Beyond the Terminal: The Other Careers in Security

Cybersecurity's public profile has never been higher, thanks to relentless breach headlines and the enduring, often dramatic, Hollywood imagery of hackers. That visibility has done much to explain why security matters, but it has done little to broaden the understanding of what a security career actually looks like. For many, the field still reads as a monoculture of coding and network defense, and that perception is leaving a large pool of potential talent on the table.

That gap in perception was on full display during a recent guest lecture at Cornell University. Students across communication, information science, and engineering saw the value of security practices—two-factor authentication, careful data handling—but when it came to their own futures, the responses were telling. They either dismissed the field entirely because it seemed to require a computer science degree, or expressed interest only if there were a clearer role for their existing skills in communication or marketing. Not one mentioned a pathway that matched their own disciplines.

This is not just a classroom anecdote; the industry cannot afford this narrow view. The global cybersecurity market hit $150.37 billion in 2021, and projections suggest it will roughly double to $317.02 billion in the coming years. That growth is fueling demand for workers, with around 3.5 million open security positions worldwide. The shortage has a dual cause: experienced professionals are leaving the field citing a lack of social recognition, and a persistent skills gap leaves many roles unfilled. Large organizations, including Microsoft, have already stepped in with campaigns aimed at closing that gap and cultivating a more inclusive workforce.

Broadening awareness of the career architecture within security is not just a recruitment exercise—it is a necessary step toward building interdisciplinary teams that can actually address the complexity of modern threats. The following roles, drawn from security teams at GitHub, illustrate how varied those career paths can be.

Security Product Marketing

A product marketer’s core job is to translate dense technical concepts into content that a wider business audience and the market at large can absorb. Technical expertise is not the entry requirement; instead, the role demands curiosity, a habit of asking good questions, and the ability to absorb and apply feedback.

A background in journalism and enterprise tech PR provides a solid foundation. Success in this niche leans heavily on research, strong writing, and the ability to connect disparate dots to help security organizations tell stories that not only sell products but shape industry narratives.

Candidates who are clear on their strengths, eager to learn, and comfortable going deep into details will find the most traction here.

– Laura Paine, Director, Product Marketing, GitHub Security Lab

Security Developer Advocacy

Developer advocacy in security sits at the intersection of technical aptitude and human communication. It is a career path that many do not discover until later, often wondering why they had not heard of it sooner. The work is built on a balance of hard and soft skills.

The mandate is to help developers worldwide improve their software security through awareness and education. This takes many forms—public speaking, video content, workshops, blog posts—but it all begins with direct interaction with users to understand their pain points. While those pain points are often technical in nature, solving them requires creativity and strong interpersonal skills.

Those who enjoy teaching, experimenting with new technology, and operating on the boundary between technical depth and people skills should look closely at this track.

– Joseph Katsioloudes, Security Developer Advocate

Product Security Engineering

The product security engineer role on GitHub’s Bug Bounty Team offers a view into the operational side. A typical background includes prior work in vulnerability management, supporting a bug bounty program, conducting root cause and variant analysis, running vulnerability scans, and helping with incident response.

The daily work is a varied mix of validating vulnerability submissions from multiple sources, analyzing root causes, and serving as the vital connector between engineering, security, and external security researchers. Coordinating and testing fixes ensures that both users and products receive top-tier, secure outcomes.

The most critical skills here are not purely technical. An interest in application security, authentic engagement with researchers and internal teams, and a deep, persistent curiosity matter more than a pre-loaded skill tree. Familiarity with common vulnerability classes like the OWASP Top 10, experience in Capture the Flags or hackathons, and a drive to learn provide the necessary springboard.

– Jeff Guerra, Product Security Engineer

These roles are just a sample of what currently exists, and the industry is already evolving to create more. The GitHub Security Lab itself is an example of a multidisciplinary security team, deliberately built to include backgrounds ranging from traditional security research to socio-technical research, developer advocacy, and advisory curation. That mix is essential to bridging the gap between open source maintainers and security researchers. The wider industry will need to follow suit if it expects to attract new talent and secure an increasingly precarious software ecosystem.