Skip to content
View vishal5589's full-sized avatar

Block or report vishal5589

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
vishal5589/README.md

Hi, I'm Viki 👋

🛡️ Assistant Manager – IT Security (SecOps) · Blue Team Defender

What I do

📍 Penang, Malaysia  ·  🕒 MYT (UTC+8)

Profile views

👨‍💻 About Me

I work on the defensive side of cybersecurity — building, running, and automating the systems that detect and respond to threats before they become incidents.

With 16+ years in IT and over a decade focused on security operations within the remittance / fintech industry, I lead detection, response, and privileged-access initiatives — and I'm increasingly bringing AI-assisted workflows into the SOC to cut analyst toil and sharpen signal.

A life-long learner and results-oriented team lead, I care about least-privilege design, fail-closed systems, and automation that scales the people, not just the alerts.

"Automating repetitive work so analysts can focus on real threats."


🎯 What I Do

🔍  Detection Engineering      →  Building and tuning high-fidelity detections
🚨  Security Operations (SOC)  →  Monitoring, triage, and operational defense
🧯  Incident Response          →  Investigating breaches, containment & remediation
🐾  Threat Hunting             →  Proactively chasing adversary behavior
🔐  Privileged Access (PAM)    →  Securing & governing privileged credentials
🤖  Security Automation        →  SOAR-style workflows, scripting & AI-assisted ops

🧰 Tech & Tooling

Languages & Query

Python KQL Splunk SPL SQL JavaScript

Security Operations

SIEM XDR BeyondTrust PAM Palo Alto Detection Engineering Threat Hunting Incident Response

Cloud, Infra & Automation

Cloudflare Workers Cloudflare D1 Zero Trust Docker GitHub Actions Linux


🚀 Featured Projects

secops-portal

🔐 Security Operations Portal
Single-file SecOps portal to track security projects & recurring BAU tasks — Cloudflare Workers + D1, dashboards, audit log, and one-click board reports. Live demo inside.

secure-selfhosted-homelab

🏠 Secure Self-Hosted Home Lab
Defense-in-depth, fully-automated home lab — network segmentation, least-privilege, fail-closed egress, secrets-scanning CI, zero public attack surface. Documented threat model + ADRs.

jarvis-secops-assistant

🤖 JARVIS — SecOps Assistant
Self-hosted AI assistant that automates threat-intel, CVE/advisory monitoring, and security reporting for a home SOC. Documented threat model + fail-closed design.

moneyallmatters

💰 MoneyAllMatters
Self-hosted household finance portal on Cloudflare's edge — Workers, D1, and Zero Trust auth.


🌱 Currently

  • 🛠️ Building security tooling and automation projects
  • 🤖 Learning AI-assisted Security Operations and Detection Engineering
  • 🧪 Tinkering with a defense-in-depth, fail-closed self-hosted home lab

📊 GitHub Stats

GitHub stats Top languages
GitHub streak

🤝 Connect


⚡ Blue team by trade · builder by habit · automating the boring so the important gets attention.

Pinned Loading

  1. moneyallmatters moneyallmatters Public

    Self-hosted household finance portal on Cloudflare's edge — Workers, D1, Zero Trust auth

    JavaScript

  2. secops-portal secops-portal Public

    Single-file security operations portal — track security projects & recurring BAU tasks. Cloudflare Workers + D1, dashboards, audit log, and one-click board reports. Live demo inside.

    JavaScript

  3. secure-selfhosted-homelab secure-selfhosted-homelab Public

    Defense-in-depth, fully-automated self-hosted home lab — network segmentation, least-privilege, fail-closed egress, secrets-scanning CI, zero public attack surface. Documented threat model + ADRs.

  4. jarvis-secops-assistant jarvis-secops-assistant Public

    Self-hosted AI assistant that automates threat-intel, CVE/advisory monitoring, and security reporting for a home SOC. Documented threat model + fail-closed design.