Breaking into Cyber 2026

As I approach twelve years in Cyber, I’ve been reflecting on my own journey, hiring security teams, and mentoring aspiring engineers. What follows are observations and lived experience from various technologist roles, including six years leading high-performing security teams across several technology companies.

This blog post focuses on the technical domains within Cyber. I acknowledge that cyber is more than just technology and engineering—sales, marketing, communications, awareness, and a slew of other roles support a broader cybersecurity program, but my experience is primarily in working on and leading security engineering teams.

Why do you want to move into cyber?

There are hundreds of bootcamps that have sprouted up to support the explosion of interest in cybersecurity, many touting the high pay as an incentive. While you can be well compensated, think about your incentives—what specifically excites you about moving into cybersecurity? Do you know what the day-to-day looks like for someone in the role? Sure, you can make a lot of money but if it’s misaligned with your long-term goals, you will not be happy. 

This is also critical in helping you sell yourself. How would you answer “Why do you want to be in [role] at [company]?” if asked by a recruiter, founder, or another security engineer? 

Security Domains

Skills and approach vary across the security domains. What you need to be successful in Security Operations is very different from what you’ll need when building tooling and controls on Security Engineering teams. Here is a sample of domains to chew on:




"The Map of Cybersecurity Domains, Henry Jiang, March 2021"

The mindmap is more than five years old (!) but many domains are still relevant. With the continued march toward using software engineering and “devops” practices across security, areas such as cloud security, application security, and architecture are now a platform capability rather than individual functions. Sprinkle in AI becoming increasingly capable (more on this below) and security orgs look very different than they did even two years ago. On smaller teams, you will likely be supporting a little bit of everything. Much of this is dependent on the business model, organizational design, budget, and skillset.

Take some time to understand where your interests lie and where things are changing. These are some examples of what domains look like:

  • Product Security: working directly with engineering teams from ideation to release

  • Enterprise Security: (sometimes known as CorpSec) securing endpoints, SaaS, networks, and implementing guardrails across enterprise technologies

  • Security Operations: enterprise-wide threat detection and response. Proactive monitoring and technical investigations

  • GRC Engineering: systems thinking and engineering practices applied to the GRC problem space

  • Security @ GitLab: an example of how GitLab structures its security organization

Early in career and security adjacent roles

I prefer the term early in career to “junior” but this is a personal preference. An early in career candidate is typically someone with 0-5 years of experience. They are building expertise and credibility but don’t have the depth to solve sticky problems just yet.

Shifting from an adjacent role such as Site Reliability Engineering (SRE), Cloud, IT, or software engineering into a security role has become more common. Depending on the role, skills may be transferable. A cloud engineer who has built and secured AWS environments could be a great fit for a Platform Security role. Engineers with SaaS administration, Identity Access Management (IAM) experience, or endpoint management could do quite well in Enterprise Security. Software engineers who can perform high-quality code reviews and understand how threats manifest in the software supply chain would slay on a Product Security or Security Architecture team.

If you’re in an adjacent role at a company with a dedicated security team, start to build relationships with that team directly. Large security teams are a luxury, and they’re always looking for ambassadors and champions. If you have the bandwidth, lend a hand where you can. If your current team doesn’t yet have regular touchpoints with the security team, offer to broker an introduction. 

Networking

Grow your network. 

Grow your network.

Grow your network.

This is a skill I wish I would have developed as I was building technical and domain expertise early on in my career. Technical depth and breadth is crucial for long-term success but meeting people with different experiences and backgrounds is critical in shaping your worldview and cultivating another skill you will need to leverage in the future: relationship building. This is how security work actually happens, but it’s also a potential boon for future opportunities. I’ve been the beneficiary of two roles because someone I worked with previously thought I would be a good fit at their company. 

Remember, people first.

This can be also be supported in a few other ways:

Social networks

Engaging with content and connecting/following thought leaders is a good first step that doesn’t require a lot of effort. LinkedIn, X, Bluesky, and Mastodon all provide very different experiences and audiences. Most people start with consuming content or “lurking” in spaces but the key is to eventually engage with content in a meaningful way. Ask a question, leave a relevant comment that invites additional discussion. This is a great way to develop your voice.  Don’t use AI for this because it’s generic and bland. 

Conferences

Attending conferences serves a few ends:

  • Hearing research from across the industry

  • Meeting folks across the career spectrum

  • Spending time with friends old and new (The week of Black Hat, DEF CON, and BSidesLV is famously called “Hacker Summer Camp” for a reason)

Your mileage may vary. Depending on the conference size and your budget you’ll split time doing some or all of the above. Blackhat and DEF CON can be quite expensive, even on a tight budget. You can aspire to attend them both one day but smaller community gatherings are likely your best bet. I’ve attended BSides NYC every year since its launch in 2016 and the best conversations I have are with folks who are curious and new to security.

In-person meet ups

Find your local meet ups to talk to practitioners in real life. BSides has over two hundred chapters, OWASP has over three-hundred globally. Offer to connect on LinkedIn or exchange contact information to cultivate those new relationships. In person meetups may feature presentations called Lightning Talks. Build expertise and form an opinion that could become the basis for a lightning talk.

NYC InfoSec is a great resource to find out what’s cooking in the tri-state area.

Mentorship

Professional mentorship can vary widely based on where you are in your career and what your goals are. Remember when I mentioned forming a relationship with the security team? Is someone on that team willing to support your professional growth? If not, the security folks you’re meeting in real life could also take you under your wing.

I wouldn’t shy away from leveraging other forms of mentorship. As part of a structure mentorship program early in my career at Etsy, I was paired with a Senior Staff engineer who gave me insight into parts of the business I knew nothing about. I was able to expand my understanding about our threat profile and team ways of working through those discussions.

Content

There are A LOT of cyber security content creators. You shouldn’t feel compelled to be one unless that’s on your vision board, but it is helpful to showcase how you write and think. This is especially important when you are just starting out and you don’t yet have the hands-on experience to get you in the door for interviews. High quality writing will differentiate you, especially with AI generated slop being flung around. 

Here is some great writing from Olivia Gallucci and Nielet D’Mello.

Education & Certifications

Certifications are a good way to build foundational knowledge within a specific area—think certifications for building and securing services on AWS and Google Cloud Platform. Certifications such as the OSCP are narrower in scope but start to formalize you as a specialist. Certifications should encourage additional exploration and hopefully allow for practical application in a role. I’ve seen some roles list “preferred” certifications such as the CISSP but by themselves, certificates are unlikely to land you a job. Understanding your incentives, building community, and earning certifications can help set you apart during recruitment processes.

How AI is shaping all of this

Whether you like it or not, AI is here to stay. Companies are looking for ways to augment teams and AI is very capable in many areas

  • Document summarization: great use case for incident write-ups or drafting incident status updates to relevant personnel.

  • Analyst co-pilot: building agents to support hunting and response

  • Threat modeling: democratizing threat modeling practices beyond security engineering

  • Pull request review: cost conscious, code reviews at scale

  • Generating Terraform configuration files

I attended Black Hat in 2025 and the amount of AI SOC vendors was dizzying.

I did not attend Black Hat in 2026 and I heard the amount of AI SOC talk was dizzying.

Alex Hurtado's “A completely scientific analysis of what I overheard at Black Hat” from LinkedIn

Next
Next

Ticket Ledger