AI Security Engineering Lead (Crypto/Web3) | Author of AISecOps | AI for Security & Security for AI | Blockchain Security | OSCE³
TL;DR: Cybersecurity leader and hands-on security engineer focused on building AI-driven security capabilities for high-pressure, high-adversarial environments.
Highlights
- 13+ years in cybersecurity, from red teaming and exploit development to global security leadership.
- Leading Security AI Automation at a globally leading cryptocurrency exchange.
- Focused on AI SOC, AI threat hunting, insider threat defense, data loss prevention, AppSec, DevSecOps, and offensive security.
- Former Head of Global AI Security COE and Head of Global Application Security at SHEIN.
- Author of the open-source book and project 《AISecOps: AI-Driven Security System》.
- OffSec OSCE³ / OSED / OSWE / OSEP / OSCP holder.
I work at the intersection of security engineering, AI automation, and security operations, turning security expertise into reusable platforms, measurable controls, and repeatable operating models.
Current focus
- Crypto exchange security: SOC anti-intrusion, Web3 APT defense, phishing, account takeover, API key abuse, cloud-native intrusion, abnormal login, and abnormal withdrawal detection.
- AI security operations: AI SOC, SOAR, AI alert triage, AI threat hunting, incident investigation automation, IOC expansion, attack timeline generation, and response recommendation.
- Insider threat & data protection: AI UEBA, behavior baselines, privilege abuse detection, sensitive-operation governance, customer-support risk monitoring, and data loss prevention.
Core background
- AppSec & SDLC: SAST / DAST / IAST / SCA, threat modeling, secure code review, SBOM, DevSecOps, API security, mobile security, and software supply chain security.
- AI system security: LLM threat modeling, prompt injection defense, data leakage prevention, access control, model governance, third-party model risk, and NIST AI RMF.
- Offensive security: red teaming, penetration testing, cloud and container attack simulation, exploit development, and adversary emulation.
《AISecOps: AI-Driven Security System》
AISecOps: AI 驱动的安全体系。一套将 AI 能力嵌入企业安全体系的方法论框架,以及支撑它落地的工程实践,覆盖安全架构、SOC 运营、AI 威胁狩猎、内部威胁检测、数据防泄漏、GRC、云原生安全、身份治理、隐私保护与 AI 系统安全。
Most of my long-form essays and books are currently in Chinese.
- 《A Comprehensive Guide to Enhancing Workplace Influence: From Theory to Practice》
- 《互联网跨境企业应用安全架构指南》
- 《安全BP(GSBP)与 BISO 团队建设实践指南》
- 《互联网企业红队建设实践指南》
- 《BlackHat USA 2025: LLM+定制化DFA增强SAST检测技术》
- 《全球视野下的GDPR合规:安全防护与风险应对》
- 《网络安全从业者的AI转型指南》
- 《金融领域跨境合规的六大 “生死线”》
- 《BlackHat Asia 2025:Java 反序列化利用链深度挖掘》
- 《聊一聊AI赋能网络安全》
- 《Black Hat 2025 USA:基于 LLM 的微服务污点漏洞检测》
- 《Max的禅修笔记:道教体系框架解读》
- 《Max的禅修笔记:中国民间信仰体系框架解读》
- 《Max的禅修笔记:佛教体系框架解读》
- 《01 《宇宙的十二种假说》开篇》
- 《02 宇宙的十二种假说:物质为本,还是意识为本?》
- 《03 宇宙的十二种假说:信息即存在》
- 《04 宇宙的十二种假说:我们或许身在模拟中》
- 《05 宇宙的十二种假说:量子世界的三种解释》
- 《06 宇宙的十二种假说:塌缩、信念与决定论》
- 《07 宇宙的十二种假说:从大爆炸到今天》
- 《08 宇宙的十二种假说:多重宇宙》
- 《09 宇宙的十二种假说:全息宇宙》
- 《10 宇宙的十二种假说:时间的三种面貌》
- 《11 宇宙的十二种假说:人择原理》
- 《12 宇宙的十二种假说:终极篇》
More writing is available on my GitHub and WeChat public account: 白帽子罗棋琛.
- Email: 186616@gmail.com
- LinkedIn: https://www.linkedin.com/in/max-luo
- GitHub: https://github.com/cybermaxluo
- Profile: https://github.com/cybermaxluo
- Open-source book: https://github.com/cybermaxluo/AISecOps/
AI-driven security operations | Crypto exchange security | AppSec | DevSecOps | AI Security



