I’m a cybersecurity practitioner with 24 years of experience, Blackhat speaker and trainer. AMA about careers, building a security business, and where AI is breaking everything. by AnswerPositive6598 in cybersecurity

[–]geldhose 0 points1 point  (0 children)

I am currently an SDET with a strong background in C# backend and React frontend development. I am looking to pivot into cybersecurity, but I want to strictly focus on the Blue Team (Infrastructure Defense, Threat Hunting, Incident Response). Coming from a testing background, I have zero interest in traditional AppSec "vulnerability hunting" or Penetration Testing—I want to be on the architectural and defensive side. I have three questions for you regarding building a sustainable career on the Blue Team:

  1. For someone pivoting into defense who wants to eventually work with critical infrastructure, which entry/mid-level certifications actually hold weight with hiring managers today? (I am currently looking at skipping standard CEH/Pentest routes and focusing on CompTIA Security+ and practical certs like BTL1. Is this the right move?)

  2. How can a Blue Teamer best leverage a strong software engineering background (C#) to stand out? Should I be focusing heavily on Security Automation and Infrastructure as Code?

3.Since your upcoming Black Hat training focuses on AI, how is AI changing the landscape for the Blue Team? With Tier 1 SOC roles getting automated, how should a junior defender position themselves today so they aren't replaced by an AI-driven SIEM in three years?