Skip to content
View DFwJZ's full-sized avatar

Highlights

  • Pro

Block or report DFwJZ

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
DFwJZ/README.md

Hey there, I'm Jason (Haozhe) Zhang πŸ‘‹

LinkedIn Email TryHackMe Medium

🎯 About Me

From drilling for oil to drilling for vulnerabilities - my journey took me from Petroleum Engineering β†’ Geophysics β†’ Computer Science β†’ Cybersecurity. I build AI-powered security systems that make vulnerability analysis less painful and more intelligent.

class SecurityEngineer:
    def __init__(self):
        self.name = "Jason Zhang"
        self.current_focus = ["AI Security", "Vulnerability Research", "Multi-Agent Systems"]
        self.languages = ["English", "Chinese", "Spanish(leaning)" ]
        self.philosophy = "Automate the boring stuff, focus on the interesting threats"
        
    def current_status(self):
        return {
            "learning": ["MCP Implementations", "CVE Research", "Supply Chain Security"],
            "building": ["Badge Verification System", "AI Triage Agents", "Security Content"],
            "contributing": ["GitLaby", "Open Source Security"]
        }

πŸš€ What I'm Working On

πŸ”¬ AI-Powered Security Research

  • Building multi-agent vulnerability triage systems using LangGraph and RAG architecture
  • Researching AI security vulnerabilities (prompt injection, SSTI, model extraction)
  • Hunting for my first CVE in supply chain and AI/ML systems
  • Implementing MCP (Model Context Protocol) servers for security automation

πŸ› οΈ Active Projects

  • SecureScope - Interactive OWASP Top 10 training platform with dual secure/vulnerable environments
  • AWS Community Day Badge Verification - Credly-style badge system with UUID verification
  • Security Content Creation - Educational proof-of-concept scripts and tutorials
  • Open Source Contributions - GitLab accessibility improvements, Omi MCP server enhancements

πŸ’Ό Professional Experience

πŸ”Ή Product Security @ Bill.com (May - Aug 2025)

  • Developed AI-powered vulnerability triage with multi-agent architecture (LangGraph + ChromaDB)
  • Reduced manual security analysis time by 60% through intelligent automation
  • Built OWASP Top 10 benchmarking framework for AI agent validation
  • Integrated Qualys, Veracode, and Burp Suite with custom Python automation

πŸ”Ή AppSec/Enterprise Security @ SiriusXM (Jun - Aug 2024)

  • Created comprehensive security documentation for 1000+ engineers
  • Reduced false positives by 70% through SentinelOne-Splunk integration
  • Built GitHub Repository Replicator with 95% test coverage and zero production bugs

πŸŽ“ Education & Certifications

πŸŽ“ M.Sc Cybersecurity - Western Governors University (2025)
πŸŽ“ M.Sc Computer Science - Northeastern University | GPA: 3.97/4.00 (2024)

πŸ“œ Certifications: CompTIA CySA+, Security+, CCSKv4, HTB CPTS (In Progress)

πŸ›‘οΈ Security Arsenal

AI/ML Security:
  - Multi-Agent Systems: LangGraph, LangChain, Google Gemini
  - RAG Architecture: ChromaDB, Vector Databases
  - ML Frameworks: TensorFlow, PyTorch, RLHF, DPO, QLoRA

Application Security:
  - SAST/DAST: Qualys, Veracode, Burp Suite, Snyk, Semgrep
  - SIEM: Splunk, Azure Sentinel, SentinelOne
  - Pentesting: Metasploit, Nmap, Wireshark, Burp Suite
  
Development:
  - Languages: Python, Rust, C/C++, JavaScript, PowerShell
  - Cloud: AWS, Azure, Docker, Kubernetes, Terraform
  - CI/CD: GitHub Actions, GitLab CI/CD, Jenkins
  
Frameworks & Standards:
  - Compliance: FedRAMP, NIST 800-53, HIPAA
  - Security: OWASP Top 10, MITRE ATT&CK, CWE

πŸ“Š Notable Projects

🎯 SecureScope - Interactive Security Training Platform

Python | Flask | Docker | JWT | OWASP Top 10

  • Interactive platform demonstrating OWASP vulnerabilities through dual environments
  • JWT authentication with bcrypt and RBAC for access control
  • Containerized for isolated testing and consistent security controls

🍯 Azure Sentinel Honeypot (SIEM)

PowerShell | Azure Sentinel | Terraform

  • Captured 1.2k+ attacks in 24 hours using IaC deployment
  • Automated log analysis and VM management reducing overhead by 70%
  • Real-time visualization of global attack patterns

πŸ€– Educational Security Scripts

Python | Security Research | POC Development

  • Proof-of-concept demonstrations for common vulnerabilities
  • Educational content for security awareness
  • Freelance security consulting and training materials

πŸ”— Traditional Active Directory Lab

Azure | Active Directory | LDAP | DHCP | DNS | VPN

  • Full enterprise environment simulation on Azure
  • Multiple protocol implementations and firewall configurations
  • Security monitoring and event log analysis

🌟 Community Involvement

  • AWS Community Day (2023 - now) - Volunteer & Website Maintainer - AWS Community Day Bay Area
  • CodePath - Student and Volunteer Teaching Assistant
  • BlackHat 2023 - Scholarship Recipient
  • SVCSI Conference - Volunteer Coordinator
  • CTF Competitions - Active on TryHackMe, Hack the Box, PicoCTF

πŸ“ˆ GitHub Stats

Jason's GitHub Stats

GitHub Streak

πŸ’‘ Current Interests

πŸ” Security Research: Supply chain vulnerabilities, AI/ML security, CVE discovery
πŸ€– AI Agents: Multi-agent architectures, autonomous security systems, MCP protocols
πŸ› οΈ Open Source: Contributing to GitLab, Omi, and security-focused projects
πŸ“š Learning: Advanced exploitation techniques, detection engineering, threat intelligence

πŸ“« Let's Connect


"Security is not a product, but a process. Make it intelligent, make it automated, make it better."

Visitor Count

Popular repositories Loading

  1. Spring2022 Spring2022 Public

    Python

  2. movieland movieland Public

    CSS

  3. NEU-CS5004 NEU-CS5004 Public

    Object Oriented Programming - code for lab and assignment

    Java

  4. NUMAD22Fa_HaozheZhang NUMAD22Fa_HaozheZhang Public

    Java

  5. YummyChina YummyChina Public

    Forked from FentPams/YummyChina

    Yummy China App

    Java

  6. CS5800-Cordiance-Experiential-Project CS5800-Cordiance-Experiential-Project Public

    Python 1