Professional Experience

Current Role

Information Security Lead

Resonate Group Ltd | Aug 2022 - Present

As the Information Security Lead at Resonate, I report directly to the CIO and partner closely with the Head of Technical Operations and CTO functions to architect business-wide security governance. My focus centers on orchestrating compliance across strict security frameworks and regulations, driving enterprise risk management approaches, and continuously elevating the security posture across both the IT corporate infrastructure and Operational Technology (OT) divisions of the business.

My core operations include:

  • Maintaining ISO27001 compliance standards
  • Managing Cyber Essentials Plus audit cycles
  • Advising CIO and CTO on organisational risks
  • Improving security controls over IT infrastructure
  • Lead changes in product security postures for OT systems
  • Directing enterprise risk registers & policies
  • Assessing emerging threats via threat intel streams
  • Organising internal & external audit campaigns
  • Developing comprehensive security training for staff
  • Auditing third-party supply chain risks

Key Achievements

  • Built security governance across IT and operational technology (OT) environments
  • Lead audit readiness across ISO 27001 and Cyber Essentials Plus activities
  • Improved and standardised supplier assurance and risk visibility for leadership stakeholders
  • Developed security awareness initiatives to improve staff engagement.
  • Established company AI policies and streamlined full scale deployment to users

Information Security Analyst

Acorn Insurance & Financial Services Ltd | Nov 2021 - Aug 2022

I worked as part of the core InfoSec team, collaborating daily with the IT and Infrastructure divisions to maintain the integrity of Acorn Insurance systems.

Key focus areas included:

  • Conducting regular supplier security due diligence
  • Aligning upstream suppliers with corporate risk appetite
  • Reviewing and implementing core InfoSec controls
  • Authoring and regular updating of security policies
  • Evaluating emerging cyber threats and mitigation profiles
  • Monitoring alerts across critical baseline infrastructure
  • Investigating unauthorised or suspicious user activity
  • Generating risk reports for company stakeholders
  • Publishing internal security awareness newsletters
  • Managing enterprise cybersecurity training portals

Key Achievements

  • Standardised vendor assessment models to decrease supplier risk onboarding loops
  • Optimised infrastructure alerting streams to reduce diagnostic response lag for critical indicators
  • Overhauled data security policies to align corporate framework logic with dynamic risk models
  • Boosted user cybersecurity readiness via scaled delivery of technical awareness content

Network Engineer

Safetynet Solutions Ltd | Sep 2016 - Nov 2021

Safetynet Solutions is a SME with 50 – 100 employees across 2 offices that supplies in-house Visitor Management solutions to customers from the education system to tenanted buildings across several countries.

My role developed massively over the course of 5 years starting from helpdesk support technician to Network Engineer, which laid a robust foundation for my specialisation in information security.

Key focus areas included:

  • Responsible for internal IT and infrastructure security
  • Providing 3rd-line customer support resolution channels
  • Maintaining support desk SLA compliance guidelines
  • Supporting software teams on complex software builds
  • Carrying out remote system installs for clients
  • On-premise deployments of server and network units
  • Maintaining SQL Server instances & cloud storage targets
  • Managing core corporate SaaS and telecommunication assets
  • Maintaining Cyber Essentials alignments across divisions
  • Evaluating upstream suppliers against control frameworks

Key Achievements

  • Engineered on-premise hardware footprints and complex multi-site deployments
  • Sustained high-tier performance across multi-region SQL databases and cloud instances
  • Led internal infrastructure hardening projects to scale structural security capability
  • Consistently beat strict SLA expectations for intricate tier-3 operational support agreements