A podcast that explores the stories of real people, their work, and its impact on the information security industry. Join security expert Caroline Wong as she focuses on the human side of security. Don't forget to follow the podcast on Twitter: https://twitter.com/humansofinfosec
Jimmy Sanders, head of information security at Netflix DVD joins Cobalt CSO, Caroline Wong, for a great conversation on everything from leadership to growing and connecting with the security community.
Gisela Hinojosa is a Senior Security Consultant at Cobalt, executing IoT penetration tests and red teaming exercises with a wide variety of security teams. With over 13 years of experience in the tech world, Gisela has held roles in admin, software engineering, QA, consulting, and penetration testing. In this episode, she shares what vulnerabilities she discovers and how security teams can extract as much value as possible from each pentest engagement. For more on this topic, make sure to check out the industry report "The State of Pentesting 2023": https://resource.cobalt.io/state-of-pentesting-2023
Tejpal Garhwal is the director of DevSecOps and application security at Pega. With more than 26 years of experience in application development and product security, he has led multiple security and dev teams, and set the direction for information security, application architecture, policy, and processes within numerous organizations. In this episode, Caroline gets his perspective on how leaders can bring security and development teams together, aligned towards a shared goal: building software that is both outstanding and secure.
Carving an unconventional path towards information security, Yael advises many a CISO, CIO and CRO. Leadership roles at BlackRock and JPMorgan during periods of crisis and growth have given her a unique technical and business perspective — instead of saying “Here’s why that won’t work.”, she asks “But what if we tried this?” In this episode you’ll learn more about Yael’s story, why she started Yass Partners, and how security teams can approach new situations with equal parts established processes and creative thinking.
Whether you're stepping into your first managerial role, or you're about to inherit a fully formed team, you might be facing self-doubt and uncertainty. Security veteran Tia Hopkins — Chief Cyber Resilience Officer and Field CTO at eSentire, adjunct professor, LinkedIn instructor — shares with Caroline how to overcome impostor syndrome as you progress, how to connect with your team, and how to set them up for success so well, others want to join.
Return guest Robert Wood is the CISO for the Centers for Medicare and Medicaid Services. He leads enterprise cyber security, compliance, privacy, and counter intelligence functions at CMS and ensures the Agency complies with secure IT requirements while encouraging innovation.In this episode, Robert discusses with Caroline how big changes and organizational pivots can bring just as much opportunity as they do anxiety. He shares his perspective on how he guides his team through turbulent times, and what other leaders can do to support their people and help them pursue new ideas on how to work better together and achieve even bigger goals than before.If you like this episode, we recommend checking out another initiative Robert is working on — The Soft Side of Cyber (https://www.softsideofcyber.com/), where security practitioners can develop their communication, critical thinking, and leadership skills.
Bipin Gajbhiye is a security practitioner, advisor, and investor. These three roles coalesce into a unique perspective on how cybersecurity professionals can achieve their goals — whether it's negotiating with the board, landing a critical investment, or advancing in their careers.
Geoff Huston has been working on the Internet since the early 80’s and, in his own words, “did his bit” to set up the Internet in Australia, as well as to set up the early global Internet in the academic and research community. In this episode, he shares with Caroline the leaps and bounds hardware has made over the decades to bring us opportunities we could have never imagined...and how the human condition inadvertently makes it all complex and insecure.If you like this episode, make sure to check Geoff's writings at www.potaroo.net/
Is the manager role the only path ahead in cybersecurity? Seif Hateb, Security Architect at Twilio, shares his view on the Individual Contributor vs Manager dilemma, and how people in the field can pursue the type of role that fits them best.And if you're just starting in the cybersecurity field, make sure to check out Seif's YouTube channel, full of expert advice on security fundamentals and how to kickstart your career -- with or without a technical degree: https://www.youtube.com/c/seifhateb
As the CISO of North America at Checkmarx, Peter works towards providing the technology, expertise, and intelligence that enable developers and enterprises to secure the world’s applications. A lifelong developer at heart, Peter shares with Caroline his insights on what motivates Dev teams to prioritize security, and why so many current strategies are failing. You’ll learn more about how to not let your tools bury you in work, how to implement mutual accountability around security, and tactics to prevent open source code from blowing up your entire application when a new 0-day comes up.
What felt like science fiction 40 years ago is our reality today. What about the technology that will come in the next 40-50 years? What could change, and how can people band together to craft a bright and equitable future?Eugene Spafford — technologist and professor of Computer Sciences at Purdue University — talks with Caroline about how advances in technology like robotics and machine learning are already impacting people’s lives, in both good and bad ways. We have a responsibility to not just consider what new tech to build, but also what we're building it for. At the end of the day, technology isn't the most important part — it's the people. If you enjoyed this episode, we recommend the upcoming book Eugene has co-authored: “Cybersecurity Myths and Misconceptions: Avoiding the Hazards and Pitfalls that Derail Us.”Here’s an overview:Cybersecurity is fraught with hidden and unsuspected dangers and difficulties. Despite our best intentions, there are common and avoidable mistakes that arise from folk wisdom, faultyassumptions about the world, and our own human biases. Cybersecurity implementations, investigations, and research all suffer as a result. Many of the bad practices sound logical, especially to people new to the field of cybersecurity, and that means they get adopted and repeated despite not being correct. For instance, why isn’t the user the weakest link?You can pre-order the book at https://informit.com/cybermyths. If you order now, you can use the discount code CYBERMM to receive a 35% discount.
Richard holds many titles, one of which is the President of the OWASP LA Chapter. Initially an architect, learning AutoCAD sparked his interest for all things technical. After a career change, Richard has held many high-profile roles in cybersecurity, bolstering numerous communities and initiatives.Don't forget to check out https://planetcybersec.com/ for a list of the conferences Richard and his team are next working on.
Security Advisor at Office of the CISO and Co-Host of Google's Cloud Security Podcast, Dr. Anton Chuvakin, chats with Caroline about the past, present and future: how a hacked computer shifted his interest from physics to security, how threats from the 80s still plague orgaizations, and how cybersecurity will continue to spill out of the digital realm into the physical world. Some helpful links on things mentioned in the episode:Anton's security predictions back in 2010: https://chuvakin.blogspot.com/2010/01/security-predictions-2020.htmlA review on those predictions 10 years later: https://medium.com/anton-on-security/checking-my-2010-security-predictions-in-2020-932f6233a731Related episodes from Anton's Cloud Security podcast: https://cloud.withgoogle.com/cloudsecurity/podcast/ep75-how-we-scale-detection-and-response-at-google-automation-metrics-toil/https://cloud.withgoogle.com/cloudsecurity/podcast/ep47-megatrends-macro-changes-microservices-oh-my-changes-in-2022-and-beyond-in-cloud-security/
Don’t have a “typical security background?” Neither did Henning Christiansen, who is now the CISO at Ottobock. Before starting in InfoSec, he tried out roles in finance, development and auditing. Until one day, he began to nurture his interest in InfoSec, which led him to roles in Bombardier Transportation, Axel Springer, and now Ottobock. With decades of experience, this is what Henning would share with anyone trying to find their footing within the industry: “Try to make sure that you find your way without really giving up on yourself, giving up on your character, giving up on what you are.”
Security Relations Leader Vandana Verma is the Chair of the Board of Directors at OWASP. Starting with the dream of supporting her family, she pursues her curiosity around technology and builds renowned expertise in application security, infrastructure, and product security. In this episode, Caroline learns more about Vandana’s story, her diversity initiatives like Infosec Girls and Infosec Kids, and what security threats are on her mind.
Zenobia Godschalk — SVP of Communications at Hedera Hashgraph, and Founder and CEO of ZAG Communications — shares how a passion for PR, tech, and privacy has shaped her career. From handling comms around cloud computing, to investor relations in InfoSec, and now spearheading awareness around distributed ledger technology, she shares helpful tips on how to build a flexible career in the world of tech, how to talk about security breaches, and what online identities could look like in the future.
With over 15 years of technical and managerial experience, Marnie Wilking has led security programs across multiple verticals — retail at Wayfair, healthcare at Orion Health, and finance at Early Warning and Wells Fargo. Listen to her story to learn how the CISO role changes in each environment, and what stays the same.
While hearing Nicole's story, Caroline learns more about the emerging Business Information Security Officer role. Nicole breaks down the unique value BISOs can bring to their organizations, and what others can learn from the role to earn a seat at the business table.
If you enjoy this talk, you can catch both speakers live at our upcoming PtaaS Exchange roadshow locations. Learn more: https://event.cobalt.io/ptaas-exchange-roadshow
Yael Nagler — founder of Yass Partners, advising CISOs, CIOs and Boards — surprised us when she said “Let me interview Caroline!” Taking this episode in a new direction, Yael asks Caroline about her story, her career, and her aspirations.
Will Gant — accomplished developer, author, software architect and co-host of the podcast “The Complete Developer” — shares with Caroline a glimpse into the Dev world. They talk about motivations, challenges, and how security teams can work better with their dev counterparts. A small hint: let your nerd flag fly.
Winner of "Best Security Podcast 2018" and "Best Security Podcast 2019," Smashing Security is a fun and informative show on tech SNAFUs. Co-host Graham Cluley shares more about his 30 years in cybersecurity, along with thoughts on malware, state-sponsored attacks, IoT, and how the cybersecurity scene today would have looked like science fiction when he started.
Without good governance, every other part of security becomes much less effective. Caroline sits down with Deika Elmi — a security leader profiled by Risk & Compliance organization “Risky Women” in 2021 — to talk about GRC’s role in creating business value, and why Confidentiality shouldn't steal the spotlight away from Integrity and Availability.
Caroline talks with tech executive Brian Carmenatty and Sanjay Deo, Founder & President at 24By7Security, Inc. They explore how teams can face prevalent threats by going back to basics with their technology and security policies.
Swathi Joshi is an Information Security executive who focuses on risk management, crisis response, security services, and cloud security engineering. She is currently the VP of Cloud Security at Oracle where she leads a global team of engineers, analysts, and operators to secure Oracle SaaS applications and keep customer data safe. Prior to Oracle, Swathi led Netflix's Detection and Response team to manage inevitable security incidents and minimize risk to Netflix.
As Chief Information Security Officer for Principal Financial Group, Meg Anderson is responsible for the information security program for the global Fortune 500 company including governance, risk & compliance; identity and access management; cyber defense operations, and more. She is passionate about enabling and accelerating business strategies while ensuring customer assets remain secure and the reputation of the company is upheld.
Jennifer Czaplewski is the Senior Director on the Cyber Security team at Target. In this role, she is responsible for leading DevSecOps, Vulnerability Management, and Endpoint Protection. Among holding several leadership roles within the information security industry throughout her career, Jennifer is also the 2021 co-chair of the Cyber Security Summit and authored a chapter of Modern Cybersecurity.
As the Chief Information Security Officer at Epiq, Jerich Beason is responsible for ensuring the security of the company’s digital assets as well as transforming the Epiq cybersecurity program into a world-class industry leader. Jerich has spent his career building industry-leading cybersecurity programs to protect some of the nation’s most sensitive assets.
Andrew Obadiaru is the Chief Information Security Officer at Cobalt. In this role, he is responsible for maintaining the confidentiality, integrity, and availability of Cobalt's systems and data. Prior to joining Cobalt, Andrew was the Head of Information Security for BBVA USA Corporate Investment banking, where he oversaw the creation and execution of Cyber Security Strategy. Andrew has 20+ years in the security and technology space, with a history of managing and mitigating risk across changing technologies, software, and diverse platforms.
Matthew Sharp leads the information security function for Logicworks as Chief Information Security Officer (CISO). His role includes responsibility for information security governance, risk management, strategy and architecture, and compliance. Rock Lambros is the CEO and Founder of RockCyber, LLC. He is a seasoned Cybersecurity and Information Technology executive with expertise in aligning Cybersecurity and technology strategy with enterprise business goals in order to reduce the risk of revenue to the organization.
Sydney Klein is the Chief Information Security and Data Officer for Bristol Myers Squibb, a global biopharmaceutical company whose mission is to discover, develop, and deliver innovative medicines that help patients prevail over serious diseases. In this episode, she discusses how she was impacted by the brilliant scientist who created the medications that have her mother here over 20 years after her initial diagnosis.
Chenxi Wang is a founder and general partner of Rain Capital Management, while also serving on the board of directors for MDU. Inspired by learning new things, she is a long-time thought leader, executive, and women in tech advocate. This episode dives into how Chenxi finds inspiration from continuously learning and encompassing a growth mindset. Listen to the latest episode of Humans of InfoSec:
Tiago Teles is an information security evangelist at a Dutch bank, ABN AMRO. He always had a tendency to look at things differently, and that’s what Tiago explains is at the heart of information security. Fueled by his passion for diversity in InfoSec, he dives into how the more we embrace diversity, the more people will join the information security industry, and the better it's going to be. Listen to the latest episode of Humans of InfoSec:
Dr. Ksenia Peguero is a senior research engineer within the Synopsis Software Integrity Group. She has nine years of experience in application security and five years in software development. She focuses her research on static analysis, JavaScript security, frameworks, and technologies. Before diving into research, Ksenia had a consultant career in a variety of software security practices, including pentesting, threat modeling, code review, static analysis, tool design, customization, and deployment. Listen to the latest episode of Humans of InfoSec:
Starting as a 15-year-old Isp system admin to becoming the Sr. Principal Consultant at Synopsys, Kevin Nassery's path is as extraordinary as it is insightful. Listen to the latest episode of Humans of Infosec here:
Episode 56 Jack Roehrig: The Educational Journey of Turnitin's CISO by Humans of InfoSec
For our latest Humans of InfoSec podcast, we’re excited to welcome Phillip Wylie on the show. Phillip has over 22 years of experience with the last 8 years spent as a pentester. Phillip has a passion for mentoring and education. His passion motivated him to start teaching and founding The Pwn School Project a monthly educational meetup focusing on cybersecurity and ethical hacking. Phillip teaches Ethical Hacking and Web Application Pentesting at Richland College in Dallas, TX. Phillip is a co-host for The Uncommon Journey podcast. Phillip holds the following certifications; CISSP, NSA-IAM, OSCP, GWAPT.
Despite the talent shortage, the barrier to entry in information security remains daunting. Yet Davin Jackson, a former flight mechanic turned senior penetration tester, learned to leverage his passion and tenacity to pursue and achieve his infosec goals. Now, Davin is invested in helping others in the field through accessible mentorship, teaching, and writing—including using Fortnite to help students understand the field. In our latest episode, Davin opens up about the challenges he’s overcome, provides wise advise on those hoping to secure an infosec job, and much more.
For our latest episode of Humans of InfoSec: Emerging Voices, we’re excited to welcome Karan Dwivedi to the show. Karan is a security engineer at Google specializing in detection and response, but he dedicates his free time to coaching and mentoring others breaking into the field. His work demystifying the interview process for security engineers, which you can explore at https://allthingspwned.com/, has introduced a methodical approach to an often daunting experience. In this episode, Karan explores his path to infosec, discusses security engineering at scale, and explains the importance of supporting the community.
For our latest Humans of InfoSec podcast, we’re excited to welcome Octavia Howell on the show. Octavia, who is currently the Business Information Security Officer at Equifax, is a seasoned leader and practitioner with extensive experience in governance, networking, and security. She is also the founder of Augustus Redefined, an organization founded to support and mentor black women in cybersecurity. In our latest episode, Octavia opens up about her career and discusses the much-needed value of strong mentorship.
Michelle Valdez, the CISO at OneMain Financial, doesn’t approach cybersecurity through the lure of the threat. Instead, she applies a methodical, problem-driven approach honed through her background in the US military, where she served as an investigator for the U.S. Air Force. Her extensive experience working in national security, intelligence, and the military has driven her communications-focused approach to cyber resilience as she focuses on interrogating the problem, not the people, and embraces failure as a pivotal step to success. In our latest episode, Michelle opens up about her impressive career and the lessons she’s learned along the way.
For the 50th episode of Humans of InfoSec, we’re excited to feature Larkin Ryder, Slack’s head of product security and former interim chief security officer. Larkin has held engineering roles at high tech companies for more than 25 years, including more than five years as a senior security engineer at Twitter. While Larkin has a proven track record of solving complex engineering problems as a manager and engineer, she brings unique humility, humor, and compassion to each challenge. In our latest episode, Larkin opens up about her career and path into security, her background in zoology—and much more.
In the latest episode of Emerging Voices, we’re excited to welcome Busra Demir to the show. Although Busra’s official title is Pentest Architect at Cobalt, where she is responsible for managing day-to-day pentest operations, her passion lies in breaking things. Busra is a hacker to her core—demonstrating an inimitable aptitude for testing applications and an unstoppable quest to achieve her pentesting goals. In our latest podcast, Busra opens up about her hacking journey, including working towards achieving every Offensive Security certification that exists.
Most people dread the ominous 3 am work call, but for Dr. Brandie Anderson, it’s energizing. As a security researcher with more than 18 years of experience and a PhD in Cyber Administration, Brandie has spent her career pursuing new challenges—and is not afraid of learning from her mistakes. Her passion has driven her to lead teams across incident response, risk mitigation, and security operations. Now a global security practice lead at Google, Brandie works with product, go-to-market, legal, and incident response teams to drive Google’s security initiatives. In our latest episode, Brandie opens up about her achievements, career path, and illuminating failures.
In our latest episode of Emerging Voices, we’re excited to welcome Preeti Ravindra to the show. With a passion for learning and an aptitude for applying new technologies, Preeti demonstrates firsthand what innovation can look like within security. She acquired her master’s degree in information networking from Carnegie Mellon and now serves as a security analytics research lead at IBM, where she focuses on improving the efficacy of IBM’s Watson for Cybersecurity. In this episode, Preeti discusses her path into security, shares her observations about the industry, and offers outstanding recommendations on seeking mentorship and achieving professional growth.
Karen Worstell, a well-known technology leader and serial CISO, has driven security initiatives at companies like Microsoft, AT&T, and Bank of America. Yet after decades of leading information security teams, Karen made a pivotal and life-changing decision to become a chaplain with a focus on palliative care. Following her passion for helping others in need, she now provides cybersecurity mentorship and coaching to give back to the community. In our latest episode, Karen looks back on her career and reflects on her latest transition.
In our latest episode of Emerging Voices, we’re excited to welcome Steven Asifo to the show. Steven is a recovering auditor who now leads GRC initiatives with the Paranoids at Verizon Media. He tackles information security problems with humor and collaboration, leveraging his business background to bridge the conspicuous gap between highly technical talent and executives. In this episode, Steven opens up about his path into infosec, what he’s observed so far, and what he's focused on next.
When information security is complex to teach, how do we build effective curriculums for diverse learning and application? Aaron Kraus, an infosec educator with more than twelve years of teaching experience, has a few ideas. With hands-on experience in GRC and infosec leadership positions at startups and financial services firms, he brings a fresh perspective on making cybersecurity relevant and easy to learn. In our latest podcast, Aaron opens up about his own struggles learning as an adolescent and adult—and how those struggles have transformed the way he teaches.
Drumwave CEO Michelle Dennedy is the privacy advocate we all need. As the co-author of the Privacy Engineer’s Manifesto and the Privacy Engineer’s Companion, Michelle has pioneered robust change at companies like Cisco, where she was the Chief Privacy Officer. She passionately believes that privacy is a fundamental human right. While maintaining executive leadership roles, she even founded the iDennedy Project, a public-service organization to address the privacy needs in sensitive populations like children and the elderly. In our latest episode, Michelle walks us through the current privacy landscape and offers captivating anecdotes about her own journey.
For our latest Emerging Voices podcast, we’re excited to welcome BiaSciLab. This 13-year-old hacker is a prolific technologist who runs Girls Who Hack and Secure Open Vote, She has spoken at several conferences—including the DEFCON Voting and Bio Hacking Villages, DEF Camp in Romania, and H.O.P.E.—and is widely recognized for her CTFs and web application hacking labs.
You can learn more about this Emerging Voices guest at www.biascilab.com. For more information about Girls Who Hack, and to purchase her soldering kits and stickers, visit www.girlswhohack.com. Help BiaSciLab with preserving election integrity by visiting www.secureopenvote.com.
As the Chief Information Security Officer at Kuwait Oil Company, Dr. Reem Al-Shammari protects one of the world’s leading oil and gas companies. Known as a “wild card” among colleagues during her professional rise, Dr. Reem applies innovative solutions from both an engineering and management perspective. She honed her unique strategies after completing her bachelor’s degree in computer engineering, finishing her PhD thesis on quality management implementation in the Kuwaiti Oil Sector, and attending Harvard’s Business School Executive Education Program. Today, she protects the Kuwait Oil Company while also raising seven children. On our latest episode, Dr. Reem discusses her work as CISO, her experience co-founding the Women in Cybersecurity Middle East Group, her perspective on parenthood, and much more.
In the race to build the world’s fastest computers, Soledad Toledano is on the frontlines. After more than eight years protecting the Lawrence Berkeley National Laboratory, Soledad is now the security engineer responsible for defending the National Energy Research Scientific Computer Center’s super computing division. With responsibilities ranging from pentesting, network security architecture, vulnerability assessment, and machine learning adoption, Soledad hopes her highly-challenging security engineering experience will help disrupt stereotypes in the field. An outspoken advocate for women entering the field, Soledad is also fighting to close the gender gap. In our latest episode, Soledad breaks down her work, recounts her path to Berkeley Lab, and dives into what she’s focused on next.
In our latest Emerging Voices podcast, we’re excited to welcomeLiz Jaluague to the show. Liz is a technology enthusiast who recently joined Deloitte as an analyst focusing on vulnerability management and cloud architecture. Liz’s background spans non-profits, sales and marketing, entertainment, politics, and the natural sciences, but her passion has always been in new technologies and civil liberties. From gaining programming experience in Python, C#, Swift, and SQL to studying computer fundamentals, Liz is a voracious learner eager to make a difference in the industry. In this episode, Liz opens up about her journey.
As a former chemical weapons specialist for the U.S. Army, Keyaan Williams knows how to remain cool. Since his service, Keyaan has dedicated more than twenty years to managing security risk, compliance, and internal control programs at large enterprises. He was also a security executive at the CDC and served as president of the Information Systems Security Association. As the founder and managing director of Cyber Leadership and Strategy Solutions, Keyann now focuses on improving the cybersecurity talent shortage and helping small businesses build security programs. In our latest Humans of InfoSec podcast, Keyaan shares some leadership advice, offers wisdom on communicating security risk to non-technical executives, and updates us on his efforts to make security a more open and collaborative space.
We’re beyond excited to welcome Ray Espinoza, Cobalt.io’s Director of Security, to the show. Ray has over twenty years of experience in infrastructure and security and has served in key security leadership positions at Amazon, Proofpoint, Cisco Systems, and eBay. As a well-respected blue team leader, Ray has managed hundreds of incidents. In our latest episode, Ray shares his story and reflects on his blue team triumphs and challenges.
We’re mixing things up here at Humans of InfoSec. Over the last few years, we’ve interviewed dozens of seasoned professionals about their experiences in the industry. Yet there are so many emerging players in the field. We want to elevate their voices, too. We’re launching a Humans of InfoSec spin-off where our very own security strategy analyst Vanessa Sauter will interview new infosec professionals. For our first episode, Caroline Wong interviews Vanessa about her path into security.
Eric Galis, vice president of compliance and security at Cengage, believes in seizing the right opportunities. A series of happy accidents propelled Eric’s career in information security, where he’s focused on automation, security monitoring, application security, and more. As a seasoned professional in the field, Eric seeks opportunities for others, particularly by advocating for people in adjacent industries and roles trying to break into the field. In this episode, Eric shares his positive outlook on the industry, provides concrete advice on fixing the workforce shortage, and offers insight into his own experiences in infosec.
Leif Dreizler, senior application security engineer at Segment, doesn’t consider himself a developer. Some of his colleagues disagree. Leif, who didn't know what computer science was when he signed up for his first CS class, unexpectedly gravitated towards the major. Although his specialization in appsec started from security consulting during his senior year of college, his background has helped embed security into engineering. Leif joined the podcast to discuss his journey into appsec, his observations about the industry, and his recommendations for entering the field.
Heather Eggers, Chief Privacy and Compliance Officer at Collective Health, tackles privacy from a unique perspective. As a former director at PwC, she was tasked with helping global technology and healthcare companies implement and improve privacy, security, and risk management programs. When communicating with C-suite executives and board members, she learned the hard way that information security must be placed in terms of business objectives. In our latest episode, she dove into her experiences bridging the gap between infosec and business, where she sees privacy heading, and how she got into the field.
In our latest episode, renowned security technologist Bruce Schneier joined Caroline Wong for an enlightening conversation on the future of public-interest technology. Hailed as a “security guru” by The Economist, Bruce has authored more than a dozen books on security and cryptography, testified before Congress, and served on multiple government committees. Bruce is currently a fellow at the Berkman Klein Center for Internet & Society at Harvard University, a Lecturer in Public Policy at the Harvard Kennedy School, and a board member of the EFF, AccessNow, and the Tor Project. Hundreds of thousands of people regularly read his blog “Schneier on Security.” He joined Humans of InfoSec to discuss the future of ethical technology and the role technologists can play in positively shaping public policy.
As Director of Security at Alto Pharmacy, Joy Forsythe focuses on helping the modern pharmacy startup improve healthcare while preserving patient security and privacy. It’s no small feat. Joy brings over a decade of experience working on software security, security monitoring, and enterprise security tools and has worked with companies including Fortify Software, HP, and Arcsight. She also ran security at Mango Health and has a masters of engineering in computer science from MIT. Joy feels passionately about supporting the next generation of infosec professionals and is actively recruiting candidates to join her at Alto Pharmacy. Joy and Caroline will also be speaking together at the People + Security panel at the Shift AppSec Summit this February in San Francisco.
From pawning the Department of Justice at the age of ten to protecting Saudi Aramco in the wake of cyberattacks, Chris Kubecka leads an inimitable life. Now the founder and CEO of HypaSec, Kubecka grew up banned from using computers—as ordered by the federal government. Thanks to a moral waiver from the Air Force, Kubecka developed deep technical knowledge from serving in the Air Mobility Command and Space Command. She subsequently fostered a deep passion for offensive and defensive methods in IT, IoT, ICS, and embedded systems, for which Saudi Aramco recruited her to protect its system. In this episode, Caroline Wong joins Kubecka on a wild regaling of her life in security.
Adam Shostack’s reputation speaks for itself. A renowned threat modelist, Adam is a consultant, entrepreneur, technologist, game designer, and educator. Among his many achievements, he helped launch the CVE, drove the Autorun fix into Windows Update, and authored the foundational text on threat modeling. He joined our podcast to discuss the history of information security, his triumphs and challenges in computer science, how he sees technology changing, and where interpersonal skills play a critical role in the field.
Like many of us, Gerhard Eschelbeck, former vice president of security engineering at Google, took an unexpected path into information security. Yet his role in the industry was transformative. In this episode, Gerhard shared how his childhood fascination with computers culminated in leading a one thousand-person security engineering team at Google. From studying viruses to understanding how humans interact with passwords, Gerhard discussed how his experiences in a nascent industry have shaped his work, helped him champion new technologies, and supported his role advising startups. Stayed tuned for all this, and more, in our latest episode.
Should security professionals open up more? Glenn Leifheit, senior security program manager at Microsoft, believes so. In this episode, Glenn shares his transformational journey learning soft skills when the hard skills came easy, how he overcame his fear of public speaking, and why vulnerability matters for colleagues and mentees. He also discussed finding opportunities in chaos and how personal experiences can radically reshape perception of risk. Listen to all this and more in Humans of InfoSec’s latest episode.
Security researcher advocate Chloé Messdaghi, now vice president of strategy at Point3 Security, views cyber as a humanitarian issue. Through deploying tactics from her nonprofit experiences and graduate studies, Chloé seeks to challenge public misconceptions of the industry. In our latest episode, Chloé joined Humans of InfoSec to discuss her unconventional route into the industry, the ways in which her volunteer initiatives shape her cybersecurity work, and why diversity is harder than it seems.
Former Lyft CISO and fellow podcaster Mike Johnson takes his new job seriously: He’s a CISO on vacation. With nearly twenty years of infosec experience, including nine years leading teams at Salesforce, Johnson has witnessed tremendous changes in the industry. In this episode of Humans of Infosec, Johnson reflects on his career and path into cybersecurity, the IT industry’s transformation and the changing CISO's role, and more. He even discusses experimental ways to cook hot dogs.
Shane began his career in the military. Through his work in the intelligence community he became involved in broader cybersecurity policy, and for the past several years has been leading teams and initiatives in the private sector. He is currently the Director of Information Security at Zendesk. In this podcast, Shane examines the critical role of security operations (KLO/RTB), as well as, emphasizes the importance of taking care and leading people in infosec.
Ryan Stinson currently manages the Security Engineering Team at Hubspot, where he enjoys leading cybersecurity efforts in a fast-paced, customer focused environment.
He began his career as an Officer in the US Air Force, where he served in a variety of InfoSec roles within the DoD. Since that time, he’s developed a federated identity management suite for the Veterans Affairs e-authentication project, built a line of business focused on security assessment, penetration testing, and security architecture at a consulting firm, and managed the application security program at the Federal Judiciary.
Kim Jones is a former CSO who has built, operated, and managed information security programs within the financial services, defense, healthcare, manufacturing, and business outsourcing industries. In this podcast, Kim explores how he got into InfoSec and the impact that his military experience has had on his career.
Charles Nwatu began his security career when he was recruited by the NSA and worked for several years in the federal government at DISA, the Defense Information Systems Agency. He then moved west to focus on technology and start-ups. Charles has held security leadership roles at LinkedIn, Twilio, and Stitchfix.
Leigh is the founder and CEO of Tall Poppy, where she helps companies protect their employees from online harassment. She was previously a Technology Fellow at the ACLU’s Project on Speech, Privacy, and Technology, and also held a variety of security positions at Slack, Salesforce.com, Microsoft, and Symantec.
In this podcast Leigh talks about building software that defends people from online harassment, and shares her passion for security, diversity, and painting.
Coleen has been in the security field for 13 years, holding leadership roles at companies like Twilio and CoreLogic. Currently, she is the head of security at Segment. Coleen believes that every customer deserves to have a security org who’s advocating for the protection of their data. In this episode, she emphasizes the importance of building relationships and treating data with respect.
Manny is currently responsible for cybersecurity operations and IT risk at IAT Insurance Group. He is a data-driven and entrepreneurial security practitioner with extensive experience securing cloud and traditional environments with an emphasis on effective detection and response. In this episode, he emphasizes the importance of learning and talks about the balance between generating revenue, maintain productivity, and addressing risk.
In this episode, David talks about his passion for the unpredictable, smashing vulnerabilities, and how he uses humor and hard work to connect with people and build relationships at LinkedIn.
If you are interested in learning more about Cobalt.io and our Defcon promo follow the link: http://event.cobalt.io/demo-for-defcon-badge
Anne Marie is a cyber strategist with over 19 years of experience in 8 industries. Sitting at the intersection of business, security, and analytics, Anne Marie has served as a trusted advisor for Fortune 500 companies, government agencies, law enforcement, security vendors, and think tanks. She is currently a VP of Security Engineering at Mastercard, a member of the Board of Directors for SSH Security, a visiting National Security Institute Fellow at GMU’s Scalia Law School, and has held a number of strategic and technical security leadership roles in her past.
In this weeks episode, Mike Shema interviews host, Caroline Wong, to learn more about her information security journey. Hearing how she got her start in the infosec industry, exploring her passion for security metrics, and how being a mother has transformed how she manages her time and work.
Will Bengtson is senior security engineer at Netflix focused on securing the cloud as a member of the security operations and tooling team. He loves tackling hard problems that have high impact from both a success and failure standpoint. Prior to Netflix, Will led security at a healthcare data analytics startup, consulted across various industries in the private sector, and spent many years at a Department of Defense contractor. Will is highly active in the security community and is on the BSidesSF and Bay Area OWASP leadership team.
Rinki is an award-winning leader and executive in security innovation with experience leading and developing innovative online security infrastructure for Fortune 500 companies like PG&E, Walmart.com, and eBay as well as other large companies like Intuit Inc. and Palo Alto Networks. In this episode, she dives into how she has driven security culture transformation in her past roles.
Rachel was a winner of the DEFCON Social Engineering Capture the Flag (SECTF) competition 3 years in a row, and has shared her animated story, OSINT experience, and the modern threat of Social Engineering. During the day Rachel works at Course Hero, an online learning platform, in UX Research. In her spare time, Rachel works as the Creative Director for the nonprofit group, Women in Security and Privacy (WISP), where she empowers women to lead the converging fields. And the rest of her time is spent on, Social Proof Security, her co-founded SE cybersecurity company.
Rock established eBay’s Security Operations Center and led the security team on the technology integration of Mergers and Acquisitions including Skype and Shopping.com. He has also served in security roles for several global, multi-billion-dollar companies, including Marathon Petroleum, Honeywell, General Dynamics, Wells Fargo, and Agilent.
He built security programs from the ground up in industries with vastly differing security and privacy requirements and oversaw multi-million dollar security budgets. Rock led successful defenses against highly-publicized denial-of-service attacks and built and managed large Security and Network Operations Centers.
Throughout her career, Emily has held a number of technology roles, including system administration, DevOps, and incident response. She specializes in Unix security and is a co-author of a book on Solaris Security. Currently, she is a senior security engineer at Agari.
Jim has held a number of impressive security leadership positions at several companies including Aetna, JP Morgan Chase, and American Express. He has been a key player in the creation of some of the industry’s most effective information sharing communities - the FS-ISAC and the NH-ISAC. He’s also known for an uncommon approach to risk management: “Take risk to manage risk.”
Tanya Janca is a senior cloud advocate for Microsoft, specializing in AppSec. She is an ethical hacker, OWASP Project and Chapter Leader, Global Security Influencer, software developer, effective altruist, and professional computer geek with over 20+ years experience.
Tanya has given several local and international talks, in addition, to sharing her teachings via workshops, blogs, and other community events.
Ty Sbano built his information security career at a variety of financial services organizations and has also done work in the retail and technology sectors. More recently, Ty has been branching out as an industry leader, career coach, technology advisor, and is currently the Head of Security at Periscope Data. He currently specializes in the areas of software security, DevOps, Security Engineering, but he attributes a lot of specialization around the vertical of Security Culture.
Georgia wrote the infosec best-seller Penetration Testing: A Hands-On Introduction to Hacking. She’s currently a founder of Shevirah Inc. a security startup that specializes in mobile security testing, and Bulb Security a consulting firm that specializes in security assessments and training. Much of her work focuses on mobile and IoT exploitation, and assessing the risk of mobility in the enterprise and the effectiveness of preventative security tools in detecting and stopping attacks.
She’s an engaging speaker who gave her first presentation at ShmooCon several years ago and has since added premiere conferences like Black Hat and keynoting OWASP Appsec Europe to her resume. Most recently she conducted a hands-on exploit development class at the inaugural Defcon China.
Kavya Pearlman is the Information Security Director at Linden Labs, where she is responsible for protecting two virtual world economies. In the past, she has worked in a variety of industries including social media, insurance, law, and cosmetology. Kavya holds a masters degree in Network Security and has many information security certifications. This year, she was named on the IFSEC Global Influencers list.
Suzan is an award-winning information security executive who has been in the field since the year 2000. She’s worked in finance, healthcare, oil, software/website consulting and food-service industries. In addition to her current day job as SVP of Application Security, Suzan is also extremely passionate about career growth and leadership. She’s built a coaching methodology with her motto, “to lead others, learn to lead yourself first.”
Jimmy Sanders has held security leadership roles at a number of different financial and technology institutions - including SAP, Fiserv, and Samsung. Jimmy currently runs Information Security for Netflix DVD and provides leadership to our colleagues in the San Francisco Bay Area as president of the local ISSA chapter. On of his big passions in life is helping to grow and connect the information security community.
Patricia Titus was the Vice President and Chief Information Security Officer at Freddie Mac, Symantec, Unisys Corporation and the Transportation Security Administration within the Department of Homeland Security. She was focused on transforming, implementing and maintaining robust IT security programs. She is now the Chief Information Security Officer And Chief Privacy Officer at Markel Corporation.
Dave Tyson started his security career in physical security and transitioned into information security in the late 90s. In 2007, Dave published the book Security Convergence, which addresses the coming together of these two fields. He has since has been a CSO and CISO many times over, including at the City of Vancouver at a time when Vancouver was the host city for the 2010 Winter Olympics, Pacific Gas and Electric, and SC Johnson.
Kevin Greene started his security work at Ernst & Young and has throughout his career worked in a variety of leadership roles in both the public and private sectors. Recently, he led Software Assurance R&D at the U.S. Department of Homeland Security, where he built the SWAMP (Software Assurance Market Place) to provide continuous software assurance services to the public. Today, Kevin serves on the advisory board for the New Jersey Institute of Technology Cybersecurity Research Center and Bowie State University CS department, which led him to his current role at MITRE.
Caleb Sima started his security career as a consultant and X-Force researcher. Since then Caleb has built a number of security startups, one of the most well-known and successful startups being SPI Dynamics which was later acquired by HP. He later made the switch over to the defender side as a managing VP of cybersecurity at Capital One. Today, Caleb invests and advises start-ups.
Robert has built and lead security engineering and technology teams at Salesforce, and before that, he spent 8 years working in security at Microsoft. Today, Robert holds a number of board and advisory roles and is currently building a people-centric solution focused on the human element as a core defense strategy for organizations.
Paralegal, mountain cyclist, malicious code researcher at eBay, security operations at Wells Fargo, cybercrime novelist, and now a principal threat researcher at a Fortune 50 company, Robin Stuart talks about her roundabout journey into information security in Episode 3 of Humans of InfoSec.
Humans Of InfoSec Episode 2, Robert Wood has a vast portfolio of work ranging from building Cigital’s Red Team to running the trust and security team at Nuna Health. Robert is well known for his adversarial thinking and strategic planning approach to his work, and today one of the things he’s focused on is helping security professionals to advance their careers. Dive into Robert's information security origin story in Episode 2 of Humans of InfoSec.
Humans Of InfoSec Episode 1, Mike Shema started out as a gamer and hacker in the late 90’s. He was part of the elite Foundstone consulting group, built a web application security scanner at Qualys, and led the Product Security team at Yahoo. Today, Mike is the VP of SecOps and Research at Cobalt. Caroline Wong sits down with Mike and discusses his journey and talks about how he has gotten to where he is today.