I build practical security projects across control assurance, risk assessment, audit automation, cloud/IaC security and security tooling.
The assurance projects use one shared fictional financial-services environment — Meridian Trust Financial Services (MTFS) — so the same risks, assets, evidence and underlying issues can be traced consistently across frameworks.
Synthetic project environment: MTFS, its people, systems, evidence, findings and management responses are fictional or synthetic. These repositories demonstrate methodology and are not presented as real client engagements.
| Project | Focus |
|---|---|
| Security Assurance Lab | Shared MTFS environment, canonical taxonomy, evidence lineage and cross-framework traceability |
| ISO 27001 Audit | Risk-based ISO/IEC 27001:2022 control assurance through findings, remediation and retest |
| Compliance Evidence Automation | Python evidence collection, YAML rules, framework mapping, integrity, reports, tests and CI |
| Operational Resilience & ICT Risk | UK operational resilience plus EEA DORA and third-party ICT risk |
| NIST CSF 2.0 Assessment | Current / Target Profiles, organisational Tier and improvement roadmap |
| UK GDPR Security Assessment | Article 32-led security/control assurance and supporting process reviews |
flowchart LR
A[Risk & Scope] --> B[Controls / Outcomes]
B --> C[Evidence]
C --> D[Testing]
D --> E[Exceptions]
E --> F[Findings / Gaps]
F --> G[Remediation]
G --> H[Retest]
Themes: risk-based scoping · design & operating effectiveness · sampling · evidence integrity · findings · remediation · analytics · cross-framework traceability
| Project | Focus |
|---|---|
| Bug Bounty Recon | Configurable Python reconnaissance workflow for authorised security testing, including fast, full, stealth and API-focused modes |
| IaC Security Project | Terraform / Infrastructure-as-Code project using separated backend, provider, main and variable definitions |
Python automation → repeatable security workflows
Terraform / IaC → infrastructure-as-code practice
Recon automation → structured discovery and probing
Evidence automation → technical evidence mapped to assurance outcomes
flowchart LR
A[Security Engineering] --> B[Technical Evidence]
B --> C[Control Validation]
C --> D[Risk & Assurance]
D --> E[Findings & Remediation]
F[Python / Automation] --> B
G[Cloud / IaC] --> A
H[Recon Workflows] --> A
- Shared assurance architecture: security-assurance-lab
- Full audit lifecycle: iso27001-audit-demo
- Audit automation: compliance-evidence-automation
- Operational resilience / DORA: operational-resilience-ict-risk-demo
- NIST CSF 2.0: nist-csf-maturity-demo
- UK GDPR security assurance: uk-gdpr-control-assessment-demo
- Security recon automation: bug-bounty-recon
- Infrastructure as Code: IACSecurityProject
Security Engineering · GRC · IT Audit · Technology Risk · Cyber Assurance · ISO 27001 · NIST CSF 2.0 · UK GDPR · DORA · Operational Resilience · Python · Audit Automation · Terraform · Infrastructure as Code