Dlaine Miley, Mercury Financial | Qualys QSC22
Dlaine Miley, senior cloud security engineer at Mercury Financial, joins Alan Shimel at Qualys Security Conference 2022 to speak about methods that drive compliance and remediation efficiency.
Transcript
This is texturong TV. Hey everyone. We're back here live at the Venetian for koalas's QSC 2022.
It's always one of my favorite events to do because you get to meet real security people and not just people who I'm interviewing. But even if you look behind as there are people standing around, you know, what we miss this where we were all working from home. You can't do this for truly.
So it's nice. It's nice to be back. It's nice here security people talking.
Of security. Let me introduce you to my next guest. I'm gonna put on my glasses so I don't miss this up.
It's delaying Miley. That's correct. Okay, and Elaine is with Mercury financial.
And before we get into the great presentation. She's doing in her case study. I'm gonna ask Elaine to tell us a little bit about herself and Mercury Financial.
Sure, so, my name is Dylan Miley. I'm a senior class security engineer with Mercury. I've been in the security industry.
I guess just a little over five years now, and I've been at Mercury for about three. So Mercury Financial is a Fintech company really really focused on being an inclusive fintech company. That is our goal.
So we were founded in 2013 and our whole goal is about helping everyday Americans build better credit so they can have a better life. It's fantastic and you know what in case anyone's interested website for mercury. com.
We are based out of Austin, Texas. We also have an office in Delaware as well. Beautiful Watson's a great town.
Love it. Uh-huh. so that's interesting and you know what Finn Texas such a Hotbed of innovation absolutely.
It is great stuff coming out of here. You mind if I ask you a couple personal questions too personal? So senior Cloud security engineer.
How did you get into this? Kind of by accident. I mean I grew up a generation that you know, we were just kind of around Tech forever.
It never really was something I kind of thought I could make a career until I kind of stumbled upon it in college and found out that security was a thing, you know something that I can make a career and it was it was a way that I found that I could make a hobby into an actual profession, which was very exciting and it's it's very much worked out because you know, when you're passionate about something it just makes it easier to do your job every day and I love that. It's such a an ever-changing industry. There's there's always something new to learn.
There's always something new to discover and it's just I love it. You're preaching through the night. I've been insecurity.
I'm ashamed to tell you how old I am but I've been insecurity about more than 25 years and like you got into it quite by accident. And they didn't have it in college when I went College. But we did get into security one of the most common questions I get more from my kids.
And their friends that my kids but their friends they've taken security classes in college. They're interested in a career in cyber. Where do you start?
How do you can't get that first job? Because every first job once you have experience. Well, I have no experience, but I did take some classes.
Advice for everyone out here. How how would you get how would you get it stuff? I will say I was just having a conversation with a friend about this the other day and it is hard because it's you know, there's so many jobs that I could get on a whole soapbox about this because I think it is kind of a problem with the industry of expecting too much experience from entry level folks right now, especially when so much of it is not any formal setting, you know, My degree was management information systems with a focus and security but it wasn't.
You know a bachelor's in cybersecurity. That's right. There's more of those now, but it's still not super common.
And so really it's just a matter of Poking around and everything you can find something you enjoy. I mean for me it was a building a home media server on a Raspberry Pi because I was bored and it looked like a fun tool, you know, and from that I realized I was learning more about command line stuff and from you know, then you can apply that to all different kinds of tools. And so I think it's really Just find something you're interested in and just start poking around in it, really and and just find something that you can have fun with whether that's you know, some of the websites was like hack this box or things like that that are just out there for people to use.
Yeah, and from there. I think it's a matter of playing everywhere you can and and find Find a culture that you work with that was I got lucky with that at Mercury that you know, our a lot of our hiring is as much more about can you work with our team, you know, as long as you are an intelligent individual we can teach you what you need to know, but do you work well enough with us that we can teach you that so be teachable. That's the key right there too.
No coachable. Yeah, and that that's true true and security you attack. It's true in life.
Right being coachable is is a huge thing, you know the nice thing about working in a fintech like like Mercury Financial is you don't have a lot of legacy. old stuff there's a lot that you know, they're kind of born in the cloud. So a certain degree so you get to work not in a green field, but in a newer environment where you could take advantage of, you know, some of the Newer technologies that you have available to you.
You're speaking here at USC and I want to get this right. So I'm putting up harnessing self-service and risk prioritization to drive compliance and Remediation efficiency. So look, I founded a company that came out with a vulnerability manager in 2003.
Okay. We've been fighting this fight. Oh, yeah.
Philippe corteau the founder of koalas was a contemporary of my he was fighting this fight. We've been fighting it as an industry. right the ability not only to find a vulnerability but to patch it the ability to automate patching.
I keep thinking this is the year right where we're really gonna automate it, you know compliance kind of really came on and like maybe 2005 2007 where we started doing. Clients instead of security in many cases now it it's kind of found its equilibrium. I think but talk to me.
What do you know in your talk? What are you gonna talk about? Maybe some best practices some some good things share it with our audience.
Yeah. Sure. So, um, well you talk about, you know us being a fintech and so we were we were found in 2013, you know, we're just now coming up on the 10 year mark, but but even so it's weird to say that a company that's less than 10 years old could have Legacy systems.
But we you know, we everyone has started like 10 years of tech is a lifetime compared to most Industries. But even with that our entire Focus has been AWS, you know, so we're Cloud native and that has been a huge huge win for us, you know in so many ways and a lot of that is with looking at things like vulnerabilities and risk and I think you make a good point of, you know going from patching to compliance to like and how they work together. So my background I started my career as a consultant at PWC.
So I have a little bit more of that kind of, you know, grc-esque mindset when looking at this and so that's kind of what I want to Really hit on that's kind of the plan with with really the talk is really looking at. How can we take these this raw data that's coming out of koalas. How can we take the numbers on the patches that we've got and the vulnerabilities and what we're doing with that and then how do you apply a risk lens to that to really decide?
Okay, you know where do I focus here who is focusing on what that's really important with the self-service part of things. You know, we have I believe I kind of six different teams that are in qualify for different purposes on you know, most of them a daily basis and so being able to really tailor, you know, the different parts of the tool and different, you know reports and such to those different teams is huge. But then it's a matter of you've got all this data.
What do you do with it and being able to context you alive it? Partially for a you know remediation plan. So, okay.
What is what is more important to me? What is you know what what should I patch first? But then also taking that to an executive level and saying, you know, this is what our This is what our raw Tech looks like and then this is how that translates to risk and to business decisions that need to be made.
So that is That that's another thing you find it security right is I for instance an RSA conference one year I once was on a panel of what metrics do we show the exact team sea level and the board? level, you know and there was someone on the On the panel who flat out said well, you got a dumb it down and that kind of funny when you think about it, right but you don't have to dumb it down. But how do we translate security speak to business speak?
And and when should we do because I'm also the opinion that sometimes security people have to learn a little business speak, right? It goes both ways. Absolutely two-way street.
So what advice do you have for people? Oh gosh. Okay.
So I think this could go into another potential soap box of data visualization, which is another love of mine. So and and part of the reason I say that is is because I think visualizing your data and visualizing things like risk or you know, like a risk scores within vulnerabilities for example is Kind of an easy way to translate information if someone you know, just seeing numbers on a page. Okay, what does that mean?
But then if you can, you know visualize it in a way that makes sense, you know, like all the koalas dashboards that are offered but and and the reason I say that shout out Dr. Trip from Baylor, I took of data visualization class and he started class by saying data visualization could have changed the outcome of the Challenger explosion and here is why and that has stuck with me. And so I I it's amazing and so I I kind of take that approach to things when I'm trying to think of how can I translate something because translating things and words from business to Tech Sometimes even if you know sometimes even the same words mean different team different things depending on which teams you're talking to but if you can display it in a way that is easy to see and easy to understand that goes such a long way.
Absolutely. Yeah, you know you mentioned and look I'm not an expert on the qualis product. But I know my way around it pretty well from being in the industry.
One of the things they have with their dashboards is different views for who you are exactly in an industry. You want to be a met. You're a manager you're direct, you know, a higher your practitioner, you know, they give you views that are relevant to you.
how do you Now, of course, it's all about how you dial in the dials, right? In your position, right? You're at you're at that border, right?
Which would the translation happening? Struggle with it. Is it something you kind of have kind of got down at this point?
I like to think I do but there's always room for improvement. And I I think it just it's it's something that kind of comes with practice and and understanding your environment because it's also different kind of depending on who you're talking to. I mean that was something I worked within, you know, the Consulting spaces you're dealing with a different client sometimes every week and so you have to learn how to translate that.
To the people that you're talking to for them to understand. I've been at Mercury long enough now it's a little easier because I know you know what our board and what our Executives can do it, you know expect so it's it's kind of a little easier to translate that and knowing their their understanding of the tech that we're you know describing but It's I don't think it's an easy task at all. I think it's something that requires constant, you know or refinement.
Yeah, and then, you know your line of business you have another. Kid another constituency to please and that's auditors. Right, and that's a whole.
Whole different language talk about that a little bit. Yeah, that's audits are we're finishing up our PCI audit right now. So we are we are right in the middle of that.
I let our PCI audit for a couple years. So I'm very familiar with that realm and That's another it's another translation because it's you know, okay, you're you're taking something and showing it to Executives to explain, you know, how they can make business decisions on it. But then you have to take that same data set and show it to your auditor and explain to them.
You know, I mean, yes, of course your auditor should know the tool and you should know, you know, the would you Basics yes should but you know with that you you need to still explain to them how it works within your environment. And that's another thing that we use qualify for every year is you know, it's for one hour the PCI scans, you know, that's huge for us having to you know, display that but then also, you know having the data to show will this is how we're actually using this in our vulnerability Management program. Excellent.
So look, we're not here to do a commercial necessarily for college. But so it sounds like koalas is giving you the ability though to really Pivot, you know, no pivot tables. I'm staying away from that but you know to Pivot the views and and and slice the information to the audience that you need to to present to.
Listen. If you want to talk pivot tables, then we're in Excel and that's completely language so we can get there. Yeah.
No. No, it's like garlic to vampires to me. I can't do that.
Then we won't go there. But yeah, and it's you know, it's interesting. I think when I kind of first Really started getting into the industry.
It was okay, you know vulnerability scanners or that just that they're just a scanner and so it's been interesting to see how yes. Koalas, but also just the Technologies overall have kind of evolved to okay now, we're not just scanning now. 0 is continuous compliance, you know and and having an agent that's constantly keeping up with that and to things like automating patching, you know, so it's okay.
We found the vulnerability we'll now what do we do with that and the fact that We're getting to a point. We just had a talk this morning with Robert Herjavec. I'm sure I butchered that but I know who you yes, they do too.
He made a point about the technology is becoming more commoditized and that it's going to be more about context and I I think it's really true that you see that in just how many Technologies there are out there of either so much that you can automate but it's still a question of okay, but what do you do with that? And how do you use that to improve your security posture? Absolutely, you know.
a lesson I learned and it's as relevant today as it was then was just because you can do something doesn't mean you should absolutely and you know when it comes to automation, especially we really do we need to say can we yes should we? I'm not sure. Yeah, and and you know, you got to be smart about that.
But you're right, you know technology is ubiquitous. That vulnerability scanning quite frankly. I mean I come from World War.
We used to have to convince people to scan once a year. com about eight years ago. And that was one of the reasons, you know, I felt it would be great for security.
But I also knew that devops brought this whole idea of continuous integration continuous delivery continue. It's everything and security had to get with that program. Absolutely.
We're gonna keep up with because things move too fast. You can't you can't have points in Time stuff and just doesn't work. Well the animation gets tough too because it's you don't want to break anything.
You don't want to break this process. Absolutely and I think it's been nice to see and I kind of an approach we tend to take Things is okay if I can automate. The actual work, but I'm going to choose when to push that automation, you know, so there still has to be kind of a person pushing the button.
Much as in devops. They had to be a person doing. Okay deploy.
Now pushing a button to play was a lot easier than what we used to have to do. Exactly. And that's where I think we need to be in security as well.
Yeah, really? Thank you so much for being with us today. com.
Yes the website good luck on your presentation. We're gonna watching and keep up and you know what? Five years in the industry.
She did it you can't too so probably you out there. There's plenty of jobs and security. Thank you.
Thank you. All right. We'll be back in a moment here in Vegas.





