Skip to content
Artwork for Professor Simon's IT and Cybersecurity Podcast

Professor Simon's IT and Cybersecurity Podcast

Professor Simon

Welcome to The Professor Simon IT & Cybersecurity Podcast, where we go beyond the textbook with real-world career advice, practical guidance, and lessons from the field. Whether you're breaking into IT or cybersecurity, building your skills, transitioning careers, or planning your next move, you'll gain practical insights to help you make better career decisions and understand what the work actually looks like. Topics include careers, certifications, IT fundamentals, SOC, GRC, leadership, AI, cloud security, and more. Cyber & IT Beyond the Textbook.

Play
  • 23 episodes
  • daily
  • Avg 11 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S1 · E31
    Tuesday · 13 min

    What Does an Entry-Level Cybersecurity Resume Actually Need? (Not What You Think)

    Most entry-level cybersecurity candidates are building resumes the wrong way. They're adding every certification, tool, and technology they've encountered, thinking more content equals more credibility. But hiring managers aren't looking for keyword volume. They're looking for credible evidence of capability. In this episode, Professor Simon explains what actually makes an entry-level cybersecurity resume effective. You'll learn why transferable IT experience matters more than generic security terminology, how to present projects that demonstrate real capability, and which certifications and technical skills actually deserve space on your resume. This is about making it easy for hiring managers to see what you can do, not overwhelming them with noise. In this episode you'll learn: Why hiring managers evaluate resumes based on credible evidence rather than keyword density, and what that means for how you structure your content How to leverage transferable IT experience from help desk, desktop support, or system administration roles to demonstrate relevant technical capability The specific level of detail needed to describe home labs and projects so they actually demonstrate competence rather than just listing activities When certifications add value versus when they raise credibility questions, and how to determine which ones deserve space on your resume Why listing technologies you can't discuss meaningfully in an interview undermines your credibility and what standard to use instead How to identify and present accomplishments that demonstrate problem-solving ability rather than just listing responsibilities or duties A practical framework for reviewing your resume from a hiring manager's perspective to identify what provides evidence versus what creates noise 🎥 Companion YouTube Video: https://youtu.be/8paAQIdtO4c 📖 Companion Blog Post: https://professorsimon.com/blog/entry-level-cybersecurity-resume 🎧 More Podcast Episodes: https://professorsimon.com/podcast 🧭 Figure out which cybersecurity path fits you: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 🌐 Website: https://professorsimon.com 💼 LinkedIn: https://www.linkedin.com/in/leonardsimon 📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity Careers IT Careers & Professional Development Cybersecurity Certifications Cybersecurity Skills & Training Security Operations Governance, Risk & Compliance (GRC) AI Governance & Emerging Technology Identity & Access Management (IAM) Vulnerability & Risk Management Security Awareness & Human Risk Cloud & Infrastructure Security Security Leadership & Strategy SOC 2 & Regulatory Compliance ISO 27001 NIST Cybersecurity Framework (CSF)

  • S1 · E30
    Monday · 14 min

    Stop Trying to Learn Every Cybersecurity Tool (Learn This Instead)

    If you're trying to gain hands-on experience with every security tool listed in job descriptions, you're making your learning journey much harder than it needs to be. In this episode, Professor Simon explains why chasing individual product knowledge creates an overwhelming and unsustainable approach that leaves you feeling perpetually unprepared. You'll discover why foundational understanding of underlying technologies makes tool knowledge transferable, how to decode what job descriptions really mean when they list specific products, and how to build a learning strategy that actually scales as your career progresses. This shift in perspective transforms an impossible checklist into a clear and manageable path forward. In this episode you'll learn: Why memorizing tool interfaces without foundational knowledge creates skills that don't transfer when technologies change How security tools within each category solve fundamentally similar problems using similar approaches What job descriptions really signal when they list specific products versus what they require you to know before applying Why employers expect to train new hires on specific tools but cannot afford to teach foundational technology concepts How to decode job postings by identifying tool categories and underlying capabilities rather than treating each product as separate Practical strategies for building deep knowledge in representative tools while developing transferable foundational understanding How to evaluate whether your learning approach creates knowledge that will serve you throughout your career 🎥 Companion YouTube Video: https://youtu.be/jAERtOA9bbg 📖 Companion Blog Post: https://professorsimon.com/blog/stop-trying-to-learn-every-cybersecurity-tool 🎧 More Podcast Episodes: https://professorsimon.com/podcast 🧭 Figure out which cybersecurity path fits you: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 🌐 Website: https://professorsimon.com 💼 LinkedIn: https://www.linkedin.com/in/leonardsimon 📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity Careers IT Careers & Professional Development Cybersecurity Certifications Cybersecurity Skills & Training Security Operations Governance, Risk & Compliance (GRC) AI Governance & Emerging Technology Identity & Access Management (IAM) Vulnerability & Risk Management Security Awareness & Human Risk Cloud & Infrastructure Security Security Leadership & Strategy SOC 2 & Regulatory Compliance ISO 27001 NIST Cybersecurity Framework (CSF)

  • S1 · E29
    Monday · 4 min

    Why Your Resume Never Reaches a Human (And How to Fix It)

    I've reviewed a lot of resumes from people trying to break into cybersecurity, and the most frustrating part isn't when someone lacks experience. It's when someone has real, relevant experience and their resume never makes it in front of a human being, because it got filtered out by an applicant tracking system before anyone even opened it. In this episode, Professor Simon explains what an ATS actually does before a recruiter ever sees your resume, the specific formatting and language mistakes that get strong candidates filtered out anyway, and why the popular advice to stuff your resume with keywords is exactly the wrong fix. In this episode you'll learn: Why your resume competes against software before it ever reaches a human reviewer How formatting choices like tables, columns, and graphic layouts get your job titles and dates silently dropped by parsing systems Why mismatched job title language between your resume and the posting can cost you a match even when the work is equivalent What separates a skills section that scores well from one that just lists tool names with no context Why quantifying your impact matters as much for ATS matching as it does for a human reader Why keyword-stuffing your resume, even invisibly, backfires with both modern systems and human reviewers What to actually prioritize if you're applying and hearing nothing back 🎥 Companion YouTube Video: https://youtu.be/c5_4cX6Rua0 📖 Companion Blog Post: https://professorsimon.com/blog/resume-mistakes-ats-filtered-out 🎧 More Podcast Episodes: https://professorsimon.com/podcast 🧭 Figure out which cybersecurity path fits you: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 🌐 Website: https://professorsimon.com 💼 LinkedIn: https://www.linkedin.com/in/leonardsimon 📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity Careers IT Careers & Professional Development Resume Writing & Job Search Strategy Applicant Tracking Systems (ATS) Cybersecurity Certifications Cybersecurity Skills & Training Security Operations Governance, Risk & Compliance (GRC) AI Governance & Emerging Technology Identity & Access Management (IAM) Vulnerability & Risk Management Security Awareness & Human Risk Cloud & Infrastructure Security Security Leadership & Strategy SOC 2 & Regulatory Compliance ISO 27001 NIST Cybersecurity Framework (CSF)

  • S1 · E28
    Friday · 12 min

    Why Access Reviews Fail (And How to Fix Them)

    Most organizations can prove their access reviews happened, but very few can prove they actually worked. In this episode, Professor Simon explores why periodic access reviews often become checkbox exercises that generate compliance documentation without preventing privilege creep or excessive permissions. You'll discover the organizational, technical, and human factors that cause well-intentioned reviewers to rubber-stamp permissions they don't understand, and learn practical approaches for designing access review processes that produce real security value instead of just audit artifacts. In this episode you'll learn: Why reviewers lack the technical and business context needed to make informed access decisions How incentive structures reward completing reviews quickly rather than completing them carefully Why compliance metrics and audit evidence don't guarantee effective access control The limitations of periodic reviews and why they can't catch problems in real time How to frame access review questions in business terms that reviewers can actually answer Practical strategies for providing context that helps reviewers identify anomalies without investigating every permission Complementary controls like just-in-time access and automated deprovisioning that reduce reliance on periodic human review 🎥 Companion YouTube Video: https://youtu.be/vSwQeHvboIE 📖 Companion Blog Post: https://professorsimon.com/blog/access-review-checkbox-exercise 🎧 More Podcast Episodes: https://professorsimon.com/podcast 🧭 Figure out which cybersecurity path fits you: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 🌐 Website: https://professorsimon.com 💼 LinkedIn: https://www.linkedin.com/in/leonardsimon 📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity Careers IT Careers & Professional Development Cybersecurity Certifications Cybersecurity Skills & Training Security Operations Governance, Risk & Compliance (GRC) AI Governance & Emerging Technology Identity & Access Management (IAM) Vulnerability & Risk Management Security Awareness & Human Risk Cloud & Infrastructure Security Security Leadership & Strategy SOC 2 & Regulatory Compliance ISO 27001 NIST Cybersecurity Framework (CSF)

  • S1 · E27
    August 27 · 12 min

    You Don't Need 100% of Job Requirements to Apply | Career Advice for IT & Cybersecurity

    Many IT and cybersecurity candidates eliminate themselves from positions they're actually qualified for because they don't meet every single requirement listed in the job description. They assume these postings represent minimum qualifications and that applying without meeting 100% of the criteria wastes the employer's time. In this episode, Professor Simon explains why job descriptions are wish lists rather than checklists, how to identify the core competencies that truly matter, and how to make strategic decisions about when you're qualified enough to apply. You'll learn to distinguish between trainable gaps and knowledge gaps, decode the language employers use to signal flexibility, and understand why the candidates who get hired often aren't the ones who checked every box. In this episode you'll learn: Why job descriptions typically describe idealized candidates rather than minimum requirements, and how understanding the hiring process changes how you evaluate your qualifications How to identify the core job function by reading past technology lists to find the fundamental activities a role actually requires The critical difference between trainable gaps in specific tools and knowledge gaps in foundational concepts, and why this distinction determines whether you're qualified How to decode job description language to identify which requirements are flexible and which are truly essential When you're qualified enough to apply despite missing 20-40% of listed requirements, and when gaps are too significant to bridge How to address missing qualifications strategically in your application by emphasizing transferable skills and demonstrating learning ability Why employers routinely hire candidates who don't meet all posted requirements, and how talent shortages create opportunities for strong partial matches 🎥 Companion YouTube Video: https://youtu.be/JB1ByJh8x7E 📖 Companion Blog Post: https://professorsimon.com/blog/you-dont-need-100-percent-job-requirements-to-apply 🎧 More Podcast Episodes: https://professorsimon.com/podcast 🧭 Figure out which cybersecurity path fits you: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 🌐 Website: https://professorsimon.com 💼 LinkedIn: https://www.linkedin.com/in/leonardsimon 📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity Careers IT Careers & Professional Development Cybersecurity Certifications Cybersecurity Skills & Training Security Operations Governance, Risk & Compliance (GRC) AI Governance & Emerging Technology Identity & Access Management (IAM) Vulnerability & Risk Management Security Awareness & Human Risk Cloud & Infrastructure Security Security Leadership & Strategy SOC 2 & Regulatory Compliance ISO 27001 NIST Cybersecurity Framework (CSF)

