
From Pre-Law to FLARE: How Josh Stroschein Became Google's Malware Analyst
About this episode
In this episode of Simply Defensive, Josh Mason and Wade Wells sit down with Josh Stroschein — aka The Cyber Yeti — a former professor turned reverse engineer now working on one of the largest malware analysis teams in the world.
Josh shares his unconventional path through .NET development, credit card processing security, and academia before landing at Google. He opens up about teaching reverse engineering while learning it himself, building educational CTFs, and the realities of making it as a full-time reverse engineer in an industry where those roles are rare.
What you'll hear:
🔹 From pre-law to pilot training to PhD in cybersecurity
🔹 How teaching RE forced him to truly master it
🔹 Life inside Google's FLARE team (via Chronicle → Mandiant)
🔹 Flareon CTF — the RE challenge that's run for 12 years
🔹 A wild Black Hat NOC story involving an infected Mac and Atomic Stealer
🔹 Using AI to build malware samples for training labs
🔹 Why going low-level is the best advice for blue teamers
Chapters:
00:00 Introduction and Welcome
00:50 Josh's Connection to Dr. Gerald Auger
02:00 The Non-Traditional Path: Pre-Law, Pilot Training & .NET Dev
05:00 Getting Into Security at a Credit Card Processor
07:00 Teaching Reverse Engineering at Dakota State
10:00 Flareon CTF and Educational CTF Design
14:00 Is Reverse Engineering Offensive or Defensive?
17:00 How Rare Are Full-Time RE Roles?
21:00 The Path to Google: Chronicle, Mandiant & FLARE
25:00 Learning Through Teaching and YouTube Content
28:00 Black Hat NOC Story: Catching Atomic Stealer Live
33:00 Using AI to Create Malware Training Samples
37:00 Building a Defang Tool (and .NET Nightmares)
40:00 Advice for Blue Teamers: Go Low-Level
🎧 Find Josh Stroschein:
→ Website: https://www.thecyberyeti.com
→ YouTube: The Cyber Yeti
→ Podcast: The Cyber Yeti Podcast
👥 Connect with the Hosts:
→ Josh Mason: https://www.linkedin.com/in/joshuacmason/
→ Wade Wells: https://www.linkedin.com/in/wadingthrulogs/
→ Swimlane: https://www.linkedin.com/company/swimlane
🎙️ Listen on Your Favorite Platform:
→ Spotify: https://open.spotify.com/show/72QTocT5FSTSPV7o1UcMS4
→ Apple Podcasts: https://podcasts.apple.com/us/podcast/simply-defensive/id1773806182
→ Full Playlist: https://youtube.com/playlist?list=PL4Q-ttyNIRAr6DVrsASx1-Fv-TsooJ3M4
👍 If you enjoyed this episode, don't forget to like, subscribe, and share with your fellow defenders. Every week, Josh Mason and Wade Wells bring you practical, no-fluff conversations with cybersecurity professionals who are doing the work.
=========================
All the ways to connect with Simply Cyber
https://SimplyCyber.io/Socials
=========================
This podcast is presented by Simply Cyber Media Group
Get every episode summarized
Each time Simply Defensive publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Simply Defensive

S6E2: John Hammond on Security Research, Storytelling, Deception, and Getting Hi...
Simply Defensive

From Blue Team Challenges to AI Innovations: A Conversation with Jason Haddix
Simply Defensive

Building Zero Trust Tools: Inside ThreatLocker with Product Manager Yuriy Tsiber...
Simply Defensive

Cyber Insurance Explained: What Blue Teams Need to Know Before an Incident
Simply Defensive