All episodes

Dave Campbell, COO @ Zcash

Apple Podcasts Spotify SoundCloud

In this episode:

David Campbell, COO at Zcash and former CISO at SendGrid our feature guest this week. News from: HomeAdvisor, Kiewit, Crocs, Webroot, Coalfire, Ping Identity, Zvelo, ManagedMethods and a lot more!

Choking out mountain lions since 2016

I am way less badass than that guy. HomeAdvisor shines on the biggest TV stage (during the worst ever SB game). Kiewit sees reason and bring a big office to Colorado. Crocs is moving their HQ a bit down the road. Webroot to be acquired. Coalfire wants to be like us. Ping talks about API security. Zvelo talks about phishing. ManagementMethods talks DLP.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript14160 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 104 for the week of February 11th, 2019. Alex, this is Valentine's Day week.

It is. Happy Valentine's Day, Robb. Happy Valentine's Day. Have you identified who's your Valentine going to be this, this year? You're not my Valentine, Robb.

Well, I, I'm not saying I'm not. I just, you know, we haven't had the formal conversation yet. Oh, I guess I have not identified it then. All right. My, my bad.

Maybe next year. Maybe if, if, if your wife listens to this, she'll have, she'll have some ideas. So, you know, before we jump into the news, why don't we go through some quick housekeeping? We do have a Slack channel. It's, it's been very active lately with, you know, almost 800 folks on there.

We also have a mailing list. If you want to get notifications every week of new episodes and show notes, sign up for that. And you can do both of those things. You can get the link for Slack and the mailing list on our website, which is colorado-security.com, or you can go to co-sec— oh boy, I just messed that up, didn't I? co-sec.co.

Yeah, that's much easier than colorado-security.com, isn't it? Yes, it is. Much easier. Hey, let's keep moving along here. We'd love it if you would rate us and subscribe on your favorite podcast player, maybe iTunes.

If you want to provide a more monetary level of support, you can go to our Patreon page and subscribe to help us support the show. And if you don't want to provide the cash, but you do want to help us accomplish the mission of making Colorado the mecca for information security, why don't you go ahead and tell a friend or a colleague about the podcast and help spread what we're doing? Awesome. Let's jump into the news first, Robb. There was a news story this week Uh, there was a trail runner that was attacked by a mountain lion and then got him in a rear naked choke, choked him out.

So he didn't just choke him out, he choked him to death. Yeah. So mountain lions, you know, they are an apex predator, right? There's, there's nothing out there that this mountain lion is scared of. Um, and, and really the fact that a human was able to survive this conflict is just pretty awesome.

Yeah. I mean, you still don't hear a whole lot about mountain lion attacks because they still don't attack people a whole lot. They are, an apex predator, but they're not dumb either. They know that they're probably not going to eat us. So there's no reason to really spend the energy.

In this case, it sounded like it was a juvenile mountain lion, so maybe it was just a little confused. Yeah. Anyway, pretty, pretty awesome for this guy. He sounds like he was significantly injured, but not, not life-threatening. So healing up in the hospital.

Anyway, this is a pretty, pretty good accomplishment for him. Yeah, I am. I'm very proud of this guy. I can't imagine what I would have done if it happened to me. I know what you would have done, Alex.

You would have died. Thank you for the vote of support. All right. Next story. We have one of our homegrown companies here.

HomeAdvisor was advertising in the Super Bowl this year. It was not during the actual game itself. It was during the pregame and the postgame. But it was pretty cool to see them on there. Yeah, it sounded like a couple national ads and a local version of the ad.

Nice for HomeAdvisor to get some press. Talking about in the article just about overall their, their marketing vision for the year. And it sounds like maybe they're going to have some ads during the Grammys and some other things like that as well. So pretty cool to see. See, local boy makes good.

Big stuff. Next, Fortune 500 construction and engineering firm KeyWit announced that Lone Tree is going to be a new regional office with up to 1,100 jobs. You know, I don't know that I saw exactly where it is, but I know it's over by Ridgegate. So we're kind of in the same ballpark as, as Charles Schwab and Sky Ridge Medical Center over there. Yeah, exactly.

And there's soon going to be another light rail stop that opens there, down there, which I think was one of the reasons for them selecting the site. Yeah. So really cool. I love to see these companies coming in in force. 1,100 jobs.

It's a lot. Yeah. Especially considering that they're an Omaha-based company, not that far away. To have another regional office over here is pretty neat. Well, as you know, there's a lot of construction in Denver.

And if you go to any construction site, you'll probably see their logo on it. So they have a lot of business going on here. All right. So speaking of companies that are moving big offices, Crocs is moving their corporate headquarters. So good for us.

They're not leaving the state. They're actually just moving down the road to Broomfield. Yeah. So they've been in Niwot since their inception, which is, you know, a little bit north of Boulder along the Diagonal Highway there, moving down to Broomfield. This was based on some of the Colorado economic development incentives, which in this case, it does seem a little bit weird to me.

That we would give a company incentives to move from one Colorado community to another. But I guess I am not in the incentive business, so I don't know exactly what was going on there. Yeah, from everything I hear, they just didn't have the, the resources to stay in Niwot for the long term as they wanted to grow. Not enough people, not enough, you know, other stuff. Yeah.

I don't know if there was threat that they would leave Colorado and move somewhere else. In that case, sure. Okay, let's give them some incentive to stay around. Well, as we move over from kind of general area news into security news, we have another pretty big general area news as well. Webroot, which is Colorado's oldest security company, you know, they were around in the mid-'90s with SpySweeper.

They've been here for a long time. We talk about them at least every 3 months to talk about their double-digit revenue growth for the quarter. They have been acquired— excuse me, they are in an agreement to be acquired by Carbonite, the big consumer backup software. Yeah. Pretty interesting announcement.

I am sad that if they are swallowed up by Carbonite, that we will no longer have the quarterly announcements of their double-digit growth. Well, maybe, maybe they'll still do it just for us. Maybe, maybe, maybe Ashley will keep sending us those, those announcements even if it's not official. But, you know, good news for them getting bought and put into a bigger company. I didn't realize how large Carbonite was.

How big are they? They were a several billion dollar company. So I think it's, it's good. You see a lot of these sort of data protection kind of companies in the sense of backup and other things like that adding, you know, sort of more traditional security capabilities to their portfolio. So that, that looks like what they're doing, and I think it'll probably be good for both companies.

So interesting, the, the sale price here was alleged to be about $618.5 million approximately, which is really close to what LogRhythm was alleged to be, uh, sold for to Tyler Bravo. And there were news stories about Ping, uh, about 3 years ago for having sold for about the same amount. So really interesting that those, you know, 3 companies are all kind of in the same area here. Uh, I don't know if that means anything, but, you know, interesting data points. Yeah.

Well, and Webroot, as you mentioned, has been around for a long time. Um, you know, when I saw the number, I thought that seemed, um, smaller than I would've expected. You know, if you dig into the numbers, it, it seems reasonable. But just, you know, the mere fact that they've been around for a long time, but, you know, they've had some ups and downs and now seems like another, another up for them. Yeah.

Hey, congratulations for those guys. You know, they brought in a new CEO. Was that like 9 months ago? Maybe even a year ago? Something like that.

Yeah. And it seems to me like he probably accomplished his goal. Yeah. Good for them. Next, Coalfire announced that they are starting the CoalCast podcast on the first anniversary of their research and development team.

So the, the pool of Colorado-based security podcasts just got a little bit bigger, but the competition for number one No, no, no different. No, no, no. Everything stays the same. Sorry, Coalfire. The podcast will actually talk about general cybersecurity topics and current events targeted, targeted, targeted at an InfoSec audience.

It sounds like their— it's their labs team, their R&D team that is going to be doing this. So, you know, talking a lot about pen testing and other things like that. I didn't realize that their labs team had been so prolific in the year since they've been an official team. They've released 5 open source tools, 2 research reports, and a whole bunch of blogs. That's fantastic.

I mean, we have talked a lot about the Coalfire blogs on the show, so I assume that's where it's coming from. Well, we have got a chance to talk about those guys, and we actually talked to one of them, right? Brian Bershell, who, who came on the show. Yeah, Bryce. Sorry, Bryce came on the show and talked about the cryptocurrency purchase they helped with.

And he's actually going to be one of the early guests on this podcast as well. Yep, exactly. All right, moving forward, there's a podcast— excuse me, a blog this week from Ping Identity talking about API security and really giving what are some— what are 4 lessons that you can learn about how to protect data through APIs. So rather than going through all the details, just kind of summarize here. Lesson 1 was secure by design, not through obfuscation.

You know, don't assume that people don't know either that the API exists or what the different commands are for your API. Good point. Lesson number 2, don't trust apps to keep secrets. You don't want to be embedding keys into your application. You know, you need to have that obfuscation away from the actual application itself.

Yeah, definitely a good one. Anything that runs locally on a machine can't ensure security. Lesson number 3, recruit end-user input. What does that mean, Alex? I think this is really talking about looking for anomalies and getting other other details from the users themselves, as well as authentication.

And then finally, lesson 4, classify and detect anomalies. Know what normal behavior looks like. Start alerting on and acting on anomalies to that behavior. So 4 keys for securing APIs, and there's more details here if you want to read it. Yep.

Next, there was a blog post from Zavelo, 2019 State of Phishing and What Is Next for Phishing Detection. Um, they give an overview in the, the blog about, uh, phishing methods and, and what they are, are seeing that's going on around phishing. As we know, um, humans are a great target, so, uh, definitely still a target going forward. Um, and talking a little bit about, uh, ways that, uh, uh, obviously you could use, uh, their product, but in general, um, what needs to happen to better detect, uh, phishing sites and other things like that. One thing I found super interesting from this article is they have a chart showing which organizations are being, um, uh, their people are pretending to be coming from.

And they have Microsoft at 13% of all emails are purported to be from Microsoft, all phishing emails. Google's at 11%, Facebook, Apple at 10%, PayPal 6%, Adobe, Dropbox at 5%, Chase, DocuSign at 4%, and then Wells Fargo at 3%. And that was what, that's, uh, That's about 10 different ones. That makes up for 71% of all phishing emails coming from that 10 domains. Isn't that crazy?

That is pretty crazy. I would have to say I probably receive phishing emails that fake those types of companies at least once a day. So, not surprising. So, interesting stuff. There's more data in here about phishing, and if this is something you're interested in, I definitely recommend just reading through it rather than believing you got everything from our summary here.

Finally, we have a blog post from Managed Methods this week talking about data loss prevention tools and really what you need to know about those. Yeah, so the blog gives an overview of what data loss prevention is, ways that you can accomplish it, and then not surprisingly, since they can provide some data loss protection through their CASB service, you know, how it is that you could use data loss protection prevention in a cloud sort of environment. Yeah, Alex, you know, kind of setting aside the article for a second, DLP has been one of those tools that as long as I've been doing security, and I assume similar for you, it's just been one of those that it's a great idea, And it's just so incredibly hard to do well. Yeah. Yeah.

What does step one look like for DLP effectiveness, you think? I think that it is knowing where your data is. Yeah. You can't really, can't really prevent the loss of your data until you know where your data is. I think that's a hard thing still for a lot of people.

And I think it's, it's really easy to fall into the trap that, you know, because I can't be effective in stopping everything, that it doesn't make any sense to stop anything, right? Yeah, definitely. And because, you know, Well, if I block USB ports, all they're going to do is figure out a way to go to one of those file sharing sites. And, you know, because I have to allow GitHub open, then, you know, they can go through that way. Just because you can't stop every channel out doesn't mean that there's no value in stopping what you can stop.

Exactly. Couldn't say it better. Cool. Well, that's it for news this week. Let's go ahead and jump over to our Slack message of the week.

A big thanks to Andre Gaeta. Andre is local security guy now. I think he's like a regional director for Mimecast. I think he's regional director, something like that. So he's not— he's no longer doing direct sales, but leading a sales team here in Colorado.

Anyway, he does this sponsorship of the Slack Message of the Week on his own, and we appreciate that very much. Every week we recognize one of the most interesting Slack messages from the channel, and that person gets one free item, swag item, from the Colorado Equal Security store. So this week our Message of the Week goes to Ben Feld. He had a post recommending some IRC security channels. Yeah, so if, if you want to go old school and do Slack the way that it was originally invented on an IRC, Uh, there were some posts in there about what, uh, what IRC channels you should join.

It was cool. Some— someone asked like, hey, I'm looking to get back into IRC, it's been a while, any security channels? And he gave, I don't know, 8 or 9 recommendations. So thanks a lot, Ben, and look forward to a note here with, uh, with your winnings. Let's go ahead and move over to our calendar of events.

As a reminder, on colorado-security.com, we do have a calendar of events, and I'll tell you guys, it is packed, packed out through about the middle of the year right now. So you can go start scheduling out what you're going to be working on what events you're going to be attending over the next few months. Speaking of events in the next couple months, we wanted to take a minute to talk a little bit about SnowFROC. That is the OWASP conference that is coming up. Tickets are on sale now for SnowFROC, so you better go check those out before they're gone.

Front Range Open— Front Range OWASP Conference. FROC. Yeah. Yes. And snow because it is here in the mountains.

Yeah, absolutely. So big Big news about that is they have, I'd say, one of the biggest names in security as their keynote speaker at the event. Troy Hunt, uh, the— of Have I Been Pwned fame, uh, is going to be there talking all the way from Australia. Exactly. I'm personally looking forward to, to going and seeing Troy talk.

That should be a lot of fun. Me as well. Um, love the, uh, SnowFROC conference. It's one of the more affordable conferences that we have. I believe it's only $75 for a ticket.

And then there's also some training this year Uh, you can throw another $30 in there, $105 for the conference plus the training. I'm looking forward to doing that, and I am sending some of my teammates over to there to, to enjoy it. As am I. Awesome. All right, moving into other events, uh, SecureSet is doing one of their expert series with Scott Hogg talking about encryption on AWS.

That's happening on the 12th. Also on the 12th and the 13th, ISSA Denver is doing their February chapter meetings. Uh, on the 13th, is one of the CTA 101 events. So if you're looking to get involved with the larger technology community, not just security, this is a good way for you to learn about what the CTA does and get plugged in. If you have determined who your Valentine is, you can take them to the February meeting for ISACA Denver on the 14th.

I'm sure it will be riveting and romantic. And I bet— I hope that there are hearts on whatever treats that they're giving out there. I sure hope so too. On the 15th, Secureset is doing one of their capture the flag events. This is, uh, the cybersecurity hackathon Show up at 5:00 to, to get learned up on what's happening.

And 6:00, the main event starts. On the 19th, ISSA Denver Women in Security is having their February meeting with Colorado Equal Security. Robb and I will be there being interviewed for the meeting. If you've been waiting, if you've been dying to get one of the Colorado Equal Security stickers, this might be your chance. Yeah, we should probably figure out maybe we should take some other swag with us as well.

We might have some swag. Yeah, we'll see how it goes. All right. No, no guarantees, but give it a shot, guys. Also on the 19th, if you're a loser and don't want to come watch us talk, uh, the Cloud Security Alliance of Colorado has their February meeting that evening as well.

Uh, on the 20th, ACES is having their, uh, chapter meeting, which is Selecting a Trusted Business Partner. Um, this might be the first ACES, uh, event that we have on the— What is ACES? ACES, um, I don't know what the acronym is for, but it is a physical security. So if you're more guards and guns as opposed to cybersecurity. But, uh, ACES has been moving more into the, the cyber realm.

Yeah, over the years. I mean, there's this, there's this whole world where there's the overlap between physical and information security, and this is a chance for you to start learning about that other side of it. Yeah. Uh, next, CitySec is having their, their evening happy hour meetup on the 20th as well. Um, so maybe after you go to ACES, you can swing by, have a beer at Ryan House with some friends.

On the 21st, SecureSet is doing a Hacking 101 on asset management. That should be exciting. And finally, last event for the next couple of weeks is Office Hours with Davis, Graham, and Stubbs. This is a chance for you to come talk about, you know, small business law, you know, understanding what are the impacts of law on your organization. So, you know, really a chance for you entrepreneurs out there to get learned up.

Sounds good. Let's move over to jobs. This week, surprise, surprise, there are some Ping Identity jobs. Oh, fantastic. Some, some fantastic jobs at Ping Identity too.

I'm hiring, number one, a manager of security operations and engineering. Would love to talk to you about this if you're someone who has, uh, run security operations in the past and is looking to do so in a dynamic environment with a real heavy focus on AWS and DevOps. We're also hiring a GRC analyst. This is someone to help support our, our our policies, our risk assessments, uh, our compliance with ISO and SOC 2, our business continuity incident response. This can be someone with very little or no experience as long as this is someone who's got a real good aptitude to learn and, and, uh, is ready to be part of a team.

Awesome. Uh, GuidePoint Security is looking for a CISO/CIO. Yeah, so GuidePoint, I didn't actually know that they had such a big presence in town, but they've been hiring a lot of folks here. They have been. They're trying to put their CISO here.

In town. Indeed. Pretty cool. Next, Carbon Black is hiring a senior director of product security. This is really cool.

Carbon Black wants to put that person in Boulder, and this is going to be the person who helps make sure that the Carbon Black products are created securely and delivered to the market with high level of assurance. Awesome. CenturyLink is looking for an application security senior lead information security engineer. Boy, that's a mouthful, right? Pretty cool stuff.

Bank of America is hiring a senior business information security officer, a senior BISO. Well, I've never heard of a senior BISO before. Pearson is looking for a senior information security analyst. SCL Health is hiring a security analyst too. Simple Energy is looking for a security engineer.

And finally, Palo Alto Networks is hiring a cybersecurity portfolio sales specialist focused on major accounts in the West. This is actually not the only sales position at Palo Alto. They're also hiring, I think, a senior director over the whole region. Wow. So if you're looking to get in sales for one of the biggest companies and security, and you're in Colorado, this is a good opportunity for you.

Perfect. Sounds like good stuff. Well, that is it for the news, Alex. We do, of course, have a riveting feature interview this week. I got to sit down with Dave Campbell.

You know, full disclosure, we've been doing this podcast for over 2 years. I've been trying to get Dave Campbell for over 2 years, right? We've probably scheduled to meet 10 times over that time. And, you know, between our very busy schedules, it's been hard to do. But Dave was the He was the CISO for SendGrid until about a year ago, and now he's the Chief Operating Officer for Zcash.

He's also the founder of Alchemy— shoot, Alchemy, there's another word after that, right? Alchemy Foundry, or I can't remember. Anyway, of his own consulting security services company here in town. He's done a lot of really interesting stuff, and I think you guys will enjoy the podcast. I felt like it could have gone another hour on top of what we did, and it would have been really valuable.

So hopefully we get him again later this year. I look forward to hearing it. All right, everyone, have a good one and happy Valentine's Day. And, you know, go give your sweetie a hug as long as your sweetie wants your hugs. Exactly.

Me too. Talk to you later. Thanks, Robb. Hi, this is Chris Martinez, CISO at Digital Globe. Welcome to Colorado Equals Security for Colorado security professionals by Colorado security professionals.

Welcome to Colorado Equals Security. This is Robb Reck here. With Dave Campbell. Dave, I'm not going to give your title because you have so many, and we'll talk about that as we go. Sure.

The first thing I want to talk about though is how you spent 6 months about as far away from here as you can. I think geographically speaking, about as far away as you can be from here, right? Yeah, that's right. So when the first dot-com bust hit, I had been working as a consultant for Andersen Consulting, which I think by that time had become Accenture. And had been pretty burned out, had been doing security assessment work for about 4 years, mostly in Asia.

And after a particularly grueling project in the States, decided to cut the cord and basically go spend some time snowboarding. So I followed a friend of mine over to Australia and then to New Zealand. Yeah. And ended up really just winging it and snowboarding every day, living in a like a Reiki commune. What's Reiki?

Reiki is a sort of healing energy transfer work. It's pretty— it's like New Age voodoo stuff. Yeah, but it was new to me. But hitchhiking to and from the mountain every day and really getting a good solid disconnected break from tech and from hacking stuff and security. 6 months of skiing or snowboarding in the South Island of New Zealand.

It was, I think, 3 months, 3 or 4 months of snowboarding, and then when the snow melted, actually I had a guitar and a backpack and hitchhiked from the bottom of the South Island to the top of the North Island and back down again. Oh my God, that's awesome! It took me 8 weeks, and I met some amazing people along the way. The New Zealand culture was very welcoming. People would give me a ride, they'd give me a meal, they'd put me to work, and I really got to see a side of the country that I think you can't get from the Lonely Planet.

Fantastic experience. So the experience— obviously the hitchhiking to me sounds like one of the coolest experiences. Do you have any particular stories about encounters along the way, up or down, that were noteworthy and you want to share with us? Sure. I got picked up by a guy who was driving an RV.

They call them caravans over there. And this guy got me hundreds of miles. He got me across the body of water that separates the North Island from the South Island. And then took me to meet his family, and the difference between the experience I've had trying to hitchhike around the US versus the experience I had in New Zealand was just night and day. The openness, the welcoming sort of feeling, and the ability to connect and interact with people is just really extraordinary over there.

So to be fair, we're talking about 17 years ago. It was a long time ago, so it might be different now. We want to be careful with recommendations for today. Right. So then, you know, kind of diving into— I do want to get into your background and stuff.

I was looking through your LinkedIn profile and like the very first job you've got listed is as a crew and then as first mate for the Watermark. Career development. And so of course I can't not ask about this. Talk to me about what is Watermark? So back then it was actually called Chesapeake Marine Tours.

Okay. And it was a company run by a gentleman named Ed Hartman. Who was an old-school maritime guy who bought a series of pretty good-sized tour boats and ran a tourist maritime business in the Annapolis Harbor. So as a kid, the Inner Harbor or the city dock of Annapolis was a really— it was an epicenter. Is that where you're from, Annapolis area?

No, but that's where I went to high school. Okay. And, uh, well, you can't be from too far away from that then, right? I was actually born in Boston, okay, but then grew up in Northern California and Southern California. We moved to, uh, to the East Coast.

I think it was for 7th grade. Okay, so 7th grade to high school, you were in Annapolis? Yep, in Annapolis. And I remember I had done some work running cables, starting with coax and then eventually twisted pair Cat5. But I really wanted to get a job where I was out in the sun, on the sea.

And so I walked into the office of Chesapeake Marine Tours and said, hey, I want a job. And they said, well, how old are you? And I looked around and saw that there was a minimum age requirement on the wall, and I said, I'm 15, and I think I was 14 at the time. But they, they hired me, they put me to work, they taught me a lot about boats, marine navigation, the rules of the road on the sea, how to use the radio, and it was a really great experience. I had a great time being out there.

The only downside was they were all motorboats, so no sailboats in the fleet, but it was a really, really great way to connect with the water and that maritime culture out there and earn Earn a few bucks along the way. I think the starting wage out there at the time was like $4 an hour. So it was an interesting place to start. And it looks like you eventually became the first mate, which I assume means you got to wear a cool hat. More stripes, more stripes on my shoulders and the epaulettes.

And it meant that the captain would have me do more responsibilities. So I would actually dock the boat, which is a non-trivial undertaking for like a 100-foot-long 40-foot-high boat that holds 300 people. For a 15-year-old kid too, right? Yeah, it was a big deal. I felt pretty good about being trusted with those kinds of responsibilities.

That's awesome. Yeah. Well, let's get a little bit into how you got into the security world. When did you first get involved with technology at all? So started, my old man brought home an IBM PC way back in the day.

So it was the original 8088, like 4.77 megahertz. Less than 640K of RAM. Yeah. And I took to it immediately, started teaching myself BASIC, got the original. Did you buy the magazines and transcribe programs out of the magazine?

For sure. And I quickly learned how to upgrade the thing with like DIPs. Yeah. Trying to get enough memory to run Flight Simulator because I always wanted to be a pilot. And so I started with Microsoft Flight Simulator way back in the day, learning about aviation, learning about radio navigation.

And it was actually a really good Because the flight simulator required so much out of the hardware, it taught me more about the hardware too, how to rip it apart and try to get more performance out of it. So pretty much just hacked away on the machine, but the real game changer was figuring out how to connect to the rest of the world, which at the time was dial-up. So my dad again got me a modem, and it took me like probably 6 months to try to figure out how to get it going, because remember back then you couldn't just Google something. Yeah, there was no user's manual. I didn't really know how to— how a serial port worked or what, you know, 8N1 meant or how to get it going.

But once that happened and I started connecting to other bulletin boards, that's when my, my sort of the, the learning curve for me getting into tech really started to become an exponential progression because there were all these other people out there like me doing the same kind of stuff. So before you know it, I was running a board and then I wanted to modify the board. So I had to get the source code for the board I was running and figure out how to really start extending it. Yeah. And that really started teaching me software development in a way that was, was engaging because prior to that, useful.

Yeah. I could do stuff and see the results immediately. And then the users of the board who were really like customers back then would get to benefit from that as well. Yeah. So it was a cool way to get, get fingers dirty.

High school timeframe or junior high or what? Yep. Yeah. Um, and then, you know, it looks like you graduated from high school in Annapolis. Is that right?

That's right. And then what'd you do after that? Let's see, after that I ended up going to the University of Colorado. Is that what brought you out here the first time? Yep, I had, we had some family friends that had property out here in Frisco, so we did a family vacation out there and I just fell in love with the mountains.

Really liked the clean air, the access to the backcountry. It just felt like a big difference from the sort of heat and humidity of the East Coast. So I did 4 years at Boulder, did a bunch of tech stuff there, started actually a consulting business under the name Electric Alchemy, which would later become a security company. But back then it was really just break-fix IT stuff because there weren't a Genius Bar. There was— people had very few options for where to go.

So I put an ad in the local newspaper, had a beeper that people would hit me on, and I'd call them back and go fix their stuff. And this was probably the Windows 3.1 era. Pre-internet, but it allowed me to generate a lot more revenue than I would have been getting working waiting tables or whatever else. And you also got to get your skills improved, right? Yep, I learned a lot doing that.

Yeah, every time you go into one of those calls, like, it's a new thing, right? They're never exactly the same as the previous one. Yeah, I remember I actually took a job with a computer company in Boulder to augment the consulting income I was generating. Company was called Connecting Point, which I think has long since deceased, but they dropped me into Wells Fargo Bank as like a 19-year-old, and suddenly I had to really up my game around Novell NetWare and a bunch of other stuff that I had cursory familiarity with, but suddenly a lot of pressure. But that really, I think, set the stage for a future in consulting where every time you drop into a gig, you've got to get oriented and start delivering value really quickly because your bill rate's pretty significant.

And the expectation is that you're going to be able to solve their problems. Don't freak out. Smile and go figure it out. Smile and figure it out. Don't be afraid of new things and find a path forward.

Yeah, that's great. So walk me through, and I see a lot of different roles you did in Gateway, TSMC, I don't know what AS Watson is in Hong Kong. I don't know which of these are worth talking about. Looks like some international experience. Yeah, so after Boulder, I took a job with Anderson Consulting in Palo Alto.

So right in the heart of Silicon Valley. The very first project they put me on was Gateway Computer. So it was an e-commerce system built on a Microsoft stack. And the project was all geared towards taking the friction out of their sales process and building a self-service configurator. And the backends back then were all AS/400.

So there's some really arcane stuff. This was not a service-oriented architecture. There was no concept of microservices or APIs or anything. It was pretty, pretty gnarly. But I started there on the technical architecture team and then started doing more and more security stuff just because I had an aptitude for it and they recognized that.

Yeah, but that was fun. It was in San Diego and it was a sort of surreal experience going from being a college student to then like flying to work on an airplane, living in a, like, the Ritz-Carlton in La Jolla. And then going to work every day with a bunch of other super smart folks. Yeah, it was, it was really, really a different experience. I didn't know there were jobs like that until I started doing it, and it was a pretty cool way to start a career.

After that, they needed somebody to go to TSMC, which is Taiwan Semiconductor. Okay, big chip fab in Taiwan. Yeah, that your first international experience? Yep, and this company is It was based in Hsinchu, Taiwan, which is sort of like the San Jose, California of Taiwan. So I landed there and quickly had to acclimate to a really fast-paced environment and also some cultural differences.

So they put all the consultants in a room with no windows and expected us to work really long hours. But I enjoyed it. It was an interesting challenge. And that project was all about building essentially a highly available US data center to basically take the load off of their Asian systems and provide better performance. So the culmination of that project was flying back to the US with an entourage of about 5 Chinese engineers to build out the data center in San Jose.

So getting— I expected that they'd want to go like sightseeing in San Francisco and do like real traditional touristy stuff, when in fact what they really wanted to do was go take a picture of themselves in front of the Cisco Logo at the headquarters there. It's awesome. Yeah, pilgrimage for them. So cool project. Was basically working on both the network architecture and the security team then, and it was it was really straightforward e-commerce stuff.

So now you're in Taiwan. Yep. You're what, twenty years old? Is that something like that? It is your first time in Taiwan.

Like what did you do in terms of like did you do fun stuff? Did you get to? So the perk at the firm was that basically they let you do these things called triangle trips where you had a travel stipend for each week or each month depending upon what your fly-home cadence was. And you could go anywhere in the world as long as it cost the same as or less than what it would take to get you home. So I took great advantage of that and saw most of Southeast Asia by just not going home and instead going with, usually with somebody from the project.

Yeah, to go explore. And we saw an awful lot of Southeast Asia using that vector. Any favorites? Really had a soft spot for Thailand. So Koh Samui is beautiful.

Bangkok was hectic and sort of a spectacle. Lots of traffic, lots of crazy stuff to see. But I really, I'm a beach guy. I like warm water. I like getting in the waves and really found a soft spot for Phuket.

And it was easy to get there from Hong Kong. Yeah, that's great. I've heard lots of positive things about Phuket. Yeah, haven't been back since the tsunami, so I hope everything's still in good shape over there, that they've been able to rebuild. But, uh, really enjoyed getting over there.

So you got to go over to Hong Kong after that? Yeah, so when the project with TSMC finished up, I went to Hong Kong, did a brief stint doing a, uh— this was their dot-com cycle, was a little bit behind the US. Yeah, but it was still rising. So I did a sports I think the project was called Sportsnet HK, which was sort of like ESPN for China over there, right in the middle of Hong Kong. But then the longer project I landed on there was for A.S. Watson, which is part of Hutchison Whampoa Limited, which is a massive conglomerate.

A.S. Watson is the— Watsons is the grocery chain, the retail chain, but it's a huge retail presence. And the project was essentially to rebuild the entire technical infrastructure for that chain of like 1,000+ grocery stores in Hong Kong and China. So big Oracle shop, a lot of big iron back in those days. There was no cloud, it was all on-prem. I got to do a lot of interesting security work, basically mostly a Microsoft stack, a little bit of Linux starting to kind of creep its way into the enterprise there.

But a long-term project working with people from Hong Kong, from the UK, people coming over from India. And really interesting, good, good outcomes. Proud of what we built. And after 2 years there, I was ready to come home and starting to feel a little bit isolated and wanted to do something different. So I'm just looking at, you know, so you came back and I know you worked for Accenture some more and did your Wamoo stints.

I'm gonna move us forward just because otherwise we're gonna run out of time. Right in the middle of this, Squaw Valley ski instructor. Yeah, so what happened there? Yeah, what happened there was that, uh, the Washington Mutual project was awesome, but they were burning me out with travel. So I was living in North Lake Tahoe in Incline Village, but flying, uh, to LA and Seattle and Chicago each week.

I'd have to be at each site for like a day and a half. Jesus, every week? Yeah, and after 6 months of that, I was really burned out. Uh, so when we, we wrapped up that project, I wanted to take some time off, uh, went to New Zealand, as we talked about at the kickoff here. And when I came back from New Zealand, the tech market was still pretty slow.

So a couple buddies of mine from the BBS days decided to come out to Tahoe, and we all got jobs at Squaw Valley for that season as ski instructors, snowboard instructors. So again, kind of riding that, that ski bum hitchhiking mentality from New Zealand, but this time in Tahoe. I had what people call an endless winter, back-to-back snow seasons. So that was a ton of fun, but by the end of that, I was starting to think about, I think I might be ready to get back into technology. And it looks like from here, is it ABN Amro was next?

No, there's something that's not on there which is notable, which was that a good friend of mine, Ashkan Sultani, he called me when I was up in Tahoe and he said, I've got a customer who's being attacked. It's a DDoS for ransom. Sounds interesting. I'd done a lot of networking and scale networking previously in my career. And this whole notion of a denial of service attack coupled with a ransom demand was interesting.

So I ended up working with him from Tahoe for several months. We ended up coming down to LA and building out a really interesting reverse proxy with an IPsec backhaul to the origin servers system that was able to withstand significant denial of service attacks. This is 2003, so 15 years ago. We built something that was essentially analogous to Cloudflare's model, but before there was a cloud, and we did it in a data center in LA at 1 Wilshire, which was just really close to the backbone. So we had a gig drop then, which was just a mind-blowing thing.

Like, the day we got the gig drop, it was a celebratory affair. But that's what really pulled me back into security. We had some, some cool sort of celebrity folks show up. Dan Kaminsky came up to our Tahoe Ski House, and I was really proud of what I built. Dan looked at it and I swear in like 10 minutes he had written some code that just broke my whole thing.

He, uh, he ruined it for me and sent me back to work. That's how you learn, right? Yeah, but it was a, it was a really fun project. We called that thing DDoS Resistance. Yeah, we had a really cool technology that we developed as part of this, but we didn't— none of us on the project knew how to run a business.

So another company that had a similar model was called DigiDefense. Which became Prolexic. Barrett Lyon was the founder there, and he did a great job. He sold that company, I think, to Akamai and then built another one. What's his new one?

Is he Direct Defense or Defense.net? I mean, Defense.net, he sold to F5. The guy is just killing it on that in that market. So hats off to Barrett for crushing it in that space. And it was fun.

He and I were peers from IRC years ago, and we were comparing notes as all this was going down. But mitigating ransom-based attacks at the time was pretty— it had a sort of Hollywood subplot to it that made the tech suddenly a lot more interesting than just the packets that we were stopping. That's really cool that you did that. So what did you guys end up doing with the tech? Did it go on a shelf somewhere?

No, we were not able to monetize it. I didn't know how to raise venture money back then. We had a lot of interest from investors, but they were all sportsbook operators. And the incentive alignment was, I think, imperfect. Barrett went and raised real venture money.

He had real business partners. So he just, he had superior execution without question. All right. Kind of moving forward a little bit. Sure.

I, I gotta talk. You have too many cool things on here. You did the Antarctic program. I assume that was with Raytheon back in the day. Raytheon had a group called Raytheon Polar.

Yeah. I had been doing a bunch of freelance stuff in the US after getting back from a stint at ABN Amro in London. And I kept seeing these job postings for security stuff at the Antarctic program. I remember seeing all those posts. Yeah.

And I was like, there's security in Antarctica? Awesome. So I ended up talking to the folks down there, ended up coming on as a contractor, as a security engineer. Did you work with Ed Fuller? Yep.

Yep. He came in. I'd been there for a bit when he came in. Came in after you. Okay.

But there are a bunch of other folks that were just super cool personalities. The culture there was amazing. There were folks that were like lifers and had deployed to Antarctica multiple, like for decades. And I'd hear all these kinds of cool lore, but it was also anchored in this science. So this, like, being able to do security in, in a way that was actually helping scientists do climate research, to look at things like global warming, to look at things like the impact of humans on the planet, right?

Uh, it was a very strong, I think, ideological, uh, benefit of being part of that program. Yeah. And I was actually able to work with a few folks that I met through the program for years. So Garrett Padgham came on to be my partner at Electric Alchemy. Me.

Sue Pomeroy came on to be running GRC regulatory compliance at SendGrid. So some real awesome relationships that have lasted way beyond that time with the Antarctic. Yeah, you're only there for a little bit over a year, it looks like. I assume that's pretty kind of a high burnout rate type of a job. Yeah, you know, I don't remember the specifics of it.

It felt like longer than that. I remember I was supposed to deploy. I was really excited about going down to Antarctica, but my daughter was born and She was due to be born right when I was about to deploy, so I had to pass the buck, and I think Garrett went in my stead. But great, great memories from that. I keep in touch with Ed Fuller, just saw him at the holiday party that you and Alex put together.

Really, really solid, good feeling about the way that whole thing went down. That's neat. Yeah, you know, you did— you've done some volunteer work in the community, and I want to talk about that, but let's see, let's get through the jobs here first. Sure. MobileScope.

I actually don't— I don't know anything about this one. Yeah, MobileScope was, uh, it came out of research that I did with Ashkan Soltani. This Ashkan guy keeps coming up. He and I have been friends for a really long time. We got to know each other through the electronic music scene in Berkeley and San Francisco, but ended up collaborating on a bunch of technical stuff.

So he pulled me in to work with Julia Angwin, who's a Pulitzer Prize-winning journo. She was at the Journal at the time. And we did a study where we instrumented the the network footprint of 100 iOS apps and 100 Android apps, looking at what information are they leaking about the user of the apps. We created identities with a bunch of PII and then monitored the network with an SSL decrypting proxy to see what these things were sharing. And the series in the journal was called What They Know.

The specific feature related to this was called Your Apps Are Watching You. So we spent a pretty good chunk of time on that. And it was great because it started raising normal people's attention to this notion of privacy might be something that you care about. And maybe you don't want to be sharing this information without your knowledge or informed consent. But the tech infrastructure we built for this, we ended up turning into a product called MobileScope.

Ended up working with Bruce Schneier on a potential productization of it, talked to a bunch of West Coast VCs. They were all super interested, but they wanted to turn it into a tool for control, uh, basically a corporate mobile MDM, right? You know, that's where the money was. Yeah. So it was really cool getting to work with Bruce on this, but at the end of the day, we ended up deciding, uh, to work with Aldo Cortese, who's an open source developer in New Zealand who creates a tool called MDM Proxy.

So we built that into the rig and then ended up We won the Journal's hackathon in New York associated with, or right around the time of this, but then ended up selling the tool and the associated tech infrastructure to a company called Evidon that I think they're called Ghostery now. So it's basically a privacy-focused company that they were more aligned with the vision of allowing this tool to be used to help people understand how their information is being shared and misused rather than turning it into a tool for corporate control. I think Ghostery, they also have a tool around JavaScript blocking and stuff. Yep. The main idea is tracking on the web is ubiquitous, and Ghostery created one of the first browser plugins to allow you to gain some control over that.

That's awesome. So it was a cool project, a quick win, and it felt like we were doing some good for the world in the process. Yeah, it looks like only a year and a few months that you did that. And about the same time, you started another one, JumpCloud? Yep.

JumpCloud, I co-founded with a few guys. Raj Bhargava, who was the CEO at StillSecure, Colorado security company. MSSP, right? Service provider. Well, they had done a bunch of productization around commercial implementations of Snort and IDS for .gov and .mil.

So I got to know Raj. He had found me through the work I did for the Journal and MobileScope. And was super interested in working together going forward. Founded JumpCloud with Raj, Casey Berg, who went on to become CTO, I think, at Returnpath, and Colin Mazzare, who's just an amazing engineer who later came to work with us at SendGrid. So pretty awesome founding team.

JumpCloud's initial pitch was essentially agent-based security for your cloud instances. This was way before People were doing agents, but we really wanted to try to unify log visibility with network activity. And at the time it was a pretty novel concept, but we were able to demonstrate that by looking at anomalies in the logs and combining it with like, why is this process then initiating a network connection? Why is Apache initiating an outbound connection? Frequently would give you a much stronger sense that there's a real compromise going on than looking at logs or network traffic and isolation.

Company ended up acquiring another company that was more identity-focused, and the product vision shifted more towards a directory as a service, which is where it is today. But the company has been quite successful. I left— it's still called JumpCloud. Okay. The, the 2 companies that merged early on were JumpCloud and Safe Instance.

Okay. But really excited to see that team execute on the vision. Yeah, the directory as a service model has become very important as companies have moved away from Active Directory as the source of truth. And it allows cloud-native companies to be able to have heterogeneous environments of endpoints and basically be able to apply consistent security policies across those. So it's, I think, a win for Colorado.

They've raised a bunch of venture money. They're hiring. And they're here in town too? They're in Boulder. And I think there's like 150 people working there now.

I should know more about them. That's interesting. Very cool. Are you still associated at all with them? No, I left after about a year.

Raj and I had a difference of opinion around vision. I wanted to focus more on the security aspect. He wanted to focus more on the directory as a service aspect. I decided to move on at that time, but still long in the company. The early investors in JumpCloud were Foundry Group and David Cohen, who's one of the co-founders of Techstars, which is an organization that I've continued to work with through the years.

And SendGrid, which was a later part of the story, was also a Techstars company. So the DNA there was pretty thick from the beginning. Well, I think we're close enough to— I know you did your Electric Alchemy for a while on the side, but if you don't mind, just talk about how you got plugged in with SendGrid and what you did there. Yeah, so like I mentioned, SendGrid had investors in common with JumpCloud, so Brad Feld had been on my board. Um, at JumpCloud.

Uh, Ryan McIntyre was on the board at SendGrid. I had gotten to know Jim Franklin, who was the CEO at the time at SendGrid, very well because I'd been trying to recruit him to, uh, join my board at JumpCloud. And what I didn't realize is that Jim's really crafty and sophisticated, and, uh, he was practicing CEO ninjutsu on me because every time we'd sit down for me to like draw him in to come join my board, he was secretly recruiting me to join SendGrid. So when I made the decision to leave JumpCloud, I reached out to Jim and said, hey, I know you've been looking for this mythical CISO for SendGrid for like a year plus and haven't found the right fit. And maybe we should see if I could be a fit there.

So he and I sat down, I talked with the rest of the leadership team, and they thought that I would be able to sort of thread the needle. All the previous candidates for the gig had come in and had I think too much of a black and white approach to, well, security has to be like this. And SendGrid's culture was notoriously kind of fast and loose, really high growth, great product market fit, but to be blunt, quite a lot of tech debt, quite a lot of security risk. And they couldn't have a sort of traditional CISO come in and try to clean up everything overnight. They wanted somebody more pragmatic.

So we decided to— I decided to join, they decided they wanted me. So at the time that I joined, the company was pretty small. I think it was, this was 2014. There must've been about 100 people. I think just north of like $25 million in revenue.

And it was super exciting. Headquarters was up in Boulder, great culture, like amazing culture, super smart people. And everyone was just pumped to be showing up to work every day. Now, as the CISO, I was freaked out because there was just a lot of risk in the beginning. Day one, I didn't have a team, so one of the very first things I did was to advocate for the creation of a team to make regulatory compliance and third-party risk and the GRC piece of it a first-class citizen of the program, to get some engineers, and to really start integrating with the engineering and the operations group to make security something that wasn't just security's job, but to make it part of just shipping code at SendGrid.

So it was an evolution and a really, really fulfilling experience. Lots of challenges along the way, but I mean, you see what the outcome was. Everyone smiles around. Well, for those who don't know, maybe you could talk about the outcome, because probably not everyone listening does. Yeah, SendGrid's one of those companies that everybody uses and nobody's heard of.

It's plumbing. It's email infrastructure as a service. And when I say you use it— So give me some examples of who uses it. Yeah, GitHub, Pandora, Spotify, Airbnb. So anytime you're using any one of those services and you get an email from them, maybe it's a notification, maybe it's a password reset, some sort of reminder, it flows through SendGrid's network.

And the reason for that is that sending email at scale is difficult. If you just try to do it straight out of your production AWS instances, it's not going to get there. It's going to be marked as spam and it's not going to hit the inbox. The magic that SendGrid figured out was that by spreading out the load across IPs of good reputation and being cognizant of what the mailbox providers like MSN, Gmail, Yahoo, Hotmail, fill in the blank, how they think about incoming mail and being sensitive to what their policies are, you can get much better deliverability. So SendGrid had a tremendous growth story, rapidly growing customers and revenue.

And then over the course of the 4 years had a successful IPO on the NYSE fall of 2017. Traded up in the public market for better part of a year before being acquired by Twilio. I think it was announced in, you know, 4th quarter of last year, 2018. And that deal I think is scheduled to be consummated here this quarter. And Twilio is kind of the same thing except they do texts instead of email.

Twilio does voice and SMS. And text. So I think that was a really good— it's a really good M&A. There's common investor DNA. So Twilio— Bessemer Venture Partners was in on both Twilio and SendGrid.

And my team spent quite a bit of time collaborating with the Twilio team because we were solving the same kinds of problems. SendGrid had a lot of problems with abuse of the platform. Spammers loved how great our deliverability was. And a lot of people, a lot of threat actors, would figure out that by hacking SendGrid, they could actually gain access to really choice targets without having to go through their normal defenses. So we had a really good reputation with Twilio long before the acquisition ever happened, and I think it makes sense.

I think that eventual integration will be good for both companies and for the world. So is it okay to ask you about the data breach that happened there a few years ago? I know it was public information, right? I can't share anything that but wasn't publicly disclosed. Well, you know, I'm not so much interested in that as I am like your experience through the data breach.

You know what I mean? Uh, you know, the technical details of any data breach, you know, you can make up whatever facts you want to in this case. I'd love to know your experience, you know, going through what's a pretty major data breach from an optics perspective, you know, managing that internal to the company, managing it personally with your personal life. If you don't mind just talking about that experience, that'd be really valuable. Yeah.

So the, The sort of cosmic irony about that whole situation was that Foundry, which was one of our investors at SendGrid, had organized a security summit that I volunteered to help organize and to give a keynote for. And we scheduled the date for this like 6 months in advance. And then lo and behold, we had this data breach and the public disclosure date for it ended up being the day of the Foundry security summit. So it was one of those things where I said, well, geez, should I man the con or should I just go give this keynote? So I ended up giving the keynote for this Foundry internal security summit meeting, probably like 50, 60 people there, but then went back to the war room and kept running the breach.

But I think that the thing that made this, that whole breach sort of tolerable was that we had a good team, we had a good process in place, we had a plan, we had good relationships with other departments like support, customer success, legal, such that when we had our turn to really be put in, in the line of fire, we performed well. We worked together as a team to get past the adversity. We also were very intentional about communicating in as transparent a way as possible with customers. And I think they really appreciated that. If you rewind the tape a bit, you remember the RSA breach where the Chinese went after the SecureID token seeds to get the stealth fighter plans or whatever it was.

But RSA had a series of statements that came out after that where they kept backpedaling and said, well, we had a situation, but don't worry, nothing bad happened. And as it all played out, you finally realized like, oh wow, everyone's totally owned and this is really bad. But it took a lot of time to get to that, and at the end of that, we were really— everybody that were customers at the time were really frustrated. Contrast that with the SendGrid approach, which was that as we uncovered the depth and the sort of magnitude of the situation, we communicated very transparently with our customers. We told them what steps needed to be taken.

We initiated password resets, and we talked publicly about what changes we were making to both our controls and to our processes. To prevent this kind of thing from happening again. And I think that got us a lot of credibility. There's always this fear when you're talking about security in the boardroom of, oh, if we have this breach, we're going to lose X much revenue or this many customers. We're going to see churn increase by this percent.

We didn't see that, and I think it's in large part due to the fact that we handled it competently. We communicated about it as openly as possible, and we took real steps and increased our level of investment to make sure that something like that didn't happen again, at least not in that same way. And it only happened once, right? I mean, the fact that it only happened once makes it a lot easier to work through. I think if you had another one 8 months later, it kind of changes the perception.

I think the public perception of a company like Yahoo now is, well, okay, you had this situation and then maybe there was some executive miscommunication or cover-up and then something else terrible happened. That type of, uh, that burns bridges, systemic stuff going on. Now, you, uh, you know, you worked at a tech company, a very visible breach made the news. Um, you, you survived, you know, you weren't let go as a part of that. What do you, what do you attribute that to?

Well, I mean, that is like the, the saying out there, right? Generally, CISOs, sacrificial lamb, and, you know, that they might lose their job. I'm not sure if I believe it's true, but I think it's worth addressing. Sure. So I worked in that capacity, in that role, as a part of a leadership team that I had kept informed about our level of risk and our level of exposure.

So this breach was not a surprise. I communicated that we had a high level of exposure, high level of risk, that we were working to remediate across the business as a priority, but alongside other priorities. Like, we were shipping a new website, we were We were building a new API end-to-end. We were opening a new data center. We were focusing on revenue and growth, and we were investing in security at a level that we as a leadership team felt was appropriate.

But I think as a CISO, I was never targeted or blamed for this event because I had allowed our leadership team as a group to make informed decisions about how to manage risk. Now, in hindsight, would we have prioritized security a little bit higher? Perhaps. This didn't happen because we didn't have the right information. I think I got a lot of credit from the other members of the leadership team and also from the board of directors for having identified specific areas of risk and put together a plan to remediate it.

Did that accelerate your ability to deliver on those plans? Without question. Super stressful. I didn't sleep. My whole team was working super hard.

It was a tense period of many months, but we ended up in the wake of the breach getting to sort of very quickly deploy a whole bunch of new process and new controls that had been planned to be slow rolled over multiple quarters. We already knew what we wanted to do. This gave us an opportunity to do it on a greatly accelerated timetable, which felt good. Great. We have about 10 minutes left, and I want to get into— You made a decision to leave about a year ago, right?

My goodness, it's been a year I've been trying to talk to you.

All right, so about a year ago you chose to leave. I don't know if you want to talk at all about that or what you're doing now and give you some time to tell me. You're doing lots of cool stuff, I know. Lots of fun stuff. So one of the things that I had been super intentional about at SendGrid and that my leadership, my managers, my bosses, so Yancy Spruill and Samir Dallaglia.

Yancy's the CFO, COO, who I reported to directly since he joined, and Samir, who came in as CEO to replace Jim Franklin. They both always encouraged me to hire not for what the company was today, but for what it would be like 2 to 4 years down the track. So I made 2 really key hires at SendGrid because I was responsible not just for security but also for IT. So for security, I hired Scott Gerlach. To be initially Director of Security and then VP and CISO.

And on the IT side, I hired Mickey Hurt, Director, I think now Senior Director of IT. And by really sort of over-clubbing on those hires, it set the table for me to be able to make a graceful exit shortly after the big milestone and to be able to know that I could walk away from that after having made a big difference, but having built a team that would be able to continue to execute and to support the rest of the leadership team, all the company's objectives, and That's really proven to be true. Those two are still there, still kicking ass, and still doing an amazing job through the IPO and the transition. So really, really happy with the way that all worked out. In terms of what I did after that, I'd been going hard for a really long time, wanted to take a break.

So after leaving SendGrid, I decided to not take any full-time gigs for at least 6 months. Some work digging into some more interesting technology. So SendGrid is email. Email hasn't really changed since the '70s. So the most interesting thing about the career trajectory at SendGrid wasn't the technology, it was the scale at which we did it.

But after taking a step back from that, I really wanted to look into 2 particular areas, one of which was machine learning and AI, and the other was distributed ledger or cryptocurrency. It's awesome you didn't say blockchain there. That's fantastic. Yeah, right. He so easily could have.

So on the AI and ML front, I took to— I had some really interesting conversations with a guy by the name of Jeremy Achin, who's the founder CEO of a company in Boston called DataRobot. So DataRobot came out of Techstars several years ago, but basically has built an engine that automates machine learning and in particular makes it easy to then sort of weaponize or productionize the models that the automated machine learning engine creates for quick deployment into cloud environments. Now the reason this was such an interesting business model for me is that I had seen at SendGrid us go through and spend multiple years with a data science team that was awesome. We had some amazing PhD data scientists, but the cycle times that it would take for them to identify a problem and then get the data they needed to then create a model, it was months or quarters. And what Jeremy's system at DataRobot could do was really expedite that and make it self-service such that your business could reap the benefits of AI and ML, but without needing to have PhD data scientists on staff.

So super interesting there. I'm— I do have an advisory board position there and do continue to advise DataRobot. Really, really long on, on that play. Yeah. So that was one thing I got super into.

Another, as I mentioned, with this distributed ledger, cryptocurrency, blockchain. I had known Zooko for a number of years. I think you had him come on the show not long ago. So I totally regret not having invested in the Zcash series seed because he did approach me about that. I was just too busy and too broke at the time to make that happen.

But he and I stayed in touch. I had been interested in blockchain slash Bitcoin for a long time. I started mining back in 2011 because At Electric Alchemy, we had a bunch of GPU power that we used for password cracking as part of red team engagements. But when we were between engagements, we'd point that hash power at mining Bitcoin and then later Ethereum. I also had been lead mentor for a Techstars company in 2016 called Bridge21 that was essentially a cross-border remittance company that used Bitcoin as the payment rail.

So essentially think Western Union, but way lower fees. And way faster settlement times by virtue of using crypto as the payment rail. So I had really been watching with great interest this distributed ledger and blockchain thing taking hold and normal people starting to talk about it and seeing how much interest it was getting in the mainstream. But the thing that really appealed to me about what Zooko's team and the Zcash company they had built around it had achieved was that he had taken novel cryptography that was really academic vaporware and he turned it into production code that really changes the, the base level of confidentiality that blockchain can provide. They had originally gone to the Bitcoin devs and said, hey, we have this mechanism for creating intrinsic privacy on the blockchain.

And the Bitcoin Core folks were like, sorry, too risky. We don't want to do it. So Zooko and company built their own protocol. They built their own coin, Zcash. And I think that this project really stands to be able to move the needle on driving widespread adoption of digital currency.

I think being technical people, we probably both agree that the future of money is digital. But if you go into a coffee shop today and pay for your coffee with Bitcoin, you've just revealed your entire net worth and your entire transaction history to everybody on the planet. Which I think is totally unacceptable if digital currency is ever going to be used for mainstream means of exchange. So the Zcash company has been able to take this novel cryptography, it's been deployed now in production for 2 years with no breaks, and it works. So it's mind-bending stuff.

I used to consider myself very technical. Now I've taken this COO role at the Zcash company, so I'm now sitting side by side with just wizards that get cryptography at a level that I probably never will, which is a humbling experience. But it's really great to be working side by side with such really smart people. And the mission and vision of the company are to provide economic freedom for everybody. So it's this notion of allowing everybody to be banked and to remove centralized control points where people in power can make arbitrary decisions about who can or cannot participate in the system.

It's an opportunity to make a big dent in the universe, and I'm really happy to be there doing that now. That's awesome. The COO change seems like a pretty significant one from everything you've done in the past. You were CEO and founder of a company for a relatively small amount of time. I assume that there's been some changes and some learning for you as you've become a COO.

Can you talk a little bit about what that's been like? Sure. Maybe what you've learned in the last— what's it only been, what, just a few months, 5 months? You know, I actually joined the company as an advisor in January and decided to go full-time and operational in September. Okay.

But I'd been leaning in and doing quite a bit of stuff. I helped to pull together a board of directors, hired a CFO and a director of security. Okay. This— the COO role, I think, was a natural progression. I had mentioned at SendGrid having the opportunity to work directly for Yancy Spruill.

He had come from DigitalGlobe where he was CFO, and the guy just has a wealth of experience. I learned an awful lot from Yancy about the people and process part. He was not a tech guy, and he'd tell you that to your face, but I learned an awful lot about how to run less technical functions that I think are equally important. And as a technical guy, I think I'd frequently overlooked the importance of those functions. So taking on that COO role, I have the benefit of having worked under some great people that taught me a lot about things like HR and finance.

It's been good to come into it with that experience.

Having that sort of 10,000 hours or the long history of security, it was really important for me to hire somebody else to ultimately own that because security can, I think, could easily distract me from doing those other functions. And you'd like it if it did, right? Yeah, it's hard to— it's tough. And I will say that the threat model at SendGrid was pretty intense because SendGrid was critical path for password resets for, you know, things like GitHub. And what important lives on GitHub?

A lot of things. But every single security incident we had at SendGrid without exception was related to SendGrid providing services for cryptocurrency companies. Or for VPS providers, like cloud infrastructure providers that were providing services to crypto. So now being, you know, a C-level exec at a cryptocurrency company, we have perhaps the greatest threat model. Why do you rob a bank?

Yeah, that's where the money is. Yeah, that's clear and present danger. Yeah, absolutely. So, but, but I also find myself inside the Zcash company, everybody has security DNA. Everybody.

Like, this company thinks about security more than any other company I've ever seen. Seen. So I frequently find myself playing devil's advocate and maybe pushing for a point of view that's more product-centric or more customer-centric rather than more security-centric, just to try to level out that situation. Yeah, that's interesting. I know we are— we're definitely gonna run out of time here.

A couple more questions for you. Sure. How many— how big is Zcash now? About 30 people, mostly engineers. Great growth.

I mean, just 2 years old, so really cool to see the growth and success. I know that We just reported a story recently, I can't remember, one of the exchanges that's focused here in Colorado just had to lay off like— ShapeShift. ShapeShift had to lay off a bunch of folks. Are you guys seeing the decrease of cryptocurrency valuations, is that impacting your guys' business? So yes and no.

So I read the ShapeShift article. Erik Voorhees is the founder CEO at ShapeShift. He's also a seed investor, an angel investor at Zcash.

Significant amount of sadness. I had friends that worked at ShapeShift. It was tough to see them make those calls. At the Zcash company, I think we've been a bit more cognizant of the fact that the company is actually funded by blockchain, what are called coinbase rewards. So literally every block that is mined, 10 coins go to the miners and 2.5 go to the founders reward.

A subset of that goes to the company. So knowing that the finances of the company are directly tied to the price of the coin, we were intentional about not getting over our ski tips on things like hiring, not overinvesting in marketing, and not, not essentially getting over-rotated on any of that. So we have no plans to lay anybody off. We have deferred plans to expand internationally. Okay.

So yes, it absolutely impacts us. But I think we've done a pretty good job of being cautious. And as a consequence, we're now well positioned to weather the storm of what people are calling crypto winter. Awesome. Yeah, so I'm gonna change topics on you.

Sure. You know, we had a lot of folks listening who are looking to get into security, you know, SecureSet students, people who'd like to know what is it, you know, you'd be hiring. Now put your CISO hat on. Sure. Or, you know, your career-long security guy hat on.

What should these people be doing to get prepared to go get a job in security? You know, I actually just had a conversation, a friend of mine, Ann Mitchell, who she wrote the CAN-SPAM Act. She's a lawyer who's been at that intersection of tech and regulation for a long time. But I was speaking with her son who's in this exact situation of, hey, I want to get a job in security. So I started talking to him about what he's into, and it was really interesting because I think he's doing a lot of the right stuff, which is that he's experimenting with multiple operating systems.

He's learning software engineering and things like networking, which I think are actually more important than, for example, going and getting an associate's in cybersecurity. Security or master's in cyber, that sort of thing. I'm probably not alone in saying that I have a strong bias towards hiring security people that have either a software development background or have an interest in learning software development. I think the days of the security team being folks who manage firewalls but don't code, I think those are over. At SendGrid, we had The security team had a very strong bias towards software engineering and ended up as part of this cloud migration that the company took on building a whole bunch of custom code that they've recently open sourced.

They called it Krampus. It's on SendGrid. Helps you basically keep your cloud infrastructure in check. But to get back to your original question, I think a strong focus on fundamentals and a strong focus on software engineering is essential for anybody that wants to pursue a career in information security. Awesome.

Well, Dave, we are just about out of time. I want to give you a chance. Anything I didn't ask you that you want to share with the community or you wish I'd asked? You know, I just want to give a shout out to you and Alex. I know you guys do a tremendous amount of work.

You built this community, you run the Slack forums, did the holiday party, and you've done this podcast. I do know from the time I spent contributing to the OWASP community that it's a huge It's a huge time suck, to be really blunt. It takes a lot of time, a lot of energy, time away from the family, time away from the wife and kids. But we really value and appreciate what you guys do, so sincere gratitude and appreciation for all that. I wasn't trying to set you up for that.

Thanks for the kind words. You bet. Well, I think that's it. I really do think that there was a lot of stuff we didn't get into that I'd like to talk about more, so maybe I can get you in 6 months or something. Sure.

Update. Yeah, there are a bunch of security companies that I really like. This— anybody that knows me well knows that I'm super jaded and distrust most vendors, but there are probably a half dozen companies, small, mid-sized companies, I think are really interesting and love to come back and talk a little bit more about what they're doing. Cool. Great.

All right, well, talk to you soon. Learn more about the Colorado security scene at colorado-security.com, where you can information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Equals Security.

Back to all episodes