Voices of the Vigilant

Jess Vachon

Voices of the Vigilant is where bold conversations meet unflinching purpose. Hosted by Jess Vachon, cybersecurity leader, Buddhist minister, and founder of Vigilant Violet LLC, this podcast explores the front lines of digital resilience, ethical leadership, and equitable transformation in tech. Through authentic dialogue with boundary-pushers, disruptors, and unsung heroes, each episode dives deep into the human side of cybersecurity—where strategy meets values, and innovation is grounded in integrity. From career pivots and cultural shifts to systemic inequities and visionary leadership, nothing is off the table. This isn’t another tech podcast filled with jargon. Voices of the Vigilant is for those who lead with intention, speak truth to power, and are ready to reimagine what’s possible in an industry that’s overdue for change. 🔔 Subscribe, share, and step into a community where vigilance is both a practice and a path forward. "Humanizing cybersecurity with candid tales from cyberspace and beyond!"

  1. Sep 20

    The Art of Redirecting Force

    Attackers used to smash the window and run. Now they copy the key, walk through the front door, and blend into your normal tools, tickets, and processes. That shift changes everything, from how we train leaders to how we budget, procure security tools, and prove we can recover when prevention fails. Jess sits down with Stacy Cameron, founder and CEO of CyCam Strategies and a fractional security executive with deep federal cybersecurity experience. Stacy shares how she learned to make compliance and security standards usable instead of painful, why mentorship programs like the UMBC Meyerhoff Scholars Program produce stronger long-term talent, and what government service looks like when the mission is urgent but the processes are complex. We also get tactical about modern threats: ransomware groups living off the land, deepfake and voice impersonation risks, and why “assume breach” demands real resilience, not just more tools. Stacy breaks down how to prioritize the basics, align executives to their incident responsibilities early, and build a security program that can detect, respond, and recover even when budgets and procurement cycles cannot keep pace with the threat landscape. Subscribe to Voices of the Vigilant, share this with a security leader who needs a reality check, and leave a rating and review so more defenders can find the show. This episode is brought to you by Onyxia Cyber — the Operational Cyber Resilience Platform that turns security data and asset intelligence into action. Onyxia helps security teams spot risk early, sharpen their strategy, and tie day-to-day operations to measurable business outcomes. Trusted by Fortune 500 leaders. Book a demo and mention Voices of the Vigilant to get your first month free → https://www.onyxia.io/?utm_source=podcast&utm_campaign=vigilant_violet Send us Fan Mail Support the show https://www.vigilantviolet.com/ www.linkedin.com/in/jessvachon1

  2. Aug 20

    Ask a Different Question

    AI agents don’t just answer questions, they take actions. That’s the shift that keeps a lot of security leaders up at night, because when software can move fast enough to outrun review, trust becomes the real control plane. We sit down with Jaz Lin, founder and CEO of Skyrelis, to talk about what it looks like to build AI agent security when speed is the default and quality is too often optional. Jaz’s path is the kind that only makes sense in the rearview mirror: aspiring journalist and chief editor, then network engineer, CCIE, security leader across major vendors, and finally someone who has lived on both sides of the table. We dig into why journalism and cybersecurity share the same muscle: working the facts, challenging assumptions, separating false positives from true positives, and staying honest about what you can’t prove yet. That outsider perspective shows up again and again as we talk about identity, belonging, and how to keep your own voice in an AI era that rewards the most predictable pattern. Then we get concrete about AI governance and AI runtime security. Engineering teams can ship agentic workflows at a pace security teams can’t always see, creating a growing visibility gap. Jaz explains why prompts and instructions aren’t enough, what “black and white” runtime controls could look like, and why she believes policy should be decoupled from applications so it can be enforced consistently across cloud environments and SaaS products. If you care about AI security, agent visibility, policy enforcement, and keeping humans accountable for decisions, this one will sharpen your thinking. Subscribe, share this with a security friend, and leave a review so more builders and buyers can find the conversation. This episode is brought to you by Onyxia Cyber — the Operational Cyber Resilience Platform that turns security data and asset intelligence into action. Onyxia helps security teams spot risk early, sharpen their strategy, and tie day-to-day operations to measurable business outcomes. Trusted by Fortune 500 leaders. Book a demo and mention Voices of the Vigilant to get your first month free → https://www.onyxia.io/?utm_source=podcast&utm_campaign=vigilant_violet Send us Fan Mail Support the show https://www.vigilantviolet.com/ www.linkedin.com/in/jessvachon1

  3. Jul 15

    Forensics, Felonies, and Digital Receipts

    When data “walks out the door,” the hardest part isn’t always the malware, it’s the human story behind the keyboard. We sit down with Ankara Managing Director Alyssa Lisiewski, a cyber forensics and intelligence practitioner who has worked across the intelligence community, the Department of Defense, and enterprise security, and who has testified as an expert witness in federal and military courts. Together, we unpack what it really takes to follow a digital trail when the threat actor is unknown, evidence is messy, and the stakes are high. Alyssa shares how early curiosity with computers, a criminology foundation, and years of hands-on digital forensics shaped her investigative approach. We talk about the pivot from classic crime scene fascination into computer forensics, the value of mentors who take a chance on you, and the grind of working full time while earning a graduate degree. From there we get into “preventive forensics” and thinking like an adversary, how threat intelligence connects to forensic analysis, and why insider threat and insider risk are rarely just technical problems. We also go where security conversations often avoid: the psychological weight of major crimes work, what it means to see people at their worst, and why boundaries matter when compartmentalization starts to fail, especially after becoming a parent or working from home. Alyssa explains how she now blends threat actor attribution, deep forensic investigations, and post-breach litigation support, and why building flexible, sustainable roles is the future of cyber investigations. Subscribe for more practical security conversations, share this with someone building a career in digital forensics or insider threat, and leave a review so more listeners can find Voices of the Vigilant. This episode is brought to you by Onyxia Cyber — the Operational Cyber Resilience Platform that turns security data and asset intelligence into action. Onyxia helps security teams spot risk early, sharpen their strategy, and tie day-to-day operations to measurable business outcomes. Trusted by Fortune 500 leaders. Book a demo and mention Voices of the Vigilant to get your first month free → https://www.onyxia.io/?utm_source=podcast&utm_campaign=vigilant_violet Send us Fan Mail Support the show https://www.vigilantviolet.com/ www.linkedin.com/in/jessvachon1

  4. Jun 17

    Three Pivots In

    A lot of people think cybersecurity has one “right” entry point: computer science degree, IT help desk, then a straight climb into security. Courtney Hans is living proof that the best security leaders often come from the roads nobody expects. She’s led adventure travelers through remote terrain, earned an MBA, built security programs as a first security hire inside a fast moving SaaS startup, and now serves as VP of Cyber Services at ANV Cyber helping policyholders use cyber insurance as a relationship that reduces risk, not just a payout after a bad day. We get into how confidence is built, not gifted. Courtney shares the real experiences that taught her “I can do hard things,” and why that matters when you’re laid off, starting over, or walking into a board level conversation. From there, we unpack the day to day reality of security leadership: influence without ownership, trust as your main lever, and why curiosity beats fear based messaging when you’re trying to build a security first culture. You’ll also hear a grounded take on modern cyber risk management, including how insurance questionnaires miss nuance, how to avoid wasting budget on the wrong security tools, and why hardening what you already own in Google Workspace or Microsoft 365 can deliver fast wins. We touch AI security, changing best practices, and the leadership skill of saying “I don’t know yet” while still staying accountable and helpful. If you’re planning a cybersecurity career pivot, hiring security talent, or trying to make security work for the business instead of against it, this conversation will give you language, frameworks, and a mindset you can use immediately. Subscribe, share this with a friend who’s considering a pivot, and leave a review to help more people find the show. This episode is brought to you by Onyxia Cyber — the Operational Cyber Resilience Platform that turns security data and asset intelligence into action. Onyxia helps security teams spot risk early, sharpen their strategy, and tie day-to-day operations to measurable business outcomes. Trusted by Fortune 500 leaders. Book a demo and mention Voices of the Vigilant to get your first month free → https://www.onyxia.io/?utm_source=podcast&utm_campaign=vigilant_violet Send us Fan Mail Support the show https://www.vigilantviolet.com/ www.linkedin.com/in/jessvachon1

  5. May 13

    Downloading Random AI Tools Is...A Career Choice

    Everybody wants AI right now, and that includes the teams security rarely sees as “technical.” When marketing, HR, and ops start downloading agent tools, prompt packs, and random code from the internet, we get a new kind of software supply chain risk, one that most security programs are not staffed or tooled to handle. I sit down with Amber Bennoui, a product leader and builder who has worked across cloud security, developer pipelines, and software supply chain security, and who now co-leads community efforts through the AI Security Alliance (AISECA). We talk about the mindset behind frontier work: learning fast, asking better questions, and refusing to ship “AI features” that do not answer the basics of who, what, when, where, and why. Amber shares what it looks like to pressure-test guidance with peer reviewers so it works in real companies, not just on a spreadsheet. We also go deep on Jiffy Labs, Amber’s project to bring visibility, scanning, and risk scoring to the AI artifact ecosystem. Think inventory for prompts, models, and agent components, plus practical ways to assess provenance and lineage when security tools are blind to what is actually being pulled into environments. From the Mythos conversation to the reality of ephemeral code rewritten by autonomous agents, we unpack why traditional security patterns struggle and why the AI “shared responsibility model” is still missing. If you care about AI security, AI governance, DevSecOps, and the future of AppSec, this conversation will sharpen how you think and what you ask for next. Subscribe, share the show with a friend, and leave a review to help more people find Voices of the Vigilant. This episode is brought to you by Onyxia Cyber — the Operational Cyber Resilience Platform that turns security data and asset intelligence into action. Onyxia helps security teams spot risk early, sharpen their strategy, and tie day-to-day operations to measurable business outcomes. Trusted by Fortune 500 leaders. Book a demo and mention Voices of the Vigilant to get your first month free → https://www.onyxia.io/?utm_source=podcast&utm_campaign=vigilant_violet Send us Fan Mail Support the show https://www.vigilantviolet.com/ www.linkedin.com/in/jessvachon1

  6. Apr 29

    GRC Has Layers!

    Security teams get asked the same question in a hundred different ways: “What’s the ROI?” We go straight at it with Monica Reagor, Manager of Information Security Compliance at Crestron Electronics and host of the My GRC POV podcast, to show how governance, risk, and compliance becomes a growth lever when it’s done with clarity, data, and the right relationships. We trace Monica’s path from technical IT roles into compliance, then zoom in on the real work of modern information security compliance: translating legislation into executive decisions, turning requirements into engineering action, and mapping frameworks like NIST and ISO 27001 so you can scale evidence, audits, and certifications without burning out your team. We also talk about why “I don’t make money” is the wrong framing and how security can protect revenue, reduce loss, and even help win contracts when customer security questionnaires become the price of entry. Then we get into the pressure cooker: AI governance, privacy, supply chain risk management, and the reality that regulations evolve across US states, federal agencies, the EU, and APAC markets at the same time. Monica shares why operating to the most restrictive standard can be the simplest global strategy, and why GRC must show up early so teams can move fast with documented risk decisions instead of last-minute blockers. If you’re building a GRC program, defending a security budget, or trying to connect compliance to real business outcomes, you’ll leave with language you can use and a clearer mental model for the layers. Subscribe, share this with a teammate who needs it, and leave a review with your biggest challenge proving security value. This episode is brought to you by Onyxia Cyber — the Operational Cyber Resilience Platform that turns security data and asset intelligence into action. Onyxia helps security teams spot risk early, sharpen their strategy, and tie day-to-day operations to measurable business outcomes. Trusted by Fortune 500 leaders. Book a demo and mention Voices of the Vigilant to get your first month free → https://www.onyxia.io/?utm_source=podcast&utm_campaign=vigilant_violet Send us Fan Mail Support the show https://www.vigilantviolet.com/ www.linkedin.com/in/jessvachon1

  7. Mar 19

    Podcasthon 2026 Special - Cyberjutsu’s Playbook For Belonging In Cybersecurity

    We are participating in Podcasthon 2026. Podcasthon is the world’s largest podcast charity initiative, bringing together podcasters globally to raise awareness for charitable causes. In support of this noble cause, we spotlight the Women’s Society of Cyberjutsu with CEO Mari Galloway, tracing how hands-on training, cohort mentorship, and a tight-knit community create real jobs and lasting confidence. We unpack CyberjutsuCon 2026, the “Beyond The Patterns” theme, and a make a clear ask to support growth. In this episode we discuss: • Origins of Cyberjutsu and the early workshop model • Mary’s path across SOC, vuln management, sales, and leadership • Why hands-on labs beat lectures for real skill transfer • The evolving mission to include chapters, academies, and grants • measuring impact with surveys, testimonials, and outcomes • Cohort mentorship that builds leaders and peers • Accessibility, scholarships, and low-cost entry points • CyberjutsuCon 2026 format, theme, and community vibe • Sponsorship tiers, current partners, and funding needs • Chapter expansion targets in Miami, Chicago, Seattle, Midwest • Vigilance as authentic leadership and daily practice If you know me personally, even if you don't know me personally, but you know me professionally, and we've done business together before, I expect you to step up. We need you to step up. You have no problem using the talent that is being produced by Cyberjutsu and other organizations. It's time for you to help. This is an easy way for you to invest in developing and growing talent  for your organization. It is a no brainer. Please get a hold of Mari, get a hold of me, go to the website - https://womenscyberjutsu.org/ and make difference. This episode is brought to you by Onyxia Cyber — the Operational Cyber Resilience Platform that turns security data and asset intelligence into action. Onyxia helps security teams spot risk early, sharpen their strategy, and tie day-to-day operations to measurable business outcomes. Trusted by Fortune 500 leaders. Book a demo and mention Voices of the Vigilant to get your first month free → https://www.onyxia.io/?utm_source=podcast&utm_campaign=vigilant_violet Send us Fan Mail Support the show https://www.vigilantviolet.com/ www.linkedin.com/in/jessvachon1

  8. Mar 17

    Speaking Security: Leadership, Language, and Learning to Pivot

    Security fails when it’s written for auditors instead of humans. Jess Vachon sits down with cybersecurity and privacy leader Ash Mohanaprakas to unpack how the best security programs feel practical, lightweight, and deeply aligned to the mission, even under pressure. Ash shares how she helps organizations turn security from a cost center into a strategic advantage that supports enterprise deals, customer trust, and acquisition readiness. Ash’s story is anything but linear: an Oxford-trained linguist, a first-generation immigrant, and one of the only undergraduate student parents during her time there. We talk about how language and identity shape the way people interpret risk, why “translation” is an underrated security leadership skill, and how her early governance, risk, and compliance work at a huge university taught her to design controls that researchers can actually live with. The conversation also gets candid about imposter syndrome, early-career salary constraints, and the confidence that comes from learning hard frameworks by doing real work. From ISO 27001 to SOC 2, we dig into what companies get wrong when they overbuild compliance with endless policies, and what to do instead when you need scalable security with minimal friction. We also tackle AI security and AI governance: why “AI-first” is not a differentiator, how to think about agentic workflows, and where AI can genuinely reduce repetitive GRC tasks so humans can focus on complex risk decisions and culture. If you care about cybersecurity leadership, pragmatic compliance, risk management, board communication, and building security programs that scale, this one will land. Subscribe, share this with a security leader who’s drowning in documentation, and leave a review with the most “unread policy” moment you’ve seen. This episode is brought to you by Onyxia Cyber — the Operational Cyber Resilience Platform that turns security data and asset intelligence into action. Onyxia helps security teams spot risk early, sharpen their strategy, and tie day-to-day operations to measurable business outcomes. Trusted by Fortune 500 leaders. Book a demo and mention Voices of the Vigilant to get your first month free → https://www.onyxia.io/?utm_source=podcast&utm_campaign=vigilant_violet Send us Fan Mail Support the show https://www.vigilantviolet.com/ www.linkedin.com/in/jessvachon1

Ratings & Reviews

5
out of 5
2 Ratings

About

Voices of the Vigilant is where bold conversations meet unflinching purpose. Hosted by Jess Vachon, cybersecurity leader, Buddhist minister, and founder of Vigilant Violet LLC, this podcast explores the front lines of digital resilience, ethical leadership, and equitable transformation in tech. Through authentic dialogue with boundary-pushers, disruptors, and unsung heroes, each episode dives deep into the human side of cybersecurity—where strategy meets values, and innovation is grounded in integrity. From career pivots and cultural shifts to systemic inequities and visionary leadership, nothing is off the table. This isn’t another tech podcast filled with jargon. Voices of the Vigilant is for those who lead with intention, speak truth to power, and are ready to reimagine what’s possible in an industry that’s overdue for change. 🔔 Subscribe, share, and step into a community where vigilance is both a practice and a path forward. "Humanizing cybersecurity with candid tales from cyberspace and beyond!"