An experienced development team lead with a strong background in cybersecurity and technical expertise, offering 6 years of experience in cybersecurity, web application development, product architecture, and team management. Skilled in using and designing SOAR products from a user-centric perspective and adept at leading development teams to successfully complete complex tasks.
Overview
6
6
years of professional experience
1
1
Certification
Work History
Principal Development Lead
D3 Security Management Systems
05.2021 - 02.2024
Led the development team in maintaining SOAR product features, managing the entire project lifecycle using Agile methodologies to ensure the secure and efficient delivery of functionalities aligned with organizational policies.
Led the development team to transform the SOAR web application from a monolithic to a cloud-native architecture, enabling SOAR web application to handle large volumes of data through cloud-based auto-scaling.
Worked and communicated with customer-facing cyber engineers and QA, and used and tested SOAR products in depth from the user's perspective. In the process, I also gained knowledge and passion for cyber security, including the kill chain process, mitre attack, incident response, configuration management, vulnerability management, cryptography, and various security devices, such as firewalls, IDS, IPS, DLP, and EDR.
Improved efficiency and management by utilizing Python and Node.js scripts for batch processing tasks, such as automating Google sheets handling, monitoring daily code commits from developers, and sending bulk emails.
Product Architect and Senior Full Stack Developer
D3 Security Management Systems
04.2019 - 04.2021
I participated in the design and development of the core functions of SOAR products, covering the entire incident response lifecycle. This process begins with detection, including event collection, event classification, and labeling according to Tactic and Technique, followed by event escalation to an incident. Next is the response phase, which includes incident response management and incident correlation. Then comes the containment, reporting, recovery, and remediation stages, which involve playbook configuration, integration with 3rd party security products, and the playbook runtime mechanism. Finally, the process concludes with the lessons learned stage, including generating incident response and analysis reports.
Following this, the technologies involved in both the design and development include React, JavaScript, CSS, HTML, .NET Framework, Python, MongoDB, MSSQL, Kubernetes (K8s), and Docker.
Junior Full Stack Developer
D3 Security Management Systems
01.2018 - 03.2019
Developed and implemented both the case management and asset management projects using JavaScript, HTML, CSS, Kendo UI, SQL Server (MSSQL), and the .NET framework.
Education
Bachelor of Science - Computing Science
Simon Fraser University
Burnaby, BC
06.2017
Skills
JavaScript (ES5 and ES6)
HTML
CSS
React
React Router
Redux
Redux Toolkit
Kendo UI
JQuery
Python
Net(C#)
REST API
SQL Server(MSSQL)
MongoDB
PostgreSQL
Kubernetes (K8S)
Docker
Excellent Communication Skills
Collaboration Skills
Documentation Skills
Languages
English
Full Professional
Chinese (Mandarin)
Native or Bilingual
Certification
CISSP - Certified Information Systems Security Professional
Timeline
Principal Development Lead
D3 Security Management Systems
05.2021 - 02.2024
Product Architect and Senior Full Stack Developer
D3 Security Management Systems
04.2019 - 04.2021
Junior Full Stack Developer
D3 Security Management Systems
01.2018 - 03.2019
CISSP - Certified Information Systems Security Professional
Bachelor of Science - Computing Science
Simon Fraser University
Similar Profiles
ZIXUAN YUANZIXUAN YUAN
Full-Stack Developer / Project Lead at D3 Security Management Inc.Full-Stack Developer / Project Lead at D3 Security Management Inc.