Ahead of the Breach

Zoom's Andy Grant on Offensive Intuition and Letting Hackers Hunt

31 min · 9. apr. 2026
episode Zoom's Andy Grant on Offensive Intuition and Letting Hackers Hunt cover

Description

What happens when you remove timeboxes, rigid scope, and checklist-driven testing from offensive security? In this episode of Ahead of the Breach, we sit down with Andy Grant to explore what it looks like to build an intuition-driven offensive security program, one designed to let skilled engineers follow the signal instead of the schedule. Drawing from more than a decade in consulting and product security, Andy shares how traditional two-week pentests often cut off discovery just as understanding begins to form. His solution: hire exceptional hackers, give them space to explore, and focus on the most impactful risks rather than superficial coverage metrics.

Comments

0

Be the first to comment

Sign up now and become a member of the Ahead of the Breach community!

Get Started

1 month for 9 kr.

Then 99 kr. / month · Cancel anytime.

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

All episodes

51 episodes

episode Gary Lobermier on Scaling Red Team Automation with AI to Run Hundreds of Real Attacks Daily artwork

Gary Lobermier on Scaling Red Team Automation with AI to Run Hundreds of Real Attacks Daily

Most security teams test their detections once a year. Gary Lobermier, Lead Adversarial Security Engineer at Northwestern Mutual, built something different: a custom automation platform that executes hundreds of MITRE ATT&CK techniques daily across Windows, macOS, Linux, and AWS, giving his team real-time signal on whether their defenses actually hold. In this episode, Gary breaks down why off-the-shelf purple team tools fall short at enterprise scale, the procedure-level gap nobody talks about in the MITRE ATT&CK framework, and what EDR vendors don't advertise about their own coverage limits. He also shares how his non-traditional path (from network admin to red teamer) shaped the way he thinks about adversary emulation and detection engineering. If you're building or scaling an offensive security program and want to know what continuous validation actually looks like in practice, this one's worth your time.

1. maj 202631 min