3 ms·
I have nothing more to add than up-vote this and parent comment. Execs don't get bonuses nor career tracks through good security. And it's hard to make a career
by NotPavlovsDog 6y ago
I have nothing more to add than up-vote this and parent comment.
Execs don't get bonuses nor career tracks through good security. And it's hard to make a career or professional friends in the org by telling people they are doing things wrong.
And all the fantabulous security breaches we have had through the years have failed to sink a single company.
Concentrate on "products that drive value" unless you already enjoy the security field and can't imagine your life without it.
A long time back, personal story: was excluded from certain exec meetings for a time after I brought up that a simple website scan showed multiple vulnerabilities, which should probably be fixed before our big upcoming pitch, so as to avoid a highly probable deface and embarrassment. Tried to fix it through email for 2 weeks before then, went public in the org as a last ditch effort to prevent damage. Only thing it damaged was my prospects in that org. They took it as an insult and not loyalty to the org.
- alangibson 6y ago> And it's hard to make a career or professional friends in the org by telling people they are doing things wrong. This is a really good point. Every one will cringe when they see you coming, and that's going to drag on your career.
- NotPavlovsDog 6y agoThe contacts I have that are successful professionals in security work as gun-for-hire consultants. They are contrarian, enjoy pointing out shortcomings, and, being consultants, don't have to stay after their report is delivered.
- alangibson 6y agoThat makes a lot of sense. Good input for the OP.
- jaegerpicker 6y agoThis is my exact experience also as a app security engineer and the reason I now longer work in that field. If you are good, then most of the time you are the boy who cried wolf or people forget you exist. If you are bad or learning and something happens you are the fall guy for everything. It's not a job that I'd jump back into unless I had a rock solid personal reference for a company that cared about security deeply.
- NotPavlovsDog 6y agoThank you for sharing your experience. Needless to say, everyone's experience will be different, but, especially for security work, it is important to think about core factors in implementation: policy and psychology. If you are not associated with "winning", and are a "nagger" vs an "enabler", this diminishes prospects.