Shaun McCullough
Certified InstructorCloud Security Architect at GitHub
Specialities
Cloud Security
Experience SANS training through course previews.
Learn MoreLet us help.
Contact usConnect, learn, and share with other cybersecurity professionals
Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders
Become a member for instant access to our free resources.
Sign UpMission-focused cybersecurity training for government, defense, and education
Explore industry-specific programming and customized training solutions
Sponsor a SANS event or research paper
We're here to help.
Contact UsCloud Security
Shaun spent 20+ years at the National Security Agency working in all aspects of cyber operations. A software engineer, manager, researcher, and operations lead, including as the technical director of the Blue, Red, and Hunt teams. Today, Shaun is a staff level Cloud Security Engineer at GitHub focusing on cloud infrastructure. Shaun is also the lead author of SANS SEC541: Cloud Security Threat Detection, which focuses on how attackers target cloud infrastructure and what security analysts, SOC operators, and detection engineers can do to protect their organizations.
Shaun is a clear, organized speaker. He is interactive and encourages interaction. He knows his stuff and is very good at explaining the material.
The professionalism, content, and delivery is outstanding. This is my third course and Shaun has been the best instructor. He's well prepared and full of information and knowledge.
Shaun is very well-paced, well-spoken, and incredibly knowledgeable about any of the questions I have regarding the information being presented, and then some.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
You are entering Level Cloud Security at the SANS Cyber Solutions Fest 2021. This full-day session, led by SANS cloud expert Shaun McCullough, will explore innovative cybersecurity solutions that can help security teams adapt to cloud deployments in areas such as network security, threat intelligence, container and serverless security, and many more. The focus we need to look at is what comes next in Cloud Security?
The evil Professor Moriarty is hunting for a hiding Sherlock Holmes, whose whereabouts are only known to Sherlock’s brother, Mycroft. In this webinar, we will discuss how Moriarty and his gang hacked into Mycroft’s web environment to search for clues, and how Sherlock turned the tables and detected their every step. This webinar is based on a newly released SANS poster that focuses on Cloud Threat Detection, set in the world of modern-day Sherlock Homes.
This is a 2-hour hands-on workshop. As with any enterprise environment, we can (and should) focus on hardening our defenses to keep the adversaries out, but these defenses may some day be evaded via a variety of methods. Cloud is no different.
Captain Maverick has helped the Aviata Cloud team build and deploy a Kubernetes infrastructure to manage the applications needed to run the `Airborne io 24` aircraft and its mission of navigating the globe in the most advanced aircraft ever created.
In AWS, the Lambda function represents a new approach to crafting and deploying compute workflows. While they free us from the burdens of patching VMs, lurking in the dark are countless ways deployment and operations can go horribly wrong.
Part 1: Building a Cloud Security Strategy: A Step-by-Step GuideIn this session, SANS Institute experts will guide you through the key steps in developing a robust cloud security strategy. Whether you're just starting or looking to strengthen your approach, this webcast covers everything from understanding your cloud environment to building a threat detection program and preparing for incident response.
In this first session of our detection engineering webinar series, we will discuss what detection engineering really is, how it might be different from what you are currently doing, and what tools we use to implement a detection engineering process.
Part 5: Key Insights from Cloud Security Experts: Straight Talk on Cloud SecurityIn this final session, industry leaders reflect on key lessons from the series, highlighting critical aspects of cloud security, such as the shared responsibility model, evolving security architectures, and the role of continuous monitoring. As AI and advanced tools for threat detection continue to grow, the panelists share advice on staying ahead of the curve by focusing on long-term security strategies and fostering collaboration between security teams and cloud providers.
Review relevant educational resources made with contribution from this instructor.