Shaun McCullough
Certified InstructorCloud Security Architect at GitHub
Specialities
Cloud Security

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCloud Security

Shaun spent 20+ years at the National Security Agency working in all aspects of cyber operations. A software engineer, manager, researcher, and operations lead, including as the technical director of the Blue, Red, and Hunt teams. Today, Shaun is a staff-level Cloud Security Engineer at GitHub focusing on cloud infrastructure. Shaun is also the lead author of SEC541: Cloud Security Threat Detection, which focuses on how attackers target cloud infrastructure and what security analysts, SOC operators, and detection engineers can do to protect their organizations. He has been recognized as one of the top-rated speakers at RSAC Conference, with top-ranked sessions in both 2024 and 2025.
After taking SEC560: Enterprise Penetration Testing with Ed Skoudis in 2011, Shaun knew that using an offensive mindset to create defensive infrastructure was the career path for him. That SANS course changed the trajectory of his career, launching him directly into a renewed focus for information security and never looking back. Since that time, Shaun has immersed himself in learning and understanding the industry, its gaps, and how he can utilize his vast skill set to be a part of it all.
In his current role, Shaun’s focus is on cloud infrastructure and creating new ways to run secure workloads for organizations. Working in both security engineering and software development through the years, Shaun has a particular affinity with the Cloud, as it brings together these two distinct worlds. Knowing the Cloud can be so much more than a virtualized copy of traditional IT infrastructure, Shaun enjoys diving into the *how* of the cloud, reimagining new architecture and operations design patterns that move infrastructure security into the future. He thoroughly enjoys the freedoms, and challenges, of combining these two disciplines into a new type of IT infrastructure.
Shaun is happiest when creating something brand new and really stretching the boundaries of an organization, product platform, or new ways of thinking. He understands that while some of these creations will be a great success, others will not. However, even with the failures, he gains new perspective and skills to take into future projects. This is the type of atmosphere Shaun likes to create for his students.
As a hands-on practitioner with a gift for architecture design, Shaun explores the good and bad of how the Cloud is changing the way the industry secures and runs infrastructure. He believes one of the biggest challenge students face is that the big cloud infrastructure companies are releasing new services that look less and less like the standard on-prem virtualized infrastructure, which in turn presents a steep learning curve for students. As an instructor, Shaun wants to give back to students just as SANS instructors have helped him through the years and therefore provides his own stories and life experiences in the classroom.
Back in 2011 in his first SANS course, Shaun was blown away by the fact SANS instructors were not just relaying canned content, but were sharing their experiences, deep research, and unique perspectives. Now, a SANS instructor himself, he has seen first-hand how students elevate their game after engaging with SANS training, which inspires him to continue to further his own game and stretch his comfort zone.
Shaun gives back to his profession by mentoring and supporting the next generation of cyber professionals at his work. He has spoken at numerous private conferences, SANS events and at BSides DC. He has a bachelor's degree in Computer Engineer from Virginia Tech and a master's degree in Information Security Engineering from the SANS Technology Institute, where he is now a faculty member, as well as numerous professional certifications including: GSE, GSEC, GCIA, GCFE, GXPN, GCIH, GREM, GCFA, GCCC, and GCPM.
In his spare time, Shaun enjoys chauffeuring his children around town and refurbishing old or building new wood furniture.
Shaun is a clear, organized speaker. He is interactive and encourages interaction. He knows his stuff and is very good at explaining the material.
The professionalism, content, and delivery is outstanding. This is my third course and Shaun has been the best instructor. He's well prepared and full of information and knowledge.
Shaun is very well-paced, well-spoken, and incredibly knowledgeable about any of the questions I have regarding the information being presented, and then some.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
SANS 2026 Cloud Security Exchange Summit Solutions Track delivers a focused look at the tools, architectures, and operational strategies driving secure and resilient cloud environments across AWS, Google Cloud, and Microsoft Azure.

Move beyond chat-based AI. This session shows how agentic AI can automate cloud security workflows, mapping Copilot CLI concepts to real use cases like Terraform compliance, CIS benchmarks, and detection validation.

Part 5: Key Insights from Cloud Security Experts: Straight Talk on Cloud SecurityIn this final session, industry leaders reflect on key lessons from the series, highlighting critical aspects of cloud security, such as the shared responsibility model, evolving security architectures, and the role of continuous monitoring. As AI and advanced tools for threat detection continue to grow, the panelists share advice on staying ahead of the curve by focusing on long-term security strategies and fostering collaboration between security teams and cloud providers.

In this first session of our detection engineering webinar series, we will discuss what detection engineering really is, how it might be different from what you are currently doing, and what tools we use to implement a detection engineering process.

Part 1: Building a Cloud Security Strategy: A Step-by-Step GuideIn this session, SANS Institute experts will guide you through the key steps in developing a robust cloud security strategy. Whether you're just starting or looking to strengthen your approach, this webcast covers everything from understanding your cloud environment to building a threat detection program and preparing for incident response.

In AWS, the Lambda function represents a new approach to crafting and deploying compute workflows. While they free us from the burdens of patching VMs, lurking in the dark are countless ways deployment and operations can go horribly wrong.

Captain Maverick has helped the Aviata Cloud team build and deploy a Kubernetes infrastructure to manage the applications needed to run the `Airborne io 24` aircraft and its mission of navigating the globe in the most advanced aircraft ever created.

This is a 2-hour hands-on workshop. As with any enterprise environment, we can (and should) focus on hardening our defenses to keep the adversaries out, but these defenses may some day be evaded via a variety of methods. Cloud is no different.

The evil Professor Moriarty is hunting for a hiding Sherlock Holmes, whose whereabouts are only known to Sherlock’s brother, Mycroft. In this webinar, we will discuss how Moriarty and his gang hacked into Mycroft’s web environment to search for clues, and how Sherlock turned the tables and detected their every step. This webinar is based on a newly released SANS poster that focuses on Cloud Threat Detection, set in the world of modern-day Sherlock Homes.

You are entering Level Cloud Security at the SANS Cyber Solutions Fest 2021. This full-day session, led by SANS cloud expert Shaun McCullough, will explore innovative cybersecurity solutions that can help security teams adapt to cloud deployments in areas such as network security, threat intelligence, container and serverless security, and many more. The focus we need to look at is what comes next in Cloud Security?

Review relevant educational resources made with contribution from this instructor.