Skip to content
View dan-chui's full-sized avatar

Block or report dan-chui

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
dan-chui/README.md

Hi, I'm Dan 👋

Technology Risk & Cybersecurity Analyst • Tokyo, Japan 🇯🇵

Bridging enterprise risk management, security operations, and AI-assisted security workflows through hands-on projects, threat hunting, and governance-focused security initiatives.


About Me

I am a Technology Risk and Cybersecurity Analyst with a background in financial risk governance and enterprise risk management.

My recent work focuses on:

  • Technology Risk & IT Risk
  • Security Governance & GRC
  • Security Operations & Threat Hunting
  • Microsoft Security Technologies
  • AI-Assisted Security Workflows
  • Risk Analytics & Automation

I enjoy translating technical findings into structured risk insights and exploring how governance, controls, and security operations intersect in modern organizations.


🚀 Featured Project

🤖 AI SOC Analyst Agent

AI-Assisted Threat Hunting Platform

A cybersecurity capstone project combining:

  • Azure Log Analytics
  • Microsoft Defender for Endpoint
  • OpenAI
  • Python
  • MITRE ATT&CK

Key enhancements introduced during refactoring:

  • Time-window guardrails
  • Row-limiting controls
  • Sensitive data redaction
  • Table, field, and model allowlists
  • Human-in-the-loop remediation controls
  • Environment-variable configuration

➡️ https://github.com/dan-chui/AI-SOC-Analyst-Agent


🔎 Threat Hunting & Security Operations

💣 Ransomware Intrusion Investigation

  • Reconstructed a multi-stage ransomware attack
  • Identified persistence, credential access, staging, and impact activity
  • Mapped findings to MITRE ATT&CK
  • Produced structured incident analysis

➡️ https://github.com/dan-chui/Threat-Hunt-Ransomware-Investigation

🛰️ Tor Browser Threat Hunt

  • Investigated endpoint activity using Defender telemetry
  • Analyzed network communications and process execution
  • Reconstructed attack timeline
  • Escalated findings based on risk context

➡️ https://github.com/dan-chui/Threat-Hunt-Tor-Browser-Investigation


🛡️ Governance, Risk & Compliance

Vulnerability Management Program

  • Risk-based remediation framework
  • Ownership and reporting workflows
  • Prioritization methodology

➡️ https://github.com/dan-chui/Vulnerability-Management-Program

ISO/IEC 27001 Risk Register

  • ISO 27001-aligned risk assessment
  • Likelihood and impact scoring
  • Annex A control mapping

➡️ https://github.com/dan-chui/Risk-Register


📊 Risk Analytics & Automation

Value at Risk (VaR) Portfolio Analysis

  • Multi-asset portfolio risk model
  • Historical and Parametric VaR
  • Python-based workflow automation
  • Quantitative risk analysis

➡️ https://github.com/dan-chui/VaR-Portfolio-Analysis


🧰 Skills & Technologies

Security Operations

Threat Hunting • Incident Analysis • Alert Triage • MITRE ATT&CK • KQL • SIEM Analysis

Microsoft Security

Microsoft Sentinel • Defender for Endpoint • Microsoft Entra ID • Azure Log Analytics • SC-900

Technology Risk & Governance

Technology Risk • IT Risk • GRC • ISO 27001 • NIST CSF • IT Controls • Vulnerability Management

Data & Automation

Python • pandas • NumPy • Excel • Data Analysis • Risk Analytics • Git/GitHub


🎓 Certifications

  • Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
  • CompTIA Security+
  • ISC² Certified in Cybersecurity (CC)
  • MIT Sloan – Cybersecurity for Managers
  • AWS Certified Cloud Practitioner

📬 Connect


Currently exploring opportunities in Technology Risk, IT Risk, Security Governance, GRC, Security Operations, and cybersecurity-adjacent analyst roles in Tokyo and international environments.


🇯🇵 日本語

Danです 👋

テクノロジーリスク & サイバーセキュリティアナリスト|東京

金融リスク管理のバックグラウンドを活かしながら、現在はテクノロジーリスク、セキュリティガバナンス、サイバーセキュリティ分野に取り組んでいます。

特に以下の領域に関心があります。

  • テクノロジーリスク / ITリスク
  • セキュリティガバナンス / GRC
  • セキュリティ運用(SOC)
  • 脅威ハンティング
  • Microsoft Security
  • AIを活用したセキュリティ分析

主なプロジェクト

🤖 AI SOC Analyst Agent

Azure Log Analytics、Microsoft Defender、OpenAI、Python を活用した AI支援型脅威ハンティングプロジェクトです。

主な改善点:

  • ガードレールの実装
  • PII(個人情報)保護
  • データ取得範囲の制御
  • 人による承認プロセス
  • 設定・ドキュメントの改善

➡️ https://github.com/dan-chui/AI-SOC-Analyst-Agent


保有資格

  • CompTIA Security+
  • ISC² Certified in Cybersecurity (CC)
  • Microsoft SC-900
  • MIT Cybersecurity for Managers
  • AWS Certified Cloud Practitioner

リンク


現在、東京を中心に以下の分野に関連するポジションに関心があります。

  • テクノロジーリスク
  • ITリスク
  • セキュリティガバナンス
  • GRC
  • サイバーセキュリティ
  • セキュリティ運用(SOC)

Pinned Loading

  1. AI-SOC-Analyst-Agent AI-SOC-Analyst-Agent Public

    AI-assisted SOC Analyst Agent using Azure Log Analytics, Microsoft Defender, OpenAI, and Python for threat hunting and security investigations.

    Python

  2. Threat-Hunt-Ransomware-Investigation Threat-Hunt-Ransomware-Investigation Public

    Threat hunting investigation reconstructing a multi-stage ransomware attack using Microsoft Defender telemetry, KQL, and MITRE ATT&CK mapping.

  3. Threat-Hunt-Tor-Browser-Investigation Threat-Hunt-Tor-Browser-Investigation Public

    Threat hunting investigation analyzing Tor Browser activity using Microsoft Defender telemetry, KQL, and structured incident reporting.

  4. Vulnerability-Management-Program Vulnerability-Management-Program Public

    Risk-based vulnerability management framework covering prioritization, remediation workflows, ownership, and reporting.

    1

  5. Risk-Register Risk-Register Public

    ISO/IEC 27001-aligned risk register with likelihood-impact scoring and security control mapping.

  6. VaR-Portfolio-Analysis VaR-Portfolio-Analysis Public

    Python and Excel-based Value at Risk (VaR) model demonstrating portfolio risk analytics, covariance analysis, and quantitative risk management.

    Jupyter Notebook 1