Welcome to the SecRoles Blog
This is the first post on the SecRoles blog. Going forward, this is where I'll share what I'm seeing across the cybersecurity job market - what roles are growing, where companies are hiring, what skills hiring managers actually look for, and how to navigate a job search without losing your mind.
What to expect
A few things you'll find here:
- Market data. What's happening in pentesting, GRC, cloud security, AppSec, detection engineering, and the rest of the field.
- Practical guides. How to read a job description, how to negotiate, how to break in without three years of experience for an "entry-level" role.
- Behind the scenes. How SecRoles is built and what I'm learning while building it.
Why a blog?
Most cybersecurity job advice online is either generic ("get certs!") or written by people who haven't hired in years. I talk to candidates and hiring managers almost every week. The goal is to write the things I keep telling people one-on-one, but in public, so the next person searching at 1am can find them.
If there's a topic you'd like me to cover, send a note to hello@secroles.com.