Security Confidential S1 E6 Mitch Spaulding

This week on Dark Rhiino Security’s Security Confidential podcast, Manoj Tandon is joined by Tyler Smith and Mitch Spaulding for a conversation about career paths, cybersecurity education, and the future of the industry. Mitch shares how an early interest in technology and gaming led him into hands-on cybersecurity work, while Tyler reflects on his transition from military service into security leadership. Together, they discuss DLP, remote work, IAM, zero trust, cybersecurity layoffs, and practical advice for young people looking to build a career in cyber.

00:00 Mitch Spaulding’s Early Path Into Cybersecurity

03:35 DLP, Monitoring, and Real-World Security Lessons

07:36 Tyler Smith’s Transition From the Military to Cybersecurity

11:21 Cybersecurity Layoffs and Why Security Is Mission-Critical

14:51 Why IAM and Zero Trust Matter for Remote Work

22:26 Advice for Young People Entering Cybersecurity

Connect with Mitch Spaulding on LinkedIn

Connect with Tyler Smith on LinkedIn

Connect with Manoj Tandon on LinkedIn

Transcript

Manoj Tandon: Hello everyone. This is Manoj Tanden with Dark Rhino Security. Welcome to our podcast, Security Confidential. Today we are honored to have Tyler Smith joining us, as well as Mitch Spaulding, who unfortunately is moving on to greener pastures, but we’re honored to have him for this one last show as a DRS employee, as a Dark Rhino team member. You know, Mitch is a special person. In that how he came up through cybersecurity, and really when you look at the atmosphere with COVID-19, his story will resonate because it’s about how one can educate themselves and really come up through a career in cyber. And you know what, same is true for Tyler. Tyler served in Afghanistan as a frontline infantryman and made a transition to owning a cybersecurity company. So I think in these times it would be inspirational maybe for some of the folks to listen to a little bit about what these gentlemen have to say, and we’ll learn a little bit here. Mitch, I think it would be great to start off with you and give us a little bit of an insight, you know, how you went from being a lacrosse player in high school to being a Uber cybersecurity master.

Mitch Spaulding: Just starting off, I was always really big into technology and video games growing up. So I think that kind of just got my initial interest in, I wouldn’t say cybersecurity, but just the tech field overall. It wasn’t until later on until I got to high school and I saw, you know, it came around, you know, the summertime once school’s out and everything and I had to find a job. So when I was looking for jobs, I wasn’t necessarily looking for something to make minimum wage. I was more looking for something to better myself and then, almost like learning a skill, kind of like an apprenticeship. I wanted to better myself in that regard so that way I was always learning. So then that way, if I went to college or something, I’d always have something to fall back on or continue after I had done something like an internship. So I was looking for certain jobs and I saw this just this general security help desk role kind of come through with OhioHealth. I was a freshman or sophomore in high school, and I took the opportunity. They didn’t really require any true background in cybersecurity. They were just more looking for a young kid who had the eagerness to learn. So luckily they chose me and then that kind of started my journey down cybersecurity. While I was on that internship I learned a lot about IBM’s QRadar system. I learned basically how a SIEM operates and what are the inner workings of something like a SIEM. Granted, I mean, it was IBM QRadar. I don’t know where their product stands on the market currently, but I’m sure there’s other different SIEM platforms on the market regardless. But it was really cool. I got to learn a ton about what SIEMs do. Further from that, I also got some hands-on DLP experiences, Symantec DLP. I thought that was really cool. One thing that was kind of interesting about it was I had a lot of friends whose parents coincidentally worked at OhioHealth and I would see my parents’ friends pop up, their email addresses pop up on the DLP system and I think that’s what kind of made it real for me. I was like, “Okay, these are real people.” This is actually happening. It’s not just like statistics or data in a spreadsheet. This is real.

Manoj Tandon: Were there any interesting things that they were doing that they were showing up on the DLP system? I’m just curious.

Mitch Spaulding: Oh, A ton. I just don’t think I can say it.

Manoj Tandon: Okay.

Mitch Spaulding: It wasn’t like my friend’s parents weren’t doing anything crazy or anything. But yeah, there was some really nasty stuff that would kind of pop up here and there from other employees. I’m sure Tyler probably knows a little bit of what I’m talking about.

Tyler Smith: Yeah.

