Technology Risk • Enterprise IT • Cybersecurity | Tokyo, Japan 🇯🇵
Bridging financial risk, enterprise technology, cloud, and cybersecurity through hands-on projects focused on risk management, governance, Microsoft technologies, and security operations.
I'm a risk and technology professional with more than 15 years of experience spanning financial risk management, quantitative analysis, and technology-focused projects.
My recent work explores the intersection of Technology Risk, Enterprise IT, Cloud, and Cybersecurity, combining my background in risk management with hands-on experience across Microsoft security technologies, Azure, Python, security operations, and governance frameworks.
Current areas of interest include:
- 🛡️ Technology Risk & IT Risk
- 🏢 Enterprise Technology & IT Operations
- 📊 Governance, Risk & Compliance (GRC)
- ☁️ Cloud & Microsoft Technologies
- 🔐 Cybersecurity & Security Operations
- 🤖 AI-Assisted Security & Automation
- 📈 Risk Analytics
I enjoy understanding how technology, infrastructure, security, governance, and risk management work together to improve organizational resilience and support better business decisions.
My portfolio demonstrates practical work across cybersecurity, technology risk, governance, Microsoft security technologies, AI-assisted security, and quantitative risk analytics.
AI-Assisted Threat Hunting Platform
A cybersecurity capstone project combining:
- Azure Log Analytics
- Microsoft Defender for Endpoint
- OpenAI
- Python
- MITRE ATT&CK
Key enhancements introduced during refactoring:
- Time-window guardrails
- Row-limiting controls
- Sensitive data redaction
- Table, field, and model allowlists
- Human-in-the-loop remediation controls
- Environment-variable configuration
➡️ https://github.com/dan-chui/AI-SOC-Analyst-Agent
- Reconstructed a multi-stage ransomware attack
- Identified persistence, credential access, staging, and impact activity
- Mapped findings to MITRE ATT&CK
- Produced structured incident analysis
➡️ https://github.com/dan-chui/Threat-Hunt-Ransomware-Investigation
- Investigated endpoint activity using Defender telemetry
- Analyzed network communications and process execution
- Reconstructed attack timeline
- Escalated findings based on risk context
➡️ https://github.com/dan-chui/Threat-Hunt-Tor-Browser-Investigation
- Developed a risk-based remediation framework
- Defined ownership and reporting workflows
- Applied vulnerability prioritization methodology
- Connected technical findings with business risk
➡️ https://github.com/dan-chui/Vulnerability-Management-Program
- Developed an ISO 27001-aligned risk assessment
- Applied likelihood and impact scoring
- Mapped risks to Annex A controls
- Documented risk treatment and governance considerations
➡️ https://github.com/dan-chui/Risk-Register
A quantitative risk project connecting my financial risk background with Python-based analytics.
- Multi-asset portfolio risk model
- Historical and Parametric VaR
- Python-based workflow automation
- Quantitative risk analysis and reporting
➡️ https://github.com/dan-chui/VaR-Portfolio-Analysis
Technology Risk • IT Risk • GRC • ISO/IEC 27001 • NIST CSF • IT Controls • Risk Assessments • Vulnerability Management
Microsoft Entra ID • Identity & Access Management • Microsoft 365 • Windows • IT Operations • Enterprise Infrastructure Concepts
Microsoft Azure • Azure Log Analytics • Azure Monitor • Microsoft Defender • Microsoft Sentinel
Threat Hunting • Incident Analysis • Security Monitoring • MITRE ATT&CK • KQL • SIEM
Python • pandas • NumPy • Excel • Quantitative Risk Analysis • Git • GitHub
- Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
- CompTIA Security+
- ISC² Certified in Cybersecurity (CC)
- AWS Certified Cloud Practitioner
- MIT Sloan – Cybersecurity for Managers
- LinkedIn: https://www.linkedin.com/in/danchui/
- Blog: https://happy-bytes.vercel.app/
📌 Interested in opportunities across Technology Risk, IT Risk, GRC, Enterprise IT, IT/Business Analysis, Cloud & Infrastructure Operations, Microsoft technologies, and Cybersecurity.
テクノロジーリスク • エンタープライズIT • サイバーセキュリティ | 東京
金融リスク管理、定量分析、テクノロジー分野で15年以上の経験を持つリスク・テクノロジープロフェッショナルです。
これまでの金融リスク管理の経験を活かしながら、現在はテクノロジーリスク、エンタープライズIT、クラウド、サイバーセキュリティの分野に関心を広げ、Microsoft Security、Azure、Python、セキュリティ運用、ガバナンスに関する実践的なプロジェクトに取り組んでいます。
特に以下の分野に関心があります。
- テクノロジーリスク・ITリスク
- GRC・セキュリティガバナンス
- エンタープライズIT・IT運用
- クラウド・Microsoftテクノロジー
- サイバーセキュリティ・セキュリティ運用
- AI・自動化
- リスク分析
Azure Log Analytics、Microsoft Defender、OpenAI、Pythonを活用したAI支援型脅威ハンティングプロジェクトです。
主な改善点:
- ガードレールの実装
- 機密データ・PII(個人情報)の保護
- データ取得範囲の制御
- 人による承認プロセス
- 設定・ドキュメントの改善
➡️ https://github.com/dan-chui/AI-SOC-Analyst-Agent
- Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
- CompTIA Security+
- ISC² Certified in Cybersecurity (CC)
- AWS Certified Cloud Practitioner
- MIT Sloan – Cybersecurity for Managers
- LinkedIn: https://www.linkedin.com/in/danchui/
- Blog: https://happy-bytes.vercel.app/
現在、東京を中心に以下の分野に関連するポジションに関心があります。
- テクノロジーリスク・ITリスク
- GRC・セキュリティガバナンス
- エンタープライズIT・IT運用
- IT・ビジネスアナリシス
- クラウド・インフラ運用
- サイバーセキュリティ・セキュリティ運用
