Andrew Olson
Verified Expert in Engineering
Security Architecture Developer
London, United Kingdom
Toptal member since November 19, 2021
Andrew is a seasoned security leader covering the strategy and architectures of complex digital security, cloud, and enterprise initiatives. He has extensive experience working with multidisciplinary teams and C-suite leaders across the banking, finance, technology, and retail sectors. Experienced in leading, consulting, devising, and executing strategies, Andrew maintains a highly technical skillset and enjoys advising on digital and cloud platform security and transforming business security.
Portfolio
Experience
Availability
Preferred Environment
Windows, Visual Studio Code (VS Code), Office 365, Confluence, Amazon Web Services (AWS), Google Cloud, Azure, SaaS
The most amazing...
...I've accomplished is starting with a few simple ideas and building a foundational cloud security capability for a bank to deliver its services.
Work Experience
Consulting Security Architect
Enterprise Blueprints
- Managed and built a security team of architects to provide consultancy to global clients.
- Evolved internal controls to continue ISO 27002 accreditation.
- Managed security architecture for Southeast Asian banking platform.
Security Architect
International Airlines Group (IAG)
- Oversaw the security of the platform and its use by various brands within the group.
- Spearheaded data security architecture within the group.
- Developed the platform security strategy to meet the data demands across the group.
- Managed the security engineering function to ensure alignment with security objectives.
- Provided security leadership on automation, microservices, and event-driven architectures and platform integration security.
- Defined and realized cloud security architecture for the group (AWS) to be adopted by multiple operating companies.
Enterprise Architect | Cloud Security
Lloyds Banking Group
- Crafted a bank-wide strategy for cloud security and roadmap that balances aggressive adoption with “secure-by-default” thinking with Azure, GCP, AWS, and other SaaS.
- Formulated capabilities such as key management, data leakage, and data exfiltration prevention.
- Defined a solution balancing identity management concerns with IAM capabilities within the cloud.
- Advocated cloud security priorities across the bank from engineering through technology and security leadership (CISO, CTO).
- Developed security capabilities to support large-scale migrations to the cloud from data centers.
- Refined a multi-cloud security approach to support portability and operational concerns.
Cloud Security Architect
HSBC
- Provided a clear strategy for cloud security and roadmap including service consumption and integration, DevSecOps, response, and remediation.
- Performed industrialized approaches for securing cloud services run by the bank based on the current threat landscape and risks.
- Defined automation of security patterns and guardrails across cloud platforms (GCP, AWS).
- Managed stakeholders across technology and business teams and leaders across the bank’s organizational units and technology vendors and consultancies.
Digital Security Architect
National Australia Bank
- Uplifted API authentication methods within the bank.
- Led the improvement of central DevOps security (DevSecOps) capabilities to increase agility and predictability.
- Led security architecture for microservices and AWS cloud deployments.
- Architectured a new compliance gate, enabling rapid automated deployments within the cloud.
- Aligned security with divisional divestment strategies.
- Spearheaded architectural governance and strategy across on-premise and cloud.
- Performed technical leadership on application security strategies.
- Acted as a stakeholder manager and liaisoned with senior business leaders, architecture, and delivery teams.
Lead Digital Security Architect
Lloyds Banking Group
- Developed fraud solutions to support customer enrolment journeys.
- Developed transactional verification solutions that interacted with customers via apps and the web.
- Defined the SaaS strategy for fraud and authentication platform integrations.
- Oversaw and managed the delivery of featured teams to ensure alignment with architecture objectives.
Lead Security Architect
Natwest Markets
- Led the delivery of architecture for an enterprise data classification and data leakage solution.
- Aligned security solutions with divestment and ring-fencing goals.
- Performed stakeholder management of multi-disciplinary teams: senior leadership and C-suite, programme management, the architectural leadership team, and delivery teams in engineering, support, and security assurance.
Senior Digital Security Architect
Lloyds Banking Group
- Performed strategic leadership on resourcing for third parties and internal bank staff to deliver key programs.
- Provided security architecture for a new retail online banking service.
- Delivered solutions for card fraud prevention systems.
- Provided stakeholder management to ensure solutions are fit for purpose and pragmatically balanced security and business needs. This also involved identifying and assessing concerns and reusable assets such as patterns, standards, and roadmaps.
Senior Security Consultant and Technology Specialist
Microsoft
- Performed architectural and business leadership for broad and complex technical issues to customers and partners.
- Provided architectural and specialist guidance on using Microsoft security technologies, including DLP, antimalware, and secure application publishing.
- Developed and implemented an end-to-end security solution for the British Library's turningthepages.com project, allowing the public to view rare manuscripts online.
- Designed Microsoft security architecture for a major bank’s mortgage lending application, minimizing costs and operational overhead.
- Designed the architecture and led the security team for the national health provider email migration to Microsoft Exchange Online to scale up to 1.2 million users.
- Created a global PKI for one of the largest pharmaceuticals headquartered in the UK.
- Built a PKI and supervised its implementation for a major emergency service in London.
IT Security Consultant
IBM
- Architected DMZs and a malware solution for DMZ for a retail company and an institutional bank in the Asia Pacific.
- Built a remote access VPN solution for the same businesses.
- Architected and implemented a PKI to be used by those companies.
Systems and Security Architect
Campbell Soup Company
- Owned all security-related activities for the Asia Pacific region.
- Mentored and provided technical leadership to the IT team within the Asia Pacific, spanning multiple countries and cultures, including Australia, New Zealand, Indonesia, Japan, and Vietnam.
- Managed system and network security compliance, including security compliance of regional applications and infrastructure.
- Developed, planned, and delivered the architecture for major systems (e.g., ERP, manufacturing) to support the overall business requirements for the Asia Pacific region.
- Built and maintained global security policies and procedures together with the worldwide security team.
Experience
Continuous Compliance (aka Deputy)
Certifications
AWS Solutions Architect Associate
Amazon Web Services
Certified Information Systems Security Professional (CISSP)
ISC2
Skills
Tools
HashiCorp, Microsoft Teams, VPN
Platforms
Amazon Web Services (AWS), Google Cloud Platform (GCP), Azure, Windows
Languages
Python, Snowflake, SAML
Frameworks
OAuth 2, JSON Web Tokens (JWT)
Paradigms
DevSecOps, Application Architecture, Management
Storage
PingFederate, Google Cloud
Other
Certified Information Systems Security Professional, IT Strategy, Enterprise Architecture, Security Architecture, Information Security, Stakeholder Management, Cloud Security, IT Governance, Data Security, Leadership, Application Security, Software as a Service (SaaS), Agile Practices, OpenID Connect (OIDC), APIs, Solution Architecture, Containers, Tokenization, Platform as a Service (PaaS), SaaS, Web Application Firewall (WAF), Cloud Migration, Patterns, Fraud Prevention, Compliance, Classification, Architecture, Data Loss Prevention (DLP), Presales, Public Speaking, Sales Presentations, Client Success, PKI, Data-level Security, Antivirus Software, Firewalls, Computer Networking, Virtualization Technology, DMZ Networks, Enterprise Resource Planning (ERP), IP Networks, Consulting
How to Work with Toptal
Toptal matches you directly with global industry experts from our network in hours—not weeks or months.
Share your needs
Choose your talent
Start your risk-free talent trial
Top talent is in high demand.
Start hiring