Security Operations Microsoft Security Applied AI

I design, modernise and lead security operations.

I help organisations improve SOC and MXDR capability, combining deep technical experience in Sentinel, Defender and KQL with service design, AI adoption and people leadership.

12+ years in cybersecurity
Cross-functional leadership across service delivery and technical account management
3 domains: technology, service, leadership
Operational capability map Active
SENTINEL DEFENDER APPLIED AI LEADERSHIP SERVICE DESIGN KQL / SIEM SECURITY OPERATIONS
SOC & MXDR Microsoft Sentinel Microsoft Defender KQL Applied AI Service Design People Leadership SOC & MXDR Microsoft Sentinel Microsoft Defender KQL Applied AI Service Design People Leadership

What I do

Specialist capability without the usual silos.

I work across the technical, operational and leadership layers of security delivery. This is useful when the problem does not fit neatly into one job description.

01

Build and improve security operations

SOC and MXDR service design, operating models, process improvement, technical assurance and delivery optimisation.

SOCMXDROperating models
02

Modernise Microsoft security environments

Sentinel, Defender, KQL, detections, integrations and automation shaped around how analysts and services actually operate.

SentinelDefenderKQL

How I work

Technical enough to challenge the detail. Senior enough to move the service.

My background spans hands-on SOC delivery, SIEM engineering, security architecture, client-facing technical leadership and cross-functional team leadership across Service Delivery and Technical Account Management.

That means I can move between analysts, engineers, clients and senior stakeholders without losing the thread.

Technology
Sentinel · Defender · KQL · SIEM
Service
MXDR · Operating models · Assurance
Leadership
Teams · Clients · Change
Applied AI
Evaluation · Procurement · Adoption
One consultant Across the full delivery chain
security.ai / operational-use-case

01 Identify a high-friction analyst workflow

02 Evaluate AI against operational controls

03 Integrate with existing SOC processes

04 Measure quality, consistency and time saved

OUTCOME Useful AI, not theatre.

Applied AI

Interested in what AI changes in the SOC, and what it does not.

I have been directly involved in the procurement and deployment of AI-enabled SOC technology, alongside practical experimentation with local and edge AI using NVIDIA Jetson hardware.

My focus is operational: where AI can reduce friction, improve consistency and support analysts without weakening accountability.

12+ years from frontline SOC work to principal solution design
Cross-functional leadership experience across Service Delivery and Technical Account Management
End-to-end technology, service, client and leadership experience

Contract enquiries

Need someone who can bridge security technology, service delivery and leadership?

I am open to contract engagements across security operations, MXDR, Microsoft security, solution design and applied AI.