Security engineer with 8 years in application and cloud security for fintech and SaaS. Builds security into the development lifecycle, leads incident response and has reduced critical vulnerabilities while helping teams ship faster. Pragmatic about risk, fluent with engineers and executives, and focused on controls that teams can actually adopt.
- Built an automated security pipeline with SAST, dependency and secret scanning across 200 repositories.
- Reduced open critical vulnerabilities from 140 to 6 in 9 months with a risk-based remediation program.
- Led response to 12 security incidents, containing each within the 4-hour target.
- Designed IAM guardrails in AWS that removed 1,800 unused privileged permissions.
- Trained 150 engineers in secure coding, cutting new high-severity findings by 50%.
- Partnered with legal on 3 vendor risk reviews a month, approving suppliers within 5 days on average.
- Performed 60+ threat models and design reviews for payment features handling £2B a year.
- Ran the bug bounty program, triaging 400 reports and paying out for 45 valid findings.
- Achieved PCI DSS certification for 3 consecutive years with zero major findings.
- Developed a security champions network of 20 engineers across 8 teams.
- Built automated detection rules in the SIEM that reduced false-positive alerts by 60%.
- Led a security awareness campaign for 1,200 employees that cut phishing click rates from 12% to 3%.
- Tested 50+ web and mobile applications for clients in banking, retail and government.
- Wrote reports with remediation guidance that clients rated 4.8 out of 5 on average.
- Developed 10 custom testing scripts in Python that the team reused on later engagements.
- Organized 12 meetups a year for 150+ members on application security topics.
Security: Threat modelling, AppSec, Cloud security, Incident response, PCI DSS
Tools: Burp Suite, Semgrep, AWS, Terraform, Python