Root To CISO
Do you aspire to become a Chief Information Security Officer?
The Root to CISO podcast provides firsthand career stories from experienced CISOs on their journey to success in the cybersecurity industry. Offering valuable guidance for aspiring professionals in the field through personal experiences and practical advice.
Root To CISO
You Have The Cybersecurity Certification But What Can You Do With It? | Root To CISO Podcast
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
What does it actually take to build a successful career in cybersecurity?
In this episode of Root to CISO, Kris Rides sits down with John Masserini, cybersecurity consultant and experienced security leader, to unpack the real-world skills, experiences, and career decisions that shaped his journey into cybersecurity.
He talks about how his career did not begin with a cybersecurity degree or a perfectly defined career path and how he worked in programming and banking, worked across application development and data center operations, and eventually found himself responsible for securing an early online stock-trading platform.
John also challenges the idea that a cybersecurity degree, certification, or a long list of credentials automatically makes someone job-ready. He explains why hands-on experience matters, why cybersecurity professionals need to keep learning as the threat landscape changes, and why CISOs should invest in structured internship programs to develop the next generation of cybersecurity talent.
In this conversation, we explore:
🔐 How and why cybersecurity education and real-world experience can be very different
🔐 Why hands-on practice can matter more than credentials alone
🔐 How internships can help develop stronger cybersecurity talent
🔐 How working across different roles helps shape careers
🔐 Why continuous learning matters in a rapidly changing cybersecurity industry
🔐 How cybersecurity professionals can become more valuable beyond certifications
Whether you are starting your cybersecurity career, considering a move into cybersecurity, hiring cybersecurity professionals, building an internship program, or already working as a security leader, this episode offers a practical look at what actually helps people succeed in the field.
🎙️ Listen to Part 1 of our conversation with John Masserini on Root to CISO and look out for part 2!
#RootToCISO #Podcast #Cybersecurity #CybersecurityCareers #CISO #CyberSecurityJobs #CybersecurityLeadership
Hi, and welcome to the Root to CISO podcast. It's me, Kris Rides. I'm gonna be your host and I'm gonna be chatting to seasoned chief information security officers about their career journeys. We're gonna be unencrypting their real life stories and searching for the hidden keys to help you fast track your cybersecurity career
kris-rides_2_06-29-2026_141714Hi, everybody. I have John Massarini with me here as my guest on the Root to CISO podcast. John, thank you so much for joining us
john-masserini_2_06-29-2026_171714Thank you for ha- for having me. It's to finally get this done
kris-rides_2_06-29-2026_141714Yes, I know. We've been trying to get this together and, what with sound and quality issues, hopefully none of those will come out. We will actually get there and get this recorded. That's the plan anyway. Um, so thank you again. So I met, just for everybody out there, I met John through the BSides South Florida, which you've been, you know, one of the major people putting that together, which is an absolutely amazing event. Um, I was very blessed to be asked to do the keynote. We did a keynote, uh lunchtime keynote, back there with, some good CISO friends of ours, Margarita and Johan, and talked through their careers, and here we are now doing our Root to CISO. I feel like we're almost coming full circle.
john-masserini_2_06-29-2026_171714Yeah, it was, um, y- first of all, thank you very much for, you know, coming out to a first BSides, you know, making the trip and, and kinda stepping in and doing that keynote. That was, that was amazing and, and I, I mentioned to you before, we just had such positive feedback. Um, you know, we- it was just, it was fantastic. So, you know, I know, I truly appreciate it. I know the other members of the BSides board really appreciate it, and, yeah, look, look forward to having you back on stage pretty soon.
kris-rides_2_06-29-2026_141714Yeah, I love that. It, it was an amazing, amazing event. The turnout for a first BSides was just insane. Um, I've gone to a lot of BSides. I've spoke to quite, spoke at quite a few of them. I've been talking. I just got my approval through for BSides Las Vegas actually, so that will be, I think that's probably about eight or nine years in a row I've spoken there, and I've been there 10-plus years. Great, amazing event, and everybody that puts the BSides events on all over the world just, like, I feel they're so passionate. It's just a great example of the passionate type of people that we have in our industry, and we're blessed for that.
