Principal-Level Security Platform Engineering
Network Security Engineering
Hands-on engineering ownership of the platforms that enforce network and application security in regulated enterprise estates — Imperva WAAP and DDoS, ExtraHop RevealX NDR, and Illumio micro-segmentation — from architecture and policy design through automation, staged enforcement and the operating model that keeps them effective.
Imperva — Application & DDoS Protection
WAF Onboarding at Scale
Repeatable onboarding runbook for moving applications behind Cloud WAF and WAF Gateway: discovery, origin protection, DNS/CNAME cutover, TLS and certificate handling, health checks, staged monitor-to-block transition and rollback criteria. Onboarding treated as a product, not a ticket.
DELIVERED
Policy Engineering & False-Positive Management
Tuning rulesets per application rather than per estate — signature tuning, custom rules, exception lifecycle with expiry, and a measured false-positive budget. Blocking that application teams trust because they understand why a rule fires.
DELIVERED
DDoS Operating Model
Network-layer and application-layer DDoS protection, always-on versus on-demand posture, BGP and DNS diversion paths, time-to-mitigation targets, and the runbook for a live event. Includes consolidating overlapping DDoS tooling onto one operating model.
ARCHITECTED
API & Bot Protection
API discovery and schema enforcement, Advanced Bot Protection classification tuning, Account Takeover and Client-Side Protection. Covers the gap between a WAF that inspects requests and a WAAP that understands the application.
DELIVERED
Change Control, Alerting & Lifecycle Ownership
Policy-as-change-record, peer review, scheduled windows, back-out plans, and alert routing that distinguishes attack from regression. Platform ownership through upgrades, certificate rotation and capacity events.
DELIVERED
ExtraHop RevealX — Network Detection & Response
East-West Visibility & Coverage
Sensor placement, TAP and SPAN strategy, and VPC/VNet mirroring so lateral movement is actually observable. Coverage measured against the asset inventory — a named percentage of east-west traffic inspected, not an assumption that it is covered.
DELIVERED
Detection Tuning & Noise Reduction
The real NDR problem is rarely coverage; it is signal. Baseline establishment, tuning by asset criticality, suppression with review dates, and detection quality tracked as precision over volume. Fewer, better alerts that analysts act on.
DELIVERED
Deployment Models
RevealX 360 (SaaS) and RevealX Enterprise (self-managed) — choosing by data-residency and regulatory constraint rather than preference. Decryption strategy including TLS 1.3, and where packet capture is proportionate versus excessive.
ARCHITECTED
SOC Integration
Detections into SIEM/SOAR with context that makes triage faster — device role, peer behaviour, protocol anomaly — plus playbook hooks. NDR earns its licence by shortening investigations, not by adding a queue.
DELIVERED
Demonstrating Platform Value
Articulating NDR return: mean-time-to-detect movement, blind spots closed, tooling retired, and analyst hours recovered. Written for a budget holder, not a console.
ADVISED
Illumio — Micro-Segmentation & Breach Containment
Labels & Dependency Mapping
The label model is the project. Role / application / environment / location taxonomy agreed before any enforcement, then traffic-flow dependency mapping to see what actually talks to what — which is almost never what the CMDB claims.
DELIVERED
Policy Modelling Before Enforcement
Draft policy tested against observed flows, so breakage is discovered in modelling rather than in production. Ring-fencing, environment separation and core-service exceptions designed explicitly.
DELIVERED
Staged Enforcement
Visibility → test → selective enforcement → full enforcement, per application tier, with defined exit criteria at each stage and a rollback path. Segmentation fails when it is switched on; it succeeds when it is staged.
ARCHITECTED
Platform Coverage
Illumio Segmentation for data-centre workloads, Segmentation for Cloud, Endpoint for user estate, and Insights for lateral-movement risk visibility — scoped by where the containment value actually is.
ARCHITECTED
Exception Governance
Every exception owned, justified and dated. Segmentation decays through undocumented permits — the operating model matters more than the initial rollout.
DELIVERED
Network Engineering Foundations
Protocol & Routing Depth
TCP/IP, DNS, BGP/OSPF routing, NAT, VLAN and overlay design. Reading a packet capture is the difference between diagnosing a WAF false positive in minutes and escalating it for days.
DELIVERED
Firewalls & Load Balancers
Palo Alto PAN-OS and Panorama, Check Point, Cisco Firepower, Fortinet, F5 and Netscaler — rule-base hygiene, policy optimisation, SSL offload and the interaction between load balancing and inline inspection.
DELIVERED
Packet Inspection & Telemetry
Deep packet inspection, Wireshark/tshark analysis, flow telemetry and capture strategy that is proportionate to storage and privacy constraints.
DELIVERED
Hybrid & Cloud Networking
ExpressRoute and VPN failover, VNet/VPC peering, private endpoints, transit architectures and cloud-native firewalling integrated with the enterprise estate rather than bolted beside it.
ARCHITECTED
Automation & Infrastructure as Code
Platform Automation
Python and PowerShell against platform REST APIs — bulk onboarding, policy export and diff, drift detection, evidence collection for audit. JSON and YAML as the interface between security tooling and pipelines.
DELIVERED
Infrastructure as Code
Terraform and Ansible for repeatable security-platform configuration, Git-based review, and CI/CD-style promotion so a control is deployed the same way in every environment.
DELIVERED
Policy as Code
Segmentation and WAF policy expressed, reviewed and version-controlled as code — making a control change a reviewable artefact instead of a console action nobody can reconstruct.
ARCHITECTED
Operating Model & Technical Leadership
Design → Implement → Operationalise
Translating security architecture and risk decisions into deployable engineering, then owning the lifecycle: deployment, configuration, troubleshooting, resilience, upgrade and change control.
DELIVERED
Maturity Uplift
Moving a platform from installed to effective — defined ownership, documented runbooks, measurable coverage, tuned detections and an exception process. Most platforms underperform for operating-model reasons, not technical ones.
ADVISED
Principal-Level SME Leadership
Design authority, standards, peer review and mentoring — influencing engineering practice without direct line management, and holding a position credibly with both engineers and senior stakeholders.
DELIVERED
Stakeholder Management
Working across application, infrastructure, network, SOC and security-architecture teams. Onboarding an application to a WAF or enforcing segmentation is a negotiation before it is a configuration.
DELIVERED
Value & Cost Discipline
Reducing tool overlap and alert noise, retiring redundant capability, and evidencing what each platform returns. Security platforms are judged on outcome per pound, like any other investment.
ADVISED
Regulated Financial Services Context
Banking & Capital Markets Environments
Engineering inside regulated financial-services estates — change freezes, segregation of duties, evidence requirements, and the reality that an outage carries regulatory weight as well as operational cost.
DELIVERED
Regulatory Alignment
Control design aligned with DORA, NIS2, PRA and FCA operational-resilience expectations, ISO 27001 and NIST CSF — expressed as engineering requirements rather than policy text.
ARCHITECTED
Resilience & Incident Support
Network-security troubleshooting under pressure, supporting incident response with traffic evidence, and designing for degraded-mode operation rather than assuming the control plane is available.
DELIVERED
Platform Summary
Imperva (Thales)
Cloud WAF · WAF Gateway · Advanced Bot Protection · API Security · DDoS Protection · Client-Side Protection · Account Takeover Protection · CDN
ExtraHop
RevealX 360 (SaaS) · RevealX Enterprise (self-managed) · NDR + NPM + IDS consolidation · full packet capture · TLS 1.3 decryption · behavioural ML
Illumio
Breach Containment Platform — Segmentation · Segmentation for Cloud · Endpoint · Insights · dependency mapping · staged enforcement
Adjacent Estate
Palo Alto PAN-OS / Panorama · Check Point · Cisco Firepower · Fortinet · F5 · Akamai · Zscaler · Darktrace · Vectra · Guardicore · Arbor