Cyber Security

Threat analysis, blue team operations, and building positive security culture through orange teaming. This is my primary professional focus - where I spend most of my time.

Security Culture Threat Analysis Digital Forensics Secure Development AI Governance

Why Cyber Security?

Billions of people means billions of devices - and billions of attack surfaces. Cyber Security isn't just a career choice for me, it's one of the most important fields in the modern world. The threat landscape evolves constantly, making each day a different challenge. One day could be 650+ zero day vulnerabilities, the next a malware incident.

4+ Years

4+ Years in Cyber Security

Spanning self-directed study, a degree apprenticeship, and hands-on experience in real organisational environments - covering security culture, compliance, threat analysis, and defensive operations.

Focus Areas

What I work on

My focus is primarily defensive and organisational - building cultures that take security seriously, understanding the threat landscape, and applying governance to protect people and data.

01

Security Culture

Orange teaming - building positive security behaviours across organisations. Training individuals, running phishing simulations, gamification, awareness campaigns, and making security something people engage with rather than ignore.

Orange Team KnowBe4 Awareness Training
02

Governance, Risk & Compliance

Policy controls aligned to ISO 27001:2022, risk registers, compliance functions, and information security management. Translating regulatory requirements into controls that actually protect the business.

ISO 27001:2022 ISMS Risk Management
03

Threat Analysis

Analysing threat intelligence, understanding attacker TTPs, and mapping current threat actors and campaigns to defensive controls using frameworks like MITRE ATT&CK.

MITRE ATT&CK OSINT Threat Intel
04

Digital Forensics

Post-incident investigation - examining compromised systems, recovering artefacts, and tracing attack timelines to understand what happened, how, and what to do next.

Evidence Analysis Log Analysis Incident Response
05

Blue Team Operations

Defensive monitoring and detection - using SIEM tooling, Microsoft Defender, and security operations to identify suspicious activity and respond before damage escalates.

Microsoft Defender SIEM Detection & Response
06

Secure Development

Applying security principles to software from the ground up - input validation, secure authentication, OWASP best practices, and reviewing code with an attacker's mindset.

OWASP Secure Coding Code Review
Governance & Assurance

AI governance & assurance

GRC doesn't stand still - organisations are adopting AI and agentic tooling faster than most policies can keep up with. This is where a lot of my current governance attention goes.

01

AI Governance in the Workplace

Helping organisations adopt AI responsibly - defining acceptable use policies, approval routes for new tools, and data handling rules so adoption doesn't outpace the controls around it.

AI Governance Acceptable Use Data Handling
02

AI Usage in Security

Applying AI defensively - using it to accelerate triage, log analysis and threat detection - while staying alert to the risks it introduces, from prompt injection to sensitive data leaking into third-party models.

AI-Assisted SecOps Prompt Injection Data Leakage
03

AI Policy & Agentic Workflows

Governance for AI that acts, not just answers - guardrails, approval gates and audit trails for agentic systems that can take real actions, and the policies that define what they're allowed to do unsupervised.

Agentic AI Guardrails Audit Trail
04

Supplier Management & Assurance

Ongoing due diligence, security questionnaires and assurance reviews (ISO 27001) to keep supplier risk visible for the life of the relationship.

Third-Party Risk Due Diligence ISO 27001
Tools & Technologies

My toolkit

Tools I use day-to-day or actively work with across both technical and business environments.

Technical Tools
Kali Linux Wireshark Nmap Metasploit Burp Suite AlienVault OTX OSINT Framework Python (scripting) Bash Linux CLI VirtualBox / VMware TryHackMe Hack The Box
Business & Platform Tools
KnowBe4 Microsoft Defender Forcepoint SharePoint Azure AD / Entra Microsoft Graph Microsoft Purview Microsoft Fabric Power BI ISMS.online MS Admin Centers
Roadmap

Goals & certifications

Qualifications I'm working through to formalise skills across security operations, governance, and Microsoft cloud platforms.

CompTIA Security+

In Progress

Vendor-neutral foundation cert covering network security, threats, compliance, and cryptography. Widely recognised as an industry entry point.

CISSP

Planned

Industry gold-standard certification covering eight domains including governance, risk, asset security, and identity management.

SC-900 - Security Fundamentals

Planned

Microsoft certification covering the fundamentals of security, compliance, and identity across cloud services.

SC-200 - Security Operations Analyst

Planned

Microsoft certification for threat detection and response using Sentinel, Defender, and cloud-native security tooling.

SC-300 - Identity & Access Admin

Planned

Microsoft certification covering identity governance, conditional access, privileged identity management, and Entra configuration.

Get In Touch

Have a security question?

Whether it's a consultation, advisory work, or you simply want to talk shop - I'm open to the conversation.