Experience
25 years across defence, technology and higher education
A full career history, from research scientist to Associate Director of Cyber Security, spanning the University of Southampton and QinetiQ (formerly DERA).
University of Southampton
Nov 2023 – Mar 2026
£600m+ research-intensive university
Associate Director Cyber Security (CISO)
- Led all cybersecurity strategy, operations, and risk management for a £600m+ research-intensive university serving 30,000 users, with direct executive reporting and full accountability for a £500k operational budget and strategic influence over multi-million-pound capital investments.
- Secured executive approval and £600k funding for an outsourced security operations capability providing 24/7 managed detection and response, reducing mean time to respond to critical alerts by approximately 75%.
- Established the University's executive security reporting framework, delivering quarterly briefings to the University Executive Board, Audit & Risk Committee, and Professional Services Executive—embedding cybersecurity as a standing agenda item in institutional governance for the first time.
- Authored and owned the University's Cyber Incident Response Plan and all cybersecurity policies, and served as a standing member of the Business Continuity Group. Bronze command lead for cyber incidents.
- Expanded the cybersecurity team from two to nine professionals through targeted external recruitment and internal talent development, building specialist capabilities in security operations, identity management, and security architecture.
- Led a successful ISO 27001 certification programme, enabling a £25m contract with the NIHR (National Institute for Health and Care Research).
- Shaped the strategic direction of a multi-million-pound identity and access management transformation, influencing vendor selection, operating model design, and implementation approach for a SaaS-based IAM platform underpinning the University's zero-trust ambitions.
- Commissioned an independent NIST CSF 2.0 maturity assessment of the University's IAM capability, then translated the target operating model and roadmap into a resourced cyber improvement programme—driving maturity from below 1 towards a target of above 3.
- Led the end-to-end procurement and delivery of the University's cyber training platform to all staff and postgraduate students, achieving over 75% completion of security awareness training within the first 12 months.
- Founder member of the University's AI Research Ethics Working Group, helping shape institutional frameworks for responsible AI use in research.
Aug 2021 – Nov 2023
Head of Cyber Security
- Authored the organisation's first board-approved Information and Cyber Security Strategy, establishing a multi-year roadmap that aligned security investments with institutional objectives.
- Developed and led the organisation's first executive-level Cyber Incident Response Plan, conducting tabletop exercises with senior leaders that tested decision-making under pressure.
- Established risk-based security governance that balanced protection requirements with operational needs, improving stakeholder engagement and reducing friction between security and academic communities.
- Safeguarded £10m in annual research funding by maintaining certifications and security standards required by funding bodies.
Jun 2020 – Jul 2021
Information and Cyber Security Architect
- Designed and secured approval for a £3m security improvement programme addressing critical audit findings, developing business cases that quantified risk reduction and operational efficiency gains.
- Led enterprise-wide deployment of multi-factor authentication across 43,000 accounts, reducing unauthorised access attempts by 90%.
- Delivered endpoint detection and response capabilities across 20,000 endpoints and 1,000+ servers, establishing the technical foundation for the managed detection and response capability that followed.
- Implemented a comprehensive vulnerability scanning and management programme for the University's 2,000+ server estate, significantly reducing time-to-patch for critical vulnerabilities.
Apr 2018 – May 2020
Senior Cyber Security Advisor
- Established Cyber Essentials certification processes that enabled the organisation to compete for research funding opportunities previously inaccessible due to security requirements.
- Demonstrated leadership readiness through two interim appointments: Acting Head of Information Governance (six months), chairing the DPIA review board; and Acting Head of Information Security (seven months), managing a team of four analysts.
Apr 2012 – May 2018
Senior Infrastructure Engineer
- Senior member of a 15-person team providing tier 3 support for enterprise IT infrastructure across multiple data centres, responsible for 3+ petabytes of networked storage, 1,800+ virtual machines, and 600+ Linux servers serving a 30,000-user organisation.
- Designed and built the Administrative Data Research Centre – England (ADRC-E) secure data analysis environment, handling UK Official Sensitive data from the Office for National Statistics. Led the implementation of protective monitoring using AlienVault SIEM.
- Wrote the business case and led the procurement process for a £500k storage platform upgrade.
- Provided mentoring and technical guidance to junior engineers.
Earlier Career — QinetiQ (formerly DERA)
Sep 2001 – Apr 2012
Internet Systems Engineer / Senior Internet Systems Engineer
- Progressed from principal engineer to senior technical lead within QinetiQ's managed security services business, responsible for designing, implementing, and operating 24/7 secure hosting infrastructure serving UK Government and commercial clients.
- Led the technical development and implementation of QinetiQ's first commercial hosting services, establishing capabilities that became core to the business's managed services portfolio.
- Provided security consultancy for the design and implementation of secure networks across research and commercial projects, encompassing hardened system configuration, network architecture, and firewall policy design.
- Primary tier-3 engineer for the managed hosting service and support engineer for QinetiQ's 24/7 managed intrusion detection service.
- Mentored and developed junior engineers throughout, delegating progressively complex tasks while providing guidance to ensure quality delivery.
Sep 1999 – Sep 2001
Research Scientist, DERA
- Began career in UK defence research, combining software development, infrastructure engineering, and security research in an environment focused on emerging technology challenges for the Ministry of Defence.