Mitch Spaulding: Yeah, the DLP system can be a real human cesspool.

Manoj Tandon: Oh, I can imagine. Straight up.

Tyler Smith: I had, way back in 1999 or 2000, I was working with a major tire manufacturer and they had installed these little internet kiosks throughout their headquarters in all their offices and anybody could go onto those kiosks and go search. Well, as it turned out, you guys—I’ll spare you the salacious details, but there were a lot of sites being visited that maybe should not have been visited during work hours. And I think probably back then we didn’t even have a DLP. And that probably started some of those kinds of things, started the world of data loss protection if you will.

Mitch Spaulding: Yeah, definitely. Things like that triggered companies to control their network.

Tyler Smith: Just because people would go look at anything and everything you can think of. If people can get on a computer and look at it, they will. And usually, if no one’s watching them or they think that they’re in private, they’ll look at some really weird stuff.

Manoj Tandon: How do people not think that people can’t see what they’re doing on something like a corporately managed device?

Tyler Smith: Yeah. I mean most of that’s just failure of communication to employees on the part of, you know, “Here’s our policy, by the way; you agree not to do this stuff because you know that we can inspect what’s being done.” But a lot of companies have gotten a lot better about that over the last several years. It never ceases to amaze when you find yourself in a situation where somebody’s like, “Hey, you need to go get so-and-so’s laptop,” and then they get into the reasons behind it and you’re just like, “They did what?”

Mitch Spaulding: Yeah.

Tyler Smith: They did what?

Manoj Tandon: You know, it’s okay. I mean, those things over time, I’m sure people will get more and more educated and we might see less and less of it, but you would think that at checkpoints at airports people wouldn’t try and take guns through. I think about that. I mean, doesn’t it say in big block letters all over the place: no knives, guns, bottled water, all these things? And you’d think by now people would know. Maybe people will never know and that’s why there needs to be some oversight.

Tyler Smith: Well, yeah. I mean, we wouldn’t have those things if we didn’t need them. You know, all these things are born out of necessity. I remember the story, and there’s plenty of people I’m sure who deployed overseas that have similar stories, but I remember coming back and hearing about the guy in another company that dropped his gear down for inspection and everybody heard the sound of a hand grenade hit the asphalt.

Mitch Spaulding: It’s a very distinct noise. So when you hear that dull metallic thud, you know, everybody looks over and you kind of see that guy looking down at his stuff and…

Manoj Tandon: Oh, man, if I would have heard that noise, I would have probably outran Usain Bolt.

Tyler Smith: It would have been “clink, goodbye, later.”

Manoj Tandon: I mean, you came through military to cyber and Mitch started off in high school. What was your movement? How did that happen? How do you go from being a guy carrying a SAW to—

Mitch Spaulding: Owning a cybersecurity company?

Tyler Smith: The way that I got into security, it was definitely circuitous, if you will. I got out of the Marine Corps. I was expecting to make it a career. I got hurt and medically discharged at the end of my enlistment. And so I didn’t really know exactly what I was going to do. And I thought I’d get into physical security. And so that’s what I did for a while. I was a weapons instructor, firearms instructor. I went back to school and studied International Studies, Security, and Intelligence. And that for me was very interesting because you get to learn about how all of these different agencies, both nationally and internationally, interact to complete the overarching mission of gathering intelligence and security, providing security for everyone at large.

Tyler Smith: And the transition came—I found myself in a position where I couldn’t go any further in the physical security realm. It just wasn’t attractive. It wasn’t what I wanted to do. So I switched to a technology job. I started working at Apple, and someone I worked with there kind of gave me the nudge and said, “Hey, you’re not bad with this technology stuff. Maybe you should come over and give security a try.” And I was a little hesitant at first, but it really checks a lot of boxes on a personal level, and that is everything to do with being of service to others. In security, a lot of people overlook it. Especially in times like this, we see people talk about things like essential employees. Security is one of those essential professions. It just is. Whether it’s physical security or what we do, which is far less felt by the world at large. Your average person doesn’t have a clue that there’s dozens and dozens and dozens of professionals that are working to keep the things that they use every day safe, and functional, and accessible for everyone to use. I mean, and that is the traffic lights, the systems that work behind the scenes to make sure that the shipments get to the grocery stores, your credit card and banking information, literally all of these things, the phones that you use to call, these are all protected by security professionals. And it’s truly, in my opinion, I think it is the everlasting war, so to speak. It’s being fought every day. It has been fought every day since we as a society globally switched to these electronic formats and we depend so heavily on them. People have no idea that this battle is going on. I mean, you pick out any major corporation and they have to be the winner in thousands of attacks, thousands of little fights every single day, if not hundreds of thousands. And if they lose, they just have to lose once. And that puts people’s information in jeopardy.

Manoj Tandon: On that point of major corporations, Mitch, before we started the podcast, you made mention you’ve heard of a lot of layoffs recently. Are the layoffs you’re referring to—are they in the cybersecurity industry?

Mitch Spaulding: They are, and I think that’s what is the crazy thing about it. You would think cybersecurity would be one of the last…

Manoj Tandon: I’m sorry. Yeah, that’s exactly right. Right. I from what Tyler was saying and what you’re describing, I think that those worlds are kind of at odds with each other, right? Cybersecurity, you would think no one would—

Mitch Spaulding: Be getting rid of people.

Tyler Smith: Yeah. And I think a lot of it is because people really don’t understand how deadly serious it is. And I use that terminology very intentionally. When I say “deadly serious,” I mean these are the things… you may not understand advanced projectile physics or even a simple gravitational equation, but if you step off the top of a building, you better hope it’s not too terribly high because when you hit the ground you’re going to die. Your understanding of it is irrelevant.

Tyler Smith: And that’s what really kills me about this whole thing—you see people getting laid off in mass and it’s because for a lot of companies, they just look at security like it’s just another cost center, and then they don’t give it the gravity that it truly deserves.

Mitch Spaulding: Yeah. I think companies see it as a cost center until it actually happens to them, until they’re actually breached, and at that point they’re like, “Okay, this is actually important and I shouldn’t have made the mistake of seeing it as a cost center.” With all these companies, they’re not just exposing personal information. They’re putting their entire brand, their entire reputation at risk by not investing in cybersecurity and laying off these people. Their reputation is severely at risk for this.

Manoj Tandon: You know what, Mitch? You look at some industries have actually taken that seriousness to heart. Like the insurance sector, their governing bodies have adopted a policy that the risk, cyber risks, must be reported to the board of directors of the company. That in itself is a statement that it’s not just a cost center; it is something of material relevance to the resilience of the operation, if you will.

Mitch Spaulding: Yeah. Just me as a consumer, I’m not going to want to be an insurance customer of someone who’s gotten breached or someone who’s gotten breached and didn’t disclose it, and disclosed it two or three years after the fact. That doesn’t sit well with me.

Tyler Smith: Right, and it shouldn’t. A lot of companies kick this can down the road and mostly it’s because they really don’t understand it, and to them it’s this giant greased bull that they just can’t get a handle on and they don’t even try. In reality, there’s lots of methods you can use to discover what your true risk is, measure it, and then really lay it out and say, “Okay, well, we know that these are all here. These problems are all here. How are we going to deal with them?”

Manoj Tandon: Well, going back now to Mitch for a second: In this time when most companies are laying off, you’re looking at advancing your career and you’ve kind of chosen the IAM arena for that. What makes you focus on IAM versus someone in your position could have gone into firewalls, gone into threat hunting, or DLP? There’s a multitude of places you could have gone and there’s income parity across all of them, yet you thought of IAM. Is there a driver behind that thought looking to the future?

Mitch Spaulding: Yeah. I guess my reasoning for going down this IAM route is that IAM is kind of like the new forefront. If people haven’t seen it as the forefront or the keystone of any good cybersecurity practice, it definitely is now. We’re talking about with this whole COVID thing—remote access has skyrocketed 100% or even more than that probably since March this year. So, the reason why I kind of wanted to go down the IAM route was because I want to be on that forefront. I want to make sure that people are able to sign into their workplace applications and utilities in a secure fashion. And ultimately now, a lot of these different companies, not all of them had the infrastructure for secure login when a user’s outside of the office, which probably about 100% of their users are trying to log in now from outside the office. And unfortunately, they don’t have a system to allow that access in a secure way. You know, we talk about implementing VPNs with different firewall systems. But if a company doesn’t have that, what are they going to use? And I think that’s where IAM comes in with the zero-trust approach, which essentially means that no matter who you are or where you’re coming from, you’re going to be prompted for your traditional authentication, but then also a second factor to really make sure you are who you say you are. And I think that’s pretty powerful, especially in the time we’re in right now with the coronavirus going around. And we’re going to be in it for the foreseeable future. Even though the economies are beginning to open up across the planet, this thing has not gone away. And if past history is anything, we’re going to still have outbreaks regionally. I’m not an epidemiologist, so I can’t forecast anything like that, but logical sense would say we’re going to have probably some further work-from-home activities that are going to be necessitated. I’m also thinking that it’s not even going to be like a matter of coronavirus after all this. I think you’re going to see a lot more companies be a little bit more lenient in the work-from-home policy, because a lot of different companies have shown that they were able to work, and people in companies have shown that they’re able to work from home and still get work done. So I think coming into the office in general is going to be a lot more relaxed going forward. So there’s got to be some sort of system in place there to allow for secure access.

Manoj Tandon: Yeah, that’s an interesting point, Mitch. There’s going to be some permanent changes to the workforce and I couldn’t venture a guess as to what that’s going to be in terms of the number of people that are going to work from the office just partially or work completely from home, or some mixture of that. There’s going to be some professions where you can’t—if you’re working in a factory, you can’t work from home. It’s impossible, right? If you’re a medic, you can’t do that from home. But certainly in technology, I could see that. And I would ask Tyler to chime in here because, Tyler, I think your dad’s in the real estate business. Has he had any insights on what’s going to happen to commercial real estate on this? I know this is a complete left turn from security, but Mitch kind of took us there. So I’ll just complete the thought.

Tyler Smith: Yeah. Honestly, the conversations he and I have had recently have just revolved around frustration about not being able to get our hair cut. But that’s a good question. I can’t really offer any insight into that, but certainly I think when it comes to the remote work thing, before there wasn’t a lot of evidence; there was a lot of theory about it like, “How effective are people who work remotely?” and I think that this was something that proved out the model for everyone. For me, I feel like I work a lot longer when I’m here at home, just because no one’s walking up to me every five minutes, 976 minutes, or an hour and going, “Hey, man, can you look at this thing real fast?” And I think because of that, it lets me focus more on what I’m trying to accomplish. When I have a question, it’s usually a quick email to somebody and then they get around to it when they have a second to get back to me, which is usually timely, but I think it’s not the same as me walking up to somebody’s desk and going, “Hey, man, can you take a look at this real fast?” Because when you do that, you immediately need to answer the person, and you feel the immediacy of it. Whereas, if it’s an email, you see it and go, “Okay, I’m busy with this. I’ll answer that in just a second.” And it works into your flow better, I think. But that’s just me. I know…

Manoj Tandon: I think Tyler, all in all, here at Dark Rhino, even we’ve seen it. We were talking about moving our offices and quite frankly I even question the space we have now: Do we need it all?

Tyler Smith: There’s some, even in our company, there are some roles where you can’t be at home. If you’re working in the SOC—

Manoj Tandon: You’ve got to be in the SOC. That’s a job you can’t do remotely.

Tyler Smith: But barring some of those things, a lot of the folks were able to get most of their work done remotely. Even people who were on client sites were able to get it done. And even if, let’s say, we downsize our office space by 20%. If every small-medium business in America did that, it would be catastrophic to the commercial real estate market, right?

Manoj Tandon: Yeah. That’d be quite a dent.

Tyler Smith: Yeah, it would be a huge dent.

Manoj Tandon: But you’re right. I think you and Mitch are both right that work from home, remote access, and IAM is going to be—it’s a foundational technology in cybersecurity, right? I mean, you only have three things: prevention, detection, and response.

Tyler Smith: Right.

Mitch Spaulding: Yeah.

Manoj Tandon: And IAM is a strong component of prevention. If you get the identity right, then that makes it much less likely that a bad actor is going to imitate somebody that is a good actor.

Tyler Smith: Yep. Exactly.

Mitch Spaulding: 100%.

Manoj Tandon: Right. So Mitch, there might be a lot of younger kids listening to this simply because one of the folks that we’ve partnered or are trying to partner with is the Pittsburgh Public School system, and you just caught a tail end of that here in the last couple days. What are your thoughts on the young crowd? I mean, they probably look at you and say, “That guy’s old now,” right? Yeah, you’re the old man now, dude.

