About me

Security leadership for complex systems.

I am a technical security leader who builds Security Operations, Cyber Threat Intelligence, and Security Engineering functions for product-led companies. I am at my best in complex, emergent environments, where the technology matters, the answer is not obvious, and progress depends on people working well together.

Closing the security loop

Security Engineering and Security Operations are most effective as one continuous system. Operations sees how threats, controls, and people behave in the real world; Engineering turns those lessons into stronger platforms, safer defaults, and better ways of building. Each makes the other more effective.

I connect the two through a shared feedback loop: engineer for visibility and response, learn from detections and incidents, then feed those lessons back into architecture and delivery. The result is less reactive work, earlier intervention, and improvements that remove whole classes of risk rather than repeatedly treating the symptoms.

Threat intelligence answers why

Security teams are surrounded by things they could fix, detect, or defend. Cyber Threat Intelligence provides the strategic “why”: which actors and behaviours matter to us, what they are trying to achieve, and how that should change our priorities. It turns an endless catalogue of possible threats into decisions grounded in the organisation's context.

I treat intelligence as a decision-making capability, not a feed of indicators. At the strategic level it guides risk and investment; at the operational and tactical levels it shapes engineering, detection, hunting, and response. That thread keeps daily security work connected to the threats and outcomes the business actually cares about.

How I lead

My approach combines servant and transformational leadership with intent-based decision-making. I set a high challenge and offer high support, maximise context rather than cascade instructions, and give teams the autonomy to decide how best to achieve an outcome. I think of the role less as a soloist and more as the conductor of an orchestra.

In the complex and chaotic domains of the Cynefin framework, psychological safety is an operational capability. Trust enables healthy conflict, vulnerability, accountability, and safe-to-fail experiments. The aim is not to “do Agile”, but to build a team capable of being agile: delivering better value, sooner, safer, and happier.

Outcomes over activity

Security is not simply a cost centre, it is a profit protector. A strong function protects the organisation's value streams and gives the business the confidence to enter markets, adopt technologies, and build products while leaning into risk deliberately.

That requires moving beyond local optimisation and output metrics. I use value-stream mapping and the theory of constraints to focus teams on measurable outcomes and customer impact. Culture beats technology, governance beats isolated controls, and activity only matters when it changes the result.

Current focus

Towards AI-native security operations.

AI is the most consequential shift I have seen in more than a decade in cybersecurity. Traditional automation works well for complicated, known tasks; Security Operations is dominated by complex and emergent work, including unknown unknowns. I am exploring what the security equivalent of the product and systems builder looks like, including through Kestrel: an autonomous SOC system designed to do the investigative heavy lifting, keep humans on the loop, and bring them into the loop when judgement or intervention is required.

Beyond security

I'm actively volunteering for Uncage Games, a indie-game studio using interactive storytelling to build empathy for animals and promote veganism. Away from work and game development, I enjoy classical music and playing piano, photography, travel, astronomy, religion, philosophy and learning languages.