Lloyd Sato

cv00%--:--:-- UTC

Open a channel

Lloyd Sato

Cyber Security Professional · London, UK · mail@lloydsato.com · www.lloydsato.com

mail@lloydsato.com

Profile

Cyber security professional specialising in translating technical threats into business advice. Currently a Security Operations Analyst (SOC L1) handling the full incident lifecycle; previously drove risk-led vulnerability management across an enterprise estate. Focus at the intersection of detection engineering and adversary research: reading what malware actually does, mapping it to MITRE ATT&CK, and feeding the findings back into controls.

Experience

Security Operations Analyst (SOC L1)

Dec 2025 — Present

Acumen Technix LTD · London, UK

  • Deployed Microsoft Defender for Endpoint to monitor assets and block complex malware.
  • Administered and optimised Splunk to detect and triage incidents.
  • Managed risk registers using SQL to track service impacts, ensuring GDPR alignment.

Security Analyst

Mar 2024 — Mar 2026

Tesco Stores Ltd · Lambeth, UK

  • Evaluated and prioritised vulnerabilities using CVSS and threat-intelligence-led criteria to focus remediation on the highest business risk.
  • Partnered with cross-functional technology and business teams to drive remediation to closure, managing exceptions through the formal risk-acceptance process.
  • Supported the group vulnerability-management tooling and bug-bounty programme, applying CVSS, OWASP, CIS Benchmarks, and MITRE.

Researcher

Oct 2023 — Mar 2024

University of Westminster · Westminster, UK

  • Conducted in-depth research into malware evasion techniques (AMSI and EDR).
  • Performed analysis utilising the Any.Run sandbox to dissect process injection and obfuscation.
  • Produced actionable cyber threat intelligence reports.

Security Operations Analyst (SOC L1)

Jul 2021 — Nov 2022

HSBC · Gurgaon, India

  • Analysed security alerts from Microsoft Sentinel and CrowdStrike.
  • Conducted comprehensive analysis of malware samples to identify Indicators of Compromise.
  • Developed custom scripts using Python and PowerShell to automate intelligence collection.

Education and certifications

MSc Cyber Security & Forensics: University of Westminster

CompTIA Security+: certified

IBM Cybersecurity Analyst: Professional Certificate

CREST Incident Response: in progress

Technical skills

SIEM & EDR: Splunk, Defender for Endpoint, Sentinel, CrowdStrike

Malware analysis: Any.Run, REMnux, static and dynamic analysis

Vulnerability & risk: Nessus, CVSS, risk registers, incident response

Threat intelligence: IoC identification, CTI reporting, AMSI/EDR evasion research

Frameworks: MITRE ATT&CK, OWASP, CIS Benchmarks, GDPR

Scripting: PowerShell, Python, SQL, C++

Selected work

Decoding Malicious Camouflage: malware evasion research · www.lloydsato.com/casefiles/malware-evasion/

ATT&CK detection coverage: methodology · www.lloydsato.com/casefiles/attack-coverage/

Risk-led vulnerability triage: programme case file · www.lloydsato.com/casefiles/vuln-management/

Research feed: research.lloydsato.com

Open a channel