Jon Newton is a Senior Threat Hunter on our product team, where he ensures that features, developments, and usability are optimized for our users. He’s been a key member of the team developing our SimLab and enabling field engineers to run demos that showcase how Andesite navigates threats and responds to attacks.
How Did You Get Into Cybersecurity?
Like a lot of people in this field, I took a winding path. I got a scholarship to study computer science at Howard University, but decided when I got there that I was interested in criminal justice and law enforcement. Shortly after graduating, I joined the Army National Guard as a military police officer, which I did for six years while also working armed security full-time and applying for federal law enforcement jobs.
Meanwhile, my wife, who I met in college, wasn’t excited about my career path. She kept throwing out other ideas, imploring me to make a safer job choice. She’s the one who suggested cybersecurity because it was a booming field, and she thought I’d get the rush I was looking for. So I looked into it and started pursuing different certifications. I landed an IT asset management job and parlayed that to my first cybersecurity analyst job, contracting at FDA. From there, I got a job at ID.me, where I stayed for five years before coming to Andesite.
How Did You Become a Threat Hunter?
I started out as a traditional Tier 1 SOC analyst, then became a senior analyst, and then a cyber threat analyst. When I read the description for this role at Andesite, it felt like a natural next step for me. However, this isn’t a traditional threat hunter role. Andesite was looking for someone with the background experience of a threat hunter to bridge the technical gap for the field engineers looking to demo our cybersecurity product. So, it’s kind of like being both an internal and external consultant. My job is to ask, how do we make our product better? What do we think potential or current customers will like or dislike? I love the work I’m doing and my wife was right, it is exciting.
What Makes You Good at This Job?
I like solving puzzles, and I don’t like being bored. One reason I gravitated towards law enforcement was a desire to be challenged. Once I transitioned from working as a traditional SOC analyst to cyber threat intelligence, it became more about pattern-matching bad guys and figuring out their methods and motives in order to stop them. That aligned with what I originally wanted to get out of traditional law enforcement and also scratched that itch to solve puzzles that vary from day to day and week to week. Cybersecurity is never boring.
What Drew You to Andesite, and What Are You Doing Here That You Enjoy?
My last job was also at a startup, and I really liked the rapid learning pace. When I applied for this role, knowing it was a startup and there was some overlap with my background, I knew I would have the opportunity to learn new things and deepen my skills.
I also like to build things. Before joining Andesite, I hadn’t done much red team work. Everything was more blue team side, SOC defense. One of the first things I got into here was building out adversary operations to feed into our SimLab for Andesite to detect. I had always found that work interesting, but never had the opportunity to do it before. It’s really exciting to get to build the red team operations and run them, and get back into Python scripting. I’m using those skills a lot more here than in my previous roles. Building out a substantial SimLab has been a really rewarding experience.
Has anything about working here surprised you?
I love how AI-forward the company is and the encouragement we get to use AI both in our routines and to help build things. I’ve been using AI for awhile now, figuring out how to embed it into my workflows. At my previous job, that wasn’t encouraged nearly as much. Here, the approach is, how can we safely improve productivity using AI? I didn’t anticipate that being such a big factor. While a lot of companies today are still leery of AI, Andesite is not. We prioritize using it safely, of course, but aren’t afraid to lean in on using it to our advantage.
What Excites You about Working with AI?
I think it would be interesting to build an autonomous SimLab. Having red team and blue team operator agents, enclosed in a safe environment, attacking and defending against each other would create telemetry we can use to improve our product. As models get more advanced, that will become more valuable. We’re using AI technology and agents to build defenses, but the bad guys are using it to actually attack real organizations. There’s valuable telemetry to be gained from projects like that.
What Do You Think Andesite Is Capable of Achieving?
I’m excited about the groundwork Andesite has laid in terms of working with large contracts and companies. That combined with the belief in keeping humans at the helm, while also expanding what AI agents can do will really transform cybersecurity. I think at some point Andesite will be more autonomous, but with a stronger foundation to make sure the product does what you want, when you want, in the way you want it to. Rather than just saying, “Well technically it can do these things autonomously,” we’re asking, is it doing them safely? Is it doing them well? We’re approaching building that foundation in a way that others are not, and that’s exciting to me because it speaks to the likelihood that we’ll be very successful.
As a Practitioner, What’s Your Experience with the Product? What Do You Think It Brings to the Table?
Thinking back to my first few weeks as a T1 SOC analyst, anytime an alert came in, I was like, “What do I do?!?” The alerts can tell you to do this, this, and this — but you don’t know what “this” means, how to implement it, or what tools to use. Our product does that for you. You can turn the lever on how much hand-holding it does and the amount of information it provides. That’s invaluable for a day one analyst as well as a senior analyst who has 20 escalations in their lap that they need to get through quickly, but in a way that ensures they’re still doing the right things. It’s just as valuable to the analyst who needs that information distilled.
Andesite really covers the gamut of cybersecurity practitioners. The threat hunter who wants to run automated threat reports from different data sources and put together a report for you. The Tier 1 analyst who wants it to explain an alert, tell you how you should approach it, and why you should approach it this way, with evidence. It can do all these things. Otherwise, these are things you have to learn through trial and error over years on the job. That’s my favorite thing about our product — it accelerates that learning arc and shortens the timespan to being effective. It doesn’t matter if you’re 10 years in or one, it’s still effective at saving you time.
Anything Else You Want People to Know about Andesite?
Don’t be scared of our product. Some people are leery because they’re worried it will train itself to take their job. Or they’re worried about safety, whether or not there are guardrails in place. Andesite won’t take your job, it will just make you 10 times better at it. We do a lot of work on the backend to make it safe. So don’t be scared of it, just let it show you how it can make your job so much easier and less stressful.
I heard someone say, everyone in cybersecurity who’s afraid of losing their job should think of it this way: now you have to become a manager. Human intervention and interaction is not going to go away, but neither is AI. Your skillset has to evolve. You have to learn how to manage AI agents and get the most out of them — to train and guide them to be as efficient and effective as possible. If you can aspire to be on the forefront of that, your job will be safe. If you’re a Tier 1 analyst who has no interest in learning how AI works or how it can help you grow, you’re going to be less attractive to companies that are installing these tools. As long as people in cybersecurity stay up to date with how to use AI in your workflows, you’re going to be fine.
What Does Life Look Like When You’re Not Threat Hunting?
My wife and I have been together for over 10 years. We have a son who just turned two and a five year old daughter, so most of my free time goes to them. Lots of family time, outdoors, at the park. We live just outside Philly, so every day my daughter asks for water ice and pretzels. I’ve always been a gamer too, but had to cut back once we had kids. I used to stay up all night playing video games. I can’t imagine doing that now. At this point, it feels like a commitment. So right now I’m playing a card game called Bolatro, which is like a hybrid of solitaire and poker that I have on a handheld. It’s a departure from the big expansive games I used to play in front of the TV for hours. Maybe that’s a sign of maturity.