Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 120. 120, that seems like a big round number.
It's a big number. It is, uh, but it's for the week of June 3rd 2019. I think this is officially called RMISC Week. This is RMISC Week. The governor is gonna proclaim that on Monday.
And not all facts are true. Not all facts are true. This is an opinion show. We are not journalists. But yeah, very excited this week about Rocky Mountain Information Security Conference.
And we're gonna have some good time talking about that as we go through the podcast. But first, a little bit of housekeeping. We have a Slack channel. Um, some, some 900-ish, 930 maybe, something like that. Over 900.
Over 900 people on the Slack channel. Less than 1,000, more than 900. Lots of great conversation. Um, we, we would love it if you join us. If you want to join the Slack channel, you can go out to colorado-security.com and click on the Slack button on the top of that page.
You know what else you can do on that website, Robb? You can join our mailing list. At the bottom of the page, there is a signup form. You can join the mailing list. You'll get the show notes in your email.
Be the first one to know all of the new stuff on this week's podcast. And if you don't like our voices but you do like the content, the show notes are the best way to get that. We would also love it if you would rate and subscribe for us on your favorite— or your favorite podcast player, which may be iTunes, maybe not, maybe something totally different. Well, are we on Stitcher yet? We are not on Stitcher.
We are on Spotify, so you can find us there. So we— so yeah, we are on Spotify. Stitcher requires that you put like a mention of Stitcher in your podcast. So now we're— so it's our prep work. If I say Stitcher 7 times now, does that get us like 7 podcast worth of mentions.
I don't know, we'll see. Also, we would love it if you told a friend about Colorado Equal Security, the podcast, the whole movement, the Slack channel, all of it. Let them know how great security is in Colorado and where they can find all the information about it. And finally, if you really want to support even more, if you want us to know how much you love Colorado Equal Security, we would love it if you join our Patreon campaign. It's a way for you to give financial support for the podcast.
We use it all going right back into the community so we can do things like give away stickers and give away prizes at RMI ISC, and we can continue paying for the exorbitant bandwidth for this podcast because there's so many people listening to it. It is tough. It is tough. That you can get to the Patreon also on the Colorado Equal Security podcast or website. Website.
Keeping with the theme of the website, Robb, uh, we launched something new this week. Very exciting. Under the Colorado Equal Security brand. So we are doing a salary survey. Yeah, salary survey for, uh, folks who are doing security here in the Denver area, specifically targeting those folks who are individual contributors.
So we can get, you know, all of the engineers and analysts and, you know, consultants and all the other roles that people are doing in town and start to give you some data on what does the salary look like for your peers. We have a separate survey for leaders. So if you go out to the individual contributor one, you'll be able to see a link to that other one. However, you can— we'd love to have you join. We'll run it at least through the next week or two.
I'm not sure how long we'll keep this open, but definitely looking to get a good sampling of responses. Yeah, and, uh, as I mentioned, there is a link on the front page of the website, so go check that out, colorado-security.com. Fill that survey out, we'd love your information. Uh, shout out to Chris Abbey and Jeff Ellis who have helped put this thing together. We've been thinking and talking about doing this for several months, and those guys kind of nudged it forward and helped us get this going.
So thanks, guys. Yeah, and I don't think if we mentioned it yet or not, but this is an anonymous survey. We are not taking names. Um, however, if you do participate, then you will get the data that gets captured as part of the survey. All right, why don't we go ahead and jump into the news?
The Colorado Department of Transportation is seeking proposals for a 173-mile Front Range rail train. They're looking to put a train in. Yeah, that would be pretty cool. So they're talking about sort of a commuter trail— commuter rail train that could go all the way from Fort Collins to Colorado Springs, maybe even a little bit farther. They say this is Pueblo even.
So yeah, that's a pretty long commute if you're going to make the the trek from Pueblo to Fort Collins. Yeah, you know, I think it is, it's interesting though, in that it's something I think that we really need. As I think anyone that has driven north or south these days, it used to be you'd get north of Denver, and it would be wide open, nothing there until you got to Fort Collins, and you drove south, and there'd be nothing until you got to Colorado Springs. And not quite that, that anymore. Yeah, it's all filling in.
Interesting thing about this request for proposals for proposals that they put out is they do say train, but they say also other options, any other multimodal options. So really trying to leave it open for things, I assume things like the Hyperloop and other technologies that don't necessarily fit directly with a train. Yeah, maybe, I don't know, spaceships, helicopters, those, those Onewheel hoverboard things, hoverboards, Onewheel skateboards. I love those things. Those are really cool.
Everyone should get one of those to commute. There's just one really big one. I like it. I like it. Next, Colorado students were unknowingly photographed as part of a facial recognition study at the University of Colorado Colorado Springs.
So this is interesting. They photographed more than 1,700 unwitting students, faculty members, and others in public for more than 6 years in an effort to improve facial recognition technology. They said that this was actually posted online and anyone could download it. From starting at about, well, sometime in 2016 until April of this year. And when they took it down, it was actually not taken down because of those privacy concerns, which I can imagine a lot of folks might have, but because they had made a mistake in allowing some kind of metadata on each of the photos.
Right, to know when it was actually taken. So you could see like the place and the time that the photo was taken. Like if you just think about like the privacy concerns about that, pretty significant. But The professor who did it was really specific and said it wasn't the privacy concerns that made him take it down. It was the fact that they had made that mistake around metadata.
Yeah. From his perspective, he was filming in a public area where there was no expectation of privacy. And had they not exposed extra data that they were intending to— not intending to expose, then I believe his contention was they would have continued to do this. Yeah. My— so most— mostly the article, like, okay, whatever.
I get the argument that, you know, these people are in public and And I, and I'm a little, I'm sensitive both sides on this. However, his, his response to people who didn't want to be a part of it was such a jerk thing to say. He says, he says, well, if they don't like it, they can come through and come and look through the thousands of photos we have and say, this one's me and I'll take it out of the dataset. Oh, that's a really kind way to look at this. Yes.
Right. I will. I'll be there. Let's, let's hang out. We'll both look through those photos and make sure that I'm not in there and then we can go on our merry way.
That'll be great for everybody. Yeah. So obviously this became something of a big news story. I don't know, like, where I come down on this, this whole issue exactly. Yes, I do think facial recognition is probably important.
Yes, I think it could be used by Big Brother to do bad things. Yeah. Yes, I think that in a college we want to keep people safe. I don't know. I also would say that the climate around privacy has changed over the last 6 years while they were doing this.
You know, potentially 6 years ago, you might not have given second thought to the fact that they were just, you know, pointing a camera somewhere to try and capture people's faces. But now privacy is, you know, much more in the forefront. So I could see where there might be more of an uproar now. Yeah. All right.
Well, next story we have here is around some companies that have been chosen to help modernize Antarctica's research station. Now, it's interesting to me, you know, I don't know why, but it feels like Colorado has a stronger link to Antarctica than one might imagine. Yeah, they do. I think, is it Lockheed that runs it now? Someone who is— used to be Raytheon, now Lockheed.
Yeah. Is running the sort of the operations piece down there. And they're based out of, out of Colorado. And, and these firms that won this contract, which is different than that, to modernize it, do seem to have some links to Lockheed and that contract because they're in the area. So the McMurdo Station, which is the big research station in Antarctica, it was mostly built in the '50s and '60s with a handful of or a number of little buildings kind of spread around the area, which I guess is really energy inefficient.
It's not modern. It's not easy to use. If you're going to Antarctica, you know, you expect to be in the nicest of places. And yeah, exactly. It doesn't really deliver like you might have expected.
So they're building a Four Seasons down there. Is that what this plan is about? They are building a few more modern buildings that will be more energy efficient, more bearable, decrease the the overall energy demand. So there were 4 Colorado companies that are going to be a part of rebuilding that, starting with Stantec. They are the lead designer for the, for the entire— oh no, I'm sorry, Stantec was not— it was Oz Architecture that's going to be developing the master plan.
Stantec is doing the National Science Foundation's Antarctica Infrastructure Modernization for Science project. All right, a lot of words. Yeah. And some of the things that they specifically, they were gonna have to do is figure out how to do plumbing and mechanical and other things like that in this harsh environment where the highs are usually in the teens and the lows are usually in the, you know, negative 50s to 70s. So the other 2 firms that are involved are MEP Engineering and Monroe and Newell.
They're going to just be doing engineering services as a part of it as well. Yeah. So Robb, when you said that they were modernizing Antarctica, all I could think of was you know, like building cars and jetpacks and things for penguins, or, you know, making sure that all of the penguins have all the modern facilities that they need. They're giving this— they're putting the snow into a mohawk. It's a very modern haircut for the snow.
That's right. Next, we have a story from the Business Journal around Colorado coding boot camps. Specifically, the question is, who reaps the benefits? And Alex, I'll throw it right to you as a summary. Who reaps the benefits?
Uh, I think that this was a very long article. We had lots of meat in it talking about, uh, public and private bootcamps. These are coding bootcamps more or less. Uh, private or for-profit, not-for-profit. Uh, correct.
Yeah. Sorry. Yeah. Profit and not-for-profit. And, uh, while it seemed like you could get benefit from both of those, uh, it seemed like the for-profit version of them often spent more time on acquiring students and you know, making their, their names known advertising as opposed to spending the money into the students themselves.
Whereas the nonprofits, maybe you got a little bit more benefit, uh, as a student. But the nonprofits were also more competitive, harder to get into. It's an interesting article if you're thinking about doing a coding bootcamp and, or you know someone who is. I do think it's actually worth reading. Um, for the for-profits, I think the, the question— they didn't judge to say that it was bad.
I think that they were trying to say is if you're going to do a for-profit bootcamp, make sure you look at these and ask tough questions like, what is the ratio of how much money they're spending on student acquisition versus delivering services? And what are you going to get from them in terms of education and then support in finding a new job? They did give some interesting numbers. They said that most programs range from $12,000 to $20,000 in tuition for somewhere between 3 months and 2 years of education. So it's kind of a pretty big range of, right, of both, well, of time, but not that big a range in terms of cost.
I think also, keep in mind, this is not like a Consumer Reports article. So you're not going to read this and figure out which one of the coding bootcamps that's in Denver is going to be the best or worst. It does talk about the specific ones a little bit, but mostly just in, you know, name and cost and things like that. I did think that one thing that stood out to me that they talked about was this one called Tectonic Academy. So they don't have any tuition at all there.
In fact, it pays the students to attend this course. But the way they do it is they give them apprenticeships at local companies and they get paid, I think, $12 an hour to be the apprentice there. And the companies where they're apprenticing are paying the school for them to be a part of it with the assumption that they're going to get value out of those apprentices' time. And then of course, you know, hopefully hire those folks full-time later on. They had one more interesting stat in here.
They said the average salary for folks who participate in these boot camps going in is about $74,000 prior to going into the boot camp, and after graduation it's about $70,000— I said $64,000— $64,000 going in, $72,000 coming out. So, you know, a nice— what is that, 14% raise or something like that going through the program? Pretty good stuff. Yeah, not too bad. One thing that they didn't talk about in the article, but I have heard when you're talking about the cost perspective, I know that there are some— I don't know that they have any in Denver where You actually, you can go for free, but you're required to pay them back some percentage of your salary after you get a job after getting out of the boot camp.
So that's interesting. I think you're required for, I think, 2 years or something like that to pay 10% or something like that. Anyway, anyway, moving on. Next, there's a cybersecurity worker shortage. Hadn't heard that one in Colorado that has the industry looking for veterans to fill the gap.
And you got to say, I This written— this was written by Tamara Chung as a part of the Colorado Sun, the new, the new news organization in town. I don't know what you did, Brett Fund, to get, to get this article written, but it's, it's makes you guys look awfully good over at SecureSet. A lot of focus on SecureSet taking veterans and helping train them up to become the next, you know, generation of security professionals. Some interesting stats from this. They, they said about a third of the current SecureSet class of 22 students are veterans.
And Colorado Springs, it's closer to 100% of those. And Brett said that about 40% of their students overall are veterans. So a really good pipeline of people coming out of the military and getting into a secure set. Yeah. And a little bit later on in the article, they did also talk about Colorado Springs and the efforts that are going on down there with the Chamber of Commerce and some other programs that they have trying to get cybersecurity jobs and veterans into those jobs.
I believe they said that 40% of the veterans that were leaving the military were looking to stay in Colorado Springs. And so they were, you know, making efforts to try and keep them there and, you know, obviously find jobs for them. And cybersecurity is one of those ways. There was, you know, I love pulling out interesting metrics from these things. There was a metric in the article that said nationally that for every 2.3 employed cybersecurity professionals there are, there's one open job.
So, you know, you think, hey, if I, if, you know, if I want to go poach someone, you know, I have to go take one of those 2.3 people and move them over. In Colorado, we have a significant— we have significantly more open jobs with 1.8 employed professionals for each open job. So much harder to, to take folks who have already been doing it. It just, you know, makes the shuffle between organizations all the more difficult and makes it much more important for us to build new security professionals rather than just trying to retread the existing ones. Totally agree.
Next, we had a funding announcement. Swimlane announced $23 million in a Series B round of funding. So congrats to Swimlane. I reached out to Cody Cornell. Cody is the CEO and founder, one of the founders over there.
Asked him to give me a quote about what this is about. He, you know, he mentioned, he gave me a pretty long quote. I'm going to summarize. He's excited. They're working with Energy Impact Partners for this.
So Cody mentioned that they are going to be investing and growing, uh, locally here with their footprint, but they're also going to be growing internationally. So I assume that means putting some sales folks around the world to, to help get momentum there. Um, and they're excited about being part of this community. He specifically calls out great companies locally: Red Canary, CyberGRX, SecureSet, and Ping Identity. And he says he's going to see us at RMISC this week.
Nice, we look forward to seeing him there. Thanks a lot, Cody, and congratulations to the whole team over there about the, uh, the nice new round of funding. Next, Optiv was ranked, uh, second. They had the second highest score in the current offering category for cybersecurity incident response services in a Forrester report. The Forrester Wave, which is like the Forrester's version of a Magic Quadrant.
Uh, so congratulations to, uh, to Optiv for that. I, you know, I, I think we all think of FireEye as being one of the big ones, and it looks like, you know, Optiv has really come up a lot in that area and is offering good services there. So yeah, those guys. Yeah, good for them. All right.
Next we have an article from Webroot asking the question, the burning question, what defines a machine learning-based threat intelligence platform? What defines a machine learning-based threat intelligence platform? You know what, Robb? I'm really glad you asked that question because it's something that's been burning in my mind for a long time. I do have to say that after reading this article, I'm not sure that the author actually answered the question fully.
It is a tough question. It is a tough question. There was a lot of talk about what makes up a good platform, but there wasn't a whole lot of talk about what machine learning has to do with that. But anyway, in the article, they talk about needing to have scale and scalability. So there's lots of data that comes in in terms of threat intelligence.
You have to be able to scale to be able to ingest that data and make it useful for people. Sensing and connection. So you have to be— that's very touchy-feely. It is a little touchy-feely. Uh, you have to sense all of the bad things that are out there, Robb, with lots of sensors.
We'll make a connection here. And you have to connect those things together to make the— some, some good, uh, learnings, which are the next piece, which is context and analysis. Taking that data, putting context around it, analyzing it so it can be useful for people. So does this blog post mention it? Are there any companies that offer this kind of machine learning threat intelligence platform?
You know, the The blog is by Webroot, so I'm gonna guess that potentially Webroot has one of these platforms. So if you're interested in knowing more about this, I think you can reach out to a local company, Webroot, uh, and, and find out what they do there. That's right. All right, finally we have a blog post from Security Pursuit this week, uh, and they ask yet another burning question. It seems like blog— blogs that are questions have become very popular lately.
Um, will biometrics replace passwords? Yes or no? That's a yes or no question. Yes or no? I don't think it says that.
It just asks the question. Can I give a little more nuanced answer, please? Well, so the answer is yes. They believe that it will, or at least it's moving in that direction. And they actually quote a couple of surveys.
And I was excited to see they quoted a survey by Ping Identity talking about how, how 92% of survey respondents consider biometric authentication effective or very effective for data security. Wow. Yeah, I like effectiveness. Anyway, it's moving in that direction. We do believe that biometrics will at least, if not replace passwords, at least kind of relegate it to a less prominent position.
Yep, for sure. All right, well, that is it for news this week. Now we get to do the Slack message of the week. Big thanks to Andre Gaeta. Andre, local security guy, now regional director of sales for Mimecast, has been sponsoring this for us for a long time.
We appreciate it, Andre. He He gives one free item from the Colorado Equal Security swag store to our winner every week. This week, the winner is last week's featured guest, Daniel Pettigallo. Daniel reached out really as a part of his job with the Attorney General's Office to understand what are the things that companies should be doing in order to keep their own organization secure. What are the best practices that small and medium businesses should have?
And he's looking to put this together so that they can provide it out as a part of the job at the Attorney General's office. And you guys better provide good answers because if you've read the bad ones, then they're going to provide that out as guidance and you're going to be held to it. Right. So he's trying to engage the community. Guys, if you— anytime you complain that the government doesn't know what's going on around security, this is a chance for us to actually help them know what's going on on security.
So maybe get involved. That would be great. So let's go ahead and move on to events. Uh, of course we have said this week is Rocky Mountain Information Security Conference. We're very excited about that.
Uh, Robb, we will be doing the live Colorado Equals Security podcast as part of the keynote on Wednesday evening. So everyone should be there for that. Are you— and we're gonna be there on Tuesday doing the community day, correct? Doing the keynote on Wednesday. We're gonna be doing the panel on Thursday.
Are you gonna be sleeping at the convention center? You know, I was thinking about it. Um, There is a lot of space there that we have rented, so I may just get one of the, the extra rooms that we're not using and just take a little nap from time to time. Please bring a toothbrush. Oh yeah, good idea.
I'm going to change your clothes. I'm going to be near you a couple of different times during the event. I'd appreciate it. Deodorant. I'll have all those things on hand, I promise.
So we're looking forward to that. Please come up and say hi. We will have Colorado Equal Security stickers with us and maybe even some magnets or something like that. So come up and ask us, give me some swag and And we'll see what we can do. Yeah, um, there is still time to register if you have not registered yet.
Um, you can even walk up and register if you so choose. And, uh, again, also Robb mentioned the Community Day. There are 2 free sessions on Tuesday as part of Community Day. So if you want to learn about DevSecOps or privacy, uh, you can still come last minute and register for free for those. All right, let's go ahead and jump into the event over the next couple weeks.
Even though this is RMISC Week, A couple other crazy organizations have chosen to do something and we're willing to talk about it. Number one, the IAM Meetup is doing a networking event. It's actually after RMISC on Tuesday, on the 4th. As we have said, from Tuesday through Thursday, Rocky Mountain Information Security Conference at the convention center. If you're unable to get over to Denver to attend this and you're over on the west half of the state, good news for you.
Techstars is doing their West Slope Startup Week, uh, the 5th through the 8th. On the 6th, uh, Splunk is doing their monthly First Thursday at Topgolf. On the 7th, down in the Springs, they're doing their First Friday Cybersecurity Social and Mixer. Uh, also on the 7th, ISSA Colorado Springs is doing their CISSP prep. So this is a paid program that they have over several different weekends to get you ready to take the CISSP class or test.
Looking ahead to next week, the CTA is doing a CTA 101 event on the 12th, and SecureSet is doing a Hacking 101 Intro to Wi-Fi with Women Who Code on the 13th. And finally, over the next couple of weeks, we have a new group that's getting together in town, the FAIR group, which is put together by the, the Open Group. Um, this is a, uh, FAIR is a risk— I don't know how to put it— a risk model or approach to doing risk assessments. Is that a good summary of what they do? It is a quantitative risk analysis framework.
There you go. So they are, they are putting together a new group in town for folks who are fair risk practitioners who want to get together and talk about it. They're doing their very first meeting on the 14th. And there is no website for this yet. But if you go into the link in the show notes or go to our calendar of events, you can, you can email the organizer and you can show up and, and be a part of this first group.
I believe that they are having that meeting at the Optiv headquarters. You will be able to find that information on the calendar. That is true. Thank you. All right, let's go ahead and jump over into jobs.
We do highlight a couple of, or about 10 interesting jobs each week, and believe it or not, the most interesting jobs are the first couple we go through, which are at Ping Identity. I'm hiring a couple of product security folks at Ping. We're hiring a manager of product security, and we're hiring a junior product security engineer, looking for folks who have a background in development who are looking to help us improve the security of our SDLC as we release our IAM software. Next Health is looking for a Chief Information Security Officer. Interesting.
Do you know Next Health? I do not. I don't know them either, but there it looks like they're downtown just a couple blocks away from Ping. Um, good opportunity, I hope. Um, next, Bank of America is hiring a Senior Information Security Officer.
I know this is actually a relatively senior position there. I think it's sort of America, a BISO kind of job. But a high-level BISO job. Yeah. Uh, Alteryx is looking for a senior cybersecurity engineer.
Great West is hiring architect security. It's a little bit of a strange title. That's a command. Architect security, Robb. When you, when you put this in the, in the notes, I, I thought, well, maybe he must have copied it wrong.
Like, it's really security architect, but no, it's architect security. There probably should be a comma in there. Uh, Tri-State Generation is looking for a cybersecurity engineer, either 1, 2, 3, or senior. Oh no, no, 4 senior. I threw that off.
Yeah, that would— I assume that'd be working with Reed Fudge. Reed is a fantastic guy. Yes. So this might be a good opportunity for someone who's looking to break into, into this security field or already has a lot of experience. Yeah.
Next, MedKeeper is hiring an information security engineer. The Department of the Interior is looking for a senior advisor in information assurance. In quotes, or excuse me, in parentheses, cybersecurity in industrial control systems. So if you're an ICS person, that seems like a job for you. Yeah, federal government, pretty good stuff.
Finally, if you, if federal government is just a little bit too big for you, but you do love the government life, the city of Arvada is hiring an IT security specialist. Nice. That's awesome. And that takes us to the end of the news, Alex. I know you did a feature interview this week.
I'd love it if you would of give me a little teaser. What are we going to talk about? Yeah, so, um, I sat down with, uh, James Carder of LogRhythm, uh, Joe Murdock, who runs the cybersecurity program at Red Rocks Community College, and, uh, one of their students, Matt Adrian, to talk about, uh, the partnership that LogRhythm and Red Rocks are doing to send a team to Singapore to compete in a cyber defense competition that they have in there. So Matt is one of the team members that is going to be going And we just, we talked about the competition and lots of stuff. Red Rocks, Logarithm.
I love to hear the local stuff going on. That's awesome. Yeah, should be fun. Local and not so local in Singapore. I believe also, just to, you know, give a little heads up, I think that they are the only US team that is competing in this competition.
Wow. Yeah, I love it. The whole country has, is riding on their shoulders. So you're telling me that from the Singaporean perspective, Colorado equals security? That is true.
All right, well, that'll be it. We'll talk to you guys soon. Thanks, Robb. Hi, I'm Dionne Mahaffey, Security and Compliance Manager at Entero Resources. Welcome to Colorado Equal Security, for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equal Security. This is our feature interview. Today we have a couple special guests. I've got James Carder and Joe Murdock with me. Welcome, guys.
Good to be here. Yeah, how are you guys doing? Doing well. Yeah, beautiful sunny day outside. We got through, uh, you know, maybe through the, the spring rains and into some nice weather.
Got a long weekend ahead of us. You guys got any big plans? Uh, repairing some trees from the recent, uh, winter storm, and then, uh, got a little family photo shoot before our next baby comes. So awesome. There you go.
There you go. I'm actually headed out to the United Kingdom This week I'm gonna be over there for InfoSec Europe conference. Oh nice, that'll be fun. Yeah, I think so. So half our staff at LogRhythm will be out there too.
Yeah, that's what I heard. So I may try and drop by your office out there. Wow, international espionage. That's right. Cool.
So the reason that we have us all together today, we wanted to talk a little bit about something that that you guys are doing together. But before we get there, maybe why don't you do some, some quick intros? Joe, you want to start? Yeah, so I'm Joe Murdock and I run the cybersecurity program here at Red Rocks Community College, finishing up my 5th year doing that. We are a Center of Academic Excellence designated by the NSA and DHS for our program, so first 2-year school in the state to earn that a few years ago.
Yeah, we have a great cyber program. It's growing. Our students are doing great things, which we'll talk about. Yeah, it's exciting times. Awesome.
James? Yeah, James Carder, the Chief Security Officer for LogRhythm and VP of LogRhythm Labs, which is just an R&D function within LogRhythm. I've been there for 4+ years now, going on 5 years, and then been in information security for 22 years or so. Yeah, that's nothing. Yeah, I know.
Since I was 18. Wow. I'm almost 40. Wow, that's pretty crazy. What were you doing when you were 18 in cybersecurity?
Air Force, military. Very nice, very nice. So Joe, you mentioned that the program here is certified as a Center of Excellence by the NSA. Maybe talk real quick about the program, what you guys do, courses you offer, areas of training, that kind of stuff. Yeah, so essentially we're a 2-year program, so students earn an Associate of Applied Science in Cybersecurity.
And, you know, they start with, you know, fundamentals of computers and networks to, you know, identify how they work. And they take an intro to programming class in Python, which is big in, you know, in scripting things. And, you know, they finish up with digital forensics and enterprise security. Security, looking at how you implement the whole package across an enterprise. And, you know, while they're in that, they'll go through things like, you know, Security+, vulnerability assessment, maybe a Windows Server class, maybe a Linux Server class.
Kind of just depends on which path that they go. And yeah, it takes, you know, 2 years if students are going full-time. So our degrees are half general ed and they're half program-specific, so they'll take the English, math, science in addition to the program courses. Very nice. Yeah, and a lot of them, you know, they're the ones that get really involved, they get job offers before they graduate, which is great.
And a lot of our students go into industry, some, you know, transfer to 4-years as well. That was actually the next question I was going to ask. See, it seems like you guys have a mix of people that are going out into the workforce after this. We do. There are people that are going on to more education.
Yeah, and, you know, depending on where students end up, you know, the company— we have a pretty good partnership with Northrop Grumman. You know, they want them to continue pursuing their education, so, you know, they'll continue pursuing the 4-year while they're working. And we have probably a quarter of our students who are actually working in industry, and they're just trying to skill up and, you know, learn new things. And, you know, maybe they're a network person right now and they want to get into a specific security position, and so they come take some of the classes to help them achieve that. Nice.
And speaking of some of your students, we have one of your students with us, Matt Adrian, who we're going to talk to in a little bit here. So I guess let's talk about why it is that we have both LogRhythm and Red Rocks in the same room together today. You guys are working together on a competition, I understand. There is. There's a competition being held in Singapore.
So it's an international competition, mostly going to be Asia-Pacific region. And one of the opportunities that we had was to, instead of just getting our name on a booth or, you know, being able to sponsor certain things, we decided to sponsor an actual team to compete. And so, you know, we researched some of the areas I'm associated with You know, I do a lot of work for CU Denver, for CU Boulder some, and I knew a guy who was an instructor at Regis, and they have their annual competition. And he said, you really should talk to Red Rocks. And so that's, that's how we got engaged.
But we're going to sponsor the Red Rocks team in this cyber competition in Singapore, full expenses, air travel, hotel, you name it. And we saw it as a great way to not just represent the U.S. in this competition, but to represent Colorado and our local community where, you know, we're headquartered as well. And so that's, that's, that's how this all came to— came about. Yeah, so, so maybe, I don't know who's the right person to talk about it, but talk a little bit more about, you know, what the competition is, what it entails, when is it, how long is it? Yeah, so I mean, you know, we have competitions here in the U.S.
The one that James is talking about as far as Regis, they sponsor the Rocky Mountain Collegiate Cyber Defense Competition, which is the Rocky Mountain region. So there are teams that compete from, I think, roughly 7 states, you know, every spring. And, you know, our team here, Red Rocks was the first 2-year school to compete in that competition 4 years ago, and they've been, you know, doing it ever since. I guess we've been doing it, you I'm the coach, so I sit in the coach's room during the competition and can't talk to the students. So it's a little tough, but, you know, the students did a great job.
Obviously, you know, James and Logarithm heard about it. So this competition in Singapore, it is going to be second week of June, and it's put on by Singapore's Ministry of Defense, and it's a capture-the-flag-esque type of competition from, from what we can gather. They're not releasing a lot of the details on how it works, so it should be interesting. From what I understand, CTFs for them are a little bit different than, than how we do them over here, and there's some sort of Jeopardy kind of style involved in it. So some trivia, is that the— not sure.
I mean, they won't say. Want to give anybody an advantage, I guess. Well, it's interesting because like I think some of the teams in region and APAC can actually attend some type of training that they're gonna offer. So it says that there's no quote-unquote experience required. So you go to this kind of— I don't know if it's a boot camp session or what.
Yeah, it's like an online training, I think, over the next couple weeks. And I think we're blind to that. Yeah, because so we can't see it. So the team out of the US, I don't know if it's some kind of strategic advantage, right? But, but yeah, we can't attend that remotely.
Remotely, but the folks in the APAC region can. Yeah, yeah. And then, you know, uh, there's only one U.S. team invited, and that is Team Logarithm, which is going to be the students from Red Rocks Community College. So that's pretty amazing. But that is pretty amazing.
Yeah, like James said, they're, uh, they're not giving a lot of the details. So I don't know, they may not want us to win. Maybe that may be true, right? That may be true. Uh, so James, is this— is it just a competition, or is there a conference that goes along with this?
And how is it that you guys are involved in— you said sponsoring— how is it that LogRhythm is involved in the competition itself? Yeah, as Joe mentioned, it is a competition just put on by the Ministry of Defense. I don't think there's a specific conference tied to it. Honestly, how we got involved is through the ministry and through other channels. They said, you know what, it'd be really good for LogRhythm if you go sponsor this competition in some capacity.
So we said, All right, we see what you're saying. So that's literally how we got involved. And there was obviously a business aspect of it for us through this, but we just didn't want it to be a traditional, we just write you a check for sponsorship and you throw our logo somewhere and kind of go that route. It was an opportunity to do something unique. Yeah, that sounds pretty cool.
So I imagine this is the first time that you as LogRhythm, you guys have done something like this where you've sponsored an actual team in a competition. Yeah, yeah, we— I mean, I think a lot of our folks have competed before. A lot of our employees, a lot of our researchers have competed in some of these competitions, but this is the first time we're actually sponsoring an outside team or even sponsoring any team outside of, you know, any team outside of LogRhythm, especially in an international setting. Yeah. So Joe, are you guys taking any special measures to get ready for this competition?
Obviously you don't have the advantage of the specific training session that they're offering, but are you guys taking any steps to make sure, you know, obviously beyond the normal education that you're giving, to make sure the team is prepared? Yeah, I mean, I think one thing that makes the team special here at Red Rocks is that it's student-driven. I mean, you know, the students want to be part of it. They want to spend time outside the classroom. And in their free time learning, you know, various systems and that sort of thing.
And as far as practicing, I know that some of the engineers at LogRhythm have been facilitating their Log Wars CTF with the students. So I think on Wednesday we had our whole Cyber Club, which is, I don't know what, about 15 students or something like that, doing a Log Wars CTF event this week with Jake and and some of your other engineers, which is awesome, right? Because then not only do they get to see, you know, how LogRhythm does CTFs, but they also get to see the LogRhythm product, and it's an actual SIEM that, you know, companies use, and it's beneficial for students, I think. Definitely. So yeah, and then I mean just trying to, you know, sharpen their skills in all the various systems because we have no idea what's going to be in the competition.
I think the other thing too is we, you know, we brought the Red Rock team out to our headquarters in Boulder, and we had our threat researchers meet with them. Our marketing team and a few others did like the here's the LogRhythm overview of how we came to be, but our researchers came in and have competed in these in the past and have actually built our CTF that we give. And it was kind of a what tips and tricks can we give you, what are some skill sets that you may need to bolster up on before you go based on what we know about the competition. So things like forensics, and there's a malware analysis component, things like that. So there's areas that are very specific and specialty areas, and so we're trying to just come up with a, here's some of the things that you need to look at before that competition, but also here's some of our tips and tricks around that.
Yeah, great. So when is the competition and how many people are going? Competition is June 13th and 14th, Thursday and Friday. We've got 4 students from our cyber team going. So our cyber team, the actual team, is about 12 students.
We've got 4 of them going, and one of the requirements— well, you know, our school president wanted to make sure they're over 21 and they got to have a valid passport. And luckily there's only 4, so it made, made my job easier. They're identifying them. But yeah, I think— I believe there's a few other international teams as well. Israel, Italy, Romania, and all the Asia-Pacific teams.
So yeah, I think total teams are going to be 3 to 4 from what I understand. Nice, nice. That sounds really exciting. I bet that's going to make the summers of those kids. I would assume, yeah.
And I'm sure we'll hear from from Matt later on that. I never got an opportunity to go to Singapore until last year, maybe 2 years ago, and like I said, I'm almost 40 years old now, so now you got these, these guys and kids and everybody else that get to go in their, you know, early 20s, late teens, and just able to compete in this and get a trip to Singapore, which is a really awesome country. Yeah, that's pretty cool. Yeah, because I don't think any of us have been to Singapore, any of the students, and then I'm going with them as well. Yeah, that's good.
So you get to go along with them, Joe? I do, yeah. So, you know, it's really exciting for me. Yeah, my boss covered my trip over there, so that's awesome. Yeah, my wife is in education.
You don't always get a lot of those fringe benefits, so that's a pretty good benefit. Yeah, yeah. Well, and I mean, it's great marketing, you know, not only for Logarithm but for Red Rocks, you know, just another thing we can use to identify the prestige of the cyber program here. And I think the other thing too, it's not like, you know, this is like Red Rocks Community College, right? So it's people trying to get into the industry, trying to do certain things.
You know, it's not, you know, some of our other bigger universities around here that probably get a lot more funding and a lot more of everything else. And so I think it really speaks to the local community for Colorado and for where we're at. So I think that's another really cool aspect of this whole thing. Awesome. Well, let's grab Matt and we'll talk to Matt a little bit about what he's doing and being a student here.
So welcome, Matt. Maybe if you'd take just a minute to introduce yourself and who you are. Thanks so much, Alex. It's awesome to be on Colorado Equals Security. It's a huge treat.
So I'm finishing up my, my first full-time year, and I had a few other classes before that, and so I should be graduating with the cybersecurity AAS that Joe mentioned next spring of 2020. So I actually have a background in music. I did some help desk work for Apple retail and years ago, and so it's really cool to get back into that and really dive into the network specifics and everything that Joe was talking about in the program. I was the president of the Cyber Club this past year, and we were able to talk with a lot of professional kind of industry people and get either tours or, you know, guest visitors to come speak to us. And then obviously the Rocky Mountain Collegiate Cyber Defense Competition was a huge part of my year.
Nice. So what was it that drove you to get into the program here at Red Rocks? So a big part of it was actually Joe was able to secure a National Science Foundation scholarship called the Cybersecurity Scholarship Program. I was actually working full-time in admissions here at Red Rocks And I was doing a lot of outreach work with Joe and heard about the scholarship, had this prior experience, kind of interest in tech. And so I applied for the scholarship and got it.
And so I left my job, became a lowly student worker, and went full-time in the program and just got as much out of it as I could. That's awesome. So what are your plans for the future? You said this is your first full year in. Do you have one more year?
Yeah, so because of my previous degrees in music, I'll just have to be part-time this next year. I may try and take some more networking-specific stuff like my CCNA, but I did recently just secure an internship at NREL doing cloud computing and cloud security and their kind of NIST compliance because they're a federal national lab. So I'll be doing that this summer and this fall, and I was one of the interviewees at Northrop Grumman. And so kind of just balancing things and seeing what the timeline looks like for all of that. But at least for the summer, I'm secure and kind of just continuing to learn and expand my skills.
That's awesome. So now that you do have some cybersecurity experience, you've been taking classes for a year, what is it that you think that that you like most about the industry and the skills that you've learned? What is it that piques your interest? So there's a number of things. I love tech, and I think security is such an important— I mean, the more I talk to industry people and go to conferences or meetups like OWASP or CSA, anything like that, listening to Colorado Equals Security, it's just like so critical.
And I know, I think back in 2017, I heard that there were 10,000 unfilled jobs in cybersecurity. So coming from music, you know, I would be lying to you if I said that the job availability and just like growth in the industry wasn't very attractive. But I've really enjoyed, you know, learning how our world works. Like so much lives online. And so that's a big part of what drew me.
That's awesome. So have you ever been to Singapore before? I have not. I've gotten close. I've been to Hong Kong.
I have a number of friends from music school that are there, but I've never been to Singapore. And I've been doing a little bit of research, and it looks like they're doing some amazing stuff with technology. So it'll be cool to see some of that firsthand and interact with citizens and students from that country. Maybe I'll add something here. It's interesting, the Singapore government is heavily invested in cybersecurity and technology.
And it's one of the few nations that are really touting this whole smart nation piece. And everything you do there, there's a sensor for almost everything. Like you go through a toll sensor, your car gets registered. There's just everything that they do is all through technology. And funny story is, the actual minister, the prime minister actually codes.
And so there's another group that I know that's kind of this chief scientist of a company and he's friends with the prime minister and the prime minister will write code and send it to him and say, hey, how does this look? Or, I can't figure this part out. And I'm like, you're the prime minister of Singapore. Why are you writing code? But that's how invested they are in technology.
Yeah, I was watching a National Geographic feature and the stuff they're doing in schools, they're teaching like preschoolers the fundamental kind of skills to code and build out, you know, linear kind of programs and problem solving. So it'll be cool to be in that situation and interact with them. Yeah, what are you looking forward to most about going? Well, I think the competition is going to be awesome. We don't know exactly what it's going to be, but it's definitely given some focus to these first couple weeks of summer of learning some new tools that James and his team introduced us to for, you know, reverse engineering and malware analysis and binary analysis.
And, you know, that's definitely kind of upper-level cybersecurity stuff, and so getting to dive into that early has been what I've loved about being at Red Rocks is, you know, I've gotten to do a whole internship where I got to do a lot of cloud stuff, which is not necessarily— I mean, it's getting into the curriculum this fall, but that's developing rapidly. And I think speaking to industry like LogRhythm and Raytheon and these different companies, they really like those kinds of skills, and it's super fascinating to be able to do that. And so it's been fun to start to dive into that. And if I recall, I think this, this guy's really looking forward to durian fruit. Durian, yes.
Good old stinky durian. You know it. Thanks, James. I don't think anyone is looking forward to durian. No, he actually is.
I actually am. I love it. He is.
So tell us about the rest of the team that's going. You don't even necessarily need to tell us names, but just like, you know, you guys have a broad variety of skill sets, you guys complement each other. Are there areas where, you know, you have people that are stronger than others? Talk about how that team is going to work together. Yeah, I think that's part of what we're trying to develop.
We were all on the RMCCDC, the Rocky Mountain Collegiate Cyber Defense Competition Red Rocks team, and so we do have some of that teamwork built in already. One of our members was on our networking firewall team. One of the other members was our Windows Server team, and so they helped manage those systems during that competition. And then our— the other third member beside myself was actually our team captain. So we do have a kind of mix of things that we've been focused on over the last year.
And it was cool doing Log Wars because we'd had maybe 10 minutes exposure. So I mean, really not a whole lot more than the other team— club members, excuse me. And we got 12 of us together and all the teams with our Singapore members did really, really well. And so I think the communication is already there, the teamwork is already there, like that information sharing and kind dialogue of, hey, I'm struggling with this, do you remember what James and his team said about that? Oh, I got this question, you know, what does that look like?
And interacting with that capture the flag engine, I think it's going to go really well. So we still need to continue to research before— for the next 2 weeks before we go, but I'm pretty confident. I think we may do well. It's hard to know because we don't know much about the competition itself. Don't worry about it, you're just representing the entire United States.
Yeah, no pressure. That's what everybody keeps saying. That's right, it's no big deal. We just won't let you back in the country unless you win. That's it, no biggie.
So I guess anything else that we didn't talk about that you guys want to hit on about the competition or Red Rocks or anything else? Or LogRhythm? Well, I'm not gonna— but let's not do a product pitch for LogRhythm. Let's not get you going on that, James. We could be here No, no, I'm just, I'm just really looking forward to this, this competition.
And I think, you know, when you look at our industry and you look at the, you know, the, the lack of available kind of resources and people that are trained for security, this is just a really cool way of, you know, you can go to a program, you can do a lot of different things, but now take your skills on the international level. And I think that's just a really great experience experience for kids coming out of college and trying to break into our industry and show that they are a capable security professional. And I think that will serve them well in the hiring process. It'll serve us well as the people that are hiring people. But one of the kind of things that I harp on with people trying to break into our industry is don't just tell me about classes or don't just tell me about like, you know, some of the skills that you have.
Tell me about what have you really tried to apply. What research have you done? What, you know, show me examples of you impacting or influencing something. And I think that when I look at this competition, you know, we'll just assume they're going to come back winners. And if they do, that's a pretty awesome thing to put on your resume.
It's like, yeah, we competed in this competition that's international and against other countries. And we came out here and this is my role. And I think that's just a really cool way to demonstrate your skill set. Yeah, I would agree with that. I mean, you know, there's only so much as an instructor that we can teach you in class, you know.
And in the field of IT and security, I mean, there's just so much out there and it changes so rapidly that you've got to, you got to put in time outside of class. And our students that do that, you know, the ones that are part of our Cyber Club and our Cyber Team, those are the ones that really reap the rewards of that because, you know, James and I were talking about this earlier. This industry is just growing exponentially and it's going to continue to grow and there's jobs out there for people who have the skill set. And, you know, going to school and, you know, getting involved in those extracurricular activities and, you know, just on your own, I mean, building your own little home network or, you know, whatever it is. Will help you, as James said, apply those skills, which then gives you something to talk about in an interview.
If you've just been in class, you can talk about the class, but if you can talk about how you secured your home network and maybe helped your neighbors, something like that, it's, I think, very beneficial. Awesome. Can I give one quick plug? Yeah, please. We are hosting a Summer Cyber Patriot camp.
Okay. And Cyber Patriot, that's the, the high school level competition for security. And so we'll have, I think, August— July 29th through August 2nd here at our Lakewood campus will be the Cyber Patriot camp. So registration details will be coming soon on our cyber program page, but we're gonna have hopefully 50 high school students from around the area for that. So, and a lot of our Cyber Club students will be the instructors for that camp.
So that'll be awesome, very beneficial, and a way for them to give back too. Once you have that, let us know. We'll get it on the website and help promote it. So awesome. Thanks, you guys.
I appreciate it. Matt, good luck in Singapore. Thank you, Alex. This has been Colorado Equal Security, and we will talk to you next time.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.