Home › Blog

The Five Stages of DevSecOps Grief (And Why the Therapist Was a YAML File All Along)

Let's talk about the psychological journey. Because that's what this has been. Not a technology evolution. A collective trauma response dressed up as a methodology.

The Infrastructure Engineers

First came the Ops people. The originals. The ones who understood that production is a haunted house and every deployment is walking in barefoot. They didn't need a manifesto. They had pagers. They had 3am calls where the answer was always DNS. They built the thing, they ran the thing, they got blamed for the thing.

Then someone said "Infrastructure as Code" and they felt seen for the first time in their careers. Finally. Codify the suffering. Version control the pain. At least now when it breaks at 3am you can git blame someone specific.

Psychologically? This was the acceptance phase masquerading as innovation. They'd always been doing the work. Now they had a language for it that made the developers stop looking through them in meetings.

The Developers

Ah, the developers. Bless them.

The developer psyche is a fascinating study in cognitive dissociation. "It works on my machine" isn't a meme. It's a defence mechanism. A beautifully constructed psychological boundary between the self and the consequences of the self's actions. Freud would've had a field day.

DevOps was supposed to break that wall down. "You build it, you run it." And for about fifteen minutes it worked. Then they just automated the dissociation. CI/CD pipelines became the new "it works on my machine" — except now the machine was everyone's machine and the blame was distributed across a YAML file that nobody fully understood but everyone committed to.

The developer relationship with security has historically been one of avoidance attachment. Security is the parent who says no. The one who makes you eat vegetables. So when someone whispered "shift left" they heard "shift away" and carried on pushing to main like nothing happened.

The Security People

My people. And I say this with love and clinical detachment.

Security practitioners have been operating in a state of chronic hypervigilance since approximately 2004. Every year is "the year of the breach." Every conference is "we need to do better." Every vendor pitch is "what if you could see everything?" as if omniscience was ever the problem. The problem was always that we could see everything and nobody listened.

The security psyche is fundamentally one of Cassandra complex — cursed with foresight, punished with irrelevance. We've been saying "put security in the pipeline" since before the pipeline existed. We wrote policies that nobody read. We ran scans that generated reports that generated emails that generated meetings that generated action items that generated more policies that nobody read.

-As-Code was supposed to be our liberation. Security as Code. Policy as Code. Compliance as Code. Everything as Code. Did I mention Everything as Code? Because apparently if you can't express your existential dread as a Terraform module it doesn't count.

And yet. For years. DevSecOps was just DevOps with a security logo on the deck. The "Sec" was silent. Like the 'k' in knife — technically present, functionally ignored, and occasionally dangerous if you forget it's there.

The Vibe Coders

Now we arrive at the newest entrants to the grief cycle. The post-AI generation. The ones who learned to code by prompting, who build by vibes, who ship by velocity, and who have never once manually resolved a merge conflict because Claude did it for them.

I'm not mocking them. Well. Not entirely.

What's psychologically interesting about the vibe coding cohort is that they exhibit classic Dunning-Kruger acceleration. Not because they're stupid — they're not — but because the tooling has compressed the time between "I have no idea what I'm doing" and "I have deployed to production" from years to hours. The unconscious incompetence phase now lasts about as long as a coffee break.

And then reality arrives. The app works. The app scales. The app gets breached. And suddenly they're standing in the same haunted house as the Ops people, barefoot, at 3am, and the LLM is confidently suggesting they check the DNS.

The Code Doomers

Every psychological ecosystem needs its depressive realists. The Code Doomers serve that function. They're the ones posting "software engineering is dead" while actively committing code. The cognitive dissonance is chef's kiss.

What they're actually experiencing is anticipatory grief — mourning a professional identity that hasn't died yet but feels terminal. And fair enough. When the junior dev next to you ships in an afternoon what took you three sprints, the narcissistic injury is real. The defence mechanism is doom. If I declare it dead first, I can't be killed by it.

But here's what the Doomers miss: the code was never the point. The judgment was the point. Knowing what to build, why to build it, what not to build, and what happens when it breaks. That's not going anywhere. That's just wearing different clothes now.

The Newly Born Test Engineers

And then — beautifully, inevitably — the testing renaissance.

Because when everyone can generate code at the speed of thought, the only thing that separates "shipped" from "catastrophe" is whether anyone checked. Vibe coding produces vibe bugs. AI-generated code produces AI-generated vulnerabilities. And suddenly the person who knows how to write a proper test suite isn't the boring one at the party anymore. They're the designated driver and everyone's grateful they exist.

The test engineer psyche is undergoing a status renegotiation unprecedented in software history. From "QA is where careers go to plateau" to "you're the only person who actually knows if this works." That's not a job title change. That's a psychological reframing of an entire discipline's self-worth.

So have we finally reached the DevSecOps era?

Honestly? Maybe. But not for the reasons anyone predicted.

Not because we got the tooling right. Not because we wrote enough -as-Code. Not because a vendor finally cracked the integration problem.

Because AI broke the old excuses.

Developers can't claim security is too hard when the AI writes the fix. Security can't claim developers won't listen when the pipeline enforces the policy automatically. Ops can't claim they weren't told when everything's in the commit history. Testers can't be ignored when the velocity of generation demands the velocity of verification.

The psychological barriers — the avoidance, the dissociation, the hypervigilance, the blame distribution — they're all still there. Humans don't change. But the architecture has changed around them. The seams between Dev, Sec, and Ops aren't just thinner. They're codified. Enforced. Automated.

DevSecOps was always a psychological contract more than a technical one. And like all contracts, it only works when the cost of breaking it exceeds the comfort of ignoring it.

AI just made ignoring it very, very expensive.

Welcome to the era. Finally.

Shoes optional. It's still a haunted house.

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

Originally published on LinkedIn ↗

← All writing