01
Security Leadership
Owning security posture at an organisational level: policy, governance, budget and the trade-offs between them. Security decisions are argued in business terms because that is where they are approved.
Security Practice
A decade spent auditing, testing, defending and building systems — first as an auditor and penetration tester, later as the person accountable for an organisation’s security posture.
Defence in depth
A conceptual model of layered security. Select a layer to see what it holds. This represents no specific deployment.
Edge & Perimeter
Traffic control, filtering and protective services in front of the platform.
Controls at this layer
Practice areas
01
Owning security posture at an organisational level: policy, governance, budget and the trade-offs between them. Security decisions are argued in business terms because that is where they are approved.
02
Assessing and building applications with the trust boundaries drawn deliberately. Most application vulnerabilities are disagreements between components about who enforces what.
03
Securing cloud estates where the perimeter is configuration rather than hardware. Misconfiguration is quieter than an application bug and frequently more expensive.
04
Vulnerability analysis and controlled testing across applications, APIs and infrastructure, delivered as prioritised findings with remediation guidance engineering teams can act on.
05
When several clients share one backend, authorisation belongs in exactly one of them. API security work is mostly the discipline of keeping that true as the surface grows.
06
Network architecture, firewall policy and segmentation across on-premise and cloud environments, with boundaries enforced at the network layer rather than by convention.
07
Security positioned inside the delivery pipeline. If the secure path is slower than the insecure one, engineers will route around it — so the secure path has to be the fast one.
08
Identification is the beginning. The work that matters is prioritisation, remediation tracking and reducing the window between a vulnerability existing and it being closed.
09
Structured audit engagements across application, protocol, code and infrastructure layers — including a blockchain platform audit that identified more than 40 critical vulnerabilities.
10
Working with recognised control frameworks because they give a technical position a shape non-technical stakeholders can evaluate and approve.
Governance frameworks
Framework experience from security, infrastructure and governance work. Listed separately from personal certifications.
Certifications held
40+
Critical vulnerabilities identified
Historical security audit engagement — a blockchain platform assessed across its application, peer-to-peer layer, codebase and infrastructure. No vulnerability details, reproduction steps or exploit information are published.