Evan Kirstein

Evan Kirstein

Founder, Airspace Collective - CISO, Study GRC

Actions

Evan is an Information Security professional in the financial sector with 10+ years of experience in system/network administration, internal red/blue team, and GRC who believes in function over form. Their talks and work center on where to start, what to measure, and how to keep it running when budget, time, or power are against you.

In their off-hours while not defending dollars from devious digital delinquents, Evan is a lifelong tabletop and video gamer and homelabber with an interest in Meshtastic/LoRa, ARES EMCOMM, and amateur radio as KJ5MCN, as well as drones, cars, motorcycles, and karaoke mics. An avid learner and community builder, Evan holds an M.S. in Cybersecurity from Western Governors University, writes practical how-tos for the CyberSleuth Chronicles, and serves as the Chief Information Security Officer for Study GRC, a nonprofit providing free Governance, Risk, & Compliance training and real-world experience to the public.

Area of Expertise

  • Business & Management
  • Government, Social Sector & Education
  • Information & Communications Technology

Cyber on a Shoestring: Building Wagyu Career Skills and Experience on a Ramen Budget

Landing a cybersecurity job requires experience but getting that experience can feel impossible when you are trying to break in, switch specialties, or stretch out a tight budget. This presentation shows you how to build real, demonstrable skills without needing expensive gear or paid programs.

We will explore free and affordable ways to create meaningful hands-on experience through home labs, GitHub repositories, blog posts, certifications, and practical projects. You will learn how to build both broad cybersecurity fundamentals and specialty-focused skills for Offensive, Defensive, OSINT, and GRC paths, including key tools to prioritize as you grow.

We will also cover how to market your skills more effectively. From strengthening your resume and LinkedIn profile to improving your personal brand and networking strategy, you will walk away with a clear roadmap for showcasing your work and building a community that helps you keep learning over time.

https://youtu.be/MFfSUoq9kJo?si=GsiU_LiHEjfdVkB5

The Drone Renaissance 2: #DronesForGood

When disasters knock out internet, cellular, and power, disaster responders and small businesses need comms that are fast, cheap, and independent. This talk proposes a practical, Off-Grid, open-source approach that marries two accessible technologies: 3D-printable, payload-capable FPV drones carrying small, ruggedized payloads that can deploy GPS-enabled, text-based LoRa mesh nodes and solar-backed repeaters to restore basic situational awareness, triage, and coordination within hours, not days.

Why now? Rapid innovation in hobbyist drones and proven wartime/off-grid adaptations have dropped costs and expanded capabilities; meanwhile, Meshtastic’s open ecosystem makes low-bit-rate messaging and GPS location sharing viable for community groups. Attendees will learn how to choose frames/components, navigate high-level legal/ethical boundaries, design resilient meshes, and deliver waterproof/fire-resistant handheld nodes to victims and responders. We’ll cover antenna elevation strategies (balloon, arborist lines, tall structures, perch-and-stare) and pre-incident solar repeater placements in high-risk regions.

Old-School RBAC, New-School Risk: JML for SaaS, Guests, and AI

Access control didn’t disappear with cloud, it fractured. This hands-on workshop turns old-school RBAC and joiner/mover/leaver philosophies and processes into a modern exercise leaders can run Monday morning. Participants map three exemplar roles, spot segregation-of-duties conflicts, and design time-bound exceptions and guest controls that work across SaaS, collaboration suites, and AI add-ons without relying on any specific vendor. A timed tabletop tests urgent transfers, external auditors, and AI plugin surprises, forcing practical decisions under constraints. Attendees leave with a one-page role catalog, a JML workflow, and a “first five moves” checklist tied to audit-ready outcomes. The result is immediate, durable access hygiene: fewer foot-guns, smaller blast radius, and a cadence for quarterly reviews that executives understand and teams can sustain at scale, everywhere.

The S.E.P. Field on Every Corner: Watching the Watchers - (2hr Workshop)

Flock Safety automated license plate reader cameras are being installed at the entrances to neighborhoods, apartment complexes, schools, and municipal roads across America at an extraordinary rate -- and most people who drive past them every day have no idea they are being logged. This workshop teaches participants to find them.

The detection methodology relies on the cameras' own wireless management interfaces. Flock Safety cameras are networked devices, networked devices have MAC addresses, and MAC addresses have organizationally unique identifiers that are publicly resolvable. Participants learn how to build MARVIN -- a MAC Address Recon for Vehicle Infrastructure Nodes war-driving kit -- around accessible hardware (a compute module such as a Raspberry Pi or laptop, a USB GPS dongle, and a set of ESP32S3 WiFi+BLE radios), then learn how to use it to passively enumerate Flock-associated hardware on every block they pass.

Participants leave with knowing how to build a working detection toolkit, a complete open-source software stack, a geo-referenced dataset from a real survey run, and the analytical methodology to turn raw Wi-Fi probe observations into a GIS-ready map of surveillance coverage.

Target audience: Privacy researchers, RF and hardware hackers, civil liberties advocates, journalists, homelab builders, etc. No RF or wireless background required - relevant 802.11 concepts are taught from scratch.

Venue requirements: Standard projection and audio. For hybrid delivery: a second video source (document camera or similar) for the hardware segment, a shared text channel serving both in-person and online attendees, and ideally a co-host to support remote participants during the hands-on lab.

Preferred duration: 2 hours. Expandable to 4 hours with a live field survey pass and extended coverage geometry and GIS analysis.

Format: In-person, online, or hybrid (in-person and online).

First public delivery: Wild West Hackin' Fest, Deadwood, South Dakota - October 2026.

Ethics and legal: Entirely passive, receive-only methodology. No active probing, no association or authentication, no packet injection, no credential capture, no images taken. Workshop datasets are sanitized or synthetic. The session frames this explicitly as civic documentation of public surveillance infrastructure, not as evasion of law enforcement.

NolaCon 2026

The Drone Renaissance 2 #dronesforgood

When disasters knock out internet, cellular, and power, disaster responders and small businesses need comms that are fast, cheap, and independent. This talk proposes a practical, Off-Grid, open-source approach that marries two accessible technologies: 3D-printable, payload-capable FPV drones carrying small, ruggedized payloads that can deploy GPS-enabled, text-based LoRa mesh nodes and solar-backed repeaters to restore basic situational awareness, triage, and coordination within hours, not days.

Why now? Rapid innovation in hobbyist drones and proven wartime/off-grid adaptations have dropped costs and expanded capabilities; meanwhile, Meshtastic’s open ecosystem makes low-bit-rate messaging and GPS location sharing viable for community groups. Attendees will learn how to choose frames/components, navigate high-level legal/ethical boundaries, design resilient meshes, and deliver waterproof/fire-resistant handheld nodes to victims and responders. We’ll cover antenna elevation strategies (balloon, arborist lines, tall structures, perch-and-stare) and pre-incident solar repeater placements in high-risk regions.

May 2026 New Orleans, Louisiana, United States

KernelCon 2026

The Drone Renaissance 2: #DronesForGood

When disasters knock out internet, cellular, and power, disaster responders and small businesses need comms that are fast, cheap, and independent. This talk proposes a practical, Off-Grid, open-source approach that marries two accessible technologies: 3D-printable, payload-capable FPV drones carrying small, ruggedized payloads that can deploy GPS-enabled, text-based LoRa mesh nodes and solar-backed repeaters to restore basic situational awareness, triage, and coordination within hours, not days.

Why now? Rapid innovation in hobbyist drones and proven wartime/off-grid adaptations have dropped costs and expanded capabilities; meanwhile, Meshtastic’s open ecosystem makes low-bit-rate messaging and GPS location sharing viable for community groups. Attendees will learn how to choose frames/components, navigate high-level legal/ethical boundaries, design resilient meshes, and deliver waterproof/fire-resistant handheld nodes to victims and responders. We’ll cover antenna elevation strategies (balloon, arborist lines, tall structures, perch-and-stare) and pre-incident solar repeater placements in high-risk regions.

April 2026 Omaha, Nebraska, United States

Wild West Hackin' Fest Mile High 2026

The Drone Renaissance 2 #dronesforgood

When disasters knock out internet, cellular, and power, disaster responders and small businesses need comms that are fast, cheap, and independent. This talk proposes a practical, Off-Grid, open-source approach that marries two accessible technologies: 3D-printable, payload-capable FPV drones carrying small, ruggedized payloads that can deploy GPS-enabled, text-based LoRa mesh nodes and solar-backed repeaters to restore basic situational awareness, triage, and coordination within hours, not days.

Why now? Rapid innovation in hobbyist drones and proven wartime/off-grid adaptations have dropped costs and expanded capabilities; meanwhile, Meshtastic’s open ecosystem makes low-bit-rate messaging and GPS location sharing viable for community groups. Attendees will learn how to choose frames/components, navigate high-level legal/ethical boundaries, design resilient meshes, and deliver waterproof/fire-resistant handheld nodes to victims and responders. We’ll cover antenna elevation strategies (balloon, arborist lines, tall structures, perch-and-stare) and pre-incident solar repeater placements in high-risk regions.

February 2026 Denver, Colorado, United States

CactusCon - CISO Village

Old-School RBAC, New-School Risk: JML for SaaS, Guests, and AI

Access control didn’t disappear with cloud, it fractured. This hands-on workshop turns old-school RBAC and joiner/mover/leaver philosophies and processes into a modern exercise leaders can run Monday morning. Participants map three exemplar roles, spot segregation-of-duties conflicts, and design time-bound exceptions and guest controls that work across SaaS, collaboration suites, and AI add-ons without relying on any specific vendor. A timed tabletop tests urgent transfers, external auditors, and AI plugin surprises, forcing practical decisions under constraints. Attendees leave with a one-page role catalog, a JML workflow, and a “first five moves” checklist tied to audit-ready outcomes. The result is immediate, durable access hygiene: fewer foot-guns, smaller blast radius, and a cadence for quarterly reviews that executives understand and teams can sustain at scale, everywhere.

February 2026 Mesa, Arizona, United States

Wild West Hackin' Fest Deadwood 2025

Cyber on a Shoestring: Building Wagyu Career Skills and Experience on a Ramen Budget

Landing a cybersecurity job requires experience but getting that experience can feel impossible when you are trying to break in, switch specialties, or stretch out a tight budget. This presentation shows you how to build real, demonstrable skills without needing expensive gear or paid programs.

We will explore free and affordable ways to create meaningful hands-on experience through home labs, GitHub repositories, blog posts, certifications, and practical projects. You will learn how to build both broad cybersecurity fundamentals and specialty-focused skills for Offensive, Defensive, OSINT, and GRC paths, including key tools to prioritize as you grow.

We will also cover how to market your skills more effectively. From strengthening your resume and LinkedIn profile to improving your personal brand and networking strategy, you will walk away with a clear roadmap for showcasing your work and building a community that helps you keep learning over time.

October 2025 Deadwood, South Dakota, United States

NolaCon 2025

Cyber on a Shoestring: Building Wagyu Career Skills and Experience on a Ramen Budget

Landing a job requires experience. But how do you get Kobe beef experience without a job or shift gears in your cybersecurity career to a facet of cyber that you don’t have any work experience in while your budget keeps your pantry stocked with Cup Noodles?

In this presentation, we will discuss free and affordable ways of building effective experience and skills in ways that are easily demonstrated through homelabs, repositories, blog posts, certifications, and more, covering aspects of both general cybersecurity as well as more facet-specific examples for Offensive, Defensive, OSINT, and GRC, etc. alongside some core tooling examples to focus on learning for each. Additionally, we will talk about how to better market your skills, personal branding, and experience in a resume, on LinkedIn, etc. to build an effective network and community to foster continual learning as time goes on.

May 2025 New Orleans, Louisiana, United States

Evan Kirstein

Founder, Airspace Collective - CISO, Study GRC

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top