{"id":501,"date":"2021-07-13T21:20:11","date_gmt":"2021-07-14T02:20:11","guid":{"rendered":"https:\/\/secognition.com\/?p=501"},"modified":"2023-08-20T08:56:42","modified_gmt":"2023-08-20T13:56:42","slug":"getting-into-security-the-hard-way","status":"publish","type":"post","link":"https:\/\/secognition.com\/?p=501","title":{"rendered":"My Security Journey"},"content":{"rendered":"<p>Hi I&#8217;m David and I love working with technology.<\/p>\n<p>Back in the olden days I was fascinated by a project where in elementary school where we would write letters to pen pals in a different city&#8217;s school.\u00a0 What was special about this project was that the letters were written on a computer and then all the different letters from students were mail merged together and sent through a modem at (300 baud!) to a bulletin board service (BBS) where schools would connect and retrieve their letters.<\/p>\n<p>I was captivated by the process to get these letters from point a to point b.\u00a0 Putting all my classmate&#8217;s letters together.\u00a0 Retrieving the Hayes modem out of the computer closet. Plugging it into the port on an Apple 2E and into an actual phone line.\u00a0 Making sure the terminal software connected to the right place.\u00a0 Inputting a phone number and gobbledygook strings to make the connection happen.\u00a0 Hearing the high pitched whines and static from the modem speaker, negotiating the connection. Seeing the system menu of the remote computer system and putting our written words into the ether for others to retrieve.\u00a0 Just the fact that I remember this 30+ years later shows how impressed I was by this.\u00a0 The computer lab at my school became my early morning and after school hangout.\u00a0 I wasn&#8217;t the most popular kid in school by a long shot.<\/p>\n<p>At the same time, envisioning making a career in computers was neigh impossible.\u00a0 I was great at remembering facts and figures for history, geography and economics classes.\u00a0 I was a student who couldn&#8217;t wrap his mind around mathematics.\u00a0 I went to summer school, got tutors but my math grades were just barely passing.\u00a0 That being said, I kept being told, how can you be so good with computers but so poor at math.\u00a0 Without math, I was advised there was no way to go into computer science and work with computers as my career.<\/p>\n<p>When it came time to go to college, I had barely passed a 10th grade advanced math class in addition to my regular senior math class.\u00a0 So I played to my strengths in the social sciences and with the guidance councillor&#8217;s help ended up in&#8230;. a political science program in college to hopefully go to law school.\u00a0 Funny how at 16 years old you&#8217;re supposed to take decisions as to how the rest of your life will be shaped<\/p>\n<p>Suffice it to say, I had a mediocre college career and didn&#8217;t see much of a future.\u00a0 I bounced around in different jobs until a friend of mine helped me get a gig doing internet tech support at an Internet Service Provider (ISP) just after Y2K.\u00a0 It was glorious, staying inside in air conditioning, working on computers, helping people out with their problems to get connected to the internet.\u00a0 It was heaven compared to what I was doing before.\u00a0 I made some really good contacts there a lot of whom I still reach out to today.<\/p>\n<p>Now you might be asking yourself, that&#8217;s all well and good &#8211; But what does that have to do with Security &#8211; I&#8217;m getting to that.\u00a0 A little less than a year into tech support, I was promoted to a network operations job.\u00a0 I moved to Toronto and set up a new life in a new city.\u00a0 I&#8217;d be one of the people responsible for making sure the ISP network ran correctly from a data and voice perspective.\u00a0 Glamorous &#8211; I know.\u00a0 Since I was the low person on the rotation I got the worst jobs.\u00a0 Calling people to follow up on tickets.\u00a0 Entering new phone numbers and calling cards into the voice switch (DMS-500 FTW), testing long distance terminations to places like China and Russia at silly hours of the morning and evening to see if they worked.\u00a0 I soaked it all in and I loved it!\u00a0 I learned so much of the basics of networking in this job, not just TCP\/IP but voice switching as well.\u00a0 Imagine my shock when someone opened up the menu to change long distance terminations to a better provider than our usual cut rate providers or troubleshooting voice T1 circuits, putting an actual physical loopback plug on a patch panel and seeing all the channels respond back.\u00a0 It was long but I learned so much about how networks interconnected from a voice and data perspective.<\/p>\n<p>Eventually I got to travel and install all this equipment in datacenters all across Canada and the US.\u00a0 I had just come back from the facility 60 Hudson in NYC in the late evening the day before 9\/11\/2001.\u00a0 I was watching the video footage on a day off I had, I thought it was a video game.\u00a0 I had woken up late, turned on the TV to see lower Manhattan covered in soot and dust.\u00a0 This experience stayed with me.<\/p>\n<p>I stayed in the NOC at this ISP for 2.5 years and moved on to another ISP in an engineering and planning role where their value proposition was installing fiber optic connections in office buildings and selling 10 and 100 Mbps symmetric ethernet connections to companies in the building for the same price as a ADSL or cable modem line, IN 2003!!!\u00a0 It was a wonderful time building out networks and getting folks on net.\u00a0 Again, I learned so much about core networking, peering to other companies and how to setup a router to create L2TP connections for ADSL clients.\u00a0 Unfortunately, a lack of experience on my part in the finer parts of business &#8211; really did the network always have to be up when we wanted to experiment, yes yes it did.\u00a0 Just remember kids, spanning tree is important no matter if the client says they don&#8217;t want to pay for &#8216;extra&#8217; packets they found on a network sniffing tool.\u00a0 Rebooting core switches during the day for code upgrades without warning because a fault was found, also a no-no.\u00a0 I had become something crazy, a functional alcoholic at night and waking up early to go back to work crazy hours to do it again the next night.\u00a0 I got laid off after making many stupid decisions and returned home humbled and burnt out.<\/p>\n<p>But from the ashes a phoenix rises again.\u00a0 This time some friends reached out for a networking expert to join their growing security firm.\u00a0 They had security knowledge but were signing large enterprise customers to do SOC work and consult on firewall and IDS\/IPS managed services.\u00a0 I knew the routing and switching part, I picked up the security part pretty quickly when on the first day I was asked to join a meeting with the Juniper Networks Sales Engineer to demonstrate their newest firewalls that we were going to start selling to our biggest customer within a few weeks.\u00a0 I have never learned as much about people and process than in this first security job.\u00a0 Lets understand in 2005 security wasn&#8217;t exactly the buzzword inducing craziness it is today.\u00a0 I picked up a lot through osmosis and seeing other wonderful security professionals do their jobs and work with folks to get to the crux of problems in security.\u00a0 I also got to travel all over the world and experience many new cultures.\u00a0 From Tianjin China to Toulouse, France to Phoenix, Arizona, Green Bay, Wisconsin and many stops in between &#8211; it was one of the best times of my life consulting on major security projects, meeting great people, learning how different companies get things done.\u00a0 This is still the way I do things today.\u00a0 If anything, to stay humble, ask questions, be respectful and collaborate fully with your peers.<\/p>\n<p>I&#8217;ve been in a few other places since then, I&#8217;ve picked up more than a few certifications and went back to school and completed a degree with a concentration in network operations and security and am working on a graduate degree in cybersecurity.\u00a0 I&#8217;m at management level now, so I don&#8217;t touch equipment as much as I used to but this is another discipline to learn and get better at.<\/p>\n<p>If anything I can recommend these would be the top 5 maxims:<\/p>\n<ol>\n<li><strong>Put in the work<\/strong>: The best way to learn is by doing something.\u00a0 Labbing, trying things, soak up the knowledge from your work colleagues.<\/li>\n<li><strong>It&#8217;s OK to fail<\/strong>:\u00a0\u00a0\u00a0\u00a0 Reflect on your mistakes, realize what went wrong and how you would do things differently.<\/li>\n<li><strong>Keep learning<\/strong>:\u00a0\u00a0 Use the resources at your disposal, books, computers, cloud, break things and fix them.\u00a0 Understand concepts deeply.\u00a0 Security changes so quickly from one day to the next you have to stay up to date or else you&#8217;ll be a relic.<\/li>\n<li><strong>Stay grounded<\/strong>:\u00a0 Don&#8217;t fly off the handle if you can avoid it.\u00a0 Complain about problems at the beginning of meetings but try to quickly move into &#8216;solution mode&#8217;.<\/li>\n<li><strong>Be positive and set an example for others<\/strong>: We all have off days, but if the positive days outnumber the negative ones then you&#8217;re still ahead.\u00a0 Take time for self care, take vacations, meet new people, sleep in once in a while.\u00a0 Nothing worse than being the guy who&#8217;s always &#8216;At Work&#8217; in all situations.<\/li>\n<\/ol>\n<p>That&#8217;s enough for now &#8211; If you made it this far, more power to you.\u00a0 If you have experiences to share, put them in the comments I would love to hear how people got into tech, cybersecurity and risk management.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hi I&#8217;m David and I love working with technology. Back in the olden days I was fascinated by a project where in elementary school where we would write letters to pen pals in a different city&#8217;s school.\u00a0 What was special about this project was that the letters were written on a computer and then all&hellip; <br \/> <a class=\"read-more\" href=\"https:\/\/secognition.com\/?p=501\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[5],"tags":[],"class_list":["post-501","post","type-post","status-publish","format-standard","hentry","category-security"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/secognition.com\/index.php?rest_route=\/wp\/v2\/posts\/501","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/secognition.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/secognition.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/secognition.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/secognition.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=501"}],"version-history":[{"count":0,"href":"https:\/\/secognition.com\/index.php?rest_route=\/wp\/v2\/posts\/501\/revisions"}],"wp:attachment":[{"href":"https:\/\/secognition.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=501"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/secognition.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=501"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/secognition.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=501"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}