Last Deployment
George Mason University, USA 2026
TRUSTED BY LEADING FIRMS & GLOBAL CONFERENCES
ACCENTURE
George Mason University
BSides
Hacktivity
JFrog
Research-backed sessions for technical teams, security conferences, and executive audiences. Each topic is grounded in hands-on work – not recycled whitepapers or abstract best practices.
How cloud security actually fails in practice – identity misconfigurations, metadata service abuse, lateral movement paths, and why the shared responsibility model leaves bigger gaps than most teams realize.
The attack surface of AI systems – prompt injection, model poisoning, API exposure, and why the security assumptions we built for traditional software don’t map cleanly onto AI infrastructure.
What makes distributed systems resilient isn’t just redundancy – it’s understanding where the trust boundaries break. Sessions draw from real architecture reviews and research into how attackers move through complex systems.
What DevSecOps gets wrong, how to embed security that actually catches real threats, not just the ones that scanners are configured to find. Based on experience designing security into enterprise software delivery pipelines.
Container isolation is weaker than most engineers assume. This session covers how container breakouts actually happen, from real-world research into microservices, Kubernetes, and shared compute environments and what defenses actually hold.
Cloud identity is the new perimeter – and most organizations don’t know how it fails. This session covers IAM misconfigurations, service account abuse, cross-cloud identity paths, and how attackers chain these into full compromise.
Chen’s presentations satisfy both technical and business audiences. Bridging the gap between code-level vulnerabilities and executive risk management.
Talks Delivered
300+ (in-person, remote)
Technical Depth
L400+
Keynote Session
Chen is known for turning complex cloud research into clear, practical insight for engineering and security teams. His talks are grounded in independent research, real vulnerability discovery, and hands-on work breaking actual systems – not recycled vendor material.
The goal is not to overwhelm audiences with technical detail, but to give them a clear mental model of how attacks actually work and what those patterns mean for the decisions they make.
How models, APIs, and chatbots become attack surface. Moving beyond “AI for security” toward “security of AI”.
How offensive techniques are being automated and what this means for defenders trying to keep up with attack tooling that doesn't sleep.
What comes after basic container hardening - runtime behavior, supply chain attacks, and the security assumptions that break at scale.
Ready to level up your event or team? Whether it’s a conference, workshop, or internal session, send over the details and I’ll get back to you directly within 24 hours.