AI Security2024 – Present
Microsoft 365 Copilot — Secure Launch
Led the secure deployment of M365 Copilot using Purview and SharePoint Advanced Management — insider-risk policies, data security posture management (DSPM), and oversharing controls before enabling generative AI on corporate data.
AI Security2025
Agentic AI & Power Platform Governance
Defined DLP policy for Power Platform connectors used by AI agents and built a secured AI Champions sandbox; configured Onyx policies governing data leakage and anomalous agent behaviour across users, agents, and cloud assets.
SecOps2024 – Present
Microsoft Security Copilot
Operationalized Security Copilot for the SOC — deployed the conditional-access optimization agent, generated incident reports, and identified use cases to improve detection and response efficiency.
Cloud Security2023 – Present
Defender for Cloud — CSPM & CWP
Matured cloud security posture management across multiple Azure subscriptions; aligned Azure Policy to NIST SP 800-53, ISO 27001:2022, and the Azure Cloud Security Benchmark, with DevOps pipeline integration.
Cloud Security2024 – Present
CASB / Shadow IT Program
Refreshed CASB policies across Defender for Cloud Apps and Zscaler, cutting false positives by up to 75%; blocked high-risk unsanctioned generative-AI SaaS on endpoints.
Identity2023 – Present
Conditional Access & Entra ID Protection
Re-architected Conditional Access and sign-in / user-risk policies with device-trust enforcement; presented MFA and risk strategy to CIO, VP, and Director stakeholders.
SecOps2024 – Present
Microsoft Sentinel — SIEM & SOAR
Stood up Sentinel workspaces, data connectors, watchlists, and threat indicators; defined log-source, retention, and automated incident-response strategy.
GRC & Audit2014 – 2023
ISO 27001 Certification & vCISO Programs
Led ISO 27001 certification audits (2013 & 2022 standards) and virtual-CISO engagements for clients across healthcare, financial services, and MSP sectors; authored 140+ ISMS documents.
GRC & Audit2025
NIST CSF 2.0 Upgrade (IT + OT)
Contributed to a multi-day workshop upgrading the Cybersecurity Framework from 1.1 to 2.0, incorporating OT into the assessment and scoring with VP / Director stakeholders.
No projects in this category yet.