The Art of Cybersecurity Mastery: From Entry-Level to Staff+

Florian Noeding

BSidesSF 2025 — Here Be Dragons · Day 1 · Main

Overview

Adobe Principal Security Architect Florian Noeding drew on fifteen years of experience — from econophysics to software engineering to bug bounty hunting to product security — to deliver a practical framework for advancing from an entry-level security role to staff and principal levels. The talk covered resume writing, acing technical interviews, understanding career level expectations, and the organizational mechanics of getting promoted at senior levels. ---

Watch on YouTube

Visual summary for The Art of Cybersecurity Mastery: From Entry-Level to Staff+ by Florian Noeding
Visual summary for The Art of Cybersecurity Mastery: From Entry-Level to Staff+ by Florian Noeding

Key moments

  1. 1:15 Technical focus: Memory safety in C/C++ requires secure-by-design systems
  2. 4:29 Career insight: Improving deployment pipelines builds crucial developer empathy
  3. 5:19 Technical insight: Cloud metadata services expose critical SSRF vulnerabilities
  4. 6:02 Case study: Hacking crypto exchange build systems for cloud deployment keys
  5. 7:59 Resume strategy: Create separate resumes for offensive and defensive roles
  6. 8:45 Resume tip: Highlight specific engineering impact over generic risk metrics
  7. 9:20 Career tactic: Use bug bounties to demonstrate hands-on real-world experience
  8. 10:44 Interview key: Show empathy for the engineering effort required for remediation

The Art of Cybersecurity Mastery: From Entry-Level to Staff+

Speaker: Florian Noeding

Conference: BSidesSF 2025 — April 26-27, 2025, San Francisco

YouTube: Watch the full talk

Reading time: ~7 minutes

TL;DR

Adobe Principal Security Architect Florian Noeding drew on fifteen years of experience — from econophysics to software engineering to bug bounty hunting to product security — to deliver a practical framework for advancing from an entry-level security role to staff and principal levels. The talk covered resume writing, acing technical interviews, understanding career level expectations, and the organizational mechanics of getting promoted at senior levels.

Introduction

Career development advice in cybersecurity often stays at the surface level: get certifications, network, do CTFs. Florian Noeding's talk at BSidesSF 2025 went considerably deeper. Speaking from his own non-linear path — a physics degree that had nothing to do with security, a stint as an engineering manager, years of software development, and an eventual transition into AppSec at Adobe — Noeding offered specific, structured guidance on what it actually takes to move from entry-level to staff-plus in a product security career.

The talk was framed explicitly as mentoring advice, the kind Noeding provides to individual mentees but adapted for a room full of people he'd never met. His central thesis: a career is a forty-plus year journey, and the best strategy is not to map out a twenty-year plan but to follow curiosity and optimize for the next step.

Writing a Resume That Actually Gets Read

▶ Watch: Resume strategy for security roles (08:02)

The most common resume mistake Noeding sees — and he has interviewed over 100 candidates — is a generic document that signals the applicant doesn't know what they want. People apply for defensive roles, offensive roles, and SOC analyst positions with the same resume. The result is a document that tells the interviewer nothing useful.

His prescription: write a separate resume for each role type. A defensive resume highlights threat modeling, vulnerability management, and blue team work. A penetration testing resume emphasizes offensive tooling, bug bounty findings, and red team engagements. The resume should tell a story of how the candidate's specific skills will help that specific organization.

For early-career candidates, Noeding noted a second common failure: vague impact statements. Phrases like "I reduced security risk by 30%" mean nothing without context. Instead, he advised candidates to describe concrete outcomes: how they improved engineer visibility into risks, how they made it easier for developers to write secure code, how they tackled a complex, open-ended security problem. The difference between listing responsibilities and demonstrating impact is the difference between getting an interview and not.

He also highlighted bug bounty hunting as a differentiator for recent graduates. It demonstrates self-directed motivation and a willingness to learn technical depth outside of coursework — exactly what hiring managers like Noeding look for.

The Technical Interview: What Interviewers Are Actually Measuring

▶ Watch: Technical interview structure and SQL injection hierarchy (12:02)

Noeding's interviews are not trivia contests with fixed correct answers. They are conversations designed to get as close as possible to actually working with a candidate on a real problem. He looks for five things: technical depth, empathy with engineers, communication clarity, curiosity, and the ability to say "I don't know."

He walked through his hierarchy of questions using SQL injection as a case study. The ladder begins with the most fundamental: what is SQL injection? A vague answer — "it's when someone puts weird stuff into a form and the website gets confused" — is technically correct but tells him nothing about how the candidate thinks. A strong answer articulates the mechanism precisely: it's when insufficient separation between data and code allows an adversary to partially or fully control the database, bypassing application logic.

From there, questions escalate: How do you prevent it? What are parameterized queries and why do they work? What are the edge cases — how do you safely handle dynamic sort orders or field selection that depend on user input? And at the staff level: how do you mitigate SQL injection at scale across multiple products with different tech stacks, and which other parts of the security organization do you pull in?

The depth of answers across multiple domains is what Noeding uses as a proxy for curiosity. Candidates who have genuinely explored the problem space know this material not from memorization but from having followed threads of genuine interest.

The open-ended problem he typically poses for product security roles: "You've been assigned to help secure a new company-wide login page. How do you work with the team?" He's watching for whether candidates start with threat modeling, how they balance security controls with business usability considerations (password storage, MFA friction), what tech stack choices they propose, and whether they understand the organizational dimensions of the work.

Career Levels: What Actually Changes as You Advance

▶ Watch: Career level differences and sphere of influence (18:02)

Noeding drew a clear distinction between what changes — and what doesn't — as security professionals advance from junior to senior to staff and principal. Technical skill increases from junior to senior, then plateaus. A principal security architect is not dramatically more technically capable than a strong senior engineer.

What changes dramatically is sphere of influence. A junior engineer influences their immediate tasks. A senior engineer influences their team. A staff engineer influences an organization. A principal influences the enterprise — or a large chunk of it. The job transitions from doing work to guiding work, from writing code and conducting assessments to setting strategic direction and enabling others to be more effective.

Noeding acknowledged this shift is genuinely difficult. He noted that he has to explicitly protect time to stay technically sharp, negotiating with his manager to ensure he doesn't become purely managerial. At the principal level, the technical depth that got you there must be actively maintained, because it is part of what justifies the role.

The path to staff-plus, he argued, runs through becoming what he called a "specializing generalist." The alternative — becoming extraordinarily deep in one narrow area, such as cryptography — creates a very small market for one's skills. The specializing generalist is surprisingly broad (cloud, networking, compliance, application security, leadership) and surprisingly deep in several intersecting areas. Every principal-level security person Noeding works with at Adobe fits this description.

The Mechanics of Getting Promoted at Senior Levels

▶ Watch: Promotion mechanics and visibility at senior levels (26:03)

The most practical section of the talk addressed how promotions actually happen at senior levels — a process that differs fundamentally from junior-to-senior advancement.

For staff and principal promotions, the decision is not made solely by one's direct manager. Directors and principals elsewhere in the organization also weigh in on whether to endorse a candidate. If those people don't know who the candidate is, they cannot advocate for them. This is what "visibility" means in the context of promotion: not general recognition, but specifically being known by the people in the organization who will be asked whether they can vouch for you.

Noeding's practical advice: work on cross-functional projects. Collaborate with engineers outside your immediate team. Present work to leadership. Write things that people read. The goal is for your manager's peers — other directors and principals — to have independent knowledge of your contributions, so that when promotion discussions happen, you have advocates you may never have formally met.

He also recommended the book Staff Engineer by Will Larson as one of the first things he tells mentees to read. The book clarifies what the job actually is, which is different from what most people imagine it to be before they get there.

A final practical note: never demand a promotion by a specific date. The timing of promotions depends on organizational capacity, business need, and the relative readiness of other candidates. Instead, the goal is to reach alignment with one's manager on the specific criteria that would constitute readiness — and then systematically demonstrate those criteria, with someone senior enough to sponsor the path to that work.

Notable Quotes

"A career is a forty-plus year journey. I simply followed my curiosity — and the question for you is: what is your next step?"

— Florian Noeding, ▶ 02:00

"My interviews are not trivia contests. I don't have a set of fixed questions where I want exactly one answer. My interviews are conversations. I want to get as close as possible to actually working with you on a problem together."

— Florian Noeding, ▶ 12:02

"If you follow your curiosity, this hard work becomes much easier. Once you've mastered your craft to a certain degree, move on and learn something new. Rinse and repeat."

— Florian Noeding, ▶ 30:03

Key Takeaways

  • Tailor resumes to specific role types. A single generic resume signals ambivalence to hiring managers. Resumes should tell a targeted story of impact, not just responsibilities.
  • Technical interviews reward mental model clarity, not memorization. The ability to articulate precise, nuanced explanations of security concepts — and to reason through edge cases — is more valuable than knowing a fixed set of answers.
  • The jump to staff-plus is a change of job, not just a promotion. The work shifts from direct technical impact to organizational influence, strategic alignment, and enabling others. Candidates who haven't internalized this shift often struggle to make the case for themselves.
  • Becoming a specializing generalist is the most reliable path to principal-level. Broad knowledge across cloud, networking, compliance, application security, and leadership — with genuine depth in several areas — is how every principal Noeding works with got there.
  • Visibility is an active project, not a side effect of good work. Cross-functional collaboration, presentations to leadership, and written work that reaches across organizational boundaries are how the people who endorse promotions come to know who you are.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

Career advice from a credible practitioner, delivered competently, and it belongs at a LinkedIn Learning seminar rather than a security conference. The SQL injection interview hierarchy is mildly interesting for thirty seconds. Everything else is the same 'be curious, get visibility, read Staff Engineer' material floating around every mid-career mentorship channel.

Heather Calloway (CISO) — PASS

Thoughtful career development guidance from someone with genuine experience, but this is not a security talk — it is a professional development talk that happens to be delivered by a security practitioner. The content has value for its target audience; it simply has no governance or defender story for Heather to evaluate.

→ Top-rated talks at BSidesSF 2025 — Here Be Dragons

All talks from BSidesSF 2025 — Here Be Dragons