Now you can Instantly Chat with Paul!
About Me
A full-stack cyber security professional with 10-years’ experience for Fortune 500 clients. Since 2010, he has worked on security automation and tooling, penetration testing, code review, and security architecture on AWS Cloud and on-prem. He wa...tooling, penetration testing, code review, and security architecture on AWS Cloud and on-prem. He was a software developer for four years before went to postgraduate studies in University of Sydney and Georgia Institute of Technology.
Skills
- Cloud Security, Web Security, Mobile Security, IoT Security, Container Security
- Security & Infrastructure as Code, Security Automation & Tooling, SecDevOps, CI/CD
- Penetration Testing, Code Review, Threat Model, Security Architecture, Reverse Engineering
- Security Logging & Monitoring, SIEM, IDS/IPS, Firewall, WAF
- Cryptography, PKI, SSO, OpenID Connect
- Security Framework (NIST, ISO, OpenSAMM), Compliance (PCI, SOX, HIPPA), OWASP 10, Best Practices, Vulnerability Management
Skills
-
-
-
-
-
-
-
- 5 Years
Advanced
-
- 3 Years
Intermediate
-
-
- 10 Years
Expert
-
-
-
-
-
-
-
- 15 Years
Intermediate
-
- 15 Years
Advanced
-
- 5 Years
Advanced
-
-
-
- 10 Years
Advanced
-
- 5 Years
Expert
-
- 6 Years
Advanced
-
-
-
-
- 10 Years
Expert
-
-
-
-
-
- 10 Years
Expert
-
- 10 Years
Advanced
-
- 3 Years
Advanced
-
-
-
-
- 5 Years
Advanced
-
- 5 Years
Expert
-
- 10 Years
Advanced
-
- 10 Years
Advanced
-
-
- 10 Years
Expert
-
-
- 2 Years
Advanced
-
- 10 Years
Expert
-
-
- 3 Years
Intermediate
-
- 10 Years
Expert
-
-
-
- 5 Years
Expert
-
- 7 Years
Advanced
-
- 4 Years
Expert
-
- 3 Years
Expert
-
- 2 Years
Beginner
-
-
- 3 Years
Expert
-
- 3 Years
Advanced
-
-
-
-
-
-
- 5 Years
Advanced
-
-
-
-
-
-
-
-
-
-
-
-
-
- 3 Years
Expert
-
- 2 Years
Intermediate
-
-
- 10 Years
Advanced
-
- 2 Years
Beginner
-
- 10 Years
Expert
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- 5 Years
Expert
-
-
-
-
Portfolio Projects
Description
Architecture design for migrating on-prem application to AWS Cloud for Bloomberg Tax Technology
- Design the overall architecture that leverage ECK for Apache Spark with API Gateway, Kinesis, SQS, Lambda, S3 and other AWS native service for Bloomberg online tax system
- The resulted architecture improves the performance of tax report from 18 hours to minutes
Design and implement CI/CD pipeline with Green/Blue and Canary deployment
Show More Show LessDescription
Work within an AWS consulting team to define and implement security guardrails for Citi Group
- Review 100+ security auto-detection and auto-remediation guardrail rules
- Design security guardrail patterns with almost all whitelisted AWS services (e.g., CloudWatch, CloudTrail, Lambda, Config, CloudFormation, KMS, CMK, SSM, SNS, SQS, EKS, IAM, EC2, ELB, VPC, WAF, etc.)
Implement the guardrails using Python Boto3, with CI/CD pipeline of Sceptre, cfn_nag, awspec, pyunit, Pylint
Show More Show LessDescription
Implemented security tooling and automation an AWS PaaS for Pearson
- Implemented a Python serverless security tooling with AWS services, including Lambda, S3, DynamoDB, CloudWatch, SNS, SQS, SSM, API gateway
- Implemented Jenkins and Gitlab CI/CD pipeline with Checkmarx, AppSpider, BlackDuck, Qualys, and Sonar
Built Gitlab CI/CD pipeline runner Docker images for security scanners
Show More Show LessDescription
Built the application security program from scratch for Delta Dental
- Leveraged AWS services and third-party security tools to design hybrid Cloud security architecture
- Designed the overall AWS security logging and monitoring solution
Implemented security automation for security log analysis using Splunk and Python
Show More Show Less