When I finished school, I had a big dream: I wanted to become a captain at sea!
But I couldn’t even apply to study nautic, because I had not done the required internship on a ship. Now I would need to wait for one year, do the internship and apply.
Until then, I had to do something. But what?
I had always been good at math, but had no idea what job I could work with a degree in Mathematics. “It’s just for one year. Don’t overthink it.” So I started to study Computer Science.
Over the year, doubt crept in. I would have finished my studies before I could even know if I'd pass the fitness for sea service examination. Without it, my study would not be useless, but I would have had to pivot from a nautical to a technical role on board. Not my desired outcome...
Somewhere along the way, I dismissed the dream of becoming a captain at sea and found a new North Star in becoming a pentester. After my bachelor’s degree, I couldn’t find a role that would let me practice on the job, so I ended up in software development.
I was disappointed. Being a software developer seemed to be a total waste of time and my goal was far out of reach.
But when I attended my first local security conference, I talked to a red teamer who completely changed my perspective. He said, “a lot of junior pentesters struggle, because they lack the basics. They have never developed software or administrated servers.” That’s exactly the two things I was currently wasting my time on.
Maybe it wasn’t a total waste?
Embrace detours
It’s basically like driving on a highway. Everything looks good and smooth on the map, but when you go out in reality, you may get stuck in traffic jams or roads might be closed entirely. Sometimes the detour is necessary. Sometimes it’s even faster than following the original track. You can complain about it or you can just embrace it and maybe discover your new favorite restaurant, enjoy the awesome views along the way and maybe even meet the love of your life?
I had chosen a path when I signed up for my Master’s degree in Applied IT Security and started working as a software developer to be able to pay for my studies. It was not the straight route into pentesting I had wished for, but at least I was roughly moving in the right direction. Following my new North Star.
Knowing the experience I gained as a software developer was useful changed everything for me. Suddenly, there was meaning in the job I previously just did to earn money and keep moving. The experience gained was valuable. It started to be fun.
When we stop complaining and start to view detours as opportunities, are they still detours or do they eventually become important milestones on our path?
So when I was offered a new role to build the company’s data protection management system from scratch, I just asked one question: does this sound like a good new experience? Will it likely teach me new skills? Will it make it more likely to land a job in security? After 3.5 years in software development, it was time for something new, so I accepted another detour.
Turn on dead ends
My role as data protection coordinator didn’t turn out to be as much fun as I wished. I was no longer motivated. After 1.5 years, it had become the boring meaningless job I never wanted. I had been applying to junior pentester roles, but without practical skills, I couldn’t land a job. At least, I got the best rejection I could have imagined: a list of topics I should learn before applying again.
Until then, I had to stay on my path. My company had paid for my studies and I would have had to deal with student debt if I left too early. It sounded reasonable to stay and count down the months, until I was free to go. I was caught in a dead end.
Today, I would like to thank my former boss for kicking me out of my comfort zone. I spare you the details, but being no longer allowed to take my dog to work on top of a meaningless job was too much. “Fuck that debt. I have to leave. NOW.”
So within a few weeks I switched companies and got back into software development. Here I was, back where I started. We found a good solution for the debt and everything was not as bad as expected. Most importantly, I was moving again. And my dog was back in the office! #wuff
Today, I’m at peace with this dead end. It taught me valuable skills I just didn’t know I would need today. But the most important lesson is maybe, that we need to accept dead ends for what they are, get aware when we are trapped, step back, and move on.
Stand up for yourself
Back in a developer role, I was still committed to becoming a pentester, but not really acting on it. Until one day, I learned that most of the team would go to JavaLand and I wasn’t invited. I was pissed off.
Sure, I understood, that they had asked for it. I hadn’t. And someone needs to stay and work on the customer project in case something bad happens and needs to be fixed ASAP.
After a night of sleep, I caught myself. That was stupid. I just wanted to have fun for three days on the conference. But how would bring JavaLand me even an inch closer to becoming a pentester? This was an opportunity to ask for something that would actually move the needle for me.
In the end, I made a deal to earn my first pentesting certification (eWPT). I would have preferred starting with network pentesting, but as web application pentesting was closer to software development, it was a good compromise.
At least, I would learn some hands-on skills and a certificate would bring me closer to my first pentester job. Of course I hadn’t planned to stay longer than necessary in that developer role.
Before I even finished that certification, another door opened. I was offered to build the company’s AppSec program from scratch. Of course, back then nobody even knew there was a name for what I should do. They told me I should do some security stuff and maybe pentest some of our own products. YES! Of course I’ll accept that detour.
Be willing to abandon your North Star
Remember how I had abandoned my North Star before? I wanted to become a captain at sea, but abandoned that dream for becoming a pentester. Reality had killed the first dream.
This time, I was sure I found the right profession. The job that I can work for the rest of my lifetime without it becoming boring. Hacking all sorts of systems and applications. Finding new ways in all the time. For me, that sounded like standing in front of the great walls of Troja and trying to figure out, how to conquer a city nobody had ever conquered. What an adventure!
But something had changed. I was working in security now. For the first time, I got trust from my management to build something that should actually improve software security at scale. No compliance bullshit. Just AppSec that works.
Compliance followed later, but it didn’t mess with what worked. I basically had the freedom to explore what AppSec measures were out there, what our teams needed and come up with my own ideas of what might work. Then I would test and implement them. It was fun. Maybe I should explore this detour a bit longer.
This time, a headhunter changed everything. There was this company I had wished to work for for many years. The one that gave me the list of topics to study. When he called, he couldn’t hide for which company he was hunting talents. It was the wrong time. My AppSec program was still too fragile, but we stayed in touch.
Maybe a year later, we spoke again. In the meantime, he had gained better insights on what the job of my dreams actually looked like. How much time do you actually spend hacking? How much is routine? Writing reports? Traveling to customers?
When we separated this time, reality had caught me. Again. I had abandoned another North Star. Working as a pentester or red teamer was no longer pulling me.
I had been delusional. I had again, wasted time on learning hacking skills and gaining pentesting certifications. But again, those skills would prove valuable later, just not in the way I had imagined.
So how can I finally find the one thing? A North Star I wouldn’t need to abandon in the future?
Know when to jump
For a long time, I had known I wanted to be my own boss. I had wanted to travel full-time and explore the world. I just didn’t know in what direction I wanted to take my own business.
Should I stay in AppSec? The field I never chose? A field I accidentally stumbled into? Or should I finally follow my passion?
For over a decade, there had been a passion that I could turn into a job: photography. But I had always been scared, that becoming a professional photographer would kill my passion. The idea of photographing a new dog every day at the same locations seemed too boring.
In the end, my calling for freedom, overland traveling and adventure grew so big, I couldn’t resist anymore. I had to jump and build a business around the skill I got: building AppSec programs.
Some people might build their identity around a job, but for me, that just didn’t work.
I had to accept, that there was not that one thing that would be my job or passion for the rest of my life.
Dance with chaos…
In 2025, I made my dream come true. I quit my job, got rid of most of my belongings and left Germany. I was finally free and on my own adventure!
Not as a captain at sea, but at least I’m now steering my good old Chevy Blazer through Europe and Northern Africa.
I learned pretty fast that I had underestimated with how much chaos and uncertainty this lifestyle naturally comes. No fixed income. No place where I belonged. Just freedom without security.
But it was the same freedom and exploration that eventually let me arrive in AppSec. While I never wanted to be an AppSec person, I’m still drawn towards understanding how companies work, how complex systems work, what makes them fragile and how to optimize them for resilience.
Looking back, to me the most interesting domain within pentesting had always been social engineering. I had been interested in philosophy and psychology for years. Always driven to understand why people do what they do.
When I built my own AppSec program from scratch, I had been using this the whole time. I had analyzed the system, processes and tried to understand why people wouldn’t act even so they knew what the expected secure behavior was.
As an external consultant, I lost this connection. I was too far away to talk to the developers and project leaders to understand their system, culture and needs. I had to come up with my own approach once again.
… to create order
So how did arriving in AppSec actually look like?
Last year, I came up with the AppSec Ownership Model. Something, that had been in my head for a long time. In short, it’s how I would distribute AppSec responsibility between all roles involved in developing secure software. My blueprint to a resilient AppSec system.
First, I published my AppSec Ownership Model on YouTube, but it was too rigid. Whenever I want to update something, I would need to produce a completely new video. That’s why the model is now available here on Substack.
Somewhere along the way, I just wanted to do research. I wanted to talk to fellow AppSec Leads, listen to their stories, learn about their challenges and figure out, what actually works in AppSec. I wanted to soak in all the other perspectives, see what we can learn from each other and publish it. And of course, sharpen the AppSec Ownership Model.
Besides that, I had to find something better than classical consulting. Something that can connect me again with the company’s culture, processes, and people.
That’s why I created the AppSec Terrain Check. A diagnostic assessment where I interview people in different roles who are involved in developing secure software. This allows me to understand their system and figure out where it is most fragile. That way, I can make it visible to the AppSec team and help them optimize their system for resilience.
If you are building an AppSec program yourself, I would love to hear your story. Feel free to send me a DM here or on LinkedIn.
Conclusion
If career planning works for you, you are lucky. If it doesn’t, there is nothing wrong with you. I think it doesn’t work for most people. And if you see people that found exactly that job or role that matches their passion, they probably ended up there by accident, too.
So how can you arrive at the right place following your own accident?
Embrace detours: you never know what a detour will teach you or if it will end up being the place where you want to arrive.
Turn on dead ends: If your job feels meaningless and you hate it, leave. Do something else, no matter what. Just something that is fun and teaches you something new.
Stand up for yourself: Nobody is coming to push your career. Take responsibility to develop your own skills. If you want support from your company, create a win-win. How do they benefit from your new skill?
Be willing to abandon your North Star: A North Star is just a direction you’re curiosity did take you. Try to find out if your imagination and reality actually match. If not, find a new direction.
Know when to jump: We all get stuck in our comfort zone. If you really want something to become reality, at some point you must jump and see what happens.
Dance with chaos to create order: After you jumped, life might be chaotic. You might underestimate the challenge you accepted. But this time will make you grow and eventually you will stabilize your life at a much better place. If not, you’re not dead. You can try again.
In this fast moving world, it becomes even more critical to find your own path. How could I have known back then that doing AppSec research and AppSec system diagnostic could even be an option?


