Skip to content
View dan-chui's full-sized avatar

Block or report dan-chui

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
dan-chui/README.md

Hi, I'm Dan 👋

Technology Risk • Enterprise IT • Cybersecurity | Tokyo, Japan 🇯🇵

Bridging financial risk, enterprise technology, cloud, and cybersecurity through hands-on projects focused on risk management, governance, Microsoft technologies, and security operations.


👨‍💻 About Me

I'm a risk and technology professional with more than 15 years of experience spanning financial risk management, quantitative analysis, and technology-focused projects.

My recent work explores the intersection of Technology Risk, Enterprise IT, Cloud, and Cybersecurity, combining my background in risk management with hands-on experience across Microsoft security technologies, Azure, Python, security operations, and governance frameworks.

Current areas of interest include:

  • 🛡️ Technology Risk & IT Risk
  • 🏢 Enterprise Technology & IT Operations
  • 📊 Governance, Risk & Compliance (GRC)
  • ☁️ Cloud & Microsoft Technologies
  • 🔐 Cybersecurity & Security Operations
  • 🤖 AI-Assisted Security & Automation
  • 📈 Risk Analytics

I enjoy understanding how technology, infrastructure, security, governance, and risk management work together to improve organizational resilience and support better business decisions.


🚀 Featured Projects

My portfolio demonstrates practical work across cybersecurity, technology risk, governance, Microsoft security technologies, AI-assisted security, and quantitative risk analytics.

🤖 AI SOC Analyst Agent

AI-Assisted Threat Hunting Platform

A cybersecurity capstone project combining:

  • Azure Log Analytics
  • Microsoft Defender for Endpoint
  • OpenAI
  • Python
  • MITRE ATT&CK

Key enhancements introduced during refactoring:

  • Time-window guardrails
  • Row-limiting controls
  • Sensitive data redaction
  • Table, field, and model allowlists
  • Human-in-the-loop remediation controls
  • Environment-variable configuration

➡️ https://github.com/dan-chui/AI-SOC-Analyst-Agent


🔎 Threat Hunting & Security Operations

💣 Ransomware Intrusion Investigation

  • Reconstructed a multi-stage ransomware attack
  • Identified persistence, credential access, staging, and impact activity
  • Mapped findings to MITRE ATT&CK
  • Produced structured incident analysis

➡️ https://github.com/dan-chui/Threat-Hunt-Ransomware-Investigation

🛰️ Tor Browser Threat Hunt

  • Investigated endpoint activity using Defender telemetry
  • Analyzed network communications and process execution
  • Reconstructed attack timeline
  • Escalated findings based on risk context

➡️ https://github.com/dan-chui/Threat-Hunt-Tor-Browser-Investigation


🛡️ Governance, Risk & Compliance

Vulnerability Management Program

  • Developed a risk-based remediation framework
  • Defined ownership and reporting workflows
  • Applied vulnerability prioritization methodology
  • Connected technical findings with business risk

➡️ https://github.com/dan-chui/Vulnerability-Management-Program

ISO/IEC 27001 Risk Register

  • Developed an ISO 27001-aligned risk assessment
  • Applied likelihood and impact scoring
  • Mapped risks to Annex A controls
  • Documented risk treatment and governance considerations

➡️ https://github.com/dan-chui/Risk-Register


📊 Risk Analytics & Automation

Value at Risk (VaR) Portfolio Analysis

A quantitative risk project connecting my financial risk background with Python-based analytics.

  • Multi-asset portfolio risk model
  • Historical and Parametric VaR
  • Python-based workflow automation
  • Quantitative risk analysis and reporting

➡️ https://github.com/dan-chui/VaR-Portfolio-Analysis


🧰 Skills & Technologies

🛡️ Technology Risk & Governance

Technology Risk • IT Risk • GRC • ISO/IEC 27001 • NIST CSF • IT Controls • Risk Assessments • Vulnerability Management

🏢 Enterprise Technology

Microsoft Entra ID • Identity & Access Management • Microsoft 365 • Windows • IT Operations • Enterprise Infrastructure Concepts

☁️ Cloud & Microsoft

Microsoft Azure • Azure Log Analytics • Azure Monitor • Microsoft Defender • Microsoft Sentinel

🔐 Cybersecurity

Threat Hunting • Incident Analysis • Security Monitoring • MITRE ATT&CK • KQL • SIEM

📊 Data, Risk & Automation

Python • pandas • NumPy • Excel • Quantitative Risk Analysis • Git • GitHub


🎓 Certifications & Professional Development

  • Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
  • CompTIA Security+
  • ISC² Certified in Cybersecurity (CC)
  • AWS Certified Cloud Practitioner
  • MIT Sloan – Cybersecurity for Managers

📬 Connect


📌 Interested in opportunities across Technology Risk, IT Risk, GRC, Enterprise IT, IT/Business Analysis, Cloud & Infrastructure Operations, Microsoft technologies, and Cybersecurity.


🇯🇵 日本語

Danです 👋

テクノロジーリスク • エンタープライズIT • サイバーセキュリティ | 東京

金融リスク管理、定量分析、テクノロジー分野で15年以上の経験を持つリスク・テクノロジープロフェッショナルです。

これまでの金融リスク管理の経験を活かしながら、現在はテクノロジーリスク、エンタープライズIT、クラウド、サイバーセキュリティの分野に関心を広げ、Microsoft Security、Azure、Python、セキュリティ運用、ガバナンスに関する実践的なプロジェクトに取り組んでいます。

特に以下の分野に関心があります。

  • テクノロジーリスク・ITリスク
  • GRC・セキュリティガバナンス
  • エンタープライズIT・IT運用
  • クラウド・Microsoftテクノロジー
  • サイバーセキュリティ・セキュリティ運用
  • AI・自動化
  • リスク分析

主なプロジェクト

🤖 AI SOC Analyst Agent

Azure Log Analytics、Microsoft Defender、OpenAI、Pythonを活用したAI支援型脅威ハンティングプロジェクトです。

主な改善点:

  • ガードレールの実装
  • 機密データ・PII(個人情報)の保護
  • データ取得範囲の制御
  • 人による承認プロセス
  • 設定・ドキュメントの改善

➡️ https://github.com/dan-chui/AI-SOC-Analyst-Agent


保有資格・専門研修

  • Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
  • CompTIA Security+
  • ISC² Certified in Cybersecurity (CC)
  • AWS Certified Cloud Practitioner
  • MIT Sloan – Cybersecurity for Managers

リンク


現在、東京を中心に以下の分野に関連するポジションに関心があります。

  • テクノロジーリスク・ITリスク
  • GRC・セキュリティガバナンス
  • エンタープライズIT・IT運用
  • IT・ビジネスアナリシス
  • クラウド・インフラ運用
  • サイバーセキュリティ・セキュリティ運用

Pinned Loading

  1. AI-SOC-Analyst-Agent AI-SOC-Analyst-Agent Public

    AI-assisted SOC Analyst Agent using Azure Log Analytics, Microsoft Defender, OpenAI, and Python for threat hunting and security investigations.

    Python

  2. Threat-Hunt-Ransomware-Investigation Threat-Hunt-Ransomware-Investigation Public

    Threat hunting investigation reconstructing a multi-stage ransomware attack using Microsoft Defender telemetry, KQL, and MITRE ATT&CK mapping.

  3. Threat-Hunt-Tor-Browser-Investigation Threat-Hunt-Tor-Browser-Investigation Public

    Threat hunting investigation analyzing Tor Browser activity using Microsoft Defender telemetry, KQL, and structured incident reporting.

  4. Vulnerability-Management-Program Vulnerability-Management-Program Public

    Risk-based vulnerability management framework covering prioritization, remediation workflows, ownership, and reporting.

    1

  5. Risk-Register Risk-Register Public

    ISO/IEC 27001-aligned risk register with likelihood-impact scoring and security control mapping.

  6. VaR-Portfolio-Analysis VaR-Portfolio-Analysis Public

    Python and Excel-based Value at Risk (VaR) model demonstrating portfolio risk analytics, covariance analysis, and quantitative risk management.

    Jupyter Notebook 1