All episodes

Mary Writz, VP of Product Management at ForgeRock

Apple Podcasts Spotify SoundCloud

In this episode:

Mary Writz, VP of Product Management at ForgeRock is our feature guest this week. News from: Udemy, VF Corp., Scale Factor, DarkOwl, Automox, SentinelOne, Swimlane, root9B, LogRhythm, Coalfire and a lot more!

Lone Tree is the new downtown?

A new downtown in Lone Tree, with 40,000 jobs. Udemy and Scale Factor bring jobs to Denver. VF Corp sheds Kontoor brand. DarkOwl releases a new darknet risk scoring tool. Automox partners up with SentinelOne for automated patching within endpoint protection. Swimlane wins some awards. root9B investigates Operation ShadowHammer. LogRhythm blogs on healthcare security. And, Coalfire releases a new scanning platform.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript9421 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 112 for the week of April 8th, 2019. This is Robb Reck, CISO from Ping Identity.

And this is Alex Wood. How are you, Robb? I'm doing great, Alex. How are you? I'm wonderful.

It's a beautiful weekend, right? Finally seems like spring may have come. Oh man, so nice, so nice. My younger son had a soccer game yesterday, was outside for a little bit, just hanging out in the sun. It was wonderful.

Yeah, we did a couple of bike rides this weekend, and I know we ended up playing some sports outside, basketball in the cul-de-sac and everything. Anyway, It's nice to get the weather changing. That means it's going to snow next week, right? Is that how it goes? And it'll destroy all of those brand new leaves that have been sprouting from the trees, right?

Exactly. Yeah. Well, why don't we go ahead and dive into the podcast? We have some housekeeping to go through first. There's a Slack channel.

Have you heard about this before? What? What are you talking about, Robb? I don't— I've never heard of this. So Slack is basically like a big chat room that all the folks who can join— there's a link to join on the front of the colorado-security.com website.

We have over 850 security practitioners here in the Denver area who are parts of this, and we'd love to have other folks join us as well. We also have a mailing list, so you can check out our website, colorado-security.com. Go there for more than just the mailing list, but at the, the bottom of the main page, you can find the mailing list sign-up. Sign up there, and you will get the show notes in the mail from us, be the first to know when a new show comes out, and get all the details. And one way you can help us as a show is if you would rate us and subscribe on your favorite podcast listener.

Helps other folks find us if there's more ratings out there saying nice stuff about us, so we'd appreciate it if you'd help get the word out. If you don't want to rate us, which of course you should, then it would be great if you just told a friend about how great Colorado Equal Security is. Get them to listen to the podcast and just spread the word. So if you've already rated us and you've already told a friend and you want to do even more, well, you could help financially support the show through Patreon. This is an opportunity for you to help us defray the cost of the show, and we make sure everything that you guys give to that goes right back into the community.

All right, so let's jump into the news. First, there's going to be a massive development in, uh, Lountree to create a new downtown and potentially 40,000 jobs. This is going to be on the east side of 25, which is kind of different than all the other development, you know, like Schwab and, um, well, everything else has been on the west side of the freeway. This is going to be just on the east side of Ridgegate there. Yeah, so expanding across the highway should be interesting.

I think sounds like there's going to be sort of 2, uh, 2 sections there. Um, but building that out, which I guess is not surprising at this point, the, the light rail kind of swings around on that side and, and dumps you off over there. So, uh, expansion down in Lone Tree. Uh, it looks like it's gonna have about 12 million square feet of office, retail, and healthcare space, um, 10,000 homes, more than 60 acres of parks. Uh, pretty cool stuff.

It's gonna be the, uh, Lone Tree City Center, and it's gonna be their new downtown, which is kind of funny because I didn't know that Lone Tree had a downtown. So I didn't know they had an old one even. Well, Lone Tree is not that old, so I can't imagine that the downtown is very old either. Next, we have a couple stories about companies that are coming to Denver. Is it Udemy?

Udemy? Probably Udemy. Who knows? Udemy, which is a San Francisco tech firm that does training, is leasing in Lodo to put down roots in Denver. Yeah.

So they, they do, they do training, as Robb said, and they're looking to hire as many as 200 employees.

The expectation is that they will have 50 more by year's end, bringing the, the total currently to about 70. And then kind of a similar theme, the Austin company Scale Factor is making Denver its second national office. They are currently at about 12 employees, uh, and they plan to be within 100 or to be at 100 within a year. Uh, it's a finance and accounting platform that helps email— that helps small businesses with their back office needs. It sounds maybe like a little bit of a QuickBooks or Xero or something.

Or maybe like an ERP type system. I'm not sure. Yeah. Uh, next, um, VF Corp, which as we know is bringing their headquarters to Denver, uh, they've announced that they are going to be spinning out one of their some of their companies into a separate company, Contour Brands. So this is something that had been in the works for a while.

I think that they had said, you know, even when they announced that they were going to be moving here. So if you were hoping that Wrangler, Lee, and some other brands were going to be headquartered in Denver, well, you're going to be really disappointed here because they're not. Too bad. But it looks like those, those companies that are spinning off by themselves are pretty big with over $2.7 billion in annual revenue. Yeah.

And I believe that they are going to be headquartered in North Carolina at, I think, the previous Wrangler headquarters. So moving over to the more security-focused news for the week, Dark Owl has announced a release of a new darknet cyber risk scoring tool. Yes, it is called DarkInt Scores, and this calculates an organization's footprint on the dark web and converts it to a numerical value. So, you know, credit score for the dark web, I guess. Yeah, and it's really interesting to think about, like, what does that exactly mean?

And, and, and how do you, do you want to have a good score? Do you want to have a bad score? Uh, right. It's going to be something to figure out as it goes, but it's great to see them trying to put some data to this versus what I've seen from other services is basically just, here's anecdotal information. Right.

And it doesn't give you any kind of relative posture versus others. Yeah. And it looks like you can get that information either through their, uh, their web app or through an API. So this could be something that you feed into, you know, a GRC tool or, uh, or your SIEM, right? Your SIEM incident response Is there something else to see, you know, how you are essentially performing over time?

Yeah, pretty cool stuff. Uh, next, uh, SentinelOne and Automox announced a partnership where you can automate patching, um, through SentinelOne. So SentinelOne is a, uh, call it next-gen, uh, antivirus company. And with this integration, there'll be more ties through the SentinelOne agent. So you'll be able to tell Uh, what patches are missing and other things like that and do sort of auto remediation through AutoMox.

Yeah. Pretty cool stuff. You can, you can make, you know, just use the, using SentinelOne, I think you can make it do the deployments of patches. So pretty cool tools. Yeah.

Uh, next, uh, Swimlane, our local SOAR security automation or security orchestration automation and response company, uh, has won 3 new InfoSec awards. These are all given by the InfoSec Awards group in 2019. Uh, number one, they got most innovative in enterprise security. They got most innovative in security orchestration, automation, and response. And they got, quote, next gen in the incident response category.

I wonder if next gen means that they're too early for their technology. Is that what that means? I don't know what that means. Or the, uh, all of the first gens are now old and crotchety. All the last gens are too old.

That's right. So now we've got a new gen. They're, they're now old and are too slow at responding to incidents. So they needed next gen. Anyway, uh, congratulations to Swimlane.

Uh, next up we had a blog post from Route9B. Uh, this was talking about Shadowhammer and, uh, I don't know, I'm sure people have heard about Shadowhammer in the news. This was a, um, a campaign that they infiltrated the ASUS software update service. So when you were getting downloads, um, through their, their auto updater, you got malware installed. This is, this is the old watering hole attack here from a trusted vendor.

Of course, if they make your laptop, The interesting thing about the campaign though was that even though there were many people that were infected, there were only about 600 MAC addresses that the malware that was put there actually downloaded sort of a second stage. So they were clearly as part of this targeting certain computers. And as part of this blog post, Root9b goes into a little bit about the campaign itself, but also them cracking the, uh, the downloader itself to get the MAC addresses out. So there's a list of the MAC addresses in this. Yeah, pretty cool that, you know, a local company is working on this, uh, this story.

That was one of the, um, one of the big stories here for, for a couple weeks in security. Anytime you can find a, a main major manufacturer like that who's distributing malware, it's big news. So congrats to those guys. Uh, next we have a blog post from LogRhythm around evaluating your cybersecurity position in healthcare. I would say number one, this is not a healthcare-specific blog.

If you want to read it, they do, you know, kind of put it that way. I assume they did that for like search engine optimization, but as I read through it, it doesn't actually seem all that focused on healthcare. It's just really any organization's security operations. You know, they point out the fact that, uh, it's, you know, we're all under-resourced. We all have more work to do than we can, and, and there's a big trend that it takes a long time to find bad guys once they're inside your environment.

So they're pushing toward shifting from prevention to detection in your security controls and evaluating the maturity of your security practice, your security operational practices, to make sure that you will catch things when they're happening and really focusing on that as a first step. Nice. And our final article this week is from Coalfire. They had a blog introducing their new scanning platform, Coalfire OneScans. So this is actually written by a friend of mine, Beck Larson.

I think you've probably met Beck at different events over the years. Um, she's— I think I have. She's the director of scanning services over at Coalfire. Um, so they announced this, uh, this new platform, Coalfire OneScans, that's going to do PCI-approved scanning, um, for both internal and external services. It really looks like they've just tried to turn this, uh, into a, an easy-to-consume service versus, you know, when you buy like a, a Rapid7 or a Qualys or whatever, where you're really kind of running your own tools.

This is a service you sign up for, you provide some details, and they go do all the work for you. Yeah, I, I feel like some of the other, uh, big PCI shops like Trustwave or things like that have services like this as well. So it makes sense for, uh, Coalfire as they've gotten bigger to do that too. Cool, cool to see them making that, that maturity step, uh, new step forward. Well, that's it for the news.

Let's go ahead and jump over to our Slack message of the week. Big thank you to Andre Gaeta. Andre is the really the mastermind and the, the, the pocketbook behind the Slack Message of the Week. 2 important points. Yeah, Andre, we appreciate what you do there.

Uh, every week we recognize one person who started some good conversation or made a really useful post in the Slack channel. This week we want to give a shout out to Esell, and, and this is E-S-E-L-L, that's his call name, and I don't know him personally, so I'm going to just go ahead and use that as the only thing we identify him by. Um, he started a really good conversation about OSCP, and I don't know when it was, like 2 or maybe 2 years ago, 3 years ago that OSCP became really a highly demanded cert and something that people are really working hard for. Yeah, it's definitely something that it takes a lot of work to get and shows that you have diligence and dedication and skill. So kind of seems like it took the place of the G-PEN maybe, or Certified Ethical Hacker as those things that are the most in-demand skills for your offensive side.

Right. Anyway, so congratulations to Ecel. We will send a note over. So you're welcome to pick something from the Colorado Equal Security Security Store, your favorite piece of swag that's valued below $25. We're looking forward to seeing you around town and whatever that is.

Awesome. Let's jump over to events first. Before we get into the events of the week, we, we need to, I think, conclude our Rocky Mountain Information Security Conference keynote discussion. Let's recap. Yeah.

The first night was Tuesday night. We have Michelle Dennedy. Michelle Dennedy is a chief privacy officer from Cisco. Yep. We start off on Wednesday morning with Kim Zetter, the author of the Ooh, it's the Stuxnet book.

What's it called again? Countdown to Zero Day. Countdown to Zero Day. Yep. Then closing out day 2 on Wednesday, it's going to be me and you doing a live episode of Colorado Equal Security where we will be interviewing Debbi Blyth as our featured guest.

Debbi's the CISO for the state of Colorado. Thursday morning, we have Mikko Hypponen, who is the CEO of F-Secure. All right. And then our final keynote. Go ahead, Alex.

So going with tradition, we are again closing out the conference with a comedian, Nancy Norton. She is a local comedian here. She, within the last— was it last year or is it 2017? It was last year. Last year she won the Boston Comedy Festival.

Yeah, very, very cool stuff. So she's an up-and-coming comic. She's a local one here and someone who we're really excited to hearing. And I think it'll be a good way to close out the conference. Yeah, should be good.

Looking forward to hearing her. All right. Next, we do remind you that we have a calendar of events on the website at colorado-security.com if you want to go check out everything that's happening in the community. We do our best to keep that up to speed, up to, up to date. Um, and I remind you one more time, in July there is a, a week-long cyber camp that's being held by NCC down in Colorado Springs.

This is July 15th through 19th. This is a chance for your teens to get out there and really get some exposure to, to cybersecurity and, um, really hopefully, you know, give them a visibility about what a career in that space might look like. I'm telling you early so you can sign up because, you know, summers go fast and this is going to fill up. Yep. First event, CTA is having their Progress and Potential: A Profile of Women Inventors on US Patents on April 9th.

Also on April 9th, SecureSet is doing a beginner's intro to capture the flag. On April 9th and 10th, ISSA Denver is doing their April chapter meetings. On the 12th of April, there's the office hours with Davis, Graham, and Stubbs for some legal advice. On the 15th, SecureSet is doing a Denver Blue Team workshop, Fundamentals of Network Defense. Uh, all on the 16th, there is the Denver Splunk Meetup.

Also on the 16th, CSA Colorado is doing their April chapter meeting. The 16th is very popular because it also is going to have the Denver IAM Meetup at the Wine Coop Brewery. Um, one more on the 16th and rolling over to the 17th, ISSA Colorado Springs is doing their April chapter meetings. On the 17th, ACES is doing their April meeting. That is the physical security group that's meeting there.

Also on the 17th, DENSEC is doing their April hangout at the Rheinhaus. On the 18th, the CTA is doing their Insight Series. This is about AI-enabled analytics, business intelligence and analytics in the area— in the era, excuse me, of artificial intelligence. Maybe they're talking about the area of artificial intelligence also. So that'd be good.

Yeah. Did I say that's the 18th? Because that's the 18th. That's the 18th. Also on the 18th, ISACA Denver is doing their April, uh, annual general meeting.

So this is the big meeting that they have every year. Um, they do board elections and lots of other stuff like that. They usually have cake there too. I bet that they have cake. Yeah, it's pretty good stuff.

Uh, finally, also on the 18th, uh, SecureSet is doing a cybersecurity meet and greet at the SecureSet Academy. This is a chance for you to, to get to meet not only the folks there, but other folks in the community. Uh, on the 19th, PMI Mile High is doing their 21st annual symposium. So this is the Project Management Institute chapter here in town. Yeah, that's pretty fun.

And the last event for this week, the CSA Denver is getting— is doing a Denver CCSK training on the 19th and 20th. So 2 days training if you want to go get cloud certified, cloud security certified. I assume Muhammad Malki is giving that training. You know, I Don't know off the top of my head, but that seems like a pretty safe assumption. I think it's a good guess.

Yeah. All right. So that's, that's a lot of events in the next 2 weeks, Alex. It is. So if you need to learn stuff, get busy.

Yeah. All right. Let's go ahead and jump over to jobs. There are a couple of opportunities at Ping, so I'll do those first. I'm hiring a junior product security engineer.

This is someone who has development background, but you don't necessarily have to have a bunch of security background, just someone who's, who's a strong developer who wants to get more involved with doing application security. And then if you want to be that person's boss, we are also hiring a product security team lead who will help, um, who will help us kind of organize about half of our product security team focused on our SaaS products. And that person should have some more experience in security and still have a strong development background. Risk-Based Security is looking for a threat intelligence research slash analyst, and I believe this job is listed in Boston but also can be remote here in Denver. Yeah, that sounds right.

Recurly is hiring a senior application security engineer. Zivelo is looking for a senior software engineer. Bank of America is hiring a cybersecurity incident manager. Visa is looking for a senior cybersecurity engineer. Adams County is hiring an information security analyst.

Dish Network is looking for a cybersecurity threat hunter. And finally, NBCUniversal is hiring a cybersecurity architect. Um, and that is for DDI, which is DNS, DHCP, and IPAM. Well, you did a better job paying attention to that than I did. Well done.

Well, that is it for the news this week, Alex. Uh, I think this week you sat down with Mary Writz. You want to talk about that at all? I did. Um, I've known Mary for an awfully long time.

We worked together at IBM and probably came there about the same time. Um, she's done a number of things over her career. Uh, she's been a penetration tester, led, uh, teams of penetration testers and hunt analysts and other things like that. She is now on the product management side of security. And so I talked to her a little bit about that.

But also, um, what is really cool is when we put out the call a couple months back for people to come help the show, maybe do interviews for us, Mary stepped up and said, hey, I would love to do some interviews. So Mary is going to be doing a series of interviews with women in cybersecurity, a lot of them on the, the product side, which is, you know, sort of a side that we don't hear from a lot. But this is sort of the, the first introduction, and that is interviewing Mary. And then in the future weeks, we'll have some interviews from Mary interviewing other women in security. Awesome.

Well, and if that inspires anyone else listening that wants to help us with interviews, reach out. We would love to get your help, and we can give you some details on how to do that. I think that's it for this week. Awesome. All right.

We'll look forward to listening to the interview next, and we'll talk to you next week. Thanks, Robb. Hi, this is Rich Schliep, the CISO for the Colorado Department of State. This is Colorado Equal Security for Colorado security professionals by Colorado security professionals.

Welcome to Colorado Equal Security. This is our feature interview, and this is Alex Wood. I have a very special guest today. Welcome, Mary Writz. Hey, thanks.

Glad to be here. Awesome. Glad to have you here, Mary. I'm excited for this conversation. We've known each other for an awfully long time now.

Yes. You know, we started working together— oh my gosh, it was probably— it's getting close to 20 years. Yes. It's not 20 years, but it's getting close. Almost.

Yeah. We worked together at IBM, not ever on the same team, but in the same Yep. And we've been doing that for— or we did that for, I don't know, 6, 7 years probably before I left anyway. Yeah, maybe even longer than that. But, you know, we've stayed in contact and it was always great for, you know, when you were organizing sort of IBM security alumni events, we'd get together and things like that.

Yeah. But for those people that don't know you, why don't you tell us a little bit about yourself? Sure. I am— well, right now I'm leading a product called— it's an identity and access management product. I'm not used to being the interviewee.

I'm VP of Product Management, and I really enjoy this job. I enjoy product management, but my history has always been cybersecurity. When I started at IBM, I joined a pen testing team. Did some application testing, did some network security testing, some forensics work, security intelligence work, and then I joined a services arm where I started developing services. It was like product, but on the services side.

Then I just kept going with the product management from there in different areas and developing products and services. Managed services, professional services, hunt teams. I did the ArcSight sim, and I'm with ForgeRock. Nice. I don't even know if I know, were you doing security before you came to IBM, or what were you doing?

How did that lead up to that? Great question. So I had just, you know, when I joined IBM, I just graduated college, so I was fresh out of college. But I had been— First job? Yeah, it was my first job.

Nice. And I had been working at a small startup in downtown Denver, and they did data, data stuff, but I was the IT admin. And they thought they got hacked one day, so I started poking around, and I, I learned about Nmap and started scanning things. And then I was starting grad school in Boulder, and on the email list, IBM was looking for pen testers. At the time, they called it ethical hacking.

Yep. And I was not qualified, but I thought, I'm gonna throw my hat in the ring. And I got an interview, and I thought, man, I didn't do a great job in that interview because I don't know what I'm doing. But nobody knew what they were doing then. Exactly.

So I knew just as much as anybody else. In fact, maybe more because I knew how to use Nmap. Yeah, so I— then I— so my first real big job out of school was IBM. Nice. What was— what did you go to school for?

Was it computer science, or— I did information systems and math. And then graduate school is telecom. Nice.

So, so you got in, you started doing pen testing. What was that like learning that whole trade? You know, in the early 2000s when it was a much different world than it is today? You know, I joined the team and they were afraid to let me touch any customer systems. They sat me in a corner.

Probably rightly so. I don't know that I would hire even today anyone off the street and let them immediately go jump do stuff like that. But they sat me with— remember that big red Hacking Exposed book? Yeah. Okay, so I sat in the corner and read that, and, and it felt like— I don't think it was months, but it felt like months were going by.

And I thought, no way they're gonna keep paying me to just read books. So I set up Linux on my box, and I set up Nessus, and I started scanning things. And I was reading, you know, Smashing the Stack for Fun and Profit, and playing around with buffer overflows. So I So I went to my boss and said, look, I, I can do all of these things. And then they said, okay, and then they let me loose.

Um, but actually they put me on an app testing team, which was kind of white box hacking. So you're like a multi-tenant environment trying to get to customer B from customer A. Um, so that was pretty safe for me, but then I just kind of learned on the job just by doing kind of what I did to get started, which is just playing around. You know, playing around with lab environments and workstations that I had at my disposal. Yeah, if I remember right, at some point you ended up leading that team too. Yes, I did.

Yeah, for many years, and that was probably my most fun job. Like, I think of that the most fondly. We were having the best time. It was in an era where you could— we hacked into banks, we hacked into jewelry stores, we'd walk around and crack everybody's Wi-Fi network. I mean, everything could be broken pretty simply.

Now I, I look at what the pen testers are doing and it's so sophisticated and they're so focused in one tiny discipline. But at the time we were just, we were doing anything. We would take any kind of pen testing gig, whether it was a system or an application or Wi-Fi or network or whatever. Well, I think things were, were so less defined then too on you know, what a pen test was or the things that you should be doing. Not that things aren't creative today, but it was kind of like choose your own adventure, right?

It's like, hey, you're hiring me to do something. You don't exactly know what you're hiring me to do. I don't know exactly what you're hiring me to do. We're going to go break some stuff and have a good time. Yeah, yeah, yeah.

It was good, but it did get boring. I remember thinking if I see one more SQL injection, like I was just going to barf. I'm— it's probably gotten a little bit better, but I'm sure that pen testers today have some of the same feel. Maybe it's not SQL injection, but it's I'm sure that there's something out there it's like, oh my God, if I can't— if I see this one thing again, it's gonna go crazy. Yeah.

Uh, all right, so you mentioned some of the things that you did, but after that team, what was the next step for you? Uh, the next big step was moving into, um, product and portfolio management. So I was designing some services with IBM. I think my favorite one was DDoS. I think DDoS is really interesting because it's the most unfair, imbalanced attack.

You know, as someone that's trying to provide a robust environment, you just have to be able to take a punch, and that's expensive, and it's pretty cheap to launch an attack. So I really enjoyed this. I enjoy working on DDoS. I moved to Hewlett-Packard and did some professional services work, primarily building hunt teams, looking for new ways to find threats and breaches in the environment with big data. So playing around with Jupyter Notebooks and some machine learning algorithms, which I really enjoyed because it was innovative, creative, forward-thinking.

How can we find stuff we haven't found before? And at the time, big data was fairly new. So we had this new toolset at our disposal that we never had before. We could look at lots of data over longer periods of time. So that was fun.

I always have fun when I'm pioneering new areas. Hunt teams is pretty cool. So what was it that, that made you move over to the product side? Was it just something that's sort of organic? Did you have a conscious thought of why you wanted to go that direction?

It was offered to me, and I just thought, oh, I'll give it a try. I've always been pretty curious. And in security, my path has often been something gets presented to me as an option and I think, sure, I'll give that a try. And every couple of years I get bored with what I'm doing, so it feels like a right time to try something new. And, um, yeah, that, that defines a lot of the steps in my career.

I mean, that's pretty cool that you'd be willing to, to take that chance, do something, you know, brand new that you've probably never done before. Yeah, I think a lot of people, if you think, uh, you know, penetration tester like the last thing that they want to do was go move over and to do— to be a product manager, right? It's, you know, I don't want to say the complete opposite, but it's— it is very different, I would think. Yeah. Although if you look at my, uh, skill set, so while I was leading a pen testing team, I, I always bubbled up to positions where it was a cross of business leadership and technology leadership.

So I— it kind of makes sense when you think about— so I was leading an ethical hacking team, but I was never the best pen tester. I was always kind of the worst pen tester because I could do it, but I'm slow. So, but I could recognize the value in the team and what they're contributing because I deeply understand it. But also I was like best suited because I was good at talking with customers and getting deals signed and like shouldering responsibility and authority that a lot of the pen testing team just just not want to have to deal with. And so it kind of makes sense that I tended to straddle both technical and business, which is the sweet spot of product management.

Yeah. Yeah. Do you think that having, having those technical skills has helped you on the product management side? Yeah, absolutely. I feel I couldn't— it gives me this credibility that, um, which is like my feet are firmly planted in the ground.

I'm not intimidated by Um, while I don't feel smarter than anybody in the room, I don't feel intimidated by anybody in the room. Like, I've worked with the smartest people. I can do what they do, albeit I'm much slower. But it just gives me this conviction that I, you know, I, I can get to the bottom of technology and understand what's going on and help design it. So it's helped me feel confident about decision-making, but also gives, um, other people confidence about me that I know what I'm doing.

That's good. So I think I took maybe one step farther than I wanted to get, so I want to backtrack just a little bit. So I think many people probably know the term product manager, but they may not know actually what a project manager or a product manager actually does. So what do you, in your words, what do you do? What's a product manager?

Okay, so a product manager In my case, you're probably thinking about a software-based solution or a SaaS-based solution. You're really at the hub of getting that product built. You're the core person thinking about the roadmap, how the product's going to work, what features are going to be really important. You work with— the hub around— the spokes around you are engineering. You'll be paired with an engineer, a group of engineers that are building What you're thinking about.

Another spoke is marketing, so you've got to make sure marketing understands the value of the product. You talk to all the customers because you want to understand what they need to make sure you're building things that are useful. You talk to support to make sure they can support the product. Really, you're at the hub of these software companies understanding the problem, working with engineers to understand, can we solve that problem? Telling sales, here's what we solved and why it's cool.

Here's why you'd be able to sell it because we solve a real problem. And you're in the middle of all of that. So largely people look to you for having a good vision about where your product's going, where the industry is going, so that you're usually thinking 1, 2, 3, 5 years ahead because it takes a long time to build things. It's fun because you get to talk with— it can feel intimidating to say, okay, I've got this. I've managed products that bring in several hundreds of million dollars a year, and it's kind of intimidating to be the person that's deciding what's the future of that product.

But you have to realize you have access to really smart engineers, really smart architects, industry experts, all of the top customers with their expertise. Helping give you a lot of input. And it really becomes clear— I feel like at some point it becomes really clear what your direction should be if you're paying attention and talking to people and listening. So I find it, yeah, it's pretty satisfying. Although the downside to product management is anything that goes wrong, you're sort of— it's your fault.

Yeah, you're the one on the hook, Mary. You either get all the glory or beat up So it can be highly satisfying and also incredibly stressful. Yeah, I'm sure. Do you— are there any particular lessons that you, you feel like you've learned? You know, product management is sort of a skill that goes across many different disciplines, but you know, you've done it in, in security.

Are there things you think you've learned about security from being a product manager? Yeah, I think I mean, there's a few lessons I've learned in security in particular. I think about products I've worked on that have failed and why they failed. And I did work on one product that found this really great— it would find breaches that hadn't been found any other way but through DNS data. And it was so cool, and the algorithms were rock solid, the math was great.

Problem is you can't collect DNS data at most enterprises in the way we need it. It's really fragmented. You would have put thousands of taps out there. It's just practically a nightmare to try and get that data. It solved a great problem, but practically, it's a huge amount of friction to figure out how am I going to get this up and running for the customer.

It's going to be this huge project for them. I now have to become a DNS expert, and I'm not a DNS architecture expert. Expert. So I like to look at— I like to be really practical. So I like to think about, okay, what are the data feeds that we can commonly get that aren't an act of Congress to get?

And then try and find breaches on those. Because to, to crack the DNS problem is just— it gets really big, really hard. Or you— my favorite problem with, with that particular technology was you would, you would know for sure you had a a breach, and you could never figure out which host was actually breached because it was proxied so many times upstream. So it was like somebody out there somewhere is making a DNS request. I know that, that they're 100% sure someone out there is owned.

I don't know who. I cannot find it. Yeah, yeah. So I like to, um, yeah, I— which is why, I mean, the biggest lesson is to, to talk with people and get to understand what it's, what it's like in the security operations center, in the data engineering, when we're thinking about what data do we have access to, what can we do with it, what's your situation. You just can't build something in a lab and say, it's cool, it works in a lab.

Yeah. I mean, I think that that sort of echoes security in general and how security has started to grow up a little bit. Yeah. You know, I think, you know, early on in my— in our careers, you know, back at IBM, it was still you know, kind of people, you know, shaking their fist. It's like, take more care about security, pay attention to us.

There's all these bad things. And it wasn't— no one really thinking about, okay, well, what's the value? Yeah. How can I get engaged people to care about this? How, you know, all those sorts of things.

As you know, and we're a little bit better at that now, you know, the industry has grown up a little bit. We're not awesome yet, I don't think, but we're getting better. So it's interesting to hear that from sort of the other side too. Yeah. The other thing I've seen in security is you're— so there's always a lack of skill sets in security, so you want to build tools that are simple and easy.

So you're trying to build something that a junior analyst could work with, but you've also got to enable the experts. You've got these level 4 hunters that know exactly what they're doing. Right. And so you're building 2 ends of the spectrum, and that can feel sort of— you need to do that, but that can feel confusing to marketing and sales. Well, what are we?

Are we simple or are we complex? Well, we had to solve both, right? There's like these 2 groups, and we're trying to enable the junior people to be better, but we can't limit the experts that have got to go in there and do what they need to do. I feel like that's a particular challenge with security and the skills gap right now. Just trying to get the right balance between simplicity and stuff that's highly valuable but ends up being complex because security is a complex problem.

There's not always an easy, simple button. That is definitely true. If somebody could come up with an easy button, it would put a lot of us out of work, but it would be great. Yeah. I feel like you're driven in product management to do that.

Build something that's dead simple. Well, I can, but then it just solves a very simple use case for these people that need to use it, and they need more. Like, that's not that useful to them, right? Yeah, exactly. Yeah.

So you spent a lot of time doing product management for what I would call sort of traditional security products. Yeah. Um, now you're doing identity management. Yeah. Um, which— big change.

That is a big change. And I think you know, sort of finally we're seeing identity management be more in line with security, you know, sort of, um, you know, in the way back it was kind of like, oh, there's security things and then there's identity things, and those, those are different, that they, they play different areas. And now, yeah, you know, identity-based security, uh, zero trust, you know, all this stuff is sort of coming to the forefront of the security side, and it's all based on identity. Yeah. I, I, it's why I wanted to make the switch because I saw insecurity.

So we started looking at network security. That was kind of the first thing we tackle. And then you do operation or operating system security, OS security, and then application security. But as the perimeter disappears more and more, identity is the thing that you can key off on. Identity becomes that perimeter.

So identity is, and user behavior is increasingly important. Which was really interesting to me and made me want to learn more about identity. On the flip side, identity has this whole other side of it, which is not cybersecurity related, which is an identity of a consumer for, I don't know, like your iTunes account or your Spotify account, just enable you to grow your business digitally. And so it's been interesting to be in a product that does both. So Part of the product is security and part of it is actually growing business.

And that one, so it's been fun to learn an entirely new domain. And I remember thinking, how hard could it be to learn identity? I'd pick it up pretty quick, right? Every day I learn something new. Identity is this really deep nuanced area and there's people that have been doing it their whole life and they call them identerati.

I don't think I've ever heard that term before. I hadn't either. But that's pretty cool. Yeah, so I was going to ask, pretty steep learning curve? It's a very steep learning curve.

I'm not sure I'll ever completely master it, but I mean, I know it really well now, but to master it at the deepest level, man, it's, yeah, it's pretty deep and nuanced. Oh, that's pretty cool. And I think it's a good place to be. Because, you know, it is— it was what was not sexy before is now the sexy thing. So you're definitely in the right place.

Yeah, it's fun. It's fun. And really every identity, every application needs identity. So you get to think about technology from the mainframe all the way to service meshes and Istio. So you're just— you get to like think about all the technology in the land, which is fun.

It's fun. Yeah, that, um, you mentioned some of the sort of, you know, more cutting-edge stuff there. Is there anything that you see going on in security right now, or identity, or both, that really excites you, uh, you know, could make a, you know, a big difference? Well, um, I, you know, I feel like with security it's, it's always the basics that really make the biggest difference, which is the I feel like that's kind of the bummer answer, but I feel like there's a lot of possibility with machine learning. We're not there yet to unlock the value of that.

I think it's aspirational still. What I think is interesting with security is the new models of application development where you're breaking things out into microservices with service meshes and sidecars for security. So, how do you I, um, it's not going to solve any problems. It's only going to make things harder. So not only do we have to secure all of the architectures from times past— mainframe, client-server, web apps— and now we've got to do these service meshes.

But I think they're really interesting and something to keep a pulse on as we try and enable, you know, like new, new ways of developing apps and having, you know, your IT infrastructure sit. Yeah, I totally agree. Yeah. So, so switching gears a little bit. Yeah.

One of the reasons that we're doing this interview is that you're awesome and I wanted to talk to you. But one of the other reasons that, that we're talking is because a few months back we had sort of put out a call to people and said, hey, if you want to help us, we would love for some people to step up and do interviews and other things like that. And you were one of the people that stepped up and said, Hey, I have an idea. I'd love to interview some people. Yeah.

So I guess maybe to start, you know, what was the idea that you had? And, you know, what are you looking to do? Yeah, I thought, you know what, I would love to hear more women voices on Colorado Equal Security, and I would love to hear more of the product perspective. And so I sent you a note saying, hey, if you'd be interested, I know several women in the product side of cybersecurity. And they're pretty awesome, and I could interview them just to, you know, infuse some new angles.

Although you do have women on your show and you do do product stuff, so— but I just felt like we do some. I felt like I could add more, and also I thought it would just be fun to get to talk to people. And yeah, yeah, so— and then you said yes, so here we are. We said yes, here we are. Um, so yeah, and I thought that was a great idea.

We always love to have more women on the show. And, you know, while we talk to founders and things like that, and that's, you know, a little bit producty, but it's not necessarily in the weeds kind of producty. And I don't think that we, we generally as security people hear that perspective much at all. So, so women or not, I thought that that was an interesting perspective and that people might want to hear that. So I'm glad that you we're interested in talking about that stuff.

So, do you have sort of an idea of what this is going to look like? I know that you have gotten at least a little bit done in terms of the interview process, but— Yeah. So, I was going to start with 3 interviews. So, I have 3 pretty awesome product leaders in different areas. And so, I'll do 1 interview with each of them.

So, I'll do kind of a mini, you know, you'll get 3 different interviews with 3 different women in product. One currently is in the marketing, product marketing side. One leading product development, and one leading the product from the services side. So, a big pen testing team, but how you build out that kind of offering. Because product, I think of it with a capital P. It's not just software.

It could be a service. It could be a SaaS. It could be You know, there's all different kinds of products, things you buy. Nice. And so, you already have some lined up.

Are you looking to get more people beyond the ones that you're thinking about? Yeah, I'd love to. Yeah, I'd love to keep it going. Yeah. Awesome.

Well, if people are interested in talking to Mary, reach out to us and we'll get you guys connected. And then Mary can do some additional interviews. Yes, that would be awesome. So I am really looking forward to that. This is the first interview in that series, and we're probably not going to run them in a direct series, but they'll be kind of spliced in with all the other stuff, so people can look forward to that.

Switching gears again, what else interesting has been going on with you? Is this an exciting ski season for you? This was a great ski season, a lot of snow. Um, yeah, I, I listened to a lot of music, so that's pretty good. I'm into, um, yeah, it's been pretty fun.

I've been traveling quite a bit. What's been, um, so I'm a mom of a 3-year-old, and so my life the last couple years has been figuring out how to navigate doing all the fun things I want to do for work and also be a mom. So that's been, that's been a fun challenge for me, and I feel like I'm starting to make some progress there. So you figured it out? Well, so what's the secret?

I'm sure everyone will want to know what the secret is. Yeah, well, I started out, so I have to travel a lot in product. You need to visit customers and go to conferences, so Your life needs to be traveling. And when I first had her, I remember I traveled 14 weeks straight, and I thought I might just quit. You know, I might just— maybe I should be a stay-at-home mom.

And then I remembered, I love what I do. I really love it. So how do I figure out how to do this? And so what I do now is I take her half the time. So I have someone that will travel with me.

And so half the time I take her and half the time I don't, which works pretty well for now. But it's challenging to— it's a— I would say it's a struggle to have— be a mom of a young child in an executive role. So I'm— it's something that takes a lot of my time and trying to figure out how to keep everything afloat right now. Yeah. And you said 3?

She's 3. Yeah, just turned 3. So you got another year maybe before you know, her activities are probably going to limit traveling with you. I know. Yeah, I'm not sure.

Well, but maybe it'll feel different then, you know? Maybe. Yeah, I— it seems to me every year I have to recalibrate my approach. What worked when she was 1 was different than when she was 2, is different than when she was 3. So I imagine every year will be a recalibration.

But, um, but I sure love being a mom, and I sure love my job, so I'm glad that right now I found a way to do both. That's awesome. And I mean, I think that's a good thing to hear too, because I know a lot of times people struggle with those sorts of choices.

And being a dad, it's a little bit easier for me. Yeah. But, you know, that's always a struggle for me too. I've been in jobs where I travel a fair amount, and it's no fun being away from your kids, being away from your family. Yeah, it's like, it's the right thing for the job, the wrong thing for your family.

Um, but I do find that, you know, kids tolerate traveling just fine. I, I think it's more just— it just has to feel right to you. So I don't think it's a problem if I travel, but if I travel too much, I, I actually think my daughter's okay, but I tend to get a little squirrely about it. And I just, yeah, start to wonder if I'm making good life choices. But, um, yeah, so, well, you know, and I've— I know a lot of people that when they have young kids, they just, they don't want to do anything.

They want to make everything as routine as possible. You know, let's, you know, this is our exact schedule, we're going to keep on that schedule, we're never deviating from that schedule. Um, and I honestly think it's healthier for kids to have a little, you know, you don't want it to be crazy, but you want some more variability. Some, you know, get them used to the, the weird crazy life that, that's out there. And also you know, to see lots of places.

You know, your daughter's probably not going to remember exactly all the places that you went, but experiencing lots of different things I think is awesome, especially as a young child. Yeah, yeah, we have a lot of fun times together. We go to San Francisco a lot, so we definitely see weird things, and because we take public transportation around there. Yeah, awesome. Um, anything that I have missed, Mary?

Anything you wanted to talk about that we didn't touch on? No, this was great. Thank you. Awesome. Well, first of all, I'd like to thank you for stepping up and, you know, being one of our— I don't even know what— we don't have a title for you yet.

Guest contributor, honorary Colorado Equal Security interviewer. Well, we'll have to think of a formal title for the people that we're having do these. But, you know, I appreciate that you are willing to do this. I appreciate the interesting perspective. That you're trying to bring.

And I know people are going to love the interviews. So thank you for that. Yeah, I'm happy to be here. I listen to the podcast. I've listened to almost every podcast, so I'm a big fan.

So awesome. Pretty fun to get to be a part of it. Well, we were talking before we started about how, you know, both of us, you know, Colorado is the place, right? You know, it's— it is sometimes can be career limiting if someone says, hey, I have an awesome job for you, but you got to move to San Francisco or New York or whatever. But, you know, I think we both realize that Colorado is that special place and it makes sense for us to be here.

Yeah, I— yeah, I— for job-wise, it always seems like I should move, especially to the Bay Area, but I just want to be here. So I figure out how to stay here and I love it here. Awesome. Well, thanks again, Mary. It's great talking to you.

Yeah, we all look forward to the interviews. This has been Colorado Equal Security, and we will talk to you next time.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes