
The Evolution of Offensive Security: Insights from Dave Mayer
About this episode
About The Guest(s):
Dave Mayer is an Offensive Security professional with extensive experience in Red Teaming and Penetration Testing. He has a background in computer science and has worked for companies like Citibank and Grim before founding Neuvik. Dave is also a mentor and educator in the field of Offensive Security.
Summary:
Dave Mayer, an experienced Red Team professional, shares his journey in the field of Offensive Security. He discusses his background in computer science, his transition from development to Red Teaming, and his work at Citibank and other consulting firms. Dave emphasizes the difference between Red Teaming and Penetration Testing, highlighting the intent and level of detail involved in each. He also provides insights into when organizations should consider conducting a Red Team operation and the importance of cloud security in today's hybrid environments. Dave recommends learning programming and scripting languages like Python and PowerShell to excel in Offensive Security. He also discusses the role of bug bounties and disclosure programs in finding vulnerabilities and improving security.
Key Takeaways:
- Red Teaming is focused on remaining undetected and achieving a specific objective, while Penetration Testing aims to find as many vulnerabilities as possible across multiple systems.
- Red Teaming should be conducted after organizations have matured their vulnerability scanning and Penetration Testing processes.
- Cloud security is crucial in today's hybrid environments, and understanding cloud platforms and APIs is essential for Offensive Security professionals.
- Learning programming and scripting languages like Python and PowerShell is important for automating tasks and building tools in Offensive Security.
- Bug bounties and disclosure programs can be valuable for finding vulnerabilities and improving security, but organizations should provide clear contact information for researchers to report vulnerabilities.
Dave's social media and Neuvik website:
Get every episode summarized
Each time Phillip Wylie Show publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Phillip Wylie Show

Vulnerability Research, AI Slop, and Why Fundamentals Still Win with Stephen Sim...
Phillip Wylie Show

Purple Teaming with Sarah Hume: Turning Threat Intelligence Into Actionable Test...
Phillip Wylie Show

From English Teacher to OSINT Investigator: Lindsey Yagi-Hatake on Breaking Into...
Phillip Wylie Show

AI, Automation, and the Future of Penetration Testing with Herman Zubenko
Phillip Wylie Show
