enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Jacuzzi Group

My Journey in it and Cybersecurity

Ray Malmassari, Sr. Director, IT Security and Infrastructure, Jacuzzi Group

Ray Malmassari is a seasoned cybersecurity expert with nearly 15 years of experience, currently the Sr. Director, IT Security and Infrastructure at Jacuzzi® Group. With advanced degrees from Western Governors University, Ray is in the final stages of completing his Doctorate in IT with a focus on Cybersecurity from Capella University. His portfolio of certifications includes CISSP, CCISO, CNDA, and PMP. Ray passionately shares his wealth of knowledge through his YouTube channels @TheCyberUpdate and @CyberSageRay and Medium blog @TheCyberUpdate, benefiting enthusiasts and professionals alike.

Embarking On a Tech-Driven Path

My professional journey in IT began in 2011 when I took my first steps as a desktop support technician. That same month, I started a bachelor's degree in IT security, driven by a lifelong fascination with technology. Over the years, I've navigated through roles as a systems engineer, security engineer, and architect, leading to my current position as Director of IT and Cybersecurity. My career progression is a testament to my inherent ambition and the insatiable curiosity I hold for the tech space. Now, as I work toward my doctorate in IT with a focus on cybersecurity, my commitment to learning continues.

Facing the Cybersecurity Goliaths

Today's enterprise security landscape is riddled with challenges. The obstacles are numerous, from budget cuts and staffing shortages to the barrage of security vendors claiming their solutions are the remedy for all cyber ailments. My role requires me to be as inventive as possible to meld business objectives with cyber risks and financial realities. It's a balancing act of strategic poise and practical vision.

The Evolution of Enterprise Security

Over the last 13 years, I've witnessed a significant transformation in enterprise security. What was once a subset of IT has now earned its rightful place as a standalone department, often represented in the boardroom by a Chief Information Security Officer (CISO). This evolution reflects the elevated importance and intricacy of safeguarding our digital infrastructure.

"What Was Once a Subset of it has Now Earned Its Rightful Place as a Standalone Department, Often Represented in the Boardroom By A Chief Information Security Officer (Ciso)"

Strategizing Against Cyber Threats

To mitigate the risks associated with cyber threats, I've learned that having an accurate inventory of IT assets and clear visibility into the environment is critical. In the past, I've utilized tools like Tanium to construct an accurate asset database, which has been instrumental in my ability to protect against cyberattacks. It's a fundamental principle: you cannot protect what you are not aware of, making visibility the first line of defense in the cybersecurity battleground.

Emerging Technologies and Their Impact

I am convinced that generative AI will significantly impact enterprise security. This revolutionary technology is changing the game's rules, enhancing the capabilities of not only defenders but also adversaries. Therefore, staying wellinformed and educated about generative AI has become an essential part of my role in enterprise security.

Staying Informed in an Everchanging Domain

In this rapidly evolving field, I keep myself updated by indulging in various cybersecurity podcasts, such as Cyberwire, SANS Internet Stormcast, and Life of a CISO, and participating in discussions with my peers in the IT community. Staying current also involves studying for certification renewals and attending educational webinars. This blend of learning and community interaction ensures I remain at the forefront of cybersecurity developments.

Charting the Course Ahead

As a director, I stand at the helm, navigating through the complex and stormy seas of enterprise security. My story is one of continual growth and adaptation, facing each challenge with a steadfast commitment to protect and serve in the digital age. It's about equipping those following in my footsteps with the knowledge and foresight needed to continue this critical work. For those embarking on this journey, my advice is to remain vigilant, embrace continuous learning, and always be prepared to evolve with the ever-changing tides of technology and security threats.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief