Episode 718 ·
The Secret to Empowering Employees & Embracing Serendipity with Mario Duarte, VP of Security at Snowflake
Today we’re talking to Mario Duarte, VP of Security at Snowflake. We discuss how to understand what motivates your employees and put them in roles that fit, why you should listen first before telling people how to do security better, and why remaining open to serendipity creates opportunities that structured planning alone may miss.
All of this right here, right now, on the Modern CTO Podcast!
For more about Snowflake, check out their website: https://www.snowflake.com/en/
In case you missed it, here's our episode with Beyond Identity - https://moderncto.io/jasson-casey/
Have feedback about the show? Let us know here
Produced by ProSeries Media.

About Mario Duarte:
Mario Duarte is the Vice President of Security at Snowflake. Previously, they were the Director of Security at GoGrid from April 2012 to October 2014. Prior to that, they were a Sr. Security Analyst at UCSF from April 2011 to April 2012, and a Sr. Security Consultant at Dolby Laboratories from July 2010 to January 2011. Mario Duarte has also served as a Security Architect at Ross Stores, Inc. from May 2008 to July 2010, and as a PCI SOX Consultant at Bare Escentuals Beauty, Inc. from January 2007 to December 2008. Additionally, they were the Security & Privacy Manager at LifeMasters Supported SelfCare from January 2006 to December 2007, and the Security Manager at Moody's KMV from January 2001 to December 2005. Finally, Mario Duarte served as an Information Security Manager at XUMA from January 2000 to December 2001, and as a Security Engineer at Ernst & Young from January 1998 to December 2000.
Mario Duarte completed a Bachelor of Science in Applied Economics at the University of San Francisco.
About Snowflake:
Snowflake delivers the Data Cloud — a global network where thousands of organizations mobilize data with near-unlimited scale, concurrency, and performance. Inside the Data Cloud, organizations unite their siloed data, easily discover and securely share governed data, and execute diverse analytic workloads. Wherever data or users live, Snowflake delivers a single and seamless experience across multiple public clouds. Snowflake’s platform is the engine that powers and provides access to the Data Cloud, creating a solution for data warehousing, data lakes, data engineering, data science, data application development, and data sharing. Join Snowflake customers, partners, and data providers already taking their businesses to new frontiers in the Data Cloud.
Transcript
(Intro Narrator at 00:00:00) Today, we're talking to Mario, VP of Security at Snowflake, about lessons learned going from manager to individual contributor and then back to manager. You're listening to Joel Beasley, Modern CTO.
(Joel Beasley at 00:00:19) I am super interested in what you guys do. I'd spoken to someone else that is it Jason or just?
(Mario at 00:00:25) You mean, oh, it's Jason. You mean from Beyond Identity?
(Joel Beasley at 00:00:28) Yeah, from Beyond Identity.
(Mario at 00:00:29) He's brilliant, man. He's an absolutely brilliant guy, just a nice guy. Really sharp. Really smart.
(Joel Beasley at 00:00:36) He gave off the cuff these brilliant analogies to, I believe, baking bread and all of this stuff when we were talking about security. I thought, man, this guy is either incredibly sharp on his feet or he's put deep thought into this. Either way, it's impressive.
(Mario at 00:00:51) No, he's very smart. Very sharp. Yeah.
(Joel Beasley at 00:00:54) How did you meet Beyond Identity?
(Mario at 00:00:56) I have a colleague, a former colleague. He actually went to go work at another company, really good startup security company. Anyway, so at Snowflake, he was a field CTO, field security CSO. So he gets to go meet with customers, talk to them about how to secure their Snowflake deployment, how to make it more secure, etc. And, you know, him and I, we always geek out on things, and we always talk about new products and what are we seeing out there. And he says, "Hey, I need you to do me a favor. I need you to go talk to this company called Beyond Identity." I'm like, "What do they do?"
(Mario at 00:01:34) And he's like, "No passwords." I'm like, "Man, really? That thing didn't stick three, four years ago." And he's like, "Just do me a favor. Go talk to them." Alright, fine, just because of you. And so he introduced me to them, and immediately, they pitched the whole no password idea. And when they started describing how they were going to do it, I immediately just, my eyes lit up, and I was like, "Wait a minute. Okay. I get what you're doing. It's no password, but the technology you're using could be used for even more things. So if we're going to do this, I need you to do something for me with this technology." And, you know, they're a startup. It's great. You could talk to startups. They can do things. And if it makes sense to them, they may embrace that, and they did. And it was at the right time.
(Joel Beasley at 00:02:33) So for other technical leaders, whether they're in security or just the CTO or CSO, they're listening to this. What flag should go off in their mind and they think, "Oh, I might want to give, you know, Beyond Identity a chance"? Because as you said, I'm not even in the specific security niche. I'm just in technology and tech leadership. And, boy, do I hear passwordless just read so much that I just tune it out. So why would they go look at Beyond Identity? What problems are they experiencing?
(Mario at 00:03:03) If you look at, most, if you're using passwords today, most people are using passwords. Okay? Most companies haven't done this journey to do passwordless. If you talk to most of these companies who are still using passwords, I'd bet you my bottom dollar that the top five help desk ticket issues that they have has to invariably be about, "Hey, I locked my account. I forgot my password. Can you please reset my password?" by a significant amount. Like, you'll see, you know, help desk support tickets heavily represented around user credentials, resetting of passwords. That's one.
(Mario at 00:03:51) As more regulations force companies to have stricter password policies. So, you know, instead of just 90 days, 60 days, 30 days. And then you have to come up with like 20 characters, 25 characters, 30 characters, and then you have to remember them. Of course, you're not going to remember them, so you have to buy another tool that will help you generate new passwords, reset new passwords, etc. That's still, you know, you're going to have to buy more, you're going to buy another tool. You support that tool, and it's not always perfect. You know, those password managers, they're good. I'm not going to dismiss them. They're helpful, but they come with a price. So as a CIO or a CTO, let me just say just a CIO, somebody who's not necessarily, maybe security doesn't report in their organization, having to support this help desk, that costs money. It usually is around 10 to 30 minutes to resolve a password.
(Joel Beasley at 00:04:51) We need like a fine-tuned ChatGPT that can do that, or you can just go use Beyond Identity.
(Mario at 00:04:58) Right, right. So for other leaders that maybe not worry so much about the improvements of security, think about the reduction of tickets that you can now focus your energy, your help desk, your systems people on the things that you, that your company needs. And I would argue that there's always work to be done. So now if I can tell you I can make you more productive, I can make your systems people productive by another additional 25, 30% daily, who wouldn't take that?
(Joel Beasley at 00:05:29) Well, thanks for sharing. I really like Jason when I met him. I liked what his company was doing. You know, it's strange. You meet these people, and when they're really, really good people and they're doing something interesting, I just feel like I want to help them. So every chance I get, I'm like, "Yeah, Beyond Identity." So thank you for giving me some perspective there. Now, you're working at one of the largest companies in tech. Snowflake is huge. You've climbed up all the way to the VP level. Right? And security is critical to the product that you guys, you know, produce and the company that you have. A lot of the individuals listening to this show, they're in technology leadership. They're even in security, many of them. And I constantly get messages, you know, "Joel, how do I get to the next level? How do I grow into my career? Is it another security certificate? Is it, you know, spending time with my peers?" Like, how do I actually grow and become better inside of my career?
(Mario at 00:06:26) Yes. I think the most important thing, sounds really basic, is understand, first, what is the business that the company you're in does? What is it that they do? Okay? Who are their customers? What are their demands for your either services or widget, whatever you're selling, whatever it is. You're in the business of something. Maybe nonprofits, maybe let's put nonprofits on the side right now. Let's just talk about companies or for-profit. And you first need to understand what that business model is. I would talk to the sales team. I would say to the sales team, "Hey, tell me, you know, how is security? Is security playing a part in your daily sales cycle?" In other words, is it a roadblock for you when you're meeting with customers? And trying to understand that and hearing people out first, listening, and then figuring a way of saying, "How can I, instead of making security a challenge, a blocker, how do I make it a selling tool for my salespeople?" If there's such a possibility, do that, if there are opportunities there. So, ultimately, what I say, if you look at a business and think about an analogy, when we talk about an analogy, I think about a vehicle, a car. And wheels in a car, in that car, are different groups within a company: finance, marketing, legal, tech, whatever. One of those wheels is security. Now if that wheel is a square wheel and then the rest of them are round, that driver, the CEO, is going to ultimately pull over and say, "I can't take that square wheel. I can't move efficiently. There's a lot of friction. It's not aligned with the rest of the business." And they're going to replace that square wheel with a round wheel. So, really, if you want to move up in security in a company and as you go in your career, really generally try to understand what business you're in, your company's in, and figure out how to align security to help with that growth.
