This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Dallas Baker. Dallas is a US Army Veteran and Cyber Professional. He has worked for many companies including PerimeterX, Blue Shield, and PayPal. He is skilled in Python, SQL, Information Security, JavaScript, Networking, and more.
Chapter Titles:
00:00 Introduction
01:10 Did you get your skills from the military?
08:41 Transitioning to civilian life
14:25 Rules of thumb when designing a website so you’re less prone to getting hacked
21:45 Credit Card frauds
26:35 Analyze, Understand, and Influence
29:48 Phishing Emails
31:05 Raising employee awareness about Phishing
34:39 Making Cyber interesting
39:11 HUMAN Security
47:06 How many companies have it right?
49:20 Tips for Small Businesses
56:40 Upcoming events for Dallas
Audio:
Important Links:
Transcript
Manoj Tandon: Hello everyone, welcome to another episode of Dark Rhino Security’s Security Confidential. Today, we are honored to have Dallas Baker join us. Dallas is a U.S. Army veteran, a cybersecurity professional, and someone with extensive experience in cybersecurity and technology. He is skilled in Python, SQL, information security, JavaScript, and networking. He has worked for some of the best-known companies out there, including Blue Cross of California, PayPal, and PerimeterX. Thank you for being here on a Friday, Dallas. I appreciate you taking the time.
Dallas Baker: It’s an honor. Thank you.
Manoj Tandon: Whenever we get ex-military professionals on, there are standard questions we always ask. Did you pick up your cybersecurity and technical skills in the military, or did the military help prepare you for this journey in any way?
Dallas Baker: Yes, it’s kind of an interesting thing. When I first went into the military, I went in as an IT specialist. Basically, I was helping commanders and officers fix printers, get their internet working, and handle simple things. Sometimes I would walk across the desert just to find out their laptop wasn’t working because it wasn’t plugged in and the battery had died.
Manoj Tandon: Holy smoke, man. That’s got to be the most dangerous networking job in the world. You had to walk across a desert to fix somebody’s laptop? That’s combat pay, I hope.
Dallas Baker: Yeah, it’s comical because typically where the commanders are, they’re not in combat zones, but you’re sweating, walking all the way there, and you’ve already asked the questions like, “Is the battery dead?” or “Is it plugged in?” They’ll say it’s plugged into the wall and laptop, but then you realize the power brick and cable aren’t connected. So there’s no power.
Manoj Tandon: I’m actually glad to hear you say that because when I was an engineer, one of the first troubleshooting questions was always, “Is it plugged in?” I can’t tell you how many times the issue really was that the computer wasn’t plugged in.
Dallas Baker: It happens. You overcomplicate things and look for this huge problem, and it turns out to be the simplest thing.
Manoj Tandon: Sorry, now that I derailed your train of thought, let’s pick it up where we left off.
Dallas Baker: Growing up was pretty difficult for me. I went to five different high schools, and I didn’t necessarily have plans to go to college, which is why I joined the military. While I was in high school, though, I took AP Computer Science, and that’s where I picked up my programming skills. Initially, I didn’t have any experience in cybersecurity. When I got out of active duty, I was working on websites and mobile application development, which I mostly self-taught through Udemy, Pluralsight, and similar platforms. I got my start by going through the Yellow Pages and calling small businesses with outdated websites, asking if I could redesign them and make them more appealing for customers. That’s how I built a portfolio, and eventually I worked for larger companies doing web application development and testing.
Manoj Tandon: That’s very enterprising. Honestly, you should have started your own company.
Dallas Baker: That’s actually still a goal of mine. I just need to stop thinking about it and do it. I had a friend who was a designer, so he handled all the visuals and I converted everything into code. We had a good thing going. One day, I contacted a small software company in Asheboro, North Carolina, and told them their website looked outdated. Their expertise wasn’t in web development, so they invited me in. I ended up taking the job because, with starting a business, sometimes you’re living on ramen noodles while all your money goes into development and finding customers. Having a steady job was more secure, and I wanted to sharpen my skills and work with bigger clients. Eventually, I did contract work with AT&T, then moved to California and worked at Uber doing automation testing for internal web tools. After that, I worked at Apple on Apple.com. I didn’t touch the back-end systems; I focused on front-end development. I learned a lot about JavaScript there because before that I had mostly worked with older frameworks like C#.
Around the 2016 election, there was concern about potential Russian meddling in elections, and the federal government pushed states to establish cybersecurity operations to monitor for nation-state threats. At the time, I had moved from active duty into the National Guard. I got a call saying they needed people to work in cybersecurity. I told them I didn’t know the first thing about security, but they insisted I come talk to them. When I got there, the list of required skills was four pages long, and I told them I maybe knew the first page. They explained they just needed technical people. The state had run out of money, and the military helped fund the operation through a partnership between the National Guard and the California Department of Technology. While I was there, contractors and experts came in and taught us what we needed to know. That’s where I really got into cybersecurity, and that’s also where I met my mentor, Dennis Chao.
Manoj Tandon: Listening to your story, it strikes me that you had a pretty clear sense of direction. You already knew you wanted to work with computers before you joined the military. But there are a lot of veterans who don’t have that clear sense of mission when they transition back into civilian life. What guidance would you offer them?
Dallas Baker: I think a lot of people join the military because they don’t know what they want to do yet. Some people come from rough environments, some don’t have support systems, and for others it’s a family tradition. In my case, I knew from a young age that I wanted to work with computers, so when I enlisted, I specifically requested an IT-related role. If someone is transitioning out and they weren’t in a technical military role, it can be tougher. You may have to work some less glamorous jobs while you build experience. One of the hardest things is that civilian employers don’t always see military experience as equal to private sector experience or a college degree.
Manoj Tandon: Why do you think that is?
Dallas Baker: I think it’s perception. People assume the military is just about carrying rifles and blowing things up. They don’t realize the military created the internet and that there are incredibly technical jobs within the military. What the military definitely gives you is perseverance, determination, and work ethic. But employers sometimes don’t realize the technical depth involved. That was a big challenge for me when I first got out. Employers would say I didn’t have enough experience, even though I had been doing technical work for years.
Manoj Tandon: We hire a lot of veterans, and our experience has been overwhelmingly positive. The work ethic is there, the willingness to learn is there, and they’re loyal people.
Dallas Baker: One thing I’d tell companies is not to just see “U.S. Army” and assume everyone spent their time carrying a rifle. Look at their MOS. Understand the actual skills they used in the military.
Manoj Tandon: Switching over to cybersecurity, you mentioned PerimeterX and Apple. Those front-end interfaces are vulnerable to attack. Are there any best practices you’d recommend for hardening websites?
Dallas Baker: When I was at Apple, my role wasn’t security-focused. I was mainly working on customer experience and design. Apple is obsessed with pixel perfection. Every little detail on the page has to be perfect. But later, at PerimeterX, I really started learning about the broader world of attacks. At Blue Shield, we were very focused on simply blocking everything because of the sensitivity of healthcare data. At PerimeterX, though, I realized it wasn’t that simple. You can’t just block everything because you have millions of legitimate users trying to buy things online.
That’s where I learned about attacks like card testing, where attackers use stolen credit card numbers to see which ones are still valid. They may not even buy anything, but every transaction attempt costs the business money. You also have account takeovers, botnets, and malicious JavaScript packages. Websites today are basically built with “Legos” — developers pull in all these third-party packages instead of building everything from scratch. The danger is that those packages can be compromised. Attackers can inject malicious code into a JavaScript library, and suddenly it’s stealing customer data in the background.
Manoj Tandon: That’s third-party risk in a nutshell.
Dallas Baker: Exactly. One example is Magecart attacks. Attackers inject malicious JavaScript into checkout pages. Customers think they’re securely buying something, but the malicious code is quietly copying their credit card information and sending it to attackers. That’s why monitoring JavaScript in real time is so important.
Manoj Tandon: I recently sat through a briefing on the Verizon Breach Report, and one thing they pointed out was that credit card fraud has shifted heavily toward card-not-present transactions.
Dallas Baker: Exactly. Attackers monitor online checkout forms because customers don’t realize anything malicious is happening. Everything looks normal. That’s also why I always recommend not storing passwords directly in browsers. Use a dedicated password manager whenever possible.
Manoj Tandon: One thing I noticed on your profile is that you wrote, “I want to analyze, understand, and influence other people.” What does that mean to you?
Dallas Baker: It’s not about manipulating people. It’s about understanding how others think and why they see the world the way they do. Everyone’s experiences shape their perception of reality. If you can genuinely understand someone’s perspective, even if you disagree with them, you can have better conversations and better collaboration. I also believe that if you’re going to argue against someone’s viewpoint, you should be able to argue their position better than they can themselves. That understanding gives you an advantage, especially in cybersecurity, where understanding adversaries is critical.
Manoj Tandon: That mindset seems incredibly valuable when building a cybersecurity culture within an organization.
Dallas Baker: Absolutely. Security can’t be handled by a handful of people sitting in a back room. Everyone in the organization contributes to security. Most ransomware attacks happen because someone clicked on something they shouldn’t have. That’s an incredibly hard problem to solve because people make mistakes.
At Blue Shield, we regularly conducted phishing exercises. One time, even one of our analysts clicked a phishing simulation link and had to go through retraining. If security professionals can make that mistake, anyone can. The issue is that most cybersecurity training is dry and forgettable. People rush through it just to get the certificate. I think training needs to be interactive and engaging. Show people how attacks actually work and what happens behind the scenes. Make it tangible.
Manoj Tandon: I completely agree. Cybersecurity training is often painfully dry.
Dallas Baker: Exactly. People don’t truly understand the consequences until they experience being a victim. Security awareness training needs to create that emotional connection.
Manoj Tandon: You also brought up understanding adversaries psychologically. That’s something I rarely see included in cybersecurity programs.
Dallas Baker: Most security programs focus entirely on technology — firewalls, detection systems, prevention tools. But so many attacks are based on social engineering and manipulating human behavior. Technology alone won’t solve that problem.
Dallas Baker: One of the things I find fascinating about Human Security, where I work now, is that they don’t just block bots. They actively track criminal groups and work with agencies like the FBI to take them down. The goal isn’t just to keep blocking attacks forever; it’s to remove the incentive for attackers in the first place.
Manoj Tandon: How do you do that?
Dallas Baker: You raise the cost of attacking to the point where it’s no longer worth it. Sometimes that means creating honeypots or feeding attackers fake data. For example, if attackers are testing stolen credit cards, maybe we intentionally make half of them appear valid when they aren’t. Then the attackers sell worthless data and lose credibility. Or maybe we make their attacks require vastly more infrastructure and resources. The idea is to make attacks expensive, frustrating, and unprofitable.
Manoj Tandon: How many companies are really doing this well?
Dallas Baker: Honestly, probably only a handful. Most companies focus on blocking attacks because they can measure and market that. “We blocked 50,000 threats this month.” But very few are focused on eliminating attacker incentives altogether.
Manoj Tandon: Let’s shift to Main Street USA. Suppose I’m a small business with maybe 20 or 30 employees and limited resources. What practical advice would you give them?
Dallas Baker: Small businesses face a difficult challenge because they don’t have the time, money, or personnel that large organizations do. Their focus is survival and making money. But one thing they can do is share information more effectively. Criminal groups share intelligence constantly. Businesses generally don’t. We need better collaboration and information-sharing among businesses, especially smaller ones. If one company gets attacked through a WordPress vulnerability, every similar business should know about it immediately so they can protect themselves too.
I saw this firsthand at Blue Shield. Different Blue Shield organizations across states didn’t always share information about attacks because they didn’t want to appear vulnerable. But by keeping attacks quiet, they allowed attackers to simply move on to the next target. We need stronger cybersecurity communities, almost like ISACs for small businesses, where companies can share alerts, tools, and intelligence.
I also think cybersecurity needs to become something people actually want to engage with. Right now, security teams are often seen as the people who make everything harder. We need to change that perception and make security approachable and collaborative.
Manoj Tandon: Dallas, we’re right at the hour. Is there anything you’d like to plug before we wrap up?
Dallas Baker: I’ll be at Black Hat this coming August, so if you’re there, stop by the Human booth and say hello. We’re hiring, and we’re always happy to talk with people about partnerships, careers, or cybersecurity in general. Security doesn’t have to be complicated or miserable. We’re a friendly group, and we just want to help make people safer online.
Manoj Tandon: Fantastic. Dallas, thank you so much for giving us your time. This has been a fantastic conversation, and I think our listeners are going to take away a lot of practical insights.
Dallas Baker: Anytime. It’s been an honor, and I really appreciate the invitation.
Manoj Tandon: Take care and have a great weekend.
Dallas Baker: You too.
To learn more about Dallas visit LinkedIn
Check out the other episodes in Season 7:
Ep. 0 Bonus: What is Ransomware?
Ep. 1 Ron Eddings – Cybersecurity Advocate, Creative Director, Podcast Executive
Ep. 2 Josh Harrington – Director of Security at Wattpad
Ep. 3 Joshua Brown- H&R Block, Zero Trust, and Cyber Culture
Ep. 4 Dallas Baker – Veteran to Cyber Professional
Ep. 5 Paul Hamman – Stepping Out of Your Comfort Zone
Ep. 6 Karim Hijazi – Prevailion, Entrepreneurship, and The Introverted Iconoclast
Ep. 7 Rafael Nunez – Mentor, Motivational Speaker, and Veteran
Ep. 8 Brian Haugli – Roe v Wade, Data, and Understanding Controls
Ep. 9 Greg Edwards – Canauri, Failure, and Ransomware
Ep. 10 Ranbir Bhutani – CyberCulture, Myth Busting, and Zero Trust
About Dallas Baker

Dallas is a US Army Veteran and Cyber Professional.
He has worked for many companies including PerimeterX, Blue Shield, PayPal, and HUMAN where he is currently the Threat Intelligence Analyst.
He is skilled in Python, SQL, Information Security, JavaScript, Networking, and recently obtained a new certification in Cyber Threat Management
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
