
Roni Chen
Verified Expert in Engineering
Security Engineer and Developer
Toronto, ON, Canada
Toptal member since May 12, 2026
Roni is a security engineer with 7+ years of experience in detection engineering, threat hunting, incident response, and fraud prevention across enterprise environments. She specializes in building scalable security analytics, SIEM detections, and automation workflows using Splunk, Python, and cloud technologies. Roni improves visibility, reduces false positives, and strengthens security operations.
Portfolio
Experience
- SIEM - 8 years
- Splunk - 7 years
- Incident Response - 7 years
- Security Orchestration, Automation, and Response (SOAR) - 7 years
- IT Security - 6 years
- Fraud Detection, Anomaly Detection - 5 years
- Cyber Threat Hunting - 4 years
- SOC 2 - 4 years
Preferred Environment
Windows, Linux, Splunk, Python, Windows PowerShell, AWS IAM, Visual Studio Code (VS Code), CrowdStrike, Git, Reports
The most amazing...
...thing I've built is a Python-based identity risk and fraud detection framework that identifies anomalies and improves real-time security decisioning.
Work Experience
Cybersecurity & Cloud Consultant
Marcviews
- Conducted technology risk assessments across AWS and Azure environments, identifying critical security gaps and reducing organizational risk exposure.
- Designed and implemented cloud security baselines aligned with SOC 2 and ISO 27001 requirements, strengthening security governance and compliance readiness.
- Developed automated detection and response workflows using Python and PowerShell, improving Mean Time to Detect (MTTD) by 40%.
- Performed threat hunting and vulnerability assessments, identifying high-risk exposures and supporting remediation efforts across cloud environments.
- Collaborated with infrastructure and engineering teams to enhance cloud security controls, access management, and monitoring capabilities.
- Supported audit and compliance initiatives by documenting security controls, validating remediation activities, and preparing evidence for assessments.
- Delivered security awareness training and SOC operational playbooks, improving incident response consistency and organizational security maturity.
Senior Information Security Analyst
Tata Consultancy Services
- Led Tier 3 security incident investigations across enterprise environments, coordinating end-to-end breach response activities.
- Performed advanced threat hunting and log analysis using Splunk and QRadar across large-scale infrastructure.
- Developed and tuned detection rules and SOC playbooks, reducing false positives and improving alert accuracy.
- Conducted forensic investigations on Windows and Linux systems, improving incident response efficiency and time-to-detection.
- Enhanced security monitoring workflows by correlating multi-source telemetry and improving visibility across enterprise systems.
Security Compliance & Fraud Prevention Analyst
Leumi Bank
- Conducted fraud and AML investigations within a regulated financial environment, analyzing suspicious activity patterns and high-risk transactions.
- Evaluated and enhanced the effectiveness of KYC processes, transaction monitoring systems, and fraud detection controls.
- Supported PCI DSS compliance initiatives and internal/external audit processes, ensuring adherence to regulatory and security standards.
- Contributed to enterprise risk assessments and regulatory reporting across multiple stakeholders.
- Leveraged data-driven anomaly detection techniques to identify emerging fraud patterns and reduce overall financial exposure.
Network Security Specialist
Hot
- Monitored network traffic and system activity to detect anomalies, service disruptions, and potential security threats.
- Investigated and escalated suspicious network behavior, supporting incident triage and security response processes.
- Performed troubleshooting across TCP/IP, DNS, and routing infrastructure to maintain secure and stable network operations.
- Documented network incidents and security findings to improve visibility and support downstream security analysis.
- Developed foundational expertise in network security monitoring, access control, and infrastructure security operations.
Experience
Behavioral Biometrics Fraud Detection Platform
https://api.aye-verify.com/developerI implemented role-based access controls (RBAC), automated workflows, and reporting capabilities to improve operational efficiency and strengthen governance over organizational assets.
I also developed dashboards and analytics features that provided real-time visibility into asset utilization, compliance posture, and risk exposure across the environment.
Asset Management & Compliance Platform
I also implemented role-based access control (RBAC), automated workflows, and dashboards to provide real-time visibility into asset utilization, compliance posture, and risk exposure.
Mini EDR - Threat Detection & Telemetry Correlation Engine
The project focused on:
• Security telemetry collection and normalization
• Detection engineering and behavioral analysis
• Process/network correlation
• Suspicious execution path monitoring
• Authenticode signature validation
• Endpoint visibility and forensic logging
• Risk scoring and anomaly detection
• Structured JSON event generation for SIEM ingestion
I implemented detection logic to identify suspicious execution patterns, external communications, and unsigned binaries while reducing noisy alerts through deterministic correlation.
The system was designed with a security operations mindset to simulate real-world EDR visibility, detection workflows, and incident triage processes.
Education
Bachelor's Degree in Computer Software Engineering
The Open University of Israel - Israel
Certifications
AWS Certified Security
Amazon Web Services (AWS)
CompTIA Security+
CompTIA
Skills
Libraries/APIs
REST APIs, Auth
Tools
Splunk, Logging, AWS CloudFormation, AWS IAM, Azure Key Vault, BigQuery, Git, IBM QRadar, Amazon CloudWatch, AWS CloudTrail, HashiCorp Vault, VPN, Terraform
Languages
Python, C, Java, Bash, JavaScript
Paradigms
Security Orchestration, Automation, and Response (SOAR), Role-based Access Control (RBAC), Penetration Testing, DevOps, Automation, Web Architecture, User Behavioral Analytics (UBA), DevSecOps, HIPAA Compliance
Platforms
Vanta, Windows, Amazon Web Services (AWS), YouTube, Linux, Visual Studio Code (VS Code), CrowdStrike, Docker, Kubernetes, Azure, Google Cloud Platform (GCP), Apache Kafka, CrewAI
Industry Expertise
Cybersecurity
Frameworks
Windows PowerShell
Storage
Microsoft Entra ID, Datadog, PostgreSQL, Data Validation
Other
SIEM, Incident Response, Security Monitoring, MITRE ATT&CK, Security Analytics, Fraud Detection, Anomaly Detection, SOC 2, Fraud Detection, Threat Detection and Response (TDR), IT Security, Endpoint Security, Network Security, Access Control, Vulnerability Management, NIST, Identity & Access Management (IAM), Security, Cybersecurity Operations, Tactics, Techniques, and Procedures (TTP), Data Security, Red Teaming, Endpoint Detection and Response (EDR), Cyber Forensics, Threat Analytics, Threat Modeling, Forensics, IT Governance, Security Information and Event Management (SIEM), OWASP, Web Application Security (Web AppSec), Security Engineering, Vulnerability Assessment, Application Security, Endpoint Protection, IDS/IPS, Security Assessment, Auditing, Web Security, AI Security, Large Language Models (LLMs), AI Trust, Risk and Security Management (AI TRiSM), Incident Handling, Monitoring, IT Automation, Observability, Cyber Threat Hunting, Automations, Compliance, Authentication, Malware Analysis, Cloud Security, Zero Trust, ISO 27001, Cloud Infrastructure, Offensive Security, IT Audits, Quality Assurance (QA), Risk Models, Architecture, Security Audits, Artificial Intelligence (AI), Azure Data Factory (ADF), Azure Databricks, Unity Catalog, Infrastructure, Fivetran, Cloud Platforms, Information Security Management Systems (ISMS), Proxies, Firewalls, System Administration, SOC 1, PCI DSS, Intrusion Prevention Systems (IPS), Intrusion Detection Systems (IDS), SecOps, Single Sign-on (SSO), Helpdesk, Microsoft 365, IT Administration, Static Application Security Testing (SAST), Google, Reports, Reporting, General Data Protection Regulation (GDPR), Software Architecture, Documentation, Policies & Procedures Compliance, Security Policies & Procedures, FastAPI, Web App Security, IT operation, AI Agents, Prompt Injection, Agentic AI, OWASP Top 10, Technical Leadership, Cloud, Industry.Technology.Identity & Access Management (IAM), Architecture.Cloud Architecture, OAuth, Application Monitoring, Incident Management, SaaS, IT Service Management (ITSM), Log Management, Data Structures, Database Systems (SQL), Computer Networking, Operating Systems, Software Engineering, Log Analysis, Digital Forensics, Technology Risk Assessments, Data Protection, AML, Risk Analysis, Financial Crime Investigation, Data Analysis, Financial Risk Analysis, Security Automation, Threat Identification, Security Operations Centers (SOC), TCP/IP, Network Troubleshooting, Infrastructure Monitoring, ISP Network Operations, DNS, Incident Analysis, Risk Management, Security Compliance, CIA triad, encryption basics, secure protocols, Vulnerability Scanning, AWS Cloud Security, Risk Assessment, Infrastructure Security, Security Architecture, Secret Management, Cloudflare, CI/CD Security, Microsoft Azure, RBAC (Kubernetes RBAC), Container Security, Hetzner, Solution Architecture, ISO 27701, CI/CD Pipelines, LangChain, Startups, Agile Software Development.Integration.APIs, Industry.Technology.Technical Program Management, Dynamic Application Security Testing (DAST)
How to Work with Toptal
Toptal matches you directly with global industry experts from our network in hours—not weeks or months.
Share your needs
Choose your talent
Start your risk-free talent trial
Top talent is in high demand.
Start hiring