BSides Toronto 2025

Bootstrapping Security in the Wild: A Ground-Up Guide for Remote-First Teams
2025-10-04 , ENG 103

“Welcome to the company! We are excited to have you join our team!
You are our first security hire! We do not have a formal Security or IT team.
So let us know if you need anything.”

Where do you begin?


This talk explores how to build scalable, audit-ready Security and IT operations.
You will gain the most from this talk if you are the first or only security hire at a fully remote company and are expected to protect everything (duh!) while keeping teams productive.

You'll learn how to:
- Enforce Zero Trust device enrollment using MDM with minimal friction
- Deliver seamless IT support inside Slack or Teams without a whole helpdesk team
- Move from reactive access management to structured governance
- Integrate Security and Privacy directly into everyday workflows

These are real, working patterns designed for teams that balance scale, compliance, and speed.

Topics

Zero-Trust Device Enrolment

Using MDM server assignments to ensure all accesses and hardware are delivered in an unopened box on Day 1 and revoked on Day X to/from all employees.

Ubiquitous IT support

Building a low-friction Service Desk using Slack, Jira, etc. for compliance purposes. Importance of making it easier for people to ask for help without context switching and the pitfalls of not providing timely assistance to employees, often leading to security implications due to solutions that are built in silos

Decentralizing GRC and Vendor Management

  • Creating a vendor management process jointly owned and maintained by Finance, Legal, IT and Security
  • Assigning app ownership for accountability and getting help to maintain audit posture

Zero Trust SSO Adoption

  • SSO adoption as a security boundary, not just IAM hygiene
  • Overhead and dynamically elevating/de-elevating roles based on risk and need

Who am I?

I'm a Security Engineer at a global digital privacy company, where I’ve spent the last few years building security programs from the ground up.

What do I do?

I’ve been in software and security since 2017, and I specialize in transforming chaos into scalable, privacy-respecting operations.

What do I care about?

I care about security that doesn’t get in the way, privacy that isn’t just checking boxes, and systems that survive audits without making anyone miserable.

Why am I speaking?

Because I wish someone had told me earlier that it’s possible to start with security without getting intimidated or to continue on this path without burning out. Or burning bridges.