BSidesSF 2025: The Art of Cybersecurity Mastery: from Entry-level to Staff+

I am employed as a Principal Security Architect at Adobe at the time I published this article. All opinions are my own.

Lessons learned and advice I’m giving to my mentees: how to get into cybersecurity or advance their careers. This talk covers my own journey spanning 15 years of professional experience to eventually achieving the Principal (director-level, just no reports) level at Adobe in 2022.

I cover:

  • how to write better resumes: Write resumes specific to the role(s) you are applying too. Highlight how you can benefit the organization, describe whether you learned / supported / lead activities and your impact.
  • for recent graduates and early career: stand out by doing “side quests”, like bug bounty hunting. This demonstrates hands-on experience and motivation to potential employers (Bug Bounty is a major reason I have a career in security).
  • how to ace the technical interview: a description of how I test candidates for solid technical understanding, empathy for software engineers, nuanced communication and potential. An overview of what to practice and learn.
  • how to advance your career to Staff+: The shift from doing the technical work to guiding the work, choosing what to work on and sphere of influence. And an explanation of what it means to gain visibility.
  • and specific to security: the power of being a specializing generalist.

All presented within this year’s theme of “there be dragons”.

Materials: