Threat hunter, incident responder, and security engineer. I build security operations from the ground up.
BSc Computer Science · MSc Artificial Intelligence · PhD in being a nerd
I was part of the founding team that built ExpressVPN's Security Operations Center from nothing — and I've spent the years since scaling it into a 18-person, 24/7 operation spanning threat hunting, detection engineering, security engineering, and incident response.
My work spans the deeply technical and the strategic: hunting novel threats across endpoint, network, and cloud telemetry, architecting AI-driven automation, standing up detection-as-code pipelines, and driving security compliance across half a dozen frameworks. Before ExpressVPN, I cut my teeth at JPMorgan Chase, Accenture, and BHP.
Architecting the SOC's AI roadmap.
I built the AI agent now working alongside our L1 tier, re-checking alerts, tickets, and ~30 dashboards to catch the outages and escalations that slip through the cracks.
Grew a 5-person threat-hunting team into a 18-person, 24/7 tiered SOC, adding an L1 monitoring tier and a dedicated brand-protection capability.
Built a detection-as-code pipeline where every detection is version-controlled, peer-reviewed, and tested before it ships, plus a Claude skill that opens PRs to create and refine detections.
Drove compliance across ISO 27001, SOC 2, PCI-DSS, the EU Cyber Resilience Act, and UK Cyber Essentials, taking each from gap assessment through certification and audit.
Deployed Carbon Black EDR across 500+ workstations and 800+ servers, and built a security data lake to centralize logs and cut SIEM costs.
Designed a Threat Modeling program and an ML anomaly-detection model sifting millions of data points to surface novel threats.
Triaged and investigated SIEM events with a cross-region analyst team; analyzed and mitigated malicious activity across the firm.
2019–20Managed a government Federated Identity service for 5M+ users; delivered an RFID 2FA + SOC monitoring PoC exhibited at Asian Utility Week 2018.
2018–19Scanned and assessed open vulnerabilities across web applications and internal servers using Qualys.
2017A niche job board built for cybersecurity careers — connecting practitioners with roles that actually fit, across SOC, security engineering, penetration testing, cloud security, and GRC.
A competitive, gamified language-learning app. Learn vocabulary and grammar through story-driven scenarios, starting with beginner Chinese (HSK1), while battling in real-time PvP matches or against AI "ghost" opponents to earn XP, streaks, and leaderboard ranks.
Built language-agnostic from day one, with Dutch and more on the roadmap alongside sound design, a story overhaul, and a training mode.
Hiring, speaking, collaborating on a side project, or just want to talk about security — my inbox is open.