Security Bsides Las Vegas 2024

Tracking and hacking your career
2024-08-07 , Florentine B

Employees, especially those earlier in their career, often expect managers to provide a plan for career growth. Experienced managers know this effort needs to be collaborative or it will likely fall flat.

Employees that take an active role in this process will have more agency in shaping their career.
This talk is geared towards individual contributors (ICs), but still applicable to people managers.

We’ll demonstrate how to translate your company’s ladder into the skeleton of a Career Development Plan (CDP). A custom CDP is a powerful tool that can help you during promotions and makes filling out self-reviews a breeze. It’s also a durable document that will help protect you from career setbacks when you switch teams, your manager leaves, or when you change companies.

Another aspect of shaping your career is being comfortable talking about your accomplishments. We’ll briefly cover how to make your work visible to others.

This combined with a CDP helps you achieve whatever’s next. This could be Senior to Staff AppSecEng, IC to manager, or changing disciplines from CloudSec to CorpSec.

The most consistent person in your career is you, make sure you are recognized for your work.


Outline

Brief intro

Why individual contributors should be active in their career growth
- you should be the most invested person in your career
- managers change, if you rely too much on your manager you can be set back when this happens
- increases your agency
- more likely to get recognized for your work
- makes it easier to get promoted

How companies think about performance
- what is a career leveling?
- security eng examples from Dropbox and levels.fyi
- what is calibration/review season?
- what does performance review season look like at mature-ish companies?
- how do people get promoted at mature-ish companies?
- what are some failure modes during calibration?

Intro CDPs
- why is a CDP useful?
- how does it avoid some of the failure modes during calibration?
- how to create a CDP from a ladder

What can you do with a CDP?
- help plan your next phase of growth. This could be getting promoted, becoming a manager, switching to a new discipline in security, etc.
- use it to create/update your resume
- use it to onboard your new your manager

Getting comfortable sharing your success
- Posting in Slack
- Presenting to your team
- Blogging/conference speaking/podcasting

Summary
- audience should understand the value of tracking their career progress and leave with the tools to get started tracking their career progress and mapping their company’s ladder to a CDP

Leif Dreizler is an information security professional with over a decade of experience. He is currently leading an engineering team that builds features of Semgrep’s product. Previously, Leif was a Senior Engineering Manager at Twilio Segment where his team was focused on building customer-facing security features and internal security tools.

Leif is a conference organizer and active member of the security community, and is passionate about helping folks on his team and within the broader security community develop in their careers.

Misha Yalavarthy is currently an Security Engineering Manager of a research team at Semgrep that is building rules to find vulnerabilities in our customers code. Before Semgrep, she was the Security Engineering Manager for the Detection and Response team at Sentry and was responsible for building the program from the ground up. Prior to that, she was a Senior Security Engineer at Cloudflare focused on internal security and building detections to secure the global network and infrastructure.