![]()
Principal Software Engineer
Obsidian Security ¡ Full-time
May 2022 - Present
⢠3 yrs 1 mo![]()
Executive Mischief Consultant
Mischief Industries ¡ Self-employed
Jul 2016 - Present
⢠8 yrs 11 mos![]()
Sr. Manager of Applied Research
Cylance Inc. ¡ Full-time
Jul 2016 - Sep 2020
⢠4 yrs 3 mosLead a distributed team of eight (8) in researching new software security techniques for Windows, macOS, and Linux stop computer exploits and malicious software. Provided subject matter expertise and thought leadership for the C-suite, sales engineers, and customer support operations.
⢠Designed a patent-pending method for defeating a malicious software technique to protect customers from zero-day exploits and malware
⢠Architected a fully undetectable malware mutation platform to validate machine learning model efficacy and evade antivirus engines to demonstrate competitor weaknesses in sales engineering demonstrations
⢠Researched new techniques for bypassing anti-exploitation mitigations in security software and evading next-gen endpoint detection and response (EDR) software
⢠Authored dozens of expert analysis and commentary of new vulnerabilities and security incidents for customers, information security journalists, and marketing efforts
⢠Facilitated cross-platform and cross-team research projects to improve collaboration and professional development growth of team members
InSecurity Podcast: Jeff Tang on Demystifying âFilelessâ Malware
Cylance Detects IE Scripting Engine Memory Corruption Vulnerability (CVE-2018-8653)
InSecurity Podcast - Jeff Tang: Stop Trying to Make âWeaponizedâ Cyber Happen
![]()
Chief Scientist
VAHNA ¡ Full-time
Mar 2013 - Jun 2016
⢠3 yrs 4 mosCo-founder of a start-up growing to $1M in revenue in 12 months with 5 employees to create a next-generation endpoint security platform. Collaborated with customers to understand business security problems and engineer technology solutions.
⢠Architected core security platform to deliver a minimum viable product to customers in 3 months
⢠Built a cross-platform (Windows, macOS, Linux) host agent to establish secure network communications, gather telemetry information, and perform automated remediation tasking
⢠Engineered a cloud-based data pipeline for ingesting and analyzing large volumes of telemetry data to correlate and identify malicious activity in near real-time
⢠Conducted incident response investigations to identify a foreign nation state intelligence actor exfiltrating sensitive data and assisted with the Federal Bureau of Investigationâs (FBI) case
⢠Designed and instructed a variety of beginner to expert level cybersecurity training classes: Advanced Penetration Testing, Assembly for Reverse Engineers, Hacking with Python, Basic Malware Analysis
Desmond invests in cyber security firm
![]()
CNO Developer
ManTech ¡ Full-time
Oct 2011 - Mar 2013
⢠1 yr 6 mos![]()
Global Network Exploitation and Vulnerability Analyst
National Security Agency ¡ Full-time
Jan 2009 - Sep 2011
⢠2 yrs 9 mos![]()
Systems Administrator
FotoFlexer
Jan 2007 - Dec 2008
⢠2 yrs¡ Architected a highly available and scalable server infrastructure for FotoFlexer.com utilizing geographically load-balanced DNS, reverse proxies, and SQL replication
¡ Prototyped a FotoFlexer.com extension to mobile phones for photo uploads via MMS
¡ Performed a cost-benefit analysis for offloading computational workloads to cloud computing
¡ Triaged security incidents and worked with developers to implement countermeasures without impacting user experience
![]()
Database Programmer & Systems Administrator
UC Berkeley
Mar 2006 - Dec 2008
⢠2 yrs 10 mos¡ Developed a Flash/PHP/MySQL backend for Bounce, a new media conversation game presented at ZeroOne San Jose / International Symposium of Electronic Arts 2006
¡ Researched AI concepts to identify and devalue malicious behavior attacking collaborative filtering projects: Eigentaste (Jester), Donation Dashboard
¡ Coordinated with network administrators to investigate possible security incidents and prevent future attacks
¡ Identified nondeterministic bugs in several research projects and collaborated with the team members to develop and deploy patches
![]()
Summer Technology Analyst - Critical Infrastructure Engineering
Goldman Sachs
Jun 2008 - Aug 2008
⢠3 mos¡ Constructed a web based administrative system for Kerberos credential management
¡ Designed a data transformation service framework to integrate information feeds and data schemas for LDAP, Kerberos, and Sybase
¡ Implemented an incremental update process for the corporate directory to reduce the amount of stale data