@clintgibler
Clint Gibler
14 days
๐’๐ญ๐š๐ซ๐ญ๐ฎ๐ฉ ๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ: ๐‘๐š๐ญ๐ข๐จ๐ฌ ๐š๐ง๐ ๐š 24-๐Œ๐จ๐ง๐ญ๐ก ๐‡๐ข๐ซ๐ข๐ง๐  ๐๐ฅ๐š๐ง How companies like Datadog, HashiCorp, GitHub, GitLab, Segment, Optimizely staff security teams, based on CISO interviews.
1
1
16

Replies

@clintgibler
Clint Gibler
14 days
TL;DR: Tad Whitaker recommends: - 1:40 security:Full Time Employee (FTE) ratio - 1:100 IT:FTE. GitHub had a 1:40 ratio. GitLab 1:24.
1
0
1
@clintgibler
Clint Gibler
14 days
Tad recommends adjusting the ratio based on how critical your company is as a vendor within your customerโ€™s supply chain attack thread model: - Critical: 1:29 - High: 1:40 - Medium: 1:75 - Low: 1:100
1
0
2
@clintgibler
Clint Gibler
14 days
The post describes the purpose of the core types of security teams (IT, Security Operations, GRC, and Product Security) and provides a comprehensive 24-month hiring plan broken down by quarters and teams, with specific job titles and levels for each role. Great resource love it!
1
0
1