Now Playing

2025 EES Verizon: I’m a Cybersecurity Expert: AMA

EES 2025 Verizon Cybersecurity
Details
Length
56:11
Views
21
Featuring
AMA
Featured Company
Verizon
Published
Oct 8, 2025
Find Your Path Forward

Ready to build your tech career?

AI-native engineering courses taught by senior engineers from the companies you want to work at. CS students and CodePath alumni enroll at no cost.

About this video

Wayne Archibald, a certified cybersecurity leader at Verizon, takes student questions on breaking into security: which skills and certifications matter, what a typical week looks like, and how to get a first role. Recorded as a breakout session at the 2025 Emerging Engineers Summit.

Transcript

Hi everyone, my name is Dana with Copath. We’re super excited to welcome you to our cyber security AMA session. Before I introduce the session, just a couple quick reminders to utilize the chat, keep your comments relevant to the session.

Take a minute to please give us your feedback so that we know how you enjoyed the session. And we’re super excited for today. So with the reminders out the way, I’m excited to tell you a little bit more about our speaker, Wayne Archable, who is a certified cyber security leader with over 20 years experience in defense strategies and leading high performance teams.

As an associate director at Verizon, he spearheads the security operations center within the threat management center, safeguarding Verizon’s networks. With degrees from Howard and George Washington University and certifications like CompTIA Security Plus, Wayne combines technical skill with resilience. And in his free time, he mentors, reads, travels, and coaches youth soccer.

Please show him some love in the chat and join me in welcoming Wayne to the stage. Hey everyone, glad to be here. Thank you so much for the wonderful introduction.

The only thing I’m not seeing is the preo. Not sure what happened to it. U Oh, here we go.

Okay, awesome. Some reason it stopped, but no problem. I will get into it again.

I don’t know why I did that. Okay, here we go. Okay.

All right. Here we go. Okay.

Thank you so much for the great introduction. Really appreciate everyone for being here today. It’s always good to come and talk to all the fun people at CodePath.

So, I hope everyone’s enjoying the summit. Let’s get into it. I’m Wayne.

And I’m here to talk about my favorite subject, cyber security. You heard a lot about this in the intro, so I’m not going to get too much into it. Moving on, I’m going to start with, a simple question, and I’m sure everyone is going to answer pretty much the same way.

Who has a smartphone currently or who likes gaming, playing games online, who likes streaming music or other media. I myself I can’t stop listening to the clips right now. I’m trying to finish up Wednesday on Netflix.

I just can’t get enough of of of that good stuff. I’m always doing something online. Well, when we’re online, every time we go online, we leave a trail.

And this is called the digital footprint. This is all our posts, our comments, the data collected by the websites and we want to make sure that everything that we do when we post, we want to think about it before we post it because this stuff stays out there forever. I’m sure you’ve heard this before.

But you want to make sure that everything that’s out there, you want to be a good reflection of yourself. And a good tip that I give people all the time is to Google yourself. I Google myself like every three months just to make sure that you know what people are seeing is what I want them to see.

And you know even though we might have social media that we lock down sometimes if for example I go to like you know I I read a lot of Variety magazine if I go to their Facebook page Instagram page and I post something even though my social media is locked down the comment is public. So you want to make sure that you know you’re doing all of that. Making you know making sure that what you post is a great reflection of yourself.

All right, let’s talk a little bit about hacking. And a hacker is an individual who uses technical skills and deep knowledge of computer systems and networks to explore and manipulate digital environments. So looking at this screen, we have a living room here.

We have a nice kitchen here. Who can tell me what on this screen can be hacked? I’ll give you a few seconds and then I will show everyone what exactly can be hacked.

You can type in the screen. You can come off mute if you want to. If you can Okay, awesome.

I see some good stuff here. I Allison summed it up nicely, but yeah. Good good stuff.

Guado, Rachel, Michael, Derek. Very good answers. Very good answers.

So, yeah. So, pretty much everything here, you know, almost every device that’s connected to the internet can be hacked. We call these devices internet of things.

And what an internet of thing is is pretty much a device that is connected to other devices. And you know, it’s you you may not think that some of these things can be hacked easily, but when a lot of these devices are built, they’re not really built built with great security in mind. Like your phone or your tablet or your laptop.

So some of these things are actually pretty easy to manipulate. Okay, so who’s out to get you? I’m a paranoid person.

I always think people out to get me, but when you think about bad actors, they’re really out to get anyone they can get. Talked about hackers. Not all hackers are bad, but you know, for the most part, there are a lot of bad actors out there.

Fishing is all about tricking into tricking you into getting your info through emails and texts. You probably got some texts from, you know, someone posing as Netflix or Amazon or some other company. Malware.

These is this is software like a malicious software that viruses that can damage device or steal data. Social engineering which is the one that always scares me the most because so many people fall for it especially unfortunately older people and these are bad actors who manipulate people into revealing confidential information sometimes giving up a lot of money. And then of course we have AI threats which are some of the newer threats and these are some of like the deep fake videos that you see that spread misinformation and AI generated fishing emails that are even more difficult to spot and I’ll talk a little bit about some things you should look for.

All right, so let’s play a quick let’s do a quick exercise. This is an example of a fishing email. And who can tell me like what are some things you should look out for in this email?

And okay, cool. Aha. I got some smart people here.

I knew this was going to be a smart crowd. I knew there were smart people here last year. I knew there going to be smart people again this year.

So we got domain, hover over the button, old logo, lowquality photos. That’s true. Poor formatting links.

Ah, awesome. So, yeah. So, quickly, you know, I know this may not be super clear, but if you look at the email address, the from email address, sometimes they will kind of trick you.

Here you see it has netflix-.com. More than likely, if you’re getting an email from Netflix, it’s going to be from Netflix.com. They have the logo usually on the email.

Don’t let the logo fool you. It’s always better to check the domain for the email address and also your name is probably going to be on there, but you know, finding someone’s name and email address is really not that hard. It’s it’s very very easy simply because people put out a lot of that information out there.

Also number four, you want to make sure that you don’t click on links. You know, you can hover over it sometimes to see what the link is actually taking you to because usually it’s a bad actor’s website. And also on your mobile device, you can actually hold your phone over the the link and it will kind of show you what the address is.

I never recommend that because, you know, I have fat fingers and you might accidentally click on the link itself. So these are some of the I want to talk a little bit more about the AI that’s a good one Brian also gram errors some of the threats that we see at Verizon AI cyber cyber attacks you know we don’t get too much of the deep fakes and stuff but we do get deep fakes in terms of videos but we have had instances where people have posed as like the CEO there was a case many years ago or maybe not many years ago, but another company in China where someone CEO called them or they thought it was a CEO and they sent them $2 million. You know, you have to watch out for things like that and just make sure that you are communicating with someone that you actually should be communicating with.

Quantum threats right now. That’s one of the a major one. Quantum computers are super powerful computers that break in break the encryption that protects our data and you know quantum computers can crack codes like that protect bank accounts, medical records, even military secrets.

Hackers are also even stealing encrypted data which is weird because you know once data is encrypted it’s basically unreadable but they’re stealing it now hoping to decrypt it later once quantum computers are strong enough. And of course, you know, now we have bigger and better ransomware, you know, because of AI and and and some of the other technologies that are out there. Ransomware is of course when you lock up a computer and they kind of demand money for you to unlock all your files.

Supply chain attacks. This is what you see mainly with companies who do business with other companies. So for example, large companies do business with Google.

Sometime there are network connections. If I compromise one company, I can probably get into the network of the other company. And you know, we talked about IoT devices and how the security isn’t that great.

So some of those are kind of easy for bad actors to exploit. All right, another poll question. We have some questions here, some choices here.

Which of the following do you think is an associated cost when it comes to a ransomware attack? And I know folks are going to just eat this up because man, you guys are too smart. I should have, you know, when I did these I was like, I’m going to make this starter because I know these guys are brilliant.

But yeah, you are absolutely right. Jeffrey, Tan, Tanzim, Brian, thank you very much. The answer is D.

So when you think about how much money we lose to cyber sec to cyber crime every year, experts predict that by 2031 we will lose about $276 billion. And that’s because there’s a new ransomware attack literally every two seconds. You know and hackers are improving their methods.

They’re making their attacks more effective. And of course, the cost of ransomware goes way beyond just paying a ransom. When you think about it, we’ve been talking for about 12 minutes.

If you look at the bottom where it has the 2025 year 108,000 109,000 per minute, you multiply by 12, we’re way over a million dollars in losses just since we’ve been talking here, you know. But you know there are also damages like to your reputation you know u and you know if you have great company secrets you can lose those. So there’s a there’s a huge cost outside of just the money alone.

So this image is kind of wild. I took a picture of myself and I uploaded it and I went I said I I asked either Gemini or Chat GBT to create an image of myself as a cyber hero. And I don’t think that the dude looks like me, but I love how awesome he looks in that suit.

But I wanted to talk just, you know, a few minutes about AI because it’s a double-edged sword. I personally think it’s a wonderful thing because we either embrace it or we, you know, we lose to it. And as cyber security professionals, we use it for you know to kind of spot unusual behavior that might be an attack.

We respond to threats faster through automation. We sift through massive amounts of data to find patterns of malicious activity. So you know I look at it as as a chess game.

You know everyone’s using the same to tools to fight. But I I always like to believe that we always have the upper hand. For the most part, they’re getting smarter, but we’re also getting smarter.

All right, another poll question. Who can tell me what is cyber security? You know, what do you think cyber security is?

And we have a couple choices here. Owning technology and software tools, people, processes, technology, antivirus, software, and firewalls, laws and regulations. You see, you guys are just, man, I can’t I You see, I can’t keep with you guys.

Jeffrey, Selena, Brian, Matteo, J Snore, you guys are killing it. So, yeah, the answer is B. People, processes, and technology.

And I love this definition because it sums it up beautifully. You know we set up the processes and we make sure the systems run smoothly and we use technology to defend against all the cyber threats that we face. So there are many different areas of cyber security and I won’t talk too much about them but you know we have things like network security where we protect the infrastructure that connects devices and systems within an organization.

We have application security IoT security we talked about a little bit. This is about protecting all IoT devices. Endpoint security and that’s pretty much anything that’s that connects to a network is considered an endpoint.

Tablet, cell phone, laptop, etc. And cloud security that protects data. This is very important because a lot of companies nowadays are storing data in the cloud. I personally back up my phones in the cloud, my laptop in the cloud.

So, I want to make sure that everything that’s out there is correct. And technically, you’re kind of right, Brian. I mean, the all the answers are kind of right, but you know, B is kind of the most right simply because it encompasses everything.

But good good catch. So, yeah. So this is my favorite part of cyber security because when I did my first certification that talked about the key concepts of cyber security and I thought it was awesome.

If you remember one thing today or one of the many things that I want you to remember today always remember this this is called the CIA triad and it’s mainly because it’s confidentiality integrity and availability. Everything we do in cyber security is about the CIA triad. So confidentiality is all about pretty much keeping secrets.

It it means that you only the people who need to know something are allowed to see it. You know when you have your password on your tablet for example, you want to make sure that everything on there is stuff that you don’t want anybody else to see. Or you know if you share a tablet with a family member, they are authorized to see but you don’t want some random person looking at your information.

Integrity is about making sure that things are real in a you know in a sense and untouched. So it’s about making sure information is accurate and hasn’t been messed with. When I created this presentation I saved it on my desktop.

I wanted to make sure that no one messed with it. So when I open the presentation it starts looking weird and I have no clue what what I’m talking about. And availability is all about being able to get the information when you need it.

When I’m driving to work and I want to listen to clips, I want to listen to clips at that point in time. We are here today. I’m here.

You’re there. And, we want to make sure that the network and everything is up. And that’s what availability is all about.

Moving on. All right. So, what do we actually do in this field?

You know it it changes depending on the company but here are some of the common things that that that we do. So we monitor network you know my team especially we monitor network traffic for security incidents. There are folks that I work with who actually fix issues when we find them.

I work with a team that does great threat research. We’re always trying to find out what threats are out there that may impact Verizon. And I work with some folks who do some great things such as penetration testing.

And penetration testing is basically we talked about hackers. There are good hackers and bad hackers. Good hackers they do penetration testing.

And what’s that doing is like you’re going outside the company and pretty much hacking into the company and you get paid for this to make sure that when they find issues we can fix them before bad actors find them. In terms of what I do personally, like me, you know, was mentioned in the introduction, I’m associate director. I lead a security operations center team with for the cyber defense organization at Verizon.

We have about 28 people in the US and in India. It’s a 247 365 day shop. We assess security risks.

We analyze threats. Me personally, I’m always trying to improve our processes. Making sure things are more efficient.

And the favorite part of my job is mentoring my team. You know, I am lucky I was lucky enough to have great leaders who made me a leader. And I believe it’s a leader’s job to create other leaders.

So I look forward to that every single day. So why a career in cyber security? I could simply say because it’s awesome.

But I’ll give you a little more information. So, you know, the first bullet here says the future is digital. Really, today is digital.

Everything we do is you know, everything we do is in the digital space for the most part. You know, if I’m going to Chick-fil-A, I’m I’m in the digital space. If I’m buying movie tickets, if I’m watching Netflix, if I’m buying the latest retro Air Jordans on Nike, on my Nike app, all of these things is the digital life that we live in.

Variety, there’s a lot of different roles and I’ll show a few of them later on that you know, you can get involved in if you choose this field. The demand for professionals is usually very high. Right now there are different reports you might see 400,000 500,000 open jobs in the US there are about two or three million worldwide and most people find this job very satisfaction it can be very satis you know they get a lot of satisfaction out of it can be stressful at times but me personally me personally I love coming to work every day knowing that I’m safeguarding the customers you know for Verizon I’m a customer a lot of my forensza customers and they entrust us with a lot of their personal data and I love you know coming to work every day and and protecting that.

So it can be challenging but it can be also be very rewarding you know because the salary is pretty good and I’ll talk a little bit about that in some upcoming slides. So you know what can you do now to get ready for a career in cyber security? You’re in school right now.

You can do things like math, computer science, but also things like creative writing and ethics. Me personally, I like I write a lot of reports for executives and I find creative writing very very very handy. And even with tools like chatgbt and gemini of course you know it’s it’s always good to write first and then you know you can use these tools to kind of polish look for corrections etc. But when you’re presenting to executives, you know, they want to kind of hear your voice.

Majors, if you choose to go to college, cyber security, information technology, which is what I did at Howard. And other ways you can join a cyber security club. There are a lot of them out there.

You can ask a teacher to you know, integrate things like the CIA triad. I also always recommend internships or apprenticeships. Not only are they great ways to build skills, but you know, if you go for an internship or, you know, a job later on when you leave school, you have some stuff to put on your resume.

And the more opportunities you get, of course, the more you can add to your resume. All right, another poll question. In the field of cyber security, what combination of skills do you think is essential for cyber security analysts to succeed?

And we have a couple choices here. Technical skills like networking and programming with soft skills such as communication and critical thinking. Primary soft skills as they are the most important are dealing with people a degree or technical skills and you know some of these are right.

So you know think about what you think is the best one and I see a lot of A’s coming through. Ian, see you with the A. Brian, Sitane, Lzandro.

Yeah. And, you know, I think you guys are actually right, you know, as usual. Brilliant folks.

So, you know, I it’s great for a great mix of technical and soft skills. Some of the technical skills. A degree, depending on what you’re doing.

My my junior analysts don’t really need a degree. They can have a degree and or four years of working experience. Or if they just really have a lot of skills, you know, we consider them.

But, you know, a proficiency in in a language is good. They don’t, my analysts don’t write code, but they do, they do a lot of technical stuff. And I always believe that learning a language always helps you technically and just basic you know things about like operating systems, network security etc. Soft skills are very important because communication is very very very important.

No matter what you do in cyber security for the most part you’re going to work in a team and you’re going to need to communicate with that team technically and non-technically and then you’re going to have to work with people who are not technical people. Collaboration and teamwork. I meet a lot of people who think that you know working in cyber is a solo game.

Unless you’re a consultant and even if you’re a consultant, if you work for a company, it won’t be. You have to collaborate. You have to meet people.

Critical thinking, logical reasoning. And it’s always good to keep up on the trends. There are a lot of great blogs, a lot of great magazines, a lot of great podcasts that kind of talk about what’s happening and what they think is going to happen.

IT certifications. I’m a big fan of them. There are a lot of them.

Some are harder than others, some more expensive than others. I always recommend CompTIA Security Plus for two reasons. A, the book is ridiculously easy to read, I think.

You you know, you folks read a lot more than I do, I’m sure, being in school. And I read this book in like a couple of days, maybe a week or so. And the exam is $279, I think, which, you know, sounds like a lot of money, but some of them are like a,000, $2,000, $3,000.

So, if you’re interested in a, security certification, there are others like ISC2CC, but I always recommend security plus. Like I said, there’s a lot of variety in this field. And, there are a lot of great career options.

I’ve pretty much I’ve done a lot of these. I’ve been a work in cyber operation obviously cyber security manager, cyber security analyst. But you know there’s something for you know for you depending on what you feel that you want to do.

Yes GC is not cheap. It is it is it is quite expensive. All right.

All right. So, I talked about how rewarding this career path can be. And you know, when you look at at the average you’re going to see a lot of different things, but for you know, for the most part, the average is about 100,000.

But of course, this is like the average. They know for they’re looking at the low end for people who are starting and then they’re looking at the high end for people who are more advanced in the career. You know for junior analysts that I know they we they started around 80 and then like lead analysts they’ll probably be like 130 135 140 and then when you go into management it you know it gets a little higher than that but you know basically it’s a great it’s you know it’s very rewarding a lot of work but very rewarding.

These are some examples of salaries by job types. So for example, if you’re an analyst zero to one year experience, this would be fresh out of college, fresh out of high school, depending on what it is, 80,000 88,000. If you’re a pentester, they have 76,000 here, but if you’re an established pentester, even even if you’re just starting, it could be a lot higher than that.

And then as as you move on to your career of course you know and you get build more skills and get more experience things get you know you can start to make a much better living. So a poll question and this may be the last one. Who do you think is responsible for cyber security?

You know, there is a lot happening and man, you guys, I can’t keep up with this crowd. Like, you know, I I feel like you you should be teaching me some stuff. But Dwayne, Gloria, Julie, Amy, you know, you’re all right.

It see everyone is responsible. You know, we all have a responsibility in cyber security. We can all protect ourselves and we can also preach the gospel of what I like to call the cyber security.

I’m constantly telling my mother not to answer emails and not to answer text messages and her friends because unfortunately older people sometimes they you know they you know like you know is it true that if I give this guy $500 I can get 3,000 later on? No, it’s not true. They’re going to take you 500 and you never hear from them again.

But yeah, you know, basically, you know, there are a lot of things you can do to be what I call you know, a cyber warrior. So you can master your password, use unique, complex passwords for every account. Some experts recommend 16 digits.

16 Digits might sound like a lot, but when you think about it, if you do things like you know, use a mixture of words and numbers and exclamation marks and other special characters, etc. you can come up with 16 very easily. Recognize fishing, you know, look, you know, make sure that that email, text message, make sure that it’s legit. I personally recommend if you get a message from a company and they you need to you feel the need to call them back call them on you know the number or go to the website itself.

Don’t click on anything in any of these text messages or emails. Keep your system updated. You know most devices make it pretty easy.

I have a lot of Apple devices Windows machines and you know it’s pretty much you get the notice saying that there’s an update just push that button and get that update in. The reason why they have these updates is because they usually find vulnerabilities which are weaknesses and the key is to get the update in before the bad actors find this weakness on your system. Protect your digital footprint.

Like I said, make sure that you don’t want to, you know, you want to make sure that people see the best of you. You know what I mean? You don’t want to end up on like Worldstar Hip Hop or one of these other blogs looking crazy.

You want to make sure that you know people especially your grandparents people other people in your family you care about you want to make sure they see the best in you. You know cuz unfortunately when people you’ve met me today hopefully I’ve given you a good impression and that’s the impression that you have of me now. When people see weird things on the internet that’s the impression they have of you the first time they see you.

So, you want to make sure that they’re not seeing anything crazy and thinking that you’re actually that person because you may not be. Secure public Wi-Fi. Always it’s always good not to use public Wi-Fi.

I always recommend getting a VPN on your device. You can actually get some pretty good good ones. I use one that’s free.

I can’t remember what it’s called right now. But when I’m traveling, especially out of the country and, I go to a lot of, you know, different hotels, I like the fact that, you know, I’m all of my communications are are encrypted and and, you know, bad actors can’t get into my devices. All right, so this kind of brings me to the end of the presentation.

If you want to learn more, there are some great resources here that I like. The National Institute, National Initiative for Cyber Security Careers and Studies. They have a lot of great information about for folks who want to get into this field.

The National Cyber Security Alliance, they do a good job of having a lot of online safety basics that you can look at and also share with your family and friends. You know especially people who may not be as cyber secure as you are as you are you want to make sure that they you know that everybody is doing their part in cyber security to make sure that we have a much safer world. So yeah that brings me to the end of presentation at this point I will take any questions that you have.

ProtonVPN that I think that’s the one that I do use. I think that’s the one I use and it’s actually really good. You know it’s it’s actually really good.

And the good thing about VPNs too is that you know if you’re trying to stream and you connect to a network in the US and you’re outside the country, you know, some streaming services don’t allow you to stream if you’re outside the US, but if you’re using a VPN, then they’ll never know and you’ll be able to do so. So yeah, it’s a good that’s a good one. All right.

As someone who wants to work in the cyber security field, what tools, searchs, daily practices do you recommend we start with? That’s and does Verizon have rotational roles for recent grant? Good questions.

If you want to get into the field, I recommend trying to focus on what you want to do because there’s a lot I made a lot of people say they want to get into cyber security, but the roles you know, kind of do different things. You know, for example, I’m a cyber security analyst. U, I won’t necessarily be, you know, working in network security or penetration testing or something like that.

So you want to kind of try to narrow down exactly what you want to do and then learn as much as possible about it. There are lots of free resources on the internet. Lots of books you can buy, a lot of blogs you can read.

In terms of tools, you know, there’s like Hack the Box and some other great gaming hackathons and stuff like that. Those are also good ways to learn. Daily practices.

I always recommend finding a great blog. I read I think it’s CISO.org. I read like security world.

I read like a couple of them and they have great just cyber security news in general. Certifications like I said security plus is a great one. IS-2 ISC2 C CC it used to be free for some people.

So if you go to isc2.org or and look up CC. And I think that literally means cyber security certificate or certificate in cyber security. They they used to have like free training and I think their first exam was free.

I’m not sure if that’s still happening, but that might be something you want to check out, you know. Let me see if I see anything else here in the chat. Oh, here we go.

Okay. Interested in pentast pen testing starting off with IoT devices. How would you recommend getting started?

Definitely try to find any course that you can find on pentesting because or you can actually there are a lot of c certifications that you can do with pentesting that will actually give you hands-on training in pentesting. And that’s pretty much the best way to go because pentesting is different from like for example being a cyber security analyst you know pentesting you’re actually is actually a technical kind of hands-on role where you kind of have to kind of practice getting you you know doing using all the different tools I think wireshock is one of them and some other tools to kind of you know kind of make sure that you could you know what you’re doing in terms of getting into the different systems. And I missed the last part of that question but coming back to the first question I forgot in terms of roles rotating roles we do have rotating roles for gra for recent graduates.

We also have at Verizon internships. We just had a big class that was there from June to August this year and we actually one of my mentees was actually a high school student from that program year before last and now he’s at UMD. So, yeah, you know, definitely, you know, go to the verizon.com, I think it’s look up, internships or co-ops, because I think the applications actually start in October.

They start very early. So yeah. So yeah definitely in terms of pen testing and IoT devices not sure about pentesting but IoT devices because at Verizon of course we are more interested in pen in doing pen testing on on large systems.

So I don’t know but yeah I would recommend probably just googling that and see what you find. But yeah because that might be more yeah that might be more that’s different from kind of pen testing. It’s the same realm because it’s like considered you know hacking but yeah you might want to just look that up and see.

I’m not really sure too sure about hacking into IoT devices. All right. In the quantum space, there are companies that are actually doing a lot of stuff with quantum cryptography right now.

I don’t think we do a lot of that Verizon. We probably do, but not on a large scale right now. A lot of stuff that we’re doing is more in AI.

But I’m sure if you look for opportunities with companies who are doing that kind of stuff and you might find a lot of companies a lot of organizations are doing that probably in the federal space doing things like quantum cryptography with quantum computers etc. So that might be a good place to start looking in terms of internships and apprenticeship opportunities. Yeah, definitely definitely. Yeah, you can do it during or you know apply while you’re applying to roles.

You know the the in in terms of any activity that can help you get into cyber security there is no like right or you know right or wrong time to do it. So you can definitely do it before I meet a lot of students who are already doing a lot of things in cyber security and they you know they’re kind of ahead of the pack because they’re doing a lot of stuff long before they like come out of school or long before they go to do a certification or long before they get a degree. So definitely it would be good before or during but you know before is always better because then when you apply for a security role you already kind of know and you already have something to talk about.

So definitely definitely I would recommend doing it that way. Very good questions. Okay.

With the rise of cyber security threats, is there a general safety measure that feels like it’s often overlooked? That’s a great question. I think for me I think it’s social engineering mainly because as human beings we’re basically trusting individuals.

Mainly because I’ve been in cyber security so long I’m utterly paranoid about everything and everyone. But social engineering scares me the most because it’s literally so easy. You know you someone can talk to you and really make you feel comfortable and make you feel make you feel like what you’re doing in terms of giving them your information is the right thing to do.

So I think that’s often overlooked. I think people get emails and text messages especially if it’s something that tells you what you want to hear. You know, I have friends who tell me things like, you know, this guy said if I put in $500, I’m gonna double it in a month.

Like, you know, that doesn’t happen. You know, I’ve been investing for years. Your money doesn’t double in a month.

That just doesn’t happen. But it sounds great. And, you know, if you are strapped for cash, you definitely want to hear that, you know, so you might actually do that.

You know so definitely social engineering is one of the one that scares me the most because it takes no skill in terms of you know technology it’s really all about how good someone can craft a message and with AI you can craft really great messages that is true most attacks are from a human perspective I mean that’s why in cyber security they say humans are the weakest link but I believe humans are also the strongest link because not only are they easy in a way to manipulate to maybe give up their password and stuff like that and access to different things, but they’re the ones who can see you know some of these threats and kind of take measures to stop them from you know from becoming real serious issues. So you’re right, we do make the mistakes and we do fix them. Okay, cool.

As someone who mentors other cyber professionals, what is something you want to see new professional do more of to promote their growth? That’s a great question. I like to see them doing things that are going to especially if you’re a student.

Like my mentee for example, when he was in school, not only did he have good grades, but he did a lot of volunteering. He taught students. But he learned as much as he could for to prepare himself for college.

He did a lot of networking. I think people don’t network enough. You know, you’re going to meet a lot of people as you go to school and come to these summits and you know, go to college and they’re going to say, "Yeah, you know, reach out to me if you have a question." By all means, reach out to them.

They usually do mean it when they say reach out to them and they usually will respond. And I think most mentors just want to see that passion, you know, because the mentee drives the mentor mentorship mentorship relationship. And if they see that passion and you come to them with questions and you you know you you you you’re doing what you’re supposed to be doing for your own personal growth.

That’s something that I like to see. I like to see people kind of the one thing that attracted me professionally to my mentee was that I wasn’t the best high school student at all. I was okay.

And then I went to college and then luckily I met friends there who really inspired me to be the best that I could be. But he was already a great student in high school and he had a lot of passion for his community and what he wanted to do with his career in the future and that’s the one thing that I really really liked. So definitely promote yourself as much as you can, network, learn as much as you can and always have something to talk about you know you might meet someone who says something like you know tell me about yourself you know and that’s some people don’t get the question but basically the question is what are you interested in?

What are you doing now? What do you want to do in the future? And you know what are you going to do with that?

So, you know, always have that in the back of your mind, like, you know, what they call the elevator pitch. Basically, you should be able to say, "Hey, I’m Wayne. You know, I’ve always been interested in pentesting and, I’m reading a lot about it lately.

I’d like to talk to you a few minutes because I know that you’re in the field." and, you know, these are things that, really, really inspire people to want to mentor people. So definitely that’s a great way to go. Are there certifications that are good for SWE roles?

And I know SP and cyber security requirements are two different roles. But I like to use certification structure and learn how to secure backend code or AWS deployment. Ah, that’s a good question.

Good question. There are some certifications ISC2 had one called and I haven’t heard about in so long. But there are a lot of them that are related to software.

I don’t know too many of them because I, you know, I I I haven’t really done a lot of that in years. But there are a lot of them geared more towards software and AWS deployment and things like that. And if you’re interested in AWS for example, I think Google has some stuff, Amazon has some stuff, some certificates that out there.

I think the Google one’s actually not that expensive. But they’re kind of different because cyber security for the most part when you do a certification, it’s a general cyber security kind of certificate. So it talks about pretty much everything I talked about today at a very high level.

They’re not going to get into the nitty-gritty of pentesting or you know what a CISO does and stuff like that, but they will give you a very high level information about what all of these people do. So yeah, I mean but you know if go to isc2.org and just do a quick search there probably is something there because they do a lot of things. Also, CompTIA might have something also, and that’s CompTIA comia.org.

Top platforms, pot podcasts or blogs that help you stay up to date. You know, I kind of don’t really listen to the same thing over and over again in terms of blogs. Simply because some of them in my opinion are too opinionated and I don’t like opinionated information.

I want to be fed the facts and then I can get what I want out of it. Which is why I do more like a cso cso.org or cs.com. I think security world.

There’s a couple of good ones. I don’t know what to say for me right now. And even sometimes I’ll just do like a quick search in Google cyber security news and just look at what’s what’s kind of hot, what’s hot, you know, what people are talking about.

Hackernews.com, they’re a good one. They talk about mostly things that involve vulnerabilities and ways that people are hacking into systems etc. but podcasts are good but and especially because I like to read so much I really prefer to kind of go to those magazines and those online magazines and kind of get my articles there. But there are some really good podcasts.

I just don’t I find if I listen to the same person over and over and over again I’m kind of just getting one perspective and with magazines they usually have several writers and that’s you know so I usually get my information from there. But good question very good question. I know a lot of cyber security roles in the US require security clearance and I’m unable to obtain one.

Would you recommend I still go into cyber security? Yeah, to be honest, this is the first role. I’ve been in the field over 20 years, and the role that I’m in now is the first role where I’ve needed a clearance.

I have never needed a clearance before. Because it all depends on what you do. So, for example, at Verizon, if you’re doing certain things with the government, you know, they might have government data.

One second. They might have government data where you need a clearance and you might have to get a clearance for that. And then of course you might have to get a secret clearance depending on what type of data it is.

But for the most part you don’t need a clearance especially if you’re looking at a lot of these startups out here or some of the smaller companies that may not do you know may not have extremely sensitive data. You probably won’t need a clearance. So, I recommend definitely going into the field.

Because for the most part, you you may not need one. You know, it all depends on the role, but most roles, I don’t think you require a security clearance. But good question, Michael.

Good question. Question. I’m early in my career with about a year of entry- level IT support experience, and certification, and networking security plus.

What advice would you give me for getting that first cyber security role? Good question. Network, network, network.

There are two guys currently on my team who, they got in, actually I have a senior manager that reports to me and he got into cyber security doing, IT support, before he got into cyber security. And how we got into cyber security was basically talking with different people in the organization and then he eventually met someone who decided to give him a chance because a lot of the entry level roles once you have a good IT background and the good thing about IT support is that they teach you a lot of stuff about you know networks in general you can definitely do some roles in cyber security. So definitely I would say network as much as possible wherever you are and you know when you meet these people be very clear that you want to you want to get into cyber security.

One of the things I learned in my career is that sometimes you think people automatically know what you want to do but you have to literally tell them like hey I’m an IT support right now but really I really want to be in cyber security and I would like you know to you know learn everything I can from you or I like to spend half an hour with you and kind of pick your brain on what I should do to kind of get into this field there but network as much as possible. You know, learn to sell sell yourself and someone will give you a shot. But that’s the best way to do it.

Good question. Very good question. What projects would make you stand out?

I’m a recent grad and trying to land my full-time role. Yeah. Anything that involves, I like hack the box and those things.

And any type of capture the flag type of activity because there’s something you put on your resume. I remember years ago we hire we we were about to hire a young woman and she she never worked before. That was literally the only experience she had that she was a part of a hackathon and she did really well and she talked about you know what the project entailed and what she did and what she learned from the project.

So, you know, those are definitely really really really good things to to do to make yourself stand out from the pack, you know, because everyone’s going to have a resume that says they got this degree or they went to that school or whatever. What separates people is really experience. And the experience can come from a job.

It can come from a hackathon. It can come from you literally just kind of doing your own thing and what you’ve learned from it. Volunteering at the church with the church, building computers, all of that kind of stuff is things that you can do to make yourself stand out from the rest.

But good question, Matteo. Good question. Good luck to you.

All right. Well, thank you so much, Wayne. Please, please, please show Wayne some love in the chat.

He dropped some amazing insights and hopefully you learned a little bit about cyber security. Before we wrap up, Wayne, I would just want to ask you one last question. What is your number one piece of advice that you would share with the emerging engineers joining the session today?

Yeah, number one piece of advice, keep learning. Keep learning as much as you can. I’m probably twice the age of some of you you smart folks here.

I’m I still learn every day. Every day I’m trying to learn something new. So keep learning as much as possible and you know keep networking.

The more people you know the more opportunities will be open to you. So keep learning, keep networking. Amazing.

Thank you. Thank you. Thank you so much.

Continue to show your appreciation for Wayne in the chat. And just a reminder that tomorrow is the day three and the final day of EES. We hope you enjoy day two and we’ll see you at 9:00 a.m.

Pacific, 12:00 p.m. Eastern for our closing keynote. Thank you so much.

Take care everyone. Good luck.