Jay White, Microsoft | OSS North America 2023
Join Mike Vizard in an interview with Jay White, Security Principal Program Manager at Microsoft, as they discuss the challenges and importance of diversity and inclusion in the cybersecurity field within the context of the Open Source Security Foundation. Jay sheds light on the difficulties faced in getting individuals from diverse backgrounds involved in cybersecurity, emphasizing the need for increased awareness and access to organizations like the Open Source Security Foundation and the Linux Foundation.
Transcript
This is Techstrong tv. Hello, and welcome back to the Open Source Summit in Vancouver. We're here with Jay White, who works with Microsoft, but is working on diversity and inclusion for the Open Source Security Foundation, which is a big job and, and a significant challenge these days.
Jay, welcome to the show. Oh, Thank you very much, Mike. Thanks for having me.
Diversity and inclusion's been an issue just about everywhere we go in it, but what makes it more difficult to get folks involved from different backgrounds in cybersecurity? Uh, Well, that's a great question. So the difficulty really lies in, uh, first of all, being aware that the open places like the Open Source Security Foundation exist, um, and individuals from underrepresented communities don't have that knowledge.
They don't know that the Open Source Security Foundation exists. Didn't even know the Linux Foundation exists. Um, and then, uh, what's even more, um, what's even more astonishing about this is that these individuals are inside of our HBCUs.
They're inside of our, our, our, uh, no Hispanic universities as well. They're inside and, and sometimes they're inside of even our, our most, uh, prestigious universities across the board. They don't know that these open source communities exist, and they don't know that they're, that they are avenues to get into cybersecurity.
Everyone thinks that you want to get into one of the big name organizations, you know, like, like First is Microsoft and, and the Amazons and the Googles, and they say, well, that's our way in. But they don't know that you can get in sooner than that. Mm-hmm.
Through being contributors to open source projects, um, you can learn more development wise in these communities as well. Um, so one of the biggest initiatives we have inside of the Open ssf and inside of the de and I, uh, special interest group under the education, um, sig, under the best Practices working group, um, is outreach, right? Mm-hmm.
And, uh, and being a, a vehicle for getting that information out, uh, to those individuals and those underrepresented communities to know that, hey, you can get into cyber this way and then create the network you need to have because, you know, it's not what you know necessarily for who you know, um, to help propel your careers. Aren't we a little too obsessed with people who have four year college degrees and we need folks who can just have a certain understanding of how software works and might have an knack for it. You know, what just had, uh, this conver just say this conversation in a talk I gave yesterday, um, being a person with a PhD, right?
Um, I went the long way and I'm talking about certifications and education, everything else because my understanding, especially being from uh, underrepresented communities, is that I have to be three times, uh, more than the average person applying for the same position to get into these organizations, right? Um, so that's the route I went. Having gone that route and having been in these roles now and looking at the problems that we're having, finding good talent, you have to realize that positions are no longer static in nature.
They're dynamic in nature and the dynamics around these positions live where it's not just be a coder, it's not just have an understanding of supply chain, but now it's having an understanding of how to be a good coder within the right supply chain, understanding C I C D pipelines, how to secure them effectively, how to inventory them, and having to know what happens on one end of the chain and on the other end of the chain, which takes a level of dynamics that's seen today that wasn't seen yesterday. Those individuals don't have degrees that know that, right? Mm-hmm.
And, and I'll, I'll, I'll take a step back and, and, and, and take a step back from that for a second and say the, the good majority of them are sitting in their homes, learn this stuff themselves. The classroom is not teaching that effectively enough, but they're learning it, and we're not targeting those individuals and saying, Hey, those individuals need to come in and teach us something. Mm-hmm.
Right? So, yeah, To your point, DevOps, I don't think I can name a few colleges that have an actual DevOps program. It's much more of something that is taught from the ground up with a hard one experience, right?
Absolutely right. You, you, you hit the nail on the head. And these programs in school are very static in nature.
I have a colleague of mine, um, that's getting ready to stand up a, a class, uh, at Carnegie Mellon dynamic. So dynamic that, that he's teaching very real world understanding, uh, of, of software engineering from a perspective of community building, from a perspective of nonprofits, from a perspective of what really happens during the development process towards a viable solution that you don't see, uh, organically amongst different programs even in the most prestigious institutions. Why is Microsoft keen about this particular project?
Is it just that there's so many positions to fill and they have a vested interest, or are they, is there some other incentive from them? Um, you know, Microsoft wants to do things in for the, for the greater good, not just of, of Microsoft. I mean, the, the mission itself is empowering everyone and every organization, uh, to, to do, to do more, right?
So the empowerment piece to that is making sure across humanity, that, that we're positioning everyone to do their best work. And that can only be done through diverse thought, inclusivity of everyone involved, and then an equitable, uh, situation where everyone has the same access to the same resources. Um, that can't happen effectively in a silo.
So it can't be siloed to Microsoft. We have to reach out to other organizations. We have to partner and collaborate, um, through organizations like the Open ssf, uh, to make sure that we achieve that, that vision of bringing people in, but also helping people find their place even outside to be effective collaborators towards our, our very similar objectives and, and solving our very similar issues and concerns.
What do we need to do to improve the outreach? Cuz people would go, well, there's an imbalance in the supply and the demand, and eventually they'll be a rebalancing as people become aware of that and, you know, the economy will naturally take care of that. I think we've been waiting on that now for 10 years or so in cybersecurity space, but what does it take to kind of get more people involved?
What does that conversation look like? You know what allyship, true allyship, um, it's not enough for somebody from an underrepresented community like me to say, Hey, we need you to go out and say, look, come in the water's warm. It's not enough for me to do that in my community.
I can do that. I could be living proof that you can, that you can enter in this field. But I didn't come into this space through somebody reaching out to me.
I came into this space getting ready to retire from the military, uh, and saying, well, I want to do something that's going to give me a paycheck when I'm done. When I started in it in tech, you know, this was 20 something years ago, and it was because I saw that as an avenue to make money. I didn't see it as something that I, I, I had a keen and and passion about.
I developed that over time, but no one guided me to that. I just read the tea leaves. The problem is we need more people to guide, and I can reach out, but it takes true allyship to get that message out even further so that my reach is further.
See, I can reach out, but my reach needs to be further. So I need allyship to do that, and that means that people from represented communities need to provide me the space, provide me the resources to further reach, right? And then that, and that way I can increase the outreach and everything else we're talking about here.
So much of what we do is dependent upon a happy accident. Myself. I answered the wrong ad in the New York Times 30 years ago, and here I am.
Absolutely. And I like the happy accident. Absolutely.
That's where we can characterize my whole existence As a happy accident. Jesus. Um, as you think it through for a minute, are the people who are involved in education not actually kind of helping, they're not really painting the picture for how to get from point A where they are in the classroom to something that looks like an actual career.
I feel like a lot of times the academics are teaching, uh, theory, but you know, that's, and then they give you a, a degree or a certificate and then you're out the door and there's no what now? So there's a couple of, uh, couple of issues there, and I, and I, I'll start with, um, you know, one, it's more individuals who earn degrees don't necessarily end up doing what they earn their degree in. So where does that start?
That starts with the mentorship and guidance on what kind of degrees of individuals should be pursuing, right? There's not enough conversation around what someone's passionate about. Uh, moreover, what somebody, you know, you have a, I wanna do this.
Well, is that what you're really passionate about? No, but I think it would be cool to do. Mm-hmm.
What are you passionate about? What do you want to end up doing? There's not enough patience given, uh, to people to help them decide which way they want to go.
And then, then the other end of that coin is on the other end of things with the educator, there's not enough people saying thank you. Um, when I say there's not enough people saying thank you, there's something that can be said about an educator really understanding the impact they've had from an individual who reaches back and says, thank you for A, B, and C. Then that educator can say, well, that worked, and then they can replicate it, and then they can prove upon it and make it better.
Those are metrics as well. You can't improve upon what you do without having a clear understanding of what those success indicators are. So there's not enough people going back to say, thank you and thank you for this, this, this, because through this I was able to do this.
Then the educator can better design, uh, their curriculums, can better design their plans even inside of a curriculum already given to them. They can take that curriculum and provide better direction and guidance within themselves and then in their sphere to replicate that. Thank you.
10 times fold, right? So before they hit me up for the alumni check, they should say, Hey, you want to come talk to some of your old teachers and then I'll give 'em the alumni check? Absolutely.
Absolutely. Where are they now? I was supposed to ask, as we play around with some of the notions that go on your ex-military mm-hmm.
There's a lot of structure and discipline in the military, shall we say. Does that lend itself to cybersecurity in some ways? Uh, yes and no.
Right? So yes, because to keep your eye foc keep your focus, keep your discipline, keep your eye on the ball. Um, the, the, the things that I used to do in the military lend themselves from a security standpoint, just being constantly vigilant.
Uh, some of us call each other bank robbers, you know, learn learning what the, what the adversary, understanding what the adversarial do. So now you know how to mitigate, right? Um, but then the other ends a a no, because it, because there's a, there's a beautiful, uh, art to, uh, to cybersecurity.
It's a beautiful art to information security in general. Um, knowing that information security is a business functions, not technology functions, a business function, information security in that art form. Every industry, every organization in that industry, every business unit in that organization, in that industry has a different security posture.
Are you finding everything Unique? The structure looks different. The way you put different policies and pieces, the way you enforce them looks a little different, right?
So there's a beauty in that. Um, The military will teach you structure to teach you discipline, give you a foundation of rigidity. What I like to call is the, the, the, the, the messy middle.
As long as you develop your bookends, right? And the military gave me the bookends. Bookends are solid, the structure's solid.
The middle can be as messy as it wants to be. There's, I think there was a book that was written, a book, the book that wrote this, I can't remember. I, I can't remember.
But the, but the, the, the messy can be as middle as the, the middle can be as messy as it wants to be. Long as those bookends and those structures solid, right? You have an organization point, you have an orientation point, right?
And I think that's what the military allowed me to do, but I had to provide my own. And this comes through experience and time to understand the creativity that lives here in the middle. Are you at all worried that it seems like the attackers are better organized than the defenders these days?
So, you know, do we need to kind of look at the playbooks and say, Hey, the other guys, the adversaries are getting a lot better at their game and maybe we gotta up our game. Uh, I'm not sure if they're a little bit better. I say they have more time.
Right? There, there was a, there was a, so I watched, um, over the last couple of years, you know, and of course being from the military, I pay attention to this stuff as a matter of fact, having served in that environment, right? So it's a, you know, when we left Afghanistan, and I recall, uh, one of the quotes from, from the adversaries at that point said, well, you got the watch, but we got the time, right?
Mm-hmm. So I, I look at the cyber game like that, right? Yeah.
Us, um, defenders, we have the watch, right? But the threat actors, they have the time, right? They can, they got, they can research whatever they need to research.
They can organize whatever systems they want to organize, get their groups together and do all that kind of stuff. And when they're ready attack, we have to sit there and watch and wait, right? Not that they're better, it's just that, that we're watching and waiting for something to occur that we may not necessarily know yet.
Right? So you don, you're talking about known versus unknown threats and vulnerabilities, right? We don't know what we don't know until we know it, they are, on the other hand, they don't care what we know it, what we don't know.
They're just researching and doing and collecting and, and, and, and taking their time to do whatever they need to do. And As one ex-military fellas said to enemy, it's a lot easier to throw grenades than it is the catch em Abso Absolutely. Absolutely.
Um, Everybody and his brother is talking about ai and we're talking about asking people to enter this security field. So do you think that this is a good field to still enter, or will AI take all up a lot of these functions and tasks and you know, what, what do you think ultimately is gonna be the impact? Um, so I think what we all, uh, should remember is that your, your, your ai uh, your AI system is built, uh, configured and developed by an individual.
And the large language models, as wonderful as they are, uh, they're still fallible, um, through that human input and through human error, as long as human error is an element, there'll always be room for a cyber professional who's willing to be creative enough, um, to address a lot of these emerging continuous, that's, this is a beauty of, of information security. The beauty of cybersecurity in general, being able to embrace the suck that is emerging risk, emerging threat. And I say the suck.
That is because you, you have to continuously, uh, get creative, expand your mind on what could occur, not what, well, not what's already occurring, but what could occur as a result. And then you have to get creative with things that happen in aggregate. You gotta be able to read the tea leaves, right?
Which gets incre, which gets incredibly hard, but that also comes through time and experience. There's always gonna be room for more individuals because of that. Yes.
For folks that wanna maybe explore cybersecurity as a career, where do they find you? Where do they start? Absolutely.
Um, well, Jay White, you know, you find, you find me, find me in most places, but come to the open Ssf, right? I'm all over the place in the open ssf. So as soon as you, uh, join the open ssf, as soon as you join any working group, wait a second, I'll show up.
Just, just give it a second. I'll show up. Uh, find me there.
Um, you know, come in the water's warm. Yeah. All right.
You heard it here, folks. Jay's watching, he's watching for you. Come help him out.
Jay, thanks for being on the show. Hey, thank you very much. All right.
And we'll be back in a minute.





