Skip to content
View dmchaledev's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report dmchaledev

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
dmchaledev/README.md

David McHale

Security Engineer · DevSecOps · Game Dev

Cloud-native security products by day. Indie games by night.

HailBytes Lost Rabbit Digital Steam X LinkedIn


Technical Proficiencies

Domain Technologies & Skills
Security & GRC Attack Surface Management, Security Awareness Training, SOC 2, FedRAMP 20x, HECVAT, NIST CSF, ISO 27001, 13 compliance frameworks
Cloud & Marketplace AWS Marketplace, Azure Marketplace, AWS GovCloud, Azure Government, BYOC (deploy-in-your-tenant) architecture
Infrastructure as Code Terraform, Packer, multi-cloud image pipelines, CI/CD
Offensive & Recon reNgine, GoPhish, Burp Suite integration, phishing simulation, multi-phase recon pipelines
AI & Integrations MCP servers for AI agents, OpenAI / Ollama analysis, REST APIs, SIEM, OIDC SSO / SAML / SCIM, SARIF export
Languages & Dev Python, Shell, HCL, JavaScript / TypeScript, GDScript
Game Dev Godot, browser extensions, Steam release pipeline, Android-first design

What I'm Building

🛡️ HailBytes — Cloud-Ready Cybersecurity for AWS & Azure

Enterprise-grade security tools that deploy in your own cloud tenant in minutes, not months. Two products, full attack surface coverage.

  • HailBytes SAT — Security Awareness Training. Phishing simulation with 45+ templates, post-click training, board-ready reporting, and white-label MSSP branding.
  • HailBytes ASM — Attack Surface Management. 30+ recon tools across a 7-phase pipeline, first-party AWS / Azure / GCP / Cloudflare asset discovery, AI-powered analysis, and a built-in MCP server.
  • Outlook Phish Reporter — one-click phish reporting from Outlook.

3,000+ active deployments · 650M+ security events tracked · 13 compliance frameworks

🎮 Lost Rabbit Digital — Indie Game Studio

An indie studio I run with my brother. 55K+ players · 9 games shipped · 6 Steam titles

  • Starbrew Station — free-to-play sci-fi idle game, 17,000+ players and counting.
  • Spud Customs — border patrol decision-making in a potato kingdom.
  • Tumblefire — fast-paced wild west roguelike shooter.
  • Fragile Frontier & Reel Talk — co-op chaos and cozy multiplayer fishing, both 2026.
  • Ultra Zoom — a browser extension for high-fidelity image zoom on any page.

Pinned Work

Terraform Modules · API & MCP Docs · Security Policy Templates · reNgine + Burp Integration · GoPhish Training Templates · GoPhish · reNgine (upstream)


Professional Profile

Security Engineer and founder focused on making enterprise-grade security accessible through cloud-native, marketplace-deployable products. At HailBytes I build and operate HailBytes SAT and HailBytes ASM on AWS and Azure Marketplace, both running on a bring-your-own-cloud architecture so customers keep their data in their own tenant. The work spans the full stack of a security product company: Terraform and Packer pipelines for multi-cloud deployment, GRC and compliance across 13 frameworks, AI agent integration via MCP, and the offensive tooling that informs all of it.

When I am not building security products, I run Lost Rabbit Digital, shipping games on Steam and building consumer tools like Ultra Zoom.

Value Proposition

  • Product-grade security. I turn frameworks and controls into deployable products, not just documentation.
  • Cloud-native by default. Marketplace listings, BYOC architecture, and IaC pipelines customers can stand up in their own cloud.
  • Full-stack builder. Comfortable across security engineering, DevSecOps, AI integration, and product delivery from infrastructure to go-to-market.

GitHub Streak
Top Languages

Pinned Loading

  1. yogeshojha/rengine yogeshojha/rengine Public

    reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous …

    HTML 8.7k 1.3k

  2. HailBytes/gophish-training-templates HailBytes/gophish-training-templates Public

    Professional email templates and landing pages for employee security awareness phishing simulations using GoPhish. Ready-to-deploy campaigns with realistic scenarios, educational content, and custo…

    HTML 42 8

  3. HailBytes/security-policy-templates HailBytes/security-policy-templates Public

    Comprehensive NIST CSF-aligned security policy templates for SMBs. Ready-to-use policies covering incident response, data protection, infrastructure security, and compliance requirements with pract…

    Shell 7 3

  4. HailBytes/rengine_burp_integration HailBytes/rengine_burp_integration Public

    A Python tool that seamlessly integrates reNgine and reNgine-ng reconnaissance data with Burp Suite Professional for enhanced web application security testing workflows.

    Python 6 1

  5. HailBytes/hailbytes-api-docs HailBytes/hailbytes-api-docs Public

    Official API and MCP server documentation for HailBytes ASM (Attack Surface Management) and HailBytes SAT (Security Awareness Training). OpenAPI 3.1 specs, integration guides, and SDK examples.

    1

  6. HailBytes/hailbytes-terraform-modules HailBytes/hailbytes-terraform-modules Public

    Official Terraform modules for deploying HailBytes ASM and SAT on AWS and Azure. Single VM, HA hot-hot, and auto-scaling tiers. Requires active HailBytes Marketplace subscription.

    HCL 1