Live data from Hacker News

I quit infosec and I couldn't be happier

paulsec.github.io

1–10 of 175 posts

Re: I quit infosec and I couldn't be happier

#4
I was a CISO for a Credit Union, and retired early. Couldn't be happier now, I would never go back to infosec. The stress and anxiety was terrible. Infosec is a target for management if there is a breach, fortunately for me I never had an incident, though. After 3 years my mental state is so much better, I highly recommend retiring/switching carreers if your unhappy in your job.

Re: I quit infosec and I couldn't be happier

#6
I'm probably oversummarizing, but this seems to boil down to burnout caused by (from the post):

> But why don’t they just patch? It’s not that complicated after all.

And you kinda see this later on when the author talks about what they worked on post-transition out of infosec as a mainline career:

> I finally joined Michelin in December 2016 where I started working in the CERT team where my main mission was to automate scanning and reconnaissance phases [emphasis added] on internet-facing assets and this was my real first experience on the other side of the story - defending infrastructure and where I finally experienced change management (and the complexity behind it), impact evaluation and so on.

It seems like the author burned out not because of the work but because wherever he ended up, there was no strategic initiative to streamline and automate patching to a point where it's largely invisible. It's also a hard problem given the risks of patching bringing reliant services down and the need to automate a slew of testing to validate that said patches won't torpedo production and mission critical systems.

The bit above is important not just because it solves a problem but because (I'm convinced that) people like knowing they actually built something and enacted lasting change. And security may be one of the least likely engineering disciplines where you'll experience building a tangible product as an IC.

At least in software security it's a bit easier with build and deployment pipelines offering an opportunity to block when patches are outstanding, but I can see where the burnout would arise when a strategic effort to invisibly ensure patching isn't in place or well funded. No one gets to build anything, and likewise, nothing gets solved because nothing was built.

---

So if I could add another takeaway:

• if your job involves running around and putting out fires, consider recommending up the chain and across the aisle all the ways to prevent the fires. And if those recommendations don't catch fire (so to speak), may be worth exploring alternative means to address the burnout risk long term with the current role.

Re: I quit infosec and I couldn't be happier

#7
> The main warning I might just give to people is to keep proper distances between work and personal life

I've been thinking about this a lot lately. As a millennial, I've tied so much my self-worth into my career and recently, started questioning this belief and I think the next generation (i.e. Gen Z) might be on to something around quiet quitting, their generation placing extra emphasis on pursuing things that make them happy and viewing work as .... well, work.

Re: I quit infosec and I couldn't be happier

#8
post #2

This is about developer burnout, and doesn't really point to anything in particular regarding infosec.

I don't think it was meant to be an "infosec is wrong and I'm right so I'm leaving" type story.

I like that the author wasn't afraid to make a change, not everyone can but it makes for an interesting story!

Re: I quit infosec and I couldn't be happier

#9

> The main warning I might just give to people is to keep proper distances between work and personal life I've been thinking about this a lot lately. As a millennial, I've tied so much my self-worth into my career and recently, started questioning this belief and I think the next generation (i.e. Gen Z) might be on to something around quiet quitting, their generation placing extra emphasis on pursuing things that mak…

LOL welcome to your thirties. Try to lean more towards the weird new hobby side of things, instead of the 20yo girlfriend side.

Re: I quit infosec and I couldn't be happier

#10

Got to be honest, I only clicked on the link because 'quitted' bothered me, but the Take-Aways are interesting.

Stuck out to me as well—author uses it only once apart from the title, and it's in scare quotes. Are they calling attention to the fact that it's not the usual form of the word, but then failing to explain why that's important to the subject of the post?

In any case, TIL that although "quit" is most common for past tense/past participle, "quitted" is sometimes included in dictionaries as an alternative.

Post reply on HN