Live data from Hacker News

I quit infosec and I couldn't be happier

paulsec.github.io

111–120 of 175 posts

Re: I quit infosec and I couldn't be happier

#112
post #89

Earlier quoted context omitted.

Average tenure for a CISO is lowest of any C suite. You will likely take the hit in the event of a security incident and be fired. Tedious work. What to do is often obvious. Getting everyone to do it is the hard part and usually devolves into politics. Thankless job, you can only be wrong once. Just not appealing and CISO is becoming legally sketchy, requiring a lot of diligence out of a CISO to not end up in legal t…

> Average tenure for a CISO is lowest of any C suite. Do you have any stats to support this statement? I work as a Information Security Officer, other firms have BISOs or other names for this kind of position. Additionally, a lot of what you are describing is either cliché ("you can only be wrong once"), only true for certain types of businesses or regions. There have been examples where CISOs have experienced legal…

BISO and CISO are generally not the same. A BISO function tends to be an interface between information security and business units.

Re: I quit infosec and I couldn't be happier

#113

I have been an information security consultant for a long time. Software dev background. 2006 start app sec consulting -> senior consultant —> principal consultant -> CTO (of small consulting firm) -> get bought by NCC start my own company 10 yrs ago -> CTO/managing principal -> sell company -> still consulting. Done so many different things but the common theme is app sec. Finding bugs and risks in software via reve…

As someone with a C/C++ background considering a move in this direction career-wise, would you still recommend it?

It really depends on what you want to do. We hire folks from dev backgrounds all the time and many stick around and enjoy it. If you get pushed into some corporate app sec role where you aren't doing interesting problem solving, I do not recommend it. If you get to really dig into security problems and challenges using engineering and technical skills you have acquired, yes, it is still fun. You get to take apart other people's puzzles (apps/code) and there are tons of opportunities for automation, scripting, writing tools, etc. It is an awesome field to grow in when you have a lot of hard CS and development skills and can apply them meaningfully. That makes things pretty narrow in terms of roles out there that check all of the boxes I mentioned, but, yes, it is still interesting and fun. Look at all the cool things people have done with fuzzing over the last 5-10 years, starting with AFL which really changed the game. Now people do fuzzing with VMs (qemu) etc. Just a ton of really cool stuff that a solid C/C++ dev can really dig into and play with :)

Re: I quit infosec and I couldn't be happier

#114

Earlier quoted context omitted.

> Never be a CISO Can you share why?

Average tenure for a CISO is lowest of any C suite. You will likely take the hit in the event of a security incident and be fired. Tedious work. What to do is often obvious. Getting everyone to do it is the hard part and usually devolves into politics. Thankless job, you can only be wrong once. Just not appealing and CISO is becoming legally sketchy, requiring a lot of diligence out of a CISO to not end up in legal t…

At a former job I worked directly under the CISO doing architecture audits.

He described his job as "we shouldn't do this, or this. we probably need money for both, or failing that, implement some really annoying, workflow-impacting changes that will annoy people. so gib mony plz".

inevitably the org would say no to both, so he asked for that in writing and then played the CYA game hard when it went bad.

"a cortisol rollercoaster followed by begging followed by more rollercoaster" was a phrase he used.

Re: I quit infosec and I couldn't be happier

#115

Earlier quoted context omitted.

> Never be a CISO Can you share why?

Average tenure for a CISO is lowest of any C suite. You will likely take the hit in the event of a security incident and be fired. Tedious work. What to do is often obvious. Getting everyone to do it is the hard part and usually devolves into politics. Thankless job, you can only be wrong once. Just not appealing and CISO is becoming legally sketchy, requiring a lot of diligence out of a CISO to not end up in legal t…

> Average tenure for a CISO is lowest of any C suite. You will likely take the hit in the event of a security incident and be fired.

As far as I can tell, this is the actual purpose of a CISO: being the sacrificial goat when an entity experiences a security event that ends up in the news. I say this without any sarcasm.

Re: I quit infosec and I couldn't be happier

#116

Got to be honest, I only clicked on the link because 'quitted' bothered me, but the Take-Aways are interesting.

It is valid in English to use quitted in this manner, but it does look and sound odd. Most dictionaries list quitted as an alternative simple past/past participle of to quit, but admittedly it's uncommon to see it in modern English. Usually quitted is used in the sense departed or left (following French usage), which, while perhaps archaic, is perfectly valid in English as well.

Re: I quit infosec and I couldn't be happier

#117

This really resonates with me. I'm also passionate, and most corporate gigs I've had over 20 years kill my soul. I wish there was a place I could use my skills where they weren't wasted, where I could perform at the top of my game and really make incredible things happen. The reality is I spend 90% of my time trying to work around some stupid bureaucratic limitation, and it's not uncommon for my work to be literally…

OMG, its like you're speaking right to me! :-)

I have a multi-decade career, and for like the first decade or decade and a half or so, i tried to stay as long as reasonably possible at whatever big compoany i worked for....being raised to think that loyalty, and working a long number of years at the same employer was a sort of weird badge of honor. I got hit by bureacratic BS/blocks on such a constant basis, and then got hit by my first layoff...then i thought: "oh man, its me, i'm the problem, maybe i'm not as good as i thought, etc." Then I got yet another corporate job....and then another layoff...which by the way both layoffs were to due to re-orgs, and impoacted many people, and not specific to my performance. But, you know, the ego and heart gets hit hard.

So, i tried 1 year (during the middle of the pandemic) to work for a non-profit...thinking that maybe i can use my passion and people and tech skills for some good causes...Nope, never again! The sample size is of course so small (I only worked for a single non-profit), but i encountered the same corporate blocks as in the for-profit world, but with a vastly reduced paycheck. I still love my peers in the non-profiut, and while i was there i actually made a difference in thousands of people's lives, as well as gaining accoloades from IRS for a model and taxpayer experidnc e that i developed foir some web potals that i lead the dev. for. And, i still very much believe in what the non-profit where i worked does...But wow was the org. crazy disfunctional! Anyway, over the last couple of years since then, i keep jumping from one big company to another....and after all these decades i feel i have more passion than ever before for the tech and the problem spaces! ...BUT...now i have less patience for corporate buracratic BS/blocks...so i jump more often nowadays; which i dont like doing. Maybe i will try small, for-profit firms and see how things go....but, man, corporations really do know how to hamper those among us who have the passion, drive, and technical chops to really make a difference. Passion and competency - at least at the big boys/girls where i worked - seem to count for nothing nowadays.

Re: I quit infosec and I couldn't be happier

#118
post #31

This really resonates with me. I'm also passionate, and most corporate gigs I've had over 20 years kill my soul. I wish there was a place I could use my skills where they weren't wasted, where I could perform at the top of my game and really make incredible things happen. The reality is I spend 90% of my time trying to work around some stupid bureaucratic limitation, and it's not uncommon for my work to be literally…

I recommend smaller companies were you take an architect type role where you build the systems, or at least have a domain you control and are accountable for. I've been doing exclusively that since about 2005. It has it's own problems, mainly pressure to constantly get things done, which is fine, but it can be unrelenting sometimes. The soul sucking large corporate entities, I couldn't agree more. Stay away from that…

> I recommend smaller companies...

Yep, this is the direction i wish to take next. ;-)

Re: I quit infosec and I couldn't be happier

#119

I had watched a few courses on information security and noticed that those working in the more management / corporate related infosec roles seemed to be massively overweight, almost all of them (I am too, btw). Not saying that to shame anyone, just: Does the job make you miserable or stressed out? I have been forced to do the infosec role as a "side thing" in a couple of jobs now, mainly because nobody else was aroun…

* high or higher stress role

* can be demanding or irregular in terms of hours

* real, genuine infosec requires deeper knowledge of OS's, protocols, tools, programming & scripting, etc. Gotta be a little more experience to get that, and even more experienced to move away from it into mgmt or higher level roles. In other words, older office worker, and that means more gut.

Re: I quit infosec and I couldn't be happier

#120

Earlier quoted context omitted.

I read astalavista and thought you meant AltaVista. After rereading, I'm not sure.

astalavista was the security search engine (or portal-like website). AltaVista was a Google competitor, IIRC.

AltaVista was the search engine of the internet, way before Google.

Developed by Digital to showcase the power of their CPU the DEC Alpha IIRC...

Post reply on HN