Security Insight & Response Platform
Genius AFC
Aug 2017 - Dec 2019 (2 years 5 months)
In this project, I designed and lead the security team to build a Cloud Security Insight and Response Platform. The goal was to collect, process, and analyze security event and related metric data from various sources in real-time to provide security insights & analysis with SIEM. Which include threat awareness, operational risk, application, or service abnormally, system breach. Integrated with CVE bulletin and threat intelligent data source to mitigating 0-day risk.
Gathering and analyze various data types and sources. Includes firewall, IDS/IPS, WAF, SLB and API Gateway, SSO/IAM/, Application, System.
Designing architecture of SIEM and functionalities for security activities.
Build threat analysis model referred to MITRE ATT&CK.