![]() |
|
Rant about how working in cybersecurity sucks - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: General (https://sinister.li/Forum-General) +--- Forum: The Lounge (https://sinister.li/Forum-The-Lounge) +--- Thread: Rant about how working in cybersecurity sucks (/Thread-Rant-about-how-working-in-cybersecurity-sucks) |
Rant about how working in cybersecurity sucks - synec0ha - 08-21-2022 I haven't stopped by the forum in awhile, but I recently graduated and got a job as a Jr Security Analyst. My final semester of school was crazy, and I've been working 50+ hours a week since I got my job. I'm heading back to school soon for a more theory and law-based cybersecurity course with the hope that I can move beyond being a Security Analyst and become something more. But you guys, it kind of sucks. I spend my days doing security audits, writing basic reports on those audits for sales, implementing security projects, monitoring security tool alerts, and dealing with email compromises and malware. My days are actually pretty interesting, but I'm slowly getting sick of some of the portions of my job. You know what clients have some of the worst security and stupidest users? Doctors and lawyers. Most of them are cheap fucks too, even though they make $$$. It's retarded. One lawyer office had 3 users emails compromised in a month. Bad ones too, invoice fraud, data exfiltration, that kind of shit. Account Manager for the client proposed a security project including MFA (which no one had LMAO) AND THEY TURNED IT DOWN? At that point I started to wonder if all of this is even worth it. For every client that seems to take their security seriously, there's 5 more who don't give a fuck. I can do my audits and write my post-compromise reports, but at the end of the day it just feels like I'm wasting my time. Maybe that's just because I'm at an MSP. Here's some other shit I've seen:
I've sat at my desk and daydreamed about the ways I can get these clients fucked. I've thought about dropping the company names or IPs of unsecured systems on sketchy hacking forums. I've even thought about pwning them myself, since I know all the vulnerabilities and passwords anyway. So far I have resisted, but I'm worried one day I'll snap. I'm also worried that I may not be cut out for this. I've only been doing this for a few months and I'm already at this point. Anyway, that's my rant. I felt like this is the only place I can say these things, especially the last part, without being judged. Maybe I'll even find some other disillusioned security 'professionals' like myself. |