PHAN HOANG LY
FRESHER CYBERSECURITY
Date of Birth: September 24, 2003
Phone: 036*******
Email: ********@*****.***
Address: **/**/*, ****** **. 2, Thu Duc Ward, Ho Chi Minh City OBJECTIVE
With a solid foundation in network security and penetration testing, I am seeking a full-time position as a fresher to apply my skills in network security, monitoring, and incident response. I aim to apply my skills to contribute to the company's cybersecurity efforts while continuing to learn and grow in the field. EDUCATION
Posts and Telecommunications Institute of Technology (PTIT) Major: Information Security
Year: 2021 – 2026
SKILLS
• Network Security: Firewall, VPN, IPSec; IDS/IPS (Splunk, Wazuh, Snort, Zeek); log & traffic analysis
• System Administration: Windows/Linux, access control, virtualization (VMWare, VirtualBox)
• Penetration Testing: Metasploit, Burp Suite, Nmap, Wireshark
• Programming: Python, Java, C/C++
• Cloud & Monitoring: AWS, ELK Stack, centralized logging, CloudWatch
• Soft Skills: Problem solving, teamwork, time management, ….
• English: TOEIC 650 (Reading & Listening)
PROJECTS
DDoS Attack Monitoring and Mitigation Oct 2024 – Nov 2024 Built a traffic monitoring system using tshark, scapy and Flask dashboard to detect flood attack and HTTP latency spikes. Automatically mitigated DdoS attack via iptables and nginx in a VMWare environment. Protecting DHCP Server March 2025 – April 2025
Deploy DHCP service on CentOS 7 and perform attack scenarios using Kali Linux with tools such as Yersinia and Ettercap to carry out attacks. Meanwhile, on the DHCP server, use Snort and Iptables to detect and prevent attacks in a virtualized environment.
Monitoring Abnormal Traffic on AWS May 2025 – July 2025 Implemented centralized logging using the ELK Stack and Splunk on AWS to aggregate and analyze logs. Monitored abnormal HTTP behavior with CloudWatch alerts and responded by blocking malicious IPs through Network ACLs, enhancing security and operational efficiency. RL-based Intrusion Prevention System on AWS Aug 2025 – Oct 2025 Implemented an IPS system using Deep Q-Network to detect and respond to DDoS attacks (SYN flood, Slowloris, HTTP flood, ...) in real-time. The model learns from Zeek/nginx logs and performs actions such as blocking TCP, limiting connections, and triggering timeouts to ensure system continuity. Enterprise Network Security System on AWS Oct 2025 – Dec 2025 Designed and deployed a secure AWS infrastructure using VPC with DMZ, private and management subnets. Deployed a Flask web app with integrated Wazuh (SIEM), Keycloak (SSO & RBAC), OpenVPN, and encrypted RDS (KMS, Multi-AZ). Implemented MFA (Cognito), TLS encryption, input validation (SQLi/XSS protection), and automated security monitoring via CloudWatch, GuardDuty, and SNS. ACTIVITIES
Completed courses on CCNA, CompTIA Security+, CEH, AWS, strengthening knowledge in networking, system security, and cloud monitoring.