Overview
What I do
- Run the annual Cyber Essentials Plus certification cycle end to end:
- assess the environment against the five controls and identify gaps
- drive remediation with IT and engineering teams
- collate the evidence ahead of the audit
- work alongside the external assessor during the audit stage
- Managed and delivered the annual penetration testing programme for over two years, coordinating scope, vendor engagement, and remediation tracking through to closure
- Develop and maintain IT security policies, SOPs, and incident documentation aligned to ISO 27001 and GDPR
- Conduct Business Continuity (BCP) and Disaster Recovery (DR) reviews with senior management and engineering teams
- Manage the organisation's AI tools and their security
- Deliver security awareness training and phishing simulations across the organisation
- Collaborate with DevOps, compliance, and governance teams to put risk reduction into practice






