25 years across defence, technology and higher education
A full career history, from research scientist to Associate Director of Cyber Security, spanning the University of Southampton and QinetiQ (formerly DERA).
University of Southampton
Nov 2023 – Mar 2026
£600m+ research-intensive university
Associate Director Cyber Security (CISO)
Led all cybersecurity strategy, operations, and risk management for a £600m+ research-intensive university serving 30,000 users, with direct executive reporting and full accountability for a £500k operational budget and strategic influence over multi-million-pound capital investments.
Secured executive approval and £600k funding for an outsourced security operations capability providing 24/7 managed detection and response, reducing mean time to respond to critical alerts by approximately 75%.
Established the University's executive security reporting framework, delivering quarterly briefings to the University Executive Board, Audit & Risk Committee, and Professional Services Executive—embedding cybersecurity as a standing agenda item in institutional governance for the first time.
Authored and owned the University's Cyber Incident Response Plan and all cybersecurity policies, and served as a standing member of the Business Continuity Group. Bronze command lead for cyber incidents.
Expanded the cybersecurity team from two to nine professionals through targeted external recruitment and internal talent development, building specialist capabilities in security operations, identity management, and security architecture.
Led a successful ISO 27001 certification programme, enabling a £25m contract with the NIHR (National Institute for Health and Care Research).
Shaped the strategic direction of a multi-million-pound identity and access management transformation, influencing vendor selection, operating model design, and implementation approach for a SaaS-based IAM platform underpinning the University's zero-trust ambitions.
Commissioned an independent NIST CSF 2.0 maturity assessment of the University's IAM capability, then translated the target operating model and roadmap into a resourced cyber improvement programme—driving maturity from below 1 towards a target of above 3.
Led the end-to-end procurement and delivery of the University's cyber training platform to all staff and postgraduate students, achieving over 75% completion of security awareness training within the first 12 months.
Founder member of the University's AI Research Ethics Working Group, helping shape institutional frameworks for responsible AI use in research.
Aug 2021 – Nov 2023
Head of Cyber Security
Authored the organisation's first board-approved Information and Cyber Security Strategy, establishing a multi-year roadmap that aligned security investments with institutional objectives.
Developed and led the organisation's first executive-level Cyber Incident Response Plan, conducting tabletop exercises with senior leaders that tested decision-making under pressure.
Established risk-based security governance that balanced protection requirements with operational needs, improving stakeholder engagement and reducing friction between security and academic communities.
Safeguarded £10m in annual research funding by maintaining certifications and security standards required by funding bodies.
Jun 2020 – Jul 2021
Information and Cyber Security Architect
Designed and secured approval for a £3m security improvement programme addressing critical audit findings, developing business cases that quantified risk reduction and operational efficiency gains.
Led enterprise-wide deployment of multi-factor authentication across 43,000 accounts, reducing unauthorised access attempts by 90%.
Delivered endpoint detection and response capabilities across 20,000 endpoints and 1,000+ servers, establishing the technical foundation for the managed detection and response capability that followed.
Implemented a comprehensive vulnerability scanning and management programme for the University's 2,000+ server estate, significantly reducing time-to-patch for critical vulnerabilities.
Apr 2018 – May 2020
Senior Cyber Security Advisor
Established Cyber Essentials certification processes that enabled the organisation to compete for research funding opportunities previously inaccessible due to security requirements.
Demonstrated leadership readiness through two interim appointments: Acting Head of Information Governance (six months), chairing the DPIA review board; and Acting Head of Information Security (seven months), managing a team of four analysts.
Apr 2012 – May 2018
Senior Infrastructure Engineer
Senior member of a 15-person team providing tier 3 support for enterprise IT infrastructure across multiple data centres, responsible for 3+ petabytes of networked storage, 1,800+ virtual machines, and 600+ Linux servers serving a 30,000-user organisation.
Designed and built the Administrative Data Research Centre – England (ADRC-E) secure data analysis environment, handling UK Official Sensitive data from the Office for National Statistics. Led the implementation of protective monitoring using AlienVault SIEM.
Wrote the business case and led the procurement process for a £500k storage platform upgrade.
Provided mentoring and technical guidance to junior engineers.
Earlier Career — QinetiQ (formerly DERA)
Sep 2001 – Apr 2012
Internet Systems Engineer / Senior Internet Systems Engineer
Progressed from principal engineer to senior technical lead within QinetiQ's managed security services business, responsible for designing, implementing, and operating 24/7 secure hosting infrastructure serving UK Government and commercial clients.
Led the technical development and implementation of QinetiQ's first commercial hosting services, establishing capabilities that became core to the business's managed services portfolio.
Provided security consultancy for the design and implementation of secure networks across research and commercial projects, encompassing hardened system configuration, network architecture, and firewall policy design.
Primary tier-3 engineer for the managed hosting service and support engineer for QinetiQ's 24/7 managed intrusion detection service.
Mentored and developed junior engineers throughout, delegating progressively complex tasks while providing guidance to ensure quality delivery.
Sep 1999 – Sep 2001
Research Scientist, DERA
Began career in UK defence research, combining software development, infrastructure engineering, and security research in an environment focused on emerging technology challenges for the Ministry of Defence.
Get In Touch
Interested in working together or discussing a role?