Jason Edwards
Certified: The GIAC GSLC Audio Course
This audio-first cybersecurity course is built for busy professionals who need security that works in real environments, not just on slides. You’ll learn how to design monitoring, logging, SIEM, and SOAR operations that produce usable visibility, reduce noise, and support fast, defensible response. Along the way, you’ll connect technical controls to practical program execution: ownership, SLAs, governance, decision rights, and evidence that holds up during incidents and audits. You’ll also strengthen your ability to explain risk in business terms and prioritize work using context like exposure...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 33 — Explain AI Types and Capabilities Leaders Must Understand to Govern Risk 10.02.2026 18:52
This episode explains essential AI concepts that security leaders must understand to govern risk and make defensible decisions, reflecting exam expectations around emerging technology oversight and high-level risk-benefit analysis. You will define machine learning, deep learning, and generative models in practical terms, then distinguish training from inference so you can reason about where data f...
Episode 32 — Build Application Security Testing Strategy: SAST, DAST, SCA, and Triage 10.02.2026 17:09
This episode builds a practical application security testing strategy and clarifies how SAST, DAST, and SCA complement each other, a common exam angle because leaders must understand where each technique fits and how to manage outcomes. You will learn clear definitions for each testing type, when to run them in the lifecycle, and how to triage findings based on exploitability, exposure, and busine...
Episode 31 — Drive DevSecOps Adoption With Measurable Controls and Shared Ownership 10.02.2026 17:35
This episode explains how to operationalize DevSecOps so security becomes a shared responsibility across development, operations, and security teams, which is frequently tested through questions about governance, workflow integration, and measurable outcomes. You will learn how to place security controls into delivery pipelines where they provide fast feedback, how to tune thresholds so only high-...
Episode 30 — Secure Infrastructure as Code With Reviews, Policy Gates, and Guardrails 10.02.2026 14:40
This episode explains how to secure infrastructure as code (IaC) so speed and scale do not amplify misconfigurations, a theme the exam tests through governance, cloud security, and operational control alignment. You will learn how IaC changes the risk landscape by making infrastructure changes frequent and repeatable, why reviews must focus on security-relevant properties such as exposure, identit...
Episode 29 — Manage Dependency and Component Risk Across Build Pipelines and Releases 10.02.2026 14:29
This episode teaches dependency and component risk management, a key exam topic because modern application security depends heavily on third-party libraries, containers, and services that can introduce urgent, high-impact vulnerabilities. You will learn how to inventory components so you know what you actually run, evaluate risk using exposure and asset criticality, and build upgrade and patch pro...
Episode 28 — Operationalize Secure Coding Expectations Without Slowing Delivery Excessively 10.02.2026 15:02
This episode focuses on making secure coding expectations practical, consistent, and scalable, aligning with exam expectations that leaders can drive behavior change without creating counterproductive friction. You will learn how to define secure coding expectations as patterns and defaults, such as safe input handling, robust authorization checks, careful error management, and appropriate use of...
Episode 27 — Prioritize Application Risks Using Threat Modeling and Abuse-Case Thinking 10.02.2026 15:46
This episode explains threat modeling and abuse-case thinking as methods to prioritize application risk, a concept the exam often evaluates through risk-based decision making and practical governance. You will learn how to identify assets, entry points, trust boundaries, and data flows, then describe attacker goals in abuse cases that make risks concrete and comparable. We show how to rank risks u...
Episode 26 — Secure the SDLC by Embedding Security Requirements and Design Reviews 10.02.2026 15:18
This episode teaches how to embed security into the software development lifecycle through requirements and design reviews, an exam-relevant topic because it tests leadership ability to operationalize security without blocking delivery. You will learn how to express security requirements as testable outcomes, where they should appear in planning and backlog workflows, and how to run lightweight de...
Episode 25 — Improve SOC Handoffs With Playbooks, Case Management, and Evidence Standards 10.02.2026 15:43
This episode focuses on improving SOC handoffs so investigations remain coherent across shifts, teams, and escalations, a frequent exam concept because it combines process control, evidence quality, and operational resilience. You will learn how playbooks create consistent actions for common incident types, how case management preserves timelines and decision rationale, and how evidence standards...
Episode 24 — Build Use Cases That Improve Detection Fidelity and Analyst Confidence 10.02.2026 14:37
This episode explains how SOC use cases translate raw data into actionable detection, and why use-case quality is often the difference between a trusted monitoring program and an alert factory, making it highly relevant to exam questions on monitoring strategy and operational management. You will learn what a use case must include, such as a clear trigger, context, expected analyst actions, and su...
Episode 23 — Set SOC Metrics That Drive Quality, Not Ticket Volume Theater 10.02.2026 15:23
This episode teaches how to select SOC metrics that reflect real security outcomes, a topic the exam tests through governance, measurement, and leadership judgment questions. You will learn why raw ticket volume and alert counts often reward shallow work and noisy detections, then shift to quality-focused measures such as time to detect, time to contain, true positive rates, investigation complete...
Episode 22 — Staff a SOC With Clear Roles, Skills, and Escalation Paths 10.02.2026 17:52
This episode covers SOC staffing as an operating design problem, emphasizing exam-relevant concepts like role clarity, escalation discipline, and sustainable coverage rather than simply “adding headcount.” You will define common SOC roles and capabilities, including tiered analysts, incident responders, detection engineers, and content managers, then learn how responsibilities should shift as matu...
Episode 21 — Choose SOC Operating Models: In-House, Outsourced, Hybrid, and Follow-the-Sun 10.02.2026 19:02
This episode explains how to choose a SOC operating model that fits organizational risk, coverage needs, and maturity, a common exam theme because leaders must justify tradeoffs in cost, control, speed, and accountability. You will compare in-house SOCs, outsourced providers, hybrid arrangements, and follow-the-sun coverage, focusing on what changes in ownership of detection engineering, alert tun...
Episode 20 — Define SOC Mission and Scope That Matches Business Risk and Maturity 10.02.2026 16:08
This episode defines what a Security Operations Center is supposed to accomplish and how to set mission and scope so the SOC delivers measurable value, a frequent certification exam theme where governance must align to operational reality. You will learn how to articulate mission in terms of outcomes like detection, triage, and coordinated response, then define scope by assets, data sources, cover...
Episode 19 — Design Disaster Recovery Targets: RTO, RPO, Testing, and Restoration Evidence 10.02.2026 15:50
This episode explains disaster recovery targets and how leaders translate them into tested capabilities, reinforcing exam-critical definitions like RTO and RPO and the operational implications behind them. You will define recovery time objective as the time needed to restore service availability and recovery point objective as the acceptable window of data loss, then learn how to select targets ba...
Episode 18 — Build Business Continuity Planning That Reflects Real Business Dependencies 10.02.2026 17:58
This episode teaches business continuity planning as a practical map of what must keep working during disruption, focusing on dependencies and priorities that are commonly evaluated on the certification exam through governance and operational resilience questions. You will learn how to define critical business processes in business language, identify dependencies across people, vendors, applicatio...
Episode 17 — Operationalize Lessons Learned Into Program Improvements and Reduced Recurrence 10.02.2026 16:04
This episode shows how to turn incidents into measurable program improvements, a theme the certification exam often tests by asking how leaders prevent recurrence and mature capabilities over time. You will learn the difference between a narrative debrief and a lessons-learned process that produces prioritized actions with owners, deadlines, and success criteria. We cover how to reconstruct timeli...
Episode 16 — Drive Eradication and Recovery With Verification, Monitoring, and Closure Criteria 10.02.2026 17:10
This episode covers eradication and recovery as disciplined phases that restore trustworthy operations, not merely “getting systems back online,” and it emphasizes exam-relevant concepts like verification, monitoring, and closure criteria. You will learn how to remove the root cause by eliminating attacker tooling, persistence, and access paths, including credential resets, patching, configuration...
Episode 15 — Run Containment Choices Without Breaking Business Operations or Safety 10.02.2026 16:36
This episode teaches containment as a set of deliberate choices that must stop attacker progress while protecting critical operations, a leadership balancing act that appears on the certification exam across incident response and program management. You will define containment goals, compare partial versus full isolation, and learn how to choose containment actions based on severity, scope, and op...
Episode 14 — Coordinate Communications: Legal, PR, Executives, and Affected Stakeholders 10.02.2026 16:17
This episode explains how to coordinate communications during security incidents so technical response is not undermined by confusion, contradictory messages, or premature conclusions, an area the certification exam often tests through leadership judgment and process alignment. You will learn how to segment audiences such as executives, legal, public relations, regulators, customers, and internal...
Episode 13 — Preserve Evidence Correctly: Chain of Custody, Logging, and Forensics Readiness 10.02.2026 16:07
This episode focuses on preserving evidence so investigations remain credible and actionable, a key exam theme that connects incident response, monitoring, and governance. You will define chain of custody as the documented control of evidence from collection through analysis and storage, then learn what “forensics readiness” looks like before an incident occurs, including centralized logging, time...
Episode 12 — Build Triage Discipline: Severity, Scope, Impact, and Containment Priorities 10.02.2026 17:25
This episode builds the triage discipline that separates high-performing response teams from noisy, reactive ones, and it reinforces the exam-relevant skill of prioritizing correctly when multiple problems compete for attention. You will learn how to determine severity using a balanced view of business impact, urgency, exposure, and confidence, then estimate scope by identifying affected systems,...
Episode 11 — Lead Incident Response as a Lifecycle With Clear Roles and Authority 10.02.2026 16:10
This episode teaches incident response as a managed lifecycle, emphasizing the leadership decisions that determine whether response is calm and effective or chaotic and delayed, which is heavily tested across governance and operations topics on the certification exam. You will define the major phases from preparation through detection, containment, eradication, recovery, and post-incident improvem...
Episode 10 — Reinforce Crypto Decisions With Practical Threat Models and Failure Modes 10.02.2026 13:26
This episode teaches how to make cryptography decisions using practical threat modeling so controls are matched to real attacker behaviors and operational failure modes, rather than selected by habit or trend. You will learn how to define the asset, attacker, likely paths, and desired outcomes, then translate that model into a clear choice between secrecy, integrity, authenticity, and access contr...
Episode 9 — Design Password Storage That Survives Breaches Using Modern Hash Strategies 10.02.2026 14:11
This episode explains how to store passwords so that a database breach does not immediately become an account compromise event, focusing on modern hashing strategies and the governance decisions leaders must enforce across systems. You will learn why reversible storage and fast hashes fail, how slow password hashing functions reduce guessing speed, and how unique salts prevent identical passwords...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.