In line with Echelon's value of People with Personality, we are excited to continue our Cybersecurity Champion series, where we spotlight the incredible individuals who make up our team. Each month, we share the stories of professionals whose talent, dedication, and unique perspectives help keep organizations secure.
Meet Steve Snider, Senior Cybersecurity Manager at Echelon Risk + Cyber. Steve built his career in offensive cyber operations for the Department of Defense before moving into the private sector, where he led red team, penetration, and wireless testing engagements for large organizations. Today he focuses on strategic advisory, helping clients build stronger, more resilient security programs.
What's a lesson from your time in military cyber operations that still shows up in how you work with clients now?
It's something that's probably more valid than people realize. The low-level threats, the ones using publicly available tools, are the ones you're going to see in network defenses. Those are the ones you're going to detect. What people don't realize is how many tools, exploits, and implants exist that high-level threat actors use. They can be sitting in a network, gathering data, exfiltrating information, and people will never realize it because those actors are using tools most people aren't even aware of.
Offensive techniques evolve fast. What's changed the most in the attacker playbook since you started this work?
I'm not on the technical side of things day to day anymore, but what I've noticed is the sheer number of Active Directory exploits available now for elevating permissions inside a network. There are so many ways to escalate access once you're in, and most of them come down to configuration rather than missing patches. I rarely see a client that isn't exposed to at least some of those paths. Earlier in my career, when I started in consulting, it was more about gaining access to a server in whatever way you could, then finding things within that server to elevate your access from there. Now the paths to elevate permissions once you're in a network are far more numerous.
If you were advising a security leader who could only fix one thing in the next 90 days, what would you tell them to prioritize?
The security team. The people on the team. There's all kinds of tooling out there, but without the right people configuring it, tuning it, and making changes, the default settings are never going to be what you're actually looking for. Getting the right people in those positions is what I'd prioritize first. The trait I look for most is curiosity, people who always want to learn and improve.
What's something you've really come to appreciate about being part of Echelon Risk + Cyber?
The people on our team, especially on the offensive security team. Watching them grow and gain knowledge over the past few years and seeing how excited they get when they figure out a solution to a problem they've been working through has been great. Just great people all around.
Outside of work, how do you like spending your time? Any hobbies or interests that you're passionate about?
I live in Denver, so I like getting up into the mountains when I can. Skiing, camping, taking my Jeep out on some off-road trails. I also try to get out of the country a few times a year. Most recently I went down to South America. Asia is next on my list. I'd like to get over there and try the food.
What does being a Cybersecurity Champion mean to you?
Constantly finding ways to help clients improve their network security. I prefer engagements where a client wants to actually improve their security stance, not just check a box knowing that nothing's going to get fixed. If they're not going to actually improve their security stance, compliance doesn't really do its job at that point. Clients like that are fewer and fewer than they were when I started as a consultant eight years ago, and to their credit, most of them are upfront about it from the start.
Curious about a career in Cybersecurity? Discover more about Echelon's team, culture, and open positions.