  • S1 · E26
    August 25 · 12 min

    Accepted Risk Management: Why Your Old Risk Decisions Need Review

    Most organizations have formal processes for accepting cybersecurity risks, but almost none have real mechanisms for ensuring those decisions get revisited when conditions change. In this episode, Professor Simon examines why accepted risks become permanent fixtures in risk registers, the organizational dynamics that prevent their review, and what happens when decisions made years ago continue to shape your security posture despite dramatically different circumstances. You'll learn practical approaches for treating risk acceptance as a time-bound commitment rather than a permanent status, including how to implement expiration dates, define reassessment triggers, and build sustainable review processes that actually fit within normal security operations. Whether you're inheriting a risk register full of old decisions or trying to prevent new acceptances from becoming invisible, this episode provides the framework for maintaining an accurate view of your organization's actual risk posture. In this episode you'll learn: Why risk acceptance decisions based on specific conditions at a point in time become outdated as circumstances change, yet persist indefinitely in most organizations How accepted risks disappear from active attention while new risks receive scrutiny, creating risk registers that grow less accurate over time The impact of personnel turnover on institutional knowledge about why risks were accepted and what assumptions justified those decisions Why most risk acceptance processes focus exclusively on approval workflows while neglecting ongoing management and reassessment How to implement mandatory expiration dates and reassessment triggers that force deliberate renewal rather than indefinite persistence Practical approaches for assigning ownership and creating lightweight review processes that actually happen within operational constraints Strategies for auditing inherited risk registers and building sustainable accepted risk governance that maintains accuracy without creating compliance theater 🎥 Companion YouTube Video: https://youtu.be/H9wKc2YNebw 📖 Companion Blog Post: https://professorsimon.com/blog/accepted-risk-management-review 🎧 More Podcast Episodes: https://professorsimon.com/podcast 🧭 Figure out which cybersecurity path fits you: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 🌐 Website: https://professorsimon.com 💼 LinkedIn: https://www.linkedin.com/in/leonardsimon 📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity Careers IT Careers & Professional Development Cybersecurity Certifications Cybersecurity Skills & Training Security Operations Governance, Risk & Compliance (GRC) AI Governance & Emerging Technology Identity & Access Management (IAM) Vulnerability & Risk Management Security Awareness & Human Risk Cloud & Infrastructure Security Security Leadership & Strategy SOC 2 & Regulatory Compliance ISO 27001 NIST Cybersecurity Framework (CSF)

  • S1 · E25
    August 25 · 14 min

    The 5-Step Framework for Getting Into Cybersecurity (Stop Collecting Random Certs)

    If you're trying to break into cybersecurity, you've probably asked yourself what certification to get first, whether you need a degree, or how to get experience when nobody will hire you. These questions often come too early because most people are preparing for an entire industry instead of preparing for a specific job. In this episode, Professor Simon walks through his established five-step framework, Discover, Foundation, Skills, Proof, and Entry, that provides an ordered process for making career decisions instead of collecting random credentials. You'll learn why the sequence matters, how each step builds on the previous one, and how to use this framework to create a targeted path into cybersecurity rather than following generic advice. In this episode you'll learn: Why you need to research specific cybersecurity roles before making decisions about certifications, degrees, or home labs How to build the right technical foundation based on your target role rather than following a generic IT path When and how to make intentional certification decisions that connect to your career destination instead of stacking popular credentials How to create proof of your abilities through projects and documentation that demonstrates reasoning and troubleshooting skills Why realistic entry points into cybersecurity often don't have security in the job title and how to identify valuable stepping-stone roles How the five steps connect as an ordered process where each step influences the next What questions to ask yourself at each stage to make better career planning decisions 🎥 Companion YouTube Video: https://youtu.be/ty5YVM0XACE 📖 Companion Blog Post: https://professorsimon.com/blog/5-step-cybersecurity-entry-framework 🎧 More Podcast Episodes: https://professorsimon.com/podcast 🧭 Figure out which cybersecurity path fits you: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 🌐 Website: https://professorsimon.com 💼 LinkedIn: https://www.linkedin.com/in/leonardsimon 📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity Careers IT Careers & Professional Development Cybersecurity Certifications Cybersecurity Skills & Training Security Operations Governance, Risk & Compliance (GRC) AI Governance & Emerging Technology Identity & Access Management (IAM) Vulnerability & Risk Management Security Awareness & Human Risk Cloud & Infrastructure Security Security Leadership & Strategy SOC 2 & Regulatory Compliance ISO 27001 NIST Cybersecurity Framework (CSF)

  • S1 · E24
    August 24 · 16 min

    Cybersecurity Isn't One Career Path. Stop Preparing Like It Is.

    If you're studying for multiple cybersecurity certifications, building labs across different security domains, and learning everything from penetration testing to compliance frameworks simultaneously, you might believe you're building a strong foundation. But you're actually preparing for five different jobs while employers are trying to fill one specific role. In this episode, Professor Simon explains why cybersecurity isn't a single career path and how scattered preparation prevents you from demonstrating readiness for any particular position. You'll learn how to choose a realistic destination role first, then work backward to build the focused skills, certifications, and projects that actually get you hired. In this episode you'll learn: Why cybersecurity encompasses fundamentally different roles that require different skill sets, certifications, and preparation strategies How scattered preparation across multiple security domains makes you appear unfocused to employers rather than versatile The critical difference between realistic entry-level security roles and positions that require substantial prior experience How to research specific job postings to identify what employers actually require for different security positions Why choosing a focused destination role increases your chances of landing your first security job rather than limiting your options How to work backward from your chosen role to select the right certifications and build relevant projects that demonstrate job readiness Practical steps to refocus scattered preparation into a targeted strategy that tells a coherent story to hiring managers 🎥 Companion YouTube Video: https://youtu.be/X5qqRx-Q7i8 📖 Companion Blog Post: https://professorsimon.com/blog/cybersecurity-career-paths 🎧 More Podcast Episodes: https://professorsimon.com/podcast 🧭 Figure out which cybersecurity path fits you: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 🌐 Website: https://professorsimon.com 💼 LinkedIn: https://www.linkedin.com/in/leonardsimon 📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity Careers IT Careers & Professional Development Cybersecurity Certifications Cybersecurity Skills & Training Security Operations Governance, Risk & Compliance (GRC) AI Governance & Emerging Technology Identity & Access Management (IAM) Vulnerability & Risk Management Security Awareness & Human Risk Cloud & Infrastructure Security Security Leadership & Strategy SOC 2 & Regulatory Compliance ISO 27001 NIST Cybersecurity Framework (CSF)

  • S1 · E23
    August 20 · 10 min

    Why Passing an Audit Doesn't Mean You're Secure | Compliance vs Security

    Security compliance audits provide valuable external validation and help establish baseline practices, but passing an audit isn't the same as having effective security. In this episode, Professor Simon explains the critical distinction between meeting compliance requirements and actually reducing risk in your daily operations. You'll learn what audits actually measure, where the gap between documented controls and operational reality appears, and how to use compliance frameworks as tools within a broader security program rather than treating them as destinations. Whether you're a security manager navigating leadership expectations or a practitioner trying to understand how compliance fits into security strategy, this episode will help you think more clearly about what passing an audit actually demonstrates. In this episode you'll learn: What compliance audits actually measure and the limitations of point-in-time evaluations in continuously changing environments How controls can satisfy audit requirements through documentation while providing minimal operational security value Why audit scope boundaries, sampling methodologies, and risk acceptance processes can leave significant security gaps unaddressed The structural reasons that create misaligned incentives between passing audits and addressing real security risks How to monitor the gap between documented controls and operational practice in your own organization Practical strategies for using compliance frameworks as foundations while building security programs around actual risk What compliance does well and how to have productive conversations with leadership about what audit results demonstrate 🎥 Companion YouTube Video: https://youtu.be/i0UggmmGpdM 📖 Companion Blog Post: https://professorsimon.com/blog/why-passing-an-audit-doesnt-mean-youre-secure 🎧 More Podcast Episodes: https://professorsimon.com/podcast 🧭 Figure out which cybersecurity path fits you: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 🌐 Website: https://professorsimon.com 💼 LinkedIn: https://www.linkedin.com/in/leonardsimon 📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity Careers IT Careers & Professional Development Cybersecurity Certifications Cybersecurity Skills & Training Security Operations Governance, Risk & Compliance (GRC) AI Governance & Emerging Technology Identity & Access Management (IAM) Vulnerability & Risk Management Security Awareness & Human Risk Cloud & Infrastructure Security Security Leadership & Strategy SOC 2 & Regulatory Compliance ISO 27001 NIST Cybersecurity Framework (CSF)

  • S1 · E22
    August 20 · 15 min

    What Does a SOC Analyst Actually Do All Day? (The Reality)

    If you're considering a SOC analyst role as your entry into cybersecurity, you need to understand what the job actually involves beyond the common perception of monitoring dashboards and stopping active attacks. In this episode, Professor Simon walks through what a SOC analyst really does during a typical shift, explaining the investigative work, context gathering, decision-making, and documentation that make up the bulk of the role. You'll discover why foundational IT knowledge matters more than most people realize, how to distinguish between normal and suspicious activity, and what skills you should actually focus on developing. This realistic picture of SOC work will help you prepare effectively and set appropriate expectations for this critical cybersecurity career path. In this episode you'll learn: Why most SOC analyst work involves investigating whether unusual activity is actually suspicious rather than responding to confirmed attacks How foundational IT knowledge in areas like Active Directory, networking, and operating systems enables faster and more accurate investigations The investigative process of gathering context, forming hypotheses, and testing them against evidence to determine what actually happened Why documentation and communication consume significant time and how these skills impact team effectiveness How to distinguish normal activity from genuine threats by building environmental knowledge through false positive investigations What factors to consider when making escalation decisions that balance thoroughness with resource management Practical recommendations for building the foundational skills that matter most in real SOC work 🎥 Companion YouTube Video: https://youtu.be/a-_49UnRRYQ 📖 Companion Blog Post: https://professorsimon.com/blog/what-does-soc-analyst-do 🎧 More Podcast Episodes: https://professorsimon.com/podcast 🧭 Figure out which cybersecurity path fits you: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 🌐 Website: https://professorsimon.com 💼 LinkedIn: https://www.linkedin.com/in/leonardsimon 📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity Careers IT Careers & Professional Development Cybersecurity Certifications Cybersecurity Skills & Training Security Operations Governance, Risk & Compliance (GRC) AI Governance & Emerging Technology Identity & Access Management (IAM) Vulnerability & Risk Management Security Awareness & Human Risk Cloud & Infrastructure Security Security Leadership & Strategy SOC 2 & Regulatory Compliance ISO 27001 NIST Cybersecurity Framework (CSF)

  • S1 · E21
    August 19 · 13 min

    What Does a GRC Analyst Actually Do All Day? (Real Responsibilities Explained)

    People considering cybersecurity careers often hear that GRC is an accessible entry point, especially for those less interested in deeply technical security operations. But when you ask what a GRC analyst actually does during a typical workday, the answers tend to be frustratingly vague. You hear about frameworks, policies, and compliance, but nothing that helps you understand what the work actually feels like. In this episode, Professor Simon walks through the real daily responsibilities of a GRC analyst, from conducting risk assessments and validating controls to managing vendor risk and tracking remediation efforts. You'll learn where technical knowledge matters, what skills actually make someone effective in this role, and how to evaluate whether GRC work aligns with your interests and strengths. In this episode you'll learn: Why risk assessments require both technical knowledge of attack vectors and business understanding of how organizations actually operate How control validation and evidence collection demand enough technical literacy to evaluate whether security controls actually work as intended What vendor risk management really involves beyond sending questionnaires, including critical evaluation of security responses and informed risk decisions Why remediation tracking requires balancing technical credibility with communication skills to work effectively between engineering teams and business leadership How policy and framework work connects abstract compliance requirements to practical implementation constraints in real technology environments What skills and preparation you need to succeed in GRC roles, including the balance between technical literacy and stakeholder communication How to evaluate whether GRC analyst work matches your career interests and what to expect in entry-level positions 🎥 Companion YouTube Video: https://youtu.be/Pyk4Dsh-PYg 📖 Companion Blog Post: https://professorsimon.com/blog/what-does-grc-analyst-do 🎧 More Podcast Episodes: https://professorsimon.com/podcast 🧭 Figure out which cybersecurity path fits you: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 🌐 Website: https://professorsimon.com 💼 LinkedIn: https://www.linkedin.com/in/leonardsimon 📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity Careers IT Careers & Professional Development Cybersecurity Certifications Cybersecurity Skills & Training Security Operations Governance, Risk & Compliance (GRC) AI Governance & Emerging Technology Identity & Access Management (IAM) Vulnerability & Risk Management Security Awareness & Human Risk Cloud & Infrastructure Security Security Leadership & Strategy SOC 2 & Regulatory Compliance ISO 27001 NIST Cybersecurity Framework (CSF)

  • S1 · E20
    August 18 · 12 min

    Your First IT Job Sucks. Should You Stay or Leave?

    Your first IT job is stressful, overwhelming, and probably underpaid. But the real question isn't whether it's difficult. It's whether you're actually learning anything useful while you're there. Most advice tells you to either tough it out because you need experience, or leave immediately because no job is worth your mental health. Both answers are too simple. In this episode, Professor Simon provides a practical framework for evaluating whether your difficult first IT job is building valuable skills or just wasting your time. You'll learn how to distinguish productive discomfort from destructive dysfunction, assess what you're actually learning, and make smart decisions about when to stay and when to move on without damaging your early career. In this episode you'll learn: How to distinguish between productive discomfort that builds skills and destructive dysfunction that just wastes time What actually matters in a first IT job: skill development, responsibility growth, and access to mentorship rather than title or pay How to evaluate whether you're gaining transferable technical skills or just getting better at tolerating a broken environment Why both staying too long and leaving too quickly can harm your career, and how to find the right balance How to assess whether you have access to people who can teach you, and why that matters more than management competence When staying in a difficult job becomes the bigger risk to your career development How to create a clear story about leaving an early job that makes sense to future employers 🎥 Companion YouTube Video: https://youtu.be/QqNO32f0JlE 📖 Companion Blog Post: https://professorsimon.com/blog/first-it-job-should-you-stay-or-leave 🎧 More Podcast Episodes: https://professorsimon.com/podcast 🧭 Figure out which cybersecurity path fits you: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 🌐 Website: https://professorsimon.com 💼 LinkedIn: https://www.linkedin.com/in/leonardsimon 📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity Careers IT Careers & Professional Development Cybersecurity Certifications Cybersecurity Skills & Training Security Operations Governance, Risk & Compliance (GRC) AI Governance & Emerging Technology Identity & Access Management (IAM) Vulnerability & Risk Management Security Awareness & Human Risk Cloud & Infrastructure Security Security Leadership & Strategy SOC 2 & Regulatory Compliance ISO 27001 NIST Cybersecurity Framework (CSF)

  • S1 · E19
    August 17 · 13 min

    Stop Collecting Certifications. Build a Certification Strategy Instead

    If you have three or four certifications but your career still feels stuck, adding another certification probably won't fix the problem. In this episode, Professor Simon explains why collecting credentials without clear purpose often becomes a career barrier rather than an accelerator, and how to shift from reactive certification decisions to strategic planning. You'll learn a practical framework for evaluating which certifications actually serve your specific career goals, how to distinguish between learning value and resume value, and when to stop pursuing credentials and focus on gaining hands-on experience instead. This approach helps you avoid wasting time and money on certifications that don't connect to where you actually want to go. In this episode you'll learn: Why additional certifications have diminishing returns and how hiring managers actually evaluate credential collections How to work backward from your target role to identify which certifications genuinely matter for your specific career path The critical difference between learning value and resume value in certifications and how to evaluate which type you need Why pursuing advanced certifications before building foundational knowledge creates a credentials-to-competence gap that damages credibility How certification value varies dramatically by industry, organization type, and specialization area The four-question framework for evaluating whether a certification deserves your time and money When to stop pursuing certifications and focus on practical experience, portfolio projects, or other skill-building activities instead 🎥 Companion YouTube Video: https://youtu.be/xoYlz1i19XY 📖 Companion Blog Post: https://professorsimon.com/blog/stop-collecting-certifications-build-strategy 🎧 More Podcast Episodes: https://professorsimon.com/podcast 🧭 Figure out which cybersecurity path fits you: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 🌐 Website: https://professorsimon.com 💼 LinkedIn: https://www.linkedin.com/in/leonardsimon 📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity Careers IT Careers & Professional Development Cybersecurity Certifications Cybersecurity Skills & Training Security Operations Governance, Risk & Compliance (GRC) AI Governance & Emerging Technology Identity & Access Management (IAM) Vulnerability & Risk Management Security Awareness & Human Risk Cloud & Infrastructure Security Security Leadership & Strategy SOC 2 & Regulatory Compliance ISO 27001 NIST Cybersecurity Framework (CSF)

  • S1 · E18
    August 14 · 14 min

    No Cybersecurity Experience? Stop Applying Only to Security Jobs

    If you've sent hundreds of applications for cybersecurity positions with little response, the problem might not be your qualifications, it might be your strategy. Entry-level security roles face extraordinary competition, while adjacent IT positions that build the same foundational skills often go overlooked. In this episode, Professor Simon explains why your first security job might not have "security" in the title, and why that could actually accelerate your career. You'll learn which IT roles map to specific security specializations, how internal mobility works, and how to strategically build the hands-on experience that security hiring managers actually value. In this episode you'll learn: Why entry-level cybersecurity positions face disproportionate competition compared to IT roles that build similar skills How operational IT experience provides the systems knowledge that makes security professionals effective Which specific IT roles map to different security specializations, from help desk to IAM, network support to SOC analyst, and systems administration to security engineering Why internal mobility from IT to security roles is often easier than external hiring and how to position yourself for internal transfers How to actively build security-relevant experience, visibility, and relationships while working in IT positions When direct entry into security roles still makes sense based on your background and circumstances How to evaluate job opportunities based on skill-building potential rather than job title alone 🎥 Companion YouTube Video: https://youtu.be/jp_2sSxNHl4 📖 Companion Blog Post: https://professorsimon.com/blog/no-cybersecurity-experience-stop-applying-only-to-cybersecurity-jobs 🎧 More Podcast Episodes: https://professorsimon.com/podcast 🧭 Figure out which cybersecurity path fits you: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 🌐 Website: https://professorsimon.com 💼 LinkedIn: https://www.linkedin.com/in/leonardsimon 📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity Careers IT Careers & Professional Development Cybersecurity Certifications Cybersecurity Skills & Training Security Operations Governance, Risk & Compliance (GRC) AI Governance & Emerging Technology Identity & Access Management (IAM) Vulnerability & Risk Management Security Awareness & Human Risk Cloud & Infrastructure Security Security Leadership & Strategy SOC 2 & Regulatory Compliance ISO 27001 NIST Cybersecurity Framework (CSF)

  • S1 · E17
    August 12 · 13 min

    Why Phishing Click Rates Are a Bad Security Metric

    Most organizations measure security awareness program success by tracking one simple number: what percentage of employees click links in phishing simulations. When that number drops from fifteen percent to eight percent, leadership celebrates and the security team gets recognized for improving employee behavior. But that declining click rate often tells you something different than what you think. In this episode, Professor Simon explains why simulated phishing click rates measure pattern recognition rather than genuine security judgment. You'll learn what click rates actually reveal, what critical behaviors they miss, and which complementary metrics actually indicate whether your organization is building real security culture. Whether you design security awareness programs or simply want to understand how organizations measure human security risk, this episode will challenge how you think about program effectiveness. In this episode you'll learn: What phishing click rates actually measure and what critical information they miss about employee security behavior How employees learn to recognize simulation patterns rather than developing transferable security judgment Why reporting behavior and post-click actions matter more than the initial click itself What aggregate click rate percentages hide about repeat offenders and concentrated risk patterns How metric pressure creates perverse incentives that make simulations less realistic and organizations less prepared Which complementary metrics reveal whether security culture is genuinely improving beyond pattern recognition Practical approaches to measure reporting rates, repeat behavior, and post-click actions alongside traditional click rates 🎥 Companion YouTube Video: https://youtu.be/LKoEuon3YJI 📖 Companion Blog Post: https://professorsimon.com/blog/why-phishing-click-rates-are-a-bad-security-metric 🎧 More Podcast Episodes: https://professorsimon.com/podcast 🧭 Figure out which cybersecurity path fits you: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 🌐 Website: https://professorsimon.com 💼 LinkedIn: https://www.linkedin.com/in/leonardsimon 📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity Careers IT Careers & Professional Development Cybersecurity Certifications Cybersecurity Skills & Training Security Operations Governance, Risk & Compliance (GRC) AI Governance & Emerging Technology Identity & Access Management (IAM) Vulnerability & Risk Management Security Awareness & Human Risk Cloud & Infrastructure Security Security Leadership & Strategy SOC 2 & Regulatory Compliance ISO 27001 NIST Cybersecurity Framework (CSF)

