Senior Cyber Security Consultant
Senior Cyber Security Consultant with over 10 years of experience across central government and FTSE 100 clients. Specialising in cloud security, secure application development, and security architecture, with expertise in risk management, DevSecOps, vulnerability management, and cloud security frameworks (ISO 27001, NIST, OWASP). Skilled in leading security transformation programmes and collaborating with senior stakeholders to implement robust security strategies.
Internationally recognised certification focusing on cloud security, governance, and risk management, aligned with ISO 27001 and NIST security frameworks.
Specialised qualification for cyber security checks and assessments, with a focus on government compliance and threat mitigation.
Certification in integrating security practices within the DevOps lifecycle, ensuring secure development, continuous integration, and deployment processes.
Advanced expertise in securing AWS environments, with a focus on identity management, monitoring, data protection, and compliance with industry standards.
Recognised as an expert in designing scalable, highly available, and fault-tolerant systems using AWS cloud services and infrastructure.
Specialisation in securing Microsoft Azure environments, with proficiency in implementing security controls, threat protection, and monitoring solutions.
A Master's degree focusing on the latest cyber security strategies, technologies, and risk management, obtained with distinction from a leading institution.
Spearheaded the automation of vulnerability management using AWS Inspector and AWS IAM for access control, ensuring compliance with ISO/IEC 27001. Implemented encryption using AWS KMS and SSL/TLS, and secured VPC endpoints for sensitive data, enhancing security posture and operational efficiency.
Designed and implemented an AWS Firehose solution for secure log delivery to Splunk, ensuring compliance with NIST 800-53. Reduced infrastructure costs while maintaining efficient log management, improving scalability and security for log storage and monitoring.
Developed and integrated OWASP-based secure software development guidelines into the SDLC, educating developers on secure coding practices, vulnerability management, and risk assessments, significantly reducing security vulnerabilities across the organisation.
Conducted a comprehensive evaluation of AWS Security Lake versus Splunk for log storage, presenting a business case that identified significant cost savings on storage and indexing fees. Managed the transition plan, coordinating teams to integrate the solution and optimise costs, while maintaining Splunk for monitoring and alerting.
September 2022 - Present
As a senior consultant, I lead cloud security strategies, risk assessments, and security transformations for government and defence clients. My responsibilities include:
April 2020 - August 2022
As lead engineer, I led the architecture and development for the company’s core product. I was responsible for ensuring the quality and scalability of the product, and coordinating the technical direction. My key responsibilities included:
July 2014 - April 2020
Advised on secure API and hosted application implementations for client data solutions. Managed resources, change requests, and agile workflows for portfolio clients, ensuring data integrity and availability.