Security Confidential S7 E2 Josh Harrington

This week on Dark Rhiino Security’s Security Confidential podcast, Host Rory Meikle welcomes Josh Harrington. Josh is a CISSP, CCSP-certified Director of IT and Security at Wattpad. He has a degree in Information Technology with a specialization in Networking and IT Security and a minor in operations management. With nearly a decade of cyber and IT-related experience, Josh has utilized his knowledge of industry threats and emerging technologies to guide businesses in advisory roles from implementation to leadership development both internationally and in the Greater Toronto Area.

 

00:00 Introduction

01:22 Josh’s story

03:10 The challenge of a Cybersecurity career

04:00 How has your previous experience helped prepare you for your position today?

05:55 Hands-on Experience: required or not?

07:42 Wattpad

08:22 Security Challenges for open-source platforms

11:50 Top 3 areas of Security

15:10 Must have Security tools

16:20 The Future of Cyber: Where is it going?

21:13 3rd party risk

23:40 Key points for employees regarding security

27:32 Message for young cyber professionals

33:37 What has helped you grow in IT?

36:50 A must for a resume

42:27 Connecting with Josh

Transcript

Rory Meikle:
Hello everyone and welcome back to another episode of Security Confidential. I’m Rory, and with me today is Josh Harrington. Josh is a CISSP and CCSP-certified Director of IT Security at Wattpad. He has a degree in Information Technology with a specialization in networking and IT security and a minor in Operations Management. With nearly a decade of cyber and IT-related experience, Josh has utilized his knowledge of industry threats and emerging technologies to guide businesses in advisory roles, from implementation to leadership development, both internally and in the Greater Toronto Area. Josh, welcome.

Josh Harrington:
Hey Rory, thanks for having me.

Rory Meikle:
Absolutely. It is great to have you. You definitely have a resume of a true security professional and someone who has been in this game for a long time.

Josh Harrington:
[Laughter] I appreciate that. It’s something I want to continue to grow, so although it may be impressive now, let’s see where it is in the next five to ten years.

Rory Meikle:
Absolutely. Your career has been extensively involved in tech, from a support analyst all the way to an engineer and now Director of Security. Talk to me about this journey for you and at what point you transitioned more toward a security role rather than an engineering role.

Josh Harrington:
Yeah, great question. I think the truth is I’ve always had my eyes on security and being within the security industry, but when I started, security wasn’t as big as it is now. So I did the next best thing and wanted to work in IT because I thought that might be the best way to start a security career, and it turns out that was the right decision for me. I’ve always been keen on things like automation and coding, and that’s where we start to see the software engineering side as well. I think that’s a great avenue for solving problems, and certainly early in my career, that’s what I did to the point of automating tasks at work where I was able to start researching areas that I had a keen interest in. I then thought about software engineering as a career, but all credit to individuals who can do that. For me, staring at a screen and coding for a week straight was a challenging task. I found that what I really enjoy is problem solving, and I think that’s what you see in security. It’s a lot of problem solving, and it’s constantly changing. The same thing applies within consulting. You see a lot of challenges and then solve those from both a business perspective and a technical perspective. For me, every day that makes coming to work and doing my job a lot easier to the point where it doesn’t necessarily feel like a job; it’s more of a passion.

Rory Meikle:
That makes total sense. Do you think with security there’s more of a challenge and every day is shifting? You never really know what the day might hold.

Josh Harrington:
Yeah, absolutely. If we look at the past couple years with SolarWinds and Log4j, those events caused a lot of individuals to shift their thinking and approach each day asking, “What’s the new challenge going to be?” and “How do we think toward the future and proactively solve it?” Having the ability to go into work and know, “This is what I’d like to work on,” and then in some cases doing a complete 180 and saying, “This is what I have to work on,” certainly adds to the job itself.

Rory Meikle:
How have your previous experiences helped prepare you for your current position today, whether it was positions leading up to becoming Director of IT Security at Wattpad or even roles before joining the organization?

Josh Harrington:
I think my previous experience helped me become a well-rounded practitioner, and that’s a theme I speak to often. In security, you’re working with everyone in an organization. To implement security and IT properly, you need to be involved from start to finish, whether that’s threat modeling and understanding projects being put forward or continuous security once something is operationalized. The positions I’ve held allowed me to understand that process and build relationships, both managing my team and working with stakeholders. IT support and software engineering helped me understand code, product, and the user experience. Consulting exposed me rapidly to many different things. Before Wattpad, I worked at a company where growth came through mergers and acquisitions, so you needed a strong understanding of taking something that exists and bringing it into the fold of the organization, whether that was people, process, or technology. Today at Wattpad, which is a very user-centric platform, I’ve gained a lot of perspectives that help me properly position projects and explain to end users the need for security. That experience continues to pay dividends.

Rory Meikle:
Do you think when you’re looking at someone who’s maybe a CISO or IT Director, it’s more beneficial to have someone who’s had experience from the ground floor all the way up, or someone who comes in with certifications and leadership skills but not necessarily hands-on experience?

Josh Harrington:
I think what really sets someone apart is their willingness to learn. I’ve seen people from all walks of life transition into cybersecurity successfully. You have CPAs who move into cybersecurity leadership roles and lawyers who pivot into more technical roles. They may not initially have the background, but they’re willing to learn and apply their previous experience in meaningful ways. Certifications like CISSP help, but ultimately it comes down to curiosity and the desire to build upon your experiences and apply them to the business.

Rory Meikle:
Absolutely. It’s that eagerness to learn and understand your organization and all the challenges that come with it. At Wattpad, your company provides an open platform for readers and writers, correct?

Josh Harrington:
Yeah, absolutely. Wattpad is all about the users. Like many platforms, the user base really makes the organization. At Wattpad, it’s about sharing your unique story, connecting with readers in a safe space, and sharing experiences through written language. Who knows—your creativity could become the next Netflix or Hulu hit. We’ve already seen stories originating from Wattpad become major productions.

Rory Meikle:
That’s awesome. What kind of security challenges come along with that type of open platform?

Josh Harrington:
We face a lot of the same challenges as others in the industry—ransomware, business email compromise, malware—but what’s unique to Wattpad is treating users as an extension of the platform and security program. We have to monitor content to ensure it adheres to regulations, laws, and compliance requirements. We also have to deal with web scraping and spam. There are good actors on the platform, but there are also people trying to scrape content, repost it elsewhere, or redirect users to malicious websites. Inwardly, it’s also about making sure code is secure and ensuring the organization understands security as a whole.

Rory Meikle:
One thing you mentioned that I hadn’t really thought about is that you’re not only trying to protect your data from malicious actors coming in, but also from people taking things out, like stories and content users created.

Josh Harrington:
Exactly. Data is the new oil, and we certainly have a lot of data. It’s about securing it from all angles while making users feel safe enough to share their creativity because they know it’s in good hands.

Rory Meikle:
That user experience is key to getting people to keep coming back to the platform.

Josh Harrington:
Definitely. One of the broader challenges within the security realm itself is finding ways to share challenges and work together as an industry. Security has traditionally been viewed as very secretive, but I’d love to see more collaboration through conferences and shared findings. That openness is something security practitioners should continue moving toward.

Rory Meikle:
Absolutely. If a small company brought you in to build out a security program, what are the top three areas you would start with?

Josh Harrington:
I’d focus less on technology initially and more on people and process. First, I’d build relationships and crawl the organization the same way you’d crawl a website. You’ll uncover both strengths and weaknesses, old pen test reports, governance structures, and business needs through conversations. Second, I’d establish foundational planning—policies, alerting, reporting, and foundational controls. Third, I’d focus on cybersecurity awareness training and building a program of security champions within the organization. Most companies are limited on budget and staffing, so you need advocates throughout the organization until you can justify additional resources. If we’re talking strictly technology, then it’s asset and data management, alerting and logging, and incident readiness.

Rory Meikle:
I think you hit it perfectly with partnerships and communication. Security isn’t just a technology problem; it’s a people problem too.

Josh Harrington:
Exactly. Often when you listen to people, they’ll tell you where the risks and pain points are. Even today, through one-on-one conversations, I still uncover risks and areas for improvement. If you’re in an organization with zero risk, let me know because I’ve never seen one.

Rory Meikle:
What kind of security tools are must-haves for organizations of any size?

Josh Harrington:
If you don’t know what you have, how can you secure it? If you can’t detect issues, how can you respond? And if you don’t track successes and failures, how do you improve? Your security tools need to support those directives. The exact products vary depending on organization size and budget, but the focus should always be visibility, detection, and response.

Rory Meikle:
When you think about the future of IT security, where does your mind go?

Josh Harrington:
Cybersecurity is becoming increasingly complex. We hear buzzwords like quantum computing and blockchain, but we still haven’t solved many of today’s problems. I think the future centers around data, human capital, automation, and third-party risk. Threat actors are moving from broad shotgun-style attacks toward much more targeted attacks because they have more information available to them. Cybersecurity is no longer a “nice to have”; it’s a necessity. It’s not a matter of if an incident will happen, but when. Organizations need to think about how they’ll respond when it does happen.

Human capital is another major area. We need to empower employees across the organization—not just security teams—to think with a cybersecurity mindset. Even your marketing team should understand the importance of security because cybersecurity affects the entire business.

Rory Meikle:
I think you’re right. Often the least cybersecurity-minded person in the company becomes the weakest point.

Josh Harrington:
Absolutely. And third-party risk continues to grow because organizations are so interconnected now. If a trusted vendor gets compromised and sends you a malicious link, there’s an inherent trust relationship there. We need to look beyond traditional brick-and-mortar security and think about cybersecurity as a collaborative ecosystem involving vendors, partners, and users. It really takes a village.

Rory Meikle:
What are some key points you try to hammer home with employees regarding security mindset?

Josh Harrington:
Security isn’t the “house of no.” It’s the “house of yes, if.” We can do things, but we need to understand the risks and controls involved. Messaging needs to be clear and consistent, and people need to feel like peers rather than feeling like security is talking down to them. Security awareness should be continuous and tied into how the business operates. Regardless of whether someone works in accounting, design, or engineering, security should be one of the pillars they think about in their work.

Rory Meikle:
That’s definitely the best way to approach it.

Josh Harrington:
Exactly. Eventually things like MFA just become part of everyday life. At first there’s friction, but over time it becomes normal because people understand it’s necessary to stay secure.

Rory Meikle:
What advice would you give to analysts or lower-level IT workers just starting their careers who look at your journey and think, “I want to be like Josh”?

Josh Harrington:
I’d say life isn’t about replication; it’s about finding your own path. Learn from others, ask them where they succeeded and where they failed, but don’t try to copy them exactly. Look at your career systematically. Think about how each decision contributes to your goals. Stay curious and keep learning constantly. I’ve got books in nearly every room of my house because learning extends beyond just your industry. Volunteer, attend conferences, join Slack communities, connect with people on LinkedIn and Reddit. Growth comes from stepping outside your comfort zone.

Imposter syndrome is also part of growth. If you feel like, “Should I really be here?” that often means you’re learning and pushing yourself. I worry more when I stop feeling that way because that might mean I’m no longer growing.

Rory Meikle:
That’s such a great perspective. Security changes constantly, so if you’re not staying current, you’ll get left behind.

Josh Harrington:
Absolutely. Certifications are valuable, but you have to want to continue learning outside your normal work hours. Some of the best ideas come from outside your direct field.

Rory Meikle:
What are some things outside of work that have helped you grow?

Josh Harrington:
Take classes or explore interests that have nothing to do with cybersecurity. You don’t need to master everything, but you’ll grow your network and your perspective. Maybe you take a basket weaving class—there’s still something to learn from it. Everything in life is relationship building. I’m passionate about hockey, and now there’s hockey analytics where people combine sports and data science. That cross-disciplinary thinking creates innovation.

I also try to connect with and learn from everyone I meet. Listening is one of the most important skills you can develop. People will remember when you connect them with opportunities and relationships.

Rory Meikle:
That networking aspect is huge.

Josh Harrington:
Definitely. When you’re trying to grow, it’s less about talking about yourself and more about listening and learning from others.

Rory Meikle:
When hiring new cybersecurity employees, what stands out to you on a resume?

Josh Harrington:
Your resume needs to align with the role, but what really matters is what makes you stand out. I’m looking for technical skills, soft skills, curiosity, and evidence that someone is learning outside of work. Certifications are great, especially practical ones, but I also want to know what personal projects someone is working on. Maybe it’s a home lab, Raspberry Pi project, media server, or home automation setup. Those projects show curiosity and initiative.

I’m also interested in hearing about failures. I want to know how someone reacts under pressure, what they learned, and how they moved forward. Failing fast and learning quickly are important traits.

Rory Meikle:
That’s such a valuable point. Failure teaches more than success sometimes.

Josh Harrington:
Exactly. There are no bad stories—just lessons learned.

Rory Meikle:
Last question: what’s next for you in cybersecurity and in life?

Josh Harrington:
I’m very happy at Wattpad. I enjoy the culture, the team, and building the program there. Long term, I’m interested in lending my experience to multiple organizations, maybe eventually building my own consultancy. Outside of work, I just got scuba certified because why not? Maybe flying planes is next. You only get one life, so have fun with it.

I’m also a huge fan of Audible and continual learning. One recommendation I always give people is Brené Brown’s lecture on The Power of Vulnerability. Vulnerability is important because it reminds us we don’t know everything and that’s okay.

I also recently attended RSA and joined the ISSA Cyber Executive Forum after meeting Candy Alexander, the international president of ISSA. Maybe I’ll even start a chapter in Toronto. It’s all about continual growth and taking on a little more than you’re comfortable with.

Rory Meikle:
I think that’s the perfect message to leave people with: continue to grow and continue to learn.

Josh Harrington:
Absolutely. And pay it forward. Reach out to me on LinkedIn if you need mentorship or have questions. Be vulnerable, ask questions, continue to grow, and that’s where you’ll find success.

Rory Meikle:
That’s the perfect way to close this out. Josh, it’s been a pleasure chatting with you.

Josh Harrington:
Likewise. I’m happy to come back anytime and talk about whatever’s current in the industry.

Rory Meikle:
I’ve had a great time and learned a lot. Thank you again for taking the time out of your day, and I look forward to connecting again soon.

Josh Harrington:
Appreciate that, Rory. Thanks.

Rory Meikle:
All right, thank you.

To learn more about Josh visit LinkedIn

Check out the other episodes in Season 7:

Ep. 0 Bonus: What is Ransomware?

Ep. 1 Ron Eddings – Cybersecurity Advocate, Creative Director, Podcast Executive 

Ep. 2 Josh Harrington – Director of Security at Wattpad

Ep. 3 Joshua Brown- H&R Block, Zero Trust, and Cyber Culture

Ep. 4 Dallas Baker – Veteran to Cyber Professional

Ep. 5 Paul Hamman – Stepping Out of Your Comfort Zone

Ep. 6 Karim Hijazi – Prevailion, Entrepreneurship, and The Introverted Iconoclast

Ep. 7 Rafael Nunez – Mentor, Motivational Speaker, and Veteran

Ep. 8 Brian Haugli – Roe v Wade, Data, and Understanding Controls

Ep. 9 Greg Edwards – Canauri, Failure, and Ransomware

Ep. 10 Ranbir Bhutani – CyberCulture, Myth Busting, and Zero Trust

Josh Harrington's profile picture for Dark Rhiino Security's Security Confidential podcast

Josh is a CISSP, CCSP-certified Director of IT and Security at Wattpad.

He has a degree in Information Technology with a specialization in Networking and IT Security and a minor in operations management.

With nearly a decade of cyber and IT-related experience, Josh has utilized his knowledge of industry threats and emerging technologies to guide businesses in advisory roles from implementation to leadership development both internationally and in the Greater Toronto Area.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top