Skip to content
Artwork for Cyber Work
Technology

Cyber Work

Infosec

Learn how to break into cybersecurity, build new skills and move up the career ladder. Each week on the Cyber Work Podcast, host Chris Sienko sits down with thought leaders from Carbon Black, IBM, CompTIA and others to discuss the latest cybersecurity workforce trends.

  • 20 episodes
  • Updated Aug 18, 2025

Episodes20

  • Aug 18, 2025 · 56 min

    From stealing servers to saving lives: Working in red teaming | Jim Broome

    Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast Jim Broome of Direct Defense has been doing red teaming since before it became a term — back when a "pentest" meant $25,000, no questions asked and walking out with a server under your arm. In this episode, Jim shares wild stories from decades of ethical hacking, including breaking into major tech companies, causing a cardiac event during a physical penetration test, and why he believes soft skills trump technical knowledge for aspiring red teamers. Learn why most companies aren't ready for red teaming, how to transition into cybersecurity from unexpected fields like education or event planning, and what it really takes to succeed in offensive security. 0:00 - Intro to legendary red teamer Jim Broome 1:00 - Cybersecurity Salary Guide 2:58 - From BBS and ham radio to cybersecurity 7:07 - Evolution from network admin to red teaming 12:02 - GPS hacking and testing inflight entertainment systems 15:31 - Hiring teachers and event planners as ethical hackers 23:36 - Breaking into Symantec and stealing servers in the 90s 28:33 - Physical pentest causes cardiac event 34:06 - When companies should (and shouldn't) hire red teams 39:44 - Why red teaming is "a punch in the mouth" 44:09 - How AI is changing offensive and defensive security 48:12 - Essential skills for aspiring red teamers 50:39 - The groundskeeper who got domain admin 52:18 - Best career advice: Be humble View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast About Infosec Infosec's mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ's security awareness training. Learn more at infosecinstitute.com.

  • Aug 11, 2025 · 44 min

    Why Hackers Are Stealing Encrypted Data Now To Decrypt Later | David Close

    Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast David Close, Chief Solutions Architect at Futurex, discusses the reality facing our digital world: quantum computing will soon break the encryption protecting everything from mobile banking to satellite communications. But here's the twist — hackers aren't waiting. They're harvesting encrypted data now, betting that quantum computers will eventually crack today's "unbreakable" codes in a strategy called "harvest now, decrypt later." David explains how NIST's new post-quantum cryptography standards are already being deployed by companies like Google and CloudFlare, why crypto agility is essential for future-proofing your security infrastructure, and how you can break into the exciting field of cryptography — even without a PhD in mathematics. 0:00 - Intro 1:00 - Cybersecurity Salary Guide 3:06 - Meet David Close from Futurex 3:52 - David's journey from embedded systems to cryptography 5:05 - What Futurex does and 40 years of crypto innovation 6:39 - The role of Chief Solutions Architect 8:21 - Evolution of cryptography from payments to enterprise 10:13 - How David discovered his passion for cryptography 13:23 - Post-quantum cryptography explained 15:16 - Why quantum computers break current encryption 16:05 - The "harvest now, decrypt later" threat 18:19 - NIST's new quantum-resistant algorithms 20:02 - Real-world quantum threats to satellites and IP 22:43 - What organizations can do now 25:25 - Crypto agility and future-proofing systems 28:41 - Resources for staying current on cryptography 30:45 - Career paths in cryptography beyond algorithm development 32:18 - Getting started in cryptography careers 34:26 - The cryptography landscape in 15 years 37:34 - Regulatory enforcement of new crypto standards 39:43 - Best career advice: Finding the right vehicle 41:29 - David's current reading and recommendations 42:35 - Where to find David and Futurex online View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast About Infosec Infosec's mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ's security awareness training. Learn more at infosecinstitute.com.

  • Jul 28, 2025 · 35 min

    Working in ransomware response, investigation and recovery | John Price

    Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast John Price of SubRosa joins today's Cyber Work Podcast to share insights from his unique career path spanning UK military counterintelligence, banking cybersecurity and founding his own digital forensics consultancy. John breaks down what really happens when ransomware hits small and medium businesses, why most companies choose recovery over legal action, and how his team helps organizations get back on their feet quickly. He also discusses the growing threats facing industries like automotive dealerships, the critical role of documentation in forensics work, and why AI will reshape both offensive and defensive cybersecurity strategies. 0:00 - Intro 1:00 - Cybersecurity Salary Guide 2:34 - Meet John Price 2:51 - Early career in military counterintelligence 5:13 - Career journey from military to banking to SubRosa 8:34 - Role as founder and head of SubRosa 10:51 - Digital forensics and breach response operations 13:13 - Typical ransomware response process 17:57 - Building and managing a forensics team 19:50 - Unusual cases and industry-specific threats 24:29 - Importance of writing and documentation in forensics 27:36 - Breaking into digital forensics without experience 30:46 - Future of email security and AI's impact 33:47 - About SubRosa and AI security focus View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast About Infosec Infosec's mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ's security awareness training. Learn more at infosecinstitute.com.

  • Jul 21, 2025 · 42 min

    From security audits to privacy consulting: Building a GRC practice | Will Sweeney

    Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast Will Sweeney, founding and managing partner of Zaviant, joins the Cyber Work Podcast to discuss the evolving landscape of data privacy and GRC (governance, risk and compliance). With experience overseeing complex information security audits for Fortune 100 companies, Will shares insights on everything from the key differences between security auditing and implementation to whether privacy regulatory frameworks will continue multiplying or begin consolidating. He offers practical advice for GRC aspirants, emphasizing the importance of understanding core security processes rather than getting lost in framework structures. Will also discusses the challenges of starting a consultancy practice and provides valuable career guidance for those looking to transition into the data privacy and compliance space. 0:00 - Intro 1:15 - Cybersecurity Salary Guide promo 2:30 - Will Sweeney and his early tech background 6:45 - Building his first high school website 9:20 - Career pivot from IT to data privacy and GRC 12:15 - Audit vs. implementation: Understanding the difference 16:30 - Starting Zaviant and the GDPR opportunity 20:45 - Current challenges in data privacy compliance 24:10 - Common security gaps companies overlook 28:30 - Breaking into GRC: Skills and career advice 32:45 - Starting a consultancy: Hidden challenges 36:20 - The future of privacy regulations and AI impact 40:15 - Career advice for help desk professionals 41:30 - Closing thoughts View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast About Infosec Infosec's mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ's security awareness training. Learn more at infosecinstitute.com.

  • Jul 14, 2025 · 45 min

    From "dead-end job" to CEO: Building an IT consulting business | John Hansman

    Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast John Hansman of Truit joins today's Cyber Work episode to share his journey from a "dead-end job" in electronic security to building a thriving managed IT services company. As the co-host of the Business & Bytes podcast, John brings a unique perspective on how small businesses can leverage AI tools to solve fundamental challenges while maintaining strong cybersecurity practices. He shares practical AI tools that business owners are leaving on the table, discusses the mindset shifts required for entrepreneurship, and explains how his company pivoted during the pandemic to emerge stronger than ever. 0:00 - Intro to today's episode 0:50 - Cybersecurity Salary Guide 2:15 - Meet John Hansman 4:20 - Early tech experiences and family influence 8:45 - The career transition from dead-end job to entrepreneur 12:30 - Starting an MSP during the pandemic 16:15 - CEO role vs. hands-on technical work 20:45 - Business & Bytes podcast format and pivot 25:30 - AI tools for small businesses 31:20 - John's AI toolbox and custom GPTs 36:00 - Career transition stories and mindset challenges 42:15 - Getting out of your own head as an entrepreneur 47:30 - About Truitt and cybersecurity services 50:45 - Wrap up and where to find John View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast About Infosec Infosec's mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ's security awareness training. Learn more at infosecinstitute.com.

  • Jun 16, 2025 · 52 min

    From FBI Cyber Agent to Police Tech Innovator | Andre McGregor

    Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast Andre McGregor of ForceMetrics shares his incredible journey from reluctant FBI recruit to cybersecurity entrepreneur. Despite initially declining the FBI's recruitment call, Andre went on to become a special agent, tackling high-profile cybercrime cases involving nation-state actors like China, Russia and Iran. Growing up in marginalized communities shaped his commitment to creating safer police-community interactions, leading him to develop ForceMetrics — a platform that gives law enforcement officers real-time contextual data to make better decisions and de-escalate situations. This episode dives deep into cybercrime investigation techniques, the challenges of building secure law enforcement technology, and how data can transform public safety. 0:00 - Intro to today's episode 1:36 - Cybersecurity Salary Guide 2:31 - Meet Andre McGregor 4:03 - Early tech experiences and nonprofit work 10:50 - FBI recruitment story and cybercrime work 15:30 - Nation-state hacking investigations 25:28 - Creating ForceMetrics platform 29:45 - How ForceMetrics works in practice 38:48 - Technical security challenges 42:00 - Future of AI in law enforcement 43:00 - Career advice for security professionals 47:20 - Best career advice received 49:20 - More about ForceMetrics and contact info View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast About Infosec Infosec's mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ's security awareness training. Learn more at infosecinstitute.com.

  • Jun 2, 2025 · 34 min

    Build your own pentesting tools and master red teaming tactics | Ed Williams

    Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast Ed Williams, Vice President of EMEA Consulting and Professional Services (CPS) at TrustWave, shares his two decades of pentesting and red teaming experience with Cyber Work listeners. From building his first programs on a BBC Micro (an early PC underwritten by the BBC network in England to promote computer literacy) to co-authoring award-winning red team security tools, Ed discusses his favorite red team social engineering trick (hint: it involves fire extinguishers!), and the ways that pentesting and red team methodologies have (and have not) changed in 20 years. As a bonus, Ed explains how he created a red team tool that gained accolades from the community in 2013, and how building your own tools can help you create your personal calling card in the Cybersecurity industry! Whether you're breaking into cybersecurity or looking to level up your pentesting skills, Ed's practical advice and red team “war stories,” as well as his philosophy of continuous learning that he calls “Stacking Days,” bring practical and powerful techniques to your study of Cybersecurity. 0:00 - Intro to today's episode 2:17 - Meet Ed Williams and his BBC Micro origins 5:16 - Evolution of pentesting since 2008 12:50 - Creating the RedSnarf tool in 2013 17:18 - Advice for aspiring pentesters in 2025 19:59 - Building community and finding collaborators 22:28 - Red teaming vs pentesting strategies 24:19 - Red teaming, social engineering, and fire extinguishers 27:07 - Early career obsession and focus 29:41 - Essential skills: Python and command-line mastery 31:30 - Best career advice: "Stacking Days" 32:12 - About TrustWave and connecting with Ed About Infosec Infosec's mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ's security awareness training. Learn more at infosecinstitute.com.

  • May 12, 2025 · 12 min

    The Future is Cloud: Master Azure Certs for Cybersecurity Success | Guest Wilfredo Lanz

    Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast Infosec instructor Wilfredo Lanz joins Cyber Work Hacks to break down the critical differences between the Azure AZ-104 certification for cloud administrators and the AZ-500 certification for cloud security professionals. Wilfredo explains why these complementary certifications can supercharge your cybersecurity career and emphasizes that cloud skills aren't optional in today's tech landscape. Whether you're in government, healthcare, finance or any other sector, cloud proficiency is quickly becoming mandatory for all cybersecurity professionals. 0:00 - Intro to cloud certifications 1:00 - Cybersecurity Salary Guide promo 1:35 - Meet Wilfredo Lanz and intro to Azure certs 2:06 - Azure vs. AWS and other cloud platforms 4:45 - Industries favoring Azure (government, healthcare, finance) 7:00 - AZ-104 Administrator vs. AZ-500 Security Engineer certifications 9:31 - Why all cybersecurity professionals need cloud skills 10:30 - "Cloud is the present and future" — career implications 11:45 - Wrap up and final thoughts View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast About Infosec: Infosec's mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ's security awareness training. Learn more at infosecinstitute.com.

  • May 5, 2025 · 8 min

    Cloud career roadmap: Azure Administrator vs Security Engineer certs | Guest Wilfredo Lanz

    Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast Today on Cyber Work Hacks, Infosec Boot Camp instructor Wilfredo Lanz discusses the importance of Microsoft Azure certifications for IT and security professionals. With over 90% of businesses moving to the cloud, understanding how to administer cloud resources is crucial. Wilfredo highlights the differences between the Azure Administrator Associate and Azure Security Engineer Associate certifications and how they can enhance career opportunities in IT, cybersecurity, project management and networking. Tune in to learn how cloud certifications can future-proof your career. And don't miss out on the free cybersecurity salary guide ebook linked in the description. 00:00 - The booming IT and cybersecurity job market 00:52 - Free cybersecurity salary guide 01:29 - Meet Wilfredo Lanz: Azure certification expert 02:20 - Azure administrator associate vs. Azure security engineer associate 04:53 - Importance of cloud certifications for IT and cybersecurity professionals 07:53 - Pursuing Microsoft Azure certs – View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast About Infosec Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.

