Security Architect2021 - PRESENTInternational Airlines Group (IAG)
Technologies: AWS, Snowflake, OAuth 2, Containers, Tokenization, Information Security, SAML, PingFederate, PaaS, SaaS, Web Application Firewall (WAF), Patterns, IT Strategy, APIs, Solution Architecture, DevSecOps, Cloud Security, Data Security, Security Architecture, Enterprise Architecture, Stakeholder Management
- Oversaw the security of the platform and its use by various brands within the group.
- Defined security patterns for the use of data by various actors.
- Developed the platform security strategy to meet the data demands across the group.
- Managed the security engineering function to ensure alignment with security objectives.
Enterprise Architect | Cloud Security2020 - 2021Lloyds Banking Group
Technologies: AWS, Google Cloud Platform (GCP), Azure, HashiCorp, PingFederate, SaaS, PaaS, SAML, Containers, OAuth 2, Cloud Migration, IT Strategy, APIs, Patterns, DevSecOps, Cloud Security, Data Security, Security Architecture, Information Security, Enterprise Architecture, Stakeholder Management
- Crafted a bank-wide strategy for cloud security and roadmap that balances aggressive adoption with “secure-by-default” thinking with Azure, GCP, AWS, and other SaaS.
- Formulated capabilities such as key management, data leakage, and data exfiltration prevention.
- Defined a solution balancing identity management concerns with IAM capabilities within the cloud.
- Advocated cloud security priorities across the bank from engineering through technology and security leadership (CISO, CTO).
- Developed security capabilities to support large-scale migrations to the cloud from data centers.
- Refined a multi-cloud security approach to support portability and operational concerns.
Cloud Security Architect2019 - 2020HSBC
Technologies: Google Cloud Platform (GCP), AWS, Patterns, IT Strategy, Cloud Security, DevSecOps, Data Security, Security Architecture, Information Security, Enterprise Architecture, Stakeholder Management
- Provided a clear strategy for cloud security and roadmap including service consumption and integration, DevSecOps, response, and remediation.
- Performed industrialized approaches for securing cloud services run by the bank based on the current threat landscape and risks.
- Defined automation of security patterns and guardrails across cloud platforms (GCP, AWS).
- Managed stakeholders across technology and business teams and leaders across the bank’s organizational units and technology vendors and consultancies.
Digital Security Architect2018 - 2019National Australia Bank
Technologies: OAuth 2, OpenID Connect (OIDC), APIs, IT Strategy, Application Security, Patterns, Solution Architecture, Cloud Migration, Cloud Security, Data Security, Security Architecture, Information Security, Enterprise Architecture, Stakeholder Management
- Uplifted API authentication methods within the bank.
- Led the improvement of central DevOps security (DevSecOps) capabilities to increase agility and predictability.
- Led security architecture for microservices and AWS cloud deployments.
- Architectured a new compliance gate, enabling rapid automated deployments within the cloud.
- Aligned security with divisional divestment strategies.
- Spearheaded architectural governance and strategy across on-premise and cloud.
- Performed technical leadership on application security strategies.
- Acted as a stakeholder manager and liaisoned with senior business leaders, architecture, and delivery teams.
Lead Digital Security Architect2017 - 2018Lloyds Banking Group
Technologies: APIs, OpenID Connect (OIDC), JSON Web Tokens (JWT), Solution Architecture, Enterprise Architecture, Cloud Security, SaaS, Fraud Prevention, Data Security, Security Architecture, Information Security, IT Strategy, Stakeholder Management
- Developed fraud solutions to support customer enrolment journeys.
- Developed transactional verification solutions that interacted with customers via apps and the web.
- Defined the SaaS strategy for fraud and authentication platform integrations.
- Oversaw and managed the delivery of featured teams to ensure alignment with architecture objectives.
Lead Security Architect2016 - 2017Natwest Markets
Technologies: Classification, Architecture, Information Security, Security Architecture, IT Governance, Data Loss Prevention (DLP), Data Security, Cloud Security, Enterprise Architecture, IT Strategy, Stakeholder Management
- Led the delivery of architecture for an enterprise data classification and data leakage solution.
- Aligned security solutions with divestment and ring-fencing goals.
- Performed stakeholder management of multi-disciplinary teams: senior leadership and C-suite, programme management, the architectural leadership team, and delivery teams in engineering, support, and security assurance.
Senior Digital Security Architect2011 - 2016Lloyds Banking Group
Technologies: APIs, Application Security, Application Architecture, Fraud Prevention, Security Architecture, Stakeholder Management, IT Governance, Data Security, Cloud Security, Information Security, Enterprise Architecture, IT Strategy
- Performed strategic leadership on resourcing for third parties and internal bank staff to deliver key programs.
- Provided security architecture for a new retail online banking service.
- Delivered solutions for card fraud prevention systems.
- Provided stakeholder management to ensure solutions are fit for purpose and pragmatically balanced security and business needs. This also involved identifying and assessing concerns and reusable assets such as patterns, standards, and roadmaps.
Senior Security Consultant and Technology Specialist2006 - 2010Microsoft
Technologies: Windows, APIs, Security Architecture, Presales, Stakeholder Management, Public Speaking, Sales Presentations, Architecture, Client Success, PKI, Data-level Security, Information Security, Antivirus Software, Application Security, Data Security, Enterprise Architecture, IT Strategy
- Performed architectural and business leadership for broad and complex technical issues to customers and partners.
- Provided architectural and specialist guidance on using Microsoft security technologies, including DLP, antimalware, and secure application publishing.
- Developed and implemented an end-to-end security solution for the British Library's turningthepages.com project, allowing the public to view rare manuscripts online.
- Designed Microsoft security architecture for a major bank’s mortgage lending application, minimizing costs and operational overhead.
- Designed the architecture and led the security team for the national health provider email migration to Microsoft Exchange Online to scale up to 1.2 million users.
- Created a global PKI for one of the largest pharmaceuticals headquartered in the UK.
- Built a PKI and supervised its implementation for a major emergency service in London.
IT Security Consultant2004 - 2006IBM
Technologies: Firewalls, PKI, Windows, VPN, Computer Networking, Security Architecture, Data-level Security, Application Security, Antivirus Software, Virtualization Technology, DMZ Networks, Data Security, Information Security, Enterprise Architecture, IT Strategy, Stakeholder Management
- Architected DMZs and a malware solution for DMZ for a retail company and an institutional bank in the Asia Pacific.
- Built a remote access VPN solution for the same businesses.
- Architected and implemented a PKI to be used by those companies.
Systems and Security Architect2002 - 2004Campbell Soup Company
Technologies: Firewalls, Enterprise Resource Planning (ERP), DMZ Networks, Antivirus Software, IP Networks, PKI, Security Architecture, VPN, IT Governance, Data Security, Information Security
- Owned all security-related activities for the Asia Pacific region.
- Mentored and provided technical leadership to the IT team within the Asia Pacific, spanning multiple countries and cultures, including Australia, New Zealand, Indonesia, Japan, and Vietnam.
- Managed system and network security compliance, including security compliance of regional applications and infrastructure.
- Developed, planned, and delivered the architecture for major systems (e.g., ERP, manufacturing) to support the overall business requirements for the Asia Pacific region.
- Built and maintained global security policies and procedures together with the worldwide security team.