Written by Brian McGraw on January 27, 2026 | Categories: Security Leadership

Firing Security Team Members: When It’s Time to Act

Empty security team desk with badge representing difficult termination decisions

Nobody teaches you how to fire people in security certifications. The CISSP has nothing on it. Neither does the CISM. But if you lead a security team long enough, you will face this decision. And how you handle it will define your leadership more than any policy you write or tool you deploy.

I have terminated people I genuinely liked. I have delayed terminations I should have made sooner. Both taught me something about what firing security team members actually requires from a leader.

Why Security Teams Are Different

Firing someone on a security team carries weight that other departments do not experience in the same way. Your team operates with elevated access. They know where the vulnerabilities are. They have seen incident details that never left the SOC. The trust required to do this work means that when someone is not working out, the rupture feels more personal.

There is also a scarcity problem. The security job market is brutal for employers and candidates alike. Good people are hard to find, which makes managers hesitant to let go of mediocre performers. I have watched leaders tolerate poor performance for years because they convinced themselves that a warm body with clearance was better than an empty seat.

That math is usually wrong.

The Signs That Termination Is Coming

Performance issues rarely arrive as a surprise if you are paying attention. The trajectory matters more than any single incident.

Pattern of missed commitments. Everyone drops a ball occasionally. But when deadlines consistently slip, when deliverables require multiple revisions that should have been caught earlier, when you find yourself following up on things that should be done, you are watching a pattern form. The question is whether the person recognizes it and is working to correct it.

Resistance to feedback. I pay close attention to how people respond when I give them direct input. Defensiveness once is human. Defensiveness consistently is a problem. If someone cannot hear feedback without deflecting, blaming circumstances, or explaining why the feedback is actually wrong, they have hit a ceiling they may not be willing to break through.

Culture erosion. This one is subtle but destructive. A single team member who consistently complains, undermines decisions in side conversations, or refuses to collaborate can poison a team faster than any external threat. Other team members notice. They start wondering why leadership tolerates it. Your best people quietly update their resumes.

The trust gap. In security, I need to trust that when someone says a control is implemented, it actually is. When someone reports a vulnerability as remediated, I need that to be true. If I find myself auditing someone’s work because I am no longer confident in their accuracy, the relationship has fundamentally changed. That gap rarely closes.

When to Fire Someone on Your Security Team

The decision point is not usually a single event. It comes when you answer three questions honestly.

First, have you given this person clear feedback and a genuine opportunity to improve? Not hints. Not suggestions buried in positive comments. Direct, documented feedback with specific expectations and a reasonable timeline. If you have not done this, you are not ready to terminate. You are ready to start managing.

Second, has the person demonstrated capability and willingness to change? Capability without willingness is a motivation problem. Willingness without capability is a skills gap that may or may not be closeable. Neither without both means you are waiting for something that is not coming.

Third, what is the cost of continued employment? This is where leaders get stuck. They calculate the cost of backfilling a role, which is significant, but they forget to calculate the cost of keeping someone who is damaging productivity, morale, or trust. That cost compounds daily. The security team leadership research is clear: high performers leave teams that tolerate low performers.

When you can honestly say you have given clear feedback, the person has not demonstrated sufficient change, and the cost of inaction exceeds the cost of action, it is time.

How to Do It Right

The actual termination conversation is not complicated if you have done the preparation. Keep it short, direct, and free of ambiguity. This is not a negotiation or a feedback session. The decision has been made.

State the decision clearly in the first sentence. Explain the general reason without relitigating every incident. Describe the logistics of their departure. Answer questions about severance and benefits. Do not apologize for the decision.

What happens next matters as much as the conversation itself. Your remaining team will be watching how you handle the transition. They want to know two things: was this fair, and am I safe?

Address the team promptly but appropriately. You cannot share details of personnel decisions, and you should not. But you can acknowledge the change, express confidence in the team, and be available for questions. The SHRM guidelines on termination meetings provide a solid framework for the mechanics.

The Terminations I Got Wrong

Early in my career, I delayed a termination for eight months because the person was technically competent. Their code reviews were solid. Their incident response skills were strong. But they treated junior team members poorly, took credit for collaborative work, and created an atmosphere where people dreaded interactions with them.

I told myself the technical skills were too valuable to lose. What I actually lost were two junior analysts who quit within six months because they did not see the behavior changing. One of them told me directly in their exit interview that they left because leadership would not address the problem everyone could see.

That was an expensive lesson in what tolerance really costs.

I have also moved too fast. Once I terminated someone during their first week after discovering they had misrepresented their experience in the interview. The facts supported the decision, but I did not slow down enough to document the gap between their claims and their demonstrated knowledge. HR had to clean up my process failure, and it created unnecessary risk.

The Role of Documentation

Documentation is not about building a case for legal protection, though that matters. Documentation forces clarity in your own thinking. When you have to write down specific incidents, the patterns become harder to ignore or rationalize.

For performance issues, I use a simple framework: date, specific behavior observed, impact on team or deliverables, feedback given, and expected change. When I review several months of these entries, the trajectory becomes undeniable. Either the person is improving or they are not.

This documentation also protects your remaining team. When departures are clearly connected to documented performance issues, it reinforces that the standard applies equally. When departures seem arbitrary, it creates anxiety that undermines performance.

After Firing Security Team Members

The work is not done when the person leaves the building. Security teams require specific offboarding attention. Access revocation needs to happen immediately and completely. Credentials, tokens, and certificates they may have generated need rotation. Any systems where they had administrative access deserve additional scrutiny.

I also spend time in the weeks following a termination watching for team dynamics changes. Sometimes the departure relieves tension that was holding the team back. Sometimes it creates anxiety that needs addressing. The NIST Cybersecurity Workforce Framework emphasizes the ongoing nature of team development, and departures are a significant part of that cycle.

The team that remains is the team you are building. Their experience of this process shapes whether they see you as a leader who maintains standards or one who avoids hard decisions.

The Harder Truth

Firing someone means admitting something went wrong. Maybe you hired the wrong person. Maybe you did not manage them effectively. Maybe the role changed and they did not change with it. Accountability runs in multiple directions.

The leaders I respect most are the ones who can hold both truths: this termination was necessary, and I could have done things differently that might have changed the outcome. The humility to examine your own contribution does not make you soft. It makes you better at the next hire, the next coaching conversation, and the next difficult decision.

Getting better at hiring the right people is the best way to have fewer of these conversations.

Your security program is only as strong as the team executing it. Sometimes protecting that team means letting someone go.

📬 Stay Ahead of the Storm

Weekly insights on security leadership — no vendor spin, no recycled advice.

Subscribe Now!