Founder of Teloa | AI Agent Engineering & Product Development | AI Native Security
I build agent-based systems that turn professional expertise into working AI teams. I founded Teloa and drive product design and engineering for an open-source AI-Native Team Studio, bringing agent runtimes, skills, memory, tools, permissions, and collaboration into a shared workspace.
My background spans 13+ years in cybersecurity and global security leadership. I currently serve as AI Security Engineering Team Lead at a globally leading cryptocurrency exchange and previously led global application security and AI security functions at SHEIN. Today, I apply that experience to AI engineering: designing how agents take on responsibilities, coordinate work, use tools, and operate under human oversight.
Teloa — AI-Native Team Studio · Founder
An open-source, self-hosted workspace for one person to build, manage, and run a team of AI employees. Built on an agent runtime, Teloa combines role-based knowledge and skills, tool integration, permissions, multi-agent collaboration, and automation.
Our first industry focus is in-house cybersecurity for internet businesses. Drawing on experience across application security, cloud and infrastructure defense, data protection, identity governance, red teaming, security operations, and business risk and compliance, we are turning security-team expertise and workflows into reusable knowledge, skills, and collaborative AI employees. The goal is One Person Security Center: a small human team directing a digital security workforce across these domains. My ongoing AI Native Security writing provides a framework for this work: how architecture, organizations, controls, metrics, and operating models change when agents become part of the enterprise workforce.
AISecOps: AI-Driven Enterprise Security · Author of an open-source book covering AI for Security and Security for AI.
- What the Next AI SOC Looks Like: A Codex for Security Operations · 中文
- Confessions of a Last-Generation AppSec Engineer · 中文
- Security Organizations May Ultimately Have Only Three Types of Roles · 中文
- The Next Generation of the Security Industry: From Delivering Outcomes to Delivering Value · 中文
- Where Does Red Teaming Go When Attackers Become Agent-Powered? · 中文
- AI Native Security: What Will the Security Framework Ultimately Look Like? · 中文
- From Agent to AI Organization: Why We Built Teloa · 中文
Most of my long-form writing is in Chinese.
Technical Papers & Guides
- 《A Comprehensive Guide to Enhancing Workplace Influence: From Theory to Practice》
- 《互联网跨境企业应用安全架构指南》
- 《安全BP(GSBP)与 BISO 团队建设实践指南》
- 《互联网企业红队建设实践指南》
- 《BlackHat USA 2025: LLM+定制化DFA增强SAST检测技术》
- 《全球视野下的GDPR合规:安全防护与风险应对》
- 《网络安全从业者的AI转型指南》
- 《金融领域跨境合规的六大 “生死线”》
- 《BlackHat Asia 2025:Java 反序列化利用链深度挖掘》
- 《聊一聊AI赋能网络安全》
- 《Black Hat 2025 USA:基于 LLM 的微服务污点漏洞检测》
Personal Essays & Reflections
- 《Max的禅修笔记:道教体系框架解读》
- 《Max的禅修笔记:中国民间信仰体系框架解读》
- 《Max的禅修笔记:佛教体系框架解读》
- 《01 《宇宙的十二种假说》开篇》
- 《02 宇宙的十二种假说:物质为本,还是意识为本?》
- 《03 宇宙的十二种假说:信息即存在》
- 《04 宇宙的十二种假说:我们或许身在模拟中》
- 《05 宇宙的十二种假说:量子世界的三种解释》
- 《06 宇宙的十二种假说:塌缩、信念与决定论》
- 《07 宇宙的十二种假说:从大爆炸到今天》
- 《08 宇宙的十二种假说:多重宇宙》
- 《09 宇宙的十二种假说:全息宇宙》
- 《10 宇宙的十二种假说:时间的三种面貌》
- 《11 宇宙的十二种假说:人择原理》
- 《12 宇宙的十二种假说:终极篇》
| OSCE³ | OSED | OSWE | OSEP | OSCP |
|---|---|---|---|---|
| HTB CYCLONE | HTB HAILSTORM |
|---|---|
![]() |
![]() |
WeChat public account: 白帽子罗棋琛




