
LevelUp Cyber · 2024-10-01 · 31 min
Key moments - from our scoring
Substance score
51 / 100
Five dimensions, 20 points each
Malav Vyas, a security researcher at Palo Alto Networks with over five years in cybersecurity, breaks down the reality of security research as a career path. Researchers spend their time divided between proactive vulnerability discovery (reverse engineering software, firmware, and IoT devices to find unknown vulnerabilities before attackers do) and reactive threat analysis (like analyzing the Frosty malware campaign used against Ukrainian infrastructure). Vyas emphasizes that security research is not an entry-level role - it typically requires foundational experience in penetration testing, strong computer science fundamentals, and deep knowledge of operating systems and networking. He recommends aspiring researchers start with penetration testing jobs, engage with the community at conferences like DEF CON and Black Hat, follow researchers like Live Overflow and James Forshaw (Google Project Zero), and build a portfolio through personal research projects. On AI's impact, Vyas sees the biggest value in threat classification and vulnerability prioritization rather than novel vulnerability discovery - helping organizations decide which of hundreds of CVEs to fix first based on actual business risk. He maintains that defenders currently benefit more from AI than attackers due to token limitations in large language models for complex binary analysis.
Security researchers spend roughly half their time on proactive vulnerability discovery - reverse engineering software, firmware, and devices to find unknown exploitable flaws - and half on reactive work like analyzing new malware campaigns, building detections, collaborating on disclosure processes, and publishing findings through blog posts and conference presentations.
It's a mid-career role requiring 2-3 years of prior experience in penetration testing or similar hands-on security work, plus either a master's degree or significant self-directed research projects published publicly, not a starting position for newcomers to the field.
You need strong fundamentals in computer science, programming (pick one language and master it), operating systems internals, networking, and deep knowledge of your chosen domain (like Windows exploitation or IoT security), gained typically through penetration testing work or published research.
Defenders benefit more currently because AI helps with threat classification and vulnerability prioritization, while AI tools for attackers (like automated reverse engineering and vulnerability discovery) are still too immature due to context token limitations in large language models.
Follow Zero Initiative (which hosts vulnerability research competitions), Live Overflow (YouTube channel emphasizing the 'why' behind exploitation), James Forshaw at Google Project Zero (Windows exploitation techniques), and Unit 42 (Palo Alto Networks' research division) for high-quality, accessible research content.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode covers foundational concepts about security research roles and career paths with some practical advice, but much of the content is broad, repetitive, and lacks concrete technical depth. The guest discusses general research concepts, conference recommendations, and career progression, but provides few non-obvious insights that would significantly advance a B2B operator's understanding of security research as a function or practice.
Security researchers time is divided between two things. One is purely research, which is just diving into any software firmware, IUT device or anything that can be exploited.
the main problem is not getting any detections. That's not the problem that they don't have enough detections. The problem is how do you differentiate what's important important and what's not.
The advice given is largely conventional within cybersecurity circles: learn fundamentals, practice coding, attend conferences, network with peers, and specialize in a domain. The AI discussion touches on threat classification and prioritization, which is somewhat timely but still fairly predictable. There are no contrarian positions or first-principles arguments that challenge common thinking about security research careers.
you'll need to understand how Windows works. You need to understand internals of it. You need to understand how how it is actually programmed. Because to break something, to figure out now wal way to break into something, you first need to understand how it actually works.
start out with something as an individual contributor, build your way up to security researcher
Malav Vyas is a security researcher at Palo Alto Networks with 5+ years of experience working in the field and having contributed to actual vulnerability research and detection. He is a genuine practitioner rather than a pure thought-leader or career podcast guest. However, his relatively junior level (still in individual contributor roles after 5 years) and lack of evidence of major industry impact limits the score - a more senior researcher or executive would score higher.
I have little over five years of experience in this domain.
right now I'm doing the same for Pelo to Networks and yeah, it's a great experience smoking so far with Networks on security research.
The episode lacks concrete examples, data points, and named companies (except very generic mentions of Palo Alto, SNDK, etc.). The Frosty group malware example about thermostats is vague and unverified. References to Zero Initiative, Live Overflow, and Google Project Zero are mentioned but not explained with specifics. No metrics, timelines, or dollar figures are provided to ground claims about the research field or career prospects.
One example would be a recent Frosty group Melbare campaign. So there's a going on in Ukraine. I guess I might be blurry on details
let's say you provided them six and great vulnerabilities and company can only fix like ten a month. That way they will have sixty vulnabilities.
The host asks reasonable opening questions and demonstrates genuine interest, but rarely follows up with pushback or deeper probing. When the guest admits uncertainty or vagueness (e.g., about dark web usefulness, career tracks), the host moves on rather than pressing for clarity. The conversation stays at a surface level without the host challenging claims or extracting more specific insights. There are few signs of the host having done research on the guest or topic beforehand.
So research is an area that I'm not overly familiar with. I'm just I get the concept of research and what it is
Do you find that maybe that research is maybe is an entry level type of role or is that more of a long term like I'm going to work my way up to get into that
Computed from the transcript - who did the talking, and the words that came up most.
Join us for an exciting episode of LevelUp Cyber with special guest Malav Vyas from Palo Alto Networks and host Tony Bryan as they explore the pivotal role of cybersecurity research in defending against breaches and hacks. Cybersecurity research goes beyond just understanding known threats - it involves analyzing emerging attack patterns, identifying vulnerabilities, and developing cutting-edge solutions to stay ahead of cybercriminals. In this episode, you'll hear how deep research informs the creation of more resilient systems, fuels innovations in threat detection, and helps prevent sophisticated attacks. Malav will break down how research teams at Palo Alto Networks use data analysis, machine learning, and real-time threat intelligence to strengthen defenses across the cybersecurity landscape. Tune in to discover how top experts are using research to predict and prevent cyberattacks before they happen!
Transcribed and scored by The B2B Podcast Index.
Good afternoon, and welcome to this week's episode of Level of Cyber My name is Tony Brian, your host and executive director of Cyber Up. They're looking forward to this conversation. It's been a week or so since I've recorded the show, but you know, had an opportunity to meet our guest today recently and dive in and learn a little bit more about the importance of just the role that cybersecurity research plays in the overall kind of ecosystem and the function of a cybersecurity kind of best practices and a team.
So let's just dive in. So Mala Bias as our guest today. He joins us from California and Palo Alto Networks. I've had a great opportunity to meet you, Mala.
I'd love for you to take a second introduce yourself to our listeners and how you got to where you're at today. Good Thanks Tony for getting with this opportunity to talk and give an advice to anyone who's listening and starting their career in this amazing field. So yeah, my name is Marlow. I have little over five years of experience in this domain.
I started really early in this cybersecurity space. Like almost everyone, I wanted to hack Facebook and get free Wi Fi forever. So that's how I got started in this field. I never got free Wi Fi or Facebook access.
The same time, I got to learn a lot about this field that is cybersecurity and amazing people that are here. And so I initially started with learning a lot about pentesting website security, and eventually after working with a really good company which is SNDK co Operation, where I led several of. Product security efforts. I moved on to Sending Buffalo, where I got my taste for security research.
I took that experience and continued working on security research, Melbourne analysis, exploit development, all those good stuff for Uptics and right now I'm doing the same for Pelo to Networks and yeah, it's a great experience smoking so far with Networks on security research. So research is an area that I'm not overly familiar with. I'm just I get the concept of research and what it is, but in terms of the world of a security team, it's something new for. Me that I've not necessarily seen a lot of jobs.
So, like, what is a normal day in the life you know of a cyberspedia researcher for somebody at a corporation or a company like Palo Alto. So usually this time was divided. Security researchers time is divided between two things. One is purely research, which is just diving into any software firmware, IUT device or anything that can be exploited.
So dive into that, figured out any any reverse engineer basically REGOs engineer the form or binary figure out if there are any vulnerabilities that you can explore exploit. So that's the one point. Another part is constantly delivering detections, so we also have to help out with product development and build any intellections for any new attack or malo effort that is going on. We also help out with that, So that's kind of divided time.
Take a lot of meetings, discuss design changes stuff like that, or the boarding stuff. And at the same time, once you have something concrete to present. For example, let's say that you find something really critical bug in Windows, something you have to collaborate with a lot of procedures, go through a lot of procedures, go through PR public really management. Then there is also a legal less aspect in WOLD before you can report and then.
Get a CEV. We usually once we have something actionable in our research, we publish a block to Bolt's Unit forty to. I'm sure you've heard about it. It's a research division inside the Balolto networks.
So we publish a blog and then someone to seeing research across various conferences that are in this piece. So it's always fun to go on conferences, present and meet a lot of people. So that's kind of a gist of what we do on a data dabasis. Do you find just out of my own curiosity, do you find that the research that you're doing is very proactive or very reactive in nature?
Right? Like? Are you? Because I feel like in my brain there's really you said two parts of the research.
There's really two parts of you know, the threats, right, there's the threat after the fact. We're trying to prevent the threat ahead of the fact. So, in this opportunity or doing the research, are you focused on one or the other or both? How does that normally shake out?
It's it's usually both, So most of the part we are only focusing on the proactive things. So let's say you're working for a company who specializes in IoT security or something like Linux, OS security, cloud security, whatever. So a researcher's. Responsibility would be to seek out threats.
So something that does not exist, you need to figure out if that is possible, because most of the time products are not concretely like one hundred percent secure, like design is not good, they are exposing secrets something like that. They are they have glaring vulnabilities, but at the same time they are not public because no one ever thought of doing that, right, That does not mean that there is no publicly available exploit or vulnerability. That does not mean that that product is secure.
So as a researcher, your responsibility is to figure out what is a critical product, What is a critical device or software that needs to be one hundred percent secure, So you'll dive into it and figure out vulnerabilities on your own. And that's a that's a major part. But in some cases there are several threats. So one example would be a recent Frosty group Melbare campaign.
So there's a going on in Ukraine. I guess I might be blurry on details, but one party used a Frosty goop malware too remotely turn off all thermostas. So if you remember it's it's really cold over there in Ukraine, and if someone just turns off all the thermostats in a facility, that's that can be a little life connecting, right. So that's that was one of the incidents.
So incidents like this, they need reactive approaches. So you need to just get on get on that project, reverse engine like get the sample of that malware, reverse engineer, figure out any details instead of way for us to like a novel way for us to detect this h secured right, because we don't want that to happen to anyone else, let alone your customers. So that's the reactive part. But if something like that happens, then it would be of the utmost priority.
Do So I'm gonna go to the edge of like okay, so like let's say I'm listening today and you've inspired me to like, man, that sounds interesting. I love to research and find some like what are some things I could do on my end to maybe set myself up for success for a security research type of role or a company like pollow up to their classes or certifications. What advice would you give to me, like break in doing similar things that you're doing. First, it would be really critical to prepare yourself to just learn forever.
Right, So it's a research rule that means that you'll be learning, you'll be getting on some new things every day. Every day is a different day in research. So first you need to get your fundamental strong of computer science, networking, how programming works, how compilers, how compiler works. And once you have figured out your domain of expertise, it always helps to get onto YouTube, like start with YouTube and a couple of really good blocks to learn more about this field.
So let's say right now you're inspired and you want to do one of they research for Windows applications. So I'm just giving an example here because from field to field, there are various domains, countless domains of security. Right, there's a lot of things you can do for research. That is network security, that is firewall security.
That are countless things that you can do. So if you're talking about one ability security one ability research for Windows Windows applications, you'll first need to understand how Windows works. You need to understand internals of it. You need to understand how how it is actually programmed.
Because to break something, to figure out now wal way to break into something, you first need to understand how it actually works. Unless you know all the design specifics, all the protections that are in that are implemented, you won't be able to find a novel be So as a first step, I would suggest to start pick any any language, programming language that you like and uh yeah, and get more expertise in it. And it always helps to have deep insights into network and operating systems for any of the rules.
So I was just used up from there. That's great advice. The you know, is there other specific resources or do you have people that you follow maybe to like lean into, you know, they give some really solid advice of just the research, right, Like I know there's great GRC folks and great pin testers are there, you know folks out there that kind of lead this research that they give some folks to follow and maybe jump in and learn a little bit more. Obviously yourself included in that.
Next, right, like notable researchers to jump into and start learning a little bit. From Sure, there are two organizations who leave the full front of all the ability research. One is Zero Initiative. So Zero Initiative organizers spawned to a challenges for novel vulnerabilities and research into various devices.
If I remember correctly. Last year, they even had a tesla in that event where they invited several researchers and whoever broke. Into the tesla they get to keep it. So after these events, a lot of researchers they uh write really writers all the blog posts, and a couple of them also cover YouTube videos.
Right. One is live overflow. I would I would suggest anyone who is starting into the research go with a live overflow. They like, uh, I don't know his real name, but he starts with the really intricate details, so he does not say he just doesn't say that, uh, send this payload and it's act.
That's not how it works. Right, goes into. Why why are we doing this and what exactly makes us insecure? So those kind of background details always have so live overflow anything related to zero initiative, and that is Google Project zero.
So Google Project zero is Google's own team for security research. They that is James Foreshow, who's basically if I had to name one person in this field, it would be James Forsher, who figures out the novel techniques in Windows exploitation and publishers those regularly through Google Zero day. Google Zero team, Right, and that is always pallel to networks Unit forty two, So unit forty two researchers try to keep it really simple so anyone can understand, but at the same time deliver high quality research.
So I keep trying to go through. That's a great answer and great resource. I keep trying to go through, Right, Like a lot of folks at the entry level trying to break in and nothing that you said that I heard is like, man, research is an entry level kind of role, right, Like I'm you know, I see you have an advanced degree. You know there's some levels of that.
Do you find that maybe that research is maybe is an entry level type of role or is that more of a long term like I'm going to work my way up to get into that and and build a career around that. Uh, that role and function, I. Would say it's somewhere in the middle. It's definitely not a place to start your career with, right because research requires a lot of background knowledge and a lot of skills that you can only get while working.
So let's say if you want to if you're if you just want to start with the research, you would need like a couple of years of master's degree. Then couples to do your own research, get some research papers out of public publications, and then you'll be eligible for some sort of security research row. But instead, if you just start with. A simple pendesting related job, right, if anyone has work pintesting, they would know that pendesting is never really straightforward and simple.
You have to be innovated. You will target will always through some sort of cow boys that you need to find a year round and any sort of pendesting bug bounty or any sort of like getting formed wrasp of security concepts and computer science as a whole that will help you get started. And if you if you just if you are like me and don't. Want to waste the time and wait until you're wait for your first paycheck, if you don't want that, then it will be best to start with the entry level roll in pen testing.
Yeah, I like the What I do like about the field of research and what you're doing is it's it's a It presents itself as an easier way to show your work, right, Like a lot of times people struggle to show Like if I do a if I find an exploit, all I can really do is walk you through what I did. It's really hard for me to show you. Right, So I think with the research aspect of it, there is a final deliverable, right, that's going to come that you can that's going to describe your logic and your thought process and to continued to share with other people.
Where I think it does really afford what you alluded to, a very solid kind of pathway to highlight your skills and to show others. And you could start that. You know, you get that pin testing job and start to build out that research on your own and your free time and really just build out a really solid portfolio to make that transition into that space. So that's a really solid piece of advice and.
Anything you'd add to that. I mean in terms of like you know, githubs always is a great tool, but if you don't you're not a code or you don't know how to find the research, you know, it really makes it hard to do. Have you found that coding languages has definitely helped, you know, we talked a little bit about before we hopped on but like you know, on understanding code, and you alluded to earlier the ins and outs of how all the things works. Right, Like.
I'm I'm going to two part this question. Right, A lot of times we're education is going fast, right, college is community college, and so I feel like it's more And even my program in sidebr up we're very short term credentials skills based. But what we're describing here, I don't necessarily feel like fits into that bucket, right, because there's you can't just get a particular set of skills but understand how. All the things work to do their research right.
Well, what advice would you give for the balance of like, you know, knowing all the things and then not really knowing anything and like building the foundation of like code and understanding how it all works to get to that end game. What's the you know, how do you balance that as a as a professional orner? Right? So, uh, that's a really good question.
Do things first You need to understand, like you have to be comfortable with not knowing things right first. You Once you're comfortable with not knowing things, that's that's where you'll you get like comfortable learning around. Right. For example, if you if you constantly learn let's say I'm researching some sort of new protocol right for any i UTI devices.
If I'm not comfortable reading any sort of documentation, if I if I don't know what questions to ask, even if if I'm sitting in front of best scholars, if I don't know what questions to ask, then then it's not worth it, right, Nothing good will come out of that. So you'll have to first make sure that you ask good questions and meet more people like That's that's what I tell everyone that our industry cybersecurity is really amazing. If you walk up to any any random person that you've never met and just go up to him and ask any question, if he knows anything, then he'll gladly dive into details.
Like everyone is really passionate about that work in this industry. That's that's what differs us from other industries, right, So everyone is really passionate, so even if they don't know about something, they'll point you to someone. So people are really great resource for starting are doing any sort of research. For example, if your expertise lies into network security and you meet someone who's doing car security, automative security, if you just walk up to him and ask any questions, I'll tie into more details, tend more event workshops, events, and definitely that would help.
And there are also research conferences so different from def Corn and black Hat. Definitely, they are amazing. They are also in this Sorry, educational conferences I'm forgetting the word for here, but for those conferences was for example, that is US next. These conferences make.
Their research public, so there will be some PhD student or some doctor who spent like three to four years looking on the same research. So if you attend their workshops, if you attend that tech talks or uh PSD defenses, everything is public on YouTube for the channel US next uh uh and you'll learn a lot. So that's like figuring out where and how you want to learn. That's the critical part.
Once you master of those guests, once you can you are comfortable reading research papers, That's that's where you'll make most out of your career. So I feel like we got to say the two letters we've all come to grow and love is AI? Right? What what role do you think AI plays and jobs like security research roles moving forward?
Right? You have you have information, endless amounts of information that comes to your real time. Right, sometimes it's accurate, sometimes it's inaccurate, right, but could play a pretty important role and make things faster. What do you kind of predict you know, the future of this research transitions or transforms over the next couple of years as AI and you know, chatbots and things start to evolve and to become much more of an integral part of our day to day lives and our kind of corporate technology role.
When do you see that plane in the research side? So I believe that AI would play a critical role in classification of threats. Right so, right now, if we think about alerts and threads in a really big corporate environment, the main problem is not getting any detections. That's not the problem that they don't have enough detections.
The problem is how do you differentiate what's important important and what's not. For example, let's say you're doing a pantest for a company. You've figured out you find one hundred and fifty cvs known cvs voltantlity holds inside that network. Well, fifty is still a small number, but for a media company that that would be anywhere in five hundreds or six in works right, So your jobs and your responsibility and by providing them report.
But the main challenge for a companies starts from that. Once they have that report, once they have that number of cervis, how do you prioritize how do you know what hole they should be fixing right, Because once vulnerbilities have been identify, it's a really long process because if you think about it, you found a severe scal injection, let's say in a log in portal of a website which has millions of users every day. You can't just make that change in that website. You need to go through a couple of like multiple chains, right.
You need to modify that code, get several approvals, you need to test that thoroughly, and then it. Makes into the production. So what I'm saying is that every vulnerability that you need to fix has human costs associated with it. So you need to make sure that you focus on right vulnabilities first, prioritizing on what to fix first.
It's as it is as critical as identifying the ties. So let's say you provided them six and great vulnerabilities and company can only fix like ten a month. That way they will have sixty vulnabilities. So that will take sixty months for them to fix everything, and in that duration there will be a lot more.
And let's say something non critical is prioritized first, and some high severity CV which is like off tense cvsscore, yes, remote code execution and everything is attended at last, right. So that's the challenge that I think that AI can help us all figuring out what is exposed, what is critical to fix, what has real danger to confidentiality, integrity and a vailability. So that's the area where EI will try to help us out. I've never asked this question, and this is just share more personal curiosity.
Who does AI help more? The good guys are the bad guys? Who do you think it? Who has the advantage in this?
In this regard for AI, as it gets better, I. Would have decided defenders on this one because it reduces that time a lot by a lot for attackers. It also helps. Right because I haven't used AI a lot on the attacking side, that could be a lot of efforts.
Because I know that there are several reverse engineering tools. I definitely use LLM for diverse engineering a binary making sense out of it, but it's not as mature enough to accurately reverse engineer, help reverse engineer findable abilities. It's not as good because context limit on AI is a bit limited right now, so number of tokens that to can pass to an LLM model right now is limited. So to find accurate vulnerability, to have a control flow properly, like identifying souce and sing those kind of things require an AI to have complete view of the binary and which were definitely most critical bandity cases that would definitely help, Like that would definitely create an issue for total.
Limit that we have for current element solutions. So in future, definitely it can help us from the a techo site, But right now it's. Proving really useful for defenders. Yeah, do you we didn't, I'm not.
I don't also talk about the dark web very often, but I feel like I know, a couple of years ago and event there's a lot of tech new new startup companies were making software and technology that had intended to like scrape the dark web and use data to analyze real threat attracts. So they you know, claimed that they could predict an attack within you know, a day or two and that it was going to happen or a breach that was going to happen by monitoring traffic on the dark web. Right, So, like I imagine the world of research, especially for pal Alto, right, like monitoring those things to be important for your customers.
Do you do you find that you spend a lot of time there in the dark web and find in that stuff for you know, where where are you? Yeah? Like how does the dark web roll play in this idea of research and data? Yeah, for companies that that's a really good question.
But like several years ago when I was really early in my career at cybersecurity for cybersecurity, when I first learned about darknet and stuff like that, like what like what horrible things that goes on there? I found myself a bit repelled from that. So since then, I haven't textload dark work at all, I would say, and recently, if I hear correctly, I've. Heard most and.
It news that dark web is not what it's it used to be, right, thanks to a lot of efforts from US Government's US government, they stopped a lot. Of trime and a lot of horrible things that were going on in dark web. It's it's it's still it's on that. So from my understanding, I don't think dark web is as useful for predicting threats.
But I might be wrong because I've never done anything in that regards. I think I've seen it once on the screen that somebody else pulled it on or something, but it's not something I've necessarily been interacted with or. Or done anything with. What what is the potential kind of career path for somebody in security research?
Right? Like is there? You know? I feel like it's is it?
Is it more of an individual contributor type of role? Like how what is that like that? What does that structure look like on a research team? Right for for a corporation?
So, uh, in security job and careers, everything is. Is a bit better than normal software engineering jobs. I would say grand. Market is that indicating that software engineering diment for software engineerings is a bit going down, but at the same time it's rising for security researchers.
