My CV

Technical security leadership.

I lead security operations, security engineering, incident response, and cyber threat intelligence programmes for technology businesses.

Professional experience

Aug 2026 - Present

Director of Security Operations

Mews, London

  • Lead Mews’ global, 24/7 Security Operations and Cyber Threat Intelligence teams.
  • Own the tribe’s strategy, operating model, and P&L, balancing security outcomes, customer trust, and regulatory obligations with sustainable commercial investment.
  • Provide transformational leadership across a distributed, multidisciplinary tribe, establishing clear accountability, decision-making, and performance expectations.
  • Shift the function from activity-based delivery to measurable outcomes: reduced business risk, faster and more effective response, greater operational resilience, and improved customer confidence.
  • Oversee the SOC’s detection, investigation, and incident response capabilities across Mews’ production environment.
  • Lead the Cyber Threat Intelligence team, translating strategic and operational intelligence into informed business decisions, threat-led priorities, and stronger defensive coverage.
  • Partner with Engineering and Product leadership to embed security into architectural decisions, platform development, and the product delivery lifecycle.
  • Advise executive stakeholders on cyber risk, major incidents, investment priorities, and the security implications of strategic initiatives, including acquisitions.
  • Represent Security Operations with customers and partners, strengthening trust before, during, and after security incidents.
Jul 2025 - Jul 2026

Senior Engineering Manager, Technical Security

Mews, London

  • Built an in-house, 24/7 Security Operations function to protect the Mews product ecosystem, its customers, and their guests.
  • Partnered with the relevant Engineering tribes to build a resilient DevSecOps pipeline.
  • Crafted the Security Operations strategy, including target operating models and target cyber state.
  • Developed the Security Operations Playbook, including the policies, standards, and guidelines that enable the programme.
  • Implemented automation, shift-left, and self-service platforms to embed Security Operations into the software development lifecycle.
  • Supported regulatory compliance across ISO 27001, SOC 2, GDPR, CCPA, NIS2, DORA, and PCI DSS.
  • Worked with Product teams to establish security as a core product feature and business enabler, driving deeper customer engagement and new business opportunities.
  • Engaged Mews customers before, during, and after security incidents to embed security practices into how products are built, shipped, and scaled.
  • Led customer engagements that inspired confidence among Mews customers and partners.
  • Supported M&A processes by auditing the security posture and practices of prospective acquisitions.
  • Influenced product architecture in areas overlapping with Security Operations, including logging, metrics, and traces.
Jul 2024 - Jun 2025

Senior Cyber Security Manager

Square Enix, London

  • Managed and led the Security Operations and Security Engineering teams, ensuring they had the skills, resources, and support to carry out their roles effectively.
  • Crafted the cyber security strategy around Square Enix’s strategic inputs, with a focus on the team’s vision and mission, strategic objectives, target cyber state, top risks, and target operating model.
  • Managed security budgets, ensuring cost-effective investment in security tools and technologies.
  • Oversaw compliance with industry regulations and standards, including J-SOX, PCI DSS, and the Online Safety Act.
  • Developed and implemented security policies, standards, and guidelines aligned with Square Enix’s strategic objectives and regulatory requirements.
  • Ensured security systems and technologies were configured, monitored, and maintained to the highest standards, with issues identified and resolved promptly.
  • Conducted regular security assessments and audits, ensuring issues were addressed and remediated in a timely manner.
  • Maintained a thorough understanding of the threat landscape and emerging security trends to continually improve Square Enix’s security posture.
  • Co-led the Trust & Safety programme, defining strategy, policies, and governance to mitigate risks relating to user safety, community integrity, and legal compliance.
Sep 2019 - Jun 2024

SOC Manager

Square Enix, London

  • Established an internal Security Operations capability from the ground up, encompassing governance structures, personnel roles and responsibilities, operational processes, service offerings, and supporting technologies.
  • Oversaw the operational management of Security Monitoring, Incident Response, Cyber Threat Intelligence, Threat Hunting, and Threat and Vulnerability Management, ensuring continuous detection, analysis, containment, eradication, and recovery across enterprise and production environments.
  • Developed a Security Operations Centre strategy and multi-year roadmap aligned with the risk profile, regulatory obligations, and business objectives of a global, cloud-native gaming enterprise.
  • Designed and implemented performance metrics, key risk indicators, and service-level dashboards to assess operational effectiveness, control coverage, detection fidelity, and programme maturity.
  • Collaborated with game development and IT stakeholders to integrate security requirements, monitoring capabilities, and control validation into corporate systems and gaming platforms throughout the system development lifecycle.
Jan 2019 - Aug 2019

SOC Manager

Mimecast, London

  • Managed daily SOC activities, ensuring continuous 24/7 monitoring and incident response coverage through a coordinated follow-the-sun operating model.
  • Developed and mentored SOC personnel to improve analytical capability, operational efficiency, and structured career progression within the team.
  • Oversaw and optimised security monitoring technologies, including SIEM, EDR, NDR, and threat intelligence platforms, to improve detection fidelity, reduce false positives, and mitigate alert fatigue.
  • Defined and maintained SOC performance metrics and KPIs to evaluate operational effectiveness, measure service outcomes, and communicate programme value to executive leadership.
  • Coordinated incident response escalation procedures with Legal, Public Relations, and other stakeholders to ensure timely, consistent, and risk-informed response actions.
  • Formulated and designed a SOC strategy aligned with Mimecast’s business objectives and cyber security strategy.
Earlier roles

Individual contributor experience

Apr 2018 - Dec 2018 Security Incident Response Analyst, Mimecast, London

Jan 2017 - Mar 2018 SOC Analyst, Mimecast, London

Oct 2015 - Dec 2016 Security Analyst, Deloitte, Barcelona

Selected appearances

Talks, webinars & case studies

Recorded Future · CISO Office Hour

Defending User Security and Brand Integrity with Intelligence

Watch on source
Mews · Mini Podcast

Security is not a cost center, it’s a profit protector

Watch on source
Elastic · Customer Story

Japanese gaming giant protects in-game digital artworks and NFTs with Elastic

Read case study