At CyberHawk Limited, I lead incident response for managed clients, from alert triage and forensic investigation through containment, root cause analysis, and post-incident reporting. I also led the investigation of an SSL VPN breach at EXIM Bank, followed by phishing simulation and awareness training for bank staff.
For Ghana Airport Company Limited, I led full SIEM onboarding: I designed the HLD and LLD, onboarded 150+ log sources and 50+ network devices, and integrated security tools into centralized monitoring. I also engineer and tune detections using threat intelligence and MITRE ATT&CK, and developed custom QRadar Pulse dashboards for client security operations.
I deployed QRadar log collectors and onboarded the Parliament of Ghana and the Ghana Civil Aviation Authority into centralized monitoring. I also deliver monthly threat and security posture briefings to parliamentary leadership, and supported SOC analyst onboarding and training at newly built SOCs.
Earlier, as a Cybersecurity Consultant at B&P Cyber Intelligence Consult, I designed and deployed SIEM and IDS solutions and led incident response and forensic investigations for phishing, malware, and ransomware incidents. I maintain my personal site and technical writing at ptsatsu.github.io, and continue hands-on DFIR practice through Blue Team Labs Online.

