After 15 years in IT, I feel completely burned out. My company merged a couple of years ago, and my three-person team has steadily inherited more responsibilities, including new deployment processes, infrastructure changes, and support for additional platforms. Some changes—like adopting infrastructure as code—have been worthwhile, while others have felt unnecessary. We are already struggling to keep our organization's infrastructure running, and now I'm being asked to take responsibility for the entire company data lake as well. That conversation was the point where I mentally checked out.
I earn enough that making a drastic career change would be difficult, but I'd like to move away from constant operations work. I've been considering a pivot into information security because it seems like a possible way to use my infrastructure background in a different role. For those who have made a similar transition, what paths did you take? Is security a reasonable direction, or are there other less operations-heavy options I should consider?
5 Answers
It can help to rebuild an identity outside work while you decide what comes next. Spend time on family, hobbies, learning, or anything that reminds you that your job is only one part of your life. You don’t have to make a dramatic career decision while exhausted; first get to a more stable place, then compare roles based on workload, autonomy, on-call expectations, and management quality rather than title alone.
Be especially careful about accepting ownership of the data lake without the authority, staffing, and budget to support it. An overloaded team accumulating technical debt creates real operational and security risk. Put the concerns in writing, ask management to identify what will be deprioritized, and don’t let an informal expectation turn into permanent 24/7 responsibility. If leadership has no credible plan to address the workload, quietly prepare for an exit while keeping your income stable.
Don’t assume security will automatically be less stressful. Governance, risk, and compliance can involve a lot of audits and documentation, while security operations can still mean alerts, incidents, and on-call work. Your infrastructure experience would transfer well, though, especially into cloud security, platform security, security engineering, or incident response. Look closely at the actual day-to-day responsibilities before choosing a role.
You may be dealing with burnout more than a permanent loss of interest in technology. Before committing to a new field, take whatever leave you can, set firmer boundaries, and give yourself time to recover. A lower-pressure role that pays slightly less may be worth considering if it gives you back your health and personal time. Infrastructure architecture, internal consulting, cloud engineering, technical writing, training, and vendor-side roles could also reduce the daily operational load without throwing away 15 years of experience.
Start by treating this as a workload and management problem, not necessarily a need to abandon your entire career. Document everything your team handles, estimate the time and risk involved, and make priorities explicit with your manager. Work a sustainable week, stop silently absorbing unlimited responsibilities, and keep a written record of requests, risks, and decisions. Management often reacts more strongly to measurable capacity, outage, and security risks than to general statements that the team is overwhelmed.
We have tried tracking the workload, but the response was essentially to automate more with AI, which then became an excuse to add even more work. My manager is also stepping down, and hiring is on hold until a new director arrives, so for now I’m mostly trying to get through it without burning out completely.

The technical side of security usually benefits from strong networking and systems knowledge. People coming from administration or engineering often have a better foundation than someone who only knows the compliance side.