
Threat Hunting Pipeline
False-negative detection for SOC log filtering with a closed-loop rule-generation workflow on Dify — turning missed alerts into new detection rules automatically.

I'm Nguyễn Hải Lâm — AI Engineer at Viettel Cyber Security, shipping agentic systems for Cybersecurity (SOC / Threat Hunting), Legal AI and Software Testing. Now moving toward Technical PM to own outcomes end-to-end.
Four overlapping practices I bring to every engagement — from the first whiteboard sketch to the dashboard you check at 2am. Each one ships with evals, observability, and a runbook.
Multi-agent platforms with LangGraph, FastMCP and tool use — engineered for real workflows, not demos.
SOC threat hunting pipelines and legal-domain RAG — with evals, guardrails and closed-loop improvement.
Kafka · Spark · DuckDB pipelines processing millions of records — clean architecture, calm at scale.
Translating ambiguous problems into shipped systems — scope, stack, evals, timeline and stakeholder clarity.

Nguyễn Hải Lâm — AI Engineer at Viettel Cyber Security, based in Hanoi. Working across Cybersecurity (SOC / Threat Hunting), Legal AI and Software Testing. IEEE Access 2025 co-first author and National AI Olympiad 2025 winner.
3+ years across 5 organizations shipping agentic platforms, multi-tenant RAG, and data infrastructure — from research to product to production. Now transitioning toward Technical PM to own scope, delivery and outcomes across cross-functional teams.
Same loop, every project. It bends with the problem but never breaks the discipline.
Understand the user, the data, and the unfair edge AI should create.
Sketch the system — prompts, retrieval, evals, latency budget and failure modes.
Ship a thin vertical slice fast, then harden with tests, logs and dashboards.
Measure with real users, kill what doesn't work, double down on what does.

False-negative detection for SOC log filtering with a closed-loop rule-generation workflow on Dify — turning missed alerts into new detection rules automatically.

Production multi-agent platform with tool calling, inter-agent communication and multi-tenant orchestration for enterprise workflows.

Large-scale data pipeline analyzing GitHub activity — streaming ingestion, lakehouse storage and fast analytical queries over millions of records.

Hybrid search + multi-agent RAG over Vietnamese procurement / legal corpora, with MCP tools for citation-grounded answers.

Agent that reads PRD/SRS and auto-generates test cases — cutting QA time and standardizing the test process across teams.

Peer-reviewed study on LLM prompting strategies, published in IEEE Access (2025). Co-first author.

"Hải Lâm thinks about AI the way good engineers think about distributed systems — evals, latency, observability, cost. Calm execution, every time."
"He owned our multi-agent platform end-to-end. LangGraph, FastMCP, multi-tenant — production-grade from day one."
"Rare combination: research depth, product taste, and the discipline to ship. Our QA agent shipped in weeks, not quarters."
Field notes on building AI systems that survive contact with real users — from retrieval edge cases to agent failure modes.
Read all essaysAgentic AI platforms, security/legal AI systems, software-testing agents, and the data infrastructure behind them. Greenfield builds or rescuing prototypes that need to ship.
I've owned systems end-to-end across 5 organizations. Moving into Technical PM lets me combine that engineering depth with delivery, stakeholder alignment, and outcome ownership.
LangGraph + FastMCP + Dify for agents, Qdrant for retrieval, vLLM for serving, FastAPI on the backend, Kafka / Spark / DuckDB on data, Langfuse for observability.
Yes — production systems at Viettel Cyber Security and AIZ, 1M+ records processed, IEEE Access 2025 co-first author, and a National AI Olympiad 2025 win.