Soft Skills Engineering - Episode 19: Firing someone for a coding mistake and getting demoted

Episode Date: July 25, 2016

In episode 19, Jamison and Dave answer these questions: Would you ever fire someone over a coding mistake? For example, should you empathize with ignorance and explain how SQL injection works or is ...the mistake so basic as to be intolerable. Would you change your answer if the mistake was found during a code review or found as the source of a data breach? How do you positively represent the desire to be demoted? I am called a ‘senior engineer’, but I got that way because of null instead of actual skill. I would like to be a senior engineer at some point, but I would be a better one if I travel more where I have seniors to look up to, established processes etc rather than stressing about defining everything myself; but that’s a weird thing to say to a current or potential boss and is hard to do without also volunteering for a pay cut.

Transcript
Discussion (0)
Starting point is 00:00:00 It takes more than great code to be a great engineer. This is Soft Skills Engineering, the podcast, with your host here, Dave Smith. I'm your other host, Jameson Dance. Welcome, ladies and gentlemen, once again. It's another great day on the podcast. I feel like there's an intro voice that every podcast has, and it's different from your regular voice.
Starting point is 00:00:22 Why do you think that is? Because you're just so excited. That's true, yeah. Hey, let's get this thing started. It's your drive time morning commute, and we're ready to go it's your morning show voice yeah uh yep do i you're saying i have one of those i think we both do oh geez now i'm gonna be self-conscious i'm sorry but yours is good oh phew well uh we have a couple of questions today i think do you want me to read the first one i
Starting point is 00:00:53 would i would love for you to read the first one so this is from a listener named would you ever fire someone over a coding mistake for example should you empathize with ignorance and explain how sql injection works or is the mistake so basic as to be intolerable would you change your answer if the mistake was found during a code review or as the source of a data breach little bobby tables yeah i think we both agreed pretty heartily on this like no with a little asterisk, right? Do you want to talk about your philosophy about this? Yeah, so I would say that
Starting point is 00:01:32 if you're working for a company with an organization or a process where one mistake like this can turn into, by one person, can turn into a huge disaster, then I wouldn't generally blame the person. I would blame your process or your organization. You know, like where was the code review on this? Where was the QA on this?
Starting point is 00:01:50 Where was like any kind of like training? you know i mean how did this get out into the wild or maybe you are the only person then you can't be fired because you're the boss it's fine so that's my first response the question mentions code reviews and in my mind code reviews are are to help you identify and fix those mistakes so they're serving their purpose if they're finding mistakes if if i got fired for mistakes in code reviews then yeah if you don't have why would you have code reviews if you're not expecting mistakes right um also like if you choose bad tools um sql injection for example is a totally solved problem and if you choose the wrong tools for the job uh then sql injection
Starting point is 00:02:36 is possible so you should almost fire the person who chose that tool you know yeah actually i'm still not suggesting even firing that person fire the person who chose that person every time there's a mistake in the code review that's caught you get a new ceo because ultimately they are responsible for the whole organization minus one new ceo no i think i agree with your basic premise that is people don't work in a vacuum and people make mistakes and part of the purpose of an engineering organization is to prevent those mistakes from ruining your business and it's it's really hard to blame one single person um either if you don't
Starting point is 00:03:27 have any processes then it's not that single person's fault or if you do and then they fail like then look at your processes and maybe they maybe they could get better yeah yeah it also depends on whether it was exploited you know like if you put out an sql injection that doesn't automatically mean that someone's going to take advantage of it right away and if they don't and you find it and fix it then no harm done right but if someone takes advantage of it and like i'm going to ask you this james and let's say i put out an sql injection vulnerability in my code and then a hacker gets onto it figures it out and uses it to like do a massive data breach or you know change customer data do something really really bad for my business um then what is it
Starting point is 00:04:09 different uh i i think i i still will stick to my guns that um that's an organizational failure not an individual failure i don't see why the consequence of it is different i guess maybe there's PR that goes into that and the company trying to save face and people kind of get sacrificed to appease people that are mad and if your junkie website ended up with me
Starting point is 00:04:42 having my identity stolen or my bank account compromised or something I would be super mad about at your junkie website and would demand action you know but I don't know that firing someone who makes a mistake communicates the best thing to the engineering organization.
Starting point is 00:05:06 Because, well, now that I'm saying that, I don't know, maybe it makes you a lot less likely to make a mistake. Well, I don't know. If you found out somebody got fired and then... I mean, let's say you do that. You fire the one person who wrote the mistake. That is, by the way, the person that is least likely to ever make that mistake again.
Starting point is 00:05:24 Yeah, I know. Well, I was going to say they're going to go and examine their lives and figure out how the hometown of their birth affected the line of code that they typed and what they could do to change it. Huh. Yeah, I think the key is your organization needs to get better in response to mistakes. And in most cases, I don't see how firing could make that happen. Because it seems like you'd want to encourage vulnerability and admitting not knowing something. maybe this person made a mistake because they were scared to ask for help that they saying they didn't know like i mean they maybe they didn't even know sql injection was a was a thing that
Starting point is 00:06:03 could happen and and they didn't ask for help because they wanted to show off like all the awesome stuff they could do by themselves and then they just pushed this out they just pushed this out uh and then if they're fired like it's gonna clamp down on people's openness make it even worse you know maybe you already have a culture where people are afraid to ask questions and then they get fired. And now, now what, you know? Yeah. Maybe I read the code and I realize I have done the same thing that that person got fired for. And I don't know, that would make me feel kind of horrible. Every mistake like this is an opportunity to learn. And either an individual is going to learn or an organization is going to learn. And, you know, you can either
Starting point is 00:06:41 say, well, oh, I didn't know about SQL injection. Now I do. I know how to avoid it. I'll use the tools correctly next time. Or like Jameson saying, maybe you have a culture where review doesn't happen well people can't ask questions and you know this is a chance for you to learn that and i just don't see firing as being the right answer here because you're also going to create secondary effects if you fire someone you don't know what they'll be but there definitely will be an effect like joe did you hear about bob you got fired for that sql injection you know those conversations are going to happen so that will definitely happen and it's really hard to predict i i could kind of see one situation which maybe you could defend it say you have all these policies you
Starting point is 00:07:26 have code reviews you have unit tests you have a lot of stuff to help make sure you don't break things and someone just yolos and deliberately works around them all to push out something and it breaks everything and has huge consequences i could maybe see in that situation taking action against that person because but but even then what led them i mean i would not do that to like get one more jira ticket done in my week you know i would only do that if there was the threat of death hanging over my head like you must get this out now and you don't have time to wait for all the unit tests and by the way your unit tests take five hours and like there are all these things that would contribute to that person feeling like that was a good idea and maybe
Starting point is 00:08:12 maybe those are the culprit too very well possible um we we've talked a little bit about learning from these mistakes and as kind of a tangent this is why one of my favorite things to do is read both debugging stories and production outage stories because they're always these um just insane sequences of fantastically rare events and that reveal some tiny thing that someone missed five years ago that has been sitting dormant forever. And like, how can you say that is your fault
Starting point is 00:08:53 and you should have caught it when it's sat there for five years and hasn't broken anything? And I don't know, I always learn from them. And sometimes I feel like I'm glad I write JavaScript when I read about how someone's like automated config management rolled back a change and the rollback had a bug in it.
Starting point is 00:09:11 So it wiped out the config files and then it brought down the whole Microsoft cloud. And man, the worst I can do is make the button disabled when it should be enabled. Your button had an outage. Yeah, it did. No more five nines on that button. So, oh, actually, yeah, that makes me think of another thing. I feel like if you did this, the ops team would be disproportionately punished. and yeah it feels to me good point um when they have the disproportionate amount of responsibility
Starting point is 00:09:47 for maintaining stuff in production and that just feels kind of unfair like they they do more of the work that is related to production stuff so of course their work will affect production things more i don't know that that just seems gross since the question was asked would you ever fire someone over a coding mistake i think maybe we should say well what coding mistakes can you get fired for like what does that look like or would you fire someone for jameson uh i mean if their code had like horrible racist things in it i guess your comments are just totally inappropriate yeah or like they deliberately defaced some public property or something what if what if this developer exhibits a pattern of mistakes just over
Starting point is 00:10:41 and over and over you said oh i get i get what you're i'm objection leading the witness what a coincidence that you bring that up i was just thinking about that dave no i think you have good stuff to say about this what do you what do you well i mean i i can't imagine a scenario where i would fire a developer for one coding mistake i just can't think of any uh james and you mentioned like well what if it's a life support critical system and someone died as a result of it and even then i'm like where was your process to protect people's lives you know so fire the ceo yep um but if a developer makes the same mistake over and over and you've talked to them about it and they just continue to do it at that point you start to ask the question this developer maybe is
Starting point is 00:11:31 too costly to have on our team you know like i just can't they can't keep coaching them like this uh if they're just going to make the same mistakes and not improve and so yeah i think that's when you start to have the conversation maybe it's time to move on but one mistake i have a really hard time imagining a scenario yeah i agree with you cool question answered yep fire the ceo fire the ceo you missed a semicolon sorry of course they well no they're happy because they get their golden parachute that's true ceo's like sweet sweet double my 10 million in stock options kicks in um oh uh one more comment on this dang it it slipped my mind i know i have it oh no
Starting point is 00:12:19 my joke was just so good it was worth it we can edit this out i'm willing to wait oh well it's lost like tears in the rain gone yep okay okay do you want to read our second question yep let's do it so this one's from an anonymous listener uh this person requested to be anonymous so it's going to be juicy they said how do you positively represent the desire to be demoted i am called a quote senior engineer but i got that way because of null instead of actual skill and paraphrasing here i think this person means basically by accident i would like to be more i would like to be a senior engineer at some point but i would be a better one if i travel more where
Starting point is 00:13:14 i have senior developers to look up to established processes etc rather than stressing about defining everything myself but that's a weird thing to say to say to a current or potential boss and it's hard to do without also volunteering for a pay cut what do you do that was a long question jameson can you sum that up for us yeah yeah i think another way i would sum this up is i don't know everything how can i be a senior engineer um i i think you could go two ways at this question one way is um one sense i'm getting from this question is this person feels like they maybe don't have a lot of people to learn from which i think that's the thing you can demand at any level you can be a senior engineer and want someone to mentor you still
Starting point is 00:14:04 it's not like no one can tell you what to do just because you have some job title and and that one if you don't have it in your organization uh you kind of just have to seek it out outside just find people you look up to and talk to them about questions you have oh yeah okay but the other one is i don't think you need to know everything to be a senior engineer and and i don't think you can be a senior engineer and think you know everything because that means you've got some kind of delusions going on there's i've talked about her stuff before there's an engineer i really admire named julia evans and uh she i would call her like the patron saint of developer curiosity that's a good one she just loves uh like writing these blog
Starting point is 00:14:53 posts that start with how does this thing work and then she just writes down the stuff she learns as she uses it and Googles it and asks people. And she's very open about what she doesn't know. And that allows her to learn a ton of stuff. And I don't think that in any way makes her not a senior engineer. I think that's a sign of a senior engineers. She's very able to learn things both from other people and from Google and also to figure things out on her own. So I don't think, I don't think you have to know everything to be a senior engineer. But isn't there some kind of baseline where like maybe established process like he specifically used the term established process here um yeah how do you
Starting point is 00:15:32 figure that out without someone on your team to look up to uh that's what agile consultants are for right perfect you don't need to be a senior engineer just bring in the actual consultants yeah ask someone else i the that baseline of what a senior engineer is is so fickle and and fungible i think it's really hard to define i agree so so on the one hand um this listener might have a false expectation where uh they're expecting there to be this class of engineer that can guide them that may actually not exist but on the other hand it could very well be that this person literally has no idea what they're doing you know and it's like i just need someone yeah ask very basic questions in which case yeah you probably do need someone um
Starting point is 00:16:24 i really i would really like to know exactly where this person is on that spectrum part of it maybe is what are the people around them like do they feel like people around them think they are smarter than they are and they don't uh they they maybe can't live up to it or do they just think like i'm in charge of all these people or i have this seniority over these people and, and I can't do it, but, but it's not like people have this unrealistic expectation of them. Yeah, maybe. I don't know. I will say though, that when I've moved into leadership roles, I have felt this way too. Like I have no idea what I'm doing. I don't know where to go. I'm, I'm just kind of playing it by ear here. And in a lot of ways, it felt the same way as I felt when
Starting point is 00:17:12 I was just starting out as a developer. And you're like, well, surely someone knows how to do this and they can point me in the right direction. But you know what? You figure it out. And sometimes you have to step into the void a little bit in order to actually start improving. And, you know, sometimes it's no big deal. You take, it's a little bit uncomfortable.
Starting point is 00:17:29 You're pushing your envelope of what you understand and know, but you're also growing as a result. So I would say, don't be too afraid to be in the situation. But on the other hand, I've also seen people say, look, I don't want to work at this job anymore because I don't have anyone to learn from. Have you ever been in that situation, Jamison? Oh yeah, for sure.
Starting point is 00:17:46 And I think that's actually a pretty crappy situation. It's great to have people to look up to and learn from, especially when you're starting out. Yeah, that's kind of what I was trying to talk about at the beginning, that you do need someone to learn from. You can learn stuff on your own. It can be a lot faster to learn from other people. And that's a harder problem to solve.
Starting point is 00:18:07 So now let's talk very tactical. So you're at your job. You don't want the responsibility you have, but you also don't want a pay cut. How do you manage that? just do a slightly worse job over time and then what why what does that get you uh you know i hadn't thought that far that's the extent of my plan just do a little crappy so i had a co-worker who was very happy
Starting point is 00:18:36 to be in what we call an individual contributor he did not want any leadership responsibility he just wanted to own the project that he owned, work on the code that he worked on, and nothing else. And when he would go in for his annual compensation review, and the manager would present his raise, he would literally say, you've got to stop giving me these raises. Because I know that you're going to pay me more, and then you're going to expect more from me. I don't want to do more. I like my job. I like where I'm at. I don't want more money. And I remember managers telling me this one time, and they were just so surprised that anyone would not want to make more money, even if it meant getting more responsibility, but this guy didn't. And you know
Starting point is 00:19:14 what? That's, I think that's totally fine. He did a fantastic job at what he did and he just had no interest in extending his responsibility beyond that. There's also sometimes opportunities to just move to different roles in the company. And I guess this depends a lot on the company, But sometimes that doesn't necessarily involve a change in pay. We've talked about kind of the dual tracks for advancement that Facebook does and some other companies do too, where you can advance technically, you can also advance kind of managerially. And maybe if the stuff you don't enjoy is kind of the process type thing, then you want to move into a more technical role. so there might be some opportunity to just um just kind of slide sideways into something that fits your yeah maybe your skill set a little better you literally slide when that happens
Starting point is 00:20:10 your desk is on wheels and you just roll it over to the side but ultimately it is going to be a hard pill for your company to swallow in most cases i think if you say to them i want to make the money as if i were had this level of responsibility but i want to have less responsibility and so if you really are serious about having less responsibility you might just want to say i don't want to pay raise next year i just want you to you know drop my responsibility a little i i would first try saying i want to focus on being an individual contributor not say anything about a pay raise because don't talk about the money side of it at all yeah don't say it at all and then if they don't bring it up then great you did a really good point really good
Starting point is 00:20:56 point but if you if you say like and i will hand back to you giant company that has thousands of times more money than i do this chunk of money that means a lot more to me than it does for you by the way then then they'll be like sure we'll take your your tiny pittance and you may not even know if you're on the high end of your pay scale maybe you're not maybe you're already underpaid yeah maybe you are ah jameson you're so wise you really put the skill in soft skills I put the soft in soft skills. Flabby skills. This is a tricky one.
Starting point is 00:21:33 I have not, I have encountered the feeling basically everywhere I worked that like, do they know what I can actually do? I'm pretty sure they're overvaluing my skill set or like I don't know enough to be as capable as I want to be in the job. but I've never actually done anything about it as in go and ask for it to, to, to do less. How have you managed? Have you just accepted the responsibility and enrolled with it? Yeah, I just, I just do a crappy job like in my plan. So I actually one time got pushed into more of a leadership responsibility than I wanted. And I was fairly confident that it was by accident and management didn't actually know that i was working in this level and so i i went to my manager and rather than say hey i have too
Starting point is 00:22:21 much responsibility i want to do less i said hey can you coach me on how to be a how to be like a team lead you know and and my man because it was more i wanted to make them aware of it without telling them that i didn't want it and it was funny because his response to me was oh you're a team lead and he was like i didn't think you had been here long enough to be doing that and I was like, yeah, I guess it kind of just happened. And he's like, oh, and it was a very different conversation than saying I want less responsibility. You know, I was able to couch it in a positive light
Starting point is 00:22:53 and then he got the message and worked on it. And I think in that case, I actually did kind of return back to a little bit more of an individual contributor role. I think that is a fantastic point you made though, that asking for help, I think this is what I was trying to say earlier when I was talking about Julia Evans,
Starting point is 00:23:10 that I don't think that asking for help is a sign of weakness And just because you have more responsibility, it means you're not allowed to ask for help. Like the help that they give you, if you have more responsibility, now affects the organization more positively. So it's easier to help you and help everyone else than it is to individually help every single person get better at their job. Yep. So I think a good organization would be overjoyed to have someone that recognizes that they want to get better and they'll work at it. Yeah, totally.
Starting point is 00:23:42 And I think they would love to support you. Yeah, I think so. If there's no one that can help you, then you're in a sad spot. Yeah, that's true. It'll also, I think, put your leadership in the right mindset about you so they know what you're doing and what level you're contributing at instead of leaving them to guess. Because it sounds like maybe you've stumbled into this, dear listener, and as a result, it's possible they don't know. And if they don't know, maybe they won't even pay you what you think you should be paid at that responsibility level anyway. So this might help on the financial side.
Starting point is 00:24:12 Sure. Yeah, this is a tricky one. I'm interested to hear if you do anything about this, how it goes. Yeah, we'd love to hear that. We've had a couple of listeners do that where they take our advice or they reject our advice. Really, you could go either way. And then they come back and write in and say, well, here's what I did and here's what the outcome was. Those are the best. So if you share that with us, we would love to hear what you did. And if you agree, we'd love to share it with our listeners too for sure question answered boom done done done all right well how can people hear more from us well you could play this episode again that's true so literal um the best thing to do is find us on twitter our twitter handle is at soft skills
Starting point is 00:25:04 E-N-G and we post every new episode there when it comes out we're doing them about weekly you could follow Dave on Twitter he is DJSmith42 if I remember right or Jameson who is Jergeson J-E-R-G-A-S-O-N yeah I've been on kind of a roll of
Starting point is 00:25:19 just cat videos lately so sweet we can't really find those anywhere else on the internet so you should follow Jameson yeah I think I've cornered the market great well thank you for listening we'll catch you next week farewell

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.