Cyber Security 

  • Leo Cunningham

    Providing insight and strategy to InfoSec, AI, Tech, Product Security, IT Risk, Cyber Security, Cloud Security, Engineering and Product development. Covering compliance remits within Banking, SaaS, FinTech, Digital Health, HealthTech, Startups and e-commerce across global remits.

    I am developing security-focused cultures, processes, and methodologies while building award-winning teams throughout my career. Keynote speaker and contributor.

    Specialities;
    • Providing CISO and CIO services.
    • Startup mentor and tech leader
    • Building engineering capability for Cloud Sec, GenAI, App Sec, DevSecOps, RM, GRC, Security Intelligence, Product Security, Vendor DD, Pen Testing, Compliance, Security and Risk functions from the ground up.
    • InfoSec / Cyber/ DP Policies, Frameworks, Road maps etc.
    • RCSA Management and Programme Delivery.
    • B2B/B2C
    • DevSecOps (SAST/DAST)
    • Security Architecture, LLM, Cloud, Mobile, App, Web and Cryptography.
    • Good understanding of Cloud Infrastructure AWS/GCP, Docker, Kubernetes, etc.
    • Implementing functions: Red, Blue, Purple Teams.
    • Audit Delivery and Performance.
    • Knowledge: ISO27001, NIS2, SOC1/2, NIST, EU GDPR, SOX, CCPA, HIPAA etc.
    • Building engaging cultures and collaboration towards cyber.
    • Gaining buy-in from senior stakeholders (ExCo, Directors and Risk Management committee members).

    Tools/systems used in my career: Wiz, Orca, Vanta, SCC, SecurityHub, ElasticSIEM, Sentinal One, Looker, Splunk, DataDog SIEM, Snyk, Auth0, Okta, 1Password, Cloudflare WAF/ZTN, OneTrust, Maltego, Shodan, Metacompliance, HackerOne, Bugcrowd, Kandji, Jamf, Malduino, Qualys, ZenGRC, AWS/Azure/GCP, Jira.

    Through my experiences, I understand the impact of what a business requires and how this affects customers and associated business partners while having a solid understanding of current and emerging technologies. Security should be a business enabler.

    Certified Data Privacy Solutions Engineer. Certified Social Engineering (Redgoat Cyber Security/GCHQ). Winner of ‘Best Information Security’ at the Scottish FinTech Awards 2019. Winner of the Snyk Influencer Award 2021. Runner up, 'Outstanding Leadership' Award via Scottish Cyber Awards x2. Nomination for ‘Best use of Security within a DevOps project’ via DevOps Industry awards. Runner up ‘Individual Contribution to Cyber Security’ via Computing Security Awards (top 15 CISO/Security Influencers). CISO Platform Top 100 (Time 100), Finalist 'CISO of the year' via Cyber OSPAs.

    Opinions and comments expressed are my own and do not express the views or opinions of my employer.

  • Leo Cunningham

    Providing insight and strategy to InfoSec, AI, Tech, Product Security, IT Risk, Cyber Security, Cloud Security, Engineering and Product development. Covering compliance remits within Banking, SaaS, FinTech, Digital Health, HealthTech, Startups and e-commerce across global remits.

    I am developing security-focused cultures, processes, and methodologies while building award-winning teams throughout my career. Keynote speaker and contributor.

    Specialities;
    • Providing CISO and CIO services.
    • Startup mentor and tech leader
    • Building engineering capability for Cloud Sec, GenAI, App Sec, DevSecOps, RM, GRC, Security Intelligence, Product Security, Vendor DD, Pen Testing, Compliance, Security and Risk functions from the ground up.
    • InfoSec / Cyber/ DP Policies, Frameworks, Road maps etc.
    • RCSA Management and Programme Delivery.
    • B2B/B2C
    • DevSecOps (SAST/DAST)
    • Security Architecture, LLM, Cloud, Mobile, App, Web and Cryptography.
    • Good understanding of Cloud Infrastructure AWS/GCP, Docker, Kubernetes, etc.
    • Implementing functions: Red, Blue, Purple Teams.
    • Audit Delivery and Performance.
    • Knowledge: ISO27001, NIS2, SOC1/2, NIST, EU GDPR, SOX, CCPA, HIPAA etc.
    • Building engaging cultures and collaboration towards cyber.
    • Gaining buy-in from senior stakeholders (ExCo, Directors and Risk Management committee members).

    Tools/systems used in my career: Wiz, Orca, Vanta, SCC, SecurityHub, ElasticSIEM, Sentinal One, Looker, Splunk, DataDog SIEM, Snyk, Auth0, Okta, 1Password, Cloudflare WAF/ZTN, OneTrust, Maltego, Shodan, Metacompliance, HackerOne, Bugcrowd, Kandji, Jamf, Malduino, Qualys, ZenGRC, AWS/Azure/GCP, Jira.

    Through my experiences, I understand the impact of what a business requires and how this affects customers and associated business partners while having a solid understanding of current and emerging technologies. Security should be a business enabler.

    Certified Data Privacy Solutions Engineer. Certified Social Engineering (Redgoat Cyber Security/GCHQ). Winner of ‘Best Information Security’ at the Scottish FinTech Awards 2019. Winner of the Snyk Influencer Award 2021. Runner up, 'Outstanding Leadership' Award via Scottish Cyber Awards x2. Nomination for ‘Best use of Security within a DevOps project’ via DevOps Industry awards. Runner up ‘Individual Contribution to Cyber Security’ via Computing Security Awards (top 15 CISO/Security Influencers). CISO Platform Top 100 (Time 100), Finalist 'CISO of the year' via Cyber OSPAs.

    Opinions and comments expressed are my own and do not express the views or opinions of