session: portfolio.chu / status: live
ANALYST ON CALL

Chu Detection engineering & security operations

I'm a security professional building detection engineering systems, from adversarial ML detection pipelines to CI/CD security gates and SOC automation. Currently working toward a career in security operations and threat detection, with hands-on training across RangeForce, Let's Defend, and TryHackMe.

3
Shipped projects
4
Certifications
6/7
Findings resolved · OpsShield

Projects

ordered by most recent
TICKET-03 · 2026
OpsShield
In progress
Role
Security engineer, Team 3 (Packet Patrollers)
Scope
Application & cloud security hardening for a capstone platform launching July 30, 2026

Leading the security workstream on a cross-functional capstone: closing out formal security findings, standing up dependency and dynamic scanning in CI, deploying a Wazuh SIEM with custom detection rules, and coordinating a pre-launch penetration test and audit, alongside cloud security controls built on the team's AWS environment.

OWASP Dependency-Check OWASP ZAP (DAST) Wazuh SIEM AWS GuardDuty AWS Security Hub Penetration testing
TICKET-02 · 2026
SecOpsAI
Shipped
What
An adversarial AI detection engineering system, built end to end
Why
To show that ML-based detection can be threat-modeled, hardened, and operated like any other production security control, not treated as a black box

Threat-modeled with STRIDE mapped to MITRE ATT&CK, then built a full pipeline: a CICIDS2017 data pipeline over Kafka, an XGBoost classifier that measurably beat a rule-based baseline on F1, adversarial hardening across five attack types using IBM's Adversarial Robustness Toolbox, and a production FastAPI service with JWT/API-key auth, immutable audit logging, and an automated alert-to-containment pipeline, all shipped with GitHub Actions CI/CD.

STRIDE / MITRE ATT&CK Kafka XGBoost IBM ART FastAPI GitHub Actions
TICKET-01 · 2026
ShieldFlow
Shipped
What
An automated AppSec pipeline and SOAR platform, targeting OWASP Juice Shop
Why
Manual triage doesn't scale; this proves a severity gate and automated response can catch and act on findings before they ship

Built a GitHub Actions pipeline running Semgrep, Gitleaks, Trivy, and OWASP ZAP with a severity gate that blocks deployment on critical findings, then wired up Shuffle SOAR locally with three action-oriented playbooks covering deployment blocking, developer identification, and CVE enrichment via the NVD API. Published a live dashboard tracking results in real time.

Semgrep Gitleaks Trivy OWASP ZAP Shuffle SOAR ~97% faster triage

About

background

I'm working toward a career in detection engineering and security operations, the parts of security where you're not just finding problems, but building the systems that catch them automatically, at scale, before they cause damage.

My work through Expadox Lab has focused on taking security tooling from "checklist" to "engineered system": threat models that actually drive detection logic, CI/CD pipelines with real severity gates, and SIEM rules mapped explicitly to MITRE ATT&CK rather than copied from a template.

  • IBMCybersecurity Analyst
  • CiscoCyberOps Associate
  • CiscoCybersecurity Essentials
  • CiscoTechnical Support Fundamentals

Contact

open to opportunities

Looking for roles in SOC analysis, detection engineering, or security operations. Reach out, happy to walk through any of the projects above in more depth.