π Hiroshima, Japan | π‘οΈ Cybersecurity Professional | π― SOC β’ CTI β’ Vulnerability Management | π Security Researcher
Building practical cybersecurity capabilities through hands-on labs, cyber threat intelligence, vulnerability management, and security automation to help organizations detect, investigate, and defend against evolving threats.
I'm a multidisciplinary cybersecurity professional combining technical expertise with a unique educational background spanning computer science, business, and social sciences. Based in Japan, I'm actively seeking cybersecurity opportunities while building Mei Vault Systems - a security-focused startup project where I'm developing practical solutions and expanding my technical portfolio.
Education:
- π B.S. Computer Science (Software Engineering) - University of the People
- π B.Com (Hons) Management Studies - University of Cape Town
- π B.A. Social Sciences (IR, Economic History, Industrial Sociology) - University of Cape Town
- π Application Development Security & Secure Coding Practices
- π Network Security & System Administration
- π€ Python Automation for Security Operations
- π Security Information & Event Management (SIEM)
- π― Risk Assessment & Mitigation Strategies
- π‘οΈ Detection Engineering & Threat Hunting
- π Google Cybersecurity Professional Certificate
- π ISC2 Certified in Cybersecurity (CC)
- π Network and Application Security - University of the People
- π Data Science Certificate - University of the People
- π CompTIA Security+ (In Progress)
π‘οΈ Cybersecurity Portfolio
Comprehensive portfolio demonstrating security frameworks, incident response, and hands-on tools:
- NIST Cybersecurity Framework implementation
- Security audits and risk assessments
- Linux & SQL security operations
- Threat detection with Wireshark, tcpdump, Suricata
- SIEM implementations (Splunk, Chronicle)
- Python security automation scripts
Tech: Python Linux SQL Wireshark Suricata Splunk NIST Framework
Professional end-to-end vulnerability assessment framework demonstrating enterprise security operations.
A comprehensive vulnerability management lifecycle project showcasing:
- Multi-scanner vulnerability assessment (OpenVAS, Nessus Essentials Plus)
- Risk-based prioritization using CVSS + business impact analysis
- Compliance mapping across NIST 800-53, ISO 27001, CIS Controls, PCI-DSS, HIPAA
- Python automation for scan orchestration and reporting
- Flask-based real-time metrics dashboard
- SIEM integration (Wazuh) with correlation rules
- 415+ vulnerable services across isolated lab environment (Metasploitable2/3, DVWA, OWASP Juice Shop)
- Professional executive and technical reporting
Tech: OpenVAS Nessus Python Flask Wazuh Docker VMware NIST ISO 27001 Jupyter
Key Achievement: Built enterprise-grade vulnerability management lab demonstrating 225+ CVE assessments with automated remediation workflows and multi-framework compliance validation.
Comprehensive Cyber Threat Intelligence (CTI) investigation into a multi-domain recruitment fraud campaign using structured OSINT methodologies and industry-standard intelligence frameworks.
This end-to-end investigation demonstrates professional CTI tradecraft through evidence-based intelligence collection, infrastructure analysis, behavioural correlation, and defensive reporting.
Highlights include:
- Intelligence Lifecycle applied from collection through dissemination
- Multi-domain infrastructure correlation across five operational domains
- Passive DNS, WHOIS, Certificate Transparency, and SSL analysis
- Technology stack fingerprinting and cloud infrastructure analysis
- MITRE ATT&CK mapping and ATT&CK Navigator layer
- Diamond Model and Attack Lifecycle analysis
- Detection engineering with SIEM, Sigma, Splunk SPL, and Microsoft Sentinel (KQL) examples
- Intelligence Requirements, Intelligence Gaps, and Confidence Assessments
- IOC development, STIX 2.1 and MISP intelligence exports
- Mermaid attack graph and executive intelligence reporting
Tech: CTI OSINT MITRE ATT&CK ATT&CK Navigator STIX 2.1 MISP Passive DNS WHOIS Certificate Transparency Sigma Splunk KQL
Key Achievement: Produced a complete Cyber Threat Intelligence investigation including structured OSINT collection, MITRE ATT&CK mapping, ATT&CK Navigator, STIX/MISP intelligence exports, detection engineering recommendations, and executive reporting for a real-world multi-domain recruitment fraud campaign.
Enterprise-grade AD environment showcasing Windows Server administration and security:
- Windows Server 2025 deployment and configuration
- Active Directory Domain Services (AD DS) setup
- Group Policy Objects (GPO) implementation
- User management and security policy enforcement
- PowerShell automation scripts
Tech: Windows Server 2025 Active Directory PowerShell Group Policy DNS DHCP
Real-world security automation demonstrating Python's power in cybersecurity operations:
- Login process automation and analysis
- Pattern detection using regex
- Security log parsing and investigation
- Automated threat detection workflows
Tech: Python Regex Security Automation Log Analysis
Portfolio hub featuring documentation, academic projects, and professional development work focusing on DevSecOps and secure coding practices.
- Intelligence Lifecycle & Structured Analytic Techniques
- Open Source Intelligence (OSINT) Collection & Analysis
- Threat Actor & Infrastructure Profiling
- Passive DNS, WHOIS & Certificate Transparency Analysis
- MITRE ATT&CK & ATT&CK Navigator
- Diamond Model & Attack Graph Analysis
- STIX 2.1 & MISP Threat Intelligence
- Indicators of Compromise (IOC) Development
- Threat Hunting & Intelligence Reporting
- Threat Detection & Incident Response
- SIEM Engineering (Splunk, Chronicle, Wazuh)
- Detection Logic Development
- Sigma Rule Development
- Microsoft Sentinel (KQL)
- Splunk SPL
- Network Traffic Analysis (Wireshark, tcpdump)
- Intrusion Detection Systems (Suricata)
- Vulnerability Scanning (OpenVAS, Nessus Essentials Plus, Nuclei)
- Risk Assessment & Prioritization (CVSS, Business Impact Analysis)
- Patch Management & Remediation Validation
- False Positive Analysis & Multi-Scanner Correlation
- Compliance Mapping (NIST 800-53, ISO 27001, CIS Controls, PCI DSS, HIPAA)
- Windows Server Administration
- Active Directory & Group Policy
- Linux System Administration
- TCP/IP, DNS & DHCP
- Network Security & Monitoring
- VMware Workstation
- Enterprise Lab Design & Isolation
- Python (Security Automation & Analysis)
- PowerShell
- SQL
- Flask
- Git & Version Control
- Docker
- Secure Software Development Lifecycle (SSDLC)
- Jupyter Notebooks
Highlights
- π Completed an end-to-end Cyber Threat Intelligence investigation into a multi-domain recruitment fraud campaign
- π‘ Produced STIX 2.1 and MISP intelligence exports for operational sharing
- π― Developed SIEM, Sigma, Splunk, and Microsoft Sentinel detection opportunities
- π‘οΈ Built enterprise vulnerability management and Active Directory lab environments
- π Developed security automation using Python, PowerShell, and Flask
- π§ Applied the Intelligence Lifecycle, MITRE ATT&CK, Diamond Model, and ATT&CK Navigator
- π Earned industry certifications including ISCΒ² CC and Google Cybersecurity Professional Certificate
I'm passionate about staying ahead of emerging cyber threats and helping organizations build resilient security postures. My unique combination of technical skills, business acumen, and understanding of organizational dynamics enables me to approach cybersecurity challenges from multiple angles.
Core Values:
- β Ethical security practices and responsible disclosure
- π― Proactive threat hunting over reactive responses
- π Continuous learning in an evolving threat landscape
- π€ Knowledge sharing and community contribution
π View My Resume
π‘ Open to collaboration on cybersecurity projects and security research initiatives
π Currently based in Hiroshima, Japan (UTC +9)
