There’s a particular kind of clarity that arrives slowly. It doesn’t come from a single bad day or a single frustrating meeting. It accumulates — quietly, over months — until one morning you realize the gap between the work you want to do and the work you’re being allowed to do has grown wider than you can comfortably stand across.
That’s where I’ve been. And after a lot of reflection, I decided to start exploring opportunities outside of my current company. This was not an easy decision. I have forged many friendships with others inside and outside of my organization. I have earned trust and respect by many that I have delivered expertise and services to. I did it the right way.
I want to write about that decision honestly, because I think the dynamics that shaped it are worth talking about. Not as grievances, but as patterns that a lot of people in security — and in knowledge work more broadly — will recognize.
The role I was already doing
For some time, I’ve been performing the responsibilities of a role beyond my official title. That happens in a lot of organizations, and for a while it can feel like an opportunity — a chance to prove what you’re capable of before the title catches up. I am not one to be hung up on titles; however, when the title gatekeeps certain perks and benefits, it can feel as though I was being punished for exceeding expectations in a managerial role, when a Director title was well within the range of the scope of work I was executing.
When the title doesn’t catch up, and the conversations about it keep getting deferred, something shifts. The work stops feeling like an investment in your future and starts feeling like a quiet expectation that you’ll keep doing more for the same recognition. The signal a company sends by not promoting someone who is clearly doing the job is, eventually, louder than anything that gets said in a one-on-one.
I’m proud of the work. I just stopped believing the trajectory was real.
Return to office, without the math
The return-to-office decision was the one that surprised me the most — not because I’m philosophically opposed to being in an office, but because of how the cost was handled.
Or rather, how it wasn’t.
A mandate that doesn’t account for what it actually asks of people — commute time, fuel, childcare logistics, the loss of the focused hours that remote work made possible — isn’t really a workplace policy. It’s a transfer of cost from the employer to the employee, dressed up as culture. When the spreadsheet only includes one side of the ledger, the people on the other side notice.
I would have respected a leadership team that said, “Here’s why we believe this matters, here’s what it will cost you, and here’s how we’re going to help absorb that cost.” I would have disagreed with parts of it, probably, but I would have respected it. What I struggle with is a policy that treats the people executing it as a line item that doesn’t need to be balanced. For the past 18 months, I have been operating in a negative cash flow situation, patiently waiting for that elusive promotion to Director or some kind of merit increase reflective of the hard work and dedication it takes to transform a shell-shocked Security Operations Center from prior leadership into an efficient and engaged one.
When the decision was announced, it represented a 50% increase in my weekly expenses, sans the inflation and price of commuting skyrocketing. For someone working 60-70 hours a week in a work from home scenario, it stopped making sense to get excited to put in the extra time. I began spending 2 hours per day commuting into an office to have Zoom meetings with people in the same physical location as I. Since the organization spanned multiple time zones, I was being expected to commute home and climb onto more meetings when I got here.
Innovation, mentorship, and the entrepreneur problem
One of the things I love most about the security field is that it rewards people who think laterally — who build things, mentor newer practitioners, contribute to the community, and bring what they learn back into their day jobs. The best security teams I’ve ever seen are made up of people who do all of those things.
It’s hard to do any of them inside an environment that treats outside engagement as a risk to be managed rather than an asset to be cultivated.
I’ve wanted to mentor more. I’ve wanted to build things — small things, useful things — that help other practitioners. I’ve wanted to operate, in some modest way, as an entrepreneur alongside my day job, the way many in this industry do. The structural friction against doing those things added up. Not a single “no,” but a steady accumulation of “not like that,” “not without approval,” “not in a way that touches anything we do.”
At some point, the cost of staying creative inside that environment exceeds the cost of finding a different one.
The social media policy
This is the one I’ve thought about the most before writing.
A reasonable social media policy protects an employer from genuine reputational and legal risk. I’ve worked under reasonable ones. They give you room to be a professional with a voice, while drawing clear lines around the things that legitimately need protecting.
What I experienced was different. The lines weren’t around risk; they were around expression itself. The effect — whether intended or not — was that thinking out loud became something to do quietly, in private channels, where it couldn’t compound into the kind of professional reputation our field actually runs on. In security, your public thinking is part of your craft. Suppressing it isn’t a neutral act.
I don’t think anyone set out to silence me. I think a policy got written by people optimizing for the wrong variable, and the practitioners living under it absorbed the cost.
What I’ve learned
A few things I want to carry forward for the duration of my career:
The clearest signal a company sends about your future isn’t in what people say to you. It’s in what gets approved, funded, titled, and protected. Watch the verbs, not the adjectives.
Policies are philosophies in disguise. A return-to-office mandate without cost consideration tells you something about how the organization weighs its people. A restrictive social media policy tells you something about how it views their voices. Neither of those things is incidental.
The security field — maybe more than most — depends on practitioners who are allowed to keep growing in public. Mentoring, building, writing, speaking, contributing. An environment that treats those activities as suspect will, over time, lose the practitioners who do them best.
And finally: leaving well matters. I’m not writing this to settle a score. I’m writing it because I think honest reflection is more useful to my community than a polished announcement would be, and because someone reading this is probably weighing some version of the same decision.
What’s next
I have been so fortunate to have found an opportunity to work with a group of likeminded professionals that share a common mission of treating their employees as their number one asset to cultivate and to grow. The title issue has been resolved: I will be stepping back into a Director-level position that makes sense in both scope and breadth. The financials made complete sense, and the organization fully supports a remote-first culture, eliminating the 50% tax I was being assessed to maintain a job that I was growing more and more distant from. The organization has allowed me to continue my passion of building through my newly-formed LLC called Webelo Solutions. To reciprocate, I have gladly prioritized my employer’s needs first, and in return, they have given me a voice and an outlet to create tools and mentor professionals. There is mutual trust and clear expectations. Finally, they are giving me my security voice back on social media channels. No longer is every post treated like a potential reputational hit to the organization. I do not anticipate being summoned into the principal’s office to be interrogated about a general post about burnout, RTO, or a security topic that is opinionated.
My interview process was lengthy, but well worth the investment. I had an opportunity to test what matters most to me as a cerebral thinker in each corresponding round. The organization I am joining will remain a secret for the foreseeable future while I get up to speed and learn the nuances of the culture, the technical stack, and the processes that make them an admired organization.
If you’re building something where a security practitioner with a builder’s mindset and a mentor’s instinct would be valued — not tolerated, valued — I’d love to hear from you.
And if you’re reading this from inside a situation that sounds familiar: you’re not imagining it. The accumulation is real. Trust the math you’ve been doing.
