Cyber Game Changers Women Who Lead, Secure and Inspire

Blacks in Cyber Village @ DEF CON 33 · Day 1 · Blacks in Cyber Village

Overview

This compelling panel discussion, "Cyber Game Changers Women Who Lead, Secure and Inspire," brought together three distinguished women in cybersecurity: Jess Hoffman, Deputy CISO for the City of Philadelphia; Nikia Henderson, a Cyber Strategist and Portfolio Manager at CISA; and Ariel Bane, CISA's Region Three Chief of Cybersecurity. The session at the Blacks in Cyber Village conference served as a powerful platform to highlight real stories, offer invaluable lessons on career building, mentorship, and the crucial work of fostering resilient and inclusive networks within the cybersecurity domain. Far from a traditional technical deep dive into vulnerabilities or exploits, this talk instead focused on the human element of cybersecurity leadership.

Watch on YouTube

Visual summary for Cyber Game Changers Women Who Lead, Secure and Inspire
Visual summary for Cyber Game Changers Women Who Lead, Secure and Inspire

Key moments

  1. 0:00 Introduction: Cyber Game Changers Panel Goals
  2. 1:13 Ariel Bane's CISA Role and Mission
  3. 3:00 Diverse Paths to Cyber Security Leadership
  4. 4:10 Jess Hoffman's Career Path and Learning Advice
  5. 6:25 Jess's Diversity-Focused Podcast Hosting Story
  6. 7:50 Keys to Success: Transitioning to Deputy CISO

Cyber Game Changers Women Who Lead, Secure and Inspire

Speakers: Jess Hoffman, Deputy CISO, City of Philadelphia; Nikia Henderson, Cyber Strategist, Portfolio Manager, CISA; Ariel Bane, Region Three Chief of Cybersecurity, CISA

Conference: Blacks in Cyber Village

YouTube: https://www.youtube.com/watch?v=qN9qduX-fFM

Overview

This compelling panel discussion, "Cyber Game Changers Women Who Lead, Secure and Inspire," brought together three distinguished women in cybersecurity: Jess Hoffman, Deputy CISO for the City of Philadelphia; Nikia Henderson, a Cyber Strategist and Portfolio Manager at CISA; and Ariel Bane, CISA's Region Three Chief of Cybersecurity. The session at the Blacks in Cyber Village conference served as a powerful platform to highlight real stories, offer invaluable lessons on career building, mentorship, and the crucial work of fostering resilient and inclusive networks within the cybersecurity domain. Far from a traditional technical deep dive into vulnerabilities or exploits, this talk instead focused on the human element of cybersecurity leadership.

The speakers, each with unique backgrounds and career trajectories, shared their personal "keys to success" in navigating and excelling within the challenging cybersecurity landscape. Their collective goal was to inspire, provide practical tools for career advancement, and empower attendees to shatter stereotypes and achieve professional excellence. The panel showcased a diverse blend of experience, from deputy CISOs and supervisory roles to executive leadership, underscoring that there are multiple, often non-traditional, pathways to significant impact and leadership in the field.

The discussion transcended mere career advice, delving into the psychological and interpersonal aspects of professional growth, such as overcoming imposter syndrome, the power of manifestation, and the indispensable role of community and mentorship. By sharing their journeys, including pitfalls and triumphs, Hoffman, Henderson, and Bane provided a holistic view of what it truly means to be a "cyber game changer"—not just in terms of technical prowess, but in leadership, resilience, and the ability to inspire others.

Background

▶ Watch: Introduction: Cyber Game Changers Panel Goals (0:00)

The cybersecurity industry, while rapidly expanding, continues to grapple with significant challenges related to diversity and inclusion, particularly the underrepresentation of women and minorities in leadership and technical roles. This panel emerged from a recognition of these disparities, aiming to provide role models and actionable strategies for success. The speakers themselves exemplified varied entry points into the field, some transitioning from traditional IT paths, others from entirely different disciplines like education or business and finance, highlighting that a singular, linear career trajectory is no longer the norm, nor is it necessarily the most effective.

A key backdrop to the discussion was the critical mission of the Cybersecurity and Infrastructure Security Agency (CISA), a federal agency dedicated to protecting the nation's critical infrastructure. Ariel Bane and Nikia Henderson, both working at CISA, provided insight into the agency's vital, often unseen, work in safeguarding sectors like healthcare, energy, banking, transportation, and public safety. They underscored the increasing frequency and complexity of cyber incidents, particularly from sophisticated nation-state actors like the People's Republic of China (PRC) and Volt Typhoon actors, who engage in espionage and intellectual data theft by "living off the land." This context reinforced the high stakes and constant vigilance required in modern cybersecurity.

The panel also touched upon the practical realities of working within government, including navigating budget cuts and workforce transitions, yet maintaining unwavering commitment to the mission. The discussion implicitly addressed the evolving nature of cyber threats, from zero-day vulnerabilities to the emergence of new technologies like AI and quantum computing, which constantly demand new skills and adaptive strategies from defenders. The emphasis on soft skills, continuous learning, and networking as crucial complements to technical knowledge stemmed directly from the dynamic and complex environment in which these leaders operate.

Key Findings

▶ Watch: Diverse Paths to Cyber Security Leadership (3:00)

The panel discussion unveiled several core principles and strategies that the speakers identified as fundamental to their success and for any aspiring cybersecurity professional:

  • The Power of Manifestation and Goal Setting: Ariel Bane articulated a structured approach to manifestation, encouraging attendees to "start with the end in mind." This involves visualizing career goals, conducting a gap skills analysis to identify necessary tangible steps, and "acting as if" one has already achieved the desired role. This practice not only builds confidence but also helps identify what one truly enjoys or dislikes in a role, preventing commitment to unsuitable paths.
  • Community and a "Gang Gang" of Mentors: Jess Hoffman championed the concept of a "gang gang" of mentors, emphasizing that no single mentor can provide all the necessary guidance. The collective wisdom and support from a diverse group of mentors and a strong professional community were highlighted as crucial for navigating challenges, gaining different perspectives, and receiving validation. Ariel reinforced this, stating that realizing she wasn't alone in her struggles was a significant step in overcoming imposter syndrome.
  • Overcoming Imposter Syndrome: Acknowledging the pervasive nature of imposter syndrome, which a majority of the audience also experienced, the speakers offered practical coping mechanisms. Jess's approach involved acknowledging its inevitability ("it's coming, I know it is") but refusing to let it derail her day, drawing strength from the belief others have in her. Ariel advocated for open communication with supervisors, seeking continuous feedback as a form of validation, and building personal resilience to accept failure as a natural part of the learning process.
  • Embracing Non-Traditional Career Paths: The panel collectively demonstrated that there is no singular, prescribed route to success in cybersecurity. Jess Hoffman's journey from teaching to Deputy CISO, Nikia Henderson's pivot from business and finance to cyber policy, and Ariel Bane's progression through various federal agencies showcased the value of diverse experiences and skills. They explicitly stated that traditional certifications or linear career progression are not the only, or even always the best, indicators of potential.
  • Continuous Learning as a Core Competency: Ariel Bane stressed the critical importance of being a continuous learner, especially given the rapid evolution of cyber threats and technologies (e.g., Kubernetes, containerization, AI, quantum computing). She advised against trying to master everything but rather to know "a little bit about everything," focusing on foundational areas like operating systems, networking, and software applications. While certifications can standardize knowledge, she noted that targeted, high-value certifications aligned with career goals are more effective than accumulating many irrelevant ones.
  • The Primacy of Soft Skills: Nikia Henderson and Ariel Bane passionately argued for the paramount importance of soft skills over purely technical capabilities, especially in leadership roles. Key soft skills identified included personal resilience (viewing failure as feedback, "fail fast, fail hard, bounce back"), discernment (knowing which ideas to prioritize and present), creativity (rethinking problems when faced with "no" as a redirection), communication (storytelling, professional writing, presentation), and overall human-to-human skills. Nikia emphasized that technology can be taught, but character and fit are often more critical hiring factors.
  • Identifying and Leveraging a Unique Value Proposition: Ariel Bane shared her personal strategy of identifying and strengthening her unique skills, rather than solely focusing on weaknesses. Her expertise in automating, orchestrating, and optimizing systems provided a distinct advantage, earning her recognition and awards. This approach encourages individuals to find their niche and build upon it, creating a differentiated professional identity.

