Frank Y.

Frank Y.

Senior Cyber Security Manager @ livi bank

About

Experienced cybersecurity executive and engineer with over 10 years of experience in cybersecurity domains and strong portfolio of industry certifications to demonstrate deep expertise in both first and second line of defence, including CISSP, CISM, CCSK, and GIAC certifications.A continuous self-learner committed to stay ahead of emerging threats and technologies, with strong cloud security skills in both Azure and AWS. Familiar with various industry compliance standards and frameworks, including CIS, NIST, and ISO.Effective communicator and collaborator with cross-functional teams beyond IT department. Proven track record in developing cybersecurity programs, driving compliance requirements, and security initiatives.Seeking new challenges and opportunities to work with companies looking to improve security posture and build cyber resilience and contribute to infosec community

Country

-

City

Hong Kong SAR

Industry

Government Administration

Skill

Kusto Query Language (KQL), Detection-as-code, Detection Engineering, DFIR, Cross-functional Team Leadership, Fortinet Firewall, Endpoint Security, SOAR, Cyber Threat Hunting (CTH), Zero Trust Networking and Endpoints, Network Defense, Network Traffic Analysis, Intrusion Detection, Incident Detection and Response, Packet Analysis, ISO 27001, NIST CSF, Help Desk Support, NDR, Mobile Security

Experience

livi bank

Senior Cyber Security Manager

livi bank

LinkedIn
2024-11 - Present · 1 yr 11 mos

Hong Kong SAR

•Optimized Microsoft Sentinel SIEM with built-in analytics and contents, integrating telemetry from Microsoft Defender for Endpoint, Defender for Cloud Apps, Defender for Identity, and Microsoft 365 Defender; fine-tuned configurations across these solutions within the Microsoft Ecosystem to enhance detection fidelity and strengthen proactive threat prevention. • Engineered and deployed over 150 custom detection rules tailored to the Bank’s threat landscape, significantly improving threat visibility and response agility. • Designed and operationalized a robust Digital Forensics and Incident Response (DFIR) workflow with additional open source tools, ensuring timely and comprehensive artifact collection and accelerating forensic analysis. Significant Achievements: o Lead IT Security team through the Intelligence-led Cyber Attack Simulation Testing (iCAST), a red-team exercise mandated by the Hong Kong Monetary Authority (HKMA) under its Cyber Resilience Assessment Framework (C-RAF). Achieving good result validated the bank's ability to detect, respond to, and recover from advanced cyber threats using real-world intelligence. It demonstrated strong cyber resilience and compliance with HKMA’s regulatory expectations for cyber maturity, reinforced trust with regulators and stakeholders.

New York City Economic Development Corporation

Vice President

New York City Economic Development Corporation

LinkedIn
2023-9 - 2024-11 · 1 yr 3 mos

•Conduct self assessments to identify gaps in current cybersecurity measures against NIST Cybersecurity Framework (NIST CSF) and ISO 27001. Ensure compliance with NYDFS Cybersecurity Regulation and NY Shield Act •Collaborate with relevant IT teams to ensure the effective implementation of baseline of security controls defined by the Center for Internet Security (CIS) Critical Security Controls. •Introduce and integrate Cyber Threat Intelligence (CTI) from various sources into existing security solutions •Implement Malicious Domain Blocking and Reporting (MDBR) DNS Protection from MS-ISAC •Collaborate with US Coast Guard and MTS-ISAC, provide advisory services based on Maritime Cybersecurity Assessment and Annex Guide (MCAAG) to relevant operators Significant Achievements: o Developed a comprehensive cybersecurity program using method similar to the HKMA C-RAF, achieving positive outcomes in Cybersecurity Maturity Assessment, IT General Control Audit, and multiple audits. This initiative significantly improved organizational resilience and ensure compliance with key regulatory standards, such as NYDFS and the NY SHIELD Act, in a highly regulated government environment. o Developed a robust 3rd-party risk assessment program that align with Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM). The program evaluate and monitor supply chain cyber risks associated with onboarding 150+ new software and cloud solutions. o Greatly enhanced Respond and Recover capabilities by developing extensive Incident Response Plan (IRP) and Continuity of Operations Planning (COOP) Plan. These plans were tested during annual Disaster Recovery (DR) exercises and cybersecurity tabletop exercises to ensure business continuity

New York City Economic Development Corporation

Assistant Vice President

New York City Economic Development Corporation

LinkedIn
2021-2 - 2023-9 · 2 yrs 8 mos

•Mentor and cross train team members to support IT Risk management responsibilities •Creating, testing and implementing network disaster recovery plans to ensure business continuity. •Performing risk assessments and testing of data processing systems. •Maintain and enhance information security and data integrity programs: develop and implement security standards, baseline, processes/procedures, and guidelines. •Implement Check Point Mobile Threat Defense to protect corporate data across all mobile attack surfaces • Oversee application security process, including secure coding practice following SSDLC and OWASP best practice, as well as conducting vulnerability assessment. • Develop and implement IT policies, procedures, and best practices to ensure compliance and efficiency • As subject matter expert (SME) on AWS and Azure Security Engineer, implement and manage cloud security measures, such as Microsoft Sentinel, Defender, and Cloud App Security CASB, to protect corporate cloud Significant Achievements o Established effective Risk Management and Vulnerability Management Program. Identify, evaluate, and address risk and vulnerabilities with Cyber Risk Register and Qualys platform. Collaborate with cross-functional teams to address cyber risk, such as vulnerabilities remediation and cyber insurance.

New York City Economic Development Corporation

Senior Security Analyst

New York City Economic Development Corporation

LinkedIn
2019-9 - 2021-2 · 1 yr 6 mos

• Provide guidance on types of controls required to mitigate information security risk on all IT projects • Perform regular security assessments such as Phishing Simulation and Risk Assessment • Maintain and optimize security tools, including firewall, SIEM, SWG, EDR/XDR, DLP, NDR…to create multi-layered security architecture. • Strengthen corporate email security and continuity with Proofpoint solution; Enforce SPF, DKIM, and DMARC on corporate email domains. • Manage Next-Generation Firewall and different security solutions to protect primary and remote sites • Defend corporate websites with Cloudflare Web Application Firewall (WAF) and Radware DDoS Protection Significant Achievements o Implemented Darktrace’s Network Security Monitoring/NDR NDR solution and integrated it with SIEM. This integration enhanced threat detection capabilities with advanced AI insights to effectively identifying and addressing sophisticated threats, including insider threats and zero-day exploits o Implement Fortinet Network Access Control to provide network visibility, control, and protection from rogue devices; ensure all 2000+ devices connect to corporate network are compliant

New York City Economic Development Corporation

Security Analyst

New York City Economic Development Corporation

LinkedIn
2015-9 - 2019-9 · 4 yrs 1 mo

• Develop and deliver mandatory corporate training program for 500+ employee to raise security awareness and fosters a security-conscious culture within organization • Apply Wi-Fi traffic shaping and control through 90+ Cisco Meraki access points • Design IT Security policies and standards to improve security posture • Implement VMWare vRealize Operation Manager to provide operation intelligence • Upgrade existing security control with Network Access Control for automated detection and restriction of non-compliant devices • Upgrade existing web content filtering to Forcepoint Web Security Cloud to deliver complete protection for on-premise and roaming users • Manage IAM; Reduce attack surface by securing privilege identities with Privilege Access Manager (PAM) Significant Achievements o Replace legacy log management tool with LogRhythm SIEM platform, which provide SOAR capabilities to automate incident response workflows, shorten threat detection and response times. o Replaced legacy antivirus with Crowdstrike Falcon platform for Next-Generation Antivirus and Endpoint Detection and Response (EDR/XDR) on 1,000+ endpoints with proactive threat detection, real-time visibility, and streamline remediation with advanced cross-domain orchestration.

New York City Economic Development Corporation

Technical Support Manager

New York City Economic Development Corporation

LinkedIn
2013 - 2015 · 2 yrs

• Apply Microsoft Updates to system with Windows Server Update Service (WSUS) • Remediate application vulnerability by patching system using GFI LanGuard • Utilize EventTracker SIEM to perform log analysis • Manage EMC Avamar software to maintain backup and provide disaster recovery • Manage Trend Micro OfficeScan and Deep Security to provide comprehensive protection from endpoint to servers • Managed VMWare vSphere environment that host 400+ servers, ensuring high availability and optimized performance for critical infrastructure. • Evaluate and enforce data at rest encryption on supported servers/systems; implement BitLocker 500+ endpoint • Assign tasks and mentor MIS Interns; 4 interns successfully obtain full time position in the team

New York City Economic Development Corporation

Technical Support

New York City Economic Development Corporation

LinkedIn
2007 - 2013 · 6 yrs

• Document process and policy to provide guidance for team member and users • Manage RSA Secure ID for multi-factor authentication (MFA) for remote access • Manage Centrify Suite to centralize authentication and access control for Mac clients • Provide support for Microsoft, Macintosh, network connected devices such as printers and scanners, with BMC-Trackit ticket system

Education

SANS Technology Institute

SANS Technology Institute

LinkedIn

Cyber Defense Operation

2019 - 2022 · 3 yrs
Pace University

Pace University

LinkedIn

Computer and Information Systems Security/Information Assurance

2012 - 2015 · 3 yrs

With Advance Graduate Certificate in Security and Information Assurance

Stony Brook University

Stony Brook University

LinkedIn

Computer Science

2001 - 2005 · 4 yrs

Frank Y.'s Contact Information

Email

******@***.com

Phone

(**) *** ****

Find the Right Leads
Find Verified Contact Data

Try with: Jensen Huang @ nvidia.com Click to autofill
LeadContact awards, five-star ratings, and GDPR compliance badges

What LeadContact does well

Find verified emails, phone numbers, and decision-makers with 98% accuracy.

Find Leads

Find Leads

Find the right people by company, role, industry, location, and more.

925M+ professional profiles

Find Leads
Find Emails

Find Emails

Access verified email addresses for your target contacts.

657M+ emails

Find Emails
Find Phone Numbers

Find Phone Numbers

Get cross-validated phone data from multiple top sources.

239M+ phone numbers

Find Phone Numbers

More Accurate. Lower Cost.

Find contact data in 1 tool with 98% accuracy

LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.

LeadContact Logo
Competitor Tools

All these = $289 per month

Great conversations start with the right contact.

It’s time to find yours.