All episodes

James Brown, Director, Infrastructure and Security at Invoca

Apple Podcasts Spotify SoundCloud

James Brown, Director of Infrastructure and Security at Invoca is our feature guest this week and is interviewed by Jason Jaques. News from DISH, Convercent, Cloud Elements, Stack Hawk, F5, Ping Identity, Coalfire and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

  • NO EVENTS COMING IN NEXT TWO WEEKS

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12348 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode— what are we at— uh, 204 for the week of March 29th, 2021. Alex, we've— we're closing out Q1 here, closing out with a bang.

We are closing out, and you know what that means, Robb? Get to go on vacation. It means what? Sorry, get to go on vacation. Oh, vacation time it is.

I'm going to be missing next week's podcast because it is spring break and it is time for me to, to leave these snowy climes and find myself a wonderful beach somewhere to lay on. Are you planning to do anything for, for getting out of town? You know, I think, uh, this upcoming week is my kids' spring break also. Um, we, we had an interesting thing this year in that, um, my wife, who is an educator, and my kids— they're now in different school districts— have different spring breaks. It's the first time we've had that happen to us.

Um, so my wife is on spring break this week and the kids get next week. I think, uh, we may take a few days and go skiing, but, uh, nothing too crazy. Not going to Mexico, that's for sure. Yeah, well, I'm sorry for you on that. I know.

Soon. Hey, let's jump over to, uh, just some reminders. We do have a Slack channel, and the Slack channel is once again super vibrant. Um, I, I really do think that that's maybe the best part of this whole community is getting to meet folks there. So if you haven't signed up yet, what are you waiting for?

Go out to colorado-security.com and find that Slack link. Yeah, and you know, the, uh, the Slack apocalypse from this week seems to have passed for the moment, so you're still safe joining the Slack channel. Uh, also we have a mailing list. If you go to the website colorado-security.com, there is a web form you can, uh, use to sign up for the mailing list. You'll get exactly one email every week with the show notes after the Uh, new podcast comes out.

Uh, we'd love it if you would rate us and subscribe on your favorite podcatcher. Uh, that, that would be a great way for us to find more folks and basically come up higher in the search results. If you search for Colorado on iTunes, how close to the top of the list are we, I wonder? Oh, you won't know unless you look. That's right.

Go do it. Subscribe. Um, if you rate us at a 5-star, I assume we will move up one spot in that list. So Um, also tell a friend, let them know all the great things that are going on with Colorado Equal Security— Slack channel, the podcast, the website, everything else— so that they can enjoy it and be participants with us too. And finally, we just want to do a big thank you to our patrons.

You know, we have a great group of people who help financially support the show. You guys make a big difference for us, so we're not having to shell out all of the cash to support it. And frankly, it's also got some morale boost for us to have some folks who support us. So if you want to join join that group of supporters for the show, you can click the Patreon link on colorado-security.com.

Speaking of the community, I got a question. You know, a few weeks ago we did our 200th anniversary, our 200th episode, and we asked ourselves questions. We interviewed each other versus, you know, interviewing someone else in the community. Well, I got a question a couple weeks late. He's like, well, I really wish you guys would have talked about that.

And I said, you know what? I think we can arrange that. So this question came from Chris Ard. Chris is the CISO for Newmont Mining, and he asked, what are some of your favorite resources to stay on top of security, including like websites, books, other podcasts, or security community events? Alex, you want to take a first run at that?

So, well, first I have to say, so it took Chris a couple weeks to dig up that question. It did take him a couple of weeks to dig up that question at Newmont. Newmont, yeah, yeah. Okay. Resources from my perspective, I think the biggest thing for me is that I've collected a large list of sites that I monitor, and I have these all in a giant RSS feed and in an RSS reader.

Probably, I don't know, 150+ sites that I look through. And I think that that's been really valuable to me and all kinds of different sites from Uh, you know, more technical to, uh, Krebs to, you know, lots of different things. And that, that really helps me, uh, keep a pulse on what's going on. I don't necessarily read everything that's in there, but I do usually look at the headlines for all of the stories that come in, uh, in any particular day. Yeah, my, my logic was with all those sites is always that it's not that I'm going to know everything that's happening, it's that I'm not going to be surprised by a big thing that happens, right?

Like, right, first, first thing in the morning, one of those is going to tell me it when SolarWinds happens or whatever, and we don't know pretty quickly. So for me, favorite resources, you know, it goes in different ways. You know, what we just talked about in terms of awareness, you know, I get great awareness, you know, not to pat our own community on the back, but from our Slack channel, you know, people definitely quickly let us know about breaking news in the security community, and that keeps me on top of things. Similarly on Twitter, when I do a good job keeping up on that, a lot of the folks I follow, you know, let me know what's coming. In terms of like kind of more, not necessarily current events, but more trends, my very favorite resource is a podcast called Unsupervised Learning by Daniel Mesler.

He's a security guy. He currently works for Apple, although you wouldn't know that just listening to his show. And really, he's just, he just goes through what are the trends in technology and security and kind of the human world that are going to be impacting us. And as leaders, we need to be thinking about how to prepare for those. He does a weekly podcast and I get a ton of value out of that.

And that makes me feel like I'm not surprised by whatever's coming down the road. And, you know, he does exactly what I do. And the only difference is that he actually, I think, spends more time actually reading these things and then collates it for other people and charges them to, to get that information. So maybe I should go into that business. That sounds like a lot of work, Alex.

Work. All right. So this is— I think this is a great conversation that, you know, the two of us have answered, but I think the rest of the community probably has some good perspectives on resources to use as well. So why don't we throw this out to the community? We'll start up a a discussion, uh, thread on this in the podcast channel of Slack, and we'd love to hear from you guys on, on what resources you use.

And let's use that as a way to, to make the mega list of security resources. Sounds good. All right, let's jump into the news. Uh, there is a new billionaire list from Forbes, and the, uh, richest billionaire in Colorado has changed, Robb. So how do you feel about this, Alex, being, uh— now you're number 2.

So, uh, Phil Anschutz, the, uh, the owner of the company that I work for, uh, was the wealthiest resident of Colorado and, uh, was displaced by Charlie Ergen, uh, who is the— I don't even know what his technical title is anymore. I think he's a founder. He's a founder and chairman of the board for both Dish and EchoStar. Yeah. And I think whatever the, uh, the new subsidiary part that's the, the wireless carrier and all this stuff too.

Lots of stuff. Anyway, so his net worth nearly doubled in the last year to $10.6 billion. So congratulations to him, just surpassing Phil Anschutz at $10.1 billion. Although I will say anecdotally, I've heard that the Forbes list is not necessarily accurate. I don't know in which way.

I don't know if that means that Charlie Ergen is actually worth $1 billion or $100 billion, But I've heard that they— that there's a little bit of guessing in terms of making the numbers. Yeah, it makes sense. I'm sure that there's a lot of inaccuracies there. But to round out the list of billionaires in Colorado, uh, number 3 on the list is John Malone, who's the chairman of the Liberty Media Group and Liberty Global, uh, worth about $8.2 billion. Make— it makes him the 300th richest in the country.

Uh, Kenneth— is it Tuchman or Touchman? Uh, the founder of T-Tech. Uh, he is, uh, $3.2 billion, and putting him at the 951st spot. James Laprino, which you might guess is the owner of Laprino Foods, is $3 billion, number 1,002 on the list. Pat Stryker, granddaughter of the founder of Stryker Corp., is worth $2.9 billion, putting her at 1,073.

And the poorest billionaire in town, which is one of the most ridiculous things I've ever said, is Gary Magnus, the son of Bob Magnus, the founder of TCI, the big Denver-based cable television company, and he's at number 1,790 with $1.6 billion in wealth. You know, Stryker Corp sounds like the, the company in it, you know, that a bad guy owns in a Marvel movie. It sounds like— is it Airplane? Stryker? What's the— sorry, we'll keep it, keep it moving here.

All right, me? I think it's me, right? It's you. Yeah. Yeah, so this is some interesting news.

You know, if you remember from that, um, that 200th episode, I did talk about my very favorite interview on the podcast was with the founder and CEO for Conversant. Well, the news this week is that Conversant has sold. They were purchased by OneTrust. And if you remember, we actually talked about OneTrust on the show not that long ago, right? Like a couple months, I think, months ago.

They were, um, the Uh, the fastest growing company in all of America over that previous year, and, and now they have acquired Conversant. Yeah, they grew— it was either like 3,100% or 31,000%, um, you know, over that time period, which is crazy. Uh, OneTrust, of course, started in the, the privacy space, but they have, uh, they've enhanced their, their platform and gone into slightly different areas. Now including, uh, Conversant software, which they're going to be pulling into the platform. Yeah, so Conversant, you know, the simplest way to refer to them is probably as a whistleblowing technology.

If you see something at work, this is a way to report whatever you saw. Um, and, you know, now they're, they're going to be built into that OneTrust platform, which I think is probably nothing but good for Conversant. Yeah, good stuff. Congrats to them. Uh, next, another, uh, acquisition note.

Uh, UiPath acquires Cloud Elements, which is based here in town, uh, to help deliver expanded API automation capabilities. Yeah, this is another, uh, I should have said on the last story, congratulations to Cole Krems, who's the head of security for Conversant. And here we get to say congratulations to Ed Fuller, who's the CISO for Cloud Elements. It's really cool to see Cloud Elements, who's really built a nice API management platform, uh, get moved into a larger platform that they're going to be, you know, one, one of the components of. Yeah, uh, good stuff, and, uh, glad to see that there are great companies in Colorado.

I'm, I'm a little sad that it's not going the other way around with both of these, where, uh, you know, we're not— Colorado companies aren't acquiring other companies, but, uh, good nonetheless. It is good nonetheless. Hey, speaking of good stuff, this is really the only part of the show I care about, you know. Hopefully everyone's fast-forwarding to this. This is our update on the, on the Colorado Inno's Tech Madness tournament.

And how are those tech those tech, uh, companies doing, Alex? I am, uh, super excited about this, Robb. Uh, so on— we're down to the, the final 2 companies now. We skipped like 3 rounds in a row here, didn't we? It seems like a lot of rounds got skipped.

It goes really fast. I think there are only, you know, the, the voting I think is even less than a week worth of time. So that— less than— it's like 2 to 3 weeks for this whole thing to happen. Um, anyway, but on one side of the bracket, uh, the, the finalist is Pi Insurance. We've talked about on the the podcast before.

But on the other side, very excited to say that StackHawk is the other finalist, uh, in this year's Colorado InnoTech Madness. And so this is ongoing right now. Uh, if you go to the link in the story, you should be able to vote, uh, so that you can see, uh, if StackHawk is going to be the winner. Yeah, I mean, this is one time where I can honestly say vote early and vote often, and, uh, Hey, let's let's make sure we bring this home for the security community and our friends over at Stackhawk. Yeah, I expect if they win that when they accept they will give a nice caca as part of the the acceptance speech.

I'm sure there's a very elaborate gala where where all of the awards are given out here. I'm sure that there is. All right, next we have a a blog from from David Stauss at Biteback Law talking about the Colorado Privacy Act being introduced, which is pretty cool. Uh, it— this seems like the, the trend of the year. Almost, uh, every state that I can think of is, if they don't have one already, is introducing a brand new privacy bill.

And Colorado appears to be in that same boat. I, I really feel like we got to get David back on the show. It's been, been 3, 4 years since we've had him. And yeah, obviously this is a topic that would be very interesting to our, to our listeners. So I think it's, uh, it's— that's our challenge, is let's get David back to on the show to teach us what's going on here with this.

Obviously, in the short term, since we don't have him here to talk to you, you should just, uh, read the blog and learn about it that way. Yeah, and it, you know, looking at it, it does seem fairly similar to many of the other privacy acts that are either in place now or coming into place, uh, that being GDPR, CCPA, Washington privacy law, Virginia privacy laws, all very similar, slight differences in them, but all you know, focused on, on consumer rights. Good stuff. Yeah, I'm excited. Number— I actually, and I'm excited that Colorado is doing it.

On the same side, I really wish Colorado didn't have to do it, that we had a federal law that could, could, you know, get rid of this patchwork of privacy laws that we're going to have at the end of it. Um, but, you know, I guess that's probably not something that we can easily impact here, uh, from our, from our studio. Yeah. All right, moving along. This is a fun list from govtech.com.

They have identified the top 25 government servants who are helping with technological innovation within their agencies. And this is actually across the whole country, so the fact that we're talking about it on this podcast might give you some indication of what state showed up. Yeah, I think that this is— it's a pretty cool list. This is the Doers, Dreamers, and Drivers list for GovTech, and we actually have more than one person with Colorado connections to talk about in here. The first, and I don't think it'll be any surprise, is Debbi Blyth, who is the, the CISO for the state of Colorado.

Debbi's been doing great stuff for a long time, and so it's great to see her recognized here. Yeah, super excited for Debbi to get this recognition. Well deserved. She has been, man, probably like 7 years or so at the state. Really, really proud of the work she's done.

We also have another employee of the state, Jenna Griswold. She's the Secretary of State, and she's really been pushing pushing Colorado forward to be at the front line of things. And once again, you know, the fact the way we've done election or mail-in election and, you know, the security controls in place really put us at the top of the heap on that. Yep. Uh, also on the list, um, is Kevin Ford, who's the Chief Information Security Officer for the state of North Dakota.

And you might say, well, why are we talking about Kevin Ford? Why are we talking about Kevin Ford? This is not North Dakota Equals Security. Although according to his award, North Dakota does sound like it is pretty high on security. So Kevin used to be the CISO for CyberGRX here in town and was recruited away to that position as CISO for North Dakota.

Yeah, he's— we definitely think of him as one of our own. Lived in Colorado, got involved with the community before stepping up to, you know, to start that service for the state of North Dakota, and we appreciate that and want to reward that. The last name that I wanted to call out on the list, there's not really a Colorado connection here, but Christopher Krebs is on the list, you know, for his work as the head of CISA. I think, you know, it's just neat to see the security. There's a lot of security conversation on this list, and it makes me glad to know that the government's starting to move in that direction.

Wonderful to see. All right, next, another announcement. Uh, F5 Networks has appointed 2 senior executives, um, to their, their executive team. And well, one of them I guess is a promotion or a lateral motion. Um, and so Gail Curry, who joined F5 in 2018 in a different role, has now been promoted to SVP and Chief Information Security Officer.

Congratulations to Gail. Gail is a big part of the community here in Colorado, and you know, I— you and I have known her for man, a long time previous to this, previous to going to F5, she was the CISO for Oracle's cloud headquartered in the DTC office here in town. She went over to F5 to become the GM of their Silverline product line, which really was her first chance getting out of security and really running a business unit. And now, you know, obviously F5 has been in the news recently with some some security news. So I think she's stepping into a really important role at a really important infrastructure company, and very excited for Gail to do that.

And she'll be doing that here from Colorado. Yeah, it is cool too, looking at what her responsibility is going to be. So she is going to do enterprise security, so, you know, your sort of traditional CISO role. Also, uh, the company's product security, as well as, uh, the service offerings that go along with that. And the responsibility of showcasing to customers the use of F5 security technologies.

So pretty broad. Yeah, I love it. You know, I think Gayle's gonna do great at that. I'll, you know, candidly, when I was first getting into Ping and I was, you know, figuring out how do you do security at a tech company and, you know, focus on product security as well, I sat down, I took Gayle to lunch and picked her brain on how she was doing a lot of stuff and got a lot of value from her. So I appreciate her willingness to share.

And once again, congratulations on the new opportunity, Gail. Yeah, congrats. Moving to our next story. This is a blog from Ping and it's focused on what Ping Identity is doing for Women's Day, or for really, it's not just Women's Day, but it's more broadly how Ping is focused on women in the workplace. So it kind of started mentioning that we had a whole company holiday on March 8th, International Women's Day.

And it wasn't just a holiday, you know, where you're supposed to just go hang out with your family. The intention was to in some way acknowledge what women are doing to help, to help make the world a better place. And this article goes into a bunch of other things that Ping are doing to engage women and trying to improve the ratio of women in the tech industry. Yeah, in addition to that, talking about Ping's commitment to equity, inclusion, and diversity, not just with women and the Women in Ping group, but just all across the board. So pretty cool, and congrats to Ping for that.

Yeah, it's been fun to watch this develop over the years. When I got there, you know, it didn't exist, and it went from a nascent idea to something that is, you know, really has some real momentum in the organization, and I really appreciate that, that commitment from, from Ping. All right, jumping to our last story. This is from Coalfire. They have been awarded the first UKAS ISO 27701 accreditation, so This is pretty cool for them.

You know, ISO 27001 is the security standard, 27701 is the privacy standard, and they aren't— they are assessors for 27701, and they have now been accredited for giving those accreditations out. So congrats. Obviously really cool stuff. Coalfire is often at the front end of any new compliance requirements, and it's nice to see them, uh, once again, uh, getting on this one. So good, good, good work up there to the, uh, the Denver-based big consulting firm.

I thought it was, uh, interesting to see that they had been, um, been approving people for 27701 certification before being accredited, um, and so I guess people were sort of an unaccredited, um, uh, certification. But now since they're accredited, all those people automatically get accredited certification. So congrats. Love it. All right, let's jump over to the Slack message of the week.

Big thanks to Andre. Andre Gate has been our supporter for forever, and each week we pick one community comment from Slack that, that drove the conversation forward or we just wanted to acknowledge. And this week that person will get to— well, that person gets to pick an item from the Colorado Equal Security store. And who did we pick this week, Alex? This week's winner is Colin Grady.

Colin is very active in the Slack channel, and he posted this week. I believe he was the first person to post about the, uh, the cargo ship that is stuck in the Suez Canal, which resulted in lots of talk about that, uh, ship being stuck and status and memes and everything else. And that's the only reason I knew about this story, by the way. I, I know, yeah, other people have other news sources, but I didn't know, and it's big news. Uh, and I think Colin, either this week or last week, probably last week, finally Uh, announced he closed on the condo.

He's been taking us along on his journey as he's been putting offers on condos, and, and I think he's, he's now closed on that. So congratulations on that as well, Colin. Yeah, I did note that, uh, someone else— uh, it could have been Colin— someone posted a, a website that, uh, I think is something like istheshipstillstuck.com. That was awesome. And, uh, when you go to that website, it tells you based on the amount of time it's been stuck there, um, how much has been lost Um, in, I don't know, in GDP, I guess, or whatever.

When I looked, it was like $34 billion has been lost by this ship being stuck in the Suez Canal. We looked at a very similar time then, Alex, because that's what— that's the number I saw too. Maybe it's not updated so much. Good stuff. All right, let's jump over to the calendar of events.

Um, as a reminder, that was great. Let's move on from events. Oh yeah, that's basically— we do have a calendar on the website showing all of the events happening in the next Uh, well, as far out as we see scheduled. Um, however, on the show we just talk about the next 2 weeks worth of events. And to your point, Alex, there are no events in the next 2 weeks.

None at all. Yeah, I think that everyone decided these are, you know, spring break and, and everything else. We'll just take a little break here and come back in a couple weeks. Uh, so, you know, why don't we use that real quick? I don't know if you're ready for this.

Just do you have any kind of, uh, RMISC sneak preview you want to give? Yeah, that's great. So we're, um, We are almost 2 months out from, from RMISC, um, and, you know, we've had a little bit of a different timing this year because we're not used to trying to put together a virtual conference, but, uh, we should be sending out, uh, shortly here the, uh, acceptances for people from the call for presentations. So if you, uh, if you put in a presentation in there, you should be getting a notification here soon. And our plan is to actually open registration for RMISC on April 8th.

So that's about 2 weeks from now, uh, or less than 2 weeks if you're— when you're listening to this. And, um, so yeah, we're getting pretty excited about that. We're— I can say that unofficially we have a couple keynotes, uh, and, you know, maybe I can talk about those a little bit even though we haven't officially signed the papers. I think, uh, one of the really cool ones is, uh, Chris Hadnagy, who is going to come in and do a keynote. So, uh, you guys may know Chris from the socialengineer.org podcast and website.

He also runs the Social Engineering Village at DEF CON, and, uh, you know, just sort of a personality in the security world. So I think that that should be interesting. Um, and the other one is, uh, Jennifer Brown. She's going to be talking about, uh, diversity, equity, and inclusion. That's awesome.

Cool, Alex, it's really cool. And, uh, and the dates, basically it's, uh, the first week of June, is that right? Is that when it is? Uh, so we are— we're doing the 8th, 9th, and 10th of June. And you might say, holy cow, 3 days of a virtual conference, that's a lot.

Well, it is. It's 3 half days. So we wanted to make sure that, uh, we got, you know, enough time in for people, but also didn't want to, you know, put people through the wringer of being on, on Zoom for 8 hours a day for 3 days. It's a good idea. I love the way you think.

Yeah. All right. Hey, we did talk about events for a while. Let's jump over to jobs now. Uh, we starting off with the top job on the list is, I think, came right from you, the Broadmoor The, the resort hotel in the Springs is looking to hire an information systems network administrator.

Yeah, the Broadmoor is one of the companies in the Anschutz portfolio, and while this is not directly a security job, um, it has a lot of security responsibilities, and the IT team down there does a lot of good stuff in security. So it'd be cool if you're down in the Springs. Uh, GitHub is looking for a chief of staff for security. Yeah, pretty cool that they're hiring that here in Denver too. Yeah, um, Forensic Discovery— that's, that's the name of the company— they're hiring a senior digital forensics investigator, and that's here in Denver as well.

Yeah, and we talked about this a little bit earlier, Robb, but, uh, I had not heard of Forensic Discovery before, but apparently it is a fairly large forensic company and it is based here in Denver. Uh, I can't believe we keep finding new companies. I know, they just keep popping up. Who knows? Uh, Alterra Mountain Company is hiring an IT application security analyst.

Alchemy Security, with our good friend Joe Bonnell, Jobo, over there, is hiring a systems administrator. Yeah, and I think while it says system administrator, I think you're probably going to be doing a lot of security work related to that. Uh, Alteryx is looking for a cybersecurity operations intern for the summer of '21, and this is the, the intern section of the job list. Yeah, we start— we already finished the rest of the jobs. The rest of this is interns.

Ping Identity is hiring a cybersecurity intern. That's, that's, uh, on my team there. If you have any questions, reach out to me on Slack. Rule 4 is hiring a summer intern. The state of Colorado is hiring a legislative IT audit intern.

Yeah, a little, uh, little turn there— IT audit intern. And then finally, FireEye is hiring an incident response and red team internship for, uh, summer of 2021. And this is a remote opportunity. I think in the job post it technically says Toronto or something like that, but I believe it can be anywhere. Awesome.

Well, that is it for jobs and that's it for the news. But good news is we do have an interview this week, uh, thanks to Jason Jaques. He sat down with, um, the IT and security leader and a poker superstar, James Brown, who is the director of infrastructure and security over at Invoca. And we get— I know James, but now the rest of you are going to get to know James as well. Uh, did they talk about how it was to, um, play the theme song for Rocky III when, you know, when he fights Ivan Drago.

I, I can't imagine having a conversation with James on that was recorded where I didn't make some kind of allusion to— yeah, I just don't know how you get through it without doing it. Yeah, we'll see if Jason— make a dancer, I don't know, something. We'll see if Jason Jaques has better, uh, with, uh, self-control than I do. Yeah, I doubt it, but we'll see. All right, well, that's it.

We'll, uh, we'll talk to you guys again next week. Thanks, Robb. Hi, this is Rich Schleip, the CISO for the Colorado Department of State. This is Colorado Equal Security for Colorado security professionals by Colorado security professionals.

Hello, Colorado Equal Security. I'm Jason Jaques. My spotlight interview this week is with a member of the community, James Brown, the Senior Director of Information and Security at Invoca. Enjoy. James, thanks for joining me on the podcast today.

Glad to be here. So let's talk a little bit about, uh, the elephant in the room first before we dive into, uh, where you're from. You are the 2020 poker champion for Colorado Equal Security. How do you feel about that? I feel pretty good about that.

I'm still waiting on, you know, the feeling of holding that trophy in your hand for the first time. But yeah, I'm feeling pretty good. Yep, I do have a trophy for you and I'm gonna send it shortly. Um, but let's, uh, let's explore poker just for a, just for a little bit. So you actually played poker for a living, correct?

I did for, uh, just under 2 years when I was much, much younger. How old were you and how did that come about? I was about 19, 18 to 20, that range in there. And it started online, you could play, there wasn't really a lot of poker rooms. And I had won a freeroll, just free to enter tournament, and I won like $2.

And then I put that $2 into another tournament, won several hundred, and then, you know, had thousands after a few weeks, like I kind of had a knack for it. I then cashed out some of that and I started playing in live poker rooms, live games, and I just consistently, you know, was making money doing it and just kept, kept up with it. So you are what they call a ringer and you're just taking all of the security people's money around here in Colorado. I don't know how I feel about that. Yeah.

I mean, to be fair, I did give you all a disclaimer ahead of time. No, it's, it's, it's It's kind of funny because the winnings do seem to go around. I've actually even won one of the events that we did, and it was out of sheer luck. I just went all in like 6 straight times and kept doubling up. So sometimes, you know, sometimes luck happens.

Yeah, I think, I mean, if you ask any poker player, I think they'd probably tell you they'd rather be lucky than skilled. Right, right. Another thing to remember too, I mean, there's you can't win every game, right? And what a lot of people, I think, don't really understand about poker and playing it for a living is it's very different. You know, now I play for fun, like I do things that I wouldn't have done back then.

And you, you build in losses to your strategy when you're playing for a living. So you do lose games, and you're really looking for that, you know, extra 1 to 2%, just to edge you up. So you have, you know, the ability to sustain. Right. So why did you stop playing poker?

It was literally the worst job I've ever had. And mind you, keep— my first job was detasseling corn. So I would go out in cornfields, get shredded, like arms and legs sweating with pollen falling in it. And I would do that over playing poker for a living again. It was the most stressful, like exhausting job.

And it just took all the joy out of playing the game. You know, like I actually enjoy playing poker and like, for years. I just, I never touched it after I stopped playing because of traumatized I was. Yeah, weeping for a week to pay rent. You know, when you turn a hobby into a profession, it definitely changes your outlook on the hobby.

100%. That's, that's what I have noticed too. So I totally get that. Uh, well, let's actually shift gears and get back on track with, uh, with this interview. Uh, that was kind of a nice distraction, but, um, let's talk about where you're from.

So you were born in California, right? I was, yeah. Where at in California? Simi Valley. So just north of LA.

Okay. How was that to grow up in, I guess, the suburbs of LA? It was pretty cool. I mean, I was 6 when I moved away, so there's not a ton to remember, but I remember the nice weather and earthquakes and fires. Kind of odd.

I remember the smell of wildfire stuck with me. And moving to Minnesota, I didn't grow up in California, but when I came back and smelled wildfire again, I knew exactly what it was. It was such a distinct smell that I remembered from my childhood living there. Wow. Okay.

So there must have been some fire seasons there. Oh yeah. SoCal, it's basically just a perpetual fire season down there. Oh, interesting. I've never spent a ton of time in Southern California, mostly Northern California for me, like the San Jose area.

But yeah, I would, I would not want to be around kind of the fire smell all the time. Last year was bad enough here in Colorado. Yeah, it was rough. So, okay, so you left at 6. Where'd you go after that?

Minnesota. We, we moved. So the first time I saw snow was in Minnesota. We moved up there, we drove up there. And we pulled in, it was a really, really small town way up in northern Minnesota, like maybe like an hour or 2 from like the Canadian border.

And I'd fallen asleep, I guess, somewhere maybe in like Nebraska or something and woke up and there was like snow as tall as I was outside. It was insane. We had like a wood-burning fireplace. So we had to cut wood, literally like go outside and chop down trees and like chop wood to put it in a fireplace unit, like freeze to death. And that was my introduction to Minnesota.

And I decided at that moment, I did not like it there. Did you know what snow was at the time? Like, or did you look out and go, what is all that white? Yeah, I mean, I figured it out quickly, but yeah, it was, it was insane. It was so much of it.

And you must have gotten used to it and learned to enjoy it because you came to Colorado. No, actually, I was traumatized by it that I, when I turned 18, you know, I was playing poker. I rolled up my bankroll and used that to move out to California so I could get away from the cold. And I lived out there for, geez, I think like 14 years. Before moving to Colorado.

And the reason I came to Colorado was I realized that winter didn't have to be death.

In Colorado, there's this nice balance, you know, like it's still 40, 50, you know, snow comes and melts a few days later kind of thing. So, right, way more manageable. Yeah. Okay, so your travels took you back to California and then Colorado? Yep.

Okay, so why Colorado?

Mostly the mountains. We were, my wife and I were looking for a place to buy a house. We wanted to be able to get into backcountry and we'd taken a bunch of road trips out to the Boulder area and we loved all the hiking and scenery and stuff like that. So on a whim, we just decided to start looking at homes and we got really lucky, found a nice place and moved out this way. And the market was so good that we just figured we'd chance it.

If we didn't like it, we could probably not lose money, but we absolutely fell in love with it. Did you have jobs at the time or did you move out here without jobs? Yeah. So I actually went remote, same company. I had just been working remote periodically throughout my tenure there and I opted to go remote again.

My wife is a psychologist and she had just finished her postdoc hours. So she was kind of venturing out on her own. And it was a good opportunity. You know, at that time she didn't have a huge client base, so we just had to make the move then. Okay.

Yeah. Perfect timing. And then you have— you moved up to the Boulder area and that's, that's kind of where you've been, right? Or have you lived in other parts of Colorado? Nope.

Yeah, we, we driven around Boulder quite a bit and we knew we didn't want to live like right in the city. So we found, you know, it was pretty cool that there's all these little kind of subdivisions or whatever. We're specifically in Gunbarrel, which is, you know, like a mile or 2 northeast of Boulder. That's nice, you know, got a grocery store, a couple of restaurants, and some nice neighborhoods. But it's, you know, we're 100 feet from 10 miles of farmland, which is, which is really cool.

Yeah, yeah, very cool. And I know that, uh, you have, you have one, um, well, you have probably many claims to fame, but one of your claims to fame is that you have been to every state in the US. Is that right? I have. That is true.

How did that come about? Just a lot of road trips. Okay. Like with most things, right? Like you just start doing something and then like you realize that you made it significantly through, so you might as well just finish it.

Yeah. I'd taken so many road trips, you know, through high school and stuff. I was a skateboarder, so we'd, you know, drive to different cities and states to skate different stuff and We just ended up getting through most of the states and I figured I'd finish it out. I still like, I don't like to count Hawaii and Alaska because I was incredibly young when I went there that I hardly even remember it. So I'd definitely like to go to those 2 again so I can like remember something about the state, but right.

Yeah. All of them. So to cross off all of the states then, was there, let's say, I don't know, 4 or 5 on your list at the very end and you're like, let's just hurry and drive through those states and call it good. Or how did that happen? There's actually one, it was Florida.

We were on a road trip and we got to Georgia and we ended up having to turn around. So I didn't get to Florida. So it was, I wanna say it was, I was like 23 or something like that. It was probably like 4 or 5 years where like this one state had just kind of existed that I hadn't been to yet. And I never particularly wanted to go to Florida.

Yeah. Not that there's anything wrong with it. It just wasn't kind of like, my scene, I guess, like the key, you know, Florida Keys and stuff like that. It just wasn't super intriguing, but we ended up finally going with, you know, family down there when I think it was like 22 or 23. Checked it off.

Yeah, very cool. How did you cross off— there's, there's a lot of the states in kind of the northeast part of the US that I've never been to. Like, how'd you do Delaware? How'd you do like New Hampshire? How'd you do some of these weird obscure states that nobody ever seems to To go to?

We like, basically all of New England was a specific road trip for sightseeing. And it's absolutely beautiful up there. Like, especially if you get like the fall and like, you just got these rolling hills of like, you know, trees changing color and stuff like that. So that was a deliberate trip to check those off and mainly just to be able to see the scenery. Oh, nice.

Okay. Like the leaves changing, that kind of road trip. Cool. And then the other— so you've got a couple of hobbies since you've moved to Colorado beyond poker, obviously. You're into snowboarding, correct?

I am, yeah. Where's your favorite place to go? I'm a huge fan of Winter Park. They always seem to have pretty good snow and they've got some good tree runs up there. Yeah.

Have you been to all the different resorts? No. Yeah, I haven't. I'm not nearly as dedicated to checking off resorts as I am states. Okay.

All right. Fair enough. Um, mountaineering, that's, that's probably your main hobby, correct? That is, that is taking up a rather rapidly increasing amount of my time. Okay.

Let's talk about that. Um, how did you get into that? Uh, maybe what is it first, but how did you get into it and, and, uh, and Where is that taking you nowadays? Yeah. So when I got into it, I actually didn't know what it was.

I really just enjoyed like hiking in the backcountry. Like I liked getting off the beaten path, you know? And so I'd drive my truck on an off-road trail until the road ended and then I'd start hiking. And that to me was always fascinating to get out to places where people rarely go or, you know, you run into other people. Right.

So I liked exploring and someone had turned me onto this concept of 14ers, like these really high peaks. And I was like, oh, that could be fun. Sounds miserable, but it could be fun. And so I tried a couple and I found it to be really challenging. There was a lot of things I was learning in terms of like how to scramble and like, you know, bring the right amount of water and food and get off the mountain safely.

And so I got hooked and I just started hiking more and more. And I think after I got through like maybe about a dozen of the 14ers, I started really understanding what mountaineering was, which was, you know, this concept of Like rock climbing, but alpine style. So you make it to the top of these peaks through, you know, various levels of difficulty. You know, you've got a class system where, you know, your normal hike is like a class 1, maybe. Tough hike might be like a class 2, and then you got 3, 4, and 5.

To get to some of these peaks require a level of technical skill in terms of like climbing. That was really intriguing to me. So I started rock climbing. I started running. Started, you know, weightlifting.

So I went through this whole like investment into conditioning myself to be able to make it up these mountains and, you know, hike further and harder. And it's been pretty exhilarating. Yeah. Yeah. And you have, you have hiked at this point about half of the 14ers in Colorado.

I think you mentioned one time to me. Yep. Just under half. I think there's like, depending on like what you look at as the source. I think there's 54 or 58.

Um, my goal is I'm trying to go for all 58 here within a year, and I've gotten through, I think, 20 now. So, okay, so in 2021, like this calendar year, you're going to attempt to do them all? Yeah, well, so I started at the end of July of 2020, um, hiking, and I got through 20 of them Well, I got through 18 of them by like October, and then I took a couple month break, uh, to condition and let my body heal a little bit. That's a little rough on it. Yeah.

Um, and then I've got 2 winter summits, um, in the last couple weeks. So I'm now back into like summit mode. So my goal is to finish them out by roughly July. Wow. So how many more do you have to do by, uh, by July?

Yeah, like 30 of them. That's the point. You're— I was gonna say your dog is excited to go with you. Yeah.

Um, wow, so you have 30 to go in, um, all right, let's see, we're recording this in March, April, May, June. You got like 3, 4 months to do 30. Yeah, the— so the other thing to keep in mind too is what a lot of people kind of forget or don't realize is that a lot of them are together. So like there's a total of 3 trips that I have planned that is going to account for about a dozen of them. Oh, 12 or 13 of them.

So if you think about that, in like a 2-week span, I'm gonna knock off half of them essentially that I have left to do. Um, so you do 4 in one trip and like you set it up so you camp and then you do like a couple-mile summit and then another couple-mile summit and you're done with 4. Yeah, yeah. Are you able to, uh, to actually work while you're doing any of this? Or are you completely disconnected?

It's a little, it depends. I will tell you when I did Elbert, which is the highest peak in Colorado, I set out to do that one and I'd taken the day off and something urgent came up at work with like a customer call. And they had some questions for me around like security and compliance. So when I was on the summit, I had a video call with a bunch of folks from my team. On the side.

And apparently, like, when you're that high up in the air, like 14,000 feet, you've got line of sight to a cell phone tower pretty much anywhere. Wow. Yeah. We're, uh, so did you have video on? Were people able to like see where you— that's, that's pretty hilarious.

I was, uh, in this little kind of like walled-off area of rocks, um, and it was, you know, pretty close. And about 5 minutes in, uh, someone asked like, hey, where are you? And so I panned out with my phone and I was like, well, I'm technically the highest thing in Colorado right now. Wow. Yeah, they got a kick out of that.

Yeah, yeah. I have never been on a call with, uh, somebody at the summit of one of the peaks. Yeah, now I've got something new to, to potentially check off as well. I'm not— I don't think I'm gonna do the mountaineering, but yeah, well, maybe we'll hop on another call here in a couple months and I'll dial in from the top. Let, let somebody else do the mountaineering.

I'll just be on the video call. There you go. That's funny. Well, hey, let's, um, let's talk about, uh, security and tech and, um, how did you— what's kind of your getting into the industry story? Um, so security specifically was always kind of a passion of mine.

You know, I'm, I'm one of those folks that, you know, I was like a nerd, uh, hardcore when I was younger. And like, you know, winters in Minnesota, like I would tear down computers, I'd rebuild them. And over time, you know, when, you know, the internet started getting really popular, this notion of security was kind of where like the deviants ended up, right? Like the really curious people got tired of breaking the computers and rebuilding them. They started looking at like software and how you could deconstruct it and find holes in it.

And then it always appealed to me. So I'd always kind of like kept up with it. I started going to DEF CON. We'd road trip out there every year and that really kind of pulled me into that scene. And then fast forward to California, I kind of broke into the tech industry out there and I was working at a consultant firm and doing a lot of like Windows environment sysadmin kind of stuff.

And we had a couple customers that were having some security issues. They needed to do some forensics and some coworkers knew that I was particularly interested slash skilled in it. And it turned out really quickly to become a branch of the firm I was at. So we started doing more of it. I started developing skills and researching more and then went on future jobs to do the same thing.

And then kind of ventured into leadership and ended up where I'm at now. Okay. So did you actually start in, in really the security or tech space before poker? No. So I got, when I got to California, like I said, I took my bankroll.

So like the amount of money that you play poker with, right? So you've got like several thousand dollars, then you take a little bit of that at a time to sit down at tables. Why? And you never touch that, right? Because that's your livelihood.

If that goes away, then you don't have anything. Well, I decided to quit. So I took that bankroll and that's what paid for the move out to California. And I just got a job in sales, like telemarketing kind of stuff, like typical kind of college-style job when I got out there. And I worked that for, I don't know, maybe like a year, year and a half.

And then I started working for a like onsite, like small business computer support company. Okay. And that, that small business computer support company, was that LanSpeed? No. So that was Make It Work.

It was like these little red Mini Coopers you drive around. It's a pretty cool gig, but no, LanSpeed came after Make It Work. That was the consultant firm that kind of broke me into the security space. Oh, okay. Okay.

So you're driving around little Mini Coopers, you're fixing people's computers. Is that basically what it was? Yeah. Awesome. They tried to keep me there.

I mean, I give them a lot of credit. I'm one of those people where like, I just, I've got to be challenged and, you know, fixing computers, like removing malware was like, that kept me busy for about 3 hours. So they ventured out from, you know, started doing small business support, stuff like that, but it was still not quite the challenge I was looking for. That's what kind of led me over to LaneSpeed. Okay.

And then at LandSpeed, that's where you really pivoted from just kind of the tech industry to security, right? Yeah. I mean, that place was really cool. The owner, Chris, is still a good friend of mine and we talk every so often, but he really kind of unleashed me out to the world. So he let me venture really deep into Linux and supporting and maintaining those systems, like security.

So he really did a great job, I think, of fostering and keeping me challenged and allowing me to grow. But yeah, that's what really sent me rocketing into the security space. Okay. And you haven't looked back. So, so that's good.

Yeah, it's, it's a really fascinating space for sure. And yeah, tech in general moves very quick. But security is like alarming at the rate at which it evolves. Yeah, yeah, it's, it never slows down. That's for sure.

So your next gig after that was RightScale.

Tell me about that. Is there anything notable or interesting? Yeah. I mean, so I actually came in there to do a little bit more on the tech side of things. So I started there to virtualize their telecom system.

So I'd done a lot in telecom too, which is this weird sidebar. I hate talking on the phone, which is really interesting too. I love telecom. That's funny. But yeah, so I started there and I virtualized the system and kind of the tail end of that project, the head of security over there got to know me a little bit better and had some challenges there.

He was trying to find where there was vulnerabilities in the platform there and stuff. So I kind of went to town working for him at that point, just punching holes in our platform there. And I filed a bunch of bugs and Kind of filled up a backlog and then he kind of turned me loose on like third parties that we were using, you know, being a modern SaaS company, we use Google and these other ones, but I ended up actually finding a bug. It was like an auth bypass in Google Groups. So I was, I got on the Bug Bounty Hall of Fame for Google and got a check from them for filing a bug with them.

Oh, that's pretty awesome. So how did you find it? So I was, I was tasked with doing a phishing, like scam essentially, like, you know, we would go through and like phish our internal employees and like figure out like how, how well are folks, you know, kind of privy to this. And this was quite a long time ago at this point. It was probably like at least 10 years ago.

So it was still kind of new, but one of the things that I wanted to do is be able to send like a valid email. And what I figured out quickly, it was like the standard, like if you just spoof an email in, like Google did a pretty good job of throwing up the spam warning. And I knew that was going to demolish the click-through rates of the phishing email. So I set out to figure out a way of getting in. And what I found is if you had 2 different organizations in Google, you could populate Google Groups with your recipients and you could send it like by spoofing it or whatever, and it would bypass any authentication whatsoever.

So if I sent it as you, it would actually just hit, I don't know if it was like a backend set of SMTP servers that Google had or what, but it would go back there and it would validate it at that point. There was no authentication. I didn't have to log into an account or anything like that. And then they would send it through and it was so bad that they would actually take your Google picture, right? And they'd apply it to the email.

So like they went, invalidated the email even better by sending it through. So, you know, we had like 98%, you know, click-through rates on the phishing email. Oh yeah, yeah, that, that definitely sounds like a pretty serious issue. I'm glad they, um, they addressed that. Yeah, and it's kind of tough, right?

I mean, because you, you have to deal with the complications of, you know, sending mail because, you know, sometimes you're sending it from a laptop, you know, sometimes you've got application servers. And I understand the the difficulty of kind of fixing that problem and applying trust and authentication around, you know, email accounts. But yeah, it was pretty bad. Wow. Okay.

So after RightScale, that's when you joined your current company, Invoca, right? Yep. So what— let's talk about that. You've, you've been there for quite a while. What's, what's your role and responsibility there and, and some of your challenges?

So I am the senior director of infrastructure and security. So I started there as, I guess, just an ops engineer. You know, it was really early. I think there was only like 60 people in the company when I started. Okay.

So I was kind of just like the token tech guy at that point. Yeah. So you've seen it grow quite a bit. I have. Yeah.

And I have to say, I've thoroughly enjoyed it. For me, you know, solving problems in new innovative ways is is what I love. And starting there, you know, we quickly started running into security and compliance-related situations with our customers. You know, we've got a growing number of, you know, enterprise customers, and, you know, they have questions, you know, they have concerns, and they have, you know, vendor reviews they have to do, you know, they have to make sure that we, you know, meet certain levels of security and compliance standards. So I started jumping in more and more to these kind of conversations.

And at the same time, I kind of stepped up to build out the first SRE team. So we moved from ops over to site reliability engineering, and I stepped into a management role and with it kind of took the security aspect as well. So yeah, I've had the ability to kind of grow from the ground up these teams. And I have to say, like, I'm pretty proud of, of the teams, particularly the SRE team, you know, if you look at the headcount that we have compared to a lot of comparable companies, you know, we operate and get a lot more done with maybe a third to a fourth of the headcount. We've focused heavily from the beginning on automation and this concept of, you know, shifting left, which is a big thing in security that you're hearing now, right?

It's like shifting that left. We had that mindset kind of from the get-go, which allowed us a pretty cool edge. Yeah, yeah, that's very smart. And so for, for listeners that are not aware of what Invoca does, can you explain what you guys do? Yeah, so we are a call analytics company.

Um, I think the easiest way is to think about like a big company and you have someone that's, you know, marketing, uh, your product and you're sending out all these, you know, advertisements to people. And a lot of time with considered buys, you know, if it's something that's significant, whether it's, uh, really expensive, you know, built-in like barbecue system, uh, or, you know, like a car, you typically don't just go to a website, throw it in a cart and check out, right? Like you usually have questions and you want to, you know, get some more information. And oftentimes what happens is some marketer pays some amount of money to send, you know, some ad to you or some, you know, kind of advertisement that, that gets you interested. And then you call in and when you call in, you lose that that attribution, you lose that tracking.

So the marketer doesn't know if this ad's working, if that one's working. And what we do is we bridge that gap. So we step in and we allow them to kind of tie their marketing dollars to the actual conversions. And then meanwhile, we're doing a lot of really cool stuff now with machine learning to help give some additional, like, conversational intelligence, allowing folks to get more insight into the calls that are coming into their contact centers and how to optimize those better. That's very cool.

So where do you see this going for you over the next, I don't know, say 5, 10 years? Where does the technology, where does the security evolve to within, let's say, not just for yourself, but for Invoca? That's a good question. I think one of the things that security is not particularly great at, and we haven't learned from the wider tech industry yet, is that it's really paramount that people understand it, right? It became really obvious, like with personal computers, that like people didn't know what they were or how to use them, right?

So the market was very niche until we taught the world how to use these things. And I think security is struggling with that right now. People don't understand it. They don't understand, you know, their role in securing themselves and by extension then the company and instituting best practices, drawing lines between how their car or their cell phone can compromise them or their family or their companies. So that kind of shortcoming, I think, is if I had to wager, the next kind of iteration is over the coming years more on that.

We need to create more solutions that help level people up to do the right things from the get-go. And then also zero trust. I think you're seeing a big shift in the security industry now where we're shedding these kind of old ideals of setting up these huge super structured walls around our environments and trying to keep everyone inside of them. COVID quickly bulldozed right through all those walls. We immediately realized that the world is a vector and we need to just deal with that.

So you're seeing a lot of companies now, I think, shifting to ensuring that you have strong contracts between services. You've got strong authentication authorization. So I would expect that we'll see a lot more of that shift. And I'm particularly interested in that. I love helping people and I love setting up systems that are resilient.

So if someone compromises an application server, it doesn't compromise the company. So building that resiliency into systems is something I've really, really enjoyed doing. Yeah, and I like that you use the term level up people. I think that's a great one. And I know that some of your passions in the security space are, you know, you consider yourself a red teamer, right?

Yep. And your passions are STEM. And in fact, you've actually organized a capture the flag event in the past. It's true. So you're definitely trying to level up people.

What made you organize a CTF event and how did that go? How did that come about? Um, yeah, it was honestly a little selfish if I— Okay. Yeah, no, that's fair. So we, um, what I found really quickly, um, hiring in, you know, site reliability engineering and security is really difficult, right?

To find talented people. And it was really tough to build a pipeline and I needed to hire a security engineer and we had this idea like we can, um, put together the CTF and get our kind of name out there and at least have the folks that are in the security space. At this time, it was in Santa Barbara, so it was a pretty tight-knit tech community, but we could establish ourselves as like a security company, and that would allow us to hopefully attract or better attract some of the security talent there. So we set out, me and a coworker at the time, Jimmy, put it together and it was wildly successful. It turned out incredible, um, from the get-go.

So it just became something we did annually. Um, we didn't do it, um, this year. Typically we have it in February, um, but we are looking at potentially doing it in the fall and moving into virtual. Um, that's something I want to do anyways, you know, open it up to more communities by going virtual anyway. And the one thing I think that was particularly successful about our CTF is that we had a really cool gradient.

Um, we had very easy challenges, so someone could come in with literally no experience whatsoever. Yeah, we had literally the, like, junior team from Shellphish, which if you're not familiar, that's the UCSB information security, uh, red team. So they go and compete and have won, you know, the capture the flag at DEF CON a couple years. So they came in and, you know, They destroyed the challenges for sure, but they kept busy for the couple of days that we had it. So it was a really cool spectrum.

It was really open and available for everyone. We had lock picking and stuff like that too. Yeah. That's awesome. So you're going to, you're going to keep doing that then?

Yeah, absolutely. Do you put that on the calendar for Colorado Equal Security so that the community is aware of it? Not yet, but like I said, the, because it was in Santa Barbara, like we'd filed there, we didn't have anything virtual for folks. But as soon as I moved out here, I immediately wanted to start looking at doing it virtual and bringing it to this community. So absolutely, when we get some more details, I'll be shouting from the mountaintops.

Yeah. And, you know, it's funny, obviously virtual, you can do it anywhere, but if you ever do one that's not virtual, I'm sure there's plenty of people in the community that would, that would love to be a part of that and help out. Oh, for sure. You know what? This is something like I'll throw out there too.

Back on the STEM topic, one of the things that I think is pretty unfortunate is like we have a hard time exposing security to kids, you know, getting them interested in the field. And I thought it'd be a really cool idea if we created like a dumbed-down, like 3 to 4 hour version of the CTF, where you had just like a set of maybe a dozen challenges, and like a progression through that we could then kind of go on the road, we could give it to like computer science departments, or we could even come in and kind of host a few-hour event for them so we could get, you know, more kids interested in this concept of computer security younger and, you know, hopefully in turn get more into the field in the coming years. So if anyone's, you know, knows or has, you know, aspirations to break in there— I don't have kids or, you know, really understand much about them. So yeah, yeah, um, yeah, I'll have to put some thought into that. Maybe there's, there's some people I can connect you to to actually, um, make something like that happen.

That's a, that's a great idea, though. I will say that. Yeah. Yeah. So let's— we're kind of coming up against the time.

Any shoutouts to any mentors that you've had in life or, or mentoring that you're doing these days? Yeah. I mean, I've had, I've had a pretty fortunate run, I think, at companies. Like I said, you know, Chris Sherwin is the CEO and owner of Lane Speed, and he was always first to open up doors and expose me to new technology and keep me challenged. And he was pretty awesome.

And then I worked for Phil Cox at RightScale and he was awesome at just giving me new ideas. I think honestly, one of the most impactful folks recently though is Colin Kelly. He's the CTO of Invoca and he's probably responsible for a vast majority of the growth I've had from a leadership aspect over the last few years. He's been a huge influence in keeping me on my toes and kind of adjusting my expectations, you know, for, for growth, translating, you know, those kind of impacts and the level of effort needed for change as an individual contributor versus, you know, a manager and moving on to a director is very different. And he helped me navigate that, I think, quite well.

Very cool. Very cool. It's always important to have mentors in life. And so if anyone's out there listening, You know, find yourself some, find some, find some people that are, that are willing to, to give you advice and some mentorship. And, and you just have to ask.

Usually a lot of people are, are definitely open to it. So you are on the Colorado Equal Security Slack channel, correct? How do people find and follow you on social media? You can follow my mountaintop adventures if you like. I have a I'm very like streamlined with my social media.

Like the only thing I put on there is like climbing mountains. That's pretty much it. So Instagram, I'm on there. I post, you know, folk for family and friends and stuff like that. So they can kind of follow along.

I mostly use social media because I don't like telling stories multiple times. So I can go through and post my kind of like trip recap of this mountain. And then like everyone just sees it and they don't have to explain it to, you know, family and friends like 12 times over. But yeah, so it's Jameson Brown on Instagram. I'm on Twitter.

I don't really use that much. I think the easiest way to reach out if you have any questions or get ahold of me is either through Slack or LinkedIn. Right on. Very cool. Well, thanks for joining me today, James.

It's been great to catch up and hear kind of your story and evolution of your career and Good luck on the poker stuff, but not too much luck. Yeah, thanks. And yeah, I will, I will catch you later. That concludes my interview with James Brown. Be sure to follow and support Colorado Equal Security on Patreon.

This is Jason Jaques saying be safe out there.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Equals Security.

Back to all episodes