Skip to content
View cybermaxluo's full-sized avatar

Block or report cybermaxluo

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
cybermaxluo/README.md

Hi, I'm Max

AI Security Engineering Lead (Crypto/Web3) | Author of AISecOps | AI for Security & Security for AI | Blockchain Security | OSCE³

0x01 About Me

TL;DR: Cybersecurity leader and hands-on security engineer focused on building AI-driven security capabilities for high-pressure, high-adversarial environments.

Highlights

  • 13+ years in cybersecurity, from red teaming and exploit development to global security leadership.
  • Leading Security AI Automation at a globally leading cryptocurrency exchange.
  • Focused on AI SOC, AI threat hunting, insider threat defense, data loss prevention, AppSec, DevSecOps, and offensive security.
  • Former Head of Global AI Security COE and Head of Global Application Security at SHEIN.
  • Author of the open-source book and project 《AISecOps: AI-Driven Security System》.
  • OffSec OSCE³ / OSED / OSWE / OSEP / OSCP holder.

I work at the intersection of security engineering, AI automation, and security operations, turning security expertise into reusable platforms, measurable controls, and repeatable operating models.

Current focus

  • Crypto exchange security: SOC anti-intrusion, Web3 APT defense, phishing, account takeover, API key abuse, cloud-native intrusion, abnormal login, and abnormal withdrawal detection.
  • AI security operations: AI SOC, SOAR, AI alert triage, AI threat hunting, incident investigation automation, IOC expansion, attack timeline generation, and response recommendation.
  • Insider threat & data protection: AI UEBA, behavior baselines, privilege abuse detection, sensitive-operation governance, customer-support risk monitoring, and data loss prevention.

Core background

  • AppSec & SDLC: SAST / DAST / IAST / SCA, threat modeling, secure code review, SBOM, DevSecOps, API security, mobile security, and software supply chain security.
  • AI system security: LLM threat modeling, prompt injection defense, data leakage prevention, access control, model governance, third-party model risk, and NIST AI RMF.
  • Offensive security: red teaming, penetration testing, cloud and container attack simulation, exploit development, and adversary emulation.

0x02 AISecOps

《AISecOps: AI-Driven Security System》

AISecOps: AI 驱动的安全体系。一套将 AI 能力嵌入企业安全体系的方法论框架,以及支撑它落地的工程实践,覆盖安全架构、SOC 运营、AI 威胁狩猎、内部威胁检测、数据防泄漏、GRC、云原生安全、身份治理、隐私保护与 AI 系统安全。

0x03 Selected Writing

Most of my long-form essays and books are currently in Chinese.

Technical Papers & Guides

  1. 《A Comprehensive Guide to Enhancing Workplace Influence: From Theory to Practice》
  2. 《互联网跨境企业应用安全架构指南》
  3. 《安全BP(GSBP)与 BISO 团队建设实践指南》
  4. 《互联网企业红队建设实践指南》
  5. 《BlackHat USA 2025: LLM+定制化DFA增强SAST检测技术》
  6. 《全球视野下的GDPR合规:安全防护与风险应对》
  7. 《网络安全从业者的AI转型指南》
  8. 《金融领域跨境合规的六大 “生死线”》
  9. 《BlackHat Asia 2025:Java 反序列化利用链深度挖掘》
  10. 《聊一聊AI赋能网络安全》
  11. 《Black Hat 2025 USA:基于 LLM 的微服务污点漏洞检测》

Personal Essays & Reflections

  1. 《Max的禅修笔记:道教体系框架解读》
  2. 《Max的禅修笔记:中国民间信仰体系框架解读》
  3. 《Max的禅修笔记:佛教体系框架解读》
  4. 《01 《宇宙的十二种假说》开篇》
  5. 《02 宇宙的十二种假说:物质为本,还是意识为本?》
  6. 《03 宇宙的十二种假说:信息即存在》
  7. 《04 宇宙的十二种假说:我们或许身在模拟中》
  8. 《05 宇宙的十二种假说:量子世界的三种解释》
  9. 《06 宇宙的十二种假说:塌缩、信念与决定论》
  10. 《07 宇宙的十二种假说:从大爆炸到今天》
  11. 《08 宇宙的十二种假说:多重宇宙》
  12. 《09 宇宙的十二种假说:全息宇宙》
  13. 《10 宇宙的十二种假说:时间的三种面貌》
  14. 《11 宇宙的十二种假说:人择原理》
  15. 《12 宇宙的十二种假说:终极篇》

More writing is available on my GitHub and WeChat public account: 白帽子罗棋琛.

0x04 Certifications

0x05 Contact

0x06 GitHub


AI-driven security operations | Crypto exchange security | AppSec | DevSecOps | AI Security

Popular repositories Loading

  1. AISecOps AISecOps Public

    📚【更新中】AISecOps: AI-Driven Enterprise Security|AI 驱动的安全体系。一套将 AI 能力嵌入企业安全体系的方法论框架,以及支撑它落地的完整工程实践——从安全架构、GRC、云原生、数据隐私到 SOC 运营、身份治理与 AI 系统安全。开源中文技术专著,CC BY-NC-SA 4.0。/*⚡🌊🛡️*/

    143 24

  2. IDAProMCP_Max IDAProMCP_Max Public

    IDA Pro MCP 插件

    Python 18 3

  3. cybermaxluo cybermaxluo Public

    4

  4. black-hat-usa-2026-talks black-hat-usa-2026-talks Public

    Black Hat USA 2026 议题中英文技术解读|Talk analysis, detection strategies, and defensive engineering for security engineers.

    2