Andrew Simmonds
~/andy $

Andrew Simmonds
SOC Analyst

I work in security operations, investigating and responding to threats, with a background in Microsoft security hardening and compliance frameworks like SOC 2 and SMB1001.

Sydney, Australia andrew@simmonds.co.com LinkedIn
// about

SOC Analyst at CyberCX in Sydney. Before that, I spent close to two years at a Microsoft-focused MSP supporting 300+ SMB tenants, working hands-on across SOC monitoring, phishing investigation, incident response, and Entra ID hardening, and led the company's SOC 2 Type 2 programme from readiness into the audit observation period.

My approach is direct and hands-on. I'd rather ship a working, well-documented control than write a slide about it.

I ground my work in established frameworks, frequently building from NIST CSF, so security decisions map to recognised standards rather than guesswork.

Just as important, I translate security risk into plain language: turning technical findings into clear, actionable decisions that non-technical stakeholders can understand and act on.

// experience
Jul 2026 — Present

SOC Analyst

CyberCX
  • Monitor, triage, and investigate security alerts across multiple client environments.
  • Document investigation findings in concise, evidence-based reports.
Oct 2024 — Jul 2026

Cybersecurity Specialist

Ember Technology
  • SOC monitoring and incident response across a 300+ tenant SMB base, handling alerts through the full IR lifecycle from triage to lessons-learned hardening.
  • Selected to lead the company's SOC 2 Type 2 programme from readiness into the audit observation period: policy rewrites, vendor risk assessments, change management, and technical control mapping.
  • Hardened client environments with conditional access, MFA, geo-fencing, and Intune and Defender configuration, lifting Microsoft Secure Score across the estate.
  • Took clients from no formal controls to a full Microsoft security baseline (Defender for Endpoint and O365, Entra ID, Intune).
  • Owned end-to-end incident response for phishing and account compromise: detection, containment, eradication, recovery, and post-incident review that fed back into tenant hardening.
2024

Cybersecurity Intern

Datacom
  • Self-selected to research the ASD Essential Eight Application Control maturity model and presented practical implementation strategies to senior stakeholders.
  • Hands-on exposure to CrowdStrike Falcon and Microsoft Sentinel in an enterprise environment.
2023 — 2024

Technical Support Specialist

Harvey Norman
  • Resolved complex hardware and software issues for consumer and business clients, an early hands-on step into IT and customer-facing technical support.
// selected work
Azure deployment

End-to-end app service build for a financial services client

Designed and deployed a full Azure application stack from scratch: App Service with managed identity, Key Vault in RBAC mode, Azure Files storage, an encrypted database, and Entra authentication scoped to a security group. Worked alongside the application developer through to a live production handover.

Azure App Service Key Vault (RBAC) Managed Identity Entra Easy Auth Azure CLI
Compliance

SOC 2 Type 2 programme

Led a SOC 2 Type 2 programme from readiness into the audit observation period: authoring the full policy set, embedding adherence across the team, and establishing change controls and evidence collection. Mapped controls to operational practice so the programme reflected how the business actually runs, not a paper exercise.

SOC 2 Type 2 Policy Authoring Change Control Evidence Collection
// capabilities

Security Operations

Microsoft SentinelDefender XDR Alert Triage Incident Response

Identity & Endpoint

Entra IDConditional Access MFAIntune Defender for Endpoint

Email Security

Defender for O365SPF / DKIM / DMARC Anti-spoofing

Governance & Compliance

SOC 2 Type 2Essential Eight SMB1001 GoldNIST CSF Purview

Tools & Scripting

KQLSPL PowerShellSQL Linux
// certifications
2026CompTIA Security+ (SY0-701)
2026Microsoft SC-900
// education
2024Diploma in Cybersecurity (NZQF Level 6)
2018BCom, International Business · Diploma in Chinese Language
// contact

Want to connect? Happy to chat about security operations, Microsoft security or compliance.