Artwork
iconShare
 
Manage episode 513065905 series 3673385
Content provided by LegitimateCybersecurity. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by LegitimateCybersecurity or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://staging.podcastplayer.com/legal.

Why train when you can just hire?” In this episode, BlueVoyant Senior Vulnerability & Risk Analyst James Gustafson explains why that mindset—and the myth that AI can replace fundamentals—is putting orgs at risk. From Army “combat cable guy” to enterprise VM leader, James breaks down how to move from scan → prioritize → fix, how to develop junior talent without gatekeeping, and where AI actually helps (and where it absolutely doesn’t).

🎧 Audio listeners can subscribe on any platform (Spotify, Apple, etc.) or here: https://legitimatecybersecurity.podbean.com/

💼 Media & interview requests: [email protected]

You’ll learn

Why scan ≠ secure and how to make risk registers stick

The hiring shift: junior roles, budgets, and AI misconceptions

Packets vs. button-ology—what juniors lose when tools do too much

How to communicate VM risk at 10k+ asset scale

AI’s “sweet spot” for practitioners (and the painful edges)

Chapter Breaks

00:00 Cold Open — “Misconceptions about what AI can replace”

00:17 Intro — Who is James Gustafson (BlueVoyant)

01:14 Origin Story — Movies, IRC, and early curiosity

03:13 Army to IT — “Combat cable guy” and real-world networking

04:31 Breaking In — 2009 job market, degrees & certs

05:48 Obsession & Passion — How to pivot from IT to cyber

06:39 Where Did Juniors Go? — Budgets + AI hype

08:20 AI Reality Check — Risk shifts, phishing, unknowns

10:02 History Rhymes — From mainframes to printing press to AI

14:05 VM at Scale — Actionable comms, policy, and ownership

15:18 Why Orgs Scan but Don’t Fix — The uncomfortable truth

17:06 Priorities vs. Patching — Firefights and thin teams

18:05 SOC Then vs. Now — Packets, Snort, SIEM & automation

19:54 Button-ology vs Fundamentals — Hiring for platforms

22:10 Teaching Without Gatekeeping — Recreating “packet” intuition

28:07 Training the Next Gen — Translating deep knowledge

30:26 Parenting & Passion — “Be excellent at something”

34:27 What’s Going Right — Industry sobers up on AI

36:33 Thought Experiment — If we “laid down arms” in cyber…

38:08 Wrap — Why fundamentals still win

#cybersecurity #vulnerabilitymanagement #bluevoyant #ai #riskmanagement #soc #infosec #careerincybersecurity #cve #CISAKnownExploited #wireshark #Qualys #tenable #crowdstrike #microsoftdefender

  continue reading

20 episodes