I help organisations secure their environments and meet compliance, bridging hands-on Microsoft security, SOC operations, and GRC frameworks like SMB1001 and SOC 2.
Cybersecurity specialist at a Microsoft-focused MSP, supporting 300+ SMB tenants. Hands-on across SOC monitoring, phishing investigation, incident response, and Entra ID hardening, and selected to lead a SOC 2 Type 2 audit readiness programme.
My approach is direct and hands-on. I'd rather ship a working, well-documented control than write a slide about it.
I ground my work in established frameworks, frequently building from NIST CSF, so security decisions map to recognised standards rather than guesswork.
Just as important, I translate security risk into plain language: turning technical findings into clear, actionable decisions that non-technical stakeholders can understand and act on.
Designed and deployed a full Azure application stack from scratch: App Service with managed identity, Key Vault in RBAC mode, Azure Files storage, an encrypted database, and Entra authentication scoped to a security group. Worked alongside the application developer through to a live production handover.
Drove a SOC 2 Type 2 engagement end to end: authoring the full policy set, embedding adherence across the team, and establishing change controls and evidence collection. Mapped controls to operational practice so the certification reflected how the business actually runs rather than a paper exercise.
Looking for a hand with security or compliance?