Security, Compliance & Infrastructure Engineer with 15+ years of experience across on-premises, co-location, hybrid Microsoft, Microsoft 365, and cloud-connected environments. Career built on deep hands-on ownership of Windows Server, Active Directory, ADFS, Exchange, SQL Server, IIS, Hyper-V, DNS/DHCP, VPN, SSL/TLS, Sophos firewall, Veeam, SCOM, Azure DevOps Server, backup and recovery, controlled change management, and vendor coordination across production commercial environments and multi-site MSP delivery.
Currently serves as the sole infrastructure, Microsoft 365 security, compliance, and governance owner for a production commercial software environment, with recent expansion of Microsoft 365 security and governance capability across Microsoft Purview Information Protection, DLP, Defender suite including Defender for Endpoint P2 in passive mode alongside ESET as primary endpoint protection, Microsoft Sentinel workspace readiness, Microsoft Priva, Microsoft Fabric / Power BI governance, and Power Platform CRM administration.
Sole owner of the EU Cyber Resilience Act (CRA) readiness programme covering SBOM analysis, CVE identification, Dependency-Track deployment, vulnerability disclosure workflow design, Article 14 CSIRT reporting readiness, and evidence organisation. Built a sanitised security control-mapping portfolio artefact aligning example security, identity, vulnerability-management, data-protection, incident-response, backup/DR, supplier, infrastructure, secure-development, and customer-assurance controls to EU CRA readiness themes, ISO/IEC 27001:2022 Annex A, NIST CSF 2.0, and SOC 2 Trust Services Criteria. Brings additional security-relevant context from data analytics study and practice, Python-based analysis, and blockchain and digital-asset workflow familiarity — supported by CI-validated DevSecOps, SBOM, compliance-mapping, and Linux operations labs.
Click any project to expand full detail.
Full-lifecycle deployment of Microsoft 365 security, compliance, and governance capabilities as sole owner of the company's production Microsoft 365 environment.
Sole owner of the CRA compliance programme covering EU customer markets.
Delivered government-funded School Network and Wireless School Network Upgrade Projects across multiple Auckland schools.
Primary on-site and remote engineer for approximately 30 Singapore client environments across Finance, Shipping, Logistics, Hotel, Pharmaceuticals, Automobile, Food & Beverage, and Manufacturing industries.
Sanitised control-mapping workbook demonstrating an inventory-first approach across EU CRA readiness themes, ISO/IEC 27001:2022 Annex A, NIST CSF 2.0, and SOC 2 Trust Services Criteria. Includes 48 example controls across 10 domains, with risk addressed, evidence-sensitivity classification, status, maturity scoring, gap tracking, framework legend, and sanitisation log.
GitHub Actions pipeline with Gitleaks secret scanning (full git history), Trivy IaC/container scanning for HIGH/CRITICAL findings on every push, Docker image build-and-push blocked on scan failure, and weekly Dependabot monitoring. Terraform lab validates AWS VPC, security groups, ECS cluster, and IAM task execution roles through CI without exposing credentials. Containerised FastAPI service with Prometheus metrics, Grafana dashboard, AppDown/restart-loop alert rules, deployment runbook, and incident-response scenario.
Sanitised real-world .NET SBOM analysis using CycloneDX, 201 NuGet components, CVE identification, compliance risk assessment, end-of-support component identification, and Dependency-Track integration for Azure DevOps pipeline. Findings report with remediation recommendations.
Linux administration, service management, user and permission administration, firewall and network configuration (nftables/iptables), log analysis, Nginx, and process/system monitoring with CI-validated broken/fixed service pairs and incident runbooks.
Owns technical delivery across infrastructure, security, Microsoft licensing, certificates, hardware, software, connectivity, backup, firewall, DNS, hosting, and cloud-service dependencies.
Completed a Graduate Diploma in Data Analysis while employed full time, building practical capability in Python, Pandas, NumPy, data cleaning, validation, exploratory analysis, dashboard outputs, and structured reporting. Applies this background to security and infrastructure work through evidence review, noisy-output investigation, vulnerability data interpretation, CVE and CVSS analysis, incident documentation, and operational decision support. Capstone project: AI-Driven Air Quality Forecasting System for Auckland CBD using machine-learning-based time-series modelling.
Maintains practical familiarity with digital-asset workflows across exchanges, wallets, exchange deposit and withdrawal flows, blockchain explorers, transaction-hash verification, token-contract review, network selection risk, and failed or pending transaction review. This adds practical domain fluency for security, trust-and-safety, platform-operations, and fintech or crypto environments where user-side risk, transaction verification, platform reliability, and abuse patterns need to be understood.