London, England, United Kingdom
Architect of clouds, detector risks, with a focus on finance and energy—no vulnerability left unturned. My spare time is spent engineering software in .NET (C#) or the MERN stack. I create cyber security and threat intelligence apps.
- Responsible for all non-functional requirements related to security. - Implement "secure-by-design" across all Guardian projects. - Capture and refine InfoSec requirements and ensure integration into information systems. - Perform security reviews, identify gaps in security posture, and develop response plans. - Create, support, and maintain comprehensive threat models. - Conduct risk assessments and take ownership of risk management implementation (NIST RMF). - Manage risk, assumptions, issues, and decisions throughout each system's lifecycle.
Working alongside 2 others in the Security Improvement Programme (SIP) Architecture team, offering cross-discipline consultancy and support for the 50-person SIP, primarily advising project-based security architects and proving concepts ahead of project initiation via the security improvement programme.
Lanware is an IT managed service provider trusted by London’s top independent financial firms. Short-term contract to support the SOC with migrating from Splunk to Sentinel and reviewing their general security posture. Full security audit of all client M365 and Azure tenants, plus the refactoring of a problematic 2000-line Python script to smaller and easier to support PowerShell scripts. Supported the migration from Mimecast Web Security to Zscaler.
Mesmerise helps companies unlock the potential of spatial computing and AI with a focus on security and ethics. Promoted from Senior Security Engineer, my role was pivotal in steering the company's innovative product and service offerings. My responsibilities spanned the full spectrum of product development and solutions architecture, ensuring that each of the three products were built on a foundation of enterprise-ready public cloud infrastructure. Headed the day-to-day operations of software engineering, platform engineering, and design teams. Strict agile/scrum environment with fortnightly sprinting and DevSecOps methodologies for continuous integration and deployment. Served as the tech lead for achieving key industry certifications, including ISO 27001, SOC 1, and SOC 2, demonstrating a commitment to the highest standards of data security and privacy.
I spearheaded Mesmerise’s inaugural cyber security initiative, working directly with the CISO to fortify networks and digital products within a tight timeline. Despite rapid growth to 150 employees in 3 years, the introduction of a cyber security framework was a foundational milestone, culminating in the prestigious achievement of ISO 27001 certification. Designed and deployed PIM in Azure. Integrated SSO across all third-party applications. Automated access reviews to ensure continuous compliance. Designed and implemented a comprehensive identity governance framework. Swiftly remediated vulnerabilities highlighted by external penetration testers. Authored the vulnerability management policy. Implemented phishing-resistant MFA. Overhauled Conditional Access policies. Configured Microsoft Purview and Priva to manage and protect data across the enterprise. Designed a secure network with a virtual WAN, Firewall, and VPN gateway to safeguard administrative access. Deployed Azure Sentinel. Modernised infrastructure templates to leverage virtual network integrations, private networking, and NSGs.
Lanware is an IT managed service provider trusted by London’s top independent financial firms. Served as Interim CTO (Sept-Dec 2022), appointed by the MD. Architect of a business-critical and latency-sensitive cloud portfolio management solution. Migrated a dozen boutique asset managers with $300 billion AUM from private cloud infrastructure to Azure, navigating complex regulatory requirements. Directed the design and implementation of a comprehensive DR strategy in Azure, personally authoring the pivotal "Azure DR Runbook”, including for AVD. Oversaw the design and deployment of key security tools, including Splunk, Defender, Mimecast, and Darktrace. Led the transition from SCCM to InTune. Played a leading role in developing the AVD solution with FSLogix, introducing innovations such as IGEL, VDOT, and IaC (Bicep and PowerShell) to automate image servicing processes.