Security BSides Las Vegas 2025

From Help Desk to CISO
2025-08-04 , Florentine B

This talk explores cyber career pathways and draws from the personal journey of Nicholas Carroll, who started his career in entry level IT and ascended to the role of a CISO. We will delve into the challenges and opportunities that shape these kinds of career progressions, providing a roadmap for those starting in entry-level IT roles and aspiring to advanced cybersecurity positions. The talk will highlight the importance of continuous learning, certifications, and hands-on experience in climbing the career ladder. We will also discuss tools to help guide career steps including the Cyber Career Pathways Tool, a resource that helps individuals understand the tasks, knowledge, and skills needed to advance in their cyber careers. Attendees will gain valuable insights into transitioning from roles like IT Helpdesk to more specialized cybersecurity roles, and ultimately to leadership positions like CISO. The talk will conclude with practical recommendations for those looking to move up in their careers, emphasizing the importance of mentorship, networking, and staying abreast of the latest trends in cybersecurity.


In the rapidly evolving field of cybersecurity, the journey from an entry-level IT role to a leadership position like Chief Information Security Officer (CISO) can be both challenging and rewarding. This talk, inspired by the career trajectory of Nicholas Carroll, a CISM certified Cybersecurity Instructor and former CISO, aims to provide a roadmap for those aspiring to climb the cybersecurity career ladder.

The talk will begin with an overview of Nicholas Carroll's career, highlighting his transition from an IT Helpdesk role to a CISO. The talk will also highlight how skills gained outside of IT and cyber can help translate to success in technical fields whether it be troubleshooting as a mechanic, customer service skills in retail, and beyond. This real-life example will serve as a testament to the possibilities that exist within the field of cybersecurity, demonstrating that with dedication, continuous learning, and the right opportunities, one can rise from an entry-level position to a leadership role.

One of the key takeaways from this talk will be the importance of continuous learning and certifications in advancing one's career. Staying up-to-date with the latest trends, technologies, and threats is crucial. Certifications like CompTIA Security+, Certified Information Systems Security Professional (CISSP), and Certified Information Security Manager (CISM) not only validate one's skills but also open doors to new opportunities. We’ll also discuss the pitfalls and limitations of certifications and how to balance the pursuit of continuous education in cost effective ways throughout a career.

The talk will delve into career guidance toolsets including the Cyber Career Pathways Tool, a resource developed by the Cybersecurity and Infrastructure Security Agency (CISA). This tool helps individuals understand the tasks, knowledge, and skills they need to advance in their cyber careers. It provides a clear roadmap for progression, from entry-level roles to intermediate and advanced positions.
Another major takeaway will be the importance of hands-on experience. While theoretical knowledge is important, practical experience is what truly sets one apart. Attendees will learn about the value of internships, co-op programs, and entry-level positions in gaining this experience. Especially in a time when it feels like even entry level cyber jobs require years of experience. They will also learn about the role of projects and contributions to open-source platforms in demonstrating their skills to potential employers and ways to highlight experience outside of cyber in ways that can translate to success in cyber career pathways.

The talk will also emphasize the importance of soft skills in advancing one's career. As one moves up the ladder, skills like communication, leadership, and strategic thinking become increasingly important. Drawing from Nicholas Carroll's experience, the talk will provide tips on how to develop these skills and use them to influence decision-making and drive cybersecurity initiatives within an organization.
The talk will conclude with practical recommendations for those looking to move up in their careers. Attendees will learn about the importance of mentorship and networking in opening doors to new opportunities. They will also gain insights into how to navigate the challenges that come with transitioning to new roles, and how to position themselves for leadership positions, even if they’re just starting out.

In summary, "From Help Desk to CISO" is a comprehensive guide for anyone looking to advance their career in cybersecurity. Attendees will leave with a clear understanding of the steps they can take to move up the career ladder, and the tools and resources they can leverage to achieve their career goals.

Nicholas Carroll is a seasoned cybersecurity professional with a career spanning over two decades. He currently serves as a Manager of Cyber Incident Response with Nightwing, leading a team of cyber threat intelligence and DFIR professionals defending Fortune 500 organizations and government agencies. Prior to this, he held the position of CISO for a state government agency, overseeing election cyber projects. His journey in IT and cybersecurity began at the help desk, providing him with a broad perspective on the field. But his skills earned in jobs outside of IT and cyber helped craft the success he has today. He is also a certified cybersecurity instructor, demonstrating his commitment to continuous learning and knowledge sharing to help grow the field.

This speaker also appears in: