Hi, I'm

Bui Thanh Toan

Security Engineer

Detecting threats before they become incidents — SIEM · Threat Hunting · MITRE ATT&CK · ISO 27001

About Me

Security Engineer with 4+ years of experience protecting enterprise infrastructure. Started as an IT Operations Engineer at Digi-Texx and evolved into a dedicated Cyber Security specialist with deep expertise in SIEM operations and detection engineering.

I specialize in building detection pipelines aligned with MITRE ATT&CK, operating enterprise SIEM platforms (Wazuh/Splunk), and conducting proactive threat hunting to uncover adversary activity before damage occurs.

Currently at STS Software Technology, architecting centralized security monitoring and driving ISO/IEC 27001:2022 compliance initiatives across the organization.

0 Years in Security
0 Companies Secured
ATT&CK MITRE Framework
27001 ISO/IEC 2022

Technical Skills

Security Operations

  • Wazuh / Splunk SIEM
  • Threat Hunting
  • Log Analysis
  • Detection Engineering

Offensive Security

  • Penetration Testing
  • MITRE ATT&CK
  • Caldera / Atomic Red Team
  • OSINT / Dark Web Intel

Infrastructure

  • Linux / Windows Server
  • VMware ESXi
  • GitHub Actions / CI-CD
  • Fortigate / Cisco / Aruba

GRC & Threat Intel

  • ISO/IEC 27001:2022
  • Risk Assessment
  • OpenVAS / Rapid7
  • MISP / CIS Benchmark

Experience

01/2025 — Present

IT Security Engineer

CÔNG TY CỔ PHẦN CÔNG NGHỆ PHẦN MỀM STS

  • Architected and operated a centralized SIEM platform (Wazuh/Splunk), processing multi-source security logs across endpoint, network, and cloud environments to enhance enterprise threat visibility.
  • Led continuous security monitoring and incident response operations, reducing false positives through advanced rule tuning and behavioral detection techniques.
  • Designed and expanded detection engineering frameworks aligned with MITRE ATT&CK, strengthening coverage against brute force, lateral movement, C2 communication, ransomware, and data exfiltration.
  • Conducted proactive threat hunting leveraging OSINT and dark-web intelligence; automated external threat ingestion via n8n API integrations for real-time intelligence correlation.
  • Led vulnerability management lifecycle — scanning (OpenVAS/Rapid7), risk prioritization, and remediation tracking — improving overall security posture.
  • Implemented enterprise hardening standards based on CIS Benchmarks across Windows/Linux servers, VMware ESXi, and network devices; enforced TLS and secure configuration baselines.
  • Contributed to ISO/IEC 27001:2022 ISMS implementation: risk assessment, control mapping, and security policy development.
  • Delivered executive-level security reports and risk assessments, translating technical findings into business-impact insights.
WazuhSplunkMITRE ATT&CK OSINTn8nISO 27001Threat Hunting
02/2023 — 01/2025

Cyber Security Engineer

Công Ty TNHH DIGI-TEXX

  • Centralized security monitoring using Wazuh and Splunk; developed detection use cases aligned with MITRE ATT&CK for Endpoint, Network, and Gateway environments; optimized alert rules for brute-force, exploitation, scanning, lateral movement, and data exfiltration.
  • Detection Engineering & Threat Hunting: designed and tuned detection rules for ATT&CK techniques (T1110, T1059, T1105, T1071, T1021, T1486); integrated MISP threat intel feeds; conducted purple-team simulations with Caldera and Atomic Red Team.
  • Vulnerability Management: periodic infrastructure and application scanning using OpenVAS and Rapid7; analyzed findings, prioritized remediation, and tracked risk reduction.
  • System & Network Hardening: implemented CIS Benchmark configurations across Windows/Linux servers, VMware ESXi, and network devices (Fortigate, Aruba, Cisco); enforced TLS hardening and secure configuration baselines.
  • Endpoint & Log Security: deployed and managed Sysmon, Auditd, File Integrity Monitoring (FIM), and Windows Event Forwarding; monitored Microsoft 365 via Office 365 Management API.
  • Designed server/network security controls including segmentation, access control policies, and secure architecture for internal systems and AI Camera projects.
  • Provided security consultation to development teams, supporting secure deployment practices and incident troubleshooting.
WazuhSplunkMISP OpenVASRapid7CIS BenchmarkSysmon
01/2022 — 01/2023

System Engineer

Công Ty TNHH DIGI-TEXX

  • Provided technical support and troubleshooting for Windows and Linux end users, ensuring minimal downtime and SLA compliance.
  • Administered Windows and Linux servers including user account lifecycle management (creation, deactivation, permission control, internet access policies).
  • Deployed and operated VMware ESXi virtualization infrastructure: VM provisioning, cloning, snapshot management, resource allocation (CPU/RAM/Storage), and performance monitoring.
  • Managed Git repositories on GitHub: repository structure organization, access control, branching strategies, and permission policies.
  • Designed and implemented CI/CD pipelines using GitHub Actions: automated build, test, and deployment workflows; self-hosted runner setup and maintenance; pipeline monitoring and failure resolution.
VMware ESXiLinuxWindows ServerGitHub ActionsCI/CD
05/2021 — 12/2021

IT Operations Engineer

Công Ty TNHH DIGI-TEXX

  • Proactively monitored and maintained IT infrastructure including servers, virtualization platforms, backup systems, network devices (switches, routers, firewalls), CCTV systems, and internet connectivity.
  • Performed Level 1 incident response based on established SOPs, ensuring timely diagnosis and resolution of infrastructure and application-related issues.
  • Identified anomalies through system and network monitoring, conducted initial root cause analysis, and escalated critical incidents to minimize service disruption.
  • Maintained detailed incident records, prepared technical reports, and collaborated cross-functionally to improve operational efficiency and prevent recurrence.
MonitoringIncident ResponseNetwork DevicesSOP

Certifications & Education

Certified Threat Intelligence & Governance Analyst (CTIGA)
02/2026
CCNA (200-301)
NGN Networking Academy · 04/2022
Red Team Specialist
Cyberjutsu Academy · 07/2023 – 03/2024
Linux Professional Institute (LPI)
BKACAD Institute of Technology · 06/2022 – 09/2022
Cyber Security
iSPACE Cybersecurity College · 04/2019 – 04/2021

Open Source Projects

Detection Rules Library

A curated collection of Wazuh and Sigma detection rules mapped to MITRE ATT&CK. Covers credential access, lateral movement, ransomware indicators, and defense evasion. Rules validated with Atomic Red Team and Caldera simulations.

WazuhSigmaMITRE ATT&CKSIEMDetection Engineering

Threat Hunting Playbooks

Structured threat hunting playbooks with ready-to-use Wazuh and Splunk SPL queries for each ATT&CK technique. Each playbook includes hypothesis, step-by-step investigation guide, response actions, and false positive handling.

Threat HuntingSplunk SPLWazuhMITRE ATT&CKIncident Response

IOC Checker

Python CLI tool for automated IOC analysis — checks IPs, domains, and file hashes against VirusTotal and AbuseIPDB. Features auto-classification, color-coded Rich terminal output, bulk processing, and JSON/CSV export.

PythonVirusTotal APIAbuseIPDBThreat IntelCLI

OSINT Scout

Enterprise attack surface & credential exposure recon tool. Aggregates Shodan, Censys, and HackedList.io darknet breach intelligence — open ports, CVEs (CVSS-weighted), and compromised credential counts — into a two-dimensional risk score.

PythonShodan APICensys APIHackedList.ioOSINT

Get In Touch

Open to new opportunities in security engineering, threat detection, or blue team roles. Let's connect.