Summary
Overview
Work History
Education
Skills
Accomplishments
Certification
Timeline
Generic

Vanessa Kong

BENTLEIGH EAST

Summary

Results-driven, Passionate, Multi-Award Winning/shortlisted Security professional and mentor with notable success in planning, analysis and implementation of security initiatives. Strengths in providing and implementing comprehensive AWS infrastructure design by leveraging security best practices and the real scenarios/use cases, implementing and managing security tools, as well as using Python or Typescript scripts to provide easy solutions to fixing security problems and uplifting application availability. Experience in stakeholder management, cross-team collaboration and project management. Certified in AWS, Cybersecurity, Terraform and Azure.

Overview

3
3
years of professional experience
1
1
Certification

Work History

Security Engineer

Wesfarmers Onedigital
10.2023 - Current

Wesfarmers OneDigital is a multi-business corporate which has 3 business sectors: OnePass, OneData and Catch.com.au and. My day-to-day work here mainly involves interactions with OnePass and OneData, and sometimes will cover Catch as needed. My main contributions include the following:

- Leading and owning the CNAPP tool transitioning project from Orca to Wiz for OneDigital:

  • Stakeholder management: including vendor assessment, involvement in communication with Wiz Account Manager on project progress, quote discussion, project planning, executive reporting, etc.
  • Platform implementation: including Wiz POV deployment to critical AWS accounts, SSO and Access Package setup, SIEM integration, GitHub integration, issues and vulnerabilities review, fine tuning user access, etc.

- Developing Security in SDLC Roadmap.

- Developing PowerShell scripts for sending alerts on Microsoft Entra ID Application Registration secret expiry and Enterprise Application SAML certificate expiry to Slack, which ensures our platforms' availability and prevents any service outages caused by secret expiry.

- Conducting security design reviews: including infrastructure design reviews, security header reviews, ad hoc change reviews, etc.

- Collaboratively working with the Platform and IT Support team on application access management.

- Reviewing and managing AWS access.

- Contributing in development API standards.

- Contributing in documentation uplift.

- Contributing in Wiz and NoName BAU for Catch.

- Other BAU tasks: including Zscaler, Access Package requests, travel exemptions, etc.

- Mentoring other team members.

Senior Security Engineer

Cyber@Mantel | Mantel Group
06.2023 - Current

Brand Development Contribution:

Cyber@Mantel is a recently-established cybersecurity brand in Mantel Group, where there is quantities of internal initiatives to be done. My contribution include the following:


- Leading a team on developing in-house Incident Management solution:

  • Developing project strategy.
  • Working collaboratively with the team on doing technical research and brainstorming ideas for gamifying the solution and increased involvement across the company, as well as and developing user stories.
  • Facilitating meetings with different stakeholders.
  • Communicating with our continuous assurance platform team on solution integration and translate their needs/requirements into step-by-step plan for my team.
  • Supporting team for any technical issues or blockers.


- Coaching and mentoring other team members:

  • Taking ownership of the Mantel Group Traineeship program: developing project roadmap, mentoring the mentors, sprint planning, facilitating workshops, collecting feedback for the trainees, etc.
  • Providing 1-on-1 mentorship to the Cyber trainee by helping her build personal development plan, guiding her on soft skills and answering her day-to-day questions on all aspects.
  • Providing a long-term mentorship to other team members by catching up with them regularly, helping them build both short-term and long-term plans, etc.


- Involved in recruitment process and interviews


- Client project:

  • Planned and conducted AWS cloud security assessment for the client both manually and using Plerion.
  • Created and communicated plans with the client for migration and remediation on IAM, data protection, networking security and automation.
  • Implemented migration and remediation steps, including introducing Infrastructure as Code (Terraform) and CI with OIDC configuration to the team, AWS Control Tower, rolling out SSO access for all the employees, implementing quick wins, migrating the workload to a new infrastructure following cloud security best practices, etc.
  • Educated their employees for engineering best practices, including secret management, CI/CD management and so on, by providing documentation, learning resources, materials and workshops.


Cloud Security Engineer

CMD Solutions | Mantel Group
02.2022 - 05.2023

- Client Project 1:

  • Helped them migrate one of their critical containerised applications from Azure to AWS using Terraform.
  • Contributed more than 80% of the code.
  • Implemented security best practices alongside the new infrastructure, including least privilege, secret management, networking security, etc.
  • Collaborated with our tech lead to help the developers on continuous application troubleshooting.

- Client Project 2:

  • Worked collaboratively with the team on deploying CSPM solution into their GitHub Actions pipeline using Cloud Conformity.
  • Designed and implemented solutions for increasing the availability of GitHub Actions runners by 3 times and reducing disaster recovery time from around a few hours to just a few minutes.
  • Monitored GitHub Actions runner performance using New Relic.

- Client Project 3:

  • Designed and implemented solution for Integrating SIEM solution with AWS Security Hub, which afterwards was used as an example in a presentation in AWS Activation Day event delivered by our tech lead. I helped him on preparing the slide deck.
  • Deployed Route 53 Resolver Firewall using Firewall Manager.
  • Worked collaboratively with the team on developing golden images for Red Hat Linux and Amazon Linux 2 using EC2 Image Builder.
  • Designed and initialised a Python script for cleaning up thousands of unused and legacy AMIs and associated EBS Snapshots across multiple AWS accounts. (Offboarded the client without finishing it)


Internal Initiatives:

  • Cohosted a security workshop for both internal and client audience for 3 intakes in a row as well as developed lab content for it.
  • Helped facilitating the Traineeship Program and provided support for the trainees.
  • Helped facilitating and hosting meetups and events in our office.

Associate Cloud Security Engineer

CMD Solutions | Mantel Group
09.2021 - 01.2022

Assisted the seniors on multiple projects on:

  • Maintaining and expanding client's AWS platform.
  • Monitoring misconfiguration alerts.
  • Upgrading CI/CD pipelines.
  • Application and server mapping and analysis, cost estimation and security risk analysis for a migration project.

Helped facilitate the Traineeship Program.



Cloud Engineer Trainee

CMD Solutions | Mantel Group
06.2021 - 08.2021
  • Implemented and supported automated CI/CD processes (GitLab CI).
  • Automated infrastructure and application deployment and provisioning.
  • Deployed AWS security services using Terraform.

Education

Master of Networking (Cybersecurity) - Networking & Cybersecurity

Melbourne Institute of Technology
Melbourne, VIC
06.2021

Bachelor of Management - International Business

Jinan University
China
06.2018

Skills

AWS

Cloud Security

Azure (Entra ID, Sentinel, Automation Runbook)

DevSecOps

Terraform

CDK

Python

Typescript

CI/CD (GitHub Actions, Bitbucket Pipeline, Buildkite GitLab CI)

CNAPP (Wiz, Orca)

Security policy development

Problem Solving

Stakeholder Management

Identity and Access Management (Entra ID, Zscaler)

Leadership

Mentorship

Accomplishments

  • ARN Women in ICT Awards (WIICTA) 2022 Graduate Award Winner
  • ARN Women in ICT Awards (WIICTA) 2023 Rising Star Award Finalist
  • 2023 Australian Women in Security Awards The One to Watch in Protective Security Award Finalist
  • Spoke at Melbourne Cyber Security Meetup Wesfarmers OneDigital office in February 2023 on How to Start your Career in Cybersecurity as a Graduate
  • Blogger, check out my page here: https://medium.com/@vanessakong0805

Certification

  • (ISC)2 Certified in Cybersecurity (CC), May 2023 - May 2026
  • Microsoft Certified: Azure Fundamentals, Jan 2023
  • AWS Certified SysOps Administrator – Associate, Dec 2022 - Dec 2025
  • AWS Certified Security – Specialty, Jul 2022 - Jul 2025
  • AWS Certified Developer – Associate, Feb 2022 - Feb 2025
  • HashiCorp Certified: Terraform Associate (002), Sep 2021 - Sep 2023
  • AWS Certified Solutions Architect – Associate Jul 2021 - Jul 2024
  • AWS Certified Cloud Practitioner, Jan 2021 - Jan 2024

Timeline

Security Engineer

Wesfarmers Onedigital
10.2023 - Current

Senior Security Engineer

Cyber@Mantel | Mantel Group
06.2023 - Current

Cloud Security Engineer

CMD Solutions | Mantel Group
02.2022 - 05.2023

Associate Cloud Security Engineer

CMD Solutions | Mantel Group
09.2021 - 01.2022

Cloud Engineer Trainee

CMD Solutions | Mantel Group
06.2021 - 08.2021

Master of Networking (Cybersecurity) - Networking & Cybersecurity

Melbourne Institute of Technology

Bachelor of Management - International Business

Jinan University
  • (ISC)2 Certified in Cybersecurity (CC), May 2023 - May 2026
  • Microsoft Certified: Azure Fundamentals, Jan 2023
  • AWS Certified SysOps Administrator – Associate, Dec 2022 - Dec 2025
  • AWS Certified Security – Specialty, Jul 2022 - Jul 2025
  • AWS Certified Developer – Associate, Feb 2022 - Feb 2025
  • HashiCorp Certified: Terraform Associate (002), Sep 2021 - Sep 2023
  • AWS Certified Solutions Architect – Associate Jul 2021 - Jul 2024
  • AWS Certified Cloud Practitioner, Jan 2021 - Jan 2024
Vanessa Kong