Life at SecIron is a series about the people behind the platform. This time, we speak with Jeff Woong, Senior Manager, Enterprise Solutions, about psychology degrees, pen tests that pass, and why “I don’t know yet” can sometimes be the best answer in cybersecurity.
Jeff sits at the intersection of our customers and engineering teams. When a bank wants to understand how IronWALL holds up against the latest hooking frameworks, or a government team needs a proof of concept conducted on their application, Jeff is often the one in the room.
His journey into cybersecurity took an unconventional route, and that perspective comes through in the way he approaches both the technology and the people behind it.

Mobile applications have become one of the main ways businesses interact with their customers, especially in banking, fintech, government services and digital identity. At the same time, attackers are becoming more sophisticated. It is no longer only about protecting the backend or network. Attackers can target the application itself, the device environment, runtime behaviour, screen sharing, overlays, hooking, tampering and many other attack vectors.
For businesses today, mobile application security is becoming part of protecting the entire digital service and ultimately protecting the user. Security can no longer be treated as something that is only tested before an application goes live. It needs to continue protecting and monitoring the application while it is running in the real world.
My journey into cybersecurity was actually not very traditional. My background is in psychology, and throughout my career I have worked across sales, product management, entrepreneurship, pre-sales and solution consulting.
What attracted me to cybersecurity was the problem-solving aspect. I enjoy understanding how something works, figuring out how it can be broken, and then thinking about how to protect it.
Mobile application security became particularly interesting to me because it combines many areas together: application architecture, operating systems, malware behaviour, user behaviour and even the way attackers think. There is always another layer to understand, which makes the work very interesting.
What I enjoy most is that my role is not limited to just presenting a product.
I get involved in understanding customer environments, analysing applications, discussing security architecture, supporting technical evaluations and POCs, translating security requirements into practical solutions, and sometimes troubleshooting very specific application behaviours.
I especially enjoy taking something technically complicated and turning it into something that customers can clearly understand and act on. Every customer also has a different environment and different security concerns, so there is rarely a completely repetitive day.
The fact that there is always something new to learn.
Attack techniques keep changing, operating systems keep evolving, applications become more complex, and security controls have to evolve together with them.
What excites me most is when we encounter something we have not seen before. Instead of simply asking “Does our solution detect this?”, I enjoy understanding exactly how the attack works, what conditions make it possible, and how we can design a better defence against it. That constant learning process is probably what keeps cybersecurity exciting for me.
One common misconception is that if an application has passed a penetration test or is available on the official App Store or Google Play Store, then it is already secure.
Those are important security measures, but they are only part of the picture.
Once an application is installed on a user’s device, it is running in an environment that the organisation does not fully control. The device could be rooted or jailbroken, compromised by malware, manipulated through hooking frameworks, running inside virtual environments, or exposed to other runtime attacks.
Mobile application security therefore needs to protect not only the application before release, but also the application while it is actually running on users’ devices.
I enjoy the amount of exposure and ownership I get.
Because we work closely with customers across different industries and markets, I get to see many different security requirements, application architectures and real-world problems.
I also like that my role allows me to work across different areas rather than staying inside one narrow job scope. I can be discussing architecture with a technical team, analysing an application, supporting a POC, helping improve internal knowledge, or explaining a new attack technique to a customer. That variety gives me a lot of opportunities to learn and grow.
My academic background is actually in psychology rather than computer science or cybersecurity.
I have always been very interested in understanding how people think, how systems work and why people behave in certain ways. Interestingly, I think that mindset has also helped me in cybersecurity, because security is not only about technology. It is also about understanding behaviour, motivation and how someone might approach a problem differently.
Outside work, I also enjoy building Gundam and other model kits. I probably spend far too much time thinking about how to display them properly.
Don’t be intimidated by how much there is to learn.
Cybersecurity is huge, and nobody knows everything. Instead of trying to memorise every tool or technology, focus on understanding fundamentals and keep asking questions: How does this work? Why does this vulnerability exist? How would an attacker exploit it? How would I defend against it?
I also believe you do not necessarily need to come from a traditional cybersecurity or computer science background. Curiosity, problem-solving ability and the willingness to continuously learn can take you very far.
Most importantly, do not be afraid of not knowing something. In cybersecurity, saying “I don’t know yet, but I’m going to find out” is often the beginning of learning something valuable.
SecIron is hiring across Malaysia, Thailand, Cambodia and the Philippines. If you are curious, like taking things apart to see how they work, and want to spend your days on one problem that matters, see our open roles.