Group Purchasing
Group Purchasing

Doug McKee

Certified InstructorDirector of Vulnerability Intelligence at Rapid7

Specialities

Offensive Operations

Doug McKee

About Doug McKee

Doug McKee’s work centers around the core principle that real defense starts with understanding how an attacker thinks. As Director of Vulnerability Intelligence at Rapid7, he leads teams that turn vulnerability research into practical defense. His approach follows the “think red, act blue” mindset, using offensive insight to drive defensive precision. That same philosophy shapes his work as a SANS Author and Instructor, executive advisor for Rapid Risk Radar, and long-time advocate for hands-on, data-driven security research.

Doug has written training on product security testing to help defenders “break things safely” and apply those lessons to build stronger systems. His research blends offensive analysis, vulnerability discovery, and exploitation to expose where technology fails and how to transform those failures into protection strategies.

Doug’s cybersecurity journey began in public service with the U.S. Department of Defense, where he performed penetration testing, malware analysis, and risk mitigation for critical systems. He later led Protiviti’s Dallas Cyber Lab before joining McAfee’s Advanced Threat Research team as Principal Engineer and Lead Security Researcher. After the McAfee–FireEye merger, he became Director of Vulnerability Research at Trellix, where he led a global team focused on exploit development and vulnerability discovery. As Executive Director of Threat Research at SonicWall, he guided teams tracking thousands of new vulnerabilities each year and translating that intelligence into actionable defense and product content. Today at Rapid7, Doug continues that mission, combining field research, exploit data, and attacker behavior analysis to help organizations focus on the threats that matter most.

Doug holds multiple information assurance certifications, including the CNSSI 4013–4016 series and several SANS and Offensive Security certifications across multiple domains. A SANS 660 Capture the Flag winner and Department of Defense Award of Excellence recipient, he earned both his Bachelor’s and Master’s degrees in Computer Security and Information Assurance from East Stroudsburg University of Pennsylvania. He also serves as faculty at the SANS Technology Institute, an NSA Center of Academic Excellence in Cyber Defense. His research has resulted in numerous CVEs and has been featured in Wired, Politico, Bleeping Computer, VentureBeat, and many other leading publications.

Doug regularly speaks at conferences including RSA, Black Hat, DEF CON, and Hardware.io, where his sessions range from highly technical to process improvement. Known for his ability to translate highly technical concepts to any audience and practical teaching style, he emphasizes learning through real experiences. Students describe his classes as fast-paced, immersive, and deeply relevant. His philosophy is simple: “Attackers never stop learning and adapting, so neither can we.” For Doug, success in cybersecurity isn’t about perfection but instead about persistence, curiosity, and the courage to learn from our mistakes.

Qualifications Summary
  • SANS Certified Instructor of SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking
  • Director of Vulnerability Intelligence, Rapid7
  • Former Executive Director of Threat Research, SonicWall
  • Former Director of Vulnerability Research, Trellix
  • Former Principal Engineer & Lead Security Researcher, McAfee Advanced Threat Research
  • Former Security Engineer, US Department of Defense
  • Selected as one of the 32 Most Influential Malware Research Professionals (2019)
  • Master of Science in Computer and Information Systems Security, East Stroudsburg University of Pennsylvania
  • Bachelor of Science in Computer Security and Bachelor of Science in Computer Science, East Stroudsburg University of Pennsylvania
  • Faculty Member, SANS Technology Institute
  • GIAC Certifications: GXPN, GDAT
  • OSCP, OSWP, and CNSSI 4013-4016 Certified
  • Conference Speaker: RSA, BlackHat, DEF CON
  • Rapid Risk Radar Executive Advisor
  • CyberPlayback Advisory Board Member

Press & Media