All domains

OVERVIEW 04 / CYBERSECURITY

Security analysis from source code to attack surface.

My security background includes validating reported exploit proofs of concept, examining blockchain infrastructure and contracts, and building security lab environments. I combine source analysis with a view of the wider system: the service, its dependencies, and its trust boundaries. My current projects extend that work into threat intelligence and controls for AI-assisted operations.

Conceptual emerald protective shield and inspection lens beside service modules.
EXPLORE DOMAIN / SECURITYConceptual illustration

THE ENGINEERING SCOPE

What I work on.

Practical capabilities, grounded in professional work and the projects below.

SYSTEMS VIEW01 — 04
jv.ENGINEERING01UnderstandCode, assets, and trust boundaries02InvestigateReports, signals, and test cases03ValidateReproduce and assess behavior04ImproveRemediation and operational controls
Cybersecurity: Connected through hands-on engineering.CONCEPTUAL ILLUSTRATION
01

Exploit & attack-surface analysis

I validate reported proofs of concept and examine the trust boundaries around validators, bridges, minting flows, and smart contracts.

  • Proof-of-concept validation
  • Smart-contract review
  • AWS Nitro Enclaves
02

Source & runtime testing

I use static analysis, dynamic testing, and fuzzing to investigate code behavior and support practical remediation.

  • SonarScanner
  • Burp Suite
  • Go
  • Rust
  • Fuzz testing
03

Threat intelligence & research

I work on a security-center project and threat-analysis tooling, connecting research and collected signals to a clearer investigation workflow.

  • CA Security Center
  • Threat intelligence
  • Static analysis
04

Security in operations

I bring security into platform work through lab isolation, operational checks, access controls, and guardrails for agent-driven workflows.

  • Linux
  • OpenShift
  • Bash
  • Cloudflare Zero Trust
  • Agent guardrails

PROFESSIONAL EXPERIENCE

The work behind the knowledge.

The parts of my career most relevant to cybersecurity.

  1. October 2021 – February 2023Crypto.com

    Blockchain Security Analyst

    • I validated hacker-submitted proofs of concept and investigated their behavior and impact.
    • I used Go fuzzing to investigate denial-of-service behavior and applied static and dynamic analysis to Go and Rust code.
    • My tooling included SonarScanner, Burp Suite, and Grafana, alongside security guidelines and validator checks.
  2. March 2020 – October 2021Hong Kong ASTRI

    Engineer, Blockchain

    • I built Linux and container security lab environments to support testing and investigation.
  3. June 2018 – August 2018HKT

    Intern

    • I supported Nessus vulnerability scanning, alert configuration, and network audits during my internship.

APPLIED ENGINEERING

Projects & systems.

Public repositories and focused overviews of my work. Explore the purpose, implementation, and contribution behind each project.

PROJECT OVERVIEWActive

Terraform cloud foundations

Infrastructure as code for my OCI and Cloudflare environment, with resources and changes kept understandable in Git.

  • Terraform
  • OCI
  • Cloudflare
  • Nginx
PROJECT OVERVIEWActive

Model routing & controlled access

LiteLLM routing and Cloudflare Zero Trust around the model infrastructure used by my tools and AI workflows.

  • LiteLLM
  • Cloudflare Zero Trust
  • Model routing
  • AI infrastructure
PROJECT OVERVIEWActive

Guardrails for an operations agent

Self-developed security controls around the Pinax ops-ui agent, focused on the boundary between a request and an operational action.

  • Agent security
  • Ops UI
  • Guardrails
  • Operational automation
PROJECT OVERVIEWActive

AI development & end-to-end QA

Agent workflows and QA platforms in my environment, supporting development with code review and behavioral checks.

  • Codex
  • Claude
  • Hermes
  • OpenClaw
PROJECT OVERVIEWActive

CA Security Center

My current security-center project, alongside work on threat intelligence and static source-analysis platforms.

  • CA Security Center
  • Threat intelligence
  • Security research
  • Static analysis
PROJECT OVERVIEWActive

Code & contract security analysis

Source-analysis tooling and attack-surface review, informed by my work on validator systems, bridges, minting, and smart contracts.

  • Static analysis
  • Attack surface
  • Smart contracts
  • Go
PROJECT OVERVIEW

NFT deployment work

NFT deployment projects informed by my blockchain engineering and smart-contract security background.

  • NFT deployments
  • Blockchain
  • Smart contracts
PROJECT OVERVIEWActive

Backups, monitoring & update policies

The operating layer of my environment: Grafana visibility, backups, and workload-specific decisions about updates.

  • Grafana
  • Backups
  • Synology
  • Watchtower
CONTINUE EXPLORING
Cloud & InfrastructureAI & AutomationBlockchain & Data