Available for engagements

Speaking

Two decades on stage at DEF CON, ISC2, Stanford, CCC, JavaOne, and ROOTCON.

Adversarial AI, autonomous SOC architecture, offensive security research, zero knowledge computing, multi-party computation, bio-inspired defense, Kubernetes hardening, hardware-rooted identity, complex systems science, and financial systems security. Every talk is backed by published research, working exploits, and production deployments — for audiences that want to be challenged, not just informed.

John Menerick

Conference history

23 engagements
2002
ROOTCON
Satellite Foolery and Hijinks
2003
JavaOne
Java Security
San Francisco
2003
Stanford University
Complex Systems Engineering Limitations
2010
SigInt
Echo Chambers and Systems in Hacker Culture
2005
Northwestern
Video Game Programming series
2005
University of Minnesota - Twin Cities
C++ / C Programming for Robotics lectures
2004
SIGINT Development
Guest Speaker
Intentionally not recorded.
2003
SIGDEV
Guest Speaker
Intentionally not recorded.
2008
PayPal
Complex Systems & Distributed Systems in Security
Corporate engagement
2007
eBay
Security Imagineering
Corporate engagement
~2005
Notacon
Security Research
Cleveland, OH
Recurring
OWASP Bay Area Chapter
Cracking Financial Systems & others
2014
DEF CON 22
Open Source Fairy Dust
Las Vegas, NV
2015
DEF CON 23
Backdooring Git
Las Vegas, NV
2015
ROOTCON 9
BackDooring Git
Philippines. Part of winning Hacker Jeopardy team.
2015
ROOTCON 9
Open Source Internet Infrastructure Insecurity
Philippines
2016
ROOTCON 10
Liberating Self Driving Cars
Philippines
2015
GrrCON
Backdooring Git
Grand Rapids, MI
2015
SkyTalks (DEF CON)
ERP inSecurity
Intentionally not recorded.
2015
DerbyCon
Backdooring Git
Louisville, KY
2015
CCC (Chaos Communication Camp)
Security Research
European security community
Recurring
BSides Cleveland
Multiple Talks
See IronGeek archive.
Recurring
ISC2
Various topics from Bug Bounty to Purple Teaming Operational Excellence
Top Rated Speaker.

Talk topics

Nineteen areas
01

Adversarial AI & the autonomous SOC

What happens when your SOC learns faster than your attackers evolve? Energy-based detection models, self-healing security architectures, and autonomous response loops — built and battle-tested, not theoretical.

02

Offensive security & supply chain risk

From backdooring Git repositories to cracking financial systems at scale — talks that make engineering teams audit their own code before the session ends.

03

Security architecture at scale

Zero trust isn’t a product, it’s a discipline. Designing and breaking architectures across cloud-native, distributed, and legacy environments — from scar tissue, not a slide template.

04

Complex systems & security engineering

Security is a complex adaptive system. Drawing on cybernetics, developmental biology, and game theory to think about defense the way nature thinks about resilience.

05

Machine learning in information security

A force multiplier for attackers and defenders alike. Applied ML for threat detection, anomaly modeling, adversarial inputs, and the practical limits of what models can and cannot do in production.

06

Distributed systems & information theory

The theoretical speed limits of a secure distributed system: multi-terminal information theory, Slepian–Wolf compression, MAC/BC interference management, and physical-layer network coding.

07

Zero knowledge computing

Prove you know something without revealing what you know — from cryptographic fundamentals to authentication, privacy-preserving computation, and trust minimization in deployment.

08

Computing through the noise: circuit-scalable MPC

When the network itself works against you. The Constant-Rate Compiler and interactive coding — fusing error correction with encryption to hold zero trust over failing, noisy, or jammed channels.

09

The straggler solution: coded MPC for the edge

In decentralized IoT, waiting for the slowest node is a death sentence. Private and Rateless Adaptive Coded Computation (PRAC): reliability through polynomial codes without the bloat of redundancy.

10

Beyond the algorithm: unconditional security

The shift from “hard to break” to “impossible to observe.” Information-theoretic security and GHZ quantum states — where physics, not complexity, keeps data private.

11

Multi-party computation beyond bit-perfect

Computing together without any party learning another’s inputs — even over a broken network. Coded MPC across noisy, adversarial environments that would cripple traditional protocols.

12

Agentic AI & autonomous security operations

The MAESTRO and TAME frameworks: governed multi-agent security systems with cognitive light cones, guardian swarms, and bio-inspired collective intelligence — machine speed without losing human accountability.

13

Self-healing infrastructure & regenerative security

Salamanders regrow limbs; your cloud should too. Developmental biology, anatomical homeostasis, and TOTE loops applied to systems that recover without human intervention — regeneration, not backups.

14

Hardware-rooted identity & ephemeral credentials

Shared secrets are a liability. YubiKeys, FROST threshold signatures, Vault, and short-lived certificate chains — a concrete path from password chaos to phishing-resistant identity, from production deployments.

15

Kubernetes security & cloud-native hardening

The full attack surface: Pod security policies, CNI network policy enforcement, scheduler privilege, CI/CD pipeline injection, and secrets management — with CIS Benchmark-aligned remediations.

16

Threat hunting & advanced incident response

Alerts are noise; hunting is signal. macOS and Linux first-responder forensics, APT detection patterns, SIEM failure modes, Loki/Splunk pipelines, and IOC scanning at scale.

17

AI governance, ethics & the worthy successor

When an agent decides to contain a threat, who owns the consequences? Governance frameworks, the Petrov Rule for machine judgment, and systems powerful enough to matter and accountable enough to trust.

18

Financial systems security

The highest consequences for failure and the most creative adversaries: financial APIs, DPAPI exploitation, cryptographic protocol weaknesses, and the attack surface of modern payment infrastructure.

19

Bio-inspired defense & morphogenetic security

Morphogenetic field theory, bioelectric signaling, and developmental biology applied to network defense — resilience through goal-directed behavior encoded at the architecture level, not more rules.

Engagement information

Formats
Keynote, deep-dive workshop, panel, fireside chat
Duration
20-minute lightning · 45-minute main stage · 90-minute workshop
Audience fit
Security engineers and architects, CISOs, ML and AI practitioners, cloud and platform engineers, academic and government audiences, financial services
A/V
Slide deck (PDF or Keynote), lapel or handheld mic, HDMI output
Bio & headshot
Available on request. Full speaker kit provided on booking.
Fee
On request. Travel and accommodation arranged by the event organizer.
Booking
[email protected] or via LinkedIn