Back to Writing

    May 2019: In this month's feature Aaron Johnson, Global Cybersecurity Governance, Risk Management and Compliance Leader at Dana Incorporated, shares his story

    May 14, 2019

    Throughout 2019, this mini-series will interview leaders from around the globe to discuss areas of cybersecurity. The purpose is to help students and those new to the industry gain perspective and guidance from professionals in the field. These interview insights aim to kick-start or re-energise your career journey in cybersecurity. This month’s edition features Aaron Johnson, Global Cybersecurity Governance, Risk Management and Compliance Leader at Dana Incorporated , as he shares his story about: How he characterises his role within the cybersecurity ecosystem How he identified and explored various opportunities during his career What, if any, information would he have liked to know starting out in his career What motivated him to pursue his passion How he suggests others new to the field get involved Johnson’s career journey began with 10 years in the United States Navy. He explains how their approach to determine best positional fit has served as the cornerstone for evaluating numerous professional opportunities. “When joining the Navy, they administer a standardised test called the Armed Services Vocational Aptitude Battery (ASVAB). ASVAB does not tell the individual what they are proficient in; rather, the test demonstrates where they may achieve the best results. I wanted to be military police officer. However, I was instead recommended as an electronics technician. While I had no prior electronics experience, I was eager to dive-into the experience.” Johnson’s early career as an electronics technician drove his desire to pursue computing and networking courses at university. “I had not initially considered cybersecurity; however, I connected with a government cybersecurity assurance professional in my network and they asked if I was interested. I jumped at the opportunity!” These are his insights. How would you characterise your role within the cybersecurity ecosystem? Johnson describes his role as the Cybersecurity Governance, Risk Management and Compliance (GRC) leader for a global manufacturing organisation. “The role of GRC can serve various purposes based on the company and the sector. The scope of the conversation can also elude to the differences between the role and responsibility of an enterprise resource planning (ERP) system GRC team and their Corporate Information Technology (IT) GRC counterparts. In this global organisation, I am responsible for cybersecurity: training and awareness governance business engagement assurance activities third party risk management regulatory compliance We wear many hats with various levels of accountability and responsibility as part of a GRC team. My teams often have a variety of skill sets that range from highly technical to those with deep business acumen. Over my career, I noticed people jump into cybersecurity in three ways: as a systems administrator or networking engineer because of their transferable skills as an auditor because of their strong controls background as a compliance person because of their curiosity for technology I came up in compliance and was eager to develop a technology skill set driven by my curiosity and experience with the Navy. I quickly learned the important role governance can play in corporate cybersecurity as the design and implementation of capabilities and controls greatly influenced our ability to better protect critical assets. The right governance model can serve as a business enabler, while the opposite can hinder the ability to flex with market demands and customer trends. In cybersecurity, we are laser focused to secure our environment leveraging the Confidentiality, Integrity and Availability (CIA) model in line with business expectations. This model is at the forefront of every governance-related decision. Our goal is to securely enable the business to achieve their goals and objectives.” How did you identify and explore various opportunities during your career journey? “I never had a pinpoint focus around what I wanted to do; however, I was always open to new opportunities. I may not have always had a specific target company when I was exploring the job market. Rather, I had a general idea of what I wanted to do and evaluated the needs of an organisation against my interests. I continued to find career-related success by leaning on my professional experiences, continuously learning new skills and leveraging the leading practices I had acquired during my journey. I leveraged ASVAB to apply a similar approach with cybersecurity positions – evaluate open roles and their requested skills or qualifications against my prior experiences and desire to continuously up-skill. While organisations may have targeted specific skills, I tailored my approach around my experiences to demonstrate my ability to adapt to numerous situations and learn quickly. I see many young people today that analyse if they are proficient in the skills advertised in a job application and refuse to apply if there is a mismatch. This may be less about a person’s proficiency, and rather their aptitude and curiosity to learn something new. If cybersecurity is an area of interest, I would first suggest gaining an understanding of the foundational components and ask how these apply to your current role as a student or working professional. A similar approach can be applied at home to drive more risk-aware behaviours. This approach has continued to open doors to new professional opportunities. This change in mindset is why I believe I have 30,000 cybersecurity professionals working side-by-side to deliver more secure outcomes for our business.” What, if any, information you would have liked to know starting out in your career? “I wish I would have started my IT education earlier. When I was younger, my grandmother would recall how my grandfather advised to ‘stay away from computers. They were just a fad that will go away. You did not want to find yourself working with something that would not be be around in 10 years.’ This was a wide-spread theory in the mid 1980's - computers were only a trend and would vanish in a decade. I stayed away from computers due to this pressure; however, I wish I would have started my learning earlier. Always pursue your passion and interests irrespective of your career path. This, in combination with your life lessons, education and experiences can serve as a cornerstone to any professional journey. Be prepared for any opportunity - you never want a road block like the lack of formalised education to prevent professional doors from opening.” What motivated you to pursue your passion? “I always had two primary motivations: Hunting challenges . I enjoy the challenge of new, difficult projects that are outside of my comfort zone - potentially due to my natural curiosity to gain familiarity with certain subject matter, the degree of difficulty or level of complexity. These were the types of experiences that always allowed me to grow and expand my knowledge base at an exponential rate. Being a sponge . I always aim to continue to grow professional either via certifications, work with new teams, explore new technologies and engage with professional organisations. I spent a great deal of time with a Network Operations team early in my career and would always ask questions to educate and push myself to continue to up-skill. As a result, I knew when an opportunity presented itself and was of interest, I would be in a good spot to take advantage.” How would you suggest others new to the field get involved? “I have three recommendations for those pursuing opportunities within the cybersecurity space. Ask questions . Engage with your network to learn about their career and areas of expertise. Often in meetings, we will notice numerous heads nodding in agreement. I learned over time to repeat what was said and ask for clarification. I often felt I was the only one who did not quite understand what was said early in my career. I learned over time there was value to ask clarifying questions or ask for further explanation - this approach would often benefit everyone in the room. Never hesitate to raise your hand if something does not sound right or is unclear. Chances are high you are not the only one with questions. Weigh your interests . After years in cybersecurity, I continue to see numerous entry paths for students and those professionals seeking new opportunities. In a previous position I was determining whether I wanted to pursue a technical or business-centred career path in cybersecurity. My boss at the time highlighted that I did not have to decide one route or the other. There was always formal business education, with certifications, day classes, online training and education materials for the more technical track. Refrain from discounting the amount of freely available training and specialised certifications to build technical skills. Be open to new opportunities . Some young professionals attempt to enter the cybersecurity industry with very prescriptive objectives that often miss ‘once-in-a-lifetime’ opportunities in other sectors. I would refrain from excluding an opportunity that may better align with my interests because I was too laser-focused on a cybersecurity domain. We cannot be so quick to forget there is an element of cybersecurity within every role in an organisation and at home.” In conclusion, this month’s edition was supported by Aaron Johnson, Global Cybersecurity Governance, Risk Management and Compliance leader at Dana Incorporated. Cybersecurity is intriguing, in-demand and considered as an excellent career starter. Please be on the lookout for next month’s edition of Decoding Cybersecurity: Interview Insights with Leaders as the journey continues. Please leverage the comment box below to suggest future topics or guests, provide feedback or share with others.