Professor Simon's IT and Cybersecurity Podcast

Professor Simon

Welcome to The Professor Simon IT & Cybersecurity Podcast, where we go beyond the textbook with real-world career advice, practical guidance, and lessons from the field. Whether you're breaking into IT or cybersecurity, building your skills, transitioning careers, or planning your next move, you'll gain practical insights to help you make better career decisions and understand what the work actually looks like. Topics include careers, certifications, IT fundamentals, SOC, GRC, leadership, AI, cloud security, and more. Cyber & IT Beyond the Textbook.

  1. 1d ago

    What Does a Penetration Tester Actually Do All Day? (Reality vs Expectation)

    Most people imagine penetration testers spend their days breaking into systems and exploiting vulnerabilities. The reality is quite different. For every three hours spent on technical exploitation, you might spend fifteen hours documenting findings, writing reports, and communicating with clients about remediation. In this episode, Professor Simon walks through what professional penetration testers actually do during a typical engagement, from scoping and rules of engagement through reconnaissance, testing, documentation, report writing, and client communication. If you're considering a career in penetration testing, this realistic picture of the profession will help you understand whether your skills and interests truly align with the actual day-to-day work. In this episode you'll learn: Why scoping and rules of engagement define the success of an entire penetration testing engagement before any technical work beginsHow penetration testers actually allocate their time, with reconnaissance and enumeration consuming more hours than active exploitationWhy careful documentation and evidence collection during testing directly determines the quality and usefulness of your final reportHow report writing serves as a core deliverable that must address multiple audiences from executives to technical teams to auditorsWhy communication skills and the ability to explain technical findings in business terms often matter more than advanced technical abilitiesWhat skills you should develop now if you're considering a penetration testing career, including technical writing and client interactionHow to honestly assess whether your interests and strengths align with the full scope of penetration testing work, not just the exciting parts 🎥 Companion YouTube Video: https://youtu.be/Cc0VnbTmWK0📖 Companion Blog Post: https://professorsimon.com/blog/what-does-penetration-tester-do🎧 More Podcast Episodes: https://professorsimon.com/podcast🧭 Figure out which cybersecurity path fits you: https://careervectors.com🔗 Resources, blog & more: https://professorsimon.com/links🌐 Website: https://professorsimon.com💼 LinkedIn: https://www.linkedin.com/in/leonardsimon📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity CareersIT Careers & Professional DevelopmentCybersecurity CertificationsCybersecurity Skills & TrainingSecurity OperationsGovernance, Risk & Compliance (GRC)AI Governance & Emerging TechnologyIdentity & Access Management (IAM)Vulnerability & Risk ManagementSecurity Awareness & Human RiskCloud & Infrastructure SecuritySecurity Leadership & StrategySOC 2 & Regulatory ComplianceISO 27001NIST Cybersecurity Framework (CSF)

  2. 2d ago

    Degree, Bootcamp, or Self-Taught: The Best Path Into Cybersecurity?

