This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Karl Sharman. Karl is head of cybersecurity of solutions and consultancy for Stott and May in North America. He has helped build and scale teams across multiple types of business including Fortune 500, Pre-IPO late-stage ventures, early-stage startups, security consultancies, and MSSPs. Karl Sharman is often brought on by companies for either extremely difficult hires, mass hires at speed and scale or discreet leadership hires. As a contributor and a consultant to the cybersecurity sector, Karl contributes with regular white papers, podcasts and public speaking, He was recently featured in the top 1% of Search & Staffing Professionals globally by LinkedIn.
Chapter Titles:
00:10 Introduction
01:34 How to transition to cybersecurity from another profession
05:33 Is soccer not a lot more fun than cybersecurity?
07:52 Commitment, passion, and perseverance for cybersecurity personnel
08:36 Why work at Dark Rhino Security vs Disney, Goldman Sachs, Nike
10:45 Do people quit over money? 14:44 Diverse voices and personnel engagement and being valued
18:26 When a company scales what changes?
22:42 Maintaining your values during hypergrowth
25:24 The one question that should be asked in every interview
26:35 Is it okay to put people under pressure in an interview?
30:45 Strategies that work for cybersecurity companies
34:45 Rapid advancement-get comfortable with being uncomfortable
41:51 Right processes with the right people
43:01 2021 outlook for cybersecurity? Detection and Response?
44:58 Karl Sharman’s upcoming works
Audio:
Important Links:
Transcript
Manoj Tandon: Hello everyone. Welcome to another episode of Dark Rhino Security Confidential. Today, we are honored to have Karl Sharman join us. Karl is the Head of Cybersecurity Solutions and Consultancies for Stott and May across North America. Karl has helped build and scale teams across multiple types of businesses, including Fortune 500 companies, pre-IPO and late-stage ventures, early-stage startups, security consultancies, MSSPs, and MDR organizations. He is often brought on by companies for extremely difficult hires, mass hiring at speed and scale, or discrete leadership hires. Karl is also a contributor to the cybersecurity sector through regular white papers, podcasts, and public speaking appearances. He was recently featured in the top one percent of search and staffing professionals globally by LinkedIn. Thank you for joining us.
Karl Sharman: No, it’s my pleasure. Thanks for having me on.
Manoj Tandon: It’s great to have you. In cybersecurity, we’re seeing tremendous growth in the industry. Hiring people and retention are critical topics. One of the things I’d love to get your opinion on is, for anyone looking to make a career transition into cybersecurity, do you have any pointers on what they should do to get a foothold in the industry?
Karl Sharman: Of course. It’s a huge topic right now. I’m not the biggest fan of saying there’s a shortage of people in cybersecurity because I really don’t think there is. I think there are a lot of people who want to work in security. The issue is often with employers themselves. They have requirements that are very unicorn-like, where expectations are too high for what they’re looking for. It’s an incredibly competitive market, and we need to bring a range of people with different backgrounds to the table to create more security professionals. Transitioning into cybersecurity is one of the best ways to accomplish that. One of your previous guests, Karla, and I have both been strong supporters of people transitioning into security, whether that’s women returning to the workforce after raising children and retraining into cybersecurity, or professionals seeking an entirely new career path. I’m actually a great example of this myself. I started in the soccer industry doing recruitment for Premier League and Football League clubs in the UK. I wanted to try something different in the business world and happened to fall into recruitment because it was similar to what I was already doing in soccer. But I had to learn cybersecurity. I spent time taking courses and learning as much as possible about the industry. So, for anyone making that transition, I think the first thing to consider is education. People immediately think education means time and money, and they want immediate results, but there are accessible ways to do it. Go take a SANS course, work with Cybrary or InfoSec Institute, and complete short certification programs that demonstrate your commitment to the field. You don’t necessarily need a bachelor’s or master’s degree in cybersecurity. Then the second thing is mentorship. I’ve surrounded myself with mentors who are CISOs of major banks and heads of consulting practices. Their finger is on the pulse of the industry, and they provide guidance and intelligence that help shape my own career path. For anyone transitioning, those two starting points are critical: education and mentorship. Don’t be afraid to ask people for their time.
Manoj Tandon: A couple of things. First, isn’t football a lot more fun than cyber?
Karl Sharman: I get that a lot. Obviously, I lived what many people consider a dream job. I got to watch soccer for free every day, travel across Europe, and visit incredible stadiums. But the flip side is that it’s long hours, you don’t see your family much, and it can be an incredibly political and cutthroat environment. It taught me how to defend myself, how to promote myself, and how to navigate the politics of the boardroom. I learned a tremendous amount during that time. But I work for more than money. What drives me is adding value to people’s lives. In soccer, you’re often just moving players between contracts. In cybersecurity, you can genuinely help companies defend themselves and protect their operations. That gives the work a deeper purpose for me.
Manoj Tandon: There are no easy jobs worth doing. Commitment, passion, and perseverance are traits we always look for when hiring. I think you’re absolutely right about mentors and education. Most people are looking for someone who is motivated and willing to learn.
Karl Sharman: Exactly. There are so many companies that can’t compete with the top banks or major corporations. People get fixated on wanting to work at Disney, Nike, or Goldman Sachs, but sometimes the better route is starting at a smaller company like Dark Rhino or a twenty-person organization. There are stepping stones in every career. You might have to start as an IT manager or administrator before transitioning fully into cybersecurity. One thing I always tell people is that there is no straight line to becoming a CISO. Everyone wants that title eventually, but there isn’t a direct path. You need mentors, continuous learning, and opportunities that push you outside your comfort zone. That’s where growth happens.
Manoj Tandon: Let me ask you this: do you think people quit primarily because of money?
Karl Sharman: The primary reason people quit is because of their managers. We can’t get around that. Politics, leadership issues, and poor management are still the biggest drivers. Salary is part of it, especially because cybersecurity professionals can often jump for ten to twenty percent increases, but it’s not the only factor. People also chase prestige. Working for a Goldman Sachs or Citigroup carries status and recognition. But retention is about much more than money. Companies need to focus on engagement, development, and making people feel heard and valued.
Manoj Tandon: That’s something we focus heavily on at Dark Rhino. We’re a smaller company, but we try to provide flexibility and quality of life. People can bring their dog or child to work if they need to. We also give employees exposure to interesting projects and specialized work they might not see at larger organizations.
Karl Sharman: Small businesses have a huge advantage there because employees feel like they have access to leadership. Scaling becomes one of the hardest challenges because engagement can easily get lost as companies grow. I always look at organizational design through the lens of accessibility. How much access do employees have to their managers? How connected are they to leadership? That’s where companies succeed or fail. People want to be listened to and valued. Too many organizations rely on money alone instead of investing in development and engagement. If employees don’t feel heard or trusted, they leave.
Manoj Tandon: Every interview really is a two-way interview.
Karl Sharman: Absolutely. Candidates should do due diligence on companies. Ask about career growth, promotions, and how employees are developed. If the interview process feels completely one-sided, you’re probably not talking to the right organization. People want to feel like their contributions matter.
Manoj Tandon: When companies go through hyper-growth, how do they maintain cultural fit and values while scaling?
Karl Sharman: Honestly, people overcomplicate scaling. All you’re really doing is adding more people. The key is maintaining the core values that got you there in the first place. Look at companies like DoorDash, Disney, or Netflix. Their values haven’t fundamentally changed as they scaled. Netflix has always focused on hiring A-players. Disney still operates around the principles Walt Disney established decades ago. The mistake companies make is assuming they need to reinvent everything as they grow. You don’t. You just need to maintain focus on culture, communication, and engagement.
Manoj Tandon: One question I always think about is whether it’s okay to put candidates under pressure during interviews.
Karl Sharman: It’s a really interesting question. In soccer and organizations like the Navy SEALs, they try to replicate real-world situations to see how people respond under pressure. Security interviews should balance technical validation with candidate experience. Companies need to think carefully about whether their interview process is efficient, engaging, and reflective of real-world work. There’s a balance between testing someone’s skills and creating an environment where candidates actually want to join your organization.
Manoj Tandon: What do you forecast for cybersecurity in 2021?
Karl Sharman: I’d never say there’s ever a “good” year in security, especially when you have incidents like SolarWinds happening. But from a recruitment perspective, it’s an incredibly exciting market. There are more companies hiring and more opportunities than ever before. Areas I see continuing to grow include product security, cloud security, incident response, detection and response, and DevSecOps. Those are all areas where organizations are investing heavily right now.
Manoj Tandon: Karl, as a final question, is there anything you’d like to plug or let our audience know about?
Karl Sharman: We’re doing a lot of white papers and research projects right now, particularly around product security and incident response. These papers provide insights into the industry from both candidate and hiring manager perspectives. If anyone listening is interested in those sectors or considering a career in them, definitely keep an eye out for those reports on our LinkedIn pages and websites.
Manoj Tandon: If listeners want to connect with you, what’s the best way?
Karl Sharman: LinkedIn is the best place to start. My contact information is usually on there, and people are always welcome to reach out.
Manoj Tandon: Karl, thank you so much for joining us this afternoon. It was a wonderful conversation. We deeply appreciate your time.
Karl Sharman: Thank you. I appreciate it.
To learn more about Karl Sharman visit his LinkedIn
Check out the other episodes in Season 3:
Ep. 0 Tyler Smith – Cyber Basics: Training the End-User
Ep. 1 Manoj Tandon – Was it worth it? Lessons Learned
Ep. 2 Chenoa Moss – Healthcare IT: Innovation at the Speed of Life
Ep. 3 Karla Reffold – Do Women make more Money in Cyber?
Ep. 4 Nick York – How the OITA is helping Tech in Ohio
Ep. 5 Dr. Calvin Nobles – How Human Factors Can Impact Cybersecurity
Ep. 6 Karl Sharman – How to Hire and Retain Cybersecurity Personnel
Ep. 7 James Azar – How Secure is Your Organization?
Ep. 8 Jordan Graham – Business Lessons from a Bowhunter
Ep. 9 Chris Auger – Why Microsoft 365 is difficult
Ep. 10 Jeff Manhardt – The Power of Why
About Karl Sharman

Karl is head of cybersecurity of solutions and consultancy for Stott and May in North America.
He has helped build and scale teams across multiple types of business including Fortune 500, Pre-IPO late-stage ventures, early-stage startups, security consultancies, and MSSPs.
Karl Sharman is often brought on by companies for either extremely difficult hires, mass hires at speed and scale or discreet leadership hires.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
