Profile
A security leader who has spent thirty years across the detection lifecycle — from the first generation of enterprise SIEM through to building AI-driven cyber recovery today.
The combination is unusual: deep technical authority in SIEM, SOC, threat intelligence and cyber recovery; analyst-grade market fluency from a Global Practice Lead role at Gartner; and Partner, Director and Head-of-Practice commercial leadership across IBM, CGI, Atos and Wipro. Equally credible in front of a CISO buying committee, on a SOC floor, and in the codebase.
Capability
SIEM & SOC
Thirty years across the detection lifecycle. SIEM practitioner since the technology's earliest enterprise deployments. Designed and deployed a Security Operations Centre end to end for a regulated energy utility.
Cyber & ransomware recovery
Architectural lead on a regulated multi-cloud Cyber Recovery as a Service programme; currently building an AI-driven ransomware recovery capability for a critical national infrastructure operator.
Applied AI in security
Production use of LLMs over a graph-native intelligence core — AI-augmented IaC pipelines, automated threat extraction, and an MCP-exposed query layer. AI as leverage on judgement, not theatre.
Enterprise & security architecture
Three decades designing systems that survive vendor substitution and scale under pressure, across AWS and Azure, IaC-first, from Director and Partner-grade positions.
Commercial & sales leadership
Global Practice Lead at Gartner, Head of Cyber Defence Advisory for Northern Europe at Atos, Deputy Chief Security Architect at IBM, Partner at Wipro. Shaped enterprise buying decisions, led pre-sales solutioning, carried Partner-grade commercial responsibility.
Market & analyst insight
Gartner Global Practice and Key-Initiative lead for infrastructure, platform, operations and security — a direct view of the vendor landscape, the buyer, and where the market is heading.
Selected work
- Deployed a regulated utility's Security Operations Centre. Designed and stood up the SOC end to end for a major regulated energy utility — people, process, tooling and detection content.
- Led a multi-cloud Cyber Recovery programme reset. Architectural lead across a five-business-unit estate spanning AWS and Azure, Terraform-codified, against an approved multi-million-pound budget. Designed a gated factory-model recovery approach and the executive evidence base behind it.
- Building AI-driven ransomware recovery. Architecting and developing an AI-driven recovery capability combining cyber-recovery automation with applied AI over a recovery dependency graph, to compress recovery time under live-incident conditions.
- Built a graph-native threat intelligence platform from scratch. Founder and architect of NinjaSignal — a suite of production security applications on a self-designed multi-vector graph core, built on why graph and ML beat SIEM noise for real detection.
- Turned analyst authority into demand. As Gartner Global Practice Lead, shaped how enterprise security and infrastructure buyers made decisions — the analyst seat vendor field leaders most want on their side of the table.
Independent platform
Founder and architect of NinjaSignal, a suite of production security applications on a self-designed multi-vector graph architecture with full cross-graph traversal. The core concept predates the current AI wave — designed in 2018, building on enterprise threat-intelligence work going back to early Watson exposure in 2014.
Graph-native intelligence
Community-detection-first analytics over multi-source feeds — GreyNoise, EPSS, CertStream, APT tracking, VirusTotal — with regex-first IOC extraction.
Production engineering
FastAPI, NATS JetStream, Next.js and the Claude API across dedicated production infrastructure.
Applied AI, done properly
LLM inference as the last step over graph-derived context — the graph does the thinking, the model writes it — plus AI-augmented Terraform codification and an MCP server exposing platform queries to agents.
Advanced analytics
Monte Carlo failure injection and causal inference over recovery dependency graphs for probabilistic recovery-time modelling.
Career
| Lead Enterprise Security Architect & Transformation Advisor | NinjaIng Ltd — current |
| Head of Cyber Defence Advisory, Northern Europe | Atos |
| Partner | Wipro |
| Global Practice Lead; Head of Infrastructure, Platform, Operations & Security | Gartner |
| Director — Head of Consulting Architecture | CGI |
| Deputy Chief Security Architect | IBM |
| Master-Level SIEM Consultant | HP |
| EMEA Lead — Enterprise Security Architecture | Trustwave |
| Security Consultant | Zepko |
| Security Engineer — early SIEM era | RSA Security |
| Security Engineer | Logica |