Tommy Wong
Head of Cybersecurity, SRE, QA @ Ryt Bank
About
For the world is an exciting place, for creating stuff from nothing is challenging, for hacking everything is the way to live, stay hungry, stay curious, and keep hacking.
Malaysia
Federal Territory of Kuala Lumpur
Computer Software
Reverse Engineering, Web Application Security, Cloud Security, Mobile Security, Information Security, Network Security, Threat Intelligence, Linux, Java, Programming, Security, Microsoft Office, Windows, PHP, Vulnerability Assessment, C++, Software Development, Backtrack, MySQL, Matlab
Experience

Head of Cybersecurity, SRE, QA
Federal Territory of Kuala Lumpur, Malaysia
Heads Cyber Operations, Threat Intelligence, Cyber Defense, Cyber Governance, Security Architecture, Security Engineering and Security Research for Rytbank. Heads the SRE team that builds the Ryt Bank's cloud infrastructure. Leading the Quality Assurance function that horizontally span across the CTO and CPO org. Heavy research into incorporating AI into QA activities including requirements generations, AI guided test scoping, test case generations, etc.

Head of Cybersecurity and QA
Heading Cyber Operations, Threat Intelligence, Cyber Defense, Cyber Governance, Security Architecture, Security Engineering and Security Research for Rytbank. At the same time leading the Quality Assurance function that horizontally span across the CTO and CPO org. Heavy research into incorporating AI into QA activities including requirements generations, AI guided test scoping, test case generations, etc.

Founder
ZeroXFiftyFour
Global
Freelance work. I took up multiple red team and pentest jobs within the years that includes engagement from private sector, government agencies and oversea firms. Beside pentest, I also did various kind of security engagement for example APT forensics and malware analysis. My Arsenal: - Proxies: Burp, ZAP - Web VA: Arachni, Nikto, Acunetix - Infra VA: OpenVAS, NMAP, Nessus Community Edition - Exploits: Write my own custom exploits, MSF, Fuzzbunch, ExploitDB - Reverse Engineering: IDAPro, GDB, OllyDBG, dex2jar, JD-GUI, Bytecode Viewer, JS Detox - Others: Wireshark, VMWare, Process Explorer, InstallRite, TCPViewer, WinHex, BinText, Hiew, etc

Security Specialist (Technical Manager - Software Security Team)
Kuala Lumpur, Malaysia
After getting promoted, I now lead a team of 4 (and hiring) within the organization that is focusing on software security. Reporting directly to the Senior Director of Engineering (Shared Services). Working closely with a number of top management members, my focus is to be visionary and the strategist to improve Sitecore's software security. I actively work in security research realm focusing massively on cutting edge technology, specifically on adversarial machine learning. Besides this, I'm a true believer of test early, especially in a world of agile and DevOps. Security should be part of the requirement from early phases of development, not an afterthought. Hack the whiteboard, hack the design, hack the code and then hack the product. I also own and maintain the roadmap and strategy of the company's software security landscape. Which includes security research, security maturity program, internal pentests, external pentests, security automation, security processes, internal security awareness and security trainings.

Senior Security QA Engineer
Kuala Lumpur, Malaysia
Hire as the first Senior Security QA Engineer that works full time on Sitecore's product security, I was tasked to: 1. Setup the Sitecore Software Security team from the ground up. 2. Define the roadmap of Sitecore Software Security team 3. Define the strategy of Sitecore Software Security testing 4. Perform internal pentests 5. Schedule and liaise with external firm to perform external pentests 6. Be the internal consultant to all the agile teams within the engineering department when it comes to software security related issues 7. Point of contact for external party when there's responsible disclosure or contract related questionnaire 8. Draft the SDLC policy

Security Engineer
Works done: - First Security Engineer that is hired by Quintiq worldwide. - Setup the Quintiq Software Security Group and the Security Testing Team - Setup internal Security Research & Testing Lab using a Blade Server with VMWare vSphere - Security testing and review on Android and iOS mobile app - Pentest of multiple websites, both public and private sites - Cloud Cyberthreat Intelligence, which includes the analysis and testing of infrastructure and application layer of the Quintiq Cloud Services - Reverse Engineering using IDAPro to analyze in-house software - Lead in the technical aspect of implementing BSIMM on corporate level - Involved in the SDLC cycle of numerous development project as Subject Matter Expert to provide security advises and recommendations as early as in design phase. - Implement Threat Modeling using the STRIDE strategy in various project development - Perform Social Engineering experiment on company event to raise security awareness - Provide in-house training to Quintiq Employees - Organize in-house CTF competition to excite the interest in learning security knowledges
Tommy Wong's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.







