Security leadership for regulated companies

Or companies that know they need to step up — but don't know exactly how

Let's Talk

Who I Work With

I work with companies that need to scale security without building a large internal security organisation.

This includes regulated companies facing compliance pressure (NIS2, ISO 27001, GDPR) and growth-stage companies that recognize security gaps but don't know where to start.

Typical situations I'm brought into:

If security feels important and overwhelming at the same time, this is usually where I help.

What I Do

Most organisations don't fail security because they lack tools. They fail because governance, regulation, and engineering never fully meet.

The Intersection

I work at the intersection of governance, regulation, and engineering — translating regulatory and compliance requirements into concrete, automated security controls embedded directly into development and cloud platforms.

In a way developers actually follow and auditors accept.

Executive & Leadership

  • Security strategy and risk management
  • Governance, regulatory interpretation, and audit readiness
  • Clear ownership and decision support

Engineering & Platform

  • Secure coding and cloud security
  • DevSecOps and CI/CD automation
  • Practical controls that scale with development

How I Work

End-to-End Ownership

I take end-to-end ownership of the security outcomes I'm responsible for.

  • Clear scope and expectations
  • Pragmatic prioritisation based on real risk
  • Hands-on execution where needed
  • Minimal disruption to product development

Direct Partnership

You work directly with me — no hand-offs, no junior layers, no ambiguity about responsibility.

The outcome is security that reduces risk and friction — instead of creating it.

Services

I offer outcome-based services rather than hourly consulting.

ISO 27001 / NIS2 Readiness as a Service

I take responsibility for getting you audit-ready — policies, controls, tooling, documentation, and evidence — without slowing engineering.

Virtual Head of Security (vCISO / Security Architect)

Ongoing senior security leadership without hiring a full-time CISO. Strategy, governance, architecture, and audit interface — owned.

Audit Gap Closure & Remediation Sprints

Fast, focused closure of audit findings. I prioritise what matters, implement fixes, and support acceptance by auditors.

Why Work With Me

Security should support the business — not slow it down.

20+ Years of Experience

Proven experience across security, engineering, and IT operations in highly regulated environments.

Hands-On & Pragmatic

Automation-focused approach with practical, actionable solutions that work in the real world.

One Accountable Owner

You get one responsible partner instead of fragmented responsibility across multiple vendors or consultants.

Industry Accreditations

Holding the most esteemed certifications in the industry to ensure the highest standards of cybersecurity expertise.

ISC2 CISSP

The gold standard for cybersecurity professionals, demonstrating expertise in designing, implementing, and managing best-in-class cybersecurity programs.

ISACA CISM

Showcases mastery in information security management, with expertise in developing and overseeing robust security frameworks for organizations.

ISC2 CCSP

Signifies mastery in cloud security, validating proficiency in designing, implementing, and managing cloud environments securely.

ISACA CRISC

Demonstrates expertise in IT risk management, with a focus on identifying, assessing, and mitigating risks related to information systems.

ISO 27001 Lead Implementer

Proves expertise in implementing and managing an Information Security Management System (ISMS) according to ISO 27001 standards.

Let's Talk

If you're facing regulatory pressure, an upcoming audit or growing security risk

— I'm happy to have an initial conversation and help you assess the situation.