I quit infosec and I couldn't be happier
paulsec.github.io
I quit infosec and I couldn't be happier
1–10 of 175 posts
Re: I quit infosec and I couldn't be happier
#2Re: I quit infosec and I couldn't be happier
#3Re: I quit infosec and I couldn't be happier
#4Re: I quit infosec and I couldn't be happier
#5Re: I quit infosec and I couldn't be happier
#6> But why don’t they just patch? It’s not that complicated after all.
And you kinda see this later on when the author talks about what they worked on post-transition out of infosec as a mainline career:
> I finally joined Michelin in December 2016 where I started working in the CERT team where my main mission was to automate scanning and reconnaissance phases [emphasis added] on internet-facing assets and this was my real first experience on the other side of the story - defending infrastructure and where I finally experienced change management (and the complexity behind it), impact evaluation and so on.
It seems like the author burned out not because of the work but because wherever he ended up, there was no strategic initiative to streamline and automate patching to a point where it's largely invisible. It's also a hard problem given the risks of patching bringing reliant services down and the need to automate a slew of testing to validate that said patches won't torpedo production and mission critical systems.
The bit above is important not just because it solves a problem but because (I'm convinced that) people like knowing they actually built something and enacted lasting change. And security may be one of the least likely engineering disciplines where you'll experience building a tangible product as an IC.
At least in software security it's a bit easier with build and deployment pipelines offering an opportunity to block when patches are outstanding, but I can see where the burnout would arise when a strategic effort to invisibly ensure patching isn't in place or well funded. No one gets to build anything, and likewise, nothing gets solved because nothing was built.
---
So if I could add another takeaway:
• if your job involves running around and putting out fires, consider recommending up the chain and across the aisle all the ways to prevent the fires. And if those recommendations don't catch fire (so to speak), may be worth exploring alternative means to address the burnout risk long term with the current role.
Re: I quit infosec and I couldn't be happier
#7I've been thinking about this a lot lately. As a millennial, I've tied so much my self-worth into my career and recently, started questioning this belief and I think the next generation (i.e. Gen Z) might be on to something around quiet quitting, their generation placing extra emphasis on pursuing things that make them happy and viewing work as .... well, work.
Re: I quit infosec and I couldn't be happier
#8This is about developer burnout, and doesn't really point to anything in particular regarding infosec.
I like that the author wasn't afraid to make a change, not everyone can but it makes for an interesting story!
Re: I quit infosec and I couldn't be happier
#9> The main warning I might just give to people is to keep proper distances between work and personal life I've been thinking about this a lot lately. As a millennial, I've tied so much my self-worth into my career and recently, started questioning this belief and I think the next generation (i.e. Gen Z) might be on to something around quiet quitting, their generation placing extra emphasis on pursuing things that mak…
Re: I quit infosec and I couldn't be happier
#10Got to be honest, I only clicked on the link because 'quitted' bothered me, but the Take-Aways are interesting.
In any case, TIL that although "quit" is most common for past tense/past participle, "quitted" is sometimes included in dictionaries as an alternative.