Discussion about this post

User's avatar
Dr Sam Illingworth's avatar

Thanks, Erich, even though I'm not a software developer, this is such great guidance for getting into cyber security and security more generally. This would be really useful advice for undergraduate students as well.

JP's avatar

The "security champion" step is the one most developers skip because it feels risky - you're volunteering to own a problem nobody else wants. But that's exactly why it works. I've been shipping production code for 14 years and the devs who become the de facto security voice on their teams always punch above their weight in hiring conversations.

The timing for this transition is also pretty striking right now - 62% of AI-generated code comes out with vulnerabilities baked in, and there literally aren't enough people to audit it. Wrote about the numbers behind this if you're curious: https://blog.devgenius.io/the-code-we-cant-secure-why-cybersecurity-is-about-to-become-the-hottest-career-in-tech-1f4f466d5c38

5 more comments...

No posts

Ready for more?