Principal-Level Security Platform Engineering

Network Security Engineering

Hands-on engineering ownership of the platforms that enforce network and application security in regulated enterprise estates — Imperva WAAP and DDoS, ExtraHop RevealX NDR, and Illumio micro-segmentation — from architecture and policy design through automation, staged enforcement and the operating model that keeps them effective.

Evidence taxonomy: DELIVEREDpersonally implemented on real engagement ARCHITECTEDpersonally owned the design ADVISEDadvisory / assessment engagement

Imperva — Application & DDoS Protection

WAF Onboarding at Scale

Repeatable onboarding runbook for moving applications behind Cloud WAF and WAF Gateway: discovery, origin protection, DNS/CNAME cutover, TLS and certificate handling, health checks, staged monitor-to-block transition and rollback criteria. Onboarding treated as a product, not a ticket.

DELIVERED

Policy Engineering & False-Positive Management

Tuning rulesets per application rather than per estate — signature tuning, custom rules, exception lifecycle with expiry, and a measured false-positive budget. Blocking that application teams trust because they understand why a rule fires.

DELIVERED

DDoS Operating Model

Network-layer and application-layer DDoS protection, always-on versus on-demand posture, BGP and DNS diversion paths, time-to-mitigation targets, and the runbook for a live event. Includes consolidating overlapping DDoS tooling onto one operating model.

ARCHITECTED

API & Bot Protection

API discovery and schema enforcement, Advanced Bot Protection classification tuning, Account Takeover and Client-Side Protection. Covers the gap between a WAF that inspects requests and a WAAP that understands the application.

DELIVERED

Change Control, Alerting & Lifecycle Ownership

Policy-as-change-record, peer review, scheduled windows, back-out plans, and alert routing that distinguishes attack from regression. Platform ownership through upgrades, certificate rotation and capacity events.

DELIVERED

ExtraHop RevealX — Network Detection & Response

East-West Visibility & Coverage

Sensor placement, TAP and SPAN strategy, and VPC/VNet mirroring so lateral movement is actually observable. Coverage measured against the asset inventory — a named percentage of east-west traffic inspected, not an assumption that it is covered.

DELIVERED

Detection Tuning & Noise Reduction

The real NDR problem is rarely coverage; it is signal. Baseline establishment, tuning by asset criticality, suppression with review dates, and detection quality tracked as precision over volume. Fewer, better alerts that analysts act on.

DELIVERED

Deployment Models

RevealX 360 (SaaS) and RevealX Enterprise (self-managed) — choosing by data-residency and regulatory constraint rather than preference. Decryption strategy including TLS 1.3, and where packet capture is proportionate versus excessive.

ARCHITECTED

SOC Integration

Detections into SIEM/SOAR with context that makes triage faster — device role, peer behaviour, protocol anomaly — plus playbook hooks. NDR earns its licence by shortening investigations, not by adding a queue.

DELIVERED

Demonstrating Platform Value

Articulating NDR return: mean-time-to-detect movement, blind spots closed, tooling retired, and analyst hours recovered. Written for a budget holder, not a console.

ADVISED

Illumio — Micro-Segmentation & Breach Containment

Labels & Dependency Mapping

The label model is the project. Role / application / environment / location taxonomy agreed before any enforcement, then traffic-flow dependency mapping to see what actually talks to what — which is almost never what the CMDB claims.

DELIVERED

Policy Modelling Before Enforcement

Draft policy tested against observed flows, so breakage is discovered in modelling rather than in production. Ring-fencing, environment separation and core-service exceptions designed explicitly.

DELIVERED

Staged Enforcement

Visibility → test → selective enforcement → full enforcement, per application tier, with defined exit criteria at each stage and a rollback path. Segmentation fails when it is switched on; it succeeds when it is staged.

ARCHITECTED

Platform Coverage

Illumio Segmentation for data-centre workloads, Segmentation for Cloud, Endpoint for user estate, and Insights for lateral-movement risk visibility — scoped by where the containment value actually is.

ARCHITECTED

Exception Governance

Every exception owned, justified and dated. Segmentation decays through undocumented permits — the operating model matters more than the initial rollout.

DELIVERED

Network Engineering Foundations

Protocol & Routing Depth

TCP/IP, DNS, BGP/OSPF routing, NAT, VLAN and overlay design. Reading a packet capture is the difference between diagnosing a WAF false positive in minutes and escalating it for days.

DELIVERED

Firewalls & Load Balancers

Palo Alto PAN-OS and Panorama, Check Point, Cisco Firepower, Fortinet, F5 and Netscaler — rule-base hygiene, policy optimisation, SSL offload and the interaction between load balancing and inline inspection.

DELIVERED

Packet Inspection & Telemetry

Deep packet inspection, Wireshark/tshark analysis, flow telemetry and capture strategy that is proportionate to storage and privacy constraints.

DELIVERED

Hybrid & Cloud Networking

ExpressRoute and VPN failover, VNet/VPC peering, private endpoints, transit architectures and cloud-native firewalling integrated with the enterprise estate rather than bolted beside it.

ARCHITECTED

Automation & Infrastructure as Code

Platform Automation

Python and PowerShell against platform REST APIs — bulk onboarding, policy export and diff, drift detection, evidence collection for audit. JSON and YAML as the interface between security tooling and pipelines.

DELIVERED

Infrastructure as Code

Terraform and Ansible for repeatable security-platform configuration, Git-based review, and CI/CD-style promotion so a control is deployed the same way in every environment.

DELIVERED

Policy as Code

Segmentation and WAF policy expressed, reviewed and version-controlled as code — making a control change a reviewable artefact instead of a console action nobody can reconstruct.

ARCHITECTED

Operating Model & Technical Leadership

Design → Implement → Operationalise

Translating security architecture and risk decisions into deployable engineering, then owning the lifecycle: deployment, configuration, troubleshooting, resilience, upgrade and change control.

DELIVERED

Maturity Uplift

Moving a platform from installed to effective — defined ownership, documented runbooks, measurable coverage, tuned detections and an exception process. Most platforms underperform for operating-model reasons, not technical ones.

ADVISED

Principal-Level SME Leadership

Design authority, standards, peer review and mentoring — influencing engineering practice without direct line management, and holding a position credibly with both engineers and senior stakeholders.

DELIVERED

Stakeholder Management

Working across application, infrastructure, network, SOC and security-architecture teams. Onboarding an application to a WAF or enforcing segmentation is a negotiation before it is a configuration.

DELIVERED

Value & Cost Discipline

Reducing tool overlap and alert noise, retiring redundant capability, and evidencing what each platform returns. Security platforms are judged on outcome per pound, like any other investment.

ADVISED

Regulated Financial Services Context

Banking & Capital Markets Environments

Engineering inside regulated financial-services estates — change freezes, segregation of duties, evidence requirements, and the reality that an outage carries regulatory weight as well as operational cost.

DELIVERED

Regulatory Alignment

Control design aligned with DORA, NIS2, PRA and FCA operational-resilience expectations, ISO 27001 and NIST CSF — expressed as engineering requirements rather than policy text.

ARCHITECTED

Resilience & Incident Support

Network-security troubleshooting under pressure, supporting incident response with traffic evidence, and designing for degraded-mode operation rather than assuming the control plane is available.

DELIVERED

Platform Summary

Imperva (Thales)

Cloud WAF · WAF Gateway · Advanced Bot Protection · API Security · DDoS Protection · Client-Side Protection · Account Takeover Protection · CDN

ExtraHop

RevealX 360 (SaaS) · RevealX Enterprise (self-managed) · NDR + NPM + IDS consolidation · full packet capture · TLS 1.3 decryption · behavioural ML

Illumio

Breach Containment Platform — Segmentation · Segmentation for Cloud · Endpoint · Insights · dependency mapping · staged enforcement

Adjacent Estate

Palo Alto PAN-OS / Panorama · Check Point · Cisco Firepower · Fortinet · F5 · Akamai · Zscaler · Darktrace · Vectra · Guardicore · Arbor

Client names are withheld under confidentiality; sector context is given instead. Engagement detail available on request.

Architecture practice · Case studies · Contact