Hardening web services and enterprise systems — vulnerability assessment, TLS, and WAF — with a strong command of modern AI/ML.
“There is such a world to see.”
Information Security Team · KAIST ·Daejeon, Republic of Korea
Information Security Engineer at KAIST. My current focus (since July 2026) is web security — web application vulnerability assessment, SSL/TLS certificate management, and Web Application Firewall (WAF) operations. Before that I led information-security governance — 100+ annual security reviews of KAIST’s major IT initiatives in collaboration with the NIS and MSIT, plus MSIT-led security & privacy audits grounded in the national Cybersecurity Guidelines — and spent five years operating core academic systems, including a key working-level role in a ~USD 130M next-generation information-system program, with earlier experience migrating enterprise products to cloud-native infrastructure (Docker, Kubernetes). I also bring a professional command of modern AI/ML — from classical machine learning to LLM-based tooling — and apply it to automate and sharpen security work.
Experience
2020 — Present
Daejeon, KR
Engineer (기술원) · KAIST
Jul 2026 — Present
Information Security Team · Web Security
Lead web application vulnerability assessment and analysis — identifying and validating flaws, prioritizing by risk, and coordinating remediation with service owners.
Manage the SSL/TLS certificate lifecycle across web services — issuance, renewal, and deployment — enforcing strong cryptographic configurations and preventing expiry-driven outages.
Designing and building campus-wide certificate automation — a one-command ACME installer that obtains and renews publicly trusted Let’s Encrypt certificates, with a central portal tracking every server, eliminating manual requests and expiry-driven outages.
Operate and tune the Web Application Firewall (WAF), maintaining rule sets and policies that block web-layer attacks while minimizing false positives.
Apply automation and AI-assisted analysis to accelerate vulnerability triage and anomaly detection.
Jul 2025 — Jul 2026
Information Security Team · Governance
Led 100+ security reviews (보안성검토) per year across KAIST’s major IT initiatives — including AI/Cloud-based services and external integrations — in collaboration with the National Intelligence Service (NIS) and the Ministry of Science and ICT (MSIT), applying relevant laws, guidelines, and security standards.
Led the response to the MSIT information-security & privacy audit — driving root-cause analysis, formal objections, and supplementary evidence — which raised the institution’s official security-evaluation result, and hardened internal controls to prevent recurrence.
Ran regular and unannounced security-posture inspections (실태점검·불시감찰) across all departments, surfacing non-compliance and latent vulnerabilities before they became incidents.
Anchored reviews and audits in the NIS Cybersecurity Guidelines (국가정보원 사이버보안 기본지침), assessing architecture, access control, and data protection against national standards.
Operated media-security controls (secure USB, media-control system, magnetic data erasure), planned and personally delivered practitioner training, and managed security policy and budget.
2020 — Jul 2025
Information Development Team · Academic Systems
Served as a core working-level member of the ~USD 130M, 3-year Next-Generation Integrated Information System — deeply involved in designing the academic module (curriculum, course registration, classes, graduation) and driving verification, testing, and production deployment to a successful launch.
Reviewed and modernized 1,400+ common and major-specific graduation requirements across departments (CS, EE, Mechanical, and more), re-basing complex rules onto the next-generation system and resolving policy–system mismatches.
Redesigned graduation-assessment exception handling and the logic for internships, special lectures, and substitute courses; improved thesis-review management (proposal, defense, external committees), eliminating recurring errors.
During the transition-aligned graduation season, processed 2,000+ graduations and degree conferrals without disruption, and built new degree certificate / name / number issuance features that improved record accuracy and administrative trust.
Jan — Jun 2020
Seongnam, KR
Researcher · TmaxSoft
Developed and maintained enterprise products built on Tomcat (WAS) and the Spring Framework.
Migrated legacy products to cloud-native infrastructure (Hyper Cloud) using Docker and Kubernetes.
Jul — Aug 2019
San Jose, CA
Data Scientist · Head Start
Built and evaluated machine-learning models as a data scientist during a summer internship in Silicon Valley.
2018 — 2019
Seoul, KR
Undergraduate Research Assistant · Distributed Platforms & Security Lab, Chung-Ang University
Applied-security research that led to an IEEE publication and a patent (see Publications).
A proof-of-concept that runs the same prompt down two paths at once — straight into the model, and through a guardrail — and streams both pipelines live, so the difference between "unprotected" and "defended" is something you can watch rather than argue about. (In progress)
Departments, labs, and clubs each run their own web server, and almost nobody wants to think about TLS. Building a portal and a one-command installer that issue and renew publicly trusted Let's Encrypt certificates on their own — with central visibility over every server. (In progress)
TLS
Let's Encrypt
ACME
Automation
DevSecOps
Read more →
Skills
Security
Web Vulnerability Assessment SSL/TLS & PKI Web Application Firewall (WAF) Security Audit & Review Policy & Governance
AI / Machine Learning
Machine Learning Deep Learning LLMs & Generative AI Applied AI for Security
Cloud & Infrastructure
Docker Kubernetes
Systems & Development
Java Python Spring Framework Enterprise Systems
Languages
Korean
Native
English
Professional Working OPIc AL · highest grade
Spanish
Elementary
French
Elementary
Certifications
Engineer Information Processing (정보처리기사)
Ministry of Science and ICT, Republic of Korea · Sep 2024
OPIc — English: Advanced Low (AL) · Highest Grade
ACTFL · Dec 2025 · AL is the highest level awarded on OPIc · valid through Dec 2027