Category: Speaker

RVAsec 15 Speaker Announcements

This year for RVAsec 15 we are announcing speakers in small batches!  Tickets are still available.

While there are still more speakers to announce and the exact schedule is coming, keep an eye on https://rvasec15.sched.com/directory/speakers to read more about each speaker and see their talk abstracts!

  • David Reign – A Peek Behind the Curtain: How A.I. Works
  • Jason Ross – Social Engineering The Machine: When Your Target Runs On Attention Instead Of Anxiety
  • Michael Roytman – No Breach Required: $52 Million in Cybersecurity Fraud Settlements Built on Paperwork, Not Incidents
  • Bhaumik Shah – Breaking Tokens: Modern Attacks on OAuth, OIDC, and JWT Auth Flows
  • Andrew Skatoff – From OSINT to Detection: Building an Agentic CTI Pipeline
  • Ariyan Suroosh – Initial Access in 2026 – The Power of the Spoken Word
  • Evan Typanski – Building Custom Detections with Zeek and Spicy
  • Jon Waldman – Everything Everywhere All At Once: Untangling Security & Privacy Risks Across Today’s AI Tools
  • Max Voldman – No Breach Required: $52 Million in Cybersecurity Fraud Settlements Built on Paperwork, Not Incidents

Stay tuned for additional speaker announcements coming soon!

And if you haven’t purchased your ticket yet, get them here:

https://www.eventbrite.com/e/rvasec-2026-security-conference-tickets-1107090370099


RVAsec 15 Speaker Announcements

This year for RVAsec 15 we are announcing speakers in small batches!  Tickets are still available.

While there are still more speakers to announce and the exact schedule is coming, keep an eye on https://rvasec15.sched.com/directory/speakers to read more about each speaker and see their talk abstracts!

  • Sherrod DeGrippo – Keynote
  • Dave Lewis – Keynote
  • Heather Antoinetti – Breaking Your Silence: How to Build Influence Without Becoming a “Suit”
  • Joanna Behan – Unlocking Awareness: How an Escape Experience made Security Fun, Engaging, and Approachable
  • Brian Cardinale – I Called Your AI Agent and It Told Me Everything: Live Voice AI Red Teaming
  • Nancy Coblenz – Gigawatts and Governance: The Data Security Crisis No One Is Talking About
  • Nick Copi – Hacking Customized IDE Distributions: Methodology Behind Six Figures in Bug Bounties
  • Michael Darling – Secure by Design, Trusted Through Compliance

Stay tuned for additional speaker announcements coming soon!

And if you haven’t purchased your ticket yet, get them here:

https://www.eventbrite.com/e/rvasec-2026-security-conference-tickets-1107090370099


RVAsec 15 Speaker Announcements

This year for RVAsec 15 we are announcing speakers in small batches!  Tickets are still available.

While there are still more speakers to announce and the exact schedule is coming, keep an eye on https://rvasec15.sched.com/directory/speakers to read more about each speaker and see their talk abstracts!

  • Kyle Flaherty – Empathy, Not Telepathy: How Embedded Engineering Teams Scale Cyber Response
  • Wajih Ul Hassan – NITRO: High-Performance Tamper-Evident Logging with eBPF
  • Vas Khomyk – The Interview Engine: A Career Readiness Framework
  • Kim Mahan – Alert Fatigue Is a Misdiagnosis
  • Jeff Man – The State of Information Security Today
  • Brian Markham – Swatting Flies With Sledgehammers: Broken TPRM Programs and How To Fix Them
  • Victoria Mosby – Use It Monday: A 5-Step Method for Turning Security Findings Into Stories Executives Act On
  • Ryan O’Donnell – Catching Collection in M365: Outlook and SharePoint Canary Tokens

Stay tuned for additional speaker announcements coming soon!

And if you haven’t purchased your ticket yet, get them here:

https://www.eventbrite.com/e/rvasec-2026-security-conference-tickets-1107090370099


RVAsec 14 Video: David Young – It’s Not All Ninjas and Anonymous Masks

RVAsec 2025 Video: David Young
Security Consultant – Secure Ideas

Title: It’s Not All Ninjas and Anonymous Masks
In this talk, I’ll give you an insider’s look at what the day-to-day reality of working in cybersecurity really entails. We’ll dive into the typical tasks you’ll face, from scoping and executing the test to long-term security strategy. I’ll also share how to bridge the gap between technical jargon and business language, making complex concepts understandable for non-technical stakeholders. Of course, we can’t forget about reporting—a crucial yet often challenging part of the job. I’ll discuss the complexities of crafting reports that not only communicate risks but also drive action. Along the way, we’ll touch on the unique challenges posed by timelines and the tools we rely on. What makes this talk unique is my perspective from both sides of the fence: working on an internal team and as a consultant. This experience allows me to highlight the key differences and offer insights into how each role shapes your approach to cybersecurity.


RVAsec 14 Video: Vennard Wright – Leveraging AI in Surveillance for Public Safety Amid Privacy Concerns

RVAsec 2025 Video: Vennard Wright
CEO – PerVista AI

Title: Leveraging AI in Surveillance for Public Safety Amid Privacy Concerns
During this session, we’ll explore the dual-edged role of artificial intelligence (AI) in enhancing public safety through surveillance while navigating the complex landscape of privacy and legislation. As AI transforms law enforcement and emergency responses with its advanced monitoring and threat detection capabilities, it also prompts critical questions about privacy rights and ethical considerations. This talk will dissect the balance between leveraging cutting-edge AI technologies and adhering to evolving privacy laws. We’ll delve into the latest trends, discuss the implications of facial recognition and behavior prediction, and examine how legislation is adapting to these rapid technological advancements. Whether you’re a tech professional, policy maker, or privacy advocate, this session will equip you with the insights needed to responsibly implement AI in surveillance, ensuring public safety enhancements do not compromise individual privacy.


RVAsec 14 Video: Jon Waldman – Vendor Management 2025 – How to Make Better Vendor Management Decisions

RVAsec 2025 Video: Jon Waldman
President and Partner – SBS CyberSecurity

Title: Vendor Management 2025 – How to Make Better Vendor Management Decisions
Although vendor management has evolved, the core process remains the same: gathering and reviewing documentation to decide whether to continue business with a vendor. The key question now is how to ensure that vendors are genuinely protecting your datal


RVAsec 14 Video: Justin Varner – Oh Hotel No!: How A Helpless Hooligan Helped A Homie From Homelessness To Homeownership In 9 Months

RVAsec 2025 Video: Justin Varner
Chief of Innovation – RadZen Inc

Title: Oh Hotel No!: How A Helpless Hooligan Helped A Homie From Homelessness To Homeownership In 9 Months
This is the story of a hooligan and his fascination with exploiting physical and digital vulnerabilities in hotels for the purposes of persistent access, living off the land, and surreptitiously housing homeless people.


RVAsec 14 Video: Bobby N. Turnage, Jr. – Data Breach Management and Legal Issues for Information Technology Professionals

RVAsec 2025 Video: Bobby N. Turnage, Jr.
Attorney & Cybersecurity and Technology Team Leader – Sands Anderson PC

Title: Data Breach Management and Legal Issues for Information Technology Professionals
Please join us for a practical discussion (without the legalese!) about data breach management and minimizing the risk to your organization. In this discussion, we’ll talk through what it’s like to be in a breach situation, and we’ll cover some practical and legal considerations and suggestions that will help your organization achieve a better outcome.
Learning Objectives:

  1. Gain a better understanding of what it’s like to be in a data breach situation.
  2. Increase awareness of risks to your organization.
  3. Increase awareness of the various people and workstreams involved in working through a data breach
  4. Increase knowledge of proactive measures to improve the outcome and minimize risk to the organization.

RVAsec 14 Video: Morgan Stuart – Large Language Models for Hackers

RVAsec 2025 Video: Morgan Stuart
Data Scientist and Engineer – Canopy Nine, LLC

Title: Large Language Models for Hackers
Wield your own AI agents, for fun and profit, with open-weight Large Language Models. In this talk, the audience will learn the foundational data science that empowers LLMs to help…and hallucinate, before diving into a tutorial on “agentic” LLM techniques. Along the way, key concepts and methods are related to NIST’s AI Risk Management Framework (NIST AI 600-1) and their adversarial machine learning taxonomy (NIST AI 100-2e2023). Cut through the hype – see the limitations and attack surfaces for yourself, and explore ways you could incorporate these tools into your own practice.


RVAsec 14 Video: John Stoner – Defending Entra ID and Office 365 Using the Prism of GraphRunner

RVAsec 2025 Video: John Stoner
Security Strategist – Google Cloud

Title: Defending Entra ID and Office 365 Using the Prism of GraphRunner
For organizations using Microsoft Entra ID and O365, it’s important to understand the landscape of the Graph API, how data is accessed and the logs available to gain visibility into probes and attacks that are targeting users and their information stores.

To drive this awareness, I’ve chosen to use a red team toolkit called GraphRunner that empowers offensive cyber practitioners an easy to use method to get started probing Microsoft Entra ID and Office 365 tenants. On the flip side of this, we are going to take a look at the logs generated by GraphRunner in a simulated attack chain to better understand what a blue teamer might see and how they can build detections and hunt, not just for GraphRunner, but for suspicious activities occurring within their Entra ID and Office 365 tenant.