
I didn’t start in cybersecurity.
I started as a software engineer.
I was writing code for about 2 years, and at the time, I thought that was the path. Keep getting better, maybe aim for bigger tech companies.
But around that time, I kept hearing more about security.
Data breaches. Compliance. Systems are getting locked down.
And I realized something simple:
Security touches everything.
So I wanted to understand that side of the world.
Why I Moved Toward DoD
This was around the time when layoffs were happening everywhere.
Tech didn’t feel as stable anymore.
And I started thinking long-term.
FAANG sounded great… but also unpredictable.
DoD, on the other hand, felt different.
More structured.
More stable.
And honestly… less hype, more consistency.
So I made a move.
I got a role as a System Engineer in the DoD space.
That decision changed everything.
The Moment It Clicked
After about a year in that role, I started noticing something.
Every system we worked on had to be compliant.
Not optional.
Required.
And behind that compliance… were people managing it.
ISSOs.
At first, I didn’t fully understand what they did.
But the more I looked into it, the more it made sense:
- They were involved in everything
- They understood the system at a deeper level
- They had real influence on whether a system could go live
That’s when I started digging into the compliance (GRC) path.
What I Did Next (This Part Matters)
I didn’t just “hope” to transition.
I made it obvious.
First, I got Security+.
In the DoD world, this isn’t optional.
You literally can’t touch most systems without it.
That certification alone opened the door.
Then I went further and got CASP+.
At the same time, I had conversations with my manager.
Not vague ones.
Direct ones.
“I want to move into cybersecurity. What do I need to do to get there?”
That part is important.
Most people wait for opportunities.
I asked for one.
My First ISSO Role
Eventually, an internal opportunity came up.
I moved into an ISSO role.
And I’ll be honest…
That’s where I actually learned cybersecurity.
Not from certs.
Not from YouTube.
From doing the work:
- tracking controls
- chasing artifacts
- working through eMASS
- dealing with ATO pressure
I did that for about 2 years.
Where I Am Now
After building that experience, I moved to another company.
Now I’m leading full ATO packages.
Something I didn’t even fully understand when I first started.
That progression didn’t come from being the smartest person.
It came from:
- being in the right environment
- asking questions
- and taking opportunities when they showed up
Where This Path Leads (What You Can Choose)
At this point, there are two main directions I can go:
1. ISSE (More Technical)
- deeper system understanding
- working closely with engineers
- more hands-on security
2. ISSM (More Leadership)
- managing teams
- owning multiple systems
- more strategy and decision-making
Neither is “better.”
It just depends on what you want.
If you like technical work → go ISSE
If you like leadership and bigger-picture decisions → go ISSM
The Real Takeaway
If you look at my path…
It wasn’t planned perfectly.
I didn’t start in cyber.
I didn’t know everything.
I just:
- followed what made sense
- positioned myself in the right environment
- and moved when opportunities came up
That’s it.

Leave a Reply