I build and test the things that catch attackers. By day I'm a cybersecurity consultant working on enterprise cyber defence transformation i.e. SOC modernisation, detection strategy, and the use of AI to augment security operations. By night I write detections, break them on purpose, and build small tools to make both easier.
My work sits at the seam between offence and defence: I use offensive technique knowledge (GPEN, GWEB) to write detections that survive contact with a real adversary, and detection engineering discipline (GSOC, GCDA) to make sure emulation produces evidence rather than noise.
Deepening cloud and application security, working toward GCDA, and building tooling around detection validation. Always up for a conversation about detection engineering, purple teaming, or where AI actually helps in a SOC (and where it doesn't).
Certifications: GPEN · GWEB · GSOC · Certified DevSecOps Professional · GCP ACE · Security+

