Career Launch Series: From SOCAP to Security Engineering

Meet Sanaan Wani, an accomplished student, now a cybersecurity professional at Amazon
For recent USF graduate Sanaan Wani, cybersecurity has never been just a career path; it has been a challenge worth pursuing.
After years of competing, researching, building tools, and securing systems, Wani is now taking the next step in his professional journey. This summer, he will relocate to Dallas, Texas, to begin a full-time role as a security engineer with Amazon. Before graduation, however, he added another impressive accomplishment to an already distinguished résumé: the discovery and responsible disclosure of a software vulnerability that earned an official Common Vulnerabilities and Exposures (CVE) designation.
His journey reflects the hands-on learning, mentorship, and real-world experience that define Cyber Florida’s Security Operations Center Analyst Program (SOCAP).
Finding his place in cybersecurity
Wani graduated from USF in May with a degree in computer science, but his interest in cybersecurity began outside the classroom.
Toward the end of his freshman year, he started attending meetings hosted by USF’s cybersecurity student organizations and quickly discovered that protecting systems was more compelling to him than simply building software.
“I realized I found securing systems much more interesting than just building software,” Wani said.
That curiosity led him to become involved with CyberHerd, USF’s nationally recognized cybersecurity competition team, where he eventually served as blue team captain. Through competitions, training opportunities, and mentorship from coaches and faculty advisors, Wani developed both technical skills and a passion for solving difficult security challenges.
His path to joining the SOCAP began through Cyber Florida’s NIST-funded Industrial Control Systems (ICS) training program, where he learned from Cyber Florida faculty and staff and completed a SANS certification funded through the program. After successfully earning the certification, he applied to SOCAP and officially joined the team in August 2025.
Building skills through real-world security operations
As a SOCAP analyst, Wani worked alongside other students to help monitor and secure networks, investigate security incidents, and support clients across Florida.
His responsibilities ranged from incident response and threat analysis to developing operational improvements for the security operations center itself. One project involved collaborating with fellow SOCAP students to develop a SOC console designed to streamline ticket processing and accelerate response times.
“We do a bit of everything,” Wani said. “From weekly incident responses to writing threat advisories.”
The experience gave him exposure to the realities of cybersecurity operations while also allowing him to pursue emerging areas of research that interested him.
Discovering a vulnerability through AI-assisted research
Outside of his operational work, Wani has spent significant time exploring the intersection of artificial intelligence and cybersecurity. Inspired and encouraged by his CyberHerd teammate, Yeran Gamage, he began building his own autonomous tools to identify security weaknesses in open-source software projects.
“Seeing his success with finding vulnerabilities really inspired me,” Wani said. “He encouraged me to start looking into securing open-source software, which is what originally got me started in vulnerability research.”
Because open-source software powers much of today’s technology ecosystem, Wani saw vulnerability research as an opportunity to strengthen tools used by organizations around the world.
His AI-powered systems scan software repositories for potential security flaws. Once a possible issue is identified, he manually investigates the findings, validates the results, and determines whether the vulnerability could have broader security implications.
That process recently led to the discovery of CVE-2026-45675, a vulnerability in Open WebUI.
The flaw involved a race condition in the platform’s authentication process. During an initial deployment, the first user to log in is intended to become the system administrator. Because of the vulnerability, however, multiple users logging in simultaneously could potentially receive full administrator privileges.
In practical terms, that could allow an unauthorized individual to gain complete administrative control over the platform and its data.
Responsible disclosure in action
After identifying and validating the vulnerability, Wani followed the industry’s responsible disclosure process.
Because Open WebUI accepts vulnerability reports through GitHub, he submitted his findings directly to the project’s maintainers. The development team reviewed the report, verified the issue, implemented a fix, and ultimately assigned an official CVE identifier.
For Wani, the milestone was meaningful not simply because of the CVE designation itself, but because it validated the effectiveness of the research methodology he had been developing.
“I’ve been using my AI tooling to find and submit vulnerabilities for a while now,” he said. “Having this one fully verified, patched, and assigned a CVE was a nice nod that the methodology works.”
The accomplishment may be his first officially assigned CVE, but it is unlikely to be his last. He currently has additional vulnerability reports under review and remediation.
The power of mentorship
Wani credits much of his success to the mentors and teammates who encouraged him to pursue ambitious goals.
Within SOCAP, he found a culture that supported innovation and exploration. He points to Duy Dao, assistant security operations center manager, as a major influence on his interest in AI-driven security research.
“Duy encouraged us to consider new research and tools in the AI space,” Wani said. “He didn’t just talk about concepts; he built things and showed them to us.”
He also credits SOCAP Program Manager Ryan Irving for creating an environment where student accomplishments are recognized and celebrated.
“There was a point where I worried I wasn’t completing enough tickets because I was spending so much time focused on AI vulnerability research,” Wani said. “Ryan and Duy were incredibly supportive. They encouraged me to keep going and fully supported my work.”
That encouragement helped him continue pursuing research that ultimately resulted in a verified vulnerability disclosure and CVE assignment.
Looking ahead
With graduation complete, Wani is preparing for his next chapter as a security engineer at Amazon. Having previously interned with the company’s red team, he is eager to return and continue building his career in cybersecurity.
Beyond his professional goals, he hopes to make cybersecurity and artificial intelligence more accessible to broader audiences. One of his long-term aspirations is to create educational content that helps people better understand complex technical concepts.
“Breaking down complex technical concepts into ideas that are accessible and engaging for everyone is a fun challenge,” he said. “I think bridging that knowledge gap is incredibly important.”
Outside of cybersecurity, Wani channels his competitive nature into soccer and competitive gaming, particularly Counter-Strike 2 and Valorant.
Whether on the field, in competition, or researching the next vulnerability, he is constantly looking for opportunities to learn, improve, and push himself further. As he begins his professional career, his accomplishments already demonstrate what can happen when technical talent, curiosity, mentorship, and hands-on experience come together.
Tim Holcomb – Inside Embarc Collective and Tampa’s Startup Future
Tim Holcomb is the CEO of the Embarc Collective, a Tampa-based nonprofit helping startup founders build bold, scalable companies through coaching, connection, and community.
In this episode, Tim sits down with Sarina Gandy to explore how Embarc Collective is shaping Tampa Bay’s growing innovation ecosystem by supporting founders through every stage of the startup journey. The two discuss Embarc’s unique approach to founder support, the importance of community in entrepreneurship, the evolving role of cybersecurity and emerging technology in the region, and how partnerships with organizations like the University of South Florida are helping strengthen Tampa Bay’s future workforce.
Tim also reflects on his own career journey across industries and countries — and the full-circle experiences that eventually led him back to entrepreneurship and leadership in Tampa Bay.
The CyberBay Podcast is produced by Sarina Gandy and powered by Cyber Florida.
Cyber Florida Seeks Fla Residents for Fall CyberWorks Training Program
12-week virtual cybersecurity training program accepts Florida’s veterans, first responders, military spouses, government employees
June 1, 2026—Tampa, Fla—Cyber Florida is accepting applications for the Fall 2026 cohort of CyberWorks, its workforce development program designed to prepare Florida’s public-minded professionals for careers in cybersecurity. The new cohort begins in September 2026 and is available at no cost to eligible participants. The deadline to apply is August 31.
CyberWorks is a 12-week, fully virtual training program that guides participants toward earning the CompTIA Security+ certification, one of the most widely recognized credentials for entry-level cybersecurity roles. In addition to technical training, participants gain access to a network of peers and mentors, career-advancement support, and a collaborative learning community.
Cyber Florida welcomes applications from Florida residents who are:
- Veterans
- Transitioning military personnel
- First responders
- Military spouses
- Government employees (federal, state, local, tribal, or territorial)
“Our goal with CyberWorks is to create opportunities for those who serve and support our nation to build new skills, advance their careers, and step confidently into Florida’s growing cybersecurity workforce,” said Cyber Florida’s CyberWorks Assistant Cyber Program Manager Mai Ensmann. “This program is designed to meet learners where they are and help them succeed.”
CyberWorks is funded by the DoW CIO Cyber Academic Engagement Office and the NSA National Centers of Academic Excellence in Cybersecurity Program.
Those interested are encouraged to apply early, as space is limited. For more information or to apply, visit the CyberWorks page on the Cyber Florida website. To hear from CyberWorks graduates, check out the CyberWorks playlist on the Cyber Florida YouTube channel.
Media Contact: Cyber Outreach Manager Jennifer Kleman, APR, CPRC
mailto:jennifer437@cyberflorida.org
ABOUT CYBER FLORIDA
The Florida Center for Cybersecurity at the University of South Florida, commonly referred to as Cyber Florida, was established by the Florida Legislature in 2014. Its mission is to position Florida as a national leader in cybersecurity through comprehensive education, cutting-edge research, and extensive outreach. Cyber Florida leads various initiatives to inspire and educate current and future cybersecurity professionals, advance applied research, and enhance cybersecurity awareness and safety of individuals and organizations.
Eric Foster – Building TENEX.AI from the Ground Up
Eric Foster, CEO and founder of TENEX.AI, is building more than a cybersecurity company – he’s building an AI-native defense solution designed to change how security teams operate.
In this episode of the CyberBay Podcast, guest host and Tampa Bay Business Journal reporter Anjelica Rubin sits down with Eric inside TENEX’s soon-to-be headquarters, which is currently still under construction, for a conversation about building from the ground up. Eric reflects on his early fascination with technology, the mentors who shaped his leadership journey, and the pivotal moments that pushed him to launch TENEX. Together, they explore what it really means to be “AI-native,” how artificial intelligence is reshaping the cybersecurity workforce, and why Eric believes Tampa Bay – and CyberBay – are positioned to play a defining role in the industry’s future.
The CyberBay Podcast is produced by Sarina Gandy, powered by Cyber Florida, and supported by Bellini Capital.
Madeline Sedgwick — Cyber Threat Analyst at Palo Alto Networks and a DUUUUVALLL lifer
Episode 72 — Madeline Sedgwick
Madeline Sedgwick — Cyber Threat Analyst at Palo Alto Networks and a DUUUUVALLL lifer
Madeline Sedgwick is a Cyber threat Researcher and Threat Analyst at Palo Alto Networks Unit 42, specializing in nation-state cyber activity, covert infrastructure, and cyber intelligence analysis. Before entering the private sector, she spent six years in the U.S. Navy as an intelligence specialist, helping support some of the earliest cyber operations under United States Cyber Command.
In this episode, Madeline shares her journey from joining the Navy to becoming one of the first certified cyber targeteers supporting offensive cyber operations. She discusses the realities of tracking covert threat actor infrastructure, why defenders must understand adversary behavior beyond alerts and signatures, and how intelligence analysis helps uncover the bigger picture behind cyber campaigns. Jack Clabby and co-host Sarina Gandy talk with Madeline about fusion analysis, cyber warfare, leadership, and the challenges of translating highly technical investigations into actionable insights for government and industry leaders. She also reflects on the importance of humility in leadership, mentoring, and learning to navigate high-pressure situations with confidence and curiosity.
In the Lifestyle Polygraph, Madeline debates cybersecurity in the Star Wars universe, explains her Weird Al Yankovic Dragon Con costume, reflects on her time playing bass in a metal band, and proudly shares why Jacksonville, Florida, will always be home.
Follow Madeline on Linked in: https://www.linkedin.com/in/mesedgwick/
Teacher Spotlight: Susan Garcia

Teacher: Susan Garcia
District: Palm Beach County
For more than 20 years, Susan Garcia has inspired Jupiter High School students through innovative, real-world computer science and cybersecurity education. A former programmer and computer coordinator at Pratt & Whitney, she brings industry experience into the classroom to build students’ creativity, critical thinking, and problem-solving skills.
Garcia expanded cybersecurity and programming pathways by founding the Computer Science Honor Society and helping grow the school’s Cybersecurity Academy. Her students compete in leading national programs and competitions, including AFA CyberPatriot, CISCO Networking Academy, Lockheed Martin Cyber Quest and Code Quest, CyberLaunch, and multiple collegiate-level programming tournaments.
She is now leading the launch of Jupiter High School’s Esports Academy, developing a curriculum that integrates Scratch, Minecraft MakeCode, Minecraft AI and Cybersecurity, and Unity with C# to deliver hands-on learning in coding, game development, simulations, and cybersecurity.
Garcia was recently named a Final Four finalist for the 2026 Dwyer Award in the STEM category, recognizing her impact on students and the future cybersecurity and computer science workforce.
Thanks for all you do, Ms. Garcia!
Would you like to be featured in our Teacher Spotlight? To nominate yourself or another deserving teacher, complete the interest form below!
Jack Voltaic® Tampa Strengthens Regional Cyber Readiness















Successful Multi-Sector Cyber Exercise Strengthens Tampa Bay Preparedness
From May 18–20, 2026, Cyber Florida, in partnership with the Army Cyber Institute and a broad coalition of federal, state, local, military, academic, and private-sector partners, successfully completed the Jack Voltaic® Tampa Cyber Incident Exercise at the University of South Florida Marshall Student Center.
The three-day, immersive exercise simulated a coordinated cyberattack targeting Tampa Bay’s critical water infrastructure, creating cascading impacts across essential services and adjacent military operations. The event brought together decision makers and technical responders to test coordination, improve readiness, and strengthen cyber resilience across the region.
About Jack Voltaic®
Jack Voltaic® is an initiative led by the Army Cyber Institute designed to evaluate and enhance the resilience of communities surrounding U.S. military installations.
Because modern infrastructure systems are deeply interconnected, disruptions in cyber-physical systems, such as water, energy, transportation, and communications, can quickly ripple across both civilian and defense environments.
Since its launch in 2016, the Jack Voltaic® series has focused on:
- Strengthening civil-military cyber coordination
- Testing multi-sector incident response capabilities
- Identifying infrastructure interdependencies and vulnerabilities
- Improving regional resilience through realistic scenario-based training
The 2026 Tampa exercise built on this foundation with an expanded focus on operational execution and cross-sector integration.
Exercise Scenario: Coordinated Cyberattack on Water Infrastructure
Participants worked through a realistic, escalating cyber incident affecting water treatment and distribution systems in the Tampa Bay region. The scenario was designed to reflect the complexity of modern cyberattacks against operational technology (OT) and critical infrastructure environments.
Scenario progression included:
- Corruption of vendor-managed PLC systems
- Altered chemical setpoints impacting water treatment processes
- Theft of sensitive utility operational data
- Loss of SCADA control and degraded system visibility
These events created cascading operational challenges for utilities, emergency managers, and defense-supporting infrastructure, requiring coordinated response across multiple jurisdictions.
Exercise Objectives and Outcomes
The exercise successfully met its core objectives:
-
Strengthening Regional Response Capabilities
Participants tested and refined the ability of the Tampa Bay region to respond to a sophisticated, multi-sector cyberattack under realistic operational pressure.
-
Evaluating Emergency Management Under Stress
State and local agencies examined response coordination in an environment reflecting concurrent emergency demands and infrastructure disruption.
-
Demonstrating Regional Leadership
The Tampa Bay region further established itself as a national leader in cyber incident preparedness and cross-sector collaboration.
-
Assessing Defense Operational Impacts
The exercise highlighted potential implications for nearby defense installations, including MacDill Air Force Base, as well as U.S. Central Command and U.S. Special Operations Command.
A Dual-Track Training Environment: Tabletop and Live-Fire Integration
A defining feature of the 2026 exercise was the integration of two complementary training environments: a facilitated tabletop exercise (TTX) and a live-fire cyber range exercise (LFX).
Tabletop Exercise (TTX): Strategic Decision-Making in Action
Led in partnership with Norwich University Applied Research Institutes, the tabletop exercise brought together leadership from across sectors to:
- Evaluate response plans and procedures
- Coordinate crisis communications strategies
- Identify gaps in interagency coordination
- Discuss policy, governance, and resource alignment
Facilitated discussions enabled participants to test assumptions and refine decision-making frameworks under evolving scenario conditions.
Live-Fire Exercise (LFX): Operational Execution at Scale
The live-fire exercise, powered by SimSpace, provided participants with a realistic cyber range environment where technical teams:
- Analyzed live telemetry, logs, and simulated alerts
- Identified indicators of compromise across IT and OT systems
- Implemented containment and mitigation strategies
- Coordinated across SOC, engineering, and leadership roles
- Delivered operational briefings to executive stakeholders
The LFX environment enabled participants to directly translate tabletop decisions into technical execution, reinforcing real-world readiness.
Broad Cross-Sector Participation
The exercise brought together an extensive coalition of partners, including:
Federal and Military Partners
- U.S. Cyber Command, U.S. Central Command, U.S. Special Operations Command, U.S. Coast Guard, Florida Army National Guard, the FBI, and the Cybersecurity and Infrastructure Security Agency.
State and Local Government
- City of Lakeland, City of North Port, City of Tampa, Hillsborough County, Pasco County, Pinellas County, along with multiple state agencies.
Critical Infrastructure and Industry
Key infrastructure partners included:
- TECO Energy
- Tampa Bay Water
- Tampa General Hospital
- BayCare Health System
- AdventHealth
- US Water Services Corporation
- Academic and Research Partners
Idaho National Laboratory and the University of South Florida played key roles in supporting scenario design, technical integration, and research-informed facilitation.
Key Outcomes and Takeaways
Across all three days, participants identified several critical outcomes:
Stronger Cross-Sector Coordination
The exercise reinforced the importance of pre-established relationships between government, industry, and military stakeholders in responding to cyber incidents affecting shared infrastructure.
Improved Operational Awareness
Participants demonstrated improved ability to maintain shared situational awareness across IT and OT environments during rapidly evolving incidents.
Identification of Infrastructure Interdependencies
The scenario highlighted how disruptions in water systems can cascade into healthcare, energy, and defense operations.
Enhanced Crisis Communication Practices
Leadership teams refined strategies for communicating risk, coordinating messaging, and maintaining public trust during cyber disruptions.
After-Action Review and Next Steps
Following the exercise, participants contributed to a comprehensive after-action review capturing:
- Key strengths in coordination and response
- Gaps in technical and organizational capabilities
- Opportunities to improve communication and decision-making workflows
- Recommendations for future regional cyber preparedness efforts
These findings will inform ongoing efforts to strengthen cyber resilience across Florida’s critical infrastructure ecosystem.
Advancing Cyber Resilience for the Future
The successful completion of the Jack Voltaic® Tampa Cyber Incident Exercise underscored the value of sustained, cross-sector collaboration in addressing today’s evolving cyber threats.
By bringing together civilian leadership, military commands, infrastructure operators, and cybersecurity practitioners in a shared training environment, the exercise strengthened both relationships and operational readiness across the Tampa Bay region.
Cyber Florida and its partners remain committed to advancing this collaborative model, ensuring Florida continues to lead in building resilient, secure, and well-coordinated cyber defense capabilities.
Cyber Florida’s services and resources are available at no charge. To arrange for access to the ARCS Range, visit https://cyberflorida.org/arcs-range/. To explore no-cost cybersecurity training and educational opportunities for all levels of public sector employees, including certification preparation, visit our FirstLine page at https://cyberflorida.org/firstline/. Critical infrastructure organizations interested in completing the Florida Cyber Risk Assessment to access free resources and expert help should visit https://cyberflorida.org/cip/.






