All episodes

Eric Alexander, Sr Lead DevSecOps Engineer at The Trade Desk

Apple Podcasts Spotify SoundCloud

Eric Alexander, Senior Lead DevSecOps Engineer at The Trade Desk is our feature interview this week. News from Ibotta, Angi Homeservices, TTEC, Western Union, Ping Identity, ManagedMethods, Optiv, Webroot, DarkOwl and a lot more!

A Unicorn spotting in Denver

Ibotta is Colorado’s latest unicorn. Angi Homeservices talks about a spinoff. TTEC and Western Union both lay off employees. Ping Identity releases a private cloud solution. ManagedMethods grows a lot. Optiv has a new CTO. Webroot talks about making Threat Intelligence smarter. DarkOwl talks 8chan. The BuffOvrFlows win first place at the Wicked6 cyber games.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11624 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 128 for the week of August 12th. Can you believe it's been 128 episodes?

No, Alex. No, Alex, you sound different today. Alex, we actually have a special guest today. Andre Gaeta is going to be our co-host. Andre, thanks for joining us.

Hey, thanks for having me here. 128. Congratulations, man. Thank you very much. Before we jump into the news, Andre, how's your summer been?

Have you done anything fun? Yeah. Yeah. Yesterday, in fact, I went rafting. I don't know if anyone out there is a rafting fan.

I did it a long time ago and took a hiatus. And with a young family, we said, hey, let's go try rafting. And now we've all been bitten by the rafting bug, and now we're talking about going rafting again. So, so this is like a whitewater rafting with a guide? Yeah.

Where'd you do it? Clear Creek, right up in Idaho Springs. Yep. Hour drive. If you guys have a chance, go check it out.

It's a ton of fun. That's fantastic. And how old's your son? Is he 12? He's 12.

And it was an okay age for that? Yep. So, so we were concerned. We said, well, do we want to go to the intermediate Class 3, Class 4? And we said, let's do the beginner Class 2, Class 3.

Yeah. And within the first, you know, 5 minutes and it's like all 12-year-olds. He's like, hey, let's go do a class 4, class 5. So we're already planning the next trip for a few weekends. That's certainly been like one of the highlights of the summer.

That's fantastic. Well, it's good to get to connect. It's been a while. You know, unfortunately we don't get to talk too much as we record, but it's good to see you. Likewise, man.

All right. Moving through some housekeeping stuff. We have a Slack channel if anyone wants to get plugged in with the last I saw, 1,024. It's a good binary number. 1,024 members of the Slack community.

You can get the link to join the Slack channel at colorado-security.com. And while you're there, you can also join our mailing list so you get the show notes delivered into your inbox each Sunday at approximately noon, depending on how good a job we do with that. We also would love it if you'd rate us and subscribe on your favorite iTunes or see me, your podcast listening app, maybe iTunes, maybe Google Play. Let people know about us so we can get more listeners and tell a friend if you're interested in helping the show grow. Best way you can do that is tell a coworker, tell a friend, tell a random stranger on the train about Colorado Equal Security.

They love that. They're random strangers. And finally, if you want to support us even more, we do have a Patreon campaign where you can donate money to help the show. That goes directly back into the community. Speaking of Patreon, Andre, this week we actually had 2 new patrons sign up.

That's fantastic. Can you believe that? Yeah, no, what's the total number at now? That's not a question I'm prepared to answer right now. I don't know.

Well, on a different note then, join the Slack channel because there's a pretty cool giveaway each week. And if you get picked for the Slack message of the week, you get to pick out a pretty cool piece of swag from the Colorado Equal Security Store. Absolutely true. And we will go through who the winner is this week. But it is thanks to you that we have that competition at all.

But I do have to give a shout out to our new— to our 2 new patrons. We have Jason Hayes, who works with Allergan. He is a new sponsor for the show. And Michael Stephen, who I think you might know Michael Stephen, right? Absolutely.

Michael is the Privacy and Security Officer at Connect for Health Colorado, and they are both helping support the show. So thanks a lot to both of those guys. Yeah, guys, thank you so much. All right, why don't we jump into the news, Andre? What do we got first?

We have— I can tell you're thinking, Robb, why don't you tell me what we have first? We have news about Ibotta. So Ibotta is the local Denver tech company that does like receipt scanning and gives you that kind of perks based on what you scan. And they just got raised a new fund that values values them at over $1 billion. So, guess how many downloads of the app have been done for Ibotta?

Any idea? Well, if they have $1 billion, I'm going to guess they have 1 billion downloads. No. So, only 30 million downloads. That's a pretty good number too, though.

Yeah. Yeah. But guess how much they've given out in rewards? How much have they given out? $500 million.

What? $500 million. It's on— So, most people— So, the people are— That's like $16 a person on average or something like that. Yeah. If my math skills are right.

Yeah. Wow. They're giving money back. It's a really cool app. I haven't downloaded it yet.

I saw the article. I went out there. I was like, so I go there, I buy things, and they give me money back for the things that I buy? Like, why would I not do this? It sounds like a pretty no-brainer, except for now you're selling your data, right?

That's basically how it works is that you give your data and now they're gonna use that with marketers, I assume. I don't know. I'm sure that's a part of the platform, but, you know, data privacy is a whole nother conversation for another day. Do you really have any data privacy anyway? If it's gone, Then you might as well get something for it.

Well, so obviously good, good news for them. They're now valued at over $1 billion. That makes them a unicorn, which is a rare thing, you know, from the mythical creatures catalog. Yeah. So congratulations to Ibotta and looking forward to seeing what happens next for those guys.

Yeah. Next up in the news is Angie Home Services CEO talks about possible spinoff from the parent company. So, so Angie Services, they are owned by IAC, which is a public company on Nasdaq. And they told their shareholders in a letter this last week that they're considering spinning off 2 of their large companies, which includes Angie and Match.com. I did not know they had Match.com as a part of their umbrella.

Not so relevant to the Denver community as Angie. Angie is, of course, headquartered here in Denver. So a couple of interesting things about this. IAC has already in the past spun off the Home Shopping Network, Ticketmaster, and some other big companies that we have all heard of. So they're This is something that they do on a regular basis.

And Andy's kicking butt right now. In fact, their revenue for Q2 of this year was $343 million, which, if you add that up to 4 quarters, that's a pretty good— that's a billion-dollar company, $1.5 billion a year company type. But that is a 17% increase from the same time last year. So they're also growing at a healthy clip. That's good to see.

All right, moving on to our next story. Not quite so Good news. Teletech, or excuse me, it's now called T-Tech. T-Tech Services is going to lay off more than 170 workers. So this is interesting, right?

So their stock from the start of the year is up 55.6%, and they've outperformed 3 of the past 4 quarters. So the company on paper, right, according to the shareholders and investors, they're doing well, but they're gonna remove 179 people. And part of me in my very simple-minded brain, this just seems like a regular exercise in talent management and someone's making a big deal out of it. Yeah, and it's not— to go even a step further, they had the same day they announced this, they had multiple career fairs going. And they announced earlier this week that they're going to be hiring 2,700 associates across the US.

So I do believe you're right that this is kind of a pruning exercise more than it is a the company is in trouble. Indication. And it also looks like, you know, at least the story they're giving is that it was based on the fact that they lost a contract with a specific customer of theirs who had, like, a work-from-home acceptable— that allowed work from home. So maybe they're laying off the people who are working from home and bringing people into the office. It's hard to say.

Hard to say. I think Teletech's doing okay, and they're gonna be all right. And this is just a natural part of the business cycle. Agree. But there's another piece of news from another local company on here that maybe has layoffs that maybe are a little more significant.

Yeah. So Western Union's closing their Florida office and they laid off 9 VPs as the staff cuts began. Yeah. So this, this is actually a follow-up from a story that happened earlier in the week where they announced that they were going to be laying off 10% of their workforce really across around the world. I believe it is.

It includes multiple executive vice presidents, senior vice presidents, really a bunch of— they said like 3 compliance officers, which kind of blows my mind. They have 3 compliance officers, but they are, they are really having significant cuts across the organization. Yeah, it's such a household name, Western Union. You know, for as big and as storied as they are, right, they seem to be having some hard times with the digital transformation that's taking place. And, you know, maybe part of it's a branding thing.

I mean, there's a ton of great people over there. They've got great products and services. And, you know, one example is they've got a mobile person-to-person app similar to PayPal or Venmo or Zelle, but most people don't know about it. Um, so it's, it's, I guess they're going through that transformation and they're restructuring. Certainly, you know, we're hoping that they're going to be able to come out of this and come out stronger.

And I'm confident they will over time. But this is, you know, it's tough when you go through these changes. Yeah. I mean, they are the hometown team, so we're definitely rooting for them to, to, to make this happen. Uh, whatever we can do.

If, if you're right now about to send money using Venmo, maybe don't do that. Maybe go install the Western Union app and give it a shot. Yeah. Give it a try. Right.

Can't hurt. All right. Moving on. Uh, moving over to security news, Ping Identity, uh, everyone's favorite Denver-based identity company, uh, released this, this week a private cloud identity solution. So this has actually been like consuming my life for the last year, so I'm excited to be able to talk about this now.

Um, you know, in general you get a SaaS application, you have a multi-tenant, uh, hosted application. Well, this is very similar except it's a single tenant option. So instead of having Um, you know, if you try and move to a SaaS, you kind of have to give up on many things because you're going to the lowest common denominator. It has to work with that platform in a multi-tenant environment. Here in a single-tenant environment, you don't have to give up quite so much.

You know, you get to customize and have things that are directly customized for your organization. So we talk about this a lot in the industry, right, from a platform perspective, single-tenant versus multi-tenant. Certainly financial services companies, right, have a little bit more stringent requirements relative to compliance. And prefer that single tenant model. Talk us through some of the business drivers as Ping oriented itself around single tenant versus multi-tenant.

What were some of the drivers behind making this decision to prioritize a single tenant offering? It's a great question. So we've already had the multi-tenant, right? We've had it for a long time. Uh, it— the creation of the single tenant environment was to say, to answer the bell when people say, hey, I want all of the same features we get from your software in our data center, but but I don't wanna have to manage it, right?

I don't wanna have to have the IAM team on my staff. I don't wanna be— have to be responsible for the SLAs around uptime. I want you guys to take care of all that for me, but I don't wanna give up feature functionality. And you just don't get that from a multi-tenant environment. The other answer you were already talking about was highly regulated government organizations, financial services.

They are really interested in having a single tenant isolated environment where they can say, that's my environment and we're gonna treat it the way I want to. So this kind of answers those requirements for them. Ping is, you know, the enterprise identity play. We don't sell— do a lot of SMB type of work. So a lot of our companies are really interested in this level of control.

And I'm guessing during the contractual discussions with the enterprises you work with, as you get into liability, warranty, indemnity, multi-tenant versus single tenant, as you move into that single tenant conversation, I imagine that makes the contracting process a little bit easier because you're not sharing a tenant with other enterprises and around data privacy and other things like that. Yeah, and if you have one company that says, I want my password policy to be A, and the next company says, I want it to be B, well, a single— a multi-tenant environment doesn't work for that, right? Single tenant does. Yeah. All right, so let's move along.

Yeah, it is good. Thanks, I appreciate it. What do we got next? Next up, give me one second here, is Managed Methods increases revenue by 141% in the first half of 2019. That's, that's really good.

I like it. That's more than double, right? 141 is more than double. So, so interestingly, right, they do a lot of work with educational institutions, right, helping them manage their applications and specifically the security of their applications through APIs. Recently, I don't know if you know this, but in Texas they just passed a bill called 820, the Texas Senate Bill 820, which requires all schools in the state of Texas must adopt a cybersecurity policy.

Interestingly, Louisiana also passed a similar policy for educational institutions. I don't know how much Business Managed Methods is doing outside of Colorado, but it seems in the key area that they serve, there seems to be a lot of now legislation coming up requiring educational institutions to implement cybersecurity policies, which is great. Yeah, I agree with you that the school— they do a ton of work with schools. And I actually believe from what I heard that they do work in Texas too. So I bet you that they were part of that.

And Uh, that's a great driver for them. Congrats to them for the growth, and we're excited to see a local security company do well. Keep it up. Speaking of local security companies, Optiv has announced a brand new CTO for the Americas, uh, Todd Weber. Hey Todd, congrats.

Um, you know, it's interesting, Todd goes back with Optiv to 2005. It's infrequent in today's, specifically in cybersecurity, but most companies to see somebody with the firm for 14 years. Yeah. And it's always exciting when there's that internal promotion, someone who started early in their career committed to an organization who then gets promoted up through the ranks. Right.

It's a rarity today. It's not the standard, but good for Todd. Congratulations. I'm sure he's going to make a lot of great additions to and changes to what Optiv is already doing. Yeah, I'm looking forward to seeing what's next for Optiv.

Next up, Context Matters: Turning Data into Threat Intelligence from Webroot. Yeah. So Webroot has a, I would actually say, a pretty good spot-on blog post here around how do you use threat intelligence? And so many of us get these feeds that maybe go directly into our SIEM or, you know, into some kind of central repository, but without a lot of context around it, you're just getting a bunch of data that, you know, adds cost, adds administrative burden, but maybe doesn't add value. And they start to give some examples of how do you turn that data into specific actionable intelligence.

Yeah, this notion of context matters really resonates with me. One of my favorite clients of all time is Southwest Airlines. Uh, and there was the head of the threat and vulnerability management program. And in information security, context does matter. And, uh, he had a quote at the bottom of his email and I have to give him credit for it.

And I thought it was very clever, but it was true. And this went out on all his internal and external messages and it said, security without context is meaningless. I'm susceptible to drowning, but I don't wear a life preserver everywhere I go. There you go. Right.

That's, that's a great example. Uh, good stuff. Uh, last story here, we have a story from Dark Owl talking about 8chan. Um, I don't know, I'm sure I had actually never heard of 8chan before the, the tragedy in the last week where one of the, one of the shooters— was it the shooter in El Paso? I think it was— um, had, had put his manifesto on 8chan, um, as the, as like a place to dump it.

And really it was 4chan, uh, when 4chan got to be too restrictive They created 8chan to be like, you know, just hell on earth, basically, from what it sounds like. And, and now 8chan has been knocked off the internet. But this blog post is talking about how just because Cloudflare stopped protecting them doesn't mean they've gone away. There's actually a, a hidden site called— was it ZeroNet? I think it's called.

Yeah. Where they've been hosted. So interesting to see. Yeah. You know, it's this whole— we could spend an entire show talking about freedom of speech.

The exercise in democracy, right? Where is that borderline of freedom of speech? And where is that borderline being able to say the things that you want to say? They left 4chan because of the moderation, and they felt that it wasn't the platform they could have. Does this tie into a Silk Road type environment?

Maybe. You know, many of the folks out there, listeners, right, have access to a Tor browser and can gain access to the dark web. We are somewhat already protected by our ISPs and other controls that don't really allow us to access the full internet. But as it relates to this particular article and the unfortunate nature of what happened in El Paso, you know, from a freedom of speech perspective, where does it start? Where does it stop?

Who governs it? I think this is still uncharted waters, and even though it's 2019, I don't think we have a good answer for this. Yeah, it is, it is really tough stuff, and obviously the line between, you know, protecting people and giving freedom of speech is It's not ever set in one place. And I think this is going to push it in one direction. These types of things are going to push it the other way.

Yeah. All right. That is it for news. Moving over to the Slack message of the week. Andre, thanks for sponsoring this.

I love sponsoring this. Every week we talk about this. This is an opportunity for us to recognize someone who really keeps the conversation going in the Slack channel. Although honestly, it's been hard to pick lately because there's so much conversation. It's hard to keep up on it.

But we— I did. It wasn't hard this week. I was really happy to be able to, um, recognize Josh Gillum. Um, I don't know if you saw this post, Andre, but the Buff Overflows, which is the CU, um, capture the flag CTF type of a team, won first place in the Wicked Six Cyber Games this week. Nice job, guys.

Congratulations. So congratulations to Josh for winning Slack Message of the Week. As a result of this, you get one item out of the Colorado Equal Security store, um, of our— your favorite swag. Yeah, yeah. And people have been ordering all sorts of good stuff.

T-shirts, mugs, stickers, magnets. Go out there, check it out. There's great stuff. Has anyone bought the thong? Yes, there is one person.

Should we reveal who that is? He knows who it is. Yeah. Alex is the one. All right.

Moving along over to events, I want to do a reminder that we do have a calendar of events on the website at colorado-security.com. You can go see everything that's happening. Through the end of this year. We, every week on the show, we go through the next couple of weeks of events so you can plan out your own calendar and, and show up wherever it is. This week on the 13th, there's a Splunk meetup.

They're doing a brewery tour and a hands-on workshop making your own Splunk visualization app. It'd be cool if it was also hands-on making your own beer. That would be cool. That would be cool. I bet they can make that happen.

Also on the 13th is the local Denver ISSA chapter meeting. They're meeting on the 13th and 14th. Uh, on the 15th, SecureSet is doing a Hacking 101, an introduction to data visualization. And on the 17th, CISSP Seminar Series Domain 1, Security and Risk Management. This is such a good opportunity for anyone who's looking to get into security, or you're, you're already in and you really want to get that CISSP.

These are incredibly cheap CISSP trainings given by the local ISSA chapter. Um, on the 20th and 21st, the Colorado Springs ISSA is doing their August meetings. That's on the, the dinner on the 20th and lunch on the 21st. Also on the 21st, CTA DevOps at Scale meeting. Uh, on the 22nd, the IT Security Professionals Happy Hour is hosted by InteliSecure.

So go join InteliSecure and get to know some other security folks. On the 22nd also, the CTA Women in Government CWCC Young Professionals Board and Public Affairs Committee. It's a lot of words, isn't it? That's a lot of words. Also on the 22nd, it's a busy day.

If you want to do something on the 22nd, you have your choices. In Colorado Springs, the Air Force CyberWorx Small Business Innovation Research Seminar is happening. And if the 22nd is not good for you, on the 23rd, the day after, you can go into a beginner's intro to Capture the Flag done by SecureSet. I love those events. I've had quite a few people who've started attending those just like to get their toes into the water of security and they've really enjoyed them.

So if you're thinking about it, I recommend going. Capture the flags are a lot of fun. They do big ones like this week, Black Hat DEF CON, one of the biggest ones in the world takes place. Um, they're fun to watch and participate and see what's happening. It's really, really interesting to see how they build the stories out and then how the teams work together through a variety of techniques to capture the flag.

It's interesting. It's so cool. And it's great that they're doing an approachable way that you can get in here. You don't have to be a pro to step in here. The next day on the 24th is the next CISSP seminar.

This is on the 3rd domain, security engineering. And then final one, Andre, this is you. Yeah. August 24th, also my birthday. So feel free to send gifts.

Colorado Springs ISSA mini seminar. So on your birthday, are you going to be spending it learning about the CISSP or are you going to be in the springs with the mini seminar? I think we're going to be on a raft. Oh, you go back out. All right.

We're going back out. That's awesome. All right, let's go ahead and move over to jobs. I have a, uh, a few jobs here. I'm gonna start off with the Ping Identity jobs like we do every week.

If you're, if you're gonna work for me, you get to be on the podcast. That's pretty good. Uh, the, uh, Ping Identity opening that I want to talk about this week is our GRC analyst. We're looking for an entry-level person who's interested in getting into security. If you have some kind of a research background, maybe a writing background, and you like to learn, this would be a good opportunity for you.

Uh, SOC 2 ISO certifications, vendor risk management, business continuity. Those are the kind of domains you'd get to play with if you joined Ping doing that. That's fun. Also over at Ping is the manager of product security. You guys make great products, and if you get to be a manager of product security, that's pretty cool.

At Maxar, they are hiring a VP of enterprise security. This is a cleared position, so top secret clearance is required, or maybe they'll help you out. I don't know the answer to that, but I think this is basically the CISO on their government side. And Visa is hiring a chief cybersecurity engineer. That sounds pretty good, doesn't it?

It sounds really good. Yeah. I don't, I don't know what skills you need, but I bet they're pretty high. They're above mine. Especially after what happened with Capital One recently.

This is probably more and more important. Bank of America is hiring a cybersecurity incident manager. And I'll just say Bank of America has like 50 security positions open in Denver right now. So that's a website you might want to check out if you're looking for a job. Yeah.

Great to see Bank of America moving their operations here and hiring a lot of security folks. Um, also on the job site, Ball Corporation is looking for a cybersecurity operations lead. Uh, Terumo BCT is hiring a software security architect. And the Office of the Attorney General hiring a cybersecurity analyst. A lot of good jobs this week, huh?

Absolutely. IHS Markit is hiring a cybersecurity specialist. And Jeppesen is also looking for a cyber— a security specialist. Uh, Coalfire is hiring a vice president of cybersecurity services innovation. I would like to know more about what cybersecurity services innovation is.

Doesn't this seem like the kind of job that you give some, like, an early employee who you don't have anything to do anymore? Like, you're like, we'll just put him over there on cybersecurity services innovation, and, you know, that way we don't have to cut his pay, but, and we don't have to get rid of him. Like, it doesn't seem like a job that you actually need to hire for, so I'm super curious what this means. Yeah, if you're out there, please let us know. Uh, I mean, anything with innovation in the title sounds pretty cool.

Sounds pretty good to me. Yeah. Uh, last job, Andre. All right, Privy in, uh, Denver is looking for an IT Audit Associate Director. All right, well, that takes us to the end of the news for this week.

Uh, we do have a, a feature interview, and this is a, a fun one. We have an interview with Eric Alexander. He is the Senior Lead DevSecOps Engineer over at The Trade Desk, and this is a special one because Neither Alex nor I did this interview. We had Joe McCallister, one of the, one of the listeners and a part of the community, volunteer to do a couple interviews for us. And he sat down with Eric this week and, uh, and got the interview for us.

It's awesome that you guys expand the community and allow members to participate in meaningful ways. So, uh, continuing to grow and build and, you know, in the essence of Colorado security, you guys continue to innovate. So great job. Awesome. And if anyone else is listening and wants to help do interviews, this is your opportunity.

Well, I think that is it for us. Andre, anything else before we go? Everyone have a great weekend. Enjoy your time out there. The summer's still on and no kids are going back to school.

School soon, but summer's still on, so go out there and have some fun. All right, we'll talk to you again soon. This is James Carder, CISO at LogRhythm. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.

This is Joe McCallister with Colorado Equals Security. I'm here with Eric Alexander. Of course I messed it up a second after I said it's easy to pronounce. Of The Trade Desk. And so I would love to just kick things off with you running kind of through your background, be that education.

Are you originally from Colorado? I'm originally from Colorado. I pretty much grew up like 10 feet away from here. So when I was 3, my parents moved here and they— my dad was in retail management and he took his first entrepreneurship stab and bought a store on Pearl Street just after Pearl Street became a pedestrian mall. And yeah, I spent most of my childhood on Pearl Street, so we're sitting on Pearl Street now and this is, this is just kind of like home for me.

But yeah, I'm a 5th-generation Colorado native and we joke in the family that we're just not allowed to leave Colorado. That's awesome. So yeah, how did you kind of get into the security game? Was it something you always wanted to do or was it something that I see more of a trend as, oh, there's this thing we need you to take care of, you're now the guy for that. That's it.

That's it. I mean, I think security has a lot— I think you can see it when you go to various conferences like Black Hat and DEF CON, where if you went to those conferences 10 years ago, it was nowhere near the size it is right now. And the people that you encounter there were people that were very interested in security for various reasons. Like, it wasn't necessarily about the money. It wasn't because it looked like this great job opportunity typically.

And I think a lot of those people definitely fell into it through indirect routes. And I think a lot of those people got interested because, you know, they found themselves in an incident and they didn't have the answer. And they climbed out of that hole and they just kind of became the security person. In a lot of ways, my path into this isn't too much different. I probably about 15 years ago, I had a personal server at my house that was exposed to the internet and it got popped and I proceeded to spend like a month trying to figure out like who got into it, how did they get into it, and what was going on.

And at the time it was like a very classic tale of I didn't patch something and they found it and they got in. But through that, at the time I was doing some consulting work and we had a customer that did some DoD work and they had some questions about security. And because some of my managers and coworkers knew that I was obsessed with finding these Russian hackers that got into my home server. All of a sudden I started getting this— if security-related work came in through the consulting gig, all of a sudden I started doing that. But then I left there and I went to a company and I was more— I started more or less as a sysadmin and then I became a network engineer and part of that was managing the firewalls.

And one day one of our bigger customers, a federal customer, said, hey, you guys need to be NIST 800-53 compliant. And the powers that be said, who's going to do this? And they thought, well, Eric manages the firewalls. I think Eric should just do this. So they came to me and said, hey, we got this new project for you.

You need to take care of this thing called NIST 800-53 compliance. And I thought, yeah, sure, why not? How hard could it be? And 2 years later, once we really stamped it as done, I figured out how hard that could be, and from there I became less of just the network security engineer and more of just the security guy. And then we were acquired by a public company, so we had to start doing SOX.

HIPAA came in there in the mix at some point, and shortly thereafter, so, There's a book out there, it's called Good to Great, and I think about that book when I think about why I wanted to leave that company. And this happens so often when a company is acquired that you might have a company— in Good to Great they talk about getting the right people on the bus. So they talk about hire smart people, it doesn't really matter what their skill set is, hire smart people, get the right people on the bus, and they'll find problems to solve and they'll solve those problems. And while I have a lot of respect for the company I worked at and even for the company that acquired us and all the people associated with that. I started to see the right people get off the bus and I thought it's time for me to get off the bus.

So I found The Trade Desk.

Really what piqued my interest about The Trade Desk is it came up on my radar. We're in the business of ad tech, but if you look at our company name, it doesn't suggest we do anything with ad tech. It sounds like we're a Wall Street company. Once I saw that it was ad tech related, I thought, like, gross, I don't want anything to do with that. But there was something in the job description that piqued my interest, and it was you have to pass a coding exercise.

And it blew my mind. I was like, why would anybody— why would any information security engineer have to pass a coding exercise? But it resonated, and it was on the forefront of my mind for days after I read that, only because I taught myself how to write code a long time ago, and when possible, I'd solve problems through code. So I knew there was value there, and I really wanted to find out why it was so important for this company. So one thing led to another, and here I am.

Awesome, awesome. So yeah, there's definitely a theme of code becoming, you know, those circles are overlapping more and more and more, and programming knowledge as a security engineer, even analyst level, whatever it might be, that is helpful just based off of attacks we see in the wild. So you currently are, and forgive me, I know we talked briefly about titles and how they're strange here, right? But you are DevOps, DevSecOps, So we're— yeah, so titles— we're a very flat organization and titles don't mean as much here as they mean in a lot of organizations. But my— I'm a— so it's kind of interesting.

Internally, my title is Senior Lead Software Engineer, but I'm not a software engineer as most people would think of a software engineer. It's just that For various reasons, we have some very standardized titles, but again, they don't really mean much around here. But on my LinkedIn profile, I have Senior Lead DevSecOps Engineer because I lead a DevSecOps team, and that's really what I do. So I think a lot of people would get confused if I had on my LinkedIn title Senior Lead Security Engineer. They'd think, well, you don't do security.

What's going on there. But to help clarify that publicly, that's what I have on my title. Yeah, so that's— and I mean, that's interesting because of— and we talked prior to starting the interview here about how it's just intersecting more and more. And as companies want to move faster and break things faster too, DevOps becomes part of the culture. And therefore, coming right behind it, especially today, we see more importance placed on that middle syllable, right?

The DevSecOps is becoming way more important. So how do you guys, or how do you personally kind of go through your day? What does your— if there is, I'm sure the standard answer is there are no 2 days that are the same, but in an organization that is growing quickly as The Trade Desk is, How do you and your team kind of adapt to those challenges as new technology is coming out, as new platforms are being spun up or hardened as it is? What's your kind of process? What's your day look like?

That's a good question.

More and more my days are just a lot of meetings.

When I think about what I can do, it's how can I improve the bandwidth that my team has. So it's a lot of meetings, it's a lot of figuring out how can I improve their bandwidth. But that's me. On our team, we really do what fundamentally every security team does, or every security practitioner does, regardless of their title or their team, and it's really identifying risks and reducing those risks. So we have purview over some very specific things here, and it's identifying risks related to those things and attempting to reduce those risks.

Actually, I missed a step there. It should be identifying the risks and prioritizing and then reducing, because you'll just chase your tail if you're trying to solve all of the problems all at once. So we have this term that gets thrown around a lot internally, and it's what we call the peanut butter effect. So it's this idea of peanut butter that just gets kind of thinner and thinner, and the more things you chase after, the more thinner you are on all those things, and the less likely you are to accomplish any one of those things. So that's where the prioritization is so important.

Identify the risks, try not to freak out when you see the list of risks, and go and tackle the highest priorities. Once you fix those, then go right back down the list. It should be an iterative process. It shouldn't just be, I'm going to be blind to identifying risks just because I found a list. You should always be looking to identify new risks and prioritizing those, and sometimes you've got to stop what you're doing and Go charge after the higher priority ones now.

But that's what we do, and the dev side of it is really just us automating that. So I take an unpopular view of what DevSecOps is, and I think if you look at a lot of people and how they define that, they're really saying we're an AppSec team and we're introducing things into our software-defined lifecycle. I'm sorry, our software lifecycle, and they're saying, how can we be faster about finding risks in that lifecycle? But that's a very myopic view of risks in general, from my perspective. So we're not just looking at, you know, is there a defect that's about to go to production?

We're also looking at, you know, what systems do we have? What's our attack surface? All those related risks, and we're trying to automate being faster about identifying those, providing feedback whenever possible so that they actually don't even go into production. So, and when they do hit production, identifying those as fast as possible and remediating as fast as possible. So it's just trying to solve real-world problems through code and Reducing toil as much as possible.

Yeah, yeah, the peanut butter analogy is awesome. Usually I hear it referred to as, or I should say I refer to it as, you know, mile wide, inch deep. You can't get a great picture of everything, but as a peanut butter lover, I will now be using the peanut butter effect. I remember the first time I heard that here, and I had no idea what the person was talking about. Like, what are you talking about?

But that is so— I think it came from one of our founders, and that analogy is used so much here that, yeah, it's pretty common. Yeah. Do you have a favorite peanut butter? I like Adams All Natural Peanut Butter. See, I'm a Peter Pan guy myself.

Peter Pan, yeah? Yeah. I'd never had a favorite peanut butter until my wife refused to buy anything but Peter Pan. So now I'm a Peter Pan guy.

So this, the next question I like to throw out, it is an interesting, Opportunity, I'll say. What's been your kind of— and we use this across the career in security, right? What's been your best day in security? And I hate to say worst day. Usually I ask of a person at a company, right?

What's been your most challenging day? Because there are no worst days, right? You probably have a worst day, but what's been like your most challenging obstacle? And if either how have you overcome it or how are you continually working to overcome those?

So there's a couple things coming to mind with the worst day. It's so it's interesting that you ask this question because I always encourage people to like give that a lot of thought. Like what's your what's your good day? What's your bad day? And we should all you know I think it was Confucius that had a quote you know like.

Do what you love and you'll never work a day in your life, more or less. And there's a lot of value in that, right? Like, we should— we're all good at some things and we're bad at others, and you should really focus on the good things. Like, we should always challenge ourselves and we should always try and get better at things, but you're gonna be more efficient at the good things, and you should try and focus on those things. So what makes you happy because you're going to be motivated to go and do those things.

But at the same time, in the real world, that doesn't always work out. But I mean, I have always liked a good challenge and, you know, like when you get to that end of that challenge and if it's— the harder it is and the longer it is, the better the feeling is at the end where you're like, Man, like, I wasn't even sure if I was gonna be able to do that. It's kind of like hiking a 14er, right? Where you get to a point somewhere in the 14er where you're just like, I'm tired, I've got a headache, there's not enough oxygen up here, but I'm committed, I'm just gonna keep pushing on. And then you get to the top and you got the view and you're like, this was, this was worth it.

So when you get to the end of those things, like, those are always a good day, but there's so much that goes into getting there. That you're gonna have a ton of bad days in between. So there's, I don't see anything wrong with bad days, but there's definitely some things about security that to this day just like, you know, are challenging and I'm still trying to learn like how do you really do this better? And one of those things is really what's more or less the marketing aspect of security, right? It's taking an organization that has no forcing function for it to do any of the right things and actually convincing it that it should be doing those things.

And that's one of the things that I found the most interesting about the trade desk is it didn't have PCI compliance, it didn't have HIPAA, GDPR at the time wasn't in force. It did have SOX, but, you know, in my mind coming into it naively, I thought, SOX is gonna be so easy, like I'm just gonna knock that thing right out. But anyways, those compliance things, there's so much difference between compliance and security. Compliance is 2 entities agreeing that 2 things are gonna happen, I'm sorry, that certain things are gonna happen in an organization and then validating that those certain things are happening, but that doesn't actually always push the needle forward on security. Security.

So you take things like the Heartland breach where they literally had a PCI audit like a week before, and it sounds like most likely they reverted some things. And if compliance actually pushed security so far, I think a lot of us— it would all be done, right? A lot of us wouldn't even have jobs. It would just be considered done. And that just kind of shows that compliance is good, but it doesn't actually solve all of the security risks.

So it's very challenging to take any organization that has 100 things that they're worried about, they have 100 or 1,000 risks, and you're trying to help them understand the priority of a security risk and why that should supersede or get more attention than anything else. That can be like so exhausting to try and convince people of that, that there's a lot of times where you just feel so exhausted at the end of the day from trying to make that happen that those days can feel like bad days. But it's with enough of those push-forwards and the whole idea that the squeaky wheel gets the grease that eventually you'll make it happen and it'll turn into a good day. Mm-hmm. Yeah, absolutely.

You'll reach that summit. You'll hit the 14er eventually. Yeah. And then you just look for another one and just keep going. Yeah, there's a bigger one over there.

So it sounds like you read a lot. Would that be fair? Uh, I read a fair amount. Yeah. Yeah, I hear it.

So I heard Confucius. I read a little bit of your website, and your talk had some references to The Art of War. You mentioned From Good to Great, was it? Good to Great, yep. Do you have any other favorites, security or not security, just books you love or like to maybe apply the philosophy therein in the workplace?

You're opening a can of worms. We could talk about this for a while. So yeah, I definitely have a list. So I still like to buy paper books. I just never got into Kindles.

I don't see anything wrong with them. Some people really like to listen to books. I think that's great, you know, as long as you're learning. I just like paper books. And one of the things I do at the end of reading a book is it just goes into one of two piles.

One pile is I'd recommend that to somebody, and other pile is I just wouldn't recommend it. And, and the, the— it takes a while to figure out, is this something I'd recommend or not? And it kind of goes back to, you know, reflecting on what you learned from that book. And there's definitely some books out there that I reflected on more and more. Good to Great is a great book.

One of the things that you start to learn in security is that if every shiny object, like every new tool, really solved the problem, we'd be done by now. But it's not necessarily a tool problem. A lot of it's an organizational change problem. You really need to go and learn how to change organizations. And you need to really just kind of learn how to get things done.

I really like the book Scrum: The Art of Doing Twice the Things in Half the Time. The title is basically Scrum. It's a little bit longer. But that goes into kind of agile methodologies and the ideas behind Scrum. So here we're a Scrum team.

Within the engineering team, every engineering team is a Scrum team. We work on sprints. We adopt the Agile methodology. And doing things through an Agile methodology is very effective at just overall getting things done. So the idea that you break down really big problems into sprints, and you can prioritize the work in those sprints, and then at the end of the sprint, You can have retrospectives and say, hey, what did we learn?

How can we go faster? Do we need to reprioritize the work? There's a lot of value in those things. And then a lot of this, when you kind of look at it from a sprint perspective, the path to the summit isn't this daunting thing that you stand no chance at accomplishing. You kind of look back at it and it's It's just legs of the path that you need to get past.

You get past one leg, you go to the next leg. So I think Scrum's super important. Team dynamics are very, very important. So the book Good to Great kind of goes into team dynamics a little bit. The book Five Dysfunctions of a Team is super important.

You got to have an effective team. And those are ones that I think I probably reflect on the most. Cool. All right, I appreciate that.

So I know I asked kind of what would be your most challenging days, but what do you kind of see, especially from the DevSecOps side of things, what are the biggest challenges, be they for The Trade Desk locally or expand that out even to DevSecOps as a larger culture or community? What are those challenges? I know part of that probably is realistically the sales/marketing to the C-suite or the steering committee or the board, whatever it might be, for importance. But do you see or have you identified anything else that is really kind of that rock you're trying to break?

Once you've done security long enough, you start to realize there's so much to it, and at the end of the day, you're always trying to prove a negative. So you're always trying to say, if we do this thing, this other thing's not gonna happen, and that's impossible to prove, and it's really challenging. And then a company's got these other competing priorities that have some very clear goals, some very clear feedback loops as to whether or not you achieve those goals, like did we increase sales this quarter? So those priorities are typically gonna win, but there's the kind of marketing organizational aspect of it, and then you have to stay sharp on the security side. So, you know, it's so challenging to stay up on the security side as well.

And, you know, coding is important, for a common language, for reducing toil, but it's also one of these other things that you now have to learn. So sometimes I wonder why I even do this at all, to be honest, because it's so challenging, but— and sometimes it doesn't feel like the reward is right, but at the same time, I think I always kind of come back from that like Fortuner perspective, like It's worth the challenge to try and figure that out. And we're still on the precipice of a lot of organizations getting to the point where they have security teams. There's typically some forcing function that brings a security team into an organization, whether it's a compliance initiative, an incident, or something else that force them to do that. So I think we're starting to see a profession that has been growing rapidly but is only going to grow even faster.

You know, there's a lot of privacy laws that states and federal entities are trying to enact, and those are going to be forcing functions that force a lot of other companies to do this. We saw it in Europe with GDPR, we see it in California with CCPA. It's all signals to suggest this isn't gonna get any easier, it's just gonna get harder. So, it's that challenge of it and it's, you know, the increasing awareness of it that I find kind of interesting. Awesome.

So, you're a team leader, right? How— and this is going to be purposely kind of open-ended, and I know most of them have been already— but how do you build an effective team, or what are your kind of big goals when it says— when you're given direction to, I need you to just make an effective team, and that's the only guidance you get? What is your ideal state for building an effective team? So if you're building a new team, you're in a unique opportunity to, like, be really picky about who you hire. And hire smart people and enable those smart people to do what they do best.

And, you know, there's a lot of philosophy that goes into how you actually do those things on a day-to-day basis. So, you know, there's the idea of, you know, staying inclusive on changes. It's not just one person on top that's barking all the orders and trying to lead them. It's the entire team that's helping to solve the problem.

That, I mean, it sounds so simple, but I mean, that's really it. So hire smart people and serve those people. They're not there to serve you, you're there to serve them, and good things will happen. Awesome. What would you, or how would you encourage somebody, say, from a traditional IT, or maybe they are a SOC analyst, right?

Or, or they have an interest in what this whole DevOps, DevSecOps, even application security, web app testing, whatever it is, the stuff that is maybe outside of their current purview. How would you, or would you have any resources you may point them to to say, pick this book up, read these chapters, do these exercises? Anything that jumps out as This is the news to know. Yeah, I mean, so DevOps is really born out of lean manufacturing. So, you know, one of the best books to understand lean manufacturing is The Goal, and it is— I'm having a hard time remembering the name of that author, but it's basically a fiction book, fiction-type story that kind of goes into the practices and the values of lean manufacturing.

And then I think it was Kim Scott wrote The Phoenix Project, and he borrows heavily from the format of The Goal and a lot of— and DevOps is really born on lean manufacturing, so it makes sense that he would borrow heavily from a lean manufacturing book, but DevOps follows kind of the same idea. And it's this idea There's a lot of ways to describe what lean manufacturing is and what DevOps is. I really think about— I like to ski, I like to snowboard, and I think about it when I see or take a friend up for the first time that's snowboarding. When you do that, what's most interesting is when you take up a very athletic friend and you kind of ask them, hey, do you want to go over some pointers or something? They're like, no, I got this.

And they jump off the lifts and they immediately flail. They start to flail around like a fish out of water. And everything they do is so inefficient. But what you start to realize after you snowboard and ski for a while is it's a lot less about your physical ability as it is your comfortability. You being comfortable with actually the sense of falling down.

So when you get comfortable with that sense, you start to lean in on the board or the skis, and you start to have those do more of the work than you do to really physically make that happen. And I think about that— those are things that I think about, but it's really the idea of an elite athlete as well, like an Olympic athlete. An Olympic athlete is basically perfecting to the point of what they don't need to do. They're not trying to add anything else. They're trying to figure out what do I need to take away because through those efficiencies I'm going to be a better athlete.

Lean manufacturing and DevOps is really no different. I think in lean manufacturing was the idea of value stream mapping came out of lean manufacturing and you can apply it towards DevOps, towards DevSecOps as well. But it's this idea of What is our goal? So if we're a software company and our goal is to ship features that customers want to buy, then really the goal is those features. There's second-order needs that come along with that because customers are going to be attracted to the feature, but they have some expectations about security, about stability, about availability.

Things of those nature. But those things come into the goal, but you really have to look at what's the most efficient way for us to get those features out and meet all those second-order needs. And that's, you know, The Goal, The Phoenix Project, I think those are great books to kind of cue you into that. But as with anything where a term became popular, marketing teams have adopted these names and they've kind of morphed off to things that didn't really include their original meanings. So a lot of times you'll see companies where they have a DevOps team and you go and talk to a person on that team and ask them about their day-to-day and they're really describing a very, very traditional sysadmin role, but somebody wanted to call them DevOps for whatever reason.

I actually don't like the term DevSecOps. It's like, where do we really end here? Where do we just kind of add things? I always thought it should have been Agile Security, but DevSecOps kind of took off, so I figured that's the name, and if it's going to stick, use it. I don't think there is a book out there that really kind of goes into what DevSecOps is.

There was a couple speakers at RMIC, and they wrote a book. I think it's Common Failures of DevSecOps, and it's like 4 or 5, maybe, I'm sorry, maybe 7 or 8 short stories on kind of failures in DevSecOps. And that's an interesting glimpse into what DevSecOps is, but it doesn't follow the tradition of the oral story that like Phoenix Project and The Goal has. And I think we really need that. I've contemplated just taking a crack at writing that, but the peanut butter effect, I have to keep focused on what's most important, and I'm not sure that's most important right now for me.

Yeah, yeah, absolutely.

So I've noticed, and this is just a common theme, and I think it's something that people do as they progress in careers in general and in life, but I have a friend and mentor of mine that when I started kind of going through some of the more high-level discussions in information security and, and talking about GRC and risk management in particular and controls and all this stuff, he said something to me that I'll never forget, of course, because it came true. It was a prophecy that was, you will never go out and walk the street and not see something as That's a preventative control, this is a deterrent control, this is X, Y, and Z. Do you find that with DevOps as well, or is it just a security thing that now you're looking at everything? Does it induce some paranoia in you being in security by nature, and then does that kind of expand out into your current role at all? I've been doing this too long, and if anything, I worry that I'm starting to fall into the normalized deviancy bucket where like you start to just kind of get numb towards things the longer you've been here, you've been doing it, where, you know, like what was once old is new again.

It's like some repetitive cycles. I find it very interesting that it used to be, from my perspective, it used to be anybody that processed credit cards were huge targets and they were kind of the forefront of security controls, and attackers shifted and they saw an easier target. When the state of security improved for credit card processors, typically people that want to attack your system, they're a lot like businesses if they're not actually businesses or acting as businesses, where they want to— through that efficiency idea, they want to go get the most money as efficiently as they could. And cryptocurrencies, like, became that thing. And the, the cryptocurrency world got hit really hard.

And it's, it's so interesting because it was this world that wasn't heavily regulated, and the forcing function wasn't the regulation. The forcing function was people losing millions of dollars. Um, and, and I, I like to, to stay aware of incidents and, and really kind of learn from those. Those incidents, because the more you know about what incidents are actually occurring, the more likely you are to be better at prioritizing where you need to focus your time. So I don't know that I walk through the world and I see like preventative controls and different controls that, you know, like you start to see just sloppiness and you get that like spidey sense where you're like, I'm looking at this point of sale terminal and I'm seeing some things that don't look good, or I'm like, you know, I'm filling out some form online and, you know, I'm seeing some things that I don't like.

But for me, it goes back to that idea of how do you stay efficient? Like, you can fall down a pretty deep deep rabbit hole when you start looking into those things in depth. And yeah, I mean, somebody else has more time than me. They can go and dig into those things, and I'll stay focused on the things I need to. All right.

Well, it's reassuring to hear that maybe my paranoia levels will subside over time, and I'll start to normalize a bit. So my manager is somebody that used to be on the Yahoo Paranoids team. And I just like that team name. I think every security security teams should just be called the Paranoids. It's so true.

Like, we didn't get into this because we weren't paranoid. Like, most security people get into it because they are paranoid, and it's like an onion. The more layers you peel away, the more you want to cry. So it's, you know, paranoia just comes with it. Yeah, yeah.

You mentioned staying up on attacks, and breaches and stuff like that. How do you best do that? I feel like everybody has kind of a different either list of resources or RSS feeds or whatever it might be, Reddit, Twitter. How do you do that? So for a long time, I've just gone out and looked for sources that have that information.

So US breach laws have been super beneficial for instrumenting that data. So you take like California, their attorney general discloses publicly any breaches that they've been notified of. Any state that has a breach law does the same. And then there's popular sites like Krebs on Security and others that the big ones that maybe didn't fall into one of those states, they'll catch attention on those. What I usually like to do is read as much as possible, and if there is a breach disclosure where they go into depth about what happened, you can really start to see patterns, and I guess this is where I start to see preventative control patterns, where you start to see patterns and you're like, man, if you had this NIST control in place, that would have reduced your risk so much, but also PCI has this control, if you would have had that in place, place, you would have reduced your risk as well.

And I tend to take that information— so I started a subreddit, it's Security Breach, and what I was doing was posting all that there because I wanted to encourage more conversation about all these breaches, mostly the conversation of how did it happen, how could it have been prevented, but I was never able to stimulate that discussion, but I still have a spreadsheet where I'll put them in there and I'll tag them with what I think happened, and then that creates some graphics that I've used multiple times internally. So on our corp security side, you know, it's so easy for people to chase their tail and they, you know, they say like, oh man, I read this thing in the news and why aren't we doing this thing? And it's And I'll use that data to take an evidence-based approach and say, if there's something that we need to focus on the most, it's this one thing, because that's where breaches are really stemming from at the moment. So, like, a great example is the proliferation of BEC, so business email compromises. You know, the whole Nigerian scam maybe has roots going back like 100 years, But at the same time, there's teams, maybe they're in Africa or not, there's teams out there and they can monetize a compromised business email account so fast that there is a huge surge in business email compromise attacks and compromised emails.

When you read through those Attorney General breach notifications, probably 9 out of 10 of those are very traditional BEC attacks. So, it's for organizations taking evidence-based approaches towards risk reduction, it's huge evidence that you need to be focused on BEC aspects and what their tactics are and bolster your defenses there. Yeah, to bring it back home, I mean, risk management, risk prioritization, as you mentioned earlier, it's a matter of there are so many threats to any given organization. It's a matter of prioritization. Absolutely.

I think I see it time and time again where people are looking to their vendors for this insight. So they're calling up their vendors like, hey, what's going on? What are you seeing? And there's a lot of good vendors out there. There's a whole ecosystem.

I don't want to talk bad about vendors, but vendors want to sell you something most of the time. They are gonna frame something so it can be leveraged to sell you something more often than not. So, you know, fear, uncertainty, and despair is the most common sales tactic, and it'll be used commonly. But there's so much open data right now about the origins of breaches and how predominant those origins are, even across industries or specific to industries, that I think everybody should be using that data to take evidence-based approaches towards reducing risk. Cool.

And that was— the subreddit was Security Breach? It's /r/securitybreach. Cool. All right. Well, where can the fine people find you now that we told them where to find the subreddit?

I'm pretty easy to find. If you just go to ericalexander.org, it's got links to where I'm at on Reddit, where I'm at on GitHub, where I'm at on Twitter. I can't say I ever really bought into Twitter too much, but I'm there, and it's got my LinkedIn. People can find me on LinkedIn pretty easy. All right, great.

Well, thank you. Yeah, you bet. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes