
This as-told-to essay is based on a conversation with Prerit Pathak, a 28-year-old security engineer at Google in New York City. It has been edited for length and clarity.
I think some people mistakenly believe that being a ‘tech employee’ is synonymous with being a software engineer. But I’ve always had a fascination for cybersecurity.
I vividly remember jailbreaking my devices as a kid to enhance their capabilities. Hacking for me meant making something do what it wasn’t intended to do. It’s the art of navigating edge cases — to question the builder’s assumptions and make the supposedly impossible possible.
Despite that interest, I started my career as a software engineer at Dell Technologies in India.
Compared to software engineering or AI, I believe there’s a lack of public-facing mentorship and “day-in-the-life” transparency with the cybersecurity field, which makes it harder for people looking to break in to see themselves in the role.
I believe the age of AI has created a strong demand for cybersecurity roles, and I’m glad I eventually found my way back to it.
Cybersecurity became more than a side interest
During my undergraduate degree, I sharpened my skills as a security researcher through classes, self-study, and participating in “Capture the Flag” challenges. But I was still trying to understand which career path I wanted to take.
When I got an offer for a software engineering job at Dell at the beginning of my senior year, it was a good opportunity, so I decided to accept it. My software engineering experience ended up being a great technical foundation for my career.

While working as a software engineer, I found a vulnerability on a public website and reported it to the website’s management, with details on how to fix it. Eventually, through continuing that kind of work, I received appreciation letters and acknowledgments from top universities and organizations for disclosing critical vulnerabilities. Seeing the tangible impact of security research inspired me to pursue the field.
While I was working at Dell, I also set up a local chapter of the Open Worldwide Application Security Project, a cybersecurity nonprofit. As part of the chapter, I invited speakers from around the world to give talks.
At this point, I decided to go to graduate school at Carnegie Mellon University because I wanted to specialize and learn deeply about information security. Attending a top school like Carnegie Mellon meant being around people from whom I could learn, and I hoped it would help me transition into the cybersecurity field.
I moved to the US and eventually landed a job at Google
In 2021, I moved to the US to start graduate school and then completed a Google security engineering internship the following summer. I had a great internship, but my team didn’t have an opening at my level, so I went back to school to finish my degree.
In 2023, two months after earning my master’s degree, I joined Google full-time in New York.
My Google internship and graduate-school curriculum were important parts of my pivot, but I also think the things I did outside of that helped. I filed two patents, including one stemming from work I did with team members during my Google internship. These experiences, in addition to the appreciation letters I received, helped signal what I could do in security.
Now, as a security engineer, I create and run threat simulations to replicate adversary behavior in enterprise environments. The most time-consuming part of my job is usually analysis and reporting, which consists of analyzing the outcomes of the tests mentioned above, piecing observations together to form a coherent story, and finally reporting it.
Here’s my advice for breaking into cybersecurity
Before getting hired at Google, I attended conferences, learned from mentors in the security industry, and applied to and was rejected by a few companies, learning from each. I’m a huge proponent of “failing forward.” When you find and create opportunities for yourself, luck finds you.
For software engineers who want to shift to cybersecurity, like I did, I’d recommend using their technical skills to their advantage. As builders, they understand how those systems work; the pivotal shift in thinking is to understand how they can be taken advantage of.
Networking definitely has its role in uncovering opportunities, but preparing for and successfully navigating the interviews was, in my opinion, more crucial. I try to remember that an interview is a conversation between two people and that the interviewer is on your side. Asking clarifying questions before responding can improve your chances of giving a good answer. I’d also recommend thinking out loud so the interviewer can understand your thought process and, in some cases, nudge you in the right direction.
I’d suggest focusing on communication skills because stellar security engineers are empathetic partners who can convey technical risks to leadership without diluting the gravitas of any high-stakes situation.
I think it’s also important to learn what working in cybersecurity actually looks like. When I was looking for jobs, it was hard to get insight into what careers in cybersecurity could look like. Connecting with others in the field helped me learn and build my own path.
Looking back, making the shift from software engineering to cybersecurity was a leap of faith. I’m incredibly grateful I made it.
Do you have a story to share? Reach out to the reporter via email at [email protected], or via Signal at jzinkula.29.
Read the original article on Business Insider
The post Thinking about a career pivot? A Google engineer shares what he learned from taking a leap of faith. appeared first on Business Insider.




