eXecutive Security: Recent Episodes

Gene Fay

Conversations with CISOs and other important thought leaders offering advice for those wanting to enter the field, grow in the field of cybersecurity.

View Details

ThreatX surveyed 2,000 consumers in the US and UK about the cybersecurity skills gap – to get their thoughts on its causes and effects.

In this episode, Gene and ThreatX Field CISO Jeremy Ventura analyze the results, including:

  • 62% reported that if they or their child had more education around cybersecurity in school, they would have considered entering the field.

  • 90% reported that they are concerned about the future of cybersecurity if more isn’t done at an earlier stage to expose students to the field.

  • 78% are under the impression that a college degree is necessary to pursue a career in cybersecurity, and 67% thought a career in cybersecurity should be achievable through certifications or apprenticeships versus a 4-year+ college degree.

  • 52% say engaging students of all backgrounds earlier in STEM/cybersecurity courses it will help minimize the talent shortage among the cybersecurity industry.

Full survey results: https://info.threatx.com/hubfs/ug/ThreatX-global-2023-survey-cyber-talent-shortage.pdf

Jeremy Ventura on LinkedIn: linkedin.com/in/jeremy-ventura-36204676

View Details

What's the difference between working in fraud and working in cybersecurity? Nancy Schuehler, Director of Cyber Strategy and Program Execution at Verizon, has worked in both and breaks it down for our listeners.

She and Gene also dig into the pros and cons of working for a large enterprise, and of staying with one company for many years.

Nancy Schuehler on LinkedIn: https://www.linkedin.com/in/nancy-schuehler-87311610/

Verizon cyber recruiting: https://verizon.com/cybersecurity

View Details

No experience? No problem. In this episode, CISO Dane Jones explains how to build a resume that highlights a passion and aptitude for cybersecurity without any work experience in the field.

Dane Jones is CISO at HighRadius. He has been a security leader for many years, including at Lowe’s.

Dane Jones on LinkedIn: https://www.linkedin.com/in/daneejones/

Is a career in cybersecurity right for me? https://www.isc2.org/thank-you/is-a-career-in-cybersecurity-right-for-me 

(ISC)² Cybersecurity Workforce Study: https://www.isc2.org/Research/Workforce-Study# 

View Details

Cybersecurity is a great field because of the all the change, says Ted Julian. But to succeed, you have to be proactive about that change. Ted and Gene talk about how to keep up with the change, plus about his experience in the early days of cybersecurity, what it’s like to work in product management, and why joining an early-stage company is so beneficial.

Ted Julian has held leadership positions in several security companies, including Devo and Resilient. He is currently a Venture Partner at Glasswing Ventures.

Ted Julian on LinkedIn: https://www.linkedin.com/in/tedjulian/

View Details

Gene sits down with Stratejm CEO John Menezes to talk about working for an MSSP, plus gets John’s thoughts on hiring and nurturing the next generation of cybersecurity talent.

Stratejm: https://stratejm.com/

View Details

Success in cybersecurity is not about your technical skills, but your emotional intelligence, according to CISO Randy Raw. Randy and Gene talk about why he thinks this, plus his approach to hiring, why leaders need to be proactive in asking their reports how they want to be managed, why everyone needs both a coach and a sponsor, and more.

Randy Raw is the CISO at Veterans United Home Loans, where he has worked for almost 12 years. He is also a leadership coach at SABERS Coaching.

Randy Raw on LinkedIn: https://www.linkedin.com/in/randyraw/ 

Randy Raw’s blog: https://randyraw.com 

View Details

Lowe’s CISO Marc Varner has had a long career in cybersecurity, including CISO roles at Yum Brands and McDonald’s. Why does he think cybersecurity is a good career choice? Because there is always a new challenge. “What was the last really cool discovery or change in math?” he jokes. There’s something new in cybersecurity just about every day. 

Tune in to his podcast episode with Gene to hear more. They discuss his journey, keys to success in the field, skills from other experiences that are transferable to cyber, and what he is looking for in entry level candidates.

View Details

Why is the geopolitical landscape critical to cybersecurity strategy? CISO Mark Houpt breaks it down in this episode. Mark also shares his advice to the college and high school students he mentors, how to approach the ever-changing nature of cybersecurity, and how to think about a college education.

Mark Houpt is the CISO at DataBank. Previously he held senior security roles at organizations including State Farm, Lincoln Christian University, and Sallie Mae. Mark served in the US Navy from 1991 to 1999.

Mark Houpt on LinkedIn: https://www.linkedin.com/in/mark-houpt/

Mark’s recommended list of classes:

  • Microsoft CISO Workshop: https://learn.microsoft.com/en-us/security/ciso-workshop/ciso-workshop

  • Ascend Education: https://ascendeducation.com/monthly-subscription/

  • Amazon Cybersecurity Awareness Training: https://learnsecurity.amazon.com/en/index.html

  • Center for Development of Security Excellence: https://www.cdse.edu

  • ISC2 -Certified in Cybersecurity: https://www.isc2.org/1mcc

  • Cisco Networking Academy: https://skillsforall.com/course/introduction-to-cybersecurity

  • Cyberbit Remote Training: https://go.cyberbit.com/100k-worth-of-free-remote-cyber-range-training/?utm_source=nist_website&utm_medium=list&utm_campaign=free-remote-soc-team-training-nam

  • StationX - 12 Month Trial: https://www.cybersecurityjobs.com/csj-training-fund/

  • Cyber Training 365: https://www.cybertraining365.com/cybertraining/FreeClasses

  • Cyber Skyline Professional: https://cyberskyline.com/professional/purchase

  • Cybrary: https://www.cybrary.it

  • EC.Council: https://www.eccouncil.org/cybersecurity-exchange/free-cybersecurity-resources-2022/

  • Elastic: https://www.elastic.co/training/free

  • Evolve Academy: https://www.academy.evolvesecurity.com/cybersecurity-fundamentals

  • Federal Virtual Training: https://fedvte.usalearning.gov

View Details

How do you make the jump from ER nurse to SOC analyst? Alex Gatz did it, and he’s sharing his insights and tips with the eXecutive Security podcast audience. Don’t miss this fascinating discussion about making a bold career change, the power of LinkedIn, what a security researcher does, the benefits of working for a startup, and more.

Alex Gatz is a senior security researcher at ThreatX. Previously, he worked as a data analyst and ER nurse at MidMichigan Health.

Alex Gatz on LinkedIn: https://www.linkedin.com/in/alexgatz/ 

Stephen Semmelroth: https://www.linkedin.com/in/semmelroth/ 

We Hack Purple: https://www.linkedin.com/company/wehackpurple/ 

View Details

The job market has shifted dramatically in the past two years, and Mike Privette shares his thoughts on navigating it in this episode. He and Gene discuss things you can do TODAY to get your foot in the cybersecurity door. He also shares how his newsletter Secure the Job can help.

Mike Privette is the CISO, VP of Information & Cyber Security at Passport. He is also the founder of Return on Security, which publishes the Security, Funded and Secure the Job newsletters. Previously, he held cybersecurity leadership roles at various organizations, including Defiance Digital, Truist, MetLife, and Ally Financial.

Mike Privette on LinkedIn: https://www.linkedin.com/in/mikeprivette/ 

Secure the Job newsletter: https://jobs.returnonsecurity.com 

View Details

Key to a successful tech career? Re-inventing yourself every three years, says Faisal Bhutto, SVP of Cloud and Cybersecurity at Calian. Don’t go into tech if you’re not ready to be constantly learning and re-inventing yourself, he says. Hear more tips and advice from Faisal in his episode, including why money and promotions can’t be your only motivation, why you shouldn’t network only to look for a job, and how to get into cybersecurity without a tech background.

Faisal Bhutto is SVP of Cloud and Cybersecurity at Calian IT & Cyber Solutions. Previously, he was the co-founder of and COO at ENETsolutions.

Faisal Bhutto on LinkedIn: https://www.linkedin.com/in/fbhutto/ 

View Details

Corey Nenno (aka That Cyber Guy) just transitioned out of the military and into the cybersecurity industry in 2021 – so this is an ideal episode for those currently in the military looking to soon enter the cybersecurity field. It’s also one of our most practical episodes, whether you’re in the military or not – it’s filled with tips and advice on what to put on your resume, how to pass the CISSP, how to find a mentor, and more.

Corey Nenno is a Senior Cyber Intelligence Analyst at Cargill. Previously, he spent 12 years in the US Army in Cyber and Information Technology fields.

VetSec: www.veteransec.org 

Corey Nenno on LinkedIn: https://www.linkedin.com/in/coreynenno/ 

Cyber Mentor Dojo: https://cybermentordojo.com 

View Details

Alfredo Hickman fought the war on terror in the early 2000s in the Marine Corps infantry in Iraq. He shares some intense stories from his military experiences overseas with Gene, as well as how he transitioned from the front lines to a cybersecurity executive. Alfredo is passionate about helping veterans and giving back, and this episode is valuable for anyone looking to enter this industry, military or not. He shares details about his life and journey, his thoughts on cybersecurity trends in 2023, how the SANS Institute has been a resource for him and can be for others, his thoughts on mentoring, and more.

Alfredo Hickman is Head of Information Security at Obsidian Security. He previously held security leadership positions at Rackspace. Alfredo served in the US Marine Corps from 2003 to 2011.

Alfredo Hickman on LinkedIn: https://www.linkedin.com/in/alfredohickman/ 

Obsidian Security: https://www.obsidiansecurity.com 

SANS Institute: https://www.sans.org 

CyberMentoringMonday on Twitter and LinkedIn

View Details

David Cross’ advice for breaking into cybersecurity? Strategic use of gift cards. Get details on his networking through social media ideas in this episode. David transitioned out of the military into the world of high tech, where he has held numerous cybersecurity leadership roles. This episode is filled with practical tips and advice on demonstrating your skills to prospective employers, deciding what type of company to work for, transitioning military skills to the corporate world, networking, and more.

David Cross is the Senior Vice President, Chief Information Security Officer (CISO) of Oracle SaaS Cloud. Previously, he held senior leadership positions at numerous companies, including Google and Microsoft. David also served in the US Navy from 1991 to 1996.

David Cross on LinkedIn: linkedin.com/in/☢️-david-b-cross-b856657  

View Details

Zenobia Godschalk has worked closely with many cybersecurity companies over the years as the founder of ZAG Communications, a PR and marketing firm serving technology companies, and is now SVP of Communications for Hedera. She also does a lot of philanthropic work in the technology space.

LinkedIn: https://www.linkedin.com/in/zenobiaaustingodschalk/

Dark Reading Article: https://www.darkreading.com/remote-workforce/senior-level-women-leaders-cybersecurity-nonprofit

Forte Group:https://forte-group.org/home-our-mission

Andreessen Horowitz:https://a16z.com

View Details

Brian Castagna is the CISO at Seven Bridges, a leading biomedical data company. He is an experienced and skilled information security leader who has held security leadership positions at several organizations including Acquia and Oracle.

LinkedIn: https://www.linkedin.com/in/brian-castagna-1890544/

View Details

Jenn Reed has more than 25 years of product management and engineering experience in cloud networking infrastructure, security, governance, risk, and compliance across both the private and public sectors. She is currently CISO at Aviatrix, a cloud networking and network security company. Jenn served her country in the U.S. Marine Corps from 1995-2000 and again in 2003 during the Iraq war.

LinkedIn: https://www.linkedin.com/in/jennsreed/

View Details

Ramachandra Hegde is a senior executive with over 24 years of experience, including 12 years in global CISO roles, including with a Fortune 300 manufacturing multinational and a global professional services firm. He is currently senior vice president and CISO at Genpact.

LinkedIn: https://www.linkedin.com/in/ramkhegde/

View Details

Dan Schiappa, the chief product officer at Arctic Wolf, has been a technology leader for many years at organizations including Sophos, RSA Security, and Microsoft.

LinkedIn: https://www.linkedin.com/in/daniel-schiappa-bbb1062/

University of Central Florida News: https://www.ucf.edu/news/cybersecurity-team-wins-4th-national-championship/

Arctic Wolf: https://arcticwolf.com/company/careers/

View Details

Richard Ford is an experienced cybersecurity and technology leader. Currently the Chief Technology Officer at Praetorian, he has held leadership positions at many organizations, including Cyren, Forcepoint, and Raytheon. Richard also has a Ph.D. in Physics from the University of Oxford.

Personal LinkedIn: https://www.linkedin.com/in/dr-ford/

Praetorian LinkedIn: https://www.linkedin.com/company/praetorian/

ISC2: https://www.isc2.org

BSides: https://bsideslv.org

View Details

Lauren is just starting her career in cybersecurity. She has a bachelor’s degree in cybersecurity from Champlain College and is a SOC Analyst at ThreatX.

LinkedIn: https://www.linkedin.com/in/laurencampanara/

View Details

Ray has more than 15 years of experience in the information security space and is currently CISO at Inspectiv. He has held leadership positions at numerous organizations including, Cobalt.io, Amazon, Proofpoint, and Cisco.

LinkedIn: https://www.linkedin.com/in/ray-espinoza-b399821/

Black Girls in Cyber: https://www.blackgirlsincyber.com

View Details

Maarten Van Horenbeeck, who is the chief information security officer at Zendesk, has more than 15 years of experience managing security organizations, which includes building the cybersecurity-threat intelligence team at Amazon, and working on the security teams at Google and Microsoft. He is also a former board member and Chairman of the Forum of Incident Response and Security Teams (FIRST).

LinkedIn: https://www.linkedin.com/in/maartenv/

Chaos Computer Club: https://en.wikipedia.org/wiki/Chaos_Computer_Club

NIST: https://www.nist.gov

MITRE: https://www.mitre.org

Rand Institute: https://www.rand.org

FIRST: https://www.first.org

Cloud Security Alliance: https://cloudsecurityalliance.org

View Details

Defcon:  https://defcon.org  
Black Hat: https://www.blackhat.com 

View Details

Jim Routh has a long history in technology and cybersecurity as a leader and management consultant. He was formerly a cybersecurity leader for many large companies including MassMutual, CVS Health, Aetna, and JP Morgan Chase. He is also the former Board Chair for the Health Information Sharing & Analysis Center (H-ISAC) where he served for five years and former Board member for the Financial Services Information Sharing & Analysis Center (FS-ISAC). Jim currently sits on several Boards and acts as an advisor for several cybersecurity companies and venture funds. Jim brings to the boards a vast business and technology background and is considered a digital and cyber security industry expert and thought leader. Finally, Jim is an ICIT Fellow and an Adjunct Faculty member for NYU.

The Role of Cybersecurity Leaders as Educators: https://icitech.org/wp-content/uploads/2022/03/ICIT-Fellow-Perspective-The-Role-of-Cybersecurity-Leaders-as-Educators.pdf
LinkedIn: https://www.linkedin.com/in/jmrouth/

Jim Routh's Book List:
Cybersecurity and Cyberwar by Singer and Friedman

Dark Territory by Kaplan

The Perfect Weapon by Sanger

Sandworm by Greenberg

The Cuckoo’s Egg by Stoll

Spam Nation by Krebs

Future Crimes by Goodman

Data and Goliath by Schneier

Confront and Conceal by Sanger

The Fifth Domain by Clarke

America the Vulnerable by Brenner

The Code Book by Singh

Algorithms to Live By by Christian and Griffiths

Your Government Failed You by Clarke

Sting of the Drone by Clarke

Countdown to Zero Day by Zetter

Software Security: Building Security In by McGraw

@War by Harris

Fight Fire With Fire by Tarun

Kingpin by Poulsen

The Age of Surveillance Capitalism by Zuboff

The Internet in Everything by DeNardis

Senior Cyber by Schober

CISO Compass by Fitzgerald

This Is How They Tell Me the World Ends by Perlroth

Crimedotcom by White

Big Breaches by Daswani and Elbayadi

Innovating in a Secret World by Srivastava

Cyber Mayday by Lohrmann and Tan

Navigating the Cybersecurity Career Path by Patton

Tribe of Hackers by Carey and Jin

The PtaaS Book by Wong

CyberJutsu by McCarty

Cyber Defense Matrix by Yu

Shape by Ellenberg

So You Want to Talk About Race by Oluo

White Fragility by Diangelo

Hos to Be an Antiracist by Kendi

View Details

Ron is President at Gula Tech Adventures, which focuses on cyber technology, cyber policy and recruiting more people to the cyber workforce. Since 2017, GTA has invested in dozens of cyber start-ups and funds and supported multiple cyber nonprofits and projects. From 2002 to 2016, Ron was the co-founder and CEO of Tenable Network Security. He helped grow the company to 20,000 customers, raise $300m in venture capital and grow revenues to $100m, setting up the company for an IPO in 2018. Prior to Tenable, Ron was a cyber industry pioneer and developed one of the first commercial network intrusion detection systems called Dragon, ran risk mitigation for the first cloud company, was deploying network honeypots in the mid 90s for the DOD and was a penetration tester for the NSA and got to participate in some of the nation's first cyber exercises. Ron was also a captain in the Air Force.

LinkedIn: https://www.linkedin.com/in/rongula/

Gula Tech Adventures: https://www.gula.tech

Cybrary, Free Cybersecurity Training and Career Development: https://www.cybrary.it/

SANS Institute: https://www.sans.org

View Details

Bill Brown is an accomplished information technology and information security leader with experience leading M&A Security Due Diligence Response and Remediation, and leading global teams in start-up, mid-size, and Fortune 1000 companies. Currently he is CISO and CIO at Abacus Insights and an advisory board member to ThreatWarrior. He has also held security leadership positions in ClickSoftware, Houghton Mifflin Harcourt, Veracode, and Iron Mountain.

LinkedIn: https://www.linkedin.com/in/billbrownusa/

HIPPA: https://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act

Hiitrust: https://en.wikipedia.org/wiki/HITRUST

PII: https://www.techtarget.com/searchsecurity/definition/personally-identifiable-information-PII

Cyber Warrior: https://www.cyberwarrior.com/

Cloud Security Alliance: https://success.impartner.com/English/Customer/home.aspx

View Details

James Carder is an experienced Chief Security Officer, research and development leader, cyber security services expert, and go to market executive with over 26 years in both corporate security and consulting for public and private companies across various industries, the Fortune 500, and U.S. Government. Currently, he is the Chief Security Officer at iOffice + SpaceIQ. James also served in the Air Force.

LinkedIn: https://www.linkedin.com/in/carderj/

Twitter: https://twitter.com/carderjames

ISSA: https://www.issa.org/

OWASP: https://owasp.org/

Cloud Security Alliance: https://cloudsecurityalliance.org/

BSides: https://bsideslv.org/

U Minnesota Certificate Program: https://bootcamp.umn.edu/cybersecurity/

View Details

Ian Amit is an executive manager in the security and software industry with vast experience in multiple fields - from enterprise security, through retail, to end-user software, large back-end systems, corporate security policy, regulatory compliance, and strategy. He has spoken at various customer-focused seminars such as DEFCON, RSA, BlackHat, BSides, and many more.

LinkedIn: https://www.linkedin.com/in/iamit/

DEFCON: https://defcon.org

BSides: https://bsideslv.org

View Details

Tanya Janca, also known as SheHacksPurple, is the author of ‘Alice and Bob Learn Application Security’. She is also the founder of We Hack Purple, an online learning academy, community and weekly podcast that revolves around teaching everyone to create secure software. Tanya has been coding and working in IT for over twenty years, won numerous awards, and has been everywhere from startups to public service to tech. She values diversity, inclusion, and kindness.

LinkedIn: https://www.linkedin.com/in/tanya-janca/

Jobs in InfoSec: https://shehackspurple.ca/2022/01/01/jobs-in-information-security-infosec/

We Hack Purple Community: https://community.wehackpurple.com/

CyberMentoringMonday: https://twitter.com/search?q=%23CyberMentoringMonday&src=typed_query&f=live

View Details

Chris Wysopal is Co-Founder and Chief Technology Officer at Veracode, which pioneered the concept of using automated static binary analysis to discover vulnerabilities in software. In the 1990’s, Chris was one of the original vulnerability researchers at The L0pht, a hacker think tank, where he was one of the first to publicize the risks of insecure software. Chris started his career as software engineer that first built commercial software and then migrated to the specialty of testing software for vulnerabilities. He has led highly productive and innovative software development teams and has performed product strategy and product management roles.

Chris is a much sought-after expert on cybersecurity. He has been interviewed for most major technology and business publications, including New York Times, The Washington Post, WSJ, Forbes, Fortune, AP, Reuters, Newsweek, Dark Reading, MIT Tech Review, Wired, and many networks, including BBC, CNN, ABC, CBS, CNBC, PBS, Bloomberg, Fox News, and NPR. He has keynoted cybersecurity and technical conferences on 4 continents.

Link: Chris Wysopal LinkedIn
Link: Cult of the Dead Cow by Joseph Menn

View Details

David McLeod is the VP, Chief Information Security Officer at Cox Enterprises. He is an experienced Chief Information Security Officer who has demonstrated success across multiple industries. David has extensive skills in Privacy, Enterprise Risk Management, IT Strategy and Governance, and Information Risk Management.

David McLeod LinkedIn

View Details

Patti Titus is the Chief Privacy and Information Security Officer at Markel Corporation. She also serves on the Board of Directors for Black Kite and the Girl Scouts of the Commonwealth of Virginia. She was recognized as a 'Woman of Influence' by the Executive Women’s Forum in 2009 and the Silicon Valley Business Journal in 2013.

Patti has held numerous leadership positions in the cybersecurity industry, including at Freddie Mac, Symantec, Unisys Corporation and the Transportation Security Administration within the Department of Homeland Security.

Patricia's Linkedin
SANS Institute

View Details

Eric Richard, SVP Engineering and CISO, Hubspot
Linkedin

SANS Institute

View Details

Special thanks to Tom Quinn for joining us in this episode:

  • Tom Quinn on Linkedin

MomentumCyber: https://momentumcyber.com/ 
Girl Security: https://www.girlsecurity.org/

View Details

Hello and welcome to the eXecutive Security podcast where we talk to CISOs and other leaders in cybersecurity about a career in this industry, specifically how to get into it, and how to advance. My name is Gene Fay and I'm the CEO of ThreatX an API security company and the host of the eXecutive Security podcast.

I started this podcast because of my two passions, cybersecurity and helping people find jobs in cyber. Over the last 17 years, I've been blessed to meet so many amazing people within this industry. People who taught me not only about cybersecurity, but how to be a great leader. For a while I've been thinking about how I can give back to the cybersecurity industry, which has been so good to me.

Also, I've been thinking about what I've learned from great leaders in this space, and I can share this knowledge with a lot of people. So this [00:01:00] is how this podcast was started. 

If you were just thinking about getting into cybersecurity and want to learn how to get started, or if you're in the field and aspire to be a manager, VP, or CISO, this podcast is for you.

I hope you enjoy it. If you have any suggestions on guests or topics you want us to cover in the future, please send me an email at genedotfayatthreatxdotcom. Thanks a lot and I hope you enjoy the podcast.