Comments
5 Reasons Security Certifications Matter
Newest First  |  Oldest First  |  Threaded View
russellnomerconsulting
50%
50%
russellnomerconsulting,
User Rank: Apprentice
11/6/2014 | 11:40:47 PM
Re: Brownie points
Long lists of certifications are only valuable when the certification and knowledge alleged to be behind it is adequately applied to business needs.  I have seen my share of paper tigers over the years, where a list of certifications were obtained as a result of compiled test question brain dumps rather than actual hands on experience and learning leading up to the qualification for taking a certification exam.   Are industry certifications valuable?  It depends is a better answer.  Professionally speaking I have my CISSP, ITIL V2 and V3, MCP, Qualysguard, eDiscovery, and nearly thirty years of industry experience to draw upon when I engage a client.  That said, the value I bring to the table is the intellectual capital, the experience, the ability to understand the business direction and holistically align security strategies with it in a manner that provides transparency and accelerated decision making.  Are these skills I developed the result of certifications?  Partially, but not exactly.  You see, a truly competent task focused technical professional in our industry must go through a constant crucible of evolution and growth in order to get to a level slightly above mediocre.  Technology changes.  We have witnessed communications move from three hundred baud dialup modems to high speed wireless in a rather short time frame.  With each advance in technology moving us closer to ease of use and functionality we move further away from security.  In practice, the speed of use and function is driven by business goals and objectives which often look to security long after the planning phase of the pet project occurred.  As a result, security is sprayed on rather than baked in to the process.  A truly certified professional who has spent the time really learning how to apply their skills will understand how to communicate and collaboratively build solutions that empower the business to thrive through trust, innovation, and accountability.  If the certified party is the equivalent of a paper tiger who passed the test with brain dumps and without proper training and experience, the business will get zero value from the resource.   In addition, when we come across such resources who are quick to work at a lower rate, they damage the rest of us by diminishing the value of the sweat equity we invested in learning our trade.  I see this far too often with outsourced entities who attempt to contact me for opportunities at compensation rates I was earning in the early 1990s.  They claim to have other certified people who will work for peanuts and I politely tell them I will be available at my premium value based rate to resolve the mess as soon as I learn who they damaged.  You can make a career out of following where some of these imbeciles land because you know all too well that a big DNU should have been stamped on the CV by a competent recruiter focused on value for the customer rather than just matching keywords indicative of a desired certification.   Sadly, these things happen on a daily basis and corporations contract the equivalent of cancer when internal controls fail to proactively red flag incompetence.  This translates to loss of value, loss of time, and loss of opportunity.   Brownie points for a certification?  Yes, but buyer beware it could just be a knockoff.  Trust, but verify is the mantra that keeps you safer than most.

    
J_Brandt
50%
50%
J_Brandt,
User Rank: Ninja
3/31/2014 | 11:13:51 PM
Re: Brownie points
There is always a balance of experience and certification.  I think it's true of all areas not just security.  It's rare that certificates only adds anything of significance to a team.  Experience, validated by certification is another matter.
yslew
50%
50%
yslew,
User Rank: Apprentice
3/16/2014 | 4:06:55 PM
Re: Brownie points
Interesting and valid from HR PoV and for fed/gov't projects.
Kristin Burnham
50%
50%
Kristin Burnham,
User Rank: Author
2/27/2014 | 3:51:27 PM
Re: Brownie points
That's a good point to make re: long list of certs. Hiring managers I've spoken to tend to agree that while some certs are necessary and valuable, experience you have in the technology trumps it all.
Mark Aiello
100%
0%
Mark Aiello,
User Rank: Strategist
2/27/2014 | 11:49:19 AM
Re: Brownie points
Hi Lorna,

It has not been my experience that Certs are perceived as being outdated. Occasionally a NASCAR looking resume with a long list of Certs will be perceived and dismissed as someone who has just passed a lot of exams. More times than not it significantly enhances the perception of someone's competency.



 
Lorna Garey
50%
50%
Lorna Garey,
User Rank: Author
2/27/2014 | 10:11:00 AM
Re: Brownie points
Do you see any generational divide in terms of thinking certs matter? Are younger IT pros more or less likely to be the ones seeing certifications as outdated?

Of course, it's likely that the longer you have been in a field, the more likely you've had time to get some certifications, so I'm not talking about a divide in who HAS them. I'm talking about perception.
Mark Aiello
50%
50%
Mark Aiello,
User Rank: Strategist
2/26/2014 | 6:09:55 PM
Re: Brownie points
Hi Laurianne...I also like Fast Times at Ridgemont High

 
Laurianne
50%
50%
Laurianne,
User Rank: Author
2/26/2014 | 3:48:34 PM
Brownie points
The point re getting ignored by automated tools that are eliminating resumes based on certification keywords is important. How do you get around that with security certs? This is one area where hiring managers can and will be picky.

Also noted: Mark likes Caddyshack. Did you spot the reference?


Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Tech Digest, Nov. 10, 2014
Just 30% of respondents to our new survey say their companies are very or extremely effective at identifying critical data and analyzing it to make decisions, down from 42% in 2013. What gives?
Video
Slideshows
Twitter Feed
InformationWeek Radio
Archived InformationWeek Radio
Join us for a roundup of the top stories on InformationWeek.com for the week of November 16, 2014.
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.