From my perspective, they've got a perception problem to fix. I was keenly interested in cybersecurity for a while (enjoy playing wargames and CTFs, still considering going for my OSCP just for fun), but following people in the industry for a while, I got the impression you have (at least) three pitfalls to look out for: 1. Working in a corporation, where the job is just compliance checklist whack-a-mole. 2. Working…
I'll add one more, the problem with compliance jobs is that it only really becomes important (to the bigwigs) when it goes wrong. Most of the time you are just a cost-center, a necessary nuisance. It's a lot harder to extract money / get promoted when your good work isn't immediately noticeable.
As a consultant I've been trying for years, with limited success, to persuade people to think in terms of business process integrity, since that more clearly ties the necessary work to the revenue output. It's an uphill slog though as prevailing culture is checklist compliance.
Doesn't help that major consulting and advising firms make more money on checklist mentalities.