At first night of the class you have partnered with another student. Please provide your first draft and let them review your paper using the First Draft checklist and review their paper as well. For every two items you find in their paper you will earn 1

profileMichelle_Michy
Findingajobasacybersecurityspecialist11.docx

Running Head: FINDING JOB AS A CYBER SECURITY SPECIALIST 1

Finding a Job as a Cyber Security Specialist 11

Literature Review

Finding Job as a Cyber Security Specialist

Action Research

Course Code:

Name:

Table of Contents 2.0 Literature Review 4 2.1 Significance of Gutsche Job Seeking Model 7 3.0 Proposal 8 3.1 Iterations 8 Iteration 1: Career identification 8 Iteration 2: Relevant skills acquisition. 8 Iteration 3: Job application and interview 9 Iteration 4: Career development. 9 References 10

List of Figures

Figure 2.1: Gutsche Job seeking model…………………………………………………….7

Figure 2.2: Iterations visual Representation……………………………………………….9

2.0 Literature Review

The significance of information towards the running of entities in the present 21 century cannot be overlooked due its functional aspect in the running of the respective entities. This is because information is a key aspect in the decision making process. Technological advancements in the present 21st century have offered conveniences in the information technology sector resulting in conveniences and efficiencies with regard to data collection, entry and processing to information. The internet is the major technological advancement that has been in the forefront in facilitating evolutionary changes in the information technology industry such as ease of information storage and access by relevant parties. Despite the advantages associated with the internet with regard to information, the major challenge faced by information specialist as a result of technological advances is cyber security. With the grievous effects of cyber security risks to various entities, entities have gone ahead and setup cyber security departments as a way of mitigating cyber security risks (Hansen, L., & Nissenbaum, 2009).

The attention given to cyber security departments either as independent units or attached to the information technology department has had a major effect not only in the corporate world but also academic world. This has resulted in individuals specializing in cyber defence career wise as a result of education institutions offering special courses in cyber security. In the corporate world, human resource departments have come up with cyber security positions with clearly laid out job descriptions in the workplace. Despite the high level of unemployment rates in our society, cyber security departments are still finding it difficult to find qualified personnel to match their information security requirements. The novelty of cyber security specialist positions coupled by the market’s high demand alongside a low number of qualified personnel makes the specialists to be amongst the most sought specialists in the present corporate world (Caldwell, 2013). With each company seeking ways of securing their data, cyber security specialists are sure of a continued employment increase due to the fact that organizations are shifting from conventional to digital functionality. A cyber security specialist is an individual whose job is to maintain the security of an entity’s information systems. This is through the prevention of cyber security threats as well as mitigating risks to the entity’s information system (O’Connell, 2012). Cyber security specialists work by ensuring cybercrimes are prevented through their knowledge and efficiency in forensic analysis, cyber threats and risks diagnosis and reverse engineering among others to establish solutions and vulnerable areas. Generally, a cyber-security specialist is in in charge of the entire information system’s security. In protecting information system networks, cyber security specialists start by designing firewalls then proceed to monitor the use of data files and finally regulate information access. Cyber security specialists are able to get job opportunities in both private and public sectors. Potential employers in the public sector range from military departments to financial institutions. In the private sector, potential employers range from private consultation firms to corporate firms among others. Other than education qualifications, the cyber security specialists are required to have on job relevant skills and expertise. Educational requirements and skills for the cyber security personnel vary with regard to the scope of responsibility with the lowest entry level being Associate Degree and the highest being Master’s Degree (Pfleeger & Caputo, 2012).

Various models have been formulated by researchers to serve as a guide in a job’s search and preparation. These models often come with various stages that highlight what the job seeker is required to do at each stage in the build-up to getting a job. With regard to the cyber security job specialist, the most appropriate job searching model to be applied is the Gutsche model. According to the Gutsche model, career objectives are the models foundation. As a result, a prospective job seeker is supposed to first consider personal career objectives during the job application process. Although the job seeker may be qualified in a variety of jobs, the choice of job to serve should be aligned to his/her career objectives. Listed objectives enable a job seeker to effectively explore any jobs before applying in order to determine job offers that best suit his/her personal career objectives (

Greitzer, F. L., & Frincke, 2010). Career objectives evaluation plays a key role in career growth as well as determining the quality of output in one’s work. A cyber security specialist is an overall Information technology student and can work in various departments in the I.T department. However, wrong choice of department will lead to zero growth of one’s cyber security skills resulting in redundancy. An example of this is whereby a cyber-security specialist starts by working as an information system’s hardware maintenance officer. Hardware and cyber security are not directly linked hence one’s knowledge and skills goes to waste. However, in the event that the same cyber security specialist starts by working as a software engineer in an I.T department, the specialist is presented with the opportunity to develop personal knowledge and skills hence career growth (Locasto & Sinclair, 2009).

In the basic perspective, career growth simply refers to the progression an individual makes up the hierarchical ladder in an organization. Hierarchical growth is often associated with increased roles and responsibilities at each stage up the hierarchy. Although the researcher’s focus is on finding a job, a career is not viewed as a job in this perspective but rather as a progressive transition since it focuses on the future outcome. Based on this argumentation, the initial step in career development is career entry by finding a suitable job (Bagchi-Sen et al., 2010). Gutsche’s model of job searching, there are six key step in finding the appropriate job. The six steps are:

1. Identifying one’s career

2. Acquisition of relevant skills

3. Research on the potential employer

4. Job application and Interview

5. Staying motivated and organized in new positions

6. Negotiating for career development

Figure 2.1: Gutsche Job seeking model

2.1 Significance of Gutsche Job Seeking Model

Career identification entails choosing one’s career based on one’s ability and passion to work in the said career. Relevant skills to be applied in the course of the career development skills are to be achieved through specialised education and training.

