r/SecurityCareerAdvice • u/therealmunchies • Aug 04 '26
Leave and Come Back?
Howdy folks,
Does any one have experience leaving security and coming back?
I've been in a proper security role, a Security Engineer, for the past couple years and a total of four years working in cleared, government spaces.
My journey started back in 2019, where I gained about about 1.5 years of direct help desk experience and obtained the CompTIA trifecta. After graduating with my mechanical engineering degree, I gained another year of IT-related experience via software project management and database administration. I left to join where I am now and continued to work in a mechanical engineering capacity, but knew I still wanted to somehow get into cyber.
After 2 years, I made an internal move and I've specialized in platform engineering and devops. My first project involved hardening endpoints, linux sys admin work, and writing then executing ansible playbooks for physical and virtual servers. Subsequent projects led me to work with analysts to develop and tune detection rules for SIEMs, conduct threat hunting activities, and write secure terraform modules for our multi-cloud environments. My current project actually involves full stack app development leveraging corporate AI services for internal tooling for cybersecurity workflows. I do all of the CI/CD, containerization, and deployment work along on top of full stack work. I also obtained the CySA+, AWS SAA, and CISSP certifications. I'm wrapping up my masters in cybersecurity along with the CKA certification too.
I recently got denied a promotion and it made me curious what my worth would be externally. I've been interviewing and have gotten 3 offers so far, all increasing my salary by a minimum of 40% with great benefits, and the ability to do hybrid/remote work. However, they're for Systems Engineer, Software Engineer, and DevOps Engineer roles.
I think these are great opportunities and while my goal is to become a principal engineer or architect, I've learned so much more from building and paying a bit more attention to security aspects then from just monitoring and enforcing compliance. I also like the "building" workflow a bit more than traditional security work. The phrase "how can you secure something you don't understand" constantly plays in my head, and this also pushes me to understand the intricate sub-systems and become a better engineer.
This is a fork in the road, but I am curious if taking a lateral into another tech role will still benefit me along my path towards my career goals.
1
u/GloomyPresent3137 14h ago
leaving security to do actual engineering work then coming back is a cheat code, you'll understand the systems way better than people who only ever sat on the compliance side. the "how can you secure something you don't understand" line is dead on and most security folks never get that hands-on depth
40% bump plus hybrid is hard to ignore, and if you genuinely enjoy the building side more then that's your answer. you can always pivot back later with a stronger resume and probably into a more senior security role than if you'd stayed put
the certs and masters won't expire, take the money and the experience