My career started with a cable tester and a ladder. As a network field services engineer at Solutions by stc, I installed FTTx infrastructure, configured managed routers at customer sites, and troubleshot connectivity issues for enterprise clients. The work was physical, technical, and immediate. If a network link went down, you fixed it or the customer called.
Within the same organization, I progressed from field engineering through IoT services and product management into leading the governance, risk, and compliance function. I served as the official SPOC for the business unit with Cybersecurity, GRC, Internal Audit, and external auditing entities. I built a team of 10 to 12 senior professionals from zero and managed continuous compliance across ISO 27001, PCI-DSS, and COPC certifications and HIPAA compliance. The path was not linear, but every step built capabilities that compounded over time.
What Field Engineering Teaches About Security
Network engineers understand infrastructure at the physical layer. You learn where cables run, how switches are configured, and what happens when a firewall rule is misconfigured. This knowledge is invaluable when assessing security risks.
Most GRC professionals evaluate controls from documentation. They review policies, check configurations in screenshots, and verify compliance against a checklist. That approach works for structured assessments. It misses the operational reality.
When I conduct a risk assessment, I think about the field engineer who will implement the control. Is the firewall rule enforceable given the network topology? Does the access control policy account for the vendor technician who needs temporary access at 2 AM? Can the backup process complete within the maintenance window given actual bandwidth constraints?
This operational perspective catches risks that documentation-based assessments miss. It also builds credibility with the technical teams who implement controls. They trust governance recommendations that account for real-world constraints.
What Product Management Teaches About Governance
Between field engineering and GRC, I spent about a year in product management at Solutions by stc. I managed cloud and IoT products, built business cases, onboarded Cloud Service Providers onto STC and Bluvalt cloud marketplaces, and worked with cross-functional teams to bring digital services to market.
Product management is about trade-offs. Every feature decision balances customer value, technical feasibility, and business viability. This framework translates directly to GRC.
Security controls involve the same trade-offs. Every control has a cost: implementation effort, operational overhead, and user friction. A GRC leader who understands business operations can design controls that maximize security impact while minimizing disruption. A GRC leader without business context tends to implement controls that are technically correct but operationally impractical.
Learning from Auditors: The Good and the Difficult
Four years of managing continuous audits taught me something about auditor dynamics that no certification course covers. The quality of an audit depends almost entirely on the experience of the auditor.
Junior auditors sometimes focus on raising observations because they need to demonstrate that they have done their job. An observation gets recorded not because it represents a meaningful risk, but because it shows thoroughness. When this happens, patience is the best tool. You build your argument logically, walk the auditor step by step through the evidence, and guide them to the conclusion. These observations are usually easy to close in the final report.
Senior auditors operate differently. They focus on core issues in the environment that actually make a difference. I had experienced auditors review some of our IoT services, and the findings they raised led to substantial improvements in the service. The audit did not feel like an obstacle. It felt like a value-adding exercise that made the operation stronger.
I go back to that story often because it illustrates what audits should be. They are not about passing or failing. They are about identifying the changes that matter most and implementing them.
The Compound Effect
Each career phase built on the previous one. Field engineering gave me infrastructure knowledge. IoT project delivery taught me team leadership and SLA management. Product management gave me business acumen and stakeholder communication skills. Combined, they make GRC work practical rather than theoretical.
When I built the governance function at Solutions by stc, I drew on all these domains. I could speak the language of the operations teams because I had done their work. I could present to executives because I had built business cases for product launches. I could design governance frameworks because I understood both the technical controls and the business processes they needed to protect.
The result: zero critical audit findings across ISO 27001, PCI-DSS, and COPC certifications and HIPAA compliance for over four consecutive years, covering a portfolio that spanned cloud, connectivity, IoT, CCTV, and enterprise IT services for 500+ employees.
The Argument for Non-Linear Careers
The cybersecurity industry values certifications and specialized experience. That focus is valid. Deep expertise matters. But cross-domain experience creates a different kind of value. It produces leaders who can connect security strategy to business operations, communicate across organizational silos, and design governance programs that people actually follow.
If you are early in your career and your path does not look like a straight line toward a CISO title, that is fine. Every domain you work in adds a lens through which you evaluate risk. The more lenses you have, the clearer the picture becomes.