Paul McCarty

CEO

Gold Coast, Queensland, Australia26 yrs experience

Key Highlights

  • Founder of SecureStack, pioneering ASPM solutions.
  • Expert in automation with tools like Ansible and Terraform.
  • Extensive experience with public cloud security across multiple platforms.
Stackforce AI infers this person is a cybersecurity and cloud infrastructure expert with extensive experience in SaaS and DevSecOps.

Contact

Skills

Other Skills

API DevelopmentAutomationCapital RaisingCloud ComputingCloud SecurityConfiguration ManagementContinuous ImprovementData CenterDisaster RecoveryDockerECSELKGitGo-to-market StrategyIDS (Intrusion Detection System)

About

I have been building innovative businesses on crazy ideas since the mid-nineties when I started my first computer store in Logan, Utah in 1996. Since then I have worked with some amazing companies building awesome products including John Deere, Boeing, Regence Blue Cross/Blue Shield, NASA Jet Propulsion Lab, US Army, and Queensland Government. In 2017 I founded SecureStack where our mission is to help software engineers build and deliver better, more secure software every single day. What I'm passionate about: Automation - I am obsessed. Truly. Whether it's backups, app stability, or deployment, I've automated it. Weapons of choice: Ansible, Puppet, shell scripts, Terraform, ruby, Cloud Formation and Powershell. (in that order) Linux - It's the best server operating system out there. I live, breath and die Linux. I'm an Enterprise Linux guy; I've contributed to Caldera and yes, I hate systemd. Public Cloud - I spend most days in the public cloud, building, automating, and finding better ways to make my systems more secure. I spend most of my time in AWS but I also have workloads in Azure, GCP and Alibaba Cloud.

Experience

Open source malware

Maintainer

Nov 2025Present · 4 mos

  • I maintain the OpenSourceMalware.com ecosystem. OSM is a database and collaboration platform purpose-built to protect organizations from malicious packages, source code repositories and other open source threats.

Safety cybersecurity

Head of Research

Mar 2025Present · 1 yr

  • Build and manage the world's best research team that consistently delivers cutting-edge research
  • Write kick ass security tools
  • Create research-related content for blog, podcast, and conference contexts

Sourcecodered

Head of Security Research & Trainer

Feb 2024Present · 2 yrs 1 mo · Australia · Remote

  • Cutting edge software supply chain security research
  • Deliver software supply chain red team engagements
  • Deliver training around software supply chain and application security

Gitlab

Software Supply Chain Red Team

Feb 2024Jul 2024 · 5 mos · Gold Coast · Remote

  • Introduce Software Supply Chain attack methodologies to the existing Red Team operational model.
  • Updated the Red Team operation model to include "continuous operations" and adapted our Rules of Engagement.
  • Interact with "Secure" product owners (SAST, DAST, Compliance) and Trust & Safety to identify areas where the Red Team and I can help.

Bsides gold coast

BSides Gold Coast Organizer

Jan 2024Present · 2 yrs 2 mos · Gold Coast, Queensland, Australia · Remote

  • • I'm one of the organizers for the 2026 Gold Coast BSides being held on May 23, 2026

Stealth startup

Advisor

Mar 2023Present · 3 yrs · Australia · Remote

  • Help startup by leveraging my experience building and running startups over 30 years
  • Act as security advisor for highly regulated industry startup

Sectalks

Gold Coast SecTalks Organizer

Jan 2023Present · 3 yrs 2 mos · Gold Coast · Hybrid

Something real ventures

Mentor

Jan 2022Present · 4 yrs 2 mos · Melbourne, Victoria, Australia

  • Listen to and mentor startup founders and offer advice or assistance when I can help.
  • Leverage my experience as a technical founder to help them navigate product design, capital raising, customer discovery, product security, and go-to-market challenges that most startups will face in their early stages.

Cyrise

Accelerator Cohort Member

Oct 2018May 2019 · 7 mos · Melbourne, Victoria, Australia

  • Completed 6-month startup accelerator with Australia's only cybersecurity accelerator.
  • Built market research and GTM for new startup SecureStack
  • Built relationships with industry buyers, advisors and investors that will last for many years

Queensland treasury

CloudOps Engineering Lead - Contract

Nov 2017Jul 2018 · 8 mos · Greater Brisbane Area

  • Built testing and deployment automation for Queensland Treasury's cloud migration and operations with Terraform, Ansible and Ansible Tower
  • I managed vendor relationships with agencies to make sure that they delivered secure code and applications
  • Spearheaded security assessments and testing for cloud environments

Qtac

DevOps Engineering Lead - Contract

Jun 2017Aug 2017 · 2 mos · Greater Brisbane Area

  • Built first CI/CD processes for AWS ECS-based workloads for QTAC.
  • Built highly scalable logging solution utilizing AWS Elasticsearch for containerized applications running in the cloud.

Securestack

CEO & Founder

May 2017Feb 2024 · 6 yrs 9 mos · Gold Coast, Australia

  • SecureStack was an early entrant to the ASPM space that I founded in 2017. Our ASPM product was the first in the world to combine source code, web vulnerability scanning, container scanning and cloud security posture testing in one product. Later on, we added compliance and SBOMs which really galvanized our position as a product that could deliver complete SDLC security coverage in one solution, one dashboard and one subscription.
  • I wrote and built the original product myself, but after raising capital from Australian venture investors in 2020 I was able to hire an amazing team and move into a product owner role. I was a very technical CEO so I spent a lot of time building partnerships with AWS, GitHub, Microsoft, and Atlassian to bring our product to a global market via those channels. I also built partnerships with small to medium MSSPs as a way to leverage those relationships to gain access to new customers and new markets. These two channels accounted for more than 80% of our annual revenue.

Magic memories

DevOps Engineering Lead

May 2016May 2017 · 1 yr · Gold Coast, Australia

  • Led a small DevSecOps team that owned all corporate cloud and application security.
  • Built first continuous integration and deployment (CI/CD) processes for the company
  • Managed all cloud and data center operations for Queensland and NSW

Corelogic rp data

DevSecOps Engineer - Contract

Apr 2016May 2016 · 1 mo · Greater Brisbane Area

  • I built Corelogics first global vulnerability management platform
  • I built intrusion detection, logging and SIEM functionality for the global organization

Cambia health solutions

Platform Engineering Lead

Apr 2012Apr 2016 · 4 yrs · Park City, Utah

  • I authored Cambia's long term container strategy. My goal was to utilize EC2 Container Service (ECS) in a way that allows Cambia to use AWS tools as well as their own. No vendor lock-in. Deployment utilizes Jenkins and Ansible to deploy applications and start and stop the Docker container fabric. Cambia needs to migrate to the cloud but we want to do so in a way that is secure and fully managed.
  • I was part of a team that was building Cambia's NextGen PaaS solution. Our buildstack uses Ansible, Docker, python, haproxy and git as the primary components of the platform stack. I helped migrate applications to AWS and looked at Rancher as a possible management/orchestration tool. The idea was to build containerized applications using Docker and migrate our existing applications to this model. I want my tool to be able to manage any endpoint regardless of where it is: AWS, Azure, local infrastructure, my macbook... wherever!
  • I owned the Cambia Redhat Linux virtual provisioning and build spec. This included the creation, test and management of Vmware templates and automation for all of our Redhat infrastructure, customized for both role and environment.
  • I migrated the existing Perl and Jenkins based web and app server deployments into Ansible playbooks, and/or Ansible Tower so our tier 2 staff can take over this responsibility.
  • Looked at Openstack and Openshift as possible complementary pieces to our in-house IaaS and PaaS tools. I also looked at using Azure as our IaaS provider.
  • I was heavily focused on scripting automation (Ansible, bash shell and Python) into our VMware linux build process using a buildstack process that builds a server, any custom NAS mounts or local LVM filesystems, installs platform components and customized application stack.
  • Administered Websphere, iPlanet, IHS, Apache, Tomcat, OpenESB, GlassFish and JCAPS web application servers and their associated monitoring
  • Managed F5 load balancers for web environments

Nexus it consultants

System Admin/Network Engineer

Apr 2009Nov 2010 · 1 yr 7 mos · Park City, UT

  • Led a small team of engineers who delivered managed services to customers in Utah
  • Introduced cloud-based infrastructure and security services to traditional SMB-focused MSP
  • Was the primary Unix/Linux and Network consultant

Tekutah.com

Infrastructure & Security Consultant

Dec 2007Mar 2016 · 8 yrs 3 mos · Park City, UT

  • I built and managed a small consultancy specializing in cloud and application security
  • Delivered security consulting services including penetration testing, risk and PCI assessments
  • Contracted with HP to create their cloud and distributed computing certification tests including ATA Client, Server, and Networking as well as the first Cloud certification in the industry

Maverik inc

Unix System Administrator

Apr 2007Dec 2007 · 8 mos · Salt Lake City

  • Managed FreeBSD and Linux distributed environment for large enterprise organization
  • Led the infrastructure team through a successful PCI-DSS tier 1 audit
  • Built and deployed automation to meet strict compliance requirements.

Linux networx

Field Linux Engineer

Apr 2004Dec 2006 · 2 yrs 8 mos · Bluffdale, UT

  • Built and installed Linux-based HPC systems in protected US government facilities.
  • Wrote and deployed custom Linux operating systems and drivers to deliver grid-based high-performance computing clusters
  • Created early IP firewalling orchestration for protected HPC clusters

Regence bluecross blueshield

Senior Unix Admin

Jul 2001Dec 2003 · 2 yrs 5 mos · Salt Lake City Metropolitan Area

  • Worked as Senior Unix Engineer on the Unix team administering Solaris and AIX.
  • Was colocated with security team to help embed security functions in Unix distributed systems
  • Cowrote first security hardening document for Unix and distributed systems for Blue Cross/Blue Shield
  • Managed Unix teams HIPAA compliance program

Iarchives

System Admin

Jan 2001Jun 2001 · 5 mos · Orem, Utah

  • • Wrote the Linux operating system and SCSI drivers for custom hardware used to run their proprietary image processing and optimization solution.

Mccarty computers

Proud Owner and CEO

Sep 1996May 2001 · 4 yrs 8 mos · Logan, UT

  • Built and managed a retail storefront and a consultancy specializing in unix and networking.
  • Managed a team of up to 8 technicians

Education

Wayne State University

Computer Science — History

Jan 1993Jan 1995

Cass Technical High School

Jan 1991Jan 1993

Stackforce found 100+ more professionals with API Development & Automation

Explore similar profiles based on matching skills and experience