Abhishek Tawde is a cybersecurity practitioner with experience in Security Operations Center (SOC) analysis, Incident Response, threat detection engineering, and threat hunting. He has worked on ransomware incidents, malware campaigns, and complex security investigations across enterprise and Fortune 500 environments.
He holds a Master’s degree in Information Systems with a concentration in Cybersecurity from the University of Texas at San Antonio and certifications including GIAC Cloud Threat Detection (GCTD), GIAC Penetration Tester (GPEN), and Certified Ethical Hacker (CEH).
Abhishek is passionate about helping newcomers break into cybersecurity and simplifying SOC and IR concepts. This is his first time presenting at BSides SATX, where he aims to give back to the community and support the next generation of security professionals.
- From Alerts to Answers: A Beginner's Survival Guide to SOC and Incident Response
Ben Mickens is a San Antonio-based cybersecurity practitioner and educator focused on AI governance, AI-enhanced social engineering, and cybersecurity awareness. He serves as Deputy Cybersecurity Cohort Program Manager at Pass IT On, Inc., teaches Security+ bootcamps, and is pursuing an MS in Cybersecurity. He holds certifications across security, cloud, and AI disciplines, including ISC2 Associate (CISSP passed), Microsoft Certified Educator, and Trusted AI Safety Expert (TAISE). A career changer with 20 years of adult education experience, he competes in CTF competitions, placing in the top 1% in several national events, and volunteers with Safe and Secure Online, delivering cyber safety presentations to community audiences.
- Your Awareness Training Is Already Obsolete: Social Engineering in the Age of AI
Brian Lowe is the Team Lead for Penetration Testing at KirkpatrickPrice, where he conducts external, internal, web application, cloud, and red team assessments for organizations across regulated industries. Before moving into offensive security, he served 23 years in the United States Air Force, retiring as a Senior Master Sergeant (E-8). His military career included deployments to Iraq, Afghanistan, the UAE, Kuwait, Saudi Arabia, and Turkey, with collaborative work alongside the FBI, U.S. Secret Service, State Department, and Department of Energy. He holds industry certifications including CRTO, GWAPT, PNPT, eCPPTv2, GCIH, and CEH, and has been credited with CVE-2025-55817, CVE-2021-40492, and CVE-2021-40353. Outside of work, Brian is a Brazilian Jiu-Jitsu black belt under Gustavo Machado, a father of six, and a PopPop of four. His kids think hacking is cool — which, honestly, is reason enough. github.com/5qu1n7
- Yet Another AI Talk — The Good, The Bad, The Ugly: AI for Pentesters
Placeholder for event-wide events! See schedule details for more information!
- Binary Jiu-Jitsu
- Script Kitty Village: Meshtastic/Meshcore
- Script Kitty Village: Wi-Fi Hacking
- Cascading Events Tabletop Exercise
- Opening Keynote by Jonathan Homer, Chief Security Officer at CPS Energy
- All Day Villages! Lockpicking, Radio, CTF Crypto Challenge! Vendor Hall!
- Join Us! - Closing Ceremonies - UC Cafe
Chandler Miller, CISSP, is an Information Security Analyst with over 7 years of experience in the financial sector, specializing in security automation and cyber defense. As Vice President of Alamo ISSA, she is passionate about mentoring others, building community, and making cybersecurity more accessible. Through speaking and community involvement, she enjoys helping others discover the many opportunities cybersecurity has to offer.
- Are You Smarter Than an ATT&CKer?
Chrissy Conklin draws from 15 years of service in the United States Navy where she performed and led a wide range of cyber operations including defensive, offensive, and intelligence missions. As a civilian, she has worked towards gaining a wide range of experiences in the cyber realm to include, Universal Studios, programming and securing ride control systems and animatronic effects. Working with Northrop Grumman, the USAF, NASA, The City of San Antonio, and municipal hospital systems, she worked towards implementing, operationalizing, and maturing Security Operations Centers to detect, alert, and automate response to incidents. She has been the manager of the vulnerability and penetration testing team of a major national bank and a professor of Information Technology and Cybersecurity at Hallmark University. She is currently the Chief Mad Scientist at LegendhasIT leading the innovation division through the evolving landscape of cyber threats to enhance security operations.
- Through the Looking Glass and what Alice and Bob Found there
Colby Farley is a cloud security practitioner with more than 10 years in cybersecurity. His work spans cloud security, incident response, threat hunting, vulnerability management automation, and large-scale AWS/GCP security. Across research and tooling, he focuses on the gaps that show up when teams trust controls, scanners, logs, or platform answers too easily. He created HarrierOps Azure to make Azure access and attack-path consequence easier to read, test, and explain.
- The Permission Is Not the Finding: From Azure Access to Consequence
Corey Flood is a Senior SOC Analyst, cybersecurity enthusiast, lifelong learner, and IT professional with over 11 years of experience across IT support, networking, cloud operations, and cybersecurity. Holding industry-recognized certifications including Security+, AWS Solutions Architect, and Network+, Corey is passionate about continuous learning, community engagement, and helping bridge the technology knowledge gap. He is dedicated to mentoring and inspiring the next generation of technology professionals.
- Your Awareness Training Is Already Obsolete: Social Engineering in the Age of AI
datapleX has been active in the hacker community since the early 1990s, with roots in BBS culture, phreaking, and the IRC underground. He co-founded the first Computer Security Association at UTSA in 2004 and captained the UTSA team for the inaugural Collegiate Cyber Defense Competition in 2005. His work sits at the intersection of offensive security, software engineering, and AI — treating attack surfaces as code problems rather than compliance exercises. He is the author of Marauders Map as Code, conducts active research through thisisunsafe.ai, and is working on hAIvenet. He holds 35 years of experience across offensive and defensive security and the GCP Professional Cloud Architect certification. Consultant. Hacker. Occasionally correct.
- Marauders Map as Code: I Solemnly Swear I Am 0wning GitOps Infrastructure
David Weidman is the founder and CEO of SenTeGuard, an AI-driven cybersecurity startup developing tools to prevent sensitive data leaks and help organizations safely integrate AI into their workflows. His work includes SenTeGuard, a multi-layered cognitive firewall for preventing intentional and unintentional sensitive data exfiltration; Moyo, a reachable information-space mapping tool. Before founding SenTeGuard, David served as a U.S. Army Cyberwarfare Officer and Captain in South Korea, where he led a 13-person technical team, advised senior military leaders to contain WMDs in North Korea. David is recently completed his Master in Public Policy at Harvard Kennedy School, where his thesis focuses on the Cognitive Security Verification Framework for mitigating semantic leakage and inference-based data exposure risks in LLM systems. He is a graduate of the United States Military Academy at West Point, where he studied Computer Science and Mathematical Sciences.
- Cognitive Security: Governing What LLMs Can Know, Combine, and Reach
David Ochel is the Director of Product Security at Hypori, where he helps product and engineering teams strengthen their security posture — and occasionally gets pulled into adjacent problems, like figuring out how to hire engineers in an era of AI-generated applications and organized interview fraud. Over 25+ years in security and privacy, he has directed corporate security, privacy, and risk management programs; worked as a product manager in privacy software; and served as a consultant, technical assessor, and auditor across various compliance domains. David lives in Austin, Texas. In his spare time, you can find him on international caving expeditions, exploring digital modes on his HAM radio, or riding his bicycle from one coffee shop to the next.
- Hiring Engineers, Not Scammers: Lessons from the Field
Dirce currently works as a seasoned Cybersecurity GRC Leader in the FinTech and Financial Services sector. With over 19 years of experience spanning across Information and Cyber Security, Cyber Threat Risk Management, Cybersecurity IT Audit, and Cyber Security Research in various industries; specifically Texas State Government, Higher Education, Healthcare and Financial Sectors. Dirce holds both a Bachelor's degree in Computer Information Systems and E-Commerce, and a Master's degree in Information Security and Information Assurance Management from Our Lady of the Lake University. He holds the following industry certifications: Associate, C|CISO, CISA, CISM, CRISC, CPDSE, CSX. In addition to his professional career, Dirce is involved with higher education in a professor capacity teaching Organizational leadership, Cybersecurity, and general IT courses for several colleges and Universities.
- From Texas to RSAC-Community Leadership through Cyber and AI Governance
Dr. J is a cybersecurity leader with extensive experience protecting critical infrastructure across complex enterprise environments. She specializes in purple teaming and integrating intelligence into operational environments, ensuring that insights don’t remain theoretical but translate into decisive, actionable impact. Her approach emphasizes precision, lethality in execution, and effectiveness in environments where speed and accuracy matter. Beyond operations, Dr. J is deeply committed to developing people. She is passionate about mentoring and growing the next generation of cyber warriors, helping others build both technical depth and operational confidence. Her leadership style centers on empowerment, collaboration, and raising the overall capability of the teams and communities she serves.
- Old MacDonald Had a Breach: Cyber Risks on the Connected Farm
Dustin Cloos is the Chief Growth Officer (CGO) at Taurean, where he helps organizations navigate the intersection of cybersecurity, compliance, technology, and business operations. With more than 30 years of leadership experience spanning military service, government contracting, enterprise IT, cybersecurity, and business growth, he has led teams and programs supporting organizations ranging from small businesses to large Federal agencies.
Dustin has worked across operations, program management, capture, solution architecture, and executive leadership, giving him a unique perspective on why security and compliance programs succeed—or fail—in practice. His experience includes helping organizations implement cybersecurity frameworks, prepare for regulatory requirements, improve operational maturity, and align technology investments with business objectives.
Dustin is a true believer that if it doesn't run it doesn't matter.
- Compliance That Breaks: Why GRC Fails in Practice (and What Actually Works)
Dwayne McDaniel is a Principal Developer Advocate who has been on a mission to "help people figure stuff out" for over a decade. At GitGuardian, he specializes in secrets security and non-human identity governance across cloud and DevOps environments. A frequent speaker at events like DevOpsDays and BSides, he helps security and engineering teams better understand complex issues.
- From Pets To Cattle To Agents: Evolving Identity And Security For Workloads
Eduardo Robles works for County of Hidalgo IT department as a Cybersecurity Analyst IV. A Linux nerd interested in Information Security, Cyber Security, Open Source, tacos, and coffee.
- Quick, Easy, AI Cyber Agents
Evan Borysko, of Greenbelt Advisors, is a fractional CISO and security adviser with 20 years of hands-on experience across enterprise IT, application development, and security programme leadership in energy, healthcare, and SaaS. He works with executive teams and boards to build security functions that open regulated markets, accelerate enterprise sales cycles, and sustain audit readiness across complex compliance environments.
- Workstation Is Still the Breach: Zero Trust Tactics from Bybit to Bitwarden
Gideon Rasmussen is a cybersecurity leader with over 20 years of experience in corporate and military organizations. Gideon has designed and led programs including information security (as Chief Information Security Officer), PCI payment card security, third-party risk management, application security and information risk management. Has diverse cybersecurity experience within banking, startups, insurance, pharmaceuticals, DoD/USAF, aerospace and defense, state government, advertising and talent management.
Gideon is a sought-after speaker, addressing audiences at conferences, universities and corporate events. He is the author of Program Architecture: Fight the Good Fight and has written more than 30 articles on cybersecurity and operational risk. A veteran of the United States Air Force, Gideon has completed the Bataan Memorial Death March four times.
- Adaptive Cybersecurity Risk Assessments
Gloria Haight is a VP of Incident Response at Synchrony, with over a decade of experience across CrowdStrike, Western Union, and Secureworks. She specializes in threat hunting, incident response, and security operations, holding CISSP, GCFA, GCIA, GWAPT, and GDAT certifications. Her work at the intersection of cyber and fraud drives her focus on investigation strategies that go beyond traditional security silos.
- Breaking the Chain: Inside the Fight Against Modern Cyber Fraud
With 15+ years of experience in information security, risk management, IT and organizational leadership, Hatim is committed to fostering cross-functional collaboration and driving secure, resilient business outcomes. His expertise includes developing and growing risk management programs and GRC funcitions, translating security best practices and compliance requirements into business values and engineering objectives, implementing process improvements, while mentoring teams to enhance operational efficiency.
- Changing Hearts and Minding the Business: Relationship Building in GRC and Security
Hemanth Gorijala is an application security professional and penetration tester with 13 years of experience in a global Fortune 500 environment. He conducts web application security assessments and reviews vulnerability reports in enterprise bug bounty programs. The exploitation chains in this talk are drawn from his own authorized assessments. He built SecretSifter to close the runtime security gap.
- Secrets That Survive Everything: Finding Runtime Credentials in Production Web Applications
Iris is a Customer Success Engineer at Red Sift, where she implements DMARC, MTA-STS, and BIMI for customers from one-person newsletters to global enterprises. She has been in email security since 2018. From starting in email support at Rackspace to backend engineering at Mailgun.
She also keeps geckos, frogs, a hognose snake, and isopods, runs a 3D printer, and has strong opinions about mechanical keyboards.
- Email Is A Liar: What Independent Creators Need to Know About Email Authentication & Security
Hi, I'm Ivan.
I work for Google Cloud.
I'm here to help & to learn.
I love my fam & I love surfing.
Join my talk & Connect with me 😎
👉 LinkedIn
- Cloudy with a Chance of Security: A Googler’s Guide to Leveling Up
Jade is a Technical Consultant at Crimson Vista, where she specializes in making the complex world of security frameworks and digital investigations accessible. With a BS in Cybersecurity from BYU and a career spanning since 2018, Jade balances high-stakes advisory work in CMMC, HIPAA, and SOC 2 with deep-dive digital forensics and crypto analysis using Chainalysis.
She is on a mission to prove that compliance doesn’t have to be dry—it’s the foundation of modern defense. When the screen goes dark, Jade is usually riding ATVs at the sand dunes, gaming on her Steam Deck, or tackling the chunkiest fantasy novels she can find.
- Ocean’s 110: You’re Either In, or You’re Out
Jen has over 15 years experience in data and security across various roles. She has implemented data security programs from the ground up and has architected those programs for the future. Now as a consultant, she has the opportunity to guide the industry toward trusted AI adoption through strong governance and security practices.
- Cntlr+Alt+Secure: Building AI Governance That Doesn't Suck
Jonathan Gonzalez graduated from the University of Texas at San Antonio with a major in Cybersecurity and Information Systems and a minor in Digital Forensics in 2020. During his collegiate career he worked in Application Security, Security Operations and Vulnerability Management before doing Digital Forensics and Incident Response (DFIR) at Crowdstrike. He is now an Assistant Vice President (AVP) of Cyber Threat Intelligence at Synchrony Financial, where he works to build and test enterprise defenses for key stakeholders. Currently, he is a graduate student studying Global Security Studies at Johns Hopkins University, deepening his understanding of the intersection between cybersecurity and global security. Outside of his professional and academic pursuits,
- Breaking the Chain: Inside the Fight Against Modern Cyber Fraud
Ludwig is an incoming Electrical & Computer Engineering freshman at Rice University with a deep technical foundation in computer architecture and programming (go, owls!). He has led technical teams and helped build cybersecurity and computer science programs in his school community. Ludwig is excited to bring that background to the Houston cybersecurity community and to continue learning from and contributing to the field.
- A Story of Llamas and Hammers: How GPUHammer Exposes a New Hardware Attack Surface for AI Systems
I'm Manuel Melendez, originally from Chihuahua, Mexico.
Received my master's from the University of Texas at El Paso and have been working at Microsoft for almost 3 years. My work focuses on doing research on attacks, Azure infrastructure, as well as validation and investigation of the attacks.
Outside of work, I like to play videogames, spend time with my dogs, and play guitar.
- Stealing Azure Managed Identity Tokens from Serverless Resources
I'm Matt Nguyen, an upcoming and young cyber professional with interests in Information Security, Security Operations, Incident Response and Malware Analysis. My background was in healthcare as a physical therapy technician, encountered cyber by accident, and decided to go to school/learn cyber full-time. I was a founder/former President of a cyber club at Austin Community College from 2024 to 2025, where I hosted 6 events with over 8 speakers and had over 100 club members. Since then, I have been attending networking events, volunteering at local conferences, and serving on the committee for a past conference this year (IntelliC0N 2025). Now I currently attend school, moderate a break into a cyber nonprofit called The GingerHacker Initiative, and am on the committee for another conference coming in 2027. In my free time, I do analyze malware but also read/nerd out on Martial arts.
- How to do: Malware Analysis
I'm the founder of Black Box Research Labs, a forensic technical due diligence consultancy focused on AI-augmented codebases. My forensic engine performs polyglot static analysis (Python, JavaScript, Go) inside air-gapped containers, applies the AIV (AI Integrity Verification) protocol for cryptographically-anchored audit evidence, and produces board-ready briefings.
I've completed forensic audits of five AI agent frameworks (CrewAI, Continue, HumanLayer, LangChain, Agno) producing 44 verified findings, data-integrity validation for the Oklahoma Conservation Commission's Blue Thumb citizen-science monitoring program, and an audit for Workspring (founder Jacob Askey provided a public testimonial). I'm a published AI researcher (arXiv:2512.07109, 302 fine-tuned Transformer models), recently presented peer-reviewed research at the OCLWA 2026 conference, and a US Navy veteran (Nuclear Electronics Technician).
- Who Reviews the Reviewers? A Live Forensic Audit of an AI Agent Framework
Over 30+ years in IT/Information Security working as a remote employee along the Texas/Mexico border.
- GSM exploit for unsolicited calls
Ryan René Rosado is a recognized cybersecurity leader with nearly 15 years of experience across government, consulting, and enterprise environments. She began her career as an enlisted Cyber Intelligence Analyst in the U.S. Air Force and has since led and supported security initiatives at organizations including EY, Avanade, and Optiv.
Ryan specializes in incident response, threat intelligence, risk management, and compliance, with a focus on translating complex security challenges into actionable business outcomes. She is a Teaching Assistant at Harvard Extension School for Network and Cloud Security and serves as an advisor to the startup Ally Security.
A frequent contributor to the cybersecurity community, Ryan has presented at leading conferences including BSides, Forum InCyber, and RSAC. She has been featured on The Security Happy Hour podcast, contributed to Dark Reading and Signal IT Magazine, and was recently recognized by AFCEA as a 40 Under Forty Emerging Leader.
- What Everyone Keeps Getting Wrong About the Cyber Gap
Shane Jones runs Ohm Security Advisory, a security consulting practice in Austin focused on penetration testing, red team operations, AI security, and secure development. Ten years in adversary simulation across TrustedSec, Optiv, JPMorgan Chase, and BMO Harris. Former USAF Security Forces. GRTE-certified. GCP SME.
- AI-Assisted Phishing: A Field Methodology for Adversary Simulation
With 15 years in tech—12 of those deep in cybersecurity—I’ve spent my career as a red teamer, pentester, and social engineer. As a U.S. Army veteran, I’ve carried discipline into the field, testing systems and human defenses alike. Beyond breaking in (with permission!), I mentor aspiring cybersecurity professionals, helping shape the next generation. I’ve delivered talks across the globe, from breaking down security threats to inspiring others to ethically hack their way to success. Whether it’s systems or people, I’m here to test it—and teach it.
- From First Steps to First Hacks: Building Your Cybersecurity Future (with a Little AI on the Side)
Trisha Apoua Ivy is a leadership and culture consultant with 25 years of experience in intelligence and cyber operations support. Her work focuses on the human side of performance in high-pressure environments, with an emphasis on sustainability, leadership, and the future cyber workforce. She continues to engage with students entering the field, bringing a cross-generational perspective on how cyber work is experienced today.
- Not a Tools Problem: The Human Side of Cybersecurity
Willie Zhang is an Offensive Security Consultant with experience protecting companies by thinking like an attacker. What started as a $1 online course on ethical hacking in college turned into a career built on finding the gaps in systems that aren't supposed to have any. Willie has a growing passion for understanding and attacking AI systems, building on a foundation of testing everything from corporate networks to the humans that run them. When he's not learning something new, Willie is in a League of Legends lobby, because apparently cybersecurity isn't chaotic enough.
- For Prompt Injection, Press 1: Hacking AI Voice Agents
Zaria Steele is a Security Analyst with four years of experience in security operations, threat detection, data protection, and compliance. She holds the Security+, CySA+, and CISSP certifications and is passionate about helping organizations strengthen their security posture. Through speaking and community involvement, she hopes to inspire aspiring cybersecurity professionals to take the leap into the field and continue growing their skills.
- Are You Smarter Than an ATT&CKer?