Episodes
Published 12/07/23
Gisela Hinojosa is a Senior Security Consultant at Cobalt, executing IoT penetration tests and red teaming exercises with a wide variety of security teams. With over 13 years of experience in the tech world, Gisela has held roles in admin, software engineering, QA, consulting, and penetration testing. In this episode, she shares what vulnerabilities she discovers and how security teams can extract as much value as possible from each pentest engagement. For more on this topic, make sure to...
Published 04/21/23
Tejpal Garhwal is the director of DevSecOps and application security at Pega. With more than 26 years of experience in application development and product security, he has led multiple security and dev teams, and set the direction for information security, application architecture, policy, and processes within numerous organizations. In this episode, Caroline gets his perspective on how leaders can bring security and development teams together, aligned towards a shared goal: building...
Published 04/06/23
Carving an unconventional path towards information security, Yael advises many a CISO, CIO and CRO. Leadership roles at BlackRock and JPMorgan during periods of crisis and growth have given her a unique technical and business perspective — instead of saying “Here’s why that won’t work.”, she asks “But what if we tried this?” In this episode you’ll learn more about Yael’s story, why she started Yass Partners, and how security teams can approach new situations with equal parts established...
Published 03/23/23
Whether you're stepping into your first managerial role, or you're about to inherit a fully formed team, you might be facing self-doubt and uncertainty. Security veteran Tia Hopkins — Chief Cyber Resilience Officer and Field CTO at eSentire, adjunct professor, LinkedIn instructor — shares with Caroline how to overcome impostor syndrome as you progress, how to connect with your team, and how to set them up for success so well, others want to join.
Published 03/09/23
Return guest Robert Wood is the CISO for the Centers for Medicare and Medicaid Services. He leads enterprise cyber security, compliance, privacy, and counter intelligence functions at CMS and ensures the Agency complies with secure IT requirements while encouraging innovation. In this episode, Robert discusses with Caroline how big changes and organizational pivots can bring just as much opportunity as they do anxiety. He shares his perspective on how he guides his team through turbulent...
Published 02/23/23
Bipin Gajbhiye is a security practitioner, advisor, and investor. These three roles coalesce into a unique perspective on how cybersecurity professionals can achieve their goals — whether it's negotiating with the board, landing a critical investment, or advancing in their careers.
Published 02/09/23
Geoff Huston has been working on the Internet since the early 80’s and, in his own words, “did his bit” to set up the Internet in Australia, as well as to set up the early global Internet in the academic and research community. In this episode, he shares with Caroline the leaps and bounds hardware has made over the decades to bring us opportunities we could have never imagined...and how the human condition inadvertently makes it all complex and insecure. If you like this episode, make sure...
Published 01/27/23
Is the manager role the only path ahead in cybersecurity? Seif Hateb, Security Architect at Twilio, shares his view on the Individual Contributor vs Manager dilemma, and how people in the field can pursue the type of role that fits them best. And if you're just starting in the cybersecurity field, make sure to check out Seif's YouTube channel, full of expert advice on security fundamentals and how to kickstart your career -- with or without a technical degree:...
Published 01/12/23
As the CISO of North America at Checkmarx, Peter works towards providing the technology, expertise, and intelligence that enable developers and enterprises to secure the world’s applications. A lifelong developer at heart, Peter shares with Caroline his insights on what motivates Dev teams to prioritize security, and why so many current strategies are failing. You’ll learn more about how to not let your tools bury you in work, how to implement mutual accountability around security, and...
Published 12/22/22
What felt like science fiction 40 years ago is our reality today. What about the technology that will come in the next 40-50 years? What could change, and how can people band together to craft a bright and equitable future? Eugene Spafford — technologist and professor of Computer Sciences at Purdue University — talks with Caroline about how advances in technology like robotics and machine learning are already impacting people’s lives, in both good and bad ways. We have a responsibility to...
Published 12/15/22
Richard holds many titles, one of which is the President of the OWASP LA Chapter. Initially an architect, learning AutoCAD sparked his interest for all things technical. After a career change, Richard has held many high-profile roles in cybersecurity, bolstering numerous communities and initiatives. Don't forget to check out https://planetcybersec.com/ for a list of the conferences Richard and his team are next working on.
Published 12/08/22
Security Advisor at Office of the CISO and Co-Host of Google's Cloud Security Podcast, Dr. Anton Chuvakin, chats with Caroline about the past, present and future: how a hacked computer shifted his interest from physics to security, how threats from the 80s still plague orgaizations, and how cybersecurity will continue to spill out of the digital realm into the physical world. Some helpful links on things mentioned in the episode: Anton's security predictions back in 2010:...
Published 12/01/22
Don’t have a “typical security background?” Neither did Henning Christiansen, who is now the CISO at Ottobock. Before starting in InfoSec, he tried out roles in finance, development and auditing. Until one day, he began to nurture his interest in InfoSec, which led him to roles in Bombardier Transportation, Axel Springer, and now Ottobock. With decades of experience, this is what Henning would share with anyone trying to find their footing within the industry: “Try to make sure that you find...
Published 11/17/22
Security Relations Leader Vandana Verma is the Chair of the Board of Directors at OWASP. Starting with the dream of supporting her family, she pursues her curiosity around technology and builds renowned expertise in application security, infrastructure, and product security. In this episode, Caroline learns more about Vandana’s story, her diversity initiatives like Infosec Girls and Infosec Kids, and what security threats are on her mind.
Published 11/03/22
Zenobia Godschalk — SVP of Communications at Hedera Hashgraph, and Founder and CEO of ZAG Communications — shares how a passion for PR, tech, and privacy has shaped her career. From handling comms around cloud computing, to investor relations in InfoSec, and now spearheading awareness around distributed ledger technology, she shares helpful tips on how to build a flexible career in the world of tech, how to talk about security breaches, and what online identities could look like in the future.
Published 10/20/22
With over 15 years of technical and managerial experience, Marnie Wilking has led security programs across multiple verticals — retail at Wayfair, healthcare at Orion Health, and finance at Early Warning and Wells Fargo. Listen to her story to learn how the CISO role changes in each environment, and what stays the same.
Published 10/06/22
While hearing Nicole's story, Caroline learns more about the emerging Business Information Security Officer role. Nicole breaks down the unique value BISOs can bring to their organizations, and what others can learn from the role to earn a seat at the business table. If you enjoy this talk, you can catch both speakers live at our upcoming PtaaS Exchange roadshow locations. Learn more: https://event.cobalt.io/ptaas-exchange-roadshow
Published 09/01/22
Yael Nagler — founder of Yass Partners, advising CISOs, CIOs and Boards — surprised us when she said “Let me interview Caroline!” Taking this episode in a new direction, Yael asks Caroline about her story, her career, and her aspirations.
Published 07/19/22
Will Gant — accomplished developer, author, software architect and co-host of the podcast “The Complete Developer” — shares with Caroline a glimpse into the Dev world. They talk about motivations, challenges, and how security teams can work better with their dev counterparts. A small hint: let your nerd flag fly.
Published 06/28/22
Winner of "Best Security Podcast 2018" and "Best Security Podcast 2019," Smashing Security is a fun and informative show on tech SNAFUs. Co-host Graham Cluley shares more about his 30 years in cybersecurity, along with thoughts on malware, state-sponsored attacks, IoT, and how the cybersecurity scene today would have looked like science fiction when he started.
Published 06/09/22
Without good governance, every other part of security becomes much less effective. Caroline sits down with Deika Elmi — a security leader profiled by Risk & Compliance organization “Risky Women” in 2021 — to talk about GRC’s role in creating business value, and why Confidentiality shouldn't steal the spotlight away from Integrity and Availability.
Published 05/31/22
Caroline talks with tech executive Brian Carmenatty and Sanjay Deo, Founder & President at 24By7Security, Inc. They explore how teams can face prevalent threats by going back to basics with their technology and security policies.
Published 05/12/22
Swathi Joshi is an Information Security executive who focuses on risk management, crisis response, security services, and cloud security engineering. She is currently the VP of Cloud Security at Oracle where she leads a global team of engineers, analysts, and operators to secure Oracle SaaS applications and keep customer data safe. Prior to Oracle, Swathi led Netflix's Detection and Response team to manage inevitable security incidents and minimize risk to Netflix.
Published 04/08/22