Skills
Security Operations
Log & alert analysis (ELK), Pass-The-Hash, lateral movement, persistence mechanisms, Windows Event IDs.
Tools / Platforms
SIEM (Wazuh, ELK), K8s, Grafana, Prometheus, Loki, Wireshark, FTK Imager, Volatility, Autopsy, Burp Suite, Sysmon.
Systems & Networks
Active Directory, Windows Server, Linux (Ubuntu, Debian, Kali), TCP/IP, ZFS, Docker, pfSense.
Programming
Python, Bash, PowerShell, SQL, C.
English
TOEIC 735, Upper-Intermediate, proficient in all 4 skills.
Methodologies
Scrum, Problem-solving, Technical Documentation Translation.
Education
FPT University Da Nang
Information Assurance — Area of study: SOC
Graduated Dec. 2025 · Da Nang · GPA 7.5 (3.0)
Certificates
Objective
Detail-oriented Cybersecurity professional specializing in Security Operations. Proven expertise in analyzing security logs, identifying complex attack vectors (such as lateral movement and Active Directory privilege escalation), and translating deep technical investigations into actionable intelligence. Seeking a SOC position to leverage hands-on experience with the ELK stack and malware analysis to actively strengthen organizational security posture.
Work Experience
Cybersecurity Intern
Sep 2024 – Apr 2025
FPT Software Da Nang
- Project: Trained in PortSwigger and Burp Suite tools, enhancing practical skills in web application security. Gained a solid understanding of ISO 27000 series standards, information security management, and risk assessment practices.
- Role: Conducted penetration testing on product websites to identify potential security risks or vulnerabilities. Compiled detailed reports on findings, providing actionable recommendations for mitigation and improvement.
Projects
Wazuh SIEM & Threat Detection Lab
2026
Wazuh, pfSense, Sysmon, Suricata, VirusTotal
- Architected an isolated threat hunting environment utilizing pfSense to segment 5 VMs (Wazuh manager, attacker node, and Linux/Windows targets).
- Enhanced endpoint visibility by deploying Wazuh agents integrated with Sysmon, Suricata, and File Integrity Monitoring (FIM) for robust host and network intrusion detection.
- Automated threat intelligence lookups by integrating the VirusTotal API into Wazuh to enrich security alerts and detect malicious file hashes.
On-Premise DDoS Attack Detection using LLMs
2025
IoT, MQTT, Grafana
- Designed and implemented a real-time observability dashboard (Grafana, Prometheus, Loki) to visualize critical MQTT broker metrics and system performance.
- Engineered a data collection pipeline to enable high-fidelity monitoring and incident detection for the backend system.
Database Forensics & Insider Breach Recovery
2026
Docker, ZFS, MySQL, Bash, n8n
- Developed automated log analysis logic and Bash-based attack simulation scripts to identify and respond to malicious SQL queries.
- Engineered an automated rollback mechanism and webhook-based alerting system (via n8n) for real-time incident mitigation.