
A personal account by Felix Thümmler
IT security is a very broad field. Security research, red teaming, blue teaming, Incident Response, Threat Intelligence, malware analysis, bug bounties… the list goes on.
Many people working in the wider field of computer science have a general interest in IT security. However, they are often unsure where their interests and strengths actually lie and how they should take their first steps.
Yet getting started in 2025 is easier than ever. It has long since ceased to be necessary to hang around in dodgy hacker forums and chat rooms. There are various platforms available to support you on your journey from an interested beginner to a professional.
Nowhere else have I encountered such a diverse range of career paths as in the hacker community. I regularly meet hackers who previously worked in the hospitality industry, the healthcare sector or in administration. Similarly, I meet people who studied cyber security straight after leaving school and then entered the workforce.
Learning to hack
Anyone can learn to hack; all it takes is time and interest.
That’s easier said than done. But committing the time means that IT security isn’t a field where you simply complete a course and then pursue this profession for the rest of your career. It requires intrinsic motivation to engage with IT security topics outside of working hours. You need to feel the urge to understand in detail how things work, and you mustn’t be afraid of learning new things that you don’t yet understand.
Although the paths into IT security and the fields of work within this sector are very diverse, I’d like to use this blog post to give you a bit more insight into my career path.
Before I discovered my interest in IT security, I worked as a system administrator for about five years. First, for two and a half years as a Windows systems administrator. During that time, I looked after the in-house IT systems of various companies, ranging from a small start-up in Berlin to multinational corporations with thousands of employees.
After that, I spent 2½ years working as a Linux administrator in a data center. There, as part of a team, I was responsible for the operation, planning and expansion of the data center infrastructure.
Like many computer scientists, I’d once installed Kali and played around with it a bit, but that was about it.
The years crept by, and I could easily have carried on working as a Linux administrator in the data center for another ten years. They were very happy with me there, and the only challenge was regularly negotiating my salary to keep pace with my ever-increasing responsibilities and roles.
But somehow I’d always toyed with the idea of perhaps going to university one day. And the older I got, the less I could imagine studying amongst people in their early twenties whilst living on student grants. So it was now or never.
My entry into IT security
Then, about four years ago – on 14 October 2021, to be precise – I began my journey into IT security. Having just arrived at uni, an email landed in my inbox.
HTW Hackt, invitation email dated 14 October 2021
It made me think back to how often ‘success’ depends on chance. Whether you get an opportunity is usually beyond your own control. But you can be ready to seize an opportunity when it presents itself. And I didn’t want to let this opportunity slip by.
So I replied to that email and went along to a meeting with HTW-Hackt.
HTW-Hackt is a group of students at HTW Berlin with an interest in IT security. They had formed the group because the university did not yet offer a degree programme in IT security. It was there that I learnt what a ‘Capture the Flag’ tournament is and, above all, where I could further my own education.
Capture the Flag
Capture the Flag, or CTF for short, is a competition in which teams of hackers put their skills to the test.
Over the course of usually 24 or 48 hours, the organiser sets the teams a series of challenges from various disciplines. ‘Flags’ are short blocks of text such as ctf{31ne_Fl@gg3}, which can only be accessed by solving the challenge. If you then hand this flag in to the operator, you receive the number of points allocated for that task.
In the ‘Web’ category, this might involve finding a vulnerability in an online shop that grants access to the entire database. Only those who can identify and exploit this vulnerability will be able to obtain the flag.
In the ‘forensics’ section, on the other hand, it might involve conducting an investigation of a log file provided. If you can identify how the attackers gained access to a system, you’ll find the flag there too.

In these competitions, you learn from one another. If there was something I didn’t understand, there were knowledgeable and helpful hackers on hand to show me how things worked. And if you couldn’t solve a problem, the team would look at the other teams’ solutions after the competition. In this way, we learnt new tools, methodologies and tricks.
At HTW-Hackt, we foster a culture of ‘see one, do one, teach one’. Anyone who learnt something new that others were also interested in would share their knowledge. For example, I’ve run workshops on radio hacking, hardware hacking and various other topics.
Over time, we got better and qualified for various competitions at home and abroad. The ASTA supported us by reimbursing our travel expenses, which meant we were able, for example, to travel as a group to a final in Paris.

We had lots of fun and experienced some brilliant stories on these hacking trips, met fascinating people and made friends.
HTW Hackt
The aim of HTW-Hackt is to show students that hacking can be fun and can be learnt in a safe environment. We place great importance on ensuring that we only engage in ethical hacking and strive to set a good example for the students.
Every term, we organise a so-called ‘Newbie Event’, where we introduce ourselves to the students, show them how to use the learning platforms and then work with them to solve a simple hacking challenge. This Saturday, 11 October 2025, is no exception.
Most of us now work in various areas of IT security. Since joining HTW Hackt, I’ve found security vulnerabilities (CVEs), earned money through bug bounties and had a lot of fun tinkering with devices.
Some of us have ended up in red teaming and Penetration Testing, others in digital forensics and Incident Response. Some (like me) are in permanent roles, work as freelancers, are civil servants or even teach at universities and colleges themselves.
Nevertheless, we’re still in touch, hacking together, researching together and still showing newcomers the way into IT security. Just as someone once showed us the way into IT security.
Mint Secure
I’ve been part of Mint Secure GmbH since 15 September 2025.
Even though my journey here is only just beginning, I’ve already been given plenty of exciting tasks to tackle. From clients whose infrastructure I’m allowed to test, right through to Ransomware cases where we need to trace how the attackers moved through the infrastructure.
I could tell you more about it, but first you’d have to sign an employment contract and an NDA 😉
I’d also be happy to test your company – just book one of our services.
At Mint Secure, we also carry out security research. If you have an interesting topic, please feel free to get in touch with me.
This blog post has turned out to be longer than I’d originally planned. And a bit more personal, too. I hope it’s given you an idea of who I am and my career path.
Best regards,
Felix Thümmler aka Ori
How Mint Secure supports you
Our team brings experience from CTF competitions, bug bounties and the hacker community directly to our client projects. We support you with the following services:
Penetration Testing
Hackers with real-world experience and CTF training test your infrastructure, web applications and APIs for vulnerabilities.
Incident response and forensics
Following an incident (e.g. Ransomware), we reconstruct how attackers moved through your infrastructure.
Security Research
Do you have an interesting security topic? We conduct our own security research and look forward to exchanging ideas.
Conclusion
There are many different paths into IT security, ranging from traditional system administration to direct study, and it requires one thing above all else: intrinsic curiosity and a willingness to figure things out for yourself. Communities such as HTW Hackt and formats such as Capture the Flag make this entry point more accessible today than ever before.
It is precisely this diversity of experience – from CTF tournaments and bug bounties to real-world Incident Response cases – that our employees bring to their day-to-day work for our clients.
Would you like to have your infrastructure tested by experienced hackers, or do you have an exciting security research topic?
Talk to us.

