THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Eddie Williams, Senior Director, Information Security, Governance, Risk, and Compliance - IT Security, Versant HealthThis article is based on an interview with Eddie Williams, senior director of information security, governance, risk and compliance - IT Security at Versant Health.
Role of Senior Leadership in Championing the Recruitment and Development of Cybersecurity Talent from Non-traditional Sources
Senior leadership is the foundation. Their understanding of organizational security and business needs is the basis of recruitment and development of cybersecurity talent from whatever sources. Getting buy-in and championships from senior leadership drives the organization to recognize that its cybersecurity talent openings can be filled from a variety of sources other than traditional universities and standard career paths.
Senior leadership, as the landscape changes, should be informed of the current state and given the informational resources on where to find the best cybersecurity talent, and it falls to their advisors to bring the news of untapped sources from which to draw much-needed talent for usually a much better ROI.
Strategies Implemented to Attract New Cybersecurity Talent from Non-traditional Sources
Get leadership buy-in to establish a strong internal program for DEI and to include non-traditional backgrounds for cybersecurity talent. Break the numbers down by talent to help them see the immense ROI and retention to galvanize them to action and lean into the search.
After that, put together attractive pay, retention and training packages. Although the fiscal investment will normally be a bit lower initially, make the organization attractive to those who would come in by offering a chance to learn, grow and shape themselves to your organization, which also increases retention numbers.
"Some of the largest private and public organizations are looking for non-traditional backgrounds for cyber talent. They are ahead of the curve."
Reach out to networks, social media and government organizations to get more informed. Some of the leaders in more traditional pathways or non-traditional places can help you reach out to those who just need a chance to be seen and heard to boost your cybersecurity talent pool.
Work with an established apprenticeship training and placement organization. I am board vice president for a non-profit cybersecurity apprentice training and placement organization. An organization dedicated to just that will help find, attract, train and place talent. Low-cost packaged process.
Advantages of Looking for Cybersecurity Talent in Places Other than the Usual Channels
Diamonds Aren’t Mined from the Surface: The unique perspectives that will drive innovation in cybersecurity are going to come from organizations finding those that are not bound by traditional ideologies. Do the legwork to find them.
Shift the Paradigm to Drive Innovation and Growth: The paradigm of university students is a strong one and drives a lot of the stability and thought leadership in cybersecurity these days. They have set a standard and created a paradigm, which is not a bad thing. That paradigm, however, stagnates without fresh and, more importantly, a variegated influx of talent. That variegated talent is best sourced from non-traditional sources like apprenticeship, military, and civilian retraining programs.
Great ROI: The ROI is that the traditional initial investment is usually lower, especially when working with an apprenticeship program. Less spent in training for basic certs. Non-traditional cybersecurity entrants are also usually already specialized or specializing at a high level in the major technologies and jumping right in.
You Get Multiple Skillsets for the Price of One: Again, non-traditional candidates tend to think outside of the box and bring myriad hard and soft skill sets from other industries that help move any cybersecurity strategy forward for an organization. I’ve personally run across apprentices with backgrounds in teaching (ability to design a cybersecurity training and awareness program from scratch), law (keen eye for understanding and applying cyber regulations to their organization) and many others.
Non-traditional Candidates are Flexible. Finally, the organization can mold them into what is needed more easily. There is not a lot to unlearn.
Some of the largest private and public organizations are looking for non-traditional backgrounds for cyber talent. They are ahead of the curve.
Strategies You Envision Will Enhance the Ability to Attract, Develop, and Retain Cybersecurity Talent from Unconventional Channels
If you haven’t yet, create an apprenticeship program. Offering to train and help further adapt non-traditional cybersecurity talent will help in attracting and retaining them.
Market the fact that the organization is looking to shape the future with non-traditional talent supplementing the current workforce.
Update job descriptions with alternate but equivalent requirements for those postings that can fit an apprentice or other non-traditional candidate (e.g., "degree or certificate in XYZ and # years of experience").
I personally put boots on the ground to help organizations build programs to attract, develop and retain talent, as well as training programs for cybersecurity as a board member. I have also stood up for these same programs within several organizations I have been with, and I'm always available to answer questions.
Feel free to rephrase the questions based on your viewpoint as well. Additionally, we would appreciate it if you could share your biography along with the draft.
Author Bio:
I have been honored to generate multimillion-dollar cyber revenues for leading consulting firms across industries. With over 20 years of experience in cybersecurity and intelligence, I have crafted a career that spans industries and the consulting field, as well as the public and private sectors worldwide.
I drive organizational goals as a consultant and have helped secure a projected $100M+ in revenue in FY 21 with $30M+ in development for FY 22 through strategic relationships and business development, providing cybersecurity senior leadership through the delivery of complex engagements.
I also serve as the VP of the board for CyberUp, a cybersecurity training, placement, and apprenticeship non-profit. As an established pillar of the Kansas City and St. Louis Metro areas in the field of cybersecurity and business, I have developed business relationships with other firms and potential clients. My specialty is delivering innovative cybersecurity and technology transformations with deep industry knowledge and producing thought leadership. I solve tough issues with new ways of thinking and humbly look forward to the opportunity to continue to lead.