Available for roles in Sydney, AU

Jihun Baek

Cyber Security Analyst with hands-on experience across cloud infrastructure hardening, penetration testing, and CTF challenge engineering. AWS Certified Solutions Architect – Professional. I combine an offensive security mindset with practical systems administration to build and break things that matter.

AWS Solutions Architect
Professional · Feb 2025
AWS Solutions Architect
Associate · Jan 2025
Jihun Baek
Offensive
Burp Suite Metasploit OWASP Top 10 Pentest Reporting
Defensive / Monitoring
Splunk Wireshark AWS GuardDuty AWS WAF SIEM & Log Analysis
Cloud & Infrastructure
AWS (SAP-level) Docker Active Directory SPF/DKIM/DMARC
Development
Python Flask SQL Bash
Nov 2025 – Present
Gomaps Trading
Junior IT Systems Administrator
  • Administered network and cloud infrastructure, enforcing access control via Active Directory Group Policies and maintaining high service availability.
  • Architected scalable cloud email delivery infrastructure reducing monthly costs by 15%; hardened sending domains with SPF/DKIM/DMARC.
Feb – Oct 2025
KnockOn
Challenge Developer & Technical Mentor
  • Engineered 10+ CTF challenges modelled on real-world CVEs (OWASP Top 10, privilege escalation, SSRF) for 3 cohorts — averaging a 73% solve rate.
  • Delivered weekly technical mentoring on web exploitation, network traffic analysis, and vulnerability remediation to advanced white-hat trainees.
Hack MAC 2025 — CTF Infrastructure
Jul – Oct 2025

Co-engineered 38 CTF challenges across web, crypto, forensics, OSINT, and reverse engineering for a Macquarie University competition targeting 3 academic levels. Containerised all web challenges with Docker; wrote Python tooling to auto-generate JSON/Markdown inventories tracking challenge paths, categories, difficulty, and deployment status.

Docker Python Web Security CTF Dev OSINT Rev Eng
Penetration Test — LAMP Bulletin Board System
Jan – Feb 2025

Black-box penetration test of a self-built LAMP web application. Identified and documented 11 vulnerabilities including critical RCE via file upload, authentication bypass via SQL injection, stored XSS, IDOR, session fixation, and directory listing. Produced a structured pentest report with CVSS-style severity ratings, reproduction steps, and remediation code for each finding.

● Critical: RCE, SQLi Auth Bypass ● High: XSS, IDOR, Session Fixation
Burp Suite OWASP Top 10 SQLi XSS RCE IDOR
AI-Based Network Attack Classifier
Nov – Dec 2024

Built a multi-class attack classifier in Python on 220,000 network traffic entries. Classified brute-force, SQL injection, XSS, and system command execution using Random Forest, XGBoost, and Logistic Regression. Engineered payload features by extracting attack-tool signatures (hydra → brute-force, sqlmap → SQLi). Best model achieved 89.6% accuracy with Brute Force F1 of 0.99.

Python scikit-learn XGBoost Random Forest Feature Engineering Network Logs
2024 – 2025
Macquarie University
Major in Cyber Security
2021 – 2022
Handong Global University
Major in Computer Science