All episodes

Julie Smith, Executive Director @ Identity Defined Security Alliance

Apple Podcasts Spotify SoundCloud

In this episode:

Julie Smith, Executive Director for the Identity Defined Security Alliance is our feature guest this week. News from: Andarko, RTD, Greyhound, Health Scholars, CSG, ThreatX, Ping Identity, Coalfire, Optiv, VirtualArmour and a lot more!

The train giveth - the bus taketh away

Anadarko's future is still up in the air. RTD finally opens the G Line. Is Greyhound leaving town? Health Scholars is using VR to train health pros. CSG something something BLOCKCHAIN. And a bunch of blogs!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11332 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for April 29th. Uh, was it episode 115?

Yes, 115. Uh, this is Robb Reck and this is Alex Wood. Well, Alex, how has your weekend been? You know, it's been wonderful, nice and sunny. Although I hear it's supposed to be wintry again come beginning of the week.

Is it gonna snow? That's what I heard. Well, this is Avengers: Endgame weekend. Should we throw out spoilers for people? Yes.

So spoiler, Superman joins the Avengers and he uses his X-ray vision to see into Thanos's soul and see he's actually a good guy after all. Exactly. Um, this is all a good thing. Half the world should die. Let's move on.

All right. Well, uh, it was a good movie. I know we both enjoyed it. For those who haven't seen it yet, you know, go do it. I think it is worthwhile.

Yeah. All right. Why don't we go ahead and jump in? We have our, uh, our housekeeping. There is a Slack channel.

This is a place where you guys can come be a part of an active and thriving security community. We have almost 900 people chatting on a regular basis about what's going on in town. We are getting really close to 900. We also have a mailing list. If you go to our website, colorado-security.com, you can find lots of things there, including a link to the Slack channel, but also at the bottom of the page, you can sign up for our mailing list.

That mailing list will get you the show notes when the new episodes are released. So if you wanna be the first one to get those show notes and all the details of the episode, sign up there. If you also wanna get the episodes delivered directly onto your favorite listening device, you can go sign up on either iTunes Podcast Store or the Google Play Store, have that delivered in there. We'd also love it if you would rate us and review us positively on those places. It helps us find new listeners, which is of course, you know, a big part of what we're trying to do here.

In addition to that, we'd love if you tell all your friends how wonderful Colorado Equals Security is. Tell them to go subscribe to the podcast. Tell them to join the Slack channel. Spread the word. Yeah, that's awesome.

And of course, if you want to help even more than that, we would love your financial support at Patreon. A link to the Patreon page is also on colorado-security.com. What you guys do with that financial support allows us to do more stuff in the community. You know, swag that we've given out. You know, previously we'd, we'd been paying with that out of our own pocket.

We're now able to use the Patreon donations. The costs for hosting the website, the costs for the email list, all the things that go into supporting this come out of that Patreon campaign. We've made a commitment to you that any money that you give through that will go directly back out to the community. None of it goes into Alex's own pocket. That's true.

But, and the more you guys are able to help us, the more we'll be able to do to help improve the community. So we do appreciate what you guys do there. We definitely do. Uh, let's jump into the news. First story, in a strange twist, uh, Occidental, which is another oil and gas company, challenges Chevron's bid for Anadarko, uh, with an even bigger offer.

Well, the first offer was like $33 billion, and this new one is $57 billion. Yeah, that's crazy. We're getting some really, really big numbers here. Part of this also Occidental says that they are better positioned to take advantage of Anadarko and the capabilities that they have. You know, they're better partners than they would be with Chevron.

So that's sort of their selling point, as well as a, you know, a boatload of more cash. So apparently, and I didn't, I didn't pay attention to this the first time the Chevron offer came out, but the analysts had already foreseen this as a possibility and don't actually think much of Occidental's offer. They don't think that they're going to be able to win. Apparently, this will just drive up Chevron's purchase price and Chevron will still be the winner from the What, that's what the street seems to think's gonna happen here. Yeah.

I, I think I also saw in the article that there is a, uh, there's a breakup price. So if, um, if they do decide to go with Occidental, then Chevron still gets some sort of payout because they made— I think it was a billion dollars. They were the first one. Yeah. You know, just an extra billion dollars because that didn't go through.

Yeah. No biggie. Um, speaking of things, there, there's a new, uh, RTD line, a new light rail line. So RTD, the G line, which goes from Union Station out to Wheat Ridge, uh, I think it's out to Ward Road, has now finally opened after years of waiting. Yeah, so this, uh, is a, a new line that uses the same commuter rail that the A Line does out to the airport.

So it's not the same light rail trains that go around downtown, it's the, the slightly larger trains. And it's been delayed for a long time because they've been having the same problems there as they did on the A Line. The, uh, the crossing signals were not meeting the, the specifications, and so they just didn't open the line until they had solved that for the A Line. But this should be good for anyone who lives along that corridor. You know, it was that Arvada-Westminster type corridor out to the northwest.

Yep. Uh, it's a new way to get to work downtown. Yeah, it goes north almost to I-76 and then west sort of along I-70. Um, as you said, out to, uh, Ward Road. So, and as we, as we gain a new light rail, we're, it looks like we're gonna be losing a, a bus service.

Uh, sort of. I'm making that part up. We'll be losing a bus station. So, The Denver Greyhound bus station, which is downtown, I'm sure many people have driven by it downtown before. It occupies an entire city block and that has recently gone up or is going up on the market to, to be sold, that whole block.

So it's like 21st or 22nd and Arapahoe. Yeah. Yes, something like that. And it's a very interesting opportunity. You don't get a whole city block that comes up for sale very often.

Uh, Greyhound is still operating out of that, uh, station, but their plans are to move that most likely to Union Station. They talked about that before, but at the time didn't have the money to make that move. I'd imagine they're gonna get the money out of this sale, right? So this is the Greyhound station was built in 1975, 44-year-old, uh, trans— is that the year you were born, Alex? It is the— you know what, this is— it's very sad that we're gonna lose this Greyhound bus station.

It's the same age as I am. Uh, So it's a 50,000 square foot facility. If you guys have ever been there, it also has a second floor parking lot above it. It is pretty run down. I was down there a year or so ago and thought, man, this place could, could really use a facelift.

Apparently it's going to get a lot more than a facelift here. Looks like the, the initial offers are due by the end of May, final offers due by June 21st, and assuming they get enough interest, it will be sold A purchaser will be selected by July 1st. Yeah, I believe it said that it's zoned very liberally too. So you could have, I wanna say it was as big as a 30-story building on that site. So that would be a pretty interesting addition to the Denver skyline.

Yeah. Moving along, there is a tech company in town called Health Scholars that actually is built to use virtual reality and augmented reality to help do training for healthcare providers. Yeah, this is pretty cool. They, the first simulation that they did through this technology was back in July of last year. And it was really training doctors and nurses what to do in the event of a fire in the operating room.

So it's, you know, hey, a virtual fire, uh, figure out what you have to do in a safe way. So, you know, the other options that people could do instead of this were, we're doing like an e-learning, you know, computer-based training, or they could have people going to a simulation room. Probably, you know, e-learning is not nearly as, um, you know, as valuable. It doesn't really put you in this situation. And the problem with the simulation is you have to go travel to the off-site simulation place.

There's backfill costs because you have to have someone at the hospital working. So using this virtual reality technology reduces or saves companies about $100,000 just in backfill pay, they say. And really the overall savings is somewhere between 50% and 70% versus doing those simulation trainings. That is pretty cool. Always nice to see cool technology that also saves you money.

They also mentioned a second type of simulation that they've already created at the request of their customers. It was around what to do for a routine event, which is an advanced cardiac life support, also known as a Code Blue. Ah, interesting. Next, CSG plans to take blockchain mainstream for telecom payments. So CSG is a company that was originally part of First Data, and they provide support for system and services for payments around the telecommunications industry.

And they are developing a new product that uses blockchain to make those payments easier. Well, I know that they, they created a lab, right? At least as the first point. I don't think they have a product yet. They created a lab, which is where they're supposed to be playing with blockchain and figuring out how to get it integrated with their product.

Which is called InterConnect. And I didn't know much about CSG, so this article actually was my first real exposure. I guess InterConnect is used for telcos from different countries, you know, as, you know, let's say you're an AT&T customer and you go overseas to Europe, and AT&T will arrange with whatever European carrier they have an agreement with to pay them for your service while you're there. And InterConnect is that hub that's used for that international charging. So it seems like a place where, you know, maybe blockchain make sense.

I'm going to call baloney and say that there are probably other ways that this could be handled just fine without blockchain. But I appreciate the fact that they are looking at all possible avenues to make this new payment system work. And that sounds like about all uses of blockchain, right? All right. Next, we have some, some blogs here this week from ThreatX.

ThreatX is our local web application firewall company up north, I think, in Broomfield or some such. Um, they have a Web Application Firewalls 101, and they go through some keywords that you should understand, uh, in order to really understand how application security and specifically how WAFs work. Yeah, they talk a lot about different terms, uh, active deception, um, attacker fingerprinting, bot detection, uh, the cybersecurity kill chain, which is always an important one. Everybody needs to know about the kill chain. So they have 10, 10 phrases here that you should learn about, and they actually define what those are as well.

Maybe take a look, but they make it clear that these are just— if you look alphabetically, they only go A through C. So there's a lot more terms coming in future blog posts. I look forward to our new terms. In all reality, this is actually a very good place if you want to refer somebody just as a reference point. Lots of good terms and their definitions there. Next, we had a blog post from Ping Identity talking about killing the password for consumers.

And this is actually a really good blog post talking about consumer identity and all of the ways that, that you can have them authenticate, different ways for MFA, and even some talk about password lists and other things for authentication. I like they got into some actual scenarios later in the blog post talking about specific ways that you can improve the user experience. So they have one scenario where You know, let's say someone goes to make an especially large purchase online. You know, you have your— if you're an e-retailer, someone wants to go, you know, make a $5,000 purchase. Well, you could send a push notification to their phone, which, you know, they've already established with you saying, hey, you're making— you're looking to make a large request, you know, $5,000.

Do you want to approve it? And, you know, yes or no. So a really low-friction way to get a higher level of assurance that someone really meant to do this transaction. Yeah. There's also talk about different ways where you can do multifactor and, you know, how you talked about the frictionless piece, Robb, you know, it's, hey, let's do it with a push notification instead of an SMS.

You know, it makes it even easier and more secure. You don't have to go find where that text message came in and find the code and enter it in your app. Uh, you get a push notification, simple. And you have the context on the push too. So the push doesn't, it doesn't just have to be like a swipe yes to approve.

It can say specifically, Like, for example, you call in a call center and, and instead of being asked, what's your mother's maiden name and what street did you live on as a kid, they push a text— or excuse me, a notification to your phone that says a customer service rep is trying to verify your identity, and you can say approve, right? Yeah, really clear, clear what's going on and a really good user experience. Exactly. Anyway, good blog. I recommend that one.

Take a look. Next, there was a blog post from Coalfire talking about A Day in the Life of a Cybersecurity Professional. And I think that there have been a few of these blog posts, um, over the last few months. And this one is from, uh, Sohaib Adel, um, and just talking about his journey starting with Coalfire. Yeah.

And he actually talks about like how he even got into security in the first place, right? He was a young guy with a tech, um, a tech leaning and trying to decide what career made sense. And he talks through why he chose security and what that's looked like, what he does on a day-to-day activity and and give some advice for others who may be looking to go this way. So I would suggest this is a great blog post to share with your, your, your kids or your nephew or cousins or whoever it is who might be thinking about security as a next career path, just to get one data point about somebody else. Great point.

Next, we have a blog from Optiv called Mythbusters: Debunking 5 Common Identity and Data Management Myths. So this is clearly, as you pointed out, Alex, not written by a Denver native. It's written in British. Yes. S's instead of Z's and throwing in some random vowels here and there that, that we wouldn't otherwise have.

But the Queen's English. The Queen's English. There you go. It's the proper English as they are in England and we are not. But they go through these 5 myths.

Number 1, myth number 1 is an identity management program should be highly customized. And the truth is, if you adopt the 80/20 rule or the Pareto principle, 80% of the functionality can be deployed out of the box using those features. Myth number 2, IT teams cannot support IDM evolution. Is that true though? I don't even know if I know that myth.

Yeah, I don't— the myths in this were a little bit, um, I don't know, self-serving. It's like, maybe we have some points we want to talk about, let's make some myths up to talk. Um, but anyway, uh, just talking about that IDM could play a pivotal role in digital transformation wider in your company. Yeah, and there are more myths. I don't think we need to go through all of them, but, uh, interesting stuff there.

And certainly some really good points about how identity can be used to make your customer and your workforce uses better. And our final news item for the week, Virtual Armor had a blog post talking about spring cleaning. So, you know, it's springtime, maybe you should take a little bit of time to review your security practices. And they gave a list of different things that it would be good to take a look at. Some of those are reviewing your password guidelines, auditing your current cybersecurity program, making sure your endpoint protection protocols are up to snuff.

Ensuring you have up-to-date software, that's always a good one. Reviewing and doing some training around your cybersecurity protocols and maybe doing a tabletop exercise or a pen test or a pen test. So good stuff to do. I don't think it's just spring, but it's a good reminder to take a look at these things. Yes, spring is that time when everything comes anew.

So let's make sure we're, we're doing all those things. Well, moving over to our Slack message of the week. This is an opportunity for us to highlight some great conversations that's happening on the Slack channel. Big thanks to Andre Gaeta. Andre has been sponsoring sponsoring this for us for a long time now.

The person who wins the Slack message of the week gets one free item from the Colorado Equal Security Store, which is a CafePress store with cool branded stuff for us. Speaking of the CafePress store, I just bought some new stuff this week, Robb. What'd you get? I got a new t-shirt. You're not wearing it.

I'm not wearing it today. I'm weird. I have to wash my t-shirts before I wear them. I also got a coffee mug. I was jealous of someone who posted on the Slack channel with the, the white coffee mug with the black inside.

So I got one of those. And then I also got a hitch cover with the Colorado Equal Security logo on it. So if you see a car riding around town with a Colorado Equal Security hitch cover, that, that could be me. Now I need to get a hitch installed just so I can get a hitch cover. Yes, you should.

All right. Well, our winner this week is, uh, is Alan Gordon. Alan had a number of different posts this week. He's been quite active in the channel for a while, but, uh, big thanks to, to him. Specifically, we want to call out he posted a CSO article about trends that are happening in security, and he's pulled out some examples from there to talk about.

And I thought that was worthwhile, uh, for us to comment on. Awesome. Congratulations, Alan. We'll get you your note and you can pick something from the store. Well, let's move over to our events.

As we have been talking every week, coming up June 4th through 6th, the Rocky Mountain Information Security Conference is here in town. We're just over a month out from that. It's hard to believe it's, it's creeping up that fast. So if you haven't registered yet, you should go out and register, um, rmisc.org, and go check that out. And one of the things I wanted to talk about this week, um, one of the pre-conference trainings, uh, Chris Merritt, who is the co-founder of Vector8, they do training around threat hunting here in town, and they're going to be presenting a class, full-day class on threat hunting.

So if you want to learn more about how to be an effective threat hunter, you should go ahead and check that out and sign up for that. Is there a cost associated one? This is one of the, the paid pre-conference workshops, so there is a cost associated with that. Uh, you can find out all the details on the website. Awesome.

Uh, as, as we go through the next couple weeks worth of events, I will remind you that we do have a calendar of events on colorado-security.com. Go out there and you can not only see the next couple weeks of events, you can look out all the way to the end of the year. We have quite a few events on the calendar. First, on the 30th, the, uh, National Cybersecurity Center is doing a Cybersecurity Essentials Attack Target, where they're doing a deep dive on the Sony Pictures case. So, or the case study, excuse me.

So you can learn about what happened with the Sony Pictures hack and get some more details that hopefully can help you get better with security in your company. Also on the 30th, SecureSet is doing a capture the flag, one of their cybersecurity hackathons. On the 2nd of May, Splunk is doing a First Thursday meetup at Topgolf. This is free for anyone who signs up. You can go do some Topgolf and talk security with Splunk.

That'd be cool. Uh, Cybersecurity Colorado Springs is doing their Cybersecurity First Friday on May 3rd, so check that out. SecureSet is doing a Hacking 101: Creating a Virtual Lab with AJ Menendez on the 6th of May. And SecureSet is also doing a Hacking 101: Creating a Virtual Lab on the 10th. All right, so moving over to jobs, uh, we have a couple of jobs that are working with me at Ping.

We're hiring a junior product security engineer. This is someone who's gonna who has a development background. Specifically, we need someone who's got Java development skills who wants us to help embed security into the software development lifecycle for our products. And if you have some more experience doing that, we're also looking to hire a team lead focused on helping embed security into our different products. So if you have a little bit of management experience or you're, you know, a good software development lifecycle person who wants to get some, some team lead experience, this is a good role for you.

Reach out to me on the Slack channel or go ahead and apply on pingidentity.com. STARS is looking for an executive director of IT security and compliance. So this is the backfill for Steve Wostal. We had Steve on the show over a year ago. Yeah.

And he's been like kung fu traveling all around the country looking for wrongs to right in the last year. So he and I just chatted the other day and it looks like this is a role that they're now serious about trying to backfill more aggressively. Next, another security lead role. Trimble is hiring a cybersecurity director. Um, this is over their cybersecurity group.

Really, this is their CISO-level role. This is a replacement for Clay Parker, who has moved over to doing consulting, um, and still in the area. Congrats, Clay, on your new gig, and we're looking— hopefully we can help find a great backfill there at Trimble. Carbon Black is looking for a SOC manager. Coalfire is hiring a consultant focused on penetration testing.

Sumo Logic is looking for a security compliance and privacy analyst. And I will point out that, uh, George, who's the CISO over there, said even though this said Redwood City, he actually wants to hire it in downtown Denver. So this, this is okay for local even though it looks like it might not be. Next, the state of Colorado is hiring a senior cybersecurity engineer. Red Robin is hiring a senior security analyst.

And finally, Kaiser Permanente is hiring a cyber countermeasures undergrad intern. Sweet. That sounds exciting. It does sound exciting. I assume this is a summer internship.

Well, that is it for the news this week. Next, we have a feature interview with Julie Smith. I sat down with Julie. She is currently the executive director for the Identity Defined Security Alliance. Robb, what is the Identity Defined Security Alliance?

I'm not going to go ahead and ruin this for you guys. Listen in, you'll find out what it is. But I will say this, it is headquartered here in Denver. This is an international group headquartered in Denver. And learn more.

And Julie has a great background, not only there, but also working in a number of different security organizations. Awesome. I look forward to it. All right. Well, that's it for this week.

Enjoy the interview and then we'll talk to you guys again next week. Thanks, Robb. This is Joshua Foltz, CISO at eFolder. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.

All right. This is Robb Reck and I am here with Colorado Equals Security sitting today with Julie Smith. Julie, you are the Executive Director for the Identity Defined Security Alliance, the IDSA, as it were. Yes, I am. And we're going to just tease a little bit.

People are probably curious what the Identity Defined Security Alliance is, but I'm not going to let you tell them right now. Okay. First, I really want to know about where you're from. I understand you're from a small town in a beautiful part of the country. So talk to us about where you're from originally.

Yeah, so I grew up in Sarasota, Florida. My family actually is a third-generation Floridian, so kind of all, you know, been in that area for a long time, which is very hard to find. So how far from Tampa is Sarasota? Yeah, so Sarasota is about an hour south of Tampa. It's on the Gulf Coast.

Yeah. And it's, it's a beautiful setting. People from all over the world travel there to go to the beach, and that's where I grew up. I was, I was out in St. Pete's beach at the Don Cesar recently, and like the sand is unbelievable. Yeah, it's just, it's just crazy how soft the sand is.

It is. It's like, yeah, it's like powdered sugar almost. Yeah. So Sarasota, well, and that just that whole coast right there, St. Pete all the way down probably to Naples and Marco Island gets voted best beach. You know, they all sort of trade off, I think, in the world.

Yeah. And have been for quite some time. So yeah, beautiful area. Yeah. So, so you're from there, and is that where you went to elementary and high school and all that?

I did. Yeah. I grew up, grew up in Sarasota. Elementary, junior high, high school. Sarasota Sailors.

Actually, interesting thing, I was just back in Sarasota for the long weekend, and this is a community that is grounded in circus. So Ringling Brothers. Yeah. So it's the winter home of the Ringling Brothers and Barnum and Bailey Circus. I guess that may not even exist anymore, but it was growing up in my high school that I went to had a circus that— it was basically a student circus, a youth circus.

Really? And it's been going on for 70 years. And so this weekend was the 70th anniversary of this youth circus. Holy smokes. So when you were in high school, were you a part of this?

I was not a part of the circus. I know, that would have been a great angle, right? So disappointed. Yeah, no, I was not actually. And my brother and I were talking about whether we had friends who were in the circus or not.

So you must have thought about it at least. If you had been in the circus, what would have been your role? Yeah, that's a great question. And these are like kids anywhere from 14 to 16, 17 years old, right? And they did everything you could imagine, juggling, and they did the clowns.

Although I can honestly say I didn't really get the clown thing going on. Um, but probably, um, yeah, it would have to be the flying trapeze. Just that sort of feeling of, you know, flying. That looks amazing. Yeah, it was pretty cool.

Most likely to die. Yeah, exactly, exactly. Maybe the lion tamer. I don't know which one's— yeah, yeah, no animals in the circus. But, uh, anyway, so that was just sort of like a flashback to my high school days this past week.

So the Sarasota Sailors were also circus people. Yes, yeah, they had this volunteer circus. So yeah, it's kind of— it's just sort of ingrained in the culture in Sarasota. Great, it's a beautiful, beautiful area. Actually, the other little-known fact about Sarasota, Florida, if you ever happen to go down there, is there's the largest collection of Rubens in the Ringling Brothers— Ringling Art Museum.

Of Rubens? Yeah, Rubens, the painter, like Renaissance. Yeah. Yeah, okay. I know.

Yes, in a tiny little town in Sarasota, Florida. So yeah, so you, you ended up leaving there when you went to college, right? What I did, yeah, I went off to a little school called Stetson University. It was over on the East Coast outside of Daytona Beach. So not too far away.

Not too far, a couple, 3 and a half hours. And the reason I went there is to go— I've actually played tennis as a kid. So I couldn't be in the circus because I was spending all my days on the tennis court actually hitting tennis balls pretty much nonstop. And so I went over and played tennis my freshman year at Stetson University, a small little Baptist college. And yeah, did that.

And after my freshman year, decided that there were more important things to do, like study, of course. And so you stopped playing tennis and started studying. Exactly. And started studying my freshman year. And what did you study?

I was an accounting major. So kind of went down that path because it was a liberal arts school, which actually was kind of interesting because it had a very strong business school, but for the most part it was a liberal arts school, heavy music. And just went down the business track and the accounting professor who headed up the accounting department had the highest pass rate for the CPA exam. Wow. In the state of Florida.

So really solid program. I thought maybe that I wanted to become a CPA, but after a couple of years under, under his studies, I decided that probably wasn't the right path. So, so you said you studied, you got your accounting, got my accounting degree, yeah, 4-year accounting degree, came back to Sarasota and just sort of happened on a small organization. It was about 80 people, software company that had been recently acquired by Arthur Andersen. Okay.

The Big 8 accounting firm, Big 8 at the time. We know Arthur Andersen as the ones who are to blame for— That's right. Took the blame, took the blame for it. You're right, I should be careful. Allegedly, and they really didn't do anything wrong apparently.

We find out way later, but it still ruined them anyway. Yeah, it did. And so stumbled on this organization. So my accounting background came into play. And so do you have any kind of a software or technology background at the time?

I didn't know. I took a computer class in college and was lucky to escape there with a C, I think. And so you got a job at a software company doing accounting, or what were you doing? No, it was actually started out in customer support. So, you know, this is back in Shame to say this, but 1987, and it was right after there was a major tax law change, and they were basically staffing up for customer support people.

So, you know, to handle all those tax changes, whatever, to handle accountants calling in and asking, you know, hey, this program doesn't seem to be working right. Can you tell me? This is the calculation I expect? You know, why isn't it giving me this calculation? So as you can imagine, a bunch of stressed-out accountants leading up to April 15th, and I'm on the other end of that phone answering their— trying to answer their questions.

So it's your job to take the call and make them happy. Take the call and make them happy. Yeah, I actually think everyone in technology should have to be a call center agent at some point. I agree. To deal with the— really where the rubber meets meets the road.

I think that's a really good experience. Well, it's true, right? And then, I mean, you just think about certainly all the things that you read about around Simon Sinek, and you sort of put the customer at the center, and you think about put yourself in their shoes, right? And I think having that experience so young and right out of college is sort of having to be empathetic to what the customer is going through has always resonated with me and how I've kind of led my career, probably took me into product management and all those things where all you're doing is sort of thinking about what the customer needs and just putting yourself in their shoes. So you did customer, I guess, tech support basically, or customer support.

How long did you stay there on the phones before you found something else? Yeah, it was about 2 and a half years, I think. That's a good run. Yeah. You got good at it.

Yeah, I did stick around for a while. And I got yelled at quite a bit, to be perfectly honest. But it's a great way to learn, right? I mean, you're having to really sort of figure out the details, the guts of what's going on in the application. So from then, I moved on to the business analyst side of things.

So now evaluating tax law changes and IRS form changes and how does that translate into the software itself. I wasn't actually doing the coding. But handing off the logic. I was effectively writing the requirements and writing the logic, handed that off to a coder who would then translate that into the compiled code that would then generate tax returns. And then just kind of moved up through the ranks from there, ended up leading a big team.

By the time I left, it was a team of probably 70 people that were And this was still the software, the little software company within Arthur Andersen? Yeah, yeah. We had grown probably to a couple hundred people at that point. Okay. So it was the firm was using the software to prepare tax returns, not just for individuals, but for S corporations and partnerships and C corporations.

That was my area of expertise. And then we also sold it externally. So kind of had, you know, both sides of the equation. So yeah, I spent 10 years at Andersen and You know, one of the things that's interesting to me if I look back on it from a career perspective is the focus on professional development. I mean, back then, and certainly within a professional services organization, the professional development part was huge and played such an important part in my growth as a professional in my career.

Can you give any examples of like what that investment by the company looked like day-to-day for you? It was more of an investment. It wasn't as much on a day-to-day basis. So Arthur Andersen had a campus. They bought a university, small— I think it was a women's college outside of Chicago in St. Charles, Illinois.

This was a campus— dorms, classroom facilities, the whole thing. And They would bring in people from all over the world to come in and train, whether it was on more technical topics or more professional development topics, leadership, even things like, at the time, you're essentially buying into a partnership. So, there's a financial element to that as a partner when you rise up through the ranks of the organization, how to manage your money, how to get ready to buy into something like a professional service partnership that was 70,000 employees at the time when I left. So it was, it was the firm overall had made a huge investment. And so we would go up periodically for classes and courses and, you know, just how to be, how to be a good, you know, professional.

Anything resonate for you that like you took, if you take away one or two things from your time at Arthur Andersen, like this is, these are the most important things from that experience? That's a great question. I think starting out in customer support, back earlier, I think that is a great place to start. I think you do have empathy for the customer, and that puts you in a different mindset as a professional and how you engage with your customers, whether it's directly through providing services to them or what you're building on their behalf.

Just preparation, you know, I think is being prepared for what you're doing on a daily basis, meetings or your day or your week or planning ahead. Planning, I think, was a very important ingrained part in what we did.

Yeah, you got me on that one. It's a good answer. So you were there for about a decade. What ended up being the precipitation for you to leave? I made a decision to change my life and the scenery in which I guess I was.

I had grown up in Sarasota. I'd gone off to school not too far away and decided that it was time to really kind of just— You came back after college. You spent a decade in Sarasota still and you were ready for something new. Yeah. And so did you throw a dart at a map or how'd you pick where to go next?

I had been out to Denver enough and really more skiing in the mountains. So I'm a skier, just probably like most people who move here. And so I had been out to Colorado enough to know that it just felt comfortable. It seemed like a great city, growing, big but not too big, all the cultural things you'd need. Sports, you know, that just kind of ran the gamut.

So you stayed in Sarasota and you found a job that would relocate you out to Denver? No. Yeah, I wish. What'd you do? I packed up and moved.

Yeah, I just did it. Yeah, just decided that this was the place that I wanted to be. I had a couple of contacts here, but I didn't have anything lined up specifically, and moved out and just I just decided I would figure it out. Yeah, so, so you moved here, it sounds like probably in the '98 timeframe then. Yeah.

And what, you got here and you started looking for a job? I got here, I started looking for a job. I ended up, you know, one of the things that was interesting about Andersen, it was the, the culture, just a very strong culture, and you're working with very smart, very dedicated, very passionate people. And so when I started looking for my thing, I was trying to replicate that, right? And, and I found it a little bit challenging, and I would joke that I had a hard time holding a job for a while.

So I ended up with a small consulting company who— that basically the office had started because US West at the time was a client of this company, and that was the only reason the Denver office existed, right? So I joined them. I think they changed names to 2 or 3 times while I was there just in about a year. And so did that for a year and then— Were you doing product management or technical? It was more project management, yeah, and developing some training materials for new consultants to come on board.

So, yeah, kind of branched out a little bit. I kind of think of myself as product management and project management, program management in the early days was sort of my background, and this was something different. So, you know, kind of took a little bit of a turn in my career path, and I decided to see where that would take me. Okay. Where did it take you?

It took me— actually, it took me out to Microsoft. Yeah, for about 6 months. Out to Redmond? Yeah. So Anderson at the time had licensed some technology, or not licensed technology— excuse me, licensed content to Microsoft when Microsoft was starting up TaxSaver.

I don't know if you know. Yeah, so this is like, yeah, 1999, Microsoft wanted to get into sort of the Intuit game, basically Microsoft Money, Microsoft TaxSaver. And so that group needed some expertise of somebody that had developed software before, tax software before, and my Arthur Andersen friends called me up and said, hey, can you go help them out? So I went and spent about 6 months out in Redmond thinking— So are you to give the credit for how Microsoft Tax Saver has taken over the world over the last 20 years? Yeah.

I think they shut it down about 2 years later. What they learned is it's hard. That's hard stuff. I hate it. You don't dabble in that.

No, you definitely Definitely not. I mean, it's a pretty significant investment. You've gotta have the expertise, you've gotta be able to turn stuff very quickly because you don't know what the IRS and the states and all of that's gonna do. So I'm super curious, in all of this tax software, somehow we're gonna get to identity, and I'm curious where this is. It looks like you did work for Brocade as well?

I did, yeah.

I got into storage area networking through McData, actually. McData was a Colorado company. Joined McData as a program manager. They had acquired a software company out in Silicon Valley. Early, early agile folks, actually.

And McData was very traditional waterfall manufacturing. Hardware manufacturing. They acquired a company who was, you know, sort of Silicon Valley, agile, very quick, and those 2 organizations kind of clashed. And so they needed somebody to come in that could kind of help bridge the gap between the 2. And so that was my role.

It was to be out of Denver but yet work with this organization That was new to the company. How'd that go? It was good. I learned a lot. I learned an awful lot.

Learned a lot about Agile, learned a lot about just software and a different type of software, right? Something that was a little bit more visual, I suppose, because this was basically a discovery tool and a management tool at the time, SAN management. Management tool. So stayed with— yeah, see, my career has kind of jumped all over the place, right? I see.

But then finally we're getting to how I got involved in identity. So yeah, McData acquired Brocade. They were evil enemies. Those 2 companies came together and I stayed through the transition and then left to join Ping Identity at the time, actually. So it looks like— did you join Ping as head of the product management?

Yeah, I was. It was a very young Ping Identity. It was a very young Ping Identity. So that was in January 2008, less than 100 employees, and the product management function was really kind of just trying to get some structure and discipline around putting together product roadmaps, as opposed to being very reactive to what specific customers wanted. How do we take something to market and sell it to lots of customers?

In 2008, that would have been a single product, right? Right. PingFederate. PingFederate, the federation SAML tool, basically, at the time. So you came into a less than 100-person company and got to be part of basically building out a new product, or building out the product to be world-class, it sounds like.

Right. Yeah. So how did— I've gone through the transition of coming into an identity company without being an identity person. At least I was a security person previously, so I had a little bit of context. How long did it take you to figure out this whole identity world?

It's kind of complicated. Yeah, that's a good question. It did take me a little while. I sort of attached myself to the CTO at the time and then spent a lot of time, again, back to the customer-focused side of things, spent a lot of time out talking to customers and understanding what they were trying to do. And in the context of presenting a roadmap to them, then having those conversations.

So I sort of learned it through the eyes of customers, which gives you a little bit different perspective than sort of down in the guts, the identity standards and that kind of thing. It's almost like a salesperson in that you're just trying to hear what the problems are, right? Exactly. And then figure out what the solution is. And of course, the difference is, as a salesperson, now you try and say, Well, here you go.

I got something that will fix that. And of course, you're saying, I'm going to go build something that will fix that. Right. Exactly. That's an interesting perspective.

Yeah. I mean, it's a great way to learn. Anytime I think you can see things through the eyes of the people that are dealing with it on a day-to-day basis, it gives you a whole different perspective. So you didn't do product management the whole time at Ping? You made a change at some point?

I did, yeah. So I did product management at Ping for 2.5, 3 years, I think, and then transitioned into product marketing. So, you know, just sort of following the path, right? Continuing to build out my skill set based on the needs of the organization and just based on my interests as well. So, product management and then learning about what customers want and then kind of flipping that and turning into product marketing and how to go tell that story.

Yeah. So, for those who don't know, I think you just summarized it, right? Product marketing, maybe you could give a 2-paragraph description of what that means exactly. Yeah, I mean, to me, it's telling the story of how your technology or how your solutions can help solve the problems that they have, right? And trying to stay away from the speeds and feeds side of it, but more focused on business needs and the value that your technology technologies can provide.

Where would a practitioner in the field run into product marketing? Is this what's coming in the emails to people, or is that a different function? Where does your work go out to the world as product marketing? I think it goes out in terms of the stories that the customer— sorry, that the sales organization sells, so helping to equip them with with stories and use cases that they can talk to customers about. These are the problems that we're seeing across the customer base or the prospect base, and here's how we help solve them.

I think it is through content that shows up on the website. It's solution briefs and data sheets and all of those things.

It is manifesting itself through emails that go out to customers. So I think about it as, you know, really sort of the experts on the product and the experts on the market, and how do they tell— how do we tell that story to the story of the customers? Yeah. So you did that for about 2 and a half years, and, and, you know, you and I did not work at Ping at the same time before I got here. So what happened?

Yeah, so Ping was a fantastic place to work. I, I loved every minute of it. Andre had created an amazing culture. And it was, it was time for a change for me. So I took some time off, got a chance to travel, which was a lot of fun.

That's sort of a passion of mine. Where'd you go? And oh gosh, where didn't I go there for a while? St. Thomas, just for, you know, fun little getaway to the beach. I'd never been growing up in Florida.

Why would you go to another beach, right?

Patagonia, the Argentinian side of Patagonia. So that was amazing. Was there for about 2 weeks hiking, which was fantastic. You know, it's just absolutely gorgeous down there. And then South Africa— was in South Africa for a couple of weeks as well.

This is awesome. So yeah, yeah, it was, it was time to kind of just take a step back and focus on, you know, what was making me happy. Yeah. And, and that definitely is going and experiencing other cultures and seeing different places was the main focus for that. So kind of a little bit of a breath during your career.

Take a minute. Yeah, yeah, exactly. So I did that and then, you know, kind of eased back into it because I didn't want to write, you know, don't want to jump full into full-time right away. So I worked part-time for a little while with a kind of staying in the identity world and still staying in the Ping Identity ecosystem, if you will, and worked for a system integrator that was headquartered here in Colorado. Pegwright.

We've talked about some jobs there in the past. I know that now they're not Pegwright anymore. Right. Proof ID. Yeah, and that gave me an opportunity to see things from the services side.

So I had been on the vendor side really for all my career, but specifically in an in identity and security. I'd been on the vendor side, and so this gave me an opportunity to see things, a whole new world, right, on the services side. Very much a different approach and helping customers solve different problems. And at the time, we were probably full-blown into the skill set shortage, but it was great to see things from that side of the customer problem. Yeah, which then kind of took me into Optiv.

So I joined Optiv in 2016, and that was really when I first got my first introduction to the Identity Defined Security Alliance. Yeah, so, so high level, what was your role at Optiv when you were first hired there? Yeah, so at Optiv, I was the Director of Solutions Marketing for Identity and Access Management. So my primary role was to support the practice, so the delivery side, and, and then the presale side. So Optiv has a a team of identity experts that sort of overlay to their broader sales organization that just sells identity solutions, technology services, etc.

And so, my responsibility was the go-to-market for Optiv's identity practice. Yeah, and how big a practice is their identity relative to pen testing and other practices they have? Where does that slot in for Optiv? Yeah, from a revenue perspective, one of the bigger from a services side. From a technology resell perspective, small.

But from a services, the interesting thing about that group, and it was the leadership for sure in the identity practice, but very much more mature delivery organization than any of the other services organizations at Optiv. So you were there basically Basically figuring out how do we go to market with these services, how do we make the right partnerships. I assume you were part of those conversations as well. Yeah, it was more around the partnerships that had already been defined. Optiv does work with everybody, but the identity delivery group looked at it from a solutions perspective.

In some ways, we're a bit more selective in terms of who their partners were. That they were going to go to market with and wrap their services around. So it was really how do we bring those 2 things together and talk about it in the context of the full lifecycle, right? So from strategic consulting to the RFP process and the selection process to the implementation, architecture implementation, and then even into to post-production. So it was sort of how do you package up the service offerings along with the partners and take that to market for customers.

Awesome. So you at some point, I guess I'm not sure how to transition, talk to me about the IDSA and like when did you first become aware of the IDSA? Yeah, so that would have been right when I joined Optiv. And that was about the point in time when Optiv started to get involved. So maybe talk about the very— the history of where this thing came from.

Yeah, so the history of the IDSA is it was started as a Ping Identity Technology Alliance program is how I think of it, right? And starting— yeah, and looking out— 2015, 2016? 2015, yeah. And so, you know, this concept of identity-centric security or identity-defined security and how do you start to to take the intelligence that exists in these more traditional security technologies around user, right, the user context, and how do you bring that into an identity, in this case authentication and authorization, and make decisions based on that information. So real-time intelligent decisions, access decisions to data and protecting data.

So the way I— when I first got associated with the IADSA, or first time I heard of it, basically when I started at Ping or maybe right before, and it really answered the question for me. We'd said for years that the firewall is dead, by which we mean that it's no longer the place where you could put all your chips on your security program, but we had never really defined what should take its place. You can't get rid of an old paradigm until you put a new one in place. The IDSA for me was this basically reference architecture to say, actually, there is something to replace with, and here it is. It actually showed what are the pieces that you need to put together to take the place of the perimeter-based security program.

Right. Yeah, very much so.

Ping had driven that with several core partners. VMware and Netscope and ThreatMetrix were some of the originals. Then Optiv got involved because you needed solution providers to take that solution to market. I think it's nice also, and Ping basically realized that it's more credible if it's not coming from one of the people who is providing the services, right? Or providing the solution, I guess, the software.

Well, and we sort of took that to the next level. We being Optiv said, this is something that really has legs in terms of more of an industry focus.

And that's really kind of where that whole idea started. I was working with Robert Block at the time at Optiv, and he was involved with sort of helping to architect the early, you know, the early reference architecture, if you will, or framework around the IDSA. We started talking and, you know, felt like this is something that has a bigger impact or could have a bigger impact on the industry. Yeah. And so in 2017, we expanded it and brought in another 7 companies into that, some competitors to Ping, to try and take it more— make it more vendor agnostic, if you will.

And then this year, the beginning of 2019, we have 23 companies, both identity and security companies, that are members, as well as 7 customer advisory board members that help guide us. We just recently organized as a Colorado not-for-profit organization, so we're now truly a standalone entity and working towards becoming a 501 trade association. So, you know, the goal is really to be truly an industry. Initially, Ping had created this thing and at some point kind of handed it off to Optiv to run, and it sounds like there's been some transition from Optiv now and like How does funding happen? And I believe you're an employee of this organization.

How's that all work? Yeah, so the membership dues, so the members pay in and that's effectively what they use for the operations of the organization. So yeah, as of October 1st, I became a full-time employee, the full-time employee I guess I should say, of the IDSA as the executive director. And yeah, I've been And since the last 2 quarters, kind of created a standalone entity, it's kind of like starting up a company. All the different things that you have to take care of that you don't really think about.

So I have a lot of questions. I guess let's start off with, like, what— this is like your full-time thing. What is your mission? What's going to drive success for you in this role? Yeah, that's a great question.

And if we, I guess the way I think about it is there's different constituents, right? So there's different stakeholders in this. I think our ultimate customer for this is practitioners within enterprises or organizations. I'll say organizations 'cause it could be government agencies, it could be any type of entity, practitioners who are trying to create They're trying to make sense of the chaos that they have today, right? If you think the security chaos, in a lot of cases they've invested in lots of different technologies, security technologies, identity technologies, etc.

How do they basically leverage those existing investments to become more secure, right? So if identity is still the thing that is the most compromised in the way hackers are able to breach organizations and get access to data because that's ultimately what they want to do. And so how do we leverage the technologies that are already there today to make them more secure by using identity as the core thread through all of those different technologies, if you will? So if we can help companies be successful in implementing an identity-centric approach to security, whether it's through frameworks or through telling stories and having customers tell their story of how they've done the those who've done it in the past. You think about the 20% that are probably leading the charge around this thinking and that they recognize identity as core to security.

If we can get some of those 20% to tell the story to the 80%, then hopefully we can bring everybody along. So you mentioned some frameworks, and I'd love to hear what is it you guys are— the goal sounds great, right? We're trying to move toward identity-centric approach to security. What are the tools that you're using or the means of delivering this kind of message, this gospel? Yeah, so what we've created today is a framework, and it really consists of 3 pieces.

So IAM best practices, kind of, you know, what's good hygiene? What are the good foundational things you should do as an organization around identity? Not necessarily required, but smart things to do and will make an identity-centric approach that much more effective. We define security controls. So security controls would be things like access management and cloud access security broker, right, a CASB, and what are the capabilities you need in each of those components, and then what happens when you bring those 2 things together and you share information information across those 2 technology components.

So think about authentication and CASB and IGA technology, sort of the building blocks, and then how do you bring those together to become more secure. And use cases are sort of the 3rd component. And use cases are how do you combine security controls to be more effective, to solve more complex business problems. So that's sort of the framework that we're building out at this point, and then we'll put the business lens on it as well. So one of the upcoming technical working groups that we're going to be chartering this week actually is to look at zero trust, and there's lots of different— zero trust is a buzzword right now, but we believe that identity-centric security is the way you can actually implement and achieve a Zero Trust strategy.

And so we're looking to come out with a reference architecture that helps enable a Zero Trust approach. Yeah, so I've got the website open. It's idsalliance.org. Right. And some good resources under the framework there, use cases, and like you mentioned, security controls, best practices, customer stories.

If there's folks who, you know, great you have resources and they can browse through the website. What if folks want to talk about this? Is there any place that, like, any meetings or any way that people can, like, get more information and, like, interactive information about this stuff? Yeah, so online through the community. So register in the community.

You can join and, you know, we're still working to get people engaged and involved and interacting online. We do meetups at some of the bigger conferences. We sponsor— we'll be at Identiverse, we'll be at Black Hat, we'll be at Gartner IAM.

The idea is that we'll tell our story through a session, speaking session, panel primarily, just to get practitioners and experienced folks up and telling their story as well. And then trying to get out into the regions and through Cloud Security Alliance and IAM user group meetups and those kind of things. So we're sort of trying to grassroots, let's go where the people are that are already talking about identity. Instead of creating a new place for them, you're trying to go to where they are. Exactly.

That's great. Exactly. So there's a lot of different elements to Identity Defined Security, and you can go a lot of different ways. For those folks listening who maybe this is a new concept to them, Are there any critical few things that you could point out to say, hey, these are the places to get started with a transition? Yeah, that's a great question.

We've had lots of conversations about maturity models and here are the 5 things you need to do. Where we've started is sort of helping out with just the foundational elements of things. If you go to our blog, you'll see there's a couple of best practices blogs that have been written recently, and that's focused on what's good IAM hygiene. So just starting out there, I think identity is still hard, and I think one of the challenges as well is that identity is still very much rooted in the operational side of an organization and not so much security. So we're trying to cross-pollinate that as well so that CISOs start to think about identity as strategic to their security strategy.

But I think that's starting out with just reading through the blog and the customer stories just to kind of get a feel for exactly how can you implement this within your organization. Yeah, I've got that open. It looks like IAM Best Practice Blog Series. Several things going on there folks can use to get smarter in that area. Are you looking for anybody to help you guys?

Are you looking for volunteers, anything you want? Yeah, absolutely. And I think the community is one way to do it. If there are vendors that are interested in participating and helping us to further the mission, certainly reach out to me through the website or julie@idsalliance.org. Yeah, I think the more hands in this problem, the better.

So if, let's say at the end of— I'm gonna give you a little time— at the end of 2020, 18 months, you know, whatever it is, 20 months from now, what would make you like wildly happy if you have accomplished what things through IDSA in that time? Yeah, that's a great question. I would say that if We have an active community.

Practitioners are sharing best practices. They're talking about the integrations that they've implemented with success, or maybe they're sharing tips and tricks on how to make it better. But people actively engage in having conversations around, this is the approach we are implementing in our organization, and this is what's made us successful. And this is what we recommend to others and helping each other fast-track that process. This is awesome.

I'm excited to hear that you guys have turned into a nonprofit so you can really go after this without the same profit motive, which kind of changes the way people do business. That's exciting. And I think you guys are the best hope for kind of an open approach to Zero Trust that I've seen out there. There. So I'm excited to see it.

Is there anything— I've asked the questions I needed to ask. Is there anything that you wished I'd asked that I hadn't gotten to? That's another good question.

Um, yeah, I think you, I think you hit on pretty much everything, um, other than maybe, you know, hey Julie, I'd love to get involved in the IDSA. Hey Julie, what can I do to, to get more involved in the IDSA? Maybe put you, put you on a podcast? I would love That would be great to put me on a podcast. Yeah, and I would love to have you involved as a CISO helping guide us in the right direction.

So, well, I, like I said, I am a big fan of what you guys are doing, and anything I can do to help support it, I will. If anything else for the community before we call it an interview? I think that's it. Awesome, this has been great. Well, thanks, Julie.

It's good talking to you. And for the rest of the community, we'll talk to you guys again next week.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes