All episodes

Sam Masiello

Apple Podcasts Spotify SoundCloud

In this episode:

Feature interview with TeleTech CISO Sam Masiello. News from Hosting.com, Optiv, Ping Identity, Red Canary, InteliSecure and more!

So it's the San Franciscan's fault my rent is so high?!

So far our listener survey feedback has been that folks want more of everything (news, job postings, events, and interviews). We'll try to keep you as plugged in with local news as we can, without increasing the length of the weekly shows. We had Alex back for this week's episode, and he didn't miss a beat.  

One week left for our listener survey! Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. We're continually working to improve the show, and appreciate the feedback we get from our listeners. If you discover any audio issues, or have suggestions for our format, let us know.

This week's episode is available on SoundcloudiTunes and the Google Play store. Reach out with any questions or comments to info@colorado-security.com

Feature interview:

Sam Masiello, CISO of TeleTech joined the podcast this week. He told Robb about his career path, including security leadership stops at MX Logic, Return Path, and Groupon. Sam shares how he got into security, what keeps him going, and gives some tips for those looking to break into the industry. Thanks to Sam for joining us.

Local security news:

Job Openings:

Upcoming Events:

This Week's Events:

Notable Upcoming Events:

View our events page for a full list of upcoming events

If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript14512 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood.

Welcome to the Colorado Equals Security March 27th newscast. This is episode 8, and this is Robb Reck. And this is Alex Wood. We're here to give you some news for this week. Alex, how have you been?

How was March Madness in Vegas? Complete and utter madness. You know, I've been going with friends for a number of years, and it's one of the biggest weekends of the year in Las Vegas, so there are a lot of people there. Did you make a bracket, or did you bet on games individually? How's that work?

A little bit of everything, you know. So we made some wagers, won a few, lost a few, and spent some time at the pool. It was all good stuff. Good time was had? Good time was had.

How's your bracket looking right now? Uh, it, it's not so great anymore, but that's all right. I think that's, you know, most people are in that position these days. Yeah, well, you know, we, we're halfway through the Elite Eight as we record, and, and Oregon won last night, which is— was exciting and fun for me, uh, as a— I went to school in Oregon, not at Oregon, but up there. I have some cousins who are big Kansas fans.

Okay, they were not as excited as you. Not as excited. It wasn't, it wasn't even all that close a game. All right, let's go ahead and get moving into the security news for the week. Um, first thing is not security related, right?

The first thing we found, this article that, uh, that gives some evidence that where your last name initial shows up in the, in the alphabet will kind of dictate how successful you are in life. I am so screwed. It, you know, myself as well, right? We're both, uh, second half of the alphabet people. But I think what it showed was, you know, per every 10 characters later in the, in the alphabet you are, you know, you have a— what was it, 10% worse performance?

Yeah. Yeah, I mean, it's just interesting how there are so many factors that are out there. I mean, you could apply this to security somehow, but there are many factors out there that are, are not obvious that affect, um, you know, performance and other things like that. Yeah, and I think that kind of the gist of it was it really came back to the teachers. It looked like teachers probably spend more attention as they're going through the list at the beginning, right?

And, you know, Mr. Albertson is a great performer and we think of him that way, but But Mr. Wood, yeah, I don't know, you know, let's not bother getting that far down. Yeah. And then one of the researchers whose last name was near the end of the alphabet, I'm sure the reason why he started this research, uh, it mentioned that, you know, he's a professor also and he does his attendance in a reverse order. So he always starts with the, the Z's and goes to the A's. There you go.

All right, well, uh, interesting stuff. And, and if you are late in the alphabet, you might want to bring your teachers a little bit of extra treats and, and bribe them some more to remember your kid fondly. Exactly. Uh, second on the list, we have a story, um, again, not directly security related, but I think it's, uh, pretty important for the job market, um, that Denver, you know, is luring workers away from, from San Francisco, you know, along with a couple other cities. But, you know, Denver was in the top 4 in terms of bringing those jobs here.

Yeah, it's interesting, you know, as San Francisco becomes more expensive, housing prices are too high, it just costs too much to hire talent in San Francisco, there's a few different cities that are really benefiting from that. And, you know, Portland, Seattle, Austin, and Denver, those are the top 4 that are taking those jobs away from Denver. Yeah, and I mean, I benefited directly from this. Um, you know, my previous job at Kaiser Permanente, you know, they decided to diversify. They're based in Oakland and, uh, you know, started building out campuses here and other places where they have service, but, you know, not in the central area in Oakland because it's frankly just cheaper.

And then, you know, get more talent that's, uh, that's not in the Bay Area. Yeah, and another big one is Charles Schwab. They've built that huge office down in Lone Tree. Google's building offices out here, Microsoft as well. There's lots of folks who are, who are bringing jobs to Denver because they can find people here and where they can't out in San Francisco.

Interesting stuff. Another industry-related one here in Denver, uh, Tamara Chuang wrote this article for Denver Post, uh, cybersecurity industry hopes women will fill at least part of those 1.8 million open jobs. Yeah, so the, the CCDC competition that we had mentioned, um, in prior weeks, it finished up a couple weeks back. And the winning team was more diverse than the other team. So it was, you know, I think equal men and women.

And, you know, one of the ideas here is that, hey, diversity helps. You know, you can be more successful when you have diversity of your team members. Yeah, this is a trend that, or it's a realization that's starting to become much more understood, right? That yes, it's obvious in some competitions, but it, you know, in workplaces as well, as we get more diversity of thought, people get better at it. And women just generally are way underrepresented in security.

Teams. Yeah, and, you know, as part of that, the ISSA is starting a Women in Security special interest group, and there's an event listed on our events page talking about that first meeting, which is coming up, I believe, near the end of April. April 19th. It's at SecureSet, and it's sponsored by LogRhythm and SecureSet. So reach out.

It's just unbelievable registration numbers on that, you know, up at about 80 people have signed up already for it, and we're still almost a month away. Awesome. Uh, next, some more local news. Hosting.com, which is, uh, Denver's, Denver's own hosting provider there on I-25 in the old Gates building, they just made an acquisition of a company out east called Stelligent Systems. Yeah, and there seems like a consulting arm to help them with the, the Amazon Web Services business that hosting is delving into.

Uh, one of the specialties of Stelligent is, uh, is security services around Amazon Web Services. So I think that's an interesting play for them. Yeah, you know, I, I'm a little unsure, and I'd love to talk to someone over at hosting to understand. Generally, I think of hosting.com as being the hosting provider. You know, you use them for either Rackspace or, you know, managed services and cloud.

I'm not sure all of their offerings, but I think of them as the provider, whereas this acquisition looks like maybe they're moving more into consulting around going, you know, hosting within Amazon, which is really a different business model. Yeah, well, and I think, uh, you know, they're obviously not the biggest player in the world, um, so they're not going to win all the business. And, you know, you may as well have some way to play in, you know, other people's ponds too if you can't get them in yours. Yeah, I wonder if this is, you know, an indication of where they might be going longer term and moving away from trying to compete with Amazon on a commoditized, you know, cloud computing where Amazon just has 70% of the market, right? And maybe they're trying to move into the more specialized, higher, higher margin competition on consulting and, and implementations.

Yeah. Additionally, we have some news around hosting.com. Uh, Johan Hebinette, is that right? Do you know how to pronounce his last name? Yeah.

Yeah. Well, hey, good job. I did that. Um, the CISO for hosting.com has announced that he's leaving. He's, uh, going to be actually moving out of state to be the, the CISO for Vonage.

Yeah, and Johan's been a friend here in town for a while. Previous to hosting, he was at Scriber Medical, uh, and man, previous to that he was in it— I'm slipping my mind right now, but he's been around in Denver as a security leader for quite a while. Yeah, and I actually, I talked to him a little bit and he was— I don't want to say disappointed, but he definitely is, um, you know, thinks of Colorado as his home now. So it was a hard decision for him to have to take a job where he was moving out of state. Yeah, we'll definitely miss him and look forward to hearing how it goes.

But, you know, Vonage is going to be a fantastic opportunity for him and you know, I'm confident that Johan's going to really do a great job there. Uh, next, uh, Optiv Security, um, trying to take over the world. I think they, uh, they purchased a company, uh, on the East Coast called Comm Solutions. You know, it's a similar type company of VAR, um, but they— I think Optiv didn't have a whole lot of, uh, of presence, you know, feet on the ground kind of presence in that area, so they wanted to beef up uh, their presence out east. It was Pennsylvania, right?

I think so. You know, really, the VAR business is a relationship business, right? You can't open up a shingle, you know, nationwide and say, hey, we're everywhere. It just doesn't work that way. You have to have people, you know, feet on the ground with relationships in these companies, people who've known, taken them out to lunch, and, you know, understand the buyers in that area.

And that's really what Optiv is buying here. Those relationships. Exactly. And I think it helps both sides because it sounded like, um, like Comm Solutions didn't have sort of the breadth of services that, that Optiv does. You know, they— Optiv does offer, you know, managed security services and other things like that.

So it, it helps the, the folks out there get more services, and it helps Optiv get, uh, feet on the ground in those areas. Yeah, so congratulations to Optiv. Hopefully that's a good move for them. So Ping Identity, uh, you know, I'm, I'm the CISO over at Ping. We, we just released some news this week Ping has integrated with Microsoft, and at this point, you know, there's a public preview, which is one of the steps along the way toward releasing this service.

And I don't know which step it is, but very soon we're going to have a publicly available service where you can, you can use Ping Access, Ping's solutions, to get single sign-on into Microsoft's Azure AD environment. So, you know, summary, right now as it stands, if you use Azure AD for single sign-on, you could really only get single sign-on into cloud-based applications. With this new solution, you'll have the ability to use Ping to, to get connected right back into your, your corporate environment in those, those legacy on-prem applications that, that don't automatically work with the cloud. You'll be able to get single sign-in into all of that. Sounds like a good deal to me.

Yeah, so, so good stuff. There'll be more news on that coming up, but I thought we'd share where that's going. So, uh, Red Canary, uh, another local company here, they put out a blog post this week, uh, entitled Threat Hunting Is Not a Magical Unicorn. Yeah, so I, I put this in the— as for us to talk about because it's just something that's really interesting to me. If, if you're not real familiar with threat hunting, this is a good primer on it.

You know, what is threat hunting? What is it not? You know, you can't go buy a threat hunting tool because that, you know, what— as soon as you buy the tool to do it, it's no longer threat hunting. Basic idea is You have all your protective controls, you have your detective controls, and then threat hunting is going around those controls and saying, well, what did we miss? What's likely in our environment to be a target of bad guys?

Let's go look at that and see manually, eyes on glass, what's going on with those systems. Yeah, I sort of like to think of it as proactive detection. You know, most detective tools are somewhat passive. They're waiting to see something. You know, with threat hunting, you know, likely going to have a team of specialized people that's going to go around and look to try and find things that you might have missed.

You know, I personally think there's, there's a lot of different values of threat hunting. Obviously, you know, what we're trying to accomplish is finding if there's something wrong in the environment. But I think, you know, just as important, it's the familiarity you get with your environment by doing threat hunting that adds value. So when my security analysts are looking at those high-value systems, trying to understand what's normal, is this normal, they're now learning more about how the system works. And if there is an incident later, you know, they have a better idea what it used to look like and what normal was.

Yeah. And I think also, you know, one of the important pieces is, you know, threat hunting is not necessarily for everybody. You know, it's not going to be low down on the maturity curve. You know, you have to have other things in place before you can really get to the point where you can have specialized people that can go and look for this stuff. Not that you shouldn't be looking around in your environment to try and find bad things, but really having a defined threat hunting team and process, yeah, uh, it's not something that you're going to implement right away.

Yeah, I'll tell you my approach to this. You know, the vast majority of people who are listening to us here don't have a mature enough team to have a dedicated threat hunting function. How I, how I deal with it at Ping is we, we give the team a very small set of time to go look into threat hunting each month. Um, so So, you know, let's say for the infrastructure security guys, they have 4 hours per month, 1 hour a week. And maybe for our product or application security guys, they only get 2 hours per month.

And they're given, here's a specific threat we want you to go think through. You know, what would happen if someone compromised our CA here? Or what would happen if, you know, think about what are the high-impact threats? And then give them a few hours a month to go figure that out, right? What would they need to know?

What would they do? If they come back at the end of that and say, hey, I got this far and I had to stop because, logging wasn't turned on here, or we didn't have the right kind of visibility that we need in this area. Well, that's a great outcome, right? Because, because we realized a way for us to get better at this detection going forward is to enable those things. So I really like to timebox it, not say, hey, go run this threat down forever.

Just use a, use a couple hours to do it. You know, it's instead of your normal project work, and it's something that gives us value, you know, beyond just finding the bad guys. Yeah, I think that's a great way to tackle it. Rob. Uh, so next thing on the list, uh, came across a national or an ISSA international, uh, virtual session that you're going to be on coming up this week, right?

Yeah, so this is— it's an RSA conference virtual session, um, through ISSA. So it's, uh, I was on a panel at RSA this year, um, a CISO talk, and this is sort of a redo of that. Um, you know, we had very short time window, and so, you know, RSA has these virtual sessions throughout the year where they take people that spoke at the conference and either redo or continue the talks that they had. I'm going to be talking about just some general questions about my day-to-day job and how I got where I am, along with Garrett Felix, who's another CISO, and Pam Fusco, who's not only the CFO for ISSA International but also has been in security a long time. She's sort of our moderator.

Um, so that's, uh, on the 29th at noon, uh, Mountain Time. The— and the link to register is in the show notes for this. So if you're interested in getting on there, go get signed up. Yeah, and we'll be not only talking but also taking questions from the audience and things like that. So the last thing for our, our news segment here is something that's not necessarily news, but, you know, maybe news to us, right?

Uh, one of, one of our, our friends Matt Shufeldt sent me a note the other day and said, hey, did you see that InteliSecure had some turnover of their leadership? And, and I looked into it and lo and behold, they did. So founders Rob Eggebrecht, who I actually did an interview with for my blog maybe 2 years ago, if you guys want to look it up, you can, you can find it somewhere out there. He and co-founder Chuck Blomquist left InteliSecure, it looks like sometime mid-last year, and they've been replaced with a couple of new folks. Stephen Drew is the new CEO and Uh, who came from SecureWorks, Dell SecureWorks, previous to going to InteliSecure.

So I, I found this whole thing very interesting. You know, InteliSecure is one of the, you know, decent— they're pretty good-sized Colorado security company. They do managed security services, they do professional services. I actually have talked to them about some ISO compliance work in the past. Um, it looks like they have new leadership.

Yeah, I found it interesting too, just because it was sort of a, uh, you know, a quiet change. Yeah, it wasn't a a big fanfare. It wasn't, uh, you know, big announcements, you know, all of a sudden we've got a new, new leader over there. Yeah, so hopefully we can reach out to the new, uh, to the new leadership there at InteliSecure, uh, understand where they're going. Maybe they— if they had any strategic changes in terms of the roadmap for the company, love to know that.

Uh, if you guys, you know, I know that they do penetration testing, they do managed services, they do implementation services, that they're, they're basically, you know, in the world they're maybe the best DLP consultants consultancy out there, and they do manage DLP. They've kind of moved into other things like SIEM and compliance work as well, and I'm sure that they're quite good at those. But I know that if you're looking for a DLP project, they're, they're one of the folks to talk to for sure. All right, so upcoming events. We have 3 events this week that we'll, we'll hit on here.

Uh, on the 30th, uh, Colorado Springs ISSA has their 4th annual Cyber Focus Day, which is a full-day security conference. You know, good, good CPEs, good opportunity to learn and network with some folks in the spring. So if you're able to make it down there, highly recommend it. On the 31st, SecureSet at 5 o'clock, they have a beginner's intro to capture the flag, and that is followed by a capture the flag hackathon at 6 o'clock. So if you're interested in doing some capture the flag work, yeah, testing your skills, that should be a good time.

It's cool. You can come an hour early and get the, you know, the baseline. So when the actual thing starts, you're ready to go, or just show up at 6 o'clock if you feel like you already know how it works. And then next Saturday, we've talked about this a couple times, but ISSA Colorado Springs has their Security+ boot camp prep seminar, full-day event on Saturday. It's, it's the first of 2 sessions that, you know, kind of get you prepared to go through the Security+ exam.

Yeah, so yeah, 2 weekends in a row for that, that training session. And then they also have a redo of that in June if you can't make it to the April ones. Yeah, so highly recommend taking a look at that if you can. Uh, some events coming out, you know, a little further in the, in the distance: RMISC. We're not going to miss a week talking about this event.

Um, I did just last week sit down with one of our keynotes, Cal Fussman, and record an interview that we'll be releasing through this stream sometime soon. Not, not this week, but sometime soon we'll be releasing that so you can learn more about Cal. Kind of the, the action items for you guys: go get registered if you're not signed up yet. All of the agenda is set. You can go get your sessions confirmed and get signed up for that.

And of course, if you have any leads for sponsorship, always looking for sponsors. Sponsorship is how the conference is kept cheap and how both Denver ISSA and Denver ISACA are able to fund their events throughout the year. And if you do work for a security services or product company and you're not sponsoring yet, then what's wrong with you? Yeah, you should get with your appropriate marketing or sales folks and get them to sponsor the conference. Yeah, this is just, you know, Denver, it is the biggest conference in Denver.

And if you're a Denver-based company, get on that. Uh, you know, speaking of that, Denver BSides is the, uh, kind of the alternate conference that happens right after RMISC, and I know they're, they're also looking for, um, for sponsors for that event as well. How about, um, volunteers for BSides? Are they still looking for people to help there? You know, I, I don't know.

They— I know they usually do pretty well getting, getting volunteers, um, but we'll take a look, and next week we'll be able to get more info on that. Sounds good. On to jobs. So, uh, first job we have, Air Methods. Uh, they're looking for a director of IT security and compliance.

So Air Methods, you can save someone's life, right? That's the Flight for Life type folks. Exactly. So that, that could be a cool industry to be in. Yeah, I know some folks who've worked there.

They, you know, they have a relatively complex IT infrastructure. It'd be an opportunity to come do some important work. And helicopters. There you go. Webroot is hiring a product manager of web and network security products.

This sounds like a fun, you know, a fun job, basically helping them figure out where should their product line go and being the voice of the market back into the, into the company. Yeah, if you're someone with experience, uh, that is definitely a cool looking position. Yeah. Uh, next, Lewis and Fowler, they're looking for a senior consultant/GRC program manager. Uh, Lewis and Fowler, they're a I think mostly a product project management consultancy.

Okay. But, but you're— if you're into GRC and it looks like they're looking for someone to consult around GRC and, you know, help lead their program around GRC consulting. Are they Denver-based? Lewis Butler? Oh, interesting.

Do you know anyone over there? I don't know if I know anyone still, but I know some people that used to be there. Interesting. Yeah, interested to know more about those guys. Akamai is hiring.

So Akamai is, you know, one of the big internet security companies and Headquartered in Boston. Don't quote me on that. I think they're in Boston though. Northeast somewhere. There, there looks like they're hiring a security solutions architect here in Denver.

That's kind of cool. That is really cool. Yeah, I don't know if they're expanding here or if it's just by coincidence. Yeah, so very interesting. If you know, if you have, if you know anything about it, I'd love to understand more about what they're doing.

And if you're interested, you know, take a look and hopefully it'll work out for you. Pearson is looking for a security architect. We've talked about several Pearson jobs in the past few weeks. Yeah, Pearson's also, they were also hiring that director of security, I believe. And I know one of our, one of our mutual friends is talking to them there and has said some really good things about the opportunity and the, the, the company.

And it sounds like it'll be a pretty fun thing to do. Cool. Nelnet. So, so Vince Grimard is one of the CISOs here in town. He's the CISO for Nelnet, and he's hiring a security analyst.

I assume, I believe that this would be out of their Highlands Ranch location, which is like at Lucent and 470. Um, anyway, Vince is a, a good guy who's, who's really built that program up from nothing into a, a fairly robust and mature program. Yeah, I think he'd be a really good guy to work for. Uh, next, uh, HP Enterprise, they're looking for an ArcSight consultant. So if you're someone that, um, is in the SIEM space or has experience with ArcSight, uh, likes to travel and help people with ArcSight implementations, I think this would be the, the position for you.

As long as ArcSight exists ArcSight consultants will always do very well. Yes, exactly. For those who don't know, ArcSight is, is one seriously complex technology, and if you don't have, you know, 1.5 to 2 FTEs on hand to manage your implementation, you're gonna, you're gonna need consultants on a regular basis. Webroot, uh, once again another job from Webroot. They're, they're hiring a Mac threat research analyst.

I assume this is Macintosh. Yes. Yeah. So that looked interesting. If you're someone that, uh, likes doing research and has a Mac specialty, sounds like they would have a place for you.

I bet Dave DeFore knows about this role. This is, this is kind of in his area. Yes, I bet. It sounds like it's got Dave written all over it. Yeah, Dave is, Dave is one of our friends and one of the really smart guys over at Webroot who does their research and kind of keeps pushing them towards the more cutting-edge stuff.

Um, that he'd be a good guy to work with as well. Speaking of Dave, I noticed that he is now going to be a contributor to the CyberWire podcast. So he was speaking on that in the last week. I heard him in the last week as well. Yeah.

Uh, next, uh, CyberGRX, they are hiring— uh, they actually had multiple positions, but for, uh, for security assessors for third-party assessments. So CyberGRX is a company here in town. Um, so it's, uh, the GRX stands for, uh, Global Risk Exchange No, Global Risk Exchange, something like that. So it's— they're trying to be the central location for third-party assessments. So part of what they do is they have to assess these companies to be the, the central place for that, and they're looking to build out the team to do those assessments.

Yeah, you know, we should, we should reach out to those guys and see about getting on the podcast. You know, they're headquartered downtown Denver. I don't know— I, you know, I know vaguely what they do, but it'd be nice to know more about them. And then, uh, last on the list The town of Castle Rock is looking to hire an information security specialist. Um, I thought this was sort of an interesting role.

It's listed as information security specialist, but this is really someone that they want to, to, I think, build and run the security program down there. Um, it's probably being hired at that level because it's, you know, it's a town, it's not a big corporation that's doing it. But if you want to sort of get in on the ground floor and, and, uh, and try and help build out a security program I think this could be a cool opportunity. You know, for those who, who have been kind of stuck in individual contributor role who are looking to get into leadership, this is really a good opportunity. You go into a place that, that needs security, that doesn't have anyone to set direction.

You go do that for, I don't know, 2 years, look for either a promotion there, or you now have the experience on your resume to go get that manager-level role at some other organization. I, you know, one caveat though is that it probably won't be easy, um, you know, for better or for worse. Um, you know, jobs like that, you're probably going to be underfunded and understaffed. Um, but, you know, if you're someone that, that likes to put in hard work, it will likely be something that will be rewarding for you. Yeah, good stuff.

Well, um, that's the end of our news for this week. A couple things to mention. Number one, go sign up on our mailing list if you're interested in getting weekly emails from us kind of with the show notes into your inbox. Uh, we also have had our listener survey going for a week. We've got, we got a good number of responses on that.

If you're interested in getting added to that, you know, send it, get signed up on the mailing list, we'll get you added to the survey. Um, we're planning to keep the survey going, you know, although we won't keep emailing people about it going forward. Yeah, one other thing, I don't know if you mentioned it last week, Rob, but we added, um, a couple RSS links on the, the website. So if you want to get updates in your RSS reader for For our news and blog posts and events as well, you can go find those links on the website, colorado-security.com. All right.

Well, thanks everyone for your time, and we'll look forward to talking to you next week. Thanks, Rob.

This is Aaron Simmons, CISO of Gates Corporation. Welcome to Colorado Equals Security for Colorado Security Professionals by Colorado Security Professionals.

All right, this is Robb Reck here with Sam Masiello. Sam is in my, in my basement in the studio, uh, the lovely, uh, furnished studio. Sam, why don't you go ahead and introduce yourself and tell the listeners who you are? Sure. So, uh, hi everybody, I'm Sam Masiello.

I'm the Chief Information Security Officer at TeleTech. I've been there for about 2 years now. A little background on myself, I guess. So I, I'm one of those fairly unique people, I guess, somewhat unique in that I've always known that I wanted to be in security. A lot of people kind of stumble into it along the way or they're doing some job and then suddenly they end up doing security off the side of their desk and they realize they kind of like it.

I've actually always known that I wanted to be in security. I started running my first messaging system when I was 13 years old and started to get into it and realized some of the abuse that was happening from there and got really into network security and got a real interest in network security when I was 15, 16 years old. So were you running a bulletin board at that point? Yeah, yeah, yeah. Phone lines coming into your room, or— I did, absolutely.

It was a lot of fun. I loved it. I met some really cool people. In fact, uh, came to find out that a person that I used to know back then, uh, knows a friend of mine that I have known since high school as well, and we just happened to get connected through Facebook the other day because in fact she— I commented on something that, um, my friend had posted about her kid being sick for the past couple of weeks and this other girl responds to me and says, hey, by the way, your name and your face look really familiar. And so we start going back and forth trying to figure out how we know each other and just happen to be from our bulletin board days.

That's awesome. Yeah. Did you have a handle at that point? I did. What was your handle?

Looney. How do you spell it? L-O-O-N-E-Y. All right, except a little crazy. Still loony.

Well, I can see that. You have to be a little loony to be in InfoSec too, right? So I've known Sam for a couple years. Yeah, he's a little, he's a little loony. He's not, he's not loony.

Uh, so you ran, you ran a bulletin board for a while and that got you into network security, you said? I did. How'd that transition happen? So, uh, I just realized that network security was what interested me. You know, I, I realized that it was something that I wanted to learn more about.

Yeah. Uh, you know, networks obviously were very different then, 20x years ago, than they are today. But, um, you know, but still, it was something that was, that was clearly an interest to me. And as I started to kind of finish out my, my high school days and get into college, where I majored in computer science, uh, you know, I realized more and more that it was, it was a career that I wanted to to pursue. And it's something that, as I've went from role to role throughout my career, even though I've been in various different types of roles between software development, project management, security roles, you know, I've always, I've always had a mind's eye towards security during those, during those roles as well.

So I've always been kind of working towards, right, the roles I've been in today. So where'd you go to college? So I started my college at the University of Colorado at Boulder and then finished at the University of New York at Buffalo. Oh, that's, that's a move. It is.

But you're a buffalo either way. I am. That's right. Sort of. No, it's true.

I can't seem to get away from it. In fact, funny enough, so when my wife and I moved to Colorado— I'm moving back to Colorado and my wife moving out here. Did you meet your wife in college then? Um, in New York, yes. Okay.

So we moved to Colorado. Uh, we ended up moving to— or the first development that we bought our house in was called Buffalo Run. So it just seemed like everything we had, every place we, we lived, or everything I did just seemed to revolve around buffalo. It's your spirit animal. I guess so.

It might be. All right. So you went to college, you got your CS degree. What happened after that? So after that, gee, I was— so when I was in college, I was going to school full-time while I was working full-time.

So it was a bit of a stretch just because, you know, I was on my own when I— That's a lot of full-times. It was. Yeah. When I moved to New York, you know, I had to establish my residency there, so I worked full-time for a year or so. Funny enough, I've kind of come full circle in my career because I started off in a call center company.

In New York doing tech support for Sony personal computers. And then kind of worked my way up there in that company and then kind of kept going from there. But, um, that was my first tech job. I did tech support for Electronic Arts video games. That's much more fun.

No, no, it's not. It sounds much more fun. It's people calling and saying that they, you know, the cursor keeps scrolling around my screen. And well, that's a sound card driver issue because your joystick is plugged into your sound card. Anyway, that's a lot of technical information for you.

Yeah, yeah. Well, it doesn't sound like we had much different experiences then, because we have people breaking their computers in all various ways and then calling us for support on how to fix them. And you walk them through it. All right, so you were working full-time and you were going to school full-time. Yep, working full-time, going to school full-time.

So it made for some very long days. Sometimes I wonder how my wife, then girlfriend, stuck with me through all that, because it was, like I said, pretty long days getting up at 5 o'clock in the morning, typically at work by 6. Would work till 10 o'clock or so, go to school, come back to work around 3, work till 7, do homework, and then do it all again the next day. Yeah, you know, so it didn't leave a whole lot of time for social life, girlfriend, you know. So it was— but it made it through, right?

It was, it was about, uh, when I, when I went to school in New York, I had about 2 and a half years or so left. I did my first couple years in CU and then finished up in Buffalo, and, um, very different curriculums too, because, you know, the engineering curriculum at CU was very engineering-focused. It was all focused on computer science classes. So by the time I went to Buffalo, theirs— their program was a little bit different in that theirs was, um, I don't know what you'd call it. Not— I'll just say not as engineering-focused, right?

So yeah, so by the time I went to Buffalo, even though I'd only been at CU for 2 and a half years, I'd almost finished all the CU— all the computer science courses, but I had none of the humanities courses, none of the history, none of that. So I spent most of my time at Buffalo actually going through Getting the G, generalized stuff. Yeah, getting the generalized stuff done and then having to retake a class or 2 in computer science because you have to take a certain number of classes in that program in order to qualify to graduate in that program. Yeah, that makes sense. So, uh, while I was there, worked at the call center company.

Uh, back then it was called Client— actually, no, back then it was called SoftBank Services Group, then it became ClientLogic, and today is known as Cytel. Still around, huh? It's still around. Yeah, absolutely. It's a pretty strong competitor to Teletech as well.

So I still hear their name every now and again, which is kind of fun, right, to hear the— Insider knowledge. Yeah, from 20 years ago, right? Not so insider anymore. Then from there, moved on to a couple other roles where I did some more software development and ended up at a company called CineCore, which back then was called Check.com. So that was an affinity email-based company where we thought we were going to make our millions based off of ad impressions and ad clicks and things like that.

Uh, the premise of it basically was, so let's say for example you wanted a budweiser.com email address. So you'd go to budweiser.com, you could be robreck@budweiser.com, and that was all powered by our, our email engine, our, our, uh, our engine on the back end. And so the way we made money off the program was as part of your sign-up process, you would define some of your interests and things like that, you know, way, way before some of the, the tracking, you know, that they have today. Yeah, where they have, uh, you know, they know everything you do and everywhere you go, right? You pretty much had to tell people what you're interested in.

And so we delivered ads, um, where ad networks would subscribe to us, or ad deliverers would subscribe to us, and we would deliver ads based off of the interests of the various users of the platform. Yeah. And then, um, what were you doing there? So I did software development there to start, and then I did project management for a while as well. So as we started to evolve the company, as we realized that, um, we were not going to make our millions doing ad impressions and ad clicks and ad revenue the company started to change to work more towards businesses, work more towards telco providers, ISPs.

And so a lot of the work we started to do with them was more around premium, premium content development, premium content integration into web portals. And so let's say you were a Comcast customer and you went to comcast.net, you got this personalized portal page which is all driven by, by our technology, and we had a number of premium integrations in that page as well. So let's say you wanted MLB.tv, or you wanted a whole bunch of different movie streaming slash sports packages, right? So if you were to buy those individually, you'd probably spend $40 a month on buying those packages individually if you want to stream that content online. If you bought it through your ISP, maybe you'd get it added to your bill for $10, $12 a month.

And so again, that was all driven by our technology on the back end. So I was— once I more or less stopped doing software development there, I was doing more project management at kind of managing the integrations of those premium features into our platform. So based on my technology background, kind of got some business background there as well, you know, I was able to manage the whole process from, from end to end. Okay. So, uh, after there, uh, is where I got mixed up with MX Logic.

So this was, uh, so this was, this was in Buffalo. Then when I moved to Colorado after my wife and I got married— what brought you to Colorado? Uh, I wanted to come back to Colorado, and, you know, eventually was able to convince my wife to let you— to come out here as well. We come out here a couple times and she loved it. Um, you know, one of the, the big drivers for her back there was that she— her whole family was there, right?

Her whole family grew up literally within about a 3 to 5 mile radius of where she lived. You know, her mom, her sister lived there, her aunts, her uncles, her cousins, her grandparents— they all lived within this, this literally 5 mile radius. And so when we first met, she kept saying, no, I'm not going to leave this area, I love this area. And, you know, that was, that was pretty much it. And then over time as we were dating, because we dated for 7 and a half years.

Yeah, because we met when she was still in high school. I was just in college and she was still in high school. So we, uh, we dated for quite some time before we got married. And, um, over time, her cousins moved away, her aunt and uncle moved away, her grandparents moved away. And so, you know, all the reasons that she had for really wanting to stay there were leaving.

Uh, and so we came to the agreement that if one of us were able to get a job out here before we got married, then we would move. After we got married. So long story short, Blizzard of 2003, right, comes along. We got married in 2003. And so this teacher fair that we were going to come out here for, because my wife was, uh, was in college to become a teacher— this teacher fair was— teacher job fair was out here, uh, literally about a week or so after that, that blizzard happened.

And so my wife's trying to set up interviews. It was March, right, if I remember correctly? March 17th-ish, maybe? Something about— something around there. Somewhere in the St. Patrick's Day-ish.

Yep. Yeah. So my wife was trying to call these schools and set up interviews before the job fair so that she, you know, when she got there, it wasn't just like, you know, hand out resumes, try to get interviews, try to line stuff up as much as she could beforehand. And nobody was answering the phone, nobody was calling her back. She's getting frustrated, she's getting confused.

I said, you do realize that they just had like 3 feet of snow out there, right? So, uh, thankfully was able to get some interviews set up, had a really successful couple days at the job fair. And, you know, with the teaching profession, right, you typically know whether you're going to be teaching that next school year pretty far in advance. Where the technology field, you know, you leave a job one day and you're, you know, you're employed again the next week. So if anybody was going to find a job in advance, it was going to have to be her.

Yeah. And so she ended up getting a teaching position. And so we got married and then went on our honeymoon, and then we're in our apartment for about 2 days after we got back from the honeymoon, and then we were in the car driving to Colorado. All right. And then about a week later, she was, uh, in the classroom, you know, getting the classroom set up for the school year.

So it all, it all moved pretty fast. So you came out to— how did getting the job at MX Logic work out? It was great. Yeah, I was there for— but how did you get— I mean, did you get it before you came? Did you— no, no.

So I, I consulted with the company that I was with, Cinecore, in Buffalo for about 4 months or so. Sure. And, uh, got to the point where at that stage in my career, I just couldn't work from home anymore. I mean, I have the mentality for it, I have the work ethic for it, and I think that takes a certain type of work ethic and mentality to be able to do that successfully, just in a small apartment, I just couldn't. No matter what I did, I was always there, right?

There was no— I had a room that was my office, but it still was close enough to everything else where even if I would go out for lunch or work from outside for a little while, it just still felt like I was always right back in there. And I just, after about 4 months or so, I decided I couldn't do it anymore. So started looking for a new job and found the position at MX Logic. Doing a lot of the same stuff I was doing at CineCore, really. So it was a pretty natural transition from one to the other.

Uh, started there in December of 2003 and, uh, kind of worked my way up the chain there as well, you know, starting as a software developer, managed their QA group for a while, and then moved on to run their threat center and, and basically provide the, you know, the strategy and direction for their, their filtering product. Yeah. So, um, I sat with Scott, Scott Chasin, uh, Who was, who was the founder and president of MX Logic? Is that right? Co-founder and CTO.

Okay, excuse me. He's the founder and president of ProtectWise now. So I sat with him and actually his interview on the podcast is going to be the week after yours. So yours is now and his is a week from today. That's great.

And he said some really nice things about you. You can listen next week and you'll hear about it. But very cool. Small. It's a small world for sure.

It certainly is, especially in the security space, right? You never know who you're going to run into. Yeah. In fact, so speaking of small world, so, uh, I always kind of find it funny when, when worlds collide, right? So I told the story a little bit earlier about, uh, you know, the friend I got hooked up with from, uh, my old BBS days, right?

Just happened to connect through a friend of mine on Facebook recently. So when I was in New York in the call center, there was a guy that I sat next to who we got along pretty well. You know, we were doing, uh, doing tech support for Sony PCs. And so I don't know at what point he moved to Colorado. I don't know if it was shortly after I did or, or what, but Uh, came to find out at some point a couple years ago, or a few years ago now, that he had moved to Colorado as well and, um, knew a girl that I went to high school with, and they just happened to work at the same company for a while.

So again, kind of, kind of same, same type, type of, uh, excuse me, type of collision there where I'm connected with a friend of mine from high school on Facebook, connected with him as well, and just happened to see that him comment on something that she had posted, or she commented something he posted. And I look at it and going, wait a minute, how do you two know each other? And so, uh, so Facebook is not just for cat pictures. It also— it's not just for cat pictures, no. It's, it's really interesting when some of those worlds collide like that.

But, um, so how long were you at MX Logic? So I was there for— if you include the McAfee acquisition and then the Intel acquisition as well, it all kind of happened pretty suddenly in pretty rapid succession. So I was there from December of 2003 until Jeez, uh, 2009, '10. That's pretty good. 2010.

Almost 7— well, 6, 7 years. Yes, it was end of 2010 because I started, um, at Return Path in February of 2011. Yeah. Well, so what, what caused you to leave, uh, Intel at the time? So one of my concerns was, you know, when, when Intel came in to buy McAfee Uh, you know, I was running the, the email program at the time there, and one of the things that kind of concerned me was, you know, Intel bought McAfee largely for its antivirus engine, because the, the intention at the time was to build that whole DeepSafe platform, DeepScan DeepSafe platform that they ended up building, which was primarily to address threats moving outside the operating system and more into the silicon, right?

That was the primary reason, at least my understanding, why Intel— that's why, why a hardware company might want a software security company. Exactly, or an AV company, right, at its core, most specifically. And so one of the things that concerned me was, all right, so Mac— or Intel paid $7+ billion for this company, right? It's gonna— it's good. There's gonna be a point sometime, probably relatively soon, where it looks at why it bought the company and realizes the things that it bought it for versus the things that it didn't buy it for.

