When I got my first job in cybersecurity, it was not because anyone thought I was a security person.
A cyber threat team at Citi needed somebody who could take what the analysts were finding and turn it into something an executive would actually read. I knew a little about security and a lot about explaining things. That was the whole of the job. Nobody wrote that hire up as an innovation, and if you had asked the people who made it, I doubt they would have called it anything more than solving a Tuesday problem. Everything I have done since runs back through that room.
In the first issue of this series, I described the chair almost everyone in this field learned in. The queue, the alerts that were nothing, the occasional one that was something, the senior analyst who walked you through what you had missed. I ended that issue by telling you there were many doors into this field, including the strange one I came through.
So here is the admission that story needs: I never sat in that chair.
I came in through a side door, and then I spent years on the other side of the table hiring people who had. Which is a strange vantage point, and it is the reason I want to talk about doors before we talk about what is happening to them.
The Man Who Did Not Exist
In March 2021, I wrote a piece on this newsletter called The Myth of the Cybersecurity Archetype. It was about a man named Chad.
Some people think all cybersecurity professionals are a guy named Chad, who got a degree in electrical engineering from Stanford. He worked as a systems administrator for a couple years, then as a network engineer for a few more, before becoming a SOC analyst.
Chad was not real. He was the composite in everyone’s head, and his job was to make good people decide not to apply. Against him I set three others: Luis, a lawyer who worked out after law school that he did not much like being a litigator. Samantha, a high school graduate who was seriously into technology. And Oti, who studied international affairs before finding out cybersecurity was a career you could have.
I should probably admit that Oti was me. I put myself in that post five years ago and did not mention it, which at the time felt like modesty and now mostly looks like a missed opportunity.
Many Doors, One Floor
The doors were real, and I have watched people come through all of them. The veteran whose service built an instinct no course teaches. The lawyer who does not need to know how a network works, only enough to follow what happened and find where the exposure sits. The person moving across from IT or audit who already understands how the business makes its money. The career-changer at thirty-eight.
Two of those are mine. I was thirty-eight, and the reason anybody read my résumé at all was a man I barely knew from another part of the bank—a former Marine Corps intelligence officer who sent an email on my behalf because of where I had been in Afghanistan.
This is not folklore. In ISACA’s 2025 survey of more than 3,800 security professionals, 46% said that half or more of their cybersecurity staff had started their careers in a different field entirely. Close to half of this profession is made of people who used to do something else.
Here is the part I did not see for a long time, and it is the reason this issue exists. Those doors did not all lead to the same room. They led to the same floor.
If you have not seen it, Henry Jiang’s Map of Cybersecurity Domains lays this field out on one page: security architecture, security operations, governance, risk assessment, threat intelligence, application security, enterprise risk, physical security. It is the best ten minutes you can spend, if you are trying to work out where you might fit.
Now pick almost any branch of it. At the bottom of each one sat a job made mostly of repetition.
In security operations, it was the alert queue, which is the version everybody pictures. In vulnerability management, it was working a scanner’s output, tracking down whoever owned the server, and scanning again to find out whether anyone had actually fixed anything. In identity, it was access reviews—thousands of rows of who can reach what, asking managers to confirm things they would rather not think about. In governance, it was evidence collection—gathering the screenshots and records that prove a control does what the policy says it does. In third-party risk, it was vendor questionnaires—hundreds of them. In application security, it was triaging scanner findings, most of which were false positives.
None of it was glamorous. All of it was necessary. And every one of those jobs taught the person doing it something that could not be learned any faster.
The queue taught you what normal looks like on your own network. Vulnerability management taught you how the business actually runs, who owns what, and why an obvious fix can sit untouched for a year. Access reviews taught you how privilege accumulates, when nobody is watching. Evidence collection taught you the difference between a control that exists and a control that works. Questionnaires taught you to read a company’s security posture through what it declines to say.
That is the floor. Different rooms, different vocabulary, one shape underneath: high-volume, low-authority work, done in a building full of people better at it than you were, until one day you were one of them. The alert queue is only its most legible version, which is why it is the one I reached for first. It was never the only one.
Which is how I can tell you I never sat in that chair and still say I came up the way you did. I sat on the floor of a cyber threat management team. My high-volume, low-authority work was turning other people’s findings into language an executive could act on. I did a great deal of it, badly at first, next to people who were very good at the thing I was describing. Same machine, different room.
So the field was wide open at the entrance, but remarkably uniform once you stepped inside. Many doors, one ground floor. The doors were the different paths people took to arrive, but that shared floor was where everyone actually started.
The ground floor paid for our openness, and the field took credit for an inclusive policy it never actually had to design.
The Door Was Wide Because the Floor Was Vast
We told ourselves a flattering story about this, and I told it too. We said the field was open because it was young, because it was meritocratic, because we knew that people who think alike miss things together. Some of that was true. It was not the mechanism.
Start with the simplest fact about this field, and it is easy to miss because it is an absence: in the United States, security has never been a licensed profession. Nothing stands at the door: no exam that decides whether you may do this work, no board that decides you are ready, nothing but the judgment of whoever is hiring. What we had instead was the floor. The field let people in and found out about them afterwards. A filter that runs after you arrive leaves the front of the building open.
The rest of the mechanism was that the ground floor was enormous. There were more entry seats than there were obvious candidates to fill them, so a hiring manager with ten of them could afford to spend two on people who did not look the part. That is not generosity. That is arithmetic. The ground floor paid for our openness, and the field took credit for an inclusive policy it never actually had to design. Which tells you what happens when the arithmetic changes.
What Happens When There Are Two Seats Instead of Ten
The work is still arriving. ISACA’s 2025 survey found 47% of security professionals now help build AI governance, up from 35% the year before, and 40% are pulled into AI implementation, up from 29%. That is a new responsibility, measured, inside twelve months.
The teams are not keeping pace with it. In the IANS 2025 benchmark of 587 security chiefs, 47% reported flat team sizes, and security fell from 11.9% to 10.9% of what companies spend on technology. Not collapsing. Flat, while the job gets bigger.
The door narrows when every hire has to be safe.
Now put yourself in the chair I sat in for years. You have two junior openings instead of ten. Each one is now a larger share of everything you have. The interesting résumé—the one from the person who has never done this, but you suspect could—is a bet. With ten seats you could carry two bets. With two, you cannot carry any.
Chad comes back, and he comes back as prudence.
The door narrows when every hire has to be safe. Not because anyone became prejudiced, but because each decision started carrying more weight, and weight makes people careful. Chad comes back, and he comes back as prudence. This is not confined to the noisiest floor. The same wave is arriving on all of them.
You can already see it in the one place it would show up first. Between ISACA’s 2024 and 2025 surveys, the share of companies training their own non-security staff into security roles fell from 41% to 29%. That is the internal transfer—the door I have spent a career telling people to walk through—closing by nearly a third inside a year while nobody announced it. Open entry-level roles held steady across the same period. The work at the bottom is being hollowed, not eliminated. This is a narrowing, not a collapse, which is precisely why it is worth naming now rather than afterwards.
I want to be careful here. That drop sits next to the arrival of capable AI tooling, and sitting next to something is not the same as being caused by it. I cannot prove the connection and I am not going to pretend otherwise.
The Case Against Everything I Just Said
There is an honest argument that runs the other way, and I would rather put it in front of you than have you find it later.
If software absorbs the technical grind, then the technical background matters less, and this field should get more open, not less. The person who understands the business, who writes clearly, who can sit with ambiguity, has never been better positioned. On that reading, the doors widen.
I think both things are happening at once. The skills barrier is coming down while the seats get scarcer. Which force wins is genuinely not settled, and anybody who tells you they know is guessing.
Two Ways to Read This
If you are standing outside trying to get in: your unusual background was never the problem, and it still is not. What is changing is not the field’s appetite for people like you. It is the number of places where a bet on you is cheap enough to make. That is a harder problem than prejudice, and it is also not about you.
If you want to keep it, you are about to have to choose it on purpose for the first time, and pay for it, in a year when everything else is being asked to justify itself.
If you run a team: the variety you are proud of was bought by a ground floor you are now automating. It was never a policy. If you want to keep it, you are about to have to choose it on purpose for the first time, and pay for it, in a year when everything else is being asked to justify itself. That is the honest state of the door.
Which brings me to something I owe to this list. Five years ago, I sat down and told you cybersecurity was a future-proof career, and I told you how to outrun automation by coming here. Those posts are still up. Next time, I am going to account for them.
— Oritse
