Live data from Hacker News

I quit infosec and I couldn't be happier

paulsec.github.io

51–60 of 175 posts

Re: I quit infosec and I couldn't be happier

#51
post #32
post #21

Earlier quoted context omitted.

From what I've heard from other CISOs: You own a bunch of unsolvable risk and your head is one of the first to get lopped off if you're popped. Honestly, the CISO role probably needs a golden parachute and a direct report to the CEO for it to be an appealing path for most anyone who's experienced it at least once. The former to incentivize owning that much risk, the latter to enable the role to drive change.

That's insightful, but I still think the assumption that the CISO has to go when the company gets compromised is a bit issue. Instead of security being a team effort, with the goal being making the hard choices together, finding the correct compromises to let the business thrive while being secure - it usually makes the CISO take an adversarial position to anything in their company - since it's always their head if s…

The CISO is an odd role because it mostly has to help protect against tech risk without owning tech, and because it's a bit of a crap role, you end up with all sorts of the wrong people and behaviours in the role.

Common Pitfalls:

- Act as a gate that slows everything down, i.e. it must be secure, which in turn makes things less secure, as there's less time on the board to fix things.

- Chase massive budget. Eventually get massive budget. Buy silver bullets that don't fit in techs guns.

- Focus on the non-tech parts. We'll train people not to open cat.jpeg.exe instead if you know, auditing their usage and turning off their kit / login when they're pwned.

With anything, it's all about the people you put in place, but my experience is the average large company CISO sits on a pile of paperwork and IT security whilst their servers aren't patched.

Re: I quit infosec and I couldn't be happier

#52
post #50

Earlier quoted context omitted.

> Never be a CISO Can you share why?

They shared why in the prior two sentences, when saying what they enjoy when not a CISO. "Show up. Hack. Write report."

I asked for more detail because I’m in a role training under a CISO and rapidly approaching a decisioning point to assume their role. Sorry I didn’t make that clear in my original comment.

Re: I quit infosec and I couldn't be happier

#54
post #8
post #2

This is about developer burnout, and doesn't really point to anything in particular regarding infosec.

I don't think it was meant to be an "infosec is wrong and I'm right so I'm leaving" type story. I like that the author wasn't afraid to make a change, not everyone can but it makes for an interesting story!

It's a nice story. The author discovered he's passionate about people. Did a lot of thinking and seems happier now.

I don't think it speaks badly about the pentesting part of infosec, even though those in auditing tell me it's extremely boring to be in infosec.

Re: I quit infosec and I couldn't be happier

#55
post #20

> The main warning I might just give to people is to keep proper distances between work and personal life I've been thinking about this a lot lately. As a millennial, I've tied so much my self-worth into my career and recently, started questioning this belief and I think the next generation (i.e. Gen Z) might be on to something around quiet quitting, their generation placing extra emphasis on pursuing things that mak…

Millennial here as well, it's really excited to see our generation and the next generation reject "making money for someone else" as a way of finding meaning in life. I'm chewing on a lot of blog posts about this, regarding for example how the concept of "retirement" is terrifying. I was on a cruise recently and talking with a bunch of old people, and the subject often came up about how people were "finally taking th…

> busting ass from your 20s to mid to late 50s, and then getting hopefully another 30 years to "enjoy life?"

Its just slavery which the older generations thought was appropriate, much like having a large family to look after you was a thing before family sizes came down.

It sounds cliched, but have a bucket list of things you want to do and try to do some of them. Put yourself first and your job second because the days of businesses looking after their staff and a job for life is long gone as every recession demonstrates.

Re: I quit infosec and I couldn't be happier

#56
post #17

Funny thing is i was mentioning milw0rm this morning to a colleague and remembering the old days when astalavista was a thing :) nice story thanks for sharing!

I read astalavista and thought you meant AltaVista. After rereading, I'm not sure.

astalavista was the security search engine (or portal-like website).

AltaVista was a Google competitor, IIRC.

Re: I quit infosec and I couldn't be happier

#57

Some general (unsolicited) advice ... for whatever field you're interested in - go work for a company that sells that as a service. E.g., - Don't be an internal company accountant, go work for Big 4 accounting firm to sell your skills - Don't be in internal company IT Security, go work for a company who sells that skill It's all about moving up in the value chain. By moving up in the value chain, you're more "valued"…

How would that work for a developer?

work for a company where you are developing the comapny's main product, and where the product can be substantially improved by further development. For example, working to develop a website for a supermarket chain, or an app for dominoes pizza, will always have a limit and little respect

Re: I quit infosec and I couldn't be happier

#58
post #32
post #21

Earlier quoted context omitted.

From what I've heard from other CISOs: You own a bunch of unsolvable risk and your head is one of the first to get lopped off if you're popped. Honestly, the CISO role probably needs a golden parachute and a direct report to the CEO for it to be an appealing path for most anyone who's experienced it at least once. The former to incentivize owning that much risk, the latter to enable the role to drive change.

That's insightful, but I still think the assumption that the CISO has to go when the company gets compromised is a bit issue. Instead of security being a team effort, with the goal being making the hard choices together, finding the correct compromises to let the business thrive while being secure - it usually makes the CISO take an adversarial position to anything in their company - since it's always their head if s…

The CISO gets blamed and fired because it’s a language that shareholders understand. You think shareholders are going to understand that the CISO enabled others to make secure choices?

Re: I quit infosec and I couldn't be happier

#59

Some general (unsolicited) advice ... for whatever field you're interested in - go work for a company that sells that as a service. E.g., - Don't be an internal company accountant, go work for Big 4 accounting firm to sell your skills - Don't be in internal company IT Security, go work for a company who sells that skill It's all about moving up in the value chain. By moving up in the value chain, you're more "valued"…

I agree that is it more lucrative that way. But I super disagree with the happiness part. I don't know anyone working at an IT security company, but know many many lawyers and a handful of accountants. 90% of them ditched big law firms/Big 4 accounting firms as soon as their resume was sufficient to do so because the quality of life was terrible. Very very long hours, demanding clients and political atmospheres (As you go up) around bringing in business. By and large the folks that stayed are workaholics who highly valued money and status.

1 good friend of mine, was a super driven lawyer at a huge world-class firm in NYC. She got cancer, and had to take a leave. Fortunately she recovered fully and quit basically the first moment she got back. This isn't one of those 'she left to follow her passion in the arts' cases - she LOVES being a lawyer, but she realized she wasn't living a life. Now she's in-house at a multi-national brewing company.

Anyhow, all that to say - you may be more valued, but it's much easier to be the client!

Re: I quit infosec and I couldn't be happier

#60

Does anyone else wonder what their life might have been if you had never gotten into tech? I sometimes think I may be happier, but certainly less wealthy. My free time would probably be just that, free time - instead of having the relentless drive I have to do another app, blog post, etc. On the other hand - the "hustle" economy is everywhere now, not just tech. Everyone has a side gig, and the grass isn't always gre…

I do, knowing the physical and mental harm of being stuck in front of a computer for most of my life, believe it or not but being sat in a chair for extended periods of time is considered a stress position, and not getting the fun exercise to keep you body fit, bugs me a lot as my health declines and the so called experts ie doctors dont know enough and they are risk averse conformists.
Post reply on HN