Stephen Haywood

Senior Manager, Application Security

Chattanooga, Tennessee, United States
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

🤩
Rockstar
🎓
Top School
Stephen Haywood is a senior application security leader with 14 years of hands-on experience and a 20-year background in information security, currently leading application security at EDB and running his own consultancy. He has a rare blend of deep technical skills—pen testing, security engineering, code review, and cryptographic assessment—and proven people leadership, having grown and mentored remote, international teams at 1Password. Stephen contributes practical tooling to the community, including penetration-testing scripts and modules for the widely used Metasploit Framework, demonstrating continued developer-level craftsmanship. He has designed cloud-focused testing procedures and tools for finding high-risk AWS vulnerabilities and has shepherded product and infrastructure security programs end-to-end. Known for empathy and clear communication, he excels at translating complex security risks into actionable roadmaps and policies for diverse organizations. Based in Chattanooga, Tennessee, he pairs multi-disciplinary technical depth with a consultative mindset that helps clients move from risk discovery to measurable remediation.
code14 years of coding experience
job5 years of employment as a software developer
bookBachelor's degree Mathematics and Computer Science, Bachelor's degree Mathematics and Computer Science at King University
github-logo-circle

Github Skills (25)

metasploit10
penetration-testing10
nmap10
python10
vulnerability-scanners10
audit10
cracking10
ruby10
audit-logging10
code-auditing10
scanning10
auditing10
audit-trail10
mysql9
scripting9

Programming languages (7)

JavaShellCJavaScriptGoRubyPython

Github contributions (5)

github-logo-circle
averagesecurityguy/scripts

Dec 2011 - Aug 2020

Scripts I use during pentest engagements.
Role in this project:
userSecurity Engineer
Contributions:363 commits, 5 PRs, 100 pushes in 8 years 10 months
Contributions summary:Stephen primarily contributed to security-related scripts and tools, with the repository description explicitly stating the user's focus on scripts for pentest engagements. The commits show additions and modifications to various scripts. The work included enhancements to existing scripts such as `weak_passwords.py` and creating scripts for web vulnerability scanning, reverse shell, and for use with tools like Metasploit and ike-scan.
pythonsecuritypentestpenetration-testingcybersecurity
rapid7/metasploit-framework

Dec 2011 - Dec 2018

Metasploit Framework
Role in this project:
userSecurity Engineer
Contributions:56 commits, 3 PRs, 25 comments in 7 years 1 month
Contributions summary:Stephen primarily focused on improving the Metasploit Framework's functionality by adding and refining modules. They implemented a module to test MySQL directory write permissions, a critical security assessment tool. Furthermore, the user contributed to a FrontPage credential dumping module, enhancing the framework's ability to identify potential vulnerabilities and gather sensitive information from web servers. The user also made several adjustments to existing modules, including refactoring, improving error handling, and correcting warning messages.
metasploitmetasploit-framework
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial
Stephen Haywood - Senior Manager, Application Security