

Cybersecurity Consultant · Security Architecture · CISSP
Secure solutions, carefully architected.
I'm a cybersecurity consultant helping business and technical teams deliver secure solutions. I balance security, operational resilience and business objectives across cloud, digital and operational technology.
Cloud & OT security · Security architecture · Cyber risk advisory · habitat: United Kingdom

Three disciplines, one consultant
where security meets the business

Cloud & OT security
Securing Azure, SaaS and SCADA / operational technology, from conditional access and IAM to CIS-hardened, automated cloud estates.
the root system
Security architecture
Defining security requirements, reference architectures and design reviews grounded in NIST, ISO 27001 and MITRE ATT&CK: security designed in, not bolted on.
the stem & leaves
Cyber risk advisory
Pragmatic, risk-based recommendations, assurance reviews and governance that let the business move: security as an enabler, not a blocker.
the bloom, in service of the business
Selected engagements
six years in the field, 2019 to present

Fig. 1 · 2025 – present
National Energy System Operator
Security Consultant · Energy · OT · Cloud
In the fieldCyber security advisory across UK energy transformation programmes: security architecture for Azure, SaaS and SCADA restoration systems.

Fig. 2 · 2024
FSP
Security Architect · Microsoft Security
In the fieldInsider-threat mapping to MITRE ATT&CK, M365 E3/E5 hardening, Sentinel SIEM optimisation and a NIST-based cloud security reference architecture.

Fig. 3 · 2023
NTT DATA
Cloud Security Engineer · Global Cybersecurity
In the fieldBuilt an OWASP DevSecOps maturity assessment now delivered globally; led ISO 27001 third-party risk and Microsoft Purview for public sector.

Fig. 4 · 2022 – 2023
NTT DATA
Junior Cloud Engineer · Azure · Automation
In the fieldImproved Azure security posture by 70% with CIS standards and Ansible; delivered a cost strategy saving clients £2M across 2,000+ VMs.
- Microsoft Azure
- Microsoft 365 E5
- Microsoft Sentinel
- Microsoft Purview
- SCADA / OT
- NIST
- ISO 27001
- MITRE ATT&CK

The method
how a secure outcome is grown, in four seasons
Frame
Understand the business objectives, constraints and risk appetite before any control is proposed.
Architect
Define security requirements and design architecture across cloud, digital and OT: written down, never a black box.
Assure
Security design, risk and assurance reviews with pragmatic, risk-based recommendations.
Enable
Integrate security through the project lifecycle and support formal risk acceptance and governance.

Something worth securing?
Available for security consulting & contract engagements
