
Dai Tran, PhD
Continuously Innovative and Resourceful Security Enabler
Last updated: Aug 2026 — Updated section(s): EXECUTIVE SUMMARY, INDUSTRY EXPERIENCE
TABLE OF CONTENTS
- TABLE OF CONTENTS
- EXECUTIVE SUMMARY
- CORE COMPETENCIES
- RECOGNISED ACHIEVEMENTS
- INDUSTRY EXPERIENCE
- Staff Security Engineer - Security Automation
- Senior Engineer - Security Automation
- Senior Cyber Security Automation Engineer
- Technology Owner - Firewall Automation
- Network Security Engineer
- IT Network Support Analyst
- Network Engineer
- Network and Systems Administrator, Contractor
- Cisco Network Engineer, Contractor
- System Administrator
- ACADEMIC EXPERIENCE
- EDUCATION HISTORY
- CERTIFICATIONS AND CONTINUOUS PROFESSIONAL DEVELOPMENT
- PUBLICATIONS
EXECUTIVE SUMMARY
Principal-level Security Engineer driving AI-powered automation, scalable APIs, and cloud-native security platforms across one of Australia’s largest financial institutions. With 17+ years in security engineering spanning Commonwealth Bank, Amadeus, and enterprise sectors, leads technical strategy and engineering excellence across 5 squads within Group Security as Staff Security Engineer at Commonwealth Bank.
Engineering Leadership & AI Innovation: Architects and delivers AI/GenAI security automation systems in production — including agentic vulnerability patching, RAG-based self-service platforms, and AI security controls — while defining technical strategy, driving engineering standards, and uplifting team capability across squads. Leads strategic programs delivering enterprise-wide impact, mentors engineering teams, and communicates technical vision to inspire broader organisational adoption. Translates complex security challenges into scalable distributed systems aligned to long-term technology strategy. Proven track record of identifying delivery risks proactively, influencing senior stakeholders, and mentoring engineers through hands-on delivery.
Architect of enterprise-scale security automation frameworks including multi-vendor firewall orchestration, Terraform-based IaC platforms, and CI/CD pipelines delivering measurable operational efficiency in mission-critical financial environments. Recognised with Above Expectations performance rating and multiple industry awards for innovation in security automation.
Technical Expertise: Python/Go secure development • AI/GenAI engineering (LLM, RAG, Agentic AI) • Scalable API & distributed systems design • Infrastructure as Code (Terraform/Terratest/CloudFormation) • Multi-vendor firewall automation (Palo Alto, Cisco, Akamai) • AWS/Azure security architecture • Temporal workflow orchestration • Observability & monitoring (Splunk, Observe Inc) • DevSecOps practices • AI security controls • Docker • CI/CD pipelines
Certifications: AWS Certified Developer Associate • Microsoft Azure Security Engineer Associate • AZ-400 DevOps • PCNSE • CCNP • CEH
CORE COMPETENCIES
✅ AI/GenAI Security Engineering & Innovation - LLM application development, RAG architecture, agentic AI systems, AI security controls (LLM Guard), prompt engineering, and AWS Bedrock/Azure OpenAI implementation backed by hands-on PoC delivery and specialised training
✅ Cloud Security Architecture & Engineering - AWS and Azure security design, implementation, and automation validated by AWS Certified Developer Associate, Azure Security Engineer Associate certifications, and enterprise-scale deployments across financial services
✅ Security Automation & Orchestration at Scale - Enterprise security automation frameworks, Temporal workflow orchestration, multi-vendor firewall automation (Palo Alto, Cisco, Akamai), and security tool integration delivering measurable operational efficiency in mission-critical environments
✅ DevSecOps & CI/CD Pipeline Engineering - Secure software development lifecycle, automated security controls, GitHub Enterprise, GitHub Actions, TeamCity, Docker, HashiCorp Vault, and AppSec champion practices with AZ-400 DevOps certification
✅ Infrastructure as Code & Cloud Automation - Terraform/Terratest expertise, CloudFormation, multi-cloud IaC frameworks, self-service platform development, and automated infrastructure provisioning with Akamai DevOps Professional certification
✅ Enterprise Security Leadership & Strategy - Technical strategy development, cross-domain security architecture, federated security solutions, stakeholder management, and mentoring engineering teams across large-scale organisations
✅ Advanced Network Security & Firewall Technologies - Next-generation firewalls (Palo Alto PCNSE certified), traditional firewalls, secure web gateways, edge security platforms (Akamai, Cloudflare), and 10+ years hands-on multi-vendor firewall management
✅ Secure Software Development & Ethical Hacking - Python and Go programming, REST API development, microservices architecture, offensive security mindset (CEH certified), vulnerability assessment, and production-grade security tool development
✅ Container Orchestration & Kubernetes - Kubernetes application development, container security, Helm packaging, and cloud-native security patterns supported by ongoing CKAD certification preparation
✅ Security Research & Innovation - PhD-level analytical and research capabilities, algorithm development, security protocol design, academic publication record, and translation of research into practical enterprise solutions
✅ Cross-Platform Systems Administration - Linux and Windows server administration, cloud infrastructure management, networking protocols (CCNP certified), IPAM/DHCP/DNS, and VPN technologies
✅ Continuous Learning & Technology Adoption - Demonstrated commitment through 25+ certifications, 50+ professional training courses, and rapid acquisition of emerging technologies (GenAI, Temporal, Kubernetes) aligned with industry evolution
RECOGNISED ACHIEVEMENTS
🥇 2022 | Annual performance achievement of Above Expectations and top (75% of maximum) bonus award
🥇 2021 | Recognition of Commitment for the delivery of the CI/CD pipeline that automates firewall policy breach reporting for Network Security control team
🥇 2019 | Add Value Award for the perseverance and innovation in firewall automation and delivery of its benefits to business units
🥇 2019 | STAR: Special Thanks And Recognition Award for last-minute support for the Air Canada cutover, ensuring Amadeus customer satisfaction
🥇 2016 | STAR: Special Thanks And Recognition Award for the exceptional contributions to the firewall migration project
🥇 2008 | Full UTS Faculty of Engineering Postgraduate Research Scholarship for the Doctoral Program
🥇 2007 | Kyung Hee University President’s Special Prize for the Excellent Foreign Student
🥇 2005 | Full Kyung Hee University and Networking Lab. Scholarships for the Master course in Kyung Hee University
INDUSTRY EXPERIENCE
Staff Security Engineer - Security Automation
April 2023 – Present | Commonwealth Bank of Australia - 30,001+ Employees
Responsibilities
- Drive business outcomes by aligning technical implementations with core business and technical strategies.
- Develop technical strategy while overseeing medium to complex engineering initiatives.
- Design solutions that enable broader teams to implement product and technology strategies.
- Identify delivery risks proactively, communicate effectively, and adjust plans to achieve goals.
- Mentor and upskill other engineering teams across different squads.
- Define project stretch goals and success measures, holding the squad accountable.
- Architect, develop and deploy AI-powered security automation systems including:
- GenAI chatbot using AWS Bedrock, RAG architecture, and Streamlit — enabling self-service security configuration management and demonstrating AI applicability to leadership
- Agentic vulnerability management system using MCP servers, integrating Snyk, Sysdig, and Wiz with automated Jira/GitHub workflows for end-to-end remediation orchestration
- AI security controls using LLM Guard API for prompt injection and jailbreak protection
- AI-Powered Multi-app Auto Patcher — production deployment automating end-to-end vulnerability patching (dependency upgrades, container image upgrades, SAST scanning, PR reporting) using Claude Code agentic skills; delivered hands-on and used to mentor team on AI-driven engineering
- AI-Powered End-to-End Non-Negotiable Control Automation MVP — technical lead actively exploring and designing with product owner to automate enterprise-wide security compliance checking
- Integrate security automation workflows with Observe Inc for log ingestion and operational dashboards/alerting across security engineering platforms.
- Communicate security engineering vision to inspire teams across the Group.
- Complete design and threat modelling independently.
- Drive the development of strategic programs of work, including proof of concept developments.
- Contribute to internal online discussions around security engineering, delivery and technology (e.g., blog posts and knowledge base articles).
Strategic Programs & Leadership Roles
Providing hands-on technical leadership across 5 squads within Group Security spanning automation, edge security, DevSecOps, orchestration, API platforms, network security, and security engineering. Drives technical alignment, engineering standards, and cross-domain architecture decisions across squads — influencing roadmaps and delivery outcomes beyond any single product.
| Program/Initiative | Role | Impact/Scope |
|---|---|---|
| AI/GenAI-powered security automation PoCs | Architect & Developer | RAG chatbot, agentic vulnerability management, AI security controls |
| DevSecOps automated security checks | Technical/Solution Co-lead | Enterprise-wide automated security control compliance gates in CI/CD enabling secure-by-default development |
| Group security orchestration platform | Technical/Solution Co-lead | Centralized Temporal platform orchestrating security tool integrations and workflows |
| Edge security self-service platform | Technical/Solution Lead | Multi-tenant self-service WAAP/DDoS platform (Akamai, Cloudflare) serving enterprise-wide business units via Terraform |
| Federated security architecture | Group Security Champion | Cross-domain security solution assessments and risk mitigation |
| Corporate edge firewall policy governance automation | Technical/Solution Lead | Automated Palo Alto request validation, change plan generation, and compliance documentation |
| Security as an API | Technical/Solution Co-lead | Group-wide REST API framework enabling programmatic security tool integration and automation |
| DevSecOps | Group Cybersecurity AppSec Champion | Secure code review, AppSec standards, monthly champion meetups |
Senior Engineer - Security Automation
September 2022 – April 2023 | Commonwealth Bank of Australia - 30,001+ Employees
Responsibilities
- Continued security automation responsibilities from the Senior Cyber Security Automation Engineer role while expanding scope to include:
- Solution and Developer Lead and de facto Project Manager for the Akamai Automation Initiative, architecting, designing, implementing, and delivering the Terraform-based Akamai Automation Framework and self-service automation function benefiting business units across the bank
- Organised and facilitated the Group Security CIO Engineering Talks Forum to foster knowledge sharing, collaboration, crowd-reviewing, effective SME identification and resource allocation, and establishment of improved processes within Security Engineering teams
Senior Cyber Security Automation Engineer
May 2022 – September 2022 | Commonwealth Bank of Australia - 30,001+ Employees
Responsibilities
- Architected, designed, and implemented DevSecOps framework and practices for the bank’s Cyber Security Automation team using GitHub Enterprise, TeamCity, Docker, Checkmarx, JFrog Artifactory, JFrog Xray, HashiCorp Vault, and Bash scripting
- Designed, built, and maintained shared Python library with DevOps pipeline producing PyPI package (PyCyber) for Cyber Security Automation team’s solution development
- Served as CBA AppSec champion, performing secure code reviews and approvals while delivering talks at monthly AppSec champion meetups
- Drove initiatives that optimised, automated, and rationalised activities across Cyber Security controls
- Drove efficiencies and productivity gains through implementation of automation functions and solutions across the Cyber Security group to uplift cyber posture, including privileged service account creation automation, Splunk onboarding automation, and Akamai automation
- Influenced and drove the practice of automation standardisation across the Cyber Security group
- Conducted technical interviews and candidate assessments, contributing to team growth and maintaining high engineering standards
- Acted as a technical lead, managing and leading a small team of Cyber Security automation engineers
- Trained security architects, cyber security engineers, and control teams on automation solutions/functions and DevSecOps practices
Achievements
- Achieved the Above Expectations annual performance review and was awarded the top (75% of maximum) bonus
- Saved around 4200 hours annually for both the Splunk team and stakeholders through the delivery of the Splunk Log4J Onboarding Acceleration Automation project ahead of schedule
- Achieved the recognition of Commitment for the delivery of the CI/CD pipeline that automates firewall policy breach reporting function for Network Security control team
Technology Owner - Firewall Automation
February 2018 – May 2021 | Amadeus IT Group - 10,001+ Employees
Responsibilities
- Architected and led PAN firewall and Azure load balancer as Code design and development for on-prem and Azure environments including Terraform firewall/load balancer deployment and Palo Alto firewall configuration automation using Amadeus traffic flow blueprint, Terraform Azurerm and PAN-OS providers, and Infrastructure as Code Jenkins CI/CD pipeline
- Architected, designed, and developed software-development-based firewall automation framework leveraging multi-vendor firewall REST APIs
- Architected, designed, developed, and maintained Python-based multi-vendor firewall automation solutions for business use cases including automated end-to-end firewall path identification, SOC IP blocking, firewall change deployments, firewall permission checks, VPN cleanup, and firewall definition cleanup
- Integrated Python-based multi-vendor firewall automation solutions with Ansible and Ansible AWX/Tower to produce user-friendly, self-service web GUI portals for firewall automation consumers and facilitated end-to-end automation initiatives via AWX API calls
- Leveraged firewall automation solutions to drive improvements in processes, operational efficiency/agility, and system stability in a mission-critical environment
- Served as technical interviewer and hiring decision-maker for security engineering positions
- Mentored team members on Network Security and automation
- Applied knowledge/skills/tools: PAN & Cisco firewalling & REST API, Python, Object oriented software design and development, Linux/Windows administration, Git, Bitbucket, Jira, Ansible/AWX, Jenkins, Docker, CI/CD workflow, Visual Studio Code, Insomnia, OpenAPI, Azure network/security, Terraform, Golang, Terratest
Network Security Engineer
February 2015 – January 2018 | Amadeus IT Pacific - 10,001+ Employees
Responsibilities
- Led technical implementation of the Cisco/Blue Coat to Palo Alto migration project
- Researched, designed, and implemented Palo Alto advanced features including Threat Prevention, User-ID, App-ID, Content-ID, SSL decryption, WildFire, and URL Filtering on managed firewalls
- Managed full lifecycle of network security devices from design and engineering through implementation and maintenance
- Administered and provided Tier 3 follow-the-sun support for complex global network security infrastructure spanning 152+ Palo Alto, Cisco firewall, and Blue Coat proxy clusters using Panorama, Cisco Security Manager, and SIEM platforms (QRadar, Splunk)
- Authored technical documentation including network diagrams and knowledge base articles for global firewall and proxy infrastructure
- Supported development and definition of AMADEUS security standards, policies, and procedures, implementing them through technical means
- Delivered security consulting and implemented security concepts and audits for internal and external customers
- Collaborated with vendors’ TAC and professional services to resolve complex issues, fine-tune systems, and explore new features to meet emerging business challenges
- Applied knowledge/skills/tools: PAN firewalls and Panorama, Cisco firewalls and CSM, Qradar, Splunk, Symantec Blue Coat proxies and Management Center
IT Network Support Analyst
May 2013 – February 2015 | LION Pty Ltd - 5001-10,000 Employees
Responsibilities
- Researched and executed proof-of-concept projects on various network/security technologies such as Palo Alto and Cisco
- Designed, implemented, and administered Palo Alto firewalls via Panorama at enterprise Internet edges in Australia and New Zealand
- Planned, configured, managed, and troubleshot enterprise Cisco Unified Wireless Network of more than 600 lightweight APs and controllers across AUNZ via Prime Infrastructure
- Migrated Cisco autonomous wireless networks to lightweight wireless networks at multiple Lion dairy and drinks sites
- Configured, administered, and troubleshot more than 1000 Cisco switches and routers at more than 120 Lion sites
- Executed LAN improvement projects at multiple Lion sites to improve network performance and manageability
- Configured and managed Cisco SSL and site-to-site VPNs, DMVPN, ASA firewalls, and Riverbed Stealheads
- Collaborated with Telco for WAN link provision, monitored enterprise WAN links, and configured and deployed DMVPN 3G/4G routers to ensure business continuity
- Delivered technical consulting, level 3 escalation, and on-call support via Cherwell ticketing system, phone calls, and emails
- Created comprehensive documentation including network topology diagrams and system configurations for 120+ Lion sites
Achievements
- Successful migration from Forefront TMG to Palo Alto
- Effective prevention of Cryptolocker via Palo Alto URL filtering
Network Engineer
February 2012 – May 2013 | NETWORX AUSTRALIA - 10,001+ Employees
Responsibilities
- Designed and implemented Silver Peak WAN optimisation, Palo Alto firewall, SonicWALL firewall and VPN, VMware, Cisco switches and routers, and Cisco and Enterasys wireless solutions
- Configured and administered Palo Alto and SonicWALL firewalls, SonicWALL, Ironport, and Websense email security appliances, Aventail E-Class SRA appliances, DELL switches, Blue Coat ProxySG and PacketShaper, F5 LTM, BlueCat DHCP and DNS, Enterasys wireless and network access control appliances, VMware virtual infrastructure, and SolarWinds NPM and NTA
- Configured and administered Windows Server 2008 and SQL Server environments including MS Exchange and Active Directory, Group Policies, PKI, Failover Clustering, and Network Policy Server
- Implemented StorageCraft and SonicWALL data backup and disaster recovery solutions
- Performed data centre operations and maintained technical documentation for network infrastructure and systems
- Delivered technical consulting and pre- and post-sales support via ticketing system, remote desktop sessions, telephone, and emails
- Researched new technologies and products and their applications
- Collaborated with technology vendors and partners on product enablement
Network and Systems Administrator, Contractor
March 2011 – April 2012 | Ma & Company Solicitors, Sydney
Responsibilities
- Documented existing LAN, workstations, and server topology
- Set up and relocated LAN, Wi-Fi, ADSL/cable modems and routers
- Upgraded and updated desktop PC hardware, MS Office, MS Windows, and patches
- Deployed security measures against viruses, spyware, and intrusion to all workstations
- Created clean backup images of operating systems
- Performed daily IT/network administration and troubleshooting
- Liaised closely with PC retailers, a legal software company, a web hosting company, and an ISP to solve problems
Achievements
- Selected by management as the sole technical consultant for the company
Cisco Network Engineer, Contractor
October 2011 | HotelsCombined™, Sydney
Responsibilities
- Designed and built a new network of Cisco switches and routers for the HotelsCombined HQ office
Achievements
- Solved intractable technical problems ahead of the stipulated deadline
- Awarded bonus of 25% of total payment for supplied service
System Administrator
April 2011 – June 2011 | Master Builders Association of NSW, Sydney
Responsibilities
- Connected and enabled data replication between two independently developed database applications: EMT (Enquiry Mate Trainers) and iMIS
- Operated, administered, and customised EMT functionalities
- Extracted data from EMT to Excel spreadsheets using T-SQL
- Developed Visual Basic applications for spreadsheets to generate administrative reports for Training Managers
- Conducted training for staff on EMT and developed VB applications
- Performed casual IT/network troubleshooting
Achievements
- Solved intractable technical problems ahead of the stipulated deadline
- Improved training management efficiency by introducing new VB applications
ACADEMIC EXPERIENCE
Researcher
2008 – 2011 | Centre for Real-Time Information Networks, University of Technology, Sydney
Responsibilities
- Conducted research on security in wireless sensor networks and mobile ad-hoc networks
- Developed and evaluated proposed algorithms through simulations and implementation using MATLAB and nesC programming languages
- Organised weekly technical seminars
- Presented at international academic conferences
Achievements
- Obtained UTS Vice-Chancellor’s & Faculty of Engineering & IT’s conference funds
- Published 9 papers in renowned international conferences and journals
EDUCATION HISTORY
PhD in Computing and Communications Engineering
2008 – 2011 | University of Technology, Sydney, Australia
Thesis: Controlled Link Establishment Attacks on Distributed Sensor Networks and Countermeasures
Master of Computer Engineering (Network Security Focus)
2005 – 2007 | Kyung Hee University, Suwon, South Korea
Thesis: Security Algorithms for Wireless Sensor Networks
Engineer in Information and Communications Technology
2000 – 2005 | Hanoi University of Science and Technology, Hanoi, Vietnam
Thesis: Kerberos-based authentication for FTP applications
CERTIFICATIONS AND CONTINUOUS PROFESSIONAL DEVELOPMENT
CERTIFICATIONS
- February 2025 | Scaling Kubernetes Apps & Solutions: Kubernetes Packaging
- March 2024 | Microsoft Applied Skills: Develop generative AI solutions with Azure OpenAI Service
- September 2023 | AWS Certified Developer – Associate
- December 2022 | AZ-400: Designing and Implementing Microsoft DevOps Solutions
- September 2022 | ICAgile Certified Professional - Agile Programming
- April 2022 | Akamai DevOps Professional
- February 2022 | Microsoft OpenHack: Security, Compliance, and Identity
- March 2021 | Microsoft Certified Azure Security Engineer Associate
- February 2021 | Microsoft Certified Azure Fundamentals
- February 2021 | Certified SAFe® 5 Practitioner
- July 2020 | Certified Ethical Hacker (CEH) Certification
- April 2015 | Palo Alto Certified Network Security Engineer (PCNSE), License 6 - 881655
- June 2013 | Cisco Certified Network Professional (CCNP)
- February 2013 | Certified SonicWALL Security Administrator (CSSA)
- May 2012 | Silver Peak Certified Technical Professional Certification
- May 2012 | Blue Coat Certified Partner Systems Engineer – Visibility Training
- April 2012 | Blue Coat Partner Systems Engineer – Security Certification
- March 2012 | Lumension Certified Professional Certification
- February 2012 | Cisco SMB Specialization for Engineers Certification
- August 2011 | Cisco Certified Network Associate Certification (CCNA)
- June 2005 | Cisco Certified Network Associate Certification (CCNA)
PROFESSIONAL TRAINING
- September 2025 | Security Engineering on AWS
- August 2025 | Temporal 101 with Python and Temporal 102: Exploring Durable Execution with Python
- April 2024 | Architecting on AWS
- March 2024 | Microsoft Applied Skills: Develop generative AI solutions with Azure OpenAI Service
- June 2023 | Developing on AWS
- April 2023 | Introduction to HashiCorp Consul (Service Mesh) Hands-on Workshop
- November 2022 | AZ-400 Designing and Implementing Microsoft DevOps Solutions Course
- September 2022 | GitHub for Developers Training
- August 2022 | Containers and Kubernetes with Red Hat OpenShift Platform Training
- August 2022 | Agile Quick Start Program Training
- May 2022 | HashiCorp Advanced Data Protection with Vault Workshop
- May 2022 | Trend Micro Cloud Conformity Training
- November 2021 | SC-300 Microsoft Identity and Access Administrator Course
- November 2021 | SC-900 Microsoft Security, Compliance, and Identity Fundamentals Course
- October 2021 | AWS Security Fundamentals (Second Edition) with Certificate of Completion
- March 2021 | Linux Academy’s AZ-500: Microsoft Azure Security Technologies Course
- December 2020 | AWS Cloud Practitioner Essentials
- July 2020 | Linux Academy’s AWS Essentials Course
- July 2020 | Linux Academy’s LPI Linux Essentials Course
- April 2020 | Certified Ethical Hacker (CEH) - Linux Academy’s Prep Course
- June 2019 | Advanced Python Training
- March 2018 | DevOps for Ops
- March 2017 | Python for Ops Training
- March 2016 | Python Basics Training
- March 2015 | Palo Alto Advanced Firewall Troubleshooting PA311 Course
- March 2012 | StorageCraft Technical Training
CONTINUOUS LEARNING
- March 2025 | Certified Kubernetes Application Developer (CKAD) Study Guide, 2nd Edition By Benjamin Muschko
- February 2024 | Udemy AWS Amazon Bedrock & Generative AI - Beginner to Advanced
- October 2022 | Udemy Ultimate AWS Certified Developer Associate 2022 - NEW!
- July 2022 | Bash Mastery: The Complete Guide to Bash Shell Scripting
PUBLICATIONS
See publications.