James M.
Advisory Board Member @Technology Leaders Club
Signup · Get unlimited contacts
WORK HISTORY
Advisory Board Member @Technology Leaders Club
ABOUT JAMES M.
I help modern leaders accelerate their cyber security work using my over twenty years experience in fixing security (information security and cyber security) A UK based, security leader with international experience, 25 years in IT, 15 years in Information Security. A pragmatic inclusive leader who promotes fit for purpose security strategies based on real word experience of criminal attacks. Has led teams of up to 20 very qualified offensive and defensive technical resources. Known to work with people, process and technology in that order. Strong understanding of the relationship between technology and strategic business objectives. A long history of successful vulnerability management programs in the software development, infrastructure, and web application domains. A promoter of developer first security and devsecop tools and practices. A gifted technologist with extensive experience in areas of IT Governance, Risk Management, SDLC, Application Security, IT Infrastructure Security, Vulnerability Management and Penetration Testing engagements, Forensic Investigation. SOC setup, and SOC maturity. Certified OSCP (Ethical Hacking), Certified CFIP ( Digital Forensics), Held ISC2 CISSP for 10 years A constant promoter of the NCSC public body of work including, 5 questions for the board, 3 random words, 10 steps to cyber security, Cyber Essentials, Exercise in a box, Building a Security Operations Centre and, the Cyber Assessment Framework. Regularly consults on security strategies developed from CAF, ISF-SOGP, ISO27001:2013/2022, NIST-CSF, NIST800-53, NIST-SP800-61 Incident Management, and CREST DFIR Maturity Assessments. Recent experience of carrying out NIST-CSF CMMI Maturity assessments and building ISO27001:2022 Information Security Management Systems. Previous government collaboration with Dft and CPNI (TSIE) whilst Information Security Manager at Manchester Airport, early adopter of the CISP sharing platform (at the end of the Project Auburn) First hand knowledge of current real attacks gained through leadership in an Incident Management and Digital Forensics company and a personal interest in tracking criminal tools and tactics. Has experience working ransomware recovery cases involving advanced threat groups such as Conti, Hive, Karakurt, Blackmatter, Lockbit3, Blackcat, MedusaTeam and LorenzTeam. Hosted the “Cybersecurity as a Joint Public-Private Security Imperative” panel at Infosec 2022 with the then Deputy Director Cyber at Cabinet Office and the Deputy Director US CISA.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.