I've spent about two decades in security, and I've done most of the jobs people argue about online. Security architecture at a payments company, consulting and penetration testing, PCI work, incident response, and building an internal security program from the inside.
Then I spent four years as an industry analyst at 451 Research covering cloud, endpoint, and pretty much every category that got a booth at RSA. That's where the myth-busting habit started: once you've seen a few hundred vendor pitches, the gap between the claim and the reality gets hard to ignore.
I've also been on the other side — founding Savage Security, running product at startups like Tenchi and Valence, and starting BSides Knoxville, which has been running for twelve years. Building something is a good cure for cynicism. It's also why I'd rather help defenders fix the fundamentals than sell them the next acronym.