Equifax CEO hired a music major as the company’s chief security officer
marketwatch.com
marketwatch.com
One of the best engineers I've ever met had a bachelors in Psychology. Another was a highschool dropout. The difference though was that those folks spent a ton of time learning everything they could, and continually improved.
Having a music major isn't a bad thing at all. Having no relevant experience is a much larger concern for me.
I'd go as far as saying that this headline is harmful. It perpetuates the "only people with CS degrees can program/security/architect", which isn't true at all. We shouldn't be shaming people who come from another walk of life. More power to those who didn't get a traditional CS degree and still kick ass :)
I feel like music majors have to be very technical and studious...something that really does transfer well to any other field if they put their mind to it.
I also work with another colleague who had a scholarship to his undergrad for music, who switched to CS. Not as technical as the first colleague, but is very good at systems thinking.
A third colleague is a superb SME who understands security policy, compliance, and risk management (with a CISSP and actually using it); he was an architect and interior designer before switching careers... and is in a band. :)
Music isn't a bad background to have in IT or security fields from my perspective. Issues with anecdotes aside, I don't see the issue here if a person has demonstrated growth and expertise in the field.
The real story here is how Marketwatch (and HN, and Reddit, and Twitter, etc) is coming to the conclusion that she is unqualified simply by looking at her LinkedIn profile. I know many security professionals that have no LinkedIn profile, or list very barebones information on it because they see themselves as targets for spear phishing and see no need to give potential attackers any easy ammunition.
From looking at her LinkedIn profile (https://www.linkedin.com/in/susan-m-93069a/), it looks like she also follows this practice. If you look at her previous positions they are listed simply as "Professional".
TL;DR She may indeed be unqualified, but there is no way to determine that only from her LinkedIn profile.
Alice Goldfuss, SRE at github: "reddit is mocking the Equifax CISO for having a music degree, meanwhile I know no one in infosec with a CS one" https://twitter.com/alicegoldfuss/status/908430394529259520
When I was working at Cisco pretty much all InfoSec people I know had a technical degree, from CS to EE to sometimes Mathematics.
I'm sure there are some outliers, but saying "no infosec people have degree in CS" is just plain ridiculous.
Worked with several highly competent people in tech and infosec with music degrees, liberal arts degrees, no degree...
I'm not saying music degree people can't be good engineers, but saying "no infosec people have CS degree" is plain absurd.
A few folks got Physics degrees, but the vast majority of people I know left school to work and have not finished. Myself included.
The other very common backgrounds that I encounter is people who served in the military and people who backdoored their way into it from being sysadmins.
She could have her degrees for computer music for all we know, which at the time she got them probably would have required some serious programming chops.
You stretched that tweet pretty far. It's clearly nothing more than an anecdotal counterexample. I'm not sure how your paraphrasing quote ended up becoming such a sweeping generalization.
By the end of the interview, I felt sorry for her. I have no idea if she had relevant experience or not, she just sounded like someone who has been conditioned to argue that delays in new development are unacceptable, and that the cloud is inevitable, and if it costs more to do it right then you'll have to make do with less, and cetera and so forth.
I'm not terribly shocked that they've taken down these interviews, but I am very sorry I didn't save a copy when I found them. They were still available for viewing as of 12:31pm Eastern Time on Sept 10, and there are transcripts that you can find following the links in the article, which has been updated to note the videos were scrubbed from the internet.
Serious question, is there any way this might actually count as destroying evidence?
[1]: https://www.hollywoodlanews.com/equifax-chief-security-offic...
https://www.hollywoodlanews.com/equifax-chief-security-offic...
There is a transcript that you can still read at:
That is true in general, however in this case we know there was a major breach maybe one of the biggest ones, now all of the sudden having a Music degree _and_ seemingly not having relevant infosec experience doesn't look too good.
Had there been no breach, fine, nobody would have noticed and everyone would have given the benefit of the doubt, even say "How nice, they could pivot from a different degree etc."
Moreover what looks shady is that they changed their last first name to M. instead Mauldin in LinkedIn profile. Their interviews have been taken down etc. If they had experience and this was just an unfortunate example, they would have stood by and defended and explained what happened. The weasily hiding looks shady like they are hiding their incompetence.
That's tantamount to saying an engineering degree is just a piece of paper. Of course it implies a lot more.
I dropped out of school as soon as I realized I could make 50k/year doing IT work vs paying 50k a year to a school whose curriculum was from the stone age. I fully endorse education of all forms but our current model for educating the next generation of workforce is broken but I digress.
The story is more complicated than this http://greyenlightenment.com/equifax-hack-analysis/
1. she was hired in 2013. Butting against equifax stock on this knowledge would have resulted in a large loss.
2. The odds of Equifax (or any company) being hacked are high if hackers are determined enough. It Bitcoin exchanges, ICOs, and online wallets, which are run by STEM people, find it very hard to stop hackers, what does that say about most websites in general.
No, I don't think I'm currently qualified to be CSO anywhere - but I don't think it's a stretch that a music major could be.
It should not be acceptable to have dam built by a self taught engineer, or the privacy of 100 million ppl is safe guarded by music major even she had "relevant experience" there is a reason education and certification exist
The problem is the low quality hiring of executives. This seems to plague almost every large company out there. These "executive level" people are just part of some inner circle and know somebody who knows somebody. They might look good on paper. The reality is that boards and CEOs have too little knowledge of the specifics of their business and make chicken-shit hires.
Instead of asking the Infosec community for their thoughts this journalist is showing he is already out of his depth.
I don't like to see people get shit on (and she looked like a person who was trying hard to do a good job,) but she also looked like a person who was put in that position because someone with a lot of money knew that doing security right would be expensive, and she would be someone to comply.
As for being a dupe, it is in the sense that the same topic has been introduced multiple times:
https://hn.algolia.com/?query=equifax%20music&sort=byPopular...
Edit: it was unmarked, thank you Scott
You can still find a transcript of one of the two interviews here, but it does not include this quote