Skip to content

Danny Pham Huu Danh

Security Leader — Offensive Security, Operations & Engineering

Summary

Security leader who builds and breaks. 9+ years across offensive security, operations, and engineering — now Head of IT Security (AVP) at a regulated bank, where I built a new-generation, AI-native SOC: a governed, human-in-the-loop agent harness that lets a lean team run the full security program while humans keep ownership of judgment and risk. And I build the tooling I run: security-as-code CLIs and evidence-only MCP servers for regulation and compliance — open source in Go, C, and Python.

Experience

Assistant Vice President, Head of IT Security
CIMB Bank Vietnam

Build a new-generation SOC for a regulated bank: designed a governed, human-in-the-loop AI agent harness as the operating model and build the security tooling the team runs on, so a two-person team delivers a full program — operations, offensive security, and governance — while humans own every decision. Set strategy, build the tools we need, and guide the team. Rated Outstanding — the highest performance tier — in the first year.

Security Operations & Engineering

  • Designed the security operations model and built its tooling — a governed, MCP-connected agent harness — that lets the team run the stack (SIEM, SOAR, threat intelligence, EDR, vulnerability management, network security) with AI-assisted triage at 24/7 coverage; introduced SAST, SCA, and secrets gates in CI/CD and delivered the bank's first unified security-posture platform across cloud, vulnerability, network, and endpoint findings.

Offensive Security & Automation

  • Direct 10+ penetration-testing campaigns and a supply-chain attack simulation across core-banking, internal, and customer-facing systems, reporting exploitable risk to the CTO with remediation roadmaps and compensating controls.

  • Established the offensive methods the team follows — whitebox in the DevSecOps pipeline, validated against the live deployment for honest severity and exploit chains, and blackbox captured into reviewed, versioned skills for safe reuse — backed by a network-isolated AI pipeline that proposes candidate attack chains for analyst review.

Governance, Risk & Compliance

  • Own the IT security roadmap and report posture to the CIMB group monthly; led information-system security classification and NIST CSF 2.0 / CIS alignment and contributed to the State Bank of Vietnam regulatory dossier. Made the agent-written incident investigation double as the audit and compliance artifact — mapping findings to Vietnamese and Malaysian banking regulation.

Security Operation Engineer
Sky Mavis (Axie Infinity)

Security operations for a Web3 gaming platform handling high-value digital assets.

  • Ran detection and incident response across endpoints and cloud — custom detection rules, malware analysis, and SOAR-automated response and case management.

  • Security-reviewed third-party game builds before release on Mavis Hub — manual reverse engineering combined with automated scanning tooling.

  • Delivered Web2/Web3 security-awareness training (wallet and seed-phrase protection).

IT Security Engineer
Ampere Computing
  • Triaged alerts across Cortex XDR, SentinelOne, Cato Networks MDR, and Code42 DLP, correlating endpoint, network, and data-loss signals to escalate incidents.

  • Partnered with IT on endpoint compliance — CIS-baseline checks via Qualys Policy Compliance, with posture enforced through Intune (Windows) and Kandji (macOS).

  • Built an internal asset-management system that consolidated scattered device and software inventory into a single source of truth for security and IT operations.

Threat Hunting Team Leader
VinCSS
  • Conducted red-team engagements simulating APT-level TTPs — network, phishing, wireless, and physical security assessments.

  • Ran continuous red-team and purple-team programs with client blue teams to improve detection and response.

  • Found and responsibly disclosed an account-takeover exploit chain in Zalo and ZaloPay (platforms serving 100M+ users).

  • Contributed to VinCSS COTIP, a threat-intelligence platform aggregating 1,500+ domestic and international news sources.

Cyber Security Researcher
Cybersecurity Startup (ceased operations)
  • Researched Windows kernel and user-mode vulnerabilities and wrote custom C/C++ exploits to bypass endpoint security controls.

  • Built modular Python red-team frameworks and post-exploitation tooling spanning initial access, privilege escalation, lateral movement, persistence, and evasion.

Open Source Projects

secops

Go · SIEM/SOAR as code

A Go binary and SDK that manages Google SecOps — Chronicle SIEM and Siemplify SOAR — as code: pull live configuration (detection rules, parsers, dashboards, SOAR playbooks) into files, review the git diff, and push it back through one reconciliation engine — GitOps for the SOC — with live event search and guarded case triage on top. Ships a built-in MCP server, a machine-readable command tree, and an embedded agent guide; every mutation stays dry-run until --yes.

s1ctl

Go · EDR as code

A Go CLI and SDK that operates the SentinelOne Singularity Platform as code — pull, diff, and push across 11 surfaces with a drift command for CI: agents, policies, exclusions, threat lifecycle, remote ops, xSPM posture, marketplace, and Data Lake (PowerQuery) searches. Ships a built-in MCP server, a machine-readable command tree, and an embedded agent guide built for automation and AI agents.

splunkctl

Python · SIEM/SOAR as code

A Python CLI that operates Splunk Enterprise SIEM and Splunk SOAR as code — state pull, diff, and push across detection rules (version-controlled YAML), parsers, macros, alerts, dashboards, lookups, indexes, data inputs, HEC tokens, and SOAR playbooks-as-code; plus SPL search run and export, Enterprise Security incident review, and SIEM-to-SOAR ingest. Ships a built-in MCP server, a machine-readable command tree, and an embedded agent guide built for automation and AI agents.

banhmi

Go · MCP server

Evidence-only RAG + MCP server that serves Vietnamese banking and fintech regulation to LLMs — exact citations (article/clause), validity status, and verbatim text linked to official government sources, with no hallucination. One codebase, one corpus per country: banhmi anchors a family of six ASEAN jurisdictions — Vietnam, plus laksa (Malaysia), rendang (Indonesia), kaya (Singapore), tomyum (Thailand), and amok (Cambodia).

compliary

Go · compliance MCP

Evidence-only RAG + MCP server that serves the security and compliance control frameworks organizations are audited against — ISO/IEC 27001/27002, SOC 2, PCI DSS v4, NIST CSF 2.0 and SP 800-53, CIS Controls, and more — to LLMs as exact control citations (A.5.1, AC-2(3), Req 8.3.6), with version lineage and cross-framework mappings so superseded text is never presented as current. Framework text is licensed, so the repo ships code and metadata only — each operator builds their own corpus and runs a private MCP instance.

Skills

Governance, Risk & Compliance

NIST CSF 2.0, CIS Benchmarks, regulatory compliance, third-party risk management, IT & cloud due diligence, security audit, security policy

Security Platforms & Cloud

Google SecOps, CrowdStrike Falcon XDR, Cortex XDR/XSOAR, SentinelOne, Tenable Nessus, Qualys, Google Cloud Platform (GCP), HashiCorp Vault, Docker

Offensive & Defensive Security

Red Teaming, Penetration Testing, Exploit Development, Threat Hunting, Incident Response, Malware Analysis, Digital Forensics, Windows Internals, MITRE ATT&CK

Programming, Data & AI

Python, Go, C/C++, C#, PowerShell, Django, Temporal, PostgreSQL, MySQL, MongoDB, Elasticsearch, Vertex AI, RAG, LLM agents

Education

Master of Science in Computer Science
University of Information Technology, Vietnam National University Ho Chi Minh City

GPA: 8.15/10. Thesis on bypassing endpoint security via vulnerable Windows drivers (BYOVD); first-authored the resulting paper (Springer FDSE 2021).

Bachelor of Engineering in Software Engineering
University of Information Technology, Vietnam National University Ho Chi Minh City

GPA: 8.53/10. Thesis on static PE malware detection using machine learning; first-authored the resulting paper (Springer FDSE 2018).

Publications & Disclosures

Static PE Malware Detection Using Gradient Boosting Decision Trees Algorithm
Springer FDSE 2018 · DOI: 10.1007/978-3-030-03192-3_17
  • Applied machine learning techniques to static malware detection using Portable Executable (PE) file analysis combined with Gradient Boosting Decision Trees algorithm. Reduced training time by optimizing feature dimensions while maintaining detection accuracy.

  • Achieved 99.394% detection rate at 1% false positive rate. Cited 51 times.

Zalo Account Takeover Exploit Chain
Responsible disclosure · VietnamNet coverage · 2021

Single-click account takeover affecting Zalo and ZaloPay (100M+ users). Found and reported it as Threat Hunting Team Leader at VinCSS — coordinated disclosure with the Zalo security team, published as VinCSS advisory EX008, and covered in national press.

Professional Affiliations

Intelligent Systems Security Lab, University of Dayton
External Research Collaborator

Collaborated on web security and privacy research; co-authored a Springer paper.

Microsoft Student Partner Program
Technical Evangelist

Microsoft Azure student evangelist — ran technical workshops and talks at universities.