Hacking the Status Quo: Tales From Leading Women in Cybersecurity
Black Hat USA 2025 · Day 1 · Briefings
Overview
A panel of leading women on the Black Hat review board shared candid accounts of non-linear career paths, imposter syndrome, persistent workplace double standards, and practical strategies for building visibility in the security community — from submitting imperfect conference talks to intentional networking and defining success on personal terms. ---

Key moments
- 2:59 Valentina Palmiotti: second-career path from economics to offensive security via self-study
- 5:29 Natalie Silvanovich: 10 years at Google Project Zero, manager role achieved through persistence
- 7:00 Kimberly Price: third-career path via HR recruiting to PSIRT via on-the-job security learning
- 9:00 Key insight: imposter syndrome is near-universal even for top industry practitioners
- 10:59 Strategic career advice: intentionally taking a step back enables lateral growth
- 13:00 Ashley Chien: threat intel career spanning Google, Mandiant, and Cisco Talos
- 21:59 Panel consensus: community mentorship and public research are critical enablers for newcomers
- 33:00 Systemic barrier identified: bias in hiring and credentialing limits diversity pipeline
Hacking the Status Quo: Tales From Leading Women in Cybersecurity
Speakers: Vandana Verma (moderator, Black Hat Review Board); Valentina Palmiotti (Chompie), security research lead; Natalie Silvanovich, Google Project Zero manager; Kimberly Price, Senior Director of Application Security, GitLab; Lo (vulnerability researcher); Chien Hsin (Ashley), Cisco Talos; Nicole, security researcher
Conference: Black Hat USA 2025 — August 6-7, 2025, Mandalay Bay, Las Vegas
YouTube: https://www.youtube.com/watch?v=8V4i8TW1YXU
Reading Time: ~6 minutes
Type: Keynote
TL;DR
A panel of leading women on the Black Hat review board shared candid accounts of non-linear career paths, imposter syndrome, persistent workplace double standards, and practical strategies for building visibility in the security community — from submitting imperfect conference talks to intentional networking and defining success on personal terms.
Introduction
Black Hat's closing keynote panel brought six prominent researchers and security leaders to the stage for a conversation that dispensed with scripts and curated talking points. Moderated by Vandana Verma, the session was designed to give the audience something concrete: real stories, real setbacks, and real advice from practitioners who have navigated one of the most male-dominated technical fields at its highest levels. The panel's explicit goal was to fill the seats on next year's stage with people who were in the audience this year.
The conversation ran across three broad themes: how each panelist entered the field, what obstacles they faced and how they managed them, and how to build a presence in the security community as a force multiplier for a career.
Paths In: Second Careers, Lucky Interviews, and Hacking Forums
One of the panel's recurring threads was that there is no single correct way into security — and that this should be taken seriously as encouragement, not just platitude.
▶ Watch: Panel Introductions and Career Origins (02:00)
Valentina Palmiotti, known in the community by her handle Chompie, started in economic research, realized she was "deeply unhappy," and pivoted after finding a city-funded cybersecurity boot camp in Chicago. She taught herself by reading public research, rewriting existing exploits from scratch, and eventually producing original vulnerability research — a path that led to leading a security research team.
Natalie Silvanovich of Google Project Zero described following what she called the traditional path: an electrical engineering degree at UBC, a co-op interview for a "junior hacker" role (she got the job in part because the technical interviewer was sick that day), five years in product security frustrated that bugs weren't getting fixed, and then a decade — and counting — at Project Zero, where she is now a manager.
Kimberly Price, senior director of application security at GitLab, entered security as her third career, having previously worked in behavioral psychology and public health before becoming a recruiter at Microsoft. When the Trustworthy Computing memo landed, she found herself recruiting for the security business unit, realized she wanted to understand what she was recruiting for, and began building technical skills on the job — learning STRIDE modeling, CVSS scoring, and vulnerability assessment without formal training while managing imposter syndrome throughout.
Ashley (Chien Hsin) from Cisco Talos started hacking at 17 through Taiwan's underground forums and community conferences. A talk at one of those conferences about advanced persistent threat actors changed her trajectory — she described it as discovering "cyber detective" work — and within months she had joined a startup to track APTs. She has been doing threat intelligence ever since.
Persistent Challenges: Emotional Endurance, Double Standards, and Proving Worth
The moderator shifted the conversation to obstacles, and the panel offered responses that ranged from structural critique to deeply personal reflection.
▶ Watch: On Challenges and How to Overcome Them (14:02)
Lo, a vulnerability researcher, named "maintaining emotional endurance" as the most persistent challenge in her eight years of high-risk research work. "There will be a lot of times where I'm risking working for many months at a time on an idea, and sometimes that idea doesn't pan out, and I have nothing to show for it, and it can be very easy to attribute that to your self-worth." Her approach has been to reframe apparent failures as knowledge gains, relish genuine successes fully, and learn to distinguish research outcomes from personal worth.
Nicole identified ambiguity as her early career challenge — in a field that barely existed when she began, there were no established ladders, no clear criteria for advancement, and genuine uncertainty about whether the field itself would persist long enough to build a career in.
Kimberly was direct about ongoing sexism: "There is still going to be sexism and a variety of other isms that we face in the workplace every day." She described the persistent double standard in which assertiveness reads as leadership in men and as something else in women, and noted she spent years maintaining a professional persona at work that was authentic but deliberately calibrated to operate within those constraints. She also disclosed that for a long time she refused to participate in women-in-security groups, an instinct she has since revised: "I have now reached a point where there's a lot of people who just need to have it acknowledged that your struggles are real."
Ashley described the pressure she placed on herself as the only woman on her team to prove she belonged — a pressure that led her to suppress aspects of her identity, avoid "soft" questions, and dress to blend in. She eventually recognized that inauthenticity was not just uncomfortable but was actively limiting her ability to influence and inspire others.
▶ Watch: On Authenticity and Belonging (22:02)
Building Presence: Conferences, Communities, and Imperfect Submissions
The third major thread — and the one with the most actionable content for the audience — concerned how to build a community presence and why it matters across career stages.
▶ Watch: On Conference Participation and Networking (24:02)
Kimberly described submitting her first conference talk as a co-submission with someone who had more speaking experience — a strategy that improved both her confidence and her odds of acceptance. She noted that the current submission environment is more competitive than it was a decade ago, but emphasized that Black Hat and DEF CON are not the only venues: BSides events exist in dozens of cities, local meetups are widespread, and any forum where you speak publicly builds the skills and network that matter.
Natalie made a point that resonated visibly with the audience: when she joined the Black Hat review board, she was struck by how consistently the submissions she had held herself back from sending were better than most of what she was reading. "If I could go back in time, I would have submitted things that I thought were not 100% my best." The implicit message for women who self-select out of opportunities out of perfectionism: the standard you are holding yourself to may be significantly higher than what gets accepted.
Ashley offered a concrete data point: how she got her interview at Google. Her manager saw her Black Hat presentation, found her on Twitter, and reached out directly. Conference visibility is job-market infrastructure.
Vandana Verma framed networking not as transactional schmoozing but as ongoing relationship-building — a first LinkedIn message that references where you met, a second that adds context, a conversation that develops over time. "Cybersecurity is one industry where there's something new every day," she noted. The value of community is not just professional but intellectual: the cross-pollination of researchers working on entirely different problems is itself a source of insight.
▶ Watch: Closing Advice From Each Panelist (34:03)
Audience Q&A: The Pressure to Prove a Demographic
The session's most charged moment came from an audience member who described being told, upon expressing interest in governance, risk, and compliance, that "of course, as a woman, you would choose a non-technical route." She asked whether the panelists felt pressure to pursue areas they weren't interested in to demonstrate that women can handle technical work.
The panel's response was unified and swift. Valentina: "I would say absolutely don't. I've already been through one failed career because my heart wasn't in it. You have nothing to prove to anybody." Kimberly added that GRC is not a "soft" discipline — it requires the same analytical rigor as any other security specialization — and that anyone making that comment revealed more about their own biases than about GRC's difficulty or value.
Notable Quotes
"I held myself to such a high standard and never submitted anything that was not perfect. And if I could go back in time, I would have submitted things I thought were not 100% my best."
— Natalie Silvanovich ▶ 28:03
"I'm really grateful to have come up in a time where public research was available to guide me."
— Valentina Palmiotti ▶ 04:00
"Maintaining emotional endurance — that's the most common challenge I still face today."
— Lo ▶ 14:02
"Define your own success. What is successful for other people or for society is not really what would make us happy or feel purposeful."
— Ashley (Chien Hsin) ▶ 34:03
Key Takeaways
- Non-linear paths are the norm, not the exception. Multiple panelists entered security as a second or third career, often through adjacent roles. Diverse professional backgrounds are assets, not deficits.
- Submit imperfect work. Self-selection based on perfectionism costs practitioners opportunities they would have gotten. Review boards are not as intimidating as they look from the outside.
- Conference presence compounds. Speaking at regional and community events builds a searchable public record of expertise that opens doors independently of the job application process.
- Authenticity increases impact. Suppressing identity to fit in limits the ability to influence, inspire, and be seen — costs that are real and cumulative.
- Failures are data, not verdicts. Research that does not produce results still produces knowledge. Separating research outcomes from self-worth is a learnable skill with high return on investment over an entire career.
Slides
No slides PDF was listed for this keynote panel format.
Reviews
Dr. Zero (Offensive Security Researcher) — PASS
Inspirational career stories from accomplished practitioners. Wrong venue for this content. Black Hat is where you bring technical work; this is where you send someone who just spent too long on LinkedIn. The individual panelists — Silvanovich, Palmiotti — have done research that deserves real technical sessions, not a moderator asking them about imposter syndrome.
Heather Calloway (CISO) — SOLID
A keynote panel with four senior women in security — Natalie Silvanovich, Valentina Palmiotti, Kimberly Price, Ashley from Cisco Talos — discussing career paths, institutional barriers, and what it actually takes to build a security career from the technical ground up. Not a vulnerability briefing. A talent and culture conversation that matters for anyone thinking about the long-term health of the profession.