The Security Repo

The Security Repo

By Mackenzie Jackson & Dwayne McDanielTechnology
Download on the App Store

The Security Repo episodes

  • Securing Flight Simulators And Other Operational Technology - Coburn Slay

    In this episode of the Security Repo Podcast, we delve into the intricate world of flight simulators and their unique cybersecurity challenges with guest Coburn Slay. He shares insights into managing both legacy and modern systems, the importance of compliance in operational technology, and his journey into tech starting at a young age. We also explore broader themes like the need for simplicity in cybersecurity tooling and combating misconceptions about age in the industry.


    Coburn Slay is a passionate and driven young cybersecurity professional based in Tulsa, Oklahoma. His love for technology began at a young age, fueled by knowledgeable mentors and a natural curiosity to understand how things work. This drive has led Coburn to explore unique fields within cybersecurity, where he’s been able to gain hands-on experience and contribute to innovative research in the ever-evolving tech landscape.


    / coburn-slay-aa759a164


    https://openssf.org/


    https://openssf.org/projects/zarf/

    46 min
  • Getting Out Of Walled Gardens By Running Your Own Email - Michael Harrison

    In this week's episode of The Security Repo Podcast, we are joined by Michael Harrison, a tech veteran who discusses the benefits and challenges of running your own email server in a world dominated by major providers, along with insights into the surprising persistence of fax technology in industries like healthcare. Michael also reflects on his pivotal role in bringing internet access to Chattanooga in the 1990s and shares practical advice on navigating walled gardens and enhancing system security.

    Michael describes himself as "A geek tweaking that status quo." He is the co-founder of Ring-U.
    https://www.linkedin.com/in/mike-harrison-1985b21/

    37 min
  • Understanding Psychological Safety And Asking Questions To Stay Relevant - Deanna Stanley

    Got psychological safety?

    In this episode of the Security Repo Podcast we sit down with Deanna Stanley to learn about psychological safety and the framework she has coauthored on building the layers of trust within organizations. We also dig into a few interesting stories from her time at MITRE and end up with some very encouraging words on how to stay relevant in a constantly shifting field.
    Deanna started her career as an embedded programmer in the telecommunications industry, and was a significant contributor to Northern California having no internet for 2 days back in the late 90s. She now helps sponsor transition to Agile and DevOps and spends her days screaming “it’s the people, not the tools!” Deanna’s love of her life is her dog Grimbal, which is why she’s always covered in fur.
    Learn more about psychological safety and the framework Deanna has helped establish at https://gotps.org/
    https://www.linkedin.com/in/djstanley/

    38 min
  • Phone Phreaking, The History Of The Security Community, And Social Engineering - Matt Scheurer

    In this episode of the Security Repo podcast, we are joined by the legendary DFIR Matt to get a history of phone phreaking and how that community of hackers inspired an entire community, including DEF CON. We also talk about how social engineering attackers are carried out, including QR code phishing, aka "quishing." Matt gives some rok solid advice as well on how to approach a successful security career.

    About our guest:

    Matt Scheurer is a show host for the ThreatReel Podcast and Vice President of Computer Security and Incident Response in a large enterprise environment. He has many years of hands-on technical experience. Matt is an official "Hacking is NOT a Crime" Advocate, serves on the Advisory Board for the Warren County Career Center "Information Technology and Cybersecurity" program, and also volunteers as a technical mentor for the Women's Security Alliance (WomSA). He has presented numerous Information Security topics at countless technology meetup groups and prominent Information Security conferences, including keynotes at the Cybersecurity Collaboration Forum Cincinnati Leadership Exchange, the Information Security Summit in Cleveland, Queen City Con in Cincinnati, where he just got a black badge and a lifetime keynote spot. Matt is also a 2019 comSpark "Rising Tech Stars Award" winner and was named a "Top 12 Hacking Influencer" by Bishop Fox in 2023.


    Matt can be found online at:https://www.linkedin.com/in/mattscheurer/ and https://x.com/c3rkah


    42 min
  • Getting Started In Offensive Security: A Journey Into Tech - Alexis Diediker

    In this week's episode of the Security Repo Podcast, we ask a pentester who is one year into her cybersecurity career how she got started. Along the way, we learn about her favorite security tools, what it was like making the leap into security, and how to get started with your own journey, no matter what path you want to take.

    We are joined by Alexis Diediker, who brings a fresh perspective to her OCO Consultant role, where she uses the social engineering skills acquired from her non-tech service industry background to deliver practical insights and technical expertise in network penetration and advanced social engineering assessments. Known for her unique approach, Alexis holds certifications including Security+, PenTest+, PNPT, CRTO, and is a recipient of the Women of Cyber Academy scholarship from The SANS Institute (Certifying her in GFACT, GSEC, and GCIH).
    Alexis is currently obtaining her Bachelors and Masters degrees in Cybersecurity/IT at Western Governors University. In her free time she indulges in whiskey, riding motorcycles, and fantasy lore.
    https://eicc.edu/news/2024-student-story-alexis-diediker.aspx
    https://www.linkedin.com/in/adiediker1088/

    34 min
  • Securing Human Access Through Privileged Access Management and Just In Time Access - Aria Langer

    In this episode of the Security Repo Podcast, we take a look at the concepts around securing human identities in the enterprise. We talk about why passwords alone are not enough, why it is important to use multifactor authentication, and the dream 'golden path' of ephemeral just-in-time account creation and use. As always, we find out the best and worst advice our guest has ever heard.

    Aria Langer joins the program this week. She is a Senior Security Engineer for KraftHeinz, specializing in PKI & privileged access management. In her personal life, Aria will talk your ear off about long-distance running, sewing, music-gaming, and RPGs from the good ol’ days. And Uncle Scrooge from DuckTales comics and media.

    34 min
  • Undocumented Hacking - Applying Pentesting Skills To Navigating Bureaucracy - José Martinez

    In this week's episode of the Security Repo Podcast, we dive into an unusual topic for the program, navigating the US immigration system and the challenges that many security professionals working in the US face. Join us as we discuss how to apply lessons from the world of pentesting to succeeding in the face of bureaucracy.

    We are joined by José A. Martinez. José is the owner of too many Pokemon games which he still hasn’t played. Born in Mexico but raised in Chicago, José loves guitars, books, cameras, and trying out new food. José worked in retail before transitioning to information security as an apprentice in a consulting firm, where he currently focuses on web application pentesting as a senior delivery analyst.
    Links mentioned in this episode:
    https://www.linkedin.com/in/jose-martinez-castro/

    28 min
  • STIR/SHAKEN and Password Policies- Per Thorsheim

    In this week's episode of the Security Repo Podcast, we turn our attention to STIR/SHAKEN, a requirement for US cell phone carriers that has been implemented to stop SPAM robocalls. We also look at password policies and research into how to make better passwords.


    We are joined by Per Thorsheim. Per is the founder and main organizer of PasswordsCon, the first conference dedicated to passwords, pins and anything related to digital authentication. He has been working in infosec for 30 years, and claims to know your next password. His bio on Linkedin has more information if you’re interested.


    Links mentioned in this episode:

    https://www.linkedin.com/in/thorsheim/


    https://mastodon.social/@thorsheim


    https://www.fcc.gov/call-authentication

    35 min
  • Being a Lifeguard Instead of a Police Officer and Compliance Is NOT Security - David Hawthorne

    In this episode of The Security Repo Podcast, we look at how we satisfy the goals of compliance and security, which might seem like they would be the same thing, yet are not. We are joined by David Hawthorne. David is a technology factotum with 20 years of experience across system administration, data and software architecture, and DevOps. As the Director of Cloud Engineering at O3 Solutions, David successfully led SOC 2 and GRC initiatives. He is dedicated to delivering business value through automation and analytics and actively contributes to the DevSecOps and data communities as a speaker and mentor.We will discuss the role of the compliance audit and what frameworks like SOC2 were supposed to solve. We dive into the approach of supporting and empowering teams as a lifeguard as opposed to being a police officer yelling "no" all the time. By the end, David shares some practical advice for growing your team and staying safe as you scale.Links mentioned in this episode:http://davidhawthorne.comhttps://github.com/shellninja

    32 min
  • From The Theory Of Constraints to Scorecard Patterns for Better Compliance - Justin Reock

    In this episode of The Security Repo Podcast, we broach a wide variety of topics, ranging from The Theory of Constraints, source control horror stories, and using scorecards to drive cross-team success.

    We are joined by Justin Reock, the Head of Developer Relations for Cortex.io.
    He is an outspoken speaker, writer, and software practice evangelist. He has over 20 years of experience working in various software roles and has delivered enterprise solutions, technical leadership, and community education on a range of topics. 
    We start by talking about how the work of Ed Deming translates into modern software workflow and what that means for security. Branching from there, we dip into how developer and build tooling can and should include security. The one thing all developers have in common is source control, and Justin's background lets him share a few stories that are not to be missed.
    We end with a new twist on Best Advice/Worst Advice that gives us deeper insight into our guest.
    Thanks for tuning into this episode.
    Links mentioned in this episode:
    https://www.linkedin.com/in/justinreock/
    OpenRewrite and Modern https://www.moderne.ai/blog/overview-...
    Pre-frontal cortex podcast - https://podcasts.apple.com/us/podcast...
    IDPcon.com - https://idpcon.com/

    45 min

About The Security Repo

From the publisher's feed

The security repo is a podcast that focuses on real world security issues we are all facing today. We will take deep dives into news events and have exclusive interviews with security leaders on the…