--- title: "Vandana Verma — Support each other" url: https://appsecpodcast.com/vandana-verma-support-each-other/ date: 2020-02-08 duration_seconds: 1710 guests: ["Vandana Verma"] topics: ["Security Culture", "Careers in AppSec"] audio: https://www.buzzsprout.com/1730684/episodes/8122614-vandana-verma-support-each-other.mp3 transcript: true --- # Vandana Verma — Support each other *February 8, 2020 · 29 min* with [Vandana Verma](https://appsecpodcast.com/guests/vandana-verma/) on [Security Culture](https://appsecpodcast.com/topics/security-culture/), [Careers in AppSec](https://appsecpodcast.com/topics/careers/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122614-vandana-verma-support-each-other.mp3) ## Show notes Building a stronger security community means helping more kinds of people participate and succeed. Vandana Verma returns to discuss her early work on the OWASP board, her ideas for improving outreach, and the broader meaning of diversity in application security. Chris asks about neurodiversity, inclusion, hiring standards, and how managers can find capable candidates beyond familiar networks. Vandana explains why support and training matter alongside opportunity, and why a skills shortage cannot be solved simply by moving experienced people between companies. She also shares the story of InfoSecGirls and discusses Women in AppSec. Her message is practical and personal: actively welcome people, help them develop their strengths, and support each other as the community grows. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Vandana Verma: → [Vandana Verma’s website](https://infosecvandana.com/) → [Vandana Verma on LinkedIn](https://www.linkedin.com/in/vandana-verma/) Mentioned in this episode: → [InfoSecGirls](https://infosecgirls.in/) → [OWASP Foundation](https://owasp.org/) Chapters: 00:00 Supporting the application security community 02:58 Vandana’s early experience on the OWASP board 04:25 Priorities for community outreach 07:01 Understanding the many forms of diversity 08:07 Neurodiversity and inclusion 09:11 Making diversity a shared effort 11:48 Hiring standards and developing potential 13:24 How diverse teams strengthen security 17:34 Advice for hiring managers 19:39 Reaching people beyond familiar networks 21:46 The story and growth of InfoSecGirls 24:41 Women in AppSec 27:14 Support each other ## Transcript *4,972 words · assemblyai* **0:00 Chris Romeo:** Vandana Verma is a passionate advocate for application security. From serving on the OWASP board to running various groups promoting security, organizing conferences, she's engaged in making the global application security community a better place. She manages the InfoSec Girls organization and is a leader for the OWASP Bangalore chapter. Vandana joins us to discuss her work so far on the OWASP board, to discuss the keynote she did at AppSec DC on diversity, and to catch us up on what's happening with InfoSec Girls and WIA. We hope you I hope you enjoy this conversation with Vandana Verma. Are you trying to build a security champions program? Everyone is these days. One challenge of rolling out security champions is, how do we educate all these new folks? Security Journey has your answer. We provide a security dojo environment with level-based security education that gives your newfound champions a path to follow. And the best part? It requires almost zero administration by you. Visit www.securityjourney.com up a demo and learn how you can use the Security Dojo to connect with your security champions. Hey folks, welcome to this episode of the Application Security Podcast. This is Chris Romeo, CEO of Security Journey and also host or co-host of this podcast. I'm joined by Robert Hurlbut. Hey, Robert. **1:33 Robert Hurlbut:** Hey, Chris. Yeah, it's Robert, Threat Modeling Architect. Good to be here. **1:36 Chris Romeo:** Yeah, good to have you. And you just finished up a tour of the Midwest of the United States and got a chance to spend a little bit of time at a conference, right? Have a little bit of fun. **1:46 Vandana Verma:** Right. **1:47 Robert Hurlbut:** Yeah, I went to Codemash, one of my favorite conferences. It's always great at the beginning of the year. They have a water park there that you get to enjoy, but also lots and lots of great talks from developers as well as some security talks on application security. So those are always nice. **2:04 Chris Romeo:** Hold on. Um, a water park in Ohio in January? I'm not, I'm not seeing it. Like, it seems like it would be a little cold outside for the water slide. **2:13 Robert Hurlbut:** It would be if it was outside, but it's indoors. **2:16 Chris Romeo:** Ah, an indoor water park. Okay, that makes a whole lot more sense. All right, well, today we are joined by someone who has actually been on the podcast before, Vandana Verma, who is a person who's going to talk to us about a number of different things today that we're super excited about. So Vandana, welcome back to the Application Security Podcast. **2:37 Vandana Verma:** Thank you so much, Chris, um, and I'm glad to be part of it again. And, um, hi Robert, we are talking for the first time. **2:46 Robert Hurlbut:** Yes, uh, good to talk to you. I, I did see your keynote there at the AppSec USA and, uh, or Global USA I guess is what they call it, I'm not sure, in Washington, DC. Really enjoyed it. **2:57 Vandana Verma:** Thank you. **2:58 Chris Romeo:** Yeah, and the, uh, first interview we did was in the speaker lounge of AppSec EU back in 2018. And so if folks want to look up that episode, if you search for Women in APSAC. That was the name of the episode that we did with Jesse as well. And so yeah, you can look that up to get some history, and that's where you'll find Vandana's security origin story. But since you've been here before, let's go ahead and dive right in. And the first thing I had on my list I wanted to hear about was your election to the board of directors of OWASP. We definitely love OWASP here, as our listeners already know, because we talk about it all the time, almost nonstop. And so I'm curious to hear How, how is that going? And what does that look like as a member of the board of directors for OWASP? **3:46 Vandana Verma:** So it's going amazing. I've started understanding how the board works. What are the responsibilities of a board of director? How an open community works, because I need to understand the culture and then only I'll be able to serve. So right now I'm going through all the books that have been shipped to me. What are the responsibilities that I have to take care of? My first meeting would be next week during the Apps California time. I have attended a couple of meetings in the past, but not as a board member. So it's going fine at the moment. There are a few things which have come my way to think through it. So it's a lot of responsibility and a great challenge for me. **4:25 Chris Romeo:** Yeah, we definitely thank you for, for being a part of that and serving in that way. And so when you think about what you want to accomplish here in this time that you're going to spend on the board, which I believe is a 2-year term, what are some of your top priorities? priorities that you're hoping to achieve? **4:41 Vandana Verma:** There are a lot of things. I'll start off with the projects, which is one part which I'm very close to. So there are a lot of projects which needs attention. So they'll be like the most important for me, wherein if any projects needed attention, I try and jump in, help the community getting the right kind of attention for that project. And there are a lot of new projects which we can bring in because OWASP has been known for its flagship projects, especially if I talk about OWASP Top 10. Proactive controls and many more. So a few projects have got the attention, but the others still need it. If I say dependency checker, it's gearing up. So that's one. Then looking into the chapters, because there have been a lot of chapter leaders which left in the past. So we just want to revive the culture, redefine the culture, and bringing the old people and more people, more people or more chapter leaders. These are the 2 things and work with the co-board of directors, understand what are the new strategies we can have for the whole community? What are the new mergers or partnerships we can have with different forums so that we can have a bigger outreach? These are the, some of, these are some of the things that I have in mind, but I'm sure as I, I become more involved in different things, I'll have more things as part of the roadmap. **6:04 Robert Hurlbut:** Yeah. **6:05 Chris Romeo:** Yeah, and I know one of the big things OWASP is doing right now, which is about to launch as we record this podcast, is the migration from the old media wiki to a new— I want to call it newfangled, but it's really a nice-looking website that is very well structured and is going to make it easier for individuals to find chapters, to find projects, to see some of the things that OWASP really wants to highlight and get out to the world. Because when I heard the statistics from Mike, the executive director of OWASP, about the number of visitors to the website, it just blew my mind. It's like millions and millions of people are looking at this stuff every year. And so now there's going to be a really nice face of the organization to see the projects and the chapters. **6:53 Vandana Verma:** Right. It's like a one-stop solution for every project, chapter, anything. what's happening, conferences, all of it. **7:01 Chris Romeo:** That's great. So, I want to change gears a little bit, talk a little bit about some of the things that you covered in your keynote for AppSec DC. And so, I know that the topic for the keynote was diversity and inclusion. And so, a couple of questions to help our listeners understand kind of the things that you were focusing on there. And so, I thought we'd start with getting just kind of your thoughts about when you say diversity, what are the true forms that you described in that keynote? **7:34 Vandana Verma:** So true forms of diversity could be starting with differently abled people, ethnicity, education, culture, neurodiversity, age, but not limited to just gender gap, because there are still groups which, or individuals which feel that diversity is either not an important subject or not an issue at all. So we have, when we When we talk about diversity, we have to consider other forms as well, like not just men or women. It has to be all the people. We have to be inclusive. **8:07 Chris Romeo:** And so I guess some of those other categories, like, you know, specifically neurodiversity, kind of how does— what does diversity look like and inclusivity from a neurodiversity perspective? **8:24 Vandana Verma:** If I say neurodiverse people, they are the name itself says that they are diverse people. They have a focus area wherein they would be only able to do this particular task at that particular time. So shouldn't we welcome the creativity and innovation from them? So in cybersecurity itself, if we talk about cybercriminal, we need to have a fresh and creative mindset. That's why there are new things which are coming up. Zero days are coming up, new hacks are coming up. So we can't say a person can't be a good security researcher if that person has certain limitations of any kind. If I give you an example which I quoted there, which is one of my favorites, Stephen Hawking, he's done wonders for the community. He's a— he's like— he's a legend. He was a legend, legend, and he's still considered to be a legend in science. **9:11 Chris Romeo:** So what are your thoughts then on alienating men in diversity? **9:16 Vandana Verma:** On this, I would say that when we say alienating men, we, we shouldn't be bringing up gender issues at the cost of bringing down men. I never supported, and especially the communities that I work with, I try and make sure that we don't support such kind of things. So while we are working towards including diverse team, we should understand that we as diverse group have an equal role to play. Even if I say I'm a woman, I have a certain role to play in that picture. So mainly it should be against the preconceived notion, like this person cannot do this task. If this person is neurodiverse, that person wouldn't be able to do any kind of a tech job. Or if it's a woman, she wouldn't be able to do certain tasks. If it's a man, they wouldn't be able to play with dolls or they wouldn't be able to cook. So that's around that, wherein we're not bringing up gender issues at the cost of bringing down the other gender or men specifically, I would say, because there have been a lot of discussions in the past. Talk about Twitter, talk about emails, talk about on the stage. When diversity comes into picture, it's always about men, women. Diversity is not that. It's about supporting each other, understanding what all— what roles we all have to play. **10:25 Chris Romeo:** What do you see as some of the kind of challenges then Or I guess, yeah, what have you seen as far as the challenges in alienating men in diversity? Do you see people kind of taking— do you see men across the industry taking kind of a negative approach because they're afraid that they're going to somehow be discounted or eliminated from the process? Or what do you think is kind of going on there? **10:51 Vandana Verma:** As we talked about different forms of diversity, like in the previous discussion, we are trying to bring more diversity. We're in no way trying to reduce the existing groups. There are people who are actually sometimes scared of such kind of talks, but we need to make the other party comfortable. Let's say if we are in a room in an organization and we're talking about bringing more diversity, that has to be very clear. We want people with the right skill sets in the room, but we need different ideas, people who have different backgrounds, who have different age groups. That has to come on the table. I'm sure if we have diverse people in the room, it's going to make something better. We'll have a better project, better product, a beautiful outcome, I would say. But yes, sometimes these talks do scare men. That's what I've seen. But diversity has to be including all of us, not just men or women. Yeah. **11:48 Chris Romeo:** Now, I've heard some people say before, when they're thinking about kind of from a hiring context, somebody will say, well, you know, we support diversity and inclusivity, and but we're just going to hire the best person Yes. What's your reaction when you hear that statement? Is that, is that a valid approach or is there some type of flaw in that approach? **12:12 Vandana Verma:** So it's, it's a debatable thing, I would say, because for some people they have a perspective wherein some people say that we are a merit-based system. Whosoever falls under that particular merit, we will hire them because they have already proven their merit. But how about some people who actually want to do it, but they don't have the right skill sets? Can we train them? Merit is good. I'm all supportive of that. But we have to consider that there will be some people whom we might need to train. So if we are hiring diverse people, can we give them a month or 2 training and then take it forward? Then I'm sure it's a valid point. Tell me one thing, a person who's a topper in a class, the person who's like just passed, or the person who's passed, just passed, that person has, has created a big company and the person who scored the highest is just working working as a, as a, as a person, as a manager in some company. What's the difference? So some— so the merit is good, but numbers don't define that. How is the people? Talk to people. If someone applies for that job, try and understand why they did it and then decide whether they are best suited for that position or not. Saying just simple lines that we are— we believe in merit doesn't suffice that. **13:24 Chris Romeo:** Okay. So when you think about diversity and its role in cybersecurity, what What are the benefits specifically in the cybersecurity and application security world to having a diverse workforce? **13:37 Vandana Verma:** First of all, it saves us from the groupthink mindset. That's what I feel. Also, think about, we have been talking about skill shortage in cybersecurity, but how do we address that? If we have people, let's say from development background, and they have a zeal to learn cybersecurity, can we create some champions within the organization? Get those people as part of our cybersecurity teams. I'm sure there'll be a lot of gap that will be addressed, and we might be able to see some innovation and exchange of ideas wherein the person who's been part of development or operations team, or even the person who is working as a journalist, that person might be able to give us some view. So if I would say that we would need to actually challenge the status question and think differently in this. People who will not just agree with what one person has to say, but they have their own imagination, they have their own ideas which they can bring to the table. Another thing I would say that there's one friend of mine who did psychology, which is like especially on the criminal justice, and she has like the complete background of that. These skills are like unique, so their approach is going to be completely different than what we think. And trust me, when there is an investigation that's going on, her perspective is completely different and unique, and we always take that into consideration. Another point is, especially we as cybersecurity people, if we cultivate diversity, it's going to bring more diverse people. Talk about the communities that we are working with. Sometimes it's not just the person is feeling insecure, but sometimes let's say if I am just the only one person, I might feel that I'm the odd one out. Not the other people are making me odd one out, it's just my perception that I am just an odd one out. I think that's one of the challenges that we have in cybersecurity. We look for people who are similar to what we are accustomed to or what we look for skills that we know are effective. If we have a SOC, which is Security Operations Center, we only look for people who have that background. If it's a computer science background, someone who has experience in operating system or computer networking, they might be a good match for us. But that's not it sometimes. I like— I gave you example of psychology or lawyers. People are going for cyber law. Even I wanted to do cyber law to understand how and in what situations I can act upon in what way. **16:09 Chris Romeo:** And you mentioned the skills shortage that it seems like we've been talking about for 5 or 10 years at this point in the kind of bigger umbrella world of cybersecurity. And I am definitely a big proponent of saying, hey, we got to build more people that can help to solve this skills shortage. It's not going to happen by just moving people around because we all know lots of people in the community, and especially in the world of application security, I can't think of anybody that I know that would say they're unhappy in their job. Because if they're unhappy in their job, they just get a different one because there's so much demand for what folks are doing in the world of application security. So, the only way we get there and solve the skill shortage is to say, hey, we got to build some new people that are coming from some of these different, more diverse backgrounds. It's a great place to start. When I think about the example you shared of your friend with the psychology, criminal justice psychology background, that is like— **17:09 Vandana Verma:** Mm-hmm. **17:09 Chris Romeo:** Think of that person then doing incident response and going through the process, bringing kind of a different approach to thinking about the motivations of the people behind the attack. And that could lead to some interesting things in the investigation when you're actually profiling the people who are doing the attack versus just looking at the bits and bytes and trying to figure out what attack tool they used. **17:32 Vandana Verma:** Totally. I agree with you. **17:34 Chris Romeo:** What advice would you give someone who is a hiring manager on how they can best approach diversity? Let's give them some real concrete things that people could actually put into use. if they're in the process of hiring now or in the next couple of months? **17:50 Vandana Verma:** If I say as a hiring manager, we should actively seek out people, be it during the meetups, be it during the conferences. A lot of amazing people are hesitant to accept their capabilities that they can do it. But when you start talking to them, they'll be like, I can do this, I can do that. So we should look out for people who have different educational backgrounds and skilled enough to part of the organization. I've seen that in the past few years, organizations have started hiring the army veterans or the armed forces veterans. They have a different viewpoint. So for this, we don't need to lower our criteria for interview. We can grill the same way. We can grill people the same way. Like someone might write 6 months experience and say, I am excellent. And the other person might say that I have 2 years of experience, but I'm average. But we can grill and understand what their capabilities are. So extroverts would have higher chances of getting jobs, but sometimes when we connect with people or certain gatherings, introverts might be equally skilled enough but unable to express themselves. The point would be connect with people, tell the HR that these are the skill sets I need. If you can find me even 50% match, I can talk to people because we've seen in the research diverse groups, they don't apply for a job till the time it's like 90% or even 100% match. So company leaders or people who have the authority to hire might feel like hiring a diverse workforce is impossible. But every hiring manager or the person who has the authority can make an effort to hire and retain the diverse workforce, which is possible for the company. Okay. **19:39 Chris Romeo:** So if I kind of summarize this back here, what you're describing is Actively seeking out lots of different types of people and looking at meetups and different educational backgrounds and really engaging them. We're not going to lower the bar of interviewing. We're going to do the same thing that we would do with any candidate. It's just we have to be more deliberate to connect with people who, for example, might be introverts and might not be as high on themselves as far as getting out and telling you, hey, these are all the cool things I've done. You might have to draw some of that out. And then also looking at kind of the job requirements to say, hey, we got to try to get, you know, ensure that the job descriptions and things are set up in such a way that folks aren't going to run away from them because they don't feel like, hey, I don't, I just don't, I don't know enough of this that they're asking for. **20:32 Vandana Verma:** Yeah. So to give you an example, a few years back, if I say like 5, 6 years back, we had an assumption of a hacker to be, or a security person to be like, they will be wearing a hoodie. They will not be— they'll just be working on the computer and not be chatting with anyone. But that's not the case. We talk a lot. The people who are working on security, it's like they share knowledge. That's the most amazing community and the most amazing peeps I've found from this community. **21:01 Robert Hurlbut:** I was gonna say, so try to understand what's current, you know, what is the key things that we're looking for, and that'll help you hone in on the key skills that you're looking for and, and get rid of some of these preconceived ideas, it sounds like, as well. **21:18 Chris Romeo:** Yeah, right. But Donna, on your point about the kind of perception of the hoodied introvert who's in the basement, you know, not, not, not really representing, you know, who, who we are as a community, I had a chance to work on a video series last year to create Um, you know, kind of a security awareness style video that was more live action. **21:45 Robert Hurlbut:** Mm-hmm. **21:46 Chris Romeo:** And so we, uh, we had an attacker kind of a character who was going through and wreaking havoc in a number of different situations, but we cast that as a middle-aged woman because everybody does always focus in on, hey, it's someone in— it's, it's a man in a hoodie that would be the stereotypical person there, when we all know that If you think about who's got the ability to launch attacks against companies, there's people from all different backgrounds and all different genders that have that kind of perspective. And so, that's something that we did just to get people to think about it because it's not just a teenager or a college-aged male in a black hoodie in a basement. It could be anybody. So, let's change gears again and talk about the web app training. that you created. And so you developed this, this free web app training. And so can you tell us the story of kind of how this came to be and, and what it's turned into? **22:46 Vandana Verma:** Sure. A few years back, I started going to colleges, and even when we were part of certain conferences, we wanted to have a free training wherein we can train the counterpart and/or diverse group and help people gaining more knowledge. Let's say give them the first stop, open the first gate for them. and then let them grow through it. That's how this training came into picture. We trained across a few colleges and at a few conferences in India. The first training we did at NullCon in 2016-17, and then at Black Hat Europe, I asked the board members if we can do the similar training at AppSec USA, and everybody said, yes, we can go ahead. It was a lot of discussion around whether we can do it for free or not, but in the end, It was a free training. In that, what all things we have covered is the OWASP Top 10, how we can set up a VM. That's like the basics. Wherein if somebody who doesn't know also that how to get started with a VM, we've, we've mentioned that, how to set up Burp Proxy, how to set up OWASP Zap, and that's again another proxy, how to test all those Top 10 vulnerabilities with different applications because it's It's not just going to be one application, but multiple applications. And we give customized VM to them so that they can play around with it. They can go back home. If they have any questions, they can come back and ask us. We are over the Slack. And also my DM is always open. I share my email addresses. They can write to me and I respond back. So the training is like started off with sharing and spreading knowledge, but that has matured over the years, and soon we will open it for everyone so that anyone can go ahead and give the training. If they need any support, we'll always be around. I'll always be around. **24:41 Chris Romeo:** The last thing I wanted to hear just a little bit about is something called InfoSec Girls. And so can you tell us what that is and kind of where that program is right now? **24:53 Vandana Verma:** Mm-hmm, sure. So InfoSec Girls is very close to me, which is we started in India wherein we try We started off with the purpose wherein we want to share knowledge. We want more women to be part of the meetup groups, conferences, connect with each other. But as we grew, we've started training at colleges, in schools, and at conferences for free across the globe. And apart from that, we help other women or students to train and speak at different conferences. So recently someone, one of the InfoSec Girls spoke at PSIDE Singapore. Which was like a very, very warming opportunity for us. It was a good one. And we're just not in India now. We have a chapter in New York. We're soon coming up a chapter in LA. We are— we just launched a chapter in London. And in India, we, uh, we've covered a lot of places— Bangalore, Pune, Delhi. So it's growing up. So it's like a lot of things. We've covered students and school students, college students, women who are working professionals, or not just women but diverse group. Any training that we have given So, it's a mixed group because it's an open registration. So, a lot of men also have registered and other people have registered, and we have never said no to them. The doors are open. The knowledge is there for sharing. So, that's the prime motive behind InfoSec Girls and the other things that we do as part of even Women in AppSec or WoSec. **26:28 Chris Romeo:** I've heard that you're actually going to be doing a deeper talk about InfoSec Girls and kind of some of the history at Black Hat this coming summer. Yes. **26:38 Vandana Verma:** Thank you so much for mentioning that. So, I'll be covering how InfoSec Girls evolved and where we are right now. What are the challenges that we faced? What are the things that did not work? What are the things that worked? How people helped us? We asked for help. And the trainings that we have done in the past, all of it, would be there at that stage. So we'll have a good 50 minutes to talk about the history, past, and the future that we have thought for InfoSec Girls. **27:14 Chris Romeo:** And so folks, if you're at Black Hat this coming summer in 2020, this is definitely a talk you're gonna wanna check out and get that perspective on what Vandana's been able to do, as well as a number of other people. I think that are likely kind of helping behind the scenes. Vandana, if you wanted to just kind of leave our audience with one thing here, kind of a conclusion or a key takeaway, what would that be? **27:37 Vandana Verma:** Support each other. Ask for help if you need it. The community is there to support you. **27:42 Chris Romeo:** Thank you for taking the time to be with us today and updating us on all these different things. And we will definitely see you at a conference here soon. **27:49 Vandana Verma:** Yeah, thank you. Thanks for inviting me. It was a great discussion. **27:57 Chris Romeo:** Thanks for listening to the Application Security Podcast. You'll find the show on Twitter @AppSecPodcast or on the web at www.securityjourney.com/application-security-podcast. You can also find Chris on Twitter @edgeroute and Robert @RobertHurlbut. Remember, security is a journey, not a destination. --- Source: https://appsecpodcast.com/vandana-verma-support-each-other/