Skip to content
AppSec PodcastThe Application Security Podcast — home
57 minSeason 11, episode 15

David Quisenberry -- Building Security, People, and Programs

With David Quisenberry

Security CulturePrivacy and ComplianceCareers in AppSec

David Quisenberry shares about his journey into the security world, insights on building AppSec programs in small to mid-sized companies, and the importance of data-driven decision-making. The conversation delves into the value of mentoring and why it's important to build real relationships with the people you work with, the vital role of trust with engineering teams, and the significance of mental health and community in the industry.

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 15 chapters
  1. 00:00Meet David Quisenberry: Building Security, People, and ProgramsAudioVideo ↗
  2. 01:44That's, uh, that's a t-shirt, t-shirt idea. I wish I hadAudioVideo ↗
  3. 04:45Yeah. It's, it's one of those things where we're never goingAudioVideo ↗
  4. 06:56Um, and I love that illustration you just made about comparingAudioVideo ↗
  5. 12:43In your experience then doing this a couple of times, doAudioVideo ↗

About this episode

David Quisenberry shares about his journey into the security world, insights on building AppSec programs in small to mid-sized companies, and the importance of data-driven decision-making. The conversation delves into the value of mentoring and why it’s important to build real relationships with the people you work with, the vital role of trust with engineering teams, and the significance of mental health and community in the industry. David Quisenberry leads security teams at Capri Health, where he’s the senior manager of information security. He’s a lifetime OWASP member, former chapter president of the Portland, Oregon OWASP chapter, and co-founder of the OWASP AppSec Days PNW.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
We provide diverse training content and easy-to-digest lessons to meet individual learner needs.
Learn more about Security Journey

Connect with David Quisenberry:
SRE Engineering
The Phoenix Project

Resources
SRE Engineering
The Phoenix Project
Security Chaos Engineering
Wiring the Winning Organization
The Body Keeps the Score
Never Eat Alone
How Leaders Create and Use Networks
CISO Desk Reference Guide
Intelligence Driven Incident Response
Thinking Fast and Slow
Do Hard Things
BSIMM
OWASP Application Security Verification Standard (ASVS)
BSides

Actionable

From this conversation

  1. Assess your program against a framework

    With application security, starting with something like a BSIM framework, where you're looking across the different domains and take, take the existing— because every company, regardless of whether they have a dedicated security program or not, or a very well-built-out one, like, they're going to have some of the practices.

    13:50
  2. Prioritize threats by business impact

    We have to make sure that we're focusing on the threats that, if, acted upon, would do the most harm to the business.

    20:52
  3. Lead security conversations with the why

    Don't come in with like, security says X, like lead with the why.

    24:37
Transcript · 57 min conversation

0:00Chris RomeoDavid Quisenberry leads security teams at Capri Health, where he's the senior manager of information security. He's a lifetime OWASP member, former chapter president of the Portland, Oregon OWASP chapter, and co-founder of the OWASP AppSec Days PNW. He's a bookworm, board game geek, and dad of a minivan full of kids. His proudest moments are helping people get their start, watching self-organization unfold, and building real relationships with those he works with. David joined us to discuss AppSec programs, trust, mentoring, and the human side of application security. We hope you enjoy this conversation with David Quisenberry.

0:42David QuisenberryThe Application Security Podcast is brought to you by Security Journey. We provide diverse training content and easy-to-digest lessons to meet individual learner needs. Learners report improving their knowledge as much as 85% on AppSec topics. Learn more at securityjourney.com.

0:57Chris RomeoHey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo. I am the CEO of DaVinci, also a general partner at Kerr Ventures, and, and an AppSec aficionado. I don't know, maybe. Robert Hurlbut is with me as well. Robert, how are you this fine sunny day in Raleigh? Who knows where, how it is where you live.

1:29Robert HurlbutDoing well up in Connecticut. And, uh, yeah, Robert Hurlbut. I am a principal application security architect, as well as threat modeling lead at Acquia. And yeah, it's a great day.

1:40Chris RomeoIt's always a great day when we get to talk about AppSec.

1:43David QuisenberryCome on.

1:43Chris RomeoThat's, uh, that's a t-shirt, t-shirt idea. I wish I had a little recorder so I could go t-shirt idea. We are excited to be joined by David Quisenberry, who is going to really take us through a lot of different things. We're going to talk about, we've got a list of a lot of different takes and perspectives. Some of them will be focused on AppSec, others will be a little more generic or general to, uh, to be a little bit wider, but, uh, Quizz, we love to just jump right into the deep end and let people share their security origin story. So how did you get into this world of security?

2:19David QuisenberryYeah, I would say the, the start was as a kid. Uh, I grew up in the days where internet was just starting to, to get in people's homes. Uh, I remember, you know, the 9600 baud modem and, and working my way up from there. Um, so, you know, with that, figuring out how to hack video games, get free songs, uh, get the stuff off your computer that comes with that. Um, And, and then more professionally, uh, I started as a developer and, um, while doing that, had friends who understood OWASP Top 10 and AppSec stuff and started trying to, you know, whatever I would build, they would try to do SQL injection on and hack into. So I had to learn how to protect things early, uh, to protect against my friends. Uh, and then additionally, like, uh, just experience with, um, compromised clouds and having to do incident response. And, you know, when you see commands in your shell that you didn't write and you're like, whoa, what's going on? And then following the rabbit trail and where it goes.

3:23Chris RomeoYeah, I think incident response is something that I had the luxury, we'll call it the luxury, of being able to do for a couple of years in my career. And I don't know that I wouldn't want to go back and do it now. Like, I love the people that are out there doing it and that love that. I wouldn't want to do it now. I would say it really, I really learned a lot in that baptism by fire almost of being in a compromised environment and trying to think of ways to investigate without damaging evidence and whatnot. So how would you say, how did incident response set up your career? Did you have a similar experience?

4:05David QuisenberryYeah, I would say it opened my eyes. So once, once I started to see those things and get close to it, then I could not see it anymore. And so, you know, when I went into computer science, I was thinking more in terms of building stuff and how wonderful it is to be a developer and how it's like playing with Legos. Um, and then when I started to see more of the security ramifications of vulnerabilities and what can happen, Um, I'm somebody who cares. And so I, I had to pivot my career to just like focus on that. And it was really fun. Um, but it was also one of these things is like security is a full-time job and not just one person, but a whole team.

4:45Chris RomeoYeah. It's, it's one of those things where we're never going to be out of work, like until we want to retire. And I literally mean until we want to retire, there's not going to, if you want, if we want to work past 65 years old, There's just so many problems to solve in this space. And I'm so excited every time I meet somebody who's new, who's joining our community and has that same fire and passion to solve these types of issues. But it also causes me to reflect to say, we could literally work as long as we want in this industry because it's just not going to go away. I guess that's a message to kids out there. Don't get into cybersecurity because you want to make a lot of money. Get into it if you have a passion to solve the problems, as Quiz just shared right here, right? Money's nice, but it doesn't make getting up on Monday morning and going to work that easy.

5:41Robert HurlbutYeah.

5:42David QuisenberryAnd to like, just double-click on incident response, I think, you know, within security and like kids coming out of college, some of them get it, some of them don't, but like, there's so many different niches of security careers. And I compare it to like, uh, being a doctor or, you know, getting, getting your medical degree. Like, certain doctors are surgeons in the ER and their weekends suck. Um, and they have a ton of stress and that's your incident response team. Like, you don't have normal Fourth of Julys, you don't have normal Christmases. Like, you, you have to pound the coffee and work through the hours and get her done. Um, whereas other types of careers, whether it's cloud security or application security, security architects, Um, are more like your, you know, uh, specialist doctor who does like pain medicine or something like that, who can actually schedule their time and, and, and have a normal weekend, have a normal, uh, holiday. So for the kids out there, uh, think about what you want. Like there's, everything has its own, um, pluses and minuses. Like the, the pluses was, you know, incident response is like, you're dealing with these like legit incidents. It's kind of sleuthing. You feel like a detective. Uh, the team that you're with, like, because it's so traumatic and intense, like you bond like nobody's business.

6:56Chris RomeoUm, and I love that illustration you just made about comparing cybersecurity to the medical profession with the specialties and various things. I'm going to borrow that. I'll reference you twice, which is standard practice before I appear to just share it with the world. But that's, it's a great, It's a great perspective though, because people, especially when, I don't know if you guys have the same experience, but often college kids will reach out and say, hey, can we, can I meet with you? I just want to learn more about cybersecurity. And, and I always ask them that the first question I always ask is why cybersecurity? And unfortunately, too many times I hear, well, you get paid a lot. You're going to be, you're going to be very unhappy, but I also spend time trying to explain, okay, cybersecurity is an umbrella, but I like your thing. I like your idea better. It's like the medical profession. There's all these different specialties. You know, you can be the ER doc or you can be the proctologist, which I'm cool with.

7:56Robert HurlbutRight.

7:56David QuisenberryAnd some are very relational, you know, like a family physician is like a very relational job. Um, I think application security is kind of like that. And then there's other, like a security architect where it's like, you're like a medical researcher. Like you're digging in the weeds, you're thinking through this stuff. Slow thinking.

8:10Chris RomeoWho's the, what's the, what is the equivalent of the proctologist though, in the world of cybersecurity? We probably shouldn't answer that. And we probably shouldn't answer that because somebody's going to be like, wait, I do that. You call me a proctologist. Come on.

8:23Robert HurlbutWow. I love the way we start. Uh, so, so, we have some questions for you today, uh, just to start off with, uh, Give us some of your insights, if you would, on building AppSec programs at small, mid-sized companies from the ground up. I mean, we talk a lot about the large enterprises, and, but what's special about the small, mid-sized companies and their challenges?

8:50David QuisenberryYeah, so my experience, I've never worked for an application security or security at a large company. So I'm a senior manager of information security. So I have cloudsec, AppSec, security operations in my company. We're roughly 1,000 employees. Um, before that, I had a similar role at a company that was maybe 400 employees. Um, and before that, uh, when I was a developer, there was no security team. And, you know, I tried to do my best and we had 12 developers, you know, it was a very small company. Um, so I would say for the companies that are like 400, or 1,000, where I think, you know, the deals start driving the security needs. So when you start dealing with bigger AR customers, Fortune 500, dealing with banks, dealing with defense contractors, et cetera, then they come in with their security addendums to the contracts. And then all of a sudden, business starts understanding like, oh, we need to think about some of this stuff and do some of this stuff. But the challenge is, is oftentimes you have 1 or 2, maybe 3 security people. Um, my experience has been a lot of those people, uh, actually come from more like a compliance or a GRC background, um, because the initial need for the business is filling out the questionnaires. It's not actually doing the, the hardening or the vulnerability management or the AppSec, you know, threat models, et cetera, et cetera. It's like just filling out these forms and like getting the answers from the engineering teams. And throwing them in there. And then, you know, my experience has been that the world we live in now, I call it like it's, it's the restaurant where the, the kitchen's right in the middle. So with big businesses, when there's big ARR, they want to see how the food's made. They want you to make it right there and then pull the restaurant with all the eyes on it. And so as a business, even a small business, like you have to start having more mature practices than you have people for. So I think the, the number one thing with, um, building an AppSec program at a small company is you're not going to have the headcount. You're going to have, you're going to have a limited amount of people. Um, those people often aren't going to get paid very well. And this is a, this is a lesson too, for like those young folks who are thinking about security in terms of the paycheck, uh, which is a horrible way to think about it, but I get it. Like money is what our culture talks about all the time. Um, but at these smaller companies is where you get paid in experience. Um, so, you know, I like to joke, uh, anytime a big thing comes up, I learned this from my boss. It's like, okay, this is a great opportunity for experience points. It's like the boss, you know, in, uh, some D&D campaign. And, um, and so with the small team, Like number one, I just look for people who are good at one, learning, like they're curious, they can read really fast, they can dig into the things and kind of distill what needs to be actioned on. And then are they hard workers? Do they like, do they complete what they start? Because when you only have a team of 2 or 3 people, you have to be really nimble. One of the advantages I think of a smaller mid-sized company that maybe is different in a large company, this is an assumption because I don't really know, but there's a lot less tape you got to get through to get things done. So if you have ideas around how to improve something, you can actually action on them quite quickly. So like, the, the ramp up of a new, a new threat modeling regime, or a new SDLC step, or, you know, even a new tool, like, you can make the decision, POC the thing really quickly, and then like, you in a few weeks, month, like have it live in production and rolling out. Uh, whereas I think at bigger companies that might take a lot longer.

12:43Chris RomeoSo in your experience then doing this a couple of times, do you normally, is there normally a CISO in place by the time you get there or are you reporting to somebody else in the org structure?

12:59David QuisenberryYeah. So the first place I was at, um, had a director of security, not a CISO. And yes, at my, at my current place, we have a CISO who's responsible for quite a bit more than just a security CISO. He's also head of IT and privacy and clinical apps and a bunch of other things.

13:17Chris RomeoWhen you start one of these new programs, and we can even expand it to, you know, AppSec, CloudSec, security operations, Where do you like to start? Because I think a lot of people could find themselves in a similar place to where you've been and could be sitting there thinking, okay, I have this responsibility. I've got this great greenfield opportunity, but I don't really know where to start. So I'm curious from your perspective, doing it a couple times, where do we start?

13:50David QuisenberryYeah, no, that's a great, that's a great call out, Chris. And, um, I think one of the things that that you have to do that I, you know, I put on my shoulders is the only way you get that headcount, the only way you get that budget is with the data, and then storytelling with that data. And so I think, you know, with application security, starting with something like a BSIM framework, where you're looking across the different domains and take, you know, take the existing— because every, every company, regardless of whether they have a dedicated security program or not, or a very well-built-out one, like, they're going to have some of the practices. So doing like BSIM and like figuring out, like, within the software development lifecycle, uh, like, where, where do they have threat modeling? Where do they have security requirements? Where do they think about what could go wrong and what they're going to do about it? Um, what do they currently do for code review? Do they have some sort of checklist that a developer uses? Do they have, like, even if it's a pen test puppy mill, like, do they have some sort of pen test that they're doing against the app? Um, and figuring out like that broader landscape of practices. So like BSIM framework for AppSec, um, most clouds, whether it's AWS or GCP or Azure, will have, uh, you know, like a Well-Architected Framework or something like that. Uh, Google's Security Foundations Blueprint, um, seeing kind of where, where the org maps against that. Um, and then more generally, like a, a NIST Cybersecurity Framework. Um, I start there, get the data, get like, where are the biggest gaps? Understand, um, for me, I, you know, it's maybe painful, um, and maybe it adds more risk, but I do it anyway. Uh, I like to read the contracts. I like to see what are the security addendums that we've signed up for. Um, one of the things that I've done in the past, uh, where maybe encryption end-to-end or, you know, internal encryption on internal services wasn't as dialed as it needed to be. Um, going through the contracts and seeing which contracts require both internal and external, uh, encryption in transit, and then tying that back to ARR and being able to go to the business with like, okay, 80% of our ARR has the security requirement, therefore I need 25% of, you know, engineering headcount for the next quarter to do, you know, do this work. Um, so data matters a lot. And then, um, figuring out where you can actually make, make a dent. I like to, especially when starting out in a newer thing, like orchestrate an early win, find something that you can prove that you can get something over the line and get done and make it better. It's not fun, but our jobs, we do have to do a lot of internal marketing. So like managing up, up to the board, up to the C-suite, up to, you know, heads of engineering, different directors, The more I found, the more I can like show the business that there's a defined level of maturity or health. Like so, I work at a healthcare company. We talk a lot about know, engage, and manage. And so, like within your health population, like 60% are like generally healthy people. 20% are like not healthy, and you have to do something about them. And then there's this like unknown risk of like 20% of the population where like they don't go to the doctor. doctor, so you don't really know what they have going on. So part of security too is like, okay, where are there parts of things where we just have no idea? Let's at least, you know, do some discovery, be able to categorize that risk, and then, you know, as we know more, we can, we can better manage it. Yeah.

17:27Chris RomeoAnd I want to, I want to just acknowledge, I want to make sure people realize what they just heard. And so I'm going to highlight this, but what Chris just shared with you is a very short masterclass in how to build a business case For success inside of a company. I love the fact that you tied back to the business from that perspective, because for decades in security, I know, because I've been around for decades, we have not done a good job at building business cases to use data to explain what we're trying to do. And instead, we just showed up and said, well, you have to do this because we're the security team and what's wrong with you? Now, but you just gave an example about how you build a conductive relationship between security and other facets of the business where business people can now make risk decisions based on what you've laid out here for me. You said, you're showing me, if I'm the CEO, you're showing me here's the things that where we have inherent risk, here's the pathway and the budget and the resources we need to be able to mitigate that risk. Business person, it's on your— you can now decide how much risk you want to accept. And because it's all laid out, they're not just— it's not just, I need 3 people. It's, it's, I need 3 people to be able to solve these business needs for you.

18:49David QuisenberryYeah. Yep. And the world we're moving in with all the ransomware, with all the other stuff, big companies don't just take you at your word that you're doing things. They want to see just like an auditor. Like you think a SOC 2 is bad? Like try working with one of the biggest banks in the country. Um, they want to see all these different controls. Um, you know, when you're a small company, it's, uh, you, you get on the call and they'll have like teams of people that are just each domain, you know, and you're like, uh, you know, I joke, it's like being a, um, you know, like a middle school basketball player playing against the pros. Uh, you do your best, but—

19:24Chris RomeoI love that. Uh, I've had that experience a couple of times myself in, in various startups that I've that I've been a part of. And, uh, I don't know. I like to think of myself as Michael Jordan against a bunch of teams of middle schoolers in that scenario. But that's just—

19:39David QuisenberryYeah, there's, there is that element too. There is that element too.

19:42Chris RomeoThat's just me. I, I, uh, yeah, I had, I had some fun a couple of times with calls like that where I had, I had people, I had folks like multiple teams represented and, and I don't mean to be cocky, but they all had probably a couple of years of security experience. And like, I've been doing this for decades. And I'm like, this is how we architected it. Well, what about this? Well, that's why we did this. What about that? Well, see, this is, see the architecture. That's why we did this in such a minimal, simple way, because that doesn't, that's not a threat because this thing doesn't exist. And like, they all got to the end and they're like, uh, okay. Like, you made me fill out a 200-page questionnaire, right? And in a 30-minute phone call, right? Uh, I was able to explain the architecture of how we simplified things to make it so that there weren't any of the problems that you're concerned about in such a way. But, um, you know, you live and learn. It was, it was a good experience. Uh, what do you consider success for that? Let's say that I'm gonna, I'm gonna frame this in the concept of first year, one-year mark. How do you, what, what have you, like, what are the metrics? What are the success things that allow you to say, I feel good about what I just did this past year?

20:52David QuisenberryYeah, I think in, in year one, uh, understanding how how the business operates, how the business makes money. So, um, as a security person, like, the part of our challenge is there's always things to dig into, and you can, you can drop in these black holes that take a ton of time. And we have to make sure that we're actually focusing on the threats that, if, you know, acted upon, would do the most harm to the business. So I think after year 1, if you have a a clean understanding or a cleaner understanding of what are those business processes that make the company money, keep the company in business, and what are the threats to those processes. Like, that's, that's a big plus one. Having an initial review against a framework like a BSIM or a, you know, OWASP ASVS, or in the context of a broader business, like the NIST Cybersecurity Framework, I don't know if I said it, but with those, you do want to do an annual refresh. So, you know, my experience has been like the first year of a company, you get an inch deep and pretty wide and you kind of feel like you know things. And it's really in year 2 and year 3 that you learn where more risk lives. And then the other thing in year 1 is you want to build those relationships. You want to know who are the people across the company that, that care about security, that don't care about security, that are really important to the business. You want your Rolodex to not be— you're not going to have deep relationships with all those people, but you want to have at least cursory relationships with everybody across the board in year 1. And ideally, like a few projects that you're collaborating on with some of the key players. So, um, you know, we're gonna get into it, I think, in a little bit around like building trust, but the, the best way to build trust is through like mutual projects.

22:51Chris RomeoYeah. And I want to go there next. Um, I guess my simple yes or no question for you is, you ever thought about writing a book and capturing the things that you just described?

23:01David QuisenberryYeah, I will someday. Yeah. You need to. Right now I'm trying to write a spy novel, but it's not, you know, fun. Yeah.

23:07Chris RomeoNo, you need to, you definitely, you need to write a book based on this experience though, because Just the things that you've laid out here, you've already, you've laid out probably 3 chapters in just those, but it's stuff that people, it's hard for people to get that. Like nobody's real. I've never seen a book where anybody's written program building at that level. And just the conversation about the business case, like it seems like it's simple, but I see so many people that don't even think that way about the need to generate a business case.

23:37David QuisenberryIt would be, it would be good to write. And then I think, you know, with the book, the, you know, the number one thing I think that I could also give to people would be like at the end of each chapter, like a short little like action plan. So like to-do list of like, you know, if you're gonna do 3 things, these are the 3 things to do. If you're gonna do 10, here's, you know, go have some fun. And then write back and blog about it and tell us how it went.

24:02Chris RomeoYeah. Well, hey, let us know when the book's done. We'll have you on the show again to launch it.

24:06David QuisenberryMight have to ask your help to market it.

24:08Chris RomeoWell, let's talk about this idea of trust with the engineering teams, because it seems like a logical connection point based on what we just talked about in building the programs. It seems like trust with engineering teams is going to be a foundational block if we're thinking about stacking a bunch of Legos on top of each other. So what are your, what are your steps for success or tips to, to build that trust? I'm guessing people don't just trust you inherently when you appear. You say, I'm from security. No, no.

24:37David QuisenberryIf you're a security person and you hop in a channel and you're like, hi, they're all like, why are you here? Um, so I think number one is, uh, like for my teams, as we build the team, we do a lot of internal, um, processing of like, who are we as a team? And one of the things that we, we really want to be as a team is that trustworthy partner. And so I would just say like, building trust with engineering teams is not just the leader building that trust with engineering team, it's every single person on the security team. So big believers in like, I think you kind of alluded to it early, like don't just come in with like, security says X, like lead with the why. Why are we doing this? What's the business justification? Why is it worth their time? Engineers, developers, product people, they all have a ton on their plate. lot of competing priorities. They have a mountain of tech debt that they would love to get to, but new features that are always like competing against that. And then security is like one more thing on top. Um, we're, we're big believers in like knowledge is power. So we have a, a book club that we've been doing for a couple of years and we invite engineers to participate in it with us. And we read books that matter to them too. So like SRE Engineering by Google, uh, The Phoenix Project. Right now we're reading Security Chaos Engineering, which is an amazing book. And so for engineers to like participate in group thinking with us and to hear the conversation around like, we really don't want to feel like a trash bag around your ankle swimming across the swimming pool. I joke that, you know, we want the security team to be like, and the practices to be like the US Olympic swimsuit back in 2008, the Once, I think it was the Speedo Phantom, it was like so successful that like it was banned from all future Olympics. Um, but a lot of security at a lot of places feels like a trash bag around your ankle. And so engineers run from that. Uh, they got to move fast. So like showing them that like resilience is what we're after. And, um, and getting to the why. Just some practical stuff. So attending their standups. Um, so as a manager, like giving people freedom, one, to read books and to like learn stuff and not just burn midnight oil, but like, that's part of your job. You can read things on the clock. attending standups of, you know, some of the core teams, like an infrastructure team and/or SRE team or whatever. What we've found is when you, when you regularly attend standups and have a representative there, then they start to bring, you know, the things that are on their minds. And you also, you get so much more perspective on where the real risk lies. So, That's another thing. I'm not quite sure how to say it, but security is like raising teenagers. You want to have conversations with people. You don't want to just come in with like strict, strict things and then they're doing all sorts of stuff on the weekend and not telling you about it. Um, I'd much rather know where the real risk is and be kind of choose my battles. Um, be silent on some things. And then, uh, I alluded to it, but like, joint projects. So, um, something that we've done that I think helped engineering trust us is asking their advice on projects that we're building for different security tools. So, you know, we build different automations, different things. We're not software engineers, you know, other than like some CS grads and some other stuff. And so asking, asking people about, is this the right pattern or should we be thinking about something else? Like, and then they become more like your software engineering mentor.

28:16Chris RomeoYeah.

28:19David QuisenberryAnd you, you have this more of like a pure relationship and not a, um, as much coming in from the outside.

28:25Chris RomeoThat's a powerful statement that you just made there. It's showing vulnerability to another team based on their expertise. Just, I love that idea and I've never thought about it from that perspective before, but that's also something I'm going to carry forward from this conversation. Because it, it, it sets you up as partners, not as a, somebody who's in charge versus somebody who's supposed to be listening. You're saying, hey, I realize that you, your team are experts in writing software and we're not, we're experts in security. So take a look at this and tell us how we could help us, help us design a better pattern. Oh, I love that idea. I can't wait to find a way to use it. It's such a powerful concept to be able to use.

29:17David QuisenberryAnd we're all teammates. We all can help each other in different ways.

29:20Chris RomeoYeah.

29:20David QuisenberryWow.

29:21Chris RomeoThat's really cool. That one's going to stick with me for a while.

29:24Robert HurlbutYou mentioned mentoring. Let's talk a little bit about that. There's a statement you made, mentorship is not what people think, reframing the mind to think about trusted relationships. So first of all, tell us what people typically think what mentorship is, and then this concept of reframing that, your mind to think about those trusted relationships.

29:48David QuisenberryYeah. So, you know, my experience with, with mentorship is, um, you know, depending on the organization, there's a lot of different organizations that are trying to provide value to their membership. And so they'll like create a mentorship program as part of it. Like, so WeSys does this, OWASP chapters sometimes do this, uh, different nonprofits in town I've done this with. Um, and, and so like, you know, there's somebody who's in charge of like kind of pairing people up, you know, someone more experienced, someone more junior, certain career aspirations. And, and what I've found is a lot of the people that are coming to them, like as a mentee, they want the mentor to kind of like give them that checklist or lay out like things to work on and it's more like transactional. And the mentor, they don't have time to build that. And they were really hoping that the mentee will come at it with kind of the things that they really want to grow in and like kind of self-drive and then like check in on stuff. So my experience with those types of relationships is that, you know, They do get you like a person to talk to. There is like a seed. Sometimes it's better than others. I will say as someone who's like organized those things and tried to pair people up like that, that is an art and a science and takes a ton of time and it's not easy. But the, where I'm going with mentorship is like the, everybody should have mentors in their life and they do. But you're going to, just like anything in life, like you're going to get out of it what you put into it. And what I would say is with With the best mentors in my life, like things don't come easy. You have to work at it. And so maybe a story for this would be when I switched careers about 6, 7, 8 years ago, I was in financial services for about 10 years, which is probably why I care so much about like revenue and money and things like that is 'cause that was my world for a while. And when I went back to get into software. I went to code school, like sold my practice, et cetera. And I was learning, like relearning how to program. And someone on LinkedIn, a guy that I knew in college, he used to be a salesperson at a software company in Portland. And he saw that I was doing this career reboot. And so he just pinged me on LinkedIn and he is like, hey, like if you want, like I'm happy to make an introduction to our VP of engineering at Jama Software. It's a software company in Portland. Just had the largest acquisition in like Portland history. I think it was $1.2 billion. Um, but he's like, I'm happy to make this introduction. Um, and it goes back to like networking. And so I reached out to this guy, um, Jeff Holman's his name. And I reached out to him and he was very kind. And he said like, yeah, come in, you know, um, I get here early. So if you can come in at, I think it was like 6:30 or 7 in the morning to the office, uh, I'll, you know, I'll give you 15 minutes or something. And so I went in, um, you know, at that point in time, not knowing, you know, here I am like learning JavaScript and some basic stuff, uh, you know, fairly intimidated, um, going into this office, like no one's there except for him and we're having coffee. And, um, and he's talking about, you know, how they— I was trying to like line up an internship, like, can I get an internship somewhere? And he's like, you know, we, we do internships with University of Oregon and Oregon State or maybe PSU and, you know, move people through this, this like 3-month cycle here, 3-month cycle there, et cetera. It was like, you're in a code bootcamp. Like you're not going to be able to do, um, our internship. So like, you can't let rejection hurt you. Like you have to just push through it. So like ending the call is like, I don't remember exactly what I said, but I said something along the lines of, you know, would you be okay if I periodically touch base with you and just let you know kind of how things are going? Um, and I will say now, like having sat in Jeff's shoes to some degree with other people, like you never know if the person's actually going to follow up. Most people don't. So like for every 10 people that say like, do you mind if I keep in touch with you? Like 9 out of 10 are not going to do it. Um, but I did with Jeff. I, you know, I would reach out to him maybe once every 3 months or so and, and like let him know, okay, I'm doing my internship here. I'm trying to learn this and just ask his advice. Um, so I'm a big believer with your What you want to do is you want to say the words, if you were me, that's the secret sauce. If you were me and you're trying to do X, what would you do? And then whatever they do, like, go and do it. Give it a try, even if it's not successful, to try it. And then to, you know, have a reason to come back and talk to them again and say like, here's what, you know, here's what went well. Here's what didn't go well. Um, over time, like with Jeff, he is you know, one of my most trusted mentors now. Like we've been in relationship for 2 or 3 years as a mentor-mentee. It's not like a formal thing, but whenever I have questions about, you know, like my company had a merger, so like how to think about mergers, how to think about building out a program, like it's really good to have mentors in other verticals. So like having a couple mentors that are director of engineering, VP of engineering, have some mentors that are in product. Those are superpowers. If all you do is hang out with security people, you're going to really limit, uh, you know, what you can do. You're going to be that bodybuilder who has really good biceps, but like can't run 2 miles.

35:18Chris RomeoTiny little legs, chicken legs.

35:20Robert HurlbutYeah.

35:21Chris RomeoLet me, uh, let me, let me just summarize a couple of things that I think that I just heard you say, which I think are very important in the, in the mentoring relationship. One, I heard you say that you weren't afraid to reach out, but you also lived within the constraints of the mentor, meaning you showed up at 6:30 for the coffee. If you're asking somebody as a mentee to take their valuable time to help you, if they say 6:30 is when I'm available, you show up at 6:20 at the door, patiently smiling, waiting for the conversation. Um, another thing that I, that I took away from what you just said is don't fear rejection or don't let rejection squash you because you kept that relationship going, which when most people, like you said, most people, I would say even 99 out of 100 people would've stopped following up with someone who gave them that type of a message in the first meeting, but it didn't dissuade you. And then it turned into a, a lot, much longer-term mentor relationship. So I think that's a very valuable thing to take away as well. Yeah. So I mean, just not being afraid and asking for advice, like, what would you do if you were in my shoes? And it turns out that's how I answer everybody that ever asks me questions about anything now in life. I'm like, if I was in your— I say the same words. I say, if I was in your shoes, here's what I would do. Because one, it helps me to empathize with them. It helps me to kind of mentally set the state of how I'm going to answer the question based on what I've learned about them and their current situation and where they are and the challenges they're facing. But then I'm also able to factor that across 50 years of making mistakes, screwing things up, making people mad at me. I can factor all of that into the answer that pops out the front. So I love your, once again, another chapter in the book here, mentorship, like. That's, but what you just shared there is, is gold. And, and I'll throw one more thing on it just, uh, 'cause this is something that I learned from a mentor that, uh, that I, uh, I worked with over the last couple of years. Um, I was in the process of trying to raise money for my first startup and, uh, he, I sat down with this guy, mutual friend had connected us. And, um, so over the breakfast meeting, he's, he's, you know, I'm telling him the whole story about where we are as a company. He's like, okay, here's what you need to do. And he gave me a homework assignment and he said, contact me when you've, when you've completed this and we'll meet again and we'll, we'll talk about it. When I called, I emailed him 3 days later, said, okay, I'm, I've got it. I've got it in a state. I'm ready to talk about it. And so we go, we scheduled another meeting a week later and we sit down. He's, he goes, you know what? He goes, most people never call me back after that.

38:15Robert HurlbutRight.

38:16Chris RomeoThey don't.

38:16David QuisenberryRight.

38:16Chris RomeoI never hear from him again. He's like, this was kind of a test to see how serious you were about this relationship. And he's like, you passed with flying colors. And I didn't know that, but like he gave me some very, very, he gave me some advice based on what he would do and laid out something that I could build to help me answer my own question. And, but I took that away too. I do the same thing with people like, hey, can you mentor me? Great. I'll do a call with anybody. And at the end of it, I give them something to do. And I say, hey, reach back out when you're done with that and we can talk through it and see where you are. Because it's a, it's, I think it's a fair ask of them. And I thought it was fair when I was on the other side of it, because I was asking someone who is very busy already, has lots of other things to do with life. I'm asking him to do something basically for free. No, not basically, for free. I'm asking him to give me a few thousands of dollars worth of consulting if he was going to charge somebody for it. Right. So. I feel like that's a fair ask of somebody. Like, here's what you need to do to move what you told me forward. We can meet again and talk about it that way. I'm not, I'm not there to check the box for you. I'm not a compliance officer. I'm adding value. And if you want to play along, I'll keep working with you as long as you want to, you want to move yourself forward.

39:32Robert HurlbutYep. Yeah.

39:34David QuisenberryAnd I think those, you know, those little like take-home assignments or projects or things to follow up on, like As mentees see men— as mentors see mentees do that and like have quality work, like that also makes it easier to make an introduction at a company or whatever, because you know that person is probably gonna be a decent worker.

39:53Chris RomeoUm, yeah, that's a good point. I hadn't even thought about it from that perspective, but before recommending, and, and we're all very careful with recommending people for anything because—

40:04David QuisenberryRight.

40:04Chris RomeoStart names.

40:04David QuisenberryYeah.

40:05Chris RomeoYeah. When I, when I recommend somebody, I'm signing my name next to theirs saying, I'm vouching for this person. Like they are going to to be awesome at whatever the job is you need done. So that's, I hadn't even thought about that, but that does give us some evidence towards being able to connect somebody and feel like, I don't wanna burn my friend, but yeah, I'm sending this through.

40:24David QuisenberryAnd for the, you know, for the folks that are like seeking out some of these relationships, it's, it's very similar to other things in life where, you know, earning the trust of someone where it's not easy to get their trust and then they recommend you to someplace like that has a lot more weight to it than the person that's just always name dropping. So if someone takes a while to earn their trust, like that's actually a really good thing. Yep.

40:54Chris RomeoSo what about, let's just touch on this mental health point and just for a second. So from your perspective, what is the importance of mental health and how does community play a role in mental health in our industry?

41:12David QuisenberryYeah. So I wanted to talk about this just for a little bit, like after COVID, um, you know, there was, everyone had a lot of mental health issues before COVID Um, but then having a couple years where we didn't be around people as much, um, and, and it was, you know, it was just a weird time. Some people lost people. It was, it was hard. Um, there's a lot of folks right now that are struggling. There's a lot of folks that before COVID were really active in different software communities, different meetups. And some of them, you know, maybe don't, don't, like they're not married or they don't have like a long-term partnership, like, you know, they date or whatever, but don't have kind of the rocks. And a lot of folks that, like myself, that do have family, like we just, we don't go out and we don't do as much as we used to. And so for the people out there that don't have families, like it can be a really lonely time. Um, and, and so like, I just want to say like OWASP, um, Open Web Application Security Project, there's, there's chapters in almost every city in the world. Um, BSides, also a very vibrant, uh, community where there's conferences you can get involved with helping to plan those, planning those to make them go well is, is really like a year-time job. Um, volunteering for people, not only trying to like get a job, because when you volunteer for something, people get to see how you communicate, how you work, like your ability to follow through on things. So it's a really good way to, um, you know, build connections that can help you land a job. But, but also for the folks that already have careers, um, these different security communities really are communities. And, um, one of the challenges that I've seen with people getting into security is there's so much work to be done. And if you're viewing it as like a completionist and like, I'm not going to be happy until the maturity is at this point, it can, it can be overwhelming and people can be totally, totally get burnt out, totally be like, why did I choose this career? This is horrible. And it's in the context of the community when you go to like BSides San Francisco, Chris, I think you were there. I was there. I love that conference because everyone in the room does this for their day job, and you have real conversations around vulnerability management or protecting, you know, AI threat modeling, you name it. But seeing that, like, you're not alone in your struggles really helps with that mental health thing. And then just having those relationships where you're having a beer with somebody or a burger or going on a hike or whatever. I would say if You know, just for people, like all of us probably can do better at inviting more people into our clubs, into our things. Um, and sometimes as security people, uh, we, you know, we just eat, drink, and live security and all the conversations around security. Um, it is good to break it up sometimes and take people fishing or going on a hike or playing board games or doing something that is Yeah. Is totally different because then you get a sense of, of the more full people. Yeah.

44:29Chris RomeoI was just going to bring that up because it's something that I've gotten into in the last, last few months or so, is just realizing that there is life away from computers. There is life away from work. There are things that it's good to have things to get away from what we do on our day jobs. And whatever that is, whatever you like to do, get in the great outdoors, for example, get outside of your house, get away from the screen, leave your phone, you know, at least on silent in your pocket in case there's an emergency or you get trapped in the woods or something. But like, get away from the normal flow that we're in from a work perspective because I mean, I watch people that do what we do. They work. I mean, nobody works 8 hours a day for the most part. We should work 8 hours a day or less. Like we don't really need to work 10 or 12 hours a day, but a lot of us like to. But then they go and play video games for 4 hours and then they go to sleep. And it's like, I'm not picking on people that play video games. It's not my intention. But there's a big world out there with trees and forests and streams and things and natural beauty and whatnot that you can experience if you get away from the virtual world. And I've just, I've made an effort to do that over the last number of months is just to get away from spending so much time in front of a computer screen or any screen in general. And I'm just happier as a result of it. Because I'm not, I'm not as caught up in it. It's amazing when you step away and get that perspective. Um, just the, the, just the, the way your brain starts to process things. Like I, every morning I get up and walk my dogs, for example, and turns out I have a lot of good ideas. A lot of ideas get worked out while I'm walking the dogs around the block. Because I'm really, I'm not in front of a screen. I'm getting, I'm moving, I'm getting exercise. They're mildly behaved, I guess we would say. So I'm kind of managing them, but my brain also just has time to just noodle on things. And like, I'll kind of like get back and I'm like, oh, I got to go write this down. 'Cause like I had an idea while I was out walking around. And it's just, it speaks to getting away from this multi-screen compression system that we're inside of all the time where it's like, You know, can I just squeeze out another 30 minutes of work? Like, get outside is my big takeaway there.

47:09David QuisenberryAnd, and invite people. So if you're doing something, invite, you know, invite people, you know, or even like pinging people, um, just letting, you know, letting people know in this day and age that they're important to you. And, um, we can't do that enough. There's a lot of people that are struggling and, and they're, and they're good people.

47:29Robert HurlbutYep. All right.

47:30Chris RomeoWell, we got to deal with this last one. Um, cause this is something that you pointed out based on something that I wrote this, uh, this idea with my, uh, my experience at this, this hockey game. So I'll set it up real quick. And then if you guys have any questions about it, but, um, I did write about this as well, but I'll give you kind of the short version of this. I'm a lifelong hockey fan. I am a, uh, sometimes a poor sport. As a hockey fan, because my team has not been doing well for the last 8, 9 years or so after many decades of greatness, we'll say. But I had a chance to be in my local arena here watching my team, who was the visiting team, play the home team. And my team is just playing terrible there. I'm like, I came all the way over here to watch you play and you were in my city and you're Playing like junk. And so they continued, the score continues to go higher and higher. And I'm sitting there just, just like fuming in my seat. Like, do I get up and go home? I'm in that, that mental state right there. And I happened to look over to kind of the next set of rows next to me. And there's, there's like a, there's a family there. And they didn't, didn't look like your traditional hockey fans, I guess. Like they weren't like wearing hockey jerseys or anything, but they were like super happy to be there.

48:51David QuisenberryYeah.

48:53Chris RomeoAnd so I just kind of, the sociologist in me, this happens occasionally. I start, I kind of start watching, observing them for a while. And the dad has literally got this little girl. She's probably 7 or 8 years old. And he's like kind of swinging her around and she's just, as the music's playing, she's having a great time. And then I hear what he's saying to her as he's swinging her around. And he's saying, cancer came for the wrong girl. And I'm just like, I'm sitting over here fuming about this stupid game, which has no real benefit for the universe at all. Like it has zero benefit. And this little girl in the next set of seats over is basically fighting cancer as a 7 or 8-year-old. But then, but her parents were like so positive and so excited about the experience and just were doing such a great job. But it was like, it really got me thinking. an even bigger level than we just talked about kind of from a work perspective. But like, there are things that matter in life and there are things that don't. And I certainly knew that intellectually, right? Like, it's not like I wouldn't have argued against that fact, but it was, it was just a, it was just a bit of a gut punch, but it was a good gut punch because it just reframed my perspective and it stuck with me for the last number of months since then that there is more to life than stupid games. There's more to life than work. There's more to life than just playing video games and being, you know, focusing on your own enjoyment. Like people in the world are struggling with things that often you don't even get a chance to get that perspective. So just changed my perspective on that. Yeah.

50:31David QuisenberryI love, Chris, that you posted that on LinkedIn and other places because we, yeah, we all tunnel and we get so caught up in things that Are just bubbles that are gonna pop at some point. Um, and it, it resonated for me cuz I, um, I lost my dad at 17. So my dad died of a brain tumor. He was 45. Um, happened fast. Uh, I was fortunate to have, so my dad, um, he was a baseball player. So, you know, we talk about professional sports and how great they are, whatnot. Like, That was his life, and I was lucky that he retired when I was nine, so I got some good years with him. But you know, when he was on his deathbed and we knew like okay, he's dying in the next couple hours, I remember asking my dad, you know what? What's the most important thing? And his answer was loving and being loved. It's the relationships that. at the end of the day, like, you know, here's a guy who played an X number of All-Star Games, won the World Series, you know, all these different things. And none of that matters. It's the people around you.

51:44Chris RomeoWow.

51:46David QuisenberryAnd then my daughter, so, you know, you, you had that experience with a 7 or 8-year-old. My, my oldest daughter, when she was about 20 months old, got cancer, childhood leukemia. And, uh, very, very, very thankful that, you know, she was born around this time and not 1980. Um, because with, you know, ALL and different types of leukemia, there's actually really, really great survival rates now. Um, and so she's, you know, she's thriving, she's great, she's getting ready to drive a car. Uh, but yeah, I, I very much, um, can get sucked into work. And, um, it's really, for me, important to remember the people around me, why I'm here, who's going to show up at my funeral. Um, all those good things.

52:37Chris RomeoYeah. Wow. Thank you for sharing that perspective and everything. And, uh, we normally have more questions. I'm not going to ask anymore. This is a good time. This is the right time to end. This is, this is, I, and my hope is that people will ponder the things that we discussed here. And take it to heart. Like, I think that's all we can ask people to do is just think about it. Think about your own life in this context. And, uh, hopefully, you know, hopefully you will see some places you can change. You can, you can make some adjustments to focus on what's most important in your life. But thanks for listening to the Application Security Podcast.

53:09David QuisenberryThank you. I do want to give some books though.

53:12Chris RomeoOh yeah. Okay, sure.

53:13David QuisenberryWe got to give a book list.

53:14Chris RomeoYeah. Because I'm a book guy. Give at least one book or more.

53:17David QuisenberryUm, okay. So here's, here's some books. Um, if you haven't read the Cisco Desk Reference Guides, Volume 1, Volume 2, those are excellent. They're books that you want to read a couple of times through. First one's more big picture. Second one's more tactical. Um, the newer book by the guy who wrote The Phoenix Project, uh, Gene Kim, Wiring the Winning Organization. Very quick read. Uh, lots of really good stuff in there. around leadership and around like team performance. As we think about how hard life is right now for a lot of people, there's a really good book on trauma that, you know, a lot of us, we think about trauma in terms of like a violent experience or something like that. But there's also a lot of trauma that comes from like not having attachment with your parents. And one of the things that, you know, came outta COVID is a lot of parents had their own worlds rocked and that affects our kids. Um, and so The Body Keeps the Score is a really good book on trauma.

54:21Chris RomeoI've heard that one before. Yeah.

54:22David QuisenberryUm, Security Chaos Engineering, excellent book on building a program. Um, you know, thinking about security and, and trying to move away from security theater. Uh, so highly recommend that book. Um, for the incident responders out there or people curious about incident response, uh, my favorite incident response book is Intellins. Intelligence-Driven Incident Response. I think there's a second edition of it now. But it is, it is excellent. For building relationships and mentorship, Never Eat Alone. It's an oldie but a goodie.

54:56Chris RomeoYep.

54:57David QuisenberryAnd then for just how we think, Thinking Fast and Slow by the late Daniel Kahneman. And then you were talking about, like, the ideas you have walking and how like in life, sometimes just having open space can unlock all sorts of things for us. It also is really, really good for building resilience. So there's a great book called Do Hard Things: Rethinking Resilience. It'll blow your mind. It's a really good book. It's one that I listened to and then I bought the book because I'm like, okay, I need to read this like slower and like Underlying shit. And then the last one is not a book, but it's a white paper and it's one. So I had a professor in college who said like, dig the well before you need it. And that's for me, like what reading is. And so this is something that I try to go back to once a year and read and reread and think about, but it's, it's how leaders build, what is it? How Leaders Build and Use Networks. in the Harvard Business Review. I think it was from 2007, but it talks about like 3 different types of networking. So you have operational networking, you have strategic networking, and I forget the third one, but it's this idea around like that deep, deep networking across your org and then outside of your org that, you know, the best leaders commit to and nurture.

56:25Chris RomeoVery cool. Well, yeah, thanks for sharing those. I recognized a few of them that I've read in the past, and then a few that I want to add to my list as well to, to knock them out. So, Chris, thanks for being a part of the show and for being— thanks for being vulnerable with us through this process. And also telling you, you got to write a book. There is a book to be written from your expertise. And so we can't wait to read it. Can't wait to announce it on the show here in the future.

56:50David QuisenberryAwesome. Thanks, guys. Thanks, Robert. Thanks, Chris. Thanks, listeners.

10,561 words · transcript by assemblyai

More on Security Culture

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.