Live data from Hacker News

I quit infosec and I couldn't be happier

paulsec.github.io

41–50 of 175 posts

Re: I quit infosec and I couldn't be happier

#41
post #35
post #27

Earlier quoted context omitted.

The author is French, the usage of quitted is more likely a mistake outright. As for the quoted version it's explained next to it, he's quitting professionally but likely will continue as a hobby, in French you'd use quotes to highlight the fact it's not to be taken literally.

OP here, that is correct and I am french, I thought that it was right actually. what should have been the proper way to say I left that industry?

> I quit infosec...

Re: I quit infosec and I couldn't be happier

#42
post #24
post #21

Earlier quoted context omitted.

From what I've heard from other CISOs: You own a bunch of unsolvable risk and your head is one of the first to get lopped off if you're popped. Honestly, the CISO role probably needs a golden parachute and a direct report to the CEO for it to be an appealing path for most anyone who's experienced it at least once. The former to incentivize owning that much risk, the latter to enable the role to drive change.

Any Cx0 that has a boss besides the CEO isn't a C at all.

You'd be surprised how often this happens though. I've seen all the following structures:

CISO -> COO -> CEO

CISO -> CIO -> COO -> CEO

CISO -> CSO -> COO -> CEO

CISO -> CLO -> CEO

CISO -> CLO -> CFO (wtf?) -> CEO

And none of:

CISO -> CEO, or even

CISO -> CSO -> CEO

The only one I've seen be extremely effective aside from a direct reporting relationship has been where the role reported up to the CLO (general counsel) and said role reported up to the CEO directly. Reporting up to the CIO or CFO (again wtf?), there were conflict issues at play where the CIO or CFO was obligated to prioritize their main mission. CISO to COO worked fine generally from what I saw, as did CISO to CSO to COO, but it meant the CEO was often shielded from issues where they could impactfully move the needle where needed.

---

The CFO one was at a company owned by private equity, which makes perverse sense when you consider that most business leaders consider infosec to be a pure cost center rather than a business enablement function. Doesn't help that many CISOs historically never ran their shops with business enablement in mind either, which put a lasting dent in infosec's reputation as a function that many emerging leaders are still trying to rehabilitate.

Re: I quit infosec and I couldn't be happier

#44
post #35
post #27

Earlier quoted context omitted.

The author is French, the usage of quitted is more likely a mistake outright. As for the quoted version it's explained next to it, he's quitting professionally but likely will continue as a hobby, in French you'd use quotes to highlight the fact it's not to be taken literally.

OP here, that is correct and I am french, I thought that it was right actually. what should have been the proper way to say I left that industry?

"I quit infosec and I couldn't be happier" is how I'd have written it.

Thanks for the good-read!

Re: I quit infosec and I couldn't be happier

#46

Some general (unsolicited) advice ... for whatever field you're interested in - go work for a company that sells that as a service. E.g., - Don't be an internal company accountant, go work for Big 4 accounting firm to sell your skills - Don't be in internal company IT Security, go work for a company who sells that skill It's all about moving up in the value chain. By moving up in the value chain, you're more "valued"…

Yes. You always want to be part of a profit center, where (directly or indirectly) there is revenue associated with what you do, rather than being part of a cost center where you are just an expense for the company.

Re: I quit infosec and I couldn't be happier

#47
post #35
post #27

Earlier quoted context omitted.

The author is French, the usage of quitted is more likely a mistake outright. As for the quoted version it's explained next to it, he's quitting professionally but likely will continue as a hobby, in French you'd use quotes to highlight the fact it's not to be taken literally.

OP here, that is correct and I am french, I thought that it was right actually. what should have been the proper way to say I left that industry?

"To quit" is an irregular verb in English, the past tense is just quit instead of quitted. So "I quit" can be either present or past tense, but from context it would be clear that "I quit infosec" is past tense.

Re: I quit infosec and I couldn't be happier

#48
post #35
post #27

Earlier quoted context omitted.

The author is French, the usage of quitted is more likely a mistake outright. As for the quoted version it's explained next to it, he's quitting professionally but likely will continue as a hobby, in French you'd use quotes to highlight the fact it's not to be taken literally.

OP here, that is correct and I am french, I thought that it was right actually. what should have been the proper way to say I left that industry?

Grammarly helps but having been in infosec, you probably will have concerns about sending your private data to that cloud :)

Re: I quit infosec and I couldn't be happier

#49

Some general (unsolicited) advice ... for whatever field you're interested in - go work for a company that sells that as a service. E.g., - Don't be an internal company accountant, go work for Big 4 accounting firm to sell your skills - Don't be in internal company IT Security, go work for a company who sells that skill It's all about moving up in the value chain. By moving up in the value chain, you're more "valued"…

How would that work for a developer?

Re: I quit infosec and I couldn't be happier

#50

I have been an information security consultant for a long time. Software dev background. 2006 start app sec consulting -> senior consultant —> principal consultant -> CTO (of small consulting firm) -> get bought by NCC start my own company 10 yrs ago -> CTO/managing principal -> sell company -> still consulting. Done so many different things but the common theme is app sec. Finding bugs and risks in software via reve…

> Never be a CISO Can you share why?

They shared why in the prior two sentences, when saying what they enjoy when not a CISO. "Show up. Hack. Write report."
Post reply on HN