Will Liu
Security Architect @ NYC Health + Hospitals
About
I believe in making the world a better place and seek to use my knowledge and skills to help organizations secure intellectual property and customer information. I'm currently focused on Incident Response for the City of New York. Finding ways to improve detection, and response capabilities for internal customers.
United States
New York City Metropolitan Area
Information Technology & Services
Cloud Security, Log Analysis, Network Security, Information Security, Linux, SQL, Databases, Firewalls, Wireshark, Incident Response, Data Analysis, Snort, Networking, Network Forensics, Analysis, Information Assurance, Computer Forensics, Splunk, TCP/IP, Flow Analysis
Experience

CERT Lead
New York City Metropolitan Area
• Participated as the lead incident handler for large scale computer intrusion investigations. • Led and managed a team of incident handlers, forensics analysts, malware analysts, and interns. • Set the overall strategy and services to be provided by the incident response team. • Defined projects and workflows to reduce the mean time to detection and respond.

CERT Specialist
Greater New York City Area
• Performed Incident Handling duties • Updated incident response policies to reflect current team, processes, and technologies. • Analyzed existing security policies and provide recommendations for risk reduction, and improved threat detection. • Evaluated and provided feedback for Proof of Concepts. • Assisted content development with the creation of new detections and refinement of existing ones. • Reviewed, analyzed, and correlated logs for security events. • Delivered recommendations and actions to improve detection, escalation, containment, and resolution of incidents. • Performed dynamic malware analysis to extract IOCs. • Mentored interns providing feedback and coaching.

Security Engineer
Greater New York City Area
• Administered, configured, and tuned multi-site distributed SIEM deployment. • Onboarded data feeds into SIEM using a variety of methods including syslog, and local agents. • Alerted, monitored, and troubleshooted issues in SIEM environment. • Lead POC evaluations of anti-malware, endpoint detection response, and data loss prevention tools. • Supported suite of endpoint security tools deployed in environment including DLP, AV, Application Whitelisting, and Incident Response tools. • Configured CASB policies to align with data security policies. • Maintained current corporate antivirus solution, including tweaks to policy rules, and troubleshooting. • Deployed network monitoring tools, IDS across corporate environment. • Performed incident response, including triage and analysis of suspicious email.

ITCFP Participant, Engineer
Herndon, Virginia
• Assisted in creating a backup and restore plan for the different services used by the group. • Developed a plan for incorporating network monitoring into existing infrastructure using open source tools. • Identified CVE's that impact the existing infrastructure. • Assisted the QA/test team with the development of plans to evaluate compliance with government secure mobile initiatives.

Incident Response Specialist @ SOC
Annapolis Junction, MD
• Worked in a 24x7x365 operation environment, responding to alerts, incident reports, and searching for malware. • Interrogated different logs to determine the vector, and scope of a potential compromise. • Triage alerts, identify false-positives and false-negatives and escalate when needed. • Mined logs to find indications of compromised devices.

MSISPM Graduate Student
Carnegie Mellon University's Heinz College
Greater Pittsburgh Area
Studied Information Security Policy and Management at Carnegie Mellon University. My studies focused on network security, digital forensics and incident response. Academic Projects Introduction to Reverse Engineering • Manually unpacked malware using OllyDbg to assist in identifying the original entry point and used ImpREC to reconstruct the import address table. Host Based Forensics • Analyzed NTFS, FAT, and Ext file system data structures using a hex editor. • Utilized Sleuth Kit digital forensics tools to carve files out from NTFS and FAT partitions. Applied Information Assurance • Worked in a team environment, hardening a small network by minimizing services, installing antivirus, Snort IDS, arpwatch, tcpdump, Nagios, configuring firewalls, routers and centralized logging. • Participated in a simulated exercise utilizing different tools including Snort, Splunk, NTOP, and Wireshark to identify Arp spoofing, data exfiltration, network scans, IRC communication, SQL injections, Web directory traversal attacks and DoS attacks. Network Forensics • Analyzed pcap file for evidence of different types of scanning activity. • Utilized a hex editor and file headers to manually carve out files from a pcap file. • Conducted basic static and dynamic analysis of malware binaries by analyzing windows library imports, strings, network traffic behavior, and presence of packing. Network Security Analysis • Coded regular expressions to parse through log files for beaconing activity from malware. • Utilized Wireshark to analyze IPv6 traffic, and DHCP protocol traffic. • Analyzed malware using different Linux commands including xxd, strings, md5, and files.

Information Security Intern
Washington D.C. Metro Area
• Conducted open source intelligence analysis on various threat actors and the risk they pose to Boeing and its portfolio of products • Identified data points to feed into a dashboard that will be used by the Information Security Leadership Team.
Will Liu's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.