Technical Deep Dive

▶ Watch: Jess Hoffman's Career Path and Learning Advice (4:10)

While the panel was primarily focused on career development and leadership, the speakers' roles are deeply embedded in the technical realities of cybersecurity, influencing strategic and operational decisions that have profound technical implications. Their insights, though not detailing specific code or exploits, illuminate the critical technical domains and challenges they navigate daily.

Ariel Bane, as CISA's Region Three Chief of Cybersecurity, oversees a multi-disciplinary team that engages in comprehensive cyber preparedness, risk mitigation, and incident response and coordination for critical infrastructure owners and operators. This involves hands-on technical analysis and keyboard work by her team to ensure the resilience of vital sectors such as healthcare, energy, and financial institutions. Her work directly confronts the threats posed by sophisticated actors, including nation-state groups like the People's Republic of China (PRC), exemplified by the Volt Typhoon actors. These groups employ advanced tactics, often "living off the land" within victim networks, making detection and remediation technically challenging. Ariel's successful webinar on this topic underscores the need for deep technical understanding of adversary tactics.

Jess Hoffman, as the Deputy CISO for the City of Philadelphia, is responsible for the cybersecurity posture of an entire major metropolitan area. This role inherently involves managing the security of diverse and often complex IT infrastructure, including critical services like public transportation and 911 emergency systems. She highlighted the prevalent challenge of old, outdated infrastructure within government entities, which presents significant technical vulnerabilities and complicates defensive efforts. Her team's daily work involves securing these systems against a constant barrage of threats, requiring a blend of technical expertise, strategic planning, and resource management.

Nikia Henderson, a Cyber Strategist and Portfolio Manager at CISA, focuses on the strategic implementation and operationalization of cybersecurity initiatives. While she humorously admitted to disliking coding due to dyslexia, her role is intrinsically linked to the effective deployment and management of technical solutions. She ensures that the right people, with the right technical skills, and adequate funding are in place to achieve cybersecurity missions. This involves understanding the technical landscape, identifying emerging threats, and translating complex technical requirements into actionable strategies that can be executed by technical teams. Her work bridges the gap between high-level policy and on-the-ground technical defense.

The panel referenced several key technical areas and challenges:

  • Zero-day vulnerabilities and their impact on incident response.
  • The growing importance of application security, particularly concerning modern architectures like Kubernetes and containerization. Ariel acknowledged missing this "wave" and the continuous effort required to stay updated.
  • The looming impact of Artificial Intelligence (AI) and quantum computing on future cybersecurity landscapes, emphasizing the need for proactive skill development in these areas.
  • The foundational technical skills, which Ariel identified as crucial for any cyber professional: a deep understanding of operating systems, networking, and software applications.
  • The often "invisible" nature of cyber attacks compared to physical assaults, yet their profound impact on daily life and critical services.
  • The strategic value of automation, orchestration, and optimization of processes, which Ariel identified as her unique value proposition. These are technical solutions that enhance efficiency and effectiveness in cybersecurity operations.

The discussion also provided a stark reminder of the breadth of CISA's critical infrastructure sectors, currently numbering 16 and soon expanding to 17 with the inclusion of space. These sectors include water, gas, utilities, freight, air, transportation, medication, manufacturing, food, and public safety (911). Protecting these diverse environments demands a vast array of specialized technical knowledge and continuous adaptation to evolving threat landscapes.

Demo / Proof of Concept

▶ Watch: Jess's Diversity-Focused Podcast Hosting Story (6:25)

This panel discussion did not feature a traditional technical demonstration or a proof of concept in the sense of showcasing a specific tool, exploit, or defensive technique. The nature of the talk was instead focused on leadership, career development, and the human elements of cybersecurity.

However, the speakers themselves served as a powerful "proof of concept" for the principles they espoused. Their real-world achievements and the impact of their work demonstrated the efficacy of their strategies for career building, resilience, and fostering inclusive networks. For instance:

  • Ariel Bane's leadership in coordinating cybersecurity advisers across the nation for the FIFA Club World Cup games, involving five million people and 18 host cities (including Mexico and Canada), showcased the practical application of her strategic and leadership skills on an international scale. Her engagement with the Ukrainian government in Poland on cyber defense during wartime further highlighted the global impact of her expertise. The overwhelming success of her webinar on PRC/Volt Typhoon actors, attracting over 1,000 registrants for the first session, underscored her ability to address critical technical threats and disseminate vital intelligence effectively.
  • Jess Hoffman's journey from an education background to Deputy CISO of a major city, despite initial rejections, exemplified the power of manifestation and perseverance. Her initiative to start a podcast segment to promote diverse voices in cybersecurity demonstrated her commitment to community and breaking traditional molds.
  • Nikia Henderson's transition from business and finance to a strategic role at CISA, driven by events like the Edward Snowden revelations and a retailer hack, illustrated the non-traditional pathways into cyber and the critical need for strategic thinking in the field. Her ability to operationalize complex cyber strategies for CISA, ensuring proper funding and personnel, proved the value of her unique skillset.

These examples, drawn directly from their experiences, served as compelling evidence that the principles of continuous learning, strategic networking, personal resilience, and leveraging soft skills are indeed "game changers" in the cybersecurity domain.

Defensive Implications

▶ Watch: Keys to Success: Transitioning to Deputy CISO (7:50)

The insights from "Cyber Game Changers" offer crucial defensive implications, not just for individual practitioners, but for organizations striving to build more robust and resilient cybersecurity postures. The focus on human capital, strategic thinking, and adaptive learning is integral to effective defense in an ever-evolving threat landscape.

For Organizations and Hiring Managers:

  • Diversify Hiring Strategies: The panel strongly advocated against relying solely on traditional certifications or linear career paths. Hiring managers should broaden their scope, considering candidates with diverse backgrounds and non-traditional entry points into cyber. This brings varied perspectives and problem-solving approaches, essential for tackling complex threats.
  • Prioritize Soft Skills: Organizations must recognize that technical proficiency alone is insufficient. Interpersonal skills, personal resilience, communication, discernment, and creative problem-solving are paramount. Investing in training and development programs that foster these soft skills for all employees, especially in leadership, will lead to more effective and adaptable teams.
  • Foster a Culture of Continuous Learning: Given the rapid pace of technological change (e.g., AI, quantum computing, Kubernetes, containerization) and evolving threats (e.g., PRC/Volt Typhoon), organizations must actively support and incentivize continuous learning. This includes providing access to relevant training, workshops, and opportunities to explore new domains like application security.
  • Build Strong Internal Communities and Mentorship Programs: Creating a supportive environment where employees feel comfortable discussing challenges like imposter syndrome and seeking feedback from supervisors can significantly boost morale and performance. Formal and informal mentorship programs ("gang gang" of mentors) are vital for knowledge transfer, career guidance, and retention.
  • Strategic Resource Allocation: Nikia Henderson's role highlights the need for organizations to strategically allocate funding and personnel to cybersecurity initiatives. Understanding the "why" behind technical investments and ensuring alignment with organizational missions is critical for operationalizing defense effectively.
  • Engage with CISA: Critical infrastructure owners and operators must actively engage with CISA for cyber preparedness, risk mitigation, and incident response. As Ariel Bane noted, CISA is a "voluntary agency," meaning proactive collaboration is key to leveraging their expertise in protecting the 16 (soon 17) vital sectors.

For Individual Defenders and Aspiring Professionals:

  • Embrace Continuous Learning: Stay perpetually curious and committed to learning. While a deep dive into operating systems, networking, and software applications forms a strong foundation, also stay abreast of emerging technologies like AI and quantum computing. Focus on certifications that strategically align with your career goals rather than collecting them indiscriminately.
  • Cultivate Soft Skills Aggressively: Actively develop personal resilience, viewing failures as feedback and "no" as a redirection to find alternative solutions. Practice discernment in presenting ideas, demonstrating thoughtful prioritization. Enhance communication skills through storytelling, professional writing, and presentations, as the ability to translate technical jargon is a "secret sauce."
  • Build a Robust Network: Actively participate in conferences and professional communities like Blacks in Cyber. Cultivate non-transactional relationships with mentors and peers, offering support and value even when not directly asking for something. This "gang gang" of mentors is invaluable for guidance and opportunities.
  • Identify and Strengthen Your Unique Value Proposition: Discover what makes you stand out. Whether it's automation, orchestration, optimization, or a unique blend of technical and interpersonal skills, focus on honing these strengths rather than solely trying to fix every weakness.
  • Practice Manifestation and Goal Setting: Clearly define your career aspirations and work backward to identify the skills and experiences needed. "Act as if" you are already in that role to build confidence and identify potential misalignments early.
  • Understand the Broader Context: Recognize that cybersecurity extends beyond technical exploits. Comprehend the strategic implications of threats, the operational challenges of protecting critical infrastructure, and the human element in every cyber defense effort.

Key Takeaways

  • Diverse Paths to Success: Cybersecurity careers are not linear; success can be achieved through varied backgrounds and non-traditional routes, with diverse experiences being a significant asset.
  • Continuous Learning is Non-Negotiable: Staying updated on foundational technical skills (OS, networking, software) and emerging technologies (AI, quantum, Kubernetes, containerization) is crucial, with strategic certifications complementing practical experience.
  • Soft Skills are Paramount: Personal resilience, communication, discernment, creativity, and human-to-human skills are often more critical than purely technical abilities, especially for leadership and team effectiveness.
  • Community and Mentorship are Essential: Building a strong, non-transactional network and a "gang gang" of mentors provides invaluable support, guidance, and opportunities for growth and overcoming challenges like imposter syndrome.
  • Embrace Failure and Redirection: Viewing failures as "feedback" and rejections ("no") as "redirections" fosters resilience and encourages creative problem-solving, rather than leading to defeat.
  • Identify Your Unique Value: Focus on strengthening your distinct skills and value propositions, such as automation or optimization, to differentiate yourself and drive impact within your organization.

About the Speaker(s)

Ariel Bane serves as CISA's Region Three Chief of Cybersecurity, where she leads a multi-disciplinary team covering five states and Washington D.C. Her team is responsible for cyber preparedness, risk mitigation, and incident response for critical infrastructure owners and operators, including vital sectors like healthcare, energy, and banking. Ariel is a GS15, having advanced rapidly through various federal government roles after starting as a GS7. She received a Smart Scholarship and has experience with agencies such as the DoD, Federal Trade Commission, and Food and Drug Administration, where she gained hands-on insights into different tools as a watch officer in a SOC. She emphasizes her unique value in automating, orchestrating, and optimizing systems.

Jess Hoffman is the Deputy CISO for the City of Philadelphia. Her career path demonstrates a non-traditional entry into cybersecurity, initially having a background in education and teaching. She has experience in both federal government and private industry as an auditor before manifesting her goal of becoming a CISO. Jess is also an educator, teaching at Penn State and Temple, and is a podcast host, where she actively champions diversity by creating a segment focused on women and people of color in cyber. She is a strong advocate for public service and community engagement.

Nikia Henderson is a Cyber Strategist and Portfolio Manager at CISA. Her journey into cybersecurity was inspired by real-world events, including the Edward Snowden revelations and a retailer hack through an HVAC system, prompting her to pursue a Master's in Cyber Policy after earning a Bachelor's in Business and Finance from Spelman College. Nikia's expertise lies in the strategic implementation and operationalization of cybersecurity, focusing on ensuring that organizations have the right people, funding, and strategic outlines to accomplish their missions. She identifies her superpower as translating technical information into strategic approaches, effectively bridging the gap between technical operations and organizational goals.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

This is a career development and representation panel — judge it on that lane, not against a kernel exploit talk. On its own terms, it's competent and genuine: three credible speakers with real government seats sharing honest career narratives for an audience that doesn't often see itself represented at the front of the room. Nothing here is groundbreaking, and it won't change how a single defender operates tomorrow, but it's doing what it set out to do with reasonable sincerity.

Heather Calloway (CISO) — SOLID

Three credible, senior practitioners sharing real career experience in a community context that has genuine value for its intended audience. But this is professional development content, not security leadership content — and those are different things.

→ Top-rated talks at Blacks in Cyber Village @ DEF CON 33

All talks from Blacks in Cyber Village @ DEF CON 33