guest@sec-ops:~$
Type help for commands, or use buttons to browse:

SECURITY ANALYST & ENGINEER PORTFOLIO

Over two decades of IT Experience starting with a keen interest in IT Security, Operating Systems, Self-Hosting, Community Management, and Server Hosting.

Location: Yorkshire / United Kingdom / Remote | Professional: LinkedIn Only | Email: contact@phish.me.uk

CURRENT & RECENT EXPERIENCE

Major Credit & Financial Institution Threat & Vulnerability Management Lead Apr 2024 – Present
  • Program Ownership & Strategy: Strategic steering of the corporate Vulnerability Management Program, Penetration Testing, and Anti-Malware Solutions to align with corporate risk appetites.
  • Governance & Policy Ownership: Total responsibility for security policy management, standard formulation, and governance enforcement across areas of oversight.
  • Team Leadership & Mentoring: Direct line management of analyst teams (ranging from entry-level to seasoned specialists), setting career blueprints, project targets, and personal growth goals.
  • Penetration Testing Governance: End-to-end scoping, scheduling, and governance of corporate penetration tests to meet audit, compliance, and client obligations, including budget tracking and methodology definition.
  • Vendor & Supplier Relationship Management: Leading product evaluations, contract negotiations, service reviews, and tool onboarding during phases of infrastructure migration and transition.
  • Cross-Functional Collaboration: Aligning business partners, engineering departments, and external assessors to delegate vulnerability remediation, meet deadlines, and present metric-based risk reports to senior executives.
Major Credit & Financial Institution Senior Security Operations Engineer Feb 2022 - Mar 2024
  • Training and mentoring of junior colleagues, supporting their security journey.
  • End-to-end ownership of the Vulnerability Management process (Scanning, Triaging, Incident Response, Reporting, Automated Rescoring).
  • Audit support for ISO27001 and PCI-DSS, evidence collection, and QSA interviews.
  • HR Support for sensitive requests such as DSARs and evidence collection.
Major Credit & Financial Institution Senior Specialist, Network Security Oct 2018 – Feb 2022
  • Governance and PCI-DSS compliance oversight.
  • Delivered on enterprise cloud migration, migrating core services to the cloud securely.
  • First setup and onboarding of enterprise productivity and cloud threat protection suites.
  • Email security, DLP controls, and security incident response.

CAREER HIGHLIGHTS

Cyber Simulation War Room (May 2014 – May 2016)

Helped deploy a technical war room with a start-up mentality. Deployed the server stack, supported partners, and delivered training/consultancy relating to Security Operations and Incident Management during major cyber scenarios.

Major Financial Services Company (Oct 2018 – Present)

Work in a high-pressure role, responsible for vulnerability management including policy, standards, engagement and reporting both to teams and senior executives. Built the program out from nearly nothing to comprehensive estate-wide scanning. Likewise, Penetration Testing, identified key gaps, applied strong governance controls and worked closely with teams on scoping, testing, remediation and improving posture. Fortunate to work here, where we can break the mold and move forward with ideas and improve the status quo.

High-Throughput Digital Gaming Enterprise (Jan 2017 – Oct 2018)

Brought in as Junior Security Analyst, supporting the SOC expansion. Worked with engineering to decommission legacy SIEM, deploy and maintain new SIEM systems, configure alerts, and manage sensor feeds.

PREVIOUS WORK & EDUCATION

Digital Gaming Enterprise: Senior SOC Analyst (2017 - 2018)
Defense Security Contractor: L1 SOC Analyst (2016)
Cyber Simulation Provider: IT Technician & Cyber Consultant (2014 - 2016)
Defense Aerospace Facility: Computer Operator / Spacetrack Analyst (2008 - 2014)

Education: Bachelor's Degree in Computing & Psychology (2014-2020)

Training completed towards: Cloud Security, Network Security, and Security Operations (Certs)