SOC
HEAD OF SECURITY OPERATIONS · EXPRESSVPN

Cherlynn
Cha

Threat hunter, incident responder, and security engineer. I build security operations from the ground up.

BSc Computer Science · MSc Artificial Intelligence · PhD in being a nerd

View work → Get in touch
8+
years in security
018
built a SOC from scratch
1,300+
endpoints under detection
24/7
always-on coverage
00 / Profile

Security, built from the ground up.

I was part of the founding team that built ExpressVPN's Security Operations Center from nothing — and I've spent the years since scaling it into a 18-person, 24/7 operation spanning threat hunting, detection engineering, security engineering, and incident response.

My work spans the deeply technical and the strategic: hunting novel threats across endpoint, network, and cloud telemetry, architecting AI-driven automation, standing up detection-as-code pipelines, and driving security compliance across half a dozen frameworks. Before ExpressVPN, I cut my teeth at JPMorgan Chase, Accenture, and BHP.

01 / Experience

Where I've operated.

ExpressVPN

2020 — Present
Head of Security Operations · 2025 SOC Manager · 2023–25 Lead Threat Hunter · 2023 Senior Threat Hunter · 2022–23 Threat Hunter · 2020–22
Now

Architecting the SOC's AI roadmap.

I built the AI agent now working alongside our L1 tier, re-checking alerts, tickets, and ~30 dashboards to catch the outages and escalations that slip through the cracks.

Grew a 5-person threat-hunting team into a 18-person, 24/7 tiered SOC, adding an L1 monitoring tier and a dedicated brand-protection capability.

Built a detection-as-code pipeline where every detection is version-controlled, peer-reviewed, and tested before it ships, plus a Claude skill that opens PRs to create and refine detections.

Drove compliance across ISO 27001, SOC 2, PCI-DSS, the EU Cyber Resilience Act, and UK Cyber Essentials, taking each from gap assessment through certification and audit.

Deployed Carbon Black EDR across 500+ workstations and 800+ servers, and built a security data lake to centralize logs and cut SIEM costs.

Designed a Threat Modeling program and an ML anomaly-detection model sifting millions of data points to surface novel threats.

JPMorgan Chase

Attack Analyst

Triaged and investigated SIEM events with a cross-region analyst team; analyzed and mitigated malicious activity across the firm.

2019–20

Accenture

Security Analyst

Managed a government Federated Identity service for 5M+ users; delivered an RFID 2FA + SOC monitoring PoC exhibited at Asian Utility Week 2018.

2018–19

BHP

Threat & Vuln. Mgmt

Scanned and assessed open vulnerabilities across web applications and internal servers using Qualys.

2017
Education
MComp, Artificial Intelligence
National University of Singapore · 2020–2022
Education
BComp, Computer Science
National University of Singapore · 2014–2018
02 / Side Projects

Things I'm building.

● LIVE parrotjobs.com ↗

Parrot Jobs

A niche job board built for cybersecurity careers — connecting practitioners with roles that actually fit, across SOC, security engineering, penetration testing, cloud security, and GRC.

Job Board Cybersecurity Community
PRE-RELEASE coming soon

LingoDuel

A competitive, gamified language-learning app. Learn vocabulary and grammar through story-driven scenarios, starting with beginner Chinese (HSK1), while battling in real-time PvP matches or against AI "ghost" opponents to earn XP, streaks, and leaderboard ranks.

Built language-agnostic from day one, with Dutch and more on the roadmap alongside sound design, a story overhaul, and a training mode.

Next.js React Native · Expo Supabase Real-time PvP
03 / Speaking & Writing

On stage & in print.

Speaking
Featured writing
TechCrunch · Jan 2024
A startup's guide to cyberthreats — threat modeling and proactive security ↗
TechRepublic · Aug 2021
Behind the scenes: a day in the life of a cybersecurity threat hunter ↗

More talks & writing on the way — follow along on LinkedIn ↗

04 / Toolkit

Skills & certifications.

Programming
Python · Java · JavaScript · SQL
Platforms
AWS · Kubernetes · Terraform
Security tooling
Splunk · Carbon Black EDR · OSQuery · Burp Suite · Wireshark · pentest tooling
Certifications
AWS Solutions Architect Associate AWS Security Specialty SANS GIAC GCIA ISO/IEC 27001 Associate
05 / Contact

Let's
talk.

Hiring, speaking, collaborating on a side project, or just want to talk about security — my inbox is open.

cherlynn@live.com.sg LinkedIn ↗