Live data from Hacker News

I quit infosec and I couldn't be happier

paulsec.github.io

31–40 of 175 posts

Re: I quit infosec and I couldn't be happier

#31

This really resonates with me. I'm also passionate, and most corporate gigs I've had over 20 years kill my soul. I wish there was a place I could use my skills where they weren't wasted, where I could perform at the top of my game and really make incredible things happen. The reality is I spend 90% of my time trying to work around some stupid bureaucratic limitation, and it's not uncommon for my work to be literally…

I recommend smaller companies were you take an architect type role where you build the systems, or at least have a domain you control and are accountable for. I've been doing exclusively that since about 2005. It has it's own problems, mainly pressure to constantly get things done, which is fine, but it can be unrelenting sometimes.

The soul sucking large corporate entities, I couldn't agree more. Stay away from that if you can. You really only need one big company household name to spice up your resume and you probably have that already. I have mine and never went back.

Re: I quit infosec and I couldn't be happier

#32
post #21

Earlier quoted context omitted.

> Never be a CISO Can you share why?

From what I've heard from other CISOs: You own a bunch of unsolvable risk and your head is one of the first to get lopped off if you're popped. Honestly, the CISO role probably needs a golden parachute and a direct report to the CEO for it to be an appealing path for most anyone who's experienced it at least once. The former to incentivize owning that much risk, the latter to enable the role to drive change.

That's insightful, but I still think the assumption that the CISO has to go when the company gets compromised is a bit issue. Instead of security being a team effort, with the goal being making the hard choices together, finding the correct compromises to let the business thrive while being secure - it usually makes the CISO take an adversarial position to anything in their company - since it's always their head if something bad happens....

Amazing CISOs lead security by enabling others to make secure choices that still let them move quickly and deliver value. To do that - they shouldn't always be one hack away from losing their job.

Re: I quit infosec and I couldn't be happier

#33
Some general (unsolicited) advice ... for whatever field you're interested in - go work for a company that sells that as a service.

E.g.,

- Don't be an internal company accountant, go work for Big 4 accounting firm to sell your skills

- Don't be in internal company IT Security, go work for a company who sells that skill

It's all about moving up in the value chain. By moving up in the value chain, you're more "valued" / appreciated / sought after.

You're general happiness will be much better as a result, and you'll also make much more money.

Re: I quit infosec and I couldn't be happier

#35
post #27

Earlier quoted context omitted.

Stuck out to me as well—author uses it only once apart from the title, and it's in scare quotes. Are they calling attention to the fact that it's not the usual form of the word, but then failing to explain why that's important to the subject of the post? In any case, TIL that although "quit" is most common for past tense/past participle, "quitted" is sometimes included in dictionaries as an alternative.

The author is French, the usage of quitted is more likely a mistake outright. As for the quoted version it's explained next to it, he's quitting professionally but likely will continue as a hobby, in French you'd use quotes to highlight the fact it's not to be taken literally.

OP here, that is correct and I am french, I thought that it was right actually. what should have been the proper way to say I left that industry?

Re: I quit infosec and I couldn't be happier

#36

> The main warning I might just give to people is to keep proper distances between work and personal life I've been thinking about this a lot lately. As a millennial, I've tied so much my self-worth into my career and recently, started questioning this belief and I think the next generation (i.e. Gen Z) might be on to something around quiet quitting, their generation placing extra emphasis on pursuing things that mak…

Millenials still had cause to buy into the Regan-era story of hard work and hyper capitalism leading to a glorious future for the common person. Zoomers have never been able to buy into that lie because they were born into a world where it is so obviously untrue.

Re: I quit infosec and I couldn't be happier

#37
> Taking your passion and making it your day work is obviously tempting but also a risky game, as you will keep “working” tirelessly if you’re not putting barrier

Risky game indeed. It’s 1:24am here in Australia and I’ve finally stopped attempting to reverse a network protocol for an embedded device which I’m pentesting. Reading the article is a good reminder of what can happen if you push it too far. The challenge is with this type of work you often have to put in the hours, particularly if it’s a hard target..

If you lack the passion and drive you simply just won’t retain and develop the skills required to deliver. If seasoned pentesters disagree, then I’m all ears.

Re: I quit infosec and I couldn't be happier

#38
post #20

Earlier quoted context omitted.

Millennial here as well, it's really excited to see our generation and the next generation reject "making money for someone else" as a way of finding meaning in life. I'm chewing on a lot of blog posts about this, regarding for example how the concept of "retirement" is terrifying. I was on a cruise recently and talking with a bunch of old people, and the subject often came up about how people were "finally taking th…

> How terrifying is that, busting ass from your 20s to mid to late 50s Agreed. I'm all onboard with delayed gratification. I'm onboard with "putting in the work." But waiting (literally) decades before living it up... sounds totally backwards.

The flip side is there are people out there that do everything they want now. A couple people I know have been doing that for quite some time. They're getting older now - they've raided their retirement, they don't have much in terms of savings, no assets. Life is getting more difficult for them as they get older. My advice would be to find some balance. Go on some great adventures within reason. There's no reason to buckle down entirely until you're 60 but be smart about it.

Re: I quit infosec and I couldn't be happier

#39
Does anyone else wonder what their life might have been if you had never gotten into tech? I sometimes think I may be happier, but certainly less wealthy. My free time would probably be just that, free time - instead of having the relentless drive I have to do another app, blog post, etc.

On the other hand - the "hustle" economy is everywhere now, not just tech. Everyone has a side gig, and the grass isn't always greener. So, who knows.

Great post and best of luck in management.

Post reply on HN