Pyae Heinn Kyaw

Pyae Heinn Kyaw

Known as Heinn

Cyber Incident Response Specialist

Hands-on incident responder with experience across endpoint forensics, threat hunting, malware analysis, and cloud incident response within enterprise CSIRT environments. Strong focus on Windows investigations, memory forensics, attacker tradecraft analysis, persistence mechanisms, and behavioural detection engineering across Windows, macOS, Linux, and cloud environments. Experienced investigating endpoint compromise, suspicious execution, identity-related threats, phishing activity, and malware incidents while continuously improving investigative workflows, telemetry visibility, and security monitoring capability. Passionate about defensive security outside work through malware research, home labs, CTFs, community contributions, and technical presentations.

2/2 SANS CTF Winner BTLO Global #1 GIAC Advisory Board
4+ Years in Security
8 GIAC Certifications
#1 BTLO Global Rank
Top 1% TryHackMe
2/2 SANS CTF Winner

Professional Experience

AI Cyber Incident Responder, CSIRT

Mar 2025 – Present

Salesforce — Melbourne, Australia

🌐 Remote
  • Command coordinated AI defense systems that detect, contain, and neutralize threats in real time — systems that use reasoning and automation to maintain critical operations under attack
  • Investigate complex endpoint and cloud security incidents across Windows, macOS, Linux, AWS, Azure, and GCP environments within Salesforce's enterprise CSIRT function
  • Perform deep endpoint investigations involving suspicious execution, persistence analysis, credential misuse, malware activity, and identity-related compromise across enterprise environments
  • Conduct threat hunting across endpoint and cloud telemetry to identify attacker behaviour, visibility gaps, and suspicious execution patterns bypassing existing detections
  • Support containment and remediation efforts during high-priority incidents while improving investigative workflows and telemetry visibility
  • Support development and tuning of security alerts, detection workflows, and telemetry correlation logic to improve incident response effectiveness
  • Contribute to internal CSIRT projects and workflow improvements to increase investigative efficiency and response capability

Associate Cyber Incident Response Specialist

Feb 2023 – Feb 2025

EnergyAustralia — Melbourne, Australia

🔀 Hybrid
  • Conducted hypothesis-driven threat hunting across endpoint and network telemetry to identify suspicious execution patterns, persistence mechanisms, and attacker behaviour
  • Supported incident response investigations involving phishing, malware, endpoint compromise, and operational technology (OT) environments
  • Worked as a technical SME for multiple security platforms supporting incident response workflows, telemetry analysis, and investigative efficiency improvements
  • Participated in purple team activities focused on validating detection coverage and improving endpoint visibility across enterprise environments
  • Provided 24×7 cyber incident response support within a specialised CSIRT environment

SOC Analyst

Jun 2022 – Jan 2023

KDDI Summit Global Myanmar — Yangon, Myanmar

🏢 Onsite
  • Led SOC monitoring and incident response activities across enterprise environments
  • Conducted web application penetration testing, vulnerability assessments, and proactive threat hunting activities
  • Improved security awareness initiatives through phishing simulations and internal training development
  • Supported cyber risk assessments and security-focused systems design reviews

Cyber Security Analyst

May 2019 – Aug 2019

Kernellix — Yangon, Myanmar (Internship)

🌐 Remote
  • Performed web application penetration testing and vulnerability assessments
  • Developed automation scripts using Python and Bash to support security testing and reporting workflows
  • Assisted with technical reporting and remediation recommendations for identified vulnerabilities

Achievements

GIAC Security Professional (GSP) Badge

GIAC Security Professional (GSP) — Analyst #506

2026

Achieved GIAC Security Professional (GSP) certification, becoming the 506th analyst globally to earn this distinguished certification. GSP represents the pinnacle of GIAC certifications, requiring holders to have earned at least 3 GIAC Practitioner Certifications and 2 GIAC Applied Knowledge Certifications (5 total GIAC certifications), demonstrating comprehensive expertise across multiple cybersecurity domains.

SANS Offensive Operations Coin

SANS Offensive Operations Coin Winner (SEC504 Course)

2026

Awarded for winning the final capstone challenge of SEC504: Hacker Tools, Techniques, and Incident Handling on the last day of class. The challenge tests comprehensive understanding of offensive security techniques and incident response.

SANS Lethal Forensicator Coin

SANS Lethal Forensicator Coin Winner (FOR508 Course)

2024

Awarded for winning the final capstone challenge of FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics on the last day of class. Demonstrates advanced skills in memory forensics, threat hunting, and incident investigation.

CSOM Gold Challenge Coin

CSOM Gold Challenge Coin

2026

Awarded by Centri (formerly Security Blue Team) for passing the Certified Security Operations Manager (CSOM) exam with a score of 97% — earning the rare gold coin reserved for candidates scoring 90%+ on their first attempt. CSOM covers how to plan, build, and mature security operations teams: performing threat modelling to identify threats to the organization, understanding security operations functions and the value they bring, building a SOC across people, technology, and processes, conducting maturity assessments for SOC, IR, Hunting, and CTI teams, and harnessing metrics for reporting and identifying issues. Aimed at security professionals with 2+ years' experience, it forges technical managers by developing both management principles and hands-on technical skills.

BTL2 Challenge Coins

BTL2 Silver Challenge Coin

2024

Awarded by Centri (formerly Security Blue Team) for passing the Blue Team Level 2 certification exam. BTL2 focuses on advanced threat hunting, log analysis, and incident response across enterprise environments.

Research & Community Projects

⚔️

MITRE ATT&CK Contributor

Contributed T1546.018 — Event Triggered Execution: Python Startup Hooks to the MITRE ATT&CK framework, documenting a persistence technique used by threat actors.

View Technique →
📋

Insider Threat Matrix Contributor

Contributed AR5 (Uninstalling Software) and DT095 detection techniques to the Insider Threat Matrix, helping organizations detect insider risk behaviors.

View Contribution →
🦠

Malware Analysis Research

Published static & dynamic malware analysis research on Mustang Panda TONESHELL malware, documenting TTPs, C2 infrastructure, and detection opportunities.

Read Analysis →
🥇

BTLO Global #1

Ranked #1 globally on Blue Team Labs Online (BTLO) CTF platform across all defenders. Authored walkthroughs for CTF challenges and investigations.

View Profile →
🎓

TryHackMe Top 1%

Ranked in the top 1% of users globally on TryHackMe. Authored walkthroughs for CTF challenges covering DFIR, threat hunting, and security analysis.

View Profile →
🔬

Lab Environment Research

Built malware analysis and DFIR lab environments to analyse persistence mechanisms, attacker behaviour, and anti-analysis techniques. Continuous experimentation across endpoint telemetry, memory forensics, cloud investigations, and detection engineering workflows.

🎖️

GIAC Advisory Board

Awarded by GIAC for achieving an outstanding score (90%) on the GCFA exam, demonstrating expert-level knowledge in forensic analysis and incident response.

2024
🛠️

Technical DFIR Projects

Built forensics and incident response tools including AWS Log Analyzer, CrowdStrike Log Analyzer, Command Line Analyzer, and Enterprise Grade Browser Forensics Suite to accelerate investigation workflows.

📝

Write-ups & Presentations

Exam reviews, conference presentations, and CTF write-ups published on PHK Knowledge Sharing.

View All Write-ups →
🎙️

BSides Myanmar 2025 Speaker

Presented "The Art of Windows Memory Forensics" at BSides Myanmar 2025, covering memory acquisition, analysis techniques, and malware detection in volatile memory.

2025

Certifications

GIAC / SANS

8 certifications

🛡️ Verify
GIAC Security Expert (GSE) GSE In Progress
GIAC Security Professional (GSP) #506
GSP
GIAC Assurance in Security Architecture and Engineering (GASAE) GASAE In Progress
GIAC Experienced Forensic Analyst (GX-FA) GX-FA
GIAC Experienced Forensic Examiner (GX-FE) GX-FE
GIAC Experienced Incident Handler (GX-IH) GX-IH In Progress
GIAC Certified Forensic Analyst (GCFA) GCFA
GIAC Certified Forensic Examiner (GCFE) GCFE
GIAC Certified Incident Handler (GCIH) GCIH
GIAC iOS and macOS Examiner (GIME) GIME
GIAC Experienced Intrusion Analyst (GX-IA) GX-IA In Progress
GIAC Certified Intrusion Analyst (GCIA) GCIA In Progress

Centri / Security Blue Team

2 certifications

🛡️ Verify
Blue Team Level 2 (BTL2) BTL2
Certified Security Operations Manager (CSOM) CSOM

TryHackMe

2 certifications

🛡️ Verify
TryHackMe Security Analyst Level 1 (SAL1) SAL1
TryHackMe Security Analyst Level 2 (SAL2) SAL2

Hack The Box

1 certification

🛡️ Verify
HTB Certified Defensive Security Analyst (CDSA) CDSA

CyberDefenders

1 certification

🛡️ Verify
Certified CyberDefender Level 1 (CCDL1) CCDL1

INE / eLearnSecurity

1 certification

🛡️ Verify
INE Certified Threat Hunting Professional (eCTHP) eCTHP

EC-Council

1 certification

🛡️ Verify
Computer Hacking Forensic Investigator (C|HFI) C|HFI

ISC²

1 certification

🛡️ Verify
ISC2 Certified in Cybersecurity (CC) CC

Education & Courses

Degrees

Master of Information Technology

James Cook University, Australia

2019 – 2021

Master of Business Administration

James Cook University, Australia

2019 – 2021

Bachelor of Science (Computing)

Edinburgh Napier University, UK

2018

HND in Computing & Systems Development

Info Myanmar University, Myanmar

2015 – 2017

Courses

FOR508 — Advanced Incident Response, Threat Hunting & Digital Forensics

SANS Institute

FOR518 — Mac and iOS Forensic Analysis and Incident Response

SANS Institute

SEC504 — Hacker Tools, Techniques & Incident Handling

SANS Institute

Investigation Theory

Applied Network Defense — Chris Sanders

Hunting Adversary Infrastructure

IntelOps

Skills & Tooling

SIEM

SplunkMicrosoft SentinelGoogle Chronicle IBM QRadarCrowdStrike Next-Gen SIEM

EDR / XDR

CrowdStrike EDRMicrosoft Defender XDR Cybereason EDRTrellix HX

Digital Forensics

Windows ForensicsLinux ForensicsmacOS Forensics Memory ForensicsiOS Forensics

Cloud IR

AWSAzureGCP

Threat Intelligence

Threat IntelligenceHunting Adversary Infrastructure Supply Chain Compromise AnalysisStatic & Dynamic Malware Analysis

Other

Threat HuntingPurple TeamingOT/ICS IR AI AutomationProofPoint Akamai WAFZscaler ZIARapid7 VMTrellix ETP

Development

PythonBashPowerShell HTMLCSSPHPMySQLC++

Get in Touch

Open to collaboration, speaking opportunities, and interesting security problems.