Profile
I am a versatile, highly experienced Cyber Security Analyst with a strong background in enterprise technology, security operations, threat analysis and complex infrastructure environments. I bring a combination of deep technical expertise and analytical capability, with extensive experience understanding how enterprise systems operate, identifying vulnerabilities and attack vectors, analysing malicious activity, and translating technical intelligence into practical defensive outcomes.
My experience spans complex enterprise environments across leading UK organisations and institutions, providing me with a broad understanding of infrastructure, applications, networks, identity, endpoint technologies and security controls. This technical foundation enables me to assess threats not simply from a theoretical perspective, but from an understanding of how adversaries can exploit real-world environments.
I have a particular interest in Threat Intelligence, Threat Analysis and Counter-Intelligence, including understanding adversary behaviour, identifying indicators of compromise, analysing attack techniques and developing intelligence-led approaches to cyber defence. I am comfortable investigating complex technical problems, correlating disparate information and establishing the likely cause, impact and potential threat associated with an incident or activity.
I am an articulate and credible communicator, able to engage effectively with technical specialists, security teams, senior stakeholders and business leadership. I am experienced in translating complex technical and security issues into clear intelligence, risks and recommendations that support informed decision-making.
I combine technical depth, investigative thinking and strong analytical problem-solving skills with an understanding of enterprise risk, service continuity and security assurance.
Core Cyber Security & Intelligence Capabilities
Threat Intelligence & Adversary Analysis
Ability to analyse technical and contextual information to identify threats, adversary activity, attack patterns, indicators and potential compromise. Strong understanding of enterprise environments and how threat actors can exploit infrastructure, identity, applications and network services.
Cyber Threat Analysis & Investigation
Experienced in analysing complex technical problems and security events, correlating information across infrastructure and applications, establishing root cause and assessing potential impact, risk and attack paths.
Malware Analysis & Reverse Engineering
Practical experience analysing malicious software and suspicious artefacts using tools and techniques including Cuckoo Sandbox, Invincea, Cynomix, IDA Disassembler, OllyDbg and x86 Assembly. Able to examine malware behaviour and technical characteristics to support understanding of indicators, capabilities and potential threat.
Counter-Intelligence & Defensive Security
Strong understanding of the requirement to identify, assess and counter malicious activity within enterprise environments. Able to apply technical knowledge to support defensive strategies, identify weaknesses that could be exploited by adversaries and develop intelligence-led approaches to reducing organisational exposure.
Security Architecture & Technical Assurance
Experienced Technical Analyst capable of assessing complex technology environments, identifying security and resilience considerations, challenging proposed designs and ensuring solutions align with organisational standards, controls and operational requirements.
Incident Analysis & Problem Resolution
Creative and decisive investigator with extensive experience diagnosing complex technical problems. Able to rapidly establish relationships between systems, infrastructure, applications and user activity to identify likely causes and appropriate remediation.
Security Monitoring & Detection
Experience with enterprise monitoring and management technologies including Splunk, SCOM and SCCM, supported by extensive knowledge of Windows, networking, identity and infrastructure technologies. Strong understanding of the telemetry and technical evidence required to identify anomalous activity and investigate potential compromise.
Identity, Infrastructure & Enterprise Security
Deep technical knowledge across Active Directory, Windows, virtualisation, networking, DNS, DHCP, VPN, firewalls, SSL/TLS, Exchange, IIS, SharePoint and enterprise infrastructure. This provides a strong foundation for analysing attack surfaces, privilege, lateral movement, persistence and potential routes to compromise.
Network Security & Communications
Broad understanding of TCP/IP, wired and wireless networking, DNS, DHCP, VPN, firewalls, SSL/TLS, load balancing and enterprise network architecture. Able to analyse network architecture and communications from both operational and security perspectives.
High Availability & Service Resilience
Extensive experience designing and supporting resilient enterprise environments including clustering, F5/Citrix NetScaler, Microsoft Load Balancing and SQL replication. Strong appreciation of availability, resilience, business continuity and the consequences of security incidents against critical services.
