TL;DR
- Todd Bane joined Expel in April as Director of Professional Services, after a career that runs from bank IT to the Pentagon to Mandiant.
- He makes the case that IT generalists—the people who’ve touched every system in an environment—turn into the best security architects.
- He keeps a 1978 John Deere running himself, has played guitar since he was 12, and would take permanently damp socks over a permanently damp handshake without a second of hesitation.
Todd Bane’s first computers were military cast-offs. His dad is former military, and when a unit decommissioned old equipment, Todd got to take the wiped machines home and start taking them apart. DOS prompts, hardware he could open up, nothing he could break that anyone would miss.
That turned into a computer engineering degree (and a reading habit). He picked up 2600: The Hacker Quarterly regularly in college, and one opinion piece stuck with him: an argument that cyber was going to become the front line of warfare. “Obviously, here we are,” he says.
From bank IT to the Pentagon
Todd’s first job out of college was at a banking institution, and it was really two jobs. Half of it was network engineering during the big virtualization push, and the other half was securing the environment—IDS, IPS, and endpoint security software. A couple of years of that gave him a wide view of how IT actually works before he narrowed in on security.
From there, he went almost entirely into cyber, on a Department of Defense contract at Headquarters, Department of the Army, based out of the Pentagon, plus security operations center work in Crystal City. Then a contract in Hawaii. “Taking one for the team, obviously,” he joked. “No one else would do it. Just me.” (Editor’s note: Sign me up for the next Hawaii contract.)
The Hawaii role made him the Pacific Theater subject matter expert for endpoint security systems, which meant working across every branch of the military and partner agencies. He finished that stretch back at Fort Meade at DISA HQ, working with Army Cyber, US Cyber Command, and the occasional project with NSA. Around that same time, Mandiant released its APT1 report. Todd read it, a friend told him it seemed right up his alley.Later he applied and he started at the beginning of 2015.
What followed was, by his own description, a little bit of everything: federal work, incident response support, operationalizing Mandiant’s in-house endpoint tools inside customer environments, SOC transformation, compromise assessment, threat hunting. The company was growing fast, and that meant opportunity.
He eventually moved from principal consultant into leadership, building out enablement services around SIEM, SOAR, and EDR. He stayed through the split—Mandiant to Google Cloud, FireEye to Trellix—and took a Director of Engineering role at Trellix covering professional services and customer success, where his teams built tools (a lot of them AI) for the professional services group.
Then he wanted to get back to the work itself. “I wanted to get back more into the focus of security operations and things around SIEM and SOAR,” he says. “That’s what led me here.”
Why generalists make the best security architects
Todd started as an IT generalist, which is a common route into security. He thinks it’s an underrated one.
“I have an immense amount of respect for anyone who gets into that IT generalist role as a starting point, because you get maximal exposure to IT as a general environment,” he says. “It really reinforces some of the foundational skills and requirements for someone who’s a good security architect.”
What he sees now is people entering cybersecurity and jumping straight into a narrow discipline, usually ethical hacking. He’s careful to say there’s nothing wrong with that, but he thinks something gets lost.
“There’s less of that really broad knowledge that allows you to have a full view of what security is for the entire enterprise,” he says. “Generalists have seen and touched all kinds of different systems, and they see how they work. Your ability to apply that to security fundamentals strengthens your skills.”
What he’s building here
Director of Professional Services can mean a lot of things. At Expel, it starts with helping customers get more out of their SIEM, which is where our managed SIEM offering comes in.
Todd’s been here since April, and he’s watched the team move fast. “I’m impressed at the speed and pace we’ve been able to mature what we’re doing, how we’re delivering it, and the automation we’re building behind it,” he says.
But SIEM is the starting point, not the destination. “I don’t want to stop at SIEM, because that’s not the entirety of security,” he says. “My goal here is to look at what ails our customers, the toil they’re experiencing day to day, and find the opportunities where we can bring expertise to help them hit their security goals.”
The part you can’t codify
Todd’s spent the last few years building AI tooling, so he has opinions about where it fits. What stood out to him at Expel wasn’t the automation. It was what people do with the output.
“You can throw something at somebody and it’s, ‘Yeah, this, this, this—but no, these don’t look right,'” he says. “Their gut feeling, their knowledge and experience, captures that. You can’t codify that. It’s a very human element that machines don’t really do.”
That’s the piece he points to when he talks about how Expel works. “Our philosophy on how we do human-led, AI-accelerated work really enforces that judgment element. I think that’s a massive differentiator.”
Fun facts and a very important question
Todd has, in his words, more hobbies than time. He’s a DIY guy, which he says is unavoidable as a homeowner, but the appeal goes past necessity. “Building things, learning how to use tools to solve a problem—not just digitally, but kinetically, in the physical world. I love that.”
He also loves machines, especially old ones. He owns a 1978 John Deere tractor he maintains himself. “It’s an absolute beast. I love older machines because it’s not so much circuitry. You get to actually work on the mechanical elements, and it’s a change of pace. It keeps the other areas of your brain sharp.” He lives on enough land to keep the tractor busy, plus gardens, plus has a never-ending list of things to fix.
Then there’s music. He’s played guitar since he was 12 or 13, took every music elective he could in college, and played in bands that produced their own material.
As for his very important question, we asked Todd whether he’d rather have permanently damp socks or a permanently damp handshake. He answered before the question finished landing: socks.
“I’m already outside, I’m already doing stuff. I can deal with damp socks.” (He does note one caveat: avoid trench foot.) The handshake, though, is a non-starter. “I would never want to land a sweaty palm into a handshake, ever. Now you’re pushing that on someone else. I believe in a good, firm, professional handshake. I think that’s important.” (Editor’s note: Even the thought of a damp sock sends shivers down my spine, but I am not Todd.)
