• 1 Post
  • 27 Comments
Joined 2 years ago
cake
Cake day: June 18th, 2023

help-circle
  • Say I’m from country X and I make widgets for $10 each. The US decides to put a 25% tariff on goods from country X. That means that each time I want to sell a widget in the US, I need to pay 25% of its value as a tax. If I was only making a 25% profit on each widget, that means I’m now breaking even on each widget and not making any money. That won’t work for me, so I raise my widget prices to, say, $14. Now I have to pay 25% of that, or $3.50, as a tariff, which leaves me pocketing $10.50, which is about what I was making before. Widget manufacturers in the US don’t have to do that, so their prices stay much lower than mine, so presumably they get more sales and the US economy is strengthened.

    The problem is, the US is not a manufacturing superpower anymore, and even for the things that are manufactured here, most of the raw materials come from overseas. So the only thing these tariffs are going to do is drive up the price of everything. And once those prices are up, they’re not going to come back down, even if the tariffs are removed; in my scenario above, it’s likely that when I raised my widget prices to $14, all the US widget manufacturers would just raise their prices to $13 and make a bunch of extra money.

    Long story short: more money getting siphoned out of the pockets of the working class.

















  • Hey all! I’m trying to figure out where I go next in this career. I’m working at a mid sized company that is owned by a company that is owned by another company. Started out as a software dev about right years ago and spent a lot of time as a security champion; finally moved to the InfoSec team about two years ago. It’s a small InfoSec team: three people total. So I do a lot of stuff: contact reviews, vendor security assessments, firewall log monitoring, code reviews, run security trainings, coordinate external pen tests, gather SOC 2 evidence, incident response… Lots of stuff.

    I like most of the work well enough (though the GRC stuff is not my favorite), but recently my boss and my teammate quit, so our team of three is down to me. There’s some support available from the security team of the parent organization, and a very competent contractor, but it’s largely just me.

    What I’m wondering mostly is: if I go elsewhere, what kind of role am I looking for? I feel like this Jack-of-all-security-trades thing I’ve got going on can’t be super normal, can it? And also, is my current situation something I should embrace, and take the opportunity to run the InfoSec team? Having someone with two years of security experience at the wheel seems suboptimal to me, but maybe it’s worth doing for the experience?

    My ideal would be working with a team of five or six, with people I can learn a lot from; my concern is that right now, most of the learning I can do is from my own mistakes.