A recent ISACA “Ask Me Anything” discussion with Zinet Kemal, Senior Cloud Security Engineer, TEDx Speaker, Author, and Career Changer, explored transitioning into a security career and keeping up with AI advancements. Kemal is an expert in cloud security, LinkedIn Learning Instructor, bestselling author and internationally recognized cybersecurity advocate.
Learning to give yourself permission to be a beginner again
One of the central themes of the Ask Me Anything discussion, which took place on ISACA’s Engage online community, was how to transition into a cybersecurity career. Kemal transitioned from a career in law to cloud security and shared with discussion participants that her skills in research, analytical thinking, communication and advocacy from her law background are valuable in her cybersecurity career.
Kemal encouraged career changers to connect their previous career to their new one by identifying transferable skills, learning fundamentals first to build a technical foundation and getting as close to the work as possible (including through labs, projects, and/or internships).
“Give yourself permission to be a beginner again,” wrote Kemal as part of the discussion. “Career transitions can be uncomfortable, especially when you have already established yourself in another field. That's part of the process.”
Top information security challenges this year
When asked about the top information security challenges she’s facing this year, Kemal shared: keeping pace with AI security and governance, identity and access management and security at cloud scale.
“AI is evolving incredibly fast,” wrote Kemal. “Enterprises are trying to build the right governance, security controls and review processes while security vendors are also racing to introduce new tools to secure AI. It sometimes feels like we are building the guardrails while the road itself is still being built.”
The need for human oversight
Another discussion in the Ask Me Anything thread focused on automation and the need for human oversight, as organizations can sometimes rely too heavily on automated cybersecurity controls and AI-driven monitoring.
“Automation can create confidence at scale, but it can also scale flawed assumptions,” wrote Kemal. “I still believe strongly in human oversight, periodic control testing, independent validation, red/purple teaming and measuring control effectiveness rather than simply measuring whether a control exists.”
Catch up on the entire Ask Me Anything thread on Engage here. Submit topic and guest ideas for upcoming Ask Me Anything sessions to volunteer@isaca.org. Connect with Zinet Kemal on LinkedIn here.