Upon acquisition of the relevant skills and knowledge, the job seeker should seek prospective job openings and research on the employer to establish career development prospects (Bagchi-Sen et al., 2010).

Job openings that are relevant to the job seeker’s career objectives should be applied and interviews conducted. If successful the job seeker should view his/her entry position as a stepping stone for ascension up the career hierarchical ladder (Cone et al., 2006).

It is advisable that the jobseeker should stay motivated and organized in new positions as a way of showing ability for new challenges. The job seeker should also expound his/her qualifications in case higher career development positions require additional academic qualifications and skills (Cone et al., 2006).

Upon satisfying administrators that he/she is capable of responsibilities and challenges that come with a higher position, the job seeker should creatively negotiate for career development (Cone et al., 2006).

3.0 Proposal

This action research’s proposal is a cyber-security specialist’s job seeking process. The research question addresses the research problem as job seeking process. The literature reviews clearly states about the absence of cyber security specialists hence making it easier for qualified cyber-security specialists to get jobs. The strategy listed in this research paper is key in filling a cyber-security position in a company. This action research process will entail five iteration processes as listed below.

Iteration 1: Gathering Requirements. This first iteration is founded on the job’s requirements. Prior to qualification for a job interview, the interviewer is required to have met all the prior necessary requirements. Job requirements for the job of a cyber-security specialist include an undergraduate degree in Cyber security, relevant on job experience, knowledge of data security diagnostic tools and IAT level II security certification.

Iteration 2: Gap Analysis. The second iteration is focused on analysing the gap to be filled by new employee. In order to secure the job, the new employee is required to impress the Human resource manager on his/her ability to effectively fill the job position. The employee is required to have relevant academic qualifications, relevant job experience, knowledge of cyber security tools and frameworks such as DIACAP, DISA, ACAS and SCAP among others. Analytical skills and data collection capabilities are also relevant in filling the gap in cyber security specialist.

Iteration 3: Updating Resume

Prior to the application of a new job, a job applicant is required to update his/her resume so as to meet ensure that his/her credentials and qualifications are aligned to the job requirements. Cyber security specialists are often general I.T conversant with makes them qualified to fulfil various general I.T roles and responsibilities such as data entry among others. This therefore necessitates the updating of one’s resume in line with a new job requirements. In the case of a cyber-security specialist, the job applicant should focus on specific skills, qualifications and credentials to match job requirements.

Iteration 4: Apply for a Job

The other important documents in the job application documents are a cover letter alongside the resume and other relevant documents such as copies of credentials. A successful resume update is always followed by a job application process during which the applicant may be required to attach copies of credentials for credibility and background checking among others.

Iteration 5: Plan to fill Requirements

After a successful job application process and interview, a successful employee should fill the job requirements through ones skills, qualifications and on job training to acquaint him with the necessary on job procedures and protocols. The new employee should be able to effectively and efficiently fill the respective roles and responsibilities that come with the position.

Figure 2.2: Iterations visual Representation

The visual representation diagram above shows the four iterations with each following the four distinct phases of action research. From one iteration to the next iterations hence closing in on the expected outcome. The four phases of action research are plan act, observe and reflect with each iteration following the laid down action research phases.

References

Bagchi-Sen, S., Rao, H. R., Upadhyaya, S. J., & Chai, S. (2010). Women in cybersecurity: A study of career advancement.  IT professional,  12(1), 24-31. {http://ieeexplore.ieee.org/document/5403174/}

Caldwell, T. (2013). Plugging the cyber-security skills gap.  Computer Fraud & Security,  2013(7), 5-10. {http://www.sciencedirect.com/science/article/pii/S1361372313700629}

Cone, B. D., Thompson, M. F., Irvine, C. E., & Nguyen, T. D. (2006, May). Cyber security training and awareness through game play. In  IFIP International Information Security Conference (pp. 431-436). Springer US. {http://link.springer.com/chapter/10.1007%2F0-387-33406-8_37#page-1}

Greitzer, F. L., & Frincke, D. A. (2010). Combining traditional cyber security audit data with psychosocial data: towards predictive modeling for insider threat mitigation. In  Insider Threats in Cyber Security (pp. 85-113). Springer US. {http://link.springer.com/chapter/10.1007/978-1-4419-7133-3}

Hansen, L., & Nissenbaum, H. (2009). Digital disaster, cyber security, and the Copenhagen School.  International Studies Quarterly,  53(4), 1155-1175. {http://onlinelibrary.wiley.com/doi/10.1111/j.1468-2478.2009.00572.x/full}

Locasto, M., & Sinclair, S. (2009, February). An Experience Report on Undergraduate Cyber-Security Education and Outreach. In  Proceedings of the 2nd Annual Conference on Education in Information Security (ACEIS 2009), Ames, IA, USA.{http://pages.cpsc.ucalgary.ca/~locasto/papers/sismat.ACEIS.pdf}

O’Connell, M. E. (2012). Cyber security without cyber war.  Journal of Conflict and Security Law,  17(2), 187-209. { http://jcsl.oxfordjournals.org/content/17/2/187.short}

Pfleeger, S. L., & Caputo, D. D. (2012). Leveraging behavioral science to mitigate cyber security risk.  Computers & security,  31(4), 597-611. {http://www.sciencedirect.com/science/article/pii/S0167404811001659}

image1.png

image2.png