  • S1 · E16
    August 12 · 13 min

    Do You Actually Need a Home Lab to Get Into Cybersecurity?

    If you've been researching how to break into cybersecurity, you've probably encountered conflicting advice about home labs. Some people insist they're absolutely essential, while others dismiss them as a waste of time. The truth is more nuanced than either extreme. In this episode, Professor Simon explains what employers actually look for when evaluating candidates, why having a lab matters far less than what you learned from it, and how to decide whether building your own environment is the right investment of your time and resources. You'll learn to evaluate lab projects based on the skills they develop rather than treating them as resume checkboxes. In this episode you'll learn: Why employers care more about what you can explain than what equipment you own The critical difference between following tutorials and solving actual problems How to design lab projects that start with questions rather than infrastructure Why documentation and communication skills matter as much as technical work When alternatives like cloud platforms or CTF challenges might serve you better than building your own lab How to present lab work effectively in interviews and on your resume Practical criteria for deciding whether a home lab fits your learning style and career goals 🎥 Companion YouTube Video: https://youtu.be/ybiVnlGFW_s 📖 Companion Blog Post: https://professorsimon.com/blog/do-you-need-home-lab-cybersecurity 🎧 More Podcast Episodes: https://professorsimon.com/podcast 🧭 Figure out which cybersecurity path fits you: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 🌐 Website: https://professorsimon.com 💼 LinkedIn: https://www.linkedin.com/in/leonardsimon 📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity Careers IT Careers & Professional Development Cybersecurity Certifications Cybersecurity Skills & Training Security Operations Governance, Risk & Compliance (GRC) AI Governance & Emerging Technology Identity & Access Management (IAM) Vulnerability & Risk Management Security Awareness & Human Risk Cloud & Infrastructure Security Security Leadership & Strategy SOC 2 & Regulatory Compliance ISO 27001 NIST Cybersecurity Framework (CSF)

  • S1 · E15
    August 11 · 14 min

    How to Get Cybersecurity Experience When Nobody Will Hire You

    Aspiring cybersecurity professionals face a frustrating paradox: entry-level positions require years of experience that seems impossible to obtain without first getting hired. While common advice suggests building home labs and earning certifications, most candidates struggle to translate these activities into credentials that hiring managers actually recognize as meaningful experience. In this episode, Professor Simon explains what hiring managers really mean by experience and how to transform your learning activities into credible evidence of capability. You'll discover why simply completing tutorials isn't enough, and learn practical strategies for demonstrating judgment, decision-making, and professional maturity through documentation and communication—even before landing your first security role. In this episode you'll learn: Why building elaborate home labs doesn't automatically create experience that hiring managers recognize What hiring managers actually mean by experience and how they evaluate candidate capability How to document your learning activities to demonstrate judgment and decision-making rather than just activity completion How to identify and articulate security-relevant experience in IT roles you already hold Why documenting failures and learning from mistakes provides stronger evidence of capability than only showing successes How volunteer work and community contributions create real accountability that home labs cannot replicate Practical steps to immediately change how you approach projects to build credible, demonstrable experience 🎥 Companion YouTube Video: https://youtu.be/hozGJyPl49g 📖 Companion Blog Post: https://professorsimon.com/blog/how-to-get-cybersecurity-experience-when-nobody-will-hire-you 🎧 More Podcast Episodes: https://professorsimon.com/podcast 🧭 Figure out which cybersecurity path fits you: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 🌐 Website: https://professorsimon.com 💼 LinkedIn: https://www.linkedin.com/in/leonardsimon 📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity Careers IT Careers & Professional Development Cybersecurity Certifications Cybersecurity Skills & Training Security Operations Governance, Risk & Compliance (GRC) AI Governance & Emerging Technology Identity & Access Management (IAM) Vulnerability & Risk Management Security Awareness & Human Risk Cloud & Infrastructure Security Security Leadership & Strategy SOC 2 & Regulatory Compliance ISO 27001 NIST Cybersecurity Framework (CSF)

  • S1 · E14
    August 10 · 13 min

    You Have Security+. Why Can't You Get a Cybersecurity Job?

