๐ฏ Professional Development Phase (Since June 2025)
Current Phase: Dedicated to professional advancement through certification and global industry engagement while targeting senior cybersecurity roles in Singaporeโs regulated sectors
๐ CISSP Certification Preparation
Target: Q3 2025 examination (studying 15+ hours/week)
๐ International Conference Attendance
BlackHat USA & DefCon 33 (August 2025) for latest cybersecurity trends
๐ค AI Security Integration Learning
On-going AI-powered cybersecurity solutions and automation workflows
๐ Target Sectors
Financial services, technology, and critical infrastructure in Singapore, with emphasis on regulated environments
Experience
Senior Information Security Officer
DCS Card Centre
๐
Jul 2024 - June 2025 ๐ Singapore
๐ข Singaporeโs leading payment card issuer with expanding footprint across China and Asia-Pacific via partnerships with Mastercard, Visa, and UnionPay
๐ฏ Directed multi-country security governance programs across Singapore, Malaysia, and China, integrating PCI DSS, DLP, SSO, and incident response capabilities under regulatory pressure
- Led enterprise PCI DSS v4 readiness project, assessing 100+ control points and achieving 80% compliance within timeline constraints
- Designed and deployed enterprise SSO solution supporting 200+ users across multiple business units, enhancing identity governance
- Implemented organization-wide DLP solution across 200+ endpoints, reducing sensitive data incidents by 25%
- Standardized technical controls across Singapore, Malaysia, and China via a unified security architecture framework, streamlining reporting and compliance
- Conducted comprehensive security assessments resulting in 30% reduction in critical vulnerabilities
- Developed automated incident response procedures and playbooks, reducing mean time to resolution (MTTR) by 40% and improving incident visibility
Career Break | Professional Development
Personal & Family Care
๐
Sep 2022 - Jul 2024 ๐ Malaysia
๐ฑ Balanced caregiving responsibilities with continuous upskilling in cybersecurity
- Family caregiving responsibilities
- Earned Google Cybersecurity Professional Certificate with 98% average completion rate across 6 specialized courses
- Actively participated in cybersecurity communities and maintained awareness of industry trends and emerging threats
Information Security Engineer
HuoXian Security Technology
๐
Sep 2021 - Sep 2022 ๐ Beijing, China
๐ข Cybersecurity startup in Beijing focused on intelligent AppSec, serving 100+ enterprise clients across key industries
๐ฏ Bridged technical expertise and business goals to drive IAST platform adoption, strengthen product accuracy, and enable high-conversion pre-sales engagement
- Produced end-to-end technical documentation for the interactive application security testing (IAST) platformโincluding deployment, API integration, and troubleshootingโstreamlining onboarding and reducing setup time by 35%
- Delivered technical demos and solution briefings to 50+ prospects, achieving an 80% demo-to-trial conversion rate and driving early-stage customer acquisition
- Maintained and fine-tuned 500+ vulnerability detection rules aligned to OWASP Top 10, reducing false positives by 30% and improving enterprise deployment accuracy
- Transformed customer feedback into actionable product roadmap priorities through cross-functional collaboration, driving 3 major feature releases and boosting retention by 25%
Information Security Engineer
Information Security Services Digital United (ISSDU)
๐
Nov 2017 - May 2021 ๐ Taipei, Taiwan
๐ข Taiwan's premier cybersecurity consulting firm serving 200+ enterprise clients across financial services, manufacturing, and government sectors
๐ฏ Led end-to-end security consulting engagements, including risk assessments, SSDLC implementation, and technical enablement programs for enterprise clients
- Conducted 30+ comprehensive security assessments using OWASP methodology, identified and remediated 100+ critical vulnerabilities including SQL injection, XSS, CSRF, and authentication bypass flaws
- Designed and implemented SSDLC frameworks for 15+ enterprise clients, reducing post-deployment security issues by 60% and improving secure coding practices
- Revolutionized assessment delivery process through automation and standardization, reducing cycle time from 15 to 7 days while maintaining quality standards, improving team efficiency by 40%
- Led a technical enablement program to instill secure coding habits across 100+ developers from diverse industries, achieving a 95% satisfaction rate and demonstrable improvements in code quality and security awareness
Leadership & Collaboration
Cross-Functional Project Leadership
Led cross-functional PCI DSS v4 compliance initiative across IT, Risk, and Operations teams, aligning 30+ stakeholders and delivering milestones on time under regulatory scrutiny
Regional Security Management
Oversaw regional cybersecurity programs across Singapore, Malaysia, and China, standardizing technical controls and strengthening risk governance in alignment with compliance mandates
Strategic Stakeholder Engagement
Partnered with senior leadership and department heads to align enterprise security strategy with business objectives, translating technical priorities into measurable organizational value
Mentorship & Cybersecurity Enablement
Mentored 30+ developers through secure coding workshops and led enterprise-wide security awareness training, building a security-first culture across business units
Education
M.S. in Information Systems
National Tsing Hua University
๐
Sep 2012 - Jun 2016 ๐ Hsinchu, Taiwan
๐ Ministry of Education Scholarship โข Economic Affairs Technology Competition Award 2013
๐ Ministry of Education Scholarship โข Economic Affairs Technology Competition Award 2013
B.S. in Information Management
National Chung Hsing University
๐
Sep 2008 - Jun 2012 ๐ Taichung, Taiwan
๐ Trend Micro Technology Competition Awards 2011-2012
๐ Trend Micro Technology Competition Awards 2011-2012
Key Achievements
Led Compliance Project
Achieved 80% PCI DSS v4 compliance across 100+ control points in financial payment systems
Enhanced Team Efficiency
Reduced assessment delivery cycle by 50% and improved team productivity by 40%
Designed SSO Solution
Implemented SSO solution serving 200+ users across multiple business units and regional offices
Enhanced Security Operations
Reduced security incidents by 25% through DLP implementation and automated response procedures
Certification
CISSP (In Preparation)
Target Q3 2025 for enhanced cybersecurity leadership
Google Cybersecurity (2024)
Professional Certificate in cybersecurity principles (2024)
ISC2 Certified in Cybersecurity (2024)
Foundation certification in cybersecurity
ISO27001
Attended ISO/IEC 27001 Lead Auditor Training (SGS, 2011) + ISMS Transition & Implementation Training (NQA, 2018)
Certified Ethical Hacker (2020)
Penetration testing and vulnerability assessment methodologies
Languages
English
Working Proficiency
Chinese
Native
Malay
Advanced
Core Skills
๐ก๏ธ Compliance & Standards
Security Compliance
ISO 27001
PCI DSS
Data Protection
๐ Security Assessment
Application Security
Vulnerability Mgmt
๐ง Development & Operations
SSDLC
DevSecOps
Security Integration
๐ Identity & Data Security
IAM
DLP
๐ค Emerging Technology
AI Security
Tech Stack
๐ก๏ธ Application Security Testing
SAST: Fortify, Checkmarx, Semgrep
DAST: Nessus, Qualys, Tenable
DAST: Nessus, Qualys, Tenable
๐ป Development & Automation
Programming: Python
Workflow Automation: N8N
Scripting: PowerShell, Bash
Workflow Automation: N8N
Scripting: PowerShell, Bash
๐ Data Loss Prevention
DLP Solutions: Seal Suite