This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Amelia Jarboe. Amelia is a Cybersecurity Controls Engineer. She has held many positions in the field of cybersecurity. She is a graduate of The Ohio State University. In addition, to her work, as cybersecurity controls engineer she is on the Steering Committee for Machine Learning and is speaking at the ISSA Central Ohio Infosec Summit.
Chapter Titles:
00:00 Introduction
01:10 How Amelia got into Cybersecurity
03:57 A passion for protecting people with Cybersecurity
06:47 OSU’s Cybersecurity Program
07:40 Imposter Syndrome in Cybersecurity
12:25 Compliance and Cybersecurity
15:20 Continually verifying and validating the controls in place
16:17 Top metrics in Cybersecurity
17:47 A technique to convince decision-makers about cyber spend
21:25 Controls to begin a Cybersecurity program with Spikes and Gaps
26:38 Guidance on frameworks in Cybersecurity
30:20 Cybersecurity is an everyone’s problem
32:27 Individual privacy and Cybersecurity
36:37 Causes for Cybersecurity incidents
39:12 Engaging the end-users in Cybersecurity
41:13 Machine learning
43:13 Mentorship at the High School and Elementary School levels
49:24 The freedom to fail as a base for great success
50:00 ISSA in Central Ohio appearance
Audio:
Important Links:
Transcript
Manoj Tandon: Hello everyone, welcome to another episode of Dark Rhino Security Confidential. Tonight we are honored to have Amelia Jarboe join us. This is her first podcast, so it’s awesome that she chose us to be on the show.
Amelia has an illustrious background—she’s a graduate of The Ohio State University, one of my favorite schools. She has performed many roles in cybersecurity: Senior IT Analyst in Risk and Compliance, Senior Analyst in Applied Security, and currently, she’s a Cybersecurity Controls Engineer at Cardinal Health. Welcome to the show, Amelia. Thank you so much for joining us.
Amelia: Of course. Thank you so much for having me on. I appreciate it.
Manoj Tandon: We’ve got a ton of questions for you, and we’ll try to get through as many as we can. But let’s start here—being a woman in cybersecurity, we find women are still underrepresented, and we’d love to see that change. As an OSU Computer Science graduate, you had many paths—how did you end up in cyber?
Amelia: I have to back up quite a ways. I always joke that my parents predestined me for IT—specifically cybersecurity. In 1999, I dressed up as the Y2K bug for Halloween.
Manoj Tandon: The Y2K bug! You’ve got to send us a picture of that.
Amelia: I’ll see what I can do.
Manoj Tandon: That was when IT outsourcing really kicked off. But go ahead.
Amelia: The real turning point was in high school. I was lucky to have a female computer science teacher—Mrs. Herron. There were only two women in a class of about 35, but she noticed my interest and encouraged me to attend a Women in IT Day at Microsoft.
Manoj Tandon: That must’ve been impactful.
Amelia: It really was. It was my first time seeing women across all areas of IT, including security. That’s where I started exploring it. Initially, I thought I’d go into software development, but by my senior year, I realized cybersecurity was where my passion was—because it’s about protecting people.
Amelia: I especially wanted to protect vulnerable populations, like seniors. Hearing stories about scams targeting them really stuck with me.
Manoj Tandon: We see that all the time—it’s scary how often seniors get targeted.
Amelia: Exactly. And that fear of something like that happening to my own family really motivated me.
Manoj Tandon: We’re also seeing it on the other end with kids. In our STEM programs, we’re teaching them not to click links or ads in games. Do they actually listen?
Amelia: They understand it, but whether they follow through is another story. They know the basics—don’t share personal info, don’t trust strangers online—but execution varies.
Manoj Tandon: There’s no real identity verification online—it’s easy to create a fake persona.
Amelia: Exactly. You can create an entirely fake life online.
Manoj Tandon: At OSU, did you specialize in cybersecurity?
Amelia: To a degree. I had a minor in Information and Computational Assurance. But what stood out most was that many of my professors were women, which was incredibly encouraging.
Manoj Tandon: That’s a big shift from the past. Do you see more women entering the field?
Amelia: I do. As we break the stereotype of cybersecurity being “someone in a hoodie in a basement,” we’ll see more diversity. I personally dealt with imposter syndrome—I didn’t feel like I fit the mold.
Manoj Tandon: There really isn’t a mold in cybersecurity.
Amelia: Exactly. People come from all kinds of backgrounds. The diversity is one of the strengths of the field.
Manoj Tandon: One common trait I see is creativity—the ability to improvise.
Amelia: I completely agree. I was a classically trained violinist, and a lot of those improvisation skills translate directly into cybersecurity.
Manoj Tandon: Same here as a guitar player. Music theory isn’t rigid—you can break the rules if you understand them. Cybersecurity is similar.
Amelia: Exactly.
Manoj Tandon: Let’s shift to compliance vs cybersecurity. Many breached companies were fully compliant. How do you reconcile the two?
Amelia: Compliance is a snapshot in time, but security needs to be continuous. You can pass an audit one day, and the next day something changes. We need continuous validation of controls.
Manoj Tandon: So more of an ongoing evaluation model?
Amelia: Yes—mapping compliance to security controls continuously. Not just checking boxes once.
Manoj Tandon: Are there key metrics people should track?
Amelia: It depends on the audience, but a simple one is: are your logs coming in as expected? Are systems behaving as they should? Start with visibility.
Manoj Tandon: How do you explain these concepts to non-technical decision-makers?
Amelia: I ask myself, “How would I explain this to my parents?” Strip it down. Don’t say “log aggregator”—explain the purpose.
Amelia: For example, HTTP vs HTTPS: HTTP is like broadcasting everything publicly; HTTPS adds protection. That level of explanation resonates.
Manoj Tandon: That’s powerful. For smaller companies, where should they start?
Amelia: First—breathe. Then focus on risk. Ask: how likely is something to happen, and how big is the impact?
Amelia: Start with high-risk areas—where a small misstep leads to big consequences.
Manoj Tandon: How do you define “crown jewels”?
Amelia: Not just revenue-generating systems, but also the dependencies behind them. Anything that, if it fails, disrupts operations.
Manoj Tandon: And disaster recovery?
Amelia: It’s inseparable from cybersecurity. If you can’t recover, you’re not secure.
Manoj Tandon: Favorite frameworks?
Amelia: PCI is actually fun—it’s very hands-on. And NIST, because it breaks things down clearly and maps well to real controls.
Manoj Tandon: That’s the first time I’ve heard “PCI” and “fun” together.
Amelia: It’s the hands-on aspect—actually testing things physically.
Manoj Tandon: I like that. You also mentioned cybersecurity being everyone’s problem.
Amelia: Yes—keeping it simple and not gatekeeping knowledge is key. The more jargon we use, the more people tune out.
Manoj Tandon: Let’s talk privacy. With all these state laws emerging, where is this going?
Amelia: Either we’ll get federal regulation, or states will converge toward a common model. Otherwise, we risk a fragmented system where consumers lose.
Manoj Tandon: And companies may default to the lowest standard.
Amelia: Exactly—and that hurts users.
Manoj Tandon: What about the tension between privacy and business models like Facebook?
Amelia: “Free” isn’t free—you’re the product. That’s the trade-off.
Manoj Tandon: That’s what we teach kids too.
Amelia: Exactly.
Manoj Tandon: Let’s talk security incidents. What are common causes?
Amelia: Lack of user training and misconfigurations. Security is everyone’s responsibility, but not everyone understands it yet.
Manoj Tandon: We always say your people are your biggest security asset.
Amelia: Absolutely. And explaining the “why” behind policies makes a huge difference.
Manoj Tandon: Are companies getting better at that?
Amelia: Yes. Security awareness programs are improving. People are interested—they just need clarity.
Manoj Tandon: That’s great to hear. Let’s touch on your mentorship work.
Amelia: I’ve worked with middle and elementary schools. With middle schoolers, we taught agile and problem-solving. Kids come up with amazing ideas.
Amelia: With elementary students, we focused on hands-on STEM—like making “snow” with baking soda and shaving cream to teach experimentation.
Manoj Tandon: I’m sure parents loved that.
Amelia: We warned them!
Manoj Tandon: That hands-on approach is key. It builds curiosity.
Amelia: Exactly—and gives them freedom to fail.
Manoj Tandon: That’s a great phrase—“freedom to fail immediately.”
Amelia: And that’s how people learn best.
Manoj Tandon: Couldn’t agree more. Any events or shoutouts?
Amelia: I’ll be speaking at the ISSA Central Ohio Summit in May. Also, the International Consortium of Minority Cybersecurity Professionals is a great organization to join.
Manoj Tandon: We’ll include those links. Amelia, this was fantastic. Thank you for joining us.
Amelia: Thank you so much for having me.
Manoj Tandon: I have a feeling you’ll be getting more podcast invites soon. You were a great guest.
Amelia: I appreciate that—thank you.
Manoj Tandon: Take care.
Amelia: You too.
To learn more about Amelia Jarboe please visit https://www.linkedin.com/in/ameliajar…
Check out the other episodes in Season 4:
Ep. 0 Dark Rhino Security – Cyber Basics: The Rundown on Ransomware
Ep. 1 Rob Duhart Jr – In Cybersecurity There are Builders and Breakers, You Need Both!
Ep. 2 Rob Oden – Is a Traditional Computer Science path necessary for Cybersecurity?
Ep. 3 Chad Weinman – Compliance does not correlate to Cybersecurity
Ep. 4 Rob Oden (part 2) – Should the office of the CISO be separate from IT?
Ep. 5 Ross Young – Foreign Cyber Espionage Capabilities
Ep. 6 Ilya Bodner – How to land your first customer
Ep. 7 Samara Williams – Why is there a lack of people going into STEM?
Ep. 8 Amelia Jarboe – A passion for protecting people with Cybersecurity
Ep. 9 Hans Vargas-Silva – Compliance is a low bar for Cybersecurity
Ep. 10 Fredrik Oedegaardstuen – Cautionary advice on Automation
About Amelia Jarboe

Amelia Jarboe appears on this episode of Security Confidential.
Amelia is a Cybersecurity Controls Engineer.
She has held many positions in the field of cybersecurity.
She is a graduate of The Ohio State University.
In addition, to her work as a cybersecurity controls engineer she is on the Steering Committee for Machine Learning and is speaking at the ISSA Central Ohio Infosec Summit.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
Share and spread the word!
