Board Members
Mars Cheng is a Head at TXOne Networks' Cyber Threat and Product Defense Center, where he oversees product security incident coordination and response, threat detection operations, and advanced threat research. He also serves as Vice Chairman of the Association of Hackers in Taiwan and is the founder of the HITCON CISO Summit, which he served as General Coordinator from 2023 through 2026, working to strengthen collaboration among the security community, industry, and government while building practical bridges between Taiwan and the international community. In addition, Mars is a visiting lecturer at the NATO Cooperative Cyber Defence Center of Excellence (CCDCOE) and serves as a cybersecurity auditor for the Executive Yuan's National Information and Communication Security Taskforce (NICST), the Ministry of Economic Affairs, and the Ministry of Digital Affairs, contributing to joint efforts by Taiwan and NATO to strengthen critical infrastructure and government cybersecurity.
Mars has delivered more than 65 presentations at international cybersecurity conferences, including Black Hat USA / Europe / MEA, RSA Conference, DEF CON, CODE BLUE, FIRST, HITB, HITCON, Troopers, NOHAT, SecTor, S4, SINCON, ROOTCON, ICS Cyber Security Conference (Asia and USA), CYBERSEC, CLOUDSEC, and VXCON. A dedicated cybersecurity educator, he has taught more than 30 training courses for organizations including Global Cybersecurity Camp (GCC) 2024 and 2026, Taiwan's Cybersecurity Elite Talent Training Program (NICS program), the Ministry of National Defense, the Ministry of Economic Affairs, the Ministry of Education, the Ministry of Finance, HITCON Training, and numerous private enterprises.
His research focuses on ICS/SCADA security, enterprise network security, threat hunting, and emerging cybersecurity issues. To date, he has been credited with more than 10 CVE IDs and has published three papers on applied cryptography in SCI-indexed journals. Mars also served as General Coordinator of HITCON 2021 and 2022, and as Vice General Coordinator of HITCON 2020.
Chung-Kuan Chen is currently the security research director in CyCraft, and responsible for organizing the research team, and Adjunct Assistant Professor in Soochow Uiniversity, Taiwan. He earned his PHD degree of Computer Science and Engineering from National Chiao-Tung University (NCTU). His research focuses on cyber attack and defense, machine learning, software vulnerability, malware and program analysis. He tries to utilize machine learning to assist malware analysis and threat hunting, and build automatic attack and defense systems. He has published several academic journal and conference papers, and has been involved in many large research projects from digital forensic, incident response to malware analysis. He also dedicates to security education. Founder of NCTU hacker research clubs, he trained students to participate in world-class security contests, and has experience of participating DEFCON CTF (2016 in HITCON Team and 2018 as coach in BFS team). He organized the BambooFox Team to join some bug bounty projects and discover some CVEs in COTS software and several vulnerabilities in campus websites. Besides, he has presented technical presentations in technique conferences, such as BlackHat, HITCON, CHITB, RootCon, CodeBlue, FIRST and VXCON. As an active member in Taiwan security community, he is the chairman of HITCON review committee as well as director of Association of Hacker In Taiwan, and member of CHROOT - the top private hacker group in Taiwan.
Kyo is the Head of the Panasonic Cyber Security Lab, where he leads the development of the IoT and cybersecurity strategies. Working closely with the Panasonic Product Security Center in Japan, he oversees international cybersecurity initiatives and drives cross-regional collaboration on product and technology security.
His expertise includes IoT security, cloud security, AI security, and cybersecurity talent development. He is also an active contributor to Taiwan’s cybersecurity community, promoting industry collaboration, technical exchange, and practical talent development.
Kyo served as General Coordinator for HITCON Cyber Range from 2023 to 2025 and continues to contribute to HITCON 2026. He is committed to bridging industry, technology, and talent development to advance the cybersecurity ecosystem.
Since 2006, my research has focused on technology foresight, cybersecurity policy, hacker behavior, mobile and cloud security, and proactive cyber defense. I have also contributed to the drafting of a cybersecurity white paper for Taiwan’s Executive Yuan.
In 2016, I began a four-year secondment to Taiwan’s National Security Council, where I contributed to the development of the “Cybersecurity Is National Security” strategy, the drafting of cybersecurity legislation and regulations, and the review of cybersecurity research and technology programs. During this period, I also supported the implementation of government cybersecurity policies, security assessments, and audits, and participated in international cybersecurity cooperation.
From 2020 onward, I continued conducting cybersecurity research and providing related professional services through positions at the Cybersecurity Institute of the Institute for Information Industry, and the Institute of Information Science at Academia Sinica. During this time, I was also elected to the Board of Directors of the Taiwan Hacker Association, where I helped advance cybersecurity talent development and organize cyberattack and defense demonstrations and exercises.
In 2024, I joined the Department of Information Management at Yuan Ze University, where I teach courses in computer networks, information systems analysis and design, and cybersecurity management. I also supervise master’s students and undergraduate capstone projects that apply artificial intelligence to cybersecurity research, with findings published in academic journals.
Jeff Chao is the CEO and Founder of TRAPA Security, where he leads the development of Blue Team Exercise and Cyber Range solutions. Prior to founding TRAPA, he served as a security engineer at a semiconductor corporation and a senior vulnerability researcher at Team T5.
His research expertise spans Android, IoT, and binary vulnerability discovery. He has reported over 10 critical vulnerabilities to major international corporations, presented his Samsung Secureboot exploit research at Black Hat USA 2020, and secured 3rd place at PWN2OWN Tokyo 2020 with Team TRAPA. As a member of the HITCON CTF team, he has achieved multiple second-place finishes at DEFCON CTF, organized over 10 international CTF competitions, and pioneered Taiwan's first Attack & Defense style CTF.
Sean Chen specializes in product security assessment, PSIRT operations, vulnerability research and disclosure, and IoT security, with extensive hands-on experience in product cybersecurity. He previously served as head of the Panasonic Cybersecurity Lab, where he managed lab operations and led cross-border project collaborations with Panasonic's headquarters in Japan, focusing on product security hardening, security evaluations, and security incident response.
In the PSIRT domain, Sean brings end-to-end process experience spanning vulnerability intake, risk assessment, patch coordination, and public disclosure.
Sean served as General Chair of HITCON (Hacker In Taiwan Conference) for both the 2020 and 2021. Since joining the Association of Hackers in Taiwan in 2019, he has been deeply involved in community operations and event planning. After stepping down from the General Chair role, he has continued contributing behind the scenes — brokering relationships between vendors, government agencies, and the cybersecurity community to strengthen Taiwan's security ecosystem.
Hazel Yen is a Technical Project Manager at DEVCORE, with a background in penetration testing and a focus on bridging technology and client needs.
She is the co-founder of HITCON GIRLS and HITCON CISO Summit, and served as the coordinator of HITCON GIRLS for five years, contributing to its growth and development. She also served as the coordinator of HITCON Community 2018, successfully organizing the conference.
In 2019, Hazel was a speaker at Black Hat USA, where she delivered a joint presentation with women’s cybersecurity communities from Japan and Korea. With over a decade of experience in the cybersecurity community, she is dedicated to fostering collaboration, sharing knowledge, and supporting the continued growth of the community.
With over 20 years of manufacturing experience, this career spans OT automation, R&D design integration, enterprise IT infrastructure, and executive CISO/DPO governance. Passionate about driving industrial cybersecurity forward, serving as a Security Consultant at the Taipei Computer Association (TCA) to facilitate public-private partnerships and advance the practical validation and implementation of the SEMI E187 semiconductor equipment cybersecurity standard. Leveraging a multifaceted perspective, the focus remains on continuously strengthening enterprise cyber frameworks and organizational resilience to navigate digital transformation challenges.
Core competencies encompass infrastructure architecture, technical security, auditing, and risk governance, supported by more than ten prestigious international credentials, including OSCP, CISSP, CISA, CRISC, AAISM, and ISO 27001/27701/17065 Lead Auditor certifications. Dedication centers on AI security, product safety, and smart manufacturing defense—deepening strategic and technical applications to help enterprises reinforce resilience, enhance governance, and address emerging threat landscapes and compliance demands.
Leon currently serves in the Information Security Department of a financial holding company, where he is responsible for managing the cybersecurity team, driving strategic security initiatives, and establishing robust defense and management frameworks. Previously, he served as the Cybersecurity Testing Manager at the Information and Communication Security Technology Center (ICST). In that role, he oversaw the execution of security testing projects, the development of Government Configuration Baselines (GCB), vulnerability notification mechanisms, and social engineering simulations.
David Su is a cybersecurity engineer specializing in technical assessment and compliance. He is dedicated to evaluating the integrity and resilience of enterprise security from multiple perspectives. Over the years, he has been an active contributor to the HITCON community, taking part in planning and coordinating both technical meetups and on-site events to foster knowledge exchange and strengthen community engagement.
Vincent Li is an Anti-Virus Analyst at FortiGuard Labs, Fortinet, specializing in network traffic-based threat intelligence research, threat hunting, and malware analysis. He has published several technical articles on the Fortinet Blog and presented on Threat Hunting at CYBERSEC Taiwan in 2025 and 2026. Beyond his professional work, Vincent actively contributes to Taiwan’s cybersecurity community. He has been involved with HITCON as a staff member since 2018 and, since 2025, has also contributed to organizing Cyber Range x CTF and the CISO Summit.
Having contributed to the cybersecurity community since his student days, Kuro has actively participated in groups including HITCON, COSCUP, SITCON, AWS UG DevSecOps Taiwan, and the ISC2 Taipei Chapter. Throughout his career across high-tech manufacturing, financial services, and Big Four accounting firms, he has gained extensive practical experience from both client and advisory perspectives. His expertise spans enterprise security architecture, technical assessments, cybersecurity audits, and IT risk controls, with a recent focus on cloud security architecture, cloud threat analysis, and enterprise AI security management. Furthermore, Kuro is a frequent public speaker and professional instructor dedicated to promoting cybersecurity awareness and cultivating industry talent. Recognized as an AWS Community Builder (Security), he holds top-tier international credentials across information security, IT governance, and cloud domains, including CISSP, CCSP, CISM, CISA, CRISC, CGEIT, CDPSE, ISO/IEC 42001 LA, as well as multiple professional certifications from AWS and GCP.