Transitioning from 7 YOE Backend Dev to DevSecOps: What do I actually need before applying?
Hi everyone,
Looking for some advice on my career transition. Here is my context: I worked as a Backend Developer for 7 years. I recently moved to a new country and I'm currently working outside the tech industry while I look for my next IT role.
To be honest, I've lost interest in pure software development. Over the last few months, I've been exploring different areas, and Cybersecurity has always been the one that appeals to me most. However, I'm not really interested in SOC operations or Pentesting. Back when I was a developer, I was always drawn to DevOps, so shifting toward DevSecOps felt like the most logical path.
Here is what I’ve done so far:
Theory & Fundamentals: Spent the last two months studying the CompTIA Network+ and Security+ material to get solid grounding in networking and security context.
Hands-on practice: I've been building end-to-end CI/CD pipelines (from Git to deployment) and I'm currently integrating static/dynamic code analysis (SAST/DAST) and pre-commit/pre-push hooks.
I’ve already checked out roadmap.sh/devsecops, but I'm looking for real-world insights and more specific advice. A few questions for the community:
What core technical skills or practical portfolio projects should I have under my belt before applying for roles?
Is it worth actually taking the exam for Security+ (or another certification) for a DevSecOps path?
What tools or practices do you consider absolute "must-haves" for someone making this transition?
Any advice, reality checks, or suggestions on my roadmap would be greatly appreciated. Thanks in advance!
[link] [comments]