Cybersecurity Consultant

David
Griffiths

I help organizations find their weaknesses before attackers do — offensive security, incident response, and security architecture built for how teams actually operate.

01 — Focus

Where I spend my time

Offensive security

Penetration testing and red team engagements across web applications, internal networks, and cloud environments — reported in language engineers can act on, not just a scan output.

Incident response

Triage, containment, and root-cause analysis when something has already gone wrong, plus the after-action work that stops it from happening the same way twice.

Security architecture

Designing identity, network, and cloud controls that hold up under real usage — reviewed with the teams who'll maintain them, not just handed over.

Risk & compliance advisory

Translating frameworks like SOC 2, ISO 27001, and NIST CSF into controls that fit the size and shape of the organization actually implementing them.

02 — Experience

A working history

2023 — Present

Independent Security Consultant

Engaged directly by engineering and security teams for penetration testing, architecture review, and incident response retainers.

2020 — 2023

Senior Security Engineer

Led red team exercises and built out detection coverage across cloud infrastructure, cutting mean time to detect for critical alerts.

2017 — 2020

Security Analyst

Handled day-to-day monitoring, vulnerability management, and incident triage inside a growing security operations function.

Sample timeline — replace with David's real roles and dates.

03 — Certifications

Credentials on file

EQC — Diploma of Information Technology
OSCP — Offensive Security
CISSP — ISC²
CEH — EC-Council
GCIH — GIAC
AWS Security — Specialty

credentials — not actual certifications yet !

04 — Method

How an engagement runs

Map — understand the attack surface before touching it.

Test — exploit what's exploitable, safely and with scope agreed up front.

Report — a prioritized fix list, not a hundred-page scan dump.

05 — Contact

Let's talk about your security posture.

Open to consulting engagements, retainers, and one-off assessments. The fastest way to reach me is by email.