Break, Build, Repeat

Experience

Assistant Manager, Vulnerability Management @Sea Group

Jan 2026 – present · Singapore

Lead a team of five running enterprise vulnerability management and the bug bounty program across Shopee, Garena, SeaMoney, and banking entities. Drive offensive security reviews on in-house AI infrastructure and production systems, run red team engagements against high-value targets, and build LLM-based agents for triage automation and vulnerability detection.

  • Team Leadership
  • Vulnerability Management
  • Bug Bounty
  • Red Team Operations
  • AI Security
  • LLM Automation

Senior Security Engineer @Sea Group

Jan 2025 – Dec 2025 · Singapore

Supported enterprise bug bounty operations and owned vulnerability triage and risk assessment across business units. Led penetration tests, source code reviews, and red team operations against high-value assets, and built an internal data-leak detection tool with an LLM agent that cut false positives by 20–30%.

  • Penetration Testing
  • Secure Code Review
  • Red Team Operations
  • Vulnerability Triage
  • Security Automation

Security Engineer @Sea Group

Jun 2022 – Dec 2024 · Singapore

Helped run Sea's bug bounty platform and conducted security assessments, penetration tests, and source code reviews across Shopee, Garena, SeaMoney, and banking entities. Built a black-box DAST scanner for continuous asset monitoring, and represented the company at Govware SpiritCyber 2024 — placing 2nd overall in bounty earnings.

  • Penetration Testing
  • Source Code Review
  • Red Team
  • DAST Tooling
  • Vulnerability Management

Security Engineer Intern @Sea Group

May 2021 – May 2022 · Singapore

Managed HackerOne reports and streamlined the vulnerability reporting process. Performed source code reviews and penetration testing across multiple business units, and improved security scanner templates to raise detection rates.

  • Bug Bounty Triage
  • Penetration Testing
  • Source Code Review

Cybersecurity Research Intern @National Cybersecurity R&D Labs

May 2020 – Jul 2020 · Singapore

Worked with security researchers to design and build custom in-house tooling that automated key security processes, and delivered proof-of-concept implementations of emerging security tools and practices.

  • Security Research
  • Tooling
  • Automation

Education & Certifications

Offensive Security Certified Professional (OSCP)

Professional certification

B.Comp. (Information Security) @National University of Singapore

2018 – 2022 · Singapore