SEC504: Hacker Tools, Techniques, and Incident Handling

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usConnect, learn, and share with other cybersecurity professionals
Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders
Become a member for instant access to our free resources.
Sign UpMission-focused cybersecurity training for government, defense, and education
Explore industry-specific programming and customized training solutions
Sponsor a SANS event or research paper
We're here to help.
Contact UsJay Bhalodia, Managing Director of Security Customer Success at Microsoft Federal, shares his journey in evolving cybersecurity delivery.
In a detailed interview with Jay Bhalodia, Managing Director of Security Customer Success at Microsoft Federal, the 2024 SANS | GIAC Cyber Workforce Research Report highlights significant insights into developing cybersecurity maturity models. With a background from Booz Allen Hamilton and Emagine IT, Jay shares his journey and successes in evolving cybersecurity delivery and service staff, both at Emagine IT and Microsoft.
Jay emphasizes the pervasive workforce shortage in the cybersecurity industry, driven by structural challenges in talent acquisition versus development. Organizations can overcome this by implementing robust training programs that cultivate internal talent pools. These programs should mix in-house and outsourced sessions, focusing on aptitude assessments and certification achievements, with integral feedback mechanisms to ensure continuous improvement.
He also notes the complexity of certifications and jargon in the field, which can create artificial entry barriers. Jay advocates for a balanced strategy in hiring and training, emphasizing passion and diverse experiences over rigid qualifications. He recommends:
During his tenure as Director of Security at Emagine IT, Jay faced the challenge of recruiting top talent without the name recognition or budget of larger firms. By leveraging staff referrals and recruiting firms, Emagine IT successfully built a high-quality, cost-effective cybersecurity team. They focused on hiring candidates with growth mindsets and implemented accelerated onboarding models, including shadowing and reverse-shadowing, to quickly develop new hires.
Retention strategies included fostering loyalty through training, benefits, and culture, which helped mitigate the impact of turnover and build enduring relationships with replacements.
At Microsoft, Jay has seen the company transform from a non-recognized entity in security to a leading name in the field. This was achieved through aggressive sales and recruiting, initially focusing on rapid growth before transitioning to a customer success model. Jay's initiative to build the Microsoft Federal customer success organization from scratch saw it grow from 10 to 150 employees in three months, with a focus on upskilling legacy system administrators for cybersecurity roles.
Key retention tools at Microsoft include free academic benefits and immersive industry experiences. For instance, taking 40 employees to DEFCON and Black Hat conferences in the first-year accelerated passion and expertise within the team. This investment led to employees self-funding attendance at these conferences in subsequent years. Additionally, Jay's team spearheaded projects like adding voice-based capabilities to Microsoft Security tools, promoting diversity by partnering with universities to open cybersecurity career paths for vision-impaired students.
Jay Bhalodia's experiences highlight the importance of a balanced approach to talent acquisition and development in cybersecurity. His strategies at Emagine IT and Microsoft underscore the value of investing in training, fostering passion, and leveraging diverse experiences to build and retain a strong cybersecurity workforce. Through tailored training programs, inclusive hiring practices, and immersive industry experiences, organizations can develop successful cybersecurity maturity models and enhance their overall cyber resilience.
The 2024 SANS | GIAC Cyber Workforce Report includes six unique case studies from top cybersecurity leaders from leading organizations across the US. In addition, the report paints a full picture of the challenges and opportunities for building cybersecurity teams that are backed by successful hiring and development practices. To read the report in full, download it now.