Security, Risk & Project Delivery
Experienced working across complex technical programmes and enterprise change, with a practical understanding of ITIL, technical governance, assurance, risk management and controlled delivery.
Technical Expertise
Platforms & Virtualisation:
Wintel, VMware, vSphere, ESXi, Hyper-V, Citrix XenDesktop, XenApp, XenServer, App-V, AppSense, LoginVSI
Security & Malware Analysis:
Splunk, Cuckoo Sandbox, Invincea, Cynomix, IDA Disassembler, OllyDbg, x86 Assembly
Identity & Collaboration:
Active Directory, Exchange, SharePoint, IIS, Lync, Apple, iOS
Networking & Security Infrastructure:
TCP/IP, DNS, DHCP, VPN, Firewalls, SSL/TLS, Wireless, F5, Citrix NetScaler
Systems Management & Deployment:
SCOM, SCCM, Windows Deployment Services, WAIK
Storage, Backup & Recovery:
NAS, SAN, Fibre Channel, iSCSI, Symantec, HP, IBM, Dell, tiered storage
Databases & Applications:
Microsoft SQL Server, MySQL, bespoke and third-party enterprise applications
Professional Strengths
Threat-focused: Able to assess technology through an adversarial and defensive security lens.
Analytical: Strong ability to correlate technical information, identify patterns and establish root cause.
Investigative: Comfortable working with incomplete information and developing evidence-based conclusions.
Technically credible: Deep understanding of the underlying enterprise technologies that attackers target.
Communicative: Able to translate complex cyber security and technical issues into clear intelligence and actionable recommendations.
Strategic: Able to connect technical threats with business risk, operational impact and organisational resilience.
Decisive: Experienced in high-pressure problem resolution and making informed technical decisions.
Collaborative: Quickly establishes credibility and effective working relationships with technical, security and business stakeholders.
Solutions: A Creative Analyst, expert in both design and delivery, supported by a very successful track record
Communication: Very articulate, quickly builds trust and rapport with both technical and business stakeholders
Problem Resolution: A creative and decisive problem solver, able to draw on a wealth of experience
Technical Assurance: An experienced Technical Analyst, able to lead teams and align complex projects/changes to standards
Project Delivery: Deep & practical understanding of delivery methods and frameworks (ITIL)
Enterprise Infrastructure Technologies: Broad and deep knowledge, demonstrated throughout work history
Platforms: Wintel, Virtualisation, AppSense, LoginVSI, App-V, XenDesktop, XenApp, XenServer, VMware, vSphere, ESXi, Hyper-V
High Availability & Service Continuity: Clustering, F5/Citrix Netscaler & MS Load Balancing, MS SQL Data Replication
Storage, Backup, Recovery & Archiving: NAS & SAN (Fibre & iSCSI), Tiered (Symantec, HP, IBM, Dell)
Messaging, Collaboration, Directory Services: Exchange, Active Directory, SharePoint, IIS,Apple, iOS, Lync
Networking: Tech. (Cabling, Wireless, TCP/IP), Core Services (DNS, DHCP, VPN, Firewalls, SSL)
Systems Management, Monitoring & Software Deployment: SCOM, SCCM, Windows Deployment Services, WAIK, Splunk
Database, Applications & Business Systems: Broad experience in bespoke, commodity and 3rd party (SQL, MySQL)
Malware Analysis - Cuckoo Sandbox, Invincea & Cynomix, IDA dissembler, Olydbg, x86 assembly
Certifications
Microsoft: MCSA 2003, MS 2008 Enterprise Administrator, MCSA 2012. MCTS, MCP
Symantec: Certified Security Professional
Splunk: Certified Knowledge Manager
Tenable: Certified User
VMware: VCP, Cloud, End User Computing, Work Force Mobility
Various AppSense Certified Professional 2.0, iTIL V3 Foundation, Solarwinds Certified, LogRhythm Certified Professional, FireEye certified Professional
