In line with Echelon Risk + Cyber's value of People with Personality, we are excited to continue our Cybersecurity Champion series, where we spotlight the incredible individuals who make up our team. Each month, we share the stories of professionals whose talent, dedication, and unique perspectives help keep organizations secure.
1. Your path to cybersecurity runs through the Marine Corps, Army Special Operations as a combat medic, police patrol work, and DoD research analysis. What made you decide to move into offensive security after all of that, and what carried over from those earlier careers?
I was working in a secured environment while at SOCOM in Tampa, and my daughter had just been born a couple months earlier. I didn't like working somewhere I couldn't have my phone, somewhere my wife couldn't reach me if there was ever an issue. So, I started looking for something else. I'd always been interested in cybersecurity, even dabbled in it on the side, but I didn't think I was smart enough to do it professionally.
Then one day I just jumped in. I started working through some learning modules, and realized I actually enjoyed it, and that it wasn't as hard as I'd built it up to be in my head. I got my first position through an apprenticeship program. They sent me a virtual machine; I hacked into it, wrote up a report, and walked them through it on a call. Eventually they took a chance on me even though I had no IT background.
The final role before my switch to cybersecurity, my technical title was Operations Research Analyst, but the actual work was intelligence and operations analysis for SOCOM focused on threat mitigation. Anything that dealt with potential harm to service members fell under that umbrella, and cyber was a subset of it. We were seeing things like Volt Typhoon and other APT activity targeting infrastructure near bases, affecting service members and their families. That became another route into this space through the CTI side.
What's carried over is that the red team mindset should be in everything. When you build something, you should be asking how it could be misused or bypassed. I saw this early in the Marine Corps with a mine roller design. The first version used a fixed offset for a row of wheels to detonate an IED before it hit the truck. Within a couple days, someone figured out they could just offset the charge to match it. Nobody had looked at the original design with an adversarial mindset, and it ended up costing millions more to fix than it would have to get right the first time.
2. You're also an adjunct lecturer at the University of Florida. What drew you to teaching, and has explaining security concepts to students changed how you think about the work itself?
I've always enjoyed teaching. Back in the Army, I taught combat lifesaver courses as a medic, showing people how to do things like applying a tourniquet. I liked passing knowledge on and watching that moment click for someone who was genuinely interested in learning.
I wouldn't say teaching changed how I think about the work itself. It changed my perspective on the work's impact and its accessibility. In technical fields, we get insular fast. We'll say something like "there's a SQL injection" assuming everyone follows, and most people have no idea what SQL even is. Teaching pushed me to take things back a few steps: how does a computer work, how does a website load, what's the actual difference between HTTP and HTTPS, and why does any of it matter.
It comes down to speaking to whoever your stakeholder is in the language they understand, whether that's technical, financial, or just basic curiosity, and tying it back to something relatable. Why shouldn't you leave a key hanging next to your front door? That kind of framing has been the biggest takeaway, based on the questions I get from students.
3. Are there any cybersecurity trends or emerging technologies that you're particularly excited or concerned about right now?
AI is at the forefront in a few different ways. There's pen testing against AI itself, figuring out how to test for secure AI and ML infrastructure. There's also the question of how attackers are using it, and how we mesh AI into manual testing workflows without trying to automate everything, which creates its own problems if you don't have the right guardrails in place.
Honestly, it feels a bit like the early hacker culture of the 80s, when people were first figuring out everything you could do with a computer and this new thing called the internet. It feels like this generation's version of that same moment.
4. What's one piece of advice you'd give to someone aspiring to get into cybersecurity today?
Soft skills matter more than people expect, and that includes just getting into the field in the first place. Don't pay someone a thousand dollars for a mentorship bootcamp. Most of us in this industry are genuinely passionate about helping people learn and grow. Reach out on LinkedIn, send an email, ask for five minutes of someone's time. Most of us are happy to talk about the stuff we care about.
5. What's something you've really come to appreciate about being part of Echelon Risk + Cyber?
Beyond the culture and the people, what stands out most on the offensive security side is that we're small and tight-knit, which gives everyone a lot of ownership over the direction of the practice and how our methodologies evolve. You don't feel lost in the noise here. We get to sit down and actually talk through how to do things better, instead of just feeling like pen testers who happen to work on the same team.
6. Outside of work, how do you like spending your time? Any hobbies or interests that you're passionate about?
I do a lot of yard work right now, mostly fixing up the house for the enjoyment of it. I'm big into working out, I keep chickens, and I also do some blacksmithing. I've got an anvil and a forge set up in my garage. I've made a few knives, one of which my dad uses regularly, plus candle holders, hooks, and random projects. I'm currently working on a beef turner for my smoker. I still play video games occasionally, though these days when I play I feel like I could be spending that time on something else.

7. What does being a Cybersecurity Champion mean to you?
Accessibility. It's being a bit of an evangelist, being someone people feel comfortable asking questions to, and meeting them wherever their level of understanding happens to be. My grandparents and someone working with cloud infrastructure are going to have completely different frames of reference. You need to be able to speak to both of them and make security make sense for each.
Curious about a career in Cybersecurity? Discover more about Echelon's team, culture, and open positions.