Security leader who builds and breaks. 9+ years across offensive security, operations, and engineering — now Head of IT Security (AVP) at a regulated bank, where I built a new-generation, AI-native SOC: a governed, human-in-the-loop agent harness that lets a lean team run the full security program while humans keep ownership of judgment and risk. And I build the tooling I run: security-as-code CLIs and evidence-only MCP servers for regulation and compliance — open source in Go, C, and Python.
Danny Pham Huu Danh
Security Leader — Offensive Security, Operations & Engineering
Summary
Experience
Build a new-generation SOC for a regulated bank: designed a governed, human-in-the-loop AI agent harness as the operating model and build the security tooling the team runs on, so a two-person team delivers a full program — operations, offensive security, and governance — while humans own every decision. Set strategy, build the tools we need, and guide the team. Rated Outstanding — the highest performance tier — in the first year.
Security Operations & Engineering
Designed the security operations model and built its tooling — a governed, MCP-connected agent harness — that lets the team run the stack (SIEM, SOAR, threat intelligence, EDR, vulnerability management, network security) with AI-assisted triage at 24/7 coverage; introduced SAST, SCA, and secrets gates in CI/CD and delivered the bank's first unified security-posture platform across cloud, vulnerability, network, and endpoint findings.
Offensive Security & Automation
Direct 10+ penetration-testing campaigns and a supply-chain attack simulation across core-banking, internal, and customer-facing systems, reporting exploitable risk to the CTO with remediation roadmaps and compensating controls.
Established the offensive methods the team follows — whitebox in the DevSecOps pipeline, validated against the live deployment for honest severity and exploit chains, and blackbox captured into reviewed, versioned skills for safe reuse — backed by a network-isolated AI pipeline that proposes candidate attack chains for analyst review.
Governance, Risk & Compliance
Own the IT security roadmap and report posture to the CIMB group monthly; led information-system security classification and NIST CSF 2.0 / CIS alignment and contributed to the State Bank of Vietnam regulatory dossier. Made the agent-written incident investigation double as the audit and compliance artifact — mapping findings to Vietnamese and Malaysian banking regulation.
Security operations for a Web3 gaming platform handling high-value digital assets.
Ran detection and incident response across endpoints and cloud — custom detection rules, malware analysis, and SOAR-automated response and case management.
Security-reviewed third-party game builds before release on Mavis Hub — manual reverse engineering combined with automated scanning tooling.
Delivered Web2/Web3 security-awareness training (wallet and seed-phrase protection).
Triaged alerts across Cortex XDR, SentinelOne, Cato Networks MDR, and Code42 DLP, correlating endpoint, network, and data-loss signals to escalate incidents.
Partnered with IT on endpoint compliance — CIS-baseline checks via Qualys Policy Compliance, with posture enforced through Intune (Windows) and Kandji (macOS).
Built an internal asset-management system that consolidated scattered device and software inventory into a single source of truth for security and IT operations.
Conducted red-team engagements simulating APT-level TTPs — network, phishing, wireless, and physical security assessments.
Ran continuous red-team and purple-team programs with client blue teams to improve detection and response.
Found and responsibly disclosed an account-takeover exploit chain in Zalo and ZaloPay (platforms serving 100M+ users).
Contributed to VinCSS COTIP, a threat-intelligence platform aggregating 1,500+ domestic and international news sources.
Researched Windows kernel and user-mode vulnerabilities and wrote custom C/C++ exploits to bypass endpoint security controls.
Built modular Python red-team frameworks and post-exploitation tooling spanning initial access, privilege escalation, lateral movement, persistence, and evasion.
Open Source Projects
Go · SIEM/SOAR as code
A Go binary and SDK that manages Google SecOps — Chronicle SIEM and Siemplify SOAR — as code: pull live configuration (detection rules, parsers, dashboards, SOAR playbooks) into files, review the git diff, and push it back through one reconciliation engine — GitOps for the SOC — with live event search and guarded case triage on top. Ships a built-in MCP server, a machine-readable command tree, and an embedded agent guide; every mutation stays dry-run until --yes.
Go · EDR as code
A Go CLI and SDK that operates the SentinelOne Singularity Platform as code — pull, diff, and push across 11 surfaces with a drift command for CI: agents, policies, exclusions, threat lifecycle, remote ops, xSPM posture, marketplace, and Data Lake (PowerQuery) searches. Ships a built-in MCP server, a machine-readable command tree, and an embedded agent guide built for automation and AI agents.
Python · SIEM/SOAR as code
A Python CLI that operates Splunk Enterprise SIEM and Splunk SOAR as code — state pull, diff, and push across detection rules (version-controlled YAML), parsers, macros, alerts, dashboards, lookups, indexes, data inputs, HEC tokens, and SOAR playbooks-as-code; plus SPL search run and export, Enterprise Security incident review, and SIEM-to-SOAR ingest. Ships a built-in MCP server, a machine-readable command tree, and an embedded agent guide built for automation and AI agents.
Go · MCP server
Evidence-only RAG + MCP server that serves Vietnamese banking and fintech regulation to LLMs — exact citations (article/clause), validity status, and verbatim text linked to official government sources, with no hallucination. One codebase, one corpus per country: banhmi anchors a family of six ASEAN jurisdictions — Vietnam, plus laksa (Malaysia), rendang (Indonesia), kaya (Singapore), tomyum (Thailand), and amok (Cambodia).
Go · compliance MCP
Evidence-only RAG + MCP server that serves the security and compliance control frameworks organizations are audited against — ISO/IEC 27001/27002, SOC 2, PCI DSS v4, NIST CSF 2.0 and SP 800-53, CIS Controls, and more — to LLMs as exact control citations (A.5.1, AC-2(3), Req 8.3.6), with version lineage and cross-framework mappings so superseded text is never presented as current. Framework text is licensed, so the repo ships code and metadata only — each operator builds their own corpus and runs a private MCP instance.
Skills
NIST CSF 2.0, CIS Benchmarks, regulatory compliance, third-party risk management, IT & cloud due diligence, security audit, security policy
Google SecOps, CrowdStrike Falcon XDR, Cortex XDR/XSOAR, SentinelOne, Tenable Nessus, Qualys, Google Cloud Platform (GCP), HashiCorp Vault, Docker
Red Teaming, Penetration Testing, Exploit Development, Threat Hunting, Incident Response, Malware Analysis, Digital Forensics, Windows Internals, MITRE ATT&CK
Python, Go, C/C++, C#, PowerShell, Django, Temporal, PostgreSQL, MySQL, MongoDB, Elasticsearch, Vertex AI, RAG, LLM agents
Education
GPA: 8.15/10. Thesis on bypassing endpoint security via vulnerable Windows drivers (BYOVD); first-authored the resulting paper (Springer FDSE 2021).
GPA: 8.53/10. Thesis on static PE malware detection using machine learning; first-authored the resulting paper (Springer FDSE 2018).
Publications & Disclosures
Applied machine learning techniques to static malware detection using Portable Executable (PE) file analysis combined with Gradient Boosting Decision Trees algorithm. Reduced training time by optimizing feature dimensions while maintaining detection accuracy.
Achieved 99.394% detection rate at 1% false positive rate. Cited 51 times.
Demonstrated Bring Your Own Vulnerable Driver (BYOVD) attack technique, showing how adversaries can leverage legitimately signed but vulnerable drivers to bypass endpoint security products.
Research used Intel Network Adapter Diagnostic Driver (2012 version) to perform credential dumping while evading antivirus and EDR detection.
Developed an approach to web-user privacy protection that monitors JavaScript behavior by code origin rather than intercepting network requests; cited 11 times.
Single-click account takeover affecting Zalo and ZaloPay (100M+ users). Found and reported it as Threat Hunting Team Leader at VinCSS — coordinated disclosure with the Zalo security team, published as VinCSS advisory EX008, and covered in national press.
Professional Affiliations
Collaborated on web security and privacy research; co-authored a Springer paper.
Microsoft Azure student evangelist — ran technical workshops and talks at universities.