Mason Kim

Security Engineer | Platform Security & Adversarial Defense

Building security tools for adversarial eCommerce environments. Detection systems, WAF automation, and compliance tooling. Pursuing MS Cybersecurity at Georgia Institute of Technology. Terraform Associate, CEH, and CASE Java certified.

$94K Annual Savings
99.9% Availability
90%+ Threat Reduction

Research & Engineering Projects

Applied research and engineering in security, cloud infrastructure, and automation.

Commerce Abuse Defense (CAD)

February 2026 - Present

Open-source eCommerce abuse detection and scoring tool. Ingests Shopify order data and Cloudflare analytics to compute a weighted Abuse Score (0-100) across 6 detection rules. Auto-generates deployable WAF rules for Cloudflare and AWS WAF v2. Includes attack chain research documentation.

Python eCommerce Security Bot Defense AWS WAF Cloudflare

Kubernetes Security Hardening: CIS Benchmark Guide

February 2026

Comprehensive Kubernetes security hardening guide based on CIS Benchmark v1.8.0. Includes audit scripts, RBAC templates, network policies, and production-tested configurations.

Kubernetes CIS Benchmark Security DevSecOps

AWS WAF Security Framework

Production Deployment

Enterprise WAF implementation with Terraform IaC for global eCommerce platforms. Bot control, IP reputation, tiered rate limiting, and geo-blocking across CloudFront and ALB. Reduced bot traffic from 30%+ to under 3%.

Terraform AWS WAF CloudWatch DevSecOps

Log4Shell Exploit Analysis

Security Research

Reproduced and analyzed the CVE-2021-44228 vulnerability, demonstrating remote code execution, evasion techniques, and effective mitigations.

Java Log4j Security Research

E-commerce Security Enhancement

Jan 2025 - Present

Leading comprehensive security enhancement initiative for global e-commerce platform, implementing advanced threat detection and mitigation strategies.

Key Achievements

  • Conducted thorough penetration testing with external security firm
  • Implemented multi-layer security measures across 4 regions
  • Enhanced bot detection and prevention mechanisms
  • Strengthened API security and rate limiting
Security DevSecOps Penetration Testing API Security

Malware Analysis

CS 6262 - Project 2

Analyzed malware through static and dynamic techniques to extract indicators of compromise and recommend mitigations.

Malware Analysis Reverse Engineering Python

Certifications

Professional certifications in security, cloud, and application security.