# The CISO Who Took the Job Nobody Else Wanted — and Never Looked Back


Russ Kirby didn't plan to run enterprise security for one of the world's largest identity platforms. He took a role because someone had to, realized he was good at it, and then kept going. Three CISO posts and one global function at Hewlett Packard later, that accidental entry point looks less like chance and more like the kind of self-knowledge most executives spend decades faking.


Kirby is now global CISO at Ping Identity, the identity and access management firm that merged with ForgeRock — his previous employer — in 2023. That merger alone made his arrival unusual: he didn't interview for the Ping role so much as he came bundled with the acquisition. What kept him there is a different question, and the answer says something useful about how security leaders who don't burn out are actually wired.


## Personality Isn't a Hobby — It's Infrastructure


Kirby describes himself as a Type One on the Enneagram — principled, improvement-driven, oriented toward order, and by his own account, a "protector" subtype. Dismiss the framework if you like, but the underlying point is serious: he came to security because his cognitive architecture fits the work, not because the money was good or the title was impressive.


"I like finding the micro in the macro," he says. That phrase is doing more work than it looks like. Security at an enterprise level is precisely the discipline of holding two cognitive modes at once — the zoomed-out threat model and the granular log entry that breaks it. People who can't genuinely enjoy that oscillation tend to burn out or mistake noise for signal.


What's notable is that Kirby can articulate *why* he's suited to this job. That kind of self-legibility is rarer than it sounds. Most CISO conversations trend toward strategy-speak and threat landscape summaries. The ones that actually offer signal tend to start with someone being honest about their own wiring.


## From Accident to Architecture


The path to his first CISO role was not strategic. A company needed the role filled. Kirby took the challenge. He was good at it.


That's the honest version of how a lot of security careers start — necessity over aspiration — and there's nothing wrong with it. The distinguishing factor isn't how someone enters the field; it's whether they build an architecture around what they've learned or just accumulate years. Kirby did the former. After the first CISO role demonstrated fit, he actively sought the next one rather than waiting for it to find him.


Two years at Creditsafe. Four at ForgeRock. Then Ping Identity, where he now oversees enterprise security, product security, GRC, and privacy — the full stack of modern organizational risk, not just the firewall layer.


The word he uses for his good fortune is "luck," which he then immediately interrogates: luck isn't passive chance, it's the willingness to act on an opportunity when it appears. That combination of opportunity-recognition and willingness to commit is a specific skill, and in security it matters because the window for organizational transformation is almost always short. CISOs who wait for perfect conditions typically find the window closed.


## "Don't Let Perfect Be the Enemy of Good" — and What It Actually Means


The advice Kirby flags as most influential sounds like a motivational poster. In security contexts, it's genuinely contentious.


Perfectionism in security isn't just career-limiting; it can be operationally dangerous. A control that goes undeployed because the implementation isn't flawless leaves an organization more exposed than an imperfect control that's actually running. Patch management programs that stall on edge cases leave production systems vulnerable longer. Incident response plans that never get exercised because they're not "finished" fail under real conditions.


The "good enough" principle, applied rigorously, is actually demanding: it requires knowing what threshold constitutes adequate protection for a given context, then executing to that threshold quickly rather than deferring. That's harder than perfectionism, which has the comfort of an endless receding horizon. "We're not quite ready" is easier to say than "this is sufficient for current risk, deploy it."


Kirby spent four years at ForgeRock running security for an identity platform — software that authenticates and authorizes access to essentially everything else in an enterprise stack. If you're looking for a context where "good enough thinking" requires genuine precision rather than lazy trade-offs, identity security is it. A misconfigured access policy isn't a performance problem; it's an initial access vector.


## What Keeps Him Up


The truncated version of what worries Kirby most points toward the structural tensions that define enterprise CISO life in 2026: product security obligations running alongside enterprise security obligations, privacy requirements that vary by jurisdiction, GRC programs that need to speak credibly to boards that are increasingly security-literate (or at least liability-aware).


At an identity platform specifically, the stakes have a particular character. Ping Identity's software sits in the authentication path for a large fraction of Fortune 500 organizations. A compromise at the platform layer doesn't just hurt Ping — it potentially hands an attacker a skeleton key to dozens or hundreds of downstream enterprises. The CISO of an identity vendor is, in a meaningful sense, a CISO for many organizations simultaneously.


That's not a role that rewards burnout. It rewards passion, in the functional sense Kirby means: sustained, genuine engagement with technical detail, organizational complexity, and adversarial thinking that doesn't deplete the way forced enthusiasm does.


---


## HackWire Analysis


The CISO burnout crisis is well-documented at this point — retention data from multiple surveys over the past three years shows median tenure hovering around 18 months to two years, departures driven by impossible accountability gaps (full liability, incomplete authority), board impatience, and the psychological weight of defending against adversaries who only need to be right once.


Kirby's account runs counter to the burnout narrative, and it's worth asking why. The obvious answer is passion, which he names directly. But passion alone isn't sufficient — the security field is full of people who were passionate and still burned out. The more precise explanation appears to be congruence: Kirby's personality architecture, his cognitive preferences, and the actual demands of the CISO role are genuinely aligned. He isn't performing enthusiasm for a job that drains him; the job is doing what his brain wants to do anyway.


That's not a scalable hiring recommendation — organizations can't personality-test their way to CISO retention. But it does point toward a structural problem that the industry keeps skirting: the CISO role as currently constructed selects for people who are good at *getting* the job (political skill, communication, board-facing presence) without necessarily selecting for people who are good at *sustaining* it under adversarial conditions. Kirby came up through the work itself, not through a career track optimized for the title.


The identity security context is also worth flagging. Ping Identity operates in a segment that is simultaneously the most targeted (identity is the primary initial access vector in the majority of enterprise breaches in 2025-2026) and the most operationally loaded for a CISO (platform security obligations extend to customers, not just the internal organization). That Kirby is three years in and speaking with what sounds like genuine engagement rather than managed exhaustion is notable.


The "good enough" principle he cites as formative deserves more credit than it usually gets. In a sector that tends to fetishize control maturity frameworks and perfect compliance postures, the willingness to ship adequate protection quickly rather than defer indefinitely is a genuine competitive advantage for defenders.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Tools](https://www.hackwire.news/category/tools) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)