Skip to content

Latest commit

 

History

163 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

Ievgen (Jack) Bondarenko

Security Engineering · Vulnerability Research · Detection Engineering · AI Infrastructure

I work across the boundary between how systems fail and how defenders detect that failure.

On the research side, I audit source code in AI infrastructure, container runtimes, cloud integrations, and security-sensitive backend systems. That work has led to published vulnerabilities, Google VRP findings, coordinated disclosures, and upstream security fixes.

On the defensive side, I build controls that are tested end to end rather than treated as configuration: detection logic, controlled triggering, incident generation, investigation evidence, false-positive measurement, and deployment as code.

More recently, those two sides have started to converge in my work: security tooling and detection systems that combine source-level analysis, operational telemetry, reproducible engineering, and ML where it improves the security workflow.

3 CVE published 22 merged PRs

🔬 Selected Work

Open-source ML network-flow detector that turns unlabeled CICFlowMeter-compatible traffic into deterministic analyst-facing security incidents.

The v0.1 release includes a frozen temporally validated model, causal feature pipeline, deterministic incident aggregation, versioned incident-v1 output, Python CLI, Docker distribution, real-model end-to-end regression, and public CI.

The project is intentionally explicit about its limits: usable as a research/evaluation product, but not presented as production-ready.

AI & Infrastructure Security Research

  • GHSA-7gwp-5pfp-969j — MLflow, Critical: unauthenticated full-read SSRF through redirect and DNS-rebinding weaknesses in webhook delivery.
  • CVE-2026-46517 / GHSA-9xq9-36w5-q796 — vulnerability in lmdeploy, an AI model inference server, resolved through coordinated disclosure.
  • Google Cloud VRP award — SSRF, API-key disclosure, and response forgery through a per-request baseUrl override affecting Gemini and Vertex AI client paths.
  • llm-serving-security — security reference for the LLM serving stack, covering vulnerability classes and hardening across vLLM, Triton, lmdeploy, SGLang, BentoML, Ollama, and TGI.

Detection Engineering

azure-sentinel-detection-engineering

Detection-as-Code on Microsoft Sentinel and Defender: KQL detections mapped to MITRE ATT&CK, controlled triggers, incident generation, investigation evidence, false-positive measurement, and PR-gated deployment through GitHub Actions and OIDC.

🧩 Research & Upstream Engineering

Merged security and hardening work across projects including:

  • Google gVisor
  • Kubernetes
  • Firecrawl
  • Azure Sentinel
  • Swift Package Manager
  • OSV-Scanner
  • Tink

The work spans container hardening, validation boundaries, race conditions, crash handling, sandbox behavior, shared-memory security, SSRF defenses, and protocol/API behavior.

Coordinated disclosure experience includes GitHub Security Advisories, Google VRP, Microsoft MSRC, and CERT/CC VINCE.

🛡 Defensive Engineering

Hands-on work spans cloud, endpoint, identity, and network telemetry:

  • Microsoft Sentinel, Defender XDR, Defender for Endpoint, Entra ID
  • KQL, Sigma, MITRE ATT&CK
  • Security Onion, Suricata, Zeek, Wazuh
  • Elastic / Kibana
  • pfSense
  • Windows Server / Active Directory
  • Python and PowerShell

I have also worked through live red-team / blue-team engagements involving segmented WAN/DMZ/LAN environments, IDS/IPS, firewall policy, honeypots, incident response, and maintaining service availability under sustained attack.

🎯 Current Focus

  • Vulnerability research: source-level analysis of AI infrastructure, cloud integrations, container boundaries, and security-sensitive backend systems.
  • Detection engineering: tested detections, Detection-as-Code, SIEM/XDR engineering, and operational signal quality.
  • AI infrastructure security: model-serving systems, inference infrastructure, isolation boundaries, and attack surfaces created around AI workloads.
  • Security tooling: reproducible systems that connect detection, program analysis, automation, and ML without hiding the evidence behind the result.
  • Security & compliance engineering: SOC 2, ISO 27001, HIPAA, and NIST controls implemented as measurable operational systems rather than policy-only artifacts.

📜 Certifications

🛠 Tools

Research

Detection & cloud

Platforms

🤝 Connect

Open to remote roles and selected technical work in security engineering, vulnerability research, detection engineering, and AI infrastructure security.

Website: ibondarenko.com
LinkedIn: ievgen-bondarenko-b13098241
Email: hi@ibondarenko.com

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages