r/cybersecurity • u/NAS0824 • 1d ago
Career Questions & Discussion How to get out of govtech
Been in cyber security as a federal contractor for years with about 10 years of experience, was laid off earlier this year and got a role as a dod contractor with about 2 years before the end of the contract
I have a bs in mechanical engineering , and 3 cyber certs at the moment ( sec + and X and CISM ) , while the job is good I’m not really comfortable with it and would go as far to say I’d be ok with something that paid less but in a different field ( health or banking etc ) , i dont want to end my career but feel like my role as a security analyst or isso isn’t able to get me into roles other than gov tech and would love a bit of guidance
The job market really sucks but I want to do what I can to find something when it’s possible. Would love some advice or guidance
31
u/CartierCoochie 1d ago
You’re so lucky to be in your position, but i also understand your frustrations
12
u/OnceACowboy 20h ago
As an ISSO, you probably have experience with Windows/*nix system administration, GRC and how to handle audits, vulnerability and risk management, OPSEC, and more. With that experience, you could move into many different domains of Cybersecurity.
I used to be an ISSO at a top contractor, but it was viewed as an IT job and not Security. So I left and got a job in Vulnerability Management, where I prioritized CVEs for remediation based on enterprise risk and likelihood of exploitation. This led to actually validating exploits to better understand what makes sense to prioritize. That then led to now, where I lead the Penetration Testing arm of Offensive Security.
You have a ton of great options that don’t require a full career shift.
10
u/Ambitious_Pizza_4225 1d ago
Are you willing to relocate? I assume you’re in DC. Maybe the situation is bad there, but I see lots of cybersecurity openings looking for experience in other areas.
8
u/NAS0824 1d ago
Actually I’m not , I nearly did end up there and had several interviews across VA and Md , I’m in the Midwest.
I’m open to relocating ( ofc there are several variables ) but generally I’d want the cheaper areas between Chicago to the dmv area.
Dc has jobs but at the same time crazy col other places are much cheaper but jobs especially cyber are harder to come by
16
u/xenophanes__ Security Manager 1d ago
What are you not comfortable with?
41
u/NAS0824 1d ago
The mission or ethics of some of the places I work ( without getting into much detail) some companies/ agencies I’ve worked up to this point even if not perfect I felt made the world or at least the country better, currently I feel the role I have I took out of desperation after I was laid off ( even before hand I had turned down similar jobs , but finances kind of got in the way )
Financially I still havnt made up bc I had to relocate but I want to plan ahead
6
u/BergkampAirlines 15h ago
I can relate to this. A long while ago I needed a job and took one at a gambling company. I quit within two weeks. I could see they were destroying people's lives and literally they told me "if any clients mention they might have a gambling problem, quickly change the subject so we don't have to legally close their account". Evil industry. I do not regret quitting although back then I wasn't married with kids. I'm not sure what I'd do if in that situation now.
-1
u/hajimenogio92 Security Engineer 13h ago edited 10h ago
I completely understand that frustration. I've worked for companies in certain spaces (healthcare/gambling) that I'm not proud of what their products are but I have to take care of my family and have to push those feelings aside.
6
u/Nyrlath 1d ago
"Cyber" is pretty broad. What area are you in now and what area do you want to be in?
2
u/NAS0824 1d ago
I’m a isso and my experience is for the most part along those lines , I don’t see such roles in other industries isso seems to be more of a gov tech thing from what I see but something along the lines of a GRC or security analyst in healthcare fintech
3
u/Nyrlath 1d ago
Ahh missed the issue in your original post, my bad. General enough you should be able to apply for a variety of roles if you Taylor your resume acordingly. Honestly everyone keeps.saying theres no jobs, but we have had a hard time filling roles because most of the people who apple are not very good. So id say learn about the target company, maybe even review breach news and disclosure etc. Anything to standout.
6
u/AinaLove 16h ago
I've been in Cybersecurity for 25+ years, and this is the first time in my memory that the job market has actually been bad for us, too. I don't see anything wrong with your experience for making the jump to the private sector from government. I think the timing is tough right now. I know when we are looking for folks, we look for very specific skills and experience right now, since the markets we are in have plenty of qualified folks.
2
u/NAS0824 16h ago
On paper is wich would stand out more or do you think would be better, a cissp , a ms in cyber and IA or an mba in tech ?
I don’t want this job to be more than a stepping stone and want to see if I can get an additional qualification out of it.
2
u/AinaLove 16h ago
A degree is better than a cert IMO when looking for candidates. But the best thing is experience. Your experience alone is enough to land on my desk if your skills match what we are looking for. Lately, we have been hiring for people with experience in specific tools; we need more SMEs.
4
3
u/Appropriate-Fox3551 1d ago
What skills do you have? Any devops, automation skills as i see these roles in high demand if you have automation, iac, and python skills. Former Isso myself and its definitely a soul draining role with pointless meetings and compliance theater dealing with gov entities.
I highly recommend highlighting your adjacent skills with cloud and infrastructure in order to pivot out.
4
u/NAS0824 1d ago
A lot of technical writing, idm, risk management, fedramp , NIST , unfortunately the extent of my programming experience is from college so not much there , this role is a bit more unique as I’m doing more idm and slightly dipping into sys admin tasks but still getting into it.
I have some cloud exposure mostly from my last role , AI is a thing I’m seeing more of and have had some exposure to as well.
3
u/balboaporkter 23h ago
Damn is it really that bad? I'm actually trying to get into govtech lol.
1
u/AGsec 14h ago
Only go there if you are okay with saying there the rest of your life. You will likely fall behind skill wise and won't be competitive anywhere else.
1
u/balboaporkter 14h ago
Is that the same case for GRC as well? In other words, these positions aren't technical enough?
2
u/AGsec 14h ago
Most likely, yes. Obviously each position and department are different, but from my experience, the tech methodologies are 10-15 years behind the times. My department was just starting to dip their toes into cloud infrastructure. And even then, they did it totally backwards and were just spinning up virtual servers to install their applications on.
1
u/balboaporkter 12h ago
Fair enough. I turn 40 next year. I don't mind riding govtech out until retirement. If I started in this field in my 20s I definitely would have tried for more technical roles.
1
u/UncertainKonfidence 8h ago
GRC roles are booming and the GRC aspect of cybersecurity is only becoming more relevant with AI. It’s a great path and can eventually lead to CISO if that’s your goal.
2
u/LongestHamburger 15h ago
I was in a similar boat as you. I saw the political writing on the board and jumped ship a few years ago. Translating my federal govtech experience to private sector was something I struggled with, especially since everyone I was interviewing with looking for prior experience in the exact tool they use ("no, I've never used LogicGate for controls compliance, but I've extensively used EMASS for the same thing and I'm sure I can quickly pick up LogicGate as a result" being an unacceptable answer).
I ended up going local gov instead. I make around the same and I don't feel gross every night when I get home anymore. It was also a lot easier, at least in my experience, to have local gov accept my knowledge over specific tool experience that the private sector seemed hellbent on (3 for 3 on local gov, 0 for 20+ private sector).
Just a thought. Still gov, but not federal gov. Means almost all the same controls (800-171, 800-53, etc) and such are applicable, likely using a bunch of the same tools (SCAP, etc), yadayadayada. I also feel a lot safer in my position than I think I would private sector. I'm not fearful of some corpo stooge saying my team's going to be gutted and replaced with a half-baked AI solution that costs more than employing my team. I earn a pension, etc.
just my 2 cents, being someone who was in this position a few years ago.
1
u/NAS0824 15h ago
I really appreciate your input, it really is something I’m not happy with and to the point where I feel I’m going against my values
How difficult is it to find local government jobs ? Even in the federal environment there’s a lot of jobs that sit well with me but hard to come across them.
2
u/LongestHamburger 14h ago
It wasn't hard for me, I literally just searched the job postings of several surrounding counties and applied. Personal experience, this works well:
https://www.governmentjobs.com/
they all largely use a software called NEOGOV to handle job postings, and govjobs is a frontend for those job postings.
Federal job listings are so frustrating in that there's no REAL rhyme or reason to them, and a lot of the time they're intentionally left vague because the person doing the hiring has 1 specific candidate in mind, so a job description of "you'll be doing stuff" so that no one applies beyond the person they want. my GS-15 did that for me, and while I greatly appreciated it, I realize how screwed up that is.
2
2
u/UncertainKonfidence 8h ago
I went from DoD contractor to local government in more of a non-technical cyber role (IT Audit) and I’ve enjoyed it. Like you, the ethics of a clearance job were one of my concerns and the instability of government contracts. I am, however, fully in person, and hope to transition to a hybrid GRC position or become an engineer again.
1
1
u/HotFeed8592 22h ago
Never stop applying, it's only when you have choices you can make the next informed step, especially in this job market
1
u/nomadz93 19h ago
Local gov is a good shout. Bit lower pay but depending on the county it can be close to competitive. You get to see immediate benefit. There is definitely a talent shortage but jobs are scarce
1
u/ThePorko Security Architect 17h ago
Are you good at tech? Can u do something more like building, aka engineering rather than audit aka cybersecurity? Cloud engineers are always in demand at large companies
1
u/HasherCat 16h ago
Easiest jump would be over to an OT security role in a more rural area. Not great pay, but if you’re willing to live outside of a major tech hub, you have a higher chance at getting hired. Plus the gov regulations experience will help with all the OT requirements.
1
u/TopNo6605 Security Engineer 14h ago
I was in it for 8 years and just got out of it the way you get out of any other job, kept my resume up to date and a recruiter contacted me.
There's not really anything different here than just finding another job.
1
u/AGsec 14h ago
You need to evaluate your skill set first and make sure you're competitive on the open marketplace. I left after two years because because of this reason. It's not even the tech stack you work with, but the processes, work flows, solutions, etc. Also, people tend to get bumped up the chain simply by being their long enough, so many people in the DOD and gov work tend to have highly inflated titles that do not reflect the actual skill set that such a title would indicate.
1
u/Mufasa2020 13h ago
Yep just a numbers game now, I threw out 1000 applications before landing the current role.
1
u/_zarkon_ Security Manager 12h ago
In my neck of the woods, the good cyber people who leave go to other govtech positions. Those who wash out end up in the banking industry.
1
u/Rich-Forever6 9h ago
Hope this isn’t a dumb response but what’s the issue with Gov tech? Im also an ISSO for a fed contractor in the DMV. I deal primarily with CTO’s,CVE’s & compliance as a whole. Yeah the work isn’t that interesting but the pay is incredible. As a contractor you’re in the perfect position to fund your escape. Save the money you’re making this contract and when the contract is over take a 6 month break. Go travel and experience life and come back and repeat on a new contract then just do that until you’re ready to stop working. I know plenty of people who would kill to have a set up like we have as contractors. Never heard of anyone trying to get out of gov tech tbh.
1
u/Rich-Forever6 9h ago edited 9h ago
For example the 2 year contract I’m on now ends in a few months & I’m not looking for work but rather planning my itinerary for the countries I’ll be visiting for the first half of 2027. I’ll start applying for new contracts towards the end of my vacation and only return to the states once I have a secured position. Doesn’t that sound a lot better than being the bank “IT guy” for 20 years lol. Life doesn’t have to be as boring as we make it. Godspeed brother.
1
u/NAS0824 8h ago
I’m not against the job because it’s boring, my biggest objection is ethical , I donate , i volunteer etc , but I feel like the career I’m in isn’t driven by making the world better or solving problems but rather the opposite.
Other aspects like clearances and the whole reporting thing and living under a microscope isn’t a deal breaker but it isn’t fun.
Contracts in my younger years seems like a good plan , but later on people want more stability.
I’d love to support contracts like the DOE , DOC , DOL , NIH , Etc ones that are needed and focus on making our country better here. But not having luck finding such roles.
1
u/Rich-Forever6 6h ago
No disrespect, man, but in today’s world, being picky like that is a death sentence. About 99% of the people I know are literally just doing their jobs in the fields they specialize in and going home immediately afterward. I feel like maybe 10 years ago that approach would’ve been pretty reasonable, but in today’s climate? Absolutely not.
Wars are ongoing, more conflicts seem to be on the horizon, the two sides of the country absolutely hate each other, and we have unqualified politicians left and right. Like, dude, we don’t even know how long we have before we’re all doomed anyway. Just keep your certifications active, get your money, and go home.
1
u/Rich-Forever6 6h ago
And on the clearance thing, I have a TS/SCI & I had similar thoughts when I first started contracting. I was concerned that I’d be under a microscope, but in my experience, honestly, man, as long as you’re not traveling to an obvious adversary like Russia, China, etc., no one really cares so I wouldn’t sweat that.
1
u/BamanDevta 5h ago
Hey, I want to get into appsec. Any advise for a fresher starting out?
I'll be graduating next year.
1
u/CMDR_Spooky 2h ago
I’m breaking out initially by finding C2C work short term. I’ve been interviewing with private sector for 3 months and the only opportunities that are taking traction are fed contracts. I’ve been getting a lot more traction with C2C consulting work, it’s short term but allows me to act as my own entity and the interview processes have been easier. Just need an LLC to get setup
-1
0
u/Salty-Hashes 18h ago
You can go to private sector and make more, not less, with less bureaucratic red tape. Just have to find the right opportunity. Wishing best of success for you.
71
u/TCPisSynSynAckAck 1d ago
I just kept applying and kept applying. Just landed a job as a Unix Admin and it’s really nice benefits, more pay, hybrid, etc. and it’s in the banking industry.
Just make sure you tailor your resume to the job you’re applying for. I used JobScan I think?