


Mark Alvarado is a digital risk specialist with 19 years of expertise in the IT industry. Currently, he serves Academy Sports + Outdoors as a Director of Cyber Security & IT Compliance, where he is responsible for assisting enterprises in identifying digital risks and recommending solutions or controls to close the gaps.
Alvarado started his career as a business analyst and has served in various positions such as project manager, engineer and assistant admin. He is also a certified IT security specialist familiar with endpoint security, vulnerability management, identity management, data loss prevention, threat remediation, and best practices for securing IT infrastructure. Prior to cyber security, he spent 11 years working in high-speed manufacturing.
What are Some Of The Challenges that You See When It Comes to Security and Compliance in the Organization?
One of the major issues in the cyber security space is hiring good quality professionals. With cybercrime being at an all-time high, the industry already had a shortage of professionals before the pandemic hit. Most companies are still operating remotely, which increases the number of cyberattacks. Thus, overworked cyber security employees are struggling to keep up with the challenges of the job, and employers are struggling to keep hold of them and pay a fair wage.
Today, cyber professionals are aware of their value and want to make more money, especially people when talent recruiters are reaching out via LinkedIn. However, we work in the retail industry, where many of the companies are going bankrupt or not doing so well. Hence, keeping the right individual becomes a challenge. To succeed, businesses must control costs, manage operational challenges, and meet customers' demands.
I tend to target people who are eager to learn and with a strong technical aptitude. I'm willing to teach and build a team rather than bring people who are “rockstars”.
Are There Any Latest Projects You Are Working On Or Have Worked On When It Comes To It Security And Compliance?
We worked on a lot of projects that involved data privacy requirements for the various states. Today, some organizations are always in the news due to violations of FCC, SCC or CCPA rules. Therefore, we make sure to secure customers' data, and comply with GRC requirements in an effort to save prevent the business paying huge amounts of fines.
What Challenges Do You Face While Constantly Using New Technology?
Our company is growing and moving into new marketplaces, that creates challenges. The biggest challenge is keeping bad guys out. From my viewpoint, data is the most valuable thing on the planet. We have many technologies and applications that utilize our data to improve operational efficiencies and the customer experience. Securing the data in these platforms without impeding the business is always a challenge. Companies are learning how to monetize their data, but those technologies also enable bad guys to misuse data. Therefore, it's important for me to secure, manage and utilize customer data responsibly. Data privacy in the coming years will be my challenge. And in my opinion, the challenge of most retail companies.
What Would Be Your Advice For The Upcoming Professionals To Be Successful In This Field?
I think lots of times, people think of security as operational, making sure the bad guys are not in their environment. But if you don't put something in place to address GRC requirements, your business will not be able to operate or do business in certain states that may affect the company's growth. From my perspective, security is a two-headed beast in a large enterprise organization. One head is security operations and focuses on keeping the bad guys out from stealing your data. The second head should ensure that your IT Compliance program can meet federal, state, local and industry data privacy and protection laws.