Interview with three renowned women in infosec on how they got started, some of their most memorable finds, and how to encourage more women to join their field
This post is part of Mashable's ongoing series The Women Fixing STEM, which highlights trailblazing women in science, tech … Tweets: @k8em0 and @infosecsherpa Tweets: Katie Moussouris / @k8em0 : “a huge diversion from the original purpose of focusing eyes...to ‘a bug bounty is a replacement for a [penetration test]’— which is absolutely wrong... Unfortunately it's creating a very damaging ecosystem for both bug hunters and companies who want to start bug bounties.” http://twitter.com/... @infosecsherpa : “It's not about getting more women interested in tech, we already are, we're born ready.” - @k8em0 http://mashable.com/...
Context & Ripple Effects
This interview sits inside Mashable's Women Fixing STEM series and captures Katie Moussouris at a pivot point: she helped invent the bug bounty model, yet here she warns that framing bounties as replacements for penetration tests is 'creating a very damaging ecosystem' for hunters and buyers alike. Three years later, her failed Microsoft pay-equity lawsuit would recast her as a test case for equity claims across tech, giving this early critique added weight.
On the diversity side, her line that it's 'not about getting more women interested in tech, we're born ready' reframes the pipeline debate from recruitment to retention — a reading that lines up with the Girls Who Code study of 1,000 young women finding internships hostile in male-dominated workplaces, and with interviews with women at NSA and Cyber Command noting progress alongside remaining gaps.
First-order effects
- Companies running bug bounties as cheap substitutes for penetration tests are publicly called out by the model's own pioneer, who argues the practice harms both the hunters earning from it and the firms buying it.
- Employers reading the series get a redirected diagnosis: the bottleneck for women in infosec is not generating interest but the workplace conditions they meet once they arrive.
Second-order effects
- Bug bounty platforms and their customers face pressure to reposition bounties as a complement to formal security assessment — even as the market grows lucrative enough to produce researchers earning $1M+, which raises the stakes of getting the ecosystem right.
- Diversity programs weighted toward recruiting campaigns risk misallocated spend if the real attrition point is the internship stage the Girls Who Code data documents, pushing budgets toward mentorship and workplace culture instead.
Third-order effects
- If practitioner voices like Moussouris's keep setting the terms, the women-in-tech debate shifts structurally from pipeline marketing to retention and pay equity — the direction her lawsuit-as-test-case framing later pointed.
- A professionalizing bug bounty labor market may eventually force clearer boundaries between crowd-sourced hunting and contracted penetration testing, changing how security work is scoped and priced.
The trend: The women-in-tech conversation is shifting from recruiting more women into fields like infosec to fixing retention, workplace culture, and pay equity for those already there.