This article “as told to” is based on an interview with Prerit Pathak, a 28-year-old security engineer at Google in New York City, and the content has been edited for length and clarity.
I think some people mistakenly assume that "tech professionals" are synonymous with software engineers. However, I have always been fascinated by cybersecurity.
When I was a child, I often jailbroke my devices to enhance their functionality, and I remember that very clearly. For me, hacking meant making something do something it wasn’t originally designed to do. It’s an art of working within the boundaries—challenging the assumptions of its creators and turning the seemingly impossible into possible.
Although I am very interested in this matter, the beginning of my career was as a software engineer at Dell Technologies in India.
Compared to software engineering or artificial intelligence, I believe that in the field of cybersecurity, there is less availability of mentor resources and less transparency regarding 'daily work' for those who wish to enter this field, which makes it more difficult for individuals to relate to and immerse themselves in this role.
I believe that the AI era has made the demand for cybersecurity positions very strong, and I am also very happy to have finally returned to this field again.
Cybersecurity is no longer just a side hobby or interest.
During my undergraduate years, I honed my security research skills through courses, self-study, and by participating in the " Capture the Flag " flag-raising competitions. However, at that time, I was still figuring out which career path I truly wanted to pursue.
At the beginning of my senior year, I got a software engineering position at Dell offer. It was a great opportunity, so I decided to accept it. Later on, this experience in software engineering became a solid technical foundation for my career.

During my time as a software engineer, I discovered a vulnerability on a public website and reported it to the website management team, along with suggestions for fixing it. Later, by continuing to do this kind of work, I received letters of thanks and recognition from top universities and institutions for disclosing this critical vulnerability. Seeing that security research can have a tangible impact inspired me to devote myself to this field.
During my time at Dell, I also established a local chapter of an organization that focuses on global application security ( Open Worldwide Application Security Project, OWASP ), which is a non-profit entity dedicated to network security. As part of this chapter, I invited speakers from all over the world to give presentations.
At this point, I decided to pursue my postgraduate studies at Carnegie Mellon University because I wanted to specialize in information security and delve deeper into the subject. A top-tier institution like Carnegie Mellon meant that I could be among many people from whom I could learn, and I also hoped that this would help me transition into the field of network security.
I moved to the United States and eventually found a job at Google.

In 2021, I moved to the United States to begin my postgraduate studies, and then in the following summer, I completed an internship in security engineering at Google. The internship experience was very good, but there were no positions suitable for my level in my team at that time, so I returned to school to complete my degree.
In 2023, two months after obtaining my master's degree, I joined Google's New York office and became a full-time employee.
My internship at Google and my graduate courses were important parts of this transition, but I also believe that activities outside of work are equally helpful. I applied for two patents, one of which stemmed from work I completed with my team members during my internship at Google. These experiences, along with the thank-you letters I received, have helped to demonstrate what I can do in the field of security.
Now, as a security engineer, I create and run threat simulations to replicate the behavior of adversaries in a corporate environment. The most time-consuming part is usually analysis and reporting, which involves analyzing the test results mentioned above, piecing together what was observed into a coherent narrative, and finally compiling it into a report.
My suggestions for entering the field of network security
Before being hired by Google, I attended meetings, learned from mentors in the security industry, and submitted my resume to several companies only to be rejected. I learned something from each of these experiences. I strongly support the philosophy of "moving forward through failure." When you create opportunities for yourself, luck will also come your way.
Networking is certainly helpful in discovering opportunities, but in my opinion, being well-prepared and truly doing a good job is even more crucial. I remind myself that an interview is a conversation between two people, and the interviewer is on your side. Asking clarifying questions before answering can increase the likelihood of giving a good response. I also suggest thinking while speaking, so that the interviewer can understand your train of thought and, in some cases, they can even guide you in the right direction.
I suggest focusing on developing communication skills, because an excellent security engineer should be a compassionate partner who can convey technical risks to management while not diminishing the seriousness of high-risk situations.
I think it's also important to understand what cybersecurity work really entails. When I was looking for a job, it was difficult to gain any insight into what the cybersecurity profession actually involves. Connecting with others in this field has helped me learn and build my own path.
In retrospect, shifting from software engineering to cybersecurity was a leap of faith for me. I am extremely grateful that I made that decision.
as told to
Careers
More
Tech
Cybersecurity
Big Tech
Jump to
Main content
Search
Account
Jump to top of page












