Security professional with experience spanning Security Operations (SOC), Data Loss Prevention (DLP), Business Continuity (BC), Disaster Recovery (DR), Enterprise Infrastructure, Networking, Systems Administration, Telecommunications, and Multidisciplinary Engineering.
Selected from over 2,000 applicants for the UK Government-funded SANS Upskill in Cyber Programme, achieving GIAC GFACT and GIAC GSEC certifications. Invited to join the SANS Advisory Board following exceptional examination performance.
Experienced in threat detection, event triage, security monitoring, endpoint investigation, log analysis, incident response, and threat hunting using technologies including Microsoft Sentinel, Microsoft Defender for Endpoint, Splunk, and Forcepoint DLP.
Combines cyber security expertise with extensive practical experience across infrastructure, networking, storage, telecommunications, electrical engineering, electronic engineering, and mechanical engineering. Brings a strong root-cause analysis mindset developed through careers spanning operational support, fault finding, hardware diagnostics, infrastructure recovery, telecommunications engineering, and motorsport environments.
Comfortable operating across multiple technical domains, ranging from enterprise IT and network security through to hardware troubleshooting, electronics repair, systems recovery, and complex engineering investigations.
Experienced working with organisations of all sizes, from small businesses through to multinational enterprises, supporting both day-to-day operations and business-critical recovery scenarios.
Currently focused on expanding capabilities in threat hunting, detection engineering, and network security monitoring through practical projects including Zeek-based network telemetry analysis, packet analysis, and threat hunting workflows.
- Threat Detection and Alert Triage
- Threat Hunting
- Incident Investigation
- Security Monitoring
- Endpoint Investigation
- Vulnerability Management
- Data Loss Prevention (DLP)
- PCAP Analysis
- Log Analysis
- Microsoft Sentinel
- Microsoft Defender for Endpoint
- Splunk Enterprise
- KQL
- SPL
- Detection Logic Development
- Security Analytics
- Adversary Behaviour Analysis
- Event Correlation
- Threat Modelling
- Security Use Case Development
- Alert Tuning and Optimisation
- Cisco Switching and Routing
- TCP/IP
- DNS
- Packet Analysis
- Network Monitoring
- Traffic Flow Analysis
- Network Troubleshooting
- Zeek Network Security Monitoring
- Wireshark
- Windows Server
- Linux Administration
- Active Directory
- Group Policy
- AS/400
- IBM SAN Storage
- Bare-Metal Recovery
- Server Deployment
- Infrastructure Recovery
- Virtualisation Platforms
- Backup and Recovery Solutions
- PowerShell
- Bash
- Python (Foundation Level)
- Linux Tooling
- Automation Concepts
- Investigated and triaged security events from Microsoft Sentinel, Microsoft Defender for Endpoint, and Splunk.
- Conducted endpoint triage across Windows and Linux environments.
- Investigated indicators of compromise, suspicious user activity, and potential security incidents.
- Performed log analysis and developed threat-hunting hypotheses.
- Conducted packet capture analysis to identify command-and-control traffic and potential data exfiltration activity.
- Developed practical understanding of Active Directory attack paths, privilege escalation, Kerberos abuse, lateral movement, token abuse, and persistence mechanisms.
- Produced technical reports and communicated findings to stakeholders.
- Supported and administered Forcepoint Data Loss Prevention technologies.
- Investigated policy violations and insider risk events.
- Assisted with the protection of sensitive business information and regulatory compliance requirements.
- Analysed and triaged DLP events, reducing false positives and supporting policy improvements.
- Eight years of experience supporting Business Continuity and Disaster Recovery programmes.
- Managed hardware deployment activities for multiple clients supporting DR planning and recovery exercises.
- Performed bare-metal operating system recovery and infrastructure restoration.
- Supported live recovery events ranging from small organisations to multinational enterprises.
- Worked directly with technical teams, management, and executive stakeholders during recovery situations.
- Assisted in the development and execution of recovery procedures and operational documentation.
- More than ten years of monitoring and infrastructure support experience within NOC and Data Centre environments.
- Extensive experience across Linux and Windows platforms.
- Experience supporting enterprise storage environments including IBM SAN technologies.
- Strong Active Directory administration and troubleshooting experience.
- Experience deploying and recovering physical and virtual server environments.
- NOC operations experience including monitoring, incident management, escalation, and operational support.
- Practical experience supporting Cisco networking infrastructure.
- Strong understanding of routing, switching, network fault finding, and infrastructure diagnostics.
- Experience analysing network traffic and troubleshooting complex connectivity issues.
- Exposure to enterprise environments supporting critical business services and infrastructure.
- Experience supporting telecommunications infrastructure including SDH transmission systems.
- Fault diagnosis and repair of telecommunications hardware and electronic assemblies.
- Experience in repair, rework, testing, quality assurance, and technical investigation.
- Strong analytical and troubleshooting skills developed through operational engineering environments.
- Practical experience diagnosing and repairing electronic equipment at component and assembly level.
- Experience working with electrical and electronic systems, fault-finding techniques, and structured troubleshooting methodologies.
- Strong understanding of hardware diagnostics and engineering problem-solving techniques.
- Extensive hands-on mechanical engineering experience gained through motorsport and race team environments.
- Experience supporting vehicle preparation, maintenance, problem diagnosis, and fault resolution.
- Strong root-cause analysis skills developed in high-pressure engineering environments where reliability and performance were critical.
Designing and developing a Zeek-based network monitoring and threat-hunting platform focused on:
- DNS analysis
- Connection telemetry
- HTTP analysis
- TLS analysis
- Threat hunting workflows
- Network visibility
- Detection engineering
- Security analytics
Maintaining a personal lab environment used for:
- Security research
- Threat hunting exercises
- Active Directory security testing
- Log analysis
- Packet analysis
- Linux and Windows administration
- Detection engineering development
- GIAC Foundational Cybersecurity Technologies (GFACT)
- GIAC Security Essentials (GSEC)
- SANS Upskill in Cyber Programme Graduate
- SANS Advisory Board Member
- Threat Hunting
- Detection Engineering
- Digital Forensics and Incident Response (DFIR)
- Network Security Monitoring
- Zeek
- Security Analytics
- Active Directory Security
- Purple Teaming
- Incident Response
- Cyber Threat Intelligence
- OT / ICS Security
- Critical National Infrastructure Security
- Strong root-cause analysis capability
- Multidisciplinary engineering background
- Excellent troubleshooting skills
- Methodical investigative approach
- Effective stakeholder communication
- Technical report writing
- Training and mentoring experience
- Experience communicating with technical teams through to C-level leadership
- Calm and structured approach under pressure
- Ability to bridge the gap between cyber security, infrastructure, networking, and engineering disciplines