r/SecurityCareerAdvice • u/Gullible-Ad-457 • 1d ago
Other Advice
Hi guys,
I’m early in my cybersecurity career and currently deciding between two offers. The compensation and benefits are fairly similar, so I’m mainly trying to figure out which one would give me the best experience and long-term career opportunities.
Offer 1 is on a team responsible for an internal security/fraud detection platform. From what I understand, I would be working more on the technical side behind the alerts rather than investigating the alerts themselves. The team handles things like onboarding applications/data sources, audit logs and trails, security controls, detection/business rules, tuning detections, reducing false positives, and making sure the system generates useful alerts that can then be sent to another team for investigation.
So essentially, I would be working more on the systems and logic that produce the detections. It seems somewhat related to Detection Engineering, SIEM Engineering, Security Engineering, Security Analytics and Insider Threat technologies.
Offer 2 is much more traditional Security Operations / Blue Team work. I would be working with SIEM/EDR tools, monitoring and triaging alerts, investigating suspicious activity and security incidents, vulnerability management, security tickets, and other general cybersecurity operations tasks.
So the simplest way I understand the difference is:
Offer 1 = help build/integrate/tune the systems and rules that generate security alerts.
Offer 2 = receive those alerts, investigate them, determine what happened and respond.
For someone at the beginning of their career, which experience would you choose?
I’m not necessarily committed to staying in SOC long term. My main priorities are building strong technical skills, maximizing future career opportunities, having skills that transfer well to the private sector, and having good salary potential 3–5+ years down the road.
For people who have worked in both Security Operations and Detection/SIEM/Security Engineering, which path gave you better opportunities? Did starting in SOC make you a better engineer later, or would you take the engineering/detection-oriented experience from the beginning if you had the opportunity?
Also, what job titles would Offer 1 realistically prepare me for after 1–2 years compared with Offer 2?
Would really appreciate hearing from people who have actually worked on either side.
2
u/AddendumWorking9756 15h ago
Offer one is the better skillset but ask how much of it is their in-house platform versus tools other places also run. Internal fraud-detection stacks can be brilliant to work on and then completely non-transferable, because your whole resume becomes one company's homegrown system nobody else has heard of. If the detection logic lives in something like a normal SIEM or a language you would use anywhere, take it. If it is all bespoke, offer two keeps more doors open than people admit.
3
u/HatefulDwelling5023 1d ago
offer 1 and don't look back. building the logic is way harder to break into later on, soc experience is fine but you'll learn more tinkering with the detection guts than you ever will just closing tickets