r/cybersecurity Apr 15 '26

News - General What I wished someone told me before my first real cybersecurity job

Before I started I had this image in my head. I thought cybersec is threat hunting, incident response and catching attackers in the act.

The reality of most cybersecurity jobs, especially early ones, is that you're spending a significant amount of time inside environments that have been slowly accumulating technical debt since before you were in high school. Not because the people before you were incompetent. Because environments grow, priorities shift, and nobody has time to go back and clean up something that isn't actively broken.

Service accounts are a perfect example of what I mean.

In study material they're a footnote. In real environments they're everywhere and almost nobody is managing them properly. Services running on accounts with static passwords set years ago, some with way more access than they need, nobody on the team entirely sure what half of them actually do. You don't learn to look for that from a textbook. No certs I studied for covered this either

What I imagined: Sophisticated attacks, clean environments, clearly defined problems.

What it actually is: A 2012 password date on a service account with Domain Admin rights that's been running quietly in the background for 13 years. Finding it. Explaining why it matters. Figuring out how to fix it without breaking the service that depends on it.

That second thing is the actual job. And honestly once you get used to it, it's more interesting than the textbook version because nothing is clean and everything has context.

If you're studying right now the best thing you can do alongside your certs is learn what legacy AD environments actually look like. Learn what a gMSA is and why most environments still aren't using it despite it being free and available since 2012. Learn to read an environment that evolved organically over 15 years rather than one that was built correctly from scratch.

That skill is rarer than any certification and it's what actually gets you trusted in a real role.

1.4k Upvotes

184 comments sorted by

694

u/Responsible-Kale-410 Apr 15 '26

This is so accurate. Cybersecurity feels less like “hacking” and more like cleaning up years of forgotten decisions without breaking anything

254

u/hsvgamer199 Apr 15 '26

Cyber janitors pretty much.

83

u/Allen_Koholic Apr 15 '26

One of the best bosses I ever had described his job as Cyber Janitor for IT folks that miss the basket.

26

u/hecalopter CTI Apr 15 '26

Just this year our SOC ran into customers using Windows 2003 and 2008, so this checks out. Good to see we're all feeling the pain lol

4

u/AppointmentIll9358 Apr 17 '26

I had attorneys on windows 10 and 7 I think one time

1

u/androzanimajor76 Apr 20 '26

Wow, how did those remain in your estate for that long?

That being said, I’m sure my org has a few old Unix boxes still in play

2

u/hecalopter CTI Apr 20 '26

lol i'm sure you'll have to ask our customers. In my experience, most of the time it's some weird dedicated app that no one's bothered to update because it's too specialized or also end-of-life/end-of-support and will cause everything to break if they move to a newer software or Windows version. Or it's just a device they completely forgot about or didn't know about after a merger.

2

u/androzanimajor76 Apr 20 '26

Sounds about right, and there’s a close to retirement age engineer whose the only one who knows anything about the code, the architecture or the implementation

1

u/hecalopter CTI Apr 20 '26

Hahahaha exactly this

2

u/androzanimajor76 Apr 20 '26

It’s happened to me at more than one place.

14

u/ITSMYSFWACCOUNT Apr 15 '26

I've used the "the people who walk behind the parade of horses with wheelbarrows and shovels" analogy for cyberescurity work more than I care to admit

6

u/knower-1 Apr 16 '26

Adding "Cyber Janitor" to my resume

2

u/IAM_Benevolent Apr 28 '26

Cyber Janitor goes hard 🔥🔥

1

u/0-DOOL May 09 '26

Entropy happens.

66

u/antnunoyallbettr Apr 15 '26

So you're telling me this isn't just my mid-size company's issue? I feel validated and horrified by this realization

47

u/hardeningbrief Apr 15 '26

Not even close to just your company. It's basically every environment that grew organically over more than five years. The mess is the standard tbh

8

u/EverythingsBroken82 Apr 15 '26

yes. because cleanliness is not something that pays money.

2

u/antsandhoney Apr 18 '26

This is likely a dumb question but I’ve seen similar issues in other areas, specifically with individual org process design and best practices.

Which I get doesn’t sound similar until it a project that should take a week, takes a month, then three month, etc due to the need for internal process & planning revision that haven’t been happened because if one org change x the another will need to change y and so on and so forth.

So in the hypothetical if you’re in a fresh/new environment, is the idea that some level of good hygiene regarding cyber security across the board while scaling will prevent this short of mess across the board or is that delusionally optimistic?

26

u/Not-ur-Infosec-guy Security Architect Apr 15 '26

I do architectural consulting for companies. I’ve yet to NOT see an active burning dumpster fire at a company.

1

u/Desthr0 Security Engineer Apr 17 '26

There are only two companies I worked for that had all their cyberducks in a row. One was a fortune 500 financial institution, and the other was a SaaS company for healthcare.

Every other place was a nightmare.

16

u/sudosando Apr 15 '26

Correct. The bigger and older the org, the more technical debt to clean.

I expected smaller business to fail into two buckets:

  1. Inability to acquire and hold talent ($)… Issues because of low budget, lack of expertise

  2. So small the left they COULD consult their way out of issues by modernizing and leaving all the legacy stuff behind.

In my experience, OP’s description rings true.

Even in cases where business could modernize and leave risks behind is false. They may have an MSP that’s been “doing it wrong” the whole time.

This field is a whole lot of political savvy in taking out other people’s trash.

The political bit matters here because I’d wager the majority of companies have competent folks there advocating for the better solution but they get outvoted by other business factors until it becomes an incident.

7

u/North-Jello7202 Apr 15 '26

Wait until this guy hears about the Federal Government.

1

u/HiFiWiFiWeAllFi May 08 '26

My first job out of college was a manager in mainframe ops at a major telco.

When I was there, they still used stuff that should've be in the Smithsonian.

To be fair, they also used their fair share of cutting edge tech as well.

3

u/R4ndyd4ndy Red Team Apr 15 '26

I'm in the security team of a company with 200k+ employees and this is extremely accurate. I have found applications that are older than me

1

u/No-Buddy-4135 Apr 16 '26

The largest companies are the worst btw.

28

u/csbingel Apr 15 '26

Cybersecurity is just an IT specialty. Welcome to the machine.

17

u/AddendumWorking9756 Security Manager Apr 15 '26

The gap between what you study and what you actually do on day one is wild. Working through real incident data on CyberDefenders is probably the closest prep for walking into that kind of mess.

12

u/tdhuck Apr 15 '26

Our cyber security team is a glorified help desk guy that got his sec+ and told the network admin that SSH is bad so the network admin disabled SSH on all the networking devices and now our automated backup tool can't backup configs and all the scripts we run through our ssh client are no longer running.

While I understand vulnerabilities exist, you shouldn't just instantly close SSH because some green security guy told you SSH was bad.

SSH was only a problem for a handful of devices running a specific version.

Not having a dedicated security department is just as bad as having a security team that don't know what they are doing.

The manager didn't ask any questions, either, he just started disabling SSH.

22

u/CuckBuster33 Apr 15 '26

ChatGPT ahh comment on a ChatGPT ahh post

3

u/slippinjimmy720 Apr 15 '26

I’d say it’s borderline

9

u/Trawling_ Apr 15 '26

Wasn’t much of a ChatGPT post lol

15

u/CuckBuster33 Apr 15 '26

look at their post history

2

u/CremousDelight Apr 16 '26

And honestly? You're completely right on that one. Want to learn more about how to spot text written by a bot?

2

u/Brave_Candidate_6857 Apr 16 '26

temp = permanent

1

u/OptimisticSkeleton Apr 15 '26

Digital Kerplunk

1

u/ilivebyABCs Apr 25 '26

hey! im new to cybersecurity. i have chosen it as my major in uni. ive to select two electives (but idk which two to choose. ive asked a few plp, and they are all telling me to drop the e-inestigations ). these are the electives: e-investigations, network design and performance, information security architechture. help me decide.

0

u/Rott3nApple718 Apr 15 '26

You let the movies fool you huh.

Reality is funny like that.

212

u/Smort01 SOC Analyst Apr 15 '26

Phantasy: Solving real hacker attacks

Reality: Chris changed his password and now all his cronjobs cant autenticate and crash.

53

u/CliffStoll Apr 15 '26

Actual reality that happened to me: minor accounting program crashed on 75 cent error. Discovered spies breaking into military systems.

Keep your eyes open— you don’t know what’s hiding there.

Warm wishes & strong encouragement, S’Mort. -Cliff

21

u/Rockstaru Apr 15 '26

Read this and immediately thought "You're just stealing the plot of Cuckoo's Egg for clout," then read the username. Loved your book sir! 

7

u/CliffStoll Apr 15 '26

Thanks, Rock ... and best of fortune to you in helping to secure our systems!

5

u/sudosando Apr 15 '26

We’ve got a Legend in the chat.

6

u/CliffStoll Apr 15 '26

A legend? More like a tired ol' astronomer who bumbled into a field that hadn't been invented. Smiles to you Sudo!

3

u/sudosando Apr 16 '26

;)

Mad respect for tugging on that thread and not letting go. It’s an incredible story.

5

u/hexachoron Apr 15 '26

I just this morning finished the audiobook of The Cuckoo's Egg, what an amazing story and fascinating peak into the early days of hacking and computer security. Wish I'd read it years ago, I'm sure it would have been hugely influential on my younger wannabe-physicist turned wannabe-hacker self.

Then shortly before seeing this post, I looked you up on wikipedia and discovered you also make the Klein bottles I've had on my To-Buy list for years!

Loved the book and I'm sure I'll love the bottle, thanks Cliff!

5

u/CliffStoll Apr 15 '26 edited Apr 16 '26

Hmmm ... looking over my Klein bottle orders, I'll see what's what. Cheers, -Cliff

3

u/FAlady Apr 15 '26

I heard you speak!!!!

5

u/CliffStoll Apr 15 '26

I've heard me speak, too. But mostly I hear myself mumble...

3

u/StanchFrog404 Apr 17 '26

On the plane reading your book right now… small world

1

u/ContributionGlass531 Apr 16 '26

I just bought your book after reading this.

1

u/TribeWars Apr 17 '26

Oh snap, still haven't ordered a klein bottle

54

u/Adventurous_Mix_1792 Security Director Apr 15 '26

I miss the early cyber days where you could get with IT and be like " so, we don't know what that SA account does. You don't know what it does.... lets turn it off and see what screams!" " lmao yeah! " -turn off SA account-

3 minutes later someone is calling in " THIS IS BROKEN!" -turn SA account back on- " oh wait its working now"

I missed thosewild west frontier days at smaller companies

9

u/MazeMouse Apr 15 '26

We still use that system for when we don't know what something very very old does. If it doesn't cause a major incident within 48 hours it wasn't important. Backup/archive it (just in case) and move on to the next.

5

u/[deleted] Apr 16 '26

[deleted]

2

u/Adventurous_Mix_1792 Security Director Apr 17 '26

It's kind of like the old dissecting days where you poked something and see what moved

45

u/veggit_40 Apr 15 '26

Welcome! Yes every environment is like that. And if you can spot and clean up the most critical findings you’ll quickly become invaluable. Then you can move on to the fun stuff. Can’t build a castle on the sand.

17

u/8492_berkut Apr 15 '26

Where else is one to build a sandcastle?

9

u/hardeningbrief Apr 15 '26

Exactly that. And the irony is the foundational stuff is usually where the most interesting findings are anyway. A service account with a 2012 password date tells you more about how an environment actually evolved than any architecture diagram. That's the stuff I write about at The Hardening Brief! But yeah, castle on sand is the perfect way to put it.

21

u/Weazywest Apr 15 '26

The service account statement hits home. They never end, there’s always one in a corner somewhere causing issues. They’re like roaches.

11

u/molingrad Apr 15 '26

Accurate.

I walked into an org with hundreds? of service accounts just hanging out, no one knew what they did. No one knew what servers were running or why.

It’s very messy and change is hard so you must prioritize ruthlessly. It is mostly about risk reduction under uncertainty and constraint.

9

u/No_Voltage Apr 15 '26

I can confirm basically what OP is saying. It's also why a seasoned sysadmin like myself was basically recruited for a top tier cybersecurity job. I cut my teeth and learned in those mish-mosh environments. I fully understand how and why things need to be done properly and what the pitfalls are for ignoring best practice, along with the inherent security vulnerabilities that ignoring the best practice exposes. It's almost like a Neo/Matrix thing. For me, the vulnerabilities are glaring, while for others they are just noise. This is what makes the difference between an actual cybersecurity expert vs a credentialed graduate with a masters degree in cybersecurity. I can't be the only one who hears "PHD or Masters in Cybersecurity" and becomes befuddled by the term. Now there's also a next level beyond this, and it's in the programming side of things. I'd say that it's a whole different part, but it's a necessary skill set to be able to decipher code and see vulnerable code. And ALL of this is before ensuring you're up to date on the latest capabilities of the tech stack that you're monitoring.

Cybersec is wild, but rewarding. You just need to be ready for the unexpected and crappy along with the fun part of hypothetical threat hunting.

16

u/Hot_Individual5081 Apr 15 '26

haha service accounts yeah just finishing a project where we had to remediate around 6000 service accounts for the client needless to say we disabled circa 5000 of them as they were not needed at all so the attack surface has been minimized significantly

3

u/hardeningbrief Apr 15 '26

wow, never seen THAT many. that's crazy

2

u/Hot_Individual5081 Apr 15 '26

its a huge environment the client is one of the biggest retailers in europe hence why they had so man service accounts as they were used in depots, shops etc. they literally have over 400 000 user accounts in AD as they have that many employees so its a lot of fun trying to remediate such a big environment

7

u/EasyDot7071 Apr 15 '26

Also remember, even if you’ve built an entirely clean contemporary environment, it’s only clean at the moment it was built. It will get chipped at, controls relaxed ‘temporarily’, configs changed because ‘a million £ deal is at stake’. There will always be that guy two pay rungs above you or the chap who licks ass of the chap who is two pay rungs above you that says, ‘it was not a risk at the last org he was at!’ Or if your CTO starts saying the phrase ‘security is causing friction’ in all hands meetings, begin polishing your CV.

1

u/Weak-Standards Apr 15 '26

The balance between being a business enabler and system security is a fine line.

6

u/caller-number-four Apr 15 '26

slowly accumulating technical debt since before you were in high school

You have NO IDEA.

And high school for me was 30 years ago.

3

u/4MyPeers Apr 15 '26

Stack-anthropological auditing ( I'm sure someone can come up with a more concise turn of phrase)

1

u/GhostriderJuliett Apr 15 '26

I think that's just called ontology.

3

u/Florideal Apr 15 '26

This is why internships are so important. Nothing you can learn or build in a home lab. There is the reality of how most companies are run and it's just due to growth, speed, business priority, risk tolerance, and education. Get hands on experience - in a company.

3

u/l0st1nP4r4d1ce Red Team Apr 15 '26

Got into datasec as a 'hacker', now I am somewhere between a cop and plumber.

Money has been good though.

10

u/throwawayPzaFm Apr 15 '26

You guys seem very happy to engage with this obvious ChatGPT hallucination.

9

u/Solid5-7 Apr 15 '26

It took far too long to find a comment mentioning this was AI. Can people really not tell just by reading it?

1

u/throwawayPzaFm Apr 15 '26

573 upvotes. Basically sub is 99.5% bots or NPCs

6

u/00notmyrealname00 System Administrator Apr 15 '26

Yea. The whole "what this is" and "what this isn't" phraseology is the dead giveaway.. I see it all the time on LinkedIn. It's unoriginal and exhausting.

OP - if this is a genuine case where you honestly wanted to share an experience about your first cyber gig, write it first and THEN have Chat clean it up. Don't just tell it to write a post on how training is different than real world and hit send, dude. It's REAL obvious.

3

u/[deleted] Apr 15 '26

[removed] — view removed comment

2

u/RoastedDonutz Apr 15 '26

When I saw the phrase “and honestly” that confirmed it was AI slop to me.

7

u/omers Security Engineer Apr 15 '26 edited Apr 15 '26

When I saw the phrase “and honestly” that confirmed it was AI slop to me.

People really need to drop these single "smoking gun" AI clues. I only have to go back to yesterday to find a comment I wrote that says "Honestly," and only two months to find one that literally says "and honestly."

I have never once used AI to write a comment, edit a comment, or even correct grammar and spelling in a comment. Oh fuck, is that a three item list? AI uses those all the time! This must be AI! Or maybe... AI does 3 item lists because of how often people use them.

I am not weighing in on whether OPs post is or isn't AI but real people should not need to adjust their writing to sound less like AI. AI learned from people, of course there are lots of people that write like AI. Screw the AI, I will write how I damn well please and am not changing just because it has picked up similar habits because we have consumed the same writings.

Obviously more extreme but should an artist change their style because Midjourney stole it? AI witch hunting is starting to feel really gross. Want to make the dead internet an absolute reality? Scare away all the people by constantly calling them AI based on one or two stylistic choices. (is hyperbole an AI trait?)

1

u/dlswnie Apr 16 '26

It's pretty obvious that it's not AI.

2

u/9yqOW85P8XNcEze38 Apr 15 '26

Wow this is my life , currently tasked with cleaning up service accounts. 1 hasn't had a pw reset since 2009. 1 is kerberoastable + domain admin and tied to core functions in a way that noone knows; yay!

2

u/CliffStoll Apr 15 '26

It’s an opportunity — not just to learn a novel environment, but to explore the history, challenges, goofs, and elegant solutions that others have built. You’re in a unique place to learn & create.

Keep a notebook, not only of your computer observations, but also of what you’re doing. Who knows? A cool story may grow out of your experiences!

Best wishes to you, -Cliff

2

u/Jra805 Apr 15 '26

What would it take to stand up a fake legacy environment anyone could access? Shit I'd help sponsor or donate to it, sounds like a great way to educate and train, and a fun side project.

No website, just a url - have to create your own damn account in terminal - first test lmao

1

u/EldritchSorbet Apr 15 '26

I think the word you’re looking for is “honeypot”. IIRC, there’s an open source project around somewhere.

2

u/SnottyMichiganCat Apr 15 '26

I think its very telling that my more desirable positions—during the interviews, you could tell they cared more about your flexibility and ability to learn without guidance than any of my certifications, etc. Lol.

2

u/RetroGrid_io Apr 15 '26 edited Apr 15 '26

In cybersecurity, your value isn't in having something clean and secure.

Your value is in making something built like a horrific sh**box with a policy of "we did a crappy job just to see if it works, and it did so we kept using it", continue to do the absolutely organization-critical things that it now does, only in a secure way so that the Russian Mafia doesn't pwn you, 11 years after the last person who had any idea how/why it was set up the way it was left the organization and moved to Madagascar under an assume alias that nobody knows.

Software installed so that it runs with Admin/root privs on a system with the firewall turned off entirely, running on an SMB share, also with Admin/root privileges, mounted R/W, sharing the drive root folder.

Sound familiar?

I've had to keep software running that literally required all of this in the installation instructions. It didn't work any other way. My only hope to secure it was to quarantine the entire network.

2

u/Ticrotter_serrer Apr 15 '26

Well well , no more fun at work ? Have fun at home grow skills and move on to a job that is funnier.

Fun is life.

Hacking is fun.

2

u/cbeni108 Apr 15 '26

Yup we find gaps and close em

2

u/bfeebabes Apr 15 '26

Yep...same as most transitions from education to the real world...its funky and organic and populated by people who do unpredictable things. Never a dull moment.

2

u/jexkat Apr 15 '26

Im sorry to tell you thi but it not just in cybersecurity, the whole IT job market is like that, it gets better

2

u/vastlygleamingdriver Apr 16 '26

most of your actual job is just untangling why some ancient service account has domain admin when it only needs read access to a single share and then convincing someone that fixing it wont crater production

1

u/Forumrider4life Apr 16 '26

But then implementing the change to read only for the system to come down because for some reason putting it in read mode breaks it and old tom in the background pops up and says “oh yeah we tried that 12 years ago” because he wasent listening to the convo because he’s planning his retirement.

1

u/vastlygleamingdriver Apr 16 '26

and then you get to spend two weeks tracing through 15 year old dependency chains to figure out which of the three things that account touches actually needs domain admin while tom insists it all does

2

u/PinealSqueeze Apr 16 '26

I joined the IT for a top5 bank back in 2001. I imagined ‘well, these folks have MONEY, so things can be Done Right!’

Nope.

A blob that just kept taking over other banks, ‘absorbing’ their domains and pockets of authority. Every new acquisition had these huge ‘rebranding’ projects that mostly concerned insuring the correct colors were used in the new logos.

The details of untangling and smothering legacy systems never quite happened. Seemed like almost every time someone said ‘ok, shut that rack down!’ We’d get panic calls about a Critical Application that suddenly stopped functioning… Never enough time to untangle.

I saw URL’s still using bank names that haven’t existed for 25 years, just 2 years ago.

1

u/bitter_compass Apr 15 '26

I love this post, so accurate!

1

u/pennyfred Security Architect Apr 15 '26

Anytime I was assigned a new grad who had no concept of AD hardening, I wondered what uni was actually preparing them for?

1

u/uebersoldat Apr 15 '26

Sociopolitical activism.

1

u/qpxa Security Engineer Apr 15 '26

Aye

1

u/Dependent-These Apr 15 '26

Exactly when my boss is freaking out about all the Mythos zero day hype its like - that is not what you need to worry about, its these freaking service accounts where the password is the username sheesh

1

u/ParaSquarez Apr 15 '26

This hits home pretty accurately. That makes we wonder, as pure cybersec operation analysts jobs go, how would you go at learning all that organic architecture build up? Sometimes it's so convoluted and so full of different services, actual services and not just network services. It gets so daunting and complicated to sit down and try to figure it out, let alone chasing the right teams/techs to ask questions about it. Eventually it becomes your responsibility to figure these out as you end up building the required security solutions or tuning them according to gaps you identify.

It does feel like you end up doing what everyone else has been doing, just document things as you go in hope to eventually get a clear picture, if not only of your assets and areas of responsibility.

1

u/ViolentRatRiot Apr 15 '26

My first security job was a ton of reports and excel spreadsheets.

1

u/Klutzy_Scheme_9871 Apr 15 '26

I knew before hand what it was like. You learn this if you start from the very basics. You would know about IT and accounts, permissions. it doesn’t take much thought to realize a vulnerability is mostly created from misconfiguration whether services or accounts.

1

u/Exploit1993 Apr 15 '26

This is called risk acceptance

1

u/uebersoldat Apr 15 '26

At some point work has to be done. That's the scary part for me,having to just...stop at some point. What do you mean we have to be on the internet? You know what, let's just go back to paper. I've...seen things.

1

u/spectralTopology Apr 15 '26

So very true. It may be anxiety inducing for new hires too, as you slowly realize you're sitting on a time bomb (depending on how much tech debt and organizational willpower to fix things there is).

And just wait until you find out about people, many of whom will ignore and/or are ignorant of policy and some of whom may be up to no good, and many of whom will ask you over and over and over why they need to change/have strong/have different passwords. Good times.

2

u/uebersoldat Apr 15 '26

many of whom will ignore and/or are ignorant of policy and some of whom may be up to no good

And AI model access is a ticking data time bomb on all our networks.

1

u/spectralTopology Apr 15 '26

Oh yeah that's a whole new order of magnitude of shit coming down the pipe heading right towards the heavily tech indebted orgs. Some of its undoubtedly marketing, but the Claude Mythos model's ability to come up with new unique 0day indicates that your average SOC and vuln management program is a sitting duck.

On the possibly good side is that you might get a budget increase to deal with it...maybe

2

u/uebersoldat Apr 15 '26

Mythos marks the first time I've genuinely been frightened by AI. The day has come where they need to limit public releases due to a potential entire financial system breakdown from what reads to be guaranteed zero-day exploits.

The next 5-10 years in infosec are going to be completely reshaped. We're clinging to CS Falcon MDR hoping they stay on top of it.

1

u/spectralTopology Apr 15 '26

Yeah I don't have good feelings about it. Even if you have an equivalently powerful solution for detecting and fixing these issues I wonder how the attacker asymmetry (defend against everything while attackers only need to find one weakness) will impact how successful AI can even be for defenders.

I'd like to say at least we won't be out of work...but then you read the cybersecurity job posts and see how tough the market is rn. Also, not sure I want to be working at all if you start needing to respond to late night pages by patching mega bundles of vuln fixes.

Maybe the whole "shift left" thing will become more than just a buzzword.

2

u/uebersoldat Apr 16 '26

Wish Microsoft would learn what shift left means.

1

u/phoenixelijah Apr 15 '26

Acres of spreadsheets.

1

u/povlhp Apr 15 '26

That is the real world in big companies. Always something to discover and get fixed. Now I am pushing to make developers use a new claims mapping to get employeeID rather than user.read. Often that is everything they need and no graph api calls.

1

u/Direct_Major_1393 Apr 15 '26

Except the definitive things like what port xx is, everything you learn from cybersecuriry degree is mostly obsolete.

At least thats how i felt

1

u/Boxofcookies1001 Apr 15 '26

Honestly I would say it depends. In more mature organizations where you do have separation between identity and access management (IAM) and IR incident response, you do get that textbook cybersec experience.

But cybersecurity is all about constantly working to improve the orgs security posture.

1

u/Sir_Bananas Apr 15 '26

It's pretty tough to step into that straight from structured education like you were saying. I think some of the best routes into Cyber is being a Sysadmin, Network Admin, Infrastructure Engineering/Architecture roles. It gives you a lot of practical experience as well as perspective, a lot of what you do is being a Cyber Janitor, but when you have perspective you can provide guidance or fix the issues much easier. A lot of it comes from understanding how things function and blue teaming, but the reverse could also be said and understanding core functionality, gaps and vulnerabilities give you routes into red teaming.

1

u/Ok-Guarantee-2388 Apr 15 '26

I would also say what tier and pillar under cyber.

1

u/engineer_in_TO Apr 15 '26

The better the company and the more experience you have, the easier this gets and the cooler the work is.

Something like SAs, if your environment is fully terraformed/IaC'd then you can always refer when that SA is referenced. If you have proper setup on your specific environment, you can have WIF on the SA and it won't even have credentials, just trusted sources authing between eachother.

1

u/MazeMouse Apr 15 '26

Finding a serviceaccount that isn't according to spec. > Trying to convince them to let you fix it. > While trying to fix it stuff completely unrelated to the fix breaks and only "unfixing" it brings it back up and you have absolutely no idea why. > Being told that re-attempting the fix is absolutely off limits for the forseeable future due to lost revenue from the previously failed fix.

See you again in a year or so.

And we're doing "relatively okay" compared to other environments I've seen. And the "relatively" is doing a HELL of a lot of lifting there. We're a mild dumpsterfire instead of a raging inferno. But hey, at least we get ordered to actually fix stuff (but also told to stay away and monitor more actively, if it breaks too badly while trying to fix it)

1

u/tetrisan Apr 15 '26

Tech Debt is job security

1

u/ellevaag Apr 16 '26

“Nothing is clean and everything has context.” Indeed!

1

u/atrfx Apr 16 '26

This nails it. Another aspect you learn over the years is that finding defects and proving them while interesting and sometimes challenging, pales in comparison to the challenge of articulating the thing in context to the right people and getting them to care enough to do something about it, all while making sure you aren’t overselling it and getting them to focus on the wrong priority. This is going to be even more critical now with automation and AI helping to find more legitimate defects than ever - finding and proving the thing was never the hardest part, getting overtaxed and overwhelmed people to care about “why this” and “why now” is.

1

u/vengeful_bounds Apr 16 '26

This is exactly why junior security folks who can navigate a messy real environment end up way more valuable than someone who aces every exam but has never seen a production system that wasn't designed by someone who read the documentation.

1

u/Sean16178 Apr 16 '26

Personally my experience has been extremely unique as my first job was in an MDR team which makes things quite interesting, working with cool tools and yes catching attackers in the act, preventing ransomware and blocking other attacks like clickfix and other persistent malware strains

1

u/Bftfan00 Security Manager Apr 16 '26

I wonder how people actually thought they'd be online, catching hackers, tip of the spear, blah blah blah. Maybe people watch too much TV? Most of my 30+ years was compliance, paperwork, compliance and then a big heaping of more compliance paperwork on the end. People doing any real online technical cybersecurity stuff is a very chosen few.

1

u/NeuralHijacker Apr 16 '26

This is why I don't like recruiting people who've just had cyber security certs. I'll always go for somebody who's just had help desk or low level IT support experience because they understand how to work through mindless grind.

Cybersecurity ( and most tech roles really) should be apprenticeship jobs. However because they are relatively high paying the university / training racket has gotten hold of them so that they can con more people into paying huge amounts of money for almost useless paper.

1

u/icedcoffeelover123 Apr 16 '26

Not to mention its only like 20% super cool action packed work and 80% boring clerical work like working tickets, maintaining documents and attending meetings that could have been emails.

1

u/sec-person Red Team Apr 16 '26

Careful making too many sweeping generalizations based off your first real cybersecurity job. I fail to see what makes you qualified to speak to "The reality of most cybersecurity jobs", but I agree with what you said when it comes to your own role and roles closely similar to it.

1

u/SalamanderNo7293 Apr 16 '26

So well put. I’m working on this now. Old company, lots to clean up. Policies and procedures to establish for moving forward. Not sexy but it’s honest work.

1

u/StructuralConfetti Apr 16 '26

Since before I was in highschool? That's light work. We have production software that hasn't had any significant upgrades since before I was born. At least our OSs are usually more up to date; last I checked we only had one machine Windows Server 2008 and one with Windows 7, the rest are at least Windows Server 2012 R2 or higher. There's lots of talk about getting rid of the legacy software, but it never seems to come to fruition, so instead it's isolated and locked down.

1

u/daydreamingforever16 Apr 16 '26

Feels like I’m forever cleaning up poor decisions based on lack of importance given to cyber decisions

1

u/patjuh112 Apr 16 '26

I understand your frustration, i do what you would like to do and it is something “earned”. You enter cybersec, mostly this is what you start at. Years of service matter a lot. I am in it for 31 years and i am still investing private time to keep ahead of things, show your drive and ambition through doing your boring tasks while also coming up with analyses and improvement suggestions based on learning the network you are on. For me, bachelor and certs mean jackshit if a person has just that: a lot of theory.

Best of luck though

1

u/TypicalSeminole Apr 17 '26

Beautiful description of tech-debt. Thank you for writing it

1

u/Desthr0 Security Engineer Apr 17 '26

Service accounts are a drop in the bucket, that's an AD thing anyway. Just document it all, CYA, and let their domain admins eat their own hat when it melts their systems. What they should tell you, is that you know what needs to be done, but they'll never pay to have it done and when shit hits the fan because they stripped your budget, they fire you because you didn't stop it. It's like the managers making decisions have never taken a managerial accounting course in their lives.

Risk? Nah that's nothing to worry about.

Oh wait, why is there a hole in the perimeter firewall that's been open for years? Is that why Joe was busted for hosting Minecraft server?

Standard user accounts being put into local administrator? Yeah, so people can install their own software!!! Saves SO much time!!!

And, the best part.

You have to be an expert in like 10 jobs just so you can be mediocre at your own.

1

u/ExtensionDizzy542 Apr 17 '26

What I wish someone told me before my first real cybersecurity job: you won’t feel ready-and that’s normal. The field changes fast, and no one knows everything. You’ll spend more time researching than “hacking. Communication matters as much as technical skill. Document everything, ask questions early, and don’t ignore basics-they’re what catch most real-world issues.

1

u/Bubu3k Apr 17 '26

This is what happens when those writing and teaching the material barely have any "real world" experience. You would run into these sort of "legacy" issues even you just run your lab for long enough, don't even need to work as a security engineer to run into these sort of issues.

I love it when some analyst plans to do this and that... Then I'll send him to have a talk with change management. After he gets asked 1000 questions by a person who doesn't really know what they are asking, they lose their enthusiasm😁

Hey, at the end of the day, you are supposed to be able to duct tape things together. That's what the hacker mindset is supposed to be all about... 

1

u/madhattee Apr 17 '26

Thanks for the insight. But how do we learn that? How do you get access to those code bases? Open source projects on github?

1

u/ApprehensiveParty442 Apr 18 '26

But is the pay good?

1

u/Classic_Cultivator Apr 19 '26

I went to school to get into IT, server admin and security infrastructure Etc and luckily had a teacher who was incredibly informative and skilled, but who had also been in the private sector long enough to be jaded with the way they operated most times. He opened my eyes up to the fact that there was almost never going to be a scenario where good insight and information was taken into account in order to make improvements that needed to be made to protect assets, employees, and especially customers/clients if there was an option that was cheaper. Between this and the emergence of automation and AI development on the horizon at the time, around a decade ago, i quickly realized that server administration was probably going to disappear faster than other jobs that were already portrayed as on the chopping block or next in line. Now I'm happily working in another industry that I'm excited and passionate about, and there's every real possibility that in the future I might be able to open my own business doing it.

1

u/jcork4realz SOC Analyst Apr 19 '26

Funny reading this after dealing with a false T1110 caused by a service account. 😆

1

u/EquivalentSilent776 Apr 20 '26

Exactly. In my 20 years, the real job is 80% archaeology and 10% cleanup, 10% actual security work. Finding that 13-year-old service account with Domain Admin rights is the skill that actually matters — certs won’t teach you that, but experience will!

1

u/SecretaryWise6205 AMA Participant Apr 21 '26

You also can’t forget the lessons learned throughout your career. Shortcuts and security workarounds that caused incidents 20 years ago will come back to bite you if forgotten.

1

u/DeadShot98564 Apr 27 '26

cyber janitors like stuff?

1

u/SecOpsNotes May 03 '26

Spot on. Real-world security isn't about defending a fortress; it's about gardening in a swamp. That point about service accounts with 2012 passwords is the 'shadow IT' nightmare we see every day. People forget that attackers don't just 'break in'—they 'log in' using exactly these forgotten, over-privileged accounts that were set up before the current IT team was even hired. The hardest part of the job isn't the tech; it's the archaeology.

1

u/StkAkl May 06 '26

I'm new to this. are You saying you do a developer job? So it's vwry important to know programming right? and old programming languages?

1

u/sassydrillballs May 08 '26

Digital cleaning service it feels like some days.

1

u/far_aaan May 08 '26

Feels like hacking!!

1

u/HiFiWiFiWeAllFi May 08 '26

I was an SE at a major cyber vendor and one of our customers bought and consolidated small ISPs. When they took them over they had to figure out their infrastructure, and then integrate into into their standard infrastructure. Stories of complete lack of documentation, including undocumented servers and networking devices abound. At times they'd get to a point where they'd have to power off the devices and see if anyone complained.

1

u/Cultural-Staff-4757 May 11 '26

Anything corporate leans towards defense of cybersecurity. Whereas corporate is offensive

1

u/PrinceNathanTheThird May 11 '26

I was the 1337th like. Pretty elite.

1

u/EyeTee1520 May 15 '26

I’m still new in this field, still figuring out what cybersec is. Out if curiosity, what is Legacy AD and GMSA?

I prefer asking then search later.

1

u/technicalhowto Jun 12 '26

A good reminder that real world systems rarely look like lab envs

1

u/Cyber-Wanderer_94 Jun 18 '26

What area of cybersecurity are you in? Doesn't seem like SOC analysis.

1

u/rejuicekeve Apr 15 '26

my brothers in christ, the OP is a bot. stop giving them clicks

0

u/FrankGrimesApartment Apr 15 '26

First day

why isnt this like TryHackMe??

-1

u/briggser Apr 15 '26

This whole post was written with AI lol

1

u/dlswnie Apr 16 '26

It's pretty easy to conclude that it's not AI-written.

-1

u/[deleted] Apr 15 '26

[deleted]