Professional Experience

Senior Security Engineer

Mitto AG
Jan 2022 – Present

As a strategic Senior Security Engineer, I architected and led Mitto's comprehensive security compliance program, achieving ISO 27001, ISO 27701, and SOC2 Type II certifications/reports with zero critical findings. I orchestrated end-to-end security transformation by pioneering a multi-layered DevSecOps approach that reduced deployment vulnerabilities while accelerating release cycles. Developed and implemented an innovative vulnerability management platform integrating Kubernetes Trivy Operator deployments with proprietary EPSS (Exploit Prediction Scoring System) and KEV (Known Exploited Vulnerabilities) analytics for real-time threat prioritization.

Project Highlights:

  • Designed and implemented full-spectrum vulnerability management ecosystem with CI/CD pipeline integration and executive-level reporting dashboards
  • Led cross-functional teams through ISO 27001, ISO 27701, and SOC2 Type II compliance initiatives, establishing mature GRC frameworks that survived rigorous audits
  • Engineered containerized security solutions with Kubernetes operators that automated scanning across development, testing and production environments
  • Developed Python-based EPSS and KEV analysis tools that reduced critical vulnerability response times from 9 days to under 24 hours
  • Established shift-left security practices that embedded automated security controls at every stage of the SDLC

Security Solutions Architect

Dimension Data/NTT
May 2018 – Dec 2021

As Technical Security Solutions Specialist at Dimension Data, I spearheaded enterprise-level security transformations for clients across multiple sectors. Architected and implemented comprehensive OT/IT security convergence solutions for manufacturing environments, delivering segmentation across production facilities. Led SD-WAN deployments spanning multiple countries, designing resilient architectures that reduced security incidents by 64% while cutting operational costs. Orchestrated complex cloud migration initiatives, establishing secure-by-design frameworks that enabled seamless transition of critical workloads with continuous compliance monitoring.

Project Highlights:

  • Designed and implemented industrial firewall ecosystems for critical infrastructure clients, integrating Purdue Model security principles with next-generation threat detection capabilities
  • Architected global SD-WAN security frameworks for multinational enterprises, creating standardized security policies across locations while maintaining local compliance requirements
  • Developed reference architecture for secure cloud migrations, incorporating automated compliance controls, CSPM tools, and IAM frameworks that maintained compliance with ISO 27001, PCI-DSS, and SOC2
  • Established security control matrices that bridged IT/OT environments, enabling clients to achieve regulatory compliance while maintaining operational uptime
  • Led security workshops and governance sessions with C-suite stakeholders, translating complex security architectures into business value propositions

Security Engineer L3

Dimension Data
January 2013 – May 2018

As Security Engineering Team Lead within Dimension Data's MSSP division, I managed comprehensive security operations for enterprise clients across financial, healthcare, and manufacturing sectors. Oversaw enterprise-wide PKI infrastructure for multiple organizations, implementing multi-tier hierarchical designs that achieved 99.999% availability while meeting stringent compliance requirements. Orchestrated security for 100+ network security devices including next-generation firewalls, WAFs, proxies, and IPS systems across globally distributed environments. Led high-profile incident response teams during critical breach scenarios, successfully containing advanced persistent threats.

Work Highlights:

  • Lead technical teams of 5+ engineers, establishing mentorship and technical advancement that improved team professionalism and moral
  • Orchestrated comprehensive disaster recovery testing for mission-critical environments, achieving 100% recovery success rate while reducing RTO/RPO by 60%
  • Led remediation of high-severity security incidents involving nation-state actors, coordinating with vendors and implementing countermeasures that prevented data exfiltration
  • Designed and implemented cloud migration security frameworks enabling zero-downtime transitions while maintaining continuous security monitoring
  • Established automated security configuration management for heterogeneous environments, reducing security drift by 85% and enabling continuous compliance verification

Network Engineer

The McGraw-Hill Companies
July 2004 – December 2012

As a certified Network Engineer, I served as the primary technical resource for McGraw-Hill's EMEA networking infrastructure, traveling extensively to European satellite offices to provide hands-on support and implementation expertise. Orchestrated a critical infrastructure overhaul of Cisco Catalyst Chassis switches at the European Head Office, coordinating with business units to ensure zero operational disruption during the migration. Managed all aspects of network infrastructure including data center operations, WAN optimization, and telephony systems, establishing the foundation for my subsequent cybersecurity career path.

Work Highlights:

  • Led enterprise-wide deployment and optimization of routing protocols (EIGRP, OSPF, BGP) across multiple international locations
  • Designed and implemented high-availability data center switching infrastructure using Cisco Nexus technologies
  • Executed major infrastructure refresh of core Catalyst Chassis switches at European headquarters with minimal downtime
  • Managed technical support for 12+ European office locations, providing on-site expertise for complex networking challenges
  • Pioneered virtualized infrastructure deployments in data center environments, creating a modern platform for business applications

Professional Memberships

May 2018 – January 2022
Advisory board member
Centre for Research in Information and Cyber Security (CRICS) and the School of ICT, Nelson Mandela University

Inducted as an advisory board member of the Centre for Research in Information and Cyber Security at the Nelson Mandela Bay University, guiding and mentoring the next generation of Cybersecurity professionals

Skills & Expertise

Security Expertise

  • DevOps and DevSecOps Security
  • Planning, researching, and designing security architectures
  • Vulnerability and penetration testing assessments
  • ISO 27001, NIST CSF, PCI DSS, CIS and SOC2
  • Purdue Model and ISA/IEC 62443

Technical Skills

  • Multi-Vendor firewalls and proxies
  • Identity Management
  • Public Key Infrastructure
  • Web Application Firewalls
  • Vulnerability Scanning
  • Python (Automation, Security Tools)
  • Secure Coding Practices
  • Network Security Tools (e.g., Wireshark, tcpdump)

Cloud & Modern Tech

  • Cloud Architecture (Azure)
  • CI/CD (Azure DevOps)
  • SCA
  • Kubernetes & Docker
  • GIT
  • Terraform
  • SIEM (Splunk, FortiSIEM)

Management

  • Team lead and mentor for security teams
  • Preparing and presenting cost estimates and timelines
  • Proof of concept to full deployment lifecycle
  • Client relations and stakeholder management
  • Enterprise security posture management

Certifications

CISSP
Certified Information Systems Security Professional (CISSP)
Membership ID: 727693
01 March 2020
CCNP
Cisco Certified Network Professional (CCNP)
Membership ID: CSCO1179107
26 September 2012 - 2018
SAFe
Certified SAFe® 4 Agilist
05 September 2018
Azure
Microsoft Certified: Azure Fundamentals
991331460
30 April 2021
DevSecOps
Certified DevSecOps Professional (CDP)
CDP19CBBFA9
07 December 2023
Kubernetes
Certified Kubernetes Administrator (CKA)
LF-chzsne1lp8
16 November 2024

Professional Development

2024

August 2024

Prepare for the Certified Kubernetes Administrators Certification

Udemy
Certified
Kubernetes Administration Cloud

2023

December 2023

Certified DevSecOps Professional

Practical DevSecOps
Certified
DevSecOps Security CI/CD
July 2023

DevSecOps: Integrating Security into DevOps

(ISC)²
DevSecOps Security Integration
July 2023

Git Going Fast: One Hour Git Crash Course

Udemy
Git Version Control Development
June 2023

Docker & Kubernetes: The Practical Guide [2023 Edition]

Udemy
Docker Kubernetes Containers
March 2023

ISO/IEC 27701:2019 - Privacy Information Management System

Udemy
ISO Privacy Compliance

2022

April 2022

Lacework Fundamentals for Security Practitioners

Lacework
Security Cloud Monitoring
February 2022

Python for Absolute Beginners | Python Beginner to Pro 2021

Udemy
Python Programming Development

2021

September 2021

CISO's Guide to Success

(ISC)² Professional Development Institute
Leadership Security Management
September 2021

Introduction to Kubernetes and Intersight Kubernetes Services

Cisco
Kubernetes Cisco Cloud
July 2021

Web Security and the OWASP Top 10

Troy Hunt
OWASP Web Security Vulnerabilities
April 2021

Microsoft Certified: AZ-900 Azure Fundamentals

Microsoft
Certified
Azure Cloud Microsoft
March 2021

Self Study Azure Fundamentals

Microsoft
Azure Cloud Fundamentals
February 2021

Creating a Comprehensive Security Fabric v6.4

Fortinet
Security Fortinet Firewall
January 2021

FortiSIEM - Advanced Analytics 5.2

Fortinet
SIEM Analytics Monitoring

2020

December 2020

Communicating with the C-Suite

Professional Development
Communication Leadership Management
May 2020

Securing Containers at the Speed of DevOps

Professional Development
Containers DevOps Security
March 2020

Introduction to the NIST Cybersecurity Framework

Professional Development
NIST Framework Compliance

2019

Aug-Dec 2019

Certified Information Systems Security Professional

(ISC)²
Certified
CISSP Security Certification
November 2019

Risk Assessment and Management

Professional Development
Risk Management Assessment