
Get to Know Me
My professional career began at DXC, where I spent close to a decade as a Service Delivery Coordinator. My time here built a strong foundation in customer service and the technical operations required for secure partner onboardings and EDI data transfer.
Today at ecosio, I leverage this background alongside specialised training from my Master's degree in cybersecurity, various industry certifications, and hands-on operational experience as an L2 SOC Analyst and Blue Teamer.
Looking toward the future, I am actively expanding my expertise. I am currently studying the CompTIA Sec AI+ course, recognising the fast-paced growth of our digitised world and artificial intelligence, I am deeply focused on understanding its security benefits and emerging risks to help shape the future of modern SOC operations.
Professional Background
L2 SOC Analyst @ ecosio GmbH
Driving detection engineering, automation, and incident response for a modern SOC.
Detection Engineering & Automation
- Detection Engineering: Lead rule creation/maintenance across Datadog SIEM, Material Security, and CrowdStrike (mapped to MITRE ATT&CK), driving cross-team signal investigations via Slack.
- Datadog Workflow SOAR: Created custom workflows that remove L1 triage by correlating logs/signals, aggregating metadata, and delivering clean notifications to the SOC.
- Dashboard Creation: Built and managed a wide variety of dashboards to assist the SOC during signal triage and active investigations.
- Log Management: Orchestrate log integrations into Datadog Cloud SIEM, configuring indexes, log pipelines, and managing cost/billing.
- GitLab CI/CD: Automated SOC operations using Python and the CrowdStrike API to parse application reports and solve Shadow IT installs.
Platform Defense & Response
- Signal Triage & Response: Act as L2 SOC Analyst, actively triaging and escalating signals across our entire security tech-stack.
- Incident Response: Act as Incident Liaison/Tech Lead and SME (via incident.io), managing the full lifecycle from triage through post-mortem.
- Phishing Investigator: Leverage Material Security to investigate native/user reports, remediate campaigns, and orchestrate company-wide phishing education.
- CrowdStrike AIDR: Key stakeholder for AIDR workforce/agents deployment; overseeing custom policies for Data Loss Protection (DLP) and Shadow AI usage.
- CrowdStrike SaaS: Key stakeholder in onboarding of SaaS applications, reviewing posture, and remediating findings.
SOC Operations
- Signal Architecture: Engineered custom SOC pipelines to route cross-platform signals into a centralised Notion Triage Queue with a custom ticketing system.
- SOC Runbooks: Authored high-quality playbooks in Notion (scoped to MITRE ATT&CK) to provide reproducible steps and escalation criteria.
- SOC Processes: Established monthly reviews for SIEM detections, endpoint attack surfaces, and identity audits, plus documentation for rule submissions.
- Automated Threat Intel: Built a proactive, API-driven threat intel system in Notion to centralise daily feeds (Bleeping Computer, Krebs, Hacker News).
Education & Certifications
Academic & Industry
- CompTIA Sec AI+CURRENTLY STUDYING
- MSc Computer Science with Cybersecurity (Distinction)University of Sunderland • 2025
- Certified Blue Team Level 1 (BTL1)Security Blue Team • 2025
- AWS Certified Cloud Practitioner (CCP)Amazon Web Services • 2024
- Advanced Level Apprenticeship (IT, Software, Web & Telecoms)DXC Technology • 2017
Specialised Platform Training
- CrowdStrike University
- CrowdStrike Falcon Administrator
- Falcon Endpoint Data Protection Fundamentals
- CrowdStrike AIDR Fundamentals
- Datadog Learning Center
- Datadog Cloud Security Engineer Learning Path
- Datadog Core Skills Learning Path
* Certificates available upon request.