--- title: "Caroline Wong — Self-care and self-aware for security people" url: https://appsecpodcast.com/caroline-wong-self-care-and-self-aware-for-security-people/ date: 2019-06-14 duration_seconds: 2450 guests: ["Caroline Wong"] topics: ["Security Culture", "Careers in AppSec"] audio: https://www.buzzsprout.com/1730684/episodes/8122641-caroline-wong-self-care-and-self-aware-for-security-people.mp3 transcript: true --- # Caroline Wong — Self-care and self-aware for security people *June 14, 2019 · 41 min* with [Caroline Wong](https://appsecpodcast.com/guests/caroline-wong/) on [Security Culture](https://appsecpodcast.com/topics/security-culture/), [Careers in AppSec](https://appsecpodcast.com/topics/careers/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122641-caroline-wong-self-care-and-self-aware-for-security-people.mp3) ## Show notes A successful security career can still become unsustainable when work crowds out everything else. Caroline Wong shares the experiences that changed how she thinks about self-care, boundaries, and professional growth. She traces her career through security leadership roles, then describes the costs of neglecting her own needs and the difficulty of recognizing a problem while caught in it. Chris and Robert ask about work-life balance, vacation policies, and how a manager’s response shapes the real culture behind a company’s promises. Caroline offers questions candidates can ask prospective teammates and discusses what happens when personal values and organizational priorities diverge. Her advice encourages both individuals and hiring managers to pay attention to people, communicate honestly, and make deliberate changes. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Caroline Wong: → [Caroline Wong on LinkedIn](https://www.linkedin.com/in/carolinewmwong/) Mentioned in this episode: → [Cobalt](https://www.cobalt.io/) → [Security Metrics: A Beginner’s Guide](https://www.amazon.com/Security-Metrics-Beginners-Guide-Caroline/dp/0071744002) Chapters: 00:00 Self-care and self-awareness with Caroline Wong 02:19 Caroline’s path into security leadership 11:28 What self-care means and why it matters 18:29 Rethinking work-life balance 21:13 Vacation policies and real workplace culture 25:03 Questions to ask during interviews 26:13 Learning from prospective teammates 28:12 Other pressures that undermine well-being 31:34 When personal and organizational priorities conflict 32:55 Turning awareness into practical changes 33:27 Advice for hiring managers and individuals ## Transcript *5,949 words · assemblyai* **0:00 Chris Romeo:** Caroline Wong has had a long career in security, starting with eBay and leading to her role today at Cobalt.io as Chief Strategist. Caroline shares her explanation of self-care and tells her story about how neglecting self-care led to problems. She offers ideas about how to better approach self-care as a security professional, work-life balance, and ways for approaching a successful career in security. I want to take a moment to introduce you to Security Journey. At Security Journey, we believe security is every developer's job. We work with our customers to help them build long-term sustainable security culture amongst all their developers. Our approach is to provide security education that is conversational, quick, hands-on, and fun. We don't do lectures. Instead, we let the experts talk about what's important. The modules are quick, 10 to 20 minutes in length. We believe in hands-on experiments, builder and breaker style that allowed developers to put what they learned into action. And lastly, fun. Training doesn't have to be boring. We make it engaging and fun for the developers. Visit www.securityjourney.com to sign up for a free trial of the Security Dojo. The Application Security Podcast. Here we go. **1:44 Caroline Wong:** Go. **1:44 Robert Hurlbut:** Hello folks, and welcome to another episode of the Application Security Podcast. This is Robert Hurlbut, a threat modeling architect And I'm joined here by Chris. Chris? **1:55 Chris Romeo:** Hey folks, welcome. **1:57 Robert Hurlbut:** And also today we are joined by our guest, Caroline Wong. Thanks for joining us, Caroline. **2:05 Caroline Wong:** It's my pleasure. Thank you so much for having me. **2:08 Robert Hurlbut:** Absolutely. And so typically as we begin, we like to ask those who are with us to give us their security origin story. So tell us how you got started. **2:19 Caroline Wong:** Sure, so I will start by telling you about Caroline as a 16-year-old girl, and the reason I do that is not because I was taking computers apart. It was because my Chinese immigrant father asked me what I wanted to study in college, and I told him that I would like to study dance or psychology, because as far as I was concerned, I liked school. I liked my subjects equally, and the only difference it made was really did did I like my classmates? Did I have friends in my class, and did I like my teachers? So I thought okay at that point in time. I thought okay you're supposed to study what you think is interesting. So