Beyond the job title

Curiosity with a practical purpose.

I work across incident response, offensive security and the engineering that makes a SOC effective. I want to understand the attack path, the telemetry that exposes it and the response the team can actually execute.

My software background helps me follow an incident through application behaviour, endpoint execution, identity and network activity. In investigations, I correlate the available evidence, build a timeline and make clear which conclusions the telemetry supports. My experience spans Microsoft 365 account compromise, staged PowerShell malware, VPN intrusion and remote-support abuse.

Studying computer science alongside philosophy broadened the questions I ask. Teaching computing to refugee children and helping teachers use digital tools made clear communication part of the work.

At UK Water Utility, that approach extends into KQL investigation queries, Microsoft Sentinel detection workflows, Defender for Endpoint Live Response scripts and ServiceNow SecOps integration testing. My offensive scoping has also included AI chatbot testing requirements, alongside on-prem Active Directory, email security and EDR coverage.

Education, research & community ↗

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Skills, achievements, technical detail. Follow the evidence.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.