Aaron SawitSecurity engineer · Singapore

Aaron Sawit

Security engineer · Singapore

Security engineer in Singapore with a first class computer science degree and the GCIH. My day job is security risk and compliance. My training is incident handling and hands-on attack and defence. In my own time I build and run real systems, including a suite of free learning tools used by students and teachers, and I have tutored special needs students for six years, so I am used to explaining hard things simply.

See the work

Experience

Cybersecurity Engineer, GovTech Singapore

Jul 2025 to present

Cybersecurity Specialist, Red Alpha Cybersecurity

Jun 2024 to Jul 2025

  • Full-time blue team and red team training programme. Earned the GIAC Certified Incident Handler (GCIH) through SANS SEC504.
  • Completed the Hack The Box SOC Analyst path and reached Level 5 of the CSIT TISC capture-the-flag.

Private Tutor, self-employed

May 2020 to present

  • One-to-one tutoring for primary and lower-secondary special needs students, referred by a specialist from the Dyslexia Association of Singapore.
  • The reason the Versed tools exist: I build what my own students need and keep it free.

Academic Coach, RoboThink

Jan 2022 to Jan 2023

  • Taught robotics and beginner coding to children, adapting each lesson to the child's pace and reporting progress to parents.

Head Finance Clerk, Singapore Armed Forces

Feb 2018 to Feb 2020

  • Handled about $250K in transactions a year to audit standard, and managed procurement with external vendors.

Skills

Detection and response
Log analysis, SIEM (Elastic Stack), Sysmon and Windows event logs, Sigma rules mapped to MITRE ATT&CK, incident handling (SANS SEC504), Snort, phishing analysis
Security tools
Nmap, Wireshark, tcpdump, Scapy, Netcat, Metasploit, Hashcat, John the Ripper, Mimikatz, CrackMapExec, enum4linux, Ligolo-ng, YARA, Splunk, Elastic, Sysmon, Snort, PowerShell
Infrastructure and network
Linux, Docker and Compose, systemd, iptables and policy routing, WireGuard and Tailscale, DNS filtering, backups and monitoring, infrastructure as scripts
Cloud and application
Cloudflare Workers, Durable Objects, D1 and KV, Pages Functions, TypeScript, authentication with scrypt and cookie sessions, rate limiting and abuse controls, CSP and security headers
Programming
Python (tested CLI tools, log pipelines), TypeScript and JavaScript, shell
Frameworks
MITRE ATT&CK, NIST CSF, ISO 27001

Selected work

Versed

Product suite, solo · 2026, ongoing

  • Four free learning tools for students, tutors and teachers, designed, built and run by one person on Cloudflare's edge. No sign-up to play, no tracking, no budget.
  • 4 products live · 0 accounts needed to play · 1 person: design, code, ops

One box, forty services

Infrastructure, self-hosted · 2026, ongoing

  • A recycled gaming PC running forty-odd containers for my family: photos, passwords, media, DNS filtering, game streaming and local AI. Reachable from anywhere, with no port open to the internet.
  • 40+ services · 0 ports open to the internet · 14 days of restorable backups

Local AI on 2017 hardware

Performance engineering · 2026

  • Getting a 35-billion-parameter model to 66 tokens a second on two GTX 1080 Tis by measuring every assumption, including the ones in the documentation.
  • 46 to 71 tokens a second · +44% on the same hardware · 1 crash found before it shipped

Detection tooling

Blue team, Python · 2024 to 2025

  • Small, tested tools from my defensive security practice: a log triage pipeline that pairs rule-based detection with an LLM classifier, a phishing link analyser, and hand-written Snort and iptables rules.
  • 4 Sigma rules, ATT&CK mapped, green in CI · 36 offline tests on the triage tool · 3 public repositories with passing builds

Education

BSc (Hons) Computer Science, First Class Honours

Coventry University, United Kingdom · 2023

Diploma in Information Technology

PSB Academy, Singapore · 2021

Training and certification

GIAC Certified Incident Handler (GCIH)

SANS SEC504: Hacker Tools, Techniques and Incident Handling

Hack The Box Academy

SOC Analyst path: SIEM, Windows event logs, incident handling

Red Alpha

Cybersecurity specialist training, Singapore

CSIT TISC CTF

Reached Level 5

Writing