I really enjoyed dance. Still do, and psychology I've always found to be fascinating. So my my Asian immigrant father says. Well, I'll tell you what, you're not going to study dance and you're not going to study psychology. You are going to apply to the top engineering programs in California. I grew up in San Francisco and my dad didn't want me to move to the East Coast and then, you know, start a family and never come home. So he said, you're going to apply to the top engineering schools in California and whichever one you get into, you're going to attend. And so I ended up studying electrical engineering and computer science at UC Berkeley. So my junior year, I look for a summer internship. I understand that this is something you're supposed to do, and so I do. And at the time, I happened to be dating someone who lives in Silicon Valley. So I'm living in San Francisco, this person is living in Silicon Valley, and so I decide to focus my job search on Silicon Valley, and I go on the internet and I look for jobs that I might qualify for, and I end up getting this internship in IT project management at eBay, and I, and I love it. And at the end of that summer, I say to— well, I guess, okay, the summer ends, uh, the next summer comes around and I graduate. And so I contact my internship manager and I say, Carl, uh, you know, I really enjoyed working on your team last summer. I'd really love to discuss opportunities to work on your team full-time. And he says to me, Caroline, you know, we'd love to have you join the team, but unfortunately we have a hiring freeze right now. There are no IT positions open. He said, but there is an entry-level information security job available. And this was the summer of 2005. So PCI DSS, the first version of PCI DSS, had been released in December 2004. eBay, of course, as a public company, was very interested in IT security controls for SOX, and so they were looking for a policy and compliance analyst. And, and when I heard about this, I said, Carl, I literally have not heard the term information security before. And he said, you know, I think that's okay. I think you should give it a shot anyway. My understanding is they're looking for a college grad to train, you know, so you're not, you're not really expected to have a ton of experience. And so one thing led to another, and I got kind of my first big break in 2007 on the eBay global information security team when Dave Cullinane joined the company as our vice president and CISO. He joined us from Washington Mutual, and Dave asked me to be the chief of staff for the team. And he went to eBay's executives and he said, look, this company allows strangers to transact with each other on the internet. We are not doing enough about application security. We are significantly underinvested. And so I worked with him to put together the plans to build out the organization. We had started as a, as a roughly 25-person team based in San Jose, California, and we grew that to an international team of about 64 folks. And so it's funny because Now I'm on the vendor side and I have a different perspective on, oh, you know, when you hear that someone like eBay all of a sudden is growing their team, you know, all the vendors find out right away. And so at that time, I, I was taking a lot of vendor meetings. I am— Dave is the type of person with a very open-door policy. He's, he's a humble learner. He's always interested in learning from folks. And so I had the opportunity to hear a lot of vendor pitches, and we invested in some technology, and we kicked off some projects, and we hired some folks. And 6 months in, Dave said to me, okay, Caroline, now that we have the money, and now that we have the people, and now that we have the projects, we need the metrics because we need to show the value of the program. We need to communicate to eBay's executives what value they're getting for their money. And we also need to help them understand that this is not a one-time thing. They need to invest every year. And so that for me was a very exciting problem to solve. A couple of years later, I had the opportunity to publish a book on that topic, Security Metrics: A Beginner's Guide. And then sort of made my way around. You know, it's funny because when I think about each of my career transitions, they were always— they always kind of stemmed from a personal reason. So when I was in college and I looked for my internship, I based my job search around the person I was dating at the time. When I switched jobs, from eBay to Zynga, it was because I was sick of driving from San Jose— San Francisco to San Jose every day. I wanted a job with a shorter commute. And then after Zynga, I switched over to the vendor side. I started out in product management at Symantec for the Control Compliance Suite product, which was a lot of fun. And I actually— I really, really enjoyed my team there. I think that for me, as I look at my career, the things that made a great job a lot of times was the people, and I really, really, really liked my Symantec team. But I happened to be there during a time when Symantec actually had 4 CEOs in 4 years, and it was a It was, it was a challenging place to be because of that reason. And so I end up doing management consulting for Sigittal, which was later acquired by Synopsys, and performing BSIM assessments, which I really, really enjoyed doing. Sammy Miguez is one of my favorite AppSec people on the planet, and Sammy and I, we did something like 3 dozen or so BSIMs. **10:00 Robert Hurlbut:** Wow. **10:01 Caroline Wong:** And then my daughter was born. And when she was a year old, she's 4 now, I thought to myself, okay, you know, traveling around the world and, and spending one week in Sweden and one week in Tokyo and one week in Beijing and meeting with people and talking to them about software security, you know, this is work that I really love, but I really want to be home. I really want to be home more with my family. I've got different priorities now. And so I started looking for a job close to home, and I found Cobalt, cobalt.io, which is where I'm now currently the Chief Security Strategist. It's been a lot of fun. When I joined the company in 2016, we were a team of 8, and we're actually projected to almost 3 years to the date of when I joined, we're expecting to grow the team to about 80 people. So it's just been super duper fun, and I focus on security and strategy and people, which I think is uncommon but which I really enjoy. So I'm actually, for the first time in my career, a human resources professional. I'm in charge of human resources and specifically recruiting. So it's got me kind of thinking about and looking at our industry in a new way that I haven't before. **11:28 Robert Hurlbut:** Well, a lot of stuff going on there. I mean, that's fantastic just to see all the transitions. And I think it also really impressed me was some of those transitions as a result of, as you said, personal decisions. And I think it reminds myself certainly, and Chris I'm sure too, is that, you know, we can say all the things that we do professionally, but ultimately we're still people. Right? And we're all people in security, and some of the decisions we make are always going to be or will be personal decisions that we make and how they influence ourselves as persons in this industry. With that in mind, I mean, one of the reasons why we wanted to reach out to you is I did notice that you had recently given a talk or was giving some talks on self-care. I know one of the episodes that we have done in the past was about burnout. But could you tell us about that self-care and what does that mean? **12:28 Caroline Wong:** Sure. So to me, self-care is, as you said, the acknowledgment that security teams are made out of people and people are human. And there are things about us as human that affect the way that we behave and that affect our work. And, and I'm so interested in figuring out how to get security teams to work as top performers and how people can be most effective. And I believe I've come to discover myself personally that I actually perform my best at work when I'm taking care of myself as a person. And I think that, you know, there are some things that because of our biology as human beings are common. You know, I think that we certainly tend to be healthier and therefore think better and feel better when we're getting, for example, enough sleep, when we're getting, for example, proper nutrition. You know, those are some of the baseline things. And then beyond that, I think it depends on the specific individual, you know, whether we're introverted, whether we're extroverted, you know, what other sorts of things. We need to feel whole and to feel full, full of energy that we can then put into our work and into whatever areas of our lives we choose. You know, for me, I, I get a lot of energy from spending time with my family and with our pets. You know, for other folks, it might be hiking, it might be music, it might be, you know, whatever it is. that you do, you know, not only with your time, but more importantly, I think, with your mind in order to make yourself happy. I think that, I think that that's really sort of the antidote, if you will, for burnout. And I'll share a brief story about my own burnout because I did not always know these things. Going back to the story that I shared, you know, as a new college grad working on a growing information security team at one of the world's largest e-commerce websites, I had some very cool opportunities. You know, I was, I was given projects to do, and I was able to complete those projects. And when my boss was pleased with my work, he would give me more work to do, you know. And I think that's something that happens to a lot of security professionals. When you do a good job at what you're doing, you get more work. And when you're sort of used to delivering good work and you get more work, you want to continue delivering at that same level of quality. And I think the way that a lot of people try to approach that is by putting in more hours. And at this point in my life, I was living with my parents, commuting. And so a day for me looked like, okay, a weekday, I should say, you know, I'm up at 5, on the road by 6, in the office at 7, you know, working until 7, and then either headed home on the road, or maybe I'm having dinner and then heading home, you know, and then I'm going to sleep. So it's a very full day. **16:21 Robert Hurlbut:** Yeah. **16:23 Caroline Wong:** And I remember distinctly one night, it's a Friday night and I'm out with girlfriends in the Marina District of San Francisco and we're having cocktails. And I remember feeling so tired. I couldn't even enjoy a night out with my friends because I was just so tired. I was so depleted. I had such a long list of to-dos. **16:48 Robert Hurlbut:** Yeah. **16:49 Caroline Wong:** And I just, I really was not even able to enjoy myself. And so at that point I realized, okay, I've gotta make some kind of change. And I didn't know how to go about it. And so I went about it in sort of a funny, rather formal way because I didn't know how else to go about it. I had Kaiser Health Insurance at the time. And I signed up for a class. I signed up for a class on mindfulness and stress management. So of course, you know, I have this very full schedule and I add something to the schedule, but I did learn a series of techniques during that class, which I did find to be helpful. But the most important thing I think for me that needed to change, that did change over time, was this idea that I had to change the way that I thought. But before, I used to think, okay, I've got work to do. If I work for more time, I will get more work done. I had tried that, and I had found out that there was a point at which that didn't work anymore. And so I had to switch my thinking, and I had to come up with sort of a new belief system. And that involved seeing myself as a human with human needs, and not simply as, you know, a program that you, that you run and you run more and you run longer. And so that's, that's when, for me, I began to try and turn things around. **18:29 Chris Romeo:** Caroline, we always hear about people talking about work-life balance. And I feel like we're kind of doing a disservice almost as an industry because people throw that term around, work-life balance, but normally, it's kind of just an idea. Like, when you work in a big tech company, if you don't have an unbalanced work-life balance, then you never get ahead is what it seems like. So, what's been your experience with that term and kind of what are your thoughts when you hear work-life balance? **19:02 Caroline Wong:** Sure. So to me, work-life balance is actually an outcome of 2 factors. I'll say 3 factors. One of them is organizational culture. Another one is an employee's direct manager. And the third, and I would, you know, the third I was about to say most important, but, but really all three of them matter, is the employee his or herself. Now you've got organizations, uh, there's a big tech company in Silicon Valley, and this tech company, you know, on paper and on their careers page and when they're doing recruiting will talk about how they support families. You know, they say, well, uh, when you have a child, uh, we're gonna give you 4 months of parental leave. And that sounds pretty cool. However, this particular organization, their culture is actually such that when you're working there and you're interacting with the other folks that work there, you get this sort of vibe And this feeling, this underlying message that says, don't you dare take 4 months of leave, you know, because, because you're needed here, because you owe it to the company, because you owe it to your team, because, you know. And so that, so that is one example of, uh, a company culture that, that, that I think on some level may have tried to do the right thing, um, but the reality is Company culture doesn't come from policies. It can be supported by policies, but when it comes down to it, it comes from behavior. It comes from the individual managers and their behaviors and what people see as the norm. **21:13 Chris Romeo:** I think about the unlimited vacation. I almost want to say fallacy at the end of that because from what I've heard is, at least, and I don't have any studies, I think there are some, I don't have anything in front of me to back this up. But from what I've heard, the organizations that have that unlimited vacation results in people taking less vacation than they would have in a traditional 2 to 4 weeks a year, use it or lose it type of scenario. **21:41 Caroline Wong:** I have heard that also. And, and I, I would not be surprised if that is true. And the thing is, you've— if that's important to you, you've got to evaluate an organization's culture not just by what it says on the website, but, but what it really is. And then of course, as an employee, You've gotta ask for what you need. You know, if I need to take my daughter to the doctor, you know, I really wanna feel comfortable messaging my team on Slack and saying, hey everyone, I'm taking my daughter to the doctor. You know, I'm gonna be available from 11:00 AM to 2:00 PM, you know, but text me if you have something urgent, you know, whatever that looks like. And then what happens is, The response is what creates the culture, right? So if I send a message like that and my manager responds by saying, you know, thanks for letting us know, hope everything goes okay, then that is a supportive culture. You know, if my manager responds and says, okay, well, you know, what about A and B and C? You know, where are we with all this stuff? And, you know, there's different ways to respond to something like that. Um, you know, and, and employees, I think there's this concept that I discovered. Uh, Daniel Meesler told me about this the first time I presented my Self-Care for Security Professionals talk. At the time it had a different title. It was a little more edgy. Uh, Motherhood, Mental Illness, and a Career in Cybersecurity. I presented it at an OWASP meeting in the San Francisco Bay Area. And Daniel said, you know, Caroline, your talk reminds me of this concept that I learned about called psychological safety. And Google had actually conducted a study in 2012 where they sought— they went out and they tried to figure out what are the key attributes of a high-performing team. And they evaluated like half a century's worth of academic studies and they gathered all this data. And they found that one of the really key concepts is this idea of psychological safety. The idea that you could share something with your team members and that you wouldn't be ridiculed for it. And You know, I think we have all in this industry experienced or observed situations that were not psychologically safe, you know, where either we or we saw someone say something and then immediately they were ridiculed, you know. And there's something about that culture that I think inhibits I think it inhibits innovation. I think it inhibits trust between people. And so, I think there's an opportunity for us to continue to learn in this area. Yeah. **25:03 Chris Romeo:** And I think your description there of the organizational culture and then the employee's direct manager and then ultimately the employee, kind of their perspective, it just makes me think that we are in such a hot industry with lots of opportunity. And folks probably don't even think about this or realize how much control we actually have as those people who are being interviewed for new jobs. You know, when that interviewer asks you, hey, do you have any questions? That's, you know, we all know that's the time you're supposed to ask questions to appear like you're, you know, very interested in the opportunity. But that's also an opportunity to ask questions about the culture and kind of get a really solid inside look on The environment that you're potentially going into here, because, you know, if you choose incorrectly and you don't pay attention to these things, you may end up in one of these pressure cooker type of environments where everybody's working 60 hours a week. And if you're, you know, if you're not in the office working at your desk or in the office on Saturday from, you know, 8 till 5 PM, then you're seen as an outcast. That's something you want to find out in the job interview process though. I don't want to learn that in my first week of work. Yeah. **26:13 Caroline Wong:** Absolutely. I think that's a fantastic tip. I think that in an interview process, a very valuable question to ask is, hey, can you put me in touch with somebody on the team who would be my peer? Because I'd really like to talk to that person about their experience. Um, and You know, personally, if I were interviewing for a company, I might say, hey, can you put me in touch with somebody on the team who is a parent with young children? Because I'd really like to speak with that person about what his or her experience is like, you know. And so there is an opportunity, especially for security professionals who are interviewing. I think there is what I've referred to as a silver lining. To the cloud that is the talent shortage, which is that it's a supply and demand situation. And if you are the supply, there is high demand. And while I'm not going to say it's easy to get a job in security, there certainly is demand. There is a market if you have skills, if you are developing skills in this area. And so I think that You know, not everyone in every industry can say, oh, I have a choice between job A or job B. But I would say that more people who are experienced in security and who are developing skills in this area will have options to choose from. And there's something very cool about that. Because it gives you some leverage. It gives you some leverage in a hiring process to really evaluate what you're getting yourself into. **28:12 Robert Hurlbut:** You brought up some, some interesting things about potential burnout and how, especially in those cultures or the company cultures where they're overworked, they're Not sure if they're safe. I like that word safety, especially. Those seem like they might contribute to burnout, perhaps. Are there some other things that you can think of or have seen that might contribute? That if you're not doing this proper self-care, finding those situations and understanding the company culture before you join, if you can, are there some other things that you've noticed? **28:55 Caroline Wong:** So one thing that I've noticed, which I find fascinating, is that it can be difficult to prioritize our work. I think that some security people are perfectionists and they would like to do everything to 100% quality and Given a finite amount of energy, given a finite number of hours, it may not be possible to perform 10 tasks at 100% perfection, which is what some people would like to try and do. Um, it may, however, be possible to perform 3 tasks to 100% perfection and 7 tasks to a medium level or a low level. And I think that part of self-care, as well as part of organizational alignment, is to understand as a security professional what are my priorities. And that is often related to what are the priorities of my team and what are the priorities of my organization. I have been frustrated as a security team member when I get the impression that other business and technology folks at my organization don't understand why security is important. And to me, that lack of alignment is a misunderstanding on both sides. So if an organization is creating value, they want it to be secure. If that value is stored or transmitted digitally, then then we've got you know an IT security issue. So the so security folks, I think I think some security folks tend to think that everything is of utmost importance, and and and some security folks want to do everything perfectly, and so that can lead to burnout. And and I think that. One of the things that, that I've tried to learn how to do throughout my career is I've tried to learn how to prioritize and how to get on the same page as my manager with regards to my priorities and how to, you know, understand the linkage between the organization's priorities, the security team's priorities, and then my priorities. **31:34 Robert Hurlbut:** What if those don't match? **31:36 Caroline Wong:** What if they don't match? **31:39 Robert Hurlbut:** Yeah. What if they don't match altogether? **31:41 Caroline Wong:** Yeah. What if they don't match? I think that's a very realistic question. What do you do if you're a security professional and you're working at an organization that doesn't give a shit about security? I think you should— there's 2 approaches. You either try and change the situation, which depending on your role, you may or may not be able to do, or you leave. You know, to me, that's, that's really it. **32:09 Robert Hurlbut:** And that can be part of it too, right, for self-care. You know, you're— I mean, you want to do the best you can. You take pride in your work. You, you know, you're certainly, as you, as you said, as you're in security for a while, you get better at it. People know you're good at it. They hire you because you're good at it. But at the same time, you may be doing multiple jobs. You may be doing other people's jobs. All kinds of things that could happen as a result of wanting to be better and better and better and continue to perform at the same level of excellence and quality and so forth. But again, you also have to consider yourself and your— how well can you make all this work, really? **32:55 Chris Romeo:** Yeah. Yeah, let's, um, let's transition now and talk about some kind of direct actionable things, because my gut says that a number of people that listen to this are going to be nodding their head through a whole lot of the conversation here going, yep, yep, yep. And, and now they're sitting here thinking, okay, now what do I do about this? And so, Caroline, I'd love to hear your perspective on, okay, I, I know, I understand I have the problem now. Now what do I do in the first 30, 60, 90 days to, to make some change? **33:25 Robert Hurlbut:** Cool. **33:27 Caroline Wong:** Thank you. Thank you for asking that question. So first, I'm going to offer a tip for hiring managers because I think that in particular for security folks, I would be curious to know of the number of folks that are listening to this podcast episode, how many of them are on security teams with open headcount? And I would guess that there's a lot. And because a lot of folks are on teams with open headcount, that means that, you know, they're filling in. They're doing the job of the folks who haven't yet been hired. So the first piece of advice that I have is actually for hiring managers. Hiring managers, So here's something that I've observed that I think is interesting. Where do good security people come from? An easy response might be to say, well, if I want someone to do application security, then one way to go about that is to look for someone who has 5 years of application security experience on their resume. That is a relatively small pool of candidates, and a lot of those candidates, particularly the good ones, are already employed and probably well compensated. The reality, of course, is that great security people come from all sorts of different places. I will briefly mention a podcast that I host called Humans of InfoSec. It's a, it's a small show. We've only done about 2 dozen episodes to date. And one of the things that is fascinating to me, as I'm sure you guys have learned on your podcast, is when you ask people about their security origin story, everyone has a different story. And so hiring managers in security tend to try and rely on recruiters to do this pattern matching thing where they say, well, I want someone who's an application security engineer, find someone who has been doing application security for 5 years. The recruiter goes around and looks and can't find anyone because that's a very, that's a very tough thing to do, um, this traditional pattern matching. So I think that one thing that hiring managers can do, and this takes time, you know, valuable time away from all the firefighting that you're doing while you're still trying to keep things running and get some of your projects done, is to think about really what are the specific skills and tasks that I need this person to accomplish. Because if it's possible for a security hiring manager to break down a candidate's sort of, um, I won't say resume, it's really the job description. We have, we have, I think, like a, like a matching problem when it comes to security candidates and hiring managers. We, we need like, and this is a joke, but we need Tinder for security. We need, we need some sort of like, we need, we need a better matching program because a lot of times Organizations, especially if they're just getting their security team started, they don't necessarily know what they want their first security hire to do. Even for, you know, more mature organizations have a better idea, but newer security organizations, especially, you know, think about the last, you know, CISO role that you were made aware of, you know. The hiring manager may or may not have even known what a CSO is supposed to do exactly. And so we have this, we have this interesting problem to try and solve of matching security jobs with candidates. Okay, so that's on the hiring manager front. On the personal front, what do you do? I think that you should interview. Why don't you respond to some of those recruiter emails that you get in your LinkedIn and talk to some of these folks. You don't always have to take the job, you know. You know, you can— there's, there's something to be said for putting yourself out on the market and reminding yourself how valuable you are. You know, my recommendation to security people is always be interviewing because Maybe you discover something that's a great opportunity, or maybe you convince yourself that you're in a great place. The other thing, and this is a little more touchy-feely, but I think it's, I think it's worth mentioning, is to try and pay attention to how you feel when you're doing something. Ask yourself, do I like this? And ask yourself, do I not like this? And if you like it, do more of that. And if you don't like it, do less of that. And yeah, that really, that really is my biggest piece of advice. It's a little bit straightforward, but I think it is actionable. And I hope that it can help people. It certainly has helped me. be really aware. You know, I think it's, it's different when you kind of set out and you say, okay, I want to go and accomplish this thing, and you can be very goal-oriented. You know, being self-aware is almost a very different strategy to knowing oneself than to be goal-oriented. Being self-aware involves being mindful, being present, being in the moment. What am I doing right now? I'm talking to these guys on a podcast. Do I like it? Yes. Okay, maybe you should do more of that. You know, that's just like one example. And then, you know, alternately, if I'm doing something and I find that when I ask myself, do I like this, my answer is no, then I should try and figure out ways to do less of that. I think that's really a good way to go. **39:44 Robert Hurlbut:** Okay, makes sense. Well, Caroline, thank you for your time today. We really appreciate it. This is— this has been fantastic. Just to give us a another look at this topic. I'm sure we'll visit it again. I know some other things we'll probably want to look at in the future, but this is— this has really been helpful, and I'm sure it will be for our listeners as well. So thank you again for joining us today. **40:12 Caroline Wong:** It's my pleasure. Thank you so much for having me. I've really enjoyed this conversation. **40:17 Chris Romeo:** Thanks for listening to the Application Security Podcast. Our intro music is 8-Bit Kung Fu by Born and TJ. And our outro music is Southern Delight by Stefan Kartenberg. You'll find the show on Twitter @AppSecPodcast or on the web at www.securityjourney.com/application-security-podcast. You can also find Chris on Twitter @edgeroute and Robert @RobertHurlbut. Remember, security is a journey, not a destination. --- Source: https://appsecpodcast.com/caroline-wong-self-care-and-self-aware-for-security-people/