Cloud Security

Prepare for Careers in the Cloud

Now is the Time for IT Pros to Hone Business Skills
Prepare for Careers in the Cloud
As organizations increasingly turn to cloud computing to support critical business functions, what becomes of the information security personnel formerly charged with protecting those functions?

Change is coming, experts say. The shift to the cloud impacts organizations throughout the private and public sectors. As a result, opportunities change for information security professionals at every stage of their careers.

"There will be a reduction and consolidation in functions associated with IT security operations within the next year or so," says Hord Tipton, executive director of the International Information Systems Security Certification Consortium (ISC2), the security certifications body. "Curtailment will be in areas of system and network administration, but more jobs are likely to sprout up and move in other areas within IT security."

The key to success is: Know which job opportunities are disappearing and which are opening.

The Cloud Impact

An evolution of the type of outsourcing that many organizations have practiced for years, cloud computing is generally embraced as an approach for delivering and consuming IT resources, (computer, storage and applications) characterized by customer self-service and high levels of standardization and automation. Basically, cloud computing's business model is to reduce the time and cost associated with delivering new business capabilities.

Because of heavy IT presence in their cost structures and potential to uncover new market opportunities, government, financial services and healthcare are among the first sectors to migrate to cloud services, says Bert Armijo, VP of product management, cloud solutions at CA Technologies. "The push for cloud services in these industries is not just about cost, but speed and time-to-market products and services," Armijo says.

Every job right from the chief executive officer through business middle managers and IT security managers will be affected by the cloud migration, says Kevin Jackson, vice president of NJVC, one of the information technology and cloud solution providers supporting the United States Department of Defense. "This is because cloud computing is forcing a shift in enterprise IT from 'building and doing' to 'managing and consuming.'"

This shift creates the need for new roles within information security, experts says - roles that will increasingly specialize in managing agreements and deliverables with cloud providers

In With the New

So, which roles diminish with the advent of cloud?

System and network administrators that solely focus on firewalls, routers and hardware monitoring will gradually find their jobs disappearing. The cloud will move to a whole new virtual environment requiring "a management of cloud services around web applications and business and not so much around provisioning IT," says Jackson.

Current system and network administrators, therefore, need to stay on the cutting edge to keep their jobs. These professionals must train themselves in web applications and deployments, as well as virtualization.

On the plus side, the cloud movement will further enhance focus on industry-specific, business-related processes and lead to more business, privacy, application, risk and security-savvy management professionals. Who can understand how to protect and classify data in the cloud? What encryption methodologies must be deployed? How does one handle incident response and manage incidents and their impact on the company?

"There will be a clear shift in demand from blue collar IT security workers to white collar positions," says Tipton. "New jobs in areas of application security, Web 2.0 deployments, virtualization, server consolidation and configuration management will come into play in organizations within the next 6-12 months."

The cloud will also open more specific business-focused roles for individuals that will need to heavily collaborate with business leaders on topics such as how to negotiate contractual agreements with providers and monitor the changes in terms of dynamic need for services by the organization.

Preparing for the Transition

To help professionals prepare for the transition to cloud computing, experts offer this advice:

  • Students: Look at research activities undertaken by academic institutions such as Boston University, Carnegie Mellon, Duke University and North Carolina State University to understand how cloud computing works. Also, get first-hand experience by finding open source cloud platforms and creatively run programs and applications on it to know what the potential is. "It is not expensive to try cloud computing," says Armijo.
  • Practitioners: Focus on how the technology enables the delivery of new and unique business capability, says Jackson. Pros should engage with management on this topic and create their own hierarchical list of applications, environments and/or infrastructure that could be replaced by commodity cloud services. They should invest time in understanding how IT services can be tied together to business processes and creatively think of ways of making IT security a part of the application and development phase in organizations.
  • Leaders: Take charge of the transition from infrastructure-centric security to data-centric security techniques and processes. One of the best ways is to take a few ancillary applications within HR and move these application to the cloud to familiarize oneself with cloud operations and security implications. That way your organization's other leaders are prepared to handle the transition.

Unfortunately, many of the available certifications and training are vendor and product centric, says Jackson. "While the training is generally good, a practitioner should also recognize the bias involved."

Information on the evolving cloud standards is available at Security specific information is available at

Among the areas that professionals should look for enhancing for cloud services are business process management, configuration management, virtualization, web applications, deployments and security architecture.

The top skill, though, remains the ability to simply get the job done.

"The critical skill in the cloud age is the ability to integrate and deliver value," says Jackson. "If professionals are not good at delivering value to their industry and business, they will most likely not have jobs in the future."

About the Author

Upasana Gupta

Upasana Gupta

Contributing Editor, CareersInfoSecurity

Upasana Gupta oversees CareersInfoSecurity and shepherds career and leadership coverage for all Information Security Media Group's media properties. She regularly writes on career topics and speaks to senior executives on a wide-range of subjects, including security leadership, privacy, risk management, application security and fraud. She also helps produce podcasts and is instrumental in the global expansion of ISMG websites by recruiting international information security and risk experts to contribute content, including blogs. Upasana previously served as a resource manager focusing on hiring, recruiting and human resources at Icons Inc., an IT security advisory firm affiliated with ISMG. She holds an MBA in human resources from Maharishi University of Management, Fairfield, Iowa.

Around the Network

Our website uses cookies. Cookies enable us to provide the best experience possible and help us understand how visitors use our website. By browsing, you agree to our use of cookies.