About
Detection and response engineer. Ten years across banking, funds management, and government: detections as code, incidents run end to end, and an expanding focus on the AI attack surface.
Splunk ES · Sentinel · KQL · SPL · CrowdStrike · Defender · Python · PowerShell · Azure · Essential 8
Services
- Detection EngineeringATT&CK-mapped · Splunk ES · Sentinel · EDR
- SIEM Upliftonboarding · migration · coverage analysis
- AI Securityprompt monitoring · shadow AI · assistant assessments
- Incident Responsetriage → containment → recovery → review
- Security ConsultingE8 · APRA CPS 234 · NIST CSF
- Cyber Deceptionhoneypots · honeytokens · canaries
Blog
Occasional notes on detection engineering,
incident response, and the AI attack surface.
Contact
Currently contracting in detection & response —
and open to consulting engagements and advisory.