HimalayasHimalayas logo
Sonny OhSO
Open to opportunities

Sonny Oh

@sonnyoh

Security engineer focused on penetration testing, secure code review, and Python security automation.

United States
Message

What I'm looking for

I’m looking for a security role where I can build and automate penetration testing with Python, collaborate on secure SDLC/code reviews, and strengthen threat detection in SIEM/SOC—especially in real-world enterprise or industrial environments.

I’m a security engineer with hands-on experience in penetration testing, secure code review, and security automation using Python. I’ve worked across application security, vulnerability assessment, SDLC integration, and SIEM tooling in both enterprise and industrial environments.

In industrial IoT security, I executed customized penetration tests, then built automated assessment tooling using Python for Nessus, Binskim, and ZAP(DAST), increasing attacking surface by up to 50%. I also upgraded and integrated Sulley-based fuzzers and Defensics into CI/CD pipelines, improved regression testing of security controls, and supported SOC work with Splunk, data-flow design, and breach-resolution planning. I’m currently pursuing OSCP (Offsec) and bring a strong certification foundation (eJPTv2, CompTIA PenTest+) alongside an M.S. in Information Security and Assurance.

Experience

Work history, roles, and key accomplishments

CT

Security Analyst Intern

Concur Technologies

Jun 2017 - Aug 2017 (2 months)

Developed a SIEM automation program to improve threat detection and response capabilities. Upgraded a Nexpose script to scan multiple machines with input validation and CLI options, saving approximately 200 minutes per scan, and built a backup maintenance program to ensure data integrity and availability.

GH

Security Operations Center Intern

Group Health

Jun 2016 - Aug 2016 (2 months)

Analyzed security alerts in a SOC environment and used Splunk to identify suspicious activities. Designed Splunk/Nessus data flow, created a breach resolution plan, and integrated it into an IDS to support detection and response.

Education

Degrees, certifications, and relevant coursework

Western Governors University logoWU

Western Governors University

Master of Science, Information Security & Assurance

2017 -

Earned a Master of Science in Information Security & Assurance starting in 2017. Focused on information security concepts and assurance practices.

Park University logoPU

Park University

Bachelor of Science, Computer Science

Earned a Bachelor of Science in Computer Science, completed in December 2014. Studied core computer science fundamentals.

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan