What will the information security department of the future look like? The future workforce will look somewhat different than the current workforce, according to Alan Ross, senior principal engineer at Intel. IT security functions will likely change because computing itself is changing so much—and Intel is at work preparing for the new security landscape.“Our compute models have evolved along with our users’ expectations; we are no longer in the compute paradigms that [built] the environment we have today—or a few years ago,” Ross says. “Cloud computing, consumerization, BYOD [bring your own device], application development and transparency of information have put us at the point where we need to shift the focus of our IT strategy and architecture.”[See part 1 of Inside Intel: The evolution of IT security] Even while shifting their focus to these new areas, organizations must continue to build on key security issues that are important now, including business intelligence, application security, data protection, identity and access management, and infrastructure.“Based on these key focus areas and the combination of the threat landscape, legal and regulatory environments, and new compute models, we see some new focus areas emerging for the security of the workforce,” Ross says. These emerging areas and job functions include security data scientists who will work with big data, visualization, correlation and prediction tools; privacy technologists who will focus on using technology to ensure that privacy laws and policies are being met; user experience professionals who will focus on how security affects the way users interact with systems; and application security experts.Application security “is redundant to the key focus areas, but we see this area changing most rapidly and a skill gap here,” Ross says.Intel is preparing for these changes in the workforce by developing a security data scientist curriculum, and will begin training interested employees in making the transition. “We are also cross-training technologists on privacy so they can begin to make the change for us toward a privacy-technologist competency,” Ross says.The company has a formal user-experience team and is using the team’s expertise “to help us understand the best way to design user experience into our new security-related offerings,” Ross says. “On the application security front, we are training our developers on a secure development lifecycle and also working toward the right tools, technologies and behaviors to enable a secure application landscape.”Companies, including Intel, will surely face challenges in meeting the security expertise demands of the future. “We will continue to find it difficult to match talent and passion in the security field,” Ross says. “It is a rare combination when you have employees who are both talented and passionate about their work, and we see the need to continue to scale our security workforce over time, specifically in [the emerging] areas.”[Also read Security managers split on BYOS, skeptical of Android devices]As other companies become aware of some of these needs, Ross says, “we also need to keep our employees growing and engaged along with providing the right level of opportunities.”Another challenge is that technology is moving faster than the traditional IT development lifecycle. “We no longer have the luxury of taking months to years to deliver new capabilities and services to the business,” Ross says. “Security has often been seen as a disabler or [as] hindering development. This means that our business groups will start to look outside of the organization to deliver if we cannot move fast enough and exceed their expectations.” Related content news UK government plans 2,500 new tech recruits by 2025 with focus on cybersecurity New apprenticeships and talent programmes will support recruitment for in-demand roles such as cybersecurity technologists and software developers By Michael Hill Sep 29, 2023 4 mins Education Industry Education Industry Education Industry news UK data regulator orders end to spreadsheet FOI requests after serious data breaches The Information Commissioner’s Office says alternative approaches should be used to publish freedom of information data to mitigate risks to personal information By Michael Hill Sep 29, 2023 3 mins Government Cybercrime Data and Information Security feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO Security news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe