Build and improve security operations
SOC and MXDR service design, operating models, process improvement, technical assurance and delivery optimisation.
Security Operations Microsoft Security Applied AI
I help organisations improve SOC and MXDR capability, combining deep technical experience in Sentinel, Defender and KQL with service design, AI adoption and people leadership.
What I do
I work across the technical, operational and leadership layers of security delivery. This is useful when the problem does not fit neatly into one job description.
SOC and MXDR service design, operating models, process improvement, technical assurance and delivery optimisation.
Sentinel, Defender, KQL, detections, integrations and automation shaped around how analysts and services actually operate.
Evaluation, procurement and deployment of AI-enabled SOC capability, focused on practical adoption and measurable operational value.
How I work
My background spans hands-on SOC delivery, SIEM engineering, security architecture, client-facing technical leadership and cross-functional team leadership across Service Delivery and Technical Account Management.
That means I can move between analysts, engineers, clients and senior stakeholders without losing the thread.
01 Identify a high-friction analyst workflow
02 Evaluate AI against operational controls
03 Integrate with existing SOC processes
04 Measure quality, consistency and time saved
Applied AI
I have been directly involved in the procurement and deployment of AI-enabled SOC technology, alongside practical experimentation with local and edge AI using NVIDIA Jetson hardware.
My focus is operational: where AI can reduce friction, improve consistency and support analysts without weakening accountability.
Contract enquiries
I am open to contract engagements across security operations, MXDR, Microsoft security, solution design and applied AI.