Sure. And so as I looked at the email program, I thought, well, is this really going to be a long-term strategy for Intel? And so I thought, well, it's probably best that I start proactively, uh, moving on before, you know, before I'm forced to do so. And surprisingly, you know, much to my surprise anyway, you know, Intel didn't really spin it off for another 5 years after that. So it took a lot longer than I thought it was going to to actually have it finally happen.

But yeah, it did. It just took longer than I thought. But, um, that was a big part of the reason why I originally started to, to look. And I was— I'd known the people at Returnpath for quite some time, you know, being in the email space for, for so long, I get to know quite a few people in that space. And so I knew a lot of the folks over at Return Path, their president, COO, a lot of the folks over there that, um, you know, that were employed there.

So I— so it was a fairly natural and easy transition for me to, to go over there. I joined them as their chief security officer as well as their general manager of an anti-phishing product that we were about to bring to market. So ended up bringing to market, uh, their— what they called Domain Assurance at the time, which, uh, it changed names a couple times over course of the product's lifetime, but it was called Domain Assurance, and it was primarily focused around email authentication and anti-phishing. So how can you use technologies like DMARC, for example, to be able to use email authentication to be able to just— or to be able to set policy such that emails that are coming from your organization, you know, can either be potentially accepted or rejected based off of its email authentication status. Assurance level, right?

Assurance level, yeah, exactly. So brought that product to market. Uh, was at Returnpath for a little under 2 years or so. Uh, pretty proud of the fact that the, the product that I brought to market was actually sold to Proofpoint not too long ago for Returnpath. So that was, uh, that was kind of neat to be able to, you know, talk about now that, you know, the product that you brought to market a few years ago has evolved obviously since, uh, since I brought it to market initially.

But yeah, pretty, pretty neat to see that there's enough value there that someone wants to buy that. Exactly, exactly. And it validates the market too, right? Because, you know, it's It's a space where, you know, at the time that it was brought to market, you know, we talked a lot about phishing, we talked a lot about anti-phishing, and there was a lot of the feeling out there that, well, phishing is a financial services problem, right? Why should I care, right?

And I think that tune has really changed today. Been disproven. Yeah, absolutely. When you think about not only the amount of phishing that happens, but the amount of damage it's been causing— BEC scams, W-2 scams, like all the types of email fraud you see now— there's technology there that exists that can help you fight that problem. That has existed for, geez, 6, 7 years or so now that, you know, people are now finally, you know, becoming aware of.

And the fact that there is— and that there is an actual solution to that problem. There was a— one of the news articles we covered a month or so ago was about— I think, I think it was Webroot's annual report said that somewhere in the ballpark of 7 to 1, there are more phishing emails trying to capture your, your technology accounts versus your financial accounts. So they're trying to get your Facebook or your Gmail or your Yahoo accounts. And those are, those are what the bad guys are going after instead of your Bank of America login. And the big reason for that, I think, is that, you know, you have your consumer accounts, right?

You have your business account. Your business account, your, your work login, for lack of a better term, right? I'm going to assume typically has password rotation policies, password complexity policies, such that if you have your password for 90 days, it forces you to change it on the various systems. Yeah, that's right. Where on a lot of your consumer accounts, whether it's your Gmail account, your online banking account, they're not necessarily forcing you to change that password every so often.

And so if you have your password at Gmail, you probably have that same password for a multitude of other accounts as well. So if they can get a hold of your Gmail account, they probably have access to at least the kingdom, at least 50% of your other accounts as well. All right, let's, let's, um, fast forward. You, you move, you know, you're at Return Path for a couple years. Um, what's next?

Yeah, so after Return Path, uh, so Groupon was a pretty large client of Return Path at the time. Um, still is, I would imagine, uh, because they do a lot of email, as I'm sure a lot of people are aware of. If you sign up for Groupon, you get a lot of email from Groupon. But worked pretty closely with the Groupon folks during my time with Return Path. And so as, as it became clear it was time to, to move on from Return Path for a couple various reasons, um, I was already, like I said, pretty closely tied with the folks over at Groupon.

In fact, on some of the calls that they were conducting with some of their vendors, they even asked me if I would represent myself as Groupon while I still worked for Returnpath, consulting for them in some way, but still, even though still being employed by Returnpath. And so, kind of had some conversations and thought, well, since you're already kind of representing us on some of these calls anyway, why don't you talk to our guy who's building our security team and, and see if you want to, you know, see if you're a good fit for that. So, um, had some interviews with the folks over at Groupon. Great team. Love, love the company.

Love the team. It was, it was a pretty logical fit pretty quickly. And the guy that I ended up working for over there left the company about 3 months after I started. So it, you know, moved into— it moved in his role fairly quickly where I was heading up the internet security team over there. So they're, they're headquartered in Chicago.

They're headquartered in Chicago. I worked here Okay, so I worked from home out of here, which actually worked out pretty well because they also have a very large engineering office in Palo Alto, California. So Denver is a great jumping-off point between Chicago and Palo Alto. It's literally an hour and a half flight, direct flights either way, either one. Exactly.

Great company, great team. Had an opportunity to build out the team there, worked with and for some really great people over there, people I still keep in pretty close contact with. So I, I have nothing, nothing bad to say about Groupon. The primary reason that I moved on from Groupon to Teletech was I was really looking forward to getting back into a CISO-type capacity. Sure.

And, you know, I— as much as it was— as much as I was the highest-ranking, you know, internet security person there, I wasn't going to get an official CISO title, you know, if, if I didn't work out of the Chicago office, right? There were still some— they had a lot of, uh, you know, basically all their executive team was based out of there. If I was going to be able to move up in that capacity at all, it was going to have to be from one of those home office locations. As much as it was working out well, you know, working remotely, like I said, if I was going to want to move up the ladder there, I was going to have to be in one of the offices. So the, um, the opportunity at TeleTech came along after my predecessor left, and they were, uh, you know, looking for somebody for probably about 4 to 6 months or so.

Uh, seemed like a good fit, and so made the move over there and joined them in January of 2015. Yeah, so just, just a little bit over 2 years. Uh, and, you know, you took, you took over for Debbi Blyth, who's now CISO for the state of Colorado. Yep. Um, what did you— you know, for those who don't know, obviously you mentioned that Teletech's a call center.

Let's talk about scope. It's one of the bigger companies here in Colorado. You might just kind of give them some company background. Yeah, sure. So Teletech's been around for about 30, 34, 35 years or so now, about 45,000 employees globally.

Uh, of those, you know, since you mentioned it's a call center company, about 37,000 or so of those employees are call center agents. Uh, say about half or so, maybe a little more than half, are in the Philippines. And others are based through other areas throughout the world— Europe, Eastern Europe, the United States. A lot of it is dependent upon client need, client requirement. You know, we have some government clients who require people to be based out of the US.

We have some clients who have very specific language requirements, and so we build out locations based off of where those clients have needs for whatever their business might be. Okay, uh, so of that 45,000, again, 37,000 call center agents, which leaves about 8,000 or so— 6,000 to 8,000 call center— I'm sorry, corporate employees, and they're based all over the place as well, you know, between Denver and Austin and all various places around the world, you know, supporting the various call center sites that we have, our various operational programs, information security, sales, IT. Yeah, it's all spread all over the place. And headquarters is Denver, right? Headquarters is here in Englewood, Colorado.

And maybe, maybe in the most beautiful building in the area. I don't know. That nobody knows about, right? It's amazing. For those who haven't had a chance to get there, it's off of 470 and Peoria.

Peoria, yeah. On, on the, uh, the toll road out there. I think it's donut-shaped. It is a beautiful courtyard in the middle. Apparently you say they have music in the, in the summer.

Yeah, in the summer we have bands come out every Friday and barbecues, and families come out and spend some time with, um, it's a great opportunity to just, you know, have— let your family see where you spend a big chunk of your day, right? Um, but yeah, it's, it's, it's one of those beautiful buildings that nobody knows about because it's, it's off to the side of the road. It's not It's not something that people generally stop at or even necessarily see unless you're pulling into the, into the campus. But once you're in the building, I mean, it's beautiful. It's impressive.

It's a beautiful building. We have a huge multimedia room that we use for various events that, again, people just don't know is there. So we've had, we've had, I think, 3 different ISSA Denver meetings at your campus so far, and I highly recommend anyone who, who might want to go to an ISSA meeting, look for one of those at Teletech and come out and see the building. It's beautiful. It's a great campus.

Um, anyway, we appreciate you doing that. So as your role, uh, as a CISO at TeleTech, what are your high priorities? What is it you're focusing on as a program, or, you know, what are you working on maturing right now? Yeah, so there's, there's a lot, right? Um, there's a lot.

When I, when I started at TeleTech, you know, I, I didn't realize some of the challenges that existed before I got there. Sure, right. So my predecessor reported under the IT organization, which means that you know, a lot of what was done was focused around, you know, just around what was needed for the IT organization. Sure. When I came in, I was focused more on building an organizational holistic— they move you— they moved you out from IT and reporting into a higher level, into legal.

Yes. Yep. So one of the things that was very important to me coming into the company was that was able to establish an independent voice outside of IT. Sure. Right.

And a lot of great stuff was done by, by my predecessor. It was just that, you know, it wasn't because of how it reported. Yeah, it wasn't— well, the focus is on IT. The focus was on IT and not the holistic organization. If you want security to focus on the company, don't put it under IT, right?

That's right. It makes perfect sense. Exactly. So, so when I started there, I was reporting under the legal organization, which gave us that opportunity to establish our, our independence. Uh, however, it, it was difficult to get lawyers to spend money on things they don't understand.

Uh, we had some very funny conversations, you know, with the, with the, uh, with the person I reported to there around, you know, the need to bring in contractors for some things and consultants to bring in some things, uh, just because, you know, they were under the impression that, well, you have a security team, just do it, just do your job. Yeah, just, just do it, right? Uh, so it was, it was a good educational process for, for her and also for me to, you know, help make sure I understood, you know, how to educate somebody on, on the non-technical aspects of, of security, right? Because that's a very, it's a very important, uh, trait to be able to have is, you know, technical, or people who are in CISO-type roles generally come from technical backgrounds. And so it's important to be able to speak not only the technical side of the house, but also be able to speak to the non-technical side as well, which, which I did a lot of in other roles I was in as well.

Just, you're running whole business units, I'm sure you did. Exactly. But, but I never reported into a legal organization, so it was different, right? Different mindset. I worked very closely with legal and other companies, but never worked for them.

And it's different, you know, educating them in different ways. Yeah. So my focus at Teletech when I got there was, you know, how do we start building this organizational program? How do we start identifying the areas that we're not good in outside of the technical side so that we can start building, you know, security awareness programs? How do we start getting some of the things around BYOD that we didn't have in place before?

How do we start looking at risk assessments? You know, start looking at how do we— how we start doing those across the organization, understanding more about how to help the company understand from a business perspective the language of risk. And so, uh, got some good success in that program over the first year or so. We had a new CIO come in in August of 2015. I got reorged under him, uh, towards the end of 2016.

But it worked out pretty well because one of the conversations that we had was we need to make sure that we don't go back to the old guard ways where InfoSec is reporting under the IT organization. We need to have, you know, if I'm going to report to the CIO, we need to have it as 2 separate pillars where IT is one pillar, security is another pillar and it works as a partnership, not as a subservient relationship. And I'll tell you, it's been working out pretty well so far. I'll say, you know, I, I feel like there's a religious, you know, it's a religious war about where security should report. And, and I, I would have— I actually ascribed it to the security should never report to IT for a few years.

Um, I, I worked in financial services for quite a while, and that it's one of the regulators' big things is they don't want They don't want security reporting into operations at all. I went to Pulte Financial and I worked for the CIO there directly. He was just such a great supporter of my program. What I realized as I had the opportunity to talk to the executive leadership team and figure out where does everyone sit and who is there to support me and who is there— no one was not supportive, but there's a lot of people who had to be convinced, right? Um, what I realized was the CI— the general counsel was going to support me no matter what.

The general counsel is there to drive down risk, understands that security is an important risk, doesn't really understand how to do it, but is there to say, hey, Rob says that's a big risk, let's fix it. I got this guy on my side. And, and, and it occurred to me as I was there that if I moved under the general counsel, the CIO maybe would not be as motivated to support me as he was when I reported to him. Because when I was reporting to him, he's advocating it. He knows that his neck is on the line for security just as much as mine is.

And I really— at that organization, and I can't say anywhere else, but at that organization, I firmly believe the best place for security was right under that CIO, who in a lot of ways was like a second-in-command of the company as well. He had a lot of a lot of sway on the executive team, probably still does. So, you know, but my current company, that wouldn't be a good fit, right? So it really, I think it really depends on organizational dynamics and, you know, what's right for one place is not always going to be right. It does take a specific kind of CIO, a special kind of CIO, I think, to be able to properly segregate between IT and security and be able to manage them both well and not treat security as another function of IT.

I don't think every CIO can do it. But I think in your case, and in my case as well, it's worked out pretty well. So I want to, uh, branch out a little bit from your professional activities to your, uh— I know you do some community activities, right? And you're on the board for Colorado Cyber. So we've talked about Colorado Cyber on the podcast a couple times, but if you don't mind just giving a couple minutes, what is Colorado Cyber and what's the vision for it?

Yeah, so Colorado Cyber is a group that was formed a couple years ago initially. It was originally called Colorado Cybersecurity Consortium, and then we changed the name to Colorado Cyber. What we're focusing on primarily is, is how do we bring CISOs together? How do we start building a strong cybersecurity community, right? A lot of what you're doing with Colorado Equals Security as well, right?

Yeah. Where we're trying to kind of make sure we're building a, a strong security community, but not just for security community at the executive level, right? So how do you, how do you start bringing CISOs together such that, you know, they have a, a place where they can feel comfortable sharing ideas, sharing best practices, um, challenges, solutions in a way that is not, let's just say, surrounded by vendors, right? You know, it— we, we have a strong partnership with our vendors, right? We have, we have vendors who are on our board of Colorado Cyber, but, you know, we want to make sure that what we're, what we're targeting towards is, is bringing CISOs together in a way that allows us to, uh, you know, feel like we have a, a feeling of community around how we can communicate with one another and feel like we're doing it in a safe, safe place and safe way without feeling like someone's going to, you know, hey, I heard you have a problem with X and, you know, we have the, we have the solution for you, right?

So even though, like I said, we have vendors who are involved in it, it's, it's not in a way where, you know, they're, they're encouraged to try to find ways to use that community as a forum to try to sell into. So how do you— what's the— what does it look like? How do you guys bring those folks together? So we do quarterly events, uh, today Uh, we've been doing them at various different places, but we do various events on various security topics, on risk, on you name it. We're kind of covering a number of different areas, but, um, we do quarterly events that are advertised through our website.

Uh, we try to get, you know, the word out there through social media as well. I'd say, you know, we're still trying to feel our way a little bit through some of that process on how to really make sure the word is out there, right, uh, to, to various CISOs and various organizations. I think this is a great forum, so thank you for, you know, Yeah, give the opportunity to at least talk about it. And I'll tell you, I have a process before we post every podcast that I go through the calendars for all the different local security groups, and I always go to the Colorado Cyber calendar looking for events, and I haven't seen any for the last couple months. So I don't know if the calendar is not getting updated or I'm missing it, but— oh, thanks for the feedback.

We did have one, we had one in January. Yes. Uh, so that was our Q1 activity. So maybe there's nothing happened since. Yeah, so, so we're starting, we're going to start planning activity for our Q2, or you can start planning for our Q2 activity.

Excuse me, I think we're supposed to have a meeting maybe end of this week or sometime next week on, you know, starting to plan the logistics around that. So there'll be some more information on it shortly. So we'll keep— it'll be on the Colorado Equal Security calendar as well, and we'll mention it on the podcast when it pops up. So anyone who's interested and qualifies to go should be made aware of it. Um, you're, you know, I know you personally What do you personally— how do you spend your time?

I know you have a hobby that is kind of more than a hobby, right? Yeah. So, well, my kids mostly would take up a lot of my time, right? So I have 3 kids, all girls, pretty involved in various athletics between basketball and swimming, and soccer is about to start up. In fact, tonight my girls have soccer practice as well.

So I do a lot of that. Wherever my kids need to go is where my wife and I go. And because we have 3 of them and they're all in different activities, we end up having to divide and conquer quite a bit. Dabble in real estate as well? I do, I do.

I have had a real estate investment business on the side for the past 6 years or so. In fact, just recently sold, just 2 weeks or so ago now, sold the first investment property that I bought about 6 years ago. Yeah, back in November of 2010. Bought it for— or sold it. That's pretty good timing then.

It is. Yeah, it was pretty good timing. Ended up selling it for about 3.5 times what I bought it for. Awesome. So it worked out pretty well.

Congratulations. Thank you. And now parlaying that into the next one that we're actually already under contract for. And hopefully we'll be closing in about a month or so. That's great.

Congratulations. So you have— so yeah, and you also are a referee for basketball, right? I do, yes. So I've been doing it for a long time, as you know, just doing recreational leagues and things like that, uh, mostly for free just because I enjoyed doing it. Yeah, I like to play basketball.

I just love being around the game. I've played since I was 6 years old. Uh, despite that, you think I might be a little bit better, but I'm not. I'm not that great at it, but, uh, but I, I've always— I've always just loved being around it. Yeah.

And so, um, So I've been doing officiating for, like I said, rec leagues and such for quite some time, and then started this year, uh, doing it— I'll call it professionally, right? We actually get paid to do it, uh, and I'm going to be pursuing, uh, sort of actual certification for it sometime later this year. So allow me to do, you know, higher-level high school games, uh, potentially college games as well. But I've been focusing primarily on, uh, middle school and kind of— I'll call it lower-level high school games, so non-varsity. So you have 3 different jobs, if we way.

I just heard his question. You're a busy dude. Uh, so, you know, I, I do want to— you know, we're coming to the end of our time here. Um, once you— I give you such an opportunity to talk about your experience in the Colorado security community. So you've been here for, well, if math is right, you know, 14 years or so.

Um, you know, what, what's your experience been? Have you— how have you seen it change? Uh, if you just comment on that a little bit. Yeah, I, I— it's an awesome community, really. I mean, it's— I talk to my boss sometimes, or, you know, as I mentioned earlier, I report to our CIO I've talked to him a few times about just the tight-knit community that we have and the fact that we have regular dinners and activities.

We get together for social activities with our families. It's really a wonderful environment to be a part of and be in just because of the opportunities to network, the opportunities to get to know people, with people that share your interests.

From my perspective, it's been invaluable. I talk to my CIO and he says, Uh, in the CIO world— I, I don't know if this is true or not, this is just his perspective— but, um, you know, in the CIO world, you know, you don't have, uh, other CIOs like referring each other to new positions that are opening up, right? Like we do in the CISO community where, you know, someone is leaving one position and, you know, the word goes out, hey, so-and-so's leaving, you know, and we start referring people to, you know, that we think would be good fits for that role. According to him, that's just something that happened in the CIO community. It's very, you know, it's it's much more cutthroat, much more don't really care about what the other guy's doing or anything like that, where in our community it's, it's very much the opposite.

I think, I think it's really an us versus them. In security, we're all part of the us because we're so— that's right, we're so out of hand, right? Exactly right. Even if, you know, even if you work for my direct competitor, we're not competing on security, right? We're competing on product functionality and, and the better— the best we can do to, to shut down the bad guys.

Its best. And the thing that I've always found interesting too is that, you know, despite companies being at various levels of maturity in their various programs, a lot of us are still fighting the same problems and still trying to solve a lot of the same problems. So whether it's, you know, whether it's a financial services company or another company down the street, you know, who has— who's had a program or a CISO a lot longer than, say, TeleTech has, for example, regardless, it always seems like we're always trying to solve the same problems. Yeah, I would love it if someone could find me a company that's really figured out configuration and asset management. Like, you know, everyone— every big company has a CMDB, and it doesn't seem to me like anyone trusts it, right?

Basic fundamental stuff is just really, really hard. And yes, and the more we can share our successes, I think the, the better off we all get, right? Yeah, absolutely. Um, so, you know, one last question for you, uh, for those who are looking to get more into security. Hey, we talked about what a great community we have.

Maybe they, they don't know how to get into it. What would you recommend? What's a good way to get get started and start meeting folks? Best way is just get involved. I mean, there are so many events, there are so many industry groups like the ISSA, right, ISACA.

If you go to the Colorado Equal Security site, as you mentioned, there's a calendar there on all the various security events. And so if you're interested in getting involved, you just want to get better networked, or you want to find a job in security, I mean, just, just get networked because that's, that's all how a lot of these positions end up getting filled. It's true. And there's so many companies who are hiring for security roles. And I know, I know we talked about this a lot, Rob, where It takes so long to hire and find good people because people who are in the security field are already employed and they're not really necessarily looking to leave what they're doing.

If you're interested in getting into the field, just start getting involved, start getting networked, and you'll find a lot of people who are interested in talking to you more about what you want to do. There are literally events, multiple events every week. Absolutely. It seems like it's almost every night of the week there's something going on. Like you said, I think people show up and get to know folks.

And, you know, maybe, maybe you need to not use just your technical skill. You need to smile and shake a hand. That's right. Use your, use your, use your, uh, social engineering skills to, to make us like you. But it's become, it's become a much more, you know, business-focused field too.

I mean, where, you know, 10, 12 years ago, you know, technical expertise would get you wherever you wanted to go. And now there's a lot— there's a much bigger balance between technical and business acumen as well. And so You know, there's certainly a role for people who are really good pen testers or really good at certain things in security, but if you want to continue to move up that ladder, you have to have both sides of that fence. I'm glad you mentioned that. I, I just today I was talking to one of the, the managers at Ping, um, about one of the technical folks on, on our team, and we were talking about like professional development opportunities for this person.

And, and this, this guy is a super hard worker and he likes to learn a lot. We were thinking, man, You know what, he's doing all these certifications and going after all this tech stuff. You know what he really needs is to go to Toastmasters or, you know, go to, you know, one of those things where we have opportunities to work on skills that we don't think about at work, right? And frankly, as leaders, I don't generally probably do a great job of identifying what are those paths for you to go get that kind of training. And it's just something for us to think about, how we improve everyone.

Yeah, bring up bring up the level. Well, I guess any last questions, any last comments you want to have for the audience? No, no, thanks a lot for having me today. It's been a pleasure. It's been fun.

Thanks, Sam. Well, we'll look forward to talking to you soon. I'm hopeful, you know, once, maybe once a year or so, we can, you know, keep in touch and share where you've been going in the last year. All right, well, with that, we'll sign off. Thanks for listening to Colorado Equal Security, and we'll talk to you next week.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Rob by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes