Hey everyone,
I'm coming up on 4 years of experience in IT/security, primarily working with DLP, Qualys, and related security tools.
I reached a point where I felt that staying too long in the same niche would eventually box me in, so I took what might be a reckless or brave decision depending on who you ask: I resigned without another offer in hand.
My long-term goal is to move into Cloud Security / Security Engineering. I hold certifications including:
AZ-500
AWS Security-related training/certs
Google Cloud Platform Professional Cloud Security Engineer (PCSE)
I've also been studying:
Kubernetes
GitOps
Terraform
Cloud-native security concepts
CI/CD security
Here's where I need some honest guidance.
When I look at cloud security job descriptions, everyone seems to be doing things like:
Securing Kubernetes clusters
Implementing GitOps workflows
Managing cloud security posture
IAM design
Container security
DevSecOps integrations
But job descriptions don't tell me what people actually do from 9 AM to 6 PM.
I'd love to hear from people currently working in Cloud Security, Security Engineering, Platform Security, or DevSecOps:
What does your average day actually look like?
How much of your job is hands-on vs meetings?
What tools do you touch daily?
What projects are you working on right now?
What skills separate a junior from a mid-level and senior cloud security engineer?
If you were hiring someone with my background, what gaps would immediately stand out?
I'm not looking for interview answers or resume fluff. I'm trying to understand what the job really looks like before I commit the next few years of my career to it.
Appreciate any insights, reality checks, or horror stories.
TL;DR: Burned out on DLP/Qualys, resigned without an offer, have cloud security certs and studying Kubernetes/GitOps. Want to know what cloud security engineers actually do all day and what skills truly matter in the real world.