Pros
- Almost industry standard pay - Better culture across dev teams
Cons
- No domain expertise : Infosec management lacks fundamental leadership and domain expertise. Direct management is also often clueless and impulsive. There is a noticeable disconnect in team guidance, and the office culture is frequently distracted by internal gossip rather than professional development. - Unprofessional and Vulgar: Infosec leadership communication can be unprofessional and abusive with vulgar words. Strategic initiatives frequently shift on a quarterly basis, making it difficult to maintain focus or achieve meaningful security outcomes. - No work-life balance: The "on-call" requirements are unsustainable, with shifts sometimes reaching 56 consecutive hours. Candidates are often expected to work beyond the "follow the sun" hours, ranging from 50-70 hours a week excluding on call rotations. This creates a high risk of burnout and is out of step with industry standards. - Political and toxic: The work environment is characterized by heavy micromanagement and internal politics. There is a "do as I say, not as I do" atmosphere that erodes trust between staff and upper management. - Lack of growth: The organization claims a "flat structure," but this results in a complete lack of career transparency. The transition between Individual Contributor (IC) and Management roles is arbitrary and does not align with standard industry levels. - Inter-org movements: Despite official company policies regarding internal transfers, moves between teams are often bottlenecked by immediate management, bypassing HR guidelines.