Security Confidential S4 E7 Samara Williams

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Samara Williams, Manager of Threat Operations for Cardinal Health. She specializes in defense-in-depth improvement, vulnerability management, threat intelligence, technical risk communication, and cybersecurity program design and development. She has several degrees in computer science and cybersecurity and she is passionate about helping young people with STEM. She is treasurer and founding member of Empower Women of Infosec.

00:00 Introduction

01:36 Journey into Cybersecurity-South Texas to Columbus

05:08 Passion, persistence, and reliance = success in cybersecurity

08:17 Why is there a lack of people going into STEM?

15:12 Building a team in the pandemic and Social Media

20:55 Vulnerability and Risk Management and Threat Intelligence

23:34 Defense in Depth Build of Risks

26:12 Metrics to consider in cybersecurity

29:34 Making Threat Intelligence actionable

35:50 Mentorship in Cybersecurity

39:57 Organizations of interest to Samara and Scholarships

Transcript

Manoj Tandon: Hello, everyone. Welcome to another episode of Dark Rhino Security Confidential. Today, we have a very special guest, Samara Williams. We’re honored to have her. Samara currently runs Threat Operations at Cardinal Health and is focused on proactive actions, defense-in-depth improvement, threat intelligence, vulnerability management, technical risk communications, as well as program design and development. That’s quite a mouthful, but that’s the cybersecurity side of her. What people may not know is that she grew up in South Texas in a blended family, has a degree in cybersecurity, and is very passionate about helping young people with STEM. She is also Treasurer of the International Consortium of Minority Cybersecurity Professionals. Thank you for joining the show today, Samara.

Samara Williams: You’re welcome, and I’m super happy to be here. One more plug—I’m also Treasurer and a founding member of EmpoWE-R Women of InfoSec.

Manoj Tandon: Wonderful. Can you send us the web links for the organizations and we’ll make sure we include them in the show notes?

Samara Williams: I can definitely do that.

Manoj Tandon: I appreciate it. So, Samara, tell us a little bit about your journey growing up in South Texas and ending up in Dublin, Ohio, which is the furthest thing from South Texas.

Samara Williams: Yeah, it’s definitely different. I tell this story often because people ask me about it quite a bit. Both my parents are ex-military. They retired at Lackland Air Force Base in San Antonio, Texas, where I’m from. My mom is actually from the New York area. So I grew up in the South, but in an East Coast household. It was very different.

Manoj Tandon: I was thinking New York to San Antonio is quite a cultural change.

Samara Williams: It is. I don’t know that I ever actually felt like I was from South Texas. It felt like I was there and lived there, but when I got older and started thinking about what I wanted to do with life, I had a great opportunity to come to Columbus, Ohio. It’s random, don’t get me wrong. I love Columbus to death, but when people think about where they’re going to move, they’re usually not saying Columbus, Ohio.

Manoj Tandon: That’s not at the top of their list.

Samara Williams: It’s not. But at a previous employer, I used to travel to Dayton, Ohio. Every time I came up, I thought, “You know what? This is really chill. I like it here.” It still has a city feel with a small-town atmosphere, and it’s underrated. That’s how I ended up here.

Manoj Tandon: You had so many options when choosing a degree. Why cybersecurity? Why not computer science, math, or engineering?

Samara Williams: I’ll be completely honest. I was a little bit of a lazy college student. My main goal was to play basketball. I chose a school where I could play. I started in Business Computer Information Systems, but I didn’t feel challenged enough. I was bored. At the same time, I knew I didn’t want to pursue computer science, math, or something extremely difficult. Cybersecurity felt right in the middle. It also appealed to me because I’ve always been naturally protective. My mom being from New York and raising me with strong social and situational awareness really helped shape that mindset. Cybersecurity felt like a natural fit.

Manoj Tandon: Having now been in cybersecurity, if there’s a young person in high school considering the field, is a formal degree necessary to be successful?

Samara Williams: Nope. Not at all. That’s not something I even focus on when I talk to students. I’ve spoken to high school students, middle school students, and recently a group of top scholars at UTSA. What I tell them is that success in cybersecurity comes down to passion, persistence, and resilience. If you have those qualities and continue building your technical skills, you’ll do just fine.

Manoj Tandon: You’re actually the second person who’s listed those traits in that exact order.

Samara Williams: Really? Who was the first?

Manoj Tandon: I believe it was Odin. He had a similar story—humble beginnings and eventually became a highly successful architect. It’s encouraging because we want people to know they shouldn’t be discouraged if they don’t have a degree. There will always be time to get one later if needed, but you don’t need it to be successful.

Samara Williams: Exactly. And if it makes anyone feel better, there are hiring managers besides me who no longer make a degree mandatory. Many job descriptions now say “Bachelor’s degree or relevant experience,” and we’re serious about that. Relevant experience counts. Apply anyway.

Manoj Tandon: That’s great advice. We work with a lot of military veterans, and we tell them the same thing. Don’t negotiate against yourself. If you’ve been trained in cybersecurity through the Air Force or Army, we’d absolutely consider you.

Samara Williams: Just do it.

Manoj Tandon: Why do you think there is such a lack of people going into STEM? And why do minority communities have even fewer people entering these fields?

Samara Williams: I think there is a preconceived notion about what you’re supposed to be and what you’re supposed to like if you pursue a STEM career. I don’t fit most of those stereotypes, and I’m doing pretty well. When I entered cybersecurity, I noticed I was very different from many of my colleagues, both superficially and personality-wise. I’m not a huge Star Wars, Star Trek, or Marvel fan. I like martial arts movies, sports, and other things. I think misconceptions about the culture discourage people from pursuing STEM. For minority communities specifically, I believe it’s largely a lack of representation.

Manoj Tandon: I think children are often taught that STEM is hard. Science, math, and physics get presented as difficult subjects, and that becomes a self-fulfilling prophecy. If you go into something believing you’re not going to succeed, you’ve already set yourself up for failure. I think our educational system should focus more on inspiring wonder and curiosity.

Samara Williams: I support that opinion 100%, but I’d also put more emphasis on parents. Parents need to expose their children to a wide variety of interests and allow them to decide what they enjoy. My mom exposed me to many different things without pressuring me toward any specific path.

Manoj Tandon: I’m glad you brought that up. Growing up in an Asian household, there was always a strong cultural emphasis on education. I completely agree that parents play a huge role. With the right encouragement, more children would pursue these careers instead of dismissing them because they seem hard.

Samara Williams: Exactly. And even getting more granular, think about the toys we buy young girls. Are we only buying toys associated with nurses, teachers, and cooks? Or are we exposing them to careers like doctors, engineers, and scientists? Those early messages matter.

Manoj Tandon: Toy manufacturers, if you’re listening, we need some cybersecurity toys.

Samara Williams: No kidding.

Manoj Tandon: Continue.

Samara Williams: Well, this is an idea we could have here, and you’re going to have to cut me in on it, don’t take it. There needs to be a board game, maybe something like Battleship, but instead it’s a firewall. Somebody is the adversary and the other person is the defender.

Manoj Tandon: Samara, why don’t you build it and let’s see if we can get somebody to publish it? If nothing else, it would be a great gag gift. We can put it on our website and donate the proceeds to help save rhinos.

Samara Williams: That sounds good.

Manoj Tandon: That would be great. Speaking of things that changed during the pandemic, let’s talk about building a team. How did the experience of building a team during COVID change or evolve over the last year?

Samara Williams: Something important to note is that I’m also a new manager. I was learning how to manage during a pandemic while managing a fully remote team. On one hand, it was extremely challenging. On the other hand, I was able to reach a much wider audience because I offered fully remote positions. I’m proud to say I have a very diverse team. Everyone has a different background and skill set. The key thing I used during the pandemic to build relationships and recruit was Twitter and social media.

Manoj Tandon: Really?

Samara Williams: Yes. I’m very open and honest on Twitter. I’m completely myself, and I think that authenticity attracted people to me and made them feel comfortable approaching me.

Manoj Tandon: I guess I need to open a Twitter account.

Samara Williams: Twitter is where it’s at. I didn’t even open one until October.

Manoj Tandon: I never realized so many professionals were using it.

Samara Williams: Most definitely. I found my technical lead on Twitter. We work incredibly well together. It gave us the opportunity to get to know each other throughout the interview process instead of keeping everything formal. I was able to make a more informed decision, and so was he. Several other people on the team were connections that started there. We built trust before they even joined.

Manoj Tandon: During the experience of building a remote team, was there a positive outcome or gift that COVID provided which you think will remain permanent?

Samara Williams: I have a lot of opinions on this subject. I won’t go through all of them, but 2020 and even 2021 opened a lot of people’s eyes. I saw friends, mentors, and colleagues in a different light. It helped me identify relationships I wanted to continue and others I didn’t. My circle had probably become a little too large, and it became smaller but more meaningful. From a work perspective, I think it increased our sense of empathy. Seeing how supportive and understanding my team became with one another has been incredible. We willingly pick up each other’s slack and don’t expect anything in return. I couldn’t be happier, and I think COVID helped create that.

Manoj Tandon: It sounds like you selected a lot of A-players to make that happen.

Samara Williams: I try. I also inherited some A-players, which was incredibly fortunate.

Manoj Tandon: What you’re describing is actually very rare. You really have to build a strong team culture to achieve that.

Samara Williams: A lot of it comes down to being open and vulnerable, and having a team that’s willing to do the same. Not everyone is equally vulnerable or empathetic, but we don’t reject those qualities. We don’t shame people for them. That’s where it starts.

Manoj Tandon: That’s interesting because when I think of Cardinal Health, I think of a massive corporation. What you’re describing are qualities I wouldn’t normally associate with a giant enterprise.

Samara Williams: I think I got a little lucky, but Cardinal definitely has leaders who emphasize values and behaviors. There is a strong sense of purpose from the top down that allows people to be authentic. That’s what’s most important.

Manoj Tandon: That’s excellent. So that’s part of the culture they’ve built?

Samara Williams: I would definitely say that’s true within the cybersecurity department.

Manoj Tandon: Let’s talk a little about vulnerability and risk management. When COVID forced everyone remote, we saw a massive increase in attacks against our clients. Phishing attempts skyrocketed. Attackers were trying every possible method to gain access. Was that your experience as well, and did you change your strategy?

Samara Williams: A brand-new team naturally brings a new strategy. Maybe not a completely new strategy, but certainly a different emphasis. My team primarily partners with incident response, which is naturally reactive. Something happens, and they respond. Our focus is proactive. How can we get ahead of vulnerabilities? What are threat actors doing? How can we defend better against them? There was definitely an increase in activity during COVID, but at Cardinal it’s very easy to become overwhelmed because there is so much opportunity and such a broad attack surface. We’re a healthcare organization, but we’re also involved in manufacturing, logistics, pharmaceuticals, and medical devices. Prioritization becomes critical.

One thing I think is beautiful is combining threat intelligence and vulnerability management into one team. Threat intelligence gives you visibility into what’s important to the organization and what matters to business leaders. Vulnerability management gives you deep knowledge of assets, vulnerabilities, and their criticality. When you bring those together, along with industry intelligence about what is dangerous, you can prioritize based on business impact. That combination allows you to create an effective action plan, and that’s really what we’ve focused on.

Manoj Tandon: That makes complete sense. What you’ve described is a defense-in-depth strategy built around business risk. Do you use a formal risk framework?

Samara Williams: Our risk management team uses an industry-standard framework. I don’t think I can specify which one. However, our team is building more of a customized risk methodology than a framework. We try to be as objective as possible by evaluating threat actor sophistication, business impact, exploitability, current controls, and other factors. The goal is to arrive at a final risk decision that is tied directly to a remediation plan.

Manoj Tandon: You’re already ahead of 99.9% of companies.

Samara Williams: We haven’t perfected it yet.

Manoj Tandon: Many organizations struggle to define what they’re actually defending. Ask different people what assets are most critical to revenue generation and you’ll get different answers. Very few organizations take the approach you’ve described and combine those perspectives.

Samara Williams: I think breaking down the silo between threat intelligence and vulnerability management is what makes it powerful. As the team grows, there may be organizational separation, but that doesn’t mean we need to create silos. I’m passionate about process integration. How do different teams work together and make each other better? That’s what I love seeing.

Manoj Tandon: As you’ve built these integrations, have you established any metrics that you believe are critical?

Samara Williams: Yes. We’re still developing them, but one that I can talk about relates to asset management. With everything we’ve discussed—threat actor activity, threat modeling, and understanding our assets—if we can establish a truly accurate asset management process, then perhaps we can assign risk ratings to business units and prioritize accordingly.

Samara Williams: My long-term vision is assigning a measurable risk score to specific business units, applications, or processes. That allows us to prioritize remediation and also helps business leaders understand and take ownership of security risks.

Manoj Tandon: That sounds like federated security.

Samara Williams: I try not to label too many things because then I have to live up to them, but I’m definitely aiming high.

Manoj Tandon: That’s a very interesting approach. Looking at each business unit’s assets, vulnerabilities, and threat exposure allows you to prioritize effectively. That’s a valuable insight.

Samara Williams: I’ll give you another one. I recently hired someone with a financial risk background who has been moving into cybersecurity. One thing we’re exploring is whether we can tie our customized risk methodology directly to financial loss. If we can quantify the potential losses prevented by specific controls, then we can clearly demonstrate business value.

Manoj Tandon: That’s fantastic. You’re in Columbus, where quantitative risk analysis has a long history. You can absolutely use those techniques to estimate financial impact.

Samara Williams: That’s exactly what we’re hoping to do.

Manoj Tandon: That’s really good work. One thing I’ve observed over the years is that cybersecurity teams often struggle to communicate risk in a way that business leaders understand. We speak in terms of vulnerabilities, exploits, CVEs, and attack vectors, but executives are focused on business outcomes. How do you bridge that gap?

Samara Williams: That’s something I think about constantly. If you walk into a meeting and start talking about CVSS scores, attack chains, or technical vulnerabilities, most executives are going to tune out. They’re not paid to think about those things. They’re paid to think about business objectives, operational continuity, revenue generation, customer trust, and regulatory obligations. So the responsibility falls on us to translate technical risk into business risk.

Manoj Tandon: That’s easier said than done.

Samara Williams: It absolutely is. That’s why I spend so much time thinking about communication. One of the things I try to teach my team is that the work isn’t done once you’ve identified the problem. The work isn’t done once you’ve developed the solution. The work is done when the right people understand why it matters and are willing to take action. That requires communication skills, empathy, and understanding your audience.

Manoj Tandon: That’s a very mature way to look at it.

Samara Williams: I think cybersecurity professionals sometimes underestimate the value of soft skills. We focus so much on technical expertise that we forget we’re ultimately working with people. If people don’t understand what we’re saying, then it doesn’t matter how technically correct we are.

Manoj Tandon: That’s probably one of the biggest challenges in the industry today.

Samara Williams: I agree. And honestly, it’s one of the reasons I enjoy mentoring. When I talk to students or younger professionals, I encourage them to develop both sides of the equation. Yes, learn the technology. Learn networking. Learn cloud security. Learn detection engineering. Learn whatever specialty interests you. But also learn how to communicate, how to collaborate, and how to tell a story.

Manoj Tandon: Speaking of mentoring, you’ve been heavily involved in helping women and minorities enter cybersecurity. What are some of the challenges you see?

Samara Williams: Confidence. That’s probably the biggest one. I see incredibly talented people who don’t think they’re qualified enough. They’ll look at a job description and convince themselves they aren’t ready. Meanwhile, someone else who meets only half the qualifications will apply without hesitation.

Manoj Tandon: I’ve seen that exact same thing.

Samara Williams: It’s incredibly common. That’s why I spend a lot of time encouraging people to apply anyway. Let someone else tell you no. Don’t eliminate yourself from consideration before you’ve even tried.

Manoj Tandon: That’s a powerful message.

Samara Williams: I think representation matters too. When people can see someone who looks like them succeeding in a field, it becomes easier to imagine themselves there as well. That’s one reason I stay active in organizations like ICMCP and EmpoWE-R. Visibility matters.

Manoj Tandon: It certainly does.

Samara Williams: Another thing I try to emphasize is that there isn’t one path into cybersecurity. Some people come from networking. Some come from software engineering. Some come from the military. Some come from risk management or audit. Some are self-taught. There are many ways to get here.

Manoj Tandon: That’s one thing I love about this industry. People come from all sorts of backgrounds.

Samara Williams: Exactly. And those different perspectives are valuable. Diverse teams tend to solve problems better because they approach challenges differently.

Manoj Tandon: Let me ask you a difficult question. If you were speaking to a high school student today who wanted to pursue cybersecurity, what would be the first thing you would tell them to do?

Samara Williams: Start exploring. Don’t wait for someone to give you permission. There are so many free resources available today. There are online labs, learning platforms, YouTube channels, communities, mentorship groups, capture-the-flag competitions, and open-source projects. Pick something that interests you and start experimenting.

Manoj Tandon: That’s much different from when we started.

Samara Williams: Completely different. When I was getting started, information was available, but not nearly at the scale it is today. Now you can learn almost anything if you’re willing to invest the time.

Manoj Tandon: And you don’t necessarily need expensive equipment anymore either.

Samara Williams: Exactly. You can build a home lab with very little money. You can use cloud environments. You can use virtual machines. There are so many options available.

Manoj Tandon: What about certifications? People always ask about certifications.

Samara Williams: Certifications have value, but I don’t think they’re magic. They’re one signal among many. A certification can demonstrate commitment and foundational knowledge, but it doesn’t automatically make someone an expert. Experience still matters. Curiosity still matters. Problem-solving still matters.

Manoj Tandon: That’s probably one of the most balanced answers I’ve heard.

Samara Williams: I try to be realistic. I’ve met people with many certifications who struggled to apply the concepts in practice, and I’ve met people with no certifications who were incredibly effective practitioners.

Manoj Tandon: Fair point.

Samara Williams: Ultimately, cybersecurity is a field where learning never stops. If you enjoy learning, you’ll probably do well. If you’re looking for a career where you can learn something once and never update your knowledge again, this isn’t the field for you.

Manoj Tandon: That’s certainly true. The threat landscape changes constantly.

Samara Williams: And that’s part of what makes it exciting. There’s always a new challenge. There’s always something new to learn. There’s always a new problem to solve.

Manoj Tandon: That’s a great perspective. One of the things we see quite often is burnout in cybersecurity. The workload continues to increase, the threats never stop, and many teams are understaffed. What’s your perspective on that?

Samara Williams: Burnout is real. I think anyone who’s worked in cybersecurity long enough has either experienced it personally or seen it happen to people they care about. The pace can be relentless. There’s always another vulnerability, another incident, another project, another audit, another request. If you’re not careful, it can consume everything.

Manoj Tandon: How do you avoid it?

Samara Williams: I don’t know that anyone completely avoids it. I think the key is recognizing it early and creating healthy boundaries. One of the things I try to do as a leader is make sure my team understands that they’re human first. The work is important, but people matter more.

Manoj Tandon: That’s refreshing to hear.

Samara Williams: I mean it. If your people are exhausted, stressed, and disengaged, then you’re not actually building a sustainable program. You’re building something that eventually breaks. Taking care of people isn’t just the right thing to do; it’s also good business.

Manoj Tandon: That’s probably something many organizations need to hear.

Samara Williams: I think the pandemic highlighted that for a lot of people. We all saw coworkers dealing with challenges we’d never seen before. Children at home, family illnesses, isolation, stress. It reminded us that everyone is carrying something.

Manoj Tandon: That’s true.

Samara Williams: It also changed the way I think about leadership. Early in my career, I probably focused too much on outcomes. Today, I still care deeply about results, but I’ve learned that the best results usually come from creating an environment where people feel supported and trusted.

Manoj Tandon: That’s a lesson that takes some people years to learn.

Samara Williams: I’m still learning it. Leadership isn’t something you master. It’s something you continue developing.

Manoj Tandon: Looking ahead, what do you think are some of the biggest challenges cybersecurity organizations will face over the next few years?

Samara Williams: I think scale is one of them. The number of assets, users, systems, and dependencies continues to grow. Cloud adoption has accelerated. Digital transformation continues. Organizations are collecting and processing more data than ever before. At the same time, threat actors are becoming more sophisticated.

Manoj Tandon: So we’re defending a larger attack surface every year.

Samara Williams: Exactly. And because of that, prioritization becomes even more important. Nobody has unlimited resources. Nobody can fix everything immediately. The organizations that succeed will be the ones that become very good at understanding what matters most and focusing their efforts there.

Manoj Tandon: That’s consistent with the risk-based approach you described earlier.

Samara Williams: It all comes back to risk. Every decision is ultimately a risk decision. The question is whether you’re making those decisions intentionally or accidentally.

Manoj Tandon: That’s a great way to phrase it.

Samara Williams: Another challenge is talent development. There are so many opportunities in cybersecurity, but we still have a talent shortage. We need to continue creating pathways for people to enter the field and grow.

Manoj Tandon: Do you think the industry is improving in that regard?

Samara Williams: Slowly. I think more organizations are beginning to recognize that they can’t simply hire experienced professionals forever. At some point, you have to develop talent internally. You have to invest in people.

Manoj Tandon: That requires patience.

Samara Williams: It does. But it’s worth it. Some of the best professionals I’ve worked with were given an opportunity before they checked every box.

Manoj Tandon: That’s often how people discover their potential.

Samara Williams: Exactly.

Manoj Tandon: Let’s switch gears slightly. You’ve spoken a lot about mentorship and community. Has there been a mentor who had a particularly significant impact on your career?

Samara Williams: Absolutely. I’ve been fortunate to have several mentors at different stages of my career. What stands out is that each one helped me in a different way. Some challenged me technically. Some taught me how to navigate organizations. Some helped me build confidence. Some simply believed in me when I didn’t fully believe in myself.

Manoj Tandon: That’s powerful.

Samara Williams: It is. That’s one reason I try to pay it forward. Nobody gets where they are entirely on their own. We all benefit from people who invest time, energy, and encouragement into our growth.

Manoj Tandon: I couldn’t agree more.

Samara Williams: And mentorship doesn’t always have to be formal. Sometimes it’s a conversation. Sometimes it’s advice. Sometimes it’s introducing someone to a new opportunity. Small actions can have a huge impact.

Manoj Tandon: That’s very true.

Samara Williams: I think people sometimes underestimate how much influence they can have simply by encouraging someone else.

Manoj Tandon: Well said. As you’ve progressed in your career and taken on leadership responsibilities, what has surprised you the most?