  • Apr 21, 2025 · 49 min

    When AI Goes Rogue: API Security in the Age of AI Agents | Guest Sam Chehab

    Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast Today on Cyber Work, Sam Chehab, the head of security and IT at Postman, dives into API security and the intriguing concept of rogue AI agents. Chehab discusses the internal challenges posed by well-meaning developers, the potential threat of hackers using AI to create more sophisticated malware, and the evolving roles of development and security teams. The episode also navigates through Chehab's career, including his time at Nvidia and leading a zero-trust strategy deployment for Palo Alto Networks. Listeners will gain insights on integrating AI tools for API defense, the future of cybersecurity roles, and practical advice for breaking into the industry. Plus, learn about Postman's strategies and tools to ensure secure API development and management. – View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast 00:00 API security and rogue AI agents 00:45 Sam Chehab's background and career journey 03:54 Transition to data security 12:47 Implementing a zero-trust strategy at Palo Alto 20:06 Responsibilities at Postman 23:02 Understanding rogue AI agents 26:42 Ensuring API security and collaboration 27:34 Challenges in securing APIs 28:31 Postman's approach to API hygiene 29:39 The future of API security 34:42 Career advice for aspiring security professionals 39:18 The role of AI in API security 45:20 Postman and upcoming events 47:59 Outro About Infosec Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.

  • Apr 14, 2025 · 53 min

    Why Medical Device Security Needs Transparency: The SBOM Revolution | Guest Ken Zalevsky

    Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast In this episode of Cyber Work, Ken Zalevsky, founder and CEO of Vigilant Ops, joins us to discuss the importance of a Software Bill of Materials (SBOM) in the medical device industry. Zalevsky shares how SBOMs provide transparency and critical security insights, akin to the ingredients list on food packaging, to help identify and defend against vulnerabilities. We also delve into Zalevsky's extensive career in healthcare cybersecurity, starting from his early tech interests influenced by his father to his pivotal role at Bayer Healthcare. The discussion covers the impact of legacy systems, current security trends, the integration of AI in medical device security, and valuable insights for those looking to build a career in this crucial sector. Tune in to learn more about medical device security and the latest in cybersecurity trends, and get some expert advice straight from a seasoned professional. 00:00 Understanding SBOMs in medical devices 04:20 The evolution of medical device security 07:22 Ken Zalevsky's journey in cybersecurity 09:28 Challenges in medical device security 13:06 The role of SBOMs in cybersecurity 15:56 Implementing SBOMs in organizations 18:28 Ken Zalevsky's role at Vigilant Ops 22:01 Technical aspects of SBOMs 27:14 Legacy devices and security measures 28:24 Manufacturer's role in device security 30:07 Healthcare industry's response to security threats 30:42 Impact of major breaches on policy 34:13 Generative AI and machine learning in healthcare security 40:22 Skills and certifications for healthcare security careers 46:46 Career advice and educational paths 49:04 About Vigilant Ops and their services 52:15 Outro – View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast About Infosec Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.

  • Mar 31, 2025 · 51 min

    From CIA to CISO: AI security predictions and career strategies | Guest Ross Young

    Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast Ross Young, CISO in residence at Team8, joins this week's Cyber Work episode to share insights from his fascinating career journey from the CIA to cybersecurity leadership. With over a decade of experience across intelligence agencies and major companies, Young discusses the rapidly evolving AI security landscape, predicts how AI will transform security roles and offers valuable career advice for cybersecurity professionals at all levels. Learn how security professionals can stay relevant in an AI-driven future and why continuous learning is non-negotiable in this field. 00:00 Intro 00:27 Ross Young's journey in cybersecurity 01:18 Cybersecurity job market insights 02:12 Ross Young's educational path 07:38 Experience at the CIA 10:38 Transition to the private sector 13:15 Current role at Team8 18:30 Daily life of a CISO in residence 22:12 Impact of AI on cybersecurity 25:23 Identifying phishing emails 25:49 New risks with AI models 27:08 Exploiting AI for malicious purposes 30:55 Defending against AI exploits 32:24 AI in security automation 33:30 Common mistakes in AI implementation 36:59 Future of cybersecurity with AI 43:18 Advice for security professionals 46:17 Career advice – View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast About Infosec Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.

  • Mar 24, 2025 · 1 hr 3 min

    Securing Apple vs Windows: Which is harder? | Guest Weldon Dodd

    Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast Today on Cyber Work, we welcome Weldon Dodd, Senior Vice President of Global Partnerships at Kandji. Dodd discusses a recent report highlighting why Apple devices are perceived as more secure than Windows systems in the event of a global software outage. He dives into the technical and social reasons behind these security differences, explores the challenges in securing different platforms and offers career advice for aspiring cybersecurity professionals. Learn why a commitment to continuous learning and focus is essential, and get insights into the growing role of Apple in the enterprise environment. This episode is packed with valuable tips for breaking into and advancing up the ladder in the cybersecurity industry. 00:00 Cybersecurity job market insights 02:03 Weldon Dodd's cybersecurity career journey 14:39 Joining Kandji and building teams 25:22 Kandji's report on Apple vs. Windows security 30:37 Mac as a target for malicious software 32:03 Windows vs. Mac: A bigger target 33:12 Apple's growing presence in enterprises 34:00 Sector-specific Apple adoption 36:49 Impact of the report on operating systems 39:21 Career paths in cybersecurity 44:46 Skills and certifications for entry-level cybersecurity roles 50:11 Advice for aspiring IT professionals 54:20 Best cybersecurity career advice received 58:17 About Kandji and its services 1:02:30 Outro – View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast About Infosec Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.

  • Mar 17, 2025 · 20 min

    Using  ChatGPT for Offensive Security | Guest Robert Morel

    Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast In this episode of Cyber Work Hacks, host Chris Sienko welcomes Infosec Skills Instructor Robert Morel to discuss his learning path, "ChatGPT for Offensive Security." Morel outlines the seven-course path, including five courses of learning and two interactive labs, focused on using ChatGPT in various offensive security tasks. The discussion includes crafting cross-site scripting attacks, generating phishing campaigns and engineering prompts for optimal results. Morel also provides insight on effectively using ChatGPT to write detailed bug reports and demonstrate AI security skills to potential employers. Additionally, he shares information about his company, Pointless AI, a platform for bug bounty and vulnerability disclosure services. This episode offers a comprehensive guide for cybersecurity professionals looking to integrate AI tools into their offensive security toolkit. 00:00 Introduction to Cyber Work Hacks and guest Robert Morel 00:08 Overview of ChatGPT for offensive security learning path 02:53 Understanding ChatGPT and its applications 04:57 Comparing ChatGPT with other AI models 07:24 Deep dive into the offensive security learning path 12:52 Using ChatGPT for offensive security in real-world scenarios 14:43 Final thoughts and advice on using ChatGPT 18:37 Conclusion and additional resources – View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast About Infosec Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.

  • Mar 10, 2025 · 17 min

    CompTIA Network+ training: What to expect in a boot camp | Instructor Tommy Gober

    Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast In this episode of Cyber Work Hacks, Infosec Boot Camp Instructor Tommy Gober walks us through what his Network+ training course is like. He talks about the supportive learning environment and explains how the boot camp is designed for those new to the field. He covers the structure of the five-day program, touching on topics like the OSI model, binary number systems, networking hardware and more. He also shares his insights on the benefits of boot camp learning versus self-study or traditional schooling — and offers tips for taking the Network+ exam. 0:00 Introduction 1:19 Free cybersecurity salary guide 2:54 Boot camp training vs. other learning methods 4:23 In-person and online boot camp experience 9:13 Network+ boot camp daily breakdown 11:56 Network+ exam preparation and testing strategies 14:55 Final thoughts and wrap up – View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast About Infosec Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.

  • Mar 4, 2025 · 18 min

    Understanding CompTIA CEUs: How to renew your Network+ | Guest Tommy Gober

    Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast Infosec Boot Camp instructor Tommy Gober returns to Cyber Work to share insights on maintaining your CompTIA Network+ certification through continuing education credits (CEUs). Learn the best practices for accruing CEUs, including documenting projects, attending conferences and engaging in hands-on learning experiences. Tommy also discusses the importance of staying current in the field and tips for avoiding the last-minute scramble to earn CEUs. Discover how advancing your certification level can simplify the renewal process and keep you updated with the latest industry trends. 0:00 Introduction 1:28 Free cybersecurity salary guide 3:10 What are CEUs/CPEs and why are they required 5:50 What are the ways to earn Network+ CEUs 8:40 Ways to stay ahead on your CEU credits 11:35 CompTIA's CEU credit breakdown 16:40 Final thoughts and wrap-up – View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast About Infosec Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.

  • Feb 24, 2025 · 20 min

    Network+ practice questions: Tips to pass your exam | Guest Tommy Gober

    Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast Infosec Boot Camp Instructor Tommy Gober joins Cyber Work Hacks to discuss the mechanics of the CompTIA Network+ exam. This episode features an overview of different question types, including multiple-choice, multiple-answer and performance-based questions. Tommy guides you through sample exam questions, providing insights into CIDR notation, subnetting and troubleshooting IP addresses. Additionally, learn about the benefits of practice exams and receive essential tips for exam day success. This episode is perfect for anyone preparing for the Network+ certification or looking to strengthen their networking knowledge. 0:00 Introduction 0:38 Cybersecurity salary guide 2:37 Understanding Network+ exam question types 6:07 Practice question: CIDR notation 9:10 Practice question: IP addresses 11:15 Practice questions: Troubleshooting & IP addresses 15:18 Practice exam and preparation tips 17:33 Final advice 19:20 Conclusion – View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast About Infosec Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.

  • Jan 27, 2025 · 10 min

    CompTIA Network+: Is it necessary for a cybersecurity career? | Guest Tommy Gober

    Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast Infosec Instructor Tommy Gober joins Cyber Work Hacks to discuss the CompTIA Network+ certification. Despite often being bypassed in favor of Security+, Gober explains why Network+ is fundamental for a robust cybersecurity knowledge base. Learn about critical networking concepts like the OSI model, IP addresses and protocols, which are vital for understanding how cyberattacks work. Discover how strengthening your networking proficiency can enhance your cybersecurity career, even if you don't aim to become a network admin. Gober also shares top tips for excelling in the Network+ exam, including mastering port numbers and subnetting. Don't miss this enriching episode designed to boost your cybersecurity skills! 0:00 Introduction 0:50 Cybersecurity salary ebook 1:44 Overview of Network+ certification 2:55 Deep dive into networking concepts 5:15 Integrating Network+ with Security+ 7:03 Essential networking skills for cybersecurity 9:03 Top tips for Network+ exam preparation 10:02 Final thoughts – View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast About Infosec Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.

  • Jan 13, 2025 · 33 min

    Incident response: What I learned from a hands-on project | Guest Gamuchirai Muchafa

    Get your FREE 2024 Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcast Watch the video here: https://www.youtube.com/watch?v=OSZ1Qi-tzSE Today on Cyber Work, we welcome Gamuchirai Muchafa from Africa's CyberGirls program to discuss her journey in cybersecurity. Muchafa shares the rigorous application process for this mentorship program, her transition from a healthcare assistant to an IT professional and the importance of documentation in cybersecurity. We delve into her experiences with incident response challenges and her hands-on project involving an automated incident detection and response system. Muchafa also reflects on her aspirations and offers advice for aspiring cybersecurity professionals. 00:00 - Introduction 02:29 - Muchafa's journey into cybersecurity 05:43 - CyberGirls program 07:03 - Programming without a laptop 08:06 - CyberGirls fellowship projects 13:07 - Incident response problem walkthrough 20:53 - Advice for cybersecurity students 24:57 - Future plans 30:27 - Support for CyberGirls fellowship 31:37 - Outro About Infosec Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.

  • Jan 6, 2025 · 23 min

    How to hack an API: A walkthrough | Guest Katie Paxton-Fear

    Get your FREE 2024 Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=audio&utm_medium=podcast&utm_campaign=podcast Watch the walkthrough here: https://www.youtube.com/watch?v=-CvvtwKXYjE Join us on Cyber Work Hacks as Katie Paxton-Fear, known as InsiderPhD, demonstrates how to hack APIs and uncover vulnerabilities in shopping apps. Paxton-Fear provides a visual walkthrough of common mistakes in API security, emphasizing problem-solving and creativity over technical skills. You'll learn how to use tools like Burp Suite and Repeater to exploit vulnerabilities, access personal information and make unauthorized transactions. Paxton-Fears' insights make API hacking an accessible entry point into cybersecurity, highlighting the path to becoming a bug bounty hunter. Plus, discover tips on starting your API hacking journey and utilizing Infosec resources to build a successful career in cybersecurity. Don't miss this comprehensive guide to API hacking! 00:00 - Introduction to API security 03:16 - Understanding APIs and their vulnerabilities 05:26 - Live API hacking demonstration 05:43 - Exploring Burp Suite and Repeater 08:28 - Identifying and exploiting API vulnerabilities 09:50 - Real-world API hacking examples 17:21 - Tools and tips for aspiring hackers 19:31 - Steps to start bug bounty hunting 22:23 - Conclusion – View Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=audio&utm_medium=podcast&utm_campaign=podcast About Infosec Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training. Learn more at infosecinstitute.com.