Brad Mongar

Consultant at Keyhole Software

Kansas City, Missouri, United States
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

👤
Senior
🎓
Top School
Brad Mongar is a seasoned Java-focused consultant and software architect with over 25 years in programming and a decade-long tenure at Keyhole Software driving diverse client engagements. He combines deep object-oriented design and debugging skills with practical security work—contributing to the well-known SpotBugs find-sec-bugs plugin by improving XSS detection and adding a permissive CORS detector. A Certified Scrum Master and multiple IBM/Sun-certified practitioner, he prefers consulting for the variety of technical challenges it brings and mentors high-school robotics programmers, showing a commitment to coaching the next generation. Based in Kansas City, he builds adaptable frameworks and pragmatic architectures that balance maintainability with real-world constraints.
code10 years of coding experience
job16 years of employment as a software developer
bookBS, Computer Science, BS, Computer Science at Northwest Missouri State University
github-logo-circle

Github Skills (11)

javas10
audit10
static-analysis10
auditing10
xss10
java10
security10
testing9
code-analysis9
owasp8
cwd8

Programming languages (9)

HCLTypeScriptJavaDockerfileJavaScriptGoPHPHTML

Github contributions (5)

github-logo-circle
find-sec-bugs/find-sec-bugs

Nov 2017 - Jun 2018

The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
Role in this project:
userSecurity Engineer
Contributions:5 commits, 6 PRs, 11 comments in 7 months
Contributions summary:Brad primarily contributes to security-related testing and bug fixes within the find-sec-bugs project. They focused on identifying and addressing Cross-Site Scripting (XSS) vulnerabilities, modifying test cases to reflect updated findings, and improving the accuracy of the XSS detection. Additionally, the user implemented a new detector for permissive CORS configurations, indicating a focus on web application security best practices and configuration vulnerabilities. This work aligns with the project's goal of auditing Java web and Android application security.
android-applicationandroid-applicationsgroovyjavakotlin
Terraform code to create FCBH infrastructure
Contributions:3 reviews, 144 commits, 2 PRs in 3 years 1 month
terraform
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial