- Conduct comprehensive vulnerability assessments and penetration tests across enterprise networks, web applications, and APIs, identifying critical security gaps and delivering risk-ranked remediation roadmaps.
- Monitor SIEM platforms and security tooling to detect, investigate, and contain threats, minimising mean time to detect (MTTD) and respond (MTTR) across client environments.
- Develop, implement, and enforce security policies and procedures to maintain compliance with GDPR and ISO/IEC 27001 standards, reducing audit findings by ensuring continuous control alignment.
- Collaborate cross-functionally with IT and engineering teams to embed security controls that align with business objectives and reduce organisational risk exposure.
- Analyse security logs and produce executive-level reports on incident trends, vulnerability posture, and remediation progress for senior stakeholders.
- Deliver security awareness training covering phishing recognition, secure coding practices, and incident reporting protocols to 50+ staff.
