System online · accepting connections

Lloyd
Sato

$ cat /etc/role → Cyber Security Professional

Master's graduate with commercial experience in security operations and risk management. I translate technical threats into business advice.

4+
Years in Security
MSc
Cyber & Forensics
Sec+
CompTIA Certified
soc-console — tty1
lloyd@soc:~$ whoami lloyd.sato — security operations analyst lloyd@soc:~$ ./scan --credentials [OK] MSc Cyber Security & Forensics — Westminster [OK] CompTIA Security+ · IBM Cybersecurity Analyst [..] CREST Incident Response — in progress lloyd@soc:~$ tail -f /var/log/focus.log ALERT detection engineering × adversary research mapping malware behaviour → MITRE ATT&CK → controls lloyd@soc:~$
[0x02] // about

Background

Security operations, threat research, and the craft of turning adversary behavior into clear, actionable risk conversations.

I specialize in translating technical threats into business advice, managing risk registers, and implementing security frameworks like MITRE ATT&CK. Currently operating as a Security Operations Analyst (SOC L1), handling the full incident lifecycle to minimize operational disruption. Across an enterprise estate I've also driven vulnerability management, prioritising remediation with CVSS and threat-intelligence-led criteria.

I hold a Master of Cyber Security and Forensics from the University of Westminster, and industry certifications including CompTIA Security+ and the IBM Cybersecurity Analyst Professional Certificate — with CREST Incident Response currently in progress.

My focus sits at the intersection of detection engineering and adversary research: reading what malware actually does in memory, mapping it to ATT&CK, and feeding those findings back into the controls that stop the next intrusion.

lloyd@soc:~$ cat competencies.txt
  • Microsoft Defender for Endpoint & Splunk
  • Infrastructure scans using Nessus
  • Vulnerability management & remediation (CVSS)
  • Static and dynamic analysis of malware
  • Python, PowerShell, and SQL
[0x03] // skills

Technical Skills

Grouped by discipline, with proficiency clearly labelled — strongest first in each group.

SIEM & EDR

Detection & endpoint defense
  • SplunkAdvanced
  • Defender for EndpointAdvanced
  • Microsoft SentinelProficient
  • CrowdStrikeProficient

Threat Intelligence

IoCs, CTI, evasion research
  • IoC IdentificationAdvanced
  • AMSI & EDR EvasionResearch
  • CTI ReportsProficient

Vulnerability & Risk

Vulnerability management, response, GRC
  • Vulnerability ManagementAdvanced
  • Risk RegistersAdvanced
  • Incident ResponseAdvanced
  • NessusProficient

Malware Analysis

Static & dynamic analysis, sandboxing
  • Dynamic AnalysisAdvanced
  • Any.RunAdvanced
  • Static AnalysisProficient
  • REMnuxProficient

Frameworks & Standards

Industry baselines
  • MITRE ATT&CKAdvanced
  • CVSSAdvanced
  • CompTIA Security+Certified
  • OWASPProficient
  • CIS BenchmarksProficient
  • GDPRProficient

Scripting & Languages

Automation & tooling
  • PowerShellAdvanced
  • PythonProficient
  • SQLProficient
  • C++Working
[0x04] // experience

Event Log

From enterprise SOC operations to academic adversary research and back again.

Dec 2025 — Present

Security Operations Analyst (SOC L1)

Acumen Technix LTD · London, UK
  • Deployed Microsoft Defender for Endpoint to monitor assets and block complex malware.
  • Administered and optimised Splunk to detect and triage incidents.
  • Managed risk registers using SQL to track service impacts, ensuring GDPR alignment.
Defender for Endpoint Splunk SQL GDPR
Mar 2024 — Mar 2026

Security Analyst

Tesco Stores Ltd · Lambeth, UK
  • Evaluated and prioritised vulnerabilities using CVSS and threat-intelligence-led criteria to focus remediation on the highest business risk.
  • Partnered with cross-functional technology and business teams to drive remediation to closure, managing exceptions through the formal risk-acceptance process.
  • Supported the group vulnerability-management tooling and bug-bounty programme, applying CVSS, OWASP, CIS Benchmarks, and MITRE.
CVSS OWASP CIS Benchmarks Bug Bounty
Oct 2023 — Mar 2024

Researcher

University of Westminster · Westminster, UK
  • Conducted in-depth research into malware evasion techniques.
  • Performed analysis utilising the Any.Run sandbox to dissect process injection and obfuscation.
  • Produced actionable cyber threat intelligence reports.
Any.Run REMnux CTI MITRE ATT&CK
Jul 2021 — Nov 2022

Security Operations Analyst (SOC L1)

HSBC · Gurgaon, India
  • Analysed security alerts from Microsoft Sentinel and CrowdStrike.
  • Conducted comprehensive analysis of malware samples to identify Indicators of Compromise.
  • Developed custom scripts using Python and PowerShell to automate intelligence collection.
Sentinel CrowdStrike Python PowerShell
[0x05] // contact

Open a Channel

Open to cybersecurity roles, research collaborations, and contract work. Fill in the form and I'll get back to you within 48 hours.

mail@lloydsato.com London, UK · 51.5072°N 0.1276°W
Open channel