    You studied for Security+, passed the exam, and started applying for cybersecurity jobs. But you're not getting interviews, and you're wondering what went wrong. The uncomfortable truth is that the market changed faster than the advice did. Security+ has become so common that it now represents a minimum baseline rather than a competitive advantage. In this episode, Professor Simon explains why certifications alone are no longer sufficient for landing cybersecurity roles, what employers actually need beyond baseline credentials, and what you can realistically do to demonstrate capability and stand out when you don't already have cybersecurity job experience. In this episode you'll learn: Why Security+ shifted from being a competitive differentiator to a compliance baseline requirement The critical difference between knowledge recall tested by certifications and the judgment employers actually need Why many entry-level cybersecurity positions actually require prior IT experience despite their job titles What specific capabilities employers try to assess that certifications cannot prove How to build demonstrable security skills through home labs, projects, and community contributions Why getting IT foundation experience often provides a more realistic path into cybersecurity work Strategic approaches to targeting security-adjacent roles that build your track record over time 🎥 Companion YouTube Video: https://youtu.be/irFdZnP921w 📖 Companion Blog Post: https://professorsimon.com/blog/security-plus-cant-get-job 🎧 More Podcast Episodes: https://professorsimon.com/podcast 🧭 Figure out which cybersecurity path fits you: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 🌐 Website: https://professorsimon.com 💼 LinkedIn: https://www.linkedin.com/in/leonardsimon 📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity Careers IT Careers & Professional Development Cybersecurity Certifications Cybersecurity Skills & Training Security Operations Governance, Risk & Compliance (GRC) AI Governance & Emerging Technology Identity & Access Management (IAM) Vulnerability & Risk Management Security Awareness & Human Risk Cloud & Infrastructure Security Security Leadership & Strategy SOC 2 & Regulatory Compliance ISO 27001 NIST Cybersecurity Framework (CSF)

  • S1 · E13
    August 7 · 5 min

    Nobody Owns AI Governance at Your Company. That's the Problem.

    Who owns AI governance at your organization? If that question takes more than a few seconds to answer, you may already have a governance gap. In this episode, I explore one of the biggest challenges organizations face as AI adoption accelerates: unclear ownership. While legal, IT, security, compliance, and business units all play a role, many organizations still lack a single accountable owner who can make timely, consistent decisions about AI use. You'll learn why shared responsibility often leads to no real accountability, how governance gaps emerge in practice, and what organizations can do to build an AI governance program that keeps pace with technology. Why AI governance ownership is unclear in many organizations How legal, IT, security, and business teams each own only part of the problem Why AI adoption is moving faster than governance policies Real-world examples of how governance gaps create business risk Why shared responsibility is not the same as accountability Practical steps for establishing effective AI governance ownership How to build governance processes that encourage adoption while managing risk 📝 Companion Blog Post https://professorsimon.com/blog/ai-governance-ownership 🎥 Companion YouTube Video https://youtu.be/azS9C9IoUUw 🔗 All My Resources & Social Links https://professorsimon.com/links 🌐 Website https://professorsimon.com 💼 LinkedIn https://www.linkedin.com/in/leonardsimon 🎓 CareerVectors Career Assessment https://careervectors.com Who This Episode Is For CISOs and security leaders CIOs and IT leaders AI governance professionals GRC professionals Risk and compliance teams Legal counsel Internal audit teams Technology executives responsible for AI adoption If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone responsible for AI, cybersecurity, governance, or risk management. Subscribe for practical episodes covering: AI Governance Cybersecurity Leadership GRC AI Risk Management Security Leadership NIST AI Risk Management Framework Vendor Risk Management Security Program Management Cybersecurity Strategy CISSP Career Development vCISO Best Practices

  • S1 · E12
    August 5 · 9 min

    Cybersecurity, IT, or Computer Science? How to Choose the Right Bachelor's Degree

    Trying to decide between a bachelor's degree in Cybersecurity, Information Technology, or Computer Science? The right answer depends on your career goals, not the name of the degree. In this episode, I share a practical framework for choosing between the three most common technology degrees. Drawing on more than 26 years in IT, over a decade teaching cybersecurity at the university level, and experience mentoring thousands of students, I explain the strengths, tradeoffs, and career opportunities each path offers. Rather than telling you which degree to choose, my goal is to help you make the decision that's right for your interests and long-term career plans. The differences between Cybersecurity, Information Technology, and Computer Science degrees Why reviewing the curriculum matters more than the degree title The strengths and tradeoffs of each degree path How each degree aligns with different career goals Why an IT degree can provide flexibility across multiple technology disciplines When Computer Science may be the better choice How to future-proof your education and career My own educational journey from IT to cybersecurity leadership 📄 Free IT vs. Cybersecurity vs. Computer Science Degree Guide https://professorsimon.com/guides/degree 📝 Companion Blog Post https://professorsimon.com/blog/cybersecurity-vs-it-vs-computer-science-degree 🎥 Companion YouTube Video https://youtu.be/QiMnRY7C1go 🔗 All My Resources & Social Links https://professorsimon.com/links 🌐 Website https://professorsimon.com 💼 LinkedIn https://www.linkedin.com/in/leonardsimon 🎓 CareerVectors Career Assessment https://careervectors.com Who This Episode Is For High school students exploring technology careers College students choosing a major Career changers entering IT or cybersecurity Parents helping students evaluate degree programs Academic advisors and career counselors Anyone deciding between Cybersecurity, Information Technology, and Computer Science If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone trying to choose the right technology degree. Subscribe for practical episodes covering: IT Careers Cybersecurity Careers Degree Advice Career Planning Certification Strategy GRC Security Leadership Resume Strategy Interview Preparation CISSP Career Development vCISO Best Practices

Showing 1–20 of 23 episodes