Lloyd Sato

identity00%--:--:-- UTC

Open a channel

LloydSato

Role Cyber Security Professional

I read what malware actually does, map it to the frameworks defenders already use, and turn the result into decisions a business can act on.

Status
Available
Base
London, UK
Credentials
MSc Cyber & Forensics · Security+ · IBM CA
In progress
CREST Incident Response

Background

I specialise in translating technical threats into business advice, managing risk registers, and implementing security frameworks like MITRE ATT&CK. Currently operating as a Security Operations Analyst (SOC L1), handling the full incident lifecycle to minimise operational disruption. Across an enterprise estate I have also driven vulnerability management, prioritising remediation with CVSS and threat-intelligence-led criteria.

I hold a Master of Cyber Security and Forensics from the University of Westminster, and industry certifications including CompTIA Security+ and the IBM Cybersecurity Analyst Professional Certificate — with CREST Incident Response currently in progress.

My focus sits at the intersection of detection engineering and adversary research: reading what malware actually does in memory, mapping it to ATT&CK, and feeding those findings back into the controls that stop the next intrusion.

Working competenciesCurrent
  • Microsoft Defender for Endpoint and Splunk
  • Infrastructure scanning with Nessus
  • Vulnerability management and remediation (CVSS)
  • Static and dynamic analysis of malware
  • Python, PowerShell, and SQL

Capability ledger

Strongest first in every row

Everything I work with, grouped the way a job description groups it. One axis: how deep I have taken it.

  • Production11owned in a live environment
  • Applied11used in the job, alongside others
  • Lab2taken apart in a controlled environment

SIEM & endpoint

where the alerts land Case file CF-002
  • Splunk — production
  • Defender for Endpoint — production
  • Microsoft Sentinel — applied
  • CrowdStrike — applied

Vulnerability & risk

triage, remediation, governance Case file CF-003
  • Vulnerability management — production
  • Risk registers — production
  • Incident response — production
  • Nessus — applied

Malware analysis

static and dynamic, sandboxed Case file CF-001
  • Dynamic analysis — production
  • Any.Run — production
  • Static analysis — applied
  • REMnux — applied

Threat intelligence

IoCs, CTI, evasion research
  • IoC identification — production
  • CTI reporting — applied
  • AMSI & EDR evasion — lab

Frameworks & standards

the shared language
  • MITRE ATT&CK — production
  • CVSS — production
  • OWASP — applied
  • CIS Benchmarks — applied
  • GDPR — applied

Scripting

automation and tooling
  • PowerShell — production
  • Python — applied
  • SQL — applied
  • C++ — lab

Credentials MSc Cyber Security & Forensics, University of Westminster · CompTIA Security+ · IBM Cybersecurity Analyst · CREST Incident Response — in progress

Event log

Printable CV

From enterprise SOC operations to academic adversary research and back again.

Dec 2025 — Present

Security Operations Analyst (SOC L1)

Acumen Technix LTD · London, UK

  • Deployed Microsoft Defender for Endpoint to monitor assets and block complex malware.
  • Administered and optimised Splunk to detect and triage incidents.
  • Managed risk registers using SQL to track service impacts, ensuring GDPR alignment.

Defender for EndpointSplunkSQLGDPR

Mar 2024 — Mar 2026

Security Analyst

Tesco Stores Ltd · Lambeth, UK

  • Evaluated and prioritised vulnerabilities using CVSS and threat-intelligence-led criteria to focus remediation on the highest business risk.
  • Partnered with cross-functional technology and business teams to drive remediation to closure, managing exceptions through the formal risk-acceptance process.
  • Supported the group vulnerability-management tooling and bug-bounty programme, applying CVSS, OWASP, CIS Benchmarks, and MITRE.

CVSSOWASPCIS BenchmarksBug bounty

Oct 2023 — Mar 2024

Researcher

University of Westminster · Westminster, UK

  • Conducted in-depth research into malware evasion techniques.
  • Performed analysis utilising the Any.Run sandbox to dissect process injection and obfuscation.
  • Produced actionable cyber threat intelligence reports.

Any.RunREMnuxCTIMITRE ATT&CK

Jul 2021 — Nov 2022

Security Operations Analyst (SOC L1)

HSBC · Gurgaon, India

  • Analysed security alerts from Microsoft Sentinel and CrowdStrike.
  • Conducted comprehensive analysis of malware samples to identify Indicators of Compromise.
  • Developed custom scripts using Python and PowerShell to automate intelligence collection.

SentinelCrowdStrikePythonPowerShell

Open a channel

Open to security roles, research collaboration, and contract work. Send a message and I will reply within 48 hours — or just email me directly; both land in the same place.

Ready

Open a channel