Samara Williams: Probably how much of leadership is actually about people. Early in my career, I assumed leadership was primarily about making decisions, setting strategy, and solving problems. Those things are certainly part of it, but a much larger portion is understanding people, helping them succeed, and creating an environment where they can do their best work.

Manoj Tandon: That’s an important distinction.

Samara Williams: It is. Technical excellence is important, but if you can’t build trust, communicate effectively, and help people grow, your impact will be limited as a leader.

Manoj Tandon: What advice would you give to someone moving from an individual contributor role into management?

Samara Williams: The first thing I’d say is that your success is no longer measured by what you personally accomplish. Your success becomes tied to the success of your team. That’s a difficult transition for many people because they’re accustomed to solving problems directly.

Manoj Tandon: That’s a common challenge.

Samara Williams: Very common. Sometimes the best thing you can do as a leader is step back and allow someone else the opportunity to solve the problem. That can be uncomfortable, especially if you know exactly how to do it yourself.

Manoj Tandon: You’re describing a shift from doing the work to enabling others to do the work.

Samara Williams: Exactly. And that requires patience. It also requires trust. If you hired talented people, then you have to give them room to grow.

Manoj Tandon: That’s excellent advice.

Samara Williams: Another thing I’d tell new managers is to be authentic. People can tell when you’re trying to be someone you’re not. The best leaders I’ve worked with weren’t carbon copies of one another. They had different styles, different personalities, and different strengths.

Manoj Tandon: That’s a great point.

Samara Williams: The goal isn’t to imitate someone else. The goal is to become the best version of yourself as a leader.

Manoj Tandon: Let’s talk about the future of the cybersecurity profession itself. Do you think we’re moving toward more specialization or more generalization?

Samara Williams: I think we’re moving toward both simultaneously, which sounds contradictory. Organizations need specialists because technology continues to become more complex. At the same time, they need people who can connect the dots across disciplines.

Manoj Tandon: That’s an interesting answer.

Samara Williams: Think about it this way. You might have someone who specializes in cloud security, someone else who specializes in threat intelligence, someone focused on vulnerability management, and another person focused on incident response. Those specialists are valuable. But you also need people who understand how those disciplines interact and support one another.

Manoj Tandon: Systems thinkers.

Samara Williams: Exactly. People who can see the bigger picture and understand how all the pieces fit together.

Manoj Tandon: That seems increasingly important as environments become more complex.

Samara Williams: It does. And complexity isn’t slowing down. If anything, it’s accelerating.

Manoj Tandon: Let’s talk about diversity in cybersecurity. We’ve discussed representation, but do you think the industry is making meaningful progress?

Samara Williams: I think we’re making progress, but we still have work to do. The encouraging thing is that more organizations are having the conversation. More leaders are paying attention. More people are investing in outreach, mentorship, and development programs.

Manoj Tandon: That’s certainly true.

Samara Williams: The challenge is ensuring those efforts are sustainable. Real progress doesn’t happen because of a single initiative. It happens because organizations commit to creating opportunities over a long period of time.

Manoj Tandon: Consistency matters.

Samara Williams: Exactly. And accountability matters too. If diversity and inclusion are important, then they need to be treated like any other business objective. You have to measure progress and hold yourself accountable.

Manoj Tandon: That’s a fair point.

Samara Williams: Ultimately, I want people to feel like they belong. Not because of a program or an initiative, but because the culture genuinely supports them.

Manoj Tandon: That’s a great aspiration.

Samara Williams: I think everyone benefits when organizations create environments where people can bring their full selves to work.

Manoj Tandon: I completely agree.

Samara Williams: And from a purely practical perspective, diverse teams make better decisions. They bring different perspectives, different experiences, and different ways of solving problems.

Manoj Tandon: Which is exactly what cybersecurity needs.

Samara Williams: Absolutely.

Manoj Tandon: As we start wrapping up, I’d like to ask one final question. When you look back at your journey—from South Texas, to college basketball, to cybersecurity leadership, to mentoring and advocacy—what are you most proud of?

Samara Williams: Honestly, the people. The accomplishments are great. The promotions are great. The projects are great. But when I look back, what stands out most are the people I’ve been able to help and the relationships I’ve built along the way.

Manoj Tandon: That’s a wonderful answer.

Samara Williams: It’s true. There are people who invested in me throughout my career, and if I’ve been able to help someone else in return, then that’s something I’m really proud of. Whether it’s mentoring students, helping someone get their first cybersecurity job, or supporting a teammate’s growth, those things mean a lot to me.

Manoj Tandon: It sounds like you’re leaving a legacy beyond technology.

Samara Williams: I hope so. Technology changes. Roles change. Companies change. But the impact you have on people tends to last much longer.

Manoj Tandon: That’s very well said.

Samara Williams: Thank you.

Manoj Tandon: If someone listening today wants to get involved in cybersecurity, or wants to learn more about the organizations you’re involved with, what would you recommend?

Samara Williams: I’d encourage them to get involved with the community. Reach out to people. Attend local security events. Join organizations like ICMCP and EmpoWE-R Women of InfoSec. Look for mentorship opportunities. Don’t be afraid to ask questions. The cybersecurity community is generally very supportive of people who genuinely want to learn.

Manoj Tandon: That’s excellent advice.

Samara Williams: And remember, you don’t have to know everything before you get started. None of us knew everything when we started.

Manoj Tandon: That’s certainly true.

Samara Williams: Just take the first step. Keep learning. Stay curious. Be persistent. The opportunities are out there.

Manoj Tandon: Samara, this has been a fantastic conversation. I really appreciate you taking the time to join us today and share your experiences, your insights, and your passion for helping others.

Samara Williams: Thank you for having me. I had a great time.

Manoj Tandon: Before we close, I want to thank you for all the work you’re doing—not only in cybersecurity but also in helping build the next generation of professionals. We need more people like you in this industry.

Samara Williams: Thank you. I truly appreciate that.

Manoj Tandon: And to our audience, thank you for joining us for another episode of Security Confidential. As always, please like, subscribe, and share the content if you found value in today’s discussion. We look forward to seeing you on the next episode.

Samara Williams: Thank you, everyone.

Manoj Tandon: Take care.

To learn more about Empower Women in Infosec https://www.empower-infosec.org/

To learn more about ICMCP https://www.linkedin.com/company/inte…

To learn more about Samara visit https://www.linkedin.com/in/samara-r-…

To watch Samara’s Ted Talk https://www.youtube.com/watch?v=VUFqJ…

Check out the other episodes in Season 4:

Ep. 0 Dark Rhino Security – Cyber Basics: The Rundown on Ransomware

Ep. 1 Rob Duhart Jr – In Cybersecurity There are Builders and Breakers, You Need Both!

Ep. 2 Rob Oden – Is a Traditional Computer Science path necessary for Cybersecurity?

Ep. 3 Chad Weinman – Compliance does not correlate to Cybersecurity

Ep. 4 Rob Oden (part 2) – Should the office of the CISO be separate from IT?

Ep. 5 Ross Young – Foreign Cyber Espionage Capabilities

Ep. 6 Ilya Bodner – How to land your first customer

Ep. 7 Samara Williams – Why is there a lack of people going into STEM?

Ep. 8 Amelia Jarboe – A passion for protecting people with Cybersecurity

Ep. 9 Hans Vargas-Silva – Compliance is a low bar for Cybersecurity

Ep. 10 Fredrik Oedegaardstuen – Cautionary advice on Automation

Samara Williams' profile picture for Dark Rhiino Security's Security Confidential podcast

Samara specializes in defense-in-depth improvement, vulnerability management, threat intelligence, technical risk communication, and cybersecurity program design and development.

She has several degrees in computer science and cybersecurity and she is passionate about helping young people with STEM.

She is treasurer and founding member of Empower Women of Infosec.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top