Related Posts
More Posts
Additional Posts in Cyber Security Bowl
Anyone ever heard of or worked for Sygnia?
Views on carbon black as a product?
New to Fishbowl?
Download the Fishbowl app to
unlock all discussions on Fishbowl.
unlock all discussions on Fishbowl.




Working for public companies and regulated companies require a level of precision with respect to documentation. I was going to tell you to join the military, but then I realized that probably requires more documentation than private industry. Not trying to give you a snarky answer, but rather a realistic one. Why not understand why upper management is asking you for what they are. Understand regulations like sarbanes oxley, pci, ccpa and others that require this. Yes. The folks that don’t touch the keyboards at one time did, and then advanced into management to helm the ship.
Consider:
NSA if you want to fight foreign threats
Antivirus / EDR tooling
IR response consulting
Head this advise. Be careful getting into consulting. There are two types of consulting in security. Functional and technical. Often the functional side will sell itself to perspectives ad technical. In reality all you will end up doing is IT Audit writing policy and procedures and compliance paperwork. Be sure to look at your future bosses linked in because if you take that role that is the direction it is geared towards. If they aren't asking for technical certs or at a very minimum not asking you technical questions in interview it is most likely a functional job. Also many times consulting firms will tell you we will bring you in as functional (IT Audit does this) and you can transition over to technical security within a year. From my experience this is rarely ever the case.
Your perspective is valid and I understand it. However, relying solely on documentation will not prevent security threats. There appears to be an excessive focus on documentation as a way to cover our backs when instead, we should prioritize preventing/ fighting threats and training our script kiddies to fix the current knowledge gaps in the field.
That means my friend, that you are being managed wrong. If you were working for me (and I am a CISO now ) I would demand that you think about and act on threats 24x7. Of course I’d still need you to document
Have you considered IR as a consultant? I previously worked for a F50 company and moved to DFIR consulting. So much better in terms of variety in my day to day.
Digital forensics and incident response
Coach
Software engineering or data science
Mentor
Yeah, because the software engineers are never forced to document anything lol
Consulting! Check out GH and DM if you want to chat