This as-told-to narrative emerges from an extended conversation with Tannu Jiwnani, a 33-year-old professional who currently serves as a Principal Security Engineer at Microsoft’s headquarters in Redmond, Washington. The exchange has been carefully refined and edited for both clarity and conciseness, ensuring that the essence of her journey and insights are captured without distortion.
In June of this past year, after dedicating over seven and a half years of her career to Microsoft, Jiwnani reached a significant milestone: she was promoted to the esteemed role of Principal Security Engineer. When acquaintances or colleagues outside the tech sector inquire about what, precisely, her responsibilities entail, she often summarizes with a strikingly vivid description: “I fight threat actors.” In other words, her duty is not abstract but deeply practical—she actively confronts malicious individuals and organized groups who attempt to exploit digital systems for personal gain.
Her day-to-day efforts include combatting threats such as credit card fraud, phishing campaigns, and other fraudulent online schemes that exploit the vulnerability of ordinary users. Phishing scams, for example, bombard thousands of unsuspecting individuals each day with misleading links designed to steal sensitive data. Jiwnani’s work, however, addresses these challenges on a massive scale, aiming not only to remove individual threats but also to dismantle entire malicious infrastructures and protect countless potential victims at once.
When a truly critical issue arises—an incident that jeopardizes essential systems—Jiwnani steps into the role of incident commander. In that capacity, she ensures that the appropriate experts are brought together swiftly, that established protocols are followed meticulously, and that efforts are relentlessly focused on eliminating the immediate danger. Once the metaphorical “fire” has been put out, her team works on restorative measures that bring essential systems back online so that users, whether they are shopping online or relying on email for professional communication, can safely resume their activities. Equally important, her responsibility extends to ensuring that basic elements of daily life—such as access to credit cards, personal emails, and social media accounts—remain secure against compromise.
For those unfamiliar with the financial side of the industry, she explains that entry-level cybersecurity positions typically start at a base salary in the range of approximately $105,000. With the addition of corporate stock options and performance-based bonuses, total compensation often climbs notably higher. To aspiring professionals eager to establish a foothold in the field of cybersecurity, Jiwnani outlines five essential lessons drawn from her own career.
**1. Prepare for constant change in day-to-day responsibilities**
A major reality of the profession, she stresses, is that no two days are identical. The unpredictable nature of cybersecurity means that work shifts dramatically depending on the behaviors and strategies of online threat actors. During high-traffic shopping occasions—like Thanksgiving weekend or major holiday sales—malicious actors devise new methods of exploiting consumers’ digital transactions. One example she offers is deceptively simple yet highly effective: attempting to siphon a mere penny from every online purchase. Although individually minuscule, such activity multiplied by millions of transactions could result in massive theft. When situations like this unfold, she and her colleagues focus first on immediate containment: eradicating the attackers, securing affected systems, and guaranteeing operational continuity for legitimate users. Imagine, for instance, a doctor unable to access patient records in the middle of emergency treatment because of a cyber intrusion; such scenarios underline why preventing service disruption is critical. After extinguishing the initial crisis, her team analyzes the attack thoroughly—deciphering the pathway intruders exploited, strengthening alert systems, and implementing additional layers of monitoring to prevent recurrence.
**2. Cultivate knowledge early and engage in practical learning**
Jiwnani emphasizes that exploration should begin as early as possible. Prospective cybersecurity professionals should take advantage of the abundance of resources available: structured courses, university lectures, topical podcasts, curated YouTube tutorials, and newsletters such as TLDRSec, which consolidates valuable security insights from across the industry. Formal certifications further provide a systematic framework for learning, allowing learners to validate their expertise in specific domains. Yet theoretical instruction alone is insufficient. Practical exercises, such as Capture the Flag (CTF) challenges, allow one to experiment in safe, gamified environments, breaking into mock systems and sharpening defensive instincts. Tools like these simulate the pressure and creativity required in real-world incident response. While Artificial Intelligence has automated aspects of detection and enhanced analytical precision, it simultaneously introduces fresh risks, as adversaries now leverage AI capabilities for more sophisticated attacks. Jiwnani’s advice is clear: before experimenting with cutting-edge AI-assisted tools, learners must master the fundamentals of computers, networks, and security principles. Finally, human connections remain a critical element of success. Attending local meetups, industry conferences, and internships offers both inspiration and opportunity. More often than not, it is the strength of relationships—with mentors, peers, or industry professionals—that opens doors to early career advancement.
**3. Understand that traditional career paths are not mandatory**
Reflecting on her personal journey, Jiwnani highlights that her career trajectory into cybersecurity was anything but conventional. She did not begin her professional life in a technical role but in business analysis within the airline industry. Later, she transitioned into data analysis, focusing specifically on anti–money laundering processes, before gradually finding herself immersed in building tools for cybersecurity. Eventually, she moved into a formal incident responder role. At the time, her motivation was not specifically to become a cybersecurity expert; instead, she was simply exercising her strengths in IT and program management, searching for new challenges as her career evolved. Then came a pivotal moment: someone recognized her potential and extended an invitation to join their security organization as an early-stage practitioner. The learning curve was steep, but her ability to remain resourceful, deliver results even in ambiguous environments, and demonstrate resilience secured her advancement. Others may pursue more traditional education pathways: degrees in cybersecurity, computer science, or information systems, often complemented by specialized courses in digital forensics, incident detection, and threat intelligence. Yet Jiwnani’s example proves that a diversity of backgrounds can be equally valuable in reaching success in this space.
**4. Embrace remote flexibility, but recognize the value of community**
One of the rewarding aspects of working in cybersecurity, particularly at large corporations like Microsoft, is the flexibility of location. Many of Jiwnani’s teammates operate from diverse locations such as Dublin, Utah, or small towns across the United Kingdom. For much of the work, physical location has little impact on professional effectiveness. However, she notes that being part of a physical or virtual community of peers provides indispensable benefits. For example, during high-pressure moments that extend late into the night—sometimes until three o’clock in the morning—the solidarity of colleagues, whether side by side in an office or connected digitally, helps alleviate isolation and stress. While remote work allows extraordinary independence and efficiency, in-person interactions allow for human connection, collaborative problem-solving, and even shared humor, which collectively strengthen resilience. Jiwnani enjoys the balance that comes from being able both to work from home and to participate in dynamic in-office collaboration, where team members overcome obstacles together.
**5. Develop the resilience to thrive under pressure**
The final and perhaps most critical attribute of a successful cybersecurity professional, according to Jiwnani, is the ability to maintain composure in environments of extreme stress and unpredictability. Incident response often means orchestrating order amid chaos, ensuring that each individual in the room remains calm and effective, even when facing the possibility of widespread disruptions. If panic seeps in, productivity collapses. The skill of prompting clarity amid confusion does not come from university lectures; it emerges only from experience, deliberate practice, and repeated exposure to urgent crisis scenarios. Part of this composure also involves humility—the willingness to acknowledge limits and to ask questions. A frequent mistake she has observed is hesitation to request guidance for fear of appearing uninformed. Ironically, the moments of greatest vulnerability, when the stakes are highest, are precisely when proactive inquiry and collaboration prove most valuable. She encourages aspiring security professionals to be bold, to ask questions, and to blaze the trail where others might hesitate. The payoff is deeply rewarding. Few jobs, she reflects, provide such immediate evidence of impact. Restoring someone’s access to their email inbox, preventing a fraudulent transaction, or recovering stolen credentials offers instant affirmation that the effort exerted has tangibly improved another person’s life. Despite the intensity, long hours, and frequent unpredictability, this sense of direct contribution makes the work profoundly fulfilling.
Through her insights, Jiwnani reveals an inspiring story of growth and resilience in a field that demands both intellectual rigor and human adaptability. Her journey not only illuminates possible routes into cybersecurity but also underscores that thriving in the profession is less about following a rigid formula and more about developing expertise, building connections, staying adaptable, and strengthening the capacity to remain clear-headed when it matters most.
Sourse: https://www.businessinsider.com/microsoft-principal-security-engineer-shares-how-get-into-cybersecurity-2025-9