Results-driven, Passionate, Multi-Award Winning/shortlisted Security professional and mentor with notable success in planning, analysis and implementation of security initiatives. Strengths in providing and implementing comprehensive AWS infrastructure design by leveraging security best practices and the real scenarios/use cases, implementing and managing security tools, as well as using Python or Typescript scripts to provide easy solutions to fixing security problems and uplifting application availability. Experience in stakeholder management, cross-team collaboration and project management. Certified in AWS, Cybersecurity, Terraform and Azure.
Wesfarmers OneDigital is a multi-business corporate which has 3 business sectors: OnePass, OneData and Catch.com.au and. My day-to-day work here mainly involves interactions with OnePass and OneData, and sometimes will cover Catch as needed. My main contributions include the following:
- Leading and owning the CNAPP tool transitioning project from Orca to Wiz for OneDigital:
- Developing Security in SDLC Roadmap.
- Developing PowerShell scripts for sending alerts on Microsoft Entra ID Application Registration secret expiry and Enterprise Application SAML certificate expiry to Slack, which ensures our platforms' availability and prevents any service outages caused by secret expiry.
- Conducting security design reviews: including infrastructure design reviews, security header reviews, ad hoc change reviews, etc.
- Collaboratively working with the Platform and IT Support team on application access management.
- Reviewing and managing AWS access.
- Contributing in development API standards.
- Contributing in documentation uplift.
- Contributing in Wiz and NoName BAU for Catch.
- Other BAU tasks: including Zscaler, Access Package requests, travel exemptions, etc.
- Mentoring other team members.
Brand Development Contribution:
Cyber@Mantel is a recently-established cybersecurity brand in Mantel Group, where there is quantities of internal initiatives to be done. My contribution include the following:
- Leading a team on developing in-house Incident Management solution:
- Coaching and mentoring other team members:
- Involved in recruitment process and interviews
- Client project:
- Client Project 1:
- Client Project 2:
- Client Project 3:
Internal Initiatives:
Assisted the seniors on multiple projects on:
Helped facilitate the Traineeship Program.
AWS
Cloud Security
Azure (Entra ID, Sentinel, Automation Runbook)
DevSecOps
Terraform
CDK
Python
Typescript
CI/CD (GitHub Actions, Bitbucket Pipeline, Buildkite GitLab CI)
CNAPP (Wiz, Orca)
Security policy development
Problem Solving
Stakeholder Management
Identity and Access Management (Entra ID, Zscaler)
Leadership
Mentorship