Giter Site home page Giter Site logo

my banner

My name is Paul McCarty and I'm the founder of SecureStack. I like to describe SecureStack as the world's first DevSecOps Maturity Platform because we help our customers assess and then accelerate their DevSecOps journey.

πŸ’« About Me

I am a DevSecOps evangelist and thought leader obsessed with applied application security and securing the software supply chain. I like to say that I'm a technical founder who likes to work at the intersection of product delivery and security. I have built and led multiple product delivery teams: for the government, in the private sector and for my own startup, SecureStack.

I am a frequent public speaker and have presented at many events including: OWASP, SecTalks, CrikeyCon, TuskCon, RSA, AISA, and multiple BSides. I am a proud father, and I used to snowboard a lot.

πŸ“« How to reach me? paulm (at) securestack.com

My Projects

I wrote the DevSecOps Playbook in 2022 as a step-by-step guide for organizations to implement DevSecOps programs regardless of their size or industry.

The software supply chain is under increasing attack, but there is no industry standard definition of what the software supply chain is. How can we hope to secure the SSC if we don't know what's in it? This project is my attempt at creating a common definition to help organizations understand the scope and breadth of the SSC.

OSC&R is a comprehensive, systematic and actionable way to understand attacker behaviors and techniques with respect to the software supply chain. It is a matrix style document modeled on the MITRE ATT&CK matrix. I am a contributing member to the project.

The Minimal Viable Secure Product MVSP is a minimum security baseline for enterprise-ready products and services. The baseline checklist can be used at various stages of the sales cycle, from RFP through to contractual controls. I am an original contributing member.

πŸ‘₯ Connect With Me

πŸ’»Tech Stack

AWS Cloudflare Azure Google Cloud Apache Jenkins Nginx Ansible Notion ElasticSearch Docker Postman Terraform

πŸ“Š Github Status

Paul McCarty's Projects

ami_finder icon ami_finder

Find your ami_id's for all regions for your products in the AWS Marketplace

apac-conferences icon apac-conferences

A community contributed consolidated list of InfoSec meetups in the Asia Pacific region.

arjun icon arjun

HTTP parameter discovery suite.

awesome-api-security icon awesome-api-security

A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.

buildkite-agent icon buildkite-agent

The Buildkite Agent is an open-source toolkit written in Go for securely running build jobs on any device or network

bun icon bun

Incredibly fast JavaScript runtime, bundler, test runner, and package manager – all in one

clairvoyance icon clairvoyance

Obtain GraphQL API schema even if the introspection is disabled

cloud-headers icon cloud-headers

This is a authoratative listing of all the HTTP headers used by the major cloud providers

darkmass icon darkmass

Automated recon optimized for fast, efficient mass scanning

demo-java icon demo-java

GitHub Advanced Security scanning tutorial repository for Java

devsecops-playbook icon devsecops-playbook

This is a step-by-step guide to implementing a DevSecOps program for any size organization

docker icon docker

Docker - the open-source application container engine

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    πŸ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. πŸ“ŠπŸ“ˆπŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❀️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.