Need of Product Managers in Cybersecurity
I have been working in Cybersecurity - Identity & Access Management domain from last 14+ years and these days I have been noticing a trend of hiring Product Managers in IAM security controls.
While talking to one of my friend today, I was asked
Why do we even need Product Managers for IAM?
I had great discussion on this topic so thought of sharing the same on this blog.
Before I start sharing my opinion on this topic, I would like to let you know that my focus will be only on Identity and Access Management in the entire post.
I have seen product managers in companies like Oracle, CA, Sun IDM etc. Their primary job was to enhance the Identity Management products with the most needed features., so it's justified to have product manager in IAM team of such companies.
Now let's discuss the second part of this question.
Other companies which are implementing IAM products to meet the business, security & regulatory needs of their organizations are also hiring Product Managers, why?
Companies are becoming more dependent on IT these days and it's impossible to imagine any enterprise without any IT team. There's no doubt that IT is solving many problems for these enterprises but on the other hand it is also bringing many security issues with them. Existing security product and controls may not be sufficient to meet the new challenges.
For example: Earlier only password was sufficient to login into any application, then there was need to implement 2FA to secure access and now there's need to implement MFA (Multi Factor Authentication) & PAM.
Another example: Suppose an enterprise was having its own data centers so they implemented security controls accordingly but due to any reason (saving cost, meeting new business needs etc.) they decide to move partially or completely to cloud so existing controls will definitely not work for cloud.
To overcome these challenges, there's always need to
- Upgrade existing security controls
- Understanding the new needs while working with customers
- Research and Identify new products to meet new needs
- Evaluate different products by working with different vendors
- Evaluate and compare in-house products vs vendor products
- Implement new security controls
- Execution and implementation of these products in the right way ....so on...
All these tasks take time, knowledge and require dedicated professionals, and these dedicated professionals are knows as Product Managers.
Do engineers have time to research the market or to work with customers to understand their business needs? I have also played roles of Engineer, Tech Lead and Architect and some common problems which we face while working with customers is
- We start thinking about solving the problem there itself
- We start analyzing the requirements based on the given product
- We start giving solutions while discussing the requirements
Don't worry.. I have gone through that face.. I don't do that anymore.. 😊
One of the main task of Product Managers is to LISTEN TO THE CUSTOMERS & UNDERSTAND THEIR PAIN which makes this job title different than any existing job title.
I completely understand that this job title is relatively new in some of the companies (in IAM teams) and sometimes it becomes hard to explain this job title to others but THIS IS EXPECTED. It becomes difficult to make those people understand the need of Product Managers who are either new to this domain or have very less experience. One of the reason which triggered me to write this blog post (after talking to my friend). 😊
Professionals with these job titles were not needed earlier because enterprises used to implement minimum security controls just to meet the audit/sox needs but now companies are completely dependent on these. These security controls add value to the brand of the enterprises. Entire enterprise and their brand value can be impacted just because of a single breach.
Hope I am able to clarify, if not completely but to some extent, why do we need product managers in IAM or in Cybersecurity team .
I can keep on writing on this topic for entire night but would like to take a pause here.
Please feel free to drop me an email if you still have doubt and will try my best to respond asap.
Disclaimer
Comments