All episodes

Brad Bussie, Managing Principal at Trace3

Apple Podcasts Spotify SoundCloud

In this episode:

Brad Bussie, Managing Principal of Security Services at Trace3 is our feature interview this week. News from: Molson Coors, Propeller Aero, DISCON, GTRI, Aegis, Webroot, SecureSet, Ping Identity, Red Canary, ThreatX and a lot more!

A six pack of what now?

Pot infused beer - because you're way too sober right now. I-70 is being transformed. Drones are coming to Denver. Blockchain has already made it. Girls are learning science in the Colorado wilderness. GTRI makes an acquisition. Webroot's CEO gets recognized. SecureSet a new program. Blogs from Ping, Red Canary and ThreatX.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript9687 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 78, the week of August 6th. Alex, we're back together again after a few weeks apart.

Back together and it feels so good. And this is take 2, as for those of you paying attention at home, we just recorded this whole show and I messed up the mics, so we get to do it again. Yay. So if the enthusiasm is less than you'd expect, that could be why. Let's go ahead and go through some housekeeping.

Number one, we have a Slack channel. This is a chance for you guys to get together, get to know other folks in the Colorado security community. We're over 500 folks strong on there right now, 525 last I checked. That's a lot of people. It's a good chance for you to get to know folks.

We also have a mailing list, so if you check out the website colorado-security.com, you can sign up for the mailing list. You'll get our show notes and you'll know every time we have a new episode. We also love it if you would subscribe and rate us on Apple iTunes. You can also subscribe in the Google Play Store. Let us know what you think.

We'd love to get your positive comments, and of course reach out to us if there's anything we can do better. And finally, we have a Patreon campaign. So Robb and I run Colorado Equal Security out of our own funds. So, you know, we're doing this on our own dime. And the Patreon campaign really helps for other folks to give us a little, little bit of money, help fund what we're doing.

And at certain levels, like the $10 level, you will get a shout out on the show and a t-shirt. So this week, John Hubbard, thanks to John who signed up as a new patron. He gets his shout out now. Thank you for supporting us. And we will get him his t-shirt.

Thank you, John. And thanks to the rest of the Patreons as well. We really do appreciate you guys helping us pay for what we're doing here on the show. Let's go ahead and move into the news. First thing, the Colorado Department of Transportation has taken the first steps to turn I-70 into a connected roadway.

Yeah, pretty cool stuff. They're adding some sensors through the mountains on I-70 to help detect when there are traffic problems, weather, other things like that. Alex, they coined a really good phrase. Now they've called it the Internet of Roads. How do you feel about that?

You know, that hurts me. It hurts me to the core.

But, you know, one of the good things that they say in the article is that this is projected to result in an 81% decrease of unimpaired multi-vehicle crashes. Yeah, that's really cool. They've already finished a proof of concept on this. This is actually going out to production by the end of 2018. They expect to have these sensors along the side of the road.

And they'll have telemetry set up to talk to 100 of the CDOT vehicles going up and down the roads. So it's not actually working for private citizens. It is going to— it is going out to the— just to the CDOT vehicles for now. Yeah, it should be really cool. Glad that we're doing that.

I like safety. Next, Molson Coors made an announcement that they are working on a deal to create a cannabis-infused beverage in Canada. So for those of you who are hoping, it is not cannabis-infused beer. However, it is going to be, you know, cannabis-infused something. It's going to be up in Canada.

They're, you know, a mostly Colorado company or a significantly Colorado company. So it's worth talking about here, but nothing coming to Colorado anytime soon. Next, we have a drone company that's making— that's going to be moving here to Denver. It's Propeller Aero, which is a Sydney-based company. They're coming to Denver.

Basically what they do is they make drones for construction and mining companies. And they've moved into a space here in Denver with about 12 employees. Yeah, and it says that they are looking to grow to between 80 and 90 over the next year. So that is pretty cool. I think 25 of those are going to be here in Denver.

So they basically doubled the Denver headcount. Next, we had an article about blockchain's role in transforming real estate transactions. So, you know, being working for a mortgage company, everyone talks about blockchain, blockchain this and blockchain that it's going to revolutionize everything. This particular article was about the Boulder DisCon conference, which is a blockchain conference that just happened, and one of the talks was about the sale of a house in Arvada that they were taking money using cryptocurrencies. Yeah, pretty cool stuff.

They also— the guys who talked at the conference also talked about how they expect efficiencies to be created by blockchain that could shorten the the length of a closing on a house from the current 30 to 45 days down to as short as a week. Pretty cool. Blockchain is going to save the world. Speaking of saving the world, the Girls on Rock is— this is a group that's helping teenage girls from across the country get a chance to come into Colorado's backcountry, do some backpacking, and the whole goal of it is for them to learn about science. They do experiments out in the wilderness.

Yeah. I think we know that STEM is a hot topic and pushing women into STEM is even a hotter topic. So this is a camp that gets girls into the outdoors to help them experience field sciences and other things like that. Yeah. And they, in this article, also mentioned a couple of things.

Number one, they mentioned that they are looking for sponsors. So if there's any corporate sponsors out there that want to help keep this program going and thriving, that they would love that. They also mentioned that they have some special needs folks as a part of this. So it's not just women, it's trying to open up these things to folks otherwise might not have had the opportunity to it. Next, there was an announcement from Zavaro, who you may know as GTRI.

They recently changed their name. They acquired the assets of Aegis Identity Software. So this is an IAM solution that provides software for the education industry. Yeah, so obviously congratulations to Aegis and to GTRI folks who we know here in town, Aaron. It's going to give you some new stuff to go to market with and hopefully get you guys some new customers.

So So pretty cool stuff. Uh, next, Webroot's CEO Mike Potts has been recognized on CRN's, uh, annual top 100 executive list. So congratulations to Mike and to Webroot for making the list. Yeah. And Mike is a reasonably new CEO over there.

Uh, so good to see that things are going well for him. Uh, SecureSet Academy launched the SecureSet Foundation to promote, uh, cybersecurity career education. So SecureSet, which we know is a training provider. Just started this, um, this foundation to give scholarships to help diversity in cybersecurity. Very cool stuff.

They, they mentioned for now as they start up that they're going to have the founders of SecureSet Academy as the leaders of the foundation, but they're looking over the next year to hire in an executive director and some independent board members. So if you're someone who's got a passion for education, um, maybe nonprofits, and you care about security, this might be a good opportunity for you to get involved. For sure. Next, we have a blog post that gives us a chance to talk about some national news, or really global news, that, that we might not otherwise get to talk about here on the show. Generally, we don't talk about news that doesn't impact Colorado, but Cisco this week acquired Duo Security for $2.35 billion, and, and that's a, a big deal.

So we have a podcast— or excuse me, a blog this week from Ping Identity CEO Andre Durand talking about what that means. Yeah, so First, talking about how, you know, it's a great acquisition for Cisco and congratulations to the Duo folks, but then also how security and identity have been separate for a long time, like 2 ships passing in the night. But really, for modern security, you need identity. Yeah. You know, zero trust networking, other things like that.

To enable those sorts of things, you have to have identity built into your security tools. And then really, to be able to have identity work the best, you need to have multi-factor authentication, which is where Duo comes in. Yeah, and so Cisco's obviously been known as a perimeter security company for a very long time. This is giving them the opportunity to, to move into the new zero-trust world and do so with, you know, a really loved company. I think Duo is generally considered one of the most loved companies in security, so hopefully it works out well for both.

Hopefully they, you know, Cisco treats them the right way and, and we still have a successful Duo out there. Yeah, there's a lot of talk about this on the Slack channel this week. Um, many people were skeptical that Cisco would be able to maintain Duo in the positive light that it is currently. So, uh, next, Red Canary had a blog about, uh, SANS Endpoint Survey: Too Many Tools and Alerts. So this was by Keith McCammon, who's the, the CISO over there, and just talking about how I think we all know many tools give lots of alerts, you get alert fatigue.

Um, it's, it's hard to deal with that stuff. And what should we should be doing instead? Yeah, the, the challenge is how do you get 100% coverage across your organization, which I think we can all agree is good, without having 100% overwhelmed team by all the alerts that come with it, right? Yeah, I think traditionally we think, oh well, here's a piece of data, we need to collect this, we need to keep it forever. You know, every single piece of data that we can possibly find from every particular system and tool and everything else.

We got to have all of it so that we know exactly what's going on. Yep. So moving on, we have next a blog from ThreatX, another local company, about 5 negative impacts of misaligned security strategies. And the gist of this is that there are things out there that will propel you to move really fast with your security program, whether it's a breach or a compliance thing. And as you try and do that, you might move in such a way that you're misaligning your security to the business.

You're giving, you know, we're just going to slam this security control and we're just going to lock this thing down. And there's some negative impacts of that. Yeah, so you can end up with adverse experiences for prospect or current customers, overwhelmed security teams, siloed data, cumbersome technology, to name a few. Yeah, well, that takes it to the end of our, of our news here. Let's go ahead and move over to the Slack message of the week.

So number one, thanks to Andre Gaeta. Andre has been sponsoring us for this for, for quite a while now. We appreciate it. Um, Andre actually just this week announced, uh, maybe last week announced that he's moved on to a new gig. He's now, I think it's the regional director for sales for, for Mimecast.

Awesome. Um, so he's over sales for Colorado and a bunch of other states as well. Um, and, you know, obviously he didn't, he didn't ask me to mention this, but I'm sure if you're looking for email security or whatever else Mimecast does, I know they also do security awareness training and some other stuff. I'm sure he'd love it if you reach out to him about that. So the message this week was from Ruben Booker.

So congratulations to Ruben. He had a part in a discussion this week on the Slack channel about interviewing and topics for interviewing. There was a whole long discussion on that, and Ruben had some good contributions. There was a lot of other folks in there who were, who were giving great feedback as well. We just wanted to pick out one of them and recognize Ruben for, for doing that.

Go ahead and move on to our, to our calendar of events. As a reminder, on the website colorado-security.com, we do have an event calendar. That goes all the way out through the end of the year showing all the events coming up here in the Colorado area. So first, SecureSet is having their Hacking 101 on AppSec on August 7th. Also on the 7th, we actually have a couple events that aren't on the, on the calendar.

We've just decided to do an impromptu couple of lunches. So if you're in the downtown area on Tuesday and you want to get together for lunch, head out to the Slack channel and send me a note. I'm putting something down together up in the downtown area. We've got 6 RSVPs right now. We'll see how many we get and we'll go somewhere based on that.

Yeah, and I am doing the same down in the Tech Center. So let me know if you're interested in coming. It looks like we're gonna go to Burt N's Barbecue down in DTC. So it should be good. So those aren't on the calendar, a little bit less formal.

But we have next on the calendar also on the 7th, we have the National Cybersecurity Center doing the Cybersecurity Simplified event. On the 10th and 11th of August, CSA is doing a CCSK training. On the 14th, we have SecureSet doing the career conversations with Reuben Booker, who we just mentioned. On August 14th and 15th, ISSA Denver is doing their August chapter meetings. On the 15th as well, we have the CTA doing their general assembly at RiNo.

On the 16th, SecureSet is doing one of their expert series. Uh, Cody Cornell, who is the CEO of Swimlane. That actually takes us to the end of our, of our events there. Let's go ahead and jump over to jobs. Um, we have a job from Cognizant, which is the Director of Cloud Security and Operations up in their north office, I think in the Broomfield area.

Uh, Pinkerton is hiring a Security Manager. Comcast is hiring a Security Investigator. Alteryx is looking for an Application Security Engineer. Sunrun, who does solar energy, is hiring a senior information security analyst. InteliSecure is looking for a security platform engineer for SIEM.

And you know, InteliSecure is a local company doing managed services around DLP and SIEM, so I assume you'd be working on one of their product side stuff. Digital Globe is hiring an industrial security analyst lead. Ibotta is looking for an IT security analyst. Now, Ibotta is one of those up-and-coming tech companies here in town. They do sort of coupony stuff, right?

Yeah, I think you basically take a picture of your receipt, whatever you bought, and you get some kind of points or something. I know that they are, they're growing like crazy. It's going to be an opportunity to work at a tech company that, you know, expects at some point they're going to have a really nice exit and might be fun to be a part of. Jeffco Public Schools is looking for an analyst of information security. And finally, Arrow Electronics is hiring a communications specialist focused on security.

Nice. Somebody looking to do security education and awareness inside of Arrow. It's the kind of thing that I think all of our companies could use. I know I'd love to have someone like that over at Ping. Yeah, that would be pretty cool.

Okay, well, that takes us to the end of the news. Next, we have our feature interview with Brad Bussie. Brad was the co-host a couple of months ago, and he, he runs security services over at Trace3 here in town. We had a good talk about how he got where he is and, and what's coming next. Sounds good.

All right, well, that's it. We'll talk to you next week. Thanks, Robb. See ya. This is David McGuire, Director of IT Security at QEP Resources.

This is Colorado Equals Security, for Colorado security professionals, by Colorado security professionals.

All right, this is Robb Reck, and today I'm sitting with Brad Bussie. Brad, uh, we get to learn a little bit about you here today, have a fun time helping the community get to know what you do. But the first thing I want to do is I want to start talking about something that you do that's not quite so well known. Talk to me about your writing. What kind of writing do you do?

Yeah, that's, that's an interesting thing that not a lot of people know is I write science fiction and fantasy and have done that since I was very young. I'd say my first published story was to a magazine back when I was in 7th grade. Yeah. And, and so since then you've been just developing your writing and, and what kind of, uh, um, what, what have you written so far? So I'm on my 3rd book, and my plan is that I'm going to release them after editing in about a 3 to 4 month period between books.

So I'm very much wanting to not do what, you know, the, the whole Game of Thrones thing is going through, where basically people are left waiting for me to finish something and I'm taking my dear old sweet time. So I'm gonna try to get— it's gonna be 4 books. Get those all written and then release them. Do you ever— you're a Wheel of Time reader? Yeah.

So Robert Jordan, it's one of the, you know, one of the most well-known fantasy series out there, and he ended up passing away unfortunately before he finished the series.

Fortunately for those of us who only experienced him through the books, he left notes and like a plan for a co-author to finish the series for us. Yeah, and Brandon Sanderson, he's an amazing writer. Yeah. And his other series are great, and I think he did complete justice to, to his work, to Robert's work. He did a good job.

But to your point, like, it's now as a reader, I never start a series that's not done because I don't want to put myself in that situation where I'm either waiting for it or, um, or I forget, right? Like, you have to go reread the books in order to enjoy the next one. So I just, I just wait till it's done, and if it's never done, then I'm never going to read it. It's our net Netflix culture now. People love to binge and they want to make sure that things are done.

I mean, I think the only person who's really successful right now in doing that is Joel McHale and his show on Netflix. He does it weekly. It's out every Sunday, and it's one of those things where you're kind of waiting for it. It's a little strange for Netflix to be doing something like this, but check it out. I mean, he's a little crass.

What's the show called? I think it's I don't remember the exact name of it, but it's something with Joel McHale, and it's very similar to the Soup series that he did forever. But now Netflix picked it up and he can swear a little extra and talk about some, some topics. But he has guest appearances from, from people. They just show up and it's, it's really well done and funny, and it's more of the same.

Yeah, but I was kind of missing that. But, but anyway, I digress. So, so let's get I'm gonna pin you down on some dates here. When are you gonna finish your series and when are you gonna publish? So let's be somewhat vague.

I would say 2019 is a, is a pretty safe bet to see the first book. Well, that's pretty, that's pretty aggressive. That's, you know, we're not too far off from that. Not, not too far. And I'm hoping that— I do a lot of my writing when I'm traveling.

Yeah. And you'll find me on an airplane, and it's interesting because depending on who's sitting next to me, It's, it's an interesting experience when I'm writing, and everybody does this, everybody kind of peeks over and sees what somebody's doing. And I had, oh, I don't know, he was, he must have been a high schooler, and he, you could see him reading over my shoulder, and then he would, he would look at me, and then he'd look back at the, at the writing, and then he'd look back at me again, and I couldn't tell if he was like Dude, this is horrible. Or if he was like, I am watching a masterpiece in creation. Anywhere in between.

Anywhere in between. Yeah, pretty cool. So are you planning to do self-publishing with Amazon, or what's your plan? I feel, I feel most comfortable self-publishing. I think where we are today with technology, it really makes the most sense for what I'm trying to do.

Granted, if I go back to being a boy and, and really thinking about this when I was in 7th grade, it was always my, my dream to send it to a bunch of different publishers and get picked up and, and do all of that. But I think the technologist in me now is, is very focused on the, like, the Kindle platform. It's just so easy. I mean, I've got it loaded up. I've already taken my first book and, and put it in the simulation to see what it would look like.

And it's impressive. It's, it's just the marketing side of things which could be a challenge. Well, if you're trying to make money— I don't know if you are or not— but if you're trying to make money, then, then, you know, having a publisher to help get it into bookstores and that would help, right? I'd be silly if I said I wasn't interested in the money side of it. It— I think by writing everything in advance, I'm taking some of that out of the equation because I think you lose some of your magic when you start doing something just for money.

So I— my hope is that, because once, once it's on Kindle, you can't, you can't go back. That's, that's the— what do you mean you can't go back? So once it's published, you can't then take it to another publisher. That, that book, essentially, I could take maybe the second book. Yeah.

And have Tor or somebody else grab it, but once it's published on Kindle, it's, it's theirs. Yeah, so before we move on to security, just give us a little taste. What kind of book series are you writing? So I'm writing a blend of science fiction and fantasy, which you don't see very often. So think of it as the book starts— the book and the series start very much sci-fi, futuristic outer space.

We, we leave Earth because we have to. I won't spoil it why, but yeah, basically we settle somewhere else and then that's where things really go south. And then that's where you fall more into the, the fantasy side of things, just because trying to survive, technology is not really working out the way that it should. And then you get a real blend where technology almost becomes a religion. You have a very select few that control the information, the ship that's still orbiting.

Yeah. And, and it's, and it's interesting because you have a, a villain who is throughout all of the books, even though they, they take several hundred, if not a thousand years. So it's this one kind of evil character that it's, it's a, it's a story about trying to redeem that person throughout. And then as you— my plan is, as you get to the end of the the series, it becomes sci-fi again, because we try to go back to Earth because we left because of a catastrophic event. And now we want to go back and see, did we make it?

Did anybody make it? Right? Well, very cool. That's great. All right.

Well, why don't we go ahead and change topic a little bit? Sure. Where are you from? So I am from Colorado. I say that because we moved here when I was 5.

But if we got to get technical, I was born in Milwaukee, Wisconsin. But where did you grow up in Colorado? Grew up in Elizabeth. Okay. Elizabeth, Colorado.

Yeah. And, uh, did you end up leaving for college or stick around here? What was your— So I had a very interesting college experience. I went to UNC, so University of Northern Colorado, Greeley. You're a Bear?

I was a Bear. I was there for 2 years. It was a a 2-year period where I was trying to figure out what I wanted to be when I grew up. So I went, of all things, to be a journalist. And I remember distinctly my first journalism class— and we're going to go back to money here again— where the instructor was saying basically, one of you— and this is a large lecture hall— in this class is going to make it.

The rest of you are not. And all of you that are, are thinking your writing is great, it probably isn't, just from, from her experience. Yeah. And she said, if, if it's not a passion, you should do something else. So I was sitting there going, well, I like computers.

And that is when really everything changed. I ended up leaving school and getting a job instead because it kind of shook me as far as I really don't know what I want to do. Yeah. So I left, I left university, started working on credit card terminals of all things in, in tech support. And that's really what sparked me to action and said, you know what, I gotta, I need to get into what my second passion is.

And that ended up being, you know, help, help desk slash computers. Systems administration, and then ultimately security. Yeah, so how did you end up going from, you know, working tech support for credit card terminals to getting into security? It's a pretty, pretty long road from there. Someone took a chance on me, and they, they saw that I was able to troubleshoot.

They gave me a pretty fair interview, and I had been a tinkerer forever. I mean, I Back, let's see, this was like '92. I had a bulletin board system. For, for those of you that are a little old school, you know, I had people dialing up to my modem playing door games. This was like pre-email where I was a relay for emails and things.

So I just had a passion for, for computers, for like the pre-internet And I think that, that really helped me be able to just talk about how do you put a system together. I'd built a bunch of systems. My father owned his own computer company from the time I was, I was very young. He was an IBM business partner. So I'd go back in his warehouse and put together 286s, 386s.

So I just, I had a pretty varied background, and this company was great. Let me take— gave me a job on their help desk. And really, that was the catalyst that got everything started. And that's when I went back to school. Hmm.

So I did things pretty backwards and went to— say what you will about an online school, but I went to University of Phoenix. And when was this? This was in 2002, 2003. Yeah. Got my undergrad in information system security.

It was, I think it was like the first year they had offered security. Now, I'd always been interested in how things worked, how things were put together, but ultimately how to secure them. And that comes back to a story I can tell you about me being a kid and trying my hand at quote-unquote hacking. Okay, creating a credit card generator. Wow.

And essentially I didn't use it, but one of my friends used it and he ended up getting in trouble and his parents had to pay quite a bit of money because we were— what we were doing is we were buying time for games. So back— how do you— what do you mean you were creating a credit card generator? What— how did you do that? So this was back when there were batching systems mainly. So as long as you could create a number, it— like a Visa or a MasterCard, yeah, it had the, the right first numbers, it had the right numbers in the middle, and it had the random sequence at the end, there were no real checks and balances until it went through and batched.

Yeah. So think of it as he bought time on 5 or 6 different bulletin boards And then when they went to batch, that's when it would fail. So it would essentially check and see, is this credit card number good? No, it wasn't. But you still got the time, right?

They gave you the time immediately. Yeah. So he did— we did this for, you know, a week or two, and eventually it all caught back up. As you know, this one account is buying this time, and it costs the person several hundred dollars. So his parents had to pay it back.

But that one event really kind of set things in motion for me to want to, to not be on the, the bad side of it, but to catch those kinds of things. So, you know, early 2000s, you went— you were doing help desk for enterprise, or enterprise— what kind of company are we talking about? Construction, of all things. They had a, a pretty large— I'd say 5 or 6 different states. So I was, you know, just typical installing systems and then helped them implement Active Directory.

So slowly got more into systems administration over like 3 or 4 years. Yeah. And while you were there, you were going to University of Phoenix and got your degree? Correct. And so when you were After you got your degree, was it time to change from doing sysadmin, or did you keep doing it there, or what's next?

So then I moved on to— it's a, it's a club business where it was like boating and RVs and camping. So they had a, a pretty large magazine subscription and subscription for basically when you take your RV to a campsite You want to make sure it has some amenities. And basically they had a directory and they had to kind of like a KOA. Sure. You had to meet certain standards.

So went over, went over there. I was just kind of, I was kind of jumping around looking for something. Not really sure what that was. I think, I think I was searching for that next step in my career. So what was your job at this new place?

So new place was systems network, and essentially I was in charge of a large bank of IIS servers and essentially did help desk for the first year that I was there, uh, just because it was a role where it was both sysadmin and help desk. Then I convinced them, you know what, we need a full-time help desk person. And then was doing application servers, Active Directory, some light database administration, and then started to secure the IIS servers. I had a ColdFusion backend, and I think that's when everything started to click, like, I like this, this security thing. Yeah.

And that's what led me to my next job. Which I think set me off on my career, which was a security analyst for NORAD and US Northern Command. Wow. So I got— they took— again, but no military background. No.

So how do you get a job at NORAD? So interesting. Again, someone took a chance on me. So I'm, I'm big on taking chances on people just because it really helped me. But they helped sponsor me to get my secret clearance.

So I was a contractor working at U.S. Northern Command, ended up at— it's kind of a joint command, so ended up at NORAD. Is that at Cheyenne Mountain? Cheyenne Mountain and then Peterson Air Force Base. Okay. So I was building— they call it Building 2— and was there for a number of years just learning everything that I could.

Went from a team lead to a manager That's when I got really into virtualization and into applications. So they had Quest software deployed, so they had Active Role Server, they had Change Auditor, they had Entrust. So a lot of things that maybe sound familiar, but essentially that, that really again got me interested in something a little different, and that's because the— we call them the Quest guys. So the Quest software came in and they were like, this stuff wasn't even being used the last time we were here. And I implemented, you know, a firewall around Active Directory essentially with ActiveRoleServer.

So they were very interested because it was much more secure. We didn't have any central logging when I got there. Yeah. So Entrust and Change Auditor really gave us a view into the network. And you're, you know, you're thinking Department of Defense, this has got to be just super secure.

Yes and no. I mean, you've got your classified network, you've got your unclassified network. So this was an interesting period of time of just implementing controls that were coming down from DISA, which is the Defense Intelligence. And they were essentially saying, here's the things that you need to do, and a lot of the contractors were puzzled about how to implement them. So it just made sense to me.

Yeah. And I started doing that. But long story short, Quest Software was like, hey, you know, maybe when this contract is over, why don't you come work for us? And that's really when I got into sales engineering. Interesting.

So that was your— that was your move from practitioner to the dark side of Absolutely. About what year is this? This was 2011. When did Dell buy Quest Software?

2015-ish, I want to say. All right. Yeah, I had, I had some good years of Quest Software, and it may have been 2014 when Dell— it was, it was a long courtship. Were you there for, for that long? Were you there when, when Dell bought them?

Talk to me about what's it like to, to work for Quest Software as a you know, as a standalone, and then, then when they were part of Dell? It was great, and I'll, and I'll, I'll put that in, in air quotes. It was great when we were a private company. There were very firm leaders in place that believed what they believed. We had a great culture.

Things were, things were really moving forward. And then when you get acquired by a very large company with 100,000+ employees, everything changed. The, the culture really got stepped on. It was a hardware company coming in trying to figure out how to run a software business, right? One, one thing that happened that I think really messed things up is that all of the founders and the board of Quest Software, they essentially took the package and left.

So with their departure, the vision, the leadership, all of that really fell apart. So there's, there's a lot to be said about leaders of organizations. And during an acquisition, if you can hold on to those founders, do it. Because I've been through the opposite side of things, and it's, it's difficult for a culture to survive. And ultimately, you can see what happened.

They ended up divesting Quest Software and it ended up getting— they go IPO with it eventually. They tried. Okay, but it, it was taken private again by an equity firm. So now they're, they're doing some interesting things, trying to combine— they're getting rid of parts of the business. It's just, it's unrecognizable.

Yeah, as the company that I that I was there for. So how long were you there? I was there for almost 6 years. So just 2016, 2017 you left? So it was, uh, let's see, '11.

So I left in '15. Okay. And what was your next step after that? So then I, I decided I'd like to see how the sauce is made. So I went to become a product manager.

So I was a director of product management for a software company, and it was a security software company. It's— think of it like data governance, some Active Directory security, similar product line to Quest Software. Who is it? Is it someone we don't know? No, you know, I think you probably know them.

Stealthbits. Okay, Stealthbits. Yeah. And where are they headquartered? They're in New Jersey.

Okay, but I'll credit Stealth Bits to really helping me find my voice with blogging, with, you know, talking to the media, doing podcasts like this. Yeah, and, and really just solidifying my vision of like, this is, this is really what I like to do. So it was an interesting time because the product management side of things was, was fun. But I missed dealing with customers. Hmm.

That was, that was the hardest thing for me. I had a lot of developers working for me, and I'd maybe talk to a customer on occasion, but they were typically not happy with, with a feature, or they had been asking for something for a while. I had to learn a lot about agile development, and granted, it's helped round me out, but it was, it was an interesting couple of years. And so you, you were there for 2 years, and what made— what was your impetus for moving on? So I decided after a time that because I missed customers to that point, I wanted to start my own thing.

So I decided I'm getting back into consulting, I'm starting my own business, and I turned in my notice and opened my own consulting company. Which lasted all of 3 months because started working with Trace3 and we were looking at a couple of different projects and it was, it was exciting. And then I talked to, at the time, the vice president of security. He's like, hey, I'm building a security organization and why don't you come and help me build it? Yeah, you know, I'll give you all the support you need.

You basically can do what you're doing now But you have the backing of a very large company, right? So after a very short courtship, because my boss now, he's been promoted to the SVP of consulting, he's a very influential man. He is. He's literally a rock star. Hmm.

He, he was in a rock band. Yeah, and decided that he needed to have more of like something stable for his family and So he got into consulting instead of going out on the road, but he's just got such a compelling, stellar personality that before I knew it, I was quote unquote acquired. Yeah. And, and working for him. Awesome.

Well, that's great. So, so what's your role at Trace3? So I'm a managing principal of security strategy. So you'll hear me say I'm a principal security strategist. So think of it as a blend of pre-sales architecture and strategy.

Yeah. So really, I go into organizations that are asking the question of, what should we be doing from a security standpoint? We all know security is very broad, so there's, there's points where in, in the maturity model of security, they're struggling to figure out, well, what we know, what regulatory compliance is telling to do. We know maybe what our board is asking us to do. What should we really be doing?

What are the big, big picture questions you ask to come up with those answers? I assume that there's, you know, there's more than just them asking you. You have to kind of turn it back on them. So what kind of questions are you gonna ask? So typically I'll turn it around and just ask some basic questions about Like, what are you doing from an identity and access management perspective?

Being from Ping, I think you can definitely appreciate that. Like, what does your data security look like today? Things like security operations. What are you doing from a security operations perspective? Overall strategy, you know, looking at the consultative approach.

Like you're, like you're saying, just asking some of those basic questions. When was the last time you were audited? What are the, what are the things? So I'm, I'm very much about identifying pain points. So like, what, what honestly keeps you up at night?

And I know that's cliché, but for, for a lot of these organizations, there's some things that they're, that they're super worried about, and it's just helping them identify the pain so they can get well. Yeah, so talk about your team. I know you spend a good amount of time out with customers, but you have a good-sized team as well. So what kind of services do you guys offer? Yeah, so in, in those same veins of identity management, data security, security operations, so we not only do the consulting and strategy side, but we'll come in and do implementation.

So we have partners. Ping is a great partner of ours. We have, uh, we have SailPoint for certain things, Okta. So we'll come in and, and do deployments of a wide range of technology or come in and do vulnerability assessments. So that's something that's been, been pretty hot recently just with a lot of the data breaches that have been happening.

Everyone just wants to know, how are we doing? Do we have an unpatched web server that we don't know about? You'll see a lot of customers, they've got something like Qualys, but they just want us to come in and have a second set of eyes. And like 9 times out of 10, we find systems that aren't even being discovered. We find they've, they've acquired a company and they think that they've shuttered all of the systems.

They haven't been being patched. They still have customer data. There's been some breaches recently around those kinds of situations. We've actually found those kinds of things with, with some of our customers. So how big is the team at this point?

So we're up to— so when I started, there was 6 of us. Now we're at about 30, 30 people. It's a lot of growth. A lot of growth. And as a managing principal now, my team, by the end of the year, I'll have 3 principals working for me, and then we'll have what I call like the— we call it the fat middle bench.

It's, it's basically, you know, 3-ish to 4-ish years of experience and really taking a chance on those kinds of people, taking them under our wing and, and really training them up. So my model is having a very experienced principal doing 20 to 30% of an engagement, and then you have this middle bench that's being mentored and learning from the principal. And applying the principles. I'm just looking for, for really just smart people that can troubleshoot, take direction, show well in front of a customer. Those are, those are some important things.

Being technical is, is important, but some of that can be taught. Yeah, it's the personality thing that is just so difficult in our line of work to, to find that blend. I think we were talking about that earlier. Finding that. And so often you'll hear them referred to as unicorns— somebody that's very, very apt and understands technology, but then can also give a presentation or stand in front of someone like you, like, like a CISO of an organization, and not freeze.

I see that. I see that happen a lot where they just get over-intimidated and they're unable to to communicate effectively. So if you're, you know, take that a little further, if you have advice for folks who, you know, are looking to make a change into security, or maybe they're just about to graduate with a security degree or from some kind of security training, uh, what, what advice do you have for them to really get into the industry? I'd say work on your soft skills in a lot of ways. I would say blend and, and balance yourself.

Because you can be super smart and, and have picked up a lot in school and understand security at a deep level, but if you can't interview and you can't hold a conversation with somebody, those skills don't really do you much good. So if you are still in school, take a— take some kind of a speech class. That, that's something that helped me out enormously when I was younger. I, I remember that speech class that they, they hammered away the ums and the uhs and the awkward pauses. Rehearse.

Listen to yourself. Yeah, that, that, you know, I'm gonna go back and listen to this podcast and beat myself up, I'm sure, because I'm gonna go, why, why did I say that? Or why didn't I say that? Or man, I said you know like 150 times. That's, that is my tick, by the way, you know, and just preparation is, is incredibly important.

So preparing for that interview, you know, takes— there you go, you know, just try, try to find that rounded balance of, of the technology and the soft skills. Yeah, that's great. Uh, what about advice you have for folks like me, CISOs in the community? Where, where are some common areas that you've seen for improvement that folks can, can learn from? Well, I think, I think you do it pretty, pretty good compared to some of the other CISOs that I've met and that I work with, where you're real good about networking with other CISOs and I think learning what they're doing.

That would be, that would be some advice that I'd, that I'd have if you're listening to this. Don't, don't like surround yourself in that glass prison and pretend like you know everything there is to know about security. I don't, I don't think many of the CISOs listening to your podcast are that way because we all know you because we're listening, right? If you're listening, you're learning, right? Exactly.

And that's the thing, never stop learning. You, you should be a lifelong learner, especially in security. There is no done when it comes to our craft. I mean, you, you really have to continuously consume and learn from each other, even if it's not in the same industry. I think you can learn a lot by what's happening in fintech, what's happening in healthcare.

And that's, that's something that's, that's pretty important, is just sharing and having that tribal knowledge Not just from a company perspective, but from security overall. Yeah, I think we need to share more. Yeah, that's great. Uh, another question for you, get your take on something. The, the Colorado community, obviously, you know, you've, you've been here for most of your life.

Um, what's the Colorado security community been like for you, and how have you gotten engaged? And for those who aren't very well engaged, what do you recommend for them? So having lived here for a long time, but having in the last couple of years worked other places, like comparing what we have going on to something like Silicon Valley, you know, I'd say we're still a little behind the curve as far as just what, what the private equity investors and what like the venture capitalists are doing, where they're putting their money. I think we could learn a little bit about that, like attending things like VC briefings from some of these larger firms, because I think they're actually helping to shape some of the, some of the technology and, and security that we are consuming. So like artificial intelligence, you know, that's kind of a buzzword recently, machine learning, like what, but what does that actually mean?

What's really happening with that? Why are these, these companies putting money into it? How are these startups being found? I think we've got some, some interesting startups here locally, but I don't think we have enough. I think to really compete, we need, we need more.

And people can't just think, well, we have to go to the Bay in order to get our startup funded and in order to, to do that, because I think you're in too much of a microcosm when you do that. You have not enough innovation really happening. So I'd like to see more of that from a, from a Denver perspective. More, you know, more things like more companies like ProtectWise. Yeah, you know, more organizations that they come here, maybe a little lower cost of living, maybe a little I'd say broader pool of talent, because the talent's here.

I, I think it is. It, it may be a little younger, and, you know, you don't have as many people like you do in San Francisco where they're just like, yes, this is the place to be, I'm moving there because I want to be super successful. I think we need to help foster a little more innovation here locally. I'm not sure. I'd love to know what— how do we do that?

How do we help get that innovation? Because we do have, you know, a good number of startups, um, from very, very mature ones, you know, that are no longer startups. You've got the, the LogRhythms, the Pings, Optivs, uh, Webroot, Coalfire, you know, pretty good-sized organizations that started here and have stayed here. Um, and then we have, we have some really tiny ones. But how do we— I think we just need more all the way across the board.

How do we do that? Any recommendations? I think we need a compelling event. We need something that's going to pull some of that talent here, here to Denver. Or we need more programs like I'm seeing some programs in Douglas County where we're getting kids more involved and, and more comfortable with security.

So I think, I think we should start in, in 2 ways. A, trying to attract more talent to the area, and B, seeding and developing and growing some of the talent here locally. Because, you know, I don't think there is a bad idea. I think people here need to, need to experiment. They need to, to look at, at problems and how to solve those problems.

So I think either through something like ISSA, and you do this to a certain extent, but having more focus on these young people and bringing them up. Because if— I think if we don't do that, there's going to be such a shortfall. And we've all read this, the statistics. By 2019, 2020, there's going to be a massive fallout at 1.8 million jobs open. Yeah.

So we're going to need to depend on things like AI, machine learning, and that's going to— my fear though is that's going to get rid of too many of the tier 1 kind of jobs. So then there's not going to be that upward mobility and learning to get you to the tier 3 kind of analyst. So I think it's an education problem, and we need more programs and, and just getting those young people interested. It seems like what we really need is to show that career path, because what you don't want is let's show the ideal, you know, here's what you can be. You can go be Mr.

Robot, or you can go be the CISO for Western Union, or, you know, those destinations without understanding how do you get from I'm a high school junior to being one of those positions. I think it's— you're not giving them any favors, right? But if we can show, you know, here are 10 different destinations and here are 10 career paths that can get you to those, and, you know, change it as it makes sense for you, but having that as a starting point makes a big difference. I know the Women in Security group has been talking about, I think, basically putting together kind of a quiz where you talk about what you're interested in, what your aptitudes are, and it tells you which security fields are a good fit for you. I don't care what your skill set is, there is a security job that's a fit for you.

You're a people person, maybe you're a security awareness trainer. You're, you know, you don't want to ever talk to another person, maybe you're, you know, you're doing scripting on the back end, right? Or you're hacking into stuff. There's all those different paths. And we just have to show people how to get there.

I totally agree with you. And I think it's funny, while you were— while you were saying that, I think of how many people have taken one of those quizzes like, what, what Star Wars character am I? Or what D&D character am I? And that's maybe just my, my sci-fi, right? Same thing.

But if we're willing to spend time to create something like that, how about creating something that's useful from a security perspective that helps them. Yeah. Hey, here's, here's where your raw materials would take you, and then here's the 5 steps towards that, that end state. I think that's a great idea. And can't you— and couldn't you say, and here's a mentor who's done it who would be happy to come answer questions about it?

If you, if you partner all of those things together, I mean, that's, that's all it takes to be successful, right? Right. And there's, uh, there's a small nonprofit group out of Nevada And I don't know if I can say the name, but I'm a mentor for, for them. So I— they have a Slack channel, and I sit in that Slack channel and I watch all of these up-and-comers in school, and they're asking questions like, what should I do? Where am I going?

Most common asked question is, what certifications should I take? And, you know, it's one of those things where having that trajectory, like, well, where do you want to be? What would you like to do? Well, if you're going to be an auditor, you should take these. Yeah.

If you want a good blend, then, then you should take these. If you want to be a hacker or a cracker, you know, take the, the Certified Ethical Hacker. Yeah, that's great. Uh, well, you know, kind of coming to the end of our time here, do you have any final topics you'd like us to go through or words of wisdom for the listeners? Words of wisdom.

I mean, I think I touched on it a little bit, but I would say never, never stop learning. Yeah, it's one of those things where if it's a podcast like this, if it's just picking up a good business book— granted, I, I still try to be very technical and, and security is my passion— there's things that I've learned from people like, uh, you know, Tim Ferriss, right? Listening to his podcast, reading Tools of Titans. And just picking up little nuggets of wisdom, I think just help round you out as a person and really just help the security community overall. So I would urge you, just keep learning.

Yeah, awesome. Well, thanks, Brad. Appreciate your time. Glad to get to hear from you as the, and I'd call you the head of the security practice for Trace3 here in Colorado, one of the larger companies here for us. It's good to get to connect and we'll look forward to talking to you soon in the future.

Absolutely. Thanks for having me. Have a good one.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Brado equals security.

Back to all episodes