Skip to main content

Rachel Tobac

CEO of SocialProof Security and Ethical Hacker

Social Engineering · Security Awareness · Human Risk

Read full bio ↓

Speaking Fee

Fee on request

Based In

United States

Signature Topic

Social Engineering

Format

Keynote and Workshop

About Rachel

Rachel Tobac is an ethical hacker and the CEO of SocialProof Security, where she trains and penetration-tests organizations on the attack that reaches them through people rather than through code. Her subject is the phone call, the pretext and the plausible email, which is where the large majority of breaches actually begin.

She placed second in DEF CON's Social Engineering Capture the Flag contest three years running, a live competition in which entrants extract real information from real companies from a soundproof booth in front of an audience. That is unusual credentialing for a speaker on this topic: the skill was demonstrated competitively rather than described.

She was among the first to correctly read and unpack the 2020 Twitter compromise in real time, explaining publicly how it had been done and what other organizations should change while the incident was still unfolding.

She has served on the CISA Technical Advisory Council under director Jen Easterly, and chairs the board of Women in Security and Privacy. Her work has been covered by NPR, The New York Times, CNN, Forbes, NBC Nightly News and Last Week Tonight with John Oliver.

On stage she demonstrates rather than warns. Sessions typically include a live social engineering demonstration against a volunteer or a consenting target, which is what makes the material stick with an audience that has sat through security awareness training and ignored it. She is frequently booked as a keynote plus a working session for the teams who own the controls afterward.

Keynote Topics

How I Would Hack You: Social Engineering in Practice

Building Human Firewalls That Actually Hold

AI Voice Cloning, Deepfakes and the New Pretext

Security Awareness Training People Do Not Ignore

Best For

  • Cybersecurity and information security conferences
  • Company-wide security awareness events
  • Executive and board security briefings
  • Financial services and healthcare risk events
  • Technology and engineering all-hands meetings

Booking Rachel Tobac: Frequently Asked Questions

What is Rachel Tobac's speaking fee?

Rachel Tobac's fee is not published and is quoted per event. It is driven by event date, location and travel, session length, and whether a live demonstration, workshop or training block is added to the keynote. Submit an inquiry with your date and audience size for a current quote and availability.

Does she really hack people live on stage?

Yes, with consent and within agreed limits. A live social engineering demonstration is the usual centrepiece, and it is the reason the material lands with audiences who have already sat through conventional security awareness training. The scope is agreed with the organizer in advance.

Is her material technical?

No. Her subject is the human attack surface, so the sessions are built for general employee audiences and for executives rather than for security engineers. Technical teams book her too, usually to change behaviour outside their own function.

What are her credentials in social engineering specifically?

She placed second in DEF CON's Social Engineering Capture the Flag three years running, a live competition in which entrants extract real information from real companies in front of an audience. She has also served on the CISA Technical Advisory Council and chairs the board of Women in Security and Privacy.

Appears On These Lists

Book this speaker

Rachel Tobac

CEO of SocialProof Security and Ethical Hacker

Fee on request

Typically responds within one business day. No spam.