GreenSky's Ken Bowles on Auditing Controls before They Silently Fail episode artwork

EPISODE · Nov 25, 2025 · 36 MIN

GreenSky's Ken Bowles on Auditing Controls before They Silently Fail

from Detection at Scale · host Panther Labs

Over his 15-year journey through healthcare and financial services security, Ken Bowles, now Director of Security Operations at GreenSky, has collected a plethora of practical strategies for prioritizing crown jewels, managing cloud over-permissions, and building SOCs that scale effectively. He reflects on transforming security operations through AI and intelligent automation and discusses how AI is reducing analyst investigation time dramatically. Ken also asserts the importance of auditing security controls before they silently fail. The conversation touches on the evolving role of the MITRE framework, the concept of signaling versus alerting, and why embracing AI might be the best career move for security professionals navigating rapid technological change in cloud environments. Topics discussed: Building security operations programs around crown jewels and scaling outward to manage the most critical assets first. Managing over-permissions in cloud environments that have snowballed across multiple administrators without proper governance. Using AI to reduce analyst investigation time from 30 minutes to seconds through intelligent data enrichment and context. Creating true single-pane-of-glass visibility by connecting security tools and data sources for more effective threat detection. Training new security analysts with AI assistance to bridge knowledge gaps in SQL, SOAR platforms, and log analysis. Documenting institutional knowledge while encouraging analysts to trust their intuition when something doesn't look right. Understanding the limitations of impossible travel alerts and using AI to establish user behavior baselines for accurate detection. Applying the MITRE framework as a guideline rather than gospel, adapting detection strategies to specific organizational needs. Implementing signaling approaches that label security-relevant events without creating alert fatigue for security operations teams. Auditing security controls regularly to catch configuration drift and ensure protective measures remain effective over time.  Listen to more episodes:  Apple  Spotify  YouTube Website

Episode metadata supplied by the publisher feed · Published Nov 25, 2025

Embed this episode

Ready to play

GreenSky's Ken Bowles on Auditing Controls before They Silently Fail

0:00 36:16

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Detection at Scale?

This episode is 36 minutes long.

When was this Detection at Scale episode published?

This episode was published on November 25, 2025.

Can I download this Detection at Scale episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!