    If you're deciding between a degree, a bootcamp, or self-teaching your way into cybersecurity, this video breaks down the real cost and time tradeoffs of each, and more importantly, what actually determines whether any of them work for you. Degree, bootcamp, or self-teaching? This is the number one question I get from people trying to break into cybersecurity, and it's usually asked like there's one correct answer. There isn't. There's a correct answer for you, and in this video I break down exactly how to find it. All three paths genuinely work. All three also genuinely fail people, and usually not for the reason you'd expect. It's rarely about the path itself. It's about whether you actually finish it and turn it into a job search. In this video you'll learn: The real cost and time tradeoffs of a four-year degree, a bootcamp, and self-teachingWhy a degree can still act as a hard filter at some employers regardless of your practical skillWhat you're actually paying for in a bootcamp, and why quality varies so much between programsWhy self-teaching is the cheapest path but also the most likely to quietly stall out foreverWhy momentum beats pedigree at the entry level, and what that means for which path you should chooseMy honest recommendation if you already have a degree in anythingMy honest recommendation if you're starting from nothing and have to be disciplined about itDrop a comment: which of the three are you leaning toward, and what's actually stopping you from starting this week instead of "eventually"? I read these. 📖 Companion Blog Post: https://professorsimon.com/blog/degree-bootcamp-self-taught-cybersecurity🎧 More Podcast Episodes: https://professorsimon.com/podcast🧭 Figure out which cybersecurity path fits you: https://careervectors.com🔗 Resources, blog & more: https://professorsimon.com/links🌐 Website: https://professorsimon.com💼 LinkedIn: https://www.linkedin.com/in/leonardsimon📸 Instagram • X • TikTok: @profsimononline If you found this video helpful, please subscribe, leave a like, and share it with someone who would benefit. Topics covered: Cybersecurity CareersIT Careers & Professional DevelopmentCybersecurity CertificationsCybersecurity Skills & TrainingSecurity OperationsGovernance, Risk & Compliance (GRC)AI Governance & Emerging TechnologyIdentity & Access Management (IAM)Vulnerability & Risk ManagementSecurity Awareness & Human RiskCloud & Infrastructure SecuritySecurity Leadership & StrategySOC 2 & Regulatory ComplianceISO 27001NIST Cybersecurity Framework (CSF)

  3. 3d ago

    What Does an Entry-Level Cybersecurity Resume Actually Need? (Not What You Think)

    Most entry-level cybersecurity candidates are building resumes the wrong way. They're adding every certification, tool, and technology they've encountered, thinking more content equals more credibility. But hiring managers aren't looking for keyword volume. They're looking for credible evidence of capability. In this episode, Professor Simon explains what actually makes an entry-level cybersecurity resume effective. You'll learn why transferable IT experience matters more than generic security terminology, how to present projects that demonstrate real capability, and which certifications and technical skills actually deserve space on your resume. This is about making it easy for hiring managers to see what you can do, not overwhelming them with noise. In this episode you'll learn: Why hiring managers evaluate resumes based on credible evidence rather than keyword density, and what that means for how you structure your contentHow to leverage transferable IT experience from help desk, desktop support, or system administration roles to demonstrate relevant technical capabilityThe specific level of detail needed to describe home labs and projects so they actually demonstrate competence rather than just listing activitiesWhen certifications add value versus when they raise credibility questions, and how to determine which ones deserve space on your resumeWhy listing technologies you can't discuss meaningfully in an interview undermines your credibility and what standard to use insteadHow to identify and present accomplishments that demonstrate problem-solving ability rather than just listing responsibilities or dutiesA practical framework for reviewing your resume from a hiring manager's perspective to identify what provides evidence versus what creates noise 🎥 Companion YouTube Video: https://youtu.be/8paAQIdtO4c📖 Companion Blog Post: https://professorsimon.com/blog/entry-level-cybersecurity-resume🎧 More Podcast Episodes: https://professorsimon.com/podcast🧭 Figure out which cybersecurity path fits you: https://careervectors.com🔗 Resources, blog & more: https://professorsimon.com/links🌐 Website: https://professorsimon.com💼 LinkedIn: https://www.linkedin.com/in/leonardsimon📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity CareersIT Careers & Professional DevelopmentCybersecurity CertificationsCybersecurity Skills & TrainingSecurity OperationsGovernance, Risk & Compliance (GRC)AI Governance & Emerging TechnologyIdentity & Access Management (IAM)Vulnerability & Risk ManagementSecurity Awareness & Human RiskCloud & Infrastructure SecuritySecurity Leadership & StrategySOC 2 & Regulatory ComplianceISO 27001NIST Cybersecurity Framework (CSF)

  4. 4d ago

    Stop Trying to Learn Every Cybersecurity Tool (Learn This Instead)

    If you're trying to gain hands-on experience with every security tool listed in job descriptions, you're making your learning journey much harder than it needs to be. In this episode, Professor Simon explains why chasing individual product knowledge creates an overwhelming and unsustainable approach that leaves you feeling perpetually unprepared. You'll discover why foundational understanding of underlying technologies makes tool knowledge transferable, how to decode what job descriptions really mean when they list specific products, and how to build a learning strategy that actually scales as your career progresses. This shift in perspective transforms an impossible checklist into a clear and manageable path forward. In this episode you'll learn: Why memorizing tool interfaces without foundational knowledge creates skills that don't transfer when technologies changeHow security tools within each category solve fundamentally similar problems using similar approachesWhat job descriptions really signal when they list specific products versus what they require you to know before applyingWhy employers expect to train new hires on specific tools but cannot afford to teach foundational technology conceptsHow to decode job postings by identifying tool categories and underlying capabilities rather than treating each product as separatePractical strategies for building deep knowledge in representative tools while developing transferable foundational understandingHow to evaluate whether your learning approach creates knowledge that will serve you throughout your career 🎥 Companion YouTube Video: https://youtu.be/jAERtOA9bbg📖 Companion Blog Post: https://professorsimon.com/blog/stop-trying-to-learn-every-cybersecurity-tool🎧 More Podcast Episodes: https://professorsimon.com/podcast🧭 Figure out which cybersecurity path fits you: https://careervectors.com🔗 Resources, blog & more: https://professorsimon.com/links🌐 Website: https://professorsimon.com💼 LinkedIn: https://www.linkedin.com/in/leonardsimon📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity CareersIT Careers & Professional DevelopmentCybersecurity CertificationsCybersecurity Skills & TrainingSecurity OperationsGovernance, Risk & Compliance (GRC)AI Governance & Emerging TechnologyIdentity & Access Management (IAM)Vulnerability & Risk ManagementSecurity Awareness & Human RiskCloud & Infrastructure SecuritySecurity Leadership & StrategySOC 2 & Regulatory ComplianceISO 27001NIST Cybersecurity Framework (CSF)

  5. 5d ago

    Why Your Resume Never Reaches a Human (And How to Fix It)

    I've reviewed a lot of resumes from people trying to break into cybersecurity, and the most frustrating part isn't when someone lacks experience. It's when someone has real, relevant experience and their resume never makes it in front of a human being, because it got filtered out by an applicant tracking system before anyone even opened it. In this episode, Professor Simon explains what an ATS actually does before a recruiter ever sees your resume, the specific formatting and language mistakes that get strong candidates filtered out anyway, and why the popular advice to stuff your resume with keywords is exactly the wrong fix. In this episode you'll learn: Why your resume competes against software before it ever reaches a human reviewerHow formatting choices like tables, columns, and graphic layouts get your job titles and dates silently dropped by parsing systemsWhy mismatched job title language between your resume and the posting can cost you a match even when the work is equivalentWhat separates a skills section that scores well from one that just lists tool names with no contextWhy quantifying your impact matters as much for ATS matching as it does for a human readerWhy keyword-stuffing your resume, even invisibly, backfires with both modern systems and human reviewersWhat to actually prioritize if you're applying and hearing nothing back 🎥 Companion YouTube Video: https://youtu.be/c5_4cX6Rua0📖 Companion Blog Post: https://professorsimon.com/blog/resume-mistakes-ats-filtered-out🎧 More Podcast Episodes: https://professorsimon.com/podcast🧭 Figure out which cybersecurity path fits you: https://careervectors.com🔗 Resources, blog & more: https://professorsimon.com/links🌐 Website: https://professorsimon.com💼 LinkedIn: https://www.linkedin.com/in/leonardsimon📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity CareersIT Careers & Professional DevelopmentResume Writing & Job Search StrategyApplicant Tracking Systems (ATS)Cybersecurity CertificationsCybersecurity Skills & TrainingSecurity OperationsGovernance, Risk & Compliance (GRC)AI Governance & Emerging TechnologyIdentity & Access Management (IAM)Vulnerability & Risk ManagementSecurity Awareness & Human RiskCloud & Infrastructure SecuritySecurity Leadership & StrategySOC 2 & Regulatory ComplianceISO 27001NIST Cybersecurity Framework (CSF)

  6. Aug 28

    Why Access Reviews Fail (And How to Fix Them)

    Most organizations can prove their access reviews happened, but very few can prove they actually worked. In this episode, Professor Simon explores why periodic access reviews often become checkbox exercises that generate compliance documentation without preventing privilege creep or excessive permissions. You'll discover the organizational, technical, and human factors that cause well-intentioned reviewers to rubber-stamp permissions they don't understand, and learn practical approaches for designing access review processes that produce real security value instead of just audit artifacts. In this episode you'll learn: Why reviewers lack the technical and business context needed to make informed access decisionsHow incentive structures reward completing reviews quickly rather than completing them carefullyWhy compliance metrics and audit evidence don't guarantee effective access controlThe limitations of periodic reviews and why they can't catch problems in real timeHow to frame access review questions in business terms that reviewers can actually answerPractical strategies for providing context that helps reviewers identify anomalies without investigating every permissionComplementary controls like just-in-time access and automated deprovisioning that reduce reliance on periodic human review 🎥 Companion YouTube Video: https://youtu.be/vSwQeHvboIE📖 Companion Blog Post: https://professorsimon.com/blog/access-review-checkbox-exercise🎧 More Podcast Episodes: https://professorsimon.com/podcast🧭 Figure out which cybersecurity path fits you: https://careervectors.com🔗 Resources, blog & more: https://professorsimon.com/links🌐 Website: https://professorsimon.com💼 LinkedIn: https://www.linkedin.com/in/leonardsimon📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity CareersIT Careers & Professional DevelopmentCybersecurity CertificationsCybersecurity Skills & TrainingSecurity OperationsGovernance, Risk & Compliance (GRC)AI Governance & Emerging TechnologyIdentity & Access Management (IAM)Vulnerability & Risk ManagementSecurity Awareness & Human RiskCloud & Infrastructure SecuritySecurity Leadership & StrategySOC 2 & Regulatory ComplianceISO 27001NIST Cybersecurity Framework (CSF)

  7. Aug 27

    You Don't Need 100% of Job Requirements to Apply | Career Advice for IT & Cybersecurity

    Many IT and cybersecurity candidates eliminate themselves from positions they're actually qualified for because they don't meet every single requirement listed in the job description. They assume these postings represent minimum qualifications and that applying without meeting 100% of the criteria wastes the employer's time. In this episode, Professor Simon explains why job descriptions are wish lists rather than checklists, how to identify the core competencies that truly matter, and how to make strategic decisions about when you're qualified enough to apply. You'll learn to distinguish between trainable gaps and knowledge gaps, decode the language employers use to signal flexibility, and understand why the candidates who get hired often aren't the ones who checked every box. In this episode you'll learn: Why job descriptions typically describe idealized candidates rather than minimum requirements, and how understanding the hiring process changes how you evaluate your qualificationsHow to identify the core job function by reading past technology lists to find the fundamental activities a role actually requiresThe critical difference between trainable gaps in specific tools and knowledge gaps in foundational concepts, and why this distinction determines whether you're qualifiedHow to decode job description language to identify which requirements are flexible and which are truly essentialWhen you're qualified enough to apply despite missing 20-40% of listed requirements, and when gaps are too significant to bridgeHow to address missing qualifications strategically in your application by emphasizing transferable skills and demonstrating learning abilityWhy employers routinely hire candidates who don't meet all posted requirements, and how talent shortages create opportunities for strong partial matches 🎥 Companion YouTube Video: https://youtu.be/JB1ByJh8x7E📖 Companion Blog Post: https://professorsimon.com/blog/you-dont-need-100-percent-job-requirements-to-apply🎧 More Podcast Episodes: https://professorsimon.com/podcast🧭 Figure out which cybersecurity path fits you: https://careervectors.com🔗 Resources, blog & more: https://professorsimon.com/links🌐 Website: https://professorsimon.com💼 LinkedIn: https://www.linkedin.com/in/leonardsimon📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity CareersIT Careers & Professional DevelopmentCybersecurity CertificationsCybersecurity Skills & TrainingSecurity OperationsGovernance, Risk & Compliance (GRC)AI Governance & Emerging TechnologyIdentity & Access Management (IAM)Vulnerability & Risk ManagementSecurity Awareness & Human RiskCloud & Infrastructure SecuritySecurity Leadership & StrategySOC 2 & Regulatory ComplianceISO 27001NIST Cybersecurity Framework (CSF)

  8. Aug 25

    Accepted Risk Management: Why Your Old Risk Decisions Need Review

    Most organizations have formal processes for accepting cybersecurity risks, but almost none have real mechanisms for ensuring those decisions get revisited when conditions change. In this episode, Professor Simon examines why accepted risks become permanent fixtures in risk registers, the organizational dynamics that prevent their review, and what happens when decisions made years ago continue to shape your security posture despite dramatically different circumstances. You'll learn practical approaches for treating risk acceptance as a time-bound commitment rather than a permanent status, including how to implement expiration dates, define reassessment triggers, and build sustainable review processes that actually fit within normal security operations. Whether you're inheriting a risk register full of old decisions or trying to prevent new acceptances from becoming invisible, this episode provides the framework for maintaining an accurate view of your organization's actual risk posture. In this episode you'll learn: Why risk acceptance decisions based on specific conditions at a point in time become outdated as circumstances change, yet persist indefinitely in most organizationsHow accepted risks disappear from active attention while new risks receive scrutiny, creating risk registers that grow less accurate over timeThe impact of personnel turnover on institutional knowledge about why risks were accepted and what assumptions justified those decisionsWhy most risk acceptance processes focus exclusively on approval workflows while neglecting ongoing management and reassessmentHow to implement mandatory expiration dates and reassessment triggers that force deliberate renewal rather than indefinite persistencePractical approaches for assigning ownership and creating lightweight review processes that actually happen within operational constraintsStrategies for auditing inherited risk registers and building sustainable accepted risk governance that maintains accuracy without creating compliance theater 🎥 Companion YouTube Video: https://youtu.be/H9wKc2YNebw📖 Companion Blog Post: https://professorsimon.com/blog/accepted-risk-management-review🎧 More Podcast Episodes: https://professorsimon.com/podcast🧭 Figure out which cybersecurity path fits you: https://careervectors.com🔗 Resources, blog & more: https://professorsimon.com/links🌐 Website: https://professorsimon.com💼 LinkedIn: https://www.linkedin.com/in/leonardsimon📸 Instagram • X • TikTok: @profsimononline If you found this episode helpful, please follow the podcast, leave a rating or review, and share it with someone who would benefit. Topics covered: Cybersecurity CareersIT Careers & Professional DevelopmentCybersecurity CertificationsCybersecurity Skills & TrainingSecurity OperationsGovernance, Risk & Compliance (GRC)AI Governance & Emerging TechnologyIdentity & Access Management (IAM)Vulnerability & Risk ManagementSecurity Awareness & Human RiskCloud & Infrastructure SecuritySecurity Leadership & StrategySOC 2 & Regulatory ComplianceISO 27001NIST Cybersecurity Framework (CSF)

About

Welcome to The Professor Simon IT & Cybersecurity Podcast, where we go beyond the textbook with real-world career advice, practical guidance, and lessons from the field. Whether you're breaking into IT or cybersecurity, building your skills, transitioning careers, or planning your next move, you'll gain practical insights to help you make better career decisions and understand what the work actually looks like. Topics include careers, certifications, IT fundamentals, SOC, GRC, leadership, AI, cloud security, and more. Cyber & IT Beyond the Textbook.