Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Your Ad Here: Helping your organization build t...

Leif
August 09, 2023
67

Your Ad Here: Helping your organization build their security brand

Have you ever read a blog, listened to a podcast, or watched a conference talk and thought “I’d like to be able to do that someday?”

Are you a security leader that wants to help your team share their amazing work with the community but isn’t sure how to get started?

Maybe you’re one of the few people at your company that presents at conferences and want to help others?

If you want to help transform your security team’s public persona, this talk is for you!

In this presentation we’ll cover:

- The benefits of having a team that’s engaged with the community
- Tips for helping others write blogs and speak at events
- How to create a culture at your company where folks are encouraged and rewarded for presenting their work
- How to promote your team’s work to extend its reach

Leif

August 09, 2023
Tweet

Transcript

  1. About Me 🍃 Leif Dreizler Present • Senior Eng Manager

    @ Semgrep • Co-host of “404: Security not found” • Conference organizer for LocoMocoSec • Start-up investor & advisor Past • Senior EM, Security Features @ Twilio Segment • Chapter Leader for OWASP Bay Area • Conference organizer for AppSec California @leifdreizler @404pod
  2. About Me 󰣺 Present • Start-up advisory (& chump-change investor)

    • Keynote and conference speaker, podcaster Past • Practitioner for 19 years • CISO at Segment and Twilio • Keynotes: Global Appsec DC, LocoMocoSec @coleencoolidge (dm me for startup advisory help) Coleen Coolidge
  3. What we’ll talk about • The benefits of having a

    team that’s engaged with the community • Creating and reinforcing a culture where you are rewarded for this • How to promote your team’s work and extend its reach • How-to: Tips for writing blogs and speaking at event <link to slides>
  4. Disclaimer! • This is by no means required to have

    a successful career • Some people in InfoSec have great careers and never do any of this • There are plenty of good reasons not to share your work publicly • However, if you’re able to do this, you’ll reap tons of rewards…
  5. Create the culture: Leaders need to do some work first

    • Lead the speaking and writing effort; then lead the 📣 📣 📣 • Update job ladders and career dev plans; come for the “hiders” Infosec Leaders Infosec Team
  6. Create the culture: Leaders need to do some work first

    • Lead the speaking and writing effort; then lead the 📣 of others • Update your job ladders and career dev plans; come for the “hiders”
  7. Create the culture: Rewards • Reward communications & leadership results

    with promos, raises, stock, etc. • Proudly shout-out the work that helps us jump ahead in our roadmap ⭐
  8. Are you an IC who is struggling to get traction?

    • Engineering not excited to work on your tickets, or talk to you? 😬 • Are you struggling to move up the ladder at work? 💥🪜 • The common denominator could be you… so 🤒 • Lean into Communication & Leadership to help you bulldoze ftw! 🚜🏆
  9. Are you an IC who is struggling to get traction?

    • Engineering not excited to work on your tickets, or talk to you? 😬 • Are you struggling to move up the ladder at work? 💥🪜 • The common denominator could be you… so 🤒 • Lean into Communication & Leadership to help you bulldoze ftw! 🚜🏆
  10. Benefits ICs can expect • You tricked engineering into doing

    some of your work 😜 • Your promo packet just got easier to write 💰 • The common denominator is you crushing it with Comms & Leadership 📣󰘽
  11. Tracking • Originally, we were self-motivated, posting updates in a

    confluence doc • Semi-automated v2 super edition, powered by Discernible • https://discernibleinc.com/contact
  12. • First ask your team to post • Send the

    links to your friends in the industry • Post in industry Slack/Discord/etc. groups • Sites like Hacker News The power of social
  13. Outline -> ??? -> Profit (Leif) • Outline -> Blog

    • Outline -> Conference CFP submission • Blog -> Podcast • Blog -> Meetup or conference presentation
  14. Tips for outlining • Write everything down • Don’t get

    bogged down by structure or organization • It’s okay if outlining takes weeks or months
  15. Idk what to write about • Keep a personal hype

    list • Reflect on what you’ve worked on over the last year • It does not matter if other people have written about the same topic
  16. Some blog tips • Story vs. tutorial • Introduce yourself,

    the problem, and your world • Make the reader feel your pain
  17. Why podcasts? • Easy-mode presentation with less prep • Podcasters

    desperately need content • Low risk of messing up!
  18. Title • Straightforward and descriptive ◦ “How to build a

    security team and program” • Fun and descriptive ◦ “A hipster history of CORS” • The two-parter ◦ “Your Ad Here: Helping your organization build their security brand”
  19. Title formats to avoid • Anything that is super played

    out • Any sort of sexual pun or innuendo in your title 🏻
  20. About you • Professional history • Some interesting things you’ve

    worked on • Events you’ve spoken at? • A fun fact about yourself? • Links to past podcasts/conference talks?
  21. Abstract • Short enough that people read it • Not

    so short they have no idea what you’re going to talk about • Succinct, yet thorough
  22. Outline • Write your outline first • Outlines are not

    typically shared with attendees • Outlines show reviewers you’ve thought about the topic • Appropriate length is important
  23. Meetup talks tips - the Tall • Easy to get

    accepted • Wide variety of accessible topics; length is between 5-45 minutes • Tone is informal, audience is 😌, emphasis is “just share stuff”
  24. Possible meetup/conference ideas • Security tool or new process •

    Educational • Predictive or inspirational
  25. Conference talks tips - the Grande • A bit harder

    to get accepted (use the tips!) • Wide variety of accessible topics; length is between 25-45 mins • Tone is informal; audience came to learn from you (and/or stan you) Who doesn’t love a good Parks and Rec reference?
  26. Keynotes tips: the Venti • Harder to get accepted •

    Wide variety of accessible topics; length is generally between 25-45 mins • Tone is semi-formal; audience is all types • You’re going to worry and dither more - CHILL OUT From iStock
  27. Closing • Help your recruiters! • Grow your team’s careers

    and track your work • All things start with an outline • Abstract and title - attention grabbing, informative and not creepy • Use your network to promote your team’s work • All talks are basically the same; so relax - you got this!