Episode 560 ·
Discovering Java's Full Potential with Erik Costlow, Senior Director of Product Management at Azul
Today we’re talking to Erik Costlow, Senior Director of Product Management at Azul; and we discuss the art of being a good product manager; how focusing on Java gave Erik a professional advantage; and how Java is being utilized to its full potential today.
All of this right here, right now, on the Modern CTO Podcast!
Check out more of Erik and Azul at https://www.azul.com/!

About Erik Costlow:
Erik Costlow is a software security expert with extensive Java experience. He handles the security of Azul's JVMs that operate at peak speed while making security easier and better for all. Erik was the principal product manager in Oracle focused on security of Java 8, joining at the height of hacks and departing after a two-year absence of zero-day vulnerabilities. During that time, he learned the details of Java at both a corporate/commercial and community level. He also assisted Turbonomic's product management team in the data center/cloud performance automation. Erik also lead product management for Fortify static code analyzer, a tool that helps developers find and fix vulnerabilities in custom source code. Erik has also published several developer courses through Packt Publishing on data analysis, statistics, and cryptography.
About Azul:
Azul is the only company 100% focused on Java, delivering the most trusted Java platform to the modern cloud enterprise. We provide the world’s best commercial support for OpenJDK to our customers by prioritizing their success, maintaining our unwavering commitment to innovation and excellence, and advancing Java through community leadership.
Millions of Java developers, hundreds of millions of devices, and the world’s most highly regarded businesses - including 27% of the Fortune 100 - trust Azul to power their applications with exceptional capabilities, performance, security, value, and success.
Transcript
(Intro Narrator at 00:00:01) Today, we're talking to Eric from Azul all about Java and the art of product management. You're listening to the Modern CTO podcast.
(Joel Beasley at 00:00:14) Have you been hosting a podcast for a while? I know you said you did one with Java, right?
(Eric at 00:00:19) Yeah. So some friends of mine and I, we just kind of started one during the pandemic because that's what a couple of us did. So we hosted a couple of them. They're Java focused. So what we do is we kind of pick a general topic that we want to talk about. We get a couple people who know that topic pretty well, and we try to get most of them to be in Java, but one of them to be outside of Java so that we get that outside perspective. And then the intro, you don't want people to give a two-minute bio of themselves, but it's like, who are you? You know, what's your kind of key qualification, and why does it pertain to this topic?
(Joel Beasley at 00:00:55) I'm going to ask you that question. Who are you? What's your key qualification? And how does it pertain to talking about Java?
(Eric at 00:01:03) Sure. I'm Eric. I've been doing application security for actually over a decade now. And, you know, whereas a lot of people deal with the CISO of managing an organization, my focus is specifically on how to attack Java systems. So I got my start in, you know, I did a lot of development, so I wrote applications, and then I just knew how to break into them. I knew because of all the corners that I would cut during development, I knew I would probably build a system like this. So I went into security consulting, did some static code analysis to find security vulnerabilities. And if you remember back like 2013-ish, there were a lot of flaws in Java itself. And so sitting out in California in the Bay Area, I just thought to myself, boy, if I know security like I think I do, I can go deal with it in the Java platform. So that was the time I went and I joined Oracle and helped secure Java 8. So it went from kind of, I don't want to say it was the laughingstock of the industry, but it was just not a great thing at that time period because security was important. And, you know, since leaving them, I've done just a lot of security with different applications, talking with people who need to secure their applications, and it all runs on Java. And now I'm working on Azul, who produces a JVM itself.
(Joel Beasley at 00:02:23) Yeah. And so the main purpose of Azul, how do you explain that?
(Eric at 00:02:27) Yeah. So over time, there's a lot of different versions of Java. Like, there's a Java 7, there's a Java 8, there's a Java 9, and they really like to count, so they just kind of go up and up. There's a new one about every six months. And for a lot of companies, it's really difficult to make that migration to go from like 8 to 9 to 10 to 11, all the way up to 19. So they want to keep their applications on the older versions, and they also need them to run really fast because the fast stuff tends to go on the newer things because the newer things are more fun to work on. So what Azul does is we provide a JVM that's really fast, and also we provide security updates to those older JVMs that everybody has.
(Joel Beasley at 00:03:07) That's pretty cool. And were you part of like the founding team, or did you come in later?
(Eric at 00:03:12) No, I wasn't part of the founding team. The company's been around for about 20 years or so, so I wasn't really eligible to be around for the founding team. But just it's a lot of people that I've known throughout the years. They're pretty active in the Java world. So I've just run into them over the years.
(Joel Beasley at 00:03:29) Now, most of the security people I've interviewed, they were arrested by the FBI or have some sort of grandiose story about their security exploits when they were younger. Have you ever been arrested by the FBI?
(Eric at 00:03:41) No, I have never been arrested by the FBI. Yeah, the usual way that you run it is everybody who's kind of good at security, knows how to manage things, has some kind of past of stuff that they've done. So I do work with a number of people who have been, you know, they've had guns pointed at them or things, or they've been severely questioned at a time. I haven't gotten to that level, so maybe I'm just good.
(Joel Beasley at 00:04:07) There you go.
(Eric at 00:04:08) Let's say that.
(Joel Beasley at 00:04:09) Right? I like that. I got this book at Barnes & Noble when I was probably 11 or 12, and it was called Hack This Site or something like that. And it was sort of an introduction into hacking, and there was a website you could go try it on and all of this stuff. And so I got into it, and then one day I was like, okay, I'm going to try to hack my computer downstairs. Like, get into my computer downstairs through AIM. I have sisters. They're on AOL Instant Messenger. I was like, I'm going to try this. And I couldn't get it, and then I figured out how to do it. I put both computers next to each other, and I was like, how do I do this? And that taught me a lot, right? Because I was just brute forcing. I wasn't extremely educated or anything. And then I got a little bit more advanced and just picked up more and more and more things. And, you know, I think the term's like script kiddie, right? You just start using other people's scripts and other people's exploits and start to understand this. And then I took a large break from it, and I just found that I could go on ScriptLance and write people code for their projects and I could make money, and that was just an easier path for me, you know? And from there, I did that for like a decade. And then I found out after getting good at writing software for all those years that that's actually a very important part of being a good security person.
(Eric at 00:05:28) Yeah. There's all kinds of ways to break into things. So the easy one, you know, I can't maintain a knowledge of exploits of how to attack everything. So you go get the scripts of, you know, what are the example payloads that you would use to break into a certain system. And then, you know, when you know how to write the software, you can customize them should you need to. But in terms of the ability to monetize that as a career, it's way better to be on the blue team or the defenders, because ultimately, no matter how good you are, at some point all those guys get caught and then bad things happen.
(Joel Beasley at 00:06:01) And then they make movies about them and they don't get royalties either.
(Eric at 00:06:05) No, they don't. Although the guy who was the star of Catch Me If You Can, you know, the one that had Tom Hanks, he goes around to various conferences and just gives talks about what he did, and he's really interesting.
(Joel Beasley at 00:06:17) Yeah, I enjoyed that movie. And at the end, they'll actually show you the person, and they tell you where he currently lives and all of it, like the city. And I didn't know that he's going around to conferences, though. That's news to me. So he talks about it then.
(Eric at 00:06:29) Yeah. Now he's been out of prison. He's kind of a reformed guy. So he just goes around and he does consulting, and he helps people using the knowledge of how he broke into a lot of things. And as you'd expect from the movie, he's extremely intelligent. So, you know, he just shares that knowledge with everybody. And, you know, done correctly, there's a market for that.
(Joel Beasley at 00:06:51) And then for you, is your day-to-day just hacking into systems and finding exploits, or what does that look like?
(Eric at 00:06:58) No. So I'm not the guy who goes and breaks into the individual computers. I don't need to find the exploits or do all the research. Those are generally security researchers, and, you know, companies like Azul or the various security vendors, they tend to have teams of them. My responsibility, I'm product manager, so I manage things, which is I just look at the market and I say, what are the problems? How are people breaking into these systems? And then because we make a JVM, I evaluate, you know, what are the ways that a JVM would need to defend against these types of attacks.
(Joel Beasley at 00:07:31) So your official title is a product manager?
(Eric at 00:07:33) Yeah. The official title that I have is senior director of product management, which is just I have a really good understanding of what the market wants, how people need to secure their applications, and then how those applications are attacked.
(Joel Beasley at 00:07:46) When you think about the whole art, there's books, there's resources, there's courses, there's a lot of information out there about product managers. How do you describe that role and how to be good at it?
(Eric at 00:08:02) Yeah. So actually I was just talking to a friend the other day who, you know, she's looking for what her next step in a career is going to be, because she's done like some marketing, kind of developer relations work for a long time. And she says, I want to do something else that builds off this skill. So I was just saying, you know, I do product management and here's what it is. And there's almost too much information with everything now. There's books about everything. There's all kinds of videos. Everybody wants to sell you a course. But for me, I just use a chart. It's one image. It's called the Pragmatic Marketing Framework, and it just lists out all the activities that product managers can do. And basically, you take this chart and you pick about three things per quarter that you need to do really well at, because otherwise you're doing too much. And, you know, step one on the top left is this concept of what's the market problem that you're solving. And then down on the bottom right is how do you help people understand that you solve this problem. And then in between there, there's the whole concept of how do you decide what to build, who's the persona that it's for, and just how do you evaluate the requirements.
(Joel Beasley at 00:09:10) Which one is it? Is it one of these? The Pragmatic Marketing Framework. Is that any of these right here?
(Eric at 00:09:17) It's all of them.
(Joel Beasley at 00:09:18) Oh, okay. Got it. Okay. You said you pick three of these things per quarter to focus on?
(Eric at 00:09:24) Yeah. So you can only do so much in a given time. So step one is always, do I understand the market problem that I'm solving? In my case, I'm focused on helping people secure applications that they run on top of Java, so that's kind of the reason that we do anything else. And then if you look over some of these, there's distinctive competency there. That's one of the ones that I like to pay attention to because it covers the question of not what are you good at, but how are you different than other people that are good. Like, both you and I are very good English speakers, but that doesn't really set us apart from a lot of other people in the world. But what you do better than anyone else is to manage a podcast that can cover complex technical information in a way that people want to hear it. So for you, that's a distinctive competency to Modern CTO.
(Joel Beasley at 00:10:18) Nice. Thank you for the compliment. All right. So if I'm looking at this, because I don't have formal training as a product manager, I've built a lot of products, right? I spent like 17 years doing it. And of course, over the past 17 years, so many new frameworks have come out and, you know, new tactics. And like you said, there's always a new conference with a new speaker and some new way of doing things. I found really quickly, to what you were saying earlier, is that the closer you are to the customer and the problem and then the solution to it, and the more directly you achieve the solution and make it easy for the customer. That's sort of like a catch-all if you do those things really well. But when we're talking here, it looks like it goes into sort of marketing. Like, beyond just making sure that the product matches the customer's needs successfully, this looks like it goes into marketing.
(Eric at 00:11:10) Yeah. So the aim is once you build a product or once you've done the engineering work like you did for 17 years, you also had to show people that you solve this problem, and they have to be able to perceive that you solve it. Otherwise, there wasn't much benefit to actually solving it. So it's how do you get the information out there so that the other people, like the marketing teams, know what to do, the sales teams know what to sell. Because part of the aspect is without product management, there's a gap and everybody fills that gap with what they know how to do. So the marketing team will go out and say something, the engineers will go out and build something, and the sales will go out and sell something. And if you've ever had that situation where you worked on a project or, you know, the engineers built something and people look and they say that's not quite right, it doesn't solve this problem, it's because there was no kind of glue between what the customer wanted and what the market was willing to take and the requirements that got to the engineer. So a good product manager is constantly in line revising those things so that everybody has the same understanding.
(Joel Beasley at 00:12:18) Okay. So if I'm posting a job posting, right, and I'm hiring a product manager, marketing responsibilities aren't far from that. Like, they might, at a startup, handle the marketing and the product management?
(Eric at 00:12:33) You could get a hybrid like that, but ultimately the product management is kind of like a hub-and-spoke model where they're the thing that unites the other teams. Like, as an engineer, how often do you like talking to the marketing teams?
(Joel Beasley at 00:12:47) Me, personally?
(Eric at 00:12:48) Right. As a general engineer, how often do engineers want to go out there and write marketing collateral?
(Joel Beasley at 00:12:53) Almost never.
(Eric at 00:12:55) Right. So it's the product management group that kind of bridges the understanding and is like the communication translator between all the different groups.
(Joel Beasley at 00:13:03) I like it. Air traffic controlling between all the groups.
(Eric at 00:13:07) Right.
(Joel Beasley at 00:13:07) Okay. So you would go to marketing, and you would clearly articulate the problem, and then they could write copy around it and figure out graphical assets around it and all that type of stuff.
(Eric at 00:13:19) Yeah. I tend to do what I refer to as the lousy first version of a lot of decks, which gets the key message there and sets a story structure. And then some of the things that these guys can produce on marketing teams where they know how to draw images and connect items together and just tweak words a little bit. Their stuff is so much better, but now because we've worked together on the story and the polish, you end up with something really nice.
(Joel Beasley at 00:13:46) Oh, that sounds fun. Do you enjoy your job?
(Eric at 00:13:49) I think it's a lot of fun. I get to work at a really deep technical level with software runtimes that manage and let the software itself work, and then I get to go out there and communicate to people to help them get the understanding. And the reason that this is satisfying for me is that when I was just writing and building the code, I felt like I didn't understand why people wanted it or what it was supposed to do. So I like that communication aspect of, like, hey, customer, what problem does this actually solve for you?
(Joel Beasley at 00:14:18) Yeah. That's incredibly important. And so you get to go speak at conferences and communicate about this regularly?
(Eric at 00:14:25) Yeah. I do a number of conferences. I used to do significantly more of them when all the conferences were live, but they kind of quelled down with the pandemic, and now they're starting to kick up again. So I just do a lot of talks around the way. Almost all my talks are about Java security, of some ways that it's changed and what the types of modern threats are. So I just go around and I, you know, I have this nice level of credibility because I do know the Java attacks. I can actually show how they're working, explain them at a technical level, but also talk with people about why that matters to the business if they lose access to all their data.
(Joel Beasley at 00:15:01) And so being the product manager, does Azul have, are they constantly building new products, or do they have like one flagship thing? Like, how does that work? Are you maintenancing and growing existing product lines? Are you starting like brand new product lines too?
(Eric at 00:15:16) Yeah. So the Azul vulnerability detection is a new product that expands the overall market for a lot of people who run Java applications and need to make sure they're secure. Otherwise, it had kind of two main products, both of which were Java distributions that you could run and you would use them to run your applications. And the thing that people use them for is just because they were extremely fast. So it had the pauseless garbage collector.
(Eric at 00:15:41) If you've ever heard, there's an old Java joke, knock knock.
(Joel Beasley at 00:15:45) Who's there?
(Eric at 00:15:47) So as you say who's there, what you do is you pause and you drone on and you just kind of wait a little bit and you get it to the point that the other person is really frustrated waiting for the punchline and then you say Java. Right? Because the joke is it's the thing that always took a long time to start up where it would go there and it would operate and then it would have a stop-the-world garbage collection. So the role of that knock knock joke is that somebody gets frustrated because they're waiting, and then all of a sudden Java starts.
(Joel Beasley at 00:16:17) I got it. I like it. I've been a part of one Java project. Early 2000s, we were doing real estate software, and it was really difficult for the agents when they had out-of-state buyers and things of that nature. The only tools at the time were like GoToMeeting that required large software installations and complex things.
(Joel Beasley at 00:16:37) It's hard to get grandma to do that. You just want to send her a link. Right? Today, it's ubiquitous. Right?
(Joel Beasley at 00:16:42) We're doing it right now on Riverside.
(Eric at 00:16:45) But you open everything in the browser.
(Joel Beasley at 00:16:47) Yeah. So we built a screen-sharing Java application. Now for the executives listening, VPs of engineering, managers of developers or engineers, what's the business case for this? How am I saying we should look into this? Azul might be something we need.
(Eric at 00:17:05) Yeah. So the reason that anyone would take a look at Azul is, generally speaking, if you want your application to run really fast, but you don't always want to keep a cadence with taking every single new Java update and changing your core underlying platform every six months. With Azul, you have fully compatible JVM that you can use and run your application. And on the vulnerability detection side, a lot of people, I know they're being forced to run these things, they're called composition analyzers. They look over your software, and then they flag every single thing under the sun as wrong. Everything is a risk.
(Eric at 00:17:42) So what we're doing with the vulnerability detection is picking out what part of the code that you actually use versus just the code that's there, and then we're driving the attention to what is actually in use and is vulnerable.
(Joel Beasley at 00:17:56) Okay. So you being Java experts actually is one of those distinctive competitive advantages that you have over the static code analysis engines that will support 50 languages.
(Eric at 00:18:10) Yeah. They go very wide, and you get a lot of these tools that cover so many things that they do virtually none of them well. When you have an analyzer that does too many things, a lot of these security tools, they just like to report everything and raise the alarm all the time. Where a couple years ago, I was giving a presentation at a conference, and I like to have my talks be a little fun. I like to have some sings and songs in there.
(Eric at 00:18:34) So I did a song called Old McDonald Risk Management because they go here a risk, there a risk, everywhere a tsk tsk.
(Joel Beasley at 00:18:44) I hope we can put some music to that.
(Eric at 00:18:47) I think we'll see what we can do. We'll get a production studio, have an Old McDonald. But it's the point of all these guys, they walk around and they say every single thing is a risk, and a lot of these old school security guys, they just wag their finger at everybody telling them that the thing you did could possibly be wrong.
