CyberCap Interview: Patricia Gagnon-Renaud (GoSecure)
Download resourcesAbout this session
In this CyberCap CyberCast interview recorded live at GoSec, ethical hacker Patricia Gagnon-Renaud (GoSecure, CISSP, OSCP) traces her path from software development and system administration into offensive security, driven by curiosity and a desire for a career change, with her CISSP giving her the base to make the jump. She tells young people drawn to the 'wrong side' of hacking that a strong moral compass, not raw skill, is what separates authorized testing from malicious intrusion, and names curiosity plus resourcefulness across languages and frameworks as the core traits of a good tester, sustained by constant peer learning and community events like NorthSec. She describes physical intrusion engagements, a mandate she now performs regularly after initially doubting she'd get the chance, as her favorite work, combining disguise, social engineering and lock-bypass techniques. The centerpiece is a live, unscripted OSINT demonstration on the host: starting from a public LinkedIn profile, Patricia locates increasingly sensitive personal details within minutes, illustrating why call-centre 'identity verification' questions using an address are worthless and why oversharing photos (including of house keys) is risky. She closes urging youth to just try the field, since demand across its many specialties (red team, blue team, governance) is high.
Key takeaways
- Treat a strong moral compass, not technical skill alone, as the real line between authorized penetration testing and malicious hacking when mentoring newcomers.
- Do not rely on a home address as an identity-verification question in call centres or customer support flows; it is trivially discoverable through public records and social media.
- Audit what your own team posts publicly (LinkedIn history, photos including visible keys or documents) since an OSINT demo can reconstruct a home address and financial details from a public profile in under 15 minutes.
- Build a habit of cross-team knowledge sharing after each engagement (new techniques, tools, findings) to keep pace with how fast offensive security techniques evolve.
- If physical intrusion engagements interest you, know they combine disguise, social engineering and lock-bypass skill sets distinct from remote penetration testing, and are a specialty worth pursuing deliberately.
Speakers

Patricia Gagnon-Renaud is a Cybersecurity Analyst in the Ethical Hacking team at GoSecure. She has a bachelor's degrees in IT engineering, is a licensed engineer, and more recently, has become a Certified Information Systems Security Professional… Read moreRead less
Patricia Gagnon-Renaud is a Cybersecurity Analyst in the Ethical Hacking team at GoSecure. She has a bachelor's degrees in IT engineering, is a licensed engineer, and more recently, has become a Certified Information Systems Security Professional (CISSP). Her interests include social engineering, physical security, lockpicking and urbanism.
