About Me
I am a Chartered IT Professional (CITP) and Security and Platform Engineer. I bring more than nine years of experience across security engineering, secure platform operations, DevSecOps, enterprise software delivery, and cyber security education.
My work centres on turning complex security requirements into systems and practices that are resilient, measurable, maintainable, and practical to operate. I combine hands-on engineering experience in PKI, TLS, HSMs, DNS, privileged access, secure SDLC, Linux, automation, and cloud-native delivery with mentoring and technical leadership.
Across industry roles, I have worked at the intersection of secure platform operations and engineering delivery. This has included supporting DNS services handling 10B+ queries per month, building privileged-access automation using HashiCorp Vault and SSH certificate-based access in DMZ environments, and designing TLS/SSL certificate lifecycle processes across 600+ certificates and 4,000+ domains. Earlier work also included application migration, CI/CD modernisation, systems design, and resilience engineering in regulated enterprise settings.
I hold an MSc in Cyber Security Engineering with Distinction from the University of Warwick, completed through an NCSC-certified and BCS-aligned programme. My postgraduate work included applied cryptography, security architecture, penetration testing, digital forensics, network defence, information risk management, and enterprise cyber security.
My master’s research explored quantum-resistant secure messaging using ML-KEM, ML-DSA, and AES-GCM, with particular attention to key establishment, authentication, message integrity, and crypto-agility. I also hold a Bachelor of Engineering in Mechanical Engineering, which gave me an early foundation in systems thinking, numerical analysis, and engineering design.
My principal areas of interest are:
- Enterprise PKI, certificate lifecycle governance, and cryptographic key management
- Post-quantum cryptography and crypto-agile system design
- Secure-by-default platforms and zero-trust-oriented access
- Cloud-native secure SDLC, DevSecOps, CI/CD, and GitOps
- DNS resilience, platform security, and hybrid infrastructure
- Security architecture, assurance, and risk-based decision-making
- Practical, inclusive, and engineering-led cyber security education
I focus on security that can be demonstrated through clear ownership, reliable controls, useful evidence, and measurable outcomes. I am particularly interested in reducing operational fragility: replacing manual processes with auditable automation, making security decisions understandable to stakeholders, and designing controls that remain effective as systems scale.
I also believe that strong security practice depends on professional judgement and responsible leadership. Whether I am designing privileged-access controls, governing cryptographic assets, reviewing risk, or teaching future practitioners, I aim to make security proportionate, transparent, inclusive, and operationally sustainable.
For a detailed employment history, skills profile, qualifications, and professional activities, see my resume.
