Hands typing on a laptop with cybersecurity graphics

How I Actually Got Into Cybersecurity (No Perfect Plan)

·

·

How to Get in Cyber Security: Beginner's Career Guide

I didn’t start in cybersecurity.

I started as a software engineer.

I was writing code for about 2 years, and at the time, I thought that was the path. Keep getting better, maybe aim for bigger tech companies.

But around that time, I kept hearing more about security.

Data breaches. Compliance. Systems are getting locked down.

And I realized something simple:

Security touches everything.

So I wanted to understand that side of the world.


Why I Moved Toward DoD

This was around the time when layoffs were happening everywhere.

Tech didn’t feel as stable anymore.

And I started thinking long-term.

FAANG sounded great… but also unpredictable.

DoD, on the other hand, felt different.

More structured.
More stable.
And honestly… less hype, more consistency.

So I made a move.

I got a role as a System Engineer in the DoD space.

That decision changed everything.


The Moment It Clicked

After about a year in that role, I started noticing something.

Every system we worked on had to be compliant.

Not optional.

Required.

And behind that compliance… were people managing it.

ISSOs.

At first, I didn’t fully understand what they did.

But the more I looked into it, the more it made sense:

  • They were involved in everything
  • They understood the system at a deeper level
  • They had real influence on whether a system could go live

That’s when I started digging into the compliance (GRC) path.


What I Did Next (This Part Matters)

I didn’t just “hope” to transition.

I made it obvious.

First, I got Security+.

In the DoD world, this isn’t optional.

You literally can’t touch most systems without it.

That certification alone opened the door.

Then I went further and got CASP+.

At the same time, I had conversations with my manager.

Not vague ones.

Direct ones.

“I want to move into cybersecurity. What do I need to do to get there?”

That part is important.

Most people wait for opportunities.

I asked for one.


My First ISSO Role

Eventually, an internal opportunity came up.

I moved into an ISSO role.

And I’ll be honest…

That’s where I actually learned cybersecurity.

Not from certs.
Not from YouTube.

From doing the work:

  • tracking controls
  • chasing artifacts
  • working through eMASS
  • dealing with ATO pressure

I did that for about 2 years.


Where I Am Now

After building that experience, I moved to another company.

Now I’m leading full ATO packages.

Something I didn’t even fully understand when I first started.

That progression didn’t come from being the smartest person.

It came from:

  • being in the right environment
  • asking questions
  • and taking opportunities when they showed up

Where This Path Leads (What You Can Choose)

At this point, there are two main directions I can go:

1. ISSE (More Technical)

  • deeper system understanding
  • working closely with engineers
  • more hands-on security

2. ISSM (More Leadership)

  • managing teams
  • owning multiple systems
  • more strategy and decision-making

Neither is “better.”

It just depends on what you want.

If you like technical work → go ISSE
If you like leadership and bigger-picture decisions → go ISSM


The Real Takeaway

If you look at my path…

It wasn’t planned perfectly.

I didn’t start in cyber.
I didn’t know everything.

I just:

  • followed what made sense
  • positioned myself in the right environment
  • and moved when opportunities came up

That’s it.

Pro Tools for Working ISSOs

Working a real ATO package right now?

Skip the spreadsheet rebuild. These are the exact tools I use in the field as an active DoD ISSO.


Get the free RMF Quick Reference

All 7 RMF steps on one page — free when you subscribe to the weekly ISSO Insider.

One response

  1. What RMF actually is – RMFInsider

    […] If you want to move into this career → read “How I Got Into Cybersecurity” […]

Leave a Reply

Discover more from RMFInsider

Subscribe now to keep reading and get access to the full archive.

Continue reading