~/steve.net — topics/security/breaking-in/01-the-field · theme: Synthwave

Breaking In 01 — The Lay of the Land

Part of the Breaking Into Security field guide.

"Cybersecurity" on a job board covers wildly different work. The fastest way to make sense of it is four families. Most people build a career inside one of them, with side trips.

Defense (the blue team)

The people watching for attacks and responding when they happen. This is where most of the jobs are, and the most common entry point.

Offense (the red team)

The people paid to break in so the defense can fix the holes.

Offense gets the movie glamour, but it's the smallest family by headcount and the hardest to enter directly. Most good pentesters did defense or engineering first — you break things better when you know how they're built and run.

Security engineering

The people building the guardrails, and the family most undersold to career-changers — it's the natural landing spot if you come from IT or development.

Governance, risk, and compliance (GRC)

The people making sure security is provable — policies, risk assessments, audits, and frameworks (SOC 2, ISO 27001, HIPAA, PCI). Less technical day-to-day, heavier on writing, judgment, and working across teams.

Easy to dismiss if you want hands-on-keyboard work; don't. GRC hires more career-changers than any other family, pays well, and anyone who can translate between auditors and engineers is permanently valuable. In regulated industries — healthcare very much included — GRC often is the security team's center of gravity.

Which door is yours?

Rough matching, if you're coming from IT:

Next: 02 — Your IT Years Are the Head Start, on what actually transfers.

theme: apple synthwave amber c64 arcade tek
steve.net · page: topics/security/breaking-in/01-the-field
? keys try: curl steve.net or: ssh steve.net or: shell mode or: reading view