Loading…

Audience: Early Career clear filter
arrow_back View All Dates
Sunday, September 13
 

10:00am CDT

How to Do Just About Anything (Including Security): Turning Curiosity and Creativity into a Career
Sunday September 13, 2026 10:00am - 10:25am CDT
Learning something new, for me, often means figuring it out myself. While we have tutorials and AI on demand, experimentation and a willingness to get things wrong is still required. My story started with a book called “How to Do Just About Anything” and a realization that, with enough curiosity, you actually can.


This talk shares a non-linear path from breaking computers as a teen to understand them, creating within extreme constraints, and turning trial and error into a career that spans from high school dropout to security leadership, all while staying true to my art-tech-geek roots.


Rather than focusing on specialization, I’ll break down the practical patterns behind building strong fundamentals, both technical and human, combined with curiosity, creativity, and ownership can open doors and get you into conversations you weren’t “qualified” to be in.


I’ll connect these ideas directly to real-world security work: learning new domains quickly, navigating organizational complexity, and building the relationships needed to drive change. We’ll explore how incremental improvement compounds over time, how to operate in environments where “this is how it’s always been done” is the default, and how community involvement accelerates growth.


If you’ve ever felt like your path doesn’t fit a traditional mold, or you just know you can do more, this talk offers a practical perspective on how building beyond your core strengths can help you create opportunities, influence outcomes, and define your own path in security.
Speakers
avatar for Dan Browder

Dan Browder

Director, Information Security Portfolio, First National Bank of Omaha (FNBO)
Dan has over 25 years of experience working at the in technology and security spanning roles of graphic design, help desk and security risk. He leads strategic cybersecurity initiatives that shape FNBO’s security posture, with a focus on strategy, risk reporting, AI governance... Read More →
Sunday September 13, 2026 10:00am - 10:25am CDT
Swissôtel Chicago - Track 2

10:30am CDT

From Logs to Logic: Building Detections That Don’t Suck
Sunday September 13, 2026 10:30am - 10:55am CDT
Most security teams have no shortage of logs, yet turning that data into reliable detections is a different problem entirely.

In reality, detection efforts often fall apart because of messy data, vague assumptions, and a haphazard approach to building and maintaining them. The outcome is all too familiar: overwhelmed analysts tuning out alerts, threats slipping through the cracks, and detections that look impressive in presentations but crumble under real-world pressure.


This presentation pulls back the curtain on how detection engineering actually works in the trenches. We'll start with raw telemetry data and walk through the process of translating attacker behavior into testable hypotheses, then converting those hypotheses into detection logic that gets refined through ongoing feedback.


I'll introduce a practical lifecycle for detection engineering, covering research, hypothesis development, creation, validation, deployment, and tuning. This structured approach ensures that detections aren't just built once and forgotten, but evolve alongside the threats they're designed to catch.


Finally, we'll bridge detection engineering with threat hunting and broader cyber operations. You'll walk away with a straightforward framework for building detections that are not just technically sound, but genuinely useful when it matters most.
Speakers
avatar for Kyle Barboza

Kyle Barboza

Senior Threat Informed Defense Engineer, Financial Services Company
Kyle is a detection engineer and cyber operations leader focused on turning raw telemetry into actionable defense. He specializes in threat detection, incident response, and building scalable detection programs using automation and detection-as-code principles. With experience leading... Read More →
Sunday September 13, 2026 10:30am - 10:55am CDT
Swissôtel Chicago - Track 2

11:30am CDT

Deception strategy for securing cloud workloads
Sunday September 13, 2026 11:30am - 11:55am CDT
Defenders have deployed honeypots and honeytokens to detect threats targeting GCP workloads. The dynamic and ephemeral nature of cloud workloads with the resource-based policy model in GCP introduces unique characteristics that influence the design of deception. Defenders need to determine answers to questions such as: how many deceptions to deploy, what should they represent, how many of each type, how should these be named, where should the deceptions be placed? This session provides real-world insights from a security practitioner on the design of a deception strategy for cloud workloads that spans honeytokens (GCP IAM service accounts, GKE service accounts) and honeypots (compute instances, storage, pods).
Speakers
avatar for Suril Desai

Suril Desai

VP Engineering, Acalvio
Suril is VP Engineering and Security SME at Acalvio. Suril has deep domain expertise in cybersecurity and has a strong academic and industry background in Computer Science. Suril holds several patents.
Sunday September 13, 2026 11:30am - 11:55am CDT
Swissôtel Chicago - Track 2

12:30pm CDT

Models and More: using data to inform decision making
Sunday September 13, 2026 12:30pm - 12:55pm CDT
Organizations of all types are working to use data to make better decisions. This includes risk management decisions, such as whether to avoid, mitigate, accept, or transfer a particular risk. But what types of data work best? How do correlation and causation impact your risk analysis? Learn from a cyber insurance pro how they balance the speed of modeling and analytics with the deep experience of domain experts to choose what risks to accept. You will walk away with an understanding of how to effectively use different data sources to support risk management in your organization. 
Speakers
avatar for Amanda Draeger

Amanda Draeger

Principal Cyber Risk Engineer, Liberty Mutual Insurance
Amanda is a Principal Cyber Risk Engineer at Liberty Mutual Insurance. She is an Army vet, has way too many credentials, and likes yarn.
Sunday September 13, 2026 12:30pm - 12:55pm CDT
Swissôtel Chicago - Track 2
 

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -