Explore every episode of the podcast Getting Into Infosec
| Title | Pub. Date | Duration | |
|---|---|---|---|
| DEFCON 2023 | 03 Aug 2023 | 00:05:34 | |
Hey folks, I'll be at DEF CON in Vegas this year! Would love to see you all there!
yFDrTl54ZSu3KAmLWbmi Mentioned in this episode: | |||
| Rana Khalil - From Cryptography to Pentester! | 11 Mar 2022 | 00:39:32 | |
Journey into Cybersecurity and OSCP Certification with Rana Khalil This episode features Rana Khalil, a Senior Cybersecurity Assessment Analyst with a rich background in pen-testing, especially in the financial sector. Rana shares her non-traditional entry into technology, starting with a dislike for her first laptop and phone, transitioning from biochemistry to a math degree, and eventually finding a passion in computer science, leading her to cryptography and cybersecurity. Her academic journey includes significant work in cryptography, under the tutelage of Carlisle Adams, and a master’s project on web application vulnerability scanners. Rana discusses her motivation and relentless pursuit of the OSCP certification, highlighting the importance of hands-on experience, teaching, and documenting the learning process through write-ups. She also conveys the value of previous experience in related fields, the significance of specializing and pacing in learning, and shares insights into her career progression, including valuable advice for people aspiring to enter the cybersecurity field. 00:00 Introduction and Guest Background 01:47 Rana's Journey into Cybersecurity 02:45 Rana's Early Interest in Mathematics and Cryptography 05:47 Transition into Computer Science and Web Security 10:52 Master's Research on Web Application Vulnerability Scanners 13:02 First Security Job and the Impact of Public Speaking 15:11 Journey to the OSCP Certification 17:36 The Value of Self-Study and Accountability 18:53 Reflections on the OSCP Experience 20:59 Understanding the OCP Exam 21:13 The Importance of Lab Time 22:18 The Value of Documenting Your Journey 22:49 Introduction to the OSWE Certification 25:07 The Role of Experience in Security 25:16 The Life of a Security Professional 25:25 The Importance of Specialization in Security 26:24 The Value of Previous Experience in Security 29:55 The Challenges and Rewards of Pen Testing 30:43 The Balance of Work and Personal Time in Security 34:58 The Importance of Focusing on One Area in Security 37:07 The Importance of Understanding Source Code 38:11 Final Thoughts and Advice Thank you for listening! Mentioned in this episode: | |||
| ICS Gabe - Electrical Engineer to Accidental Cybersecurity ICS Expert | 11 Oct 2020 | 00:59:24 | |
Gabriel Agboruche (@ICS_Gabe) is a senior ICS and OT cybersecurity consultant, helping organizations solve their most challenging industrial control security problems. And that was a mouthful, but that's what he does. His journey's unique one, and almost didn't happen. Notes
Quotes
Links
Getting Into Infosec Info
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| BONUS - Lisa Jiggetts - Salary Negotiations | 16 Aug 2020 | 00:16:26 | |
Lisa Jiggetts is the founder of the Women's Society Of Cyberjutsu. After recording, we continued talking and the topic of salary negotiations came up. It was so good I started recording again. This topic is super important. I have seen both experienced and inexperienced people make these mistakes. Links
Getting Into Infosec
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Switching Into Infosec Success Story And Lessons Learned | 16 Jul 2020 | 00:10:12 | |
Today's episode features a story that was sent to me by a listener. He reached out to me on LinkedIn, telling me of his success story posted on Reddit. This is the audio version. I think you're going to be really interested in what he had to say. He talks about his struggles and what he went through in his journey to Information Security. Original Reddit post: Getting Into Infosec Links:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Black Lives Matter | 02 Jun 2020 | 00:01:12 | |
Transcript Hey everyone… So, as if this time was not hard enough as it was with Covid, the American Black community has been affected yet again. It's difficult to post motivating content while so many are feeling a sense of outrage and so much going on. So I'm going to pause, slow down, or at least take into consideration the posting of new content during this period. Of course, people still need to work, so I can't stop completely, and I do have episodes coming down the pipe. There's a personal story I want to share related to this. A friend and I were driving once, but he realized he left his wallet at home, which had his driver's license. I said, "Not a big deal. They can just look you up if you get pulled over." He then looked at me, and I then figured it out: he's black. It hit me then how privileged of a life I had. It then hit me how scary driving while back really is. I may not be white, Christian, and from the suburbs, but I'm not black and male. I may not have the best things to say at this moment, but I realize staying silent isn't an option. I don't have a TV, and I'm not on Twitter often, but the little I did see made me realize silence or status quo is almost as bad. Diversity and inclusion are an integral part of this podcast. I've never called it out as I just wanted my lineup to speak for itself. Many of my guests are black. For the longest time, it was rare to see a brown or black person at a security conference. It was quite lonely. For listeners outside of the US, please try to empathize with whatever social divide you have in your country. It could be the religious minority in your country, the darker-skinned, those of a "lower" social caste, the poor, or whomever it may be. There are always those that are marginally suppressed or oppressed. So…. I stand with the Black community against racism, violence, and hate. Now, more than ever, we must support one another as allies and speak up for justice and equality. ****************************************** Website: https://gettingintoinfosec.com/ Twitter: https://twitter.com/coffeewithayman See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| BONUS - Announcing Getting Into Infosec BITES | 14 May 2020 | 00:04:01 | |
Hello! Wanted to let you know I'm creating daily (almost) videos on YouTube called Getting Into Infosec BITES: https://www.youtube.com/c/gettingintoinfosec Please like, subscribe, and spread the word. The best thing you can do to support this media is to spread the word and let others know. Thanks! Links:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Kavya Pearlman - From Hairstylist to CISO to XR Superhero | 18 Apr 2020 | 00:38:39 | |
Kavya Pearlman is an award-winning cybersecurity professional with a deep interest in immersive and emerging technologies. Kavya is the founder of the non-profit XR Safety Initiative (XRSI). XRSI is the first global effort to promote privacy, security, ethics, and develop standards and guidelines for Virtual Reality, Augmented Reality, and Mixed Reality (VR/AR/MR), collectively known as XR. Kavya is constantly exploring new technologies to solve current cybersecurity challenges. Quotes:
Links:
Getting Into Infosec:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| BONUS - Pandemic and The Coming Recession / Depression | 03 Apr 2020 | 00:06:35 | |
We are in the middle of a worldwide pandemic (COVID-19), a recession is here, a depression might be coming, and everyone is remote! Everything has changed. What can you do? How can you find a job in these crazy times? What are the challenges? How can you make yourself valuable? What's going through the company or hiring manager's mind? Please share or leave an awesome review if you found this helpful. See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Syntax - Arrested Teenager to Motorcycle Racer To Pentester | 10 Mar 2020 | 00:47:27 | |
Syntax, an internal pentester for a large organization, had an interesting ride into infosec, filled with pitstops, detours, and countersteering along the way. At an early age, he was influenced by his father, got started hacking, and was wrongfully arrested for reporting a vulnerability in his High School. Hear his exciting journey into infosec, filled with life lessons. Shownotes
Quotes
Links
Getting Into Infosec
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Bonus - Cyber Security Job Search Frustrations (Ivan) | 07 Mar 2020 | 00:02:43 | |
These are quick hallway conversations with recent graduates discussing the difficulties they've faced in their job search. I did not know any of these people before interviewing, and it's the first time I'm asking them these questions. This was recorded at RSA Conference 2020. Getting Into Infosec:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Bonus - Cyber Security Job Search Frustrations (Zoe) | 06 Mar 2020 | 00:05:00 | |
These are quick hallway conversations with recent graduates discussing the difficulties they've faced in their job search. I did not know any of these people before interviewing, and it's the first time I'm asking them these questions. This was recorded at RSA Conference 2020. Getting Into Infosec:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Norman Weekes— From Contractor To Security Ops Analyst | 25 Feb 2022 | 00:33:42 | |
Norman Weekes is on the Security Operations Team at Salesforce. He is in charge of scanning their infrastructure and ensuring that everything is set up and operating properly. Norman already spent almost a year in the information security world. This is also his first official full-time security job. After going through different job contracts, he believes that if everything's shut down early, there's no reason not to just get in a good routine and go after whatever certification or whatever job you want. This episode will undoubtedly inspire and assist job contractors who are considering a career in the information security world. LINKS Linkedin: https://www.linkedin.com/in/normanjr/ Security and Privacy Framework: iapp.org Full Show Notes: https://www.gettingintoinfosec.com/ Mentioned in this episode: | |||
| Bonus - Cyber Security Job Search Frustrations (Jayesh) | 06 Mar 2020 | 00:03:59 | |
These are quick hallway conversations with recent graduates discussing the difficulties they've faced in their job search. I did not know any of these people before interviewing, and it's the first time I'm asking them these questions. This was recorded at RSA Conference 2020. Getting Into Infosec:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Bonus - David Zeichick - Cybersecurity College Professor | 04 Mar 2020 | 00:11:54 | |
So as I was at RSAC, I was trying to keep an eye out for those looking to get into the field. RSA is not usually the place for that, but I saw the NetWars tournament and figured that might be a good place to start. On my way there, I met David Zeichick, who had "College Day" on his badge. Intrigued, I asked about "College Day," and he told me all about it. I sat down with him for an impromptu interview on the topic. Links
Getting Into Infosec:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Tanya Janca - From Insecure Developer to Appsec, Diversity/Inclusion Advocate, and Mentor | 23 Feb 2020 | 00:38:59 | |
BIO Tanya Janca, also known as SheHacksPurple, is the author of ‘Alice and Bob Learn Application Security.’ She is also the founder of We Hack Purple, an online learning academy, community, and podcast that revolves around teaching everyone to create secure software. Tanya has been coding and working in IT for over twenty years, won numerous awards, and has been everywhere from startups to public service to tech giants (Microsoft, Adobe, & Nokia). She has worn many hats: startup founder, pentester, CISO, AppSec Engineer, and software developer. She is an award-winning public speaker, active blogger & streamer and has delivered hundreds of talks and trainings on 6 continents. She values diversity, inclusion, and kindness, which shines through in her countless initiatives. Founder: We Hack Purple (Academy, Community, and Podcast), WoSEC International (Women of Security), OWASP DevSlop, OWASP Victoria, #CyberMentoringMonday Notes
Tanya's Quick List For Getting Into Infosec
Quotes
Links
| |||
| Nick Vissari - Engineering Dropout to Math Tutor to Security Architect/Engineer | 04 Feb 2020 | 00:35:40 | |
Nick Vissari went from being an engineering dropout (he didn't like creative writing) to a tech consultant to a math tutor. His penchant for fixing things homed him back into tech, where he is now responsible for security in a large school district. He recently went back to school and received his cybersecurity degree as well. Notes
Quotes:
Links
Getting Into Infosec
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Page Glave - Professor of Kinesiology to Cybersecurity Analyst! | 16 Nov 2019 | 00:31:21 | |
Page Glave was a tenured Associate Professor of Kinesiology with a focus in exercise science and was successful in her field. However, she came to the realization that she can't see herself doing this for the rest of her life. She offers lots of great advice on resume tips when switching, homelabs, certifications, and how she was able to break into the field. This is her story. BIO I am an analyst, project manager, ethical hacker, and tech consultant with more than 10 years’ experience with research and project management. I spent a while in higher education – long enough to get tenure and decide it was time to do something else. I have eJPT (eLearnSecurity Junior Penetration Tester), Security+ and Splunk User certifications. I love learning and tech, so digging into all of this stuff just makes me happy. Notes:
Quotes:
Links:
Getting Into Infosec:
| |||
| Nick Jeswald - Confessions of a Cybersecurity Recruiter (Part 2) | 02 Nov 2019 | 00:48:29 | |
Part 2 of 2 - Nick Jeswald has been an external and internal recruiter in security. He shares with us what he looks for in a candidate, common mistakes made by candidates, and the nuances of hackers he's learned over the years. Show Notes SEE PREVIOUS EPISODE FOR COMPLETE NOTES & RECRUITING TIPS FROM NICK. Getting Into Infosec:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Nick Jeswald - Confessions of a Cybersecurity Recruiter (Part 1) | 25 Oct 2019 | 00:36:33 | |
Part 1 of 2 - Nick Jeswald has been an external and internal recruiter in security. He shares with us what he looks for in a candidate, common mistakes made by candidates, and the nuances of hackers he's learned over the years. BIO: I've been in infosec for 8 years, and in various IT roles since 1996 (Developer -> Sales Engineer -> BD Specialist -> Security BD -> Security Recruiting -> Dir. Corp Dev). However, I've also been one of the top recruiters for each company I worked at whatever role I've had. Show Notes:
| |||
| September 2019 Update | 23 Sep 2019 | 00:02:34 | |
Summer was crazy. My day job was keeping me super busy, and I've been really mentally occupied lately dealing with kids, family, and school. I miss producing shows and will be getting back into it. Have some really good shows queued up! I've still active on Twitter when possible, so we can stay in touch there in between shows. Oh, and by the way, it's been a year since I started podcasting! Pretty cool. So many things I want to do with the show, like animating my spoof ads and transcribing the shows. Anyway, just wanted to update you and let you know I didn't forget about you. I can't wait to release some of these amazing shows. As we depart, here is a draft of a spoof ad I put together real quick. It talks about my love of the word "cyber." See you next time. Getting Into Infosec:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Fareedah Shaheed - From Tech Curious to Information Security | 31 Jul 2019 | 00:33:25 | |
Fareedah, a lifelong learner, was always interested in technology and grew up reading her father's Cisco books. His influence led her to the field of information security, where she stepped up and is always tackling new challenges. BIO Fareedah Shaheed was born in Maryland, but spent most of her childhood outside of the US. She returned to the States in 2013 and attended the Community College of Baltimore County (CCBC), where she majored in cybersecurity. Her experiences with different cultures and the tech field led her to combine her interest in psychology with cybersecurity, and thus, her passion for security awareness was born. In 2018, she founded Sekuva with the mission to educate and support small business owners and families with understanding how to secure their sensitive information. She currently works as a Security Control Analyst at a financial firm in Maryland. Notes:
Quotes:
Links:
Getting Into Infosec:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| BONUS - Updates, Defcon, More | 26 Jul 2019 | 00:04:41 | |
Hey, everyone! It's been a while, I know. Life has been busy. Lots of transitions, so schedule has taken time to get used to. Links
Getting Into Infosec:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Niru Ragupathy - From Almost Biotech to QA to Google Security Lead | 05 Aug 2021 | 00:44:53 | |
Niru Ragupathy is a Security Engineer at Google and works as the Offensive Security Lead and manages part of the Offensive Security Team. She is currently the Tech Lead Manager. Niru sees managing as a challenging, interesting ride yet undervalued skill. She also considers it rewarding although it demands the investment of both time and effort. She believes that it is important to start leading and take things slowly but not take the decision lightly. Having planned on taking Biotech in College but being persuaded by her parents, she was thrust to take on Computer Sciences since it has greater demands in society. In the face of her struggles, Niru has found her sense of belongingness in security management. This episode will surely encourage and benefit Engineers who struggle in transitioning on management. LINKS Linkedin: linkedin.com/in/niru-ragupathy-99078233 Mentioned in this episode: | |||
| Keya Horiuchi - From Teacher, Filmmaker, and Website Design to Security Engineer! | 15 Jun 2019 | 00:29:51 | |
Keya was a public school teacher who stood out from the crowd. She loves problem-solving and challenging environments. Keya was also a filmmaker and web designer. She's currently a detection security engineer who gets knee-deep in malware on a daily basis. Notes:
Quotes:
Links:
Getting Into Infosec:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| BONUS - Audiobook Sample! | 05 Jun 2019 | 00:04:20 | |
Listen to the retail audio sample of my book: Breaking IN - A Practical Guide to Starting a Career In Information Security. Kati Fredlund narrates the book. She did an amazing job! You can read a sample or purchase the whole book here: https://t.co/DDXxfVwpD7 Full Audiobook to be released soon! See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Hossam Mohamed - Young Hacker to "Not A Security Researcher" | 26 May 2019 | 00:29:14 | |
A 19-year-old "not a security researcher" facing limitations because of his age and not having the right "prerequisites," Hossam has had to pave his own path. He also dreams in code and is one of the youngest OSCEs in the world! BIO Hossam Mohamed is one of the youngest OSCE in the world and currently working in the cybersecurity domain for a financial company in Istanbul. His area of interest includes exploit development, offensive security, secure web development, and malware analysis. He is a big Python lover. Notes
Quotes:
Links
Getting Into Infosec:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| BONUS - Consuming VS Producing | 21 May 2019 | 00:02:30 | |
My thoughts on consuming vs. production and how it relates to Getting Into Infosec. Sometimes, we get stuck learning, consuming security news, trends and etc, but we forget to produce something. Whether it be testing a new exploit we heard about, trying something new in our lab, or applying something we learned the day before, finding the right balance is important. If we're stuck, take little steps—better than no steps. Links: Getting Into Infosec:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Izzy - Random and Unplanned: From Annuities to ISO! | 13 May 2019 | 00:36:33 | |
Ismaelle Vixsama (aka Izzy) has a knack for finding strategic flaws and speaking up about them. Doing so helped her get her first full-time job as well as have repercussions for defensive egos. Her whole career is a war story. BIO: Izzy is an ISMS manager with 7 years of experience. She has worked in FinTech, Government, and Security R&D. Her work has allowed her to work on several mainstream products and services with some of the most well-recognized brands. Notes:
Quotes:
Links
Getting Into Infosec:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| David Scrobonia - Lifelong builder, Appsec Engineer, Creator of ZAP Heads Up Display | 04 May 2019 | 00:35:13 | |
From Zero to One, David is a lifelong builder. Wherever he goes, he just builds things. From an electric car to Adhoc android apps to ZAP HUD to an awesome heads up display for ZAP Proxy, he's a game-changer, IMHO. We discuss the lack of UX in the security tooling community, how contributing to Open Source got him his job, and even about imposter syndrome. BIO David Scrobonia is part of the Security Engineering team at Segment, working to secure modern web apps and AWS infrastructure. He contributes to open source in his spare time and leads development for the OWASP ZAP Heads Up Display project. Notes
Quotes
Links
Getting Into Infosec:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| BONUS - CliffsNotes To The First 20 Episodes! | 27 Apr 2019 | 00:31:21 | |
Having completed 20 episodes, I decided to take a moment to go over each episode briefly. Thanks to call my guests! Ep01 - Dan Borges: https://twitter.com/1njection Ep02 - 0daySimpson: https://twitter.com/0daySimpson Ep03 - Christina Hanson Ep04 - Matt Toth: https://twitter.com/willhackforfood Ep05 - Rob Carson: https://twitter.com/robcarson05 Ep06 - Robin Stuart: https://twitter.com/rcstuart Ep07 - Clay Wells: https://twitter.com/ttheveii0x Ep08 - Elvis Chan: https://twitter.com/FBISanFrancisco Ep09 - Virtual Kyle Kennedy: https://twitter.com/Kyle_F_Kennedy Ep10 - InfoSteph: https://twitter.com/StephandSec Ep11 - Yaron Levi: https://twitter.com/0xL3v1 Ep12 - Jack Rhysider: https://twitter.com/JackRhysider Ep13 - Marcus Carey: https://twitter.com/marcusjcarey Ep14 - Nipun Gupta: https://twitter.com/nipungupta Ep15 - Adrian Kaylor: https://twitter.com/AdrianKaylor Ep16 - InfosecSherpa: https://twitter.com/InfoSecSherpa Ep17 - InfosecJon: https://twitter.com/InfoSecJon Ep18 - Masha Sedova: https://twitter.com/modMasha Ep19 - Jared Folkins: https://twitter.com/JF0LKINS Ep20 - Leron Gray: https://twitter.com/mcohmi Getting Into Infosec:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| BONUS - MCOHMI New Song, Trap Music, and Domain Song Background | 17 Apr 2019 | 00:04:25 | |
MC OHM-I (Leron Gray) talks about his next project about tabs in the browser, trap music, and some background on his awesome song, "Domain." Getting Into Infosec
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Leron Gray - From Navy E6 to Pentester, SANS Mentor and Nerdcore Rapper! | 13 Apr 2019 | 00:38:18 | |
Leron Gray is a man of many talents. Although he didn't really get into infosec until much later in life, he always had a creative side. He now finds himself as a pentester working from home and a nerdcore rapper producing amazing beats! BIO Leron is a penetration tester and a ten-year Navy veteran with four years of experience as a Cryptologic Technician (Networks), focusing primarily on offensive cyber operations. He holds a Bachelor's degree from Dakota State University in Cyber Operations. With a passion for Python, he loves automating tedious daily routine tasks for efficiency and considers himself to always be in a position to learn more and pass on knowledge. He always enjoys competing in as many Capture-the-Flag events as possible and also often performs as a nerdcore rapper. Leron currently holds eCPPT, eWPT, GPYC, GPEN, GAWN, GCFE, and GICSP certifications. He also maintains a blog and maintains an active Twitter discussing music, information security, and wrestling. Notes
Quotes
Links
| |||
| Jared Folkins - 18 YRO Manager To Education Security To Human Hero | 03 Apr 2019 | 00:54:33 | |
Jared Folkins understands people, technology, and the world around him. He can smell a toxic environment from a mile away and has used that EIQ spider-sense for good. Jared shares with us some VERY personal stories (tear-jerker warning!) in integrity and life decisions as well a bunch of on-the-job war stories, including a famous one featured in the news! This is probably my most dramatic episode yet. Notes:
Quotes:
Links:
Getting Into Infosec:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| John Gates - From Car Mechanic to Lead IT Security Analyst | 16 Jun 2021 | 00:36:45 | |
John Gates is a Lead IT Security Operations Analyst for a global food brand. John has always liked to know how do things work - and that has proven to be a beneficial trait - from his first job as a car mechanic to IT consultancy and education to his current role. He’s also an advisor and former board member at OpsecEdu, an organization educating technologists in state, local, and education agencies on security best practices. LINKS Linkedin: https://www.linkedin.com/in/johngates/ OpsecEdu: https://www.opsecedu.com/ Intro Music: https://trash80.com/#/content/133/weeklybeats-2012-week5
Full Show Notes: https://www.gettingintoinfosec.com/john-gates-from-car-mechanic-to-lead-security-analyst/ See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Masha Sedova - From Generations of CS to Behavioral Science and Entrepreneurship | 22 Mar 2019 | 00:46:11 | |
Masha Sedova comes from a history of computer scientists! Her grandmother was in the first Computer Science graduating class in 1954 under Stalin in the Soviet Union! She loves challenges and is now utilizing what she thought was a waste of time in Liberal Arts to conquer challenges in Information Security using behavioral science, emotional intelligence, and other human factors. BIO Masha Sedova is an industry-recognized people-security expert, speaker, and trainer focused on engaging people to be key elements of secure organizations. She is the co-founder of Elevate Security, delivering the first people-centric security platform that leverages behavioral-science to transform employees into security superhumans. Before Elevate, Masha Sedova was a security executive at Salesforce where she built and led the security engagement team focused on improving the security mindset of employees, partners, and customers. In addition, Masha has been a member of the Board of Directors for the National Cyber Security Alliance, and a regular presenter at conferences such as Black Hat, RSA, ISSA, Enigma, and SANS. Notes
Quotes
Links
| |||
| BONUS - InfosecJon Learns Trust But Verify The HARD way | 21 Mar 2019 | 00:07:21 | |
InfosecJon expands on some CRAZY follies he experienced during his times in the Navy. He learns through trial by fire, literally: trust but verify! Notes
Getting Into Infosec
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| InfosecJon - From Rudderless Youth to Navy Engineer to Security Professional | 16 Mar 2019 | 00:45:43 | |
InfosecJon runs a website cataloging his learning and dedicated to helping others get in the field. He shares his personal story from a directionless youth to enlisting in the Navy (and its follies) and his tribulations getting into the field. He also shares some interesting Navy stories. Look out for the bonus episode! BIO Jon is a father, husband, and a veteran. He went from an aimless youth to enlisting into a career path he never liked. After 7 years as an electrical engineer, he got the chance to pursue his dream of working in information security. Now, he runs a website devoted to helping others. Notes
Quotes:
Links
Resources
Getting Into Infosec:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| InfosecSherpa - From Travel Agent to Law Librarian to Security Analyst! | 01 Mar 2019 | 00:44:38 | |
Tracy Maleeff (@InfosecSherpa) was a professional law librarian and at the top of her game. Looking for change and meaning, she searched until she found the field of Information Security. This is her journey. BIO Tracy Z. Maleeff (/may-leaf/), @InfoSecSherpa, is an independent information professional providing research and social media consulting with a focus on information security. She is a frequent presenter on best practices of data mining from social media, professional networking, and introduction to information security topics. Tracy has 15 years of experience as a librarian in academia, corporate, and law firm industries and earned a Master of Library and Information Science from the University of Pittsburgh. She is the Principal of Sherpa Intelligence LLC–your guide up a mountain of information. Notes
Quotes
Links
Resources
Getting Into Infosec
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Adrian Kaylor - From Network Admin to Trainer to Sales Engineer for Life | 22 Feb 2019 | 00:35:27 | |
Adrian is a Sr. Sales Engineer at Splunk who focuses on security. He has worked for various security startups in the Bay Area for the past 15 years from vulnerability management to endpoint investigation to ML-based threat hunting. Notes:
Quotes:
Links: Please thank my guests for sharing their time with us and let them know if this episode helped you.
Learning Resource Mentioned: Getting Into Infosec:
| |||
| Nipun Gupta - From Security Consultant to Security Innovator | 10 Feb 2019 | 00:23:36 | |
Nipun graduated during the recession, but found a job as a consultant which helped him gain experience quickly. He was in fact discouraged to pursue a career in information security due to his immigrant status. Nipun is now a Cyber Security Executive focused on innovation. BIO: Nipun Gupta is a Cyber Security Executive at a large global financial institution focusing on innovation. Armed with many years of experience helping Fortune 500 companies solve cyber risk challenges, Nipun is tasked to help his employer discover, adopt, access new cybersecurity solutions protecting against emerging threats. In the past two years, Nipun co-founded and ran the global Cyber Innovation Ecosystem strategy at a global consulting company with a specific focus on US and Israeli startups. He offers a strong network of security executives, startup founders, and the Venture Capital community in the West Coast and abroad. Technically proficient in network and application security, Nipun is a trusted advisor for many financial service institutions, technology, and telecom companies contributing to solutions worth tens of millions of dollars. Nipun completed his Masters of Information Technology and Information Security at Carnegie Mellon University, and has been collecting industry certifications like CISSP and SABSA ever since. Notes:
Quotes
Links:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| BONUS - My Book is OUT: Breaking IN: A Step-by-Step Guide to Starting a Career in Information Security | 25 Jan 2019 | 00:00:56 | |
My book is out! Breaking IN: A Step-by-Step Guide to Starting a Career in Information Security https://www.amazon.com/gp/product/B07N15GTPC See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Marcus Carey - Childhood Builder/Breaker to Navy Cryptologist to Founder and Mentor | 11 Jan 2019 | 00:43:34 | |
Marcus Carey has been hacking since he was five. A true MacGuyver, he had to make do with the little resources available to him. He later enrolled in the Navy, worked for 3- letter agencies including the NSA, and now has his own security startup. Marcus shares a TON with us in this episode. BIO Marcus is renowned in the cybersecurity industry and has spent his more than 20-year career working in penetration testing, incident response, and digital forensics with federal agencies such as NSA, DC3, DIA, and DARPA. He started his career in cryptography in the U.S. Navy, and holds a Master’s degree in Network Security from Capitol College. Marcus regularly speaks at security conferences across the country. He is passionate about giving back to the community through mentorship, hackathons, and speaking engagements, and is a voracious reader in his spare time. Notes:
Quotes:
Links:
| |||
| Jack Rhysider - From Odd-jobs to Network Analyst to SOC Architect to... Darknet Diaries! | 02 Jan 2019 | 00:47:36 | |
With an engineering background, Jack found himself doing odd jobs at first. Looking to get back into tech, he certed up and got a job in the NOC (Network Operation Center) and eventually became a SOC architect building a SOC from scratch. Looking to do something different, he started Dark Net Diaries, and it's been an adventure since! This is Jack Rhysider's origin story. BIO Jack Rhysider started his professional career in a NOC. He then became a network security engineer doing a lot of work to harden the network and detect threats in the network. He became a security architect and successfully built a SOC for a MSSP. He's currently the host of the podcast Darknet Diaries, where he interviews hackers or those who've suffered a major attack. The podcast has experienced phenomenal growth, so Jack now works on it full time. Notes
Quotes:
Links:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Yaron Levi - Entrepreneur to Security Architect to CISO and Security Champion | 25 Dec 2018 | 00:35:13 | |
Yaron Levi is the CISO for Blue Cross and Blue Shield of Kansas City. We talk about what he looks for in people when hiring in Infosec and a time when he took a chance on someone (against the opinion of his peers), and his chance was a big success. We also discuss a breach he had to deal with only 3 months into his job! BIO Yaron Levi is the CISO for Blue Cross and Blue Shield of Kansas City (Blue KC). In this role, he manages a team responsible for information risk management, cyber defense, regulatory and compliance, architecture and engineering, and identity and access management for an organization that provides health insurance for about 1 million members and has over $2B in annual revenue. Prior to joining Blue KC, Yaron was a Director of Information Security for Cerner Corporation, an Information Security Business Partner for Intuit, an Information Security Architect and Product Manager for eBay, and a Director of Cloud Security for ANX. Yaron is a Research Fellow for the Cloud Security Alliance (CSA). The Research Fellow designation is the highest honor and distinction given to a CSA research volunteer who has demonstrated significant contributions to CSA research. Yaron is a co-chair and lead architect of the Cloud Enterprise Architecture. Contributor to the Consensus Assessments Initiative Questionnaire (CAIQ), Cloud Controls Matrix and promoted the CSA as best practice in various cloud projects with various Fortune 500 companies. Yaron is the co-founder of the Kansas City CISO forum, B-Sides Kansas City, and is a frequent speaker on Cyber Security Architecture, DevSecOps, and Cyber Defense. Yaron holds a B.A. in Social Sciences and Management and is a graduate from the FBI CISO Academy. Notes:
Quotes:
| |||
| Samantha Cowan - From National Parks Service To Head Of Compliance | 01 Jun 2021 | 00:40:24 | |
Samantha Cowan is the Head of Compliance at HackerOne. She's the former Director of Compliance at OneLogin and former Security Engineer at CoverHound, Cyber Policy, and Zenefits. Sam initially perceived Infosec as an "unhappy job", but later found herself taking her MBA and paving her way into the security industry. Despite having her master's degree, she was not an exemption to facing rejections when applying for cybersecurity. Her episode is mind-blowing as she shares how you can break into boundaries by being confident in yourself and by not compromising to being seen as a token hire. LINKS
---------------------------------------------- Follow @coffeewithayman on Twitter for more For more information check out: gettingintoinfosec.com See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| InfoSteph - From Journalism to IT Support to Security Analyst | 18 Dec 2018 | 00:54:07 | |
Steph is brand new to the infosec field! We go over her interesting and eventful path into Information Security, reflections on her role today, and some fascinating war stories! BIO: Steph is a Security Analyst for a retail company makes up the team of one. She has a background in journalism and web hosting. She is the creator and editor of StephAndSec.com, a blog focused on technology, inclusion, and lifetime learning. Stephanie's life work is to encourage and fight for more diversity and inclusion in tech spaces for more innovative and original collaboration. She spends her time mentoring high school students, hosting virtual labs via Women In Tech-a-thons, and learning as much as she can about anything and everything. Stephanie believes that giving back to the community at every stage is very important. In addition to technology, Stephanie has a secondary passion for Psychology, so don't be frightened if you hear her discuss cognitive distortions or attachment styles. She hopes to develop research that explores the dichotomy between human beings and technology. She is currently on a mission to speak at three events in 2019 and has already been booked for one event. Notes:
Quotes:
Links:
... | |||
| Virtual Kyle Kennedy - Stories, not resumes: Breaking educational and other barriers in cybersecurity | 11 Dec 2018 | 00:09:28 | |
Today's episode is a reading of an amazing written by Kyle Kennedy, president of brainbabe.org. The reading is performed by Allison, an IBM Watson personality. I also go through some recent resources discovered to help you on your journey to a Career in Infosec. BIO: Kyle F. Kennedy is a social cybersecurity expert and president of brainbabe.org. His organization provides foundational soft-skills training for a small fee (supported by corporation donations) and plans to launch soft-skill Masterclasses in 2019. They helped organize an event called Day of Shecurity for women of diverse backgrounds to have one day of learning: tech/ hard skills, soft skills. They had opportunities for mentorship and guidance. Day of Shecurity was FREE to attendees! Links:
Full Text of Article: When you search for images under the key word “cybersecurity,” a familiar shot always turns up: a guy wearing a hoodie, operating in a dark room, fingers on a keyboard. I’d like to replace that image with…anything. To be a cybersecurity professional, you can be anything. And anyone. We’ve heard the statistics. There is currently a human capital crisis, with 1.5 million cybersecurity jobs available and no takers. The number is projected to balloon to 3.2 million by 2021. But who exactly are these cybersecurity professionals we are looking for? For so long, we have had our own definition of who can fit that talent. A good cybersecurity professional has to have a computer science degree. They must have solid professional background. They have to be male. This pattern of defining success has led us to the shortage we are experiencing today. It’s kind of like insanity, really: Doing the same thing over and over and expecting different results. What really makes up a good professional? Every human being brings a different experience. You need critical thinking and creative thinking, both. A variety of educational, ethnic, geographical, backgrounds. For example, cybersecurity is not the obvious career path for someone with a biology degree; however, a biology major might help throw a new perspective on cybersecurity given that advancements of technology will eventually interface with the human body organically creating a scary threat landscape. Often too we talk about cybersecurity in the context of oil and gas, or transport, or finance. Cybersecurity today and going forward, is a... | |||
| Elvis Chan - From Making Computer Chips to FBI Supervisory Special Agent! | 05 Dec 2018 | 00:36:00 | |
Elvis Chan is a Supervisory Special Agent Elvis Chan, who works cybersecurity matters for the FBI San Francisco Division. We discuss how we got into the FBI, Life in the FBI Cybersecurity Division, and how to get involved. The FBI is always looking for qualified applications for Special Agent and professional staff positions. Please see https://www.fbijobs.gov/ for more details. Notes:
Quotes:
Links:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||
| Clay Wells - From SysAdmin to Security Architect to Con Organizer! | 27 Nov 2018 | 00:34:55 | |
Clay Wells has been living in kernel/userland since Red Hat 4.0 Colgate. Worklife has primarily been in academia and has included programming, system administration, and information security. He's a point of contact for the DC215 group and one of the Blue Team Village coordinators at DEF CON. He also created unofficial CTF challenges for local hacker cons and organizers for the first annual WOPR Summit this March 2019 in Atlantic City. Clay, a security architect, musician, Defcon Blue Team Village Co-Organizer, and organizer of the first annual WOPR Summit, shares some really insightful tips on making it Information Security, as well as a fascinating recent war story. WOPR Summit is March 1st, 2019, in Atlantic City! Quotes:
Links:
See omnystudio.com/listener for privacy information. Mentioned in this episode: | |||