// cat lloyd-sato.cv
Lloyd Sato
Cyber Security Professional — London, UK · mail@lloydsato.com · www.lloydsato.com
Profile
Cyber security professional specialising in translating technical threats into business advice. Currently a Security Operations Analyst (SOC L1) handling the full incident lifecycle; previously drove risk-led vulnerability management across an enterprise estate. Focus at the intersection of detection engineering and adversary research — reading what malware actually does, mapping it to MITRE ATT&CK, and feeding the findings back into controls.
Experience
Security Operations Analyst (SOC L1)
Dec 2025 — PresentAcumen Technix LTD · London, UK
- Deployed Microsoft Defender for Endpoint to monitor assets and block complex malware.
- Administered and optimised Splunk to detect and triage incidents.
- Managed risk registers using SQL to track service impacts, ensuring GDPR alignment.
Security Analyst
Mar 2024 — Mar 2026Tesco Stores Ltd · Lambeth, UK
- Evaluated and prioritised vulnerabilities using CVSS and threat-intelligence-led criteria to focus remediation on the highest business risk.
- Partnered with cross-functional technology and business teams to drive remediation to closure, managing exceptions through the formal risk-acceptance process.
- Supported the group vulnerability-management tooling and bug-bounty programme, applying CVSS, OWASP, CIS Benchmarks, and MITRE.
Researcher
Oct 2023 — Mar 2024University of Westminster · Westminster, UK
- Conducted in-depth research into malware evasion techniques (AMSI & EDR).
- Performed analysis utilising the Any.Run sandbox to dissect process injection and obfuscation.
- Produced actionable cyber threat intelligence reports.
Security Operations Analyst (SOC L1)
Jul 2021 — Nov 2022HSBC · Gurgaon, India
- Analysed security alerts from Microsoft Sentinel and CrowdStrike.
- Conducted comprehensive analysis of malware samples to identify Indicators of Compromise.
- Developed custom scripts using Python and PowerShell to automate intelligence collection.
Education & Certifications
MSc Cyber Security & Forensics — University of Westminster
CompTIA Security+ — certified
IBM Cybersecurity Analyst — Professional Certificate
CREST Incident Response — in progress
Technical Skills
SIEM & EDR: Splunk, Defender for Endpoint, Sentinel, CrowdStrike
Malware analysis: Any.Run, REMnux, static & dynamic analysis
Vulnerability & risk: Nessus, CVSS, risk registers, incident response
Threat intelligence: IoC identification, CTI reporting, AMSI/EDR evasion research
Frameworks: MITRE ATT&CK, OWASP, CIS Benchmarks, GDPR
Scripting: PowerShell, Python, SQL, C++
Selected Work
Decoding Malicious Camouflage — malware evasion research · www.lloydsato.com/casefiles/malware-evasion/
ATT&CK detection coverage — methodology · www.lloydsato.com/casefiles/attack-coverage/
Risk-led vulnerability triage — programme case file · www.lloydsato.com/casefiles/vuln-management/
Research feed — research.lloydsato.com