Career Direction

Career Direction

Decision

My primary career target is AI Security / Security Engineering, focusing on securing AI-enabled applications, APIs, and their supporting infrastructure.

I will build on my Computer Science degree and existing software engineering experience rather than treating security as an unrelated new career.

The order in which I build the supporting skills is set by My Master Roadmap: foundations first (C, operating systems, networking, identity and cryptography), then application and systems security, then the AI security phases. The direction is fixed; the sequence comes from the roadmap. Right now that means Phase 1 — C and computer science fundamentals.

The actual bet

Don't bet my life on "I'll become an AI Security Engineer." Bet the next year on finding out whether I'm unusually good at securing complex software systems. Prediction requires luck; evidence doesn't. I need more evidence, not another career theory.

Why this direction

I want a technical career that supports international employability, remote opportunities, possible relocation, and long-term entrepreneurship.

AI Security connects several capabilities I want to develop:

My existing project, VeriDoc, provides a starting point for demonstrating software engineering and applied security. It does not, by itself, establish professional competence in AI Security. I need additional evidence that directly demonstrates security skills.

Career hierarchy

Primary direction

AI Security / Security Engineering.

Core supporting skills

  1. Application security and secure software design

  2. Authentication, authorization, and API security

  3. Python and Go for practical security engineering

  4. Linux, networking, and system administration

  5. Cloud infrastructure and deployment security

  6. AI application security, including LLM-specific risks

Adjacent opportunities

These are related options, not a requirement to pursue every title simultaneously.

Career ladder (don't target one job title)

  1. Software / Security Engineer — backend, Linux, networking, cloud, AppSec, auth, APIs, databases, security testing.
  2. Application / Product / Cloud Security Engineer — while getting unusually strong in AI systems.
  3. AI Security Engineer / AI Application Security Engineer.
  4. AI Security Architect / Security Researcher / Staff Security Engineer / AI Security Lead.
  5. Eventually: founder / independent researcher / consultancy / security product company.

Betting only on a job title that did not exist a few years ago is fragile. This ladder is more robust.

My sweet spot

Builder + Defender + Writer. Not developer ×4, not security ×3.

That combination is rare enough to build a career around.

Project selection rule

Before starting a substantial project, I should be able to explain:

  1. Which security or engineering skill it develops.

  2. What concrete artifact I will produce.

  3. How I will test or evaluate the result.

  4. How the work could demonstrate competence to an employer.

  5. Why this project is more valuable than finishing an existing commitment.

Prefer projects that combine several of these benefits without becoming unnecessarily large.

Learning rule

I will learn a technology when it supports a current project, fills a demonstrated skills gap, or appears repeatedly in relevant job requirements.

Interest alone is not sufficient reason to make it a priority.

A technology can remain on my future-learning list without becoming part of my current plan.

Evidence before changing direction

I will not change my primary career target simply because another field looks interesting or temporarily appears more attractive.

I will reconsider the direction when there is meaningful evidence, such as:

When reconsidering, I will record the evidence, alternatives, and consequences before making a new decision.

Evidence that would make me abandon this direction

If sustained real work shows:

This is still a hypothesis

I have not yet put in ~500 serious hours of doing AI security (finding, reproducing, threat modeling, writing reports, testing real AI apps, publishing findings). Until I have, "AI Security is my calling" is an assumption, not a conclusion.

What success looks like

Near term

Following 6–12 months

These are target outcomes, not guarantees.

Current constraints

Review policy

Review this decision quarterly or when significant new evidence appears.

Do not reopen it during ordinary weekly planning.