root@localhost:~$ cat profile.txt
+---------------------+ | Security is | | a process, | | not a product. | | | +---------------------+ /=======================\ /=========================\ /___________________________\
I am a senior cyber and information security professional providing security and technology leadership and helping organisations to achieve their security objectives.
Effective defence starts with understanding how systems are attacked, and understanding the whole lifecycle — threat, exploit, detection, response, governance — and where each piece sits within a business. Security is never an end in itself, but a means of helping businesses achieve their broader strategic objectives.
My background spans web, system and network penetration testing, application security, and governance, including at the highest levels of the organisations I have worked with. Combined with a genuine interest in people and analytical problem-solving, this has allowed me to bring together hands-on technical ability with a strategic and governance mindset.
Whether building a security function from the ground up or developing and adding new controls, I have helped organisations of all sizes succeed. I have helped businesses achieve PCI DSS, ISO 27001, 27017, and 27018 certification, among others, making security a business enabler while leading on security and technology strategy.
When not engaged with work, I enjoy continually developing my skills, building small form factor computers, homelab development, and researching and writing about information security, privacy, and free software.
Skills
Information security governance, information risk management, network penetration testing, web application penetration testing, wireless penetration testing, cyber security, application security, security architecture, IdAM, DevSecOps, cloud security, incident management and response, data protection, disaster recovery, PCI DSS, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, GDPR, NIST Cybersecurity Framework, Cyber Essentials, CIS Benchmarks, CIS Controls, OWASP ASVS, OWASP SAMM, MITRE ATT&CK
Education and Certifications
- Certified Information Systems Auditor® (CISA) - ISACA
- Certified Information Security Manager® (CISM) - ISACA
- Certified Professional Penetration Tester (eCPPT) - eLearnSecurity
- Offensive Security Certified Professional (OSCP) - Offensive Security
- Developing Secure Software (LFD121) - The Linux Foundation
- Kubernetes Fundamentals (LFS258) - The Linux Foundation
- PhD - University of Manchester
Professional Memberships
- Chartered Institute of Information Security (CIISsec)
- Information Systems Audit and Control Association (ISACA)
- Open Web Application Security Project (OWASP)