Cyber Security Technical Professional
BSc (Hons) · First Class
Four-year degree apprenticeship covering network security, threat intelligence, governance and compliance, digital forensics plus security operations. Studied alongside full-time work.
Threat analysis, blue team operations and building positive security culture through orange teaming. This is my primary professional focus - where I spend most of my time.
Billions of people means billions of devices - and billions of attack surfaces. Cyber Security isn't just a career choice for me, it's one of the most important fields in the modern world. The threat landscape evolves constantly, making each day a different challenge. One day could be 650+ zero day vulnerabilities, the next a malware incident.
Spanning self-directed study, a degree apprenticeship and hands-on experience in real organisational environments - covering security culture, compliance, threat analysis and defensive operations.
Formal qualifications across security operations, governance and cloud platforms. Awarded first, then everything still on the roadmap.
BSc (Hons) · First Class
Four-year degree apprenticeship covering network security, threat intelligence, governance and compliance, digital forensics plus security operations. Studied alongside full-time work.
SY0-701
The industry entry point for security roles. Covers threats and attacks, architecture, operations, incident response plus governance and risk.
Eight domains spanning governance, risk, asset security and identity management. The long-term target.
The Microsoft baseline across cloud services. The entry point to the rest of the SC track.
Threat detection and response with Sentinel and Defender. Closest to the day job.
Conditional access, PIM and Entra configuration. Builds on work I already own.
My focus is primarily defensive and organisational: building cultures that take security seriously, understanding the threat landscape and applying governance to protect people and data. Each area below is tagged with the colour-wheel team it belongs to.
Orange teaming - building positive security behaviours across organisations. Training individuals, running phishing simulations, gamification, awareness campaigns and making security something people engage with rather than ignore.
Policy controls aligned to ISO 27001:2022, risk registers, compliance functions and information security management. Translating regulatory requirements into controls that actually protect the business.
Analysing threat intelligence, understanding attacker TTPs and mapping current threat actors and campaigns to defensive controls using frameworks like MITRE ATT&CK.
Post-incident investigation - examining compromised systems, recovering artefacts and tracing attack timelines to understand what happened, how and what to do next.
Defensive monitoring and detection - using SIEM tooling, Microsoft Defender and security operations to identify suspicious activity and respond before damage escalates.
Applying security principles to software from the ground up - input validation, secure authentication, OWASP best practices and reviewing code with an attacker's mindset.
Security is not one job. The colour wheel splits it into teams that each hold a different part of the problem. I work across five of them: white for governance, blue for defence, orange for culture, yellow for secure build and green for automation. Select a segment to see what each one covers.
GRC doesn't stand still - organisations are adopting AI and agentic tooling faster than most policies can keep up with. This is where a lot of my current governance attention goes.
Helping organisations adopt AI responsibly - defining acceptable use policies, approval routes for new tools and data handling rules so adoption doesn't outpace the controls around it.
Applying AI defensively - using it to accelerate triage, log analysis and threat detection - while staying alert to the risks it introduces, from prompt injection to sensitive data leaking into third-party models.
Governance for AI that acts, not just answers - guardrails, approval gates and audit trails for agentic systems that can take real actions and the policies that define what they're allowed to do unsupervised.
Ongoing due diligence, security questionnaires and assurance reviews (ISO 27001) to keep supplier risk visible for the life of the relationship.
Tools I use day-to-day or actively work with across both technical and business environments.
My CV covers the complete history: roles, responsibilities, the systems I have run and the qualifications behind them. Useful if you are hiring for a blue team, SOC or security analyst role.
Whether it's a consultation, advisory work, or you simply want to talk shop - I'm open to the conversation.