#
With over 30 combined years in the developer and security community along with secure coding in .NET, our team understands the importance of including security measures throughout the software development and DevOps lifecycle.
Headquartered in Des Moines, Iowa, we work remotely, and can also provide onsite travel for customers. We use our expertise to ensure client project deadlines and business objectives are fully recognized.
February 25, 2020 RSA Conference San Francisco, California
February 2019, Clay and Milk
Eric's extensive experience includes application security automation, cloud security reviews, static source code analysis, penetration testing, SDLC consulting, and secure code review assessments.
Eric has 20+ years in software development and application security. He architected the Puma Scan static analysis engine and delivers application security assessments for clients in a wide range of industries.
Eric Johnson has more than 15 years of experience in application security automation, cloud security reviews, static source code analysis, penetration testing, SDLC consulting and secure code review assessments. As a co-founder of Puma Security, his passion lies in modern static analysis product development and DevSecOps automation. Previously, Eric spent five years as a principal security consultant at an information security consulting firm helping companies deliver secure products to their customers. Prior to that, he spent 10 years as an information security engineer at a large US financial institution performing source code audits. As a Certified Instructor with the SANS Institute, Eric authors information security courses on DevSecOps, cloud security, secure coding and defending mobile apps. He serves on the advisory board for the SANS Security Awareness Developer training program, delivers security training around the world and presents security research at conferences including: BlackHat, BSides, ISSA, JavaOne, OWASP, RSA, SANS and UberConf. Eric completed a bachelor's degree in computer engineering, and a masters degree in information assurance from Iowa State University. He currently holds the CISSP, GWAPT, GSSP-.NET and GSSP-Java certifications. Contact Eric at eric (dot) johnson (@) pumasecurity.io
Eric Mead has more than 20 years of experience in software development and application security. As a co-founder of Puma Security, he architected and built the Puma Scan static analysis engine, including the rule framework and the data-flow analysis that tracks user-controlled input through .NET applications, and he authors the detection rules that ship with the product. He also delivers application security assessments for clients in a wide range of industries, including penetration testing, secure code review, threat modeling, and cloud security reviews across AWS, Azure, and GCP.
In 2026 Eric discovered and disclosed CVE-2026-15657 and CVE-2026-15658 in a payments-connected API, coordinated through CERT/CC. His current focus is the security of AI-assisted development.
Eric's primary focus is the .NET framework, with considerable experience in front end frameworks such as Angular and React. He holds a bachelor of science degree in computer engineering from Iowa State University, with emphasis in Software Engineering and Information Security. Contact Eric at eric(dot)mead(@)pumasecurity.io.
