The parts of this industry nobody tells you.
Two collections, one publication. Career Perspectives for the people building careers. Hiring Perspectives for the people trying to fill roles. Each group leads with a verdict. The essays underneath show the working.
For people building careers.
Certifications, roles, career change, and where the industry is heading. Written for the person trying to make the next move without burning eighteen months on the wrong one.
Most certs do less than they're sold to do, and more than the anti-cert camp will admit. The trick is knowing which one signals what, to whom, at what stage.
- Certifications 9 min
Certifications don't prove competence. They prove direction
The pro-cert and anti-cert camps are both wrong. Certs still matter, but only when you understand what they actually signal in 2026.
Read the full essay - Certifications 9 min
Why Security+ is simultaneously overrated and useful
It will not get you a security job. It will get you past an HR filter. Those are different problems.
Read the full essay - Certifications 8 min
Is CISSP actually worth it in 2026?
Yes, but only for a specific person at a specific moment. For everyone else it's 12–18 months optimising for the wrong thing.
Read the full essay - Certifications 9 min
I passed CISSP and nothing happened, and that's fine
The six-month silence after passing is the cert doing exactly what it's supposed to, on a slower clock than LinkedIn implies. Here's when 'nothing happened' is normal, and when it's the market telling you something useful.
Read the full essay - Certifications 9 min
When everyone passes, nobody differentiates
Exam dumps aren't mainly an ethics problem. They're a signal erosion problem. And that hurts honest candidates too.
Read the full essay
The job description is the brochure. These essays are the job. Read before you commit eighteen months to the wrong one.
- Roles 9 min
Why most people fail trying to leave helpdesk
It's almost never a skills problem. It's a positioning problem, a portfolio problem, and a willingness-to-be-uncomfortable problem, in that order.
Read the full essay - Roles 10 min
The realistic SOC analyst path
Most guides describe the job a SOC analyst wishes they had. Here's the one they actually do.
Read the full essay - Domains 9 min
Why security architects are always the bad guys
We're not blocking your project. We're the last function in the room, asked to underwrite promises we were never invited to help shape.
Read the full essay
Switching into tech in your thirties isn't an age problem. It's a compression problem, an interview problem, and a second-beginner problem. Most advice skips all three.
- Pathways 10 min
The second beginner problem
People who change careers in their mid-thirties become beginners twice. The first time, the world is set up for it. The second time, almost nothing is.
Read the full essay - Pathways 9 min
The problem isn't age. It's expectation compression
Career changers don't fail because they're too old. They fail because they try to compress a six-year arc into eighteen months, and quit when the compression doesn't hold.
Read the full essay - Pathways 10 min
Why most career-change advice breaks at the first interview
Most career-change content is written for the spreadsheet stage, not the interview. The interview tests two things the advice never names, and that's where the plan tends to fail.
Read the full essay
AI isn't deleting IT. It is hollowing out specific roles and quietly decommissioning the apprenticeship that produced the next generation of seniors. Plan around the narrower claim, not the headline.
- Domains 9 min
AI will not delete IT, but it will shrink one kind of IT role
The 'AI replaces all of IT' narrative is wrong. The narrower version is mostly right, and worth planning around.
Read the full essay - Domains 10 min
What AI actually does to pentesting
AI won't kill offensive security. It will hollow out the middle of it, and quietly decommission the apprenticeship that produced the next generation of seniors.
Read the full essay
For recruiters, hiring managers and talent teams.
Why technical roles stay open, and what the market actually does behind the polite language of job specs. Same publication, same voice, different audience.
A series for recruiters and hiring managers. Most long-open technical roles aren't failing because the market is empty. They're failing in one of seven specific, repeatable ways. Each essay names the pathology, how it appears, and what changes the call.
- Hiring 8 min
Wrong Pool. Why Cloud Security roles stay open despite strong candidate supply
Part 1 of seven. Most long-open Cloud Security briefs aren't failing because the market is empty. They're failing because the JD has quietly defined a candidate who doesn't exist, and rejects the ones who'd actually be productive.
Read the full essay - HiringIn progress
Invisible Feeders. Why the best IAM candidates rarely have IAM in their job title
Part 2 of seven. The strongest IAM hires are sitting in platform, infra and identity-adjacent roles whose titles don't contain the word identity. Search by title and you miss them by design.
- HiringIn progress
Tool Fetishism. When platform hiring mistakes tooling familiarity for engineering capability
Part 3 of seven. Filtering for Terraform plus Argo plus Backstage plus a specific service mesh stops being a skills filter and becomes a brand filter. The candidates who pass the brand filter aren't always the ones who can build the platform.
- HiringIn progress
Architecture Inflation. How Security Architect roles quietly become leadership positions
Part 4 of seven. The title says architect. The responsibilities describe a head of function. Senior candidates read the gap from the JD and withdraw by round two, and the brief blames the market.
- HiringIn progress
SIEM Badge Syndrome. Why Detection Engineer searches collapse when platforms become proxies for skill
Part 5 of seven. Asking for three named SIEMs feels like a capability filter. It's actually a platform-tenure filter, and the engineers who think like detectors have gone deep on one platform, not wide across three.
- HiringIn progress
Responsibility Dumping. When DevSecOps becomes a workaround for organisational ownership problems
Part 6 of seven. Some DevSecOps roles exist because no one will own the security debt. The hire is being asked to paper over an org-chart problem, and the strongest candidates can smell it in round one.
- HiringIn progress
Leadership Paradox. Why Security Manager briefs often exclude both managers and engineers
Part 7 of seven. The JD asks for a manager who's still hands-on at IC depth. Each half of the pool reads itself out, and the search ends up filtering for the candidate who's least sure which job they're doing.
Market behaviours everyone argues about and nobody quite frames honestly. Double dipping, signalling, availability, the contractor premium. Written to be disagreed with, by contractors and hiring managers in roughly equal measure.
Essays that don't sit cleanly under one lens. Still worth reading.
- Pathways 9 min
Is a computer science degree worth it in the UK?
For a specific route, yes, and it's still one of the best bets going. For most people asking the question, no. Here's the tradeoff nobody selling either route wants to put this cleanly.
Read the full essay - Pathways 10 min
When you can't earn experience, cert stacking becomes the trap
If your current role won't let you touch the work you're trying to move into, stacking certs feels like the only lever. Past the second one, you stop buying progress and start buying the appearance of it.
Read the full essay - Roles 9 min
Why most people should start in IT support
Not because it's prestigious. Because it installs the operational instincts every later role quietly assumes you already have, and skipping it is what makes year two so painful.
Read the full essay - Roles 10 min
The cloud engineer myth
"Cloud engineer" is not the entry-level job the bootcamps pretend. The role advertised under that title in 2026 is a mid-level infra engineer with cloud on top, and the cert-stack candidates aren't being rejected for missing a cert.
Read the full essay - Domains 10 min
The real bottleneck in cybersecurity careers
It isn't certs and it isn't labs. It's operational time on systems other people depend on. Until you've had that, you're stuck below a ceiling no exam or home lab can lift you over.
Read the full essay - Domains 10 min
Why networking is still underrated
Less crowded than cloud or security, hiring at the junior level when most adjacent fields aren't, and the sleeper feeder route for the higher-paid disciplines five years later. Going out of fashion is precisely why it's a good bet.
Read the full essay - Roles 11 min
What a Tier 2 SOC analyst actually does at 2am
Mostly judgment under uncertainty, with imperfect tools, on systems you don't fully own, while three people who shouldn't be in the call are in the call. That's the job. The training material describes a different one.
Read the full essay - Domains 10 min
Most people should not target offensive security first
The offensive-first route is presented as a default and behaves like a low-probability bet. The pentesters doing work clients actually pay full rate for came up through defensive and infra. The detour is faster than the direct route.
Read the full essay - Hiring 10 min
When changing careers into tech is a bad call
Most career-change content assumes the move is correct and only argues about route. The assumption is wrong often enough to matter. Four situations where moving into tech in 2026 is the wrong call, three of which are common.
Read the full essay - Roles 9 min
The GRC timing trap
GRC is one of the best mid-to-late-career destinations in security and one of the worst early-career landings. The trap isn't the work. It's that GRC pulled too early severs you from the credibility GRC actually runs on, silently.
Read the full essay - Roles 9 min
The mid-career architect trap
Taking an architect title at a firm that doesn't actually run architecture as a discipline is one of the cleanest-looking moves available and one of the hardest to undo. The pay rise is now. The empty CV is year nine.
Read the full essay - Hiring 9 min
Ten years in, the things that actually compounded
The certs, the talks, the framework adoption everyone fussed over for six weeks. Most of it went flat. What compounded was operational scars, written documents, and a small number of strong relationships. The boring list.
Read the full essay - Certifications 7 min
The certification didn't get you into cyber, the signal did
The cyber or GRC cert changes your position in the hiring system, not your capability inside it. Filter-first, evaluate-later is how the market actually runs, and the candidates who understand that build different things in parallel.
Read the full essay
The next essays planned for this series. We'd rather publish ten excellent pieces than one hundred filler ones, so these arrive as they're written, not on a content-calendar schedule.
- RolesDraftingCloud engineering isn't entry-level anymoreThe market that hired junior cloud engineers in 2019 doesn't exist. What replaced it, and the realistic path in.
- DomainsDraftingThe hidden downside of a GRC careerGRC is one of the calmest, best-paid entries into security. It also quietly closes doors you may not realise you wanted open.
3 more planned.