Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is a special newscast. It's not even really a newscast here, it's just a special podcast because Alex and I were on a, on a panel at SecureWorld last week out at the Cable Center.
Hopefully some of you were there. I know some of you were there, but those who weren't might want to enjoy the, the interview that we did here. I had the opportunity to moderate the panel and we had a few great guests on there. So you guys can listen to that interview in its entirety coming up here, and then we'll be back with you in just another week or two with the, the October episode of the podcast with another interview. So enjoy.
This is Larissa Thomas, CISO at Knox Health. Welcome to Colorado Equal Security, or Colorado Security Welcome to Colorado Equal Security closing keynote. This is our, one of our very rare podcast recordings that we're doing on the road. Usually we're recording from the headquarters of Colorado Equal Security in our very exclusive studio, but today we get to come out and join the folks here at SecureWorld. We're gonna talk quite a bit about career pathing, what it looks like to move up in your career, not necessarily resulting in a CISO.
What else is out there? As we get going, we gotta get to know who our other panelists are, and they come from a really, a variety of different perspectives. We're not gonna just have a bunch of groupthink. Anyone who's ever listened to me and Alex talk before, you know we love to disagree, we love to find ways to have different perspectives, and that's what we're here to do today. So as we do introductions, as you get to know the other panelists here, I'm asking them to tell us professionally, like a little bit about your own background, but also as a part of this, I want you to tell us an example of a person who you've known who's come up into a leadership role within the security space or adjacent to security, who maybe came from what you consider to be a non-traditional path.
So why don't we just work, you know, we got everyone sitting under their picture. Let's start over at the end with Frannie and work back this way. Okay, we're gonna do the domino to start out. Yes, ma'am. Okay, so I'm Frannie Matthews, President and CEO of Colorado Technology Association, and my background is that I have been in IT, mostly large tech.
I worked for IBM for 18 years, and I was running sales teams. And so now it's 5 years in on leading the Colorado Technology Association. So if you look, I'm different than everybody else on the panel. So one of these things is not like the other, but not in the same way, because each of you are technologists in security, and I am a generalist in technology. I think one of, you know, when I was thinking about the question of who came up from a nontraditional path, a friend of mine is VP in security for Bank of America.
She was a bartender.
She does have a 4-year degree in a non-security-focused environment. She also did curriculum for teaching. And so I think there's a lot of opportunity for having general exposure in many ways that will put you into a path for you know, great security career. Cool. I thought you were going to say that you were the one with the best head of hair amongst all of us here since we're all receding and going gray here.
That's true. I'm the one that spends the most money on my hair. Some of us are beyond receding, but that's another story. But no, so I'm Richard Stanings. I'm honored to be a professor here at DU.
I teach master's programs in ICT, health informatics, and healthcare management. So if any of you are interested in doing a master's, come see me afterwards, right? I don't have discount codes or anything like this. This is after— this is DU, right? So none of that here.
But I also am chief security strategist at a biomedical startup by the name of Silera. It's a New York-based company that is using a lot of advanced technology to really change the security of medical devices and IoT systems, right? A lot of AI. Which those of you that were in my presentation earlier this afternoon would have probably got an earful already and probably not going to sleep too well tonight. But, you know, there's a lot of new technologies that we're implementing in order to orchestrate and to automate and seamlessly integrate with the existing technologies in the space.
I have— I've got a background as a CISO, CIO, CTO, and a couple of other C-level jobs as well. Which I can't even remember what they stood for at the time. But anyway, I survived and came out the other side. Before joining Cylera, I used to lead Cisco's global healthcare cybersecurity group, which had me follow our then-president John Chambers around the world to, you know, as he went and met with presidents and prime ministers and princes and sheikhs and sultans and everyone else at the top of the stack in the local country. Told them about cybersecurity, and it was my job to come in and actually prove that, yeah, we could do it, right?
You know what John had said. So my example, back to Robb's question here, is in a previous role, I was working as a consultant in a health system down in the south of the country. I won't mention too where, too close. And I was assisting the CISO down there. To implement this newfangled thing called multifactor authentication and strong authentication controls across the hospital, much to the disdain of the medical staff that hated the idea of that whatsoever.
Their idea of logging into a system was a 4-digit number. And if it was 5 digits, then they couldn't remember it. And if they had to change it, then everything stopped in the hospital. It was that kind of era. This is early days of HIPAA.
One of the guys that I was tasked with working with had come— just started at security, and he'd come in from desktop support. Rather large gentleman, as the South is renowned for. And this guy had basically dropped out of school, had done very little, and he was just jacking around in IT and had been offered a job in cybersecurity. He and I were traveling around the state, to various hospitals working together. And I obviously planted a seed in his head about, get yourself— get your degree, right?
Get some certifications, get some qualifications, right? You could go far. He was a really smart guy, but he was just bored. And during the course of about 6 months of us traveling across the state to various hospitals, this guy would load up the trunk of my rental car with massive manuals you know, for, you know, from ISC² and ISACA and ISSA and everything else, right? And GR and SANS GIAC.
And he proceeded to accumulate about 12 qualifications in the space of the 6 months I was there. He also signed up for his bachelor's degree and completed that, and at the same time was working on a master's degree. Don't ask me how he got in on the master's program. And then towards the end of his master's degree, He also managed to get himself an MBA. Super smart guy.
And he went on to become CISO of the health system and was very successful. But this is obviously a guy that came up from a very nontraditional background. He got married at 17 and had kids and had never really thought about his career until he met me. So then it was all downhill.
Awesome. Thanks, Richard.
Hello everyone. Alex Wood. I'm the Chief Information Security Officer for a company called Uplight. We make software for the utility power industry to, among other things, help decarbonize the power grid, which I think is pretty cool. I've been doing information security and IT and technology for 20-some-odd years now across a lot of different places.
I've been in telecom and healthcare and oil and gas and lots of other verticals, but kind of all centering around information security and cybersecurity. Also the co-host of Colorado's best podcast, Colorado Equal Security.
And I think, so the story that I have related to someone coming up in a non-traditional way Several jobs ago, we had an intern program, and we ended up hiring an intern that was a career changer. And in talking to her, we discovered that she'd originally done some work in technology earlier in her career, but then decided that she wanted to go back to school and get— she got her PhD in biology and was doing, I believe, genetics research. And did that for a number of years. And then when one of her children was getting ready to go to college, she was trying to convince him that he should go study cybersecurity. And as she was doing this, she had this epiphany that she was trying to convince him because that was what she wanted to do.
And it was something that she had found always fascinating and interesting to her. So she again took a pivot, sort of started back at the beginning, did a boot camp, got this internship with us, And then went on to have a great career so far. And now she is running the privacy program for a software company here in town, doing great stuff. And so I think, you know, people can come from anywhere to come into this industry, which is great. Yeah, love that.
I asked them to tell the story about folks they know who've had kind of a non-traditional path into security roles. Because I think it is so important that we understand that there is not one right path. There's not even 10 right paths. There's an infinite number of paths that can lead to great places. And as a, myself, a little bit of an intro for myself, I'm currently just Colorado Equals Security co-founder.
I don't have a job. It's been fantastic. I took the summer off. Previous to that, I've run security at Red Canary, Ping Identity, Pulte Financial, some other companies before that. In those different roles, I've hired a lot of people, and I'm going to give you guys like my biggest tip.
And if you— anyone familiar with Moneyball, the movie and the book about the early 2000s A's, looking at what they did? You know, if you're a baseball fan, and I was a pretty big baseball fan at that time, what the A's did is they would, they would go sign players that had really high on-base percentages, not a lot of home runs, not a lot of RBIs, and like people might have thought, oh, the magic is they're trying to get this high on-base percentage. Now the magic was that the A's were finding people who were undervalued by the market. And we live in this space today where people with an experience in a security role, if you got security on your title at some previous role, you're overvalued by the market. That's my perception.
And there are all kinds of other people who are not overvalued by the market. So as a hiring manager, my Moneyball play, and this is my advice for anyone hiring, is Go find someone who doesn't have security on their title who's really good at the thing you're trying to secure. If you're trying to secure your cloud, go find someone who knows how to work in the cloud. If you're trying to secure a network, find someone who's great at the network. That person who knows how to use the system, they can easily be taught what are the concepts of security that we're trying to enforce.
That's my concept from Moneyball. Until everyone else figures it out, it still works, right, until the market equalizes there. So all these examples they give, these are folks who over time, if you identify them at the right part of your career, you could have hired a great person to work on your team for less, competitively less money. Over time they build a great career, you build a great team out of it. So let's talk a little bit about what it looks like to move up in your career here in security.
So my next question, and we're gonna start with you, Alex, is what does career advancement look like? And does this necessarily have to be a people leader, an individual contributor, entrepreneurship? What does career advancement even look like? Yeah, and I think that's a great question. And one of the ways that I think about it is a lot like what you said about path into security itself is I don't think that there is a right way or a wrong way to advance.
There's lots of different ways that people can choose. Sort of in my own mind, as I was earlier in my career, I was much more technology-focused, individual contributor, and there was sort of this perception that you had to— the best path forward was to continue to be a hardcore technologist. If you did anything outside of that, you were kind of selling out. Right? Like, oh, you're gonna go into management?
Sorry, sellout, what are you doing? And so, I think I personally pigeonholed myself a lot earlier in my career by, I guess, sort of delaying the inevitable of moving into more of a leadership management kind of role. And maybe I would have done that earlier in my career if I wouldn't have sort of had that that stigma, that idea in my mind.
But one of the things that I have seen also that I think has been really important also is that many times you get to a certain level as a technologist and you hit the top level, right? Like there's nowhere else that you can go. So your only choice is now to go into a program or a management type position. And some of the companies that I've worked for more recently have been more thoughtful about that in thinking about what the levels for technologists are. And so, as you move up, there are ways to continue to still be a technologist and be very technical, but not necessarily contribute the same way as someone earlier in their career.
So, I think Finding someplace that values that and has a path for people in both technical and non-technical careers, I think, is important. Richard, I'd love your perspective, especially as a professor and as an executive. What have you seen? Well, of course, as a professor, I'm pitching here higher education, so all of you can all sign up at DU here for courses. We have— yeah, no, I'm not going to go down that path, but you know as well.
I mean, so there are— you know, when I started in this profession, cybersecurity wasn't a word, right? When all of us started here, cybersecurity didn't exist. We were risk managers, we were information data managers, we were, you know, compliance people, right? And slowly this profession has emerged out of the combination of discrete skills, right? People that had networking expertise, that had compliance expertise, that had GRC expertise, right?
And we've come together to kind of build out the profession that it is today. So it's an emerging profession, and there are many, many ways into it. And still today, the vast majority of people that come into a cybersecurity profession come in from the side. They come in from, you know, a risk management or a networking or a cloud IT perspective, or maybe even a policy perspective, right? Or a governance perspective.
There's lots and lots of skills here. It's no longer the nerdy technical pen tester type role that it was perceived to be 15, 20 years ago. So I'll give you an example of my earlier career. I spent many years at PricewaterhouseCoopers here in Denver. And PwC, after the merger between Coopers Lybrand and PricewaterhouseCoopers, decided that they were losing a lot of top talent in the IT and cybersecurity space that didn't want to become partner.
The career progression in the Big 4 was a partnership, right, where you buy in as an equity partner and you, you know, work your buns off and you earn vast amounts of money and get to play golf every Friday with customers, right? But there were a lot of people that didn't want to do that. They wanted to develop deep technical expertise in different disciplines. And eventually the company recognized they were losing these people. Because they were on a different career path than what had been prescribed by this partnership model.
So they created a role for individual contributors that could be at the top of their game, could make seriously good money, but not have to play golf on a Friday afternoon with customers, right? That they could read journals and do things that they were interested in and that their role was more interested in. And I think, you know, there's some lessons to be learned here. I have— I've risen up through the ranks. I've hit the C-level titles and I've come back down again now, right?
Because being there, you know, getting the war wounds and the t-shirts and everything else is not something that I'm really interested to do. And to be honest, if you want to be a CISO, it's a very, very stressful job today, right? You can read online about CISO burnout and it's phenomenal. It's a wide widespread problem, particularly if you're in a particularly operational role, right, or a risky company that's not investing in a big enough team and big enough tools, because you're the guy whose head's on the block. The block, you know, stops with you, right?
So I think there are many options here for people that want to either go up and come back down again and contribute in an individual way, or individuals that don't— aren't interested in leadership, who aren't interested in talking to executives. And a lot of good cybersecurity people may not be good leaders, right? And good leaders may not be good cybersecurity people. So I think you have to recognize where your strengths lie and channel your career progression along what keeps you happy at night, right? What helps you to sleep, right?
Because I didn't sleep much when I was a CISO, right?
If you have anything— New question, or you want me to— Do you want to? Yeah. I mean, you know, just in general, I think, I think you give great advice on, you know, what makes you happy, whatever. Yeah. And I, you know, follow your bliss, blah, blah, blah.
You got to pay the bills, you know. But the reality is that you tend to be really good at something. You're a DU student. I didn't say that, by the way.
You tend to be good at at things that you love. And so I think that— I think from a career path perspective, it's almost the paradox of choice, because you can go down different paths. And I think sometimes I talk to technologists, they get really worried, I'm going to lose my skills if I go down that path. But it's not like you can't jump branches. And the technology is changing so quickly.
So I think— I want to talk about durable skills because that's what I hear most from employers, that they want curiosity. Curiosity is the number one thing that I hear. They want problem-solving, critical thinking skills, knowing what's going on in a room. And so if you've got the base technology capabilities and you have those durable skills, it's really a very powerful combination. Package, but you, you know, you don't see that necessarily on job descriptions.
Yeah, I want to— I love to disagree. I'm not going to disagree with Fran, I'm going to disagree with Richard just for a second. You— I think you're conflating leadership and management as you, as you were giving your answer, and I think it's really important for us to look at career development to probably become some kind of a leader. That could be a technical leader who's leading you know, us to, you know, adopt new practices. This could be the person who, who first introduced us to the cloud or is now currently introducing us to how we can use generative AI in our organization without them having a team underneath them.
It can be the— because, because they don't want to manage people because managing people sucks. Like, I'm not saying it does, but maybe it does. It sucks. It sucks, especially at appraisal time of the year where you got to write 140 appraisals and come up with something original. For all those people that— well, this is how generative AI is so useful in the workplace.
Exactly. Exactly. Okay. Okay. I'm going to— I'm going to sidebar on this.
We were on a panel together in February, and he admitted he wrote a poem to his wife for Valentine's Day via ChatGPT. I did tell her. I did. I told her she wasn't going to get a poem without ChatGPT. It was pretty good.
It wasn't like you could have the heartfelt one or the computer one. Did she say it was much better than— Oh, it was much better than I would have written, for sure. So acknowledging that, hey, part of career advancement is taking a leadership role of some kind, right? A leadership within your discipline. I'd love to hear your guys' perspective on what that might look like other than running a team.
Have you guys seen examples of that kind of leadership? It looks like Franny wants to talk. Please. Please talk. Yeah, I mean, it's interesting because I have been in situations where I have positional leadership.
And it makes it a lot easier to sometimes say, we're going to go this direction, because you've got a title associated with it. But I think the team leader, even individual contributors that know what the job is that you're being asked to do, and then you're able to fan it out and have— Culture is really— it's a participatory sport. And if you're showing up in an enthusiastic, hey, what if we did it this way? You are, in fact, a leader. You're influencing everybody around you.
If you show up and just check the box, that's not helpful. But I don't think there's any— in the hierarchy, I don't think there's any leader that doesn't love somebody that understands what their mission is and then does this to help other people do the bigger mission. Yeah, I would add to that, do what makes you happy, right? Do what motivates you, right? What are you motivated most by?
Is that building a big team and being the big boss and getting the corner office and the dedicated parking slot? Or is it a thought leadership role or a technology leadership role? Right? There's lots of options in cybersecurity. I would advise you to pursue something that makes you happy, quite frankly, because you're going to do it for a long time.
At Uplight, for example, we have 5 levels of— well, of many job types, but of engineers specifically. And that top level is a principal. And part of being a principal, it's defined in the behaviors of that role that you are a technical leader, right? Like, your job is to do those things that you were talking about, Robb, to bring in new technologies, to advance those, to push them out through the organization, right? You're the one that is coming up with what is next, the things that we need to be using, where we need to be going.
So anyone that's in that position, That's the expectation when you go into it. So you know if you're gonna get there, that's part of what you have to be doing. Yeah, that's great. All right, Frannie, I'm looking at you for this question. Those of us who do security, our skills are mostly transferable across different industries, right?
Alex mentioned that he's run security programs in oil and gas and healthcare and financial services.
That said, having, even though it's transferable, having really good in-depth knowledge in your industry is a really good way to differentiate, right? As an oil and gas person's looking to hire a security person, they'd love to have someone who's done it somewhere else and they can bring in best practices from a competitor. As you look, lots of folks in the room here who may be looking for their, to plan a career path, what industries are going to be strongest here in Colorado over the next, call it decade? Maybe however far out you can kind of see what's going to be growing here for us. Where should they become excellent?
Yeah, a few things I would say is that we just did a study last year, and so Colorado is one of the most— it's the second most concentrated tech economy in the United States. The first is Massachusetts. What I mean by that, when you look at all the jobs that are available, You know, what a high percentage is tech-related jobs. That's one way to slice it. The other way to slice it is where are the tech jobs?
And so if you look at industries, 66% of tech-related jobs are outside of technology industry, you know, vertical. So I say that because tech is ubiquitous. And so, in Colorado in particular, there's a lot of different choices. I think you look at it— am I cutting out? Is this a little weird?
I'm not sure. You're just spitting in the microphone.
Hey, I'm close enough to spit on you, so be careful.
So, you know, you look at telecommunications. We were the world wide capital of cable. And as a result, we've got really strong telecommunications. Oil and gas is declining. Clean tech is increasing.
And so healthcare is, you know, we all get sick. We all— and we need more automation and we need more security. So those are some of the industries. But I think the ability to go from one industry to the next with your technical skills, if you've got a backpack full of durable skills, you kind of have your ticket written. Yeah, I would just add to that, if I'm allowed to comment here, Robb, is that, yeah, you need to, you need to look at the regulatory compliance framework, right?
So if you're in, if you're in oil and gas or electrical distribution, you need to understand NERC CIP, you need to understand the regulatory framework. You need to understand safety, right? Because that's a really important part of that particular industry. If you're in healthcare, you need to understand HIPAA, and you need to be able to speak the language of the business people that you're working with, whether that's doctors or whether that's hospital CEOs, right? They— if you come in from a different industry, you need to be able to pick up that dictionary and understand that that mass of terminology, right, in order to be taken seriously, really, right?
But if you were in oil and gas and you were primarily in— or you had a lot of IoT and OT experience, that leaping into healthcare, leaping into telecommunications, you know, that specialty— a lot of the principles are the same when you're talking about SCADA devices, right, versus, you know, medical devices or That are IoT-based, right? So a lot of the principles are the same. You just need to pick up the nuances of those particular industrial concerns, right? I wound up getting a telecommunications master's because I was working in the network and did not understand anything they were saying. And one of my customers said, just take a class.
Just take a class. Cool. Yeah. Cold storage.
As you talk, a little bit of, hey, it's transferable, it's not transferable. Here's my take. Yes, it's transferable. But you'll be able to get a job moving between industries. But do you want to get a job, or do you want to get the best job?
And the best job is competitive. The best job, the one that all the best people want, if that's the one you want to get, the more specialized you are, the better. If you can walk into that healthcare organization and you quote HIPAA, that matters to those folks. And if there's a difference between you and the person next to you, that difference could make it— could be it, right? So if you know what industry you're interested in and you want to get the best job in that industry, be specialized there.
Being broad-based, yeah, you're going to get a job. There's plenty of jobs. But if you wanted the best job, I think you want to be the best for that job. I'll just add one point to that, is that is really industrial cross-pollination, right? Spent many years leading security at a large financial services firm, and I was able to bring into healthcare, when I came back to healthcare, a lot of the technologies and the principles and processes that we used in financial services, which admittedly was 20 years ahead of healthcare at that point, and to, you know, kick healthcare kicking and screaming, you know, into, you know, the 20th, 21st century, right?
So I think there's that cross-pollination can be very valuable, right? Yeah. All right, I'm going to combine for our panelists. I'm going to combine 4 and 5 as we have— we don't have a ton of time left. Um, I wanted to talk about the role of formal education and certifications, and I know they're not the same thing, but I'd love to hear you guys' take on, you know, how important are these?
You know, how important is getting that bachelor's, that master's degree? You know, even, even further than that, what certifications matter? Is it Is it just early career that it matters? Is it important later on? Love to hear your take.
Richard, I'll throw it to you first. I know this is something you were interested in talking about. Of course, as a professor, I'm going to tell you that, you know, you need to get master's degrees and everything else. And, you know, you're on the DU campus. But no, seriously, I think there are a couple of points here.
One is that cybersecurity is largely seen by, you know, the Martians that habitat— that habit the HR office at most companies as being a profession. And as a profession, they're looking for a bachelor's degree for you to get a foot in the door, right? We all know that today you can send off 10,000 resumes, right, or 10,000 applications to a job, and it's all downsized by computer algorithms that determine whether you're going to get a callback from, you know, the Martian in the HR office, right, that doesn't understand cybersecurity, doesn't understand what's involved in the role, but That's the cut-down criteria. So the profession is changing. It's diversifying a lot, which is great because it used to be a boys' club when I started in it.
And now we have some great women leaders. It's still a boys' club, but we've got some great female CISOs now that are icons for all the teenage girls out there that are thinking, what do I do when I grow up, right? And that didn't exist 15 years ago. Yeah, but it's— okay, I'm allowed to say the word token. It's inconsequential, the number of women that have gotten into cybersecurity.
About 11%? Is that about right? Yeah. It's still too low, way too low. You'll be pleased to know that on my courses at DU, I've got about 60% women.
So that's a great sign for the future, right?
So the second point I wanted to make is really around the certification versus qualification perspective, right? You'll all see that there's, you know, ISACA— it was— oh no, ISSA was here today, not ISACA. But ISC² was exhibiting here again. There's a lot of organizations that are making a profession out of certifications. And, you know, I'm not going to diss them for it, but this is a moneymaking, you know, concern to some degree.
Right. So a lot of people that are at my level of my career, have abandoned that whole compliance, that whole CPEs that you need to get and paying the fees to these organizations every year. They are highly, highly valuable when you're starting your career for the first 15 years, perhaps in order for you to, to progress. There are still some organizations that require you to have a CISSP if you want to become the CISO, those sorts of things. But I'd say they're a lot less important than they were.
A degree will stay with you forever. Right? You have that qualification, academic qualification, for the rest of your life. It doesn't evaporate if you don't pay your annual fees to the certifying agency or don't get your CPEs in. Alex, what do you think?
Yeah, I think I've got a couple of points. One, I think certifications are important, but maybe not for the reason that you would normally think that they are. There is definitely work that you have to put in to be able to be certified, right? So you might be an expert in something, but it still takes you effort and work to be able to study and pass an exam. So as someone who is a hiring manager, I see that someone put in effort to do that.
Now, I don't think that they necessarily should be required because you also have, people that will just get certifications to be certified. That doesn't mean they're good at what they do. So I think it does show effort, and I think it's important because of that. I think as hiring managers, I think it's important for us to push back on requiring certain things like certifications or degrees, right? There's lots of different ways that you can get to where you need to be.
And it's really, can you do the job? Not what the qualifications that are on your resume. So obviously there are some drawbacks to, you mentioned the HR piece of this, getting through the door and getting to the right people, but I think we need to kind of push those requirements away. Talking about degrees themselves, I am also a big fan of education in general. I'm a DU alum.
I got my master's at DU. And I went back to get my master's, and I got it in a cybersecurity concentration very early on when it was sort of a new program there. And I realized that I knew a lot of the stuff that I was learning already. So, I didn't get a whole lot out of the cybersecurity portion of it. But it's funny because I didn't take— I was not a computer science person in my undergrad.
I learned a lot more in the core classes in my master's degree for fundamental concepts, things like enterprise architecture and other things like that, that I had never been formally trained in before, that I kind of knew and had picked up along the way. But having courses in those, I think, was really useful for me in kind of getting a broader picture of things. And so I think it is good to go back and do more formal education because it forces you to learn some of those types of things as well. Yeah, I got a follow-up for you, Alex. If you hire people, if you were hiring someone and you had to choose between one who had a certification on their resume, I don't know, CISSP or whatever the right certification for the job you're hiring is, the other person you're hiring is someone who doesn't have any certifications, but they have project experience, they've been working on open source projects, And equivalently, 6 months of open source work versus a 6-month certification, which of those is more interesting to you?
I would probably say the experience because I know that they have done it.
I think I might talk to both of the people, right? So obviously it all depends, right? You can have the experience, but you might not have been good those 6 months that you did it. And you could have gotten the certification, but you did it just to put it on paper and forgot everything that you learned immediately after getting it. I'll tell you, when I'm hiring, I'm always looking for people who are so curious that they just wanna get their hands in the thing, right?
And whether that's doing bug bounties, especially if I get someone who's not a developer who does bug bounties, I know how hard that is for them, 'cause that's me. I know how hard it is, and For them to go out and spend the effort trying to figure that out, like they're curious, they want to better themselves and they can show it off. I love to see that type of work. And you talked about getting your master's degree. 12 years into my career, I went back to get my master's, and at that point I was debating between a security master's or an MBA.
I ended up getting an MBA because I figured a decade of experience kind of checks the box on security, but how do I broaden my knowledge of the business and ended up being, for me, like a really useful part to help me in my career. Not that I believe I got a job because my resume said I had an MBA. In fact, I don't think it makes much of a difference to say it or not. But my ability to have conversations with other leaders in the business really was elevated by understanding their perspective and better knowing how their functions worked. All right, we have one more question.
And then I think we might have questions from the audience. Maybe. But I got one more question first. This is for you, Frannie. According to your recent— probably 6 months ago now— your recent survey that we talked about back in February, the tech industry pretty broadly has not done a good job of creating a diverse workforce.
You already hit on this earlier. I specifically want to know, what can we as panelists, but more broadly, the people listening in the room and listening to the podcast, what can we do to create a broader, more inclusive workplace in our daily jobs? Well, it kind of goes back to the previous question. We've got, in the United States, we have a track that this is what education looks like. And I'm a huge believer in higher education, but we've put it on a conveyor belt.
You graduate K through 12, and then you go directly into college. A 4-year degree program, or— that seems to be what we have defined as success. The reality is, not everybody's doing that. Not everybody is willing to sign up for how expensive it is, and they are not willing to go into debt. So we've got a huge population of talent in the— that, going back to your Moneyball, that could be going different paths.
So that's where I would start, is looking at different paths to, you know, maybe not a 4-year degree. I also think that, you know, you want to look at people that may have started in one area of your company and really show a tremendous amount of leadership that we talked about, not just doing this, but doing this, that really are underemployed. And that you could upskill within your own organization. I also— one of the things that is bothersome to me is, oh, we just don't have the pipeline. We didn't get the applications.
What are you doing? I mean, because the population shows that we've got an ecosystem of humans that are available for work. What in the process is eliminating them before they even apply? So I think it's a— we're not in the industrial age anymore. We're not in cookie-cutter ways of getting things to places.
So how do you look at your recruiting to make sure that you're not over-filtering? And going back to the algorithm, it made me cringe when you talked about it, that if you don't have this on a resume, you just— you didn't know that somebody started working at the age of 15, and they're contributing to their family, and they're— architecting a big life that maybe somebody that had the privilege of being able to go directly into a 4-year degree and never worked a minimum wage job. And yet that second individual is more likely to get through the system. So that was a long answer for you've got to do things differently. Good answer.
Always a good answer from Frannie. So I would say career aspirations start at a much, much younger age than in high school or at your 4-year degree, right? We're not training people in the United States about STEM, right? Science and technology careers at a young enough age. You compare us to China, Korea, Japan, right?
Most of East Asia, right? These people are running, you know, high schoolers are running circles around, you know, bachelor's graduates in the United States here and their science and technology capabilities. Right. They have a massive pipeline before they even get to university of people equipped in the basic fundamentals of technology architecture, right? Or, you know, software engineering or, you know, cybersecurity.
Right. So we're not doing that early enough. And that's a problem of the education system here. The second point, and this is my personal opinion, nothing to do with DU, is why the hell are we doing 4-year bachelor's degrees here? The rest of the world does it in 3.
Right? We have a whole load of bullshit courses essentially that fill out curriculums and charge students vast amounts of money to study things that are utterly irrelevant to them, right? And transferability of courses from another institution. Yeah, yeah. You know, it's ridiculous because it's an equalizing— it was set up to equalize the different schools, right?
So if you live on the nice side of town, then you had a good high school education. If you live on the the crappy side of town, then, you know, you can maybe spell your name, right? And it used to be that way in the United States. That's why we have busing and everything else. But there's no real need for us to have a 4-year degree, in my personal opinion, right?
So if you've got kids and they're thinking about where do I go for a bachelor's, go to Germany. It costs you €500 for the complete degree in Germany and it's in English, right? You know, there are a lot of options here versus paying $75,000 a year to go to Harvard or Stanford or whatever to get your bachelor's. But I think also we need to be looking at where is the real value proposition within the education system, right? It used to be that bachelor's degrees were a real differentiator for everyone.
Now they're ubiquitous. Everyone has a degree pretty much, right?
And we're now forced to, you know, to get to, you know, master's levels in order to learn the point skills that are going to take you through your career. And we've got a lot of materials at the master's level that really should be taught at a bachelor's level, in my opinion. But there's one other point I want to make, and I'm dragging on here, Robb, apologies for that, is that not all jobs require a degree in cybersecurity. That's right. There are a lot of jobs that you can do very, very well if you have an aptitude for work, if you have an understanding and you're willing to work hard towards that.
You don't need massive certifications or qualifications behind you. Yeah, maybe most jobs even. So it's changing the recruitment process would make a big difference. Tom, do we have a couple of minutes to ask questions from the audience?
Someone over here had a hand up. Was it late lady here? Hi, and, um, I'm pretty much behind your point, um, one for both Richard and Franny. Um, we definitely need to change education. We can't keep teaching the same things.
Um, you're good, you keep going. And then the other one is I agree with you guys about not a lot of, um, positions require you to have all these certifications or through education. The problem is that this is what you're thinking as a manager or as a leader, but you're not doing the HR department. So when are we going to sit with HR and really work on the process? Because the statistics tell me 2 things.
It tells me that there is a lack of workforce because we have a lot of positions open that are not fulfilled. But then the other side, when lower positions or people for lower positions are applying for these positions, they're having a hard time getting to that interview. They don't even get through the HR. So that is the main problem I see right now with our positions in security. Yeah.
It's like, it's a battle that has to be won one company at a time, unfortunately. And, Frankly, maybe we're not the right ones in the room because really what we need is to be at the SHRM, the Society of Human Resource Managers meeting, telling them how to retrain the HR recruiters to really ask managers these hard questions. Hey, this was on the previous job description. Does it still need to be here? Can we take this degree off?
But it is a one company at a time. I'll tell you, the places I've run, we've taken those things off the job descriptions. It's one company at a time, right? We need to maybe move faster, maybe move better. Yeah, I agree with that.
The other thing is, as hiring managers, I think it's important that you, if you can, hire for jobs that require zero experience to get the job. I mean, we're killing ourselves in cybersecurity that an entry-level job requires 3 years of experience, right?
That's impossible. Like, you can't do that, right? So again, it's more of a one company, one manager at a time thing. But I have purposefully made entry-level jobs that require zero previous experience because you need to get people in the door. You have to be willing to take the time to upskill people and get them in the door and get moving.
Yeah, and I'll just add to that. I think there's a disconnect between HR and hiring managers, what hiring managers would actually want. Hiring people, I was looking for certain things, but HR was filtering it because they— I was hiring in at a certain salary, right? And in order to attract someone at the right level in cybersecurity, I needed to pay twice as much as a simple developer, right? So therefore, they were making this a senior managerial role or a senior director role when in actuality it was a junior role.
So we had that kind of grade inflation in order to meet salary bands. And that's particularly noted where security reports into the technology organization under the CIO, right? Well, the other thing, if you're not hiring at those entry-level jobs, the people that you are hiring that have 3 years degree— degree or 3 years of experience, they're like, why am I doing this? I was doing this 3 years ago. And they'll leave because you're not challenging them.
And it's a, it's a career-limiting move to stay and doing things that are below your skill level. You gotta create that ladder for people to move up. I think I saw a question over there. Is that Joe? Let's get 2 more and then we gotta close it up.
Maybe 3. Hi. This may be more for podcast listeners, but I would encourage young people looking for breakthrough to get involved, right? And that is get involved in conferences. Not all of them are paid for.
Get involved in meetup groups. Get involved— what is it— Girls That Code, that sort of thing. There's a lot of things you can do to, you know, it's not the formal way to get, you know, we have SecureSet here in Denver, that sort of thing. So just a kind of a call-out to people who ask me regularly how to get involved. I'm like, Start showing up at a meetup.
You like to code, you want to learn about Java, you want to learn about cloud security, etc. ISSA, ISACA, there's all sorts of things to get involved in and just learn directly from experts. And there's plenty of people that will mentor. I'd say don't just show up, volunteer. Yeah, well said.
If you're willing to volunteer, every group wants you. Say what you're going to do and do it, and you'll be adding value, you'll be creating great relationships. It's really good advice. Good point, Joe. Thanks.
Another question? Question near the back. Way in the back. 2 in the back, it looks like. Maybe our last 2.
Yeah. Thank you. Thank you all for lending your voice. I really appreciate it. So I really want to talk more about the 4-year degree.
And Richard, his question is really— I want you to answer it first. So how can certifications become as relevant as 4-year degrees? So I think there's a difference between a degree, an academic qualification, versus a certification. Academic qualifications tend to be very broad, right? They give you a very broad education across an entire technology discipline from technology architecture to project management to whatever, right?
Certifications tend to be more pointed and focused. Right? Whether it's a SANS GAIC or, you know, an ISACA certification or whatever. Is there a role for both? Yeah, absolutely.
I don't think that they command the same power in the eyes of recruiters right now, but maybe that's something that we need to look at, right? So how could they? That's your question? How could they? I mean, get the mic, but start there.
Because I, like, I understand that, um, colleges and institutions, like, they have their own, like, criteria and they're tried and true, whereas, like, oftentimes when we see some boot camps and certs, they've been around for maybe 10 years. So you have 10 years versus 120 years in some institutions, right? So it's like you have the time is against you, but what about relevancy, especially if we think about, like, in academia, you have to focus on like, oh, can I get through this bureaucracy? Can this course be added? Whereas in a certification program, it's in real time, right?
So like, if that's a pro of the certification and that not necessarily colleges and universities can like stay to that level, like how— where's the relevancy, I guess, is what I'm trying to understand. One of the, one of the things that we've been trying to do is we have Across our company, we have a career architecture that lays out the levels and the job types and things like that. And for each one of the levels, I've been trying to put equivalency for sort of 3 different things. One is a degree, one is boot camp or some sort of less formal or lengthy type of education and certifications, and trying to say, okay, for this level, we think we could have any combination of these sorts of things to try and, I think to your point, make those things more equivalent, right? Like, does a— do 2 entry-level certifications mean the same thing as a bachelor's degree?
Or is it 3 certifications? Whatever it might be to try and level set what we would be looking for for each of these types of things, not just it has to be a degree or things like that. To, I think, your point, make it somewhat equivalent across the different ways that people can become educated and get into a profession. And I also like the question about the agility of getting the— I mean, this stuff is— changing so quickly and our structure in a 4-year degree program is lagging. So is there actually a benefit more than, you know, like, oh, well, 4-year degree would be great, but— or would be better than— I mean, it seems like certifications would be better in some instances.
I mean, I think to my— I think SecureSet, like the boot camp type of a set, is probably the the nice combination of the two where my problem with certifications is I don't know what you actually did. You answered some questions, right? Maybe you have experience to back up those questions, maybe you cheated, I don't know. It's just so hard to know, but a 4-year degree, you're gonna take some English classes along the way, right? And I think a boot camp is just really focused on we're gonna teach you some skills that make you good at this thing.
I think that that's a really nice middle ground. Where I know you're getting hands-on, you're probably learning how to do the job pretty well. It's not as broad as a degree, but it's a whole lot more than just answering questions. All right, I know— I think we're about out of time. One more question?
One more question. Gentleman standing in the middle of the back there.
Yeah, I just wanted to make a couple of comments. When you talk about degrees versus certifications, one of the big issues with degrees is that, A, they're expensive, as, uh, Franny was pointing out, not everybody has $60,000 a year to go to school. The other problem is that most of the time they're actually outdated in the information you learn. For instance, I know the professor Richard had said that once you get a degree, it's always valid. You don't have a 3-year research cycle.
You don't have CEUs. Well, I got my master's degree in IT and cybersecurity back in 2011. We didn't even talk about cloud computing because it just came on the scene in 2009, 2010, and it wasn't updated in the textbooks yet. So just seeing a degree honestly doesn't help as an employer, because most of the time if you have something— I know people who had an IT degree from the '80s or '90s, they're not relevant today, right? Where a certification is.
The other challenge you have with the certification though, as you said, is there's paper tigers, there's people who are cheating. And so that's becoming on the certification industry to change that and do more hands-on testing. And really the benefit of a certification from an HR perspective is that I know you have a minimum level of knowledge. You can at least be a member of my team, you can speak the language. If you get a Security+, You know the terms, you know the ability.
You may not be able to configure a firewall, maybe you can, maybe you can't, but at least you know what it is, right? And so for those entry-level jobs, it's really important. The people who are really doing this best to solve this cybersecurity issue right now is the federal government, because with the military, they're bringing people off the street with no degree, no certification. They give them training for a year, year and a half. They put them to work for 4 or 5 years, and then most of those people get out.
83% of the people get out in the first 4 to 6 years, and they are the ones who are going into industry. And so that's where most of the people are coming from with those 3 to 5 year entry-level experience. But it is becoming this huge barrier to entry because not everybody can do the military. And the big problem is most companies aren't willing to bring somebody on and train them for 3 months, 6 months, or 9 months to get them up to speed. And so how do we solve that?
It's really going to be a culture change across our industry. We need to start thinking about cybersecurity more like an electrician or a plumber, where you're going to a 9-month internship at a low-cost community college and not a master's degree. I've seen so many people who apply with a a 4-year degree, from bachelor's degree, and then they go 2 more years to get a master's degree. They spent $200,000, they have a master's degree, and they've never held a job, and they can't do anything even though they have a master's degree in cybersecurity. I'd rather have somebody who spent 6 months in a boot camp or a community college, has 2 or 3 certifications, who can actually do something and is ready to learn and be on the job.
So anyway, just wanted to tie together all the things you guys said. Hopefully that's helpful. Sounds to me like the answer is just to hire the people who, as they leave the military, already got that training. Guys, this has been a really great panel. I wanted to just say thank you to our panelists.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember Colorado equals security.