Skip to main content
BUSINESS-RESOURCE • 12 min read

Women in Cyber: Rachael Held on inclusion, imposter syndrome, and making the business case for security

As part of our ongoing series spotlighting cybersecurity leaders within our community, we sat down with Rachael Held, Cyber Security Director at Carpenter Technology, to talk about her unconventional path into the field, why she believes cyber security has stayed one of the more inclusive industries around, how she's building hiring paths that don't depend on the connections or money someone happened to start with, and the advice she'd give to anyone starting out or switching careers into cyber.

From English literature to securing metals manufacturing

Rachael's path into the field started about as far from a technical degree as it gets.

"It's a long and winding road, because cybersecurity didn't exist when I was in school. It didn't exist through a good half of my career in IT. I'm a cybersecurity director for a speciality metals manufacturer. I've worked for the same company for about 13 years. Before this I worked in local government in an IT and systems/network admin role. My degree is in English literature. It, conceptually, has absolutely nothing to do with what I do today."

A self-described "giant nerd," she'd placed out of most of her college math and science requirements in high school, but chose to study something she actually loved rather than something practical, later pivoting based on financial practicality.

"I decided to do English literature because I wanted to be an editor. I started a PhD, but there was no financial support, and I looked at it and thought, I can't be a quarter million dollars in debt for a degree that doesn't guarantee any financial benefit. It's also kind of a nepotism game, and I didn't know anybody. So I left grad school and went home and had to find a job, like every 21-year-old. I found one teaching people how to use their computers and software. Language comes easily to me, whether it's spoken or computer language. That ability to master languages and think critically translated directly into figuring out how to tell a machine what you want it to do."

That teaching job led to a systems and network admin role through a former student, and eventually, through a professional contact, to Cartech, where she's spent the last 13 years.

“It's the best place. Manufacturing is a wonderful place to be who you are, regardless of what that is, and contribute to something bigger. No one cared what I looked like. Nobody cared about anything other than what I could produce. I've thrived there because if you can demonstrate the value you say you can provide, you move up."

Building the "stickiest" department in the company

Rachael says her employer's emphasis on internal talent and retention shaped how she now runs her own department.

"The place I work is very big on building internal talent and keeping people, and I've carried that into my own department. What can I do to make us the stickiest department, the one people don't leave? You don't leave a job if you like it, if you like your management, if you like your pay and your future. Rachael is deliberate about making sure the door doesn't stay open only to people who already know the right person, or can afford the right certification. “People helped me get here, professional connections and mentorship gave me the opportunities I needed to succeed, so I try to pay that forward."

Why she'll never require a certification for an entry level job

Asked whether cybersecurity still offers a level of career mobility that other industries have lost, Rachael agreed, and said it shapes how she hires.

"That's the only way any of us ended up with these jobs. A lot of people in leadership are in their 40s and 50s, and this field didn't exist when we were in school, or we didn't have the chance to go to school for it at all. It's been a welcoming subgenre that prizes skill and intellectual curiosity over anything else. We all came up the informal way, and we'd like to keep that door open for everyone else, what matters is your actual ability to do the job."

She's blunt about what she does and doesn't require of applicants, precisely because certifications cost money and time that not everyone has.

"You don't have to have a Security Plus certification to apply for an entry level job at my organization. Is it nice to have? Sure. Does it say you paid the money and did the test and paid your dues? Yeah, that's fine. Does it guarantee an interview? No, not if you have something else, a list of things that show you're interested in this and you understand how computers work. That's the key. I run a SOC, intrusion analysts. The most basic skill you need is understanding how computers and software work well enough to recognize when something is weird. Demonstrated understanding of those fundamentals matter more to me as a hiring manager than a degree or a certification, unless that certification actually proves you're technically sound."

Rachael is equally direct about wanting a wider range of backgrounds on her team, not just for fairness, but because it improves the work itself.

"I want to work with people from a wider range of  backgrounds, people like me who didn't start here but found their way here. Diverse groups bring different life experiences and different relationships with society and technology. That's genuinely useful in incident response and intrusion analysis. Varying opinions and peer review are extremely important in this industry. It doesn't help anyone to sit in an echo chamber. I hate being told I'm right all the time. Nobody is right all the time."

Still, she notes the experience for young women entering the field hasn't changed as much as she'd like.

“The people I hire straight out of school still have the same experiences I had, and it makes me sad.I have a female intern who's the only woman in her classes. She also happens to be the curve breaker, someone whose grades are so high everyone else has to keep up with them. I respect her for it, because I was that person in school. I have an analyst I also hired out of my intern program who had the same experience. I'd desperately like that to change."

The worst thing you can hear is "yes"

Rachael's approach to building trust with her team starts with reframing what people are actually afraid of.

"What's the worst someone can say? I don't know, or no. It’s helpful to keep in mind when you’re nervous about approaching someone, especially someone more senior.Some of the best mentor advice I ever received was: telling me yes is actually the worst thing you can do to me, because now I've got a mission and I have to go do the thing I said I needed to do. I was perfectly happy with no. No means I don’t have to do all the work entailed with the project or the ask, I can continue my day with no new responsibilities. No is fine."

That extends to how her team treats the rest of the business.

"We've built a culture where people aren't afraid of us. We're not the police, we're not going to get anyone in trouble. If something even looks weird, I want you to tell me about it, I don't care if you're wrong. I'd rather spend six hours looking at nothing than have someone be too afraid to tell me about something that might become an incident. We also don't blame victims, period. It's not your fault, mistakes happen, you're not the criminal here. We don't do gotcha phishing tests either. Once a year we'll run something deliberately obvious and ugly, and all we want is for people to click the report button, just to make sure it works and have that engagement. That's built a much better relationship than trying to catch people out. We want a collaborative relationship with the rest of the business, not one built on fear."

The payoff, she says, is a workforce that acts as advocates rather than potential victims.

"They become empowered to push back. If they get a scam call or a threat, they come to us first. They can be resolute and advocate for security instead of ending up a victim. I've seen it play out and I love it. Troll the scammer. Tell them no."

On imposter syndrome and being the adult in the room

Asked about the hardest part of leading her team, Rachael didn't point to a technical challenge.

"Leading is easy if you lead by example and make sure everyone understands the mission and its value. The hardest part for me is imposter syndrome. There's no rulebook, nobody wrote it down. Most of this job is relationship building, meeting people where they are, providing security as a service that makes them feel more comfortable. I spend a lot of time looking around thinking, I get to decide? There's no adult in the room to check with, and then you make the decision anyway. What people value in me is the ability to make an informed decision without dithering, but internally I'm screaming that I need an adult. There comes a point in your life when you look around and realize you're the adult in the room. You are the subject matter expert. That's the imposter syndrome, right there."

She's noticed a pattern in who feels it most, and traces some of it back to the same access gaps she's spent her career trying to close.

"Most women in my position feel it, and most people of color in my position feel it.I think it's because these places weren't built for us. They don't look like us, we have to make them look like us, and it makes you feel not entirely sure you belong in the club. I often make the joke that they shouldn't have let a poor person into this club, because now I tell everybody all the new things I've learned from no longer being a poor person, so that they don't stay poor people either."

Eight months pregnant, and applying for the job anyway

Rachael's own move into cybersecurity came almost by accident, and at an unlikely moment.

"I wish someone had told me that nobody knows what they want to be when they grow up, and sometimes you see a shiny object and you chase it. I was a manufacturing systems and network support engineer, I built and maintained systems and networks, and I loved that job. But cybersecurity became more interesting to me as it became more real to my industry, ransomware became something anyone with a credit card and internet access could pull off, and that hit my industry, and my livelihood, hard. It was also just a fun puzzle. 

I started dabbling, low-key reaching out to the cybersecurity manager at my company. I was about eight months pregnant with my second kid when a senior engineer role opened in that department. I applied, figuring there was no way I'd get it since I was about to go on maternity leave. I went out on leave, and two months later, they offered me the job."

She's since built her career on the idea that technical skills transfer more readily than people assume, and encourages others to have the same courage.

"Systems admin skills, network admin skills, they're the same muscles as intrusion analysis, even red team skills. It's just a question of what you're doing it for. I switched careers completely around 35, close to midlife, and now I'm the director. Do it. What's the worst that can happen? Someone tells you no. If that happens, go ask somebody else."

Cutting through the AI hype cycle

Asked how she'd advise early career professionals worried about AI making their jobs redundant, Rachael pushed back on the premise.

"I'd stick with fundamentals. There's nothing new under the sun. Yes, technology will change how we interact with it, that's absolutely true, and there's a real skills gap in learning to use new technology for something useful. But I remember when the cloud was going to change everything and everyone was going to get laid off. It's the same story every time. When people say 'thought leaders,' they usually mean billionaires running companies that want you to buy their product. Is the technology a solid advancement? Yes. Is it going to help both defenders and criminals? Also yes. But it's not going to take entry level jobs, in my opinion. A human brain is more qualified to make those judgment calls than a machine, especially recognizing what's normal versus what isn't."

Skepticism around AI’s role in the SOC aside, Rachael is genuinely enthusiastic about some of the new tooling, particularly for people without a coding background.

"I love being able to talk to a machine in plain language instead of code. I think it's going to upskill a lot of SOC analysts who aren't coders, make them better and faster, right up there with the ones who can code. There's real room for this to upskill solid people, but like any programming language, you have to understand what you're asking the machine to do, and then fact check it."

She's more skeptical of the layoff narrative than the technology itself.

"A lot of the big companies that laid people off because of AI are now trying to hire them back. It's not cheap. People think the machine will be a more cost effective form of labor, and it just isn't, once you account for everything it takes to run it. Will there be innovation? Absolutely. Is it already being used for something terrible? Absolutely. But it's not new, it's cyclical, we'll deal with it like we've dealt with every wave before. There is a large need to secure it across all the realms of Cybersecurity that I believe will generate a need for a new skill set to master and new positions in cybersecurity."

Turning risk into dollars: how she translates security for the business

Rachael has spent years learning how to make the case for security investment to leadership, and says it comes down to consistency and facts.

"It's a multi-year effort to speak business to the business. Leadership has to see cybersecurity as important and separate from IT. I've seen a lot of industries fail badly by folding security under the IT umbrella. The organization has to understand the risk cybersecurity poses to the business to prioritize it. In manufacturing, it's well understood that cybersecurity is probably the greatest risk to the business outside of acts of God, we have to keep people safe while keeping the lines running and keep product going out the door. Once leadership understands that, you have to be ready to actually be told yes, you can't show up with grand visions and then fail to execute on them."

That means framing everything in terms leadership already uses.

"It's not lofty missions, it's ‘here are the risks, here's what we're doing about it, here's what we see coming. We are prudent with our spend and don’t chase controls or products we don’t see value in. We talk to our insurance underwriters too, cyber insurance is a major expense for any organization, and ours has gone down year over year because we work at it. That's a real goal you can set as a leader: what does your underwriter want to see to bring that number down? 

Boards and executive leadership like benchmarking against other organizations in our space. You can't just tell me you're great because you're great, show me the evidence: your controls, security by design, how you've reduced your attack surface relative to the goals and imperatives you have established. And how does that compare to others in our industry?"

Rachael points to a specific example of turning cybersecurity into a business ally rather than a blocker.

"A few years ago, some of our manufacturing peers were struggling to get investment to upgrade aging equipment. So we built a risk register: how much would it cost if this line went down right now, here are the assets involved, their age, what happens, ransomware aside, just what happens. Put a dollar figure and a downtime figure on it, which matters enormously in manufacturing, and they got the capital requested the following year to replace it all. “

"Can we just turn it off?": what she's geeking out on right now

Rachael's current interests sit at the unglamorous but high leverage end of the field.

"I have the ability to use agentic tools in my environment to reduce false positives and flag the right things to my SOC's attention, and I love it because I don't have to try as hard anymore. It's lowered the barrier of entry enough that even a manager like me, who doesn't code anymore and doesn't want to, can use it effectively. I'm also really focused on identity controls right now, especially in ecosystems where everything is on by default and shouldn't be. With all the phishing kits automating exploitation of things that never should have been turned on in the first place, my favorite form of vulnerability management is just asking: do we even need this? Can we turn it off? I'm running a bunch of identity and token controls through design and test right now, and I'm genuinely excited about it."

A key takeaway for those breaking into cyber

"Don't sleep on manufacturing for cybersecurity. It desperately needs talent, and nobody knows it's there. It's not flashy, but it's a good job with long-term stability."

We left Rachael with one quickfire, industry-old debate:

True or false: the best blue teamers learn to think like red teamers, and vice versa?

"True. They're two sides of the same coin. If you don't understand how something works, you're never going to be good at defending or exploiting it. If you understand how to exploit something, you understand how to defend it too. It’s about recognizing what you see. Know your adversary, on either side."

authorJoanna Duffy
Aug 25, 2026

Recommended

Get more insights, news, and assorted awesomeness around cyber training.

Join over 640 organisations upskilling their
workforce with TryHackMe