Answering a series of questions orbiting the larger question “how is the job (in infosec)?”. I answered this kinda rapid-fire on Reddit, but decided to come back here in the note and give it a bit more thought and embellishment…

  • Work-Life-Balance: Maybe I’m lucky here, but I’ve always felt my WLB was pretty great. Mostly I think WLB is something you have to learn to manage yourself, otherwise you can be eaten alive. Sure, I get busy sometimes, but usually I see this as “good stress”, not something that is overwhelming.

  • Hours: I work 8 hour days at most. Anything I work over that is for no other reason than I’m a nerd and I’m literally doin’ work-related/adjacent stuff in my free time because I genuinely want to. Look no further than this blog. Sometimes I write about infosec stuff, and sometimes that infosec stuff just happens to be what I’m actively doin’ at work at that time. A nice symbiosis if you ask me!

  • Companies: Most companies I’ve worked for (imo) don’t really care about infosec. There is regulation which compels them to do certain things, and there is the very real, ever-present threat landscape, but investment into infosec is always seems to be reactionary and bare-minimum-ish. Sure, there have been some exceptions, at least to some degree, but the fact is infosec is a cost center, and companies continue to see responding to potential breaches/incidents as being preferable to staffing up appropriately. As such, you’ll probably always feel understaffed in your orgs, and that’s because you are.

  • Difficulties: see “Companies” above. Besides that, infosec is hard. Even when it shouldn’t be. The basics really aren’t that hard, but you wouldn’t know that given how often even “pros” seem to get the basics wrong. I swear burnout happens mostly because it seems people just continuously seem to fail on the easiest stuff and it gets a little frustrating… One more thing, there’s a lot to learn. Which is awesome really, but if you don’t have time to learn, then you can feel constantly behind. Too many companies don’t make time for folks to skill up, and that’s an issue.

  • Getting hired: Yes it was difficult (for me), and that seems to still be the case for a lot of folks. Traditionally, it’s been hard to break in, and then easy to move up and around after that. That said, seems like the market is tightening more and more these days to the point where even experienced folks are having more trouble staying gainfully employed…

  • Getting necessary qualifications: Though a career in cybersecurity might not be as dependent on certs as it once was, you still universally see them as requirements or “nice-to-haves” on job reqs. I don’t think you need to pile up certs, but having one or two that are applicable to the job roles you are applying to can help you get past resume screens. So don’t focus on “certification paths”, instead focus on learning actual skills. I have a bunch of thoughts on what cert you should take here. It’s also worth pointing out that you don’t need to spend thousands to get the necessary skills. You’ll also have to factor in the amount of time it takes to study and actually take these exams.

  • Pay: Pay has been good. You can make good money and there’s decent opportunities. From a money perspective, I’m not sure what I’d really do in my life it wasn’t for tech, and more specifically, infosec. I know plenty of folks outside the industry and their prospects are just not as good, and most of them have worse hours, less perks, more stressful jobs, etc…

GOOD LUCK!