Jason Edwards
Certified: The GIAC GSTRT Audio Course
This audio-first security strategy course helps you turn security intent into measurable execution. You will learn how to assess current capabilities against mission outcomes and real risk, identify gaps and root causes, and prioritize improvements with clear business rationale. The course shows you how to translate technical work into outcomes leaders care about, like reliability, resilience, and reduced incident impact, then sequence initiatives so they land with minimal friction across teams. You will also learn how to build a strategic roadmap that blends quick wins with foundational capab...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 33 — Standardize with practical guidelines that scale across teams and tools 08.02.2026 17:48
Guidelines provide the flexible advice and best practices that allow a security program to scale across diverse teams and a wide variety of technical tools. This episode explores how to use guidelines to support your formal policies and standards without creating a rigid environment that stifles innovation. We define a guideline as a non-mandatory recommendation that helps the workforce make infor...
Episode 32 — Define procedures that truly work in day-to-day operational realities 08.02.2026 16:11
While policies define "what" must be done, procedures explain exactly "how" to do it, and this session focuses on creating procedures that reflect the actual operational realities of the business. We define a procedure as a step-by-step instructional guide designed to ensure a consistent outcome for a technical or administrative task. For the GSTRT certification, candidates must understand that a...
Episode 31 — Draft clear, enforceable policies people can follow without confusion 08.02.2026 15:23
The primary failure of many security programs is the presence of policies that are either too vague to be enforced or too complex for the workforce to follow. This episode focuses on the art of drafting clear, actionable language that minimizes ambiguity and fosters a culture of compliance. We define "enforceability" as the ability to objectively measure whether a rule has been followed and to app...
Episode 30 — Choose the right policy types to reduce ambiguity and rework 08.02.2026 13:46
Not all governing documents are created equal, and this episode teaches you how to choose the right policy types to match the organization’s needs and to reduce administrative rework. We define the hierarchy of documentation, starting from high-level "Program Policies" down to "Issue-Specific Policies" and "System-Specific Policies." Understanding the difference between these types is critical for...
Episode 29 — Ground every policy in clear, durable guiding principles that endure 08.02.2026 15:41
Durable security policies are those built upon a foundation of core guiding principles that remain relevant even as specific technologies and threats evolve. This episode discusses how to establish high-level principles such as "Least Privilege," "Defense in Depth," and "Privacy by Design" to guide the drafting of more granular rules. We define guiding principles as the philosophical "North Star"...
Episode 28 — Exam acronyms: quick audio reference for fast last-mile recall 08.02.2026 14:54
The GSTRT exam and the broader field of cybersecurity strategy are dense with acronyms that can be confusing under the pressure of a timed certification attempt. This episode serves as a rapid-fire audio glossary designed to reinforce your last-mile recall of critical initialisms across the business, threat, and policy domains. We cover essential terms from financial management like TCO and ROI, t...
Episode 27 — Sustain momentum using cadence, recognition, and transparent progress signals 08.02.2026 12:54
Long-term strategic success requires a commitment to sustaining momentum through consistent management cadences and the use of transparent progress signals. This session explores how to use visual management tools, such as burn-down charts and security dashboards, to keep teams and executives engaged over the lifecycle of a multi-year roadmap. We define progress signals as the measurable indicator...
Episode 26 — Overcome resistance empathetically while defending non-negotiable standards 08.02.2026 12:27
This episode addresses the delicate balance between maintaining high security standards and addressing the human element of organizational friction. We define empathetic resistance management as a technique where a leader acknowledges the operational challenges a new policy creates without compromising the core security requirements. For the GSTRT exam, you must demonstrate the ability to distingu...
Episode 25 — Drive change with executive sponsorship and visible early wins 08.02.2026 12:48
Driving organizational change is one of the most difficult tasks a security leader faces, and this episode details how to leverage executive sponsorship and early wins to build momentum. We define executive sponsorship as the active and visible support from the C-suite that provides the political cover and resources needed for major shifts. For the GSTRT exam, candidates should know how to identif...
Episode 24 — Set direction and priorities that focus teams on measurable outcomes 08.02.2026 13:34
Strategic direction requires more than just a destination; it requires a prioritized plan that focuses the organization’s energy on the most impactful outcomes. This session explores how to use the Eisenhower Matrix and other prioritization frameworks to separate urgent tasks from important strategic goals. We define outcome-based planning and explain how it differs from traditional activity-based...
Episode 23 — Earn credibility and trust by modeling consistency, candor, and follow-through 08.02.2026 13:59
Trust is the foundation of a security leader's influence, and this episode discusses how to build and maintain it through consistent professional behavior. We define integrity and transparency as core leadership values that are tested most during times of crisis or technical failure. For the GSTRT certification, candidates must understand that their reputation for follow-through is what determines...
Episode 22 — Facilitate decisive meetings that resolve issues and move work forward 08.02.2026 15:15
Meetings are often the place where security projects go to stall, and this episode provides the facilitation techniques needed to keep work moving forward. We explore how to manage a meeting's agendum and how to handle dominant voices that can derail a constructive technical discussion. We define facilitative leadership and explain its importance in reaching a consensus on difficult topics like ri...
Episode 21 — Write messages people remember and act on under real pressure 08.02.2026 14:09
Clear written communication is a primary defensive tool during both steady-state operations and high-pressure security incidents. This episode focuses on the art of writing impactful messages that drive immediate action from diverse audiences across the organization. We define instructional clarity and the use of call to action (CTA) statements in the context of security alerts and policy updates....
Episode 20 — Brief executives with precision so decisions land quickly and stick 08.02.2026 15:26
Executive briefings require a level of precision and brevity that many technical professionals struggle to achieve. This episode teaches you how to structure a high-impact briefing that focuses on the information the Board of Directors and the C-Suite actually need to make a decision. We define the executive summary and the Bottom Line Up Front (BLUF) techniques for both written and oral communica...
Episode 19 — Negotiate cross-functional alignment without stalemates, turf wars, or churn 08.02.2026 18:22
Security initiatives often stall at the boundaries of other departments, making negotiation a non-negotiable skill for a successful strategist. This episode explores techniques for achieving cross-functional alignment with departments like Legal, Human Resources (HR), and Engineering without causing organizational churn. We define principled negotiation and the concept of BATNA (Best Alternative t...
Episode 18 — Run one-on-ones that build trust, unblock work, and grow leaders 08.02.2026 17:37
The one-on-one meeting is a critical tool for any security leader seeking to build a resilient and high-trust department. This episode details how to structure these sessions to move beyond mere status updates and toward strategic unblocking and leadership development. We define active listening and empathetic engagement as core competencies that allow a manager to identify "shadow" risks or moral...
Episode 17 — Coach teams with structure to raise performance and accountability fast 08.02.2026 15:54
Elevating a technical team’s performance requires a structured coaching approach that emphasizes both skill development and measurable accountability. In this session, we explore the GROW model (Goal, Reality, Options, Will) and its application in the context of managing a Security Operations Center (SOC) or a policy drafting team. We define accountability not as a punitive measure, but as a trans...
Episode 16 — Lead with strategic clarity that rallies people and resources effectively 08.02.2026 15:24
This episode focuses on the transition from a technical contributor to a strategic leader who can provide the clarity needed to unify a diverse workforce. For the GSTRT exam, candidates must demonstrate an understanding of how a clear vision and mission statement act as a force multiplier for security initiatives. We define strategic clarity as the ability to articulate the "why" behind security m...
Episode 15 — Review key business and threat insights to reinforce durable recall 08.02.2026 14:25
As we wrap up the first major section of the GSTRT curriculum, this episode provides a high-speed review of the key business and threat insights covered so far. We reinforce the critical definitions and frameworks, such as the relationship between stakeholders, business processes, threat profiling, and risk ranking. For the exam, durable recall is achieved through the use of retrieval cues and the...
Episode 14 — Rank risks with evidence so priorities are defensible and well funded 08.02.2026 17:00
When presenting a risk register to the board, your priorities must be supported by evidence to be considered defensible and worthy of funding. This episode explores the transition from qualitative risk assessment (using high, medium, and low labels) to quantitative risk assessment (using actual dollar amounts and probabilities). We define concepts like Single Loss Expectancy (SLE), Annual Rate of...
Episode 13 — Link credible threats to objectives to spotlight what must be protected 08.02.2026 15:40
This session focuses on the critical bridge between threat analysis and business objectives, ensuring that every security control has a clear strategic purpose. We define Threat-to-Objective Mapping and explain how it helps security leaders identify the Critical Success Factors of the organization. For the certification, candidates should know how to use these maps to justify the existence of spec...
Episode 12 — Prioritize real-world threat scenarios using sharp, business-first triage 08.02.2026 20:02
In a world of infinite threats and finite resources, the ability to perform a business-first triage is essential for any security leader. This episode teaches you how to evaluate threat scenarios based on their likelihood and their potential impact on the organization's specific mission. We explore the use of the DREAD or STRIDE models for threat modeling and explain how to apply them in an enterp...
Episode 11 — Profile likely threat actors and anticipate their next strategic moves 08.02.2026 16:19
Effective defense requires an understanding of the adversary, and this episode covers the process of profiling threat actors to anticipate their tactics, techniques, and procedures. We define the various categories of attackers, including "Script Kiddies," "Hacktivists," "Insider Threats," and "Nation-State Actors," while detailing their differing motivations and resource levels. For the GSTRT exa...
Episode 10 — Translate technical risks into business impact executives instantly grasp 08.02.2026 14:02
One of the most valuable skills for a GSTRT candidate is the ability to communicate technical vulnerabilities in the language of business risk and financial impact. This episode focuses on the Risk Translation process, where technical data like CVSS scores and exploitability are converted into terms such as "lost productivity," "regulatory non-compliance," or "brand damage." We define the differen...
Episode 9 — Capture stakeholder expectations quickly and convert them into commitments 08.02.2026 14:28
Building a durable security program requires more than just technical skill; it requires the ability to capture stakeholder needs and secure their long-term commitment. This episode discusses effective interview techniques and workshop facilitation strategies used to gather requirements from various business units. We explain the importance of the Stakeholder Analysis and how to manage conflicting...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.