@Jai__Malik Security is a thankless job - anyone smart and informed enough to realize this will avoid broadcasting their expertise lest they be saddled with the work.
@Jai__Malik Issue 1- as with covid, some people want absolute assurances (which don't exist, given real world constraints) ... as the "expert" you will have to mediate countless debates between the risk averse and the reckless, both sides arguing without a firm grasp of the facts
@Jai__Malik Issue 2- it is difficult for anyone outside the field to evaluate the quality of your work; failure is sudden, public and painful; success is unseen, and tbh many people "succeed" through luck rather than skill (rather like hedge fund managers)
@Jai__Malik Issue 3- security often works against other goals (at least superficially), you will be the team scold and naysayer, with all the popularity that entails.
@Jai__Malik Issue 4- most coders prefer to write code than read it, prefer greenfield to legacy complexity, prefer creating something new rather than protecting someone else's creation - basically, it isn't fun work for the average dev personality
@Jai__Malik Issue 5- to be a true all-round cybersecurity expert you need to understand the *entire* stack of abstractions, from hardware exploits and crypto maths to network protocols to application layer to UX and human factors- not easy, you'll always have a bit of imposter syndrome
@Jai__Malik Issue 6- you're never off the clock- you'll be pinged at any random hour CTO arrives home from a long flight having read about some new exploit.. or if there's an afterhours network issue- usually it's an internal screw-up but people remember the alarm more than the resolution
@Jai__Malik Issue 7- (the final straw for me)- when you tell non-techies about your work, 100% of the time they respond with "oh, so you're like that hacker who ..." (Latest news story) And you have to smile and pretend it isn't an insult to be compared to the criminals you fight