john-masserini_2_06-29-2026_171714Yeah. Truly. Yeah, I mean, you know, the one thing you can always say about BSides is it, it's always, you know... It, it's, it's all volunteer, right? And we do it, you know, I, and I know that the six of us do it we really wanna give back to the community, right? We, we were, you know, we, we all have those folks that helped us when we were just getting into it. Like, I mean, even at this point, before it was like anything, right?
kris-rides_2_06-29-2026_141714Yeah
john-masserini_2_06-29-2026_171714the late '90s, security wasn't a career. Um, but we all can look back and point to those certain people who kinda gave us a little knowledge and helped us on our way and, and, you know, the fact that we can give back to that now in a broader scope, you know, just it, it, it's a ton of work, but that day is so special to all of us and, and, you know, again, just thanks for being part of that.
kris-rides_2_06-29-2026_141714Yeah, of course. Well, again, thanks for putting it on. Um, let's dive into what are you up to currently? What are you doing currently?
john-masserini_2_06-29-2026_171714So, uh, right now, for the last couple of years, uh, I've, uh, been doing, a lot of independent consulting. Uh, so I, I went out on my own, started my own firm. we do, uh... And I, just give you an idea about the firm
kris-rides_2_06-29-2026_141714Yeah
john-masserini_2_06-29-2026_171714um, you know, it's, it's basically me. Um, but I've partnered with, you know, a lot of other CISOs who we, I bring in as we need. I've partnered with a, a another large firm called, uh, Eugene Zanda, who is based in, in, Europe, because we were getting opportunities to do a lot of international work. And, you know, as a, you know, sole single person or even this loose collective of CISOs, know, doing international work was not something we could actually figure out how to do. So, um, you know, joining this Eugene Zanda, uh, there's 50 other of me in Europe, right? So we share work back and forth. We contract work. It, it's actually a, a really good organization. but to- together we are, you know, we, we really focus on a lot of our advisory work, right? So I do, I do a lot of VISO work here in the States, VCISO. Um, I do a lot of assessment work, so specifically NIST CSF assessments, and, I call them technology stack assessments. So really you know, especially when new CISOs come into a role, and are kind of, you know, wondering what they have, what was bought over the years, and all the historical legacy stack that they've now inherited, i'll go in and I'll help them understand, you know, not only what they have, but what's working. You know, where they have gaps, right? Maybe they have three different antivirus platforms and, and, you know, don't have cloud security or something like that, right? So, kind of go in, help them understand all their technology stack, build an ROI to fill any gaps, and get rid of duplicate, uh, solutions, all that kind of stuff. So, that's one side of the house. The other side of the house is, I do a lot of advisory work for, uh, security startups.
kris-rides_2_06-29-2026_141714Mm-hmm.
john-masserini_2_06-29-2026_171714Uh, helping them really understand the market, really how to understand, you know, how to sell to a CISO, right? So I do a lot of that kind of sales training for, for startups. Uh, you know, after, after, you know, kind of being in the seat for over 18 years, you know, everybody wants you, right? Everybody wants to get to the CISO 'cause you have the check and all that kind of stuff. And, you know, I'm never gonna answer any cold email. I'm never gonna answer a cold call, and most CISOs out there don't, right? So getting them to understand a better approach and a better way to handle it, you know, I, I spend a lot of time early in the year at a lot of sales kickoff meetings doing that kind of stuff and, and doing a lot of training and all that. So, um yeah, super busy, doing a lot of different things. Uh, you know what? Uh, well, I know we'll get into this a little bit later, but, um, I consider myself very blessed I actually found a career that I absolutely love, right? I
kris-rides_2_06-29-2026_141714Yeah
john-masserini_2_06-29-2026_171714I do. And even though I'm not behind a desk anymore, I, I'm still so involved, right? Whether it's the doing the virtual CISO work or, you know, incident response or whatever. However I'm helping a company, I still get to help a company, right? So that, that's, you know... Right now it's, it's in a really good place, especially for as long as I've been doing it. It just, um, it, it's just an incredible time
kris-rides_2_06-29-2026_141714Love that. Yeah, I guess must be fun working with companies at all different stages and all different sizes as well, right? Keeps you as, as much as you've been sitting there in the big hot seat at bigger companies, right? All of a sudden doing this, it must give you a lot of, buzz to see your, the growth and how you help companies, right? And how they, how they move on
john-masserini_2_06-29-2026_171714right. And, you know, one day I'll be doing something as, you know, we'll call it basic, but something like writing policies for, you know, a mid-size organization that is trying to go through, you know, trying to go through an audit or something like that, and their policies are either dated or really not applicable. So doing something like that, and then two hours later being on a conference call helping someone architect an entire security cloud solution, right, or an identity management solution. It's literally flipping those hats back and forth that just makes the days just fly by. I- I'll, I'll walk out at, at 6:00, and my wife will look at me, she goes, "Were you ever gonna stop?" I'm like, "I just..." You get so into it sometimes that the time just flies by. So, yeah, it, it's really, it's very different than, you know... It, it's a different kind of day sitting in that, sitting in that seat. You know, there's a ton of pressure, there's a ton of business pressure, every, all that, you know, that goes along with being that CISO. Um, where, you know, now it's very much so, you know, I still get a little bit of that, but most of it is just about helping them get better and helping them solve problems, and that's, that's kind of what the fun part is right now.
