Thanh Le

DevOps Engineer

Vietnam8 yrs 7 mos experience
Most Likely To SwitchAI Enabled

Key Highlights

  • Expert in deploying advanced security solutions.
  • Led teams to enhance cybersecurity across multiple industries.
  • Proficient in cloud security and threat detection.
Stackforce AI infers this person is a Cybersecurity Specialist with extensive experience in Fintech and IT Security.

Contact

Skills

Core Skills

Cloud SecurityThreat Detection & ResponseSecurity Solutions DesignTeam LeadershipNetwork SecurityIt MonitoringWeb SecurityEndpoint SecuritySecurity Architecture DesignIncident ResponseNetwork DeploymentIt Solutions Implementation

Other Skills

AI IntegrationCheckPointCompliance & AuditsConfiguration ManagementContainer SecurityCross-functional CollaborationCybersecurityCybersecurity ConsultingCybersecurity WorkshopsDevice ManagementDigital ForensicsEnd-user SupportEnglishIdentity & Access ManagementImperva

About

◆ SECURITY DOMAINS • Security and Risk Management • Communication and Network Security • Security Operations • CTF Player ◆ TECHNICAL EXPERTISE Security Solutions & Technologies • Network Devices: Mikrotik, Cisco, Juniper, Brocade • Wireless Technologies: UniFi, TP-Link, Ruckus • Monitoring & Logging: Prometheus, SolarWinds, Nagios • Next-Generation Firewalls: CheckPoint, Fortinet, Palo Alto, Cisco ASA • WAF: Cloudflare, AWS WAF, Imperva • IDS/IPS: Snort, OSSEC, McAfee NSP • Web Proxy: Squid Proxy, McAfee Web Secure Gateway, Bluecoat ProxySG • Vulnerability Scanners: Tenable Nessus, Ivanti, Nmap, Rustscan, Nuclei • Endpoint Security: JumpCloud, McAfee, Symantec • Data Loss Prevention: Cloudflare, Symantec • SIEM: Wazuh, AWS CloudTrail, CloudWatch, RSA NetWitness • Security Orchestration, Automation, and Response: Tufin, Shuffle • Digital Forensics: Velociraptor (Rapid7) • EDR/XDR: Wazuh • Cloud Security: AWS CloudTrail, AWS Inspector, AWS GuardDuty, AWS SecurityHub • Container Security: Falco Security, Trivy, Dockle • Software Composition Analysis: SonarQube Networking & Security Protocols • TCP/IP, OSI Model, ARP, VLAN, Switching, Trunking, Routing Protocols, Policy-Based Routing, NAT, Link Aggregation, STP, High Availability, SNMP, Network Monitoring, Load Balancing, SSL/TLS, VPN (IPsec, SSL), MFA, etc. Systems & Infrastructure • Active Directory, LDAP, DHCP, DNS, GPO, Right & Permission, NTLM, Kerberos, Internal CA, Event Viewer, Linux fundamentals, macOS security, Apple Business Manager, etc. Programming & Automation • Languages: Python, JavaScript, Rust • DevOps: Git, Docker, Kubernetes, Helm, Terraform Security Tools & Assessments • Nmap, Wireshark, BurpSuite, OWASP ZAP, Hashcat, JohnTheRipper, Hydra, Impacket, sqlmap, Metasploit, Dirbuster, Gobuster, PEASS-ng, BloodHound, Mimikatz Security Controls • Access Control Model, Firewall, Endpoint Security, IPsec VPN, SSL VPN, SSO, Multi-Factor Authentication (MFA), Web Proxy, URL Filtering, Application Control, IDS/IPS, Load-Balancer, Web Application Firewall, Certificate Authority, PKI, Data Loss Prevention, etc.

Experience

Anduin transactions

Security Specialist

Aug 2022Present · 3 yrs 7 mos · Ho Chi Minh City, Vietnam · Hybrid

  • Identity & Access Management: Administered Google Workspace for user and access management.
  • Device Management: Enforced security policies on company-owned devices via Mosyle MDM & JumpCloud MDM.
  • Threat Detection & Response: Deployed Wazuh XDR for endpoint monitoring, integrating it with Cloudflare, Truffle, and Velociraptor to build a SOAR platform.
  • Digital Forensics: Conducted endpoint forensic investigations using Velociraptor.
  • Network Security: Managed MikroTik, Cisco, and UniFi devices, implementing WPA3 with EAP-TLS & FreeRADIUS for Wi-Fi security.
  • Zero Trust Security: Operated Cloudflare’s suite, including WAF, DDoS, CDN, DNS, and Zero Trust solutions (ZTNA, SWG, CASB, DLP, RBI).
  • Container Security: Applied security best practices for Docker, including vulnerability scanning, image hardening, and runtime monitoring with Falco.
  • Cloud Security: Secured cloud infrastructure using AWS tools like IAM, GuardDuty, CloudFront, WAF, CloudWatch, CloudTrail, Inspector, and Security Hub.
  • Vulnerability Management: Performed regular assessments with Nuclei, Flan Scan, Aqua Trivy, Dockle, and AWS Inspector to remediate security gaps.
  • Threat Intelligence: Monitored emerging threats using OpenCTI and automated intelligence feeds via GitHub Actions.
  • Infrastructure Automation: Leveraged Terraform and GitHub Actions for automated infrastructure management.
  • Compliance & Audits: Ensured adherence to SOC 2 & CSA STAR through internal audits and the Vanta platform.
  • Security Awareness Training: Conducted phishing simulations & training via Gophish and Curricula (by Huntress).
  • AI Integration: Implemented Onyx AI, N8N for threat detection, security analysis and automation.
Identity & Access ManagementDevice ManagementThreat Detection & ResponseDigital ForensicsNetwork SecurityZero Trust Security+8

M.tech

2 roles

Cybersecurity Lead

Promoted

Oct 2020Aug 2022 · 1 yr 10 mos · Ho Chi Minh City, Vietnam

  • Main Responsibilities
  • Led & mentored a 6-member security engineering team, fostering professional growth and technical excellence.
  • Designed & implemented security solutions, including Endpoint Security, Email Security, DLP, NGFW, IDS/IPS, Sandboxing, and Vulnerability Management, ensuring robust cyber defense.
  • Managed multiple security projects, tracking progress and streamlining reporting to enhance efficiency.
  • Collaborated cross-functionally, prioritizing resources to ensure timely project delivery.
  • Consulted with leadership to align security strategies with business objectives and enhance engineering capabilities.
  • Hosted cybersecurity workshops & conferences, keeping the team updated on industry trends and best practices.
  • Project Contributions
  • CheckPoint NGFW: Deployed & supported FE Credit, SCB Bank, CB Bank, LienViet Post Bank, FWD Vietnam, Hanwha Life, AIA, SunLife, EVN, improving network security.
  • SolarWinds Orion: Led PoC, implementation & support for ACB Bank, VietBank, Vietsov Petro, enhancing IT infrastructure monitoring.
  • Imperva WAF: Configured & supported Sacombank, FWD Insurance, securing web applications & transactions.
  • McAfee Web Gateway: PoC, deployment & support for Shinhan Finance, FE Credit, enhancing web filtering & malware defense.
  • Symantec ProxySG: Secured web gateways for Prudential, Saigon New Port, Canon, Hong Leong Bank, Ajinomoto, optimizing internet security.
  • Symantec Endpoint Protection: Deployed for HOSE, Sabeco, reducing malware incidents.
  • Symantec DLP & EDR: Implemented for Hoi An South Development Ltd., preventing data breaches.
  • Tenable Vulnerability Management: Conducted assessments & risk mitigation for HD Saison, HTI Group, reducing security gaps.
  • RSA SecurID: Deployed MFA for EVN SPC, SCB Bank, Aviva Insurance, multiple Cambodian companies, enhancing identity security.
  • Allot Secure Service Gateway: Designed & deployed for RMIT University, improving traffic control & analytics.
Security Solutions DesignTeam LeadershipProject ManagementCross-functional CollaborationCybersecurity WorkshopsSecurity Solutions Implementation

Security Engineer

Aug 2018Sep 2020 · 2 yrs 1 mo · Ho Chi Minh City, Vietnam

  • Main Responsibilities
  • Led PoC demos, security architecture design, and consulting on Firewalls, IPS, WAF, Proxies, Endpoint Security, DLP, SIEM, and Vulnerability Scanners.
  • Designed, deployed, and integrated network & security infrastructures, enhancing resilience and protection.
  • Developed technical documentation (SoW, project plans, guides, training materials) for seamless knowledge transfer.
  • Provided incident response, troubleshooting, and support, ensuring rapid resolution of network & security issues.
  • Collaborated with vendors (Cisco, CheckPoint, Imperva, McAfee, etc.) for root cause analysis and issue resolution.
  • Worked with partners (SV-Tech, CMC, HPT, FPT, Sao Bac Dau, etc.) to address technical challenges and ensure project success.
  • Delivered cybersecurity consulting & support across industries: Banking, Insurance, Finance, Government, Oil & Gas, Retail, Healthcare, Education, Hospitality, and Transportation.
  • Project Contributions
  • CheckPoint NGFW & Sandbox: Secured networks for Dai-ichi Life, Binh Son Refinery, DatVietVAC, AsiaFoods, Saigon New Port, Big C Vietnam, EVN.
  • SolarWinds Orion: Enhanced IT monitoring for C.P Group, NovaGroup, SATRA, SONY, Vietsovpetro.
  • Symantec ProxySG (Bluecoat): Secured web access for Saigon New Port.
  • McAfee Secure Web Gateway: Strengthened malware protection for BIDC Bank.
  • Tufin Security Automation: Optimized policy management for VIB Bank, SCB Bank.
  • Tenable Security & Nessus: Improved vulnerability management for Vietnam Australia International School, Cambodian companies.
  • RSA Secure Access: Implemented MFA & identity security for EVN HCMC, multiple Cambodian companies.
Security Architecture DesignIncident ResponseTechnical DocumentationVendor CollaborationCybersecurity Consulting

One corp.

Network Engineer

Apr 2018Aug 2018 · 4 mos · Ho Chi Minh · On-site

  • Responsibilities:
  • Participated in network deployment projects for Citadines Regency Hotel, EVN SPC, Henley & Partners Vietnam Office, and other clients.
  • Deployed and configured networking solutions, including VLAN, Routing, IPsec VPN, Squid Proxy, Load Balancing, High Availability, firmware upgrades, configuration backup & restore.
  • Worked hands-on with network devices such as Cisco Switches (C2960, C3560), FortiGate 60D, CheckPoint SG1490, and Ruckus Access Points & Wireless Controllers.
  • Set up and managed a network monitoring system using Nagios, ensuring proactive detection of network issues.
  • Identified and reported technical issues to project leaders, assisting in troubleshooting and resolution.
Network DeploymentConfiguration ManagementNetwork Monitoring

Fpt information system

IT Support Technician

Jun 2017Mar 2018 · 9 mos · Ho Chi Minh

  • Responsibilities:
  • Implemented IT solutions, including network address allocation, VLAN configuration, switching & routing setup, DHCP, DNS, Windows Server with Active Directory, IIS/Apache web servers, network firewalls.
  • Worked with various network devices, including routers, switches, wireless access points, firewalls, ensuring optimal network performance and security.
  • Provided end-user support for issues related to Internet connectivity, applications, office software, Wi-Fi troubleshooting.
  • Promptly reported technical issues to specialists.
IT Solutions ImplementationEnd-user Support

Education

Posts and Telecommunications Institute of Technology

Bachelor's in Engineering Degrees — Communication and Computer Networking

Aug 2014Dec 2018

Stackforce found 100+ more professionals with Cloud Security & Threat Detection & Response

Explore similar profiles based on matching skills and experience