Live data from Hacker News

I quit infosec and I couldn't be happier

paulsec.github.io

131–140 of 175 posts

Re: I quit infosec and I couldn't be happier

#131
post #81

I have said it before and still say... InfoSec is a glorified policy writer. You spent more time 90% of the time "writing documentation" rather than on finding the security problem and suggesting the fix. That's why i choose development rather than InfoSec (despite having a knack for it), because its more technical and i don't need to explain "why" everytime.

I think you are mistaken. Obviously InfoSec is a rather generalising term, while you are abstractly describing the work of someone that works in Application Security.

I would rephrase the question... what InfoSec jobs doesn't involve spending writing documentation?

pentesting? 20% finding the low hanging fruit, 80% writing and explaining your findings.

forensics? 10% finding how they did it, 90% writing and explaining your findings.

malware/policy/security/cloud security analyst? 100% writing and explaining your findings.

the list goes on and on... you are basically and a slave for word processing software, thats why totally understand OP quitting infosec.

Re: I quit infosec and I couldn't be happier

#132

When I was 18-20 I was also passionate about infosec. But I liked development more and infosec didn't seem at that time a domain that is very easy to find employment and gain money.

You can find a role as a software engineer with a security focus.

I haven't see a lot of job postings for those. It's either a dedicated security professional, or a software engineer.

I once worked for company making a security product. The other software engineers knew almost nothing about security or secure coding practices. It was never a requirement for the company to hire people with security skills, nor did security skills even get taught! I tend to think that's the norm in the industry, but I'd be happy to be proven wrong.

Re: I quit infosec and I couldn't be happier

#133
post #21

Earlier quoted context omitted.

> Never be a CISO Can you share why?

From what I've heard from other CISOs: You own a bunch of unsolvable risk and your head is one of the first to get lopped off if you're popped. Honestly, the CISO role probably needs a golden parachute and a direct report to the CEO for it to be an appealing path for most anyone who's experienced it at least once. The former to incentivize owning that much risk, the latter to enable the role to drive change.

CISO direct report to CEO can be bad politics.

CISO direct report to CTO can be a conflict of interests for the CTO.

C-suite positions need a golden parachute because they can be career-ending. You don't climb to the C-suite then go back to being an IC or lower-level director.

CISO can be even riskier than other C-suite positions. So CISOs really need golden parachutes. But CISOs almost certainly don't get golden parachutes worth the while -- they are generally seen as less important than CTO, CFO, COO, and CEO.

Re: I quit infosec and I couldn't be happier

#134
post #20

> The main warning I might just give to people is to keep proper distances between work and personal life I've been thinking about this a lot lately. As a millennial, I've tied so much my self-worth into my career and recently, started questioning this belief and I think the next generation (i.e. Gen Z) might be on to something around quiet quitting, their generation placing extra emphasis on pursuing things that mak…

Millennial here as well, it's really excited to see our generation and the next generation reject "making money for someone else" as a way of finding meaning in life. I'm chewing on a lot of blog posts about this, regarding for example how the concept of "retirement" is terrifying. I was on a cruise recently and talking with a bunch of old people, and the subject often came up about how people were "finally taking th…

In their 20s and 30s, my siblings pursued their own interests and desires, but unfortunately, this approach did not lead to success. Now in their late 50s and early 60s, they find themselves lacking the necessary skills and experience to keep up with the rapidly changing job market. As a result, they are limited to unskilled labor, with no significant savings or retirement plans. Despite having pursued their dreams when they were younger, they are not particularly content.

They constantly ask me for money now.

Re: I quit infosec and I couldn't be happier

#135
post #88
post #21

Earlier quoted context omitted.

From what I've heard from other CISOs: You own a bunch of unsolvable risk and your head is one of the first to get lopped off if you're popped. Honestly, the CISO role probably needs a golden parachute and a direct report to the CEO for it to be an appealing path for most anyone who's experienced it at least once. The former to incentivize owning that much risk, the latter to enable the role to drive change.

CISOs are starting to report to the board. The biggest challenge is budget. It's hard to put an ROI on a theoretical risk that chances of risk happening are at best an educated guess. Most company leaders don't value detection of breach but only prevention so things like the significant cost of storing network flow logs is an uphill battle.

I fumbled on an interview once when asked “tell us how a security initiative you led brought value to your organization”. I rambled on about average breach/downtime cost but i couldn’t quantify anything on the spot. In retrospect, I should have focused on manhours saved through prevention system. It’s a hard sell!

Re: I quit infosec and I couldn't be happier

#136

This really resonates with me. I'm also passionate, and most corporate gigs I've had over 20 years kill my soul. I wish there was a place I could use my skills where they weren't wasted, where I could perform at the top of my game and really make incredible things happen. The reality is I spend 90% of my time trying to work around some stupid bureaucratic limitation, and it's not uncommon for my work to be literally…

OMG, its like you're speaking right to me! :-) I have a multi-decade career, and for like the first decade or decade and a half or so, i tried to stay as long as reasonably possible at whatever big compoany i worked for....being raised to think that loyalty, and working a long number of years at the same employer was a sort of weird badge of honor. I got hit by bureacratic BS/blocks on such a constant basis, and then…

It's a marathon. When you don't enjoy it, start a new one. There will always be bureaucracy, just deal with it and disconnect at the end of the day so you can do the things you love with the people you love.

Re: I quit infosec and I couldn't be happier

#137

Earlier quoted context omitted.

You can find a role as a software engineer with a security focus.

I haven't see a lot of job postings for those. It's either a dedicated security professional, or a software engineer. I once worked for company making a security product. The other software engineers knew almost nothing about security or secure coding practices. It was never a requirement for the company to hire people with security skills, nor did security skills even get taught! I tend to think that's the norm in t…

I have one of those jobs, which is why I brought it up :P I am a software engineer and provide security direction to a team of "pure" software engineers (who are slowly getting better at security). Sometimes I help them with the implementation of things.

Other security adjacent roles can be found in areas like web browsers, compilers, and kernels; there's a massive amount of software engineering work that goes into securing existing systems that goes beyond trying to break things. Most large companies will have many people working in such roles.

Re: I quit infosec and I couldn't be happier

#138

Earlier quoted context omitted.

This isn’t universally true. Large tech companies have a need for specialists and are willing to pay quite well for it.

They might pay well, but if you're not in a profit center for the company - you won't be as valued as much as those who are.

Generally companies that have been burned in the past for not having a good security team and have sufficient organizational memory will continue to value security efforts moving forward.

Re: I quit infosec and I couldn't be happier

#139
post #8
post #2

This is about developer burnout, and doesn't really point to anything in particular regarding infosec.

I don't think it was meant to be an "infosec is wrong and I'm right so I'm leaving" type story. I like that the author wasn't afraid to make a change, not everyone can but it makes for an interesting story!

Sure. But the title insinuated an analysis of how information security causes one unending stress, day after 20 years if working in it one develops a hardened siege mentality etc etc etc. I have read things like that befire, which were interesting perspectives That would be more on point with the title.

Anyways nothing wrong with the text, but my comment stands.

Re: I quit infosec and I couldn't be happier

#140

Earlier quoted context omitted.

I manage a monitoring and ir team and am obese. I tend to stress eat and there is a lot of stress playing defense all the time.

If you prevent all the security threats, nobody notices, and the bosses wonder why they even pay you. If a security issue gets through, the bosses wonder why they even pay you.

If you are doing this job and not reporting out on your effects, you are doing half of the job
Post reply on HN