Professional Experience & Expertise

Head of Cyber Security | Autovista Group (May 2023 – Present)

  • Strategic & Compliance Leadership: Implemented a comprehensive cyber security and compliance strategy, successfully aligning the business with GDPR, DORA, and ISO 27001.
  • Risk & Assurance: Directed the implementation of a risk-based GRC framework and completed successful external audits, including TISAX, TD Bank, and Bank of America.
  • Operational Security: Oversaw daily security operations, including SIEM monitoring, threat detection, and incident response across AWS and Azure hybrid environments.
  • Vendor Management: Led a complete overhaul of Vendor and Third-Party due diligence, significantly maturing the organization's supply chain risk posture.
  • DevSecOps: Integrated security practices into the software development lifecycle, improving resilience from development through deployment.

Group Information Security Officer | Autovista Group (July 2020 – May 2023)

  • Risk Management: Led all information and cyber security risk management activities across the group, protecting client data, brand reputation, and revenue streams.
  • Security Posture Improvement: Developed and implemented people, process, and technical controls to mitigate identified risks and enhance overall security resilience.
  • Executive Advisory: Acted as a key advisor to senior stakeholders (CISO/CRO), effectively translating complex technical risks into business-relevant insights.
  • Culture: Promoted a security-aware culture through training, communication, and engagement initiatives across the global organization.

Certifications 🏅

  • **Certified in Cybersecurity (CC)** – ISC2
  • **OneTrust Certified Privacy Professional**
  • **OneTrust Third Party Management Expert**
  • **GitLab Certified Security Specialist**
  • **Carbon Literacy Standard** – The Carbon Literacy Project

Key Technologies & Tools 🛠️

  • **SIEM & Endpoint:** Wazuh, Optiv MSS, Windows Defender Enterprise, Carbon Black
  • **Cloud Platforms:** **AWS**, **Azure**, Microsoft 365, O365, SCCM
  • **Email & GRC:** DMARC Implementation, Mimecast, Proofpoint, Phishing Campaign Tools, OneTrust
  • **Networking/Core:** AD, GPO, Cisco, Citrix, Windows Server 2012 R2, Virtualization, Salesforce