All episodes

Alex Kreilein

Apple Podcasts Spotify SoundCloud

March Madness Consumes Alex

With Alex out of town for his annual March Madness trip, Matthew Sharp filled in admirably as co-host for this week's newscast. Robb gave a bit of a debrief about this week's SNOWFROC conference. And Matt revealed what's next on the agenda for his career - CISO for NYC headquartered Logicworks. While we're sad to have him leaving Colorado, we will stay in touch, and he mentioned to be on the lookout for Denver-area jobs for Logicworks.

Sign up for our mailing list on the main site to receive weekly updates, and our listener survey - https://www.colorado-security.com/. We're continually working to improve the show, and appreciate the feedback we get from our listeners. If you discover any audio issues, or have suggestions for our format, let us know.

This week's episode is available on SoundcloudiTunes and the Google Play store.

Reach out with any questions or comments to info@colorado-security.com

Feature interview:

Alex sat down with SecureSet co-founder Alex Kreilein, who is also Managing Partner of SecureSet Accelerator. SecureSet is the Denver headquartered cybersecurity training academy. The startup accelerator makes investments in early-stage cybersecurity companies. Alex talks about his background, his experience starting up SecureSet, and the challenge of training the next generation of security professionals. 

Local security news:

Job Openings:

Upcoming Events:

This Week's Events:

Notable Upcoming Events:

View our events page for a full list of upcoming events

If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript10828 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security Podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. All right, welcome to the March 20th newscast for the Colorado Equals Security Podcast. This week Alex is in Las Vegas, uh, getting mad for March. Apparently this is a normal thing, and I'm sure he's very drunk at this point.

So we're very lucky right now, we have Matt Sharp with us. Matt, you want to introduce yourself? Yeah, great. Thanks. Appreciate you having me on in Alex's absence.

My name is Matt Sharp. I am recently hired onto the LogicWorks team as a CISO, but before that I spent a number of years with some of the premier cybersecurity consulting firms based here in Denver market. So we've known each other for a 2 or 3 years probably, right? I think that's about right. I think just about the time you went over to Crocs, maybe a little bit before you went over to Crocs, we got to know each other.

And I know, you know, you've had some experience doing the consulting route and doing the security leadership route. And why don't you just talk a little bit about how you went from consulting into security leadership and where you are now? Yeah, well, so I think for a number of years I was with the Coalfire team and then transitioned over to Fishnet that was acquired by Blackstone and merged with Acculon. During that time, I was— the consulting model looks something like finder, minder, grinder. So you find the business, you mind the business, and then you basically do the work.

And so I've sort of progressed through that transition and then decided that I was going to try my hand at actually leveraging all the content and skills to build a program. And that's what I did at Crocs. Crocs was all about basically rebooting a program from scratch. That's awesome. And then your new opportunity, if folks don't know who LogicWorks is, can you give a high level, what do you guys do there?

Yeah, LogicWorks is a firm that's actually based out of New York. They've been around for 22 years, but they're early adopters of the DevOps frameworks. Their big focus is public cloud automation, very heavy. Leading partners for Amazon Web Services with all kinds of certs up and down their competencies, and we're actually just named as a leader in the Magic Quadrant. Awesome.

Cloud automation services. Yeah, that's great. Congratulations to do that. And I guess the bad news for those of us here is that means you're gonna be leaving Colorado. Well, I think, yeah, I will definitely be leaving Colorado, but I think I'll still be very connected to the market.

So one of the other guys based out of this market that's also joining the company is a guy by the name of Chuck Price, and he's starting up their professional services team, and he's going to be based here and looking to hire for a number of roles in this market. So the company very heavily differentiates from a security perspective, and they're doing all the cool DevOps and cloud automation stuff as well. Well, definitely sorry to see you go, but awesome that you get this opportunity, and I think it's gonna be a lot of fun. You're gonna get to learn a lot of cool stuff during the process, and we're looking forward to hearing about how it goes. Cool.

Yeah, appreciate it. Yeah, definitely looking for a pretty steep learning curve. Yeah. So, well, very cool. So we're gonna go through the newscast together.

Before we dive into the news for the week, I'll give a kind of recap of my last week. I got to go to SnowFrock last Thursday. And it was, it was really a very great— it was a great conference. So congratulations to Steve Costin and the rest of the board for Denver OWASP who put the conference on. They had Jim Manico came out and Laz came out.

They had Dan Cornell. There was a lot of good speakers, a lot of good tracks. And really it was one of the more fun conferences I've been to in a while. They did it at the Cable Center down there at DU. Oh yeah, which, you know, there's a great venue, that atrium area there.

The keynotes were in there, the bigger talks were in there, and it was a really good feeling. A lot of networking, a lot of sharing, and actually some good learning that went on as well. Jim Manico, if you haven't had a chance to hear Jim talk, I highly recommend it. He's maybe my favorite speaker. He's so passionate and he's full of energy as he goes into what some might think of as a kind of a boring topic.

He's gonna go into some specifics on application security, and the talk I went to was all about OAuth. How do you use OAuth? How do you not mess up your implementation of OAuth? All those specifics and he's passionate. He's talking just lots of energy and everyone walks out of the room like, I'm going to go do OAuth.

That's awesome. It's kind of a hard thing to accomplish. Yeah, yeah. It's like getting people jazzed up about audit or security. Right, right, right.

Okay. Well, so anyway, Jim's a great guy and anyway, congratulations to the OWASP team for pulling off the conference. So let's go ahead and jump into the news for the day. Top of the list was the Level 3 and CenturyLink shareholders have both approved the merger, or I guess really the acquisition by CenturyLink of Level 3. So that was exciting news, and hopefully the last thing really for them now is federal approval of the deal.

Yeah, I think this is great. You know, you've seen a ton of consolidation in this, in this industry in general, and we've got some great security leadership. So hopefully bringing those 2 companies together continues to maintain that leadership here in Denver. Yeah, I do get a little nervous. Both teams have great leadership, like you mentioned.

Dale Drew is the CISO for Level 3 and Dave Mahon is the CSO for CenturyLink, both here in Denver, both with big teams in town. I hope that they're able to continue to keep driving into the security industry that way. Dale's a regular contributor to the security community. Yeah. I mean, I guess on the flip side, if they consolidate, there's going to be some good talent available in the marketplace.

So that's fair enough. So next is Fortune has their list of 100 best companies to work for in the country, and a local company, only one local company made the list, and it's PCL Construction. Yeah, so I was surprised to see that we didn't have more folks in the top, especially given the heavy migration towards this general market. But PCL, at first I was a little confused about it. I looked them up, the logo looks a little bit more familiar when you poke around.

And you mentioned earlier when we were talking substantial revenues, almost $7 billion in revenues. So it's a— yeah, it's for a company that I didn't recognize the name of. That's pretty impressive in the Denver market, right? Yeah, I was really pretty shocked to see that as well. But I guess they've been on this list for multiple years.

This isn't the first time. Yeah, 12, I think. And so they saw that every employee is given stock options and 90% of employees own stock in the company. I guess that really changes the culture and makes it a lot more innovative and interesting place to work. Yeah, I in particular was excited to see, you know, some folks that have been there for a while actually receive more from the profit sharing and the stock dividends than they actually do from their salaries itself.

So to hear that that's happening at more levels than just the executive level says that they're really passionate about, you know, doing things right and making sure that the entire team benefits. And it's not that's not a high-tech company, right? This isn't a startup, you know, Silicon Valley. It's construction. This is not where you expect to see such a high level of equity compensation.

So anyway, very cool. I'm glad that hopefully they keep doing that, and maybe some other companies can, you know, take a page out of their book and start doing that as well. Yeah. So we included a link this week to the, the 9 things your employees can do to help, help you fight cybercrime. Um, the interesting thing here isn't necessarily that there's a lot of innovative points in the article.

It's really that this article was written for business leaders. It was written in the Denver Business Journal for, um, you know, not for the security crowd. That, that was kind of a neat thing to see pop up on the radar. Yeah, and, you know, I generally agreed with most of the points. I, I, I think I would have, uh, really categorized it as a security awareness training, sort of, uh, framing out a security awareness training program.

But yeah, you're right, for, for the audience, um, mid-tier businesses that are looking to really empower their employees to not give away the secrets. You know, definitely an interesting article. Yeah, so I'll quickly read the 9. We won't go through a lot of details, but number 1, make sure they're using strong passwords to protect private information. Don't open suspicious links and emails.

Scan all external devices. Remind employees that public Wi-Fi networks can be dangerous. Protect company data and financial assets. It's kind of a general one, right? Yeah.

The risk of social media networks. Use only authorized software and watch for phishing scams and social engineering fraud. So, the categories, you know, I— with apologies to the author, Morgan Mahoney, who I don't know, maybe the categories aren't what I would have picked, but I certainly appreciate, Morgan, that you were able to get this article written and get it out to this audience and get some thought about security, you know, outside of the IT and the security community. Yeah, and I think he's an insurance guy if I looked it up. He's an advisor for CCIG.

I don't know, is that an insurance group maybe? I thought I clicked on it. I may have clicked on the wrong stuff, but yeah. Okay, so anyway, good for it. Yeah, you're right.

He's an insurance advisor. So yeah, very cool, and hopefully maybe he's trying to get his folks ready for cybersecurity insurance. That would make sense, right? Yeah. So next on the list, touch on Webroot's press release this last week.

For the last quarter, they now have had double-digit growth for 12 quarters in a row. For a relatively older company, that's pretty impressive. 12 quarters in a row of double-digit growth. Yeah, I think it really speaks to the fact that the endpoint market is heating up, and I think it speaks to— they've done a fantastic job from a marketing perspective. I'm pretty sure I saw Webroot advertising at DIA, so maybe they've taken a book out of the Barracuda playbook.

And yeah, I mean, you know, to see local company, endpoint company, seeing that kind of growth year over year is definitely an exciting thing for us. I know they would say they're not just an endpoint company, they're also a threat intel company. Just, I'll put that out there. They'd be mad at us if we don't throw that out there. They do endpoint and they do threat intel as well.

Yeah, okay, that's fair. I have done some mental rounding there for sure. Yeah, fair enough. So the last big news from this companies here in town is ProtectWise is now partnering with Demisto. Um, so ProtectWise, the local security company that does, uh, really it's visualization and kind of your one-stop shop for network security in your company, partnering with Demisto, which is a company I hadn't heard of.

Did you know Demisto? No, so I was surprised. So my history with ProtectWise was, um, they're essentially a DVR for, for the network, and then they layer in all of these security features on top. So the fact that, um, you know, Demisto is coming in on top of that, uh, I think gives them a pretty compelling story. I feel like, um, they had a competitor for a while.

It was Schneier's company, and I forget, it was CO3, and I think that turned into Resilience. So Resilience— I hadn't heard, um, of Demisto at all, but it looks pretty great. Uh, pretty, pretty great. The— they're talking about ChatOps, which was a term that, yeah, I wasn't particularly familiar with, so I had to look that up. So Slack Slack and HipChat are the 2 big chat ops, and we use Slack at Ping, so I'm pretty familiar with it now.

It's basically interrupting you every 2 minutes all day long. It's a very different way of doing things. I will read an interesting paragraph out of the press release. The ProtectWise and Demisto integration enables joint customers to fetch key ProtectWise observations, including detailed packet capture, for creating incidents in Demisto. Demisto playbooks leverage rich data collected by ProtectWise.

For hunting, for hunting files, IP, domain, and other indicators across the enterprise, enabling faster and more accurate response to incidents. Demisto's real-time interactive investigation using ChatOps extends ProtectWise's forensics exploration with a chatbot interface and empowers analysts to auto-document and investigate fast— faster. So basically, you know, ProtectWise finds the thing, Demisto enables you to respond to it better in your normal workflow. That's what it sounds like. Yeah.

And to me, I mean, I looked at this and I thought, gosh, this looks a lot like automation via API calls to all of your tools and then centralizing that so that you can, you know, workflow through that. They also said that there's some component of orchestration within there, and I wasn't able to dive in far enough, or I haven't met the guys to familiarize with the tech, but definitely something that looking at further, I think. Yeah, and Demisto is— they, from what I saw on the web, they're competing with Swimlane. And if you don't know Swimlane, they're another Colorado Denver area security company. They're actually headquartered in Louisville, and they do exactly this, uh, orchestration for incident response.

I'm going to sit down with their CEO pretty soon, and we'll have them actually as a feature interview on the podcast. But I guess my, my call out to ProtectWise is, hey, look and see, see if you can do this kind of a partnership with the guys in town as well, just down the road. Um, and, and hopefully we can help the Swimlane guys, uh, get some traction there too. Yeah, yeah. Uh, so last thing on the, uh, for the news here, um, we, we have recently put out the listener survey.

So if you're on our, our mailing list, you should have received a, a link to SurveyMonkey to ask you for feedback on the podcast. If you're not yet signed up on the mailing list, please go ahead and get signed up. We'll get you the survey out there. Basically trying to figure out how we should balance the time we spend here, you know, between the different segments and where you guys want to see more focus. Hey Robb, what's the URL again and where's the— That's a great question.

Where's the— I gotta go do this myself. So it's colorado-security.com and at the bottom there's a, you know, sign up for our newsletter, just an open text box at the bottom there. You hit, put your email in, hit submit and you're good to go. Okay, cool. So jobs for the week.

Number 1 job we'll talk about is over at Cognizant. This is with our very good friend Matt Shufeld. Either as the hiring— I think he's as the hiring manager here. He's looking to hire a senior cybersecurity manager, which it sounds to me like a lot of words. I don't know, cybersecurity manager.

Yeah, well, here's what I can say, having interfaced with Matt for a long time, you know, as a peer in the industry. Matt's done a very good job in creating a lot of loyalty in his teams. I think that's safe and easy to say. And I, I think the other thing is he's very intentional about finding folks, identifying, uh, areas of growth, making sure that they're passionate about that, and really kind of tapping into, um, that and stretching people. So, you know, from that perspective, I'm not super familiar with the role, but I do give a lot of credence to anything that comes out, uh, under his management.

And exact same thing for me. You know, Matt's one of the guys I respect the most in town. And if you have a chance to work for them, I highly recommend you take it. Yeah. The Credit Union of Colorado is hiring an information security officer.

I don't know much about that credit union, but generally speaking, the credit unions don't have a ton of resources, and this security is very important for them. So you'd have an opportunity to go do some innovative, interesting stuff there and hopefully, you know, make a change to the culture there. Yeah, and I think on the flip side, you know, here you have what I do think is interesting is you've got financial institution Generally, they take the security pretty serious, so getting a chance to get in there and really build up a program could be a great opportunity. Peg Wright, they are a Colorado-based IAM consultancy, and I've actually run across them quite a bit in the last year or so since I've been at Ping. They basically come into an organization, help identify where's your IAM program, and then help you find the solutions to fill it out and get you all the way to where you want to be.

They're hiring a security solutions consultant, and apparently they're also hiring a security engineer. I sent a note over to those guys as I was getting ready for the podcast to ask what they need. Basically what they're looking for here is somebody who has experience either running or administering an IAM program and having worked with some of the tools— Ping Identity, SailPoint, Okta, Oracle Access Manager— any of the big IAM solutions is what they're looking for here. Yeah, and is this intended to be— I mean, it's a consulting role, right? So this is going to tap into I would assume, I would assume that their demographic is, or their client base is national.

Is that true? Yeah, it is. They do have a national client base. I don't know if this, this role has travel or not though. Yeah, okay.

So Axios, I don't know Axios, but they are hiring an application security engineer. Do you know those guys? I'm actually not familiar with those guys. Yeah, not at all. Yeah, so take a look at the link if you're looking to do AppSec.

Engineering. NetSpy is hiring penetration testers. I think, you know, everyone, especially folks who are getting new into security, are looking for penetration testing and looking for chances to go be offensive. And here's an offensive role for you, so take a look. The US Department of the Treasury is hiring an information technology specialist, parenthetically security.

So IT specialist for the Treasury here in Denver, so you can go protect our federal government. We'd appreciate you doing that.

OTS, or Open Technology Solutions, they're a financial services provider, and, and I used to work for a competitor of theirs and got to know them pretty well. Headquartered here in Colorado, they're looking to hire a— sorry, I lost it— a junior security engineer. So, you know, if you're more junior in your career looking to, to get into financial services, this is a great place to do it. They have a broad customer base and, and can really get you A lot of exposure. Yeah, now do those guys have a fairly mature security program or is it, I mean, do you know much about that?

I don't know the details of their program. I can say that they're a fairly mature company, so I would expect that they've had a program going for 5 or 10 years. And they've had to go through numerous FFIEC examinations, so they should have the basic stuff in place. Should be in place. Swimlane, we talked about them a moment ago.

They're hiring a technical support engineer. So if you wanna go do tech support for a security company here in town, there's your opportunity there. And you said they're based out of Louisville? Yep, up in Louisville. I assume that's where this role's gonna be sitting too.

Tangible Security, I don't know Tangible Security, but they are looking for a Denver-based outside salesperson, and they call that person a hunter. So if you're a security guy, security salesperson here in town, here's an opportunity for you to get to take a look at. Then the last one is at Optiv. Optiv is, of course, the big security VAR and services company headquartered here in Denver. They're hiring a director of human resources here in Denver.

