Live data from Hacker News

I quit infosec and I couldn't be happier

paulsec.github.io

91–100 of 175 posts

Re: I quit infosec and I couldn't be happier

#91

I have been an information security consultant for a long time. Software dev background. 2006 start app sec consulting -> senior consultant —> principal consultant -> CTO (of small consulting firm) -> get bought by NCC start my own company 10 yrs ago -> CTO/managing principal -> sell company -> still consulting. Done so many different things but the common theme is app sec. Finding bugs and risks in software via reve…

As someone with a C/C++ background considering a move in this direction career-wise, would you still recommend it?

I think the trick to staying happy in cyber security is to chase down niche fields in technology. Your work won't be perceived as sexy by the broader community since you're not tracking north korea, but the trade off is that you will have fun and not have to brush shoulders with so many egos. So what's green these days? That's for you to decide, but one area I think is interesting is smart contract security on blockchains. Lots of folks are pouring into that space.

Re: I quit infosec and I couldn't be happier

#92

Earlier quoted context omitted.

Millenials still had cause to buy into the Regan-era story of hard work and hyper capitalism leading to a glorious future for the common person. Zoomers have never been able to buy into that lie because they were born into a world where it is so obviously untrue.

Zoomers aren't even old enough to determine that yet. They're in their early 20's at most and no one that age has the experience to definitively say anything regarding this. The alternative to hard work is doing nothing and that certainly will get you no where at all. The idea that a younger generation might have had it slightly better (which I think is pretty subjective anyway, previous generations have all had thei…

You're putting forward a false dichotomy. Not buying into the ethics of 'work hard for a company, they make money, you make money and that is a self evident net positive' is quite reasonable. There is no need to resort to name calling for people who don't buy into this narrative. There is quite a lot more to live, and to being a good person, then pouring your all into paid work. And it is plain to see there was a nice party from 1960 to 1980s and we're the cleanup crew. A working person could support a family, buy a home before 30 and have hobbies 50 years ago. Now that sounds like a bad joke.

Re: I quit infosec and I couldn't be happier

#93
post #85
post #53

Earlier quoted context omitted.

I was about to comment on the same... my only question to the OP (and other's who don't enforce HTTPS) is "why?!"

You'd be surprised how many top websites (e.g. Amazon, eBay) don't even implement HSTS, let alone HSTS Preload. Here's some naming-and-shaming: https://blog.majid.info/hsts-preload/

HSTS is a commitment to future downtime for your site, and as such, is not recommended if you care about uptime for your site (like, say, Amazon.com might).

Re: I quit infosec and I couldn't be happier

#94
post #21

Earlier quoted context omitted.

> Never be a CISO Can you share why?

From what I've heard from other CISOs: You own a bunch of unsolvable risk and your head is one of the first to get lopped off if you're popped. Honestly, the CISO role probably needs a golden parachute and a direct report to the CEO for it to be an appealing path for most anyone who's experienced it at least once. The former to incentivize owning that much risk, the latter to enable the role to drive change.

If a risk is "unsolvable" it gets accepted as is by the accountable person in the business side of things. They will/should have good reason why they can't solve it.

Plenty of companies keep their security teams + CISO after they get popped.

Re: I quit infosec and I couldn't be happier

#95
post #89

Earlier quoted context omitted.

Average tenure for a CISO is lowest of any C suite. You will likely take the hit in the event of a security incident and be fired. Tedious work. What to do is often obvious. Getting everyone to do it is the hard part and usually devolves into politics. Thankless job, you can only be wrong once. Just not appealing and CISO is becoming legally sketchy, requiring a lot of diligence out of a CISO to not end up in legal t…

> Average tenure for a CISO is lowest of any C suite. Do you have any stats to support this statement? I work as a Information Security Officer, other firms have BISOs or other names for this kind of position. Additionally, a lot of what you are describing is either cliché ("you can only be wrong once"), only true for certain types of businesses or regions. There have been examples where CISOs have experienced legal…

Anecdotal observation.

Articles like this: https://www.forbes.com/sites/forbestechcouncil/2020/02/10/th...

LinkedIn data is pretty reliable, so this is not a difficult thing to study sufficiently.

Re: I quit infosec and I couldn't be happier

#96
I have been working in infosec for 10 years now. I know this author doesn't want to convince anyone, and I am happy that they are happy. :)

But I am kinda wondering why this brings so much attention? To me this reads like a long trip down memory lane. Is your takeaway: "if your job and your hobby are too similar, then this will lead to burnout?" Or is it "a job in infosec will lead to burnout, because infosec has certain inherent problems?"

Re: I quit infosec and I couldn't be happier

#97
post #9

> The main warning I might just give to people is to keep proper distances between work and personal life I've been thinking about this a lot lately. As a millennial, I've tied so much my self-worth into my career and recently, started questioning this belief and I think the next generation (i.e. Gen Z) might be on to something around quiet quitting, their generation placing extra emphasis on pursuing things that mak…

LOL welcome to your thirties. Try to lean more towards the weird new hobby side of things, instead of the 20yo girlfriend side.

Sage advice.

Re: I quit infosec and I couldn't be happier

#98
post #4

I was a CISO for a Credit Union, and retired early. Couldn't be happier now, I would never go back to infosec. The stress and anxiety was terrible. Infosec is a target for management if there is a breach, fortunately for me I never had an incident, though. After 3 years my mental state is so much better, I highly recommend retiring/switching carreers if your unhappy in your job.

CISOs that have experienced a breach are worth more than ones that have not.

https://blog.nacdonline.org/posts/cisos-breach-experience-pr...

Re: I quit infosec and I couldn't be happier

#99
post #90
post #6

I'm probably oversummarizing, but this seems to boil down to burnout caused by (from the post): > But why don’t they just patch? It’s not that complicated after all. And you kinda see this later on when the author talks about what they worked on post-transition out of infosec as a mainline career: > I finally joined Michelin in December 2016 where I started working in the CERT team where my main mission was to automa…

Thanks for your reply, I liked it! > It seems like the author burned out not because of the work but because wherever he ended up Don't get me wrong and maybe I was not clear enough (my bad). The infosec part I mostly contributed to was within some consulting companies where I was hopping from one assignment to another one, having different clients every week. I saw some clients with some really strong security postu…

> The "burn out" I experienced was clearly not related to that but pretty much from hacking, writing report, sleep & repeat.

Yeah, this tracks. I rescued myself from this by switching to in-house security teams with ownership of security infrastructure.

Similar to what you did.

Re: I quit infosec and I couldn't be happier

#100
post #20

> The main warning I might just give to people is to keep proper distances between work and personal life I've been thinking about this a lot lately. As a millennial, I've tied so much my self-worth into my career and recently, started questioning this belief and I think the next generation (i.e. Gen Z) might be on to something around quiet quitting, their generation placing extra emphasis on pursuing things that mak…

Millennial here as well, it's really excited to see our generation and the next generation reject "making money for someone else" as a way of finding meaning in life. I'm chewing on a lot of blog posts about this, regarding for example how the concept of "retirement" is terrifying. I was on a cruise recently and talking with a bunch of old people, and the subject often came up about how people were "finally taking th…

A human life is barely the time it takes at a stop light when you consider we live for eternity. Learn how to love, don't try to gratify the ego.
Post reply on HN