Work

Four things worth describing

Employers and clients are not named, and specifics that belong to them are left out. What follows is the shape of the work, the decisions inside it, and what I would do differently — which is the part that is actually mine to talk about.

01 Big Four professional services firm · global scope · 2026 – present

A global breach-and-attack-simulation and remediation practice

Challenge

A very large organisation with mature controls, and no continuous, evidence-based answer to the question of whether those controls actually work — across detection, prevention and response, in every region, this quarter rather than at the last audit. Findings existed; closure did not reliably follow.

Approach

  • ATT&CK-aligned adversary simulation run continuously rather than as a periodic exercise
  • Remediation and risk-treatment lifecycle owned end to end: assignment, assessment, prioritisation, closure
  • Control owners named across technology and the business, with escalation when SLAs slip
  • Partnership across SOC and MDR, IAM and identity governance, threat intelligence, incident response, security architecture and enterprise risk
  • Posture, coverage and risk closure reported to senior leadership and governance forums

Outcome

Control assurance became a standing, threat-informed function rather than an annual event, and technical findings became risk narratives that leadership could fund. The programme is maturing toward continuous threat exposure management — the point where exposure, exploitability and closure are tracked as one loop.

  • BAS
  • CTEM
  • MITRE ATT&CK
  • Risk Treatment
  • Governance Reporting
02 Canadian security startup, then two Big Four firms · 2018 – 2026

A startup detection service, scaled twice — once well, once the hard way

Challenge

Take a detection and response capability built by a small team with startup habits, and make it a global service that survives enterprise governance, follow-the-sun staffing and client scrutiny — without losing the responsiveness that made it good in the first place.

Approach

  • Joined a Big Four firm through the acquisition of the startup and moved with the capability
  • Evolved SOC processes and playbooks blending threat intelligence, behavioural analytics and automation
  • Directly managed up to 25 people through significant organisational change
  • Later ran 24/7 MXDR operations: scheduling, analyst training, process standardisation, operational metrics
  • Recurring control-validation testing across EDR, firewall and application allow-listing to find coverage gaps before clients did

Outcome

The service made the transition from startup to enterprise operation with its detection quality intact. The more instructive result came later: when a comparable team attempted an improved variation inside an even larger organisation, it proved materially harder. The technology was largely off-the-shelf both times. What carried the first effort was the operating model, the people who remembered why each decision was made, and the customer relationship — none of which transfer in a slide deck. It is the clearest lesson I have about building security capability.

  • MDR / MXDR
  • SOC Operations
  • Team Leadership
  • Detection Engineering
  • Post-acquisition Integration
03 Multiple client environments and one internal investigation · 2013 – present

High-severity incident response and forensic investigation

Challenge

Ransomware in progress, business email compromise, and espionage cases — where containment decisions have to be made before the picture is complete, and where the evidence has to survive scrutiny long after the incident is closed.

Approach

  • Led escalations from Tier I and II analysts as the technical point of contact during high-priority investigations
  • Forensic investigation across platforms: reverse engineering, and both static and behavioural malware analysis
  • Fleet-wide artefact collection and hunting rather than host-by-host triage
  • Jupyter notebooks as the working surface for analysis — timeline reconstruction and artefact correlation kept reproducible, so conclusions can be re-run rather than taken on trust
  • Proactive threat hunting framed by ATT&CK, the Cyber Kill Chain and the Diamond Model
  • Detailed behavioural timelines — the technique that carried the insider-threat investigation which first moved me into security, and which I later formalised through law-enforcement investigation and interviewing training

Outcome

Clear, actionable reporting delivered to clients in written and verbal form, with remediation guidance matched to their risk profile rather than to a template. The investigative discipline — build the timeline, separate what is known from what is inferred — is the habit I carry into every other part of this work.

  • Incident Response
  • Digital Forensics
  • Ransomware
  • Malware Analysis
  • Threat Hunting
  • Insider Threat
04 Manufacturing and telecom instrumentation · 2001 – 2018

Seventeen years around a factory, before any of the security work

Challenge

Before security, the job was making things work on a production floor: fibre-optic telecom test instruments, the quality system around them, and the business systems that had to keep up — with the constraint that anything which stops the line does not stay switched on for long.

Approach

  • Five years of manufacturing IT and preventive maintenance systems at IBM (2001–2006) — starting as a summer job, then weekend part-time work, then an internship, then contract engagements
  • A year and a half in Japan on Yamasa's Academic Intensive Japanese Program (2006–2007)
  • Metrology technician on fibre-optic telecom instruments, then interim quality control manager
  • Webmaster and web marketing for the company e-commerce platform
  • ERP customisation and API connectors; Crystal Reports and database work
  • SharePoint and documentation control; Windows and Linux server administration
  • Then security monitoring and internal investigations, which became the next decade

Outcome

A working understanding of industrial and manufacturing environments that I did not have to acquire second-hand — availability constraints, quality systems, maintenance windows, and why an OT operator distrusts a security control that has never been run against a real line. For an employer in Japanese industry, that background is not incidental to the security work; it is the reason the security work lands.

  • Manufacturing IT
  • OT Context
  • Metrology
  • Quality Control
  • ERP Integration
  • E-commerce

Contact

The platforms behind a lot of the above are described on the Research page.