Paul Mccann

Principal Product Security Engineer at Elastic

Dublin, Ireland
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

🤩
Rockstar
🎓
Top School
Paul Mccann is a Principal Product Security Engineer with 12 years of experience embedding security into the software development lifecycle and leading cross-functional teams at companies like Elastic and Axway. He blends offensive security expertise—red teaming, pentesting and CTF design—with DevSecOps practice, threat modeling, and vulnerability risk assessment to drive secure product delivery. Paul has a hands-on engineering background, contributing a NoSQL injection training level to the popular OWASP Security Shepherd platform and building CTF challenges used at national and international events. He designs and delivers developer and executive security training, and has taught an academic module on ethical hacking, showing a commitment to education across industry and academia. Known for automating security tooling in CI/CD and owning SSDLC programs, he pairs technical depth with practical program leadership. Based in Dublin, he holds a Master’s in Information Security & Digital Forensics and often bridges offensive techniques into defensive improvements that scale across product teams.
code12 years of coding experience
job7 years of employment as a software developer
bookMaster's Degree Information Security & Digital Forensics, Master's Degree Information Security & Digital Forensics at Technological University Dublin
github-logo-circle

Github Skills (6)

javas10
mongodb10
java10
mongodb-database10
servlet10
security9

Programming languages (13)

C#JavaHandlebarsGoHTMLKotlinTypeScriptDockerfile

Github contributions (5)

github-logo-circle
OWASP/SecurityShepherd

Jun 2015 - Dec 2022

Web and mobile application security training platform
Role in this project:
userBack-end Developer
Contributions:30 reviews, 309 commits, 146 PRs in 7 years 7 months
Contributions summary:Paul implemented a NoSQL injection level using MongoDB, including schema and driver integration. This involved creating a vulnerable servlet, `NoSqlInjection1`, which queries a MongoDB database, likely to demonstrate or exploit a security flaw. They also made adjustments to the relevant JSP file and integrated the level into the Security Shepherd platform. Additional commits include ranking the new NoSQL injection level, indicating its incorporation into the training program.
application-securitymobile-applicationsecuritypenetration-testingtraining
vigour-io/is-number-like

Jun 2018 - Nov 2024

Checks whether provided parameter looks like a number
Contributions:2 PRs, 1 comment, 1 issue in 6 years 6 months
checksparameter
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial