All episodes

Brett Wentworth, Director Global Security at CenturyLink

Apple Podcasts Spotify SoundCloud

In this episode:

Brett Wentworth, Director of Global Security at CenturyLink is our feature interview this week. News from: Denver Startup Week, System76, Conga, Galvanize, CSU, OverwatchID, Red Canary, SecureSet, LogRhythm and a lot more!

Aurora, People Want to Live There

It must be official because Denver Startup Week has a schedule. Conga and Galvanize are growing. The Secretary of State race is going to hinge on cybersecurity. CSU gets $1.2M from recent cybersecurity legislation. OverwatchID gets a new headquarters. And blogs from LogRhythm, SecureSet, and Red Canary.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12321 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 76, the week of July 23rd. As you guys heard last week, Robb is on vacation, so I have a very special co-host today, Chris Triolo.

Welcome, Chris. Hi, Alex. Thanks for having me today. Glad you're here. So, Chris, we've known each other for a long time.

Yeah. Somewhere probably between 15 but not quite 20 years. Yep. Back in the day, used to work at IBM together. So, what are you up to these days, Chris?

Yeah, my latest adventure is a startup. Nice. So it's the first time that I kind of separated from a large company or even mid-sized company to something so small as this. Yeah. It's awesome.

It's very challenging. It's a lot of fun, but it's kind of a mental game, you know. It's how to keep things going and you know, try to figure out how to get to that next stage. There's no boss telling you what to do. There's no boss.

You're in charge of yourself, and that's, that's good. That's great. I mean, that's one of the things I enjoy about it the most, but it also means that you got to keep your motivation up and, you know, really tackle, you know, every day's problem. Yep, for sure. All right, well, let's jump into it.

Uh, before we get to the news, we've got some announcements. Of course, we have the Slack channel. Lots of great conversation going on in there, so make sure you jump over and join if you haven't. There is a link on the website, colorado-security.com. Also on the website, we have a mailing list.

If you want to get our show notes emailed to you every week, sign up for that mailing list. We would love it if you rate us and subscribe either on Google Play or iTunes. Of course, we appreciate good ratings, but it, you know, if you don't like us, then, you know, don't rate us highly. And then finally, we have a Patreon going. So we had this week a brand new patron join us, Steve Winterfeld.

Thanks, Steve. Appreciate the support from you. And also wanted to mention last week Robb mentioned that Chris Gellino signed up as a patron. Chris works for Carbon Black, and this is actually sort of on behalf of Carbon Black, so he just wanted to make sure that that was was shouted out there. Anyway, so let's go ahead and jump into the news.

All right, well, our first story is that the Denver Startup Week schedule has been announced. It will be September 24th through the 28th. It's 4 full days of schedule. Looked like a lot of interesting things on the calendar, maybe just because now I'm more interested in startups. Yeah, right, and what that has to offer.

Yeah, and of course Denver Startup Week is the country's largest independent non-affiliated startup festival, I guess you would call it. So looking forward to that again. I did look through the schedule and I know that Robb had submitted a session and I did not see it on the list, so I'm not sure if they, they made the cut. Oh, that's too bad. Yeah, hopefully I'm just wrong and they're there and I missed it.

Anyway, next, Aurora was ranked as one of America's fastest growing suburbs. So they were ranked number 8 on a Realtor.com list of America's fastest growing suburbs. Ahead of them were places like Apex, North Carolina, Frisco, Texas, Scottsdale— excuse me, Scottsdale, Georgia, and Arabi, Louisiana.

They noted that Aurora is growing, you know, basically because the Denver metro area is growing. Lots of jobs coming in and people need a place to live. Yeah, I thought it was interesting. You usually hear about how Denver is growing so fast, but to hear, you know, the suburb story here was interesting. The price appreciation of housing, 19%.

That's incredible. It is crazy. So pretty soon we won't be able to afford to live in Aurora either, right? That's right. That's right.

Well, I basically, when I first moved out here, the first place, it was technically Denver, but, you know, if I walked across the street, it was Aurora. You know, so that I think a lot of people came out and were, hey, there's a cheap place to live down here in Aurora. And so that's, I guess that's not going to exist nearly as much anymore. Oh well. Next item is a company named System76 has a new manufacturing facility in Denver.

Yeah, so we had talked about System76 on the show, um, I don't know, a couple months back maybe. Uh, they make Linux-based, uh, computers, right? Servers, desktops, laptops. Um, and they had committed to bringing their manufacturing back from overseas and decided to build their factory here in Denver. So the, the story, I guess, shows the— a lot of pictures of them moving into this facility and starting to get it set up.

So that's pretty cool. Yeah, I'd be interested to follow that blog over time if they're going to keep posting pictures as they set up the manufacturing. It's interesting that they call out the fact that it's manufacturing, not assembling computers, because assembling can be done anywhere, right? But to actually build the components here in Colorado, it's pretty interesting and it's pretty cool. Uh, next, uh, Conga, which is a startup here, although they're getting pretty large, announced that they are establishing their global headquarters in Broomfield.

So Conga was based here and started here. They do some services that help people use Salesforce in various ways with contracts and other things like that. And they had been looking, I think mostly through acquisition, they had acquired several companies this year to set a global headquarters and they ended up settling on Denver. Yeah, Broomfield in fact, right? And what I understand is that they got something like $8 million in tax credits to do so.

Yeah, that's pretty compelling in terms of trying to make that decision. I, I would be happy to live in Broomfield if someone wanted to give me $8 million to live there. So good stuff. Uh, next up, Denver's Galvanize acquires San Francisco-based Hack Reactor and secures $32 million in funding. So first off, that was their Series C, $32 million in funding.

That's, that's a great round of funding there. Um, so they're obviously off to the races, those guys. They're doing really well. And of course, Galvanize does, uh, training and, um, you know, sort of work co-location, other, you know, for startups. Um, I think that they, you know, even had some accelerator functionality at one point or another.

And so then Hack Reactor is a, uh, is another sort of coding boot camp or training facility, and it just added some more, more, uh, places where Galvanize would now have a footprint. So yeah, with a name like Hack Reactor, I certainly hope that they're teaching secure coding practices. You would hope so. But I don't think that's the focus of, of their you know, their organization. But pretty cool though.

Congratulations to Galvanize. They seem to be doing really well. Yep. Next, there was an article about the, the Colorado Secretary of State race that's going to be happening this fall and how cybersecurity is going to be involved in that. So the current Secretary of State, Wayne Williams, actually has a Democratic challenger, Jenna Griswold, and this— she is looking to be the first Democratic Secretary of State since the '50s.

There was actually— sorry, elected. There was one person that was appointed for part of a term that was a Democrat in the 2000s sometime. But that's pretty incredible that it has been a Republican-held office since the '50s. And of course, the cybersecurity component here, the Secretary of State's office is in charge of election security. So the big concern over election security And what they're gonna do around that is definitely gonna be a major point in the campaign, which is gonna be interesting to see.

Yeah, it's interesting that, and I hadn't heard this before, but that DHS, Department of Homeland Security, has designated election systems to be critical infrastructure. It's, I would agree with that completely, because meddling in elections is definitely sort of dangerous territory that could lead to, you know, pretty, pretty severe consequences. Yeah, for sure. And we of course know Rich Schliep over there at the Secretary of State's office doing great stuff to make sure that we all stay secure.

Next up, there's a new Colorado law that allocated $1.2 million to bolster CSU cybersecurity education. The new law is titled Cyber Coding cryptology for state records. So I think the focus of the law itself is to try to improve the security of state records, kind of following the breach earlier this year where 2,000 computers at the Colorado Department of Transportation suffered a breach. So I think that's a good thing. It's good that CSU is seeing some of that money as well.

Yeah, um, actually, when Debbi Blyth last week, um, co-hosted, um, we— she talked about some of the CDOT stuff because she was very involved in the response for that. And I, I'm hoping we're going to get her on in the future to talk about more around that. But back to this article specifically, you know, we had talked about the bill that, that this came from, and mostly to make fun of some of it. Because, you know, one of the things that they put in the bill was that they should explore new technologies like blockchain. You know, we thought it was kind of silly that you put something like blockchain into law.

I mean, yes, okay, let's explore technologies, but maybe let's not specify which ones. Anyway, some of the money is going to go for programs at CSU. Most of this, I think, is at the main campus, but also some money and activities already underway at CSU Pueblo. And then finally, they're going to use some of this money for a research project that is already ongoing that they're doing in conjunction with DHS called NetBrain, which is aimed at detecting and mitigating denial— or excuse me, distributed denial of service attacks. Can't talk.

Yeah, it's interesting to see how we can do better at mitigating distributed denial of service attacks. It's a difficult problem. Right. It is for sure. All right, next, Overwatch ID had an announcement this week.

They moved into a new corporate office. So, they're at 900 South Broadway, much bigger space than they were in before. I think they have something like 9,000 square feet or something like this. This is in one of the old Gates buildings there, kind of right by GTRI and hosting.com. So, congratulations to Overwatch ID, doing good stuff there, continuing to grow.

Yeah, it appears that they, you know, will be able to focus on growth in, you know, their professional services and customer support departments. So it sounds like they're going to be hiring some more people and fitting them in. Yeah, and we've talked about some of their jobs in the past, so I would say keep an eye out on their website if you're looking to work for a startup.

Next up, Red Canary posted a blog called Build vs. Buy. Not mutually exclusive. This was actually an older blog that they had written a while ago, and then they republished because it's just so relevant to companies today trying to make this decision whether they want to build or buy their security technology. I think that the— it's such a tricky area because we get this feeling that if we can build it ourselves, we'll be able to sort of have control over it, you know, ensure that it's got the features and functions that we're looking for. But at the same time, most of us are not, you know, software developers, right?

A lot goes into that. Yep. It's a big challenge. Yeah. And the blog was written by Keith McCammon, who's the chief security officer over there.

And I think one of the things I liked best about the article was oftentimes people look at it as a binary, right? So either build or buy. And, you know, he kind of went into, well, you know, maybe you should do a little bit of both, right? So, you know, build a little, buy a little, you know, buy some things, build some things. I definitely think there are times when it makes sense to build.

And also, it obviously depends on the makeup of your team, the makeup of your company, right? You know, if you have a software development sort of culture at your company and you have exactly that sort of resource, yeah, maybe it makes sense to build stuff. If your company just buys a lot of software off the shelf, maybe you're better off buying things for your security technologies. I think we've got to be honest with ourselves, right? We've got to know who we are before we make a decision like this.

But one of the key things that came out of the article that I thought was just really, really important to all of us is that when you do buy a third-party technology and bring it in, you have to be ready for it. Yes, and it's a, you know, it's sort of cliché, but it's the people-process-technology story. You have to have the people who are going to be able to run it and the knowledge of, you know, how it works. You have to integrate it into your processes, your operational processes, and so forth. And every time I see sort of a failed software implementation, usually it's because of that sort of thing, is that the organization really didn't prepare in one of those key areas.

Or they're not mature enough to be able to use it. People often say, hey, here's a really cool new product. I'd love to use that. Let's go get it. Right.

Well, you know, maybe you should work on some of the basics first before you go, you know, get something, you know, fancy and shiny and blinky. So anyway, good article. Next, there was an article by SecureSet, actually one of their instructors over there, and they were talking about Formalizing Cyber Threat Intelligence Planning. So this was by Chris Rule, who's an instructor at the Denver SecureSet campus. And really, this is just the first in a 10-part series.

So this is sort of the introduction to the whole blog series. And honestly, I'm really looking forward to hear the whole 10-part. And it's really looking into, you know, security intelligence and the sort of government approach to actual intelligence. You know, we think of intelligence much differently, I think, than they do on the, you know, the military, uh, sort of government side. And this is really diving into the sort of formal processes that they have, um, and kind of pulling that into cyber and being more formal about it.

Yeah. And then this first, this first part 1 of the series, what he focused on was trying to understand your threat or your adversary and looking at the 3 sort of main dimensions: capability, knowledge, and intent, and really trying to dig in. And even if you don't know your enemy very well, apparently you can do a pretty good job of trying to figure out what they'd be going after in your organization, what they'd be trying to attack, right? Yeah, good stuff. Our last article for this week is Enriching your security data with LogRhythm and Kibana.

So they had just announced this, that they've got an integration with Kibana, which is an open-source data visualization tool. And what's really unique about this, or interesting, is that, you know, LogRhythm does a really good job in gathering log sources for you and and parsing and normalizing those log sources so you can do the types of queries and analysis on top of these large datasets. And what they've done here is they've allowed you to integrate with Kibana, which would give you an opportunity to do data visualizations, for example, of large datasets that have been collected in LogRhythm. And data visualization is a very powerful tool for humans, right? We like to look and see patterns in the data.

And so sort of going above, you know, it's more in this threat hunting kind of realm if you're applying it to security data, of course. Yeah, I also think it's really cool that they are— they're willing to announce sort of an integration with an open source project like this. I think many times vendors don't want to have you use other tools. It's like, only use our tools You know, because that's what we want you to— that's what we're selling them to you for, right? Um, and they realize, hey, Kibana is a great tool.

Um, maybe it does data visualization differently or better than what we do in the tool already. And instead of you having to replicate the data that you already have in LogRhythm to somewhere else, right, hey, just, just point it at your LogRhythm data and now you can do this visualization. So I think that that's really cool. Uh, so that's it for news. Before we move off of that, I do want to remind everyone that the voting for CTAs, APEX Awards, CISO of the Year, and the other awards are still open.

So if you want to nominate someone, go out and check that out. We'll have a link in the show notes. And with that, let's move on to the Slack Message of the Week. So the Slack Message of the Week this week was by Zach Meyer. Zach started a discussion in the Slack board around managing open source software in the enterprise.

So He asked a couple questions, spawned a great discussion, so we wanted to thank Zach for doing that. And we also wanted to thank Andre Gaeta, who is our sponsor of the Slack Message of the Week. So we will connect Andre and Zach, and Zach will get to order something from the Colorado Equals Security store. So pretty cool. Moving on to events.

First, of course, we have our event calendar. So if you go to colorado-security.com/events, Click on Events, you will see the entire calendar there. We do have events all the way through the end of the year pretty much, so go check that out, get your schedules in there.

First event to mention is the GDPR Meetup at Hosting.com. It is taking place on July 24th. Next, SecureSet is doing their Expert Series with Douglas Brush on the 26th. The Denver location. And following on that, they are also doing their Experts series in Colorado Springs with Matthew Titcomb on July 26th.

ISSA Colorado Springs is doing their first of 5 CISSP exam prep sessions on the 28th of July. This is a 10-week process. They do 5 weekends every other week to help get you prepared to take the CISSP exam. That is great fun. Great fun.

SecureSet is, is busy this month. They are also hosting in Colorado Springs their Hacking 101 Application Security. And then finally, our last event in the next 2 weeks, SecureSet is doing the Beginner's Intro to Capture the Flag, and they're doing that here in Denver on the 3rd of August. So that is it for events. Let's move over to jobs.

First job we have, Cognizant Healthcare is looking for an Associate Director of Healthcare Security Architecture and Corporate Security Leader. Coalfire is looking for a Director of Cyber Risk Services. Awesome. Western Union is looking for a Senior Manager in Internal Audit. Markito has an opening for a manager of security operations.

US Bank is looking for a senior cyber defense engineer. This is actually one job that was put in the Slack channel this week. Um, and this is something that can, you can work from anywhere. Spectrum is hiring a security engineer 3. That's of course 3 times better than a security engineer 1.

Uh, and Medkeeper is looking for a senior cybersecurity engineer. Jeffco Public Schools is hiring an analyst of information security. And keeping on the school beat, Denver Public Schools is looking for an information security administrator too. And finally, GBProtect is hiring a security operations center operator. Awesome.

Well, that is it for jobs, and that is it for the newscast. Coming up will be our feature interview from For this week, Robb interviewed Brent Wentworth of Level 3— excuse me, CenturyLink. They're not Level 3 anymore. That's right. Sorry about that.

So they had a great conversation, so look forward to hearing that. And Chris, appreciate your time. Thanks for co-hosting. Thanks for having me, Alex. Awesome.

Talk to you guys next week.

Hi, this is Vincent Grimard, CSO at Nelnet. Welcome to Colorado Equals Security, for Colorado security professionals by security professionals.

This is Colorado Equal Security. This is Robb Reck, and I'm here today with Brett Wentworth. Brett, I want to talk a lot about what you're doing around security operations and talk about your role over at CenturyLink, but first I want to talk about something else you've been doing for fun. I understand that you have an impressive freshwater— saltwater, saltwater, saltwater fish tanks and aquariums. So talk to me about, number one, what's this hobby like, and And what's the coolest thing you've got?

Well, so yeah, I started doing this about 15 years ago, and I started off with a 55-gallon tank with just fish, um, to graduate up to live rock and then to coral and then to larger reef tanks. That's something I gradually started to do out of trial and error. And believe me, it's a lot of, a lot of trial, a lot of error. You, you make a slight mistake and the ecosystem is completely out of whack, or you, you buy something that looks cool in, in the store and yet ends up eating half of your, your livestock and You're like, okay, I was a pretty bad, a bad owner there. So it's, it's been a lot of fun.

We go home, you look at the tank instead of the TV. Definitely takes the blood pressure down after a long day at work. Recently actually acquired a peacock mantis shrimp, one of the more rare things to come in the trade. I, I went on the website where I normally buy, buy my livestock, and I clicked on the, hey, email me if this comes in the stock, and I forgot about it 2 years ago. Uh, got the email, it was about a month ago, and I guess, okay, uh, we're doing this, a peacock mantis shrimp.

And if you're not familiar with what they are, they are a very unique creature in the world. They have the most complex eyes in nature. They have, uh, they have where we have 2 cones or 2 sets of cones in our eyes, they have 12. So they can see, some say, upwards of 2 million more colors than what humans can see. So Yeah, it's pretty crazy.

They put them in the tank and they sit in their cave and they look and their eyes are moving around and you know that they're seeing maybe into the future or something with their crazy eye vision. The second thing they have is this club and this club is folded up underneath their belly. And when they go and they hunt, and that's what they primarily are is a hunter, taking out things like crabs that are 5 times their size, it makes this sound that you can actually hear through the aquarium. It's the force of a .22 caliber bullet. And they say that you don't want to put your hands in the tank to do cleaning because they're nicknamed the thumb splitter.

So yeah, so I have a lot of good fun things to look forward to with this pet. Hopefully that doesn't happen, but if it does, maybe it'll be a fun battle scar that I can talk about when I'm a little bit older. So a couple things to say here. Number one, anyone who's listening who's not driving right now, you should Google what a peacock mantis shrimp looks like because I got it up in front of me right now and it is the most amazing looking creature I've ever seen. They're pretty cool.

Yeah, it's like a rainbow in a crustacean. It looks like something like an alien. It definitely looks like an alien here, I'd say. Is it primarily green? Yours primarily green?

So mine is a lot of red and blue in the tail. They come in different colors and then the shell is kind of a more military green. But yeah, they look— if you're picturing it, they're like a praying mantis in the front. A lobster in the back. And yeah, that looks about right from what I— from the picture I'm looking at.

The lobster in the back especially makes perfect sense. Um, I've— I had a guy who worked for me at Pulte, Chris Sorensen. Hi Chris, if you're listening, who was another saltwater aquarium guy. And he, he was telling me that like he had coral growing in there. He had it for a lot of years, coral growing.

And eventually he found out that the coral that was growing in his aquarium was worth like thousands of dollars. Because it— I, I don't understand that exactly. But so there's people that they have their own businesses where they just have grow facilities in their basements where they have lots of powerful lights and they have coral. And, you know, that might be— they're doing something else, I don't know, I'm not going to judge. But they think the facilities are for when people knock on the door, it's to grow coral.

And, uh, they, you know, they can frag it and they can split it off and then it'll grow into 2 pieces of coral. But yeah, I have stuff in my tank that's been there for 10 years and I took it down to the pet store, could probably get some money. So maybe that's my retirement coral. There you go. Uh, so how big— how many aquariums do you have?

Uh, so yeah, there's 2 that, uh, that are saltwater, and then I have 2 that the kids have set up that are more for freshwater and turtles. Yeah. So when people come over, there's definitely an animal farm with, uh, the turtle tanks and the saltwater tanks and the cat and the dog and you know, the kids. And how big are the tanks? So the reef tank is 180 gallons.

So if you picture that in terms of water weight, that's about having a car in your living room. How physically big, like dimensions? Okay, so it's about 6 foot long by 3 foot wide and about 3 foot tall. So take up a whole wall. It's big.

Yeah, it's like a piece of furniture. It's definitely a piece of furniture. Definitely had to hire movers to get this thing into the house. Even without water, it weighed about 3 350 pounds. So yeah, it's fun.

Well, that's fun. Worst things to do with your money, I guess. Maybe my wife says otherwise, but yeah. Well, if you had to grow lights for a different purpose, that's, that's one of the worst things. We're in Colorado, just remind people.

This is Colorado equals security. There you go, it's Colorado. Well, awesome. Um, let's, let's dive into, to your background and, uh, let's start off with where are you from? So I am from, uh, Andover, Massachusetts, which is about 20 minutes north of Boston.

Okay. I spent about 20 of my first 21 years in the East Coast around New England, so mostly Massachusetts, but also a couple years in Vermont, New Hampshire, growing up on the ocean, rooting for the Red Sox and the Patriots and, you know, the Bruins and eating clam chowder and every— all that stuff. So this summer when I drive from Boston to Maine, am I going to drive through Andover? Yes, if you take 93, you absolutely will be. Is that the way that the the Maps app is going to take me?

Probably. If you're going from Boston, 93 is the main turnpike that goes through. Perfect. There you go. You can wave to Andover on the way by.

I'll wave and say hello. Good stuff. So you grew up there. You went to school out there. Yes.

Did you go to college out there, or was it just high school? Yeah, I said 20 out of 21 years. The other year was my sophomore year in college, and that was actually to come to CU. So I decided I wasn't sure I wanted to go to the business school that I was at. I went to a small business school called Babson College, and I was more of a free spirit back then, and CU seemed like more of the liberal arts mecca that I was yearning for at the time.

You know, I think it was the number one party school, not that that influenced me at all, but decided to, you know, make the pilgrimage out and had to come back to Vermont to finish school off there as an English major because of family reasons. I would have loved to stay in Colorado, but yeah, I came back, finished finished school in Vermont and sort of had an itch in the back of my mind about coming back to Colorado someday. So what happened after graduation? So after graduation, I lasted— I guess before I do that, what would you major in? So English.

English? Yeah, back when you could do things like that and sort of get a liberal arts degree. I really didn't know what I wanted to do, so I can't really do that today, sadly. But I'm a history major. Are you?

Okay, so we can definitely— no judgment here. Okay, I can read. Books and I could type a mean email. And that's just about the same skills I learned from my— Yep. So I got one job in the family industry.

It was in the semiconductor space in sales and found it wasn't really for me after graduation. And, you know, that itch that was in the back of my mind finally got a little bit too big. And one day after about 6 months after graduation, I packed all my stuff in my car and drove out west and showed up on my friend's doorstep and said, hey, mind if I crash on your couch? And they're like, okay, nice to see you, Brett. And I did.

And after maybe a month, my parents were wondering what I was doing with my life and if I was going to get a job or if I was going to come home with the tail between the legs. And I got a job at a temp agency out of Boulder that put me in with Level 3 Communications. Wow. So basically was a temp in the customer care department. Level 3 at the time was an offshoot of Peter Kiewit and Sons.

They were a construction company, and that was a big reason why we were able to lay so much fiber at that time, is because they had the right-of-ways along the train tracks. So they would actually pull the trench devices alongside the train cars and then just unspool the fiber as they went. And that was actually a huge leg up for us to be able to lay that bandwidth. So at that time though, they're also experiencing a massive growth spurt from a customer standpoint, growth spurt from an employee standpoint, and there were a lot of outages and people that were in the customer care group that were opening tickets wrong under the wrong circuit ID, not closing tickets right, and customers are asking for credits and there was really no leg to stand on. Yeah, so my job was to come in and analyze those tickets and make sure that people were doing the right closure codes, you know, under the right circuit ID, close it at the right time.

And it was pretty mind-numbing, but I was pretty— I was just happy to have a job in Colorado, and that's, that's kind of what brought me out here. So before you made the drive to Denver, did you read On the Road by Jack Kerouac? No, I have not read that one, but I've heard about it, and it's probably— it would have just been— it sounds like you would have— it might have been the inspiration. Yeah, yeah, from the East Coast to makes the drive. He does it, he stops in Denver and then he continues on to Los Angeles.

Yep, Route 66, right? Parts of it, most of it is on— well, there's a lot of it on Route 66. Yeah, yeah, interesting book. All right, so you started as a customer care temp, right? Yes.

So I assume that's not what you're doing anymore. That's not what I'm doing anymore. I, I wouldn't be on the show if that's what you're still doing. Yeah, so it was actually fairly rapid for me to get my foot in the door in the security space. Yeah, the reason why I'm in security is a person by the name of Terry Tickle.

Terry Tickle is a fairly notorious spammer, is a very unusual spammer for the time, and this is 1999. So what Terry would do, and she claimed to be a girl, would send emails to, you know, mass, mass emails to newsgroups, to message boards, to Usenet, saying, hey, if you're a young attractive man, send me pictures or videos of you getting tickled and and I'll send you money, I'll get you concert tickets, I'll give you whatever, here's a list of stuff, I have references. And the person that was doing abuse for Level 3 at the time was used to doing about 30 complaints a week, but because of Terry Tickle and sending all of these unsolicited emails and bad, you know, hey, I don't want this, there's a lot of people that were pretty upset about it, it went up to about 3,000 a week, and the person that was dealing with abuse just couldn't handle it, I was done with my analyzing tickets job for that day and I said, hey, I can help you if you're getting overwhelmed. That looks kind of interesting. I don't know what you're doing, but you're talking to a lot of people that seem pretty angry.

So I offered to help. And the reason why this was on our network is Level 3 actually had a lot of the managed modem banks at the time. So we provided service to companies like EarthLink, like NetZero, like AOL. Where we leased these modem banks and their users would dial into these phone numbers and they would be Level 3 phone numbers, but we would use RADIUS to pair it off with the ISP, give them— add them to the domain and authenticate them and get them an IP address. All of the IP addresses were Level 3 IPs, so the way it worked back in the day, still sort of works this way, is you have a problem with somebody or somebody does something bad, spamming, port scanning, hacking, things like that, You look up the IP, see who owns that IP, and then you send abuse at that company.

Right. So I pretty much helped manning the abuse desk. And so what did you do when, you know, there's 1,000 reports about the same email? What did you do at that point? So 20 years ago?

Yeah. So we had zero automation at the time. And what you would have to do is essentially sort it by subject line and you'd see that this was all from the same Terry Tickle spammer and you'd see that in the subject line, it was— a lot of times people include the IP address or the date/time, and you do your best to try to look up which account was doing that activity at that time by logging into our RADIUS logs. And from there, you could work with the ISP, you could block the phone number, you could block the IP address. Highly manual work, but I didn't really realize it at the time, but I was gaining a lot of rudimentary security skills.

Yeah, you know, I was learning routing, I was learning TCP/IP, TCP/IP. I was learning just basic Unix from logging into the RADIUS servers and finding the users. From my standpoint, I was pretty non-technical. I was an English major, but I was really liking it. I was liking the investigative part of it.

I was liking the helping cleaning up the internet, and happy to say that Terry Tickle went away. We worked with the FBI, and it actually ended up being a he. It was a male guidance counselor. Not a surprise. Yeah, not a surprise at all.

One thing I learned actually is that there's a documentary on HBO about this person that came out in the past year. I have not seen it, but— so was this person— you gotta be curious about this whole scam, right? Yeah, it sounds to me like probably this was just a proclivity of this person and there's no— there was no monetization, correct? Yeah, it was, it was this person's twisted desires that he had. Yeah, exactly.

And, uh, a lot worse things you could be into, I guess, than Yeah, I mean, sending it to maybe underage people got the FBI involved over state lines, shipping the videos, because some people said, hey, I want concert tickets, I'll do it. And, and maybe you have a federal offense at this point. Exactly. So was he actually giving this stuff? Allegedly, yeah.

Oh my goodness. Yeah, so from what I've heard, again, I haven't seen the documentary. I plan on looking at it, but he was a trust fund kid that had too much money. Much time on his hands and had proclivities, as you say, and would actually do it, but didn't realize that there would be some extreme negative ramifications, including getting me a job in security. So not all negative.

We have at least the one positive there. So you volunteered one day after you're done with your tickets. You started diving into it. Did it become a full-time thing shortly thereafter? So yeah, I think it became a full-time thing within about 2 weeks.

So within about I'd say 2 months of joining Level 3, I was full-on in the abuse desk, and it did not slow down much from there. It was kind of the, you know, the increase in spam. And at that time, there was no spam filters or, or, you know, email filtering, or even like personal firewalls were fairly uncommon. So people wanting to hack or port scan or DoS people, like all of these complaints would come into abuse, and it made for an interesting day. There was always different stuff going on, and And yeah, full-time.

And I'd say probably the first 2 years of my, my time at Level 3 was almost exclusively on the abuse desk side of things. Hmm. How many employees did Level 3 have back when you were hired? So I would say it was about 1,500 to 2,000. And a lot of them were in the Interlochen— well, actually at that point Interlochen wasn't even open yet.

So it was in the Church Ranch area around 104th and And yeah, so, so, you know, a mid-sized company but not the enterprise that it was going to grow into. Yeah, awesome. So yeah, you did abuse for a few years, and what was next step for you? So I would credit the, the next phase in my evolution to Dale Drew. Dale Drew grew to be the Chief Security Officer at Level 3, but he joined in '99 also.

He joined as a security engineer, and his job was to design and architect solutions that would protect the corporation, the enterprise. His frustration was there was nobody to operate these tools, and he did not want the engineering team to design and then operate them because then they couldn't move on to new projects. So I kind of worked with him and said, hey, if you got stuff that you want operations to start looking at, we got a team of, I think, 5 people at that point. So we started to lay in an additional layer in additional things doing The abuse work was the operations team. Yeah.

Yeah. So interesting. Yeah. Yeah, we kind of— we grew the abuse team and started layering in like 2-factor authentication and RADIUS in like early 2000s. Were you doing that?

Mm-hmm. It's pretty good. Yeah, it was good. Yeah, I just said, hey, little RSA tokens. RSA tokens.

There wasn't even soft tokens at that point, and they would expire, and then you'd have a pile of them, and then we'd— totally. Yeah. Was it like 2006 they came out? This company PhoneFactor came out with like the The first 2-factor that wasn't hardware token that I could— well, there was the grid cards, which is not fair to call 2-factor in any real way, but there wasn't a lot of options back then. Yeah, yeah.

So it was authentication and layering things like the support of the antivirus on the workstations, the perimeter firewalls, lawful process like getting subpoenas and court orders from It was usually like, who owns this IP or who owns this phone number, nothing super complex, but started getting a lot of them. Yeah, I mean, I'd say from there it was the first 10 years of my experience was kind of growing that enterprise security function, and abuse always stayed part of it, but we grew other stuff to join in as well. Yeah. So Dale was kind of developing an engineering function, and you'd started developing the operations function simultaneously? Absolutely.

Yep. So my, my boss at the time in the operations side was Ken Hartling. He's now one of the higher-ups in security over at the Sands Casino, so I still stay in close contact with him. So it's pretty much Dale and Ken with architecture and engineering and operations, and we were pretty much separate entities until I'd say 2009. And at that point, Dale became the CSO and got all of the security umbrella under, under, under one shop.

And were you guys reporting into IT? It must have been IT at the time then. Or abuse might not have been, huh? Yeah, at one point, and this is in the first 2 years, I had 26 different bosses because nobody knew really where to put us or what to do with us. Because at the time, security was just, it's kind of an add-on.

I don't really know where this belongs. So we did bounce between IT and different operations groups and I think legal at one point. But eventually Dale was in the technology group, so more of the technology architecture team, and then just sort of had operations too. So we were a little bit unique there where he was the CSO, and I think we were about the only operations team that was part of that group, but it made sense to have security all under one umbrella. So you helped develop the operations team.

I mean, honestly, going from 2000 to 2010, that's a huge difference, right? Yeah, absolutely. Over those 10 years. Can you give me some examples of the maturation you guys went through during that time? Yeah, so I think it was really the consolidation and streamlining of processes, like how we would ingest different workflows, because all of those different work injects would have to come in either through a phone call or a ticket or an alarm.

So trying to normalize that in a single set of processes, we had a wiki that would— we still have a wiki today that would kind of be a normal living document for how we can add and people can learn from the mistakes of others and update processes. So yeah, that was a big, a big thing we had to do is really to just normalize and get one consistent set of ticketing systems, one set of processes, and also an escalation protocol. You'd have to have more junior people start off at the beginning just doing basic triage and troubleshooting. And then the Tier 2 was more of the people that would work things from, you know, 2 to 4 hours and resolve probably 90% of the issues from there. And then a Tier 3 team that is more looking for the chronic issues and trying to look for trends and see what's, what's actually underlying and what we're, what we're tackling.

So at least some of what you just talked about sounds like problems that we would try and solve with a SIEM, some kind of security operations enablement tools. You know, I can't remember there being any SIEMs in 2001, 2002, 2003. Yeah. How did you go about tackling those technical problems? Yeah, so you're right, there was no SIEM.

So we essentially used the NMS tool, Network Monitoring System, that the NOC used at the time. And they had a really strong developer that was willing to really code anything if you just put that challenge to them. So we said, hey Brad, can you help ingest these logs from our Snort infrastructure and these logs from our authentication infrastructure, look for failed login attempts? And we pretty much made it into a SIEM. We had it like a right-click ticket functionality.

We had the ability to look up procedures, and that was our SIEM, I'd say, until about 2012 when we started to more in the managed security space. What would you say, and this is really a little bit of a tangent off of your work history, just to your opinion, what would you say are the core functions that you look for in, I don't want to use the word SIEM, I actually heard a great thing from Katie Winslow, who's one of the directors over at Kaiser Permanente. She said, rather than talking about a SIEM, talk about a SIEM program. Incident event management program, right? What would you say are the key capabilities in a SIEM program or technology?

So I've gone through many SIEMs, both, you know, things that we've developed ourselves but also off-the-shelf and things that were more open source that we tuned to our needs, is it really needs to be something that's adaptable and easy to configure. The worst pitfall you can fall into is you get something where you have just one guy on your team that has to become an expert in that SIEM to do anything with it. If that person leaves, which often is the case, especially if it's a commodity SIEM, like brand name thing that is marketable, that person leaves and then you have to wait 6 months just for that person to come up to speed. So I would highly recommend things that are more modular and allow for people to come up to speed on not only how to do queries but also to get new features feeds into that SIEM so you can scale that amongst not more than just one engineer but even down to the operations crew. So devil's advocate, if it's too easy, what I've seen— and most SIEMs do this, and you haven't thrown out any names, so I'm not going to either because I'm going to be not as nice about it maybe as you— most SIEMs make it really easy for me to ingest logs and then say I'm going to turn on this suite of rules for you.

And as soon as you bite into that apple of turning on the rules, you know, life is never the same, right? Yeah, like the floodgates— your floodgates are open. Yeah, and, and I, I don't mean in a good way, right? To me, that's not a good thing. False positive.

Well, but is there such thing as a good SIEM then? Well, the ones that are going to allow you to correlate across different events before you actually pop that as an alert. You know, in my experience, a lot of the SIEMs, they require a lot of that backend development to take a Feed A an X amount of alerts and feed B X amount of alerts together, that makes an alert, but without that, don't even show it to the SOC because it's not meaningful. Well, see, that's my point though, that you're talking about some extra work on the backend to make the alerts valuable, and that I agree with, that it should be, you have to do a lot of work up front to get really high signal out of those alerts, Yeah, because if you don't, it is— they make it so easy to say, hey, look, I have a pack of a PCI pack of alerts, and I've got a HIPAA pack of whatever they've got, right? They've got their, their pre-canned rules, which make perfect sense.

If I owned a SIEM company, I'd probably do that too. Yeah, but as a user, as soon as you turn on those pack of alerts, you've just doomed yourself to turning off and tuning and hunting things that are not useful for your environment. Or they're offering you pro services say, hey, you're having a tough time, then yeah, I'll smoke somebody— smoke jump somebody in there for 10 grand a day and, you know, we'll solve all your issues. So yeah, we've been through it. Um, yeah, there's no really good sim answer, but the more that it can be configurable at the front, the— as close to the front lines as possible, not at the architecture level, I think that's, uh, that's at least what we've had success with.

Okay, um, what, what about— so we talked a little bit about SIEM being— I'm gonna stay on SIEM because I think it's, I think it's such a— a lot of people listening, uh, have a SIEM, and I suspect that very few— it's a 4-letter word— very few of those people like it, right? So we talked about SIEM as maybe a log repository, seeing as a correlative tool. Yeah, SIEM as a workflow tool. You talked about, you know, kind clicking and starting a ticket from that. What about enrichment from a— do you look to a SIEM to give you enrichment of your data?

'Cause I know you guys do a lot of that type of stuff. Talk to me about that. So we have essentially, well, we have multiple views, but we use our SIEM to be both of our near real-time view of alerts that require the SOC to respond immediately because we definitely have products that we support and other issues that require 5-minute or less response time. So we have to make sure that the SOC is repeatable going after those, they know what to do. In other channels, we have more of these areas where we go and we could do research and we can search, all right, what other issues are happening with that same signature?

What other issues are happening with that same IP? So I think that goes to somewhat the log repository you were talking about. Um, the enrichment is obviously extra development work to, to make different feeds come together into something that is more meaningful for your environment. So that's the, the challenge, is the more complex your environment, the more enrichment you need to do so you're not spinning your wheels. And so I don't know if I answered the question, but it is a challenge.

It is, it is a challenge, you know. And I've been— I'd say that my view of a sim program has become much more complex over the years and adding these different elements to it. We, we basically within Ping built our own sim, you know, and as I divide those 5 things up, I'm exceptionally good at a couple of them, but I'm terrible at a couple of them. And, and how do you— and you have to find other ways to kind of, you know, call it a program rather than technology, right? How do you, how do you get those things other ways?

Yeah, but I haven't yet to see a technology technology that I think really checks all the boxes without the terrible overhead administration and/or false positive issues. Yeah, that's what my challenge is. Yeah, that's the pendulum, and you're going to have to deal with, with both sides of that. And there's no good SIEM out of the box. So like you said, you developed your own.

We've developed our own. We have a product that we've launched recently and called SLM, security log management, which is in effect a managed SIEM. We got that from CenturyLink, so we're actually— What's it built on? Can you share? So the ELK stack, or— Yeah, I believe so.

Yeah. Yeah. Yep. Cool. All right, so obviously we took a pause there in 2010 to talk about SIEMs for a little bit.

Do you want to keep it moving forward? What's been going on? Yeah, sure. And really the next big phase was the managed security, and that's the last big phase that I'm in now. About 2012, we acquired Global Crossing.

Global Crossing had a large managed firewall offering, so at that point, the SOC that I was responsible for not only took on that, but we also took on physical security, so all the badges and the doors and monitoring cameras. We layered on managed DDoS support. We layered on threat intelligence, which I believe recently you've talked to Mike Benjamin, who's my peer, who runs the threat labs. We also have Adaptive Network Security, which is our next-gen perimeter security in the cloud, so not just firewall, but connecting via IPsec tunnels and having IPS, IDS, web content filtering, DLP, etc. I think I just heard a few people say bingo when you said next-gen perimeter security.

Security in the cloud, so I want to understand that better, right? Sure. What cloud are we talking about? So you're talking about the CenturyLink cloud. CenturyLink, is that an IaaS, PaaS, or SaaS cloud?

What is that? Well, so it's— is it their offering? Their offering is an infrastructure as a service? Is it a SaaS product? I'm not sure.

Oh, sorry. Yeah, it's an infrastructure as a service. Yeah. Okay. So yeah, AWS.

Yeah. So you're connecting to our 40 to— that will be 60 gateways soon, which will be, you know, you home to a couple gateways, actually multiple, depending on how many data centers that you have, and then you're routing your perimeter traffic through those Cloud Firewall devices, and you're layering on additional services on top of that. Interesting. So is this basically like for enterprises to use for their distributed workforce to get the same things that you would get from perimeter control controls, or is this something that's going around services that they're hosting within the CenturyLink cloud? Does that question make sense?

It does. So you don't just need to be a CenturyLink customer in order to have this service. You can connect an IPsec tunnel or a GRE tunnel from off-net in order to do this to our cloud offering. But it's also to be able to control the security of the remote users. But we're also doing for large to medium data center companies.

So it's basically running some— running traffic through you guys as some kind of a cleaning— exactly, a filtering mechanism to say, hey, I'm gonna make sure that, you know, they're not getting malware, that they're not, you know, getting these. Yeah, I get it. Exactly. Yeah. Yeah, we call it our adaptive network security.

And yeah, we launched that a few years ago. It's starting to see some, some good ramp. DDoS is growing huge, especially with the Recent ransomware and DoS extortion that we've seen. Is that ramping back up again? You know, it's cyclical.

We often see a lot of copycats come along. I'd say that from our standpoint, we're getting about 120 DDoS attacks a day, and we see— it's not uncommon to see 100-gigabit attacks. We saw one yesterday, in fact, and we have over a terabit and a half of scrubbing capacity in just legacy Level 3, but CenturyLink also spun up a capability. So collectively about 3 to 4 terabits of scrubbing capacity. So the Lizard Squad was the big— was it, what year were they, 2016?

Yeah, Lizard Squad was, they had the big Christmas, took out everybody's PlayStation network. PlayStation network. Yeah, so they actually put their money where their mouth is and actually launched the attacks, but there was a lot of others like Armada Collective and others that just, they sent the ransomware and then people got it and said, boy, about time I get a DDoS provider. And that generated a lot of additional— I remember just a couple months ago there was a bunch of folks pretending to be Lizard Squad and sending out the warning notices, right? Which I assume, you know, it could be you guys behind it because it generates a lot of revenue, right?

Well, I'm just kidding. I'm not really accusing CenturyLink of— no. So hopefully you've heard from me is I have a passion about cleaning up the internet and doing the right thing, and that would be would be absolutely the wrong thing. That would be the wrong thing. Yeah, don't do that.

Uh, cool. Um, so you, you start talking about the MSS side of stuff. Yeah. Is this in addition to or instead of corporate security? So we had a combined global SOC, um, up until I would say about 9 months ago.

And when I say combined global SOC is my team was responsible for incident response and triage for corporate security, for physical security, and for managed security services. We did that, I think, out of necessity. It was based on resources where certain things would be going off one day, and then a different day other things would be going off. We had to cross-train those front lines to be able to say, all right, you know DDoS, but you also know physical and you know firewalls, so we're going to make you primary in this and secondary on that and tertiary on this, and then take that global force to be able to back each other up across all those different disciplines, because it was a lot of disciplines. And then recently with CenturyLink, we had the resources to be able to get a little bit more focused.

So now we do have a corporate security team that focuses on the threats against CenturyLink as a corporation, as an enterprise. And my team is the global combined global SOC for the CenturyLink managed security services. Awesome. Yeah. So as you tell the story, my thinking goes to, is as long as you were offering security services for both corporate and your MSS, that corporate would always get the short end of the stick.

It would always be the cobbler's children, you know, don't get shoes, because customers are needy and they pay your bills. That's how you have a mortgage, right? We ran into that challenge. I mean, I had a priority matrix that I gave to the SOC techs, so if this thing came in versus this thing, it's, you know, this is a 1, this is a 2, you would work the 1, even if 1 was on the corporate security security side, you would sometimes have to have those difficult conversations with the customer saying, sorry, it took us 15 minutes to get to your alert instead of 7 minutes. I mean, there's certain things to protect the business.

You absolutely have to respond to a zero-day or an outbreak or something that's going to be impacting to your business because that's going to impact all your customers. That's a good approach though to have thought of in advance. Here's the categorizations and what you look at first. So that in the heat of the moment, it's not who's yelling loudest. Exactly.

Yeah, oftentimes a squeaky wheel gets the oil, as we see. And I do appreciate now having the ability to focus on the managed security space, but I still work very closely with the corporate security brethren. We're all under one team now, which is great, and we're moving forward. Yeah, so you talked about cleaning up the internet and being a big fan of that, and I know you guys have done some really cool stuff around that, and there's some collaborations going on. Maybe a lot of folks listening might not know about that.

So talk to me about how you guys go about trying to make the internet a safer place. Yeah, so the most exciting part of that for me is what we're doing out of our threat labs. And Mike Benjamin, who's my peer who runs that team, you know, think of him more of the architecture and engineering of what is coming out of those threat labs. And he has a team of many, many folks that are data scientists and writing the algorithms that are looking at the CenturyLink backbone to see not only what are known threats, because that's what a lot of people are doing in the threat space, but also what looks like a threat, what other things are talking to those IPs that are known threats, and then writing their own algorithms that can kind of extrapolate using our unique backbone-down view to get a new list that I think is is absolutely unique to what CenturyLink can do. So every day his team sends us a list of things that we need to look at.

We block on average of 1, sometimes on average 2 command and controllers a day. We're also spinning up a threat notification system to be able to talk to folks that are both customers but also third parties that we say, hey, the following 1,000 IPs are infected or communicating with this Gafkit botnet or this Mirai botnet, or you're infected with this VPN filter thing that's going around today. So yeah, we're really trying to not only just be aware of it and look at it, but also communicate to the internet as a whole about it. We, of course, rolled out a a Threat Lab report in the last couple months where we, at a high level, said what we're seeing. But my job is to do more of the tactical day-to-day, and there's a lot of threats that we're tracking currently.

I'd say that there's about 195,000 active daily threats we see, and there's just no way to scale to that. So we're picking our battles on what we do, but if everybody can pitch in based on the info that we are finding, I think that would That would help a lot. So if— is there a link to the threat report that I could share with everybody? There is. It's off of sentrylink.com, or if you just search threat report off of the good old Google, that should find it.

I'll put it in the show notes as well so folks can download it directly. Sounds good. Any highlights from that report that you wanna hit on? Yeah, so it's showing that Mirai is not the only botnet that's really, or style of botnet that's still causing issues. There's another large one that we're tracking called Gafgit, and they're similar, but they, you know, you get all the headlines on Mirai.

Gafgit is also another one that's primarily a DDoS botnet. What kind of devices are in that botnet? Mirai was DVRs primarily? Yeah, I mean, it is. At least initially it was.

Yeah, so it's also, you know, IoT devices are certainly within there, but there's There's also just user home connections are in there too. I think you brought up a big point that our IoT and getting default systems out there is a huge problem because they come out of the box ready to be compromised. Nobody knows that they plug in their IP camera and it just, within 30 seconds, it's part of a botnet. Oh, it's a little choppy on the image right now. I wonder why that is.

It's because you're DoSing somebody. You don't know it. Or you might be mining Monero for somebody too, right? Yeah, exactly. You could be getting some Bitcoin.

But yeah, so the threat report is basically saying that there's a lot more things out there to keep an eye on. It's showing that the big high-bandwidth countries that have large fiber to the house or just high-speed internet, high-speed cable, those are the ones that are being used both as the victims, but also as the bots to relay attacks to others. So like US, Russia, China, Brazil, different countries like that. We have a graph that shows all of the different top 10 bad actors, but also victims, and there's definitely a lot of info. It's a lot of things we need to contend against.

Awesome. Well, like I said, I'll take a look at— well, I'll put the link in the show notes for it. So as you look ahead to, you know, the end of 2018, 2019, 2020, 2025, as far as you want to go, yeah, what do you see coming up next for, you know, for what you're doing at CenturyLink, or honestly what you're doing next at all personally, whatever you want to go? Yeah, so I think that right now security is such an active buzzword, and just it's, it's growing in the the media, everybody needs to know about security, which is great, but as a result, there's a lot of security companies that are growing up, and it's— I think some of that needs to consolidate. That's, that's what I'm seeing, is that there's just too many people that are doing too many things, and we need people to specialize in different areas to, to really differentiate and not just try to be everything to everybody.

You know, specialize in the things you're good at. Like CenturyLink is good at networks, and we have really solid network, you know, network security solutions. Um, so I think that's, you know, where I see it going is more threats, more zero days, more things to make you scared at night. Um, yeah, yeah, it's, it's, uh, what about for your team? Do you see any, any changes coming up for for what you're going to be doing?

Yeah, so recently I mentioned that we did combine with the CenturyLink SOC. I did manage the legacy Level 3 SOC, but I recently acquired the CenturyLink SOC too. So now I have 7 SOCs throughout the world. Um, trying to get them to one consistent operational model is going to be, you know, to call back to earlier, that's going to be the big challenge. And I think that's going to be probably a year.

We already started. I've been on the job for 2 months. I reorganized the team, or I will be reorganizing team by the time that this comes out. Yeah, so yeah, it's a lot of fun for me. I like to be able to optimize and make sure that we can do, do more with less and tackle things that maybe other people weren't thinking of.

And above all, just trying, trying to help. Yeah, so keeping in mind that this is Colorado Equals Security, are you guys looking to hire any security folks here in the Denver metro area? Absolutely, we always are, and we have 2 of our 7 SOC are in Colorado. We have one in Broomfield, and then we also have one down in Littleton, Colorado, which is kind of off the Mineral CenturyLink campus. And we have openings in both now.

One is the legacy Level 3 SOC, and one is the legacy CenturyLink. And so we have openings from Tier 1 and Tier 2, and then senior tech. My philosophy though is generally, especially the way I got into it, I like to give people a chance, you know, hire people in from the from the bottom floor, look for people that are motivated and trainable, but not necessarily the perfect security people from the get-go. We definitely like to promote from within. As I mentioned, I work with Mike Benjamin.

I also have peers in security engineering for the adaptive network security that I said, also the DDoS engineering side. So I have folks that have gone up through the ranks of my team that have gone from Tier 1 to Tier 3, 2 to Tier 3, then they can go to manager or they can go to engineer. And we've had folks that have made it all the way to architecture. So I'd like to try to keep it within the family. And Colorado is, uh, definitely a good work-life balance, and we'd like to attract people here, but we're finding they're, they're coming to us.

So what skill set would you like most like to see for those Tier 1s coming in? Yeah, so I like people that have some basic understanding of networking. Networking is all about what we do. I mean, client and host-based security is important too. I mean, there's a lot of different disciplines, but people out of the military, people that have experience in running telecommunications, people that come from the NOC is good.

That's a really good place where they have that ability to support infrastructure and respond quickly to alerts and know that triage step. But from our standpoint, we don't look for anything specific on a resume, just that you're willing to give it a shot and have some— get your foot in the door past our recruiters and we'll do the rest. Well, awesome. Let me think, any other questions I want to ask you? Any questions that you wish I asked you that I haven't asked yet?

Hmm.

I can't think of anything off the top of my head. So I guess I'll have one more follow-up thing then. What is the best thing about the Colorado security community? You've been here for almost 20 years now. Yeah.

And most of that, the vast majority of that, in the security community. Yeah. You've seen it change a lot. So the biggest change I've seen is the level of skill just in general and the security folks. You rewind it back 10 years or even 15 years ago, security was a hobby for people.

They would do something else they would be in IT and they go, oh yeah, I also have to do server security. Oh yeah, I have to also be watching for security events on this platform. Now people are going to school for it. They're becoming specialists. So when I said I'm looking for frontline security techs, by no means am I saying don't come to us if you have those skills already.

We definitely have places to hire you into. But yeah, huge change in the skill, and it seems like a lot of people want to come to Colorado for the work-life balance. And, uh, and yeah, that's our mantra in CenturyLink is we want to make sure that you're happy to come to work and you're happy to leave work and you keep coming back smiling the next day. Awesome. Yeah.

Well, cool. Thanks so much for your time, Brett. It was a lot of fun. All right. Thank you, Robb.

I really appreciate it. Awesome. Well, this has been another episode of Colorado Equals Security. We'll see you guys next week.

Learn more about the Colorado security scene at coloradosecurity.org. Colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes