After five years managing thousands of servers in a security startup and two more years trying to build my own security SaaS, I’ve come to a realization: I’m done with cyber.

Not with tech. Not with building. Just with security.

And honestly? That’s okay.

The Burnout Was Real

Let me back up. From 2016 to 2021, I worked at a security startup. It was incredible - we built an all-in-one cybersecurity solution that protected millions of websites across thousands of servers. I led a small team developing the security agent, designed defense strategies against attack vectors, and shipped over 100 production releases.

But here’s what the CV doesn’t tell you: it was 24/7. Security incidents don’t wait for business hours. When you’re responsible for thousands of production servers and millions of websites, you don’t really clock out. Series B funding brought growth pressure. Ship faster. Add more features. Get more customers.

After five years, I was burnt. Completely.

So I did what seemed logical - I moved to a larger company with a calmer environment. Same tech stack (Go, distributed systems, observability), just without the constant fire drills. It helped. For about a year.

Then I realized the problem wasn’t just the pace. It was that I’d lost my passion for the security domain itself.

The SaaS Attempt That Taught Me Everything

In 2022, I started contracting through an Estonian company. The plan was simple: do security consulting work to fund building my own security SaaS. I’d seen the problems firsthand. I knew I could build something better.

Spent two years on it. Helped several companies improve their security practices and reduce infrastructure costs. Built some cool open-source tools. Made connections.

But here’s what I learned: enterprise security sales is a different game than building good products.

It’s not about having the best solution. It’s about relationships, golf games, and C-level connections. That’s fine - some people are great at it. I’m not one of them. More importantly, I realized I don’t want to be.

I’m a builder, not a salesperson. And trying to force myself into that mold was making me miserable.

The Warning Signs I Ignored

Looking back, there were clear signs this wasn’t working:

When people asked about my security work, I found myself becoming… negative. Not constructively critical - just bitter. I’d rant about enterprise sales politics, cloud-native hype that’s mostly marketing, and how “DevOps” often just means teaching sysadmins Python.

That’s not who I want to be.

If talking about your field makes you angry instead of excited, that’s not passion. That’s baggage.

What Actually Excites Me

Here’s the thing - I still love building. I still get excited about solving hard technical problems. I just realized that developer tooling fits me better than security ever did.

Why? Because in dev tooling:

  • Product quality matters directly - Developers won’t use bad tools, regardless of how well you sell them
  • No enterprise sales layer - Build something useful, developers adopt it, growth happens
  • Open source works - You can prove your solution works before asking anyone to pay
  • Feedback is immediate - You know quickly if you’re building the right thing

Currently, I’m working on industrial IoT platforms - building connectors for MTConnect and OPC UA, working with distributed edge computing systems. On the side, I’m exploring AI-powered development tools.

And you know what? I don’t get bitter when I talk about it. I get excited.

The Lessons I’m Taking With Me

So what did those seven years in security teach me?

Technical chops: Distributed systems, Go microservices, handling production at scale, security architecture - all of that transfers.

What I actually enjoy: Building tools that developers use directly. Product-led growth over sales-led. Open source over proprietary black boxes.

What I don’t enjoy: Enterprise sales cycles. C-level politics. Marketing-driven technical decisions.

Most importantly: It’s okay to walk away from something you spent years building expertise in, if it’s not making you happy anymore.

The sunk cost fallacy is real. Just because you invested years in security doesn’t mean you have to keep doing it forever. Skills transfer. Passion doesn’t always.

What’s Next

I’m not abandoning everything I learned. The distributed systems experience, the Go expertise, the understanding of production operations at scale - all of that is still valuable. I’m just applying it to problems that excite me instead of drain me.

Right now that means:

  • Industrial IoT edge computing
  • AI-assisted development workflows
  • Developer tooling and automation
  • Building in public, open source first

And most importantly - working on things where I can focus on building great products, not navigating enterprise sales mazes.

If You’re in the Same Boat

Maybe you’re reading this and thinking “yeah, I feel that.” You’ve spent years in a field, you’re good at it, but you’re not happy doing it anymore.

Here’s what I’d say: it’s okay to change direction. Your expertise isn’t wasted - it just becomes context for what you do next. The technical skills transfer. The domain knowledge gives you perspective.

But life’s too short to spend it being bitter about your work.

I’m done with cyber. And that’s okay.

What I’m not done with is building things that matter, working with technologies that excite me, and actually enjoying what I do.

That’s the whole point, isn’t it?


Currently building infrastructure tools for industrial IoT and exploring AI-powered development workflows. You can find my open source work on GitHub or read more about what I’m up to on my site.