Career Village: Hacked My Way Here: Real Stories into Security

Grady Lancaster (Moderator), Ryan Makababad (Principal Security TPM · Microsoft), Jason Lee (Former CISO · Microsoft), Mayas Karaga (Principal Security Engineer · T-Mobile), Jifon Satpati (CISO · Motive)

BSides Seattle 2026 · Day 1 · Track 2

Overview

This 56-minute career panel brings together four security operators at different career stages -- a principal security TPM at Microsoft, a retired multi-time CISO (Splunk, Zoom, Salesforce), a principal security engineer at T-Mobile, and a current CISO at Motive -- moderated by Grady Lancaster, who spent five years leading security recruitment at Twilio. The panel covers how each panelist broke into cybersecurity, what skills accelerated their careers, how to get promoted, and how to break into leadership.

Watch on YouTube

Visual summary for Career Village: Hacked My Way Here: Real Stories into Security by Grady Lancaster, Ryan Makababad, Jason Lee, Mayas Karaga, Jifon Satpati
Visual summary for Career Village: Hacked My Way Here: Real Stories into Security by Grady Lancaster, Ryan Makababad, Jason Lee, Mayas Karaga, Jifon Satpati

Key moments

  1. 0:00 Panel introductions and career origin stories
  2. 8:00 Jason Lee: from DoD code reviews on AS/400 to Microsoft
  3. 10:00 Ryan Makababad: failing forward from foster care to Microsoft security
  4. 18:00 Jason Lee: stalk people on LinkedIn and buy them coffee
  5. 28:00 Number one career accelerator: relationship building and trust
  6. 30:30 Jason Lee: sales training is the missing security career skill
  7. 36:00 The smile file: documenting impact for performance reviews
  8. 46:00 Ryan: junior PM to director in 19 months through sponsorship

Career Village: Hacked My Way Here: Real Stories into Security

Speakers: Grady Lancaster (Moderator, AI/Security Recruiter); Ryan Makababad (Principal Security TPM, Microsoft); Jason Lee (Former CISO, Splunk/Zoom/Salesforce); Mayas Karaga (Principal Security Engineer, T-Mobile); Jifon Satpati (CISO, Motive)

Conference: BSides Seattle 2026

YouTube: https://www.youtube.com/watch?v=QsECmDFs_50

Overview

This 56-minute career panel brings together four security operators at different career stages -- a principal security TPM at Microsoft, a retired multi-time CISO (Splunk, Zoom, Salesforce), a principal security engineer at T-Mobile, and a current CISO at Motive -- moderated by Grady Lancaster, who spent five years leading security recruitment at Twilio. The panel covers how each panelist broke into cybersecurity, what skills accelerated their careers, how to get promoted, and how to break into leadership.

The value of this panel lies not in technical content but in the operational wisdom from practitioners who have collectively navigated careers across Microsoft, Salesforce, Zoom, Splunk, Snowflake, Intel, AWS, T-Mobile, and the U.S. military. Their advice is concrete: from Jason Lee's recommendation to take sales training to improve negotiation skills, to Ryan Makababad's strategy of documenting every positive email and IM in a "smile file" for performance reviews, to Jifon Satpati's emphasis on building trust-based relationships as the core accelerant.

For anyone navigating the cybersecurity career ladder -- especially first-time security hires, career changers, and military veterans transitioning to civilian roles -- this panel provides an unvarnished look at how security careers actually progress.

Background

▶ Watch: Panel introductions and career origin stories (0:00)

The panel opens with each member's origin story. Jason Lee started in consulting at Arthur Andersen (pre-Accenture), was run through a full-scope polygraph on his first contract with the Department of Defense doing security assurance and code reviews on AS/400 systems, eventually joining Microsoft as a client before spending 15 years there across Xbox security, Windows security, and running all of Microsoft's cryptography (PRSS). He then became SVP of security at Salesforce, CISO at Zoom during the pandemic (talking to MSNBC and CNN on his second day), and CISO at Splunk before retiring.

Ryan Makababad failed at two military assignments before accidentally landing in tech, fell in love with it, transitioned to Microsoft's identity engineering team, and moved into cybersecurity through helping customers with ADFS lockouts and multifactor authentication rollouts. She was recently diagnosed as autistic and credits military regimentation and the step-by-step teaching methodology with giving her a strong foundation.

Mayas Karaga, an Air Force veteran and current reservist, spent eight years at T-Mobile progressing through vulnerability management, assessments, business operations, and now breach and attack simulation. Jifon Satpati started as a software engineer writing device drivers, built his cybersecurity career at Intel working on hardware security products, then moved through AWS and Snowflake before becoming CISO at Motive.

Key Findings

▶ Watch: Ryan Makababad: failing forward from foster care to Microsoft security (10:00)

The panel surfaces several career acceleration patterns:

Networking beats applications. Jason Lee flatly states that applying through LinkedIn does not work when hiring managers receive 600 applications on day one. His recommendation: find someone in your target area, reach out, and ask to buy them coffee. "You'd be amazed how many people will say yes."

Build things and publish them. Jifon Satpati notes that from the hiring side, finding the right candidate is "extremely difficult." He recommends building something -- solving a problem in cybersecurity -- and publishing it on LinkedIn, because "constantly leaders are looking to see who are interesting candidates that comes in their feed."

Requirements are not requirements. Ryan Makababad got a people manager role that required 10 years of hybrid identity experience when the technology had only existed for seven. She advises ignoring posted requirements and focusing on demonstrating capability.

Sales training is the missing career skill. Jason Lee's unconventional recommendation: take sales training. "What does a salesperson do? They talk to customers who don't want to buy what you have to sell, build a relationship, negotiate on price." He maps this directly to selling promotions, selling vulnerability fixes to engineering teams, and selling budgets to boards.

Ask for what you want. Ryan emphasizes that no one will know your career ambitions unless you state them explicitly. She told Anne Johnson she was interviewing outside Microsoft to become a people manager, and Johnson created an opportunity -- resulting in a jump from junior PM to director in 19 months.

Document your impact. Multiple panelists recommend keeping a running record of positive feedback, business impact, and accomplishments for performance reviews. Grady Lancaster calls his version "the smile file."

Technical Deep Dive

▶ Watch: Number one career accelerator: relationship building and trust (28:00)

This is a career-focused panel, not a technical presentation. The technical backgrounds mentioned include code review on AS/400 systems, Microsoft PRSS cryptography infrastructure, Azure Active Directory identity engineering, Microsoft Defender, Intune, ADFS, and breach and attack simulation at T-Mobile. These serve as biographical context rather than technical content.

The closest to technical advice is the panel's consistent emphasis on demonstrating aptitude over specific technical skills. Grady Lancaster, speaking from the recruitment side, confirms: "The last six months people don't get rejected because of technical ability. It is the curiosity, the aptitude, the grit."

Demo / Proof of Concept

▶ Watch: Jason Lee: sales training is the missing security career skill (30:30)

No demo was presented. This was a moderated panel discussion with audience Q&A.

Defensive Implications

▶ Watch: Ryan: junior PM to director in 19 months through sponsorship (46:00)

The defensive implications are workforce-oriented rather than technical:

  • Security leaders should invest in internal mobility and sponsorship programs -- multiple panelists got their roles through internal advocates, not job applications
  • Hiring managers should evaluate aptitude and relationship-building skills alongside technical credentials
  • Veterans bring transferable skills (operational security mindset, grit, step-by-step discipline) that map directly to security roles, even without traditional cyber backgrounds
  • Organizations should invest in non-security adjacent teams (engineering, product, customer support) as talent pipelines for security roles -- Jifon Satpati's previous CISO at Snowflake came from an economics background

Key Takeaways

  • Networking and relationship-building outperform job applications in the current market (600 applications per posted role)
  • Impostor syndrome affects practitioners at every level, including VPs and CEOs -- comfort with discomfort is how growth happens
  • Sales training is an underutilized career accelerator for security professionals who need to negotiate budgets, convince engineering teams, and sell to boards
  • Document every positive interaction for performance reviews -- keep a "smile file" of impact evidence
  • Requirements on job descriptions are not actual requirements; demonstrated capability matters more
  • The difference between social engineering and networking is intent -- the same interpersonal skills apply
  • Sponsorship (someone actively advocating for you) is more powerful than mentorship (someone giving you advice)

About the Speaker(s)

Grady Lancaster (Moderator) works with AI and security companies on talent acquisition, previously leading security recruitment at Twilio for five years. Ryan Makababad is a Principal Security Technical Program Manager at Microsoft, an Army veteran who transitioned through identity engineering into cybersecurity. Jason Lee is a retired CISO with 15 years at Microsoft (Xbox security, Windows security, cryptography), followed by SVP of Security at Salesforce, CISO at Zoom, and CISO at Splunk. Mayas Karaga is a Principal Security Engineer at T-Mobile and Air Force veteran/reservist with eight years spanning vulnerability management, assessments, and breach and attack simulation. Jifon Satpati is the CISO at Motive, with prior experience building hardware security products at Intel and cybersecurity roles at AWS and Snowflake.

Reviews

Dr. Zero (Offensive Security Researcher) — HARD PASS

A career advice panel with no technical security content whatsoever. The panelists have impressive backgrounds (CISO at Zoom/Splunk, Microsoft crypto, T-Mobile BAS) but the discussion stays entirely in the realm of career navigation, networking, and promotion strategies. Routing to the career track -- this has zero technical contribution.

Heather Calloway (CISO) — USEFUL

A well-assembled career panel with credible operators from Microsoft, Salesforce, Zoom, Splunk, T-Mobile, and Intel. The advice on networking, sponsorship, and sales training is practical and experience-backed. However, the content is career guidance with no governance, risk, or defensive operations relevance for security leaders.

→ Top-rated talks at BSides Seattle 2026

All talks from BSides Seattle 2026