Portfolio

Work that proves it.

What I'm building right now — hands-on portfolio work, independent of any employer or client. Each one is chosen to prove a specific part of the job, not to pad a list.

Flagship
Governance & GRC

Lighthouse — GRC Platform

In progress · MVP, Phase 1 · target Aug 2026

A minimalist, opinionated GRC platform for small-to-mid SaaS companies — risk register, control-framework mapping (ISO 27001 / NIST CSF / SOC 2), third-party risk, evidence collection, and audit management in one place, with plugins for AWS Security Hub, MISP, and Slack.

Proves: ISO 27001 / SOC 2 programme design · control-framework mapping · TPRM · threat-informed risk (MISP) · evidence automation · executive dashboards.

  • Python
  • FastAPI
  • PostgreSQL
  • React
  • TypeScript
  • Docker
Read the case study →
Incident Response

IR Tabletop & Playbook Library

Published · public on GitHub

A public tabletop-exercise pack and IR playbook library — 10 scenarios across 5 industries and 5 jurisdictions, built on 5 threat-based playbooks (ransomware, data exfiltration, BEC / payment fraud, OT / cyber-physical, payment-card / POS), each with jurisdiction-specific regulatory annexes. Designed so a small security team can run any scenario unmodified.

Proves: IR programme leadership & facilitation · crisis communication · multi-jurisdiction regulatory breadth (POPIA, UK FCA/ICO, GDPR, Australia NDB, PCI-DSS) · operational documentation.

  • Incident Response
  • Playbooks
  • Tabletop
  • Multi-jurisdiction
View on GitHub →

Get in touch

Want to talk through any of this?

Happy to walk through the decisions, the trade-offs, and what didn't work.