Skip to content
View Chemo850's full-sized avatar
  • 00:58 (UTC -08:00)

Block or report Chemo850

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Chemo850/README.md

Hello there!

I am a seasoned security professional with expertise spanning physical security, security operations, internal audit, and infrastructure security. My experience includes implementing and optimizing security controls, conducting risk assessments, and driving operational security strategies to safeguard critical assets. I excel in integrating security best practices across diverse environments, ensuring compliance while proactively mitigating threats.

Overview

With extensive experience across security domains, I have built a strong foundation in DevSecOps and infrastructure security, specializing in credential scanning within SCM, CI/CD pipelines, and container environments. My expertise extends to developing and operationalizing security tooling, enhancing detection capabilities, and driving security automation across engineering workflows. I actively contribute to security platforms, refining scanning policies and integrating advanced security solutions to strengthen defenses. Additionally, I am committed to open-source security, and inspire to contribute to tools like TruffleHog to improve secret detection and remediation strategies.

Skills

Skill Associated Project
AWS Asset Management Led initiative for automated solution to discover and suspend unmanaged AWS accounts.
Code Review Pre-triaged thousands of credential findings in code for tooling accuracy.
Security Rule Writing Wrote hundreds of custom scanning policies for security tooling utilizing regex and YAML.
Linux Perform credential scanning audits utilizing trufflehog on ubuntu with bash scripting.
Planning Drive the roadmap for different company wide iniatives including credential scanning, cloud asset management and CSPM.

Frameworks

Languages

Tools

Network

SIEM

Cloud Misconfiguration

Secrets

SAST

DAST

DevSecOps

Certifications

Learning Path/Certifications in Progress

Popular repositories Loading

  1. Chemo850 Chemo850 Public

    Config files for my GitHub profile.

  2. PenTestExecStandard PenTestExecStandard Public

    Forked from penetration-testing-execution-standard/ptes

    The Penetration Testing Execution Standard (PTES) Automation Framework

    Ruby

  3. Penetration-Cheat-Sheet Penetration-Cheat-Sheet Public

    Forked from mantvydasb/RedTeaming-Tactics-and-Techniques

    Red Teaming Tactics and Techniques

    PowerShell

  4. impacket impacket Public

    Forked from fortra/impacket

    Impacket is a collection of Python classes for working with network protocols.

    Python

  5. PN PN Public

  6. webapp webapp Public

    Forked from cehkunal/webapp

    Sample Web App with Maven for Jenkins Demo

    Java