Sign in to view Sean’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Washington, District of Columbia, United States
Sign in to view Sean’s full profile
Sean can introduce you to 10+ people at Chainguard
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
439 followers
443 connections
Sign in to view Sean’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Sean
Sean can introduce you to 10+ people at Chainguard
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Sean
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Sean’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
Chainguard, backed by Sequoia Capital…
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Activity
439 followers
-
Sean F. shared thisAssemble 2026, Chainguard’s event for engineering and security leaders committed to building the future of secure software, is coming to New York City! 💜 If you like: • modern software supply chains • security that actually works in production • learning from people doing the work then this is the crowd you want to hang with! #Assemble2026 https://lnkd.in/eVsWxHZD
-
Sean F. shared thisVery fun week at NYC Tech Forum and like Chris Nguyen mentioned, already looking forward to Chainguard Assemble: https://lnkd.in/eG4u_DbU!Sean F. shared thisWrapping up a very productive NYC Tech Forum week! Thank you to everyone who stopped by our event and booth, the agencies who keep our city running, and our strong partner community, including GitLab and Datadog. Excited to continue more local events in 2026, including Chainguard’s first Assemble Conference in NYC on March 16-18! 😎 (event link in comments)
-
Sean F. shared thisGreat opportunity to volunteer with us!Sean F. shared this🚨 We’re Giving a SHIFT this holiday season! 🚨 Chainguard is teaming up with Miriam's Kitchen for a hands-on volunteer event in Washington, DC on December 16th from 1–4 PM ET, and we’re calling on our community to join us! We’ll be: ✨ Building snack packs & hygiene kits 🧵 Making warm blankets for our local unhoused neighbors 🍽️ Enjoying food, drinks & great conversations 🚗 Using Uber vouchers to get everyone there with ease Spots are limited—and filling fast! If you’re in the DMV and want to make an impact, come volunteer with us and me!! 🧔🏻♂️ 👉🏻 https://lnkd.in/eRUBXehk Let’s Give a SHIFT together this holiday season. 🎄🎅🏻 🎁
-
Sean F. shared thisLast week's Sha1-Hulud "The Second Coming" malware attack is a good reminder of a lot of things, including [maybe most importantly] that securing your software supply chain doesn't always have to wait until "next week." https://lnkd.in/eu97c_eT Register ^ to join Angela Zhang and Ross Gordon on 1/6 @ 1pm ET to learn about how Chainguard Libraries: - Prevents malware attacks such as Shai-Hulud - Provides safe, drop-in alternatives across 100K+ libraries across Python, Java, and JavaScript - Backports upstream fixes to critical and high-severity Python CVEs15-minute Live Demo: How Chainguard Libraries Protects You From Shai-Hulud and the Next Wave of Open Source Malware15-minute Live Demo: How Chainguard Libraries Protects You From Shai-Hulud and the Next Wave of Open Source Malware
-
Sean F. shared thisIn case you couldn't make the webinar (aka fireside chat aka podcast interview) earlier in the week and were looking for a 14-second summary! 😄
-
Sean F. posted thisLucky to be a part of a conversation with Dan Lorenc and Al Barnes on Supply Chain Security in Higher Ed this afternoon at 1p ET. Come on by and listen in to see how Chainguard can help: https://lnkd.in/ekqY_Fnc 📅 Tuesday, Oct 7 at 1 PM ET 🎙️ Hosted by Carahsoft Securing research environments, simplifying compliance, enabling innovation - all the good stuff!
-
Sean F. shared thisFor all my partner people out there -- Chainguard's partner program has been launched! 🚀Sean F. shared thisWe’re excited to announce the launch of the Chainguard Partner Program – a global channel initiative designed to help partners deliver trusted open source software to their customers. 🤝 The program is built around a simple idea: when we empower the right partners, we scale trust. With rising regulatory demands and a surge in software supply chain attacks - visibility and verifiability into who is creating and maintaining the code in their build environments is becoming a necessity. We’re enabling partners to do exactly that for their customers by making it easier than ever for them to build, deploy, and innovate on a foundation that’s secure from the start. Learn more and come join us in building a more transparent and secure software supply chain. 💜 https://lnkd.in/eZrZfKDq
-
Sean F. shared thisChainguard Academy has an excellent tutorial on Migrating to Python Chainguard Containers. It's a great way to experience concepts like distroless, multi-stage builds, etc. Chainguard Academy also has a "Copy Markdown for LLMs" button at the top of most pages, which is also pretty cool. https://lnkd.in/ejBwp5bB
-
Sean F. shared thisRe: AWS Summit next week: Come and join us!Sean F. shared this🚨 Kick off AWS Summit Washington, DC with Chainguard at RPM Italian! Join us Monday, June 9 for an evening of standout food, top-tier drinks, and can’t-miss conversations with the public sector pros and tech leaders shaping the future. Chainguard, Second Front, and ils.software can't wait to welcome you. 📍 RPM Italian | 6-8:30 PM | RSVP here: https://lnkd.in/eDvrekhu Can't make it? No worries, you can catch us at booth 563 at the AWS Summit DC, June 10–11, to meet the team and talk secure-by-default software. #AWSSummitDC #PublicSector #Cybersecurity #Networking #Chainguard #SecondFront #ILSSoftware #HappyHour #OpenSource #PublicSectorIT
-
Sean F. liked thisSean F. liked thisI've been working on some planning for how to prepare for what will come next from TeamPCP. I'm fairly certain they have other credentials and we will see more attacks The thing I can't help but wonder is did they start with the most popular projects, or the least? If they started with the least popular projects it's going to be a very very long year And the best prep I can think of on the short term is to have an inventory of all the software in use. If there are other easy wins, do let me know. The thing is, if there's another breach, we will learn about it and the top priority is answering the question "where am I running this software" I'm going to write all this up at some point. Even knowing how to find out about these things can be tough, but then how to respond to open source attacks isn't always obvious
-
Sean F. liked thisSean F. liked thisDC never stops. Neither do we. Swing365 Golf DC is Washington, D.C.'s only private indoor golf simulator — open around the clock for members who expect more than a tee time. Two private suites. Your schedule. Total privacy. Limited memberships available 1101 16th Street NW. ⛳
-
Sean F. reacted on thisSean F. reacted on thisMy wife and I had a great time at the American Heart Association Washington Region Ball last night. It was wonderful to see friends and colleagues supporting such an important organization. Heart disease can affect anyone, so it's crucial to get your heart checked. There are plenty of testing options available, and it could save your life. Thank you again, Tom Berti and Planned Systems International for the invitation.
-
Sean F. liked thisSean F. liked thisThe Trivy supply chain attack is wild. Compromised GitHub Actions. Malicious Docker images. Credential stealers disguised as vulnerability scans. A self-propagating npm worm. Aqua's own internal repos defaced. Meanwhile, me using Chainguard Images built from source: Bored. At home. With nothing to remediate. Build from source. Sign everything. Trust nothing you didn't build. #SupplyChainSecurity #Chainguard #ContainerSecurity
-
Sean F. liked thisSean F. liked thisHill & Valley was packed. Great discussions on Offensive Cyber, Securing Open Source, and Critical Infrastructure Protection from Sean Cairncross, White House National Cyber Director and Senator Rounds. Also, a passionate address from Trae Stephens from Anduril Industries. Even Dan Lorenc in a suit. 😁 #HillandValley #Chainguard #SecureOpenSource
-
Sean F. liked thisSean F. liked thisUh oh. Another cred stealer in PyPI, this time in litellm. This is exactly why we built Chainguard Libraries, we're immune to these attacks by design. Check your logs and start rotating credentials... https://lnkd.in/eiVPDw_K
-
Sean F. liked thisSean F. liked this1st RSA = 🎪✨ so many things to see ✨🎪 2nd RSA = let's pack some comfy shoes 3rd RSA and beyond = cough drops, moleskin, and tylenol stash ... just in case Drop a line if you want to talk about self-hosted appsec, sovereign AI, or sourdough bread making 🥖
-
Sean F. liked thisSean F. liked this
-
Sean F. liked thisEveryone’s talking about AI generated code. But not enough people are asking what happens after it’s written. More code means more packages, more dependencies, more risk slipping through. That’s why we’ve added Chainguard Agent Skills 🕵. It gives AI agents a safer set of building blocks to work from. Instead of pulling in random images or packages, they use trusted, minimal, rebuilt-from-source components with clear provenance. Less guesswork. Fewer surprises in production. If AI is going to write more of your code, the inputs it relies on need to be locked down. Check the link in the bio for more detail 🔗 #AI #DevSecOps #SoftwareSupplyChain #AiSecurity #AppSec
Experience & Education
-
Chainguard
***** ********
-
*******
****** ********* ********
-
*** ****** ****
****** ********* ********
-
********** ** ******** * ** ***** ***** ****** ** ***********
******** ** ******* ****** ***** *********** undefined
-
View Sean’s full experience
See their title, tenure and more.
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
or
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Licenses & Certifications
-
-
-
Amazon Web Services Solutions Architect Associate
Amazon Web Services (AWS)
Issued ExpiresCredential ID TXHLSB0LNEEQ1094
View Sean’s full profile
-
See who you know in common
-
Get introduced
-
Contact Sean directly
Other similar profiles
Explore more posts
-
Bradley Tusk
Tusk Holdings • 7K followers
New Substack: The Road Ahead For Secure Mobile Voting Technology I have spent $10 million and brought together a dream team of cybersecurity experts to build Mobile Voting technology that is open-source, end-to-end verifiable, and free to implement for any interested election jurisdiction. Later this year, the team will release the final mobile voting software development kit for jurisdictions, and today we have made the project repository public so anyone can track our progress. As we look to the future of Mobile Voting and how our efforts will expand to select cities across America this year, security remains core to our mission. It’s important that we scale mobile voting when our technology meets the highest standards for security. And we will be scaling soon. Learn more on my Substack: https://lnkd.in/d69fnYJ6
23
-
Stambaugh Ness
17K followers
Is your firm ready for the new DoD cyber rules expected in 𝐞𝐚𝐫𝐥𝐲 𝐍𝐨𝐯𝐞𝐦𝐛𝐞𝐫? Big changes are coming for firms working on DoD projects. Once the rule is in effect, you'll need to demonstrate your cybersecurity level to secure and maintain your contracts. This requirement is key to staying competitive. We've outlined the essential steps you should take now, including: ✔️ Conducting a readiness check ✔️ Strengthening security controls ✔️ Maintaining compliance documents ✔️ Implementing team training See the full breakdown and find out where you stand with our quick quiz. https://conta.cc/4nyEyQS #CMMC #GovCon #DoDContracts #Cybersecurity #Compliance #AEC
12
-
Mitratech
165K followers
What happens when a public defense agency gains real-time visibility into every matter, hour, and dollar? For Montana OPD, it meant completing 85–90% of system enhancements in-house, securing significant budget increases, and streamlining operations statewide. Mitratech CaseCloud™ didn’t just modernize their workflows—it strengthened their mission. Read the full story here: https://hubs.li/Q03VxtjK0
12
-
Lulora Aliu-Rexhepi
Precision Talent Solutions • 25K followers
From LOGCAP to Lürssen, the map is changing Army restructuring, European consolidation, DHS buildout, and AI-driven contracting point to a new GovCon environment. The Q3 Industry Report lays it out. Newsletter link in comments.
17
2 Comments -
DTEX
27K followers
Federal programs shouldn't have to choose between visibility and privacy. That's why DTEX Platform v7 for Government provides both under an active FedRAMP Moderate ATO. Built for federal agencies and contractors, Platform v7 unifies Insider Risk Management, Risk-adaptive DLP, and UEBA/UAM to surface context and intent, detect threats earlier, and adapt controls in real time. Platform v7 delivers the assurance federal programs expect with U.S.-only data residency and U.S.-citizen-only administration, FIPS 140 encryption, and CNSSD 504 support. Explore the guide and see how DTEX strengthens federal security programs without slowing the mission: https://lnkd.in/g9xWeyu5
32
1 Comment -
Mirantis
91K followers
Looking to secure federal cloud contracts with Kubernetes? FedRAMP compliance is a key requirement for accessing U.S. federal cloud opportunities. But for Kubernetes teams, meeting these strict security and operational standards can be complex. This guide outlines a clear path to compliance, including: • Core requirements such as RBAC, logging, and continuous monitoring • How to reduce manual effort with checklists and automation • Guidance on aligning Kubernetes environments with FedRAMP controls Explore the practical steps to accelerate your compliance journey. Read more: https://buff.ly/WaDdj9s
10
-
Shane Chiang
Momentum Z • 12K followers
In light of the recent CISA alert dated September 23, 2025, regarding a widespread supply chain compromise in the npm ecosystem, organizations must remain vigilant. The self-replicating worm, dubbed "Shai-Hulud*w" has impacted over 500 packages, enabling the theft of GitHub Personal Access Tokens and cloud API keys for services like AWS, GCP, and Azure. This malware exfiltrates credentials to actor-controlled endpoints and public repositories, while propagating by injecting code into additional packages. Such incidents highlight the cascading risks in software dependencies, potentially leading to unauthorized access, data breaches, and operational disruptions. This underscores the critical need for robust cloud security practices, particularly as enterprise cloud adoption accelerates. The Cyber Security Agency of Singapore (CSA) has released the Cloud Security Companion Guides, aligned with national standards such as Cyber Essentials and Cyber Trust. These guides provide practical frameworks for implementing secure configurations, access controls, vendor management, and incident response essential for mitigating supply chain vulnerabilities. What steps is your team taking to address supply chain risks? Share your insights below. *Shai-Hulud is a fictional giant sand-dwelling creature from Frank Herbert's science fiction series "Dune." It is known for being aggressive and territorial, playing a significant role in the desert ecosystem of the planet Arrakis. #CyberSecurity #CloudSecurity #SupplyChainSecurity #CSACyberTrust #SingaporeCompliance #MomentumZ https://lnkd.in/g8SqdQAC
6
-
TechnoMile
10K followers
NEW: Spry Methods, Inc. Selects TechnoMile to Modernize Federal Sales Operations We’re excited to welcome Spry – a trusted provider of IT and security solutions to federal law enforcement, defense, and civilian agencies – to the TechnoMile client community. To further strengthen its opportunity management capabilities, Spry selected WinIt CRM, our AI-enabled CRM that's purpose-built for GovCon small businesses, to: ▪️ Automate BD and capture workflows ▪️ Improve visibility into pipeline and sales performance ▪️ Streamline federal opportunity identification ▪️ Scale on the Salesforce platform With WinIt, Spry gains a plug-and-play solution tailored to its BD and capture processes and a flexible solution that can grow alongside the company's mission-focused work. Read the full announcement → https://lnkd.in/gnNtnf2v #GovCon x #TechnoMile x #CRM x #FederalContracting x #CaptureManagement x #BusinessDevelopment x #WinItCRM x #Spry x #Salesforce x #DigitalTransformation
25
-
Candice Smith
Precision Talent Solutions • 9K followers
🚀 BIG NEWS: Your pending clearances might come faster than you think! @OMNI Federal has been awarded a potential $427 million contract with the DCSA to support the NBIS modernization via cloud and DevSecOps. 🔍 About the Project: NBIS is a platform used across the federal government for background investigations, case initiation, adjudication, and continuous vetting. OMNI will provide: Secure landing zone deployment in AWS GovCloud at DoD Impact Level 4 CI/CD pipeline development and DevSecOps tooling Agile delivery, sprint support, user onboarding, software integration, and compliance with DoD standards 💬 Why it matters: A critical step in federal clearance modernization, this contract positions OMNI Federal to shape how secure cloud systems and DevSecOps practices are adopted across the industry. Their work will drive faster, more secure background vetting workflow, essentially supporting national security priorities every day. #GovCon #DevSecOps #CloudModernization #DCSA #NBIS #AWS #Govtech #Cybersecurity #clearance
22
4 Comments -
Adi Ruppin
3K followers
Ouch. The DOJ announced a $421,234 settlement with Swiss Automation Inc. for failure to provide adequate cybersecurity for technical drawings of parts supplied to DoD contractors. To be clear, there was 𝗻𝗼 𝗰𝗼𝗻𝗳𝗶𝗿𝗺𝗲𝗱 𝗯𝗿𝗲𝗮𝗰𝗵. Nothing was actually compromised. This case simply highlights the DOJ cracking down 𝗼𝗻 𝗳𝗮𝗹𝘀𝗲 𝗰𝗹𝗮𝗶𝗺𝘀! 𝗜𝗻 𝘁𝗵𝗶𝘀 𝗰𝗮𝘀𝗲, where Swiss Automation knowingly submitted invoices for payment while failing to meet the cybersecurity standards required by its contracts . And we saw this last year with defense contractors who checked boxes to claim CMMC compliance without implementing the actual controls. How many companies are (Unknowingly? knowingly?) guilty of the same thing? 𝗧𝗵𝗮𝘁 𝗲𝗿𝗮 𝗶𝘀 𝗼𝘃𝗲𝗿. The DOJ is now actively investigating cybersecurity compliance claims, and companies are being sued for millions when investigators uncover gaps between documentation and reality. This is just the beginning. The days when self-reporting are dying. If your compliance strategy depends on no one checking, it has an expiration date.
16
-
Arrash Yasavolian
Taoshi • 2K followers
I've been investing in and reviewing crypto projects since 2017. Let's face it, many projects in this space lack real utility or adoption. Mix in scams and memes, and the industry has seen a downturn for the worse. But crypto is far from dead. Like any maturing market, it's now seeing a resurgence in real value. The focus is shifting toward projects with true product market fit that can create disruptive products. So, what kind of products stand out by being decentralized, trustless, and hopefully open source? The ones being built on #bittensor. You can think of bittensor as a YC for decentralized digital commodities. Every subnet competes for attention and investment. It’s capitalistic by design. The weakest projects fail and are eliminated, while the strongest thrive and attract more funding from the ecosystem. Taoshi builds on bittensor. Its flagship, Subnet 8, the Proprietary Trading Network, focuses on the retail prop firm industry, a space long plagued by misalignment, scams, and predatory practices. Traders who think they’ve profited from funded accounts often watch the withdrawal button vanish from their app. It’s the perfect example of how crypto’s core principles of open source, trustlessness, and decentralization can solve real problems in a billion dollar industry. On Subnet 8, traders can review the open source rules themselves and can never be denied a payout. It’s an existing market with real demand, now met by a bittensor subnet offering a truly disruptive solution. I believe many subnets will go on to challenge or completely reinvent existing industries. It’s the first crypto ecosystem where teams are genuinely incentivized to find product market fit. Scams and memes can’t survive here. This is where teams are building real, sustainable, cash flow businesses. Nowhere else I’d rather build, the future is bright for bittensor. Checkout more details in this write up by The TAO Daily on how we're disrupting the prop firm industry below. https://lnkd.in/g_smewge
13
-
Aaron Pava
CivicActions, Inc • 3K followers
A recent EO emphasized the need to prioritize commercial off-the-shelf (COTS) software over “custom-developed” when procuring products and services. Mike Gifford, CPWA and I co-authored a piece for GovLoop in which we maintain that Free and Open Source Software (FOSS) is indeed COTS - and agencies should prioritize it in procurement decisions. https://lnkd.in/gNiD4_cd
35
3 Comments
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top content