Oneil Dixon

Information Security Analyst @Legal & General

London, GB
MOBILE NUMBERS
+91 *********19

Signup · Get unlimited contacts

WORK HISTORY

May 2025 — Present

Information Security Analyst @Legal & General

View department →

London, GB

Operating within the UK Protection Retail Division of one of the UK\'s largest financial institutions, providing hands-on technical security expertise across a complex, containerised enterprise estate on Microsoft Azure.Recognised as a Wiz CSPM & DSPM SME within the UK Protection Retail Division, owning runtime sensor configuration across Azure Container Apps and Container Registries, leading vulnerability management and remediation tracking, and upskilling teams on Wiz capabilities to strengthen cloud security posture• Manage vulnerability triage for containerised workloads and CI/CD pipelines, reviewing failed image scans and approving or rejecting exception requests based on severity, exploitability, and organisational risk appetite using Wiz across Microsoft Azure infrastructure• Embed security across the full lifecycle of internal projects and system enhancements, ensuring secure-by-design principles are applied from architecture through to deployment• Support penetration testing, governance processes, and audit preparation, ensuring stakeholder expectations and regulatory checkpoints are consistently met• Manage and calibrate security tooling across the containerised estate to improve detection effectiveness and visibility• Work closely with risk, audit, and technology teams to align security controls with business objectives and regulatory requirements• Serve as the sole Information Security approver for Palo Alto firewall change requests across Retail application teams, reviewing and governing 300+ firewall rules by leveraging deep networking and security expertise to assess risk, enforce least-privilege principles, and maintain a secure and compliant rule baseOperating in a heavily regulated financial services environment, applying enterprise-scale security governance alongside hands-on technical delivery.

EDUCATION

2014 — 2017

The College of Haringey, Enfield and North East London

Electrical and Electronics Engineering

2017 — 2020

University of Hertfordshire

Computing Technologies, Computer Systems Networking and Telecommunications

2020 — 2021

University of Hertfordshire

Bachelor's degree, Computer Science (Software Engineering & Cybersecurity)

ABOUT ONEIL DIXON

Most growing tech companies reach a point where security can\'t be an afterthought, an investor asks about PCI DSS, a customer wants a pentest report, or an audit is six weeks away and nobody owns it. Hiring a full security team isn\'t realistic yet. That\'s where I come in.I\'m an Application Security and Cloud Security consultant helping UK SaaS, fintech, and tech businesses build secure security programmes without the overhead of a full in-house team. My focus is the combination that fast-growing companies actually need: AppSec, DevSecOps, PCI DSS compliance, and cloud security end to end, hands on.I\'ve contributed to the Cloud Security Alliance\'s Trusted AI Safety Expert (TAISE) certification programme, been published as a PCI DSS v4 subject matter expert, and hold a CCSK v4 the cloud security industry\'s leading practitioner credential. I\'ve built AppSec programmes at PCI regulated tech businesses and secured enterprise containerised infrastructure at Legal & General, one of the UK\'s largest financial institutions.Most recently, I owned the entire AppSec function at a PCI regulated technology business building vulnerability management from the ground up, integrating SAST, DAST, and dependency scanning into CI/CD pipelines, conducting penetration testing and threat modelling, and serving as PCI DSS SME across multiple engineering teams. I’ve also built centralised security reporting infrastructure using API integrations and BigQuery, giving leadership real-time visibility into security posture. I didn\'t advise on these things. I built and ran them without a large team or unlimited budget.What sets me apart is the ability to work across the full stack: from writing secure code policies and embedding security tooling into pipelines, to managing PCI DSS evidence and standing in front of auditors. I understand developers. My philosophy is secure by design without unnecessary friction, because security that developers work around is no security at all.What I can help you with:• Building or maturing your AppSec programme from scratch• Integrating DevSecOps tooling into your CI/CD pipeline (SAST, DAST, secrets scanning, dependency scanning)• PCI DSS readiness, gap assessments, and ongoing compliance management• Cloud security posture reviews across AWS, Azure, and GCP• Security visibility and reporting infrastructure• Fractional Head of Security / AppSec retainer for growing teamsIf you\'re a UK SaaS, Startup or fintech business that\'s serious about security but not ready to hire a full team, let\'s talk.

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Oneil Dixon — Information Security Analyst at Legal & General in London, GB | Unifers