Skip to content
View 5G's full-sized avatar

Block or report 5G

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
5G/README.md

James Gallagher (@5G)

Senior Software Engineer • Distributed Systems • Cloud & AI

I design and build large-scale cloud systems with a focus on simplicity, resilience, and long-term maintainability. My work spans distributed architectures, serverless patterns, and the practical application of AI in engineering workflows.

I’m interested in:

  • high-integrity system design
  • event-driven cloud architectures
  • developer experience and automation
  • practical AI tools in real engineering contexts
  • security-by-default in distributed systems

I care about clear design, strong interfaces, and systems that behave predictably under load.


🔐 Security Contributions

I’m not a security engineer by title, but I have a habit of stumbling into meaningful security issues during my own engineering projects. When that happens, I follow strict responsible-disclosure practices.

CVE-2025-13932 — Infrastructure Control System Vulnerability (2025)

  • Discovered and reported a high-impact cloud/API access-control vulnerability affecting an energy-adjacent industrial control system.
  • Coordinated with CERT/CC and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) ICS team.
  • Published as ICSA-25-338-06.

Irish Government — gov.ie PDF Proxy Vulnerability (2024)

  • Identified and disclosed an issue that allowed malicious PDFs to be served through a trusted government domain.
  • Resolved in coordination with CSIRT-IE.

More details are available in the security-disclosures repository.


🛠 What I Work With

  • Cloud-native + serverless architectures
  • Event-driven and distributed systems
  • TypeScript / Python / CDK
  • API design & systems integration
  • AI-assisted engineering workflows

📫 Get in Touch

Open to conversations about system design, cloud architecture, AI tooling, or security disclosure work.

Pinned Loading

  1. security-disclosures security-disclosures Public

    Responsible disclosure write-ups for security issues I’ve identified and reported.