Tamsyn Weston
Head of Identity and Access Management @Aberdeen
Signup · Get unlimited contacts
WORK HISTORY
Head of Identity and Access Management @Aberdeen
Edinburgh, GB
Led enterprise-wide NIST CSF-aligned security posture assessment, identifying systemic control gaps, regulatory exposure (FCA, DORA), and defining a multi-year remediation strategy• Designed Zero Trust and Zero Standing Privilege strategy, addressing excessive access, identity sprawl, and privileged access risk across the organisation• Identified critical data protection and insider threat risks, including large-scale unclassified data, open access exposure, and lack of behavioural analytics capability• Defined roadmap for SOC and detection uplift, including integration of Microsoft Defender with SIEM (Sentinel) and enhanced detection engineering• Developed strategy for behavioural analytics and DSPM leveraging Varonis, including transition to cloud-based monitoring and automated remediation• Produced executive-level risk reports, investment cases, and prioritised delivery plans to support board decision-making
EDUCATION
Edinburgh Napier University
Information Systems Management, Information Technology
SKILLS
ABOUT TAMSYN WESTON
Cyber security leader specialising in transforming enterprise risk into measurable actions across regulated financial services and complex enterprise environments.Open to opportunities across UK, Europe and US - remote, hybrid, contract, fractional or permanent. I design and deliver security strategies that go beyond compliance, translating NIST, DORA, FCA and ISO principles into pragmatic, risk-based programmes that reduce exposure, strengthen operational resilience, and enable sustainable business growth. My experience spans enterprise IAM transformation, Zero Trust and Zero Standing Privilege, SOC and detection capability uplift, and data protection/insider threat programmes. I have a strong track record of identifying systemic risk, quantifying regulatory exposure, and delivering both tactical remediation and multi-year strategic transformation. I operate at board level, shaping investment decisions, influencing executive stakeholders, and aligning cyber security with commercial and regulatory priorities. Key impact includes: Delivered enterprise-wide NIST CSF security posture assessments, identifying regulatory exposure and defining prioritised remediation roadmaps Led full cyber and technology transformation programmes achieving Cyber Essentials Plus and significant CIS maturity uplift Designed and implemented Zero Trust and identity-led security architectures, reducing privilege risk and attack surface Built and enhanced SOC and detection capabilities integrating Microsoft Defender, Sentinel, and behavioural analytics Developed insider threat and data protection strategies leveraging DLP and DSPM capabilities (Varonis, Purview) Delivered cyber resilience and recovery capabilities with defined RTO/RPO aligned to regulatory expectations I am particularly focused on roles where I can lead enterprise security transformation, strengthen threat-led defence, and deliver measurable risk reduction at scale. Open to CISO, Head of Cyber Security, and senior security leadership roles (permanent, interim, or transformation-led).
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.