Security Confidential S6 E7 Erika Carrara

This week on Dark Rhiino Security’s Security Confidential podcast, Host Rory Meikle talks to Erika Carrara. Erika is an influential, strategic, business-focused, and highly accomplished C-Suite executive. She has accomplished many things such as being a CISO, Director of Information Technology, Penetration Tester, IT Security Specialist, and many more. Erika is also a Veteran of the United States Army and Mentor. She is currently the CISO of Wabtec Corporation.

 

00:00 Introduction

00:49 How did you start your career in cybersecurity? Was it something you did while in the military?

03:03 Advice for younger individuals stepping into cyber

04:27 Advice for Veterans transitioning into Cyber

06:29 Due diligence process when looking at an acquisition?

13:40 ISO 27,001 17:04 Security Frameworks for Small Businesses

22:00 What motivates bad actors?

26:40 Are there policies that you think the government should adopt that would better deter bad actors?

34:18 Can you shed some light on what defense in depth should entail for critical infrastructure companies?

37:45 3rd party risk mitigation

41:14 Small businesses: expectations regarding cybersecurity?

45:03 Code: Girl

50:00 Connecting with Erika

Transcript

Rory Meikle:
Hello everyone, and welcome to another episode of Security Confidential. I’m your host, Rory Meikle. Today, our guest is Erika Carrera. Erika is an influential, strategic, business-focused, and highly accomplished C-suite executive. She has served as a CISO, Director of Information Technology, penetration tester, and IT security specialist. She’s also a veteran of the United States Army and a mentor. Erika is currently the CISO of Wabtec Corporation. Erika, thank you so much for joining us.

Erika Carrara:
Thank you for having me on your show.

Rory Meikle:
Absolutely. First question for you—how did you get your start in cybersecurity? Was it something you fell into during your time in the military, or did you go in with that goal?

Erika Carrara:
It was definitely a non-traditional path. I served as a military police officer in the United States Army, and after I was medically retired, I took a job at White Sands Missile Range as a government service employee in the DoD space. At the time, I was working as a police support assistant, but I knew I wanted to transition into tech. So I rewrote my resume with a technical focus and applied for a contractor role supporting desktop services on base. I got my start in data entry and worked my way up—from data entry to help desk, to system administrator, and then into an analyst role. Eventually, I was selected to move back into the DoD side doing information assurance work, which ultimately led me into cybersecurity.

Rory Meikle:
That’s incredible—going from military police with no direct cyber background to where you are now. It really is. And it sounds like some of your physical security experience translated over as well.

Erika Carrara:
Absolutely. There are definitely aspects of physical security that translate into cybersecurity—things like social engineering, piggybacking, and gaining access to restricted areas. That mindset carries over more than people might expect.

Rory Meikle:
That makes a lot of sense, especially at your level where you have to think about both physical and cyber risk. I know mentoring is something you’re passionate about. What advice would you give to young people looking to break into cybersecurity, especially from a non-traditional background?

Erika Carrara:
That’s actually the sweet spot. Everyone brings a different perspective based on how they grew up, their experiences, and the types of jobs they’ve had. My advice is simple: don’t be the one to tell yourself “no.” Go ahead and try. Your unique perspective is valuable and necessary to build a strong cybersecurity program. If you have the willingness and aptitude to learn, you absolutely have a place in this field.

Rory Meikle:
That willingness to learn is huge. It’s always easier to teach someone who wants to grow. What about veterans transitioning into cybersecurity—any specific advice for them?

Erika Carrara:
Yes—take advantage of everything available during your transition. It may not seem valuable at first, but it’s only as valuable as the effort you put into it. There are so many programs offering free training in technology—Salesforce’s Vetforce, Fortinet, AWS, Microsoft, and others. Companies recognize that veterans bring strong soft skills—discipline, loyalty, teamwork—and those are incredibly valuable.

Also, use LinkedIn. Veterans get a year free—take advantage of that. Connect with people who have roles you’re interested in. They may not become mentors, but they could become sponsors. Align yourself with people who represent where you want to go.

Rory Meikle:
That’s great advice. Networking really does open doors. Shifting gears a bit—you’ve got a lot of experience with mergers and acquisitions. How should cybersecurity factor into due diligence?

Erika Carrara:
Too often, security is treated as an afterthought—a bolt-on instead of something built into the process. That’s a mistake. You need to have security conversations early, before the acquisition happens, and define your criteria upfront. Technical debt is a huge factor—you’re inheriting it whether you realize it or not. Understanding that risk allows you to factor it into negotiations.

You need a process to assess both technical debt and overall security posture early on. Otherwise, you’re walking into unknown risk that can impact compliance, cost, and long-term integration.

Rory Meikle:
That idea of technical debt is huge. A lot of companies underestimate how much work is needed post-acquisition. What about the cultural side of integration?

Erika Carrara:
That’s where a lot of integrations fail. You can merge networks, deploy tools, and align systems—but if you don’t integrate the culture, you haven’t really integrated the company. People are your first line of defense. You can have the best technology in the world, but one person making a mistake can undermine everything.

