Minhwan Park

Cybersecurity Student · Cloud & Application Security

Experience

Origin Energy
Application & Product Security Intern · Melbourne, VIC
  • Completing a 5-month placement through Monash University's Industry-Based Learning (IBL) Scholarship Program, rotating across third-party, product, and application security.
  • Third-party security: map vendor controls against SOC 2 reports, questionnaires, and ISO 27001 evidence using UpGuard and CyberGRX to support risk assessments across the vendor portfolio.
  • Product security: review architectural designs and data flows for new features and integrations, including a major banking-partner integration, verifying required security controls are in place before launch.
  • Application security: triage Bugcrowd bug bounty submissions, verifying and reproducing findings before opening tickets and routing them to the responsible engineering team; investigated and remediated duplicate Snyk findings caused by redundant repository imports by correlating Snyk logs, GitHub Actions workflows, and Jenkins pipeline configs to build an automated fix.
  • Maintained a near-zero ticket backlog for most of the placement, promptly triaging and assigning incoming ServiceNow security requests.

Projects

Autonomous AI-SOC & Threat Intelligence Lab
AWS (VPC, EC2, Lambda), T-Pot, Elastic SIEM, Tines SOAR, LLM API
  • Architected an autonomous cloud SOC on an isolated AWS VPC with least-privilege Security Groups and a DMZ deception subnet for blast-radius containment.
  • Deployed a T-Pot honeypot (Cowrie, Dionaea, Suricata) on a hardened EC2 host, feeding attacker telemetry into an Elastic SIEM with custom EQL detection rules.
  • Built a Tines SOAR pipeline that enriches alerts (VirusTotal, AbuseIPDB) and routes them to an LLM Tier-1 analyst for structured triage, auto-closing benign scanners.
  • Automated remediation behind a human-in-the-loop gate: Slack approval fires an AWS Lambda that writes a DENY rule to the subnet NACL, blocking the attacker at the VPC boundary.
Vulnerable Host Penetration Test & Threat Model
Kali Linux, Nmap, Metasploit, Nikto, dirb · Software Security coursework
  • Enumerated the host (Nmap, Nikto, dirb) and gained an initial foothold via a WordPress instance with default credentials, uploading a web shell for remote code execution.
  • Escalated to root by exploiting an outdated ProFTPD 1.3.3c backdoor and recovered stored credentials from the host.
  • Classified findings against the OWASP Top 10, documented reproduction steps and remediation, and produced a threat model of a given scenario (assets, threats, controls).
AWS Cloud Security Infrastructure
AWS (VPC, EC2), Splunk, Kali Linux, Windows
  • Built a segmented AWS network — custom VPCs, public subnets, and internet gateways — to enforce network isolation and containment.
  • Deployed Splunk with Universal Forwarders for centralized logging, and authored SPL queries to correlate logs and identify IoCs.
  • Ran red-team operations (Hydra, RDP brute-force) to validate controls, then hardened the host with Security Groups and account-lockout policies.
Infodote — Misinformation Analysis Platform
Next.js, FastAPI, Elasticsearch, Claude API
  • Built at UniHack 2026: a real-time platform that analyses any claim and returns a structured verdict, manipulation technique, and critical-thinking lesson.
  • Built a hybrid search pipeline (kNN + BM25, fused via Reciprocal Rank Fusion) over 283 verified fact-checks from the Google Fact Check Tools API.
  • Integrated Claude (Anthropic API) for RAG-grounded analysis, returning structured JSON scores anchored to verified Elasticsearch sources.

Competitions & Achievements

PicoCTF 2026 — Top 7.2% globally
Binary Exploitation, Cryptography, Forensics, Reverse Engineering, Web Exploitation
UniHack 2025 & 2026
Built Spamurai (email threat-detection tool) and Infodote across two 48-hour hackathons