10 Years Later

09/30/2026

This month marks 10 years since I started my tech / cyber security journey. It's a bit astonishing writing that sentence. Feels like it went by in the blink of an eye. I haven't given a talk or wrote a blog post in a while so I thought it'd be cool to share what my experience or learned lessons have been over the last decade. While it's been 10 years since I first committed myself to learning how to code and hack, my curiosity and imagination with technology has been an integral part for most of my life's journey. I may be aging myself when I say this but I was one of those teens that loved editing the HTML & Javascript of my MySpace page!

In 2016, I was wrapping up my Americorps service and trying to figure out what my next move would be career wise. I was trying to decide between continuing my work within the education field or becoming a social worker. I've done a lot of work within schools with kids and I was really good at connecting with and teaching them. It was a natural talent that I figured I'd further nurture. I naturally began working in the Chicago Public School system and continued working with students. Outside of work, I would frequently attend tech meetups in the city just because I liked learning about tech related topics. It became a passion of mine to start learning more about the software we interact with day to day and so I began learning the art of coding. It got to the point that I would look forward to my lunch breaks at work so that I could dive into whatever coding related project I was working on at the time.

I took some computer science related courses as electives in college but I needed a refresher. It had been a few years between taking those courses and my Americorps service, so I enrolled in Harvard's free Computer Science (CS50) via Coursera. As stated in my bio and another blog post, it was during this time that I was watching 'Person of Interest' in my downtime and saw a unrealistic hacking scene that peaked my interest. I developed a deep need to understand what I had just seen. From there, I started scouring free resources to learn the art of hacking and there wasn't much out there at the time or beginner friendly. I enventually found Zaid's Network Hacking course (iykyk) on Udemy and eagerly took in all the information I could and put what I learned to use in a lab. I knew in my gut that that was what I was meant to pursue. From there, I started scouring cyber security courses. While the beginning of my journey was heavily self-taught and relied on whatever information or courses I could find online, I decided I wanted a more structured path. To make a longer story short, I prepped, applied, and interviewed to get into Evolve Security's bootcamp. It was the more affordable path for me as a first gen college graduate. I was in a small cohort and was water hosed a plethora of information that I was responsible for showing mastery of said information through quizzes, labs, and actual security engagements. I earned my first certification (Security+) during the bootcamp and entered the field shortly after. I've now been in the field officially for nearly 9 years.

The last 10 years have been filled with challenges, transitions, ups/downs, curiosity, success, failures, and a test of my persistence and faith. It's also been filled with the love and support of my family and friends. That's honestly what's kept me going even more. While my career's journey has taught me the technical and non-technical things I need to do my job, I'm in a place in my life where I really value the true meaning of life….love, family and friends. Sounds cheesy, I know, but the losses I've experienced in life have taught me that life is truly short and when the end comes, I want my impact on the world to be more than what I accomplished at work. I want what I've poured into my family, friends, and community to be my life's message. 

With that being said, here are 10 things I've learned over the last decade since I fully committed myself to this work:

  1. ENUMERATE, ENUMERATE, ENUMERATE. Then ENUMERATE some more.
  2. Organizational dysfunction / company politics between IT and Cyber teams strongly impact how quickly or how far a project moves and is truly a risk / vulnerability in itself.
  3. You'll never feel caught up. The field is too wide and the pace of technological advancements are everlasting. Specialization is okay and can be a super power.
  4. No matter how technical your role is, GRC (Governance, Risk, & Compliance), IS an integral part of your role. We like to separate ourselves between the technical & non-technical sides and that has merit, but all roles share that common duty. For my fellow peeps that get bored with GRC work, I'm sorry but it isn't going anywhere.
  5. Protecting your curiosity is a MUST. Day to day work can burn us out but remember what led you down your path. For most hackers / pentesters / defenders, it was our curiosity that drove our passion for the work (at least thats the case for me).
  6. Your reputation travels further than your resume. Talks, write-ups, tools, and how you treated people on past engagements follow you. The industry is smaller than it looks.
  7. Your brain cannot hold all of the information you need to know. This is normal. Yes, mastery is important but building a second brain with your note taking tool of choice is a MUST.
  8. Take PTO on your birthday every year. The true meaning of life has nothing to do with employer. It's about your life's journey and whatever that looks like for you.
  9. Have hobbies outside of your work and research!
  10. You are NOT your research, number of CVE's, or job title. You are more than that. You're a finite human being that deserves to be loved and love. Go experience life with your family and friends.