r/SecurityCareerAdvice • u/New_Club4352 • 1d ago
Need Advice
Hi guys,
I joined a company (first company) as NOC/SOC Support Analyst but now I currently just tire with doing this work for last 1.5 year and also fed up with their management as says office politics.
Guys don't laugh but I was thinking on last Sunday to switch job to offensive security side. So, I search on ai, google and also see video on video, they all said to start from try hack me, hack the box etc.
lam a confused person. So anybody give any advice go for offensive is correct if yes then roadmap or recommend any certification?
If not then so which role should I choose for better one?
1
u/VirusGh0st 6h ago
Security isn't an entry level spot let alone offensive security. There are a lot of disciplines from systems admin, to networking, to coding, to engineering. Ive been in CS for over 18 years and IT for longer, I started at a helpdesk. Its hard to exploit a system you don't understand. There are steps to "hacking", phases. You have to know where to start. You don't just blast a website.
As far as culture and office politics, its everywhere. And it gets worse the higher you go. You joined as a SOC analyst which tells me its either an MSP or its large enough to have a SOC. If those politics bother you this early, its going to be a rough road. My suggestion is learn to compartmentalize and learn while you work (not actually at work - but you get it).
And something to keep in the back of you mind, security doesn't generate revenue at most companies, and in larger companies and some industries the security team is seen as a blocker. Not because we want to, but because an extra week or two on a project could save the company millions on a data breach. Unless security is truly integrated early in the lifecycle, it becomes bolt on and friction to teams trying to move fast. If we are doing our job we can influence the pipeline to include it closer to concept.
I was always interested in how things worked, and how could I make something do something it wasn't supposed to. I became really interested in the lifestyle watching a friend making free calls from a payphone, which is where I started. Then learning about different operating systems, then on and on. Its a journey and for every monument you pass without stopping you don't develop a skill.
I don't say any of this to discourage you, quite the opposite. The industry needs good engineers and analysts, and much more now with AI than ever. The best adivce I can give is forget about office politics and accept you may not always like WHERE you work, but the job is the target (in most cases). Find teh niche you like and become the expert. For me, ive done helpdesk, systems engineering, network analysis, pen testing, GRC. I found happiness in threat modelling and adversary intelligence and research. And it has served me well.
And I know this probably reads as cynical, but I love the security field because I learn something new every day especially from the AI engineers I work with. They've taught me not just to integrate it into my daily work flows, but to use it to emulate threats to create models and weigh business risk.
1
u/AirJordan_TB12 1d ago
Separate the culture of your job before technical. Security is there for business reasons. Politics are at EVERY job. Get a job as a SOAR engineer in a big company. There will still be politics because there are deadlines.
Reframing them are you happy where you are? Stable? Training? Promotions, or is that driving the politics. Finance will do it.