Mitch Spaulding: Yeah. No, seriously. I know you guys had me on this podcast only because I’m like the Zoomer correspondent.

Tyler Smith: He’s on to us, Manoj. He’s on us.

Manoj Tandon: Well, I am the old man on this podcast, so hey, things were very different in my era.

Mitch Spaulding: Yeah.

Manoj Tandon: The advice I would have given would have been very different. But those young folks who are looking for that future in cyber—What would be your guidance? And then I’d ask Tyler to chime in for that as well: What would be your guidance to those folks and a path forward? How should they how should they approach it?

Mitch Spaulding: I guess one perspective that I could recommend to younger people trying to get into cybersecurity is that there’s literally so many resources on the internet right now to get these jobs. Getting the basic understandings of the craft and then also getting some certifications. One of the ways that I got started in cybersecurity was I used this site called Cybrary. I think it’s called Cybrary.it, right? They have a huge catalog of all these different certification classes that you can take and it’s all self-paced. It’s not like you have to log in and meet with an instructor. You can do all this work on your own independently. Especially during this time when you’re being assigned one high school paper a week by your teacher since you can’t really do too much right now, take advantage of that and go onto something like Cybrary and start working on something like a Security+ course. That’s going to benefit you way more in the long run, especially when it comes to applying to colleges and maybe even getting a part-time job while you’re in college. If you have something like a Security+ and a basic understanding of cybersecurity as a whole, that’s going to go a long way. So definitely recommend taking those self-paced courses whenever you have a chance.

Manoj Tandon: And Tyler, your thoughts?

Tyler Smith: Yeah, I agree with what Mitch says. For him it’s much more tangible because he actually did the whole transition from high school straight into the security profession. But at the same time, Mitch, I kind of saw you come up as you were doing all this—I did see you come up as you were doing all this—but you can’t understate the amount of work that you’ve done. You did a lot of work. But I think the thing is, while it is quite a lot of work and it takes time, you have time if you’re a younger person.

Mitch Spaulding: Exactly. Yeah.

Tyler Smith: To invest in this, and that’s what it is: it’s an investment. And it doesn’t have to be work either. This stuff can be really cool if you’re attuned to it. The idea of building your own network at home, setting it up so that it’s secure and it’s a segmented network, and you’re capturing logs and running your own SIEM at home—these are all things that you can do using open-source tools and the guidance that’s available. I mean, YouTube is a tremendous resource. I used to have it in my mind, when someone would bring up YouTube, these thoughts of people watching stupid cat videos. Not that there’s such a thing as a stupid cat video for people listening, but they’re just valueless—

Manoj Tandon: Political correctness there, man.

Tyler Smith: Waste of time. That is kind of how it felt when someone would be like, “Yeah, I watched some stuff on YouTube.” That was the first thing that popped into my mind: “Oh, okay, so you screwed off for 4 hours and didn’t get any work done.” But that’s no longer the case. Pretty much anything you want to do in security or you need to do in security, especially with open-source tools, you can go onto something like YouTube or Vimeo and see someone actually go through the steps to set it up or explain it for you. Then couple that with something like Cybrary. You go in, you create an account, and start working your way through some of those courses, and they’ve got a ton of them. If it’s an IT course, especially security, they probably have a course that you can sign up for free. And then if you want to take the next step, you can pay to do the labs. They actually have labs that let you go in and actually set up whatever it is you’re learning about hands-on. Doing it like that, it’s a lot more fun because you’re going to actually be creating a thing. It’s not just some frowny-faced flesh drone just moaning on about some topic while you mindlessly listen and scribble stuff down on a piece of paper. But it’s going to actually be, “Okay, here’s this thing, this is how it’s used, and now go and do it.” You can do things like setting up your own firewall at home. All you need is a computer that has two network interface cards, or two NICs—not cards necessarily, but just two ports, or even one port that you set up to operate as both your in and out. You can use something like OPNsense or pfSense to download and install a firewall and then configure that firewall. It has features that are similar to those that you’d see on an enterprise-grade system that you’d have to spend thousands of dollars to buy. These are available to you for free. Set that up and run it, and you’re actually doing it, not just reading it.

Manoj Tandon: That makes a lot of sense. Hands-on practical application is the best way to learn. But then I would ask both of you a question. Tyler, you just mentioned the amount of work Mitch has done. And Mitch, you took it upon yourself, from becoming a gamer to developing that into a computer science-based career path. Why is it that we don’t see more American graduates really going into it? We have a tilted market in cybersecurity. Why do you think that is?

Mitch Spaulding: I can talk a little bit about why there’s a lack of talent pool maybe in the US from younger generations. I think a big part of that is because there’s a certain standard in everybody’s head coming up in the American school systems, and it’s that you have to be either a doctor or a lawyer. And if you don’t want to do something like that, then you have to become an accountant or go major in business or marketing. You have to go down this traditional path. And I think what makes me and Tyler both very unique is that although we’re what, 18-976 years apart, we literally went to the same high school, and I can tell you straight up—

Tyler Smith: Their values have not changed in the last 20 years. It’s still—

Mitch Spaulding: Focused on becoming a doctor or lawyer and a lot of memorization of stupid facts you’re just never going to use. It’s never applicable. It’s never like applied sciences or anything like STEM. So, I think there’s almost a stigma in the American school system where if you’re not coming out of high school and going into college as a business major, a premed major, or an accounting or finance major, people in your friend groups or your parents are going to be like, “What are you doing?”

Tyler Smith: And I even went—they had this thing that they put out to alumni from our high school and it was like, “Anybody want to come back and talk about professional development?” and I was like, “Sure, yeah, I’ll do that,” and they just never got back to me. So, I was really clear. I’m like, “Listen, this is a really great industry. It’s seen tremendous growth. It is a career that is equal to, if not greater than, becoming an attorney or a lawyer.” You walk out of school with a law degree, you’re not going to have an easy time getting a job unless you were in the top 10 in your class. And I know that because that was what I was looking at. I was going to go to law school. And the median income for somebody right out of law school, I think when I was doing it, was like $42,000 a year. This was in 2009ish. So, you can do a hell of a lot better than $42,000 a year in security. But yeah, I would never tell somebody not to get into security. I personally think it’s a great field to get into.

Manoj Tandon: I’ll tell you what, guys. In my own experience, education is a passion of mine. I do it on the side. Here I’m working with Slippery Rock University a little bit on their cyber program and trying to give some guidance to kids. What I see in general with STEM—and keep in mind that I have a biased view because I am an aerospace engineer and I spent oodles of time with math and physics and science and all that—I got into that stuff. That was my thing. I think in schools we often at the onset disadvantage the children by saying business and finance may not be that hard, but STEM is hard. “Oh, you’ve got to be really smart to do math. You’ve got to be really smart to do this.” And that’s really a bunch of hogwash. In terms of if you take two human beings, one’s a poet, the other is an engineer, you could argue they have different skill sets, but you couldn’t argue that either one is less capable than the other. It’s a real mental thing. So when you take children and you expose them to these concepts, which do require something that Mitch did where you had to apply yourself to get those initial certifications to go to cyber—that’s self-motivated learning. STEM does require that, and the way that happens is that there has to be a sense of wonder in oneself to want to take that path. If we kill that sense of wonder by planting ideations in people’s heads that these things are hard, or that you have to be a genius to do this, that, or the other, it just becomes a self-fulfilling prophecy. There’s this element of motivation, and Mitch found it through video games. I found it through a sense of wonder. I always thought it was cool to see a heavier-than-air flying machine take off. I still do. It never ceases to amaze me. But if we take that sense of wonder away in our public educational system by memorization and forcing of concepts and ideations that really have not that much of a long-term value, then we might put ourselves at a disadvantage.

Mitch Spaulding: Yeah, I couldn’t agree more.

Tyler Smith: Because that’s how it was presented to me. It was like, “Oh, this is all really hard, scary stuff in engineering.” And for me, like you said, it ignited a passion; that sense of wonder ignited a passion in me with technology. I always thought it was cool how you can set up a network and stop how people can break into it and how you can see it and stop it and help prevent it. That to me is really interesting. So much so that it drove me to learn more about it on my own time.

Manoj Tandon: As it did Mitch. Right.

Tyler Smith: Yeah. So with that, we’re approaching the top of the hour here. Mitch, I know it’s your last day, but I would like to thank you immensely publicly for all the great work you’ve done here. We’re really grateful for it and this is still home for you anytime you want it to be.

Mitch Spaulding: Seriously, thanks again. I wouldn’t have traded the last three years for anything. I’ve learned so much working at Dark Rhino Security and it’s honestly probably one of the better places to work. Nothing can compare to it.

Manoj Tandon: Deeply appreciate those very kind words. But I do want to ask you one thing, and I do want to ask Tyler one thing too. In parting, do you have a favorite quote you’d like to share with us?

Mitch Spaulding: “Always strive for success.” Always put yourself on top. That’s how I see it. Maybe from a movie, but it definitely has some real-life applications to it.

Manoj Tandon: And Tyler?

Tyler Smith: Yeah, I think it was Churchill who said, “Never, never, never give up.”

Manoj Tandon: Those are all fantastic quotes.

Tyler Smith: But yeah, Mitch, I also want to say, “Fair winds and following seas,” my man.

Manoj Tandon: Godspeed. And with that, everyone, we are signing off for this episode of Security Confidential.

Mitch Spaulding: Goodbye.

Tyler Smith: Thank you, everyone. Bye. Bye, guys.

Tyler Smith: Is, you know, that’s all really hard, scary stuff in engineering. And and uh for me, it’s like you said, it was always it it ignited a passion that that uh sense of wonder ignited a passion in me with technology. And you know, I just thought always thought it was cool how you can set up a network and stop how people can break into it and how you can see it and stop it and help prevent it. I mean that to me is really interesting. Um so much so that you know I it it drove me to learn more about it on my own time.

Manoj Tandon: As it did Mitch. Right.

Tyler Smith: Yeah. So, with that, we’re approaching the uh top of the hour here, and uh Mitch, I know it’s your last day, but I, you know, I would like to uh one, thank you immensely publicly for all the great work you’ve done here, and uh we’re really grateful for it and—

Manoj Tandon: Uh this is a this is still uh home for you anytime you want it to be.

Mitch Spaulding: Seriously, thanks again, man. I uh I wouldn’t have traded the last three years for for anything. I’ve learned so much working at Dark Grind of Security and it’s honestly probably one of the better places to work um anywhere else. It you know nothing can compare to it.

Manoj Tandon: Deeply appreciate that very kind words. But I do want to ask you one thing and I do want to ask Tyler one thing too. If in parting do you have a favorite quote you’d like to share with us?

Mitch Spaulding: Always strive for success, you know, always uh put yourself on top. That’s how I that’s that’s how I see it. you know, maybe from a movie, but um it definitely has some real life applications to it.

Manoj Tandon: And Tyler,

Tyler Smith: Yeah, I think it was uh Church Hill who who said never never never give up.

Manoj Tandon: Those are all fantastic quotes.

Tyler Smith: But yeah, Mitch, I also want to say, hey, you know, fair winds and following seas, my man.

Manoj Tandon: Godspeed. And with that, uh, everyone, we are signing off for this episode of Security Confidential.

Mitch Spaulding: Goodbye.

Tyler Smith: Thank you, everyone. Bye. Bye, guys.

Check out the other episodes in Season 1:

Ep. 0 DRS Team – Cybersecurity Conferences

Ep. 1 Luis Martin – Artificial Intelligence

Ep. 2 Stefan Ludlow – Personal Responsibility in Cybersecurity

Ep. 3 Tyler Smith – C-Suite- How to fall in love with Cybersecurity

Ep. 4 Jordan Fulk – Bourbon and IT Talent

Ep. 5 Tyler Smith and Manoj Tandon – Zoombombing, Privacy, and Working from home

Ep. 6 Mitch Spaulding – Alternative Paths to a Cyber Career

Ep. 7 Karen Hough – How to build resilience, adapt to obsticles, and thrive

Ep 8. Dakota Rae – Swim with Sharks and Thrive

Ep. 9 Tyler Smith – Tips on Implementing EDR

Ep. 10 Chris Cazel – Learning Okta

Mitch Spaulding's profile picture for Dark Rhiino Security's Security Confidential podcast

Mitch Spaulding is a cybersecurity professional whose career began with an early interest in technology and video games.

While still in high school, he pursued hands-on experience through a security help desk role at OhioHealth, where he gained exposure to SIEM platforms, IBM QRadar, and data loss prevention.

His path reflects a self-driven approach to learning, practical cybersecurity experience, and a passion for helping organizations strengthen secure access through IAM and zero-trust principles.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

 

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top