkswagen. Jonathan worked as a consultant in enterprise, which taught him the consultant mentality of helping others with data-driven decisions and also learned about the business side of things. These skills helped Jonathan to naturally transition have into his current organization, Distil Networks, which at the time lacked a professional team that straddled both technical and business expertise.
What is the average day like for a cybersecurity analyst?
Jonathan said that every organization is different, but the position can be 24/7, depending on current projects. (Distil strives to offer a good work-life balance.) The average week begins with checking your email inbox, going through upcoming projects and mapping out your week and the individual days. Every week, something comes up that derails your day and you just work around it.
Being a manager, are you spending as much time on the nuts and bolts of problems?
As a cybersecurity analyst, you have responsibility over a certain segment of projects and customers and the responsibility load increases as time goes on. As a manager, Jonathan is more likely to jump in when there is a critical issue or situation.
What should you REALLY enjoy doing? What are you going to be faced with almost every day as a cybersecurity analyst?
Jonathan’s situation is a little different than most because he is more of a consultant for a customer than an analyst working for a company. For him, he really enjoys helping customers, and most analysts will have to enjoy doing the same thing.
Cybersecurity analysts will be faced with determining which of their mundane responsibilities they can automate, as well as performing log analysis and thinking outside of the box every day. This focus on automation and streamlining of processes helps you stay ahead of adversaries.
What are the most interesting parts of the job? What are the most boring parts?
According to Jonathan, the most interesting part of the job is that information security offers constant discovery. He really enjoys seeing new team and adversary techniques that are always changing and evolving.
The most boring aspect of the job is the monotonous responsibilities that are part of every job. Some of this is attributed to systems and processes that existed prior to his arrival at Distil. Over time, a good cybersecurity analyst is supposed to automate these monotonous tasks away. You may end up working a role that keeps you up all night, but if you are confident, resilient and able to grow, you will be able to rise to the occasion.
What role do professional certifications play in the enhancement of a security career?
Professional certifications can definitely help in enhancing an information security career, although Jonathan himself does not have one. He did make note of an interesting aspect of information security: that is the dichotomy between those who swear by earning certifications and those who pride themselves on getting by without one.
Jonathan’s only concern about professional certifications was whether they can keep pace with changes in information security adequately.
How does it make you feel if you see someone with a certification?
When cybersecurity analysts first start out, and even later in their career, so much of the knowledge needed is in-house. This has changed as time goes by, moving more towards security being the bread and butter of the role. Overall, having someone around with a certification wouldn’t hurt.
What kind of companies require a cybersecurity analyst?
All companies, big and small, have a need for a cybersecurity analyst (budgetary considerations notwithstanding). In small companies, a cybersecurity analyst will be more than likely focusing on tasks like securing the perimeter.
The bigger a company is, the bigger the target for attackers. In big companies, cybersecurity analysts are more likely to be working on more narrow avenues of expertise. The downside of this is that these analysts are less likely to see the big picture.
What is something you can do today to move towards becoming a cybersecurity analyst?
Jonathan offered some good advice for those looking to move one step closer. Prospective analysts should take an online course, of which many are available today. Earning a certification, such as Certified Ethical Hacker, will also help. Lastly, Jonathan said that local security companies post job openings that list job descriptions. These will give a great idea of the skills and knowledge that hiring organizations are looking for.
Where is the role going?
The role of cybersecurity analyst is moving toward consolidation. Between moving towards deep subject matter experts from a more jack-of-all-trades approach and tooling and parsing non-traditional data sets for better insight, change is in the air. AI will also play a bigger role this year and this is not going to change anytime soon. Lastly, cybersecurity analysts will be increasingly required to wear multiple hats in an organization.
This podcast offered invaluable insights into what is like to be a cybersecurity analyst. Jonathan’s situation is unique in that he is a manager, but his path is more conventional than you might think, as many find their way into this position through a combination of experiences and learning what they love, namely information security.
For more information about this podcast, you can view it here.