First, you have to wise up to how clueless the corporate suits are and what a clown show the corporate world is from the inside. Why should I feel bad about jumping ship?
If they're going to shuffle all their OPEX to CAPEX, they'll just be stuck with garbage security tools that generate more noise than anything useful. The security talent pool is a joke, all over the world, belive me, I've run plenty of interviews. If those are the people getting hired, then good luck to those companies, they will more than sure need it.
Then you've got bug bounties, where you're totally at the mercy of the triagers. Have fun finding a solid bug just to be told it's a 'duplicate' or even worse, they accept it and then cut the bounty in half.
From where I'm sitting, playing by the rules just isn't worth it anymore. I'm not telling anyone else what to do, but the whole situation in tech is a mess worldwide. So, you should probably expect things to get a lot uglier next year, in terms of security incidents.
10 years ago, yeah, maybe you could become a black hat with not too much repercursions, at least in Romania. Nowadays, the situations is a bit different, laws are harsher, Police is smarter (lol) and you need to be smarter than all of them. Go to Thailand, Vietnam, Philippines or Italy if you want to start your criminal career.
Something to think about, I've seen an increase of old school members coming back to this place after more than 10 years of inactivity, what does that tell you?
If you want to break the patterns, you will need to change your entire mindset, and, instead of working for some corporate jokers you should build something yourself.
Really curious on what @Nytro and @Noriega have to say on this, as I'll always consider other opinions from people which I consider to be smarter than me.
Let's not normalize layoffs, this isn't going in the right direction: