Aidan McDonagh

Software & Security Engineer

Aidan McDonagh

DevSecOps · Application Security · Penetration Testing

Certified security professional building and defending production systems. Currently a Penetration Tester at Starling Bank, testing web apps, infrastructure and internal systems end-to-end. Background in Software Engineering, System Security and Ethical Hacking from the University of Portsmouth, since certified in Penetration Testing (CompTIA PenTest+, Security+).

Bishops Stortford, Hertfordshire

Experience

Penetration Tester

Starling Bank
  • Penetration testing across web applications, infrastructure, in-office/WiFi security and Windows environments (Azure AD)
  • Built internal Go security tooling: a TruffleHog triager/reporter and SAST scanning with an LLM-based reviewer
  • Building a Python-based Penetration Testing AI agent Harness and IOC Detection Script for supply chain attacks
  • Led penetration testing of Ember (a fintech acquired by Starling) and of developer-facing passkey implementations
  • Ensured Settle Up for Business was PCI-DSS compliant with Tenable ASV Scanning and Remediation
  • Go
  • Python
  • Java / Burp Suite
  • Azure AD
  • Wireless & Infrastructure Security
  • SAST / LLM Review
  • IOC Detection
  • Passkeys / WebAuthn

DevSecOps Engineer / Software Engineer (Security) & Team Lead

Sky UK
  • Tech Lead on a 12-person team building Wholesale Ethernet applications serving businesses across the UK
  • Identified severe vulnerabilities in Wholesale Ethernet 1.0 within the first two weeks and mitigated a risk evaluated at up to £14M
  • Lead the engineering team for development of Wholesale Ethernet 2.0
  • Vice Chair of the Security Forums, driving cybersecurity engagement across the company
  • Won a Google Generative AI competition
  • Django 5 / DRF
  • FastAPI
  • PostgreSQL / PostGIS
  • Redis
  • RabbitMQ
  • ReactJS
  • Bandit / Semgrep
  • Trivy
  • GitLab CI/CD
  • Docker
  • Ansible
  • Google Cloud

Software Engineer (Security)

Unipart Digital
  • Built device authentication and barcode/QR scanning systems running in production warehouse logistics
  • Reduced bundle sizes and identified/mitigated race conditions across multiple applications
  • Applied penetration-testing experience to harden current and future applications
  • React
  • Material UI
  • Redux Toolkit
  • Django / DRF
  • PostgreSQL
  • Jenkins
  • Docker Compose
  • Ansible
  • OpenStack

DevSecOps Engineer / Penetration Tester

KHIPU Networks
  • First engineer hired into the role, with freedom to select the technology stack
  • Built a SIEM service monitoring Access Points and Switches, alerting on outages or compromise
  • Built a technical-documentation generator that significantly sped up report delivery
  • Delivered analytics for Greenbone OpenVAS scans and stood up the company's Penetration Testing team
  • Node.js / Fastify
  • Angular
  • TypeScript
  • Socket.io
  • Deno.js
  • Python
  • Docker
  • RancherOS

Projects

Web Developer

Laura McDonagh Illustrations →
  • Freelance single-page portfolio site for an illustration artist, built front-to-back solo
  • Implemented lazy-loading, responsive srcsets and automated next-gen image formats
  • HTML5 / SCSS
  • JavaScript
  • Bootstrap 5
  • Node.js / Bun

Web Developer

Westport Car Parks →
  • Freelance single-page portfolio site showcasing the company's property development work
  • HTML5 / SCSS
  • JavaScript
  • Bootstrap 5
  • Node.js

Skills

Languages
  • Python
  • JavaScript / TypeScript
  • Java
  • C
  • C++
  • C#
  • Go
  • Ruby
  • Swift
  • Haskell
Web & Frameworks
  • React / Redux
  • Angular
  • Node.js
  • Express
  • Fastify
  • Nest.js
  • Django / DRF
  • HTML5 / CSS3 / Sass
  • Bootstrap
DevOps & Cloud
  • Docker / Docker Compose
  • Ansible
  • Jenkins
  • GitLab CI/CD
  • Google Cloud
  • OpenStack
  • Git / GitHub
Testing
  • Jest
  • Cypress
  • Mocha
  • React Testing Library
  • Enzyme
  • Pytest
Databases
  • PostgreSQL
  • MySQL
  • MongoDB
  • Redis
  • Firebase

Security Approach

Trained in Ethical Hacking and Penetration Testing at university under the System Security and Reliable & Secure Systems units, and applied continuously since. Currently working toward OSCP, with CREST to follow.

  • Threat Analysis: tracking current and emerging threats against the OWASP Top 10 and NIST NVD
  • Penetration Testing: applications, websites and infrastructure
  • Security Tooling: hands-on with Kali Linux, Burp Suite, SQLMap, Metasploit and Nmap
  • Virtualisation: VMware, VirtualBox and Virtual Machine Manager for isolated test environments
  • Offence vs. Defence: internal red-team exercises against the PTES external testing standard
Practice & Competitions
  • TryHackMe
  • HackTheBox
  • Vulnhub
  • HackerRank
  • UK Cyber Security Challenge

Education

BSc (Hons) Software Engineering

University of Portsmouth

High 2:1 · GPA 3.25 · Dissertation: “The HandyMan: A Bartender's Encyclopedia”

  • System Security
  • Reliable & Secure Systems
  • Security & Cryptography

A-Levels: Maths, ICT & Economics

Aldenham School

UCAS Points: 220 · 11 GCSEs A*–C

Interests

Outside of work I keep learning: courses on Udacity, Udemy and Sololearn, IBM's Quantum/Bitcoin/Security tracks, and programming challenges on HackerRank. Outside of the screen, I train self-defence (BJJ & kickboxing), play squash and golf, and played American Football at Portsmouth University.

Learning
  • Udacity
  • Udemy
  • Sololearn
  • HackerRank
Sport
  • Brazilian Jiu-Jitsu
  • Kickboxing
  • Squash
  • Golf
  • American Football
  • Powerlifting