Mike Goffin is a seasoned cyber security leader with more than two decades of technical experience and 13 years in professional roles, currently heading Cisco’s Global Threat Intelligence Program from Durham, NC. He blends hands-on engineering—contributing backend Python code to notable open-source projects like Facebook’s ThreatExchange and MITRE’s ChopShop—with strategic threat operations leadership developed during an 11-year tenure as Technical Lead at MITRE. Mike has deep expertise in threat intelligence APIs, protocol analysis, and PCAP metadata tooling, reflecting a practitioner mindset that bridges detection engineering and program-level coordination. His background in systems administration and early work building a long-lived web ticketing system show an enduring focus on operational reliability and practical tooling. Colleagues rely on him to translate complex adversary behaviors into actionable programs that scale across global teams.
13 years of coding experience
17 years of employment as a software developer
Applied Networking And System Administration, Information Security with a minor in Philosophy, Applied Networking And System Administration, Information Security with a minor in Philosophy at Rochester Institute of Technology
Trust & Safety tools for working together to fight digital harms.
Role in this project:
Back-end Developer
Contributions:152 commits, 48 PRs, 173 comments in 2 years 3 months
Contributions summary:Mike's contributions primarily revolve around the development of a Python library for interacting with Facebook's ThreatExchange API. They implemented initial code setup and structure, focusing on core functionality such as making requests, handling responses, and creating generators. They also refactored the code to include methods for GET, POST, and DELETE requests, along with features to create, edit, expire, and mark items as false positives, showcasing a broad understanding of the API's capabilities. In addition to the core functionality, they designed classes for specific object types to handle interactions with the API.
Contributions:11 commits, 1 push, 1 branch in 4 years 8 months
Contributions summary:Mike significantly contributed to the `chopshop` project by implementing new features and improving existing functionalities of the protocol analysis and decoding framework. Their work includes adding the `packet_isodate()` function, which provides a datetime object for time-related operations. They also developed the `metacap` module to parse PCAP files, providing metadata extraction capabilities. Furthermore, the user enhanced the `metacap` module with options for stream-based output.
protocoldecoder
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.