kris-rides_2_06-29-2026_141714Yeah. That's, that's amazing. Well, we'll talk a lot more about how you end up, ended up getting to here. I'm sure talk a bit about what's happening in the market at the moment and your thoughts on that. But probably a great place to start and where I normally start with my guests is go right back even to school, very first job. What, what, you know, see how that transition through to getting here was. So what did you start by doing? And did you go to school? You studying?
john-masserini_2_06-29-2026_171714Yeah, I, you know, I really tried to, think about what I was doing before was on a keyboard. And I, and you know, I, I struggle a little bit with it 'cause I really don't remember, right? As far back the-- I was, I was in my early teens and, um, I was, I was literally pumping gas in a gas station. Uh, and I had saved up enough money. Technology had always been kind of my thing. I always loved reading about technology. Um, I used to subscribe to this magazine called Omni, right? And it was all about the future space and, and technology and all that kind of stuff, and it, it was fantastic. And, and, had, uh, uh, I had an opportunity to buy a 512K Mac from a friend's brother who graduated from Drexel, right? So he w- he, he had no need for this thing anymore, so I, I, I, I took that and, you know, that was my first computer. And that was, you know, I was, I was 14, 15 years old. you know, and then I had to save up for a modem, right? And,
kris-rides_2_06-29-2026_141714Right
john-masserini_2_06-29-2026_171714all this stuff and, you know, I-- when I started looking for schools, I'm like: Well, what do I wanna do? I, I fell in love with programming because, you know, I, I was able to buy that Mac and, um... Actually, never got a college degree.
kris-rides_2_06-29-2026_141714Uh-huh.
john-masserini_2_06-29-2026_171714Um, I took courses that taught me what I wanted to know, right? So I, I took a whole bunch of math courses. I took a whole bunch of, of programming courses. Um, I, I basically got my first job, running overnight operations at a bank in Princeton, New Jersey. So they were going through-- They were installing a new computer system. They needed somebody to come in and, and kinda run the batch jobs at night. So I was doing that at night, and I was going to school to learn COBOL programming and, and ALGOL programming during the day. so that was kind of the the, the first, you know, step into technology a- a- and all that. And, you know, a- again, just kind of between school and the whole banking system runs used to run on COBOL.
kris-rides_2_06-29-2026_141714Yeah
john-masserini_2_06-29-2026_171714to, you know, immediately what I learned in school that day or that night, you know, in, in, in, uh, at work. So it was, it really just kind of evolved from there. Um, I-- You know, back then security, like I said, security wasn't a thing, so I was always doing application development. Uh, that's, where I started. So, you know, that bank, uh, was, was bought out, and I kinda went to another bank up in North Jersey. I eventually worked for, a company called EDS, Electronic Data Systems, based
kris-rides_2_06-29-2026_141714Yeah
john-masserini_2_06-29-2026_171714the old Ross Perot, the old Ross Perot days. and they, the, the software that, that bank was running that I'd become, pretty adept at, um they built a data center up in North Jersey. We were running about 30 banks on that, on that platform. So I ran the whole application development and system development team, up there. And, and it was just, it, it was programming. I did, you know, we, we would be responsible for in- installing and implementing their networks. So I had, you know, we were running ATMs. I, I had my hands, you know, one day I was in code, the next day I was trying to figure out network connectivity and run operations and do all sorts of stuff. So living in that data center world back then when, there weren't that many regulations where I could, you know, I could literally be a programmer and then run the programs at the same time, which, you know, obviously is a no-no. But, you know, back in those days, you, you were able to learn everything and, and get your hands on everything. And, boss at the time, who ran the whole data center, got transferred to Charlotte, for one of the big banks down there. And, he gave me a call one day and he said, "Look, they want to build a website, and they want to allow their customers to trade stocks on the internet. Do, do you know anything about this? Because they're worried about security and all sorts of stuff." so I'm like, "I do." And eight months later, I, I was living in Charlotte, right? And it was, uh... And that was, that was my first foray into the security side of things. I got
kris-rides_2_06-29-2026_141714me ask you, let me ask you a couple of questions about that. So,
john-masserini_2_06-29-2026_171714Mm-hmm.
kris-rides_2_06-29-2026_141714So, um, so I think, well, one thing you mentioned that I think's, uh, like still absolutely relevant today is that while you were at school and you were learning this stuff, you were then putting it into practice very quickly. And I think a lot of people that are out there that are paying for certifications and getting all of these letters after their name, then go into an interview and all they can answer is the book stuff, right? So actually, what you're talking about there is something that I've always promoted and I think is a great piece of evidence that if you can take what you're learning and put it into some sort of practice, hopefully that's in a job, but if it's not, at least into something at home, a lab or whatever, or building your own sort of tool or program. Um, there's a lot to be said, about that. Um, so that, that's a great example
john-masserini_2_06-29-2026_171714100%. You know, one of the, one of the challenges, and, and I'll, I don't intend this to be controversial, but whenever I happen to make this comment in public or in a bar, it ends up being
kris-rides_2_06-29-2026_141714go. Get ready.
john-masserini_2_06-29-2026_171714The, this is my struggle with, the current college and university programs, right? They teach stuff and, and I think it's, it comes to security, it is highly visible. It's less visible in technology in general. But when people you know, people get out with bachelor's or master's in information security, they walk into a place and they think, you know, they deserve the, you know, $150,000, $200,000 paycheck because they now have this degree And they really don't understand or know what the real world of security is like. And it's not their fault, right? I don't blame the students.
kris-rides_2_06-29-2026_141714Yeah
john-masserini_2_06-29-2026_171714they're be what they're being taught, you know, was an issue, was a challenge, was a problem years ago, The way specifically the security space evolves, it's, it's hard for someone to walk... You know, if, if you are coding in C#, if you know how to program, that language is that language. You walk in, you sit down at your desk, you get your workstation, and you can start coding, right? It's not necessarily that way in the security space, right? Every thing, every day when we walk in, we're fighting a challenge that didn't necessarily exist six months ago,
kris-rides_2_06-29-2026_141714Yep
john-masserini_2_06-29-2026_171714That evolution is something that, you know, i- is, is a challenge for when you hire people based on degrees alone, right? I-- One of the things that I am the biggest proponent of, for CISOs to do is get the internship programs going, right? I love, you know, having that they come, they spend six, eight weeks over summer working in my shop, understanding my business, my, my company, my, my security program. You get out of school, come here first. I want you here, right, 'cause we've invested in you already. And, and that I think is all too often overlooked, right? And, and all in all, it's not that expensive, right? You, you spend, you know, $2,500 a week for six or eight weeks to get a student in, right? You do something like that. It's such a great program, and that, that's-- And, and that is... You know, I didn't have-- There weren't internships back then when I was coming up through this, but I had the luxury of going to school and working at the same time,
kris-rides_2_06-29-2026_141714Yeah
john-masserini_2_06-29-2026_171714So it's kind of, you know, the same kind of concept where I learned something at school and I went, "Well, th- it works," or, "It doesn't quite work that way, but I understand," right? So yeah. I mean, the, the... honestly, one of the reasons why I like certifications like the CISSP or anything from I- ISC2, EC Council, and some of the others it's not just taking the test, it's your responsibility to keep up to date, right? To know what's going on. So, you know, just because somebody has a string of letters after their name doesn't necessarily mean they know how to do their job, having the right ones does,
kris-rides_2_06-29-2026_141714Yes
john-masserini_2_06-29-2026_171714think, another thing that's, you know, people are always the, the longer, you know, the more alphabet soup they get, the better, you know, the higher paycheck they can demand, and that's not necessarily the case.
kris-rides_2_06-29-2026_141714Yeah, absolutely. There's, I'm a big believer, people-- I get asked, that's the most, one of the most common questions that I get asked, which is, "Which certification should I do?" Like, and there isn't, one answer. Yeah, if you're experienced, right, a CISSP is the one you'll see mostly on a job description. That doesn't necessarily mean it's the right one to get. Um, what is the right one? And my big push is like, what area are you interested in? What can you take today and learn and put immediately into practice, right?
john-masserini_2_06-29-2026_171714Hmm?
kris-rides_2_06-29-2026_141714What's gonna work that way? So yeah, I'm a, I'm a big believer in that. I just got back from a conference in Chicago, uh, I'll say last week. By the time this comes out, it'll be a few weeks ago. Um, but that was called SCIAD, the SCIAD Conference, Cybersecurity Across Disciplines. It was at a community college, and there was a lot of centers for academic, excellence that were there teaching cybersecurity, and I was on an AI in the workforce, panel. I did a hosted CISO panel about the careers as well, so I did a couple of things while I was there. But it was a really amazing conversation with a very different audience and, you know, those people, those colleges are, are desperate to teach the up-to-date things to keep ahead of it, and they want their students coming out being able to add value for day one. And one of the biggest headaches that they all have is not enough companies offering internships and, and then all the companies expect that they'll just be able to pluck people at this level, you know? But at some point, there won't be people at that level if nobody's bringing them up, right? So
john-masserini_2_06-29-2026_171714Yeah,
kris-rides_2_06-29-2026_141714what you're talking about is absolutely ideal. Is there anything, I mean, anything that you would say in terms of people, like if you were talking to another CISO about, bringing in interns any of the value that you've seen through doing that? You know, not only just to give back, but anything that maybe the previous companies you've worked for has seen value, because I think that's worthwhile talking about.
john-masserini_2_06-29-2026_171714Yeah, I, I think, look, I, I think having an internship program is something needs to be a program, right? It- it's not, um, oh, just, "Yeah, we'll take two people and stick them in a room and have them rewrite policies," right? That's
kris-rides_2_06-29-2026_141714Right
john-masserini_2_06-29-2026_171714where you're gonna get your value, right? We always-- So when we were-- We typically, in an enterprise, in the summer, in the fall, you start working on next year's budget, right?
kris-rides_2_06-29-2026_141714Mm-hmm.
john-masserini_2_06-29-2026_171714there's always, during that process, um, we'd always come up with a project that we could get the internship, budget approved, that would be the, the project for the interns, right? Um, and it was more than, like I said, it was more than just a paper exercise. It was, you know, maybe, you know, automating some sort of reporting or, or, you know, helping, helping our businesses understand or, you know, expedite, I don't know, management, right? What- whatever the project was, there was, there were clear objectives and deliverables and, you know, honestly, we would assign one of our regular architects or engineers to, to oversee the project and to contribute and, and to the work on the project. But the goal was really around getting the interns to understand just how my program worked, but how the business worked, Um but it is, it does take a concerted effort, and if you think you're just gonna bring in cheap labor, it, it, it, doesn't work, right? I mean, it doesn't benefit anybody. You know, I still keep in contact with people who were interns for me 10 years ago, 15 years ago, right? you know, it just giving them that foundation I think is critical, right? And, and it's regardless of the education, Because one of the first questions I ask is, "Okay, great. You went to school. What do you do out of school? Have you ever, have you ever installed Linux on a laptop? Have you ever built your home net?" Right? Have you built a gaming platform?" Right? Anything that shows there's an initiative there is what I wanna see on my, my interns that are coming up
kris-rides_2_06-29-2026_141714Yeah. Yeah, wow. I think, I'm sure we'll talk about the, the magic two letters that are the most popular thing in the world right now, later. But I think that gives you a lot of ability to do a lot more stuff than you could even do before. Um, let's get back to your career, 'cause I realize we, we, we got s- sidelined a little bit there, but that happens. This is welcome to Root to CISO, this is how it happens. Um, so, uh, so you were just when I think we left off, you were just telling me that, um, you just got your first sort of cybersecurity opportunity.
