Post Job Free
Sign in

Cloud Detection Security Engineer

Location:
San Jose, CA
Posted:
August 07, 2026

Contact this candidate

Resume:

Huy (Hugo) Ngo

Cloud Detection Engineer Threat Detection · Detection Engineering · Incident Response AWS · Azure San Jose, CA · *************@*****.*** · 669-***-**** · linkedin.com/in/huydinhngo · github.com/HNCloudSec SUMMARY

Security professional specializing in detection and response across regulated healthcare and SaaS — tuning and operationalizing Splunk Enterprise Security detections mapped to MITRE ATT&CK, authoring Custom IOA rules and hunting threats in CrowdStrike Falcon, and running detection and response across AWS (GuardDuty, CloudTrail) and Microsoft (Entra ID, Defender, Azure Monitor) telemetry. Author of a continuously maintained Zero Trust reference spanning 75 AWS and 61 Azure services — each service documented to its threat model, control implementation, and detection coverage. EXPERIENCE

Cybersecurity Analyst — Cloud Detection & Incident Response 05/2022 – Present CommonSpirit Health — One of the largest U.S. nonprofit hospital and health systems Cyber Vigilance & Defense

– Tuned and operationalized Splunk Enterprise Security correlation searches mapped to MITRE ATT&CK — closing coverage gaps, cutting false positives, and carrying changes through senior-engineer review into production.

– Authored Custom IOA rules in CrowdStrike Falcon and tuned vendor-managed detections, hunting threats across Falcon and Splunk telemetry.

– Triaged incidents and ran playbook-driven response in Cortex XSOAR, tuning ingestion and playbook logic during the SOC's rollout of the platform.

– Surfaced anomalous sign-ins and identity attack activity from Entra ID and Azure Monitor telemetry, and triaged Proofpoint TAP alerts — retracting delivered messages and tuning policy against repeat campaigns.

– Investigated and resolved phishing, malware, and insider-threat incidents end to end — from triage through containment, eradication, and post-incident documentation — using CrowdStrike Falcon, Splunk, and ServiceNow.

– Contained and remediated cloud-identity compromises across Microsoft 365 and Entra ID, scoping blast radius through Defender alerts and sign-in telemetry.

– Prioritized and drove remediation of high-severity Defender for Cloud workload findings across production, working fixes to closure with resource owners.

– Supported enterprise governance initiatives — GCP SecOps controls mapping, Azure tenant-consolidation governance, and recurring HIPAA control assessments with audit-ready documentation. Information Security Analyst — AWS Cloud Security & Detection 05/2024 – 08/2025 Guild Education — Security Operations

– Engineered threat detection and alerting across AWS (GuardDuty, CloudTrail, CloudWatch), tuning rules to cut false positives and routing findings into ticketing (Zendesk, later Jira).

– Automated incident response with Python, Lambda, and CloudFormation, reducing manual intervention through repeatable infrastructure-as-code.

– Investigated GuardDuty credential and anomalous-behavior findings, scoping impact through CloudTrail and containing affected access keys.

– Built IAM guardrails and Service Control Policies enforcing least-privilege access, MFA, and centralized access governance via IAM Identity Center.

– Led a data loss prevention (DLP) initiative using MIND to detect and prevent leakage of PII and sensitive or proprietary data.

– Improved vulnerability management with InsightVM and AWS Security Hub, prioritizing and remediating critical findings.

– Advised on IAM, network, and third-party integration decisions in Architecture Design Reviews (ADRs) alongside senior reviewers. CERTIFICATIONS

AWS SAA — Certified Solutions Architect, Associate GCAD — GIAC Cloud Security Architecture & Design AWS SCS — Certified Security, Specialty (in progress) GCTD — GIAC Cloud Threat Detection GWEB — GIAC Certified Web Application Defender GCSA — GIAC Cloud Security Automation GCIH — GIAC Certified Incident Handler GPCS — GIAC Public Cloud Security GCIA — GIAC Certified Intrusion Analyst CISSP — (ISC) PROJECTS

Zero Trust Architecture Reference — AWS + Azure Security Engineering zta-reference.com · GitHub

– Publish and maintain a practitioner-grade Zero Trust reference for AWS and Azure across 10 mirrored layers — each service page documenting architecture decisions, secure deployment, failure modes, response playbooks, automation, and controls mapped to SOC 2, PCI DSS v4.0.1, NIST 800-53 Rev 5, CIS Benchmarks, and ISO 27001.

– Built out the Threat Monitoring & Detection and Log Analysis & Audit layers end to end on both clouds — GuardDuty/CloudTrail detection and alarm design on AWS, Defender XDR and Sentinel analytics on Azure, each carried through to its response workflow.

– Built and maintained a Python conformance pipeline (automated audit + deployable build generation), using AI-assisted development while owning the spec, code review, and verification of every AWS identifier and control ID against current standard revisions.

AWS Detection & Response Engineering Lab GitHub: aws-security

– Built a cost-controlled detection pipeline over CloudTrail, GuardDuty, EventBridge, and CloudWatch with partition-projected Athena threat hunting — validated by delivered notification rather than resource creation, with detection latency and query scan cost measured and committed.

– Authored Sigma detection rules — each with threat hypothesis, false-positive assumptions, MITRE mapping, and blind spots — tested positive and negative against a frozen CloudTrail corpus and gated in CI, so a broken rule blocks the pull request.

– Automated bounded response in Python and Lambda — lease-based idempotency collapsing repeat findings to a single action, containment scoped to the exact credential named in the finding, and destructive role containment deliberately human-gated.

– Documented a real investigation and its counterfactual — one alert tuned as a service-linked-role false positive, one orphaned workload terminated — with ADRs recording each design trade-off. NexPay — Applied Multi-Cloud Zero Trust Case Study (AWS + Azure) GitHub: nexpay-zero-trust

– Threat-modeled a PCI-scoped B2B FinTech across 7 MITRE ATT&CK–mapped attack scenarios, designing a detection-and-response path for each (GuardDuty/CloudTrail EventBridge SNS alerting and Lambda remediation).

– Designed 18 controls mapped simultaneously to Zero Trust pillars, MITRE techniques, and PCI DSS v4.0.1, each derived from the threat model's attack scenarios and trust boundaries. TECHNICAL SKILLS

Detection & Response Splunk · CrowdStrike Falcon · Cortex XSOAR · MITRE ATT&CK · SPL · KQL · threat intelligence · log correlation · threat hunting · cloud & endpoint incident response AWS Security IAM · SCPs & permission boundaries · Identity Center · GuardDuty · CloudTrail · CloudWatch · Config · Detective · Security Hub · KMS · Secrets Manager

Azure & GCP Security Sentinel · Defender for Cloud · Azure Policy · Azure Monitor · Entra ID · Key Vault · NSGs · GCP IAM & governance

Automation & IaC Python · CloudFormation · CloudFormation Guard · EventBridge · policy-as-code · CI/CD Cloud Architecture & Posture Zero Trust · threat modeling · micro-segmentation · CSPM (Prowler · Wiz CNAPP) Identity, Email & Data Okta · Entra ID · Proofpoint TAP · MIND (DLP) Vulnerability & App Security Amazon Inspector · InsightVM · Defender for Cloud (vuln assessment) · OWASP Top 10 · API security Frameworks & Compliance NIST CSF · NIST SP 800-207 · NIST 800-53 · PCI DSS · HIPAA · GDPR · SOC 2 · ISO 27001 · CIS Benchmarks EDUCATION

M.S., Information Security Engineering (MSISE) — SANS Technology Institute · In progress, expected 2027 Graduate Certificate, Cloud Security — SANS Technology Institute B.S., Cybersecurity — Purdue University Global

AI Security Training — Black Hat (“Building AI Agents,” “Breaking GenAI”), DEF CON (“AI SecureOps”)



Contact this candidate