The honest answer is: it depends on what you're actually looking for, not on generic "the field is growing" statements you've probably already heard. Here's what to weigh for yourself.
Persistent demand is a genuine strength — the skills shortage in this field is well documented across the industry, and that demand shows no clear signs of disappearing given how much more digital infrastructure businesses depend on every year.
The field also offers a wide range of specializations, from offensive testing to compliance to incident response to secure development, so there's real room to find a niche that fits your specific interests and strengths rather than being locked into one narrow path. Remote and flexible work arrangements are also more common here than in many other technical fields.
It's a continuous-learning field — threats, tools, and techniques change constantly, and stagnating is a real professional risk in a way it isn't in some more stable technical disciplines. If you're looking for a role where you learn a fixed skill set once and coast, this isn't it.
Some roles, particularly incident response, involve genuine high-pressure, after-hours work when something goes wrong. And despite real demand for experienced talent, entry-level competition is genuinely stiff, since the field attracts a lot of interest from people drawn to its reputation without fully weighing what the day-to-day work actually involves.
If you're energized by solving puzzles, comfortable with ongoing learning as a permanent feature of the job rather than a phase, and can handle some ambiguity in your day-to-day work, it's a strong fit.
If you want a role with predictable hours and a fixed skill set that doesn't change much over a career, it may not be. Being honest with yourself about which of these describes you will save you a lot of frustration down the line.
No — career changers are common in this field, and prior experience in adjacent areas like IT, compliance, or software development is often a real advantage, not a setback.
Roles like compliance, audit, and security awareness training tend to have more predictable schedules than incident response or active threat monitoring, which can involve on-call responsibilities.
It can, particularly in high-pressure roles like incident response, but it's not universal — the range of specializations means you can often find or move toward a role with a pace that fits how you want to work.