Tag: Detection Engineering

RVAsec 15 Speaker Feature: Ryan Bird

AI SOC and Securing your Environment (<– add to your schedule)

This discussion is designed to help teams figure out where AI fits in their environment from an analysis perspective, it is vendor agnostic and includes agentic deployments, as well as AI SOC services, novel attack vectors from independent research, and the overarching philosophy of how the threat landscape has just massively changed and how to adapt to it.


Ryan Bird:
Ryan Bird moved to the MVA area in 2017 with his wife. He helped train the United States Army in their ASOT level one program as well as MCTOG in 29 Palms through 2019 with Obsidian Solutions Group before working at Annapolis Defense in a Maritime Security role. After Covid hit he went on to start school at University of Maryland Global Campus and began work in his first cyber security role at RSM Defense when it was being stood up with Unit 26, He then went on to support the Department of States’ Personal Security Device program, and on to FEMA at Mount Weather supporting their internal SOC with One Zero Solutions. He has since been hired at GuidePoint as a Security and Delivery Engineer supporting Elastic and CrowdStrike.

In 2019 he was also part of the Storm the Hill event at IAVA – assisting the IAVA team by talking to congressman and women about veteran suicide in order to get the Commander Scott Hannon bill passed, which changed the VA healthcare system to auto enroll service members upon discharge. He additionally did Disaster relief work during Hurricane Florence, and supported his Uncle running for Commonwealth’s Attorney in 2025 in the City of Fredericksburg.

He has brought common security knowledge from the physical security philosophy to the cyber side of things and holds a unique mindset and experience working his way from an Analyst position to a key member at GuidePoint’s Mid Atlantic SECOPS team.

Come see Ryan Bird at RVAsec 15!


RVAsec 15 Speaker Feature: Andrew Skatoff

From OSINT to Detection: Building an Agentic CTI Pipeline (<– add to your schedule)

Modern threat intelligence moves fast, but detection engineering lags. This talk presents an agentic workflow that transforms OSINT into actionable detections using structured extraction, LLM reasoning, and automated validation. Transparent, auditable pipelines accelerate the CTI lifecycle, from ingestion to Sigma rules, while preserving analyst control, reducing time-to-detection from days to hours.


Andrew Skatoff:
Andrew is a cybersecurity senior leader with over 20 years of experience protecting critical financial infrastructure within the national financial infrastructure. He leads large-scale programs spanning incident response, threat hunting, and detection engineering, and has served as Incident Commander for nationally significant cyber events.

He is the creator of Huntable CTI Studio, an open-source agentic workbench that transforms threat intelligence reports into actionable detections using transparent, auditable AI workflows. His work focuses on applying AI as a force multiplier for security teams—without sacrificing rigor, trust, or control.

Come see Andrew Skatoff at RVAsec 15!


RVAsec 15 Speaker Feature: Chelsea Bryan

Community is a Control: Strengthening Cybersecurity Through Connection (<– add to your schedule)

Strong cybersecurity programs are not built by tools alone. This session explores how trust, mentorship, and community can directly impact incident response effectiveness, analyst retention, and long term resilience within security teams.


Chelsea Bryan:
Chelsea Bryan is a Security Operations Analyst at Virginia Commonwealth University with four years of hands on experience supporting enterprise security operations in a complex higher education environment. She works daily with SIEM platforms, endpoint detection and response tools, and network monitoring systems to triage alerts, investigate suspicious activity, respond to phishing and malware incidents, and contribute to continuous improvement of detection and response processes. In addition to her operational responsibilities, Chelsea is deeply committed to mentoring aspiring cybersecurity professionals and career changers who are working to break into the field. She provides practical guidance on building foundational knowledge, and navigating early career growth. She believes strong security teams are built through consistency, collaboration, and investing in people, and she is passionate about helping the next generation of analysts build confidence and capability in cybersecurity.

Come see Chelsea Bryan at RVAsec 15!