
IT Security Assurance
Send a job offer directly to this candidate
I am an IT Security Consultant who has a deep understanding of Information and IT security, having delivered successful projects to CGI's clients for 19 years. During that time, I have developed a good trusting relationship within MoD Security, with each department that I have worked. This includes developing and delivering Risk Assessments detailing and mitigating the risks for their consideration, approval and accreditation.
I have been recognised for mentoring graduates who joined my team and guiding them into the security practice, developing them to achieve their potential. I obtained the CISSP qualification which has been put to good use with the MoD client. I have also been a key member of five major audits covering SAS70, SOX, IBM Corporate and ITRMs.
In this role I was the lead auditor for Security Process Reviews and was recognised as the Subject Matter Expert, passing on the process and teaching new team members the best practices. My breadth of Security is wide ranging including all aspects of physical and personnel security through to deep technical skills in areas such as software lockdown.
Security Assurance – Team Lead at CGI (2026-04 – Present)
Led a team of ten people in a hostile work environment. I led Risk Register reviews, Security Surgeries, Team meetings and managed the team day to day.
Security Assurance – Information Security Assurance Management at CGI (2014 – 2026-04)
Concurrently with the Application role below, I also provided formal independent risk assessment and risk reporting activities for many projects under the ISAMP banner. This involved interpreting and articulating the risks and vulnerabilities into a business focussed view. I also contributed to the team as a Local Security Officer, ImpEx operator and Front Door administrator for the security team.
DII/F Applications Security Assurance Team Lead at CGI (2015 – 2026-04)
At a crucial time for the team, when new work was contracted, I was asked to take the reins of this team. I recruited and trained, in total, thirteen team members, leading the team of up to four members at one time. I managed large bid work, developed and streamlined processes, conducting myself as the main customer liaison and reviewing all work before being sent for customer approval.
DII/F Inc 2c Applications Security Assurance at CGI (2009 – 2014)
Similar to the previous role, however this project role differed as it dealt with client/server Applications on an air-gapped domain and very strong MoD Security accreditation criteria, the Applications frequently requiring penetration testing data to show compliance. I took a team leader role and managed one other person. I also volunteered to be the Media Registrar for our project and also as the building's Chief Fire Marshal.
DII/F Applications Security Assurance at CGI (formerly Logica) (2007 – 2009)
I conducted security assessments of applications needing to be migrated from legacy domains onto the DII/F Infrastructure.
These assessments covered: vulnerabilities, end-of-life and patch timing, mobile code and scripting, risk identification and mitigation, whilst also describing how the Application worked and how the infrastructure supported it. The Applications on this infrastructure had reach-back to legacy domains. I dealt with several teams within ATLAS and chaired weekly meetings with the MoD Security customer.
Information Security Advisor at IBM UK Ltd (2005 – 2007)
I dealt directly with the customer's security team, the IBM Service Managers, and the many support teams providing technical deliveries to the customer. I managed the account's security issues, risks and security agreement. I also reviewed the processes used on the account, organised new security developments and provided advice about critical virus incidents and patching.
I also volunteered for out of hours support for the GM account holding their emergency patching meetings. Upon leaving this role, I took it upon himself to become CISSP certified in order to further my Security career.
Security Compliance Tester at IBM UK Ltd (2004 – 2005)
The compliance tester role ensured IBM accounts were delivering the contracted requirements. The accounts changed each quarter, providing me with a wide range of experience with the different service management and security teams. I was also the SME in the field of Security Process Reviews (SPRs), which gave me the responsibility of scheduling, performing and leading these audits, updating the processes, documentation and training other members of the team to perform the SPRs.
Audit work accounted for a quarter of his time within this role. Due to the knowledge and experience obtained through the SPRs, I helped "defend" five major audits covering SAS70, SOX, Corporate and ITRMs. I performed numerous roles during these larger audits, including data reviewer, focal point role, and also worked within the project office.
Lotus Notes Administrator at IBM UK Ltd (2002 – 2004)
This role ensured the IBM Hursley domain was up and running. It comprised of database deployment and keeping the security levels maintained.
BSc in Software Engineering Management – Bournemouth University