(Joel Beasley at 00:19:04) Yeah. Well, that's what they're getting paid for, though. Right?
(Eric at 00:19:08) Somewhat. Yeah.
(Joel Beasley at 00:19:09) Yeah. That's what they're getting paid for, though. Right? I know exactly what you're talking about. I don't know how to describe it, though. I actually don't have words for it. And luckily, that's becoming less popular, though.
(Eric at 00:19:17) They are becoming less popular. So I go around and I try to change my jokes on my material every once in a while. Another one that I did is I think it was at a SNEAK conference. I gave a talk on the Security Groundhog, which is like Groundhog Day, the security guy who shows up too late, he pops his head into your project, he sees a vulnerability, and then says you have six more weeks of development.
(Joel Beasley at 00:19:43) I like that. There's a groundhog living under my shipping container about 15 feet from the studio.
(Eric at 00:19:48) Okay.
(Joel Beasley at 00:19:48) Yeah. I've recently started learning about groundhogs. We have an American groundhog on the property.
(Eric at 00:19:54) So I don't actually know that much about groundhogs, but sometimes when I make the jokes about things, people think that I happen to know a lot about the topic, and I'm like, oh, I only know enough to make a punchline.
(Joel Beasley at 00:20:05) There you go. That's all you need to know, though. Right? And by the way, thank you for doing that because technical conferences, when there's good speakers who make it fun and interesting, it's often rare, and it's greatly appreciated.
(Eric at 00:20:18) Yeah. I mean, I try to do what I can. I try to be as mobile as possible, like, move around the stage, don't just stand behind a podium, zip around, make as many jokes as I can, and not just have a meme picture up there. I still do have the memes, but you've got to have some good delivery too.
(Joel Beasley at 00:20:35) Yes. The memes are absolute requirement. Now I want to go back and talk a little bit more about the pressure that technology leaders might be experiencing to think that, hey, maybe. So the first qualifier is they would know that they have Java in their stack. Right?
(Eric at 00:20:50) Sometimes they do, but sometimes it's just it's prevalent in so many different systems. It's been around for 26 years, and I've talked to people and they say, we don't use Java. And then you look at the system, and it turns out they do.
(Joel Beasley at 00:21:02) Oh, okay.
(Eric at 00:21:02) It was in a lot of people's desk phones for years. I forget the model of it, but you know that phone that every professional had at their desk for years? Java was on there.
(Joel Beasley at 00:21:13) What was that, like, the SIP protocol or something? They were incredibly difficult to program.
(Eric at 00:21:17) I just remember that there was always that phone at every desk.
(Joel Beasley at 00:21:21) Yes. So then what's the symptom? So I think you said one of the symptoms is applications running slow. Right? So if I'm hearing that constantly, getting that feedback, I may want to look into Azul.
(Eric at 00:21:34) Yeah. If you just need to increase the compute capacity without adding additional resources. In the cloud world, you can always just go and buy more, but the problem is that gets expensive. And in the on-premises world, you can only resize up in VMware so many times. So what you want to do instead is make sure that you're actually maximizing what you have before you go out and buy more.
(Joel Beasley at 00:21:59) There was a blog post that I read by David Heinemeier Hansson, creator of Rails. And it was recent, like, this week, and he was talking about their new product, Hey, and that they're looking to actively move away from cloud computing and move to on-premise. And he listed off a bunch of reasons. I didn't understand it necessarily because I'm not an expert over there. So I made some comments on the post, and then people told me more facts that really I didn't understand. Cost-benefit analysis, do you see a lot of your customers running on-prem things? Do you think we're moving back to on-prem just from the exposure you're getting from your customers? I know you're not necessarily a cloud hardware or vendor-type person, but do you see more people going towards on-prem or towards cloud, or what direction do you see people headed?
(Eric at 00:22:47) Yeah. It's a bit of both. So Azul has a JVM that makes cloud workloads operate in a denser capacity, but also works on-premise. Personally, I'm seeing a lot of migrations in both directions. If you need to get things up and do it really quickly, the whole point of the cloud is that you can just spin up resources and get whatever you want.
(Eric at 00:23:07) But for the organizations that have a large estate, like a bank, an insurance company, for them, moving a lot of their workloads to the cloud is really, really expensive. A couple years ago, I was working on some other products, and we were helping organizations move to cloud. And I saw one company that had a mandate. They wanted to move about 300 systems to the cloud, and they moved like four of them and maxed out their entire budget for the year.
(Joel Beasley at 00:23:37) Wow. So for those people, I don't think it makes sense to go.
(Joel Beasley at 00:23:40) So why aren't these people, I can't remember the name of it. There's this awesome guy in Atlanta. I've met with him several times. I've been on his show, but they're the largest footprint of server space in the United States by square feet. Right? And so they build these massive buildings with racks and everything like that. And then ultimately their customers are often the big five. Right? So Facebook doesn't even necessarily own all of its data centers. Right?
(Joel Beasley at 00:24:05) But the point is, these big five, they don't necessarily own every data center for everything that they're doing. So if you're a big enough company, you could go rent from these massive providers. Right?
(Eric at 00:24:18) Yeah. I think that was Equinix or somebody. It might be them. I remember the job I started first out of college, we would have to go to the data center every once in a while because we just had a rack there. And I had to get scanned. They had to have my badge on file. I had to do a handprint and stuff to get in. So you can go and use those. I think the problem is that then you manage the infrastructure. So one of the benefits of the public cloud is that I just don't have to think about as much.
(Joel Beasley at 00:24:46) Dave McCall. I looked him up real quick. QTS Data Centers.
(Eric at 00:24:50) Oh, okay.
(Joel Beasley at 00:24:51) He's got a great podcast too. I want to talk a little bit about what I saw in the prep for this, which is, I think, Josh named it really cool Java things. There's a couple of really cool ways that you've seen Java used or you've used it. One, a water-powered ocean glider. Can you tell me about that?
(Eric at 00:25:10) Oh, yeah. So Java has been around a long time, and it's inside all types of embedded systems as well as a lot of cloud and enterprise workloads. And for the majority of people who work, that's what we do. We build enterprise systems and operate things. I personally think the embedded stuff is really cool, so I pay attention to it.
(Eric at 00:25:31) So the guy who created Java, James Gosling, actually used to work at a company called Liquid Robotics that built a, it's basically a water-powered robot that navigates through the ocean and is powered by the motion of the waves and solar work, and it just navigates around and reports back all kinds of data about sensors. And the cool thing was we did a podcast talking with him about uses for embedded Java, and he's explaining everything that goes on with these water-powered Java wave gliders. And he says, yeah, and every once in a while, a shark will come up and just bash into them, and so it might bite off one of your sensors.
(Joel Beasley at 00:26:12) Oh, man. That's a fun day.
(Eric at 00:26:15) I know.
(Joel Beasley at 00:26:15) I'm not going in the water to retrieve it.
(Eric at 00:26:18) Yeah. I don't know where it is. And they go, like, they also have to go up near the North Pole, which is particularly cool because compasses, you know, whereas you and I would look and say what direction is north, the reason that a compass points north is because there's a giant iron ore deposit up there. But when you get right up there, all of your compasses, they no longer work to show you where you are. So you just get really weird behaviors like that and stuff goes really off the rails, which is one of the reasons that you need a structured language that's going to give you known behaviors versus the more dynamic stuff where you see what happens only when the software runs.
(Joel Beasley at 00:26:56) How did you feel when you got to meet James Gosling?
(Eric at 00:26:58) I thought it was cool. When I talked to a friend of mine and I said, hey, we should do a podcast on embedded. He said, do you know James? He likes to work on embedded. And I thought, well, there's no way he's actually going to reach out to this. This must be a joke. And then later that day, I was introduced to him, and I was like, wow, this is really cool. What a great opportunity.
(Joel Beasley at 00:27:19) What got you on this path of being more than just individual contributor or manager? How did you get out there and start speaking at conferences and build these relationships?
(Eric at 00:27:30) So mostly, I just like to go around and kind of have fun with what I'm doing. I want to have some kind of jokes, like the songs that I do, the ability to present it and things. I kind of got a unique start in the industry because even before I started coding, I went to Illinois State University, which is one of two colleges in the United States with a circus. So I actually used to juggle and unicycle in the circus, so I always do some kind of performing and things. And it's just a nice way of getting information out there in a way that's fun. So I'm just kind of always like, what can I do that's more fun to show off these cool tech things?
(Joel Beasley at 00:28:13) What specifically caused you to get involved with the circus?
(Eric at 00:28:16) It's just the high school that I went to had a juggling club, so I learned how to juggle and, you know, I knew how to do that. And then when I went to the college, they're like, we have a circus. So I went and joined the circus.
(Joel Beasley at 00:28:27) That is so cool.
(Joel Beasley at 00:28:29) Did you travel around, or was it just stationary?
(Eric at 00:28:31) It was a regional one, so you do things over in the center of Illinois. So we never went very far. But it's just a nice opportunity. You'd wear your typical circus costume. I was never a clown, and you just go around and do these cool performances.
(Joel Beasley at 00:28:47) That is pretty neat. Yeah. We lived in a very artistic town. My wife and I are both from Sarasota, Florida, and they're known for the Ringling Brothers.
(Eric at 00:28:56) Nice.
(Joel Beasley at 00:28:56) Yeah. And it's not exactly what you think about if you've only seen a traveling circus. There's quite an art to it, and there's a whole lot of different styles. Because often when you think of circus, you'll think of the scene from the movie that you saw of the circus. And that's one very specific type of situation.
(Joel Beasley at 00:29:14) And so to see the elegant stuff that they'll do at night or the high-end black-tie type circus stuff, that is really, really interesting. And you just did a spectrum of stuff, just whatever events were going on?
(Eric at 00:29:25) Yeah. We just did different events. You know, there's a lot of circuses that do have animals, not as many anymore, but we used to get protesters every once in a while who would show up and they would say, circuses abuse animals. Now first of all, we didn't have any, but the joke that the people who ran it used to say was, we treat animals well. These are college students.
(Joel Beasley at 00:29:47) There you go. Now so you got the unicycle. You got the juggling. So you've had this entertainer streak and you communicator streak for your whole life.
(Eric at 00:29:58) It's just a thing that I try to do. Yeah. So when I first started working in the tech group, my idea was, you know, how do I become a CTO? And I was under the impression that, well, they must be the best coders. They must be the most knowledgeable people.
(Eric at 00:30:12) And the more I worked with them and the more I saw everything, I saw they're not, they're always good, but they're not always the best at that. But they are really good at talking and communicating and telling a story about why they do something.
(Joel Beasley at 00:30:26) Yeah. And then your dream to go to CTO, sort of it didn't matter. You just wanted to be doing the things that you loved, communicating and technology?
(Eric at 00:30:34) In a sense, yeah. For a point, it doesn't matter what people call you. It matters what you get to do. And as long as I get to do something that's both challenging and fun and also kind of moving the industry forward in a certain way, I find that very worthwhile.
(Joel Beasley at 00:30:52) What advice are you giving to the level of engineers and technologists that are directly below you about how to grow in their career?
(Eric at 00:31:03) Yeah. The main thing that I work with a lot of people on is the concept of picking what you do and doing that really, really well. A lot of people I know, they are pretty good generalists. And it's really nice to be a generalist. You gotta have that ability to do a lot of different things.
(Eric at 00:31:20) But when you pick one thing to work really, really well at and there's a market for that, then people who are in the market for that particular skill will start to go to you as the expert because other people can't solve it. So, for me, I focus on Java security, and people who need to know, you know, how do I secure my Java workloads, they tend to find their way over to me versus people who just need general security. There's a lot to that. So for each person, what do you want to be really, really good at?
(Joel Beasley at 00:31:54) And so you coach them through this, or you have them go explore that and come back to you?
(Eric at 00:31:59) Well, they don't always have to come back to me. It's just a matter of picking the problem that they want to work at and making sure that they have the capability of staying focused in that and not just doing it, but also being able to communicate why they do it.
(Joel Beasley at 00:32:16) I agree with that because I've lived that advice out. I had heard it from a number of people, but the one that stuck in my head was Gary V, Gary Vaynerchuk. He's a marketing personality online, and he talks about doubling down on what you're great at. That's his phrase that he uses.
(Joel Beasley at 00:32:31) Right?
(Eric at 00:32:31) Oh, okay.
(Joel Beasley at 00:32:31) And so we're just constantly trying to reinvent at the core without going off into something else. Right? I'm not trying to become a real estate podcast or whatnot. How do you do that professionally, or how have you done that to keep it fresh for yourself?
(Eric at 00:32:45) Yeah. So I don't know specifically how I've done that, but I just like to focus on, you know, how can I take this complex topic of security where a lot of people want to tune out? They don't really want to hear about it. They're kind of forced to come to the class. And how do I make those things entertaining? Because for me, it's just about having fun with the work I get to do and going out there and solving a problem.
(Joel Beasley at 00:33:10) Okay. You're making life better for people that have to go to this educational event on Java.
(Eric at 00:33:17) You have to secure your applications. Nobody really wants to do extra work. So if they have to learn something, let's make the thing that they have to learn fun. Let's make the thing that they have to do something that they just get done as a result of what they normally do.
(Joel Beasley at 00:33:34) Have you ever participated in the No Fluff Just Stuff conferences?
(Eric at 00:33:39) No, I've never participated in them, but I know a number of people who do.
(Joel Beasley at 00:33:43) Yeah. I got to go to one of those. It was right before the pandemic happened, but wow, I had been to so many conferences. And then when I went to one of those, it was just people the way you're describing yourself, and it was a bunch of those people consolidated. And they were just practitioners who could pull up the computer and live code and whatnot and talk deep with you, but they could go very deep, but they keep it super interesting up high. And so that's an art, and I think that that conference circuit has a lot of those. I hope they're doing it again. I hope they're back operating again.
(Eric at 00:34:16) Yeah. I know a number of people who go through that, so I think it is still going on. Also, I get a bunch of their emails. But yeah, they really go in there and do the live coding. I like listening to people who do live coding, but sometimes I think it's hard to watch because I don't know which part of the screen to focus on all the time.
(Joel Beasley at 00:34:33) Yeah. Man, it's strange for me having done it for so many years and then for the past two and a half, three years because of the podcast, it's just, it was something that was in my daily life virtually, and then it's just not there anymore. I kind of miss it. I've been thinking about when my kids are older, my oldest is only five, that I would get into a tinkering mindset, buy the Arduinos, get the little projects off of Amazon you can buy, and sort of show them, you know, basic circuits and how to write a basic piece of software. So I'm looking forward to that stage of my life, but I'm in this weird gap break point right now.
(Eric at 00:35:11) Oh, there's a cool thing that you can get, and it's on Amazon. It's called Snap Circuits. I've used that with my kid who's eight years old now. He just had his birthday. And what it is is every circuit or wire is just on a fixed interval item, and you just snap them together like you would a button on a shirt. And because they're a bunch of components, you can snap on to the battery, snap on to the LED, and snap on to the resistor. And it's a really easy way for them to see some of this stuff and just build little entertaining things. You know, you can't do a ton, but it's way easier. A seven-year-old with a breadboard, that's tough.
(Joel Beasley at 00:35:47) Yeah. Yeah. You could teach them about basic electron flow and whatnot. This is great. Hey, real quick before we wrap up here. What are other areas of your interest so I can put you down on our sheet for future conversations that are unrelated to Java? And sometimes we'll have things come up like robotics, and then we'll bring someone on. We just kind of banter about, you know, Elon Musk's new robotics thing or whatnot.
(Eric at 00:36:12) Yeah. So I've got my little tinkering lab there. I think this stuff is super fun, this propane thing where you just build little sensors and things because you just get to tinker with things. And for years, everybody has run, oh, I gotta have my app up in the cloud. But what gets the data to the cloud? Everybody works on these things, and I'm going to make this business process more efficient, but there's very little software that actually interacts with the real world. It's all somebody clicking there and typing and doing something, but what's producing all of those sensors and things, and what's kind of giving us that real-time visibility? And it's only these little IoT projects where you can have a sensor that does it. Also, the reason that I got on this propane sensor thing is I'm interested in home efficiency. So your house, your house is basically an unmanaged business. You gotta manage it. You know what I'm talking about because you got a house there. Right? Okay, I gotta manage a lawn contractor. Those are the guys that do it. You know, you got a propane tank. I gotta manage a propane contract. Okay, I also need to service the boiler, and the gas company and the boiler company are different firms. Oh, now I need a roofer. Who do I talk to? So I just started gathering all of this stuff, and I'm like, how can I automate this stuff and kind of offload the cognitive complexity?
(Joel Beasley at 00:37:38) We should do an episode with me, you, and Bill Nye to talk about home energy efficiency.
(Eric at 00:37:46) I've actually met Bill Nye.
(Joel Beasley at 00:37:48) You have?
(Eric at 00:37:48) Yeah. So we opened for him once in the circus. He was coming there to talk to a lot of people, and he needed an opening act, so he got us to go out there and perform to entertain everybody.
(Joel Beasley at 00:38:00) There you go. I was just thinking the other day to do something with Bill Nye. I've listened to his interviews, right? And I've listened to his books, and he's really into energy efficiency, residentially. I don't know if you've read his books recently, but—
(Eric at 00:38:14) No, I haven't run into the stuff. I don't follow him. I know his stuff, and he's a really interesting, really smart person, but obviously, I've never talked to him about energy efficiency or anything like that.
(Joel Beasley at 00:38:27) Yeah. Let's do that. Alright. Well, this has been awesome, man. Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email, [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.