Pyae Heinn Kyaw

Pyae Heinn Kyaw

Known as Heinn

Cyber Incident Response Specialist

Hands-on incident responder with experience across endpoint forensics, threat hunting, malware analysis, and cloud incident response within enterprise CSIRT environments. Strong focus on Windows investigations, memory forensics, attacker tradecraft analysis, persistence mechanisms, and behavioural detection engineering across Windows, macOS, Linux, and cloud environments. Experienced investigating endpoint compromise, suspicious execution, identity-related threats, phishing activity, and malware incidents while continuously improving investigative workflows, telemetry visibility, and security monitoring capability. Passionate about defensive security outside work through malware research, home labs, CTFs, community contributions, and technical presentations.

2/2 SANS CTF Winner BTLO Global #1 GIAC Advisory Board
4+ Years in Security
12 GIAC Certifications
#1 BTLO Global Rank
Top 1% TryHackMe
2/2 SANS CTF Winner

Professional Experience

AI Cyber Incident Responder, CSIRT

Mar 2025 – Present

Salesforce — Melbourne, Australia

🌐 Remote
  • Command coordinated AI defense systems that detect, contain, and neutralize threats in real time — systems that use reasoning and automation to maintain critical operations under attack
  • Investigate complex endpoint and cloud security incidents across Windows, macOS, Linux, AWS, Azure, and GCP environments within Salesforce's enterprise CSIRT function
  • Perform deep endpoint investigations involving suspicious execution, persistence analysis, credential misuse, malware activity, and identity-related compromise across enterprise environments
  • Conduct threat hunting across endpoint and cloud telemetry to identify attacker behaviour, visibility gaps, and suspicious execution patterns bypassing existing detections
  • Support containment and remediation efforts during high-priority incidents while improving investigative workflows and telemetry visibility
  • Support development and tuning of security alerts, detection workflows, and telemetry correlation logic to improve incident response effectiveness
  • Contribute to internal CSIRT projects and workflow improvements to increase investigative efficiency and response capability

Associate Cyber Incident Response Specialist

Feb 2023 – Feb 2025

EnergyAustralia — Melbourne, Australia

🔀 Hybrid
  • Conducted hypothesis-driven threat hunting across endpoint and network telemetry to identify suspicious execution patterns, persistence mechanisms, and attacker behaviour
  • Supported incident response investigations involving phishing, malware, endpoint compromise, and operational technology (OT) environments
  • Worked as a technical SME for multiple security platforms supporting incident response workflows, telemetry analysis, and investigative efficiency improvements
  • Participated in purple team activities focused on validating detection coverage and improving endpoint visibility across enterprise environments
  • Provided 24×7 cyber incident response support within a specialised CSIRT environment

Cyber Security Operations Centre (CSOC) Analyst

Jun 2022 – Jan 2023

KDDI Summit Global Myanmar — Yangon, Myanmar

🏢 Onsite
  • Led SOC monitoring and incident response activities across enterprise environments
  • Conducted web application penetration testing, vulnerability assessments, and proactive threat hunting activities
  • Improved security awareness initiatives through phishing simulations and internal training development
  • Supported cyber risk assessments and security-focused systems design reviews

Cyber Security Analyst

May 2019 – Aug 2019

Kernellix — Yangon, Myanmar (Internship)

🌐 Remote
  • Performed web application penetration testing and vulnerability assessments
  • Developed automation scripts using Python and Bash to support security testing and reporting workflows
  • Assisted with technical reporting and remediation recommendations for identified vulnerabilities

Achievements

GIAC Security Professional (GSP) Badge

GIAC Security Professional (GSP) — Analyst #506

2026

Achieved GIAC Security Professional (GSP) certification, becoming the 506th analyst globally to earn this distinguished certification. GSP represents the pinnacle of GIAC certifications, requiring holders to have earned at least 3 GIAC Practitioner Certifications and 2 GIAC Applied Knowledge Certifications (5 total GIAC certifications), demonstrating comprehensive expertise across multiple cybersecurity domains.

