Skip to main content

At our core, we are a community built on the strength of individuals whose efforts lead to our mutual achievements. We invite you to explore the stories of the people at the heart of our organization. 


Meet David, our very own Technical Solutions Consultant! He's passionate about tackling alert fatigue and loves the constant challenge of security operations. David values practical and insightful content, from threat intel to automation scripts. Fun fact: He's also training for Mr. Olympia! Get to know David and his take on the ever-evolving world of cybersecurity.

 

 

David Nehoda

 “Security Geek” - Technical Solutions Consultant

 “Learn what is to be taken seriously and laugh at the rest.”

 

Questions and Answers

 

Q: If you could change one thing about security operations with a snap of your finger, what would it be?

A: I would eliminate alert fatigue. The sheer volume of alerts that security operations centers (SOCs) deal with daily is overwhelming. It leads to burnout, missed critical events, and a general sense of being constantly behind. If I could snap my fingers, I'd implement perfect alert triage and prioritization, ensuring analysts only see the alerts that truly matter.

 

Q: Which security content do you like sharing with others or appreciate that is shared with you?

A: I value content that is both practical and insightful. I appreciate:

  • Threat intelligence reports: Detailed analyses of specific threat actors, campaigns, and malware, with actionable IOCs and mitigation strategies. I like sharing reports that give my team a heads-up on what to watch for.
  • Incident response playbooks: Well-defined, step-by-step guides for handling specific types of incidents. Sharing these ensures consistent and effective response across the team.
  • Vulnerability research: In-depth analysis of new vulnerabilities, including exploit details and patching guidance. This helps us proactively address potential weaknesses.
  • Security engineering best practices: Content on how to design, build, and maintain secure systems. This is crucial for preventing incidents in the first place.
  • Automation scripts and tools: Sharing scripts or tools that automate repetitive tasks can significantly improve efficiency and reduce analyst workload.

 

Q: What do you love most about security operations?

A: For me, the most rewarding aspect of security operations is the constant challenge and the opportunity to make a real difference.

  • The dynamic nature of the field: The threat landscape is constantly evolving, which means we're always learning and adapting. There's never a dull moment.
  • The problem-solving aspect: Security operations are essentially a giant puzzle. We're constantly piecing together clues, analyzing data, and trying to figure out what happened and how to stop it.
  • The impact we have: Knowing that our work helps protect the organization from harm and keeps critical systems running is incredibly motivating. We're on the front lines of defense.

 

Q: How do you stay up-to-date with industry trends and developments?

A: Staying current in security requires continuous learning. I rely on a combination of sources:

  • Social media: Following security researchers, experts, and organizations on Twitter and LinkedIn.
  • Online communities: Participating in security forums and communities to exchange knowledge and learn from peers.

Fun Fact:  I am currently registered for the Mr.Olympia bodybuilding competition October 9-12 in Las Vegas, Nevada

Be the first to reply!