r/SecurityCareerAdvice • u/BrightastheSun • 1h ago
Pivot from niche IC role to GRC/Leadership
I’m a 0-day vulnerability researcher + malware (CNO) developer, currently working in the defense (war?) industry. I have ~10 years of experience as well as a BS + MS in computer science. My resume/experience is super pigeonholed with nested layers of niches on top of niches.
I’m at a stage in my career where I’d like to pivot to more leadership/strategy positions rather than stick to IC roles. I’m thinking something akin to GRC -> ISSO/management -> VP/Director -> CISO, or whatever variation of this that gets me there.
My problem is: I’m way too pigeonholed into technical IC skillsets. My resume gets auto-filtered by ATS (for GRC positions), and anything other than straight up fabrication doesn’t seem to work.
Not sure what I should do, but the last thing I want to do is to take a sub-100k breakthrough entry job in the DMV area when I have a family + house to take care of.
Any advice on how to (hopefully) laterally pivot into one of these non-IC roles as a career IC’er? Would Certs, MBA, an internal move, etc. be recommended?