About
I'm a Cloud Security Engineer based in Seoul, South Korea. My path into security has moved steadily from endpoint and network research toward the cloud, and along the way I've kept one foot in software development and the other in security data.
I started out in a national security training program and then joined an R&D group at a security company, where I worked on ransomware defense using honeypots and automated backup, machine-learning-based anomaly detection, and packet analysis of anonymous networks such as Tor. That work led to my first academic presentations on malware classification and encrypted file detection.
I then spent a year as a full-time master's researcher in a hacking-countermeasure lab, building NLP-based Cyber Threat Intelligence systems in collaboration with a major industry partner, and researching intrusion detection for next-generation in-vehicle networks. This resulted in an international patent application on lightweight real-time CAN anomaly detection and, later, a journal publication on domain-knowledge-free cloud intrusion detection.
From there I moved into threat intelligence engineering, developing pipelines that collect and analyze threat data from hidden channels like the dark web and Telegram, running Elasticsearch-based collection systems, and standing up on-premise GitOps CI/CD environments. Two domestic patent applications on threat data storage and private-channel threat search came out of this period.
Next, at a cloud security startup, I built CNAPP components in Go: code-based CSPM covering AWS, GCP, Azure, and Korean cloud providers against CIS, NIST, and ISO benchmarks, CIEM for effective permission visibility across multiple clouds, and Zero Trust segmentation integrations with external security products. This is also where I filed a patent on generating resource relationship graphs for multi-cloud environments.
Today I work on AWS-native security operations for a large multi-account enterprise environment: standardizing services like GuardDuty, Security Hub CSPM, and WAF as Terraform code, designing and operating an Elastic-based cloud SIEM/SOAR stack with MITRE ATT&CK-based detection rules validated through breach and attack simulation, and establishing security baselines for Kubernetes and generative AI workloads.
I am most interested in where data engineering, anomaly detection, and security automation meet. If you have questions about my work or would like to discuss collaboration opportunities, feel free to reach out.
Contact
- GitHub: github.com/gunh0
- LinkedIn: linkedin.com/in/gunh0902