Matthew Burns

Senior Security Engineer • Cloud security, AppSec, IaC, governance, offensive testing

Matthew Burns

About me

Hi, I’m Matt. I’m a senior security engineer working across cloud platforms (AWS/Azure/GCP), application security, infrastructure-as-code, governance and compliance (NIST 800-53, SOC 2, FedRAMP, DoD), and offensive testing. I work where engineering meets risk: turning policies into pipelines, mapping controls to tooling, and treating security as a product feature rather than a gate.

I’m passionate about penetration testing and offensive security. I recently earned my GIAC Certified Penetration Tester (GCPN) and enjoy exploring vulnerabilities and attack vectors in my home lab.

I’m also actively exploring how AI augments modern software delivery and where it strengthens security engineering practice. A current result is devsecops.binbashburns.com, a vendor-neutral security stack modeler that maps tool selections to NIST CSF 2.0 / SOC 2 / SSDF controls and exports both a Digital SSP and a runnable CI workflow.


Experience

Penchecks Trust - DevSecOps Engineer

Aug 2025 – Presentpenchecks.com

Army National Guard (KY) - Cyber Warfare Technician (170A), Warrant Officer

Jun 2020 – Presentnationalguard.com

Defense Unicorns - DevSecOps Engineer

Aug 2024 – Aug 2025defenseunicorns.com

Coalfire - Cloud Engineer II

Jul 2023 – Aug 2024coalfire.com

DHS CISA - IT Cybersecurity Specialist

Oct 2022 – Jul 2023cisa.gov

Coalfire - Cloud Engineer I

Feb 2022 – Oct 2022coalfire.com

Bechtel Corporation - Cybersecurity System Administrator

Nov 2021 – Feb 2022bechtel.com

Senture, LLC - Security Analyst

Nov 2019 – Oct 2021senture.com


Education

CodeYou (Louisville) - Software Engineering with C# (Student)

Aug 2025 – Apr 2026

University of the Cumberlands - B.A.S. Information Technology (Cybersecurity)

Apr 2022 – May 2023

Somerset Community College - A.A.S. Information Security

2017 – 2019


Volunteer & Community

CodeYou (Louisville) - Cybersecurity Mentor (Volunteer)

Aug 2025 – Present

Pet Cancer Foundation - Governance, Risk & Compliance (Volunteer)

Jun 2025 – Present


Projects

Security Stack Modeler

Live site GitHub

SoldierSave

Live site GitHub

BadgeBox

Live site GitHub


Interested in collaborating on cloud-native or DevSecOps work? I’m always happy to connect.