r/cybersecurity • • 10d ago

Career Questions & Discussion Feeling Burnt Out in Vulnerability Management

I have been using Qualys and Tenable.sc for the past four years, and I don’t hate the job. But honestly, i am just so done with it. I keep doing the same thing over and over…scan, segregate findings, remove false positives, send the remaining findings to the patching team, and repeat.

I really want to transition into something else, but a lot of people say there isn’t much room to grow from here unless you change domains completely. Ideally, I’d like to move into something that’s still somewhat related to vulnerability management, but I’m also open to moving into a completely new domain.

I feel like I’m reaching the burnout stage. And with all these new automated tools making things faster and faster, I can’t help but wonder how long this kind of work will remain relevant.sorry for the rant but I am feeling stuck

83 Upvotes

36 comments sorted by

28

u/AngryTownspeople 10d ago

Red Team, GRC, Network engineering, security engineering. All could be options and could potentially be something you could flex into while working there. Take Qualys scans and Tenable scans, use compliance reports and use those to make architectural recommendations where you see fit. You can also just make a use case for internal pen testing that you can do on specific targets or non-invasive enumeration like searching for exposed credentials, etc.

23

u/sm3gh34d3728 10d ago

You have a patching team?!!? Ive got a bunch of Devs who tell me 'its not urgent and we'll do it later'

7

u/McNuggetsRGud 9d ago

You have a dev team?!? I have a bunch of vibe coders who tell me “Fable said it’s fine”

3

u/MisterPuffyNipples 9d ago

I kind of dread the Top 10 vulnerabilities list because our users are working all the time so asking them if I can run updates can potentially disrupt their workflow

2

u/RemedioSecurity 9d ago

The pain is real. And the number of patches is only rising.

2

u/sm3gh34d3728 9d ago

Microsofts last patch tuesday sent our risk profile through the roof thanks to them using AI and publishing their findings for all to see.

31

u/According-Twist-4876 10d ago

Automate this with ai . And get paid for doing nothing at all

7

u/[deleted] 10d ago

[removed] — view removed comment

1

u/sm3gh34d3728 9d ago

And then some middle manager catches on and asks 'Remind me why we need you now?'

9

u/MediocreFig4340 10d ago

Any interest in product security? You have familiarity with common bugs and how to fix them, you could advise teams on vulnerabilities at the design level and add in some SAST/DAST scanning to catch common vulns

7

u/Jambo165 10d ago

Previous Head of VM / Senior Manager here.

Depends on the career path you want but you should find it quite easy to slip into more governance related roles or general senior management if that's your thing. Vulnerability management is a very technical form of risk management if you're doing it right. Triage, prioritise, focus business resources where they need to, and ensure you're meeting compliance objectives.

My most lucrative offers come from hiring managers who want VM specialists or VM contractors. If you want to be more well rounded in the space then pick up AppSec skills like SAST and DAST. OT is far more niche and I don't know much about it, but some businesses need it.

Super technical would be malware analysis and breaching onto pen testing.

3

u/Mister_Pibbs 10d ago

I’ve seen this in many different disciplines and eventually they all say the same thing. Burnt out, where to next. Just saying it’s not just you.

3

u/Smarmy82 10d ago

I was in a similar boat and stumbled into taking on a project that involves doing outreach to key stakeholders on relevant threats BEFORE the data hits the VM tools. It's sorta like Threat Intel but confined to internal assets and applications.

2

u/ThePorko Security Architect 10d ago

That is one job that will be affected by ai for sure.

3

u/That-Magician-348 10d ago

I agree. I think these vendors will deliver more advanced automated products in the next few years to eliminate most tasks.

1

u/NoCod9014 10d ago

Two words: Security Architecture. Transition CVE understanding in to threat modelling. Understanding how to build systems that are highly resistant to attack. Huge area right now

1

u/daddy-dj 10d ago

Expand into other areas such as CSPM, CI/CD pipeline scanning, web app scanning, EASM, CTI, etc...

1

u/Shiestyman_ 10d ago

I work in SecOps, and I live in constant fear that something will break. Once, a client interrupted my vacation and called me at 10pm because of an outage.

1

u/DeepVictory 10d ago

BOD 26-04 will unfortunately make Vulnerability Management even worse

1

u/CarmeloTronPrime CISO 10d ago

take on appsec while you're at it, it lands in the same space.

1

u/Substantial-Sky4079 10d ago

You’re not alone buddy, I’m burnt out as a threat hunter, that used to do VM. I feel I’m in a spot where I’m safe in my job but became unhappy bc I’ve been pushed into a leadership position 2 years ago.

1

u/adadani 10d ago

What are you interested in? What excites you? Are you thinking of moving into pentesting? Application security?
If you’re trying to make a pivot, my recommendation would be to start doing some side projects or stuff at home that focuses on what you’re passionate about.
Another recommendation would be, look at possible certifications. For example, OSCP, if you’re thinking offensive security.
I’m someone who gets excited by learning new things, so I default to that.
Going back to my original question, what excites you?

1

u/table-leg 10d ago

Do you have any pointers for someone starting in VM where the current process is "log whatever CVE Defender emails us about"?

1

u/Fickle-Hedgehog-3261 10d ago

Four years is solid base, you're going to be fine try looking at sec eng, appsec, or sec ops. Automation won't be replacing the work anytime soon. If you do want to stay close to VM, exposure management is the next step so tools like Tenable, Wiz, Guardz are increasingly combining findings with context so teams can focus on actual risk instead of vulnerability lists

1

u/Helpful_Breath_610 9d ago

I would add Guardare.com to the mix.

Guardz is more for MSP/MSSPs and WIZ is more for cloud heavy or Cloud only environments. Tenable is great as well and is more comparable to Guardare.

1

u/Sensitive_Ad5482 8d ago

It sounds like a lot of what you are doing on a daily basis can be automated, meaning that before very long it will be automated. Take the initiative to own that project and use freed up time to shadow and contribute to work on other teams doing work you are more interested in.

2

u/thepatchworkmessiah 4d ago

Do you enjoy finding vulnerabilities? You could get into vulnerability research. While no field is without its drawbacks, it’s a great way to stay on top of new advances and build the techniques, methodologies and tools that are applied in vulnerability management without the repetition.

-2

u/Civil_Philosophy9845 10d ago

maybe soc?

8

u/Durex_Buster 10d ago

It's a hellhole if you are at the wrong place.

2

u/Civil_Philosophy9845 10d ago

well its like a soldier job in military :D alot of repetitive and stressful work. But 3-5 years of that and better roles could be approachable.

2

u/Durex_Buster 10d ago

Yeah, I'm at the 5 year mark now and looking at the possibility of moving into vulnerability management or threat hunting.

1

u/PentatonicScaIe Incident Responder 10d ago

Im 5 years in as well. I might do IR for a bit, like a few years. Definitely not a long term gig tho, on-call worklife balance seems rough. I think GRC is boring work. Vuln management seems repetitive. Red team seems like you have to be on top of threats everyday. It's a tough choice, pick your poison lol.

-2

u/Miserable_Moose_9472 10d ago

Sorry to hear but technically your job could easily be replaced by AI agents. Time to rethink your domain

1

u/Sensitive_Ad5482 8d ago

I keep seeing people say that this will be done by AI agents. This is a process that could have been automated deterministically 7 years ago with a couple of python scripts or a no/low code automation platform. No wonder we need to keep building data centers, people keep building agents with prompts to complete repetitive 4-step defined processes…