Li Li

Cybersecurity Professional | Penetration Testing Engineer
Beijing, CN.

About

Highly analytical and results-oriented Cybersecurity Professional with a Bachelor's degree in Software Engineering and expertise in penetration testing, vulnerability management, and security operations. Proven ability to identify critical vulnerabilities, develop comprehensive security solutions, and contribute to the successful execution of large-scale security projects, ensuring robust system protection and compliance.

Work

Hangzhou Asian Games Organizing Committee
|

Network Security Engineer

Summary

Ensured the security and availability of critical network systems for the Hangzhou Asian Games, managing daily operations, incident response, and disaster recovery.

Highlights

Managed network and system security operations, including attack detection, analysis, and response, for the critical AGIS network and venue Wi-Fi systems during the Asian Games.

Resolved over 150 network security incidents and service tickets related to the AGIS network and venue Wi-Fi, maintaining critical service uptime throughout the event.

Conducted daily operational status checks and analyzed security device alarms, proactively identifying and mitigating potential threats to network stability.

Implemented data backup and disaster recovery protocols, ensuring 99.9% data availability and system resilience for all key network systems.

Contributed to the overall security and availability of all related network systems, directly supporting the successful and smooth execution of the Hangzhou Asian Games.

Central State-Owned Enterprise
|

Security Operations Engineer

Summary

Provided critical security assurance for a major state-owned enterprise, encompassing pre-event risk assessment, real-time monitoring, and post-event analysis to ensure robust defense.

Highlights

Developed and implemented comprehensive security assurance plans, outlining strategies for risk mitigation and incident response during critical operational periods.

Conducted pre-assurance risk assessments, identifying and remediating over 50 potential vulnerabilities including exposed surfaces, high-risk ports, and misconfigured security devices.

Monitored and analyzed security device alerts in real-time, facilitating rapid incident response and assisting in the resolution of over 20 critical security incidents.

Provided security awareness training to over 100 personnel and optimized security device policies, enhancing overall organizational security posture by 15%.

Authored detailed post-event summary reports, providing key insights and recommendations for continuous improvement in defense strategies.

Major Bank
|

Attack Team Member

Summary

Participated as an attack team member in an internal bank security drill, successfully identifying and exfiltrating sensitive information to simulate real-world threats.

Highlights

Executed advanced open-source intelligence (OSINT) gathering and analysis to identify potential attack vectors and sensitive information related to the target bank.

Discovered and extracted critical sensitive documents and database credentials from internal network drives and knowledge repositories, demonstrating effective data exfiltration techniques.

Simulated real-world attack scenarios, providing actionable insights into the bank's security posture and contributing to the enhancement of their defense mechanisms.

Documented findings and collaborated with the defense team to improve incident response and data loss prevention strategies.

Central State-Owned Enterprise
|

Penetration Test Engineer

Summary

Led authorized penetration tests for a critical enterprise system, identifying vulnerabilities and ensuring high client satisfaction through effective security recommendations.

Highlights

Conducted comprehensive penetration tests on target systems following established methodologies and obtaining explicit authorization, adhering to ethical hacking principles.

Identified and documented over 30 critical and high-severity vulnerabilities, including SQL injection, XSS, and CSRF, within the enterprise system.

Authored detailed penetration test reports and provided actionable security recommendations, assisting the client in hardening systems and achieving 95% vulnerability remediation.

Collaborated with client teams to implement security fixes, ensuring successful project completion and achieving high client satisfaction.

Education

Tianjin University of Technology

Bachelor

Software Engineering

Certificates

Information Security Assurance Personnel Certification (CISAW-Emergency)

Issued By

China Information Security Certification Center

National Information Security Level Examination (NISP Level 2)

Issued By

National Information Security Standardization Technical Committee

Certified Information Security Penetration Testing Expert (CISP-PTS)

Issued By

China Information Security Certification Center

MIIT "Security Operations Engineer" Junior Certification

Issued By

Ministry of Industry and Information Technology (MIIT)

Skills

Cybersecurity Methodologies

Penetration Testing, Vulnerability Scanning, Baseline Checks, Attack/Defense Drills, Emergency Response, Incident Response, Risk Assessment, Security Operations, Threat Detection, Data Classification, Data Security Risk Assessment.

Security Tools

BurpSuite, Nmap, Dirsearch, SqlMap, APT (Advanced Persistent Threat), IPS (Intrusion Prevention System), WAF (Web Application Firewall).

Operating Systems

Windows, Linux.

Vulnerability Management

Web Vulnerabilities (SQL Injection, XSS, CSRF, File Upload), Middleware Vulnerabilities (Apache, Nginx, Weblogic).

Data Security

Sensitive Data Tagging, Regular Expression Generation for Sensitive Data, Data Security Classification and Grading (Securities, Schools, Public Institutions, Hospitals).