That one's going to be an interesting role, I think. Big challenge there, obviously. Optiv's got a pretty powerful sales force, which means a heavy flow of projects. I think it's just going to be a struggle for anyone with that much business volume to be able to maintain the, the talent to keep, to keep all those clients satisfied. Yeah.

Yeah. So that's it for our jobs. We have events for the week. There's 4 events coming up this week. On Tuesday, InfraGard has their When Good Employees Go Bad event.

That's, that's in the morning on Tuesday. The Colorado Technology Association has their STEM Talent Development Breakfast, STEM being science, technology, engineering, and math. Really, it looks like the topic here is to help come up with a strategy for how do we develop that next generation of talent to come along and, you know, give us the workforce we need for technology companies. Yeah, this one's close to home because my wife's a math teacher here in the Denver metro area, so she's always excited to see the professional environment engaging in a meaningful way because They need some— they definitely need some guidance, and it's nice for her to be able to then connect some of that story back to the kids in the classroom and say, you know, if you want to do this kind of role or that kind of role, you know, these are the kinds of salaries you can make, and pay attention because algebra is going to be important. Yeah, it's nice to have some tangible reasons to care about math in high school, isn't it?

Yeah, yeah. I think just like anything when we're building a program, if you can explain the why to people, then they engage better. That's great. On Thursday, SecureSet is doing their introduction to their threat hunting program. Yeah, so this one I feel like we should spend a little bit of time on.

I'm pretty excited to see a more proactive approach to pursuing threats in the enterprise. My sense is there's not a lot of folks out there doing this, and if they are doing it, that they're not doing it very well. I don't know if that resonates with with what you're seeing or the conversations that you're having with folks? It's really— I'd say generally it does resonate. It's really easy to spend all of your time dealing with the urgent, right?

We have vulnerabilities popping up. There was the Struts vulnerability the last week or so, and you spend your time looking through your systems to find out where the vulnerabilities are. You have to work on the audit findings or whatever it is that's really right in front of you. And hunting through your environment is never going to be urgent, but it's really important, right? So trying to find time to do that can be a challenge in any organization.

Yeah, and I think it's, you know, I think this is really, a lot of folks are innovating in terms of how do they accomplish this from a process perspective? What are the tools that you leverage to do this? But more importantly, how does it affect the way that you're staffing? So from my perspective, getting a chance to have some direct insight from the guys over at SecureSet is fantastic. I know they've been very tapped into the startup market for a while, and so, uh, yeah, I think this one's going to be an exciting one.

Yeah, very cool. So, so, so what this, uh, session actually is is an introduction to a program that they're starting. So, you know, they're an academy. You can go sign up for their 6-month boot camp for security introduction. Uh, there— this is their threat hunting program that they're, they're going to be starting to do it, and I think it's a shorter program.

Um, at this meeting they're going to talk about what you would learn during the program, and hopefully— I assume it's recruiting, right? They want to get some folks to start signing up. Yeah. So if you, if you're interested, or you're a boss in the area who might want to send some folks, or you might be interested, this is a good chance to come learn about what that new program is going to be. And these links are all in the show notes, or where?

Yeah. Okay. Yeah, all the links are in the show notes, and then also on the website. You can always just go to our, to our calendar of upcoming events to see the events. The last event this week is ISACA's happy hour and comedy show.

So they are— they have an event at Comedy Works South. You send an email to them, you get a free ticket to go see Kevin Nealon, the Saturday Night Live comic, come to his show. Just basically fun, right? Not a lot of agenda there, but good opportunity. Networking.

Networking for sure. I will say this, you know, coming off of a job search recently, the criticality of networking and We're security guys who tend to be not as social as the sales guys or the marketing guys, and I do think that it's important to prioritize that networking whether you're in a job search or not so that if you get there or you find yourself there, that you're connected enough to find jobs before they're posted on the job postings. I'll say people who reach out to me to connect while they're happily employed are people who I'm happy to have lunch with and have drinks with. People who reach out to me to connect because they just got laid off and now they think that I'm useful to know, less interesting to talk to. Yeah, it's, it's a tip, you know, get to know people before you need something from them and develop a relationship rather than just trying to, trying to use them once you, once you need it.

A few events that are noteworthy, not in the next week but coming up in the next few months. ISSA Colorado Springs is doing their their, their 2-day Security+ training. Highly recommend if you might want to get Security+ training. This is, I think it's like $50, or it's very inexpensive. You go, it is a drive to the Springs if you're from Denver, but April 1st and April 8th, um, we have those events coming up.

And you talked about that in more detail in the last podcast last week, right? I did. And, and then in June they have a second round of this. So if those April dates don't work for you there's another option in June you could attend as well. Great.

We also mentioned last week Denver's Women in Security event is getting started. I have never seen so much excitement about an event as I have around this. We put it up, within a couple of hours we had over 40 people signed up, and that was 6 or 7 weeks in advance. A lot of excitement here. Hopefully this group can really meet a need in the community and help help bring more women into security.

Yeah, so what are you seeing in terms of demographic? It's all women? Not quite. No, there's just— by invite or? Well, it's just an event you go sign up for.

We've had a few men sign up for it. The vast majority have been females though. Yeah, okay. And we also had interest from outside of security. One of the reporters from the Denver Post has reached out about it and hopefully going to get some coverage there and maybe she'll even come to the event.

There has been a lot of interest in basically why have we been so slow to get something like this going is kind of what I feel like right now. We are where we are and we're making progress. What I think is really powerful is when you look at the research, boards of directors for publicly traded companies that have women on them outperform substantially. I have to believe that that's also true for security teams with women in them. It's just diversity in thought.

Yeah, that's great. A few more events coming up. We've talked about it every week. Rocky Mountain Information Security Conference, May 9th, 10th, and 11th. Registration is open.

Go get signed up now. All the keynotes are confirmed. All of the events are locked in. You can go get your schedule going. And then the 2 days after that, the 12th and the 13th, is Denver BSides, a great event.

If you spend the previous 3 days at RMISC, you can go blow off some steam and drink some beers with a the group at B-Sides. Wax philosophical. Lots of philosophy in those conversations. Yeah. Are we fixable?

Are we too far gone? Yeah, there's some of those things. That's great. Well, that takes us to the end of the newscast. Matt, anything you want to leave the group here with?

Gosh, what would I leave the group with? I mean, I think from my perspective that the Colorado Equals Security is a very powerful thing. Really appreciate all the work that you guys have done. You in particular, Robb, and Alex as well. You know, you guys have pulled together a community in a very unique way, and we've heard it from a number of folks, including, you know, the CEO over at Veracode said he's been all over the country and he really sees something different happening here.

So the fact that we've got, you know, Hik and Loop are engaged in the conversation now and really moving the story forward is very powerful.

So I would say thank you, yeah, in a public forum. Really appreciate everything you guys have done. Well, thanks, Matt. I appreciate it. Well, with that, we will go ahead and sign off for the week.

We do have the feature interview coming up where Alex sat down with Alex Krylan, who's one of the co-founders from SecureSet. You can learn some more about SecureSet here coming up. Thanks a lot for your time, Matt. Take care. Hello, this is Ian Buxton, Senior Director of Information Risk and Security at Vail Resorts.

This is Colorado Equals Security, for Colorado security professionals, by Colorado security professionals.

All right, this is Alex Wood here with Alex Kreilein. Alex, how are you? I'm doing really well. How are you today? Wonderful.

Great, man. I think we're gonna have a great interview here. Why don't we start out though by, you can tell everybody, who you are and what it is that you do? Yeah, for sure. My name is Alex Kreilein.

My handle is @acker303, and I work as a managing partner for SecureSet here in Denver, Colorado. And I run, with a partner of mine, Dave Odom, our startup accelerator that focuses on investing in and helping support cybersecurity startups in the areas of product development, team building, sales. Awesome. Yeah, it's a really fun experiment. That's really cool.

So how is it that you got started in the cybersecurity industry? Yeah. And, you know, what is it— are some of the things that you've, you know, kind of done in your past different roles? Yeah, when I graduated from my undergrad, I had a humanities degree, right? And so I came into this from a really non-technical perspective.

But one of my first jobs out of college was working at a value-added reseller. It was a great experience. People were really smart and we sold great products, which I appreciated. But I found myself really frustrated in that most people didn't really know how the products worked, and I really wanted to learn. And the long and short is I ended up moving to D.C. and taking a job on Capitol Hill working for Congresswoman Jane Harman and supported her in energy and commerce work and homeland security and supporting some of our other staff who did some of the intelligence work.

And that's kind of how I got into cybersecurity, was through policy. And really focusing on, you know, what are the appropriate left and right limits as a country? What do we need to do to protect our companies and our assets and our national security? And, you know, I sat in my office with a little CCNA book, you know, a little, you know, I mean, some Layer 2 and Layer 3 components literally under my desk, tried to teach myself network engineering. And I ended up getting out here to Colorado as part of my work in cybersecurity when I moved over to the Department of Homeland Security.

And I helped run and manage mobile security operations programs and worked at the NIST labs in Boulder as a guest researcher through my time with Homeland Security. And it was awesome. I mean, learned how to break things, learned how to build things, learned how things should be built, and, you know, got into the research field, and it was pretty beautiful. That sounds awesome. Yeah, I got lucky.

Yeah, so I know as part of your role there, you know, one of the things that you did was you got a chance to work on the creation of the NIST Cybersecurity Framework. Yeah. You know, why don't you talk a little bit about that, you know, what you did there? Totally. And I'm sure that was a pretty cool ride.

It was fun, you know, and I came at this kind of in a weird perspective because I was kind of a jack of all trades. I worked for this interesting office at the Department of Homeland Security and focused really a lot on communication security. And that's one of the, you know, 16 critical infrastructure and key resource sectors, the communications sector. And I got pulled into this to support the whole executive order, specifically in the development of incentives and some aspects of the framework itself, and had a great opportunity to work with researchers at NIST, economists at Homeland Security and Treasury, strategy and operations managers throughout not just the federal government, but then also the private sector. And so to their credit, DHS and NIST did a really awesome job at doing outreach.

You know, I wonder how effective a lot of the inputs were, and so I think we'll see new revisions coming out for the NIST Cybersecurity Framework as part of that to make sure it's adaptive. But it was getting thrown into the deep end, you know, for, for somebody who loves communications networks and You know, really had a strong interest in offensive security, having to think about compliance frameworks, regulation, the economics involved in control development. That was really heady and really fun and important work. What do you think one of the most difficult things was in doing that work to help create the framework? I mean, I know, as part of the executive order, there was a really short runway to have that done.

Did you see challenges there? What other challenges did you guys see? Yeah, I think there probably should have been, I think, a little bit longer runway involved, not necessarily because that affected outcomes. I think it affected adoption in some way, because, you know, in order to get an entire country to really focus on a piece of policy, it takes a lot of, quite frankly, marketing and community engagement. And those are some of the things that weren't necessarily lacking, but they weren't optimized, in my opinion.

But the framework ended up turning out, I think, very, very well, in part because it's based on a number of other frameworks that are very well known and very well vetted, right? And so this is really an agreement of, out of the whole universe of other frameworks and controls that we use, which ones do we think are really essential and really effective and can be measured and tested? And so to that part, I think that worked well. You know, I still question whether or not people take it and other compliance approaches, and not compliance, but risk management framework approaches, really seriously, and if they really integrate them into their companies. So, you know, I've done a decent amount of work with the framework since it's been released.

Yeah, I have a training class that I try and teach people how to use the framework. Totally. You know, one of the things that I've noticed in using it is that in a lot of areas, it's extremely, extremely vague. Yeah. Or, or pieces are just missing.

Was that something that was, was consciously done, or was it just sort of a, you know, oh hey, we're running out of time, we just got to get this out the door? Yeah, so this is, um, I think the comment around this is not necessarily unique to the NIST Cybersecurity Framework, but rather to frameworks that are developed by committees. Where there are lots of politics involved. And that's ultimately, I think, a challenge, not for just the federal government, but organizations like GSMA and IETF and 3GPP and any kind of standards body. And I would imagine that in development of COBIT and other frameworks, some of these things also kind of sneak up on you, right?

And it's a question of, you know, should versus may, right? That's the constant debate amongst standards engineers and framework developers. And there's a lot of stuff that made it into the May category that ultimately I just don't know if people really thought was of necessary importance. And it also depends on who you are and what you're using it for, right? And it's really a user-driven doc.

And so to that end, I think the expectation is to leave it up to the users to define some of that for themselves. Yeah, I mean, one of the big things for me is, you know, that there's, there's really 3 components to it. You know, there's the core, the profile, and the tiers. Yeah. Well, when it came out, there was, there's not even an example of what a profile should look like.

Yeah, that's right. Was that a debate among the folks that were trying to create this? Hey, should we put something out there that at least gives people guidance other than, you know, sort of a big idea? Totally. So that, I'll be honest in that, that part I'm not in the room for.

Okay. But I can totally imagine what that looks like because the profile is where a lot of the sensitivity comes in, right? About like what we think is in bounds for the discussion, what's out of bounds for discussion. And there's a lot of hesitation amongst people in the federal government that when you're creating something, the natural reaction, especially in DC, is just to pound on it. And so I could imagine, but I have no way of knowing, that there's a conversation that happens about how much risk exposure do we want to open up for ourselves?

You know, to just endless infighting. And if I were the program manager on that, you know, I would have tried to limit that as much as I could. But yeah, you're right. I mean, examples of how to use it, you know, training around it, videos that go through like, you know, this is how we reasonably expect people to implement this. That's the stuff that I, as practitioner, I would love.

Yeah. Yeah, and I think that that's, you know, been one of the frustrations that I've had and partially why I created the training course that I have is so Hey, this is my idea of how you would do it. Yeah, you know, maybe, you know, we can talk amongst folks and try and figure that out. So, well, to your credit, I mean, you know, the, the people who walked into your Secure World, you know, training conference had smiles on their faces. So that seemed to have worked.

So thanks. So, you know, switching gears a little bit, you know, why don't we talk a little bit more about what it is that SecureSet is and what it is that you guys do, you know, some of the things that you're trying to provide for the community here. Yeah, so for me and my co-founder Brett Fund, you know, a lot of this was built out of, I think honestly, frustration. You know, seeing an opportunity of course, but just kind of getting tired of seeing the same story over and over again. And so what we built was a platform and The way that SecureSet works is we have a platform that currently has 2 arms to it.

The first one is a cybersecurity accelerator, which I already discussed, and the other is a cybersecurity academy, which has been up and running for the past year, year and a half. And the way that the academy works is that we go out and we actually educate. And I want to make a delineation between training and education. Training is usually something that happens over the course of a couple of days. Maybe not even a couple of days, maybe it's just one full day.

Education is something that's very progressive and long-form. And so what we've done is created a core program that has a 20-week daytime full-time component or a 36-week part-time evening component. And we teach all of the things that you would need to know to have a real operational capability at an entry level, right? We don't advertise that we're gonna make somebody, you know, the next like rockstar reverse engineer where you're gonna be crushing at assembly. You know, I mean, we teach assembly, we work through it.

That's at the higher end of the capability set. But really what we're focusing on is network security, system security, logs and detection, analysis capabilities, applied cryptography, not the math on it, right? There's some math, you know, but the application of it. And governance, risk, and compliance. And so, you know, we've really focused on that, and we're in Denver now.

We're opening a Colorado Springs campus. We'll also be announcing another campus outside of the Colorado region, and we'll be really making some great progress on, I think, changing the way that people engage security as a field and also how they learn. It's so much more efficient to do this than it is to slog through 3 years of on-the-job training where you're not actually in security. You're like a line guy taking tickets, right? Our graduates, they don't get those jobs.

They get tier 2 jobs. We've had great success in putting them into MSSPs, putting them into operational environments in healthcare and telecom. So on and so forth. We're really proud of that. So, uh, so what sort of, uh, person are you aiming at to be giving this training to?

Is this something where, you know, oh, maybe you're already in security and you're trying to hone a skill set and get better, or is this maybe somebody that's already in IT and they want to move into security? Totally. You know, what's the aim for the audience? Yeah, I think for, for us, the audience is somebody who is, you know, very technically capable But I mean, we're not talking like they're just sitting down and writing thousands of lines of Ruby, right? Or C, pick your language, right?

That's a whole debate, right? But what we normally see are people who've got some strength and capability in networking and systems. They've worked in IT probably, or they've been a really passionate hobbyist that has real capability. And I wanna delineate this from like somebody who you know, goes on Cybrary for a couple of hours, which is a great service and one we actually encourage all of our students at all of our levels to go through, but somebody who does a couple of classes and then thinks they're good, right? There's real capability that's needed, but it's absolutely not unattainable.

We're talking, you know, dedicate a couple of months of working on your own on like Linux implementation or some basic networking. If you have a CCNA, you're good. You know, if you've been a sysadmin for any period of time, you're good. We can work with that and we can make you a lot stronger, and we've proven success in that. We also have people who are currently in security who know that there's a whole world that they don't know, and so it's very common for us to get applications and to admit students for people who actually work in the security field, but they want to really level up and they want to compress a couple of years of content into a short period of time.

And the last thing I'd note is we're one of the only institutions of our category, not just cybersecurity, but code schools, data science schools, we actually have the ability to transfer almost an entire year of undergraduate computer science out of our 20-week program into Norwich University and CSU Global here in Colorado. So someone comes and takes your classes here, but they want to get a bachelor's or something like that, a bigger degree, they can take the credit from here and transfer it somewhere else? Absolutely. That's awesome. Think about how powerful that is too, right?

Like, you get to really focus on the thing you wanted to learn. You're probably paying less by coming through SecureSet. And now if you are a veteran who has GI Bill, we have a method for being able to accept the GI Bill. So there's lots of ways to come here and be successful. So that's what we do for students.

And then separately, we also have a whole program built around startups where we focus on this other frustration that we've had, right? So there's the people frustration. We need more people, we need them to be effective, we need them to be really well trained and thoughtful. But separately, we need the same things out of our products. We need products that are actually answering real problems, not just have a feature set or another threat intel feed or something that's kind of commoditized, you know, and which is really why we focused around these kind of 9 values that we have.

And some of them are like, you know, products that enable developers to make them stronger. So we have fewer and less significant vulnerabilities to begin with, right? Changing the economics about how attacking actually works, focusing on collaboration between tools and between people in security, which is, I think, a huge problem that almost no one talks about. Being able to actually make information quickly actionable, either through automation or just more effective utilization of tools and content. We have a whole list of them, and we'll be soon coming out with a white paper that discusses at least the way we view, um, the real issues in the, in the security product market.

So we'll fund companies who do a better job in those spaces. So how does someone get involved with that? Yeah, do they— do you go out and search for, for folks that have ideas? Um, do you know, are people coming to you and saying, um, hey, I've got this, this great product, but I need some money, I need some advice? How is it that, that the this starts?

Yeah, totally. So, you know, we do what we think actually is a good job of trying to be really industrious and find people who have interesting and weird and clever ideas, and we do that in a lot of fashions. We do that by working with local startup communities, not just here in Colorado but nationally. We also work with, you know, a lot of the venture funds who see deals in this space, some early-stage angel investors, But we also try and collaborate with the security research community. I mean, we actually do security.

We don't do anything else. You know, you're not going to come to the SecureSet Accelerator and be sitting next to a startup that is trying to build a better yoga studio, right? And so, by actually specializing and focusing on product development and engineering, we are naturally attracting, I think, a higher quality and caliber of entrepreneurs. Now granted, many of them are very technically focused, and that's great for us. We then also have to work on the other things of how do you build a company?

How do you deliver a service? How do you build a team? And we're very equipped to be able to do that because we've done it ourselves. And beyond just we've done it ourselves, we also work with a great number of people who have also done it successfully and unsuccessfully, where they get to tell you how they failed and what the pitfalls are and just be real about what the problems are in starting an early-stage company. So, you know, one of the things that I've seen with some startups, and you know, you mentioned this a little bit earlier, that, you know, you're trying to get products that make a difference in the market, not just, oh hey, we do the same thing as someone else but we do it cheaper, or we do it, you know, things like that.

How is it that you get that feedback to know what it is that the market really needs and that these products, you know, really will help move the needle? Totally. So we do this in a couple of fashions. So the first way is we've, we've been really industrious in trying to identify requirements in a number of different sectors. So we've actually gone and done customer interviews and evaluation at a great number of companies in the healthcare space, in telecom, in finance, in retail, and in infrastructure.

And so we have a good screen just on the front end of what's not working, and that's important and helpful for us to make some decisions, but there's really very limited benefit to the startup there. So the way that we've decided to do this so that everyone benefits is we try and bring the market into the process. So we're actively recruiting mentors, both technical and non-technical, who are ready and able to give product feedback, give input to the startups, help them build a product that meets a need that's not currently being met. And the great part is these small companies are, you know, filled with wonderful engineering talent, which is great, but they're incentivized differently from major players. Major players have marginal incentive to consider and provide feedback, right?

They end up doing it, but it takes them a very long time. For a really small company that's scrappy and highly motivated and has myself and my business partner Dave Odom kicking them in the rear every day, they have incredibly high incentive to perform, and we're going to keep them on track to make sure that they deliver back into the market. Awesome. Going back to the education component for a minute, you know, I hear over and over again that there is a, you know, lack of, you know, name your number, you know, 1 million, 2 million, however many people. Totally.

Huge. Yeah, huge. Huge. What's your feeling on what the talent market really looks like in cybersecurity. Yeah, I mean, obviously you guys are trying to provide services so that people can, you know, be better in that market.

But yeah, but do you feel like that there really is that much of a gap in the skills that we need? Yes, it's a good— it's actually a really good question, and I think it depends on what the company is that we're talking about. But so normatively, if we just localize it to Colorado, right, We think, um, that there are around 12,000 open jobs in the state for cybersecurity, but that's such a large and broad term that could encompass a number of people who are in network engineering or systems administration or compliance, right? And while I would grant you that all those are fields of cybersecurity, the job itself may not just be dedicated to cybersecurity. So the output is let's just make an estimation that there's under but around 12,000 open jobs.

The issue is that people who roll out of university systems— and I can say this confidently because I have 2 master's degrees and a double major in my bachelor's, right? Like, people who roll out of even graduate programs in engineering like myself don't come equipped with the tools to be operationally ready for an environment in information security. They don't really tend to teach applicable and actionable real information security at a university level. So much of it is spent on theory or mathematics or potentially like these interesting analytical methods like convex optimization or, you know, choose your format for, you know, how you wanna deliver some sort of equilibrium-based analysis, right? That's all stuff that's the formal methods that we tend to do in graduate programs in computer science and telecom and so on and so forth.

But you know what they don't teach you? How to harden a server. They don't teach you how to do analysis off of your SIEM. They don't teach you how to use real economics in cybersecurity like return on security investment. And they certainly don't almost ever teach you anything about like how to do reverse engineering of malware or choose your own adventure, right?

Those are things that there are very specialized universities and there's a small number of them that do them very well, but in the many universities that we have in the American West, right, there's maybe 3 or 4 that I think would do this at a level that when their graduates came out, they could go and get a job for $80,000 to $100,000 making a significant impact in that company. So, that's really what we're here for, is not to replace by any standard a university education, but it's to augment it based on years of feedback that we've gotten from the market. Awesome. You know, one of the other things that I feel like is lacking is, you know, you'll get someone who's wonderful technically, but they have— they lack a lot of the soft skills. Yeah.

They can't talk to people. Totally. Aren't able to write effectively, and I don't mean that they're illiterate, but just that they don't communicate well. There's a style of writing for management, you know, and also writing for your peers that's not like writing a technical paper, right, but that's constructing a memorandum. And so that's one of the reasons why, as part of our course structure, we teach this thing called Strategy and Analysis, and Security Culture is another course.

Where in both of those courses we talk about how to actually communicate, how to manage up, how to hopefully one day become a manager yourself, and how to create a career path for you that's gonna be successful speaking to people who may not be technical. I mean, I think you and I both know a number of CISOs who are great managers, but they may not necessarily be engineers, and that's totally fine, but you have to be able to communicate to them no matter what your background is. I completely agree. Um, so, Juancho, you would love for everyone to come and take the— take classes here. Oh, that's right, come to the Securiset Academy.

What is— what's some advice you could offer people who, um, you know, might be looking to increase their skills but can't come and, and take courses here? Definitely. And I mean, so a lot of our ethos as, as a, as a company is just trying to get people motivated, right? So we have a bunch of free guides that we give out to people that are not even our courseware. But if you want to get started and you are technical, right, one of the first things that I would do is find a CTF, find a capture the flag.

Go and just sit down and try and play. Ask questions. It, you know, there is a— I think there's a feeling that people in the security community are somewhat off-putting. And I've never felt that, especially in Colorado. This is probably one of the most collaborative and warm and open places I've ever lived, especially as a security practitioner.

And that's one thing that really differentiates the state from others. But there's a lot of CTFs. We run them at SecureSet, DEF CON 303, you know, DC719, a bunch of the other crews. I think OWASP does them. If you are not at as technical as that, but you really want to learn, join ISSA.

There's a great Denver chapter, Boulder chapter. Join ISACA if you have interest in compliance. If you're a student, they have really great and cheap rates that I availed myself of when I was a student. And you just ask questions, bug a buddy, you know. And I would really encourage people to focus on some of the primary issues too.

You know, download a, you know, an image for Ubuntu, get it going on a virtual machine, learn how to do some basic Linux administration. It is not as hard as people say. I'm not particularly good at it, and I will never hold myself out as somebody who is, but it's incredibly informative and will help you really understand the field. So you started talking about a little bit there, but I wanted to switch gears slightly towards Colorado and the Colorado security community. Yeah, you had a couple comments there, but, you know, what are some of the good things that you see about security and the security community in Colorado?

Yeah, in the— so I moved back— I moved out to originally Boulder in 2012, and it was interesting for me coming from DC, which is, you know, oftentimes seen as kind of a home for cybersecurity in the country. And I think that's an artifact of, you know, the DOD and the intelligence community being there. And that's something to be really proud of. But they do things very differently. You know, I've had friends who are staff officers or flag officers in the DOD who've never heard about Ansible, Puppet, Chef, Salt, any of the automation tools.

Like, they're totally foreign. And so one of the things that I first encountered when I came out here was that there's a great DevOps and dev community that also cares about security. That is integrated into it, that is not entirely separate. And normally they are, and that's really worrisome because people oftentimes find their way into security through being a developer. And if it's seen as they're 2 different and unrelated communities, it doesn't work.

And which is why when I moved out here, one of the first things that I did was I started engaging in the OWASP chapter, Open Web Application Security Project. And there's a great chapter in Boulder, and the people who run it are really thoughtful. And the guys down at Denver Tech Center are brilliant and hilarious, and they put on a great community, and they do awesome events and great conferences like SnowFROC. And I think the thing that, you know, comes out of that that I've seen almost everywhere else, whether it's BSides Denver, ISSA, the Denver Boulder Cybersecurity Meetup, which is one that we run through SecureSet, everybody is interested in helping you be successful. Successful.

There is almost no one, with rare exception, who is kind of a dick, you know. I mean, like, people are actually very cool here. It makes a very hard field very approachable. And I think if you just are honest and you ask questions and you're good to learn, no one will have a problem giving you some time and some advice. And, you know, Alex, I've gotten great advice from you.

Over probably the past 2 years, and from Robb Reck, which has been beyond appreciated. And it's not just limited there, right? Like, I know I can pick up the phone anytime and call 50 people and get some help. And with enough of that, you can solve any problem. I knew there was a good reason you're doing this interview.

I always like to have my butt kissed. So I appreciate that. It's true. Here, the money's on the table. There's a nightstand over there.

Well, Alex, I appreciate your time. This has been great. Any closing thoughts or anything you want to leave our listeners with? Yeah, I mean, one thing that I would, you know, try and make an effort around— there's so many brilliant people who work in this field, and I think that's partially because we tend to solve really hard problems and focus on really hard problems. And there's great researchers— Jacob Torrey, Don Bailey, A great number of them who work out here I have a lot of respect for.

Instead of focusing on trying to be cool and break stuff and hack stuff, try and do the other thing. Build something that is incredibly difficult to break. Get involved in research and contributing to projects in the community. And I think the last thing is like realize that as a practitioner, as a researcher, as a novice, you have a voice and there's also important policy policy issues that you should get involved in, whether that's with the Colorado Electronic Frontier Alliance or other organizations. But just dip your toe in the water and don't be afraid to show up to a meeting.

You know, we're, we're generally cool. Few of us bite. Most of us have beer. Awesome. That's great advice.

Thank you. Well, thanks for your time. This is the Colorado Equals Security podcast, and we'll talk to you next time. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes