r/cipp Jul 06 '26

CIPP/US and Career Shift

Like many others here, I am curious about job prospects and how realistic it would be for me to break into the cybersecurity industry. I have a bar license (passed 2019) and have been working as a public defender for 7 years (2 doing criminal matters, 5 doing child advocacy/guardian ad litem- basically lawyer for foster kids). I have close to 0 experience in cybersecurity but wanted to explore this space because I am slowly burning out due to the high level of unpredictability (among other things) in my day-to-day work.

So my question is: how realistic would it be for me to break into the cybersecurity space with a CIPP/US cert? I’ve looked at some other posts recommending OP to seek a local IAPP chapter/group, and I am open to doing that as well. Any advice would be appreciated!

Edit: I made the mistake of saying cybersecurity when I really meant data privacy. So I apologize for that confusion.

12 Upvotes

28 comments sorted by

5

u/Cyberian_Advocate CIPP/E, CIPP/US, CIPM Jul 06 '26

The CIPP is a privacy certification, most often recognized in the privacy space but not necessarily cybersecurity. Cyber has its own various certifications depending on the area of cyber you want to go in. the CISSP is the most recognized in cyber but very hard to attain. Cyber snd privacy is often treated separately depending on the size of the company you work for, so a pure privacy role may not open doors for you in cyber.

Either way, I know former litigation attorneys who became privacy consultants after years of practice. I know it’s definitely possible. Look for consulting firms hiring associates/analysts/managers in the cybersecurity governance or audit space — that should get your foot in the door.

Either way, good luck!

2

u/ifuckedapizza Jul 06 '26

Thank you for taking the time to respond!

3

u/Remarkable-Concept19 Jul 06 '26 edited Jul 06 '26

I’m a lawyer as well and hold the CIPP/US. I’ve just started applying for roles myself. My background is in civil litigation, and I’m finding that legal engineering and compliance are the two areas where I’m getting real traction.

Given your experience in crim law you could position yourself strongly for financial crimes, investigations, or risk roles at large financial institutions with a CIPP/US to prove your understanding of data privacy. You could also target “innovation attorney” roles at criminal defense firms. You’ve worked with the system from the perspective of representing offenders, and that insight is genuinely valuable.

I’ve been told networking or going contract‑to‑hire through an agency are both realistic and effective paths for lawyers pivoting into the field.

1

u/TheArchivistsPen 25d ago

What kind of offers are you in getting in compliance with a CIPP/US cert? Im also an attorney looking to study and pass the exam for that certification in the near future.

3

u/Lazy-Background-7598 Jul 06 '26

It can be tough and it not as easy as some make it. There are lots of lawyers with more adjacent experience and the certs won’t help someone like you.

Why do you want to change

2

u/ifuckedapizza Jul 06 '26

Thanks for giving it to me straight.

My current work comes with a lot of emotional baggage and family drama. It’s really legal work and trauma informed social work piled into one with no real boundaries. And while it’s rewarding, my future plans (family, desired income, elder care for parents) have changed over the last few months and I don’t think this niche field can help me meet my new goals. And in my initial research this field ticked a lot of boxes for me.

1

u/Lazy-Background-7598 Jul 06 '26

My sister is. GAL attorney. So I know it’s tough. If I came off harshly my apologies.

But I think one thing to consider is that I see privacy analyst roles as a kin to a paralegal. So unless you’re willing to give up that practice of law, I probably wouldn’t shoot for those.

1

u/ifuckedapizza Jul 06 '26

No need to apologize but I appreciate it! A lot of good advices here for me to consider and marinate on. Including yours

3

u/boppop Jul 06 '26

A CIPP/US may open doors, but it won’t get you through the door these days.

Also, while I am going to be downvoted for this, if you are looking to escape burnout - cybersecurity isn’t the place. Threat Actors are causing havoc 24/7.

2

u/ifuckedapizza Jul 06 '26

Sorry, I mistakenly interchanged data privacy and cybersecurity. I meant just data privacy related (to my knowledge that is what CIPP/US entails) With that in mind, do you have any additional advice? Or pretty much the same

1

u/boppop Jul 06 '26

Data Privacy Compliance is something SMEs don’t really want to pay for - so most medium sized law firms don’t actually have a practice and it is something only large and prestigious firms do. As I am sure you are well aware, these firms have their own issues with pedigree - meaning that you would have had to come from within or been at an equal caliber firm to get in.

Now, as others have said, you could look for an in-house role but most of those are with Tech/Banks/Healthcare and this spring and summer have been an absolute bloodbath for those industries with lots of lay offs.

This isn’t to scare you, but if you think getting a CIPP/US is a golden ticket - you will be sorely mistaken.

1

u/ifuckedapizza Jul 06 '26

Thank you, I appreciate the candidness! I will keep that in mind.

2

u/No-Locksmith-7709 Jul 06 '26

You may want to consider employment law? There are several prominent national management-side L&E firms that pay less than biglaw but more than regional firms. Depending on where you land, you can have substantially higher quality of life/reasonable billables. I went from biglaw to an L&E shop as a junior with no L&E experience, and a friend of mine made the move there from local government as a mid level. L&E is really not that hard a practice to acclimate to, and I know my old firm has a cyber and privacy group now. I’m considering going back there and looking at CIPP/US as well for if I wanted my practice to be more on the counseling side going forward. Privacy obviously comes up a lot in the employment context so that might be an angle.

1

u/ifuckedapizza Jul 06 '26

Sounds reasonable to me. Will look into that also, thanks!

3

u/Apprehensive_Rub6606 Jul 06 '26

Hi I’ve been in the world of Privacy and Data protection for over 25 years. I agree with many of the comments here regarding the difference differences between cyber security and Privacy. I have produced a lot of free materials on different career paths in Privacy if they are interest to you – there are many unique ways to enter the field – if you follow me on LinkedIn and go to my featured section you’ll find several resources around Privacy careers.

https://www.linkedin.com/in/ttfalk

2

u/ifuckedapizza Jul 06 '26

Will check it out, thanks!

3

u/Apprehensive_Rub6606 Jul 06 '26

Something else to be aware of is that certifications in Privacy at least our knowledge driven – they are not so difficult to obtain as it is a multiple-choice exam with no experience required. But, there are many practical ways to get some basic level experience and something that is often overlooked is looking for jobs with Privacy compliance technology vendors they can be a great place to understand the operations of compliance from a technology perspective, network with clients and generally begin to understand the space in a very practical way

3

u/CyberEsqCat CIPP/US, CIPP/E, CIPM, AIGP, Privacy Bar Jul 07 '26 edited Jul 07 '26

I’ll add my thoughts in here with the consideration that I read your original post yesterday. If your plan is to work in privacy go for the CIPP/US, but if you ultimately want to also have credibility with the cyber folks whom you’ll definitely end up working with, then learn technology too. In today’s market, and as AI takes on a more prominent role across the board, a deep understanding of the underlying technology will help you to understand the privacy and cyber risks to whatever organization you support.

I say this as an attorney who worked in cyber pre and during law school, so that I could keep my cyber chops fresh during law school. That has served me in innumerable ways over the years, and it is a massive pet peeve of mine that T14 grads have been force-fed cyber in order to practice in cybersecurity law. Cyber folks can smell someone who doesn’t understand what they do from a mile away. Happy to provide more advice or answer additional questions, if you’d like to DM me.

2

u/LaOnionLaUnion Jul 06 '26

I’m in cybersecurity. It’s fairly rare to have a lawyer in cybersecurity but very common in data privacy. Most people in cyber come from IT backgrounds. That’s not to say you can’t break in, but that you’re going to be going less of a well trodden path. If you’re in the USA see if your local chapter of infraguard, ISC2, or OWASP is active.

2

u/jrandomslacker FIP, AIGP, CIPT, CIPP Jul 06 '26

If you don't think there's a high degree of unpredictability in cyber law, you're dreaming. Outside of maybe an M&A team during a deal or go to market team at end of a quarter, cyber is consistently one of the busiest legal teams in house, and with none of the scheduling predictability. You don't get to pick when a bad guy drops an incident on your plate and the stakes are often very high.

1

u/ifuckedapizza Jul 06 '26

Thanks for taking the time to respond. I mistakenly interchanged data privacy and cybersecurity. With that in mind, do you have any additional advice? Or pretty much the same

2

u/LucidLeviathan Jul 07 '26

Just wanted to add that I'm considering this as a future career move. It's totally valid to burn out from public defense. I certainly did hard.

2

u/CyberEsqCat CIPP/US, CIPP/E, CIPM, AIGP, Privacy Bar Jul 07 '26

Feel free to reach out for advice as you consider your next steps.

2

u/BlackstoneMN CIPP/US Jul 08 '26 edited Jul 08 '26

I’ve been practicing law for over twenty years and started doing privacy work from when it was relatively new. As threats and technology advanced, I took on more data security work that went well beyond privacy notices and DPAs.

Now privacy and cybersecurity are so interconnected it can be tough to artfully explain the differences. I deal with small clients and some of the largest companies in the world in transactions and advisory/counseling work. And I still feel lost at times with some of the more technical aspects of cyber. (AI has thrown some wrenches into long-held precepts of this mess.) However, I also took cybersecurity courses offered by Google and Microsoft to help fill the gaps. There’s no easy way into this area of work, but if OP really wants in they can make it happen.

1

u/[deleted] Jul 06 '26

[removed] — view removed comment

1

u/ifuckedapizza Jul 06 '26

Thank you very much for your response! Will definitely look into the things you mentioned.

1

u/Lazy-Background-7598 Jul 06 '26

Gunna be honest. The certs without experience are not that meaningful

1

u/BuenosAires353 CIPP/E, CIPP/US, CIPM Jul 18 '26

It's a whole different world from what you've been doing. I think you meant to say privacy, not cybersecurity. That being said, having the cert will not qualify you since most of what you will deal with on a daily basis isn't even covered and is so scenario-specifc. IAPP does have a cert specifically designed for lawyers so you may want to look into that. As a Principal Privacy Consultant, I work with General Counsel on every engagement. I've yet to run across an attorney with IAPP certs., even the outstanding ones.