Andrew Simmonds
~/andy $ whoami

Andrew Simmonds
Cybersecurity Consultant

I help organisations secure their environments and meet compliance, bridging hands-on Microsoft security, SOC operations, and GRC frameworks like SMB1001 and SOC 2.

Sydney, Australia andrew@simmonds.co.com LinkedIn
// about

Cybersecurity specialist at a Microsoft-focused MSP, supporting 300+ SMB tenants. Hands-on across SOC monitoring, phishing investigation, incident response, and Entra ID hardening, and selected to lead a SOC 2 Type 2 audit readiness programme.

My approach is direct and hands-on. I'd rather ship a working, well-documented control than write a slide about it.

I ground my work in established frameworks, frequently building from NIST CSF, so security decisions map to recognised standards rather than guesswork.

Just as important, I translate security risk into plain language: turning technical findings into clear, actionable decisions that non-technical stakeholders can understand and act on.

// experience
Oct 2024 — Jul 2026

Cybersecurity Specialist

Ember Technology
  • SOC monitoring and incident response across a 300+ tenant SMB base, handling alerts through the full IR lifecycle from triage to lessons-learned hardening.
  • Selected to lead the company's SOC 2 Type 2 audit readiness end to end: policy rewrites, vendor risk assessments, change management, and technical control mapping.
  • Hardened client environments with conditional access, MFA, geo-fencing, and Intune and Defender configuration, lifting Microsoft Secure Score across the estate.
  • Took clients from no formal controls to a full Microsoft security baseline (Defender for Endpoint and O365, Entra ID, Intune).
  • Owned end-to-end incident response for phishing and account compromise: detection, containment, eradication, recovery, and post-incident review that fed back into tenant hardening.
2024

Cybersecurity Intern

Datacom
  • Self-selected to research the ASD Essential Eight Application Control maturity model and presented practical implementation strategies to senior stakeholders.
  • Hands-on exposure to Burp Suite, CrowdStrike Falcon, and Microsoft Sentinel in an enterprise environment.
2023 — 2024

Technical Support Specialist

Harvey Norman
  • Resolved complex hardware and software issues for consumer and business clients, an early hands-on step into IT and customer-facing technical support.
// selected work
Azure deployment

End-to-end app service build for a financial services client

Designed and deployed a full Azure application stack from scratch: App Service with managed identity, Key Vault in RBAC mode, Azure Files storage, an encrypted database, and Entra authentication scoped to a security group. Worked alongside the application developer through to a live production handover.

Azure App Service Key Vault (RBAC) Managed Identity Entra Easy Auth Azure CLI
Compliance

SOC 2 Type 2 certification programme

Drove a SOC 2 Type 2 engagement end to end: authoring the full policy set, embedding adherence across the team, and establishing change controls and evidence collection. Mapped controls to operational practice so the certification reflected how the business actually runs rather than a paper exercise.

SOC 2 Type 2 Policy Authoring Change Control Evidence Collection
// capabilities

Security Operations

Microsoft SentinelDefender XDR PurviewAlert Triage Incident Response

Identity & Endpoint

Entra IDConditional Access MFAIntune Defender for Endpoint

Email Security

Defender for O365SPF / DKIM / DMARC Anti-spoofing

Governance & Compliance

SOC 2 Type 2Essential Eight SMB1001 GoldNIST CSF

Tools & Scripting

PowerShellSQL Burp SuiteLinux
// certifications
2026CompTIA Security+ (SY0-701)
2026Microsoft SC-900
// education
2024Diploma in Cybersecurity (Level 6)
2018BCom, International Business · Diploma in Chinese Language
// contact

Looking for a hand with security or compliance?