john-masserini_2_06-29-2026_171714Mm-hmm.
kris-rides_2_06-29-2026_141714Um, what were you doing you know, when that came about? How did you jump in? I think securing a website to trade stocks, right?
john-masserini_2_06-29-2026_171714Yeah. And it, it was, y- the, the financial institution, uh, that I was, that, had hired EDS at that point, they were actually, you know, I would say, a fairly early adopter of technology, right? and there was this, there was this... Man, he, he, he was a bit of a curmudgeon, who, who ran security, for the bank. I mean, they, You know, this was way early. You know, the CISO title was not something that was tossed around very often. but, uh, you know, my job was to help him get the security around this, this web app up and running. So, you know, he was, he was, one of these lifers at the bank and, he was, he was a bit of a, bit of a hard ass. But taught me, again, almost like I was an, an intern, taught me so much about how viewing it from his side, right, from the bank, being responsible for the bank, not just being someone who ran, you know, ran the website or the application. Um, but the whole process of, you know, connecting the pieces together, right, from the back end, literally the back end mainframe, right, that was, decades old at that point, and how we were gonna get the customer data and how we were gonna authenticate and how we were gonna do the trades and all that kind of stuff. It was just, wildly informative. And, during that, critical three years in my career, it was just, spectacular, right? It was just, like, something that, um, you know, it, it was just so informative and, you know, just being on, a place where my job was cyber. It wasn't even, we called it information security back then. But it was, it was just such an amazing experience, right, to be, to be in, in, in kinda the belly of the beast at that point. and, everything went wildly successful. I mean, it's not anywhere near what the kind of functionality you see today. Um, but it was, it was stock trading 1.0 and it was-- it, it did what they wanted, right? And that's all
kris-rides_2_06-29-2026_141714Yeah. I mean, the first things never are, right? That's what everybody builds on. So that's like
john-masserini_2_06-29-2026_171714Yeah
kris-rides_2_06-29-2026_141714The platform that everybody looks at and says, "Right, where do we go next from here?" So that's amazing. It sounds to me like, like a crucial part of that was understanding the, where business and security fitted together
john-masserini_2_06-29-2026_171714Absolutely. Right? And, and, and not just business, but, you know, when I was, when I was back at the data center We had regulators, right? We ran 30 banks. The, but back then they would come in and go, "Okay, your the, the blank checks, are they secured?" "H-how do you, how do you ensure, how do you prove that the trial balances match every night?" It, wasn't, it wasn't the, the, the kind of security that you would get today, right? That it was just... A-again, nobody, nobody really, knew about it, right? I mean, none of our banks back then were really connected to the internet. I mean, you know, the biggest wide area network you had were your ATM networks, right? That was, that was kind of it so but they would always come in because they always had questions about application development, right? How are you, how are you testing it? Are you testing it in production? Are you validating the code that's going in? All that kind of stuff. So I got comfortable doing the regulatory side. Whenever they came in, if it weren't for application development, it was al- I was always the point person, so 'cause I'd be able to manage operations or help them through it, right? So when I went to, when I went to Charlotte, um, seeing the SEC involved because of the stock trades and all that, again, very different flavor of regulatory involvement and inspection and, and all that, right? You know, they, they wanted to make sure that everything was cool and, and, I wasn't being audited as a, data processor. They were being audited as a bank, right?
kris-rides_2_06-29-2026_141714Yeah
john-masserini_2_06-29-2026_171714it was, um, you know, it was same concepts, regulations, all that kind of stuff, just at a different level. So, that really woke me up to going, "Okay, this is, there's... You know, we used to get away easy, right? You know, th-this is really what, this is really what the banks go through and, and, and all that." So, that whole experience was, quite amazing and, and understanding it. My boss kind of looked at me and said, "Okay, well, what do we do next?" And, so we started, we kind of packaged up the, the little security stuff and started selling it to all of the other, the other, large financial institutions that were customers of EDS at that point. so we, we did that for, a-another year or so. And, headquarters down at, down in Plano said, "You know, we, we love what you're doing. we want you to either come to Plano and do it for commercial, or go to DC and do it for government." And, I said, "Well, I think I'm gonna take option C." And, I joined a, a security consulting firm. I moved back to New Jersey and joined a security consulting firm.
kris-rides_2_06-29-2026_141714Amazing.
john-masserini_2_06-29-2026_171714It was just the having that experience and being able to, as much as I love security, being able to consult in security back then, that was just, that was amazing. So,
kris-rides_2_06-29-2026_141714And especially as I feel like with EDS you're, like as well as that you're consulting across different companies. So a bit like you're, what you're doing now, right? Helping multiple companies. Doing that, like gives you kind of a different I, I, I, so when I first come across to the States, I've been in recruitment 25 years, but when I first come across to the States, I was in New York City for three years building a consulting business for a recruitment company focused just on banks, just on banking. So I have a pretty good knowledge of what was happening. It's quite a long time ago now, but it was so much fun to have all these different people that would work at different places. They would finish their contract or their consulting gig, and then we would place you into, place them into a next one working on all these different projects. And so it was so much fun doing that. Were you, were you doing that as a single person or did you have a team of people at that point? Or at what point did you kind of get the opportunity to move into that leader- more of a leadership position?
john-masserini_2_06-29-2026_171714So that was, um, we would, we would I would be responsible for kind of building the solution.
kris-rides_2_06-29-2026_141714Mm-hmm.
john-masserini_2_06-29-2026_171714but we always, the consultancies were always back in Plano, right?
kris-rides_2_06-29-2026_141714right
john-masserini_2_06-29-2026_171714so it, it was, um,, we had a, we had a team of about 12 in Charlotte. Um, and we were all, you know, I, I would not consider myself a leader back then, but I was kind of the lead
kris-rides_2_06-29-2026_141714Right
john-masserini_2_06-29-2026_171714the security side. Because again back in, the, the late '90s, there really wasn't a business line for security, right? It was just kinda, there were bits and pockets in here and there that were doing it. So, I knew that there were, you know, a, a few dozen people between Plano and Washington, DC where, if we wanted to roll out a firewall, we had experts that could help us stand up a firewall, right? And, that's, that's really what it was back then. Um, there, there was, there was no discussion around building a cyber team in, in Charlotte at all.
kris-rides_2_06-29-2026_141714Wow.
john-masserini_2_06-29-2026_171714everybody
kris-rides_2_06-29-2026_141714Yeah
john-masserini_2_06-29-2026_171714gonna be, you know, these little, you know, network engineering will take care of their part, and, the server, the, the platforming team will take care of the server side and all that kind of stuff. So it was never, it was never an independent kind of career path. That, my boss right then, that's when I got my CISSP, when I was in Charlotte,
kris-rides_2_06-29-2026_141714Right
john-masserini_2_06-29-2026_171714you know, trying to explain whole concept of, the domains and all that kind of stuff. He, he, he was one of my best friends at the time, and he was just like, "Look, just go do it, and if it's gonna make your career better, I'll take... That's fine. I'll, I'll approve it." So
kris-rides_2_06-29-2026_141714It's good to have the support. Always good to be, have a, good relationship with your boss, right? That gets, goes to show
john-masserini_2_06-29-2026_171714Exactly.
kris-rides_2_06-29-2026_141714Well, good. Let me, I'm gonna stop you there 'cause I'm realizing we're about halfway point, and then we're gonna come back, and I wanna go back to you, you getting and starting into a security consulting company, 'cause I'm interested in, in that, 'cause that sounds like your first sort of, not first dedicated role, but a first dedicated company with a, like, a truly security-focused outlook. So yeah, let's, let's come back to that. I'm gonna thank everybody for joining us so far on part one. Love to leave you hanging. Me and John will continue speaking in, like five minutes, and we'll record part two. But everybody else is gonna have to, wait another week before they hear what's coming next. So thanks a lot, John.
john-masserini_2_06-29-2026_171714Thank you
Speakerthank you for listening to the Root to CISO podcast. If there's something you really want me to ask on the next episode, or if you're a CISO who wants to inspire the next generation, please reach out. I'll leave a URL to my LinkedIn profile and make sure you connect and message me there. We're always looking for feedback, so please don't forget to like, comment, and subscribe wherever you get your podcasts.