All episodes

Joe Murdock, Red Rocks Community College

Apple Podcasts Spotify SoundCloud

In this episode:

Joe Murdock from Red Rock Community College is our guest this week. News from: Digital Globe, CenturyLink, BurstIQ, LogRhythm and a lot more!

Colorado = Security, for an un-romantic Valentine's Day

Valentine's Day has come and gone but we tell how you to plan to be even more unromantic next year. DigitalGlobe was purchased last year and now their parent company is moving its HQ to Denver. Colorado is piloting a digital driver's license. We're pretty good at election security in Colorado (good job Rich Schliep). LogRhythm can now sell to the government. Plus much more!

Come join us on the new Colorado = Security Slack channel to meet old and new friends. Did you catch our trivia question? Be the first to reply to info@colorado-security.com with the right answer and get any $25 item from the Colorado = Security store.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript9461 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Hello and welcome to Colorado Equals Security. Uh, this is the newscast for episode 55, the week of February 19th. And you may notice that it is not Robb introducing the podcast.

That's because Robb is out of town. So we've got a special stand-in co-host, Drew Labbo. Welcome, Drew. Thanks, Alex. Thanks for having me.

Thanks for agreeing to come in and hang out today and talk about the news. Absolutely. Always love to join. So before we jump into that news, we've got a couple announcements. Again, sign up for our mailing list.

You will get the show notes emailed to you. We don't use that for any other marketing or anything else. We're not trying to monetize your information by selling you to the highest bidder, but you do get some good stuff for it. And also check out our Slack channel. So I think that we've got several hundred people in there now, great lively discussions that happen in there.

For more info on that, you can go check out the website and click on the Slack channel button. So let's jump into the news. First story on the list, this past week of course was Valentine's. Drew, did you do something fun for Valentine's Day? We did.

I got the wife flowers even though she said I didn't need to, which means I need to. Had a nice Thai dinner last night. That was fun. So yeah, it was, it was nice. How about you?

Nothing super fancy. I make my wife a card every year, so did that. The homemade effort though, that's bigger than anything. It's a, it's a big, big thing. So anyway, if we weren't such romantics, this first article, you could have looked at the 10 ways to have an unromantic Valentine's Day in Denver.

So some interesting things on that list. The first one, you could schedule a doctor's appointment. I'm sure that that is pretty unromantic. Yes.

You could run errands. There are— Let's see, you could go to a burlesque trivia show or tribute show for The Rocky Horror Picture Show. You know, honestly, I'm not saying that that's not very, uh, unromantic. That could be something that's pretty romantic. It could be depending on what you're into, right?

Um, and then, uh, the other one, there is an anti-Valentine's Day event, the Black Heart White Pie event. So if you really have a black heart, you could check that out. But you can check out this article for more ways where you can have an unromantic Valentine's Day for next year. So entertainingly, they based this off Instacart. They tracked who was ordering what.

So if you're ordering flowers or chocolates— we're a little crunchy in Colorado, so who's to say ordering a dog collar for your significant other's pet's not romantic, right? Exactly. Who knows? Excellent. Next, we have some big news about Digital Globe.

So a couple months ago, we noted that DigitalGlobe was purchased. So, and then we said that, oh, the headquarters is now in Canada. So it's their parent company. But there's an announcement this week that the parent company is going to move their headquarters back to Denver. So that's pretty cool.

Think about the sensitive data they're handling, right? Some of that satellite imagery, some of it's classified. I imagine there will be some cybersecurity jobs or information security jobs in those 800 jobs. So Yeah, let's all stay tuned. Yep, and Chris Martinez, their CISO, is here in Colorado.

He was lucky enough not to have to move to Canada for this, so I'm sure that some of his people at other places are coming back, and I'm sure he'll like to have all his executives all in one place, right? Absolutely. So next we have, interesting, Colorado is participating in a digital driver's license pilot program. So this is interesting, this was from Fox 31 News Denver if you want to check it out. Online.

Basically, the pilot is to use your phone for your image. You can pick and choose what you're gonna display, so I think if you have a policeman that pulled you over, you can choose to display your whole, you know, all the information. I imagine if you're just showing your ID at a bar, for instance, maybe you don't show everything. So could be interesting. The more we digitize personal information, the more nervous I get.

So I imagine though, the state of Colorado, it seems like we have our stuff together here. We know quite a few people in the community, so I imagine there's a security plan around that already. So pretty interesting to to watch what happens here. It is pretty neat. I think it'll be interesting to see how they use some of the secure technologies in phones, you know, like the Secure Enclave to store stuff in the iPhone or other things like that.

But we'll have to see. Again, it does make me a little nervous also that all of a sudden this information is going to be available digitally. Also, the next story, ATM jackpotting comes to Colorado. So there's been Some— there's a story from the FBI recently that came out that said ATM jackpotting, which is essentially going and making money spit out of an ATM. So you, you put in a USB and then it overrides some commands and spits out all its money, that it's coming to the US.

But it looks like it is in Colorado also. Lucky us, it arrives finally. We've been waiting. Exactly. This has been something that I've really been looking forward to, walking by ATMs and having them spit out money at me.

Exactly, like a slot machine. Next, we have an article in the Denver Business Journal. CenturyLink's Chief Operating Officer refreshingly notes that he's concerned about personal data privacy. Yeah, there was a conference in Boulder that he was speaking at and mentioned the fact that he's concerned about the, the number of ways that people's data is taken and used in things like advertising, Also mentioned that he thinks that ISPs and other internet service providers should play a bigger role in security on the internet. So that's good to hear.

I think— I can't remember if he is an original CenturyLink person or if he is a Level 3 person, but I know that there's a lot of folks in Colorado at Level 3 that were doing a lot of this work to try and stop botnets and other things. So it's good to hear that executives care about they care about data privacy too. You read my mind. At the executive level, they're usually so focused on how do we get revenue, how do we focus on our business. To hear an executive talking about security is refreshing.

It's exciting. We need more of that for certain. Yep. Next, there's an article that Colorado received kudos on our state election security, which is great news. So they graded all of the states on how good their security was.

None of the states got an A, But Colorado got a B, which, yeah, that's pretty good. Above average. Above average. I think it was 11 states got Bs, so we're in, you know, small company there, top 20%. So shout out to Rich Schliep, who's in charge of some of that, and good stuff there.

I know they've been doing a lot of work, not only in the last election, but, you know, working on being secure for the next elections too. And more validation that Colorado is a security leader, our little town and flyover country, right? Our little state. Apparently this is drawing interest from all over the country. Everyone's looking at Colorado to see how this is going to go to get more secure in their elections.

So go Colorado! Next, Denver healthcare blockchain data company BurstIQ is raising some money. So Drew, you're a healthcare guy. What's your opinion on blockchain in healthcare? Well, it's interesting.

What I'm seeing right now is everyone is thinking that this could be the next big greatest thing, but I'm not seeing many people actually doing much about it yet. To me, this is still kind of the bleeding edge. I think it has a lot of potential. We'll see. I do ponder the complexity that that's going to add, particularly to electronic medical records.

So, watching this with fascination, and it's mysterious right now. We'll see what happens. What do you think? Yeah, I think we've talked about it on the show before that blockchain is a big buzzword right now, and it doesn't— at this point, there don't seem to be a lot of actual practical applications for it. But, you know, maybe these guys will get some money and figure out how to do it in healthcare.

That'd be pretty cool. So let's take machine learning, artificial intelligence, and blockchain and put it all together and see what happens. All right, let's get all the buzzwords and mix them up and see how it goes. We end up with Skynet. Exactly, the Terminator.

Let's see. So exciting news, another local company, LogRhythm, they got a Department of Homeland Security certification, certification to offer their cybersecurity platforms to to organizations in the government, and that's really exciting. Yeah, that's great. We love LogRhythm, great products over there. Good to see that they are going to be able to offer those inside the government as well.

I'm sure that all the government organizations that want them will benefit greatly from having their products. Absolutely. And that's all we have from the news, so let's move over to our trivia questions. So of course last week the trivia question that we had was, which former podcast guest guest boxed against Julio César Chávez? Drew, do you know the answer?

I do not. I can't wait to hear who it is. Was it you? It was not me, and it wasn't Robb either. So the correct answer was Cal Fussman.

Oh yeah, so Cal was a keynote at RMISC last year, and we had him on the podcast. A really interesting guy, and yeah, that's a great story that he tells about that boxing match. And then the winner this week was James Carder, who is the CISO for LogRhythm. So coincidence, we were just talking about LogRhythm. My world.

Yeah, so congratulations to James. He's going to be reaching out to Andre Gaeta, who's the sponsor of the trivia questions, to get his prize. So the trivia question for this week, this is a Colorado-focused question. So Colorado has the most secure vault in the world For which industry? And I am nice enough as a guest host to give a little hint on this one.

Okay. Think about how we would survive an apocalypse. That might sound nebulous, but think on that a little bit. So, all right, so this is going to be a tough one. People are going to have to think about this, but we expect lots of good answers to this.

So if you want to enter the trivia contest, send an email with your answer to info@colorado-security.com. First one to get the correct answer will win some cool Colorado Equals Security swag. Gotta love that swag. Thanks again to Andre Gaeta for sponsoring that. Thank you, Andre.

So next we have our upcoming events for the next couple of weeks. So on February 20th, we have the Colorado Security Alliance— I'm sorry, Cloud Security Alliance meeting. So that should be interesting. Also on the 20th, the Lady Coders group is having an event called called Negotiating Like a Boss. So that should be interesting.

On February 20th and 21st, we have the ISSA Colorado Springs February chapter meetings. Also on the 21st, ISSA Denver is doing their happy hour. I believe that is at Ping Identity downtown. On February 21st, CTA, Colorado Technology Alliance, we have Day at the Capitol. Cool.

So if you want— you're interested in going to meet our legislators and talk about the technology agenda, check that out. The GDPR meetup group, we've had a couple events from them in the past. They're having a GDPR overview on the 27th of February. On February 27th at SecureSet, we have a Hacking 101 workshop focusing on AppSec. Awesome.

And then the last of event that we're going to talk about upcoming is SecureSet, also on the— later on the 2nd of March doing a capture the flag. Some not quite so upcoming events, but in the not too distant future, SnowFROCK is coming up on the 8th of March, so that's almost upon us now. That's the OWASP annual conference. Yes, and we have the Rocky Mountain Information Security Conference, near and dear to our hearts, RMISC. And that is coming up on May 8th through 10th.

The call for papers just closed. We got nearly 130 submissions, so there's going to be some great content there. If you're looking to sponsor, we're still looking for sponsors, and registration is open. So if you haven't registered yet, go ahead and register. We are still in the early bird timeframe, so you get a little bit more of a discount.

Also, if you're an ISSA or ISACA member, you get an additional discount. So let's move on to jobs. The first job that we have on the list, NBCUniversal is looking for an enterprise cybersecurity officer. It's interesting, that's a Denver job. I didn't know that they had any NBCUniversal people out here.

We have Redwood Trust with a technology risk compliance analyst position open. LogicWorks is looking for a senior cloud security engineer. Leidos has a position for a senior insider risk consultant That's an interesting title, Senior Insider Risk Consultant. Yeah, so it's— I thought that was a cool one, which is why I put it in here. You're actually going to go assess people for their potential insider risk threats, and that's something that organizations don't often have the luxury to think about, right?

So that's, that's going to be interesting to see how that works out. We have Laird's, I think, Security Consulting Senior AppSec Research Engineer. Yeah, and so that's Chris Nickerson's company. They're looking for lots of good people, and This is one of the jobs that they have open right now. Salesforce, they're looking for a security architect.

This is actually a remote position. I think it's technically posted in California, but it can be remote. There's a couple Salesforce people in town, and so they mentioned that this one was open. There's nothing like doing remote work in your jammies while eating Captain Crunch cereal. Arrow has a security infrastructure engineer senior position available, and they're also looking for an IT auditor.

Couple positions over there at Arrow. And if I remember, Arrow is the largest manufacturer of electronics in the world. That is entirely possible. Definitely the largest, or at least were the largest employer in Colorado. CableLabs has a security engineer position available, and then also a principal security engineer.

So they're looking for a couple different kinds of security engineers. Mike Glenn over there sent us those jobs. So if you're interested, talk to Mike or follow the links that are in those jobs. And that's what we've got for this week. Thanks for sticking with us, Drew.

Appreciate your guest hosting. We are now going to move on to the interview. This week, Robb, even though he is not here, interviewed Joe Murdock of Red Rocks Community College. So Joe is on the faculty over there and teaches cybersecurity. Normally Robb would give us an overview of what that interview is about, but since he's not here, he can't.

So you guys are just gonna have to keep listening to the show and figure it out. We will wing it. And everyone do the snow dance out there. We want some snow up in the mountains for some skiing, so keep doing the snow dance. Awesome.

Well, thanks again, Drew. Thanks, Alex. And we will talk to you next week. Sounds wonderful. This is Brian Becker, Director of Information Security at Cronkie Sports and Entertainment.

You're listening to Colorado Equals Security. For Colorado security professionals by Colorado security professionals.

All right, this is Robb Reck, and today I am sitting with the program manager for the cybersecurity program at Red Rocks Community College, Joe Murdock. And Joe, I understand that you recently explored the Oregon Trail and you ended up, you ended up dying. That's right. Yeah, I unfortunately did not make it to Oregon. I died in in the river.

And you're not talking about— you're not talking about a video game right now, right? No, I mean, it's based off of the video game, but it was, uh, yeah, an event at the Colorado History Museum, uh, where they kind of had it set up and you had various, uh, things you could do, like, you know, hunting on a video game and that sort of thing. And, uh, yeah, crossing, crossing the river is what killed me. So, so is that— do you know if— is that exhibit open for a while, or— no, it was just a one-night deal that they had on Saturday So Colorado History Museum, one night, Oregon Trail. So maybe they'll come back again sometime.

Maybe. I mean, they, as far as I know, they sold it out, about 400 or so people. So if we write enough angry letters, maybe with the rest of us communities. And apparently dying in dysentery is still up for grabs. You didn't take that one.

No, I didn't take that one. I took death by fire while on the water somehow. Which is more impressive. Yeah, that's what I thought. All right, so let's start talking a little bit.

About what you do and really how you got there. So understanding that you run the program for cybersecurity at Red Rocks Community College here in Denver, how did you do that? Back me up, you know, 20 years ago. 20 years ago, I was actually graduating the program I now run, which is kind of interesting. Yeah, so I'm a graduate of Red Rocks Community College, grew up on the west side of Denver, and so 20 years ago I was finishing up my A+ class more than likely.

And it's interesting because that's one of the classes I teach now. Yeah, obviously changed quite a bit in 20 years. But so what was the program? Obviously there wasn't a cybersecurity program in 1997. No.

What was the, what was the program back then? It was an electronics program. Okay. So we did work with some punch cards, we did circuits and circuit boards, and yeah, quite a bit different than kind of how things run now. Yeah.

So you graduated, you got your A+ certification, which is, for those who don't know, basically like a desktop support, right? Yeah, computer hardware and software, mostly Windows OS. But yeah, it's kind of how to fix a computer, build a computer, troubleshoot it. So you got that certification. What do you do professionally?

So I worked on a help desk back then when I was at Red Rocks for a company that sold extended warranties through the Wiz and Circuit City, which I believe both are long gone now. But so I did, you know, people call up, they bought a computer at Circuit City, they were having trouble with it. I was at the other end of the number they called trying to help them out. I did that for, um, Electronic Arts video game company. If your video game didn't run, you— I was one of the guys who would try to get it, get it working.

Yeah, it was— for me it was usually sound card driver issues. That was most of my problem. Do you have a— do you remember a particular theme of problems you had? You know, I don't. I just remember sometimes people were angry when they called.

Sometimes. So in addition to those tech skills, you had to work on the soft skills of trying to de-escalate people so you could help them. Yeah. Uh, so what was next? So I finished, uh, so I have an associate— I actually have 2 associate degrees from Red Rock.

So I have the electronics one, then I have a business one as well. Uh, transferred to Metro State, did my bachelor's at Metro State, which I thought Metro was great school, just like Red Rocks. Graduated Metro State, started working for the school district as a network person. Thought I'd never go back to school. What school district did you work at?

Jeffco. Jeffco, sure. Yeah, so I worked in Jeffco for about 8 years, the last 3 being as their IT security person. Oh, great. Before I moved on to DOT, Department of Transportation.

When did you leave Jeffco? Probably mid-2008. Okay, pretty pretty early then. They were— yeah, I didn't have much resources. I was the first IT security person, so it was interesting being the first person in that job and kind of trying to define it and, yeah, see how everything worked.

And I think now they got about 4 or 5 people. Have you got to meet Chris Paschke? He's the, the CSO over there. Yeah, Paschke, uh, I met him just before I left. Okay.

Yeah, well, very cool. You said you went to Department of Transportation? Yeah, uh, then I went to DOT for— worked for CDOT, which is a great organization to work Yeah, is that over in there? About 4 and a half years. Headquarters down in Arkansas.

Um, is that the Federal Center? No, no, it's, uh, uh, like Colorado Boulevard and I-25 area. Oh sure, okay. Yeah, so they have— it's, it's back in there a little bit, but that's where their headquarters is. I manage the northeastern part of the state, so basically Highway 7 to the state line and the Continental Divide to the state line.

Okay. Yeah, some days there's a lot of driving. And you went out there like to network things? Yeah, so I mean, I was, uh, I think technically an IT systems manager, so I was responsible for all the IT that was in the northwestern or northeastern part of the state. So it was something like 45 locations, so like a lot of maintenance barns, they have their own little networks that are usually connected to the internet and then back to headquarters and then the regional offices in Greeley.

Hmm. All right, so how long did you do that for DOT? Uh, just under 5 years. Okay. Yeah, just under 5 years.

And, uh, I actually was, was planning to start a restaurant. This is back in 2012. So I got about, uh, 2/3 of the funding, and, you know, we were— my business partner and I were getting ready, and then all of a sudden, like, so our, our name— Whole Foods thought they owned our name, so they tried it was. And it was just kind of downhill from there. And so I ended up— that's, that's actually when I started teaching at Red Rocks.

So I was doing adjunct teaching starting January 2013. Well, I want to hear— I was like, I gotta, you know, I've always wanted to teach, and then I also needed to kind of bring in a little bit extra income while I was fending off Whole Foods. So I want to get into Red Rocks, but first I want to know more about this restaurant that almost happened. What kind of food? So it was, it was in the, what they call the fresh casual segment.

So when you think of like Chipotle, Qdoba, okay, you know, Mod Market, similar concept. Okay. And where it was like, you know, healthy food quickishly. Yeah. Not necessarily drive-up window.

But, and there's quite a few of those now, I think, around town. Yeah, it was right when, you know, some of those were starting to come up. And what kind of I mean, you said Mexican and you said America. What kind of food in there would you be serving? You know, so we had things like salads.

I was also focusing a lot on breakfast because like if you ever want that kind of quick breakfast, that option isn't there. Yeah. So, you know, you can go to McDonald's or Arby's and get whatever their breakfast is, but this would have been a little bit more of a healthier kind of slant on it. So it was actually going to be like a like open from 6 AM to 3 PM, something like that. So not necessarily dinner to start with, but yeah, it was mostly breakfast and lunch.

And you had a spot figured out? Um, we were looking at a couple of spots, yeah. And the way that, uh, the way that we built it was so that we could franchise it and basically just kind of cookie cutter it. Yeah, so it'd be real easy to set up another location. Did you have a favorite menu item that you maybe you still make or you really wish you had?

Yeah, I mean, you know, um, Some of them I do make. Uh, one of them on there was kind of like, uh, so if you ever go to Europe, a lot of times for breakfast they have like yogurt and, and muesli, you know, which, which like you think maybe a granola, but, uh, muesli is a little bit different than, than the granola that we have, uh, here. So like that's a pretty, pretty quick and easy one that's still relatively healthy, doesn't spike your blood sugar, that sort of thing. Yeah. So can you tell us the name that caused all the lawsuits?

We were gonna call it Whole Eats. Whole Eats. Okay. And that was the word. I mean, that's, that's an entirely separate conversation.

But yeah, essentially, Whole Foods threw their weight around on that one. Sure. So is there possibility that we go back and do this again sometime? Or is this— you know, I mean, I never want to say never to anything. But, uh, I know that would be, you know, just from what I had worked on, it's a lot of work.

I think having a, having a restaurant— and that's not to say maybe, you know, 10, 20 years from now I just don't open up my own little one-off type of situation. I, I don't think that you open up a restaurant because you want to get rich, from everything I've heard. Yeah, margins are too low. I think it's a highly competitive business, and most of them fail within the first 3 years. Yeah.

All right, so let's maybe talk about Red Rocks. So you came into Red Rocks 2013 and you did some teaching initially? Yeah, yeah. So like I said, I graduated Red Rocks back in '98. In 2013, I started teaching in the program that I now run.

It was a lot harder than I ever thought it would be. I mean, I've been doing IT for a long time, like, oh, this is really easy to teach. Well, when you're doing it, you just have to do it. When you're teaching it, you got to understand how it works and able to explain it to. Yeah, my youngest student's 17 and oldest probably early 60s.

Wow. So it's, it's a pretty diverse range of students as far as experience, how they learn, how quickly they learn things. So that, that is probably one of the hardest things I think about teaching, but I was teaching as adjunct for probably a year and a half maybe, and then the position to run it opened up, and so I applied for it and they offered it to me. Yeah, so is that full-time gig then? I, I— yeah, no, it's, it's full-time.

Um, so I think that would have been 20— probably August of 2014, I think, was when I started running it. Yeah, and teaching full-time in it. So, so what is the— what does success look like? You know, obviously with the community college, um, I, I assume there's some, some desire to give folks ramp toward a BA, a bachelor's degree afterwards, or BS. And there's also probably a desire to have, you know, an all-in-one where they graduate with your associate's and they can go work from there.

How do you, how do you look at goals and what does success look like? Well, I think it depends on who's asking that. So if you are the state of Colorado, success looks like you're graduating people out of the program. So they're coming in, they're finishing a degree, or they're finishing what we have that are called certificates where it's just the program-specific stuff and it doesn't include the general ed aspect of it. And some people do that.

They may have like a bachelor's degree from 20 years ago and they just want to go through the computer classes. But the state just sees it as, you know, whether they complete is what they're called. So they get a certificate or a degree. If it's from my point of view, I look at it as, you know, I'm successful when I help people make a change in their lives. You know, they're there because they want to learn the skills to have a better career, to have a better life, and for some people that's a certificate.

For some people, that's the entire degree. For some people, it's maybe just a couple of classes because they're already kind of in the industry and they want to get their Security+, for example. They don't really care about a degree or a certificate. So that's kind of how I approach it. And then from a student's point of view, which is obviously why we're around, you have to get to know them and figure out what do they need to be successful in their eyes.

And again, maybe that's a couple of classes, maybe it's the degree. It's gonna be challenging to have all those different, you know, different goals, right? Someone might just be there to get a specific skill, so they take 1 or 2 classes. And then you have the other people who are really looking to, to use this to springboard into a, you know, more education, or some— someone who wants to graduate and immediately go get a job doing security stuff. How do you build a program that they can cater to all those?

I mean, you know, the way that I've kind of— and, and I didn't build the program from scratch, so My predecessor had kind of started it and I just kind of took it over from there and redefined it a little bit. But the way that I run it is, you know, I want to be able to have students come through all or part of my program in a much better place where they can actually be successful in an IT career. And again, if they have aspirations of being a desktop person, then they go through, you know, our A+ class, you know, maybe a couple other classes, Intro to Networking, and then they're off. And if they want to be you know, a cybersecurity person that gets the degree and then transfers to a 4-year to get a 4-year degree, then they can go that route as well. So it's— I think community colleges are a great asset for our communities because they can offer, you know, kind of a little bit different based on what students want to get, as well as kind of what the community is looking for as far as skills.

And obviously with cyber, it's huge talent shortage. Yeah, but it is, it is kind of tough to manage because you do have just all sorts of aspects with it. So I'm just thinking about like the continuum from, you know, having each class be modular, standalone, where, you know, I could walk in and take it, whatever, you know, whatever it is, 8 or 16 weeks or 12 weeks, whatever the class is. I can come in for that, that course, take it and walk away and be done, versus, you know, it's really chapter 2 of a, you know, 4-chapter book where if I step into that class, I'm really— I don't have the information needed to understand where it's going, and I'm missing the conclusion by not sticking around. Yeah, somewhere in that extreme somewhere.

Um, I, you know, again, I think it depends on the student. So, you know, as a CTE program, so a career tech program, some people again just, you know, they may be retired, they may be a hobbyist. I want to learn how to build my computer, so they take the A+ class. Class. But I think it's really kind of, you know, what are, what are the goals of the student?

What are their personal goals? And maybe they come in and start and they say, hey, I really like this, and I'll go and maybe do some more classes. We do it a little bit differently. Just the security aspect of it, right? Is if you— if I say I want to go to Red Rocks and I want to, you know, take the security cybersecurity program, what does that mean I'm taking?

And I have— is 2 years worth of courses, I assume. What's part of that? If you come in and you want to do cyber and you have no experience, it's about a 2.5 to 3 year. So it's a 2-year degree, but I have students go through A+ and networking first before they ever hit cyber so that they have that good foundational knowledge of how the computer works, you know, how a network works and that sort of thing. If you come in with your A+, then obviously you don't take the A+ class.

But essentially then you go through roughly 2 years of our cyber program where you go through like a Security+ class, you do some forensics classes, some network defense classes. So you'll learn a pretty good understanding of kind of how security works and how it's implemented in organizations or how it should be implemented. Not always implemented, but how it should be implemented. So is it— you say it's full-time for those 2 years, 2 and a half years? Yes, if you want to finish it in 2 years, it's full-time.

So full-time is about 12 to 15 credits a semester, not counting summer. 12 to 15, that's 4 or 5 classes? Roughly. Is that right? 4 or 5 classes at a time.

Of those 4 or 5 classes, how many of them am I doing the security or other technology courses, and how many are general ed that, you know— It's usually probably about anywhere from 6 to 9 are cybersecurity-related, program-related. Okay. And then the rest are gonna be your general ed components. About half? Yeah, roughly.

Okay. Yeah, so it's about 63 credits total for the degree. Okay. And so over those, you know, over that time, you mentioned some of the stuff they're gonna learn. Are you looking— are you evolving your curriculum?

And what does that look like? You know, how was it different a year ago and how's it gonna be different a couple years from now? Yeah, I think as a As a community college, so we're part of the Community College of Colorado system, so every community college in the state's under the same umbrella corp, if you will. So we get together every few months as kind of the cybersecurity department or the CIS department or, you know, all the departments and talk about, okay, where are we at, where do we want to go. We also work with the community, so every school has an advisory board of professionals that are out there and we get some direction from them as well.

For Red Rocks, we're also what's called a Center of Academic Excellence in Cyber Defense Education, and we were the first community college in the state to receive this designation. But essentially, it's from the NSA and DHS, so National Security Agency and Homeland Security. They come through, they vet the program for the curriculum we teach, our instructors, you know, they have the experience to actually teach it. They look at our internal IT department to make sure we're actually doing best cyber practices, that sort of thing. And so it's about a little over a year-long process, but they'll either say, you know, yeah, you meet it, or no, you don't.

And so we were designated at the end of 2016, and as part of that, there's what's called the CAE community, and that's basically the faculty from all of these schools that have been designated as We get together probably 2 or 3 times a year and talk about, okay, what's the curriculum looking like? What do we need to change? Where do we want to go? That sort of thing. And then obviously the NSA has input on that as well.

So it's trying to keep everything kind of up to date, which is hard with technology, right? It changes so rapidly, and, you know, trying to update a course like within the system takes roughly a year or more just because of the process. It has to go through. Can you give me examples of any changes that you've made?

As far as courses, I developed a course for our management department that was bridging the gap between the IT side of the house and the business side of the house where what I've seen in my career is that they don't like to talk to each other. IT wants all the toys. They don't care about the cost. Business says you can't have those toys. We don't have the budget for that.

It's kind of built to where IT people— I've had IT people and business people take the class, which is exactly what it was targeted for. So you kind of get both sides in the class. But it's to kind of say, okay, IT, here's how you can work to support the business because that's why you exist. Business, here's how you can communicate with IT people because if you can't, they're not going to be able to help you, that sort of thing. As far as some of our cyber classes, We have a new Cisco security class that just got approved, I believe.

So like, we're CCNA Cisco Academy, right? And working with Pikes Peak to develop— they pretty much did all the legwork, but we have a Cisco security course now that we can teach as well, which is nice. We're looking at trying to do AWS courses. But just getting the resources to kind of run it can be a little tough. Finding AWS security experts.

Yeah, I actually know a couple of guys who are AWS certified who could teach it. We just have to figure out how to get the course set up because we can't run a course unless we have a specific amount of enrollment, which can be difficult with something like AWS just because if we marketed to the community, I think it would fly. I think we'd have people beating down the door. But right now, that's not how it's kind of set up, so trying to do that. Then we just recently became a Palo Alto Academy with our firewall course, so we're using Palo Alto curriculum to teach the firewalls.

Interesting. Palo Alto and Cisco, the partners right now. I totally agree, looking at AWS or Azure or Google Compute, any of those would, would really get your, your grad— your graduates kind of a leg up in the market versus, you know, being good at Cisco Palo Alto is, is nice. Yeah, but, you know, there's a lot of other people out there who have that, right? Right.

And it's kind of one of those things where, again, it's, it's a 2-year program at a community college, and to try and get all of these classes in, it'd end up being like a 4-year type of thing. But that doesn't mean we couldn't do it. It's just, just what do you want to prioritize, right? Yeah, exactly. It sounds to me like you're From what I've heard you say, you're equipping people to be more on the technical side, right?

A security analyst, security engineer is what you're training. Yeah, so when you look at the CAE program that I was talking about, it aligns with the different workgroups out of the NIST framework, the NICE cybersecurity education, and ours is predominantly operate and maintain. That's essentially what our program is. Program. Yeah, would be, but there are other ones.

Okay, um, so, you know, what would you say, you know, presumably quite a few people listening here who might be hiring people, um, what would you say in terms of should they be looking at Red Rocks students that are right there right now, or should, should they really expecting those folks to go on to a, to a 4-year school after, or what, what should they be thinking about Red Rocks? I think honestly, you know, if you're looking for talented cybersecurity individuals, Red Rocks is a great place to look. We have a lot of students who are getting jobs before they even finish the program. So we have a couple of companies that we work with, and, you know, they come in and they do a hiring event, and they'll essentially interview, you know, maybe 10 to 12 students. Yeah.

And then if they want to make the students an offer, then they will. And so, I mean, yeah, you know, I just— with the companies that come in and do it, I say, okay, but you got to make part of the stipulation that they finish my program before you actually hire them officially, or, you know, their employment's based on finishing. Right. Because again, I mean, to the state, which is who looks at my program, if they get all 3/4 of the way through and then they've got a job, you know, making $50,000, 60 grand in IT security and they leave the program, I mean, they're successful. Like, in their eyes, right, the student is successful.

And for me, they're successful. But it's not always seen that way. But yeah, I think the, uh, you know, I'm a product of community college, um, you know, just working with the program, I can see, uh, the dedication of most of my students that, you know, they're there, they want to better their lives, they want to learn this stuff, and especially the students that get involved in our cyber team or become a Cyber Patriot mentor for the high schools. Those are the ones that get snatched up real quick. How many students are in the program at any given time?

Roughly about 250. Is that about a 100-person cohort then per— You would think that, but it doesn't work that way because again, they may come in for the first year, get the skills they're looking for, and they go get a job or they get promoted in their current place of employment. So right now, this spring, we should graduate about 16 students out of our cyber program, out of the degree. Certificates, probably a handful more. But like, for instance, in our A+ class, which is where students start, we have 47 students currently in that with another 24 currently in that class.

So they won't all matriculate through because again some of them may move, they may, you know, they've got the skills they wanted to get and they're moving on with their life. So we covered a story about you guys last year where your team had basically created a lab environment. Can you talk to me about what that is and what that competition was? Yeah, so the competition was the Community College Innovation Challenge which is put on by the National Science Foundation, and every community college in the country is welcome to apply with some sort of idea. This year it's open, there's no predefined categories.

Last year cybersecurity was one of the predefined categories. And so basically what a group of my students have done is they wanted an environment that was where they could kind of mess around outside the classroom and do things like pen testing or building servers, tearing them down, that sort of thing. And so with the help of the local— our local in-house IT department, they were able to get some surplus equipment that they can kind of tinker around with and build up in whatever way they want to and then break it and fix it.

That's kind of what they set up. And so the Innovation Challenge is really more of an entrepreneurial boot camp than it is you know, like a cybersecurity lab thing. They just kind of built this lab and said, hey, you know, other schools, you could do this too, or maybe even we could try and, you know, sell plans or something like that. So, you know, when I heard of this initially, I was thinking it was kind of like a science fair, right, where you come up with your project and present your project and who's got the coolest project. That's really a big part of it.

Yeah, so they have their project, they do a YouTube video for the submission and, you know, kind of talk about what it is and how it's beneficial. And then if they get selected, the top 10 teams go to DC. So, you know, I was their, their faculty mentor, so we got to go to DC over the summer. They get put through a boot camp, uh, in DC, and then, uh, they actually have to present in the Senate building. So they were all, all 10 teams were set up in one of the meeting rooms in the Senate building.

So we had senators coming in to check things out, and they would kind of present there. And then they also had to make a final presentation to the judges the following day. So, and they actually took second place, which is really awesome. Yeah, that was pretty cool. Yeah.

So, uh, the team that took first, I believe, invented some sort of antimicrobial foam for hospitals to keep infections down, save some lives. Yeah, yeah. And they were ready to go to production the next day. They, they just needed the funds to actually producing it. So cool.

But it's really cool kind of seeing some of that stuff. So has the second place come along with an award too? Yeah, I think each student got $2,000 that they could use for whatever, school or play or whatever. Has it changed, you know, winning the second place there? Have they done anything more with it?

Is it kind of sticking where it is? Has it died off? No, no, we still have it. They still continue to want the students that are still there, they mess around with it. We've got additional new students that kind of go down and work with them.

Yeah. Yeah, so right now it's a bunch of equipment in a mobile rack that they can kind of wheel around. Sure. And, uh, yeah, so they're still using it, you know, trying to make things a little bit better, get newer equipment, that sort of thing. So anyone listening, is there anything they need in particular you guys need for the program?

Any hardware? Yeah, I think honestly hardware is always, uh, you know, a nice, uh, nice thing to get a hold of. And I would say if there's anybody out there that, uh, wants to look at donating some funds or wants to donate some equipment, then they can get a hold of me and we'll see if it makes sense. Like whatever equipment they want to donate, if it makes sense. I mean, we don't want 2010— What kind of equipment are you looking for?

Maybe newer blade servers or maybe some low-end firewalls. We don't need $40,000 firewalls, but some of the lower end. We've got some 5512 ASAs that got surplused out of RIT that they're gonna be getting. Nice. You know, so stuff like that, maybe some ISR routers.

Sure. So just kind of anything that's relatively recent. Yeah, that's always the hard part, right? Utilize it. It is.

I mean, yeah, because everybody's like, well, you know, if I trade it in, I get a little bit of discount on that new stuff I'm buying. So yeah, you know, but yeah, if anybody out there's got anything. And the other thing is, is just people to come down and talk to our students. You know, I think that it goes a long way when they can talk to somebody who's currently an IT security person or a network engineer or a database developer, like whatever, you know, IT kind of career, because we have lots of IT programs. I mean, in addition to cyber, we have programming and web development and that sort of thing.

So I think it's real beneficial if students can meet somebody who's currently working in the industry and just ask them questions about, you know. Well, I wouldn't imagine it'd be too hard to find those people if you ask in the right places. Yeah, yeah, and we do have, we do have quite a few that do come in. Yeah, but it's just kind of organizing it, and because a lot of our classes are during the day, and so for some people it's hard to, yeah, you know, come out to school at 10 AM on a Tuesday type of thing. Well, that sounds good.

What, what's the future look like? Do you have any, you know, any changes in mind, any where you want to take the program? Um, I, you know, honestly, I think just, just continuing to build on the success that it's had. I mean You know, with all the recognition that we've got, you know, over the last couple of years, we're getting a lot of companies that are now interested saying, hey, you know, we need the cybersecurity people, we need that talent. You know, probably the number one thing that's been on my to-do list for probably a couple of years now is trying to create an industry partnership for internships because that's kind of one of the big gotchas that we have right now is we have lots of people in industry saying, hey, we need these people, we need the talent, but we need them with 2 years of experience.

So we don't want to look at your students because they're in school. They don't have that industry experience. Students are like, I can't get any industry experience because everybody wants 2 years. So the ones that can get internships do real well. Again, the ones that get involved with our cyber team, with Cyber Patriot, they get snatched up right away.

I'm not even completing the program. Yeah, but for all the other ones who, you know, maybe are, you know, working part-time and it's tougher for them to get involved— a lot of our students have families, you know, with community college. Our average age I think is like 28 years old. So I think internships, some sort of internship partnership with a local company that is willing to take, you know, a handful of interns every semester and just kind of mentor them. And, you know, they want to hire them, great.

If not, you know, hey, they got some real good experience and, you know, they can be useful, you know, to other companies now as well. But that's, that's the biggest one. Yeah, it's just bridging that gap of no experience coming out of school to what employers say they want. So for those listening, if you're looking to start getting a pipeline of talent, bringing interns in, you know, a year or so before they're ready to go is a good way to try before you buy and, you know, make the world a better place while you get your pipeline of talent going. It's a good idea.

Yeah, and I think, you know, the companies that we currently work with, they're very happy with our students. Yeah. So yeah, it's just kind of getting others to give it a shot. So how do people reach out to you if they either want to donate some equipment or talk about internship? Yeah, so there's a couple ways.

So first I'll throw out our website for the program, so www.rrcc.edu/cyber.

That'll take you to the cybersecurity program webpage where you can learn more about the program, more about our cyber team, kind of the things that we teach. And then my contact info is on there, but you can email me joseph.murdock@rrcc.edu as well. All right, just getting this in the notes. We'll have the link at least for your website in the notes. Yeah, cool.

Well, cool. Any final comments, questions, anything you want to throw out to the community?

You know, man, put me on the spot. I should have thought about that. I would just say, you know, when you're looking for these talented people to kind of come in and help shore up your organization, look at the community college programs, you know, and look at the 4-year programs we have in the state. So we have about, I think, 7 schools in the state that are designated a Center of Academic Excellence by the NSA and DHS. And so here in the, in the metro, Red Rocks, we're the only 2-year school, but Regis, Colorado School of Mines, they're designated as well.

The Air Force Academy, you know, good luck trying to get a cadet though, I would imagine. But the Air Force Academy is as well. So there are, there are some options, especially for Denver, such a big tech area. Yeah. There's a lot of unfilled jobs.

I think the last I heard, it's around 10,000 just IT security unfilled positions in Colorado. That's amazing. Yeah, and it is something like we're working with the state of Colorado with the workforce development because they see the huge need. The thing is, it's a liability. You don't have the people for these jobs, and so it just doesn't get handled the way it should or maybe not even as Well, cool.

Well, thanks so much for your time, and we certainly appreciate your mission. Looking forward to seeing your, your students graduate and start, you know, getting— being a major part of the workforce here in Colorado. Yeah, yeah. No, I appreciate you having me on, and that's kind of really the huge rewarding thing about this job is when I have a student come back and say, hey, so-and-so offered me a job doing cybersecurity, and I'm super excited about it. You know, no more work in retail.

So that's at least for me, that's that's really rewarding to see. It's a big part of us fixing this talent gap we've got for sure. All right, Joe. Well, thanks a lot for your time. We'll talk to you again soon.

All right.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes