In this episode of Behind the Shield, Jason Shropshire sits down with Tony Bai, Chief Solutions Officer at RISCPoint, for a wide-ranging conversation on cybersecurity, compliance, emerging technology, and the future of the workforce. Tony shares his journey from serving in the U.S. Air Force and supporting cyber operations at the Pentagon to becoming a leader in the federal cybersecurity and compliance space. Along the way, the conversation dives into the evolution of FedRAMP, RMF, CMMC, cloud security, and the realities of helping organizations navigate increasingly complex regulatory environments. Jason and Tony discuss the balance between real security and “check-the-box” compliance, why over-reliance on tools and outsourced accountability can create risk, and how organizations can build sustainable security programs that actually support business operations. The episode also explores common pitfalls in FedRAMP and CMMC journeys, the importance of tailored security engineering, and why mentorship and workforce development matter now more than ever. The conversation then shifts to one of the biggest topics shaping the industry today: AI. From AI-assisted coding and automation to concerns about losing foundational technical skills, Tony and Jason unpack both the opportunities and risks that come with rapid technological acceleration. They also reflect on how today’s cybersecurity leaders can help develop the next generation of engineers and practitioners in an increasingly AI-driven world. The episode wraps with lighter conversation around mentorship, career growth, sci-fi fandoms, Legos, and what life after cybersecurity might look like. Links to things we talked about: The 1969 Apollo guidance computer - https://www.youtube.com/watch?v=B1J2RMorJXM Running Doom on a pregnancy test - https://www.popularmechanics.com/science/a33957256/this-programmer-figured-out-how-to-play-doom-on-a-pregnancy-test/ What You’ll Learn Tony Bai’s path from the Air Force into cybersecurity and compliance leadership How FedRAMP, RMF, CMMC, and cloud security have evolved over time Why “real security” goes beyond compliance checklists Common mistakes organizations make when outsourcing security responsibilities The balance between automation, AI, and human expertise Why foundational technical knowledge still matters in the age of AI How companies can better mentor and grow the next generation of cybersecurity talent The importance of long-term trusted partnerships in compliance and advisory work Chapters: 0:11 - Introduction and Guest Welcome 1:05 - Tony's Background in Cybersecurity 3:45 - Jason's Path in IT 7:45 - Evolution of Technology 9:33 - Transition to Compliance and Advisory 13:58 - Compliance, Security Engineering, and FedRAMP 19:22 - Challenges in Compliance 24:38 - Over and Under Investment in Security 35:59 - Rapid Changes in AI and Technology 49:58 - Personal Interests and Hobbies Guest Links: https://www.linkedin.com/in/williamtbai/ https://www.linkedin.com/company/riscpoint/ https://www.riscpoint.com/ Learn more about InfusionPoints: https://www.linkedin.com/company/infusionpoints/ Jason Shropshire: https://www.linkedin.com/in/shrop/ Request a Demo: https://xbu40.com/ InfusionPoints & AWS: InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments. About Us: InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets. We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement. Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.