Oxford, England
ProjectsJuly 1, 2024

Cyber Essentials Plus, ISO 27001 and security governance

Cyber Essentials Plus, ISO 27001 and security governance
Alongside operational security, I own much of the security governance work at a UK health-tech company. This includes getting the organisation ready for Cyber Essentials Plus certification and keeping its policies aligned with ISO 27001 and GDPR.
  • Run the annual Cyber Essentials Plus certification cycle end to end:
    • assess the environment against the five controls and identify gaps
    • drive remediation with IT and engineering teams
    • collate the evidence ahead of the audit
    • work alongside the external assessor during the audit stage
  • Managed and delivered the annual penetration testing programme for over two years, coordinating scope, vendor engagement, and remediation tracking through to closure
  • Develop and maintain IT security policies, SOPs, and incident documentation aligned to ISO 27001 and GDPR
  • Conduct Business Continuity (BCP) and Disaster Recovery (DR) reviews with senior management and engineering teams
  • Manage the organisation's AI tools and their security
  • Deliver security awareness training and phishing simulations across the organisation
  • Collaborate with DevOps, compliance, and governance teams to put risk reduction into practice
ISO 27001, GDPR, Cyber Essentials Plus, with working knowledge of ISO 9001, COBIT, SOC 2, SOX, NIST, PCI DSS, DSPT, HIPAA, and CIS Controls.

Related projects

Penetration testing consultancy
Ongoing

Penetration testing consultancy

Independent penetration testing as a freelance consultant, backed by more than two years of managing and delivering an annual penetration testing programme in-house.
Xcevia: a security consultancy in the making
In development

Xcevia: a security consultancy in the making

A practitioner-led security consultancy for UK SMEs that I'm building on the side. It's not trading yet. The groundwork is being laid for Cyber Essentials Plus readiness, cloud security, and DevSecOps support.
Cutting security tooling costs by 60% while widening coverage

Cutting security tooling costs by 60% while widening coverage

A vendor review at a UK health-tech company. I consolidated onto one platform that covers every operating system and the cloud, then closed the one remaining gap with a dedicated patch management tool.
Incident response and endpoint security in health tech

Incident response and endpoint security in health tech

Owning day-to-day alert handling across a multi-OS estate at a UK health-tech company, correlating cloud activity with endpoint telemetry, and leading the response to a live, high-severity security incident.
Embedding SAST into CI/CD pipelines

Embedding SAST into CI/CD pipelines

Adding static application security testing (SAST) to a health-tech company's delivery pipelines, so developers find code-level vulnerabilities before release rather than after.
EchoCare: a digital complaint management system for home care

EchoCare: a digital complaint management system for home care

An Innovate UK funded feasibility study and proof of concept with PBL Care Limited and Birmingham City University. The system replaces paper-based complaint handling with CQC-standard digital forms, NLP classification, and a live dashboard.