Core learning screen

Mei Li

From B.Tech IT Student to Security Engineering Lead

Last updated: Jan 19, 2025

Cybersecurity Engineer in Cybersecurity

Cybersecurity engineer turned security engineering lead. This career journey covers SOC night shifts, my first major incident, and how a tier-2 college background became an advantage in adversarial thinking. Written for anyone weighing security as a path.

Career Timeline

  1. Education2011-2015

    B.Tech IT Student

    Tsinghua University

    Joined every CTF I could find. Built a Raspberry Pi honeypot in the hostel as a final-year project. Spent more time on TryHackMe than on classes.

    Show more
    ContextJoined every CTF I could find. Built a Raspberry Pi honeypot in the hostel as a final-year project. Spent more time on TryHackMe than on classes.
    ChallengesCollege syllabus on security was a decade out of date. Self-study took over.
    LearningsCuriosity beats certification. A persistent CTF habit will teach you more than a brand-name internship.
    Skills acquired
    NetworkingLinuxOS internalsbasic cryptoethical hacking labsCTF teams
  2. First Job2015-2017

    SOC Analyst

    Capgemini

    First job was a 24x7 security operations centre rotation. Most shifts were boring; the few that were not, I will remember forever.

    Show more
    ContextFirst job was a 24x7 security operations centre rotation. Most shifts were boring; the few that were not, I will remember forever.
    ChallengesSleep schedule destroyed for a year. Senior analysts gatekept knowledge until you proved you cared.
    LearningsPattern recognition is muscle memory. Most alerts are noise; the one that matters does not announce itself.
    OutcomeCaught a credential-stuffing campaign that the dashboard had missed. Trust earned, transferred to threat hunting.
    Skills acquired
    SIEM (SplunkQRadar)incident triagelog analysisMITRE ATT&CKnight shifts
  3. Promotion2017-2019

    Threat Hunter

    Capgemini

    Moved from reactive SOC into proactive hunting. Half the role was technical, half was writing reports executives would actually read.

    Show more
    ContextMoved from reactive SOC into proactive hunting. Half the role was technical, half was writing reports executives would actually read.
    ChallengesConvincing leadership that "no incident this week" was the product, not the absence of work.
    LearningsAdversaries do not care about your org chart. Defenders should not either.
    Skills acquired
    EDR toolsscripting in Python and PowerShellthreat intelligencereport writing
  4. Career Switch2019-Present

    Security Engineering Lead

    Microsoft

    Switched from a services firm to a product company. Less ticket work, more design. Now I help engineering teams ship safely instead of cleaning up after them.

    Show more
    ContextSwitched from a services firm to a product company. Less ticket work, more design. Now I help engineering teams ship safely instead of cleaning up after them.
    ChallengesEarning credibility with developers who saw security as a blocker. Learned to be a partner before being a gate.
    LearningsThe best security work is invisible. If the team did not feel us this sprint, we did the job well.
    OutcomeBuilt a paved-road platform that cut critical findings by 60% within a year.
    Skills acquired
    Cloud security (AWSAzure)IAMthreat modellingsecure SDLCleadership
    AdviceGet one cert that opens doors (Security+, OSCP) and then stop collecting them. Build instead.

Mark if this helped you understand the journey.

Reflections & Questions from Readers

Share a thought, relate an experience, or ask a question. Reflections appear once reviewed (usually within 24 hours).

20-1000 characters

No reflections yet. Be the first to share what this journey sparked for you.

Inspired by this journey? Share your own →