SANS Offensive Operations Coin

SANS Offensive Operations Coin Winner (SEC504 Course)

2026

Awarded for winning the final capstone challenge of SEC504: Hacker Tools, Techniques, and Incident Handling on the last day of class. The challenge tests comprehensive understanding of offensive security techniques and incident response.

SANS Lethal Forensicator Coin

SANS Lethal Forensicator Coin Winner (FOR508 Course)

2024

Awarded for winning the final capstone challenge of FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics on the last day of class. Demonstrates advanced skills in memory forensics, threat hunting, and incident investigation.

CSOM Gold Challenge Coin

CSOM Gold Challenge Coin

2026

Awarded by Centri (formerly Security Blue Team) for passing the Certified Security Operations Manager (CSOM) exam with a score of 97% — earning the rare gold coin reserved for candidates scoring 90%+ on their first attempt. CSOM covers how to plan, build, and mature security operations teams: performing threat modelling to identify threats to the organization, understanding security operations functions and the value they bring, building a SOC across people, technology, and processes, conducting maturity assessments for SOC, IR, Hunting, and CTI teams, and harnessing metrics for reporting and identifying issues. Aimed at security professionals with 2+ years' experience, it forges technical managers by developing both management principles and hands-on technical skills.

BTL2 Challenge Coins

BTL2 Silver Challenge Coin

2024

Awarded by Centri (formerly Security Blue Team) for passing the Blue Team Level 2 certification exam. BTL2 focuses on advanced threat hunting, log analysis, and incident response across enterprise environments.

Research & Community Projects

⚔️

MITRE ATT&CK Contributor

Contributed T1546.018 — Event Triggered Execution: Python Startup Hooks to the MITRE ATT&CK framework, documenting a persistence technique used by threat actors.

View Technique →
📋

Insider Threat Matrix Contributor

Contributed AR5 (Uninstalling Software) and DT095 detection techniques to the Insider Threat Matrix, helping organizations detect insider risk behaviors.

View Contribution →
🦠

Malware Analysis Research

Published static & dynamic malware analysis research on Mustang Panda TONESHELL malware, documenting TTPs, C2 infrastructure, and detection opportunities.

Read Analysis →
⛓️

macOS ClickFix & EtherHiding Research

Reverse-engineered a macOS ClickFix campaign that hides its C2 hostname inside a Polygon smart contract (EtherHiding), letting operators rotate infrastructure on-chain for cents. Documents the full delivery chain, layered AppleScript loaders, LaunchAgent persistence, and the on-chain resolver’s rotation history.

Read Analysis → 2026
🥇

BTLO Global #1

Ranked #1 globally on Blue Team Labs Online (BTLO) CTF platform across all defenders. Authored walkthroughs for CTF challenges and investigations.

View Profile →
🎓

TryHackMe Top 1%

Ranked in the top 1% of users globally on TryHackMe. Authored walkthroughs for CTF challenges covering DFIR, threat hunting, and security analysis.

View Profile →
🔬

Lab Environment Research

Built malware analysis and DFIR lab environments to analyse persistence mechanisms, attacker behaviour, and anti-analysis techniques. Continuous experimentation across endpoint telemetry, memory forensics, cloud investigations, and detection engineering workflows.

🎖️

GIAC Advisory Board

Awarded by GIAC for achieving an outstanding score (90%) on the GCFA exam, demonstrating expert-level knowledge in forensic analysis and incident response.

2024
📝

Write-ups & Presentations

Exam reviews, conference presentations, and CTF write-ups published on PHK Knowledge Sharing.

View All Write-ups →
🎙️

BSides Myanmar 2025 Speaker

Presented "The Art of Windows Memory Forensics" at BSides Myanmar 2025, covering memory acquisition, analysis techniques, and malware detection in volatile memory.

2025

Certifications

GIAC / SANS

12 certifications

🛡️ Verify
GIAC Security Expert (GSE) GSE GIAC Security Expert In Progress
GIAC Security Professional (GSP) GSP GIAC Security Professional 506th certified
GIAC Experienced Forensics Analyst (GX-FA) GX-FA GIAC Experienced Forensics Analyst 148th certified
GIAC Certified Forensics Analyst (GCFA) GCFA GIAC Certified Forensics Analyst 23,962nd certified
GIAC Experienced Forensics Examiner (GX-FE) GX-FE GIAC Experienced Forensics Examiner 125th certified
GIAC Certified Forensics Examiner (GCFE) GCFE GIAC Certified Forensics Examiner 10,877th certified
GIAC Experienced Intrusion Analyst (GX-IA) GX-IA GIAC Experienced Intrusion Analyst In Progress
GIAC Certified Intrusion Analyst (GCIA) GCIA GIAC Certified Intrusion Analyst In Progress
GIAC Experienced Incident Handler (GX-IH) GX-IH GIAC Experienced Incident Handler In Progress
GIAC Certified Incident Handler (GCIH) GCIH GIAC Certified Incident Handler 54,090th certified
GIAC AI Security Automation Engineer (GASAE) GASAE GIAC AI Security Automation Engineer In Progress
GIAC iOS and macOS Examiner (GIME) GIME GIAC iOS and macOS Examiner 494th certified

Centri / Security Blue Team

2 certifications

🛡️ Verify
Blue Team Level 2 (BTL2) BTL2 Blue Team Level 2
Certified Security Operations Manager (CSOM) CSOM Certified Security Operations Manager

TryHackMe

2 certifications

🛡️ Verify
Security Analyst Level 1 (SAL1) SAL1 Security Analyst Level 1
Security Analyst Level 2 (SAL2) SAL2 Security Analyst Level 2

CyberDefenders

1 certification

🛡️ Verify
Certified CyberDefender Level 1 (CCDL1) CCDL1 Certified CyberDefender Level 1

Hack The Box

1 certification

🛡️ Verify
Certified Defensive Security Analyst (CDSA) CDSA Certified Defensive Security Analyst

EC-Council

1 certification

🛡️ Verify
Computer Hacking Forensic Investigator (C|HFI) C|HFI Computer Hacking Forensic Investigator

INE / eLearnSecurity

1 certification

🛡️ Verify
Certified Threat Hunting Professional (eCTHP) eCTHP Certified Threat Hunting Professional

ISC²

1 certification

🛡️ Verify
Certified in Cybersecurity (CC) CC Certified in Cybersecurity

Courses

SANS Institute

5 courses

2026 SEC503 — Network Monitoring and Threat Detection In-Depth Upcoming
2026 SEC504 — Hacker Tools, Techniques & Incident Handling
2026 SEC598 — AI and Security Automation for Red, Blue, and Purple Teams In Progress
2025 FOR518 — Mac and iOS Forensic Analysis and Incident Response
2024 FOR508 — Advanced Incident Response, Threat Hunting & Digital Forensics

Applied Network Defense

1 course

2026 Investigation Theory

IntelOps

1 course

2025 Hunting Adversary Infrastructure In Progress

Education

2019 – 2021

Master of Information Technology

James Cook University, Australia

2019 – 2021

Master of Business Administration

James Cook University, Australia

2018

Bachelor of Science (Computing)

Edinburgh Napier University, UK

2015 – 2017

Higher National Diploma in Computing & Systems Development

Info Myanmar College, Myanmar

Skills & Tooling

SIEM

SplunkMicrosoft SentinelGoogle SecOps IBM QRadarCrowdStrike Next-Gen SIEM

EDR / XDR

CrowdStrike EDRMicrosoft Defender XDR Cybereason EDRTrellix HX

Digital Forensics

Windows ForensicsLinux ForensicsmacOS Forensics Memory ForensicsiOS Forensics

Cloud IR

AWSAzureGCP

Threat Intelligence

Threat IntelligenceHunting Adversary Infrastructure Supply Chain Compromise AnalysisStatic & Dynamic Malware Analysis

Other

Threat HuntingPurple TeamingOT/ICS IR AI AutomationProofPoint Akamai WAFZscaler ZIARapid7 VMTrellix ETP

Development

PythonBashPowerShell HTMLCSSPHPMySQLC++

Get in Touch

Open to collaboration, speaking opportunities, and interesting security problems.