(Joel Beasley at 00:08:47) How long did it take you to figure that out?
(Mario at 00:08:52) I dropped out of college in my twenties, and I decided to go and, you know, do tech work. Right? I wanted to be in security. I wanted, I've always wanted to do, I always wanted to be in security, cybersecurity since I was 14, 15 years old. That was what I wanted to do. That's another story for another day. But I was full of bravado in my twenties. And I thought, you know, just being technical, being the best technical guy, being a guy who could break into companies, I mean, legally, of course, or writing the best code. You know? That was what would make my career. Right? And I had a rude awakening, and it's called the dot-com. And the dot-com, the bubble burst. And one minute, you think you're going to be wealthy as hell because your company's going to go public. And within two, three months before going public, the entire thing just collapses. And if you step back, a lot of those dot-com companies didn't really have a business model. There was a lot of money out there from a VC perspective, and it was exciting. And we drank the Kool-Aid. We brewed the Kool-Aid, drank the Kool-Aid, got drunk on the Kool-Aid, and yet we didn't have a business plan, business model. And I knew then that I needed to go back to school and understand business better. So I went and got a degree in economics at University of San Francisco. So plugging my old school. While I was still, so I did work in the daytime doing, you know, security, but also going to school at night to get a degree in economics because I knew I needed to learn the language of business.
(Joel Beasley at 00:10:41) That is so cool. And what was your first job after learning the language of business?
(Mario at 00:10:48) Well, I did a lot of, you know, I worked at a financial risk company where you started looking at defaults, the probability of a, not an individual, but a company defaulting on their, more on their loans. So that even helped me out more. That kind of got me even closer to the idea of how businesses succeed and fail, at least from what we were selling, the instruments to measure that. So it was a company, you know, it was KMV, and we ultimately got acquired by Moody's. So it was, yeah, it was a good, it was a, you know, I've worked at five, Joel, I've worked at five startups. Three of them completely failed, and I was the last man standing. Security is usually the last man standing in these things. It's horrible. It's absolutely horrible to see your friends, your colleagues, your dreams just disappear. My fourth company, or the fourth company, one of those startups, so three failed. One of them got acquired, which is KMV, got acquired by Moody's. I was able to make a little money and pay my education at USF. So I was debt free from, you know, my tuition, which was great. And then Snowflake came and that really changed everything. So I've had three failures and two success stories.
(Joel Beasley at 00:12:13) Let's talk about when you were 14 or 15 doing those very legal activities. You have any good stories that you're allowed to share publicly about, you know, your introduction to technology?
(Mario at 00:12:24) Yeah. I mean, there's not, we didn't do anything. I mean, not when you're 14, I think, not when you're 14, 15. I think what it was more in those days, you know, you were just, I mean, I, you know, I'm going to date myself, but, you know, I'm talking the '80s, man. Yeah. You know what I mean? So there was a movie called WarGames.
(Joel Beasley at 00:12:45) Yes.
(Mario at 00:12:46) I don't know if you ever seen that movie.
(Joel Beasley at 00:12:47) Oh, yeah. Many times.
(Mario at 00:12:49) Yeah. Yeah. Me too. And I just fell in love with the whole idea of just, it was a game. It was a game of trying to break in. It's just like a puzzle. So it was more an intrinsic reward to try to find holes in things and to, I don't want to say hack. Hack is, it's not the right term, but because, but you find, you figure ways around a system because every, these systems are built by humans, and invariably, they're going to have errors, misconfigurations, things that you could potentially exploit to then get in. And getting in wasn't, "I'm going to steal data. I'm going to go steal something." It was more understanding how to, you know, just you got satisfaction of breaking the systems. But it wasn't like systems were so difficult there. I mean, a lot of stuff wasn't really connected back then to begin with. But once you started getting more of the network-based stuff, that's where things got a little bit more interesting. And so there was always that passion for me. And, you know, there was a guy, his name's Patrick Heim. I still, he's still my friend, my mentor. He's been a CSO for multiple companies. I was doing desktop support for Ernst & Young in those days. This is back now, my, I'm going from my 14 to my teens to my early, my early mid-twenties. And I would work on his laptop one day after, you know, working with him for six months. That time I worked six months for his laptop, but he always had something for me to work on his laptop. Right? He asked me to come and join his team and to go and try, you know, be a pen tester or a red team. In those days, we used to call them tiger teams. So you did attacks and penetrations, what we used to call them. And I said, "Well, I've never done it professionally or anything like that or even unofficially. I'm not, you know, or unofficially." And he's like, "Don't worry. We're going to teach you." And that was my official entry into security. It was because of Patrick. And, you know, you get those opportunities.
(Joel Beasley at 00:14:57) I got into it for a very short period of time. When I was around 13, my dad had taken me to Barnes & Noble, and there was a book called, like, Hack This Site. And I thought it was so cool. I loved when they had, you know, the cool-looking prompt screens on the movies. And I saw that. I was like, on one of the covers, and I thought, "Well, that'd be so cool." It's a how-to book on how to do this stuff. And it existed. It was real, and they sold it at Best Buy. I don't know if they would today, but they did. So I bought it, went home, read through it. They had different servers you could log in, do practice, different things. They would, it was progressive education, so they'd start you with something basic to teach you. I got into that, started messing around with my, you know, my brother who was off at college and then the computer downstairs. It was really easy because I'd be at the computer upstairs and be like, "Why isn't this working?" I'd just go downstairs and go back and forth till I finally figured out how to do it. Then I was like, "Alright, now let's do it with some random people on AOL Instant Messenger." And it was more about just like, "Oh, look. I can do it, and I can change the color of their background or whatever it is." Right? And so that was fun. And then I really quickly realized that I had a lot of fun in the programming aspect of it. And I'd gotten into that quite a bit, and I realized that I could just make, I can make money legitimately on ScriptLance, which is like an Upwork now. Right? They pay. They don't care that I'm 13 or 14. They just pay and have a project and you get a profile. So I got into that and then I kind of forgot about security for the better part of a decade or so. And then when the applications I was working on started to get more popular and gain more traction, all of a sudden security became important. Right? They weren't small little projects. They were actually getting traffic. And so I had to go back to security and just refamiliarize myself with some basics. And through that act, to what you said earlier, which is what made me think of this, when you spend a decade or two writing software, building SaaS applications, you learn about, and if you're good at it and you have discipline and you really care, you learn about all the different places people would cut corners.
(Mario at 00:17:07) Yes.
(Joel Beasley at 00:17:08) And all those little places people are going to cut corners is just the first places you would check.
(Mario at 00:17:15) Yes.
(Joel Beasley at 00:17:16) And I realized, wow, I haven't intentionally been on security, but my act of becoming a programmer in this specific type of programming has actually lent me some pretty decent knowledge on where to poke around if I wanted to get in somewhere I shouldn't be. And so that was kind of cool to take a break from the industry and then realize you kind of didn't really take a break. You still have a lot of background knowledge. That felt good.
(Mario at 00:17:40) Yeah. You know, some folks say that you shouldn't pursue your passion, but this is my passion. I love this. And I think most security people are passionate about what they're doing.
(Joel Beasley at 00:17:53) Oh, yeah. I mean, I knew I wanted to do computers since the moment my dad showed me, and I did Hello World. Yeah. I felt like an unstoppable character and a superhero.
(Mario at 00:18:05) I was—
(Joel Beasley at 00:18:05) Like, that felt good. And then I spent the next forty-eight hours awake writing these super basic macros to run some DOS commands. Like, so I made a little menu, and I could press, you know, shortcuts for basic commands and learned how to pass variables. And then I was like, this is so, so cool.
(Mario at 00:18:26) Oh, it's just such a joy, isn't it? Like, it seems to be—it's a way of being very creative and having an impact on things that you can have an impact. You can automate things. You can speed things up, and there's that creativity, but that intrinsic value as well. Right? You get something out of it. And that's what—yeah, I gravitate to this stuff.
(Joel Beasley at 00:18:51) And when you're looking for opportunities as you went around your career, you looked for that and those opportunities?
(Mario at 00:18:58) You know, I was a manager when I was 28 years old, and I built my first security organization at one of these startups. And I'm—at 28, man, God bless all those 28-year-olds or 20-year-olds that are just so much more mature than me. Because I was not—I was not emotionally mature. Jesus. I can't believe I got away with all the crap. You know? I also realized that as a manager, I needed to learn more on how to be a better manager and how to understand my employees. And it wasn't just about tech stuff, which it is—a lot of it is—but it's also about people and what drives people, what motivates people. And I wasn't ready for that.
(Mario at 00:19:42) And so, you know, my thirties—most of my early thirties, late twenties, early thirties—I decided to not be a manager for about seven, eight years, and just be kind of an individual contributor, you know, an architect, security architect, certainly making my ideas influence the company. Like, I love ideas. I love to be able to say, I don't need the title. Just let me have my ideas make a difference. And that was really helpful for me. I needed to learn to be an individual contributor again and look at good managers and bad managers that I had. I think we all had that and then learned something from all of them. And then there was a point when I said, well, you know, I think it's time to go back. It's time to be a manager. It's time to manage people.
(Joel Beasley at 00:20:32) What was that moment when you said, okay, I think I've had this experience, and I'm ready to become a manager now?
(Mario at 00:20:39) I—God. You know, this is going to sound really arrogant. So terrible. You know, it would be where I would be in an organization—let's say it was a larger organization. I'm not going to say names, but where you would have a person promoted as your manager, and they weren't even in the security space. They were project managers, and they'd make them the security manager just because they were good project managers. And that to me was just—so, down to the core of my soul, my—you know, I just—I could not see that. I could not make that connection. I felt like if you don't have—if you're not a programmer or a system administrator or an engineer, or you're not coming from the tech world and you're doing this in security, how can you be a security manager?
(Mario at 00:21:35) And I felt like that really was—I, you know, I have a lot of respect for project managers. Don't get me wrong. And I'm sure some of them are really good at what they do, and even maybe they can lead security organizations, not the ones I worked for. I'm going to leave it like that. But I was like, well, if somebody's going to be making decisions for the whole company or for this group, well, jeez. I might as well give it a shot. I think I have a little bit more experience and maybe I've learned a little, but humble yourself. You're not perfect, but give it a shot. And that's what happened.
(Joel Beasley at 00:22:15) I agree. I would definitely, in my experience, agree with you and say that 80% of the time I see project managers managing something that they're unaware of as far as a practitioner, it's not great. But there is one or two of those people out there who do understand humans enough, but it's definitely the exception, not the rule.
(Mario at 00:22:38) Yeah. I think, you know, I think of it as a journey. I think we all go through our own journey in life. You know, as I've been in this industry and doing security for twenty-five-plus years now, there's like a journey. It's like every—I think most of us go through this. Like, if you read The Odyssey and Odysseus and what he went through, and you come back home and you're different. You've—it's the same but different because of the experiences you've had.
(Joel Beasley at 00:23:06) I was having a conversation like that with the sales team. Maybe last week, we were on a sales call, and we started—you know, we do our show. People sponsor our show, but then we started making shows for other companies. And we were in this one sales call, and we're like, yeah, you know, we've done—we've recorded over a thousand episodes. Right? And I was thinking to myself, it's been about seven years across all of our shows. We've done north of a thousand episodes.
(Mario at 00:23:33) I—congratulations. Awesome.
(Joel Beasley at 00:23:34) Thank you. 700 episodes. I am not a confident person in general. Okay? I am very slow to confidence. And for example, like, for me to get confident to say I was a good programmer took me over a decade. Like, to say, okay, I know enough to where I go to the conferences and I hear, you know, the experts and the people that write the core languages. I hear them have arguments and I know what the experts disagree on and what the different schools of thought are. And when I got through that entire experience, it's like, okay, now I have some confidence to say I'm a pretty decent software engineer. And then I didn't have that in podcasting until I had this realization, you know. I was saying, like, wow, you know, we have done hundreds of these. And it took me—people will often ask me, they'll say, oh, well, how long? You know, I don't like looking at my face or I don't like the sound of my own voice and all of that. And I'll say, well, I didn't either, but it took me 200 episodes to get over it. Right? So it just kind of just happened. So when I get to talk with people like you who have had this career and this growth and I've gotten to this amazing position at this huge company, I'm always trying to figure out, like, you know, all that experience that built up to their confidence. What are those lessons along the way?
(Joel Beasley at 00:24:48) So with that being said, I'm curious. What is one of the mistakes that you made many times over?
(Mario at 00:24:55) Yes. I think when it comes to your team—so I've been managing teams for a while. Right? I've built a number of teams. So sometimes there's a book called The Principles, by Ray Dalio, I think. Ray Dalio. Yeah. Yeah. And whatever—however you feel about Ray Dalio, I get it. Okay? But just there are some—
(Joel Beasley at 00:25:24) He's brilliant. Yeah. Yeah. The book is amazing.
(Mario at 00:25:27) It is—it is. I'm of the opinion that it is an amazing book. And so one of the things we don't do ourselves a service when it comes to managing, building teams is you—one sometimes feels or projects onto your team, and you think like they're going to be like you. Hey, this worked for me. This is going to work for them. What ends up happening is you put these employees in the wrong position, and you keep forcing it on them. And, you know, through time, what I've learned is sometimes folks—they have different motivations for different work humans. I know that, you know, we do have similar—there are patterns in our personalities, but there's some uniqueness to all of us. And what motivates us as well is important. So what is this whole point?
(Mario at 00:26:27) Basically, what I've learned and what I've done mistakes over and over is sometimes you hold on to an employee longer than they should have been in the team, and you're not doing them any favors. You're certainly not doing any favors to the team overall, but you're also not doing a favor to them, to the employee. And sometimes it's better to have these tough conversations at some point, and I think you might be better in a different team in the company, or maybe the company is not right for the individual as well. Freedom. This is not a—give them freedom. Let them be. Give them an opportunity to go shine where they can shine. Because I think everybody—I know everybody has a worth. Some worth. All of us do. And deep down inside, I think we want to do well. And so give those employees opportunities to do well.
(Joel Beasley at 00:27:25) I struggled with that too for a while. It was being able to find the perspective that you have to do what's best for them. Right? And you have to find the perspective that allows you to say the thing that's best for them is them moving on to their next thing. And I'll tell you, I am the person, Mario, where if we're out at dinner, I'll, you know, pull you aside and be like, hey, you got some food in your teeth. That's hard. That's a difficult thing. Most people don't want to do it. And I think for me, when I see it, I've trained—I didn't want to do it at first, but I've heard enough people talk in the, you know, Tony Robbins type space of personal development to know that, you know, sometimes these difficult things are little signals that if you, you know, master them, you just become—you can become better.
(Joel Beasley at 00:28:12) And so I think it's—I would want somebody to tell me if I had food in my teeth. Right? Even though it might be difficult for them. And so when I was first starting my company and, you know, it's all my money. Right? You get to that point where you're like, wow, when it's all your money on the line, you get real bold real fast to do the things that need to be done. Yeah. And then through that, you—I would say an advanced degree in economics would be just putting your life savings on the line on a business.
(Mario at 00:28:46) Yeah. Hard knocks. Yeah.
(Joel Beasley at 00:28:49) Hard—yes. It's an expensive university, but it's—and it's quick, but you'll figure it out because, you know, you burn the ships. So, yeah, I know I kind of—I jumped around a little bit there, but I like what you mentioned about understanding where people are motivated. And also, it took me a long time to figure out, well, a, how to frame it to where it's actually the best thing for them to move on, and, b, to understand, to your point of motivations. I used to think that they were static. And then I found out really quickly they're dynamic. Right? And people, as they go through their life, their motivation's changing. Obviously, my motivation's different when I'm welcoming a new child into the world than it is when that new child's been around for six months, and now I'm like, let's go make some more money, you know, and let's advance the career or whatever it is. So these dynamic motivations, the—I haven't found any secret to it, Mario, and you can please share if you see something I don't. But you just have to know your people. You just have to spend time with them.
(Mario at 00:29:51) You need to spend time with them and you have to be brutally transparent with them. And it starts with you. Like, you know, when I make a mistake, I will be—I think I hope—you know, it's not super perfect, but I hope to be able to tell all of my employees in front of them that I made a mistake. I was wrong. And it's okay to make mistakes. That's why we're human. What I've asked people to do is learn from your mistakes. Tell me how you're going to make it different the next time. That's the one requirement I have.
(Mario at 00:30:32) There's two requirements. One is you learn from your mistakes. Everybody makes mistakes. It's okay. Tell me what you've learned, how we're going to adjust. The other one is you never, ever put down anybody. Ever. In front of them or in—or in or behind closed doors. You may have questions about their ideas and poke holes at their ideas absolutely in front of everybody. That's okay. You know? But you don't say things like that's a stupid idea ever, or you're a dumb person for thinking that. Then if you do those couple of things and you genuinely want to listen, like you were saying, Joel, listen to your employees. Just listen. Not what you think you want to hear, but what they're really trying to tell you. You—one will find that you have a much more open and honest conversation with employees. And then you can have those really tough conversations in a safe place where you both can make a decision how you want to proceed. But you have to earn that trust. It's trust, earning trust.
(Joel Beasley at 00:31:46) Where do you get your discipline from?
(Mario at 00:31:49) I really—I used to race bikes and I used to do triathlons, race bikes amateur. And when you're really training and you're racing and you really want to get good at something, you dedicate yourself and you are constantly failing because you're pushing yourself to the failure. And you just have to realize—you'll notice within months, you're improving. You're getting better. It's a struggle for all of us to have discipline. And I would argue that if you spend too much time trying to manipulate or control things outside of you, you—it's just going to be a losing battle. I think our biggest challenge in life as people is going to be this of how do I control my emotions? And not controlling. How do you accept those emotions, but don't—
(Joel Beasley at 00:32:49) Good. We can't—we can't just gloss over that. Say that again. Not do I control them, but what?
(Mario at 00:32:55) How do I—how do I accept those emotions but allow them to express themselves in ways that are not going to be detrimental in the long run? So if you're upset about something, I find myself, if you try to hide it and not share how you feel, it's going to manifest itself in a really bad way sooner or later. You're going to blow up. Okay? It's different to say, you know, you know what you just said right now? Here's the way I'm hearing it. I got to tell you, it's kind of making me—it's kind of pissing me off. So you don't raise your voice. You don't yell at the person, but you tell them how you feel. And you say, it's not—you didn't say that. This is the way I'm hearing it. You try to be really open about it and make yourself vulnerable. Make yourself vulnerable to your employees, quite honestly. Expose yourself because that in essence will free you. It'll allow you to not let those emotions fester inside. It's not always perfect, Joel, but you've got to constantly be doing it.
(Joel Beasley at 00:33:59) 100%. I like that you discussed your training. For me, one of the—I don't have a lot of hard-set times. Like, I have to work out thirty minutes a day or whatever it may be. My rule is I have to go in and I do workout until I don't want to, and then that's when the workout starts. So I go in. I get to that point. Like, I don't care about three sets of 10. I don't care about that. I do the rep until I get to the point where my brain goes, put it down. We did it. You know, whatever. I'm like, nope. And then I just see how far I can push myself from that point. And the purpose of that is not to become this huge beast physically.
(Joel Beasley at 00:34:44) The purpose of that is to train my mind to when I get to the point where I want to quit, I do it anyways. And so if I can wake up every day and get in my morning routine and before I even begin working on whatever writing or shows or whatever I'm going to be doing, step one is to make myself do something I don't want to do. And if I can do that, then everything else is just super easy.
(Mario at 00:35:10) Yeah.
(Joel Beasley at 00:35:10) It's just this work stuff. I already—because it's this weird thing that works for me. I don't know if it works for other people. But when I can make myself physically do something I don't want to do, all the knowledge worker stuff is just a breeze.
(Mario at 00:35:23) I think we try to separate the physical aspect of our brain or our mind from the physical aspect of it. And honestly, there's no separation. And I would argue if you're not trying to stay healthy or do something to manage that stress, it's going to manifest itself in your emotions and how you think and how you conduct yourself with your peers, your employees, your clients, your customers. And that is especially important in security. I think it's important for everything, but in security, there were many times I've had to talk to customers who have a point of view about what they want to see, particularly at Snowflake. Here's what we need you to have. These controls implemented this way, et cetera, et cetera. And it's important to hear them out and understand where those controls, that regulation, or why they're asking you to do certain things. And there will be times—and often most of these Snowflake customers I dealt with will tell you that I usually said no to what they were asking, but I didn't say no in a way to say, "No, we're not going to do that."
(Mario at 00:36:33) But rather, "I hear what you're saying. We can't do that in the deployments that we have. But what if we do it this way? How would that help? Will that address your concerns?" So look for ways to get to a yes for both of you. It may not be what the client wanted initially from a technical perspective, but ultimately, maybe find a resolution. And again, if you're going to find a resolution, the one thing for security folks as well—and I know a lot of folks who are starting their career or even they've been in their career for a while—listen. Really listen first before you tell people how to do security. Hear how they work. What is their responsibility? What are the things that they need to focus on for their own jobs, their challenges? And hear how your security controls or security is making it harder on them. Empathize with them. And then start sharing how we can make it better or how we can improve security with them.
(Joel Beasley at 00:37:41) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email: [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.