Risk and security, from every perspective
I set out to understand security from every side, so over the years I've taken roles across the whole discipline, by design rather than by accident. Risk has been the constant running through all of them. What follows is that path, not a highlight reel.
I've never wanted to understand security from only one seat. So I've worked deliberately across the whole discipline, spanning hands-on engineering and penetration testing, security operations and incident response, architecture, governance and risk, and leadership. Each role was a way to see the field from another angle, and to learn how the parts actually fit together.
Risk has been the constant throughout, rather than a specialism I arrived at late. Even in the most technical roles, the work turned on identifying exposure, prioritising mitigation by business impact, and communicating the position in terms leadership could act on and fund. The engineering and the risk conversation have always been the same job to me, seen from two ends.
I'm at my most useful when I'm still learning, which is why I stay close to research and development, building classifiers, threat-modelling LLM and agentic systems, and keeping pace with where the threat landscape is heading. The day I stop learning is the day I'd stop being much use to anyone.
Roles I've held
Antan Cybersecurity Services
Founder & Principal Consultant
Independent digital, cyber, and AI risk advisory for regulated organisations and SMEs, from short certification sprints to multi-year programme leadership.
A listed global technology business
Head of Security Operations
Led the transformation of the enterprise security function, set the security strategy, and established an AI-augmented Security Operations Centre. Led adoption of ISO/IEC 42001-based AI security governance.
Independent research
AI, quantum computing & blockchain
A self-directed year spent on generative AI, multi-agent and agentic systems for red and blue team work, post-quantum cryptography, and smart-contract and decentralised identity risk.
A major New Zealand technology organisation
GM & Associate Director, Cyber Security
Established and led the corporate security function. Directed ISO/IEC 27001:2022 and SOC 2 Type 2 certification, and delivered a FAIR-grounded quantitative risk framework that sharpened executive decision-making and materially reduced enterprise risk exposure.
A national government agency
Senior Security Architect & GRC Lead, then Security Operations Manager
Owned enterprise security architecture and the agency GRC programme, then designed and built the Security Operations Centre end to end. Led security architecture for a major motorway tunnel programme, hardened intelligent transport systems, and built an anti-phishing classifier using applied machine learning.
A credit union
PCI-DSS & Information Security Consultant
Directed the full PCI-DSS lifecycle through to compliance, and embedded information security risk management inside the existing corporate risk framework.
An electricity lines utility
Senior Information Security Consultant
Defined the corporate threat profile against the sector threat landscape, integrated information security risk into the enterprise risk framework across governance, ICT, and operational technology, and designed a sector-specific maturity model.
An independent security consultancy
Founder & Director
Founded and led a consultancy serving SMEs across regulated sectors, covering ICT security governance, ISO 2700x and PCI-DSS compliance, HISO audit and implementation in the health sector, and ICT audit and penetration testing.
A global telecommunications vendor
Security Manager
Established an information security governance framework and delivered enterprise risk management through strategic assessment against business and compliance obligations. Built incident detection, investigation, response, and recovery capability.
A media and publishing group
Senior ICT Security Consultant
Developed a corporate ICT risk and security framework aligned to business objectives, embedded security within the SDLC, and supported the PCI-DSS compliance programme.
A national rail operator
Head of Security
Developed an information security governance framework aligned to strategic objectives, implemented an ICT security risk management process, managed internal audits, and achieved PCI-DSS compliance for payment card data.
A security testing firm
IT Security Consultant & Penetration Tester
Network and application penetration testing for government, corporate, and financial institutions, with findings prioritised by business risk and reported to management alongside practical remediation.
A national credit bureau
Senior IT Security Architect & Analyst
Established the organisation-wide information security programme from inception and authored policies and standards. Designed application security architectures with design decisions justified to management on a risk basis.
United Kingdom, earlier roles
Security engineering and operations
Foundational security engineering and network roles, including defence-cleared work.
Roles are indicative; full detail is available on request and via LinkedIn (opens in a new tab).
Sharing what I learn
I helped start the New Zealand chapter of OWASP, the global community for improving the security of software. Sharing what I learn openly is part of how the profession matures, and a way to keep myself honest.
Lately that has meant working through how we secure artificial intelligence, trying to bridge applied engineering and the governance frameworks now racing to keep pace with it. It's unfinished work, and I'm still learning as I go.
Want to dig into a particular chapter?
If a specific role or piece of work here is relevant to what you are facing, ask me about it directly. I am glad to talk it through.