“Position in band” is often a factor in performance reviews. Consider a common process - say you’re “senior level” and in your review you’ll be rated on six categories, then given a raise based on where you are overall relative to “meets expectations.”
If you’re senior but at the bottom of the senior band, and you’re mostly “at expectations” for your level but maybe “slightly below” in 1-2 categories, you’ll probably still net out at “meets” with a normal raise. If you’re senior but the highest paid senior - that’s probably going to net out at “below” overall, or zero-to-small raise.
The OWASP nonprofit isn’t like the well-funded Linux Foundation; it runs on a shoestring budget made worse by the loss of conference revenue during the pandemic. OWASP charters events, local meetups, training content and OSS projects - the authors of this memo focus only on the OSS project needs. The OWASP board sees itself as community first and foremost; projects should seek their own sponsorships.
Lots of stuff in the comments already about dual-track and external career options.
I'd add: can you hire a deputy who enjoys doing this?
* Ask for the next project management hire to be a true TPM, and try to pull someone who's working on something boring but is really interested in getting into your area of technology. Have them run all the Jira, summarization, execution of planning processes, comms & coordination. You'll still need to own hiring, still need to do a lot of people development work and still have to get involved in marketing & product strategy - but might get some leverage in internal pieces you don't like.
* Promote or hire another person who shows interest and aptitude in management, with the explicit plan for them to be your deputy and to take on some of the "tasks you don't really enjoy," especially if scoped to a specific area. Can you structure your work so someone else is responsible for 50% (or even more) of it? Can they do the RFP first-pass reviews, and even be responsible for pushing back on things in their area of responsibility? Can they manage some of your directs, and co-lead some of the above processes within their scope? There might be someone on the team who feels underutilized, wants more visibility, has strong relationships and is willing to learn. And if there's not - that's signal for you and your hiring process that maybe you've only hired folks like you; it may be time to have a broader set of folks on the team.
Several of the concerns revolve around the complexity of managing multiple IDs (product SKUs, prices, etc) for a single subscription - and the author reaches the conclusion that this is because it's optimized for "e-commerce and not B2B SaaS".
While from the buyer's perspective, "single negotiated cost with overages" may appear simple - it's a single bill after all - on the accounting side for the company selling the product, I'd expect it's much more complicated; with potentially different tax rates for different products and complexity around producing an auditor-defensible determination for "cost of goods sold" and "marketing expense."
So for at least some of these requests, I see Stripe's posture here as helpful - it's not "requesting a dollar figure", it's "creating a detailed enough accounting trail behind that bill to operate your business." Looking across the breadth of Stripe's products, I'd give them the benefit of the doubt here.
Her speech early in the Covid-19 era was one for the ages[1]: Short, personal, reflective of history yet with a clear call-to-action for her country. I'm not British and also found it exceptional.
I'm long past my academia phase, but recently led the PC for an industry conference (accept rate: ~15%).
1. Curation is important both for the physical limits (venues only fit a certain number of people), attention limits (attendees will usually retain only a handful of "nuggets" no matter how packed the agenda is) and interaction limits (you can't meet everyone at a large conference).
2. If the goal of a conference is not just to "stamp" research as somehow "approved", but to encourage discovery and knowledge exchange that deepens a specific area, it's important to apply that curation filter with an eye toward best advancing the goals of the conference. That means not just going for things that are okay, but those that best resonate with other presentations / attendees / research topics.
3. While the size of any one conference has to be fixed, tech has made it infinitely easier to create new conferences and journals with other focus areas. They may not start with the prestige of a larger journal, but if the papers published start to have an impact, it can catalyze an entire subfield of work.
Some conferences can be tied exclusively to "novelty" - ACM academic conferences - but others to "incremental advancements" - the bigger industry conferences in security, like Usenix Security and some to "best explaining ideas" - like Enigma.
There are new ways to find an audience for your work and create impact - that's part of the job now.
Found headspace helpful but only really noticed after a month where I made time for it every morning. In particular I appreciated some of the techniques in different courses - different forms of attention and focus, noting, visualization. My consistency has fallen off and I can see an impact on ability to find and stay in flow; but even without a regular practice I find I’m more aware of when and how I get distracted and don’t fall quite as far away from it.
And [2], from Roy Rapoport on a five-step process for dealing with problems.
In both cases, it’s not enough to say you “don’t trust” your team. You have to do the work to diagnose WHY things aren’t working the way you want - do they see there’s a problem? Do they want to fix it? Do they have the skills?
Trying to fix a problem you can’t diagnose is going to be very hard.
One and only one data point: the handle allowing the chair to move forward and back broke 2 months ago, about 6 months out of warranty. (Great for my partner, who now has exclusive use of the bike in her position… not so good for me.)
Support originally wanted to charge me $250 for replacement and service. A few YouTubes and a second call, the service person admitted that a $5 part would probably do the trick.
It’s taken two full months from that support call to get the shipping notification on that part.
Other than that, though - my experience with the bike and classes has been positive.
In a sense, the US government does the same thing. In the US tax code, you can can deduct business expenses to reduce taxes — ie, subtract expenses for a corporation you control from your personal income. This has been known be abused, as folks deduct their personal car, house, travel… as a result, if you have a business that goes long enough without a profit, the IRS will look really hard at it to make sure it’s not really leisure.
OAuth tokens used in automation tools will continue to work. Entering in username & password through auth, to automate an OAuth flow (or any other traditionally manual flow) will stop working. Breaks some puppeteer scripts too - but those have been getting flaky for a while now.
Sounds like you've mostly worked in perfectly-sized and structured corporations, where the auditors and policy-writers were perfectly connected to changing product, business and technical needs; well-staffed with policy writers and architectural governance committees who have the time, skill and background to have regular, even-handed tradeoff conversations when these issues occur, and where the engineering teams are prepped and able to engage in those conversations well.
An auditor's job is often to check if you're doing what an external standard says you should be doing (SOC 2 => AICPA trust principles; FedRAMP => NIST 800-53, etc.).
Unfortunately, these external standards may be written vaguely and while you may have policies that define X as Y, the auditor doesn't have to accept your answers. For example, when PCI requirement 5 says "Deploy anti-virus software on all
systems commonly affected by malicious
software (particularly personal computers
and servers).", your policy may say "antivirus is not required inside containers that run on platforms like GKE, as these are not commonly affected by malicious software." It's very likely you'll have a discussion about your interpretation of that requirement.
In the Americans with Disabilities Act, US law states that if you're going to create a place of public accommodation, there are certain minimum standards you must adhere to, to support those with disabilities. So you must install ramps and elevators for the mobility-impaired, offer audio-only interfaces for the blind, sign for the hearing impaired, and so on. These apply pretty broadly.
We can argue whether Australia's legislation is a good thing, but "if you are going to operate here, these are the standards you must follow" is not beyond the pale.
The thing that made this bug possible was because, while your Apple ID has to be an email address, Apple has a mechanism to avoid exposing it to third parties - unlike Google, Apple, or Facebook's single sign-on implementation; the bug seems to be in the step between verifying your identity and telling Apple whether you would or would not like your email address to be exposed.
If anything, the issue is that third parties treat the email address as a unique, unchangeable identity, and then agree to rely on Apple's assertion of what your email address is. But given how hard identity is - and the challenges in dealing with passwords, account recovery, and name changes at scale - it's a pretty reasonable tradeoff to make.