YANG GAO

Security QA Engineer · Automated Red Teaming

gy15901580825@gmail.com · linkedin.com/in/yang-gao-4bab21177 · (408) 394-2149

Security QA Engineer and Automated Red Teaming researcher in cloud-native security, adversarial ML, and AI safety. Lead architect of GenAI, FortiCNAPP’s automated red teaming platform. Focuses on scalable red teaming pipelines that find failure modes in LLM-powered security systems and convert findings into production fixes.

Skilled in threat modeling, adversarial ML, and building scalable automation. Approaches security from an attacker’s perspective, builds reproducible pipelines that run continuously in production, and communicates findings clearly across research, engineering, product, and policy teams.

Technical Skills

AI/ML Security

LLM Red Teaming, Automated Red Teaming (ART), Adversarial ML, OWASP Top 10 for LLM, Classifier Jailbreak Discovery, Threat Modeling, AI Reliability Evaluation, Model Robustness Testing

AI Infrastructure

Azure OpenAI, OpenAI API, LLM Inference Pipelines, Model Supply Chain Security, RAG System Testing, AI API Gateway Security

Cloud & Security

AWS, Azure, GCP, Kubernetes, Docker, Terraform, Ansible, CNAPP, CSPM, CWPP, Zero Trust, SIEM

Languages & Tools

Python, Java, JavaScript/React, Playwright, Selenium, Jenkins, GitHub Actions, CI/CD, Ixia, Spirent

Security Domains

Automated Red Teaming, Adversarial ML, AI Safety Evaluation, Penetration Testing, Threat Simulation, Classifier Jailbreak Discovery, Cloud-Native Security, Network Security (TCP/IP, VLAN, OSPF, IPSec), FortiOS

Work Experience

Fortinet — Security QA Engineer
Jan 2020 – Present

GenAI — AI Red Teaming & Security Research (integrated with FortiCNAPP)

  • Automated Red Teaming Pipeline Architecture: Designed and led the technical direction for GenAI, FortiCNAPP’s automated red teaming system, building scalable pipelines that continuously probe LLM-powered security features for failure modes; engineered attack libraries covering prompt injection, jailbreaking, indirect prompt manipulation, classifier evasion, and multi-turn adversarial scenarios, converting findings into concrete robustness improvements shipped to production.
  • Threat Model-Driven Evaluation Design: Partnered with FortiCNAPP’s cloud security vertical teams to define AI threat models targeting catastrophic risk scenarios, including classifier jailbreak discovery for cyber-threat elicitation, RAG pipeline poisoning, and agent tool-use exploitation; designed reproducible experiments that prioritized the highest-risk, least-covered attack surfaces and fed results directly into classifier retraining.
  • Scalable Adversarial Automation & LLM Agent Security: Built production-grade automated red teaming infrastructure using LLM agents (Claude, GPT-4) as attack orchestrators; implemented multi-turn adversarial probing, tool-use exploitation scenarios, and chain-of-thought monitoring evasion probes against FortiCNAPP’s AI-powered threat detection classifiers; producing continuous, actionable vulnerability reports used directly by engineering and safety teams.
  • AI Infrastructure Security & Supply Chain Integrity: Evaluated model supply chain integrity, API gateway vulnerabilities, multi-tenant LLM isolation risks, and RAG pipeline injection vectors across FortiCNAPP’s cloud-hosted deployments on Azure and AWS; mapped all findings to OWASP LLM Top 10 and MITRE ATLAS frameworks; communicated threat models and remediation priorities to research, engineering, product, and policy teams.

FortiCNAPP — Cloud-Native Application Protection Platform

  • Security Alert Validation & Threat Simulation: Designed and implemented automated security alert validation frameworks by simulating real-world threat scenarios, including penetration testing activities, compromised host behaviors, and anomalous cloud operations; developed Python-based scripts to generate attack patterns (privilege escalation, lateral movement, suspicious API calls) and verified accurate detection, alert triggering, and correlation across cloud-native security modules, significantly improving alert fidelity and reducing false positives.
  • Security Automation & Attack Simulation Engineering: Architected and maintained scalable adversarial test automation using Python and Playwright; built attack pattern generation scripts for privilege escalation, lateral movement, and API abuse scenarios; integrated into GitHub/Jenkins CI/CD pipelines to enable continuous security validation with measurable regression reduction.
  • LLM Agent & Agentic Attack Research: Leveraged LLM agents (Claude Code, GPT-4, Codex) to develop adversarial tooling and agentic attack pipelines; built a 7-phase Lacework-to-Terraform reconciliation pipeline orchestrated by Claude Code sub-agents; used multi-agent setups to probe tool-use exploitation and model control failures.
  • Multi-Cloud & Infrastructure Testing: Leveraged deep expertise in AWS, Azure, and GCP to validate security functionalities; utilized Terraform and Ansible for Infrastructure as Code (IaC) deployment and conducted rigorous testing within Docker and Kubernetes environments.
  • Customer Success & Issue Resolution: Acted as a key technical liaison for the Technical Assistance Center (TAC) to reproduce and analyze complex customer-reported issues; orchestrated with the engineering team to prioritize bug fixes and ensure seamless resolution of production criticalities.
  • Network Protocol & Security Analysis: Performed deep-dive testing of TCP/IP protocols and networking devices (firewalls, routers, switches); applied advanced knowledge of FortiOS to optimize test coverage for network-layer security modules.
  • End-to-End Security Validation & Release Governance: Led comprehensive security validation lifecycle for FortiCNAPP’s Lacework integration, from threat modeling and architecture review to production release; ensured security features met adversarial robustness standards and delivered measurable risk reduction at each release milestone.
  • Cross-functional Collaboration: Authored detailed user stories and test cases based on feature requirements; collaborated with technical writers to refine product documentation and supported marketing/sales teams by ensuring product readiness for a competitive market.

FortiGate

  • End-to-End Quality Engineering: Led quality engineering initiatives for complex networking and distributed firewall systems, driving test strategy from requirement analysis and feature design through release validation, ensuring high reliability and performance of security appliances.
  • Automation Framework Development: Designed and maintained scalable automation frameworks using Python, covering functional, regression, and system-level testing; improved test coverage, execution efficiency, and debugging capabilities across multiple testing layers.
  • CI/CD & Test Automation Integration: Integrated automated test suites into CI/CD pipelines using Git, Gerrit, and Jenkins, enabling continuous testing, faster feedback loops, and improved release velocity.
  • Network Protocol Validation: Performed comprehensive validation across L2/L3 networking and application-layer protocols, including VLAN, OSPF, and IPSec, as well as HTTP, HTTPS, FTP, SSLVPN, and other TCP/IP-based protocols; ensured protocol correctness, interoperability, performance, and stability across diverse network topologies and real-world scenarios.
  • Performance & Scalability Testing: Executed large-scale performance and stress testing using tools such as Ixia and Spirent; identified system bottlenecks and collaborated with engineering teams to drive performance tuning and optimization.
  • Test Management & Quality Governance: Managed test planning, execution, and defect lifecycle using HP ALM, ensuring full traceability, risk assessment, and high-quality release standards across multiple product cycles.
  • System-Level Debugging & Troubleshooting: Worked extensively in Unix/Linux environments to perform deep system-level validation, debugging complex issues related to Ethernet interface bring-up, protocol failures, and hardware-software interactions.
  • Cross-functional Collaboration: Collaborated closely with development, hardware, and support teams to troubleshoot critical issues, align on quality goals, and deliver stable and production-ready networking solutions.
Alibaba — Senior Software Engineer
Dec 2015 – Dec 2019

Alibaba Cloud Mobile Testing Platform (MobileAPP Testing): Architected and maintained a comprehensive cloud-based mobile testing service platform, enabling users to conduct automated and manual testing on real devices and emulators through an intuitive web interface — delivering advanced mobile QA capabilities and accelerating time-to-market for enterprise clients.

Key Platform Features

  • Cloud-based real device testing infrastructure supporting iOS and Android applications
  • Automated test script execution using Selenium and Appium frameworks
  • Real-time device operation and remote control via web console
  • Performance monitoring and analytics (CPU, memory, battery, network metrics)
  • Automated test report generation with defect analysis and recommendations
  • Support for large-scale concurrent testing and multi-device compatibility validation

Stack & Leadership

  • Technology stack: Java/Spring Boot microservices (backend), React SPA (frontend), Selenium & Appium (test automation), Kubernetes (orchestration), Jenkins (CI/CD), native Android app for compliance testing.
  • Requirements analysis & solution design: Translated enterprise testing requirements into scalable platform features across mobile development teams, QA departments, and DevOps organizations in an agile environment.
  • Team leadership: Mentored junior engineers on testing best practices and platform architecture; optimized task allocation, sprint planning, and code-quality standards.
  • Documentation & customer success: Maintained technical documentation, API specs, and user guides; provided tier-1 support and rapidly resolved critical production issues.
Marvell — Senior Validation Engineer
Nov 2011 – Nov 2015
  • Factory Test Application Development: Designed and developed a comprehensive Java-based Android application for manufacturing validation and factory testing of Marvell chipset-based devices, implementing hardware testing modules (LCD verification, capacitive touch calibration, haptic vibrator, and other peripherals) to ensure devices met quality standards before shipping.
  • Performance & stress testing infrastructure: Built an Android stress testing app for stability and thermal validation under extreme load; a Java memory monitoring tool to track consumption across firmware builds and detect leaks; and a current (PUT) monitoring system for power-efficiency analysis.
  • Automation testing framework: Architected a PyUnit-based automation framework with a PyQT GUI client, enabling QA engineers to design, execute, and manage automated test scenarios without extensive programming — reducing manual overhead and improving repeatability.
  • Hardware integration & driver development: Integrated sensor drivers and hardware abstraction layers (accelerometer, gyroscope, proximity, ambient light), validating functionality and ensuring compatibility with Marvell chipset specifications.
  • Comprehensive sensor testing: Functional verification, precision calibration, performance benchmarking, cross-variant compatibility, environmental/thermal testing (-10°C to 60°C), integration, and automated regression testing across firmware builds.
  • Business impact: Reduced manufacturing defect rate via pre-shipment testing, accelerated time-to-market through automation, and enabled seamless chipset integration for OEM partners.

Education

Bachelor of Science in Computer Science — Tianjin University of Science & Technology, China