DevOps SDLC security with monthly metrics that reported to senior management board for
visibility, trending and governance.
• Architected and built Verodin Mandiant Security Validation system, developed roadmap for
breach attack simulation with project phase goals, success metrics, globalization coverage,
maturity level, baseline, operation and value added services.
• Conducted forensic, threat hunting and incident investigation to determine if real attacks
happened in network, endpoint, cloud, IoT, OT, ICS. Reverse engineering malware, wrote .Net,
powershell, Python samples and custom test cases to simulate attack scenarios, and replay
artifacts collected from forensics and incident investigations. Achieved root cause analysis and
remediation.
• Research emerging threats, intelligence, industry-themed actors, and attack techniques they use
such as evasion, anti-VM, anti-debugging for targeted attack prevention. Conducted POC to
evaluate security technologies and solutions for business decision, including Infoblox,
Crowdstrike, Microsoft Hololens, EPP comparison with McAfee ENS, Trellix HX, MS Defender
ATP, AI based chat bot.
• Provided presentation on adversary simulation, presentation on ransomware attack analysis for
cross function teams, business unit and management. Demo on Windows remote exploit and
control. Achieved audience engagement and security awareness. Trained juniors and interns,
achieved team development.
Bank of Montreal
2016/11 – 2019/7
Sr Security Consultant/ Architecture
• Conducted cybersecurity strategy and architecture review and Threat Risk Assessment to
enterprise endpoint security solutions, controls, including McAfee, Fireeye, Carbon Black,
Symantec, SIEM Splunk, Arcsight, CyberArk, DLP, HIPS, using MITRE ATT&CK, NIST, SANS
frameworks, OWASP, established matrix of threat tactics, techniques verses protection
capabilities, remediation, coverage, gap, network, and platforms. The work helped in identifying
security gaps in the bank in SOC, penetration tests, and providing suggestions to department of
security strategy, architecture and innovation.
• Evaluated Next Generation Anti-Virus product suites including FireEye, McAfee, Cylance,
Windows 10 Defender, to make recommendation for enterprise strategic planning. Designed
unique test methodology to evaluate NGAV product capability in a layered structure. Designed 25
PoC test cases to break down NGAV product capabilities into specific threat technology
protection, such as anti-exploit, encryption, fileless..Created scorecard and metrics for the
success of evaluation. Wrote testing script codes and C++ malware simulating programs based
on reverse engineering malware binaries. The test cases are to test particular malware evasion
technology one by one and not mixing them up. The test cases were reviewed by faculties from
IANS, and Gartner consulting, and they are “very impressive”, “probably more thorough than most
companies that are paid to do the same work”. My test codes and cases were executed in NSS
private lab. The findings provided a view to the strength and weakness of the products and
provided a foundation for business decisions.
• Conducted POC on security technologies and solutions, including Mobile security POC with
Symantec SEP, Lookout, Zimperium; Container security POC with Twistlock, NeuVector, Qualys.
DLP and data classification POC with McAfee and Titus. Reviewed virtualization security with
Morphisec, Bromium, Analyzed BMO requirements, evaluated vendor products on efficacy,
function, performance, fitness and integration with the bank, contributed to product selection
criteria. Reported and presented recommendations to management. Provided awareness training
to clients. Improved BCP and DevOpsSec operation.
• Analyzed and documented banks status on security controls, policies, guidelines, deployments,
and procedures, including encryption, Bitlocker, forensics, FTK, penetration test, vulnerability
assessment, bug bounty, Aruba NAC, powershell logging for SIEM. Developed incident response
plan, disaster recovery plan, and playbooks. Documented vulnerability remediation, security best
practices. Hands on with security solution implementations. Traced and researched on security
trends and technologies, including machine learning, AI, Analytics, MTD, cloud security AWS,
Azure. Software development for security POC including writing IOS applications with Apple
Swift, Xcode, Android apps with Andriod Studio, SDK and API, Docker, Kubernetes, Github,
Jenkins, CI/CD, using Agile, Kanban, Jira. Provided analysis reports and recommendations.
Deloitte 2015/6
– 2016/9
Sr Security Consultant / Forensic Investigator, Reverse Engineer