Anyhow, I think I elaborated in other places. I don't think it is a bad role, but as a tech first, programming first type of person I would never be a CISO. Even as a manager I want to manage interesting technical things and spread knowledge and skills of how to build (secure) interesting technical things to people. CISO and risk management roles everywhere herd cats and don't really get to do that. So you have to keep in mind my perspective. Comp and top end of the risk management and information security management career can be really rewarding, but it is a mostly thankless job trying to get people to do things that no one will ultimately like all that much even if it is the right thing and they know it :)