However, and this is mostly for the sake of others reading this, be aware that the security industry has its own versions of the problems mentioned affecting the academic environment, and these versions are in most cases way worst than in academia. With the exclusion of some enlighten cases (which most often coincide with a good financial situation that allows for teams that do cool stuff without too-pressing metrics on the immediate business), in private companies literally everything is driven by money and to that one must add up that the incentives that the people part of the companies have (to this: in private companies the turnover is way higher than in academia). Some examples:
- Papers that don't deserve to be written? wait for that endless stream of tasks that does not deserve to be done that way (but need to be done that way the same, because <reason-you-cannot-argue-against>).
- Optimizing for the wrong things? wait for words like "cost-effective" to pop up.
- Move away from very cool stuff? yeah, that does not happen because the cool stuff are not even on the table, unless they can bring in money fast.
- Non peer-review things dismissed? wait for not-approved-by-manager-X or not-in-the-agenda-of-key-person-Y or subject-to-approval-of-Z-who-cannot-possibly-even-understand-the-value-of-that.
- No time for tech stuff? sorry, that doesn't change much unless your job is highly operational (which you won't enjoy much because it will have to be "cost-effective", thus most likely repetitive and metrics-based).
I'm not saying that every private company is a circle of hell in the security industry, but unfortunately most have far harder-to-deal-with problems than those listed for people looking for things like the author. Afaik, the common big difference is you get paid more and you see real-world cases as they happen.
(edit: formatting)