Isaac Shin

Aspiring Cloud Security Engineer

Cybersecurity student @ DePaul University with a passion for security solutions.

Projects

Mock Penetration Test / Capture the Flag

Nov 2025

• Conducted a penetration test with a black-box approach across 4 target hosts, identifying 7+ critical vulnerabilities including RCE, weak credentials, unpatched services, and privilege escalation paths
• Performed active scanning and enumeration using Nmap, Dirb, and web analysis, identifying vulnerable services, exposed directories, and permission misconfigurations, mapping attack-surface accuracy to 92%
• Executed exploitation workflows using Metasploit and privilege escalation techniques, achieving SYSTEM/root access on all targets, demonstrating 100% full-scope compromise across the environment
• Authored a comprehensive penetration testing report, documenting procedures, MITRE ATT&CK IDs, risk ratings, and remediation steps, improving threat visibility of high-risk vulnerabilities by 95%

Linux Windows Metasploit

AWS Cloud Resume

Aug 2025 - Oct 2025

• Configured IAM roles and policies to enforce least-privilege access and controlled execution of AWS services, enhancing security posture and reducing risk of unauthorized access
• Developed a static portfolio website using S3, CloudFront, and Route 53, providing secure and encrypted access through global distribution
• Implemented a serverless backend through DynamoDB, REST API Gateway, and Lambda with Python and JavaScript to track visitor count
• Automated full-stack deployments with Terraform and GitHub Actions for CI/CD

Terraform Python JavaScript

Threat Detection Analysis

Aug 2019 - Feb 2025

• Performed OSINT while seeding decoy scripts on exploit forums that routed directly to honeypots, logging 100+ non-PII user data instances for ban waves and attacker profiling
• Reviewed 3,000+ automated detection events via Webhook integrations while prioritizing critical incidents for human review, improving threat visibility by ∼98%
• Patched 7+ high-severity zero-day exploits (duplication, datastore corruption, DoS) within 10-30 minutes of discovery, preventing financial loss while maintaining functional gameplay/economy
• Authored a moderation and IRP playbook for a 9-person moderation team, standardizing triage workflows

Lua Python Discord & ROBLOX API

Experience

2024 — 2025

Security & Gameplay Systems Engineer

West Corner

• Implemented anti-exploit security schemas through obfuscation, audit trails, and server checks, ensuring fair gameplay and preventing exploit attempts by ∼87%
• Led a 7-person development team to implement 120+ unique in-game interactions and mechanics, contributing to a beta release tested by 400+ concurrent players
• Optimized memory and asset usage, reducing latency and improving in-game performance by ∼92%

Skills

Programming Languages

Python Java JavaScript SQL Lua HTML/CSS

Developer Tools & Platforms

Linux Git/GitHub AWS Terraform Metasploit Wireshark VMWare Packet Tracer

Core Competencies

IaC IAM CI/CD GRC Cloud Infrastructure Network & Endpoint Security Security Testing & Assessment

Soft Skills

Problem Solving Adaptability Critical Thinking Communication Attention to Detail Time Management