All episodes

Josh Saunders, Head of Security at Otter Products

Apple Podcasts Spotify SoundCloud

In this episode:

Josh Saunders, Senior Director of Information Security and Enterprise Risk Management at Otter Products is our feature guest this week. News from: Colorado School of Mines, Webroot, Carbonite, Optiv, Lares, Swimlane, Coalfire and a lot more!

A new logo will fix what ails us

Colorado has a new logo! The gold is for wheat, obviously. Millennials love Denver, even six in a room. Space Command gets a Colorado general. The Colorado School of Mines is aiming for the moon and Mars. More tech jobs are coming our way. Webroot is no more, long live Carbonite. Blogs from Optiv, Lares, Swimlane, Webroot and Coalfire.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript10402 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

Sometimes the world looks perfect, nothing to rearrange. Sometimes you just get a feeling like you need some kind of change.

No matter what the odds are, they The Colorado Equals Security Podcast is your local source for regional security news. Local events, and interviews with key individuals in the region. Now here are your hosts, Rob Rack and Alex Wood. Nothing's going to stop me now.

Welcome to Colorado Equal Security. This is the newscast for episode 111, and it's April Fools'.

Are you— are you tricking me, Robb? Well, I'm not sure what to believe here. Well, it is April 1st on the day that we say the podcast podcast come out, even though it comes out the day before. That's true. So that's a little bit of a trick in and of itself, right?

Man, you're blowing my mind here. I've been off for a week and I don't know what to think. So if you notice that our intro music changed a little bit, it's because we are celebrating the 30th anniversary of the release of the TV show Perfect Strangers. And for all of you young kids out there that are listening to this that have no idea what we're talking about, Perfect Strangers was sort of an iconic '80s show about, you know, an odd couple, I guess we'll say. Yeah, I love it.

It actually came out in 1989. So, you know, early or late '80s, early '90s. Yeah. I don't remember what country he was from, but I remember he said that the oldest profession in the world was sheepherder, which is supposed to be prostitute. Yes.

Yeah. Okay. All right. Hey, let's go through some housekeeping. We have a Slack channel.

The Slack channel has been very loud this week. A lot of, a lot of messages going on. Yeah, there is lots and lots of conversations out there. It's getting to the point where it's hard to keep up, which I guess that's a good thing. It is a great thing.

So if you want to join the Slack channel, go out to colorado-security.com and click on the Slack, Colorado Equal Security Slack button. That'll get you the link to join and it is free to join. You can forward that to whoever you want. We do look to keep that as practitioners in the area. We also have a mailing list.

So if you go to the website, there will be a sign-up link at the bottom. Sign up for the mailing list. You'll get the show notes in your email and you'll be the first to know when there is a new episode out. And if you want— speaking of first to know, you can also have the episodes downloaded just straight into your reader, your listener, I guess. If you want to do that, iTunes and Google Play, that'd be fantastic.

I know for those players that allow you to, we'd love it if you'd review us and tell other folks about how you like the show so we can get more listeners. Also, we'd love it if you would tell a friend, just pass along the information to someone else, let them know how great Colorado Equal Security is so we can get more people in the ecosystem. And if you said, hey, I told everyone I know, I've already subscribed, what more can I do? Is there anything more I can do? Well, the answer is yes.

We do have a Patreon campaign if you want to help financially support the show, help pay for those hosting fees and MailChimp fees or whatever other fees we have. We'd love it if you do that. Go out there and all that money goes directly back out into the community. Awesome. Well, let's jump into the news.

So first, Governor Jared Polis this week unveiled the new Colorado logo. It's a little bit different than the previous logo. There's a tree, a C, and some different colors. So when I first saw this, I said, man, is he killing— is he killing tradition? Is he getting rid of our 200— or I guess it'd be a 100-year-old state logo?

And the answer is no. He's getting rid of our, what, 60-year-old state logo? Yes. That Hickenlooper put in place. Yeah.

You know, the previous logo was a little bit— a little bit dry. It looked like a highway sign, right? It did kind of look like a highway sign. It definitely looked like a government logo. Right.

Succeeded in that, but it was not particularly exciting. But to your point about the colors on here, there's red on the flag, which is for the red soil and the rocks. There's yellow on the flag for the wheat fields of the Great Plains, and there's blue representing Colorado's rivers and lakes. So everyone's included here. Yes, let's bring all of Colorado together with a new logo.

It's a very nice-looking logo, nice freshen up. All right, next, our next story here is around millennials, and they apparently still have a crush on Denver even though it's exorbitantly expensive. Expensive for them to live here. Yeah. So Denver was ranked as 6th on the Myers Millennial Desirability Index.

So I'd— first of all, I'd like to be Myers who comes up with the indexes that they're tracking people on. But Denver was behind Dallas, Houston, Phoenix, and Orlando. Of course, that beep was Austin. But, but yeah, number 6. And I would imagine that we would be even higher if we had a little bit lower cost of living here.

Yeah. Interestingly, it looks like our cost of living or our total home value rather is about twice as much as it is on those other cities. So significantly different in terms of affordability. Yeah. I think it said in the article that the median home price in Denver now is like $427,000 or something like that.

And in Dallas, which is number 1 on the list, it's $214,000. Yeah, big difference. Big, big difference. All right. Next story here.

We talked about the Space Command that's been coming and how it might be in Colorado. Well, Trump has tapped a Colorado general to head the United States Space Command. This is General John Raymond. He is going to be the head of it, of the Air Force Space Command at Peterson Air Force Base. And that's going to be a group of about 30,000 space personnel around the globe.

Glad to see that Colorado is leading the charge in protecting outer space. You know, they say around the globe, they don't necessarily mean close to the globe, though, right? That's what you normally assume. That means on the globe. Well, you know, isn't the entire universe around the globe?

Exactly, exactly my point. Next, we have a story here from Colorado School of Mines. They have updated their programming, and they now have some new degrees in space materials management. So if you are someone that is an engineer or wants— has a child maybe that wants to go into engineering, and they want to do that engineering in outer space, you can now get a degree for that from Colorado School of Mines. It's pretty cool.

They talk about, you know, obviously the School of Mines has done a lot of drilling and boring as a, as a big, as a big part of their program since they were started. They talk about this huge warehouse they have that has different boring equipment and stuff. And they've set aside part of this warehouse to basically mimic the surface of Mars. It's going to be an interesting, cool place to learn, and certainly going to give folks the tools they need to go into the space confidently. Well, you know, Robb, I've heard that all of that boring equipment is very exciting.

Oh, man. It is, I think, pretty interesting, though. As there's been more discussion around, you know, travel to Mars or other places in outer space, you know, one of the hardest things to do is to get the materials that you need out of our atmosphere, right? So that there's a tremendous cost for all of that weight to get it out of the atmosphere. So if, say, you started a a base on the moon and then use that as your jumping off point.

You would need to get materials from outer space. And that's really what this degree and the program is trying to help with. It's awesome. All right. Next, we have just a real quick note.

The Carbonite acquisition of Webroot has completed. It's closed. So all of your Webroot friends are now Carbonite friends. So congratulations to them. Hopefully, that's great news for everyone involved.

It sounds like there was not 100% agreement, but that there would be still a large presence in Colorado. And I think as of right now, the Webroot office is the largest Carbonite office. All right, go Colorado! Maybe we can call Carbonite a Colorado company now. Um, hard to say.

Maybe not exactly. Um, next we have a blog here from Optiv around future-proofing your business with identity-centric security. I mean, you know, this is, this is just a nice way to talk about, um, how we are moving from this perimeter approach to security and putting identity at the front of that. It's iterative. It's meant to be a, you know, a way we get better, but really try and think more about who it is you're securing and what those people should have access to versus what is the area that you're in and what— how much do we trust that one area.

Yeah, for sure. Uh, they also had some good analogies in that article, so if you're looking for analogies around identity-defined security, go check that out. Uh, next, we actually have a blog this week from, uh, Lerez Security. Uh, we— Red Team Telemetry Empire Edition. So Empire is a framework around pen testing, and this is a blog talking about doing some logging and some other things using Empire.

Fairly in-depth, lots of details about gathering that data, tracking the folks using Empire. This is also sort of built around one of the, the CCDC competitions, and the, the bloggers work there at— in capturing this data at the Wisconsin CCDC state qualifier. Awesome. Well, very cool. I love to see them getting involved and giving some tips on how people can do better.

Next, we have a blog by Swimlane. This is around Microsoft's OAuth 2 implementation. This is, this is interesting. This is part 1 of a 3-part series. This first one's about endpoints and application types.

The next one's going to be around registering an application, and the third will be about Microsoft Graph API. But I, you know, as you talk about how the identity is, you know, part of the new perimeter here, well, that's exactly, you know, why you need to know things like OAuth and OpenID Connect, these different protocols that allow you to, to give rights based on who it is and, and consent to that appropriately. So this is interesting if you're looking to learn how this works and specifically how Microsoft has implemented OAuth 2.0, take a look at this blog. Yeah, interesting read. Next, we have a blog from Webroot about locking down your digital identity.

So this is actually a you know, a more consumer-focused blog. But if you have family members, children, other folks that you want to, to give some tips to on locking down their digital identities, check this out. They talk about things such as multi-factor authentication, which I think we all know is a good thing for helping protect yourself online. Yeah, it's just, it's a quick read and it'd be something you could send over to your mom or your, to your, you know, your cousins who maybe aren't quite as technically literate, help them secure their own lives too. Our final blog here this week, Coalfire has one talking about leveraging AWS's Trusted Advisor for security and compliance.

Trusted Advisor is a tool that's been around for quite a while. I'm not sure what year, but, um, you know, longer than 4 years, I know that. Um, they've been, uh, you know, really enhancing what this thing can do and giving you visibility into your instances. Um, if you're someone who's moving from the traditional approach to security in the data center to getting more into the cloud, This is a tool that you're going to want to know how it works. And this is a nice entry, you know, pretty easy to read, pretty easy to access blog post about how to use TrustSuite Advisor.

Yeah, it's a pretty in-depth blog post too, I have to say. So glad to see that there's a lot of detail in there. All right. Let's move over to our Slack message of the week. Big thanks to Andre Gaeta.

Andre sponsors this every week. We, we call out one of the people who posted in the Slack channel and they get to pick something from the Colorado Equal Security store that suits them just fine. So our winner this week is AI. That's not her name. I believe it's a her.

That's not her name, but that's what she goes by. So that's what I'm going to call her here. She's one of the planners for the BSides Denver event that's coming up. And she put a nice post in giving a lot of information about how the event's going to be in the fall this year. They haven't narrowed down the exact date, but it sounds like maybe the September timeframe.

It's going to be a different kind of approach than previous years where You know, they've had a lot of walk-ins. Um, and I think last year they said that about 400 people have come. They're gonna have a smaller group this year and everyone's gonna preregister so they don't have to turn away walk-ins at the door, which is what happened last year because of capacity constraints. Yeah. And I've seen, we've seen over the past few years that, uh, the BSides conference here has gotten bigger and bigger.

And I think they're just trying to scale that back a little bit, make it a little bit more intimate, uh, kind of get back to their roots of what BSides was about. Yeah. Good stuff. Well, congratulations. We'll, we'll get you a note to connect with Andre to pick your, your swag.

Um, next we have a calendar of events on our website. At colorado-security.com. You can go check out all the things that are happening in the security community over the next few months. There's a couple things we want to call out before we go into the next 2 weeks worth of events. First, we've been going through each week talking about one of the RMISC keynotes.

So Alex, you missed last week when we announced the most exciting one where, you know, there will be— which one was that, Robb? The, the live episode of Colorado Equals Security, you know, will be hap— will be happening there on the keynote stage closing the, uh, the first day of the main track on Tuesday. Um, but you want to introduce who are, who are, uh, third, I guess it'd be Wednesday. So, so Thursday morning, Thursday morning. Yeah.

So our Thursday morning keynote speaker, um, and I'm probably gonna put the, uh, wrong emphasis on the wrong syllable. Yeah. Um, but, uh, Mikko Hypponen, who is the, uh, CEO of F-Secure. Um, very well-known person in the, the security community, been around for a long time. Uh, very excited to have Mikko there.

Yeah. Internet superstar, uh, security superstar. Really, really excited to have him come out all the way from— I know he's from Europe. I'm not sure what country. Finland.

He's in Finland. Yep. Well, very cool. We're excited to have Mikko come out. That will be exciting.

And then, of course, next week, tune in to figure out who our final keynote is going to be. Close to the close. And then before we go on, one more thing here as I kind of looking forward, I wanted to put this one out here early because you might want to put this in your kids' calendar right now. So we talked about it last year and it's happening again this year, the NCC National Cybersecurity Center in Colorado Springs is going to be doing a week-long cyber camp for kids. So this is going to be July 15th through 19th.

It's about 20 hours of content, a way for your kids to, to learn, you know, what a cyber job looks like. So is this kind of like Tron, like you get put into the cyber? I would only assume so. Yeah. Yeah, I think they have that technology now, don't they?

That sounds awesome. I would love to do that. First, normal event. Uh, the NCC is doing their meet and greet on April 1st. April 2nd, SecureSet is doing a Hacking 101 Intro to Wi-Fi.

On the 4th, ISSA Denver is doing a happy hour at Automox. The 4th through the 6th, there is that 3-day conference which is Lady Coders happening downtown. On the 5th, uh, Cybersecurity in Colorado Springs is doing their First Friday event. Um, ISSC Colorado Springs is doing one, one of their Security+ exam preps. This is, uh, session 1.

It's happening on the 6th, and I think it happens every week thereafter for 3 weeks. Um, we probably won't talk about 2 and 3 because, you know, if you didn't go to the first one, maybe you're not going to any of them. But let you know that this is happening, and this is a really good opportunity to get some high-quality training. Yeah, very inexpensive for that kind of prep work. On the 9th, CTA is doing Progress and Potential a profile of women inventors on US patents.

Very cool. Also on the 9th, SecureSet is doing a beginner's intro to capture the flag. On the 9th and 10th, ISSA Denver is doing their April chapter meetings. And then finally on the 12th, there is once again office hours with Davis, Graham, and Stubbs. If you have some legal questions, that's what they're here for.

Sweet. So let's go over to jobs. First couple jobs are from Ping. I have same job I talked about a couple weeks now. We have a junior product security engineer.

This is someone who has some development experience, maybe doesn't necessarily have a lot of security experience, but has a passion in getting involved. And if you want to be that person's boss, we're also hiring a team lead for product security, someone who's got more experience and some, some security chops as well. But definitely developer skill set is what we're looking for here. Cloud Elements is also looking for an IT security manager. Alchemy Security is hiring a Splunk professional services consultant.

The Mental Health Center of Denver is looking for a HIPAA Privacy and Information Security Systems Officer. That's a good long title. Yes, it is. Slack is hiring a Senior Engineer focused on detection and incident response. Bank of America is looking for an Information Security Engineer.

Zayo Group is hiring a Cybersecurity Analyst III. DaVita is looking for an IT Audit Manager. And finally, Zcash, our favorite cryptocurrency headquartered here in Colorado, is hiring an Associate DevOps Engineer. Wonderful. Well, that is it for the news this week.

Uh, feature interview this week is with Josh Saunders. Josh is the head of security over at Otter Products up in Fort Collins. Had him in the Ping office a little bit ago, and we, we sat down and talked through what's going on. Sounds good. Cool.

I'm looking forward to it. All right, we'll talk to you guys next week. Thanks, Robb. Hi, this is Mary Haynes, VP of Network Security at Charter Communications. Welcome to Colorado Equal Security, for Colorado security professionals by Colorado security professionals.

Welcome to Colorado Equal Security. This is a feature interview. I'm sitting in the Ping offices with Josh Saunders, the, uh, well, you're the head of enterprise risk management and cybersecurity for Otter. Did I get that right? Technically, I'm the senior director of enterprise security and risk management.

Okay, so the new title is the ESRM movement that you'll see out there. Awesome. Yeah, well, we're gonna talk about what you do for your job and, and all that good stuff. But first, I want to know what it is— you told me that you're kind of like a prototypical Boulder guy, and I want to know what does that mean? Yeah, I assume it means you eat a lot of granola and you ask— no, I would say that this is a farm-raised chicken.

Most people would say that. I think like the Boulder dude is somebody that has a bicycle that's more expensive than their car. They run They wear a lot of Gore-Tex, and for me, I also throw in fly fishing in there. So kind of, kind of those things. And I also would say like, oh, it's too snowy to go to work today, but it's not too snowy to drive to Eldora.

So I'm gonna do a 3-hour commute in traffic. Yes. Instead of going to work. All right, so talk to me. You said you're, you're in the process of training right now.

What are you training for? Yeah, so the Colfax Marathon, kind of one of the more famous marathons in the United States here in Denver. It's a spring marathon. It's it's kind of a big deal for runners. A lot of people come here for it because they got all different distances from relay race, the 10-miler, half marathon, marathon.

So it's, it's a good thing to get your butt off the couch in December. Yeah, and start running so you'll be ready to go next month. Is it, is it in April? Yeah. So what's— do you do the full marathon?

Yeah, I'll do all 26.2 of it, hopefully, unless something drastic bad happens. But yeah, I'm hoping so. Can I ask you what your goal is? Like, how fast do you want to finish? There's a whole CIA that goes into what you'll tell people about that, but they say a good solid marathon is under 4 hours for somebody that's, you know, I'm around 40 years old, so under 4 hours I'm good.

I'm not a— that'll make you happy. Yeah, I'm not an under 3. Are you trying to PR? Nope, just finish. Okay, just finish under 4 hours and just finish.

My PR for the marathons is 3:43. I'm not a fast runner. Yeah, but I'm fast enough for me. Yeah, but I'm fast. What kind of pace is that?

Somewhere like 8:48. Okay, somewhere in there. So when I run like a 5K, that's about the pace I'm running at. So you're just doing— yeah, what is that, like 8 5Ks in a row? Yeah, the idea is to keep it out for the long range and not slow down.

Awesome. So yeah, awesome. Well, well, awesome. Let's, let's go ahead and I'd like to learn some more about your background. Where are you from?

Yeah, so I grew up in northern Ohio, always had a love for Colorado. I was fortunate, my dad was an outdoorsman and I was also in the Boy Scouts, and so I did a lot of trips to Colorado. So that kind of started my idea of moving to Colorado way, way back then. So even as a school kid? Yeah, totally.

In elementary school I came to Colorado several, several times. So did you graduate from high school out in Ohio? I graduated from high school in Ohio and then I went to a small college, North Central Central State, uh, and where is that? It's in Mansfield, it's northern half of the state. Okay.

Uh, and got an associate's degree in law enforcement, and then subsequently that's also the Ohio Peace Officers Training Academy, so you get a peace officer certificate and an associate's degree at the same time. Okay. And so I assume you went after law enforcement after that, or— I did. I was really interested in law enforcement and, uh, kind of computer science at the same time. But when I graduated, I was only 20, so I had to do an internship, and I got in with a retail company doing security work, both physical and at the time they called it system security.

Okay, and I got on with a very small police department, so simultaneously working at both. This is like somewhere in the mid-'90s, late '90s, something like that? Late '90s. Yep. Police officer jobs were harder to get back then.

There wasn't as much hiring, but there was an expanded retail growth at time, and there was a lot of upside to that job as well. So I kind of did both of those at the same time. Uh, and what's the retailer we've heard of, or is that the retailer called Meijer? They're regionally based out of Grand Rapids, Michigan. They're a combination, um, general merchandise grocers, like a Super Target or Super Walmart.

And honestly, it was one of the best things I did because I learned a lot about the industry, all the way from physical security executive protection, risk management, and bizarre things, you know, around how insurance requirements affected the organization. So did you move to Grand Rapids for this job? No, I was— it was locally where I— there was offices all over. There was an office close by where I lived. At the same time, the small police department just was just not really working out.

So there seemed to be more of a pull to this corporate security world that, quite frankly, I didn't even know about until I got the internship. So it was really, really good for me. So how long did you do that? So I was there 5 years. Okay.

And then you started as an intern, I assume at some point you weren't an intern anymore? No, I did 2 years of internship and while going to school, and then just sort of an analyst role is the same, and then team leader. Okay. And then I got fortunate, I met somebody through another friend and said, hey, have you heard of this company called Best Buy. Yeah, there's a lot of different security roles there.

And then it worked out really, really good for me to go to work for Best Buy in a regional office in Chicago with the goal of moving to Colorado to finish going to school. And that was more of a physical security role at the time, doing investigations, financial crimes, inventory crimes, different things like that. But that was kind of the stepping stone into more of an information security role there. It looks like you did business continuity there as well. Was that systems business continuity or workforce or facilities?

What was your focus? They had gone through different variations of business continuity. They'd had a couple different auditing firms come in and do all these different audits and say, what really needs to happen for a retailer that's got a central office in Minneapolis at the time, 600 stores out there. What's that need to look like? Does it need to have business continuity for a PCI environment?

Is it store operations? They struggled with that for a while. Then eventually, we developed this enterprise business continuity model, looked at hardening of the system, so disaster recovery as a partner, physical operations, so everything from what if a snowstorm shut down a portion of the US, a hurricane, how would we bring business operations back online, and as well as the technology that comes with it. And that was a springboard for a lot of other things for me there. So yeah, it looks like you were there for almost 14 years, more than 13 and a half years.

Yeah, almost 14 years total. So lots of— I'm sure you had lots of different projects and things. Yeah, many different hats, a lot of exposure, traveled the US, traveled the world looking at just, you know, and a lot of technology exploded in that time too. And one of the big things that happened is a major retailer had a breach. And with that major retailer breach came a lot of security requirements, a big push to harden our systems, make it more resilient, and push it forward to where we could identify how that would happen to us.

Yeah, and being headquartered in Minneapolis and Target, of course, being the the retailer also headquartered in Minneapolis. That's probably a very relevant story. Nice that you guys knew each other. Yeah, we knew each other. We brought on a really talented CISO at the time, and she was really good at looking at the future and kind of teaching me what that future could hold.

Yeah. And I'm really thankful for my time there. What's her name? Deb Dixon. Yeah, I think I've met her a couple of times.

That's great. Looking over those 13 years, any favorite stories or favorite projects that you did while you were there? I think we did a lot of cool stuff on the investigation side, really understanding insider threat models. I think without going into big detail, there's a lot of insider threat cases that I personally enjoyed, both from a physical security and a cybersecurity standpoint. The investigations were really cool.

But really just the expansion of the company, that was the cooler thing. When I started working there, we were planning for this 600-store readiness is what they called it, and we were at 300 stores at the time, so we were doubling the size of the company and went from 300 to, you know, over 1,000 at that point in time. So when you just put that in perspective of just retail locations, that's the cool story is how they were able to go from you know, where they started humble beginnings to a $50 billion company. There's a lot, there's so many stories in there I wouldn't even know where to start from. So how during that time, how did you move from— you mentioned this is where you started getting exposure to cybersecurity stuff.

Where, how did you get that exposure? Because it's a, you know, it's a different set of skills. How did you make that move? You know, I was fortunate. I kind of alluded to this, that, you know, I'm a kid of the late '80s, early '90s, so I was exposed to computing early on, from building computers to playing games on them.

I've always kind of had just the computing background from a fun standpoint, but the exposure is understanding what's out there. Again, I really credit to some of the people that I worked with to say the future of security work is information security. If you take that back into the time, that was a relatively new field. It's everywhere today, but in the early 2000s, there was not a lot of information security-focused people.

Technology was exploding, and therefore, so were the threats. The threats were exploding, and people did not understand, in my eyes, didn't understand what those threats could mean to an organization, whether information was more valuable than, say, cash at a retail store or customer identities were more valuable than merchandise that was on the shelves. The exposure really started layer by layer by layer of privacy. We were looking at customer data privacy at the time. Geek Squad was expanding as well.

There was just— people were bringing in machines that was a whole set of threats they would put onto the network. It was really just a layered approach of figuring out what realm is out there in the information security standpoint. I had some foundational skills, and then at the time I was pursuing a public policy degree as well, and that just kind of morphed its way into more of a risk degree and risk management, and things just kind of all came together at one point in time. So you were there, it looks like, through September 2015. What was the impetus for your change?

Yeah, so I was— my wife and I were living here locally in the Boulder area, working out of regional office and doing a lot of commuting, a ton of commuting. And I had— we didn't even talk about how you got to Denver. So maybe I'll just tell the story, then I'll come back there. Sorry. Yeah, no, I think it's better to tell how I got to Denver.

So I was really wanting to move to Denver, and I was fortunate at the time Best Buy was growing and they had a lot of different needs and wants. And I had moved to the Baltimore, D.C. area to kind of start up the East Coast operations, and I just happened to randomly mention to my boss, I said, hey, you know, I'm really trying to move to Denver, and this, this may affect me long term. And And he said, why don't you just move there with us? And that, that's literally how it happened. What year was that?

That was in, uh, 2004. Okay. Oh wow, pretty early. I had to think about that for a second. And, um, yes, packed up and moved to Boulder.

Yeah. Um, my wife and I— girlfriend at the time— she came with me, and that, that was kind of the stop. Wow. And that was the end goal, was to move here. Yeah.

So 2004 you moved here, and then all the way through 2015. Yeah, it's a long run with Best Buy. And here in Colorado, I got to, got to work out of a great office here. I did a lot of commuting. Again, we were expanding rapidly around, around the country, so, you know, it wasn't necessary to be in one place.

So, and Denver is a great state to commute out of. You can get anywhere domestically from DIA. It works out. Yeah, it's a killer place to live. And to work out of.

So you, so you had been commuting a lot, you said, 2015? Commuting a lot and wanted to start a family. And I had known through running and cycling, I had known some people at Nike, and Nike was expanding their program and looking for a global director to help with enterprise resiliency. And I got lucky and they chose me. So we packed up and moved to Oregon and started our career out there.

So you moved to Oregon in that same timeframe, business continuity, it looks like health and safety as well? Yeah, so there we called it global resiliency. I had incident response from the InfoSec standpoint, global business continuity around the world, health and safety was tagged on at the end. It's like something I seem like I can't get away from, and then a myriad of other little things. Whether it's working with the SOC, they call it the NIC there, a lot of different hats you wear there as part of a larger team.

How was it working at Nike? Nike was probably one of the best things that happened to me. It is a very professional and mature organization. It's segmented very, very well from our world from a security standpoint. It is truly global.

There's, gosh, over 80,000 employees around the world. Manufacturing sites, office sites, you name it. If there's an incident that goes on, Nike could probably be touched to it from there. So it's, it's a 24/7 job and it's definitely around the world. So any interest specifically, specifically interesting projects you can share or what you work on?

Yeah, I think during my time there we were really the incident response model. So we had a lot of things that can touch. And a good example, the Paris soccer stadium bombing. Yeah, we had both employees there, we had our guests there, so we had to figure out, is there impact for that, and does that impact touch us as Nike, and then what do we do around that impact? And that was a major incident from a life safety standpoint, not necessarily from an information security, but getting those employees out of there and making sure they're safe, and then making sure we return our business operations normally.

A lot of smaller-scale incidents that were very learning curves, how we tuned our security operations center. We also had the coup d'état in Turkey while I was there.

A lot of weather disasters, a lot of manufacturing issues, and they all kind of touch— they all touch each other, you know, back in Beaverton at this one hub. So the exposure that you get there is incredible. But also, I think the more thing for me was, you know, running a giant program.

It's quick learning. It's very, very quick learning. You go from almost 14 years of a comfort zone to trial by fire quickly. Yeah, you have to learn a lot very, very fast. So you, you know, you were only there for about a year and a half, it looks like.

So what happened? Yeah, ultimately the pull of missing Colorado, um, was too great. I had my first child while I was there, and we really missed— so your first child is not a Colorado native? She is not a Colorado native, and we actually use that against her a little bit. But the pull of Colorado was great for us.

And my wife has family right here in town. It just— it really— we really missed it here. Yeah. And it's hard for people to understand that. I think the job was awesome.

It was a really killer job, but not enough to overtrump where you want to live. Yeah, that makes sense to me. And friends and family. Yeah. And the opportunity at that first to come just come to Otter was presented to me, and I didn't quite understand the company, so I wasn't necessarily into it.

But when I met with the executive team and understood the breadth and what they were trying to do, it was a no-brainer for us to move back, and I pulled the trigger quickly and moved back. Sounds like a pretty different job too. I mean, you've been mostly focused on business continuity and incident response your whole career, and now, you know, at Otter you get to own the whole— I own the whole thing there. Yeah. So been at Otter just over 2 years.

Again, when I first started there, the idea was just to help Otter understand what the risk posture was and what the threat landscape was out there. That was everything from information security all the way down to physical security and all the risks that touch in between. Then once we understood that, it was really to build and mature what I call a realistic program. I stress the term realistic because the old adage is, how much security do you need? Well, just enough.

Well, what is that just enough? They'd been through a couple of attempts at making a security program, but they never found that sweet spot. That really is the mission, is to figure out what's the sweet spot, what do we need to protect, and how much protection do we need to put on it. Then continually advise the organization of what that looks like. So I expect that most people listening have a similar impression to what I had a couple years ago about Otter as OtterBox, as making, you know, the everything-proof phone cases, right?

Maybe you could talk to me about, you know, is that the right picture? Is there more to it? You know, yeah, and I would have said the exact same thing 2 years ago when I was doing research on the company. Otter's a fascinating story. So, uh, Kurt Richardson is the founder of Otter.

He was a— he calls himself a serial entrepreneur, but he was, um, he was kind of in the molding tool and die injection molding business. He, he was really smart about thinking about how to create things. And Otter was founded in '98, so we're just over the hump of a big anniversary. But he was making a lot of different things, and one of the things he invented was the dry box. It's just a plastic box, the gasket, but it could keep things completely waterproof and, you know, down to so many feet below water and all this.

He found that there was a big niche for that. And really, if you think about in that time what had happened was cell phones became very prominent. Cell phones were expensive and they were extremely delicate. If you go all the way back to '07 when the iPhone came out, Very delicate machine, and that kind of laid the foundation for the Defender. But you guys were around before that even, right?

Before the iPhone. Oh yeah, I would— I worked for an oil and gas company, and all those field guys who were out there, you know, fixing things out on the lines, we— I can't even remember what phones they had, but we had some kind of a standard phone. We used OtterBox. We were making cases for PDAs, Palm Pilots. Might have been PDAs.

Industrial equipment. So really that injection molding, we were making a lot of cases. But as it comes to most of our listeners, they're going to think of the cell phone case. And the Defender was kind of the first one. So it was the thick, heavy molded that you could, you could essentially, you could run over a phone with a Defender on it and it's going to protect it.

And that was the springboard for, for all the different products that they've created now. If you fast forward to today, we're certainly in the MCA world, which is mobile cases and accessories. We also have a line of outdoor products, so we make coolers, very large premium hold ice for days coolers, premium drinkware, a couple other different accessories. And then in the future, we have a different product line that will be coming out soon that's even going to diversify us even more. Well, hopefully there's a press release so we can share on the show so I can have a follow-up.

It's coming, it's coming. And, and, you know, you mentioned, uh, you know, your founders created Otter around 20-plus years ago, um, and I, I think you mentioned to me off, off the air that they've also created like a parent company that does some other stuff as well. Can you share that? So our parent company is Blue Ocean Enterprises. It's in Fort Collins as well, and it's a management consulting company, but we do have a couple other brands that some people should be familiar with.

Kind of one of our larger brands is Angel Armor. So it's a ballistics armor company. We create wearable armor for police officers, yeah, as well as door armor for different law enforcement vehicles. Interesting. Like, so you can't shoot through a door, basically?

Yep, yep. It's got different threat levels. There's a lot of work that goes into understanding that, but yeah, it would armor the door so officer gets out, you can have the door open and protect there. We also have Old Elk Distillery, which is local in Fort Collins. So we make different gin, whiskey, and Nuku bourbon cream.

That's kind of random. Yeah, it's kind of random. It's kind of neat though. It's kind of— it is neat. Is this one of the founder's hobbies is booze?

It is neat to say that we're in that business as well. And then we have some other below-the-radar businesses that you wouldn't know about. We have a design firm. We also have manufacturing of wood pellets over in Europe. So we're fairly diversified.

Wood pellets for like burning in your home fireplace? Yep, highly efficient fuel that would, you know, that just isn't necessarily popular in the US, but definitely popular outside the US. Okay, so you know, when you walked in there, you know, what became your top priorities for— I guess, you know, put myself in Josh's shoes as day one on the job. How am I gonna get— become— yeah, I think, you know, kind of what I alluded to earlier was understanding our risks. And that— I took really the first 6 months to understand the business.

I think that's a lot— that's a step that most of us should take, is just what do we do? And I actually followed the lifecycle of how do we manufacture? How do we design, implement, manufacture, transfer, and bring goods back to the US? We manufacture most of our stuff outside the US. Understand just what are the products that we make.

I've spent a lot of time understanding that, and then associate the risk with them. There's some real easy common risks that I went after right away, but kind of taking that blank slate and just understanding the posture of the company and that as it is here in the US China. We also have an office in Cork, Ireland as well. So what are all those things? We had some glaring ones.

We had a PCI need coming right away. GDPR was ramping up. We process a lot of European data. We manufacture heavily in Asia, so there's a whole slew of risk there. But also we take in information, confidential information and PII from all these different different areas, including OEM manufacturers.

So we get their information way before it's released, so we have a duty to protect— you know, I go back to CIA on that all the time— the confidentiality, availability, integrity of that information was really prevalent right away. So understanding where do we do that and then how do we build that realistic program around all these risks, that was the start of what I did the first year. I think anyone listening, I just emphasize, echo what Josh just said, that, you know, there is no answer that works universally at every company. First thing you do is figure out how your company works, what matters, and how do you defend those things. Yeah, and I think working at Nike set me up well for that because really it's the same process.

There's a, there's a group of people here locally that, that really come up with these concepts, and we get the concept all the way through prototyping and we take the prototyping out to manufacturing, bring it back. It's a huge supply chain that goes in there in between, and then obviously we sell it to customers. Our customers are the distributors and also endpoint sellers as well. Yeah, so what have been some of the projects you've done? You know, understanding that you spent some time understanding what to go do, and what did that inform you to go actually implement?

Yeah, I think the biggest part of that was really building up a maturing the information security program. So a couple easy wins right away where we were preparing for GDPR, so just really getting off the ground and making sure we're compliant under that. And compliance isn't necessarily security, but it did get us up to the road. It gives you an excuse to do some security too. Gives you a big excuse.

I think even a bigger one was getting PCI DSS compliant with our bank. There was a lot of security maturity that came in there. Staffing to the appropriate level of where we need to be, and then really getting some baseline tools and deployment out there. Whether it would be getting our endpoints secure, identity and access management, really just looking at our perimeter defenses and are they usable, and then the basics too— policy, writing policies, a lot of policy. Getting our physical security to match our information security, understanding where our data was at was a big project as well.

We're recently spinning up our business continuity program as well, and maturing with disaster recovery. Now, just getting more of an operational tempo, security operations day-to-day, and sort of maturing those tools now that we have some of them in place. Yeah, that's been the big project. When you've gone to hire— I'm gonna use this question to give some advice for those people who are looking for jobs— when you've gotten to hire folks, what are the skill sets or attributes or traits that you're looking for in your candidates? Maybe talk through the different roles you've hired.

Yeah, so I've hired, I've hired 2 analysts. I was lucky I had one person already on, and a business continuity person, but the common trait that I would say amongst all of them, and I'm hiring in Fort Collins, so my— we all say there's not enough talent out there, and I believe that, but it does get smaller when you move away from the metro area. So I'm looking at a slightly decreased pool, but we do pull a lot of people from the Denver area. But I think security people have to have that curious mindset, like, can I fix a problem and can I make it better than it was before? And we've talked about this a little bit offline— recognizing a problem and can I fix it.

There are certain skill sets that come along with that. I would like to hire people that can code if possible. That's not always available. I'd like to hire people that have a realistic view of the security world. You know, I'm not necessarily someone that chases people people with certifications.

I like to see what people can apply that. When you interview people, you do the scenarios, how would you apply that? I don't try to make the scenarios so complex, but I want to give a garden variety thing and say, how do we handle this? I'm looking for people who can chase it down, fix it, and I always, it's kind of cheesy, but I say leave it better than they found it. That's a common trait I look for.

Yeah, that's great. Any suggestions for those folks who are either career changers or, you know, just graduating who really want to impress you or impress, you know, a hiring manager during an interview process? What can they do walking in the door to, to blow someone's socks off? Yeah, I think number one is research what they're going after. I think a lot of people spend a lot of applications out there and, you know, The advice that was given to me when I was early on in my career was, pick that path and become very good at that path.

There's a lot of different paths in security. We all know that. There's a lot of different paths, but security is its path onto its own. I will look for what have people done to build their intellectual horsepower around security. I interviewed and subsequently hired an analyst, and this guy really impressed me with his personal life as it related to security.

He was not too techie, but talking about, you know, what he does at home with his home lab. And it wasn't anything off the wall, but just solving small problems and talking about how he, you know, kind of secures his family with password managers and and educates them and different things. We all know that translates into the workplace. We're always talking about the endpoint users are weak. He did that with his family, and this is a young person straight out of college.

I think just, do they have a good grasp on what is information security and how does it relate to a lot of things? I think that's impressive to me, not just reciting the CIA triad and things like that. When you look Changing topics on you, when you look to what you're going to be focusing on throughout the rest of 2019 and maybe 2020, what are the big themes for what you want to get better at and where you see improving your own program?

Really, next year is more of a year of maturity for us. What I want to get better at is just standard daily security operations. I think that hardens us as a company, that we don't miss on the basic blocking and tackling. Then how do we accelerate beyond that? I want to get really, really good at vulnerability management.

That is a symbiotic thing out there. It's a combination of my team, the information technology team. We are separate at Otter. We don't roll up the same way. Vulnerability management is probably priority number one for me.

Sure. And that also includes maturing the tools that help us with that, whether that's, as we talked about, getting our SIEM really refined, getting our endpoints refined, scanners, etc., but also how do we work well with our partners and infrastructure that are helping us get those vulnerabilities down. If we can really get better at that, I'm going to feel good. I think 2 is defining those and the roadmap that that's going generate, whether it's threat intelligence and how do we use that in combination to make it a usable program. Then I think being good partners to the business.

I say all the time that security should be business enablement. I don't ever want to hear my company refer to us as the nos. Security says we can't do this. Certainly, we're going to say no to some things, but how can we find ways to enable our business as we grow, as we move into different countries, do different products. But how can I apply defense in depth to where it does not get in the way to make the business better?

That's what I want to get better at. I'm not exactly sure what that is yet until we get into those areas, but I think that's something that we're really striving for as a team. You and I have known each other for a couple years now, and you know that I am not a buzzwords guy. But I'm going to give you a bunch of buzzwords anyway, and I'm going to see which of these— see what I say— which of these are relevant, which of them are worth talking about, and which of them are just buzzwords, right? So, you know, big data/machine learning, where does that fall for you?

To me, where we're at right now, it's somewhere in between. We have a business intelligence unit that's relatively new, so we have a lot of data. Every company has a lot of data. I think how do we harness that data to get it better and usable? There's a lot of ways the data was stored, all the way from low-level Excel spreadsheets to databases, but BI is the big word.

I think that's a buzzword on top of that. How do we use that and how do we make the enterprise better with it? I'm not exactly sure, so I kind of put it in. I know it's out there, so I'll say buzzword on one side, when I see the results. Is that the business that's looking for business intelligence, or is it security that you're looking for within your program?

I think it's the business is how I would say that. Certainly, there's a feed that plays into us, and we've gleaned a lot of information off of that to help us mature the program, but it's still in its infancy for me, so I'm not clearly on one side of the fence or the other. The cloud used to be a buzzword, and I'm not sure if it is anymore. It's not a buzzword. Where are you at on that?

Where's the cloud in your world? As I like to tell people, the CIA stores stuff in the cloud. I think we've moved past— cloud is the way to go. For a security practitioner, these highly on-prem customized environments were super hard to secure, they're super hard, and now we're moving away from that. We're getting more standardized, more baseline, and I think there's a trust in the cloud now.

We've just seen time fix a lot of that stuff where the cloud is deemed more secure in people's minds. We're willing to put our sensitive data out there. Certainly, there are some things that contractually may be recalled back, but I feel like just the world is into the cloud. So no buzzword. Blockchain.

You know, when you break blockchain down, blockchain is still a ledger.

I think blockchain is a buzzword on top of what it does. It's a way of movement. It can simplify some business processes. I don't think it's for everybody, but I think it will be less of a buzzword in more usable. What's the relevance for either Otter or your security program or security in general from your perspective?

I think from my lens, that's a hard question for me to answer. It fits into— there's a lot of accounting that goes into it, so there's a lot of record. I don't think I can really answer how it's going to fit into security today. In the future, we're going to really clearly define the way that would fit into the security stack. I'm not exactly sure of how I would say in the future would look, but I think less of a buzzword and we'll see more business cases where it's been used and shown to improve the security posture.

That's what I would say. Yeah, that's great. I know you've been somewhat involved in the— well, once or twice I think you've been in the ISSA Fort Collins group. Could you talk about that at all, your experience? For anyone who's maybe in that area, what's your experience been like so far with that?

If I could even just expand that, the Colorado security scene. So me moving back here after a while, I feel like even being gone just, you know, slightly less than 2 years, the Colorado security scene is way better. It's really grown. There's a lot of avenues out there. There are more things that you can get involved in than you have time.

Listeners of this podcast will know when you guys go through the events, I can't get to the events just because there's so many of them. Now it's almost like a pick and choose, where do you go? I think that bodes well for people that want to get into security, back to that original question. Pick some events and go to them. They're inviting.

They're very cool to go to. I've found, I found them to be really good, all the way from— there's a, there's a 2600 Magazine meetup in Fort Collins. That's, that's decent. Is it? And that's taking it way back.

Yeah. All the way through, you know, your conference that you're about to help put on. I think there's so much out there. You should get involved. Yeah, anybody listening should get involved.

For those who don't know, 2600 is a hacker magazine that started somewhere then, I assume the '90s. The '90s is when I heard of it. That's when I got into it. If it happened before then, I'm not aware of it. But it's, you know, 20-plus years of, you know, this is where hackers get their news.

And yeah, pretty cool that they're still doing meetups. Yeah, there's so many opportunities to get involved in the security community. There's so many meetups. People are willing to share here. And we do operate in sort of a secret environment sometimes, what people would say, like, I don't want to give my security posture away.

But most of the meetings I've been to, people have been super helpful. As you're building a program, whether you're getting into or just maturing your program, there's somebody there that can help you. Yeah. And I think that, that bodes well for the Colorado security community. Awesome.

Well, that's it for my questions for you. Any comments you want to make before we before we call it? I think, you know, the podcast is great. People, people talk about it, they love it, and I think I'm honored to be on here. We're glad to have you.

I mean, there's been some fantastic people. I'm a weekly listener and there's a lot of good information gleaned off of these, so I write something down every week and it's a good community to connect with. Awesome. Well, Josh, thanks for your time. Hopefully we'll get to keep in touch and We'll update folks when when your new product hits the market.

We'll get we'll get it on the on the news part of the podcast. Thanks, Robb. All right, have a good one. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info at colorado-security.com.

Colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes