All episodes

Grant Sturgis, Director of Security Operations at TTEC

Apple Podcasts Spotify SoundCloud

Grant Sturgis, Director of Security Operations at TTEC is our feature guest this week and is interviewed by Jason Jaques. News from OneClock, Ping Identity, IronCore Labs, Optiv, Red Canary, Webroot and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript9356 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 197, week of February— was it 8th? February 8th, I think.

Yeah, that is the date. 2021. Alex, happy anniversary. Yeah, happy anniversary, Robb. Uh, it's been 4 years.

Hard to believe. 4 years. That's, uh, like 4 times as long as I thought I was gonna do this for. Maybe 8 times. Wow.

Uh, so you had confidence in our abilities to pull this off? Yeah. I, and the, this last year has been like a decade long too. So that's true. It's, it's technically more than 4 years cuz 2020 was multiple years.

I think it should count for something else. Uh, so this is the, uh, what is it? The linen, uh, anniversary in the UK? In the UK. Um, if you're here in the US, fruit and flowers.

So I'll, I'll expect a, uh, a fruit bouquet sent to my house, Robb, or something. Yeah. I mean, I assume our listeners will take care of this for us, getting all of the anniversary gifts. So the traditional in the US is fruit and flowers, but the modern is appliances. So if anyone wants to send appliances, Alex, what's your address?

Well, we'll just put it out there and, you know, put it in the show notes and then you can just send something along. Maybe have a, you know, a new oven delivered or something. Love it. I love it. Well, anyway, happy anniversary.

Hopefully we will. Next year we'll have 5 and maybe we'll do something bigger. You know, maybe a, I don't know, a best of or something. We'll see people in person. That's what we'll do for 5 years.

Maybe we'll get Mr. Colorado to come on the show. Sweet. I'm not sure who that is. We'll have a year to figure it out, though. Yeah, very good.

Hey, Robb, speaking of anniversaries, did you know that during this whole time we've had other things going on besides just the podcast? Like a Slack channel. We have a Slack channel. This is a place where the community gets together, and obviously it's a very active Slack channel with almost 1,800 people in there. If you want to join it, go to colorado-security.com and click the link.

While you're there, we have a mailing list you can sign up for where you'll get one email every week with the show notes. We'd also love it if you rated us and subscribed on your favorite podcast player. That way people know how wonderful that things have been over the last 4 years, and you'll get this delivered every week to your player automatically. A couple other things you could do to support us: tell a friend, send a note to someone, say, listen to this awesome podcast. They've been going for 4 years.

It's crazy. And then maybe also you could support the Patreon campaign. If you want to financially support the show, we would love that. There's a Patreon link on the website as well. Hey, Robb, speaking of user-supported campaigns, our first story this week is talking about One Clock.

See, you don't get that kind of smooth segue after just one year of doing this. This is a 4-year type of segue. Yes. One Clock is a, is a Boulder-based company that's been doing a Kickstarter for their, for their custom, what they call it, like antique quality clock that you can get for an alarm. Yeah.

And so I think this is a little bit of a throwback trying to get you to get your, your phone and other electronics out of your room so you have a dedicated alarm clock. And help you sleep better and also help you wake up better. It goes— it says it's a minimalist clock. It's, you know, minimalist looking, but it does have a, you know, a built-in— it's kind of hard to describe. Like, it's got some music built into it, but it doesn't connect to the internet.

It just uses the built-in music and it remixes it every time. They say every, every time you wake up, it will be a different version of the music. Yeah, that's pretty crazy. Yeah, it was custom made by a Grammy Award-winning artist as well. Yeah, from War on Drugs.

He's one of the musicians with War on Drugs. So I gotta say, I'm looking at this thing. This, this clock is $250, I think, to buy. It looks— it does not look like a $250 clock to me. As I, you know, I don't know what I expect, and maybe I want it to have a, you know, be bigger or something.

I don't know, it just— it looks— it looks a little bit less than that. Well, I will say it is— it does have Swiss-made components, you know, and Swiss watches are supposed to be the best, so I'm sure that's a little bit pricey. But wasn't there something in here that's like from a— from a car? They had the same gears as a car or something like that. Anyway, should we move on?

They've raised $350,000 now as part of a Kickstarter to preorder this. So yeah, so they're doing great. Yep. All right. Next, U.S. News and World Report had their annual listing of top hotels, and we have a list of the top 20 in Colorado.

Yeah, I don't think we need to go through the whole list. No surprise that the Broadmoor, you know, hotel that you are very closely associated with, associated with, made number 2 on the list. A lot of stuff from, from Vail, a lot of stuff from Aspen on the list. But there was quite a few from Denver as well. Yeah, I was surprised at the amount of hotels in Denver, like the, the Art Hotel by the art museum, I think was the top rated in Denver.

The Ritz-Carlton made the list and a few others as well. But the number 1 hotel in all of Colorado is the Little Nell in Aspen. It's the 12th, 12th rated hotel in all of the country. Yeah, that's pretty cool. Have you been there?

I have been by there, but I have not stayed. Yeah. The Stanley Hotel did not make the list anywhere. Stanley is a wonderful place to visit. Probably not such a great place to spend the night.

It's kind of drafty. Not the most haunted hotels in America, Robb. All right, so next story we're talking about is a new COVID-19 antibody test that has received emergency use authorization, which was tested and I think maybe even developed here in Colorado. Yeah, so it was designed by scientists at DU, actually, which is pretty cool. And this, it's more precise.

It can detect more things than previous antibody tests. Yeah. So you take this test while you're sick, I think. Uh, and the idea is that they're going to tell you how sick you're going to get. This test can tell you, are you going to have minor symptoms or major symptoms as a result of it?

Um, there's some additional other correlations that they have found as a part of this testing, which, uh, was interesting to me. Like if you got a flu test or a flu vaccine in the last year, you will have, you will be likely to have less severe symptoms than if you didn't have it. Um, there's some other stuff as well that I can't remember off the top of my head. Yeah, very interesting. Pretty cool that this is being developed here in Colorado.

Next, the Colorado Office of Economic Development actually has a grant program that is in place, the Advanced Industries Collaborative Infrastructure Grant. So if you are a company in Colorado and you believe that you can help advance things, you know, technology is one of those areas, you can apply for a grant of between uh, $50,000 and $500,000 per project. It looks like they have quite a few grants available for this too. So I think anyone who's looking to build a new solution here in Colorado, this is probably worth looking at. And I guarantee, you know, if you're looking to solve cybersecurity supply chain type needs, that's going to fall, you know, within the realm of what these guys do and be some nice seed money to get started off.

Yeah, pretty cool. All right, uh, the link in the show notes has, uh, will take you into the application and you can Let us know if you end up getting this grant. We'd love to talk about that. That'd be fun. Next, we we have the results of the big annual CTA Apex Awards.

So generally, this happens in the the fall time frame. You know, with COVID I think I think initially they were hoping they could push the awards back long enough to be able to do it in person. Right. Obviously, that did not happen. But the the award show happened just last week.

And you know, as we've talked about on the show, we we had this the CISO of the Year added a few years ago. So we have a new CISO of the Year who's been crowned CIO of the Year, Tech Company of the Year, CEO of the Year, lots of good stuff. And I think we can give a summary of some of those interesting results. Yeah, I think, you know, we'll save the best for last. CIO of the Year is from Dish Network.

Yeah, Attila was the winner from Dish. Congratulations to Attila. But we do have a security person who was one of the finalists there, right? Yes, also the CIO from LogRhythm was a finalist. Yeah.

For CEO of the Year, Dan Mackin from Rule 4, who we've had several of the Rule 4 folks on the podcast before, was CEO of the Year. Congrats to Dan. Pretty cool to see a security company CEO win that. For Tech Company of the Year, Conversant. We've had Conversant, their founder and CEO, on the show in the past.

Kind of more of a compliance play, but ethics play, but pretty cool stuff. Yeah, and then Emerging Tech Company of the Year, it was won by Caruso Energy Systems, but And Zoic, formerly Password Ping out of Boulder-ish, was a finalist. So congrats to them. And obviously, we've left the best for last, the CISO of the Year. The 3 finalists this year, we had Brendan Baybeck from Oracle, we had Benjamin Edelen from the City and County of Boulder, and Artie Wilkowsky from Dish Networks.

Yes. And Robb, the winner is? The winner is Brendan Baybeck from Oracle. Brendan, who we've— I mean, you and I have known for a very long time. Yeah.

As we were both, you know, when we were doing ISSA, he was the head of ISACA for years. He's been at Oracle for a very long time. For sure. And, you know, a great member of the community, super good at volunteering. He's on the international board for ISACA, but I think more relevant here, he's been, you know, a really strong leader for security for Oracle for a long time.

Definitely. Brendan was also on the organizing committee for RMISC when I started on it. So, uh, I have known him for, you know, a good portion of my security career and, uh, very proud and happy for Brennan. So good stuff. Congratulations to that.

And it's, it's nice to, to see, you know, such a strong finalist group as well. Artie and Benjamin are also, uh, great security leaders. Yep. All right. Uh, jumping into the, uh, industry-specific news, uh, Ping Identity this week launched a new identity verification service, uh, for helping customer onboarding.

Yes, so this is cool stuff. You know, it might seem like there's a lot of press releases about new stuff, but to me, this one's unique in that this is the culmination of an acquisition that we made almost exactly a year ago. I think it was last February, we bought a company called Showcard, and one of the 2 things that Showcard is bringing into Ping is the ability to do password proofing upfront. So basically, you know, it's a combination of take a picture of your driver's license, a selfie, liveness check, you know, some validation to make sure it's not fraudulent. And then we're, we're really allowing that to be the onboarding, the verification portion of your identity management system.

And mostly being used for customers at this point because it's a more common use case than workforce. But I imagine in the future it'll be broadened out, especially as we're doing this remote work. People don't want to have to see each other in person. It's really nice to have the ability to really get confidence about who someone is to start off the IAM process. The way that the process works sounds cool too.

Many of the identity proofing services I've seen, you know, you like have to send in documents and things like that, wait for, you know, a person to review them and, and determine that you are the person that you say you are, or show up someplace in person to be identity proofed. And then, then you get, you know, approved. But here, where, you know, essentially you're doing it all in real time is, is pretty neat. Yeah, I think, you know, it's seconds from when you send in the documents to when they're reviewed versus, versus, you know, days or weeks like you're talking about. Yeah, pretty cool.

All right. We have another new service that's being announced, but this is from Ironcore Labs. We've had Patrick Walsh on the show, I think, twice in the past. And, you know, as a company, Ironcore has, I think, been trying to figure out exactly, you know, how their encryption technology is best to go to market. And they've now released a GA version of their customer-managed keys offering.

I think it's, uh, yeah, I think that that's right. It's called— so it's called Customer Managed Keys for Amazon S3, and they have a free trial right now in the Amazon Web Services Workspace Marketplace. I mean, yeah, so you could use this if, um, I assume if you're just using S3 buckets and wanted to encrypt it yourself, um, but, uh, that doesn't seem like as much of the, the use case here. It seems to me like they're trying to aim for, for SaaS products that also use S3 as a storage method, and then you can plug this in and then use your own keys to, to encrypt the data from the SaaS provider as part of that. So yeah, the intention is, is that a SaaS provider will have the ability to just plug in Ironcore's solution so they're— so that the SaaS provider's customers can do their own key management, their own key rotation, and transparently to the SaaS provider.

They— and the article even mentions, you know, this is something that the SaaS provider can upsell for. So right, not only do you make it it more secure, maybe you can make a little more money. Eh, I don't know. I'm, I'm personally, I'm always kind of, uh, offended by the idea of a SaaS provider making me pay more to get my stuff to be secure. Yeah.

But, but I, I get what they're saying. If nothing else, it's a differentiator. Well, I mean, it does take more work and usually this is a feature that gets built into, um, you know, a SaaS platform later down the line, right? We're gonna put other things in front of this and, right. And if you can just plug this in and not even have to worry about that, uh, you could immediately have this feature as part of your platform.

Yeah, it's good stuff. All right, uh, next we have an Optiv blog talking about critical areas in evaluating third-party risks. Uh, surprise, surprise, third-party risk is still a hot topic right now. Um, you know, this is talking about obviously with a backdrop of, uh, FireEye SolarWinds activity and, and what it is that you need to do to make sure that you are managing your, your third-party relationships and being keeping them secure and Uh, they have some good stuff in there. I don't know if there's anything groundbreaking here, but I think it's a good overview of things that you should be doing as part of your third-party risk program.

Yeah, I think if, if you have a program, maybe just read through this real quick and compare to see if you're thinking about the same stuff. They break the categories into, uh, risk tiering for your vendors or your third parties and looking at the inherent risk of that relationship. I think that that might get overlooked sometimes, like what exactly are these inherent risks? Uh, contractual agreements, which I'm sure most folks are working on. Doing due diligence on the third party.

And then probably another one that might get forgotten sometimes is ongoing risk monitoring. So it's not just, hey, we, we sign them up and they're good and we just let it go, but some kind of, you know, updating in the future. Yeah, for sure. So good stuff in there. Definitely check that one out.

All right, moving along here. We have a blog that's actually a combined blog from Red Canary and Microsoft, and it's, it's blog/video, right? There's, there's a little bit of blog, but really about 25 minutes of an interesting video. And this time they're talking about WMI and, and how really how to use WMI and detect WMI misuse in your organization. Yeah, and if you are a Windows shop, then WMI, or Windows Management Instrumentation, is something that you definitely want to keep an eye on because it's an easy way for attackers to do things remotely in your environment, move around, get access to other systems.

So, uh, definitely a good thing to check out here. And I did shortchange the fact that it's not just Red Canary and Microsoft. There's also an engineer from MITRE on this, on the meeting. So, so you get a lot of great knowledge there. Awesome.

And our last news story of the week, uh, is from Webroot. And this is a blog talking about, uh, 4 roadblocks to increasing employee security through user training. Yeah. So just, you know, Webroot, a lot of what they do is enabling MSPs to offer security services to their customers. And this is clearly kind of targeted at MSPs, right?

For how do you help organizations be more effective at using security training? For the 4 roadblocks they talk about, number 1, that the higher-ups in the organization don't see the value of training. Number 2, leadership expects a set-it-and-forget-it or a one-size-fits-all experience, which, you know, obviously doesn't get a very customized training. Um, training doesn't mirror the world, uh, the real-world threats. Or finally, that employees themselves aren't on board.

Those are the 4 roadblocks they talk about. Yeah. Uh, so again, interesting stuff. Uh, nothing groundbreaking, but, you know, should reinforce things if you are doing a security awareness program. All right.

Let's jump over to the Slack message of the week. Big thanks to Andre Gaeta for sponsoring this each week. Andre is the best. Talk to him if you, uh, like to talk to interesting security guys in the area. Yeah, each week due to his generosity, we get to give a $25 gift card to the Colorado Equal Security Store to somebody who wins.

And who wins this week, Alex? This week's winner is Ben Ryder. Congratulations, Ben. Ben's actually on my team at Ansheets, and he posted an article about a program where they are sending healthcare workers instead of police to situations where it makes sense. And In the first 6 months of that trial, there were no arrests as part of those encounters.

Yeah, I read this article and it was really interesting. It's called the STAR program. It's been going since June 1st. And basically there's a health— a mental health clinician and a paramedic traveling around the city in a van, and they're dealing with low-level incidents like trespassing or mental health episodes that otherwise would have gone to police officers. Right.

The team has responded to 748 incidents in the last 6 months. Seems like a lot. And none of those 748 have required an arrest. Yeah, it's pretty cool. They actually give some examples of, of some of the events that they responded to and, you know, why they were effective versus, you know, why a police response probably wouldn't have been effective.

So it's pretty cool. Yeah, I think, you know, getting this kind of detail and I wish we had, you know, more visibility around what these successes look like is it would be such a less, so much less divisive than, you know, defund the police. And the other thing is that it's easy to get polarized around, like, this is just good, right? It's just better to have the right level of response. Right.

And I don't think there's gonna be a lot of disagreement on that. Yeah, getting people help instead of sending them to jail is a good thing. Good stuff. All right, jump over to the calendar of events. We do have an event calendar on our website.

You guys can see what's coming up going out further in the future. But for the next 2 weeks, we've got a few things going on. Starting on the 10th, ISSA Denver is doing their online February meeting. On the 11th, ACES is doing their Women in Security Coffee Chat with Chris Frucci. On the 16th, the Cloud Security Alliance of Colorado is doing their February chapter meeting.

Also on the 16th, ISSA Colorado Springs is doing their February meeting. On the 17th, OWASP is doing their February meeting, and that's a combined Boulder and Denver OWASP. Also on the 17th, ACES is doing a security and healthcare, a panel discussion. With IAHSS and ACIS. I don't know what IAHSS is anyway.

I don't either. Also on the 17th, ISSA Denver has the Women in Security Special Interest Group happening. On the 18th, ISACA Denver is doing their February chapter meeting. And finally, ISSA Colorado Springs has one of their mini seminars on the 20th. That's the Saturday morning, you know, a little bit deeper dive technical, usually technical training get some CPEs, uh, hopefully enjoy your Saturday morning, get up a little earlier.

I think it's like 8:30 start time. Nice. All right, let's move over to jobs. Robb, it looks like we have some Ping Identity jobs this week. Yep.

I don't think there's any changes from last week. I'm hiring a program manager. This is someone who works very, very closely with me, uh, helping to, to manage all the great activities around the security program. We're also hiring a business analyst in my, in my team, and I'm looking for actually a couple of different product security engineers. So if you have a development background with a passion for security, This is a good fit for you.

Holland and Hart is looking for a compliance and security risk specialist. You can go work with James Johnson over there. Kaiser Permanente is hiring a cyber risk defense principal focused on incident response. Woodward is hiring a product cybersecurity engineer. Zoom is hiring someone here in Denver.

They're hiring an offensive security manager, not offensive security manager, It's offensive security, uh, focused on application security. Red Robin is hiring a director for IT security. And this is basically the, the head of the program there. It's the CISO-level position there. Henry Yu moved on from Red Robin over to, uh, over to Dish, um, go work with Artie.

If you, uh, like hamburgers, you'll get some. It's probably the place for you. Yep. Uh, not security-focused, but pretty awesome anyway. Gates Corp is hiring a CIO here in Denver.

You get to work with the, the great Sam Masiello. Vail Resorts is hiring a senior analyst, uh, in vulnerability management and also a just general security analyst. And then finally, this one's not exactly a normal job post, but it was really interesting. Um, the Colorado Attorney General's Office is opening a cybersecurity fellowship program, and I think it's a 2-year fellowship. I think that's right.

Uh, so if you are in law school and have an interest in cybersecurity, or you have recently graduated from law school and want to take this fellowship, then that sounds pretty cool. Yeah, I think it's a really neat idea. The more of these types of programs we can get, the better off I think everyone's going to be. Yeah, for sure. All right.

Well, that is it for our news this week, but we do have a feature interview thanks to Jason Jaques. He sat down with Grant Sturgis. Grant, we've known Grant for a while. He was one of the leaders over at SCL Health Security Program and then went over to Was it Intra? Oh man, I keep— I want to say that West Company is where Entrado slash West Company, West Corp. And then now recently he's moved over to T-Tech and he's one of the direct— the director of security operations for T-Tech now.

Yep. So should be interesting. We always like to listen to Jason interview people. So should be a good interview. It's better than listening to our own terrible voices.

That's right. Exactly. And we apologize for you having to listen to us on the show. All right, well, that's it. We'll look forward to talking to you guys again next week.

Thanks, Robb. Hey, this is James Carder, CISO at LogRhythm. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.

Hello, Colorado Equals Security. This is Jason Jaques. I interviewed a member of our community, Grant Sturgis. Fun conversation. Here's the interview.

Enjoy. Grant, welcome to the podcast. Thanks, Jason. Nice to be here. Thanks for having me.

Yeah, of course. So you are a part of the Colorado Equals Security Slack community, right? I am. Yeah. Awesome.

I always enjoy interviewing people from the Slack community. And you're also a part of the fantasy football thing that we did recently. Yeah, sad— sadly I am. I didn't do very well this year, but I wasn't— it was fun. I wasn't going to bring up how we did at all.

Yeah, we both did very, very terribly. You are a person that's potentially seeding an idea about a March Madness tournament for the community as well. Yeah, absolutely. I love March Madness. I think it's probably my favorite sports event of the year because, you know, it lasts a few weeks.

Anyone could win a bracket. It's really, you know, a lot of it is luck. And the college game is just so passionate and so full of youthful energy. It's so much fun to watch. I love it.

So yeah, I think we will definitely get a bracket going this year and hopefully we can get, you know, hundreds of entrants and have a nice big pot to win. And well, you know, Not money, but credit. Yeah. We'll figure out how to do it. But yeah, it's a great idea you came up with.

I like the idea. We'll have to make it happen for sure. So, let's talk about where you're from. You're not originally from Colorado, right? No.

I was raised in Houston, which is a far away different place than Colorado, and especially Boulder where I live. But after I graduated high school, I came to CU Boulder and it really changed my life. You know, in Houston, you can't really get outside and enjoy, you know, the out of doors because it's just so hot and there's asphalt concrete everywhere and humidity. And, you know, in Colorado, that's, you know, you can get outside every month of the year and get sunshine and and lots of good activities. So it was a big change for me, right?

How long did you live in Houston? Uh, I think we moved there when I was like 5, so 5 through high school, senior high school, so 18 or something. Yeah, Houston is a different place for sure than Colorado. What, what were some of your hobbies back then as, as a kid? Um, well, I played a lot of basketball, which is which was great.

And I still love that. And I grew up bird hunting, like quail and pheasant and ducks. Not in the city, obviously, but my dad lived outside of San Antonio, and he was able to take us to various places in South Texas and Central Texas. And so, yeah, that was— those are 2 big ones. Nice.

And then And then you went to school here at CU. CU Boulder, graduated with a business degree. And yeah, it was, you know, I did more fishing than studying, but that's okay. I finished. So how did you decide on CU?

You know, I really picked it out of one of those college catalogs. So the ones you flip through and they have the strengths and the weaknesses and the the student life and the Greek life and all those things. And, you know, I was looking at all kinds of crazy places. I, you know, I didn't really know. I knew I wanted to get out of Texas, but that was pretty much it.

So I really picked it out of the book, never even visited. I did early registration, got accepted, and I moved up here and, you know, never looked back. What were the other contenders at the time? Oh, that's a tough question. I think it was like University of San Francisco was one maybe for— I have no idea why.

Yeah. You know, I couldn't even tell you what the other contenders were. So you were looking for a big change from Houston is really what it sounds like. Yeah, exactly. Yeah.

I had an older brother and sister who went to school in-state and I had visited those campuses and they didn't really appeal to me. So yeah, definitely wanted to try something different. So you came up here, you went to CU. This is probably where you fell in love with Colorado and you've stayed ever since, right? Or have you gone elsewhere?

I did move away for a couple of years after graduation, but it wasn't— it certainly was— that was not a permanent move, you know, in my mind at the time. Oh, that's right. You went to Ketchum, Idaho. After college, I went to Ketchum for a year and that was just intended to be a break, a year off. And I fished all summer and I skied all winter and I waited tables and tended bar and it was fantastic.

It was so good that I had to cut myself off after a year because I felt I was at risk of getting used to that, you know. Yeah. So it was, it was a great year and I don't regret it at all. Because that's a big ski town, right? Sun Valley is the ski resort.

And they also have like a golfing resort and that kind of thing. And it's like super luxurious. It's kind of like, you know, Aspen-level luxury, but at, you know, half the size or maybe even smaller than that. Yeah. Yeah.

Okay. And then you came back here again. Colorado keeps drawing you back. Well, after that, I went to Houston because I felt like I needed, I needed some support starting a career. So I went back home.

And used my, my hometown connections to try to, you know, start a career. And I really just fell into IT. I had no real passion for it or interest in it. It was a job that was offered to me, and it turns out that, you know, I was, I was pretty decent at it. So, so it worked out well.

But I stayed in Houston for, I think, 2 years after that doing sort of desktop support and systems administration and that kind of thing. Okay. And then, and then the big Y2K bug was happening. And that was a huge project for everyone in IT. And so I saw my clients through that period, you know, preparing for it and doing all the upgrades and that kind of thing.

And then as soon as the new year came and went, That's when I decided, okay, I'm done with Houston. I'm packing my stuff, driving back to Boulder, and I didn't have a job or a place to live, but I had some friends. And so I just packed my car and came up here and figured it out. Nice. So then you were doing desktop support during Y2K.

Were you on call by chance?

That night I was not on call. I was on Congress in Austin, Congress Avenue, on a street party in Austin for Y2K. But we did a ton of work, as you can imagine, like coming up to that Y2K event. And mainly it was around inventory and upgrades, figuring out the posture of all the technologies and doing the necessary upgrades. Yeah.

I always wonder about what people were doing during Y2K because I was on call. But I had drank way too much, so I would have never been able to function or fix any of the Y2K problems. So, yeah. Right. It's always fun to hear what other people were doing.

Yeah. Okay. So you came up here and then you stayed with friends, but you knew you were going to stay in the tech industry. What did you do? So I ended up finding a job at Circadence, which people probably know that name nowadays, but it was, it was a different company back then.

It was a part of the dot-com, you know, boom and bust cycle that happened around that time. But we were, you know, it's really where I got my, my start into actual systems engineering. And we were essentially trying to put together this transport network across the internet that would have, you know, higher performance than the existing protocols. And so my job as a Windows systems engineer was putting these IIS 4 boxes out on the internet and maintaining them and operating them. And, you know, as I said, Circadence is a different company now than it was then, but I am very fortunate to have worked with several big names that were a part of that circadian opportunity at the time.

And several of them have been on this podcast. Oh, who are these people?

So I think, I'm pretty sure Steve Wostal was on the podcast. I think he's not in security anymore, I don't think, but he was for a long time. And And he's a brilliant person. David McGuire, who's a fascinating individual, has been on here before as well. And I know Rusty Perry is well connected in the community.

I don't think he's been on this podcast, but he's also a great person that I worked with back then. Very cool. Very cool. And Circadence is really the point where you kind of switched from general IT over to security, right?

Well, you know, I think that happened a little bit later. I was really into systems engineering, systems administration. And after Circadence, I spent many years at Array Biopharma. Oh, okay. Yeah.

And so it was at the end of that period that I made the pivot into security. Okay. Array Biopharma. Tell me about that. So Array was a Another great experience.

I spent, I think, 14 years there. And they were, they are, well, I guess they were, they've recently been purchased by Pfizer. Okay. They were a drug discovery firm that was focused on discovering and developing cancer drugs. And so as an IT person, it was really, you know, enjoyable and fascinating to work with these PhD-level scientists that were doing, you know, structural biology and medicinal chemistry and all of these kinds of things.

You know, as an IT person, you a lot of times end up thinking that you're a really smart person and, you know, you're educating people on how to operate a computer and these kinds of things. And in working for Array, you know, I'm working with people with dozens of years of education, you know, advanced education. PhD, multiple PhDs, and that kind of thing. So, uh, so it was, it was a pretty wild experience. And we, uh, we got the opportunity to do a lot of cool things like, um, like high-performance computing, like a Linux compute cluster that the scientists were using to do computational chemistry.

They, they work on small molecules and proteins and how they might you know, bind together or whatever. Like, I don't want to pretend like I understand the science, but, uh, but I got to put those systems together and, and help the scientists operate them, and it was really rewarding. Yeah, that sounds pretty cool. And so that's the job where you pivoted into security? Yeah, exactly.

Yep. Well, I was, I was the Linux engineer at that time, and, and, and, you know, because a lot of security tools are Linux-based and/or operated at the command line, the Linux guy sort of automatically inherits the security stuff. And I did not mind that one bit. And I relished the opportunity. And towards the end of my time at Array, definitely felt like I was ready to specialize in security and kind of get away from the IT generalist practice.

Yeah. Yeah. And then from, from there, where did you go? So I was— I got an opportunity at SCL Health, which is a local healthcare system here based in Denver.

And I was managing security operations, which was, you know, the technology side of security, everything other than GRC. And we put together a lot of, a lot of good stuff, improved the program quite a bit with with some preventative network defenses as well as multi-factor and some SOC work and a few other things like that. Yeah, there's a lot of people from SCL Health as a— I think even in the Slack community potentially, or there's certainly a lot of people around town, it sure seems, because they have a big presence, right? Well, they have, uh, I think it's either 4 or 5 hospitals in the Denver metro area. Okay.

Um, so yeah, I've, I've, I keep in touch with, with Howard, the CISO over there, but I don't know too many of the other folks anymore. Okay. And that's Howard Hale? Howard Hale. Uh, yeah.

And I, and I really owe a lot to Howard. I think he, he was a big influence on my, on me and my career. And he was really a great leader in the sense that, that he gave me the flexibility and the leeway to do the things that, that I thought needed to be done. And also the, the really unwavering confidence and support behind me. So I always knew that he had my back.

As long as we're, as long as we're, you know, moving towards a better security posture, there was, there was no question of that support. And I really appreciate that. And I model, model my own leadership philosophy after that as well. Okay. Very cool.

Yeah. Shout out to Howard. Yeah. And then, so from SCL Health, then what? So I, I was 3 and a half years at SCL.

And then moved on to Entrado, which some folks probably know the name. They've been a presence in northern Colorado for a long time. Their office is in Longmont. Headquarters is in Omaha. So it's not technically a Colorado company, but they certainly have that big presence in Longmont.

And it was really cool because You know, another, like, sort of like SCL, another really motivating mission where they work in the 911 managed network space. So, you know, it's critical infrastructure, very important, obviously. And so that was really cool to be a part of. The parent company had, you know, dozens of other companies going on, so it wasn't just 911. There was lots of other things.

That was part of the challenge is that, you know, you get pulled in a lot of different directions, which, you know, it was not boring. So that's, that's a good part. But we did a lot of really interesting kind of detection engineering and incident response, you know, at a smaller scale kind of thing, not like big incident response, but incident handling, I would say. Okay. Yeah.

And that, I think, is the, the job right before your current one. Yeah, I was there for— I wasn't there for a long time. It was just under 2 years.

And but definitely, well, then I got the opportunity to, to make a move and join TTEC, which is where I am now as the Director of Security Operations. And I've been here for less than 2 months. And it's been a fun and exciting experience so far. So TTEC, and I wasn't aware of this until probably 6 months ago, that's the old Teletech, right? That's right.

It's the same company, just a new name. Okay. And then what's interesting to me is, yeah, so you've been there 2 months. So you changed roles, changed companies during COVID You know, for a lot of the community out there— well, I shouldn't say a lot— some of the community out there that's looking to do the same thing or looking for jobs during COVID what advice would you give them? How was your experience?

Well, you know, the interview process was certainly different, but it was also the same. You know, I feel like we've gotten used to and adapted to this this remote virtual, uh, way of interacting with people. Yeah. And so interviewing with the— with them, um, you know, it felt just like another— like it felt like an extension of work. Like it was another meeting to go to and it was on Zoom and just like everything else.

Yeah. Um, you know, and but we, you know, we did have the conversations around you know, eventually this will end and people will go back to the office. And so what then? Right, right. I feel like, I feel like there's no putting the genie back into the bottle, right?

We've realized that we can work from home and still be productive or even more productive. And, and so, you know, the mandate that everyone has to go back to the office I think is probably just not realistic.

So, and yeah, we'll see how that plays out, but I feel like this is kind of the new normal from at least your officing perspective. Like, you know, hopefully we can go out to lunch again. Like, that would be nice. Yeah, exactly. So you're, because you're just totally working from home.

These days, right? I am. Have you, have you even been into the T-Tech office? And I never, never have once stepped foot into T-Tech. No, they, they shipped me my gear in a FedEx box and the next day I was working.

Okay, so yeah, um, down the road when they do bring people back, do you have somewhere to sit? Like, what's, what's the plan there? Do you have any idea? Well, it's at least an hour drive from my office. So, or sorry, from my, from my house, you know.

So hopefully I— well, I'm not planning on going there, you know, every day or regularly. I am certain that I will go down there for meetings and lunch and that kind of thing. But no, I don't, I don't plan on officing there. Yeah. Okay.

Okay. Let's talk about leadership. I know this is something you have a passion for. You uh, you study and read about a lot. How did you get into that?

Yeah, well, um, I think I owe it partly to, to Howard, as I mentioned earlier, and partly, and partly to Jocko Willink. Um, so those who might not be familiar with Jocko, um, you know, you should check out his podcast. And, and there's a book called The Dichotomy of Leadership So the book is probably more substance than the podcast, but podcast is fun to listen to. Okay. But it's also a— sorry, go ahead.

So he's got a podcast as well? Yeah, I think it's called the Jocko Podcast. Okay. Yeah. And, you know, he's a retired Navy SEAL Master Chief and he served in Iraq in the Battle of Ramadi.

And so he has all these, you know, battle stories, and he goes into military history and reads from these, you know, old books from World War I and Korea and things. Um, but the focus is really around leadership. Um, and, um, and the book and his— he also has a business— is focused on translating those lessons from from military and battle and war into the business world. And it has really helped me. And I think, I feel like it has also helped the teams that I've been a part of.

And it's really, to, you know, to me, it's about being thoughtful and intentional around leadership. And that if you, if you just try a little bit and you pay attention, it can make an enormous difference. And that a lot of people really just don't consider it. And, you know, these are the folks that sort of just clock in for work and do their job and kind of go home and, and that's the end of it. And when I think about leadership, I'm thinking about you know, having an ownership stake in the situation that you're a part of at work and, and having, you know, having a real passion to make the outcome more positive than it would be otherwise.

And rejecting the attitude that, you know, this— it's not my job, you know, that's someone else's job, I'm not going to worry about that.

And, and this applies not only to, you know, managers and direct reports, but it also applies at a peer level, you know, peer-to-peer or cross-functional or, or, you know, in whatever situation you're in.

If you understand the mission and the objective and what you're trying to accomplish, Uh, you don't need somebody telling you what to do. You know what to do. So take ownership of the situation and drive it to either, you know, drive it to completion or drive it to a, you know, a progress that you can, you know, move forward. Yeah, that's great stuff to learn around thought leadership. Is there anyone else you look up to or admire, including in security?

I do follow kind of the usual suspects on Twitter. Like Malware Jake and Leslie Carhart and John Strand and those kinds of people. Yeah. And of course, our local celebrities as well, which, you know, I don't know that I'm gonna need to drop their names here necessarily, lest we get some big heads on the Slack channel. Yeah, yeah, yeah, for sure.

So it's funny, I do have a community question for you relative to to leadership. I posed the question to somebody out there, what's a good leadership question to ask? So here goes, here's the question: Most leaders use frameworks to build teams and organize talent. Which ones have you used and why? So I would, you know, I would have to go to the Jocko framework, and that is, that's Extreme Ownership.

And That's the name of his first book, but the second book, The Dichotomy of Leadership, kind of walks that back a little bit because he says that extreme ownership is kind of a problematic term. Like, it doesn't have to be extreme like a Navy SEAL, but really the message is that, you know, you should be taking ownership of whatever situation you're in. And like I said before, it's the, uh, don't, don't fall into the mindset that it's not my job. You know, if it's not your job, then, then take the item, figure out where it belongs, and take it there and, and, and successfully deliver it to who, you know, wherever it does belong. Yeah.

So, um, so, you know, in a SOC, for example, uh, the SOC receives all kinds of crazy things, right? Like people will send the SOC who knows what, from tech support to, you know, their, the phishing message that they got in their Hotmail or their Yahoo Mail, and, or their voice, they'll bring voicemails to the SOC, you know, whatever. And so, you know, the SOC could potentially say, well, we don't support your personal email, I'm sorry. You know, Let's be a little more proactive and helpful and say, you know, technically, you know, we don't really support this. However, we've, you know, these are the, these are the red flags that you can use to identify phishing messages.

And, you know, I hope you didn't click on this. And if you did, you know, here's some resources that you can do to either monitor or protect yourself moving forward. So just take some ownership of that responsibility. I mean, people are reporting to you looking for help, you know, you should, you should do what you can to help them. Right.

And I know that you, you could probably craft your own framework because you've got your own beliefs, a couple of big beliefs around security. Tell me about those. Yeah. So I believe that The majority of enterprise security, so I'm not talking about product security or any, you know, more narrow niche like, you know, perhaps identity or pen testing or something like that, but holistically enterprise security is primarily good business practice. So, so some easy ones to use as an example are onboarding and offboarding of individuals and identities.

Like, you need to have a process to bring people on, give them the right roles and access and identity tokens and that kind of thing, as well as offboard them in a way that is, you know, complete but also adds to monitoring of those accounts after they've left. And then also inventory, you know, hardware, software inventory are number 1, number 2 on the critical controls list. And those, you know, bringing new people on and inventorying your things are really just good business processes, and they lead to good security. And I think, you know, there's a lot of other examples to be drawn, but for the most part, you know, having good sound IT and business processes lead to good security. Yeah, let's call that the Grant framework right there.

I think that works. That's great advice. It's certainly not very exciting. Yeah, but frameworks are never exciting. Yeah, I guess that's true.

How can people find you on social media? My, my handle for Twitter is so old, it's from probably the early 2000s or something like that. It's Eddie_Sysad. I guess my middle name is Edward. My nickname is Eddie, but not professionally.

I'm Grant, but I'm definitely on LinkedIn and the Colorado Equal Security Slack channel. I try to pay attention to that as much as I can. You know, that Slack channel has blown up so much. It's so active, it's really hard to keep up anymore. But I do try to poke my head in there at least once a day to see what's going on.

Yeah, you, you got to fine-tune the channels that you're a part of for sure, because some of those channels are very noisy. But I have a great time in it. There's always stuff that makes me laugh. And they're also interesting. It's really hard not to subscribe to all of them.

Yeah, for sure. So I think before I let you go, because we are kind of running up against the time barrier, there's one other thing that I wanted to ask you about. So you are a big fisherman. And I know, I mean, the listeners of this aren't going to be able to see, but you've got a picture behind you of fish in a lake. And so how did you get into fishing?

And Where are the places that you, uh, you like to go? Yeah, so I, I discovered— I, I grew up fishing down in Texas, but I discovered fly fishing when I came to college here, and I skipped many a class at CU to go to the Big Thompson and go fishing, uh, when I should be on campus. Um, but in the years following that, I, I, I ramped up my obsession beyond belief, uh, and went fishing at every opportunity, you know, every evening and weekend. I had a pickup truck that I could sleep in the back of, so I could just drive up to wherever, camp out in the back of the truck, and be, you know, streamside when I woke up in the morning. Yeah.

Um, and I got into tying my own flies because, you know, store-bought flies were both too expensive and too ubiquitous that I wanted to have something a little more unique to show the fish.

And it was a really satisfying, you know, hobby to get into. And I'm still into it. It's just now that I have kids, you can't go like fishing every night and weekend. So Yeah. Are you gonna get the kids into fishing?

Absolutely. They, they already are. So we live here in Boulder and they have some really great, um, kid ponds down by the Justice Center in West Boulder. Uh, and so I've got a couple different rods for them. I'm trying to get them into fly fishing, but they're on the spin rod now.

Yeah. Um, but yeah, it's been a lot of fun. My kids are 8 and 6, so they are definitely old enough to enjoy the the feeling of pulling in a fish and then, you know, taking it off the hook and throwing it back. Yeah, yeah, very cool. Well, this has been a lot of fun, Grant.

Appreciate you joining me. And, and yeah, do you have any final thoughts for the community? I, you know, keep doing good security, join us on the Slack channel, listen to the podcast. And Jason, thank you for the time. I enjoyed the conversation.

Wow, anytime. Thanks, Grant. That concludes my interview with Grant Sturgis. Be sure to follow and support Colorado Equal Security on Patreon. This is Jason Jaques saying be safe out there.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes