Security is a vertical that tends to attract really really smart people and people looking for a landing zone, functioning as unaccredited auditors or folks performing monk-like transcription of NIST or compliance guide. There’s no middle.
The only really technical person I know who is really happy in the space transitioned into a security-focused solution architect type role with a VAR. But he is one of those rare people who is very deep in a few tech disciplines AND loves engaging with people.
I've worked with a number of people who land in "the middle" IMO. These are application security engineers hired to staff the security teams at companies building normal b2b or b2c products. Their job is a mix of hands-on fixes in application codebases, triage of reports from external researchers, and scripting/building their own systems. They're coders who remain practical, not world-class cryptographical researchers nor spreadsheet jockeys, and they're darned useful to have in place at companies where you can't expect every developer to maintain up-to-date deep domain knowledge of the security landscape.
I've had that role twice! For me, perhaps I just haven't found the right place, it starts out as the best job I've ever had and then ends up being a terrible slog. Developers stop caring, management does the math and finds it easier to have you on staff but doing nothing really important because you keep making the dev team fix their SQL injections or XSS and they miss features and blame the fixes that you pushed for, and then you spend 90% of your time chasing dev's to update their libraries and you want to harm everyone. It's just a tough road to work if you are at all a creative developer that wants to see something you have built. I REALLY wanted to love that job but even for good companies it's very hard to find a good situation in my experience.
Same here. You're just outnumbered, and because of that you're often seen as having unreasonable requests or point of view. I don't think anybody who works in a security team is happy, it's a shit job honestly. The less you do, the happier your devs are. And at the end of the day, you look back at the years of work you've done, and there's nothing to show. No building, it was just about pushing through friction.
Security is a vertical that tends to attract really really smart people and people looking for a landing zone, functioning as unaccredited auditors or folks performing monk-like transcription of NIST or compliance guide. There’s no middle.
The only really technical person I know who is really happy in the space transitioned into a security-focused solution architect type role with a VAR. But he is one of those rare people who is very deep in a few tech disciplines AND loves engaging with people.