Bio
Experience
-
OneHub Business Consulting
-
Toronto, Ontario, Canada
-
Cyber Security Consultant
-
Sep 2023 - Present
-
Toronto, Ontario, Canada
• Developed and carried out penetration tests based on OWASP Top 10• Designed security awareness training program using KnowBe4• Investigated and restored hacked websites for clients
-
-
-
-
Cyber Security Consultant
-
Apr 2022 - Sep 2022
• Designed and carried out penetration tests based on OWASP Top 10• Identified and remediated >20 Critical and High severity issues for clients (e.g. Cross-site scripting, 2FA, TLS, SSL Pinning)• Developed SOC playbooks, use cases and performed L1 SOC investigation on Rapid7 InsightIDR SIEM (e.g. Lateral movement, suspicious port traffic)• Carried out SAST, DAST and SCA on client web applications and mobile applications (e.g. Fortify, SonarQube)• Automated alert testing for an in-house SIEM using bash and powershell and deployed instances on Azure• Created proposals and presentations to identify security gaps for clients
-
-
-
IBM
-
Hong Kong SAR
-
Analyst Programmer
-
Jan 2021 - Apr 2022
-
Hong Kong SAR
• Developed agile full stack web application for Singaporean banking client in Java/Javascript• Rewrote outdated banking website form encryption to be compatible with secure cryptographic algorithm AES-GCM (Added IV and authentication, removed dependency on padding)• Performed SAST and SCA for deployments and patched vulnerabilities for penetration test remediation (e.g. Cross-site scripting, CSP rules)• Developed mobile banking application in ReactJS• Wrote bash and SQL scripts to streamline UAT server testing• Coordinated with overseas teams on project requirements and prepared implementation plans
-
-
-
SmarTone
-
Hong Kong
-
Security Engineering Intern
-
Jul 2019 - Sep 2019
-
Hong Kong
• Developed pentesting scripts based on MITRE ATT&CK framework for PoC of EDR platform(e.g. Metasploit shellcode injection, Mimikatz credential dumping)• Deployed AWS EC2 instances for clients to test capability of EDR platform• Deployed Threat Risk Assessment for a government Wi-Fi project with >100 hotspots• Designed phishing training proposal for clients using KnowBe4
-
-
-
-
Sales Assistant Intern
-
May 2016 - Jul 2016
-
Hong Kong
• Promoted STEM educational products to schools and teachers• Worked with the sales team to plan demonstrations (University of HK, CITE2016)
-
-
Education
-
2016 - 2020University of California, Davis
Bachelor of Science - BS, Computer Science -
2010 - 2016St. Paul's College, Hong Kong
High School Diploma
Suggested Services
This profile is unclaimed. These are suggested service rates with 0% commision upon successful connection
Industry Focus. “Business Consulting and Services”
Need a custom project? We'll create a solution designed specifically for your project.
References
Social Profiles
Community