So if you want to stand. Out from normal like like regular I've bes right, I would say, go out of your way to learn more things, something that is not in your degree, something that is not in your career, and especially what I've seen that is a critically high demand for someone who understands security as well as software, how development works, how development cycle works, what typically goes on in a product development right, So if you don't understand how development process is done, if you then then it might be a bit hard for you to do proper security for it.
So that's why that is a really high demand for someone with both skills. So definitely suggest you understand software development life cycle. Uh, you develop some skills in coding, not necessarily competitive coding, but at the same time you should be able to read through someone else's code, figure out what's going on, and write a couple of your own as well. So that's one advice for the technical side.
And there is also a pathway from research into the let's say more leadership rules if you're in that kind of situation. So I would say start out with something as an individual contributor, build your way up to security researcher, and once you're in that role, assess various threats that are going on in our space, what you can do, how you can how you can build a product that can help customers protect right and without affecting their day to day operations. That's a critical part.
You need to provide security without affecting any availability of the product, right, it should not be a slowdown and. Stuff like that. So that's the path you can follow to build up to see So I'm still in the early st area, so I'm not too sure about how you can go about like a set path to see so or someone in the management management rules. But yeah, I think unfortunately a lot of companies have it started to make those career tracks just shit right.
I've seen a. Few that, you know, like what is that you know? You land here and I want to work my way up to hear that. There's still a lot of work to be done.
I think for better form job descriptions for a lot of companies and really mapping out those career tracks to get us to full employment right or at least as close to full employment as we. Possibly can, you know, as at an event this past week. And you know, there's a lot of people that don't think we ever get to full employment in this space, and I probably don't disagree with them, because it never ends, you know what I mean, Like, you're just going to constantly need some stuff, right, it's the role of research, and I think staying ahead stuff is really really important here to have that level of success.
Well, it's crazy, we're winding, We're coming down to our tail in. I told you before. It happens every time we get into a great conversation. I mean, you blink and you're at you know, at the window of kind of a minute of the show.
But you know everybody gets the same last question. You know, what advice would you give somebody looking the level of their cybersecurity career. Meet more people, right, Meet more people as many as you can online or offline. Gather various thoughts, various stought processes, ask everyone about that path, ask everyone for advice, and follow whatever you get.
So we have amazing community and security research. There are a lot of professionals who would help you out. So I would suggest that meet everyone, go to your local meetups, conferences, and attend talks and see where it lends you. That's really great advice.
There's a lot of conferences that are out there. Your secure world, your def coms, your b sides as soft as I square chapters. I'm a fan of Themferguard. It's a great way to plug in to and see the.
Law enforcement side. Right does require a little bit of a hye, a background check, but they do, of course, you know, kind of check a background if you're gonna hang out FBI folks, which is probably important. But a lot of great opportunities out. There to learn and grow.
So, man, what a great conversation and a topic very I knew very little about. Right. I think I've met one other researcher in my life and he happened to work at com Tea works at Comptea, is still quite a few years ago and just a great guy. And so you know, I appreciate the insights.
I think I appreciate you just sharing maybe not an alternative career path within cyber but a role that I think a lot of people haven't really thought to say. Man, that makes a ton of sense. I love to and research and understand how things work, and I was probably not even a blip on a lot of folks radar. That is something they could continue to do as a career.
So thanks for sharing your experience. Thanks for sharing just some great advice and some tips. I'd encourage everybody to reach out if you know you'd offered, if they have questions on LinkedIn to maybe reach out to you and take you up in your advice or follow what she had said. So any kind of party words of wisdom for our listeners today.
Well, you can ask any questions you can connect me to on LinkedIn. I think you would link my LinkedIn on the post as well. So feel free to drop any questions. I'd love to help you out, and thanks a lot for inviting me giving this opportunity.
Well, I appreciate your time today, I appreciate for everybody listening. Until next time, We'll see you guys soon. Have a great week.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.