// cat lloyd-sato.cv

Lloyd Sato

Cyber Security Professional — London, UK · mail@lloydsato.com · www.lloydsato.com

mail@lloydsato.com

Profile

Cyber security professional specialising in translating technical threats into business advice. Currently a Security Operations Analyst (SOC L1) handling the full incident lifecycle; previously drove risk-led vulnerability management across an enterprise estate. Focus at the intersection of detection engineering and adversary research — reading what malware actually does, mapping it to MITRE ATT&CK, and feeding the findings back into controls.

Experience

Security Operations Analyst (SOC L1)

Dec 2025 — Present
Acumen Technix LTD · London, UK
  • Deployed Microsoft Defender for Endpoint to monitor assets and block complex malware.
  • Administered and optimised Splunk to detect and triage incidents.
  • Managed risk registers using SQL to track service impacts, ensuring GDPR alignment.

Security Analyst

Mar 2024 — Mar 2026
Tesco Stores Ltd · Lambeth, UK
  • Evaluated and prioritised vulnerabilities using CVSS and threat-intelligence-led criteria to focus remediation on the highest business risk.
  • Partnered with cross-functional technology and business teams to drive remediation to closure, managing exceptions through the formal risk-acceptance process.
  • Supported the group vulnerability-management tooling and bug-bounty programme, applying CVSS, OWASP, CIS Benchmarks, and MITRE.

Researcher

Oct 2023 — Mar 2024
University of Westminster · Westminster, UK
  • Conducted in-depth research into malware evasion techniques (AMSI & EDR).
  • Performed analysis utilising the Any.Run sandbox to dissect process injection and obfuscation.
  • Produced actionable cyber threat intelligence reports.

Security Operations Analyst (SOC L1)

Jul 2021 — Nov 2022
HSBC · Gurgaon, India
  • Analysed security alerts from Microsoft Sentinel and CrowdStrike.
  • Conducted comprehensive analysis of malware samples to identify Indicators of Compromise.
  • Developed custom scripts using Python and PowerShell to automate intelligence collection.

Education & Certifications

MSc Cyber Security & Forensics — University of Westminster
CompTIA Security+ — certified
IBM Cybersecurity Analyst — Professional Certificate
CREST Incident Response — in progress

Technical Skills

SIEM & EDR: Splunk, Defender for Endpoint, Sentinel, CrowdStrike
Malware analysis: Any.Run, REMnux, static & dynamic analysis
Vulnerability & risk: Nessus, CVSS, risk registers, incident response
Threat intelligence: IoC identification, CTI reporting, AMSI/EDR evasion research
Frameworks: MITRE ATT&CK, OWASP, CIS Benchmarks, GDPR
Scripting: PowerShell, Python, SQL, C++

Selected Work

Decoding Malicious Camouflage — malware evasion research · www.lloydsato.com/casefiles/malware-evasion/
ATT&CK detection coverage — methodology · www.lloydsato.com/casefiles/attack-coverage/
Risk-led vulnerability triage — programme case file · www.lloydsato.com/casefiles/vuln-management/
Research feed — research.lloydsato.com