I’ve seen approaches where companies take a hard line—forcing assimilation—but that doesn’t always work, especially globally. You need to be culturally aware and adaptive. Having local liaisons who understand regional norms can make a huge difference. Building relationships is key to creating a security-aware culture.

Rory Meikle:
That aligns with what we hear all the time—security is a people problem, not just a technology problem. Let’s talk frameworks. If someone wants to build a world-class cybersecurity program, what do you recommend?

Erika Carrara:
ISO 27001. It’s not just a compliance checklist—it’s a comprehensive framework that integrates security into the business. It covers everything from IT and physical security to procurement and third-party risk. It’s also globally recognized and maps well to frameworks like NIST and CIS.

Even aligning with ISO 27001—without full certification—puts you in a strong position. It helps organizations understand both the management and technical sides of security through ISO 27001 and 27002.

Rory Meikle:
What about small businesses? Do they need to follow something as robust?

Erika Carrara:
Not necessarily. For small businesses, start with CIS Controls. At a minimum, you need the basics: asset management, configuration management, vulnerability management, and identity and access control. If you don’t know what you have, you can’t secure it. Those fundamentals are non-negotiable.

ISO 27001 can still be used as a maturity model, but you don’t need to go all-in right away. Start with what makes sense for your size and resources.

Rory Meikle:
That’s a practical approach. Now, what motivates bad actors from your perspective?

Erika Carrara:
It mostly comes down to greed and notoriety. Financial gain is a big driver, but recognition plays a role too. Being known for taking down a major organization carries weight in that world. The bigger the breach, the more attention—and often, the more money.

There’s also a level of craftsmanship to it. Some attacks are incredibly sophisticated. It’s not always fast-paced—it’s often a waiting game, like fishing. You set the trap and wait.

Rory Meikle:
That’s a great analogy. Last big question—what should governments be doing better to deter cyber threats?

Erika Carrara:
We need consistency and clarity. Right now, there are standards in certain sectors, like the Defense Industrial Base, but they’re not applied universally. That creates gaps.

We also need to bring in real experts and take a proactive approach instead of a reactive one. Define what “good” cybersecurity looks like at different levels—SMBs, enterprises, critical infrastructure—and make that guidance clear and accessible. People want to do the right thing; they just don’t know what that looks like.

Rory Meikle:
That’s a strong point—clarity would go a long way. Before we wrap up, can you tell us a bit about “Girl Code”?

Erika Carrara:
It’s part of my passion for mentoring, especially women in tech. Research shows that girls’ confidence peaks around age nine and doesn’t fully recover until their late twenties. So the focus needs to be on middle school.

“Girl Code” is about giving young girls exposure to opportunities they might not otherwise consider and helping them build confidence through experience—even failure. Failure is how we learn, but many girls are conditioned to avoid it. We need to change that narrative and encourage them to take risks and grow.

Rory Meikle:
That’s incredibly impactful work. We’ll definitely share links so people can get involved. Last question—any events or resources you’d recommend?

Erika Carrara:
Yes, the Society of Women Engineers conference in Houston—check out swe.org. Also, local chapters of Vets in Tech are great for both mentorship and networking. And remember, you don’t need a C-level title to be a mentor. Think about how much you’ve learned over the past 10 years—that knowledge is valuable to someone else.

Rory Meikle:
That’s a great note to end on. Erika, thank you so much for your time. This was an incredible conversation.

Erika Carrara:
Thank you, Rory. I really appreciate it. And I love what you’re doing with the show—keep going. Don’t be the one to tell yourself no.

Rory Meikle:
Absolutely. Thank you again—we’ll definitely stay in touch.

To learn more about Erika visit LinkedIn

Girls Who Code

Code.org

Black Girls Code

Coding Girls

Tech Girls

Django Girls

Check out the other episodes in Season 6:

Ep. 0 Bonus: Why do People Get Hacked?

Ep. 1 Brian Stoner – VP of StellarCyber

Ep. 2 Dr. Joseph – Russia, Ukraine, and Cybersecurity

Ep. 3 Tim Chase – Ethical Hacker, CISO

Ep. 4 Brian Haugli – CEO of SideChannel

Ep. 5 Nat Schere – Cybersecurity as a revenue

Ep. 6 Endre Walls – Starting in Cyber, Vendors, and Diversity

Ep. 7 Erika Carrara – Veteran, Mentor, C-suite executive

Ep. 8 Eddie Thomason – Podcast Host, Author, and Entrepreneur

Ep. 9 Greg Schaffer – vCISO, Author, and Podcast Host

Ep. 10 Jake Belcher – Sr. Director of Security Strategy

Erika Carrara's profile picture for Dark Rhiino Security's Security Confidential podcast

Erika is an influential, strategic, business-focused, and highly accomplished C-Suite executive.

She has accomplished many things such as being a CISO, Director of Information Technology, Penetration Tester, IT Security Specialist, and many more.

Erika is also a Veteran of the United States Army and Mentor.

She is currently the CISO of Wabtec Corporation.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top