Oxford, England
ProjectsJuly 3, 2024

Incident response and endpoint security in health tech

Incident response and endpoint security in health tech
At a UK health-tech company I own day-to-day security alert handling across the endpoint estate (Windows, macOS, and Linux), first as System Administrator and Threat Management Engineer, and now as DevSecOps Engineer. The most significant engagement in this role was leading the response to a live, high-severity security incident.
  • Triage and mitigate alerts from the EDR/XDR platform, escalating and responding according to incident severity and response protocols
  • Lead containment, investigation, and recovery once an incident is confirmed
  • Support cloud security operations, including access control and audit-log monitoring
  • Correlate cloud activity with endpoint telemetry to build a complete picture of an incident
  • Produce incident documentation and evidence for leadership and regulators
Incident response, EDR/XDR operations, threat triage, cloud security monitoring, incident documentation.

Related projects

Penetration testing consultancy
Ongoing

Penetration testing consultancy

Independent penetration testing as a freelance consultant, backed by more than two years of managing and delivering an annual penetration testing programme in-house.
Xcevia: a security consultancy in the making
In development

Xcevia: a security consultancy in the making

A practitioner-led security consultancy for UK SMEs that I'm building on the side. It's not trading yet. The groundwork is being laid for Cyber Essentials Plus readiness, cloud security, and DevSecOps support.
Cutting security tooling costs by 60% while widening coverage

Cutting security tooling costs by 60% while widening coverage

A vendor review at a UK health-tech company. I consolidated onto one platform that covers every operating system and the cloud, then closed the one remaining gap with a dedicated patch management tool.
Embedding SAST into CI/CD pipelines

Embedding SAST into CI/CD pipelines

Adding static application security testing (SAST) to a health-tech company's delivery pipelines, so developers find code-level vulnerabilities before release rather than after.
Cyber Essentials Plus, ISO 27001 and security governance

Cyber Essentials Plus, ISO 27001 and security governance

Preparing the organisation for Cyber Essentials Plus certification, running the annual penetration testing programme, and keeping security policy, BCP/DR and awareness training aligned with ISO 27001 and GDPR.
EchoCare: a digital complaint management system for home care

EchoCare: a digital complaint management system for home care

An Innovate UK funded feasibility study and proof of concept with PBL Care Limited and Birmingham City University. The system replaces paper-based complaint handling with CQC-standard digital forms, NLP classification, and a live dashboard.