I work in security operations, investigating and responding to threats, with a background in Microsoft security hardening and compliance frameworks like SOC 2 and SMB1001.
SOC Analyst at CyberCX in Sydney. Before that, I spent close to two years at a Microsoft-focused MSP supporting 300+ SMB tenants, working hands-on across SOC monitoring, phishing investigation, incident response, and Entra ID hardening, and led the company's SOC 2 Type 2 programme from readiness into the audit observation period.
My approach is direct and hands-on. I'd rather ship a working, well-documented control than write a slide about it.
I ground my work in established frameworks, frequently building from NIST CSF, so security decisions map to recognised standards rather than guesswork.
Just as important, I translate security risk into plain language: turning technical findings into clear, actionable decisions that non-technical stakeholders can understand and act on.
Designed and deployed a full Azure application stack from scratch: App Service with managed identity, Key Vault in RBAC mode, Azure Files storage, an encrypted database, and Entra authentication scoped to a security group. Worked alongside the application developer through to a live production handover.
Led a SOC 2 Type 2 programme from readiness into the audit observation period: authoring the full policy set, embedding adherence across the team, and establishing change controls and evidence collection. Mapped controls to operational practice so the programme reflected how the business actually runs, not a paper exercise.
Want to connect? Happy to chat about security operations, Microsoft security or compliance.