Experience

Threat Detection & Response Analyst - Aruga Cyber

Remote SOC Analyst at an MSSP, primarily working within a Microsoft-native SOC (Microsoft Sentinel, Defender XDR) while also investigating alerts across a range of client security platforms including Google Workspace, GAT, and other SIEM/security tooling. I joined through an unconventional route - rather than a traditional interview, I demonstrated a SOC case management tool I'd built, which led to the offer. Now triaging real-world alerts, reconstructing incident timelines, writing investigation summaries, and working towards SC-200 and SC-900.

Digital Forensics Technician - CACI Ltd

Building on my forensics skills, I transitioned into private forensics. Here I dealt with major UK forces and other governmental customers to conduct forensic investigations.

Digital Forensics Technician - Durham Constabulary

Digital forensics work supporting live police casework, my first exposure to evidence handling, chain of custody, and the procedural discipline that carries straight over into SOC incident handling. This is where "documented, defensible, repeatable" stopped being theory and started being how I actually work. 

Specialist Complaints Investigator - Barclays (FCA-regulated)

Investigating disputed transactions and fraud claims inside a regulated environment - pattern recognition, case documentation, working to strict compliance standards. Different domain, same underlying skill: working out what actually happened from an incomplete trail of evidence.