Mike Goffin

Global Threat Intelligence Program Lead

Durham, North Carolina, United States
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

🤩
Rockstar
🎓
Top School
Mike Goffin is a seasoned cyber security leader with more than two decades of technical experience and 13 years in professional roles, currently heading Cisco’s Global Threat Intelligence Program from Durham, NC. He blends hands-on engineering—contributing backend Python code to notable open-source projects like Facebook’s ThreatExchange and MITRE’s ChopShop—with strategic threat operations leadership developed during an 11-year tenure as Technical Lead at MITRE. Mike has deep expertise in threat intelligence APIs, protocol analysis, and PCAP metadata tooling, reflecting a practitioner mindset that bridges detection engineering and program-level coordination. His background in systems administration and early work building a long-lived web ticketing system show an enduring focus on operational reliability and practical tooling. Colleagues rely on him to translate complex adversary behaviors into actionable programs that scale across global teams.
code13 years of coding experience
job17 years of employment as a software developer
bookApplied Networking And System Administration, Information Security with a minor in Philosophy, Applied Networking And System Administration, Information Security with a minor in Philosophy at Rochester Institute of Technology
github-logo-circle

Github Skills (18)

json10
api-rest10
datetime10
python10
apidoc10
api-design10
restful-api10
datetimes10
dates10
api10
python-requests10
http-request10
packet-analysis10
rest-api10
networking9

Programming languages (14)

C#PowerShellCSSC++CHTMLTypeScriptDockerfile

Github contributions (5)

github-logo-circle
facebook/ThreatExchange

Mar 2015 - Jun 2017

Trust & Safety tools for working together to fight digital harms.
Role in this project:
userBack-end Developer
Contributions:152 commits, 48 PRs, 173 comments in 2 years 3 months
Contributions summary:Mike's contributions primarily revolve around the development of a Python library for interacting with Facebook's ThreatExchange API. They implemented initial code setup and structure, focusing on core functionality such as making requests, handling responses, and creating generators. They also refactored the code to include methods for GET, POST, and DELETE requests, along with features to create, edit, expire, and mark items as false positives, showcasing a broad understanding of the API's capabilities. In addition to the core functionality, they designed classes for specific object types to handle interactions with the API.
queryingsecurityshufflecybersecurityblue-team
MITRECND/chopshop

Feb 2013 - Oct 2017

Protocol Analysis/Decoder Framework
Role in this project:
userBack-end Developer
Contributions:11 commits, 1 push, 1 branch in 4 years 8 months
Contributions summary:Mike significantly contributed to the `chopshop` project by implementing new features and improving existing functionalities of the protocol analysis and decoding framework. Their work includes adding the `packet_isodate()` function, which provides a datetime object for time-related operations. They also developed the `metacap` module to parse PCAP files, providing metadata extraction capabilities. Furthermore, the user enhanced the `metacap` module with options for stream-based output.
protocoldecoder
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial