Stephen Haywood is a senior application security leader with 14 years of hands-on experience and a 20-year background in information security, currently leading application security at EDB and running his own consultancy. He has a rare blend of deep technical skills—pen testing, security engineering, code review, and cryptographic assessment—and proven people leadership, having grown and mentored remote, international teams at 1Password. Stephen contributes practical tooling to the community, including penetration-testing scripts and modules for the widely used Metasploit Framework, demonstrating continued developer-level craftsmanship. He has designed cloud-focused testing procedures and tools for finding high-risk AWS vulnerabilities and has shepherded product and infrastructure security programs end-to-end. Known for empathy and clear communication, he excels at translating complex security risks into actionable roadmaps and policies for diverse organizations. Based in Chattanooga, Tennessee, he pairs multi-disciplinary technical depth with a consultative mindset that helps clients move from risk discovery to measurable remediation.
14 years of coding experience
5 years of employment as a software developer
Bachelor's degree Mathematics and Computer Science, Bachelor's degree Mathematics and Computer Science at King University
Contributions:363 commits, 5 PRs, 100 pushes in 8 years 10 months
Contributions summary:Stephen primarily contributed to security-related scripts and tools, with the repository description explicitly stating the user's focus on scripts for pentest engagements. The commits show additions and modifications to various scripts. The work included enhancements to existing scripts such as `weak_passwords.py` and creating scripts for web vulnerability scanning, reverse shell, and for use with tools like Metasploit and ike-scan.
Contributions:56 commits, 3 PRs, 25 comments in 7 years 1 month
Contributions summary:Stephen primarily focused on improving the Metasploit Framework's functionality by adding and refining modules. They implemented a module to test MySQL directory write permissions, a critical security assessment tool. Furthermore, the user contributed to a FrontPage credential dumping module, enhancing the framework's ability to identify potential vulnerabilities and gather sensitive information from web servers. The user also made several adjustments to existing modules, including refactoring, improving error handling, and correcting warning messages.
metasploitmetasploit-framework
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial
Stephen Haywood - Senior Manager, Application Security