Transcription
How about use this as a mic? Yeah, yeah, yeah, use yours. It's a hook, visual hook. Be like, "Why? Why are they holding those when we literally see their mics?"
So, hi Josh, thank you so much for coming on.
Thanks for having me.
All right, guys, so I have Josh Mador here for today's interview, and we'll be asking him a few questions about his cyber security career.
So, first question: could you tell us a little bit more about how—no, could you tell us a bit more—no, could you tell us a bit about how you got into security and what you've done in your career?
Yeah, so originally I worked in IT. I worked in help desk first. I was going to community college, and I just saw people, the help desk people, helping other people.
And by the way, we cut like all of this out 'cause I'm going to yap like too much.
It's fine, it's fine. Got it.
So, I saw other people working in help desk, and I just applied, and I eventually got hired to work in IT. I worked in IT for like a few years.
Eventually, I moved to Hawaii, and I was working at a bank. Then I just saw an opening for a cyber security position, and I was already practicing different cyber security labs at that point. I had gotten my Security Plus, and I applied to it. They interviewed me, and I talked about the labs that I was practicing, and I just ended up getting hired.
So that's kind of my first cyber security job.
And then for that job, I had to set up a SOC, or like a Security Operations Center. The bank was setting up a SOC, so I kind of got in charge of that.
I had to set up the SIM, which is Security Information Event Management system, as well as their Data Loss Prevention system, that is DLP.
So if somebody sends a lot of information outside of the bank, like a bunch of social security numbers, we would flag it and investigate it, as well as like the web traffic and filtering system that would prevent people from going to malicious sites or, you know, adult sites, that type of thing.
So that's what I did for that job.
So, all hand comment, I'm going to delete this, but when I worked at—I was like going to join the forensics team, and they told me that if I would stream or go on some kind of—I'd have to report them to the police.
Just like a different person every couple—it happens way more often than you think.
That's crazy!
On their work machine, bro, they have to be dumb to be—
Yeah, do they not know? Maybe it's 'cause they don't want it on their personal computer, and they somehow think, "Better use my work laptop."
So, what do you think made the biggest difference getting into cyber security? Was it your certs? Was it your past experience?
Um, it's probably a combination of all of those things.
Um, definitely, like you can't just get a cert and then get a job, right?
Um, and experience helps too, so it's definitely a combination. But I think the—well, it's hard to say. I think those credentials and stuff will get you the interview, but once you're actually in the interview, it helps to have done some kind of project or something that you can talk about, that you can tell them to kind of convey passion or convey that you care about the job rather than just like doing certs.
So it is for sure like a combination of a bunch of different things.
What was the worst job you had in cyber security?
Uh, the worst job I had in cyber security, I was working for a local government in Seattle.
And basically, like local government, they get their budget, like basically they're guaranteed to keep functioning even if they don't work properly, if that makes sense.
Oh yeah, yeah, yeah.
Like they're not incentivized to be efficient.
So because of that, all the employees like don't really want to work properly.
And in cyber security, you have to do—well, depending on where you work, you have to do a lot of behavior modification, like getting people to do certain things, getting them to not do certain things, getting people to like help you when you're trying to do like vulnerability management or something.
And that job was really stressful because people like didn't want to work, and it just made my job really hard.
Like I would put forth a lot of effort, and then no results would happen because like they didn't have to work, they didn't have to collaborate.
They won't get right 'cause it's the local government, and you'll see this sentiment a lot in tech in local government.
So I didn't like that job just because of that.
But damn, yeah, I feel like I see that a lot in cyber security where like your job is not just your job, but it's also like making sure other people are doing what they're supposed to do, which adds like extra stress because you're not really a manager per se, but you kind of have to manage certain people's behavior.
Yes, like I was a program manager, and you have to like control people through rapport and like—
Yeah, yeah, it's being nice.
People politics, what is it?
Yeah, like corporate politics, basically.
Do you think that cyber security is still a good career to go into nowadays?
Uh, it's definitely a good career.
Um, like anything in tech and I guess the rest of the world, it's going to like keep evolving and changing over time.
Um, that's just the nature of it because the, you know, the bad guys will figure out something new, and then we have to like patch it, and then we can like automate that part, and then they'll figure out something new, and then we have to manually like patch it, and then we can automate it.
And then it's just like an ever cycle forever.
Um, like AI will come out, and well, it did come out, and it's going to advance, and then attacks are going to be born from that, and then we're going to develop defenses for that, and it's just going to keep going forever.
So you obviously, you can't go into it expecting it to stay the same.
You kind of have to like navigate the landscape and brush up your skills, but it's for sure going to be useful, and it's going to be a good career.
Well, good career is like relative, but there'll certainly be jobs for in the future anyway.
Okay, so you don't think AI is going to take over all the cyber security jobs?
Um, it for sure will take over a lot of cyber security jobs, but like a lot of new jobs will be born, I guess, if that makes sense.
So if someone is in college right now or maybe they're going through a boot camp and they're trying to get into cyber security, what do you think they should do, like on top of what they're already doing?
Because the current curriculum, you know, most things aren't changing as fast as they should be, I don't think, especially like for beginner learning resources.
So what do you think can make them a better job candidate?
Definitely doing stuff, doing something that puts the curriculum in theory into practice.
Um, like building something cyber security related.
Um, 'cause if you don't work for a company, you can always kind of like quote unquote make your own experience.
Something like this, like buy our products?
No, like build some kind of platform or something on Azure, like build a—talk I see that you are recommending people sometimes to like build a home SOC or something.
That's better than not doing anything at all.
It's like quite good actually, and a lot of people, a lot of my audience has done that.
They'll like build a SOC and then build out like an incident response plan and do like some kind of a tabletop incident response scenario and then put it all out on like a portfolio on GitHub or something like this.
And then they'll practice that a few times, and the more you practice it, the easier it is to articulate once you get into an interview.
And it's just going to help you a lot more than like the person next to you who maybe they just grabbed and they didn't really do anything with their theory, if that makes sense.
Yeah, I agree 'cause I feel like I've done a lot of resume reviews where people are like applying to hundreds of jobs, and they're like, "But I'm not hearing anything back."
And I look at the resume, and it's usually like they have their Security Plus and then maybe like a random online course or cert, and they don't have any projects.
It's really just—I think that's the biggest issue because even if you have the cert, if you don't have the experience to showcase like your technical capabilities, then a recruiter isn't going to send you to the hiring manager because they're going to think you won't be able to pass the interview.
But I don't think a lot of people think from the recruiter's perspective as much as they should when they're in the job hunting process.
Yeah, yes, I agree. I agree with this for sure.
It's really important.
All right, so I guess the last question we could do: would you say working in cyber security, have you liked your jobs? Do you like what you currently do, and do you recommend it to other people?
Um, I like some of my jobs.
Um, the job that I like the most was not in local government, and it had a decent amount of coding involved.
But I think for the most part, I think I like my jobs.
Um, I prefer like what I'm doing now more than working corporate jobs.
That's that—it's doing like cyber security, like YouTube and creating cyber security products and stuff like this for people to practice.
I find that more fun 'cause I can like really control what I'm doing, and I just have like full control of everything, I guess.
I don't get roadblocked by random people.
But um, I would recommend cyber security.
Um, you just probably have to have more patience than you think 'cause it's a lot of dealing with people and interpersonal stuff.
It's probably, to be honest, it's more than half like soft skills, I think.
And like, um, dealing—I would actually agree with that.
Yeah, you need like some technical ability, but like too much paperwork and like a lot of rapport building and interpersonal communication, like probably more than you expect.
But, uh, it's a decent career 'cause you can make a decent amount of money, and you get a lot of practice doing different cool stuff and meeting cool people.
And like, I met Sandra eventually, right? Because I was doing cyber security.
So I would recommend it.
It's a good—nice!
Yes, thank you!
Yes, I agree. I do think that cyber security and tech in general just has like a good community behind it, even in like the creator space, I guess.
But could you tell us more about what you do now, like with YouTube?
And like, what does your day-to-day look like?
Yeah, so, oh God, I don't know the best way to like to answer this.
So basically, like I'm a YouTuber, obviously, if you didn't already know.
And like kind of the meta for YouTube—can I be like really candid about like the business component?
So like the meta for YouTube is you get an audience of people who like you, and then you like sell them a product.
Um, but there's like a kind of a slider that you can use for like how much ethics you want to have.
So if you have a lot of ethics, you want to make sure that the product you sell to your audience is like actually like really good product and not some like—
Right.
So for me, I try to make like really good products.
For me, I try to anyway.
So like my previous one that I made is like a—you go through and like build a SOC in like a honeynet essentially in Azure, and it gets attacked from like adversaries, like bots on the internet.
And then you like work to like apply controls and like secure your environment essentially and practice incident response.
And then I'm making a new product now, which is like a cyber range.
So everyone's going to use like the same shared environment, and there's like an enterprise tenable for vulnerability management and then, um, dependent for endpoint for EDR.
And we practice threat hunting and like all that stuff, and everyone has a shared environment.
So that's the next product.
So I pretty much work on that all day.
Like to talk about it in a really business standpoint, like all those like YouTube videos and stuff, that's basically like marketing, right?
It's a content marketing.
But again, the ethical slider—you can make brain dead content if you don't have any ethics, or you can try to make good content if you have ethics.
So I try to make good content, but it takes a lot of effort.
So I pretty much just work on like YouTube videos and then product and then community outreach.
And then YouTube video, product, community outreach, and I just keep doing that.
Community outreach is like responding to YouTube comments and stuff, so I just kind of do that in a cycle like forever, essentially.
But I'm really bad at social media compared to you.
I would—I agree.
No, I disagree.
I agree.
You should leave that in.
I agree.
Okay, that was a brain fart.
No, I disagree.
Wait, I disagreed with my part.
Which one is that?
No, you're so good at social media.
That's way—
No, no, I think, um, for YouTube, I still find myself where I don't know what I'm doing, and I'm just like, "Oh man, I thought that video would do well," but it did not do well.
Stuff like that.
Yeah, but, uh, yeah, I think social media is a skill that constantly needs to be trained.
Yeah, it takes a lot of energy, and I noticed like, um, watching you and like trying to do stuff on my own, like growing YouTube is not the same as growing Instagram, which is not the same as growing LinkedIn, which is not the same as TikTok.
And it's just like a lot of—a decent amount of effort, right, to like do each one of those.
Yeah, that's why I stopped doing TikTok, or I like tried to do it for a bit, and I was like, "All right, I hate this. All right, get me out of here."
So I only do Instagram, LinkedIn, and YouTube now.
But LinkedIn is so different, you're right.
All the tech creators that I've been—all the tech creators I've been meeting, like the younger ones.
So I guess that is the end of this interview.
Do you have anything else you want to share? Advice for the audience?
Um, just like if you want to get into cyber security, just if you do something, it's like better than doing nothing.
And this sounds weird to say, like the more you do, the more you're going to be able to do.
Um, so just like watch Sandra's content and my content.
There's a lot of roadmaps between the both of us and like a lot of other good creators as well.
And we pretty much, for the most part, we kind of say the same thing, you know, in terms of like roadmap and stuff to do to kind of get you that job.
And, uh, yeah, I'm going to yap too much, but yeah, just, um, like don't give up, and eventually you'll be able to get something.
And when you start applying to jobs, just apply to both IT and cyber security jobs, and just make sure everything is squared away.
And like eventually, like you'll get something.
But yeah, just follow us, and, uh, yeah, thanks for watching.
All right, thanks Josh for the interview.
You guys can find Josh's links and handles in the description box below.
Why did I say that?
Test, test, test.
Start talking.
Bing bong, and the audio.
Okay, honestly, I didn't double check, but I'm really going to hope that it is.
Wait, I can see it, right?
T.
Okay, wait, where should I look?
Which one should I—not even look?
Good question.
No, no, look here.
Yeah, all right, let me see.
What do you want to be asked?
Actually, what do I want to be asked?
Um, been asked—those are porcupines.
That's so cute!
Or is that a hedgehog?
I think it is a—it's really important.
What?
I think that was good.
Okay, the first one was good.
No, I think this is a great interview.
[Music]