At Skaylink, I restructure detection logic across 100k+ endpoints, build identity-event automation playbooks, and serve as a primary escalation point for major incidents.
Previously at NCC Group and Redscan/Kroll, I led end-to-end investigations from detection through remediation, contained ransomware incidents, refined alert rules, and developed threat-hunting modules for critical vulnerabilities and zero-days.
I've mentored junior analysts, created incident and threat-hunting runbooks, supported customer service improvements, and researched IoT and firmware security at the University of Birmingham.

