Live data from Hacker News

I quit infosec and I couldn't be happier

paulsec.github.io

61–70 of 175 posts

Re: I quit infosec and I couldn't be happier

#61
I had watched a few courses on information security and noticed that those working in the more management / corporate related infosec roles seemed to be massively overweight, almost all of them (I am too, btw). Not saying that to shame anyone, just: Does the job make you miserable or stressed out?

I have been forced to do the infosec role as a "side thing" in a couple of jobs now, mainly because nobody else was around that even had the basic skills. One of the things that discouraged me from going further in that field is that it doesn't seem to make people all that happy and fulfilled. Again, I may be wrong on that, as an outsider looking in.

Re: I quit infosec and I couldn't be happier

#62

I have been an information security consultant for a long time. Software dev background. 2006 start app sec consulting -> senior consultant —> principal consultant -> CTO (of small consulting firm) -> get bought by NCC start my own company 10 yrs ago -> CTO/managing principal -> sell company -> still consulting. Done so many different things but the common theme is app sec. Finding bugs and risks in software via reve…

> Never be a CISO Can you share why?

Average tenure for a CISO is lowest of any C suite. You will likely take the hit in the event of a security incident and be fired. Tedious work. What to do is often obvious. Getting everyone to do it is the hard part and usually devolves into politics. Thankless job, you can only be wrong once. Just not appealing and CISO is becoming legally sketchy, requiring a lot of diligence out of a CISO to not end up in legal trouble. But if this appeals to you, it can be rewarding stuff, but it is not a great tech role IMO. Or a great management role.

Re: I quit infosec and I couldn't be happier

#63

Some general (unsolicited) advice ... for whatever field you're interested in - go work for a company that sells that as a service. E.g., - Don't be an internal company accountant, go work for Big 4 accounting firm to sell your skills - Don't be in internal company IT Security, go work for a company who sells that skill It's all about moving up in the value chain. By moving up in the value chain, you're more "valued"…

This isn’t universally true. Large tech companies have a need for specialists and are willing to pay quite well for it.

Re: I quit infosec and I couldn't be happier

#64

I had watched a few courses on information security and noticed that those working in the more management / corporate related infosec roles seemed to be massively overweight, almost all of them (I am too, btw). Not saying that to shame anyone, just: Does the job make you miserable or stressed out? I have been forced to do the infosec role as a "side thing" in a couple of jobs now, mainly because nobody else was aroun…

You're always, always going to be playing catch-up with criminals. It's a defense-only game. It's also like the scenario that caused the development of police radar detector-detectors, etc.

Re: I quit infosec and I couldn't be happier

#65

I had watched a few courses on information security and noticed that those working in the more management / corporate related infosec roles seemed to be massively overweight, almost all of them (I am too, btw). Not saying that to shame anyone, just: Does the job make you miserable or stressed out? I have been forced to do the infosec role as a "side thing" in a couple of jobs now, mainly because nobody else was aroun…

Security is always a cost. It's never a benefit until after someone has already been hacked, and you're the cleanup crew/IT oncologist.

I decided 10 years ago to never work in a role/company where my job didn't contribute to the bottom line. It's much more satisfying.

Re: I quit infosec and I couldn't be happier

#66

When I was 18-20 I was also passionate about infosec. But I liked development more and infosec didn't seem at that time a domain that is very easy to find employment and gain money.

You can find a role as a software engineer with a security focus.

Re: I quit infosec and I couldn't be happier

#67
post #16

I have been an information security consultant for a long time. Software dev background. 2006 start app sec consulting -> senior consultant —> principal consultant -> CTO (of small consulting firm) -> get bought by NCC start my own company 10 yrs ago -> CTO/managing principal -> sell company -> still consulting. Done so many different things but the common theme is app sec. Finding bugs and risks in software via reve…

Sounds like folks like you must have been doing a really good job if it's that much harder to exploit vulnerabilities!

Yep, memory corruption bugs on a modern OS are really hard, but still possible. That’s why sketchy firms like those that build Pegasus now pay 7 figures for a locked and loaded iOS exploit, which objectively does the same thing mine did a decade or so before. :)

Re: I quit infosec and I couldn't be happier

#68
post #53

By default when I click the link I'm directed to a non-secure HTTP version of github, which I found ironic given the page title

I was about to comment on the same... my only question to the OP (and other's who don't enforce HTTPS) is "why?!"

Why does a personal blog page need HTTPS? It's an output page, I read the contents and leave, I'm never submitting any of my information across the wire.

Someone along the way might modify the page? Unless they're using HSTS, it won't matter.

I'm all for encryption, but I'm also all for using tools when necessary, and not complicating things when not.

Re: I quit infosec and I couldn't be happier

#69

I had watched a few courses on information security and noticed that those working in the more management / corporate related infosec roles seemed to be massively overweight, almost all of them (I am too, btw). Not saying that to shame anyone, just: Does the job make you miserable or stressed out? I have been forced to do the infosec role as a "side thing" in a couple of jobs now, mainly because nobody else was aroun…

Oh, yes. Infosec has all the downsides of being an ER/ICU nurse at a miserably understaffed hospital, with ~none of the upsides of saving people or genuine patient/family gratitude.

Re: I quit infosec and I couldn't be happier

#70
I have said it before and still say... InfoSec is a glorified policy writer.

You spent more time 90% of the time "writing documentation" rather than on finding the security problem and suggesting the fix. That's why i choose development rather than InfoSec (despite having a knack for it), because its more technical and i don't need to explain "why" everytime.

Post reply on HN