All episodes

James Westbrook, Cybersecurity Analyst at Nelnet

Apple Podcasts Spotify SoundCloud

James Westbrook, Cybersecurity Analyst at Nelnet is our feature guest this week. News from: Denver Zoo, Velóce Corporation, Google, ShapeShift, Swimlane, root9B, SurveyGizmo, Ping Identity and a lot more!

And you thought your baby was ugly!

Just kidding, baby rhinos are adorable. Denver traffic is terrible. The future of medicine is here (and weird). Google is doubling down on Colorado. Boulder and Denver’s job markets are HOT HOT HOT. Denver’s ShapeShift may be the world’s greatest crypto company. Cody Cornell was definitely named the world’s best male CEO last year. root9B appoints a new board member. Here from SurveyGizmo’s Desiree Robinson. Ping drops some knowledge on us.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript14580 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 154 for the week of March 2nd, 2020. Hey Robb, you know, I think that was a Freudian slip because there is a story that we're gonna talk about today about a new calf.

A news calf. Yes, I like that. That's good. Well, Alex, we were both out in San Francisco and we both survived, and I guess we won't know for a couple weeks if we got the coronavirus though. Yeah, you know, I hear there's about a 30-day potential.

30 days? Yeah, like that's the longest. Oh man. For the potential incubation period. Um, it could be a couple weeks before we know if we have the plague or not.

Well, if you see me in per— in person somewhere, maybe don't kiss me until you, uh, until you know. Uh, okay, why don't we go ahead and go through some housekeeping? Uh, we do have a Slack channel, and I don't know if we mentioned it, but we did surpass 1,300 members. We did, like a week or two ago, something like that. A lot of people out there.

Good stuff. If you want to be one of those people as a part of the community, go to colorado-security.com and click our Join Slack button, and you'll get out there. We also have a mailing list. You can find that at the bottom of that webpage as well. Sign up for that mailing list, get the show notes emailed to you every week in your email as soon as the podcast is out.

And since you do want to help us meet new people, do go ahead and rate us and subscribe on your favorite podcast listening apps. That'll help us find new listeners. Of course, you could tell a friend if you want to tell some people in the real world versus the virtual world, and maybe those folks would listen to us as well. And you can also tell them after they listen for a while and realize how great it is that they should support us through Patreon. To help us cover the costs for running the podcast and Colorado Equal Security.

They can also find a link to Patreon on the Colorado Equal Security web page. And if there's one more thing we'd love your help with, you know, we've talked about interview volunteers for a while. We actually have a new volunteer doing an interview this week. Big thanks to John Hubbard for stepping up to do this. Of course, if you're interested in helping get involved with the podcast, if you want to be famous by asking someone else questions, we'd love to have you do some guest interviews for us.

This will be 3 weeks in a row with an interview. So we're getting some momentum. We're getting back on a roll, Robb. Yeah, I like it. Also, we do have— we mentioned it last week that we had a new patron sign up and we did get confirmation that we can talk about that patron on the show.

So congratulations and thanks to Caleb Augustine from Splunk for supporting us through Patreon. You know, at the $10 a month range, he not only gets a shout out on the show, he also gets a cool Colorado Equal Security t-shirt, which is pretty sweet. Robb, does that t-shirt have the new logo on it? It does have the new logo. We are not pawning off the old t-shirts on our Patreons.

Wow, that's awesome. So if you want a new t-shirt with a new logo, you could sign up at that level and get one yourself. And if you want an old t-shirt with the old logo, I have some of those I could hand off to you as well. Yeah, I've got a few also. Those are a little easier to get rid of.

It would help if you are, you know, really small or potentially really large because the middle sizes are mostly gone. All right, let's go ahead and jump over to the news. And the news that you alluded to earlier, there is a brand new baby rhino that was born at the Denver Zoo. I guess this is a pretty big deal. It is a pretty big deal.

This is— it's good news for the Denver Zoo. This is the first greater one-horned rhino that has been born at the Denver Zoo. And I can't remember, was it in captivity at all? But it's the first one that's been born in a long time. Yeah.

Well, the first one born at that zoo. I don't— I didn't hear that it was the first one ever born, but it was born last or September, excuse me, February 22nd. That's a Saturday. It was born to the mother Tenser or Tensing, excuse me. And apparently there was, they bought this rhino for the sake of matchmaking with a male rhino they had there at the zoo.

Yeah. So this rhino was brought in not too long ago. And however, Ohio, like yourself, from Ohio, brought to Colorado to breed. This sounds very familiar.

The difference though, is that this pair did not work out. So instead of successful mating, they had to resort to artificial insemination, which after many tries finally worked. Yeah. So the— this is a long pregnancy, one of the longest. It was a 480-day pregnancy.

The healthy baby, only 100 pounds, a little, little cute thing right there at 100 pounds right off the bat. It'll be what they said, about 8 weeks, I think, before we can actually see this, this new guy at the zoo. And for all that were wondering, there is no name yet, but I'm sure that will be coming soon. Next, in case you hadn't noticed, Denver is— the traffic here has gotten worse and we are home to one of the 3 or 2, 3 of the worst traffic bottlenecks in the US. Yeah, we've been at the top of a lot of lists and this one's not my favorite one to be on the top of.

We're not actually at the top though. So we— our worst bottleneck made it as the 15th worst bottleneck in the US. And this is The Central I-70 project, and I assume that this means over kind of by the Purina plant, right, where they're doing all that work between DIA? Yeah, I believe so. So that is the 15th worst bottleneck in the US.

The 21st worst is the junction of I-70 and I-25. It's kind of silly to me that you separate those 2 things because they're right next to each other. But hey, I didn't make the list. And finally, I-25 and 76 is the 68th worst. And in my mind, all 3 of those are close enough to each other that it kind of feels like the same bottleneck.

Right. And I guess the good news is for me, I don't drive through any of those bottlenecks on my way to and from work. Yeah, that is great. In case you were wondering, the number 1 bottleneck is the intersection of I-95 and State Route 4 in Fort Lee, New Jersey. I hate that intersection.

I know it's the worst. Yeah. But, you know, the 2nd worst is also in Atlanta, I-285 and 85. I hate that one, too. So no one likes traffic.

Good. We're not at number 1 there, but bad that we're on the list. All right. Well, in the ongoing saga of I can't believe we're living in the future, this next story comes to us here from Colorado with a local company that makes smart pills for wireless drug delivery. And when I first read this, I was like, oh, this is some kind of like they're going to— you're going to sign up to have them deliver the drugs automatically.

No, no, no. This is way more high-tech and way cooler than this. So I don't know if you want to go through it. I'm excited to talk about this though. Yeah.

So this is a pill that contains a microprocessor and the ability to have the medicine released at certain times. So a lot of times when you take medicine, it goes through your digestive system, and it's broken down, and it may not still be intact when it reaches the place in your body where it needs to be, be used. So the idea here is that you know, you can swallow this pill, it can, you can kind of track it throughout your body. And then when it's a place where, where it needs to release the medicine, you can trigger it to release the medicine right where it needs to be. So it's like, there's a sensor, you have your smartphone, right?

And it's tracking this as it goes through your body, and it will alert you and you'll like hit the button when it's time to release the medicine. There's a, you know, it's still not all the way automated, but a manual interaction by the, by the patient to make this thing happen. They specifically talk about, was it Crohn's disease? Yeah, Crohn's disease as a place where you need the medicine to get all the way down into your bowels and, you know, through the digestive tract. It's right about at the end.

And usually by then medicine's broken down and this needs to get all the way there. So that's a great example of one where you wait until it's almost left your body again before you hit a button, the medicine's released and you get it right to where it needs to be. Pretty awesome. It is a pretty awesome invention. I think as we go forward, these things will get smaller and smaller as well.

It looked like it was, you know, if you have a problem swallowing pills. This didn't look like it was a small pill. Like a horse pill, right? It was pretty big size. So it's a pretty decent size.

Also, in the mobile app, I sure hope that the picture is the same picture that they use for the game Operation as it tracks the pill through your body. If it's not, I'm gonna be really disappointed. Really disappointing. So a couple things. This— the company here in, in town is called, I think it's Veloci or Velos, Veloci Corp. And the product is called the Smart Tab.

So if you run into either of those, say, hey, good job, we're rooting for them. This would be a pretty cool thing to see actually get to market and be successful. Yeah, cool. Very cool. Next, Google made an announcement this week that they plan to grow in the United States and invest $10 million, including— $10 billion.

Did I say million? $10 billion. They lost $10 million since we started talking about this. $10 billion in the US, including offices in Colorado. Yeah.

So pretty awesome. They say, you know, they have $10 billion to invest across 11 different places in the US. Colorado specifically made the list. And they're talking about the office in Boulder where they're going to double down on the number of staff and, and look at this as a strategic office for them going forward. Yeah.

In the press release, there weren't a whole lot of specifics about what they were going to do here, but they did note that they have the capacity to double their workforce at that office. So this is great news if you're someone who's looking for a job or like to, you know, move between jobs. Not so great if you're someone looking to hire people. Right. As is this next article.

Denver and Boulder are both named among the hottest US job markets. Denver was ranked number 3 among metro areas with more than 1 million people, and Boulder took the top spot for metro areas with under 1 million people. Also on the list, we had Greeley and Fort Collins in the top 10. Greely was 6th, Fort Collins was number 7, and Colorado Springs came in number 24. So we are shooting all over the place on those top lists.

Yeah. So really it just sounds like if you want to hire somebody, it's going to have to be in Grand Junction or, I don't know, way out towards Kansas or something like that. Yeah. So the way they did these rankings was based on unemployment rates, how many new jobs there are, wage growth. There were some other factors that I don't know, but Really, we did really well on all these lists.

Our dreaded nemesis did come in above us on the big metro areas. Austin was actually the number 1 area for big metro areas. And number 2 was Nashville. Yeah, it was a little bit surprising to me. Yeah, Nashville, I know, has been growing.

It's been an up-and-coming hotspot. But for this, I would have— yeah, I would have thought it was something else. But yeah, congrats to all them. And congrats to us. And to us.

Next, ShapeShift, which is a cryptocurrency exchange company, has hired a former Apple and PayPal exec to become the world's greatest crypto company. Yeah. So this, this article is mostly about their new hire, which is, of course, great and interesting. And I'm happy to hear more about this executive. But what really struck out to me is we actually learned about a guy who I think we've talked about before on the show, Erik Voorhees.

No relations to Jason Voorhees, I expect. No, I'm sure that they're cousins. Yeah. Eric Voorhees was, was actually one of Governor Hickenlooper's blockchain council members who had been helping to try and pass legislation around blockchain in the state of Colorado. So this is a company that he founded, ShapeShift.

For some strange reason, they're headquartered in Switzerland, right? Yes. But, but he's, you know, he's a Colorado guy and a lot of ties back here and has hired this their biggest office is in Colorado, and they've hired this new executive whose name is Lisa Loud as the, as the new leader to really help drive this cryptocurrency exchange to new heights. Yeah. And it sounds like she has some, some great experience at Apple and PayPal and a number of other places.

So good luck to them. And hopefully this is a success. All right. Next story is a follow-up from one I think it was 2 weeks ago where we had the Tech Trailblazers nominations and we talked about the fact that Cody Cornell had made the list for, for male CEOs. I think there was another company that made the finalist list too.

Yeah, the— it was an AI company here locally. I forget the name. Well, anyway, the follow-up here is that Cody actually won the Male CEO of the Year for Tech Trailblazers. So Cody is the CEO of Swimlane, a friend of the show. We really appreciate all his support.

He has been on the show a couple of times. Anyway, congratulations to Cody. Well deserved. It's great to see local security companies, really well-built local product company like that doing well and getting recognized. Yeah, congrats Cody.

Also worth noting that if you come and see us and get one of our new stickers, those are paid for by Swimlane. So congrats to Cody. Thanks to them for for all the support for us over the years. Awesome. We have a news story this week from I don't know did they change their name from Route Nine B?

I don't know. I've seen that a couple times now. Feels like consistently they're saying R Nine B instead of Route Nine B on their press releases. Anyway, we're gonna call it Route Nine B until I know differently. Route Nine B has appointed a new member to their board of directors, and it's a.

Former Verizon executive John G. Stratton, who not only worked at Verizon, also has some experience in the White House. Yeah. So he had multiple roles at Verizon, including being president of global operations, which seems like a pretty big deal since he had P&L for Verizon's $120 billion network. Yeah, I've never managed that much. I can't say I have managed that much either.

And he was also named to President Obama's National Security Telecommunications Advisory Committee. Back in 2012. So obviously he's going to bring some great relationships. And I would assume for Route 9B, a lot of maturity helping them get to that next level as they're looking to grow and become a larger player. Yep.

Next, there was an interview done by Authority Magazine of Desiree Robinson of Survey Gizmo talking about inspirational women in STEM and technology. So Desiree is a friend of ours, a friend of the show. She's the Director of Governance and Security. I don't know if I got her title exactly right. I think it's about right.

Survey Gizmo now. Previously, she was the CISO at NREL. She's, you know, been someone who we've run into quite a few times in the past. Really cool to get to see her profile, see how she got into security really just through hustle and finding her way in, look like maybe 15 years or so ago, and spent the last, you know, decade and a half really building up a good security career and a you know, as this, this article goes into a primarily male-dominated field and really differentiated herself. Yeah, definitely.

This is a pretty in-depth interview. It is, you know, goes on for a fairly long time. And she gives some, some great advice in there. So I would check that out for, for those looking to get into STEM and move ahead in their career. I think especially if there's any women who are, you know, just looking for someone else who's already done this.

Desiree talks a lot about what it's been like to be a woman in STEM. And while I haven't experienced most of what she wrote about, I suspect that it'd be really relevant for those who are, you know, who are going through it themselves. Yep. And then our final news story this week. Robb, do you know what a security twin is?

I do know what a security twin is because I read this blog post. Oh, hey. This is a blog post from Ping Identity from Babur Amin over on our CTO team. And it starts off. It's really an IoT blog post.

We'll start off by saying that. There's this concept in IoT that every physical device that's gonna be on the internet has a digital twin. So, you know, your security camera, the fact that it's online, that online presence is called its digital twin, right? Makes sense? And it's gonna be used by different people for different purposes.

It's gonna be used by the manufacturer to figure out, you know, reliability and Um, you know, and understanding how customers use it. It might be used by the customer to do configurations and to actually like check what's happening on their camera, um, to do patching and all these maintenance. The, the twin has different purposes based on, on, on who the user is. And the security twin is, well, how are you gonna secure these things, right? And so you start to figure out what is the kind of information that you need in order to secure it.

Um, they, they talk about things like, uh, firmware patches, configuration updates, maintenance information as being relevant to this and the, the need that, you know, once you start to have a repository to put that data in, you can start doing intelligence and actually secure your IoT devices. Robb, that was a great summary. I'm not even gonna explain any more about it. Well done. Let's just keep it moving.

Let's do it. Just keep it moving. Uh, so with that, let's jump over to the Slack Message of the Week. Thanks to Andre Gaeta, who has been supporting us with the Slack Message of the Week for an awfully long time now. Um, he out of his own pocket has been paying for this award.

Um, if you get the Slack message of the week, uh, then you receive $25 in credit towards something from the Colorado Equal Security store. Um, and the way that you can get this is just by using the Slack channel and saying something interesting. If you say something interesting, there's a possibility that you will get picked for the Slack message of the week. Yeah. Uh, and, and of course this week we have, we have someone to recognize.

It's, it's Rishi Malik. Um, Rishi shared a story this week that I actually saw somewhere after she did it, but it was really interesting. It was about a talk that happened at RSA conference this week by John Strand of Black Hills Information Security talking about a pen test that Black Hills was engaged to do at a prison. And they were thinking about, well, how are we going to do this pen test? And they looked around the company to see who would be the right one to go in.

And, and the CFO of the company at Black Hills had a career in health, basically food, right? Like food service, food services, and said, I'd like to do it. And it just so happens that this CFO who had never done a pen test before was John Strand's mother. Yeah, it sounded like she had been interested in, you know, participating in one of these at some point, and this just happened to be the place. They talk about it in the article, but, you know, not your normal place where you would start out in pen testing.

This is a, you know, fairly high stress sort of first pen test doing a a physical part. Um, I guess we should stress that this is, this was a physical part of the pen test as opposed to her sitting at a keyboard and, and doing some of the pen tests. But she, but she did the other part too, right? By delivering USB keys into the, into the laptops to, so they could get access to do the digital part. Correct.

And I think, you know, what made this such a genius time to do it is number one, her background in, in food services where she was able to go in and pose as a health inspector cuz she'd been on the receiving end of many health inspections. And she looked, I don't know, like a middle-aged woman, very unlikely person to be a criminal trying to break into a prison. It looked like for sure. One of the other things I thought was interesting that, that John said was that not only was the pen test successful and they were— the prison was able to make changes because of it, but that the recommendations that his mom made to them in the fake health inspection probably made them improve, probably made their food service more sanitary as well. So that's pretty good.

Anyway, I know we just summarized the article. I still think it's worth a read. It was a well-written article, really interesting story, and the kind of thing that you can share with people who are not in security who will probably get them to perk up and say, oh, they broke into a prison. It was an interesting story. Yeah.

All right. So we will get Andre and Rishi together and get that $25 credit for something from the Colorado Equal Security Store. All right, let's jump over to events. Remind you on our website, we do have a calendar of events. You can go see what's going on.

There's a lot of stuff going on here this year. We'll talk about the next couple of weeks of events. But before we do, I don't think we've really talked about the Rocky Mountain Information Security Conference yet, have we? Yeah. So the, the call for papers or presentations recently closed.

And so we've made some selections around that. People should be getting notifications around being accepted to Rocky Mountain Information Security Conference to speak. Um, uh, sponsorship is well underway. We're, we're trying to get that going. Um, and then, uh, you know, we've, we're pretty much set with our keynote lineup as well.

And I think we're going to start announcing those, uh, here over the next few weeks. And I think maybe, do we want to talk about one right now? Sure. Just do it. So I know our opening keynote on the Wednesday, the, the first like full day of tracks is going to be Gene Spafford and, and Alex, you and I, we've been doing this for enough years that We remember bringing Gene in, what was it, 5 years ago maybe?

And he did a fantastic job speaking, one of the best talks I've got to listen to. And we're excited to have him back. Yeah, I mean, he's a real luminary in the field. He, he has been around an awfully long time. He was one of the people that discovered and investigated the Morris worm.

Did you know that? I did know that. And just a great person and a wonderful speaker. And we look forward to having him at the conference again this year. And tune in again next week and we'll talk about another keynote speaker.

Sweet. So let's jump into the upcoming short-term events. First, on March 3rd, the CTA is doing their Tech Day at the Colorado Capitol. On the 4th, SecureSet is doing a capture the flag for all levels. On the 5th, Splunk is doing one of their First Thursdays at Topgolf.

And then there's a couple other things on the 5th as well. Elastic is doing one of their Elastic Brews events, happy hour with Elastic. And finally, the most important thing on the 5th is SnowFROC. So if you haven't signed up for SnowFROC, you better go do that. Yeah, SnowFROC is a great conference, full day, lots of, lots of great learning.

On the 6th in Colorado Springs, they're having one of their Cybersecurity First Fridays events. On the 7th, ISSA Colorado Springs is doing their Security+ exam prep. This is the first of 3 for Security+. So if you want to do it, you better show up that first day. On the 10th, SecureSet is doing a Creating a Virtual Lab event.

I love when they do stuff like this. It's so practical, so useful for those who are looking to get into security. If you know someone who's been kind of batting it around, that'd be a great event for them to attend. On the 11th, ASUS is doing a Pandora's Box Emergency Preparedness Considerations. With all of the COVID-19 coronavirus stuff going on, Hey, maybe that's something that you should go check out.

It might be the most crowded event they've ever done. On the 12th, ISACA Denver is doing their March meeting. Also on the 12th, Northern Colorado ISSA is doing their March chapter meeting. And then the 12th through the 14th is the— is it WISIS? WISIS, the Women in Cybersecurity Conference is here in Denver.

And that one, it's actually out at the Gaylord by the airport. This is gonna be a great event. I know they're bringing in folks from outside of Colorado as well. I hope folks can make it. Yeah, this is a national conference.

It just happens to be in Colorado this year. So, uh, you definitely should check that one out. And then finally for this week, CSA on the 13th is doing a CCSK+ class. All right, let's go ahead and jump over into jobs. We do have a few jobs at Ping right now.

Honestly, I've got all kinds of jobs. If you're interested in working in security and you want to come to Ping, send me a note, go out to the website, look at the listings. Uh, we, there's a likelihood that we have a good fit for you if, uh, you know, if you've got skills in GRC, application security, or infrastructure security. Bank of America is hiring for lots of positions, including an identity data architect for zero trust. Zero trust.

That's kind of exciting. The University of Denver, DU, is hiring an information security engineer 2. Not 2 of them, just level 2. Maybe 2. Who knows? Wells Fargo is looking for a compliance officer.

Visa is hiring a director of cybersecurity engineering perimeter operations. Ooh. BP is hiring a security architect. Aegon Netherland is hiring an assistant general counsel focused on cybersecurity. And I think this is actually related to Transamerica.

Oh, okay. Flatiron School is looking for a cybersecurity lab architect and instructional designer. Kind of fun, right? So after you go to that, the class from SecureSet on creating a virtual lab, you can go apply for this job. If that's the case, that's a really good SecureSet session.

Finally this week, Snooze, my wife's favorite breakfast place, is hiring a VP of IT. Nice. So if you want to get some, I assume, cheap or free breakfasts, this is probably the place to go. I think that is it. All right.

Well, Alex, that is it for the news this week, right? I think we got everything. So next we have an interview with James Westbrook. We talked about James on the show a few weeks ago as he joined as a patron. And then John Hubbard had just so happened to schedule a meeting to learn more about him.

So we're going to get to hear more about James. Nice. I look forward to hearing it. All right, well, that's it. Everyone enjoy March and we'll talk to you next week.

Thanks, Robb. This is Mike Benjamin, a big fan of Colorado security. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.

Hey, Colorado Equals Security community. This is John Hubbard. I'm sitting down with James Westbrook. James, how's it going today? Going well.

How are you? Fine, thanks. So we were talking before we hit record, sounds like you just got back from a big snowboard trip. Yep, so I just about a month ago got back from Jackson Hole, just went up to snowboard for about a week. Just drove up there with a couple of friends and then stayed across the border in Idaho and just hit the slopes for a few days.

How was the snow? Did you have some powder? Yeah, we had just a little bit of powder. It was one of the snowier seasons that Jackson has had and You know, by the time we got to the top of the tram, uh, coming down, the snowboard was like halfway up my— or the snow was about halfway up my thighs. So I've never quite seen anything like that, but pretty good experience for sure.

I've heard the Grand Tetons are steeper than the Rockies. It was, yeah, it was definitely much steeper. Definitely learned a lot about my, uh, snowboarding skills while I was out there, uh, and the lack thereof, but Yeah, great experience, tons of snow, and every time you fell it was just a nice big powder bowl to catch you there anyway. So I've been there twice in the summer but never in the winter. Yeah, now you're making me want to go in the winter.

It's definitely worth the trip. It's, it's a beautiful place up there too. The sights were incredible. So did you stay inbounds the whole time? You didn't do any backcountry?

I did not do any backcountry. Definitely a bit above my skill set right now, and They tell you when you get up there, if you don't know, don't go. So I didn't go. Jackson Hole is not exactly a beginner mountain. No, definitely not.

It is one of the more intense ones probably in all of North America. So, okay. And are you a big outdoor enthusiast? You do a lot of things in the great outdoors here in Colorado? Yep, definitely enjoy the, uh, great outdoors we have available here.

So, uh, you know, starting to look forward to it getting a little warmer out here so I can get back to some camping, kayaking, Hiking, stuff like that, but kind of try to take advantage of it all. Any mountain biking? Not so much mountain biking. I have a mountain bike that desperately needs a tune that I've been putting off for about 3 years now, so maybe this will be the year, but we'll see. When you say kayaking, is that whitewater or— No, not just yet.

So I've kind of just got a, uh, it's much more for me more like lakes. So I've just got a pretty basic kayak that I just kind of go sit out on the lake and do a few laps and enjoy the view. So a little bit less rivers, definitely something I want to get into more though. It's a little scarier when you start going downhill. Yeah, for sure.

The water's taking you, you're not going, you're not going where you think you want to. So yeah, yeah, it's definitely a bit more of a skill set you have to have for that one. Well, the good thing is in Colorado there's, there's always a season, you know, you can do winter sports, you can do spring, you can do summer. Yep, there's always something to do, no doubt. Lots of options.

All right, well, let's, uh, dive into your background a little bit. So, uh, did you grow up in Colorado then doing some of those outdoor activities? I did, yep. So I'm born and raised here, grew up in Westminster. Um, you know, didn't do as much of the outdoor activity growing up just because my parents weren't as big into it, but as soon as I got a car, I was out there all the time.

So I did grow up here though, actually went to high school right up the street from where we're recording here. And yep, so you're a native, you're one of the few rare commodities these days. Yeah, yep, been here the whole life, so hope to keep it that way. Okay, and when did you get interested in technology? I definitely got interested in tech from a pretty young age, definitely played a lot of computer games growing up, just like Age of Empires and just online browser games even.

So spent quite a bit of time on computers just because of that and really started finding a passion in it in high school when I started doing some technology classes and realizing that there was much more hiding beneath the surface of just the game that I had running there. So your high school had technology classes. Was that programming or, you know, STEM type stuff where you do robotics or what exactly was that? So it was much more programming facing and actually I was one of the only ones. I tried like a Java course and got as far through that as I could, but then even just a lot of like simple stuff like just Office Suite and stuff like that.

So they kind of had a pretty good wide range for a small high school of tech classes available. Okay. And that's kind of where I really started to dive into the interest. Okay, did you have a computer at home that you could play around with? Yeah, so the other thing that really kick-started the passion was I had friends who were building computers so that they could play, you know, the newest games and have that— putting in video cards and overclocking.

Yeah, exactly. So finally I saved enough money from my fast food job and threw about $800 into my first computer and Definitely started diving a lot deeper after that because I really had the processing power to start doing some more fun stuff. Kind of discovered the concept of virtual machines around that time too and had my mind blown that you could run an OS on top of your OS without all the complicated, you know, partitioning your drive and stuff that I was worried I would mess my gaming computer up with. So Yeah, definitely started getting into some home labbing a little bit with that and really took it off from there. Yeah, so you're able to experiment a little bit.

And then from high school you went to Front Range? Yep, so I took a semester off after that just because I still didn't quite know what I wanted to do. I kept hearing, you know, cybersecurity is a newer field that needs so many more people, and I didn't quite know what that meant yet, so I took another 6 months, you know, just worked at a Costco and realized, oh, this is going to be the rest of my life if I don't do something. So that wasn't your calling? That was not my calling.

Nothing wrong with Costco, they treat their people well, but it was not for me forever. So, you know, used that as a reason to get back to school and try to get into something that I knew I'd have a little more passion in. So when you went back to school, did you know this is what I want to do, or were you taking a variety of courses to find out? I kind of came in here with a pretty direct goal of trying to get into security. So, and why was that calling your name?

You know, it just sounded so interesting, honestly. Like, the term cybersecurity sounded great, but also I kept reading about, you know, all of these personal privacy issues that were popping up because of the internet and all of the groups trying to fight for those rights to continue, and also just like all of the companies that were getting attacked and broken into and everything else. So even though I didn't quite know what the profession entailed yet, it was very obvious that the world was changing in a way that really needed people with those skill sets. And then I actually came here to Front Range and sat down with a counselor, and they already had established a 2-year cybersecurity program for an associate's degree. So As soon as I saw that, I was like, well, I know I don't love the school thing.

I had kind of already had the thought that I didn't know if I wanted to do a 4-year degree, so seeing the opportunity right in front of me of having an associate's in cybersecurity, I decided that would be worth the risk and went that route. Okay, is that program available at all Front Range campuses? I believe the last time I checked it was mostly in the Westminster and the Larimer campuses, but they were also very good about providing online classes and trying to make those computer classes in a reasonable time window. Like, those were usually evening classes rather than middle of the day, so they're very flexible about trying to make sure that those classes were available to people. And were you a full-time student or were you working a job as well?

So I was full-time and also still working a job as well. I was just paying it off as I went since it was so much more affordable, right? And I was fortunate enough to be able to keep living at home during that time as well. So all of those things made that possible.

And then just kind of went through the program, took 2 years, and then finished in December of 2018. Okay, congratulations. Thank you. What was some of your coursework? What did you learn?

You know, was it really academic and theoretical, or was it, you know, hands-on keyboard type stuff? It was very much more the hands-on keyboard, I would say they did a good job of getting you kind of the intro to programming, networking systems, stuff like that, kind of giving you that baseline knowledge. And then from there, they did get into more advanced classes that talked more about, okay, this is how the networks actually work. Here are some labs that we can put together to actually demonstrate that, you know, hooking up 4 routers all across the room, stepping over the cords, setting up the whole thing. So it was very— I would say it was much more hands-on rather than that theoretical knowledge.

Right, right. And the focus on networking obviously is beneficial because networking and security are so close together. Yeah, yeah. Any sort of attack is going to go across the network, right? More than likely, for sure.

So yeah, they did a good job of giving you the baseline of all of it and then kind of letting you take off on the parts that really interested you from there. Okay, so after 2 years, December 2018, you stepped out into the real world. Yes, correct. You had a little bit of experience under your belt at that point, right? Yeah, so I had done one year with a local small business who was selling LED lighting, doing some automation systems for those.

So got some cool experience with like some IoT technologies just because that's big in that space, but also just basic network and server administration. So I did that for about a year and that went through my last year that I was at school. Okay, so kind of got the hands-on as I was getting the hands-on knowledge from that as well. And then the other thing I did before I finished school that I thought ended up being really beneficial was that I actually studied for and passed the Security+ exam. Okay.

The CompTIA exam. Yep, exactly. So that definitely, you know, between the year of experience, the associate's degree focusing in cybersecurity, and then that certification kind of set me up for success to get, you know, big real first tech job where that was going to be my focus. Okay, so did you know what you were doing as you walked across the graduation stage? Did you participate in a job fair, career fair, or anything like that?

No, no, I did not actually. So, you know, probably would have helped, and I bet some of those resources are available through Front Range, but I kind of just took it on myself and tried to put together a resume and just started looking for junior sysadmin, junior network admin, those types of positions. And just kind of started throwing in a resume whenever those popped up. Was that challenging? It was challenging.

You know, there, there aren't many of those jobs that really come across because usually when you're hiring someone, you have a need that you need to fill and you need that help probably right away. So you need somebody to hit the ground running. Exactly. So those junior positions are a lot harder to find because companies have to be willing to take that person knowing that they're probably not going to be able to be a full-on day one contributor and kind of allow them the space to grow and turn into a real great contributor that can help their team. Yeah, so difficult for sure, but I got pretty lucky, I would say.

So there was one posting that I was able to actually just call up the recruiter. I just called the main line, was able to get transferred over. Really? Yeah. Yeah, small office for sure.

So got in touch with him, was able to kick off a good conversation, and then was able to go through and actually get the job there. Okay, that's kind of the old-school approach. Now everyone talks about HR filters and artificial intelligence reading your resume. Yeah, for sure. It's a lot harder these days, I would say.

It's nice to know that somewhere out there you can still get the hiring manager on the phone. Yeah. And that was at Flexential? Yes, that was with Flexential, and it was really who hired me was the remnants of Applied Trust, which was the Boulder security startup, and they got acquired by BioWest, who then got acquired by another company, and all of them came together to form FlexCentral. Okay, so I worked with that legacy Applied Trust team in the Boulder office.

Yes, correct. Okay, not the BioWest headquarters or anything, right? Yeah, headquarters. No, none of them. Stayed out of the data centers, luckily.

Okay, and you started there, you had a little bit of experience under your belt. What did they have you doing when you started? So when I first started, I kind of hit the ground running with a little bit of Linux work because they did a lot of DevOps, which was a whole, you know, that was a term I had not even heard until I got in the workplace. So that was a whole new world to me. So dived into a little bit of that, tried to get some experience.

The majority of my time though was really spent on a specific product that we had built out. It was a larger-scale VDI environment that we were running on an internal cloud, and there was a single customer running on that. So I spent most of my time at first working on that, doing their day-to-day administration and helping them implement changes to increase the production and usability of that environment. Was it Citrix or VMware? It was VMware Horizon.

Horizon, yeah, yeah, yeah. Interesting product. Okay, all right, so first exposure to VDI. Yes, you know, golden images and all that kind of stuff. Yep, definitely a little bit of, you know, not quite desktop support, but definitely still trying to work with users on the issues that they were dealing with, get to the root cause of why those were happening, and document solutions for those and if possible, just permanently get rid of those issues.

Okay, and you were serving internal FlexCentral customers or external? It was an external customer, so it was, um, you know, we hosted it on their behalf and just had a monthly fee that they paid for us to take care of that. And if they submitted a ticket or needed something updated, yeah, take care of that. Exactly. Okay, so you're doing that for a while and then moved into new responsibilities?

Yeah, so I, you know, kept working on that a little bit, um, but as my career progressed there and as our responsibilities as a team progressed, um, we were asked to really step into the cloud migration space, which was something that had been a challenge for Flexential before. Customers had a hard time getting into the data center when they had contracted for a cloud environment So we were able to step in and really help them mature that program and make it a lot easier for customers to get into the cloud that they were paying for. Okay, so having a little more transparency within their private cloud that lived inside FlexCentral. Yeah. Okay, and was that heavily VMware?

It was heavily VMware for sure. The tool that we actually used mostly for replication was actually Zerto, which is a disaster recovery tool. Um, because we also did disaster recovery as a service over there, and I contributed quite a bit to, uh, those types of projects as well. So Xerto was kind of the main tool that we used and had a great partnership with. Have very high opinion of the team at Xerto for sure.

Um, good tool, but that was mostly what we used and tried to help customers get in as quickly and easily as possible. Is Zerto multi-cloud? So could you go to VMware, to Azure, you know, AWS? Yeah, so that is something that they have put quite a bit of energy into. I never got much of an opportunity to test how it works to Azure or AWS.

I know that we had proof of concepted a couple of things, and it looked like it worked pretty well, but it is a multi-cloud tool for sure— Azure and AWS— and if they don't already, I imagine they're working on As well. So everyone should be doing DR tests, right? You know, quarterly, make sure everything fails over as expected. Did you ever get that 3 AM phone call that said, hey, the disaster's happened? Nope, luckily I avoided those.

So we did have a frontline support team who, you know, they were staffed 24/7, and luckily those individuals were nice enough to take the overnight key for us if those things did pop up. You know, I occasionally got the phone call that something was down and they didn't quite know what was going on, but for the most part they did a good job of facilitating that stuff regardless of the time of night. That's good, that's good. No one wants to see their data center go up in flames. Yeah, exactly.

Okay, so working for DR for the— looks like probably the second half of 2018 and then got a little bit more into the security side of things? Yeah, for sure. So kind of sprinkled all the way through there in the 2 years that I spent at FlexCentral, I did get some opportunities to do some internal cloud pen testing. I got to do a lot of customer-facing security assessments. Okay.

Um, so did definitely get some opportunities to get some of that security work, even as, you know, even as fun as like, uh, we did incident response as well. So occasionally a customer would say something weird started coming through on this laptop, and, you know, I'd go grab it and help actually start the processing of all that. So fun opportunities all around. They had a good security program and were able to do a lot for different types of customers across lots of different industries in a pretty short amount of time. So a customer would say, here's our environment within FlexCentral, or here's our complete environment everywhere for a security assessment?

So we had both. We, in fact, most of the ones I participated in were not even FlexCentral data center companies. Um, they were mostly, they were mostly just, uh, running things on-prem and needed somebody to come by, uh, because they realized that compliance was a thing and they needed to start dealing with that, uh, before they got hit with some penalties. So do you travel a little bit? Yes, I got a lot of travel opportunities.

I think I went on maybe 5 or 6 different engagements across different states, so had some fun getting to travel for those opportunities for sure. Any physical pen tests? I did actually do a physical pen test, uh, up in Boulder. Uh, it was the first one I did, and I don't know that I got the opportunity to do another one, but, uh, I was able to tailgate somebody through the door and just kept walking. They're like, hey, do you have a badge?

I'm like, Oh yeah, but I forgot it. I really got to get to this meeting though. Just went on my way and was able to find some unlocked workstations and stuff like that. Uh, we were in front of the unlocked computer. Yeah, exactly.

Go shake the guy's hand who had told us that, you know, started the engagement with us, who was not happy to see me, but you know, that's, that's what they paid us for. So yeah, we didn't take those engagements as far— well, not that one anyways— as far as, you know, trying to actually get into systems or anything, but did test their physical controls and were able to say, sorry, but we were able to get in, here's what happened. So yeah, lots of good opportunities all around. And then on the digital side, were you, you know, using Metasploit or tools like that to try to get inside their network and get into Active Directory? Yeah, yeah, so we did quite a bit of that, you know, both for customers and for our internal clouds, just as like continuous improvement improvement in security there.

So we were doing a lot of Active Directory pen testing for sure, using tools like Responder to try to get the hashes and then, you know, pivot across and see where we can get to. The other thing we did quite a bit of was vulnerability scanning to try to help them knock down the number of issues that we were seeing in there and check the services, see if they really were vulnerable, and then do some basic exploitation. Never tried to take anything down, never did any denial of service, anything like that, but tried to contribute to the internal security as much as we could using Nessus. Yeah, Nessus, all kinds of tools like that. Um, mostly Nessus though, just to keep the vulnerabilities right in check.

So on the customer side, I was buying a pen test once and the vendor asked me, hey, if we find something critical that needs to be patched today, what do you want us to do? And I said, oh, I never thought of that before. And I was like, yeah, stop the test, stop the test, call me, we'll figure it out. Thankfully that didn't happen, but did you ever come across anything where you thought, hey, this is really neat, this is bad, this is really, really bad? Yeah, you know, I would say that I personally saw those types of findings more on the security assessments that I did than the pen tests that I participated in.

Like you find a public database or something? Right, yeah, like the worst— I mean, some of the worst ones were like, hey, your internet gateway's external interface has admin password as the credentials, like, and from there they can do whatever they want to your whole network. So yeah, exactly. So we did we did find a few things like that. And, you know, these were, these were companies that IT was kind of a challenge.

Like, you would find 2000— Windows 2003 still running in their environments and stuff like that. So those— I did have a lot of those assessments where it was this customer obviously is very new to the IT world and doesn't understand security. So it was a good opportunity to kind of get to sit down with their leaders and say, you know, you need somebody who can help you with this, or you need to enable your team to work on these things a little bit more, because there are pretty serious issues that go with the vulnerabilities and, you know, default credentials and all the other findings that we have. Right. And did you find a successful approach to translate that technical language into the language that a business leader might understand, right?

Because they may not understand EternalBlue and RDP vulnerability, right? Some of the terms that might show up in a vulnerability report. Yeah, so we did work pretty hard to really, you know, add that value as the consultants to make sure that that was the part that they understood. Because like you said, they might not understand the technical terms that we speak in day to day, but they're the ones who have to make the decision to hire somebody or give their team the freedom to work on those things rather than other IT projects. So that was something we did work hard on.

As far as approaches, you know, I've always found that business leaders speak in terms of financial impact and business impact and stuff like that. So we tried really hard to focus on that and make it clear that you don't need to understand the actual details of this report. That's what your IT team is for, and they can ingest that. What you do need to understand is that your team probably needs help to solve these problems. So, and you need to do something about it, right?

Yes, you are responsible for providing them that help so that they can keep your business online and ransomware-free if at all possible. Sure, sure. Yeah, and as the consultant, you don't necessarily have the responsibility to fix it, but you do have the responsibility to inform, like, hey, this is a bad problem that you had. Right, exactly. Yeah, and the other thing we always tried too is that if we had a recurring customer where we were doing assessments with them on a more regular basis, we always tried to establish that baseline too and really help them understand areas that they've improved and maybe areas that they thought they had improved but we're still finding issues in and really kind of help them track that track their improvement over the years or months or whenever they're coming back to us.

Yeah, so you would go back 6 months, 12 months later maybe and do a re-engagement to see what had been fixed or what new findings there were. Yeah, exactly. And hopefully your customers had made progress. Yeah, during that, for the most part, I did see good progress. So they— it seems like they took it seriously.

And, you know, some— you did have the occasional engagement where you you knew from the start somebody was just trying to check their box and they probably weren't going to do much about anything that you told them was wrong in their environment. But luckily that was not the norm. That was definitely the exception on the work that I did. Okay. So that gave me some, some small hope that people are starting to take those things seriously.

Sure. Yeah, because again, you know, you're not the person that's on the hook for making those improvements, right? But you've got to communicate in a way that, hey, this is urgent. Yeah, this puts you at risk. Yeah, puts your whole company at risk.

Absolutely. Okay, um, internally to Flexential, what were you doing? The same sorts of security assessments and pen tests and to improve the internal services there? Yeah, so we did do some of that. Like, we did help them with quite a bit of compliance work just because compliance was another area that the professional services team was strong in.

So we were able to help them with, you know, getting PCI and HIPAA compliance given that they, you know, they wanted customers in that area or in those areas. So of course we had to make sure that those cloud environments were up to par with the expectations that come from those compliance frameworks. So So we did do quite a bit of work helping them mature those processes, and then, yeah, just quite a bit of day-to-day security work, you know, making sure that things are staying patched. We did have another engagement that I didn't contribute to but was very well aware of where a critical Cisco vulnerability had come out that was impacting a lot of the network devices there, They did— we were able to help them get that turned around very quickly, very efficiently with minimum customer impact. So we did get an opportunity to help with a lot of work like that as well.

Internal data center work. Yep. Yeah, and that's not really an area where you can take a downtime window for a reboot or anything like that. Yeah, yeah, luckily they were smart enough to usually have you know, the passive-active firewall setup in front of cloud customers. So they did a very good job of taking those types of things seriously, and when you find big issues like that, it makes it a lot easier to solve those problems.

Okay, jumping back to compliance a little bit, uh, when I hear compliance, I think of the alphabet soup, right, with PCI DSS, GDPR, HIPAA, now there's CCPA. Stocks if you're publicly traded, right? So which one, which one of those do you see being a primary need for customers these days? You know, I think it really depends on which industry you're coming from, but it seems like usually the industry will kind of map you like one-to-one with which one you need, right? Like if you're, if you're a financial provider, you probably— or if you're taking credit card payments, I should say, it has to be PCI.

If you're in the medical industry, you're probably dealing with HIPAA. Um, once you start getting into the government customers, then it's the real alphabet soup where you're having multiple of them. It's— you have FedRAMP, you have all the NIST framework and, you know, publications and everything else. So I think— I don't think necessarily that any one of them is better than the other. I think they all kind of fit a specific need and do their best to kind of, you know, inform people in those industries on what the expectations are for that industry.

Sure. So I'm thinking in terms of Venn diagrams, you know, like if you're one customer and you've got PCI here and you've got GDPR, right, there's some sweet spot in the middle where, yeah, you've got to reach the high watermark, yeah, to make everybody happy, but that can be pretty burdensome. It can be very burdensome, and it's job security for folks like you. Yeah, for sure. No doubt about it.

And, you know, I think there are good things that come from needing to be compliant with stuff, especially when you're a large business dealing with a lot of people's sensitive data. I think there is good use for those frameworks, but definitely always want to be putting back into those too and make sure that we're improving those over time and try to give back to those people who are creating those and make sure that we're all working together to improve it. Sure. Because none of them are perfect either, as everybody knows by now. So it sounds like you had a very broad range there working at Flexential.

Were there parts of the job that you didn't like or you're like, I could probably do without this? Yeah, you know, there were definitely parts that weren't so ideal, like Working with the team that I was on, we did support DevOps customers, and that was an area that I was not as strong in. But we all contributed to an on-call rotation for those customers. So it would be one of those things where, you know, you're getting paged at 2 AM and you don't really know how this technology works. You do the basic troubleshooting that you can, but if it gets anything beyond that, you're kind of you know, grasping for air at that point, trying to figure it out on the fly when you just got woken up.

So didn't love that part as much, but, you know, overall I'm very grateful for that position and the people I worked for there. I definitely was able to glean a ton of knowledge from them and developed good personal relationships with a lot of them as well. Yeah, that's great. Yeah, that's very important. And you were there up until what's like fall?

No, excuse me, January of this year. Yep. Yeah, so right about a month ago was the end of my time there. Okay, and tell me about your new position. So I just accepted a position as— well, I should say I have started a position as a cybersecurity analyst with Nelnet.

Okay, and cybersecurity analyst I think is one of the most generic job titles out there because it could mean 100 different things. Yes, no doubt. So Are you working on a large team right now, small team? I am on a— the analyst that does everything, or do you have a niche? Yeah, so I'm on a smaller team right now.

We're part of a bigger security group that exists for all of the business lines, but I am doing a little bit more work in the compliance space right now. You know, primary stuff is helping customers understand what compliance compliance controls we have in place and making sure that we can prove to them that we are compliant with, you know, whatever frameworks that they expect us to be as a vendor to them. And then also helping out with any compliance issues that might come up from our desire to start pushing some things to the cloud. So what's Nelnet's business model? What industry are they in?

So Nelnet is the biggest service provider— or sorry, the biggest servicer of government direct student loans. So, you know, the Department of Education has an amount of money that they set aside for student loans, but they don't want to service those loans from start to finish, so they call on companies like Nelnet to actually be the customer-facing provider of that and give them help when they, you know, when they want to consolidate loans or when they need more loans or when they have questions, anything else like that. So that is the main business line is the direct loans, but Nelnet has actually diversified quite a bit. So they do consumer loans as well. They're looking at opening a bank.

And then they've even bought, like they've even gone as far out of the financial world as purchasing a fiber optic company in Nebraska who's starting to do some fiber networks and broadband and stuff like that for smaller Nebraska and even a couple of Colorado communities. So very diverse. Very diverse indeed, and I am on a team responsible for helping, you know, all of those different business lines make sure that they're able to keep up with their customers' needs and stay compliant. Yeah, so you're dealing with a lot of PII, right? Names, addresses, Social Security numbers, absolutely, financial history, credit history.

Yeah, all that kind of stuff. Yeah, it's definitely a very wide range of information that we are keeping from customers. But, you know, as far as I can tell so far, I just finished my second week over there, but coming from some businesses that were a little bit smaller, because Nelnet's a pretty large one. Sure. It's been eye-opening to see how well they're handling security at such a large scale.

Yeah, that's great. That's great because I, I certainly have filled out loan applications before, and I'm sure most of our listeners have as well, whether that was for a mortgage or a car loan or a student loan or a credit card application, right? And the thought has crossed my mind, all right, who's going to see this? Where's this data going to live? Once I click submit, it goes off into the ether, right?

Yeah, there's no doubt about it. You are— every time you fill out anything like that, you're trusting somebody with a lot of your personal information, right? And it's not, um, Bob down at the corner bank anymore, right? Right. Huge databases, huge industries around, uh, personal consumer data these days.

Yeah, absolutely. Yeah, and it's been interesting to see too because You know, this is my first foray into being in a financial company and in this industry, so it's been very interesting to see that kind of stuff firsthand compared to, you know, being in a data center company where you hear about these kinds of things and you kind of help customers with it here and there, but this is much more hands-on and it's a pretty exciting opportunity. Okay, you mentioned cloud migration. Is that Nelnet wanting to take its operations to the cloud? Yeah, there's definitely some push for that, you know, for a lot of the same reasons that a lot of other businesses do it, just looking for easier management and, you know, less data center space and stuff like that.

So there's a number of reasons that they are looking at it. Okay, any particular provider or keeping your options open? I think keeping the options open. I haven't gotten to dive too far into it just just yet, so I haven't seen firsthand who they're evaluating, but I know that the public cloud providers are definitely in the mix. Right.

Amazon, Microsoft, and Google, their names are always mentioned when you talk public cloud. So is the software development in-house as well? Is there a software development team that's writing the code that manages these databases there within Elnet? Yeah, so we have— we do have internal development, and really the IT team is much bigger than anything I've worked on in general as well. I think overall there's something like, you know, somewhere around 600 or more just IT employees.

So MillNet definitely does take pride in really trying to build those solutions in-house and manage their own stuff and even provide those types of solutions to other customers. Okay, so you've been there a couple weeks now, still getting oriented and— Yeah, getting into the mix for sure. Drinking from the fire hose. That's one part of a new job is there's all these acronyms and terms that you've got to figure out what people mean when they refer to a certain system or a certain process. Absolutely, yeah, yeah.

As soon as you start dealing with the government-facing systems as well, being a vendor for them, it gets even more complicated very fast. Okay. You know, I'm still waiting on a clearance at the moment, so don't get to see as much of it hands-on just yet, but looking forward to diving into it. Yeah, I mean, we have— with this type of PII that we're managing, they do require a pretty good level of clearance before you're able to see any of it, which is appropriate, I would say, given not only the data but the vast amount of it that they have out there. So working through that process.

Yeah, that surprises me because when I think of government clearance, I think of the defense contractors of the world, Raytheon and Lockheed Martin, and right now some of those folks who work in the defense industry, not necessarily consumer side. Yeah, well, and I can tell you too, when I was, uh, when I was still working with Flexential, we did have another government department that was a customer, and it was a lower level of clearance, but I actually got a clearance for that one as well. So I think it's a lot more common than, you know, maybe people are aware of, but anytime you are working with government systems, there's usually some level of it that goes through a clearance. At least that's been my experience so far. So they're going to track down your 3rd grade teacher.

That's right. Make sure you never said anything anti-American. Yes, that's right. The last question is, uh, have you plotted to overthrow the American government?

I would hope that the answer is no. Yeah, we had a conversation about how if the answer was ever yes, it's either a very poorly timed joke or, you know, the dumbest criminal admission in the history of criminal admissions. Not the best place to admit it, but, you know, you're under oath or something at that point, right? So they could get you for perjury. Yeah, yeah, I suppose that's true too.

Okay, so you've been in the industry several years now. You know, what are some lessons learned if you could go back in time knowing what you know now and sort of preparing yourself for what the real world is like? Is there anything you would tell a version of your younger self? Yeah, I would definitely say, you know, I was able to get as far as I have so far, I think, because I had a lot of customer service jobs before that, which were just, you know, not even tech at all, like fast food and just other service industries where you're dealing with customers who don't think they owe you anything at all, and they don't, but, you know, getting talked to on a much worse level but still having to put on the customer service face. And I think I would never have realized how much of those lessons I learned from jobs earlier in my life would still continue to apply as I went further into IT because working as a consultant, I mean, that one's pretty obvious, right?

You're, you're an expert that a customer has contracted with to help them solve a problem and they expect timely updates. They want to work closely with you throughout the project to make sure that the solution is really going to work well for them. But even when you get into an internal team, you're still serving you know, other people in your business to enable them to do their jobs and do them well without distraction. So definitely, uh, wish I would have appreciated a little more of the work I was doing back then and how much of an impact it would have on my career. Sure, yeah, every job is a service job in some ways, right?

There's always a customer who you want to make sure is happy at the end of the day. Yeah, absolutely. So what are some of those skills? You know, maintaining composure under pressure? Yeah, that kind of stuff.

Yeah, maintain, you know, like if there's an outage, everybody's working together, you're doing your best. If someone's yelling, you just got to do what you can and just give the most accurate update of the current situation and just keep a cool head throughout the whole thing. And the other one I would say is just being communicative day to day, like If something goes wrong, something goes wrong. You can't solve all the world's problems and you're not always going to be perfect no matter what you're doing, but people will appreciate it much more if you just communicate that early and often. Hey, there is a risk to this.

I just want you to know in case it affects deadlines, in case we have to pay, have to have you pay more for this, you know, whatever it is, but things do occasionally go wrong, but if you communicate that, people tend to be much more receptive to it. Sure, sure. As a general rule, business leaders don't like surprises, right? Yeah, exactly. In the 11th hour that something's gone wrong.

Absolutely. Bring it up earlier. Any, uh, tips for delivering bad news, you know, whether it's a bad security assessment or an outage or a new finding, pen test finding, something like that? Yeah, I would definitely say, you know, just Cutting to the point, not beating around the bush, just say what you have to say and being receptive to any commentary that follows. You know, people can get angry when they hear that type of news, giving them the space to kind of, you know, verbally get that out and then kind of get back to the problem solving and how you're going to get to the bottom of it.

I've definitely tried to be more empathetic in those situations and let people have that moment, but then say, okay, we still need to come back and we have a problem to solve. So that's what we can put this energy into and try to actually get to the bottom of this and be done with it for good so that we don't have to keep having these types of conversations. Good, good. And then speaking of learning, have there been any books or learning materials or a mentor, maybe something or somebody that's that's had a big influence or impact? Yeah, I would definitely say all of them.

So, uh, you know, like I said, the team I worked with at FlexCentral was just fantastic. I loved working with them day to day and learned more than I ever could have imagined from them in 2 years. So, you know, getting a mentor and somebody or a team who will really help you grow is— it's critical for sure. It helps a lot. As far as self-studying and things I've done even before I really was in IT, I've definitely learned very well from having a target.

And I think in IT more specifically for me, going for certs has been a very good thing to kind of focus in on and do some studying around that. So I've studied for a lot more certifications than I have actually taken the test for. Just to get the knowledge. Yeah, exactly. Just kind of keep the knowledge increasing and then, you know, try to turn that around and go into a virtual environment and a lab where you can kind of try to build on those things and use them day-to-day effectively.

But in particular, I would say Security+, since I did it while I was still finishing school, you know, it is looked at as more of like the entry-level security cert, but when you're first getting started out, it definitely helped me get a good grip on what the business world's expectations of security were and what kind of controls needed to be in place. So studying for certifications has been very helpful for me. One platform in particular I will call out is Linux Academy. That was something I used while I was at FlexCentral for continuing education.

I got a very good amount of knowledge from that platform. It is a little bit pricey. I think it's a few hundred $100 a year or something like that, but they do have some free materials and I learned a lot from it and it was stuff that was, you know, they give you just enough of the background to be successful and then it's hands-on for the rest of it and it's just kind of an online platform so you're not stuck with the same constraints as you are if you try to go to a school and get into an actual degree program where you have to be there at certain hours during the day. Right, right, more flexibility. Yeah, absolutely.

Is there a certification you have lined up next, something you want to learn or take the test for? Yeah, I'm looking definitely at Offensive Security Certified Practitioner. Yeah, so is that the 24-hour one? Yes, yeah, and they actually just updated all of the study materials and everything for that recently too, so So, you know, I'm in the compliance world right now in this position, and that's something I have enjoyed doing in the past, but I am more of a tinkerer for sure, and that's kind of where my love for tech has always lied. So I expect that's somewhere I'm gonna want to get back into eventually.

Okay, okay, great. So when it comes to career paths, you know, not every path in information security has to lead to the CISO role, when you think about, hey, maybe one day you'd like to do this, or one day I'd like to do that, and maybe pen testing? Yeah, I mean, I think, I think my personal long-term goals probably lie further in like threat hunting or like malware reverse engineering, those types of tasks rather than technical stuff. Yeah, for sure. That's, again, it's something that I love doing and Being on the migrations team at FlexCentral, I was kind of given a leadership role, at least from the technical side on that team, and it was something that was definitely less comfortable for me.

I was glad to get the experience, and I think it was very helpful, but I think I enjoy the hands-on keyboard work a lot more. We'll see. I'm still earlier in my career here too, so there's a possibility that 10 years from now that's not quite gonna be so enjoyable for me anymore. But for right now, definitely still enjoying it. Yeah, that can be a little difficult to get your feet wet in because malware analysis is not really something you can do in your home lab unless you're writing the malware yourself.

Yeah, it's, it's definitely a long-term goal for sure. There's a lot of— I think there's a lot of day-to-day operational knowledge that you need to have to really be successful with something that high up the technical chain, right? Yeah, and it's— my guess is it's also specialized heavily to the operating system you're running. Yeah, like a Linux exploit would look very different than a Windows exploit. Absolutely.

For sure. Yeah, lots of knowledge you need to have for that to really work. So we'll start saving up for SANS courses. That's right. Yeah, so thinking 5 to 10 years out, um, do you think security is going to get any better?

You know, you talked about hearing about breaches when you were getting into cybersecurity. Do you think that's going to stop? Do you think it's going to get worse? Do you think it's going to remain the same? You know, it's, it's hard to really guess, I think, because, you know, being earlier in my career in cybersecurity, I'm working with a little bit more more limited of a, you know, more limited experience to really try to apply that to the trends.

What I can say is that in the years that I've been doing it, it seems like the breaches have gotten worse and they've gotten bigger and they've gotten more frequent. So that's a trend I obviously hope doesn't continue. And I think everybody in our industry is working long hours trying to make sure that doesn't happen, but it's definitely, you know, the technologies are going to keep changing. They're going to keep getting— technology is going to keep getting implemented faster than people can think about the security for it, even though we're trying really hard to get security in front of these types of things. So, you know, I hope things continue to get better and we're all working hard to make sure that happens, but it's going to be hard to know until we see another few years out or just keep going.

But with IoT really starting to come up and a lot of newer technologies, it's going to be hard. So I was having this conversation recently and I'd love to hear your thoughts on it. It seems like every big name that's been associated with a breach is still pretty much around, you know, like Target is still here, Home Depot, Jimmy John's, they've all had breaches. Yeah, they're still here. Uh, Sony is still here, right?

Uh, Equifax, you know, they got off with a slap on the wrist. Absolutely. So do you feel that there's going to be any more accountability in the industry for these companies that don't seem to be batting 100% and keeping their locks in place on their data? You know, I think it's going to be, it's going to be a consequence of a lot of things. Like, we'll see how the election goes.

I think that could play a role in how those things change or not. But I think it's one of those things where until the consumers who are actually having their data breach really start demanding that things change and that these businesses are punished when they were irresponsible with their data, I don't know how much change we're really going to see. And part of that is, you know, trying to help educate the public on these things, trying to educate lawmakers on these things so that maybe they can push through some legislation that will put more boundaries in place on what's acceptable and what's not. I mean, you are seeing some of that already. California passed their privacy law, which I think nothing at the federal level, right?

Exactly. And again, until we really start seeing people demanding it or there being real big individual consequences of not demanding it, I think those things are unfortunately going to continue. Right, right. I'm a big proponent of people voting with their dollars. If you're not happy with how some company didn't protect your data, then vote with your dollars.

But, you know, Equifax, I have no say in whether they hold my data or not. Absolutely. I think that one is one of the more infuriating breaches that has happened because, you know, you can vote with your dollars at Target. You can go to Walmart or some other grocery store if you're not happy with how they do it. Exactly.

But when you've got just that big provider out there and they're just running credit and everything else and nobody really has any say on the fact that their data exists with them, what are you supposed to do? Right. Yeah. And it feels a little, you know, what's the opposite of empowering, right? It makes people feel helpless.

Yeah. What am I supposed to do? Absolutely. Yeah, I think the more of those types of breaches we can prevent, the happier everybody is. Sure, sure.

Okay, we're coming up on time. Is there anything we didn't get to cover that you want to be sure to mention for the community? You know, I think, I think I feel pretty good. All right, okay, okay. Thanks so much for your time, James.

Really appreciate it, and have a good one. Thanks, appreciate it.

More about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes