Skip to content
AppSec PodcastThe Application Security Podcast — home
37 min

Tracy Maleeff -- Natural Paranoia as a Career Path? A Transition to Security

With Tracy Maleeff

Careers in AppSec

Can a career in library science become a foundation for information security? Tracy Maleeff joins Chris and Robert while making that transition, bringing research, organization, and communication skills into a field often defined by technical job titles.

Listen

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 9 chapters
  1. 00:00Tracy Maleeff’s transition into information securityAudio
  2. 08:33Recognizing when it is time for a career changeAudio
  3. 11:51Transferable lessons for developers and testersAudio
  4. 13:35Building genuine relationships in securityAudio
  5. 18:41Unexpected benefits of making connectionsAudio

About this episode

Can a career in library science become a foundation for information security? Tracy Maleeff joins Chris and Robert while making that transition, bringing research, organization, and communication skills into a field often defined by technical job titles. She explains how she explored possible directions, tested her interests, and used conversations with practitioners to understand the work before committing to it. The discussion focuses on networking as genuine relationship-building, asking for help, and finding welcoming communities at conferences and online. Tracy also shares a method for planning a career change and a book that helped shape her interest. Her story offers developers, testers, and people outside technology a concrete example of recognizing transferable skills and investigating a new path deliberately.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Tracy Maleeff:
Tracy Maleeff on LinkedIn
InfoSecSherpa

Resources
The Cuckoo’s Egg by Clifford Stoll
Security BSides

Actionable

From this conversation

  1. Follow trusted InfoSec sources

    Search by InfoSec hashtags even, and follow things.

    32:50
  2. Attend local security events

    Go to meetup.com, see what's in your area, go to BSides events.

    32:50
  3. Study the history of security

    You need to understand where security as an industry came from to fully appreciate and get where it is now and where it's going.

    32:50
  4. Make networking a give-and-take relationship

    Your very first thought would be, what can I do for them?

    19:26
  5. Volunteer on security projects

    Volunteer to Work on something with OWASP.

    29:36
Transcript · 37 min conversation

0:05Chris RomeoThe Application Security Podcast. Here we go. On this episode of the Application Security Podcast, Robert and I are joined by Tracy Maleeff. Tracy is in the middle of an interesting transition in her career. She began her career focused on the library sciences and is currently in the process of making a move into information security. So we had lots of questions for Tracy about what type of things does somebody have to worry about when they're doing a transition like this, How do you get out and network and connect with people? Is there a process that you can go through? And then she finishes with 3 actionable things for those who are transitioning into information or application security. This will definitely be worth your time to listen to and understand, so please enjoy. All right, today we are joined by Tracy Maleeff, who's going to talk to us about her career and how she's entered and joined the world of information security. Tracy, if you would start us out by explaining to us your superhero origin story, or how did you end up doing something in the world of information security?

1:35Tracy MaleeffSure, absolutely. So my story begins on a train. I was commuting in and out of the city, and I was a librarian. I worked at law firms as a librarian for about 10 years. I have a master's degree of library and information science, and I'd worked really hard to get to the office with the window and a door and things like that, but I was crying because I was tired of hitting my head on the ceiling. It's not the glass ceiling that you hear about. It was more like an opaque ceiling. I had no upward mobility. There was nowhere else for me to go. I already reported to the director and I'd already done a lot of work, widespread work in that field. I'm spending these times commuting in and out of the city to a job that I didn't really care for anymore. I loved the firm, but the job wasn't challenging me anymore. So I started to think back to what in my life, not just school, but work, had brought me joy and thought about it. And I realized that it was anything to do with computers. I was the one attempting to fix the computer at past jobs or One time when I was in college, I worked in an applied research laboratory in the '90s and found some backchannel email that nobody knew existed. And, you know, kind of getting into things that maybe I shouldn't have gotten into. So it all started to come back to me of, okay, well, I don't know why I never pursued it, but I'm at a standstill now. So let me kind of dip a toe back into tech world to see if it's something that still brings me joy. So I signed up for a lot of those meetup.com events and Girl Developers bit and went to a lot of coding classes and a lot of front-end development classes. And I just quickly realized it wasn't for me. It wasn't my thing. And I started to despair because I thought, oh, I didn't realize that there was a greater world out there. I didn't quite really understand about security yet. So I really started to despair because I thought, oh, this isn't, you know, my thing. I'm not liking this, but I still need to do something. So it was a friend who was a longtime sysadmin who had recently transferred into security, you know, said to me one night over beer, you know, let me tell you about what I do in a day. And he told me about his job, and being the librarian that I am, I took a very methodical approach to setting up alerts about security news and, you know, looking into journals and publications about information security. And I was smitten. Like, oh! That's when I had the light bulb over my head of, oh, my natural paranoia and distrust of things is a career path?

4:26Mm-hmm.

4:28Tracy MaleeffThis is fantastic. So that's when I started to, you know, I stopped going to the front-end development meetups and things like that and started to focus more on security. And then that's when I started to have revelations about how I have all these transferable skills. I mean, promoting a culture of security isn't that much different in many ways to promoting a culture of copyright compliance within an organization. Because if you do either one poorly, you get into trouble. So the, you know, it's not exactly the same, but it's similar enough. And I just think that whole outreach to users and understanding the user, but also being able to communicate between departments, as I'm realizing that I had all these skills that could apply into InfoSec world. So I just started to throw myself more and more into that. I took classes through the Women's Society of Cyberjitsu.

5:27Chris RomeoWow.

5:28Tracy MaleeffI dove into Network+. I haven't— I'm still— I haven't yet passed it, but I'm still, you know, getting knowledge about it, uh, you know, working on that, getting, getting that together, um, going to every security con that I can possibly get into. I actually just presented this past weekend at BSides Philly. That was my first ever real security conference presentation.

5:55Chris RomeoOh, cool. Congratulations.

5:57Tracy MaleeffThank you. Yeah, I was thrilled to be accepted, and my topic was— it wasn't a tech presentation, but it was about research. So I was showing people how to use social media or just general open internet searching for OSINT, or if you need to do phishing research or things like that. And I came about it from a whole different point of view. And as I got up there in front of this room full of hackers, I said to them, yes, I'm going to show you things that you probably can write a Python script for, and that's great. But I'm going to show you a different way to do things that's a little bit more organized because you're not dealing with a data dump, you're dealing with already formatted information. So I think by diffusing that right away, I was able to get this tech crowd on my side that I wasn't trying to tell them what they were doing was wrong. It's just I'm going to show you a different way and a different approach, and here are some resources you probably never heard of that that will help. So I've received tons of positive feedback about it. So I'm really pleased. So that's, you know, in a, in a, like, Brazil nut-sized nutshell. That's kind of how I got to, to here. I was just, I was discontent where I was. You know, I wanted something that brought me passion and joy. And I had to think about what that was. And then I tried it. And there were some frontend development classes that I just walked out of. There was a Ruby on Rails class that I sat in, and I think I paid $25, and I was there for maybe half an hour or less. And I don't know that I've even made it to half an hour, but I sat there and I thought to myself, I am okay to spend $25 to rule this out of my life. That's how I looked at it— not wasting $25. That was $25 well spent for me to just cross that off. and just know, I don't want that as part of my life.

7:53Chris RomeoYeah, I mean, that's a pretty cheap investment to be able to say, okay, Ruby on Rails is not for me. So I think that's really worth it. It's a worthwhile type of thing.

8:01Tracy MaleeffExactly, exactly. So yeah, I tried everything that was low cost or free just so I could have a sampling. And yeah, I had very little skin in the game. So yeah, if I went to something and I didn't like it, then I just left. And then I could cross that off and go to the next one. So again, I'm not disparaging front-end development or coding or anything like that. It's just not for me. Um, you know, I— now I do like Python, um, but just the other front-end side, I— it's just not my, not my jam. I think security is more my jam.

8:33Chris RomeoSo from, so from your previous job then, did you, did you still like doing the work? Or did you reach— was the work still good? Or did you get to the point where you really didn't enjoy doing the work and there was no other place to go?

8:49Tracy MaleeffThat's a complicated question. I didn't enjoy the work. I, I just feel like there was more that I could have done that I wasn't being able to do because, you know, we had a large staff and, you know, things were other people's jobs. So, you know, things like that. I just think that, you know, I outgrew my position.

9:12Chris RomeoOkay, so it was, it was It was the ultimate reason was there was really no place else for you to go inside of the organization.

9:19Tracy MaleeffCorrect. And I did look outwards and I did get offers from other law firms. But honestly, it was more of the same. And I wanted something different. And, you know, what really got me excited about security and the opportunities for me is on a whim, I emailed the CIO of the firm that I was at. And I asked what the firm was doing for Cybersecurity Awareness Month and told him that this is, you know, security has become my quirky hobby and I have some ideas and I'd like to help. And so his response was, okay, well, what you got? You know, and I had a presentation all ready to go, so I just emailed it. And the response was, I like all of this, we're doing all of it, and you're in charge. So they had me, they had marketing and someone from IT coordinate with me, and I created these infographics. that went out firm-wide last October, and they, you know, let me get involved with that, which was great and speaks volumes about the inclusiveness of the firm, and I'm very grateful for that opportunity. It's just that when November 1st happened, I emailed the CIO again and said, okay, well, we had a successful Cybersecurity Awareness Month. What can I do next? And that really wasn't my role. Like I said, I was in the library. So, I mean, he was very nice and just said, well, great, you can do it again next year. And I just like, The joke that I made on another podcast I did was, you know, I tasted the blood of InfoSec and I wanted more. I was like, I'm— no, I'm in too deep now. Like, I can't wait till next year. I can't keep going along with my other job and try to like pretend that InfoSec isn't out there for me. So that really got me thinking of like, I need to make a change. And the change was I quit my job at the law firm and I created my own business called Sherpa Intelligence. And I take on clients to do research, competitive intelligence, social media, and instruction too. I've gone to offices and instructed security people about how to do better internet searching and social media searching and things like that. And ultimately, my goal is to get a full-time job in security, but I knew that I needed some sort of buffer segue zone, and that's what 2016 has been for me. to get more involved with the community, learn more, just absorbing everything, and networking and meeting people. So that's, that's what I've been doing, and also taking on clients and any sort of work pieces that I can as well.

11:51Chris RomeoYeah, and I see some similarities, or I, I could, I could imagine some of the folks in our audience who are not yet full-time security people, maybe they're, they see security as a hobby They're a developer, maybe a tester. I see that there could be some things that they could apply from what your experience has been. And I think that a lot of people have the same challenge that you do, or you did, I should say, when you were at the law firm. And to be honest, that's the reason that I actually left my job in corporate America about a year ago at this point, because I reached the end. I looked around and I said, there's nowhere else for me to go. I could be happy here for the next 10 years, but there's no place else to go. And security is just such a big, you know, we have such a big need for information security professionals across the industry. It's just a great time for people to be thinking about making that transition. So I think you, I think this is the right, I think you chose the right time to jump in right now and go full speed.

12:54Tracy MaleeffYeah, I think I'm very fortunate in that. Yeah, the timing was good, and I also think the timing was good as far as inclusiveness goes. I think as far as being female and being a non-tech outsider, I feel like this was a good time that people are realizing that there's different skill sets that can help security, because I have to imagine that if it was— if I chose this a couple years ago, it may have been a little bit of a rockier road. But I really give credit to the existing InfoSec professionals who have just done nothing but welcome me with open arms, and they recognize transferable skills. And they, they— the sense that I get is that people recognize that everyone has something to contribute.

13:35Chris RomeoYeah, definitely, definitely. So you talked a lot about the different, uh, ways that you've networked and connected with people. I'd like to explore that a little bit because on the Application Security Podcast, a lot of times we keep coming back to these soft skill kind of things. We haven't spent a lot of time talking about technology in our 13 episodes so far. A little bit, but we're spending a lot more time talking about what are the pieces that the technical people are missing. I think a lot of people don't really— if we gave them the direction that I think you've done in the last year and said, okay, you need to go network and become a member, get more involved in the community, I think a lot of people would stand there and look at us and go, okay, what do I do? What's the first step? How do I do this? How would you— based on your experience in the last year and and even maybe further back, how would you recommend that somebody that doesn't know anything about this idea of networking, how should they get involved?

14:30Tracy MaleeffSure, gladly. And yeah, this is one of my areas of my wheelhouse, so I love talking about this. So I created a separate Twitter account. I had, I'd been Library Sherpa ever since 2006, 2007 on Twitter. I was an early adopter. I created this InfoSec Sherpa account And I initially had in mind that it was just going to be sort of a lurker account. I went on to see, you know, search different terms of security in Twitter and see who comes up and see who do you see most often, who's talking about this a lot. So start to follow publications and then, you know, when you see articles, most articles now have a Twitter handle for the reporter. So follow the reporter. Follow the publication and then you start to see conversations and you see people and you start to follow them and then you start to—

15:20Chris RomeoRight.

15:22Tracy Maleeffinteract with them. And before I knew it, 6 months later, I attended ShmooCon last year, my very first ShmooCon, and that was my very first security conference. And within an hour, I had 3 different people come up to me and say, oh, you're InfoSec Sherpa. I recognize you from Twitter. And that just blew my mind. But then you start talking to those people. So, okay, that, that's your icebreaker. And then that turns into a conversation. And it may turn into exchange of business cards or connecting on LinkedIn. And I think that what people lack, if they have difficulty doing networking and connecting, is I feel like you need to have a curiosity. And, you know, I don't want to go down the whole rabbit hole of talking about introvert/extrovert because I really don't like using those terms.

16:11Chris RomeoYeah.

16:12Tracy MaleeffBecause I feel like people use them as excuses. And I'm even talking about extroverts too. I feel like sometimes Extroverted people— not all of them, some of them can excuse bad or rude behavior and just chalk it up to be, oh, well, I'm an extrovert. I'm going to be loud and obnoxious. No, that's not what extroverted means. And I feel like introverted people sometimes use that as an excuse not to network with people. And why label yourself? Why give yourself something else to hide behind when all it is is just talking to another human? And if you're not comfortable talking in long spurts to people, then make it short spurts. Go into a room, give yourself 15 minutes, and then go take a 5-minute breather outside and then go back in or something like that. But anyway, back to my story is that I am very curious about people. I love talking to people, hearing their stories, just interacting with people. So I relish those opportunities to follow someone new on Twitter if I see that they made an interesting comment on something or if it's a speaker that I see. I have no problem approaching a speaker after a talk. I did that actually last Thursday. I was at an event and the speaker was this wonderful person, gave this social media security talk. I went up afterwards and even before I could say my name, she said, oh, you're InfoSec Sherpa. And then what she followed up with, I'm a big fan. And that really just— I'm like, what? I'm like, that's blowing my mind, but hi, how are you? So again, it's curiosity. Just be curious about people. And I don't mean in any weird, creepy stalker way, but just ask them what they do. How did they get started? Most people like to talk about themselves. But again, if you can do it in not an intrusive way of, hey, do you have a Net+ cert? Oh, okay, great. What challenges did you overcome to get that? Or do you think it's worthwhile for me to get that? Like, be specific. So, because I understand the security community, there's a lot of people very protective of what they reveal, and I get that, and I understand that. So, so then pinpoint what you ask, something that's not revealing about their personal life or, you know, anything that would require details about what they do.

18:41Chris RomeoYeah. And you never know what's actually going to come out of that as well. Like, you never know. I, in the last couple, and actually this past week, week, a guy that I met in line at the RSA conference 2 years ago— I put something out on LinkedIn, I was looking for a particular consultant that could help me with a certain thing, and this guy that I just met him in line, we sat together at the Innovation Sandbox for 2 hours of time but still stayed in touch. He pointed me to somebody and connected me to somebody in his network who is a marketing guru who's going to help me with some things that I have to do. So The good thing from this type of an experience is that you never know how somebody's going to help you or how you can help somebody else in the future based on that connection.

19:26Tracy MaleeffExactly. The key to networking that I think is lost on a lot of people is that, think of it like a seesaw. It is a give-and-take relationship. When you meet someone, your very first thought would be, what can I do for them? As they're talking to you and as you're shaking their hand and you're nodding, your brain should be going, what connections do I have? What could I do for them? Now, if you're just starting out in the industry, you may not have anything to offer, but what you can do is to check in with them periodically or see what they choose to disclose on social media. Again, if they put out a call for help for something. The phrase that I often use when I talk about this is cultivate your network like a garden. Don't go to someone once and then ignore them and then go back to them later because those roots will have withered and gone away.

20:17Yeah.

20:17Tracy MaleeffDon't keep going to the same plant all the time because they're going to get angry and the plant will stop bearing fruit, and that fruit being any tips or resources that might have use for you. So, you know, like take your garden pail and it comes out as a shower, right? So you just kind of check in with your network, see how things are going. Just say hi to someone. You don't even have to want anything from them or you don't even have anything to offer them. Just, hi, how are you? And especially with the holidays coming up, you can just send a happy season's greetings, happy holidays. sort of thing, you know, I'm looking forward to connecting with you again after, you know, in the new year. That's pleasant enough. So that's, you know, that's a great way to get knowledge. Again, just having, you know, sitting around a coffee shop or a bar listening to InfoSec people talk has been such an education for me. So again, even if you don't have anything to add to the conversation, just sit and listen. Be respectful of, you know, of them telling stories and just listen. And that's how you you know, you form relationships with people. So it's, you know, think of the seesaw, think of a garden, think of a way that, you know, you can help others. And then, you know, and then turn, they can, they can help you.

21:31Chris RomeoYeah. And I think about the— when I first started getting involved kind of in the public side of information security, application security, I was always thinking to myself, oh, I can't, I can't reach out to that person. That's like a famous person. But then I had to always remind myself, if the— while these people may be famous inside of the small world that we live within, nobody's gonna see them on an airplane and go, oh, do you know who that is?

21:56Tracy MaleeffYeah.

21:57Chris RomeoRight? I mean, it's a, it's a, it's a small community. And I, I really— I can say in my, you know, number of years that I've been on social media here interacting with other people around the world that are in the security industry, I've never had anybody just flat out say, no, I can't help you. I won't answer that question. I won't explain to you. This is a community of people who love to share stories and love to talk and share experiences and help mentor people. So, I would tell anybody out there, don't be afraid to reach out to somebody. Don't be upset if they don't answer right away or immediately. You might have to ping them a second time. Everybody's busy in this world. We have thousands of emails, thousands of tweets and things, so we might miss it, but the people that are in this industry, we want to help other people learn and grow.

22:49Tracy MaleeffExactly. Again, you said exactly that. Don't be upset if someone doesn't get back to you. The worst that's going to happen is that they don't respond. When I emailed the CIO of the firm, I was expecting— I thought about it. What's the worst that could happen? And I did think, well, maybe I could— like, could I get fired for asking to help with something? Like, I don't think so. So it's like, okay, the worst that could happen is that he just doesn't respond and ignores my email. Okay, well, that, you know, and then the best-case scenario wound up happening. But yeah, I thought through my head, what's the worst that could happen? And for, yeah, a lot of these, what's the worst that could happen is they, they don't respond. Well, Then, you know, then you move on. Or, you know, think about it more of computer networking for a second, of, you know, there's got to be another way to connect. So go to things like LinkedIn and see who that person is connected to. And you might know someone and say, oh, do you know so-and-so? Would you mind making an introduction for me? I know that there are some security people that they're more apt to respond if it's someone they know, you know, sending in a referral.

24:01Yep.

24:01Tracy MaleeffSo, you know, think outside the box. source it or think about it, you know, like some— think of it like a computer network. You know, the, you know, bus connection isn't the best way to do networking. You need a mesh or a star. I told you I've been studying Net+.

24:22Chris RomeoSo if you had to break down, is there a process if we go back, if we kind of move away from the networking side and start to think about preparing somebody to make a transition. If you had to break that down as a process, I mean, is there a series of steps that you went through that somebody else could follow at a high level?

24:41Tracy MaleeffI would say, you know, going to events, you know, going to events and mingling with people who are in this industry. Because if you don't get any joy out of being at the event, not just the Like, if the topic doesn't resonate with you and the people at the event, you know, you're not clicking with them, you know, that's one thing. That's a physical process you can go to is by going to events and just reading, reading up on these, the news stories and the books that are out there because it has to come from inside you. Do you get excited reading this topic? Does this interest you more that it gets your mind thinking of what else? Like, it really needs to be introspective.

25:27Yeah.

25:28Tracy MaleeffAnd you need to have experiences of going out and meeting people and experiencing things and reading these things. I mean, that's the best that I can think of is because you have to have these experiences. If you go to a B-Sides event and you walk away, you know, wide-eyed and excited and filled with ideas, then that's a good— pretty good indication that you like this world. But if you come out of it the opposite, then that's—

25:53Chris RomeoYeah.

25:54Tracy Maleeffan indication the other way. And for me, I had that at a WordPress conference. I went last year, and this I had signed up for when I was still in my experimental phase. And by the time it rolled around, I was still— I was sure that I wasn't interested in security, but I wanted to attend anyway, again, just to really make sure that I could cross that off. And I wrote a whole blog post about this experience, so I won't get into detail. I can give you the link to post later. But the takeaway for that was I didn't have a great experience. I didn't click with the people at the event. I very quickly learned from them that the majority of the people I spoke to did not care about security and had, you know, just had no desire to even listen to me, you know, say the word security or talk about it. And there was only one session that dealt with security at the whole event. And It just— also just to see the way that people were treated there, it just did not go well at all for me. So I left that event, but this is how I spun it in my mind of, okay, I don't really— don't think that this world is for me. I feel more comfortable at these security meetups that I've gone to. And then a month later, I went to ShmooCon and my mind was blown about how great the community was, and it was the complete exact opposite experience.

27:19Chris RomeoMm-hmm.

27:21Tracy MaleeffBeing able to experience something is a pretty good indicator whether or not it's for you. I was very fortunate that I had those experiences a month apart because then I didn't dwell on the negative of that one, of the first conference, because then before I knew it, I was at ShmooCon and my whole world changed. So get out there.

27:43Chris RomeoThat makes me think of the And the only reason I'm thinking of this is I actually heard somebody that I know shared this story just recently about a— this is the kid that goes to law school, spends $150,000, $200,000 on school, and then gets their first job and 2 weeks later quits as a lawyer because they're like, I hate the law. I hate this. This is terrible. Why do I have to do this all day? So that's an extreme example. But I think there's some parallels that you can draw there from. If you're thinking about, well, maybe security is something for me, then I think, Tracy, you've given some examples of going to meetups and connecting with people. Feel out that environment to see if this is really— before you invest your $150,000 or $200,000 to find out you hate being a lawyer, invest that some time to see, do I really love security or is there something else that I'm more passionate about?

28:35Yeah.

28:35Chris RomeoBecause I'm a firm believer that If you're going to take it, you should take a job where you would do the job if they— even if they didn't pay you because you love it so much. And if I think if you have that kind of passion for whatever the topic is that you're going after, whatever you're going to focus your career on, it's hard not to be successful if you love what you do. It's easy to not be successful if you're just going through the motions.

28:58Tracy MaleeffExactly. And I received some good advice from Chris Rydes. He is a recruiter in the InfoSec field. He said to even just volunteer places. places at first. If you're still trying to build your skills and also see if you like it, once you start networking with people, maybe they know of a nonprofit that you can spend some time with. Now, I know this is a very weird area because we're talking about security and just someone off the street volunteering, but I know that there's opportunities out there.

29:35Chris RomeoYeah.

29:36Tracy MaleeffOr even OWASP, like Volunteer to Work on something with OWASP. Like, put yourself out there. Lisa, put yourself in a position that you would actually deal with this to see whether or not you like it. So not just a meetup where it's a more social atmosphere, but something that's as close to a work atmosphere as possible, which would be volunteering with something. And whether that be OWASP or an organization, or even if you just know enough about security to tell people about it, maybe go to the your local library and ask the library director if they would like to have an evening of security, and then you could just spend an hour talking to people about it. And again, if that excites you, then maybe that helps point you in the right direction. So you need to actually get out there, have tactile experiences. You need to be in there doing something. You can't just sit at home surfing and going, yeah, I think that looks okay.

30:27Yeah.

30:28Tracy MaleeffBecause a lot of the marketing these days. And actually, I meant to take a picture of this. On the New Jersey Turnpike, there was a big billboard advertising cybersecurity. It was some sort of technical school advertising their cybersecurity program, and they used dollar signs for the S's in cybersecurity. And I really took offense to that. And I said, I wish I could take a photo, but I was driving. And I actually, I took offense to that. I just I don't know, I'm barely in the— I consider myself barely in the industry, and I myself don't want people in it for the gold rush. Like, I want you to be here because you care about what you do.

31:07Chris RomeoYeah.

31:08Tracy MaleeffAnd I know that that really upsets veterans if you say, you know, veterans of the industry, if you say that, you know, you're just here for the money. I have seen uncomfortable conversations unfold as people just say, oh, I'm just here for the money.

31:26Chris RomeoThose people won't last. They'll fall out when times get tough. If it's not something they love, they'll just flip to the next big thing. But I agree, I wouldn't invest. If somebody asked me— if I heard somebody say they're just in it for the money and then they asked me to mentor them, I'd be like, well, I kind of need people that are really passionate about what they're doing that aren't not just looking for dollar signs.

31:49Tracy MaleeffYeah, yeah, exactly. So yeah, so what my joke is, you know, what I lack in hardcore tech experience, I make up for enthusiasm and willingness to learn. So I have all these other skills, it's just I'm kind of, you know, missing some, some things there. But I am welcome, you know, I love to learn and I'm super enthusiastic and passionate about this. So I am using that to make my way into InfoSec world. And that's what I think everyone should have. You need to have passion and curiosity and interest.

32:20Chris RomeoYeah, definitely. So to kind of land the plane here on this conversation, I'm thinking about what would be 3 actionable things that you would share with somebody that's listening to this that's thinking, wow, I think I want to transition into security. What— and just get as specific as you can so that they could potentially write this on a list and say, I did number 1, I did number 2, and now I did number 3, and hopefully I have a better feeling now.

32:50Tracy MaleeffOkay, let me think. Number 1, I would say, is get involved on social media with the InfoSec world. So, you know, I would say, you know, InfoSec Twitter world is very educational. People share knowledge all the time. So even if you're not interested in tweeting out, just set up a Twitter account. You know, and just so that you can see what's going on, search by InfoSec hashtags even, and just follow things. Second, get out and go to meetings. Go to meetup.com, see what's in your area, go to BSides events. Again, you don't have to spend a lot of money. A lot of BSides are free or inexpensive, and most likely there's one in your general area. So to the best of your ability, go to either meetups or conventions as you can afford them, but go in person to experience things. And lastly, I would also read a lot of— just do a lot of reading. And I know that I'm not saying this just because I'm a librarian, but do it. Maybe I am. You need to do reading. There's also a lot of books about the history of security. Palo Alto Networks, for example, has the Cybersecurity Canon, which is this vetted list of books that they believe every cybersecurity professional should read. So there's a lot of history that you need to know as well. And now I was a history major, so this definitely is coming from that point of view. You know, you, you need to understand where security as an industry came from to really fully appreciate and get where it is now and where it's going. You need to have some sort of fundamentals.

34:42Chris RomeoYeah.

34:43Tracy MaleeffSo get reading.

34:44Chris RomeoYeah, what, uh, so I'll leave you with this last question. If you had to recommend one book for somebody—

34:50Tracy MaleeffOh no, I was afraid you're gonna ask me that.

34:52Chris RomeoI love this question. I, I love asking people this question because I love to read. I read all the time, and I like to read a lot cross-disciplinary. I try to read stuff in security, read fiction, mix a lot of different things— marketing, other types of things in. So if you only— if you could only give one book, I know you'd probably want to give a stack stack. But if you could only give one right now for somebody who's thinking about this transition or wants to get into InfoSec, what would you recommend for them?

35:19Tracy MaleeffI'm, I'm looking, I'm looking. Okay, so I'm going to recommend this one because a very cool guy who knows a lot about this area recommended this book to me. And I'm about halfway through it. Alan Friedman, he's the Director of Cybersecurity Initiatives at the NTIA. And he recommended to me The Cuckoo's Egg by Clifford Stoll.

35:43Chris RomeoOh yeah, cool. That's definitely a good one. That's an old book.

35:47Tracy MaleeffYes. Well, I said history. You need to do this. So The Cuckoo's Egg by Clifford Stoll. When I met Alan Friedman, he said, you need to read this book. I'm like, okay, I will get through it. I haven't finished it yet. I'm still getting through it. If I have to pick one book, that is a book that I would recommend.

36:06Chris RomeoVery cool. I'll have to go back and read that again. been probably a decade or two since I read that the first time, but it's on my shelf, still on paper.

36:14Tracy MaleeffSo, excellent, excellent.

36:16Chris RomeoSo Tracy, thank you so much for your time here today, and I know we kind of went a couple of different directions, but I think this is stuff that's really going to help our audience, especially those that are thinking about a transition. So once again, thank you, and we really appreciate you taking the time.

36:28Tracy MaleeffMy pleasure. Thank you.

36:30Thanks for listening to the Application Security Podcast. Our intro music is 8-Bit Kung Fu by Born and Teaching, and the outro is Southern Delight by Stefan Kartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org.

6,618 words · transcript by assemblyai

More on Careers in AppSec

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.