I am a practitioner who started with penetration testing and builds information security management systems.
I handle annual security assessments of infrastructure, web, and applications for automotive manufacturers and energy companies.
I assessed them layer by layer and handled the same client’s ISMS-P certification through three rounds: initial, follow-up, and renewal.
I responded by independently carrying out the technical safeguards component.
Currently, as the information security officer in a one-person team, I am preparing for initial certification while establishing AI security governance.
I am designing the framework. Since this is an area where standards are still being established, starting with defining the scope of controls themselves,
It is a position where I must establish them myself.
I hold certifications as an Engineer Information Security, CPPG, and ISO/IEC 27001 Auditor, and at Dongguk University’s International Information Security Department,
I am researching leakage paths in AI environments and comparing them against authentication criteria in the Graduate School’s Department of Artificial Intelligence Security.
5 years and 9 months of experience. Client names and vulnerabilities actually discovered are subject to confidentiality, so in lectures
do not cover them in lectures.