Interview with Josh Mason | Episode 62
E62

Interview with Josh Mason | Episode 62

In this episode of BHIS Presents: AI Security Ops, Bronwen Aker and Ethan sit down with Josh Mason for a wide-ranging conversation about cybersecurity careers, AI, small business security, and what it actually takes to help organizations make practical security decisions.

How do small businesses think about security when they do not have a full-time CISO?

And what happens when AI starts lowering the barrier for research, planning, governance, and security operations?

Not hypothetically. Not as a buzzword. But in the real world — where companies are trying to understand SOC 2, HIPAA, incident response, cyber insurance, AI governance, hallucinations, and the risks of letting tools make decisions they do not fully understand.

Josh brings a practical perspective from his background as a C-130 pilot, cyber leader, instructor, sales engineer, vCISO, consultant, and founder of Noob Village at DEF CON.

We dig into:
- What Noob Village is and why DEF CON needs an on-ramp for new people
- Josh’s path from Air Force pilot to cyber leadership
- Why communication and translation matter so much in cybersecurity
- What a vCISO actually does for small businesses
- How smaller companies think through SOC 2, HIPAA, GRC, pen testing, and incident response
- How AI can speed up research, planning, and draft creation
- Why AI-generated work still needs human review and source validation
- How companies are trying to govern employee use of AI tools
- Why cyber insurance, E&O coverage, and AI hallucinations are starting to overlap
- Where RAG and guardrails can help reduce risk
- How AI may reshape the work small businesses can do on their own
- Why trust, relationships, and human judgment still matter in consulting
- How hacker community, mentorship, and D&D all somehow fit together

This episode explores a practical shift in AI security: AI is not just changing the tools defenders use. It is changing how small businesses learn, make decisions, evaluate risk, and decide when they need expert help.

The takeaway: AI can make security work more accessible, but it does not replace experience, judgment, validation, or trust. The organizations that benefit most are the ones that use AI to accelerate good decisions — not outsource thinking entirely.

Chapters
  • (00:00) - Meet Josh Mason
  • (01:27) - Hacker Summer Camp and Noob Village
  • (06:45) - From Air Force Pilot to Cyber Leadership
  • (13:08) - What a vCISO Does for Small Businesses
  • (19:55) - Using AI for Research and Incident Response Planning
  • (24:46) - Small Business AI Security and Governance
  • (27:47) - Cyber Insurance, Hallucinations, and Guardrails
  • (31:43) - How AI Is Reshaping Small Business Security
  • (42:15) - Where to Find Josh

Click here to watch this episode on YouTube.


Brought to you by:
Black Hills Information Security 

☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/

Antisyphon Training

Active Countermeasures

Wild West Hackin Fest
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
https://poweredbybhis.com


Episode Video

Creators and Guests

Bronwen Aker
Host
Bronwen Aker
Bronwen Aker is a BHIS Technical Editor who joined full-time in 2022 after years of contract work, bringing decades of web development and technical training experience to her roles in editing pentest reports, enhancing QA/QC processes, and improving public websites, and who enjoys sci-fi/fantasy, Animal Crossing, and dogs outside of work.
Ethan Robish
Guest
Ethan Robish
Ethan Robish has worked with Black Hills Information Security (BHIS) since 2008 — first as an intern and then as a full-time Security Consultant starting in 2012. In his current role as a Threat Hunter, Ethan is involved with customer engagement, research, working with Active Countermeasures’ AC-Hunter, as well as improving BHIS HTOC and SOC offerings. Previously, he implemented defensive security solutions for the Exchange Online security team as a Microsoft intern. While in college, he competed in the International Collegiate Programming Competition (ICPC) World Finals. In his time off, he enjoys cooking, playing the piano, and reading fantasy novels.
Josh Mason
Guest
Josh Mason
Josh Mason provides strategic guidance and technical expertise to help organizations protect their data, applications, and people from evolving cyber threats. With extensive experience spanning cybersecurity, organizational development, and business strategy, Josh has advised Fortune 50 enterprises, government and military leaders, and emerging startups on strengthening their security posture. He has developed and taught courses covering secure software development, offensive and defensive cybersecurity, and risk management, and has demonstrated security solutions to executive and technical audiences around the world.