Live data from Hacker News

I quit infosec and I couldn't be happier

paulsec.github.io

11–20 of 175 posts

Re: I quit infosec and I couldn't be happier

#11
I have been an information security consultant for a long time. Software dev background. 2006 start app sec consulting -> senior consultant —> principal consultant -> CTO (of small consulting firm) -> get bought by NCC start my own company 10 yrs ago -> CTO/managing principal -> sell company -> still consulting. Done so many different things but the common theme is app sec. Finding bugs and risks in software via reversing, assessment, threat modeling, and code review.

Do I still love it after 17 years? no. A lot has changed. A lot has not. I still like it most days. By far my favorite thing has been building a team and teaching others what I learned. I hit burn out here and there. I think computers and tech are different and objectively a little less fun now for this field. When I started I could find a bug in a system and write an actual exploit (actual machine code!) for it by hand in a reasonable time scale and that was always really cool. Now teams of people are required to achieve the same exact goal. Just one of many examples.

So anyway, some get off my lawn cause I am older now, some is just me changing what I like and want from life, some is tech changes. It’s still a great field as a consultant. Show up. Hack. Write report. Leave. Never be a CISO, you can’t pay me enough to do it. The end.

Re: I quit infosec and I couldn't be happier

#12
This really resonates with me. I'm also passionate, and most corporate gigs I've had over 20 years kill my soul. I wish there was a place I could use my skills where they weren't wasted, where I could perform at the top of my game and really make incredible things happen. The reality is I spend 90% of my time trying to work around some stupid bureaucratic limitation, and it's not uncommon for my work to be literally thrown away after months or years of work.

Re: I quit infosec and I couldn't be happier

#13

> The main warning I might just give to people is to keep proper distances between work and personal life I've been thinking about this a lot lately. As a millennial, I've tied so much my self-worth into my career and recently, started questioning this belief and I think the next generation (i.e. Gen Z) might be on to something around quiet quitting, their generation placing extra emphasis on pursuing things that mak…

Millennial too. Thought for thoughts then!

For me, paid work is a means to achieve what I personally want to achieve. If I can achieve what I want during work hours that's great, stars are aligned. If not, work is just a way of getting the money I need to achieve what I want, and should never drain me.

I don't care about career, I care about being paid enough to do what I want to do of my life. I won't sacrifice personal life for it.

Work is a good chunk of the time so it should also be enjoyable as best as possible.

Of course, advancing your carrier can help get paid even more / enjoy even better, if so it might be good thing to do. It's just that it's a means, not a goal, like it seemed to be for some of our parents or grand parents.

Re: I quit infosec and I couldn't be happier

#14

I have been an information security consultant for a long time. Software dev background. 2006 start app sec consulting -> senior consultant —> principal consultant -> CTO (of small consulting firm) -> get bought by NCC start my own company 10 yrs ago -> CTO/managing principal -> sell company -> still consulting. Done so many different things but the common theme is app sec. Finding bugs and risks in software via reve…

> Never be a CISO

Can you share why?

Re: I quit infosec and I couldn't be happier

#16

I have been an information security consultant for a long time. Software dev background. 2006 start app sec consulting -> senior consultant —> principal consultant -> CTO (of small consulting firm) -> get bought by NCC start my own company 10 yrs ago -> CTO/managing principal -> sell company -> still consulting. Done so many different things but the common theme is app sec. Finding bugs and risks in software via reve…

Sounds like folks like you must have been doing a really good job if it's that much harder to exploit vulnerabilities!

Re: I quit infosec and I couldn't be happier

#18
If you're looking to avoid burnout, it helps to think of your profession as something entirely separately from your identity. I'm not an "aerospace engineer" or a "project manager", I am merely a man who plies the trades of engineering and project management during the day. That's the service I provide to society in exchange for food, fuel, land, tools, weapons, medicine, textiles, etc. (I don't think it's a fair trade but that's out of the scope of this discussion.) The parts of life that I actually consider meaningful parts of my identity occur outside of work and mostly revolve around my family, friends, religion, storytelling, and art.

This may kind of seem tautological, but I think adding the extra degree of mental separation (I am a man/woman who practices X profession vs. I am X profession) can help clear your head and open new life avenues to you. If you spend 8 years grinding for a graduate degree and enter into an obscenely competitive job market and find little success, it's easy to feel claustrophobic and like you've failed if you take a job outside your field. However if you think "for 8 years I performed statistics, writing, lecturing, and reading, and now in order to make my fortune I'll try another trade" you feel feel less indebted to your past self and make more clearheaded decisions about what to do in life.

Re: I quit infosec and I couldn't be happier

#19

I have been an information security consultant for a long time. Software dev background. 2006 start app sec consulting -> senior consultant —> principal consultant -> CTO (of small consulting firm) -> get bought by NCC start my own company 10 yrs ago -> CTO/managing principal -> sell company -> still consulting. Done so many different things but the common theme is app sec. Finding bugs and risks in software via reve…

> Never be a CISO Can you share why?

I am a CISO, but transitioning away. It is just plain boring. Lots of admin, reports, reviews, very little actual IT.

Re: I quit infosec and I couldn't be happier

#20

> The main warning I might just give to people is to keep proper distances between work and personal life I've been thinking about this a lot lately. As a millennial, I've tied so much my self-worth into my career and recently, started questioning this belief and I think the next generation (i.e. Gen Z) might be on to something around quiet quitting, their generation placing extra emphasis on pursuing things that mak…

Millennial here as well, it's really excited to see our generation and the next generation reject "making money for someone else" as a way of finding meaning in life. I'm chewing on a lot of blog posts about this, regarding for example how the concept of "retirement" is terrifying. I was on a cruise recently and talking with a bunch of old people, and the subject often came up about how people were "finally taking the trips they always wanted to," or "finally exploring xyz hobby they never had time for."

How terrifying is that, busting ass from your 20s to mid to late 50s, and then getting hopefully another 30 years to "enjoy life?" I mean I'm sure many people find enjoyment along the way but damn that just seems so depressing.

Maybe it wasn't bad when that generation was working, I know many had a very nice quality of life for relatively less effort due to higher purchasing power and lower housing costs.

Post reply on HN