Crew File / Mission Profile
Professional Profile
Shawn Campbell
AI security researcher, red-team practitioner, and hands-on engineering leader.
Twenty-six years building software and engineering teams, five of them in penetration testing and red-team practice. Shawn Campbell works where agents, applications, devices, and the teams shipping them meet: AI threat research, application security, red-team operations, and response when something goes wrong. Two decades of product and platform engineering sit underneath that as working knowledge rather than the headline.
- AI Security
- Red Team
- Security Event Response
- Engineering Leadership
- Applied AI Research
Capabilities Matrix
Core Capabilities
Security-First Engineering SurfaceSkills
AI Security Research
A runnable OWASP LLM Top 10 lab: ten vulnerable agents, one per category, with an attacker payload library, an evaluation harness, a spotlighting defense toggle, and a writeup for each. Indirect prompt injection through RAG is carried furthest, from attack path to measured defense.
Red-Team Methodology
Internal red-team operations, application-layer penetration testing, vulnerability research, proof-of-concept exploit development, and secure code review that turns findings into engineering priorities.
Security Architecture
Threat modeling, application security assessments, secure API and GraphQL design, trust-boundary analysis, and cloud-native guardrails.
Security Event Response
Triage and response for security events, including supply-chain compromise in AI developer tooling, with postmortems turned into durable engineering controls.
Agentic and AI-Assisted Development
Building with coding agents and generative tooling, and the review practice that keeps engineering judgment human: tool-use boundaries, provenance, and failure modes treated as design inputs.
Engineering Leadership
Principal-level technical direction, team formation, security standards, mentoring, and cross-functional execution across security, product, and platform teams.
Platform and Systems Depth
Distributed IoT, smart-access, cloud, and data-pipeline systems across AWS and GCP, built in Swift, Kotlin, C++, TypeScript, Go, Python, Java, and GraphQL.
Operational Record
Experience
Recent AssignmentsProfessional Experience
Brivo
Lead Software Engineer
- Leads two engineering teams of three on a cloud access-control platform with more than 100,000 deployed devices in the field.
- Leads the effort to use AI agents for zero-day discovery across the codebase, and built the threat-hunting agentic AI skills the security work runs on.
- Drives threat modeling, secure code review, CI/CD hardening, and cross-team alignment between engineering, product, and security.
- Translates platform risk into practical engineering decisions for systems connecting cloud services, devices, and user workflows.
Riffle Analytics
Lead AI and Mobile Engineer
Own venture, launched concurrently with the full-time roles below
- Founded the company and directed three contractors building privacy-aware native mobile applications in Swift, Kotlin, and C++ for data-sensitive workflows.
- Designed Python and Node.js data pipelines feeding ML systems while keeping user data protection and operational boundaries visible.
- Created internal tooling and review practices to improve mobile security posture and application resilience.
VividCloud
Principal Software Engineer 2
- Architect reviewing designs and code for 20 engineering teams, and running security testing across those same 20 teams.
- Ran internal red-team assessments and security reviews for three client platforms in insurance, warehouse management, and data warehousing, covering web, server-side Java and C#, and internal Android and iOS applications.
- Caught an unauthenticated web form during design and code review that let anyone send mail from a client internal domain. The open relay would have made a highly convincing phishing channel; it was closed before release.
- Advised on mobile application security, distributed system design, and cloud infrastructure practices with DevSecOps partners.
GrowFlow Corp
Mobile Engineering Lead and Manager
- Grew the mobile engineering team from two to eight, shipping React Native and TypeScript products used by more than 10,000 daily users across 21 states.
- Designed backend services and GraphQL APIs around role-based access, data integrity, and resilience.
- Introduced secure development lifecycle practices and peer security reviews into normal delivery routines.
Minnow
Director of Engineering, Mobile
- Led two teams, two employees and six contractors, owning Swift and Kotlin mobile architecture for distributed, sensor-driven systems connected to IoT and backend platforms.
- Coordinated mobile, hardware, and backend work across Go, Elixir, and Python services with security and quality standards in view.
- Established testing, threat mitigation, and maintainable delivery practices across both employee and contractor teams.
Vox Media
Application Security Engineer
- Ran internal red-team operations as roughly 75% of the role: application-layer penetration testing across internal and external web applications, covering the OWASP Top 10, access control, and information leakage, with particular attention to protecting journalists and their sources.
- Worked primarily in OWASP ZAP and Burp Suite, with custom Python tooling for the cases the standard proxies did not reach.
- Found a SQL injection in a public-facing comments control that exposed database contents including usernames and password hashes, then led remediation with the owning application teams.
- Partnered with development teams on secure code review, threat modeling, infrastructure hardening, and SecDevOps pipelines.
Vets First Choice
Director of Engineering - Mobile and Web Front End
- Built and led three engineering teams totaling 15 people delivering native iOS, Android, web, GraphQL, and data pipeline systems.
- Provided engineering leadership through the growth from startup to publicly traded company, serving customers across all 50 US states, Canada, and parts of Europe.
- Designed AWS platform foundations and backend services using TypeScript, Node.js, Python, and GraphQL.
- Balanced hands-on engineering with team leadership, hiring, standards, and technical direction.
Early Systems Work
Earlier Experience
Foundation LayerEarlier Experience
- 1999 - 2002: Built early web, reporting, financial-market, and EDI systems with PHP, Python, Perl, MySQL, ASP, VB6, and ASP.NET.
- 2003 - 2011: Delivered line-of-business platforms across Rails, Django, PHP, C#, SQL Server, Oracle, and ASP.NET MVC.
- 2011 - 2014: Moved deeper into mobile, microservices, and API systems with Objective-C, Java Android, Python, Go, Node.js, and JavaScript.
Selected Signals
Selected Writing
Writing, Research, and Public ArtifactsSelected Writing
Ten runnable vulnerable agents, one per OWASP LLM Top 10 category, with an attacker payload library, evaluation harness, spotlighting defense toggle, and a writeup per category.
Conference TalkBreaking Agents to Build Better OnesAn accepted hands-on lab talk on the OWASP Top 10 for LLM Applications, with slides, speaker notes, and a live demo runbook.
Lab WriteupBreaking Agents to Build Better Ones: LLM01 Prompt InjectionA local RAG prompt-injection lab for testing agent trust boundaries, attack success, and defensive spotlighting.
A practical map of input, tool, memory, and orchestration risks in production agent workflows.
Notes on AI developer environment risk, package compromise response, offline scanners, and provenance gaps.
LinkedIn PublicationTesting and Packaging JavaScript: Js's final frontierA published presentation on front-end testing and packaging practices that prefigures later delivery and security automation work.
LinkedIn PublicationServers: We don't need any stinkin' serversServerless architecture material from the public profile, relevant to cloud-native system design and operational tradeoffs.
Professional Channels
Links