Simply Defensive

← Simply Defensive4 may · 31 min

S6:E3 - Tom Dejong - Inside the BHIS SOC: Triage, Curiosity, and Career Growth

S6:E3 - Tom Dejong - Inside the BHIS SOC: Triage, Curiosity, and Career Growth4 may31 min

Episode Show Notes

S6:E3 - Tom Dejong - Inside the BHIS SOC: Triage, Curiosity, and Career Growth

Episode Summary

In this episode of Simply Defensive, hosts Josh Mason and Wade Wells sit down with Tom Dejong, Triage Lead at Black Hills Information Security (BHIS). Tom shares his unconventional path into cybersecurity — from a South Dakota apprenticeship scholarship to becoming one of the most detail-oriented analysts in the BHIS SOC. The conversation covers the realities of SOC triage, the importance of detailed documentation, mentoring new analysts, and how AI is reshaping (but not replacing) blue team work.

Whether you're an aspiring SOC analyst, a seasoned defender, or someone curious about how to build a career in cyber without a traditional path, Tom's story and practical advice will resonate.

What You'll Learn

How the Build Dakota Scholarship led Tom from apprenticeship to a cybersecurity careerWhat it's really like working triage at the BHIS SOCWhy detailed ticket notes are a force multiplier for SOC teamsThe hypothesis-driven approach to alert investigationHow to pivot off IPs, hashes, process names, and file pathsWhy curiosity is the #1 skill for SOC analystsHow AI is being used in modern SOCs (and why it's not taking your job)The challenge of building SOC training and webcastsAdvice for handling mistakes and learning from them

Episode Highlights

Tom's Journey Into Cyber From discovering Darknet Diaries and hearing John Strand mention Spearfish, South Dakota — the same town Tom was living in — to landing his first day at Wild West Hacking Fest 2022 as a BHIS intern.

The Triage Mindset Tom walks through his approach to investigating alerts: starting with detection logic, checking for prior tickets, and breaking down each piece of evidence in writing to make the logic click.

Documentation as a Superpower Why Tom believes detailed notes aren't just nice-to-have — they're essential for the next analyst down the line and for his own thought process.

AI in the SOC Tom's honest take on using AI for investigations, polishing client communications, and writing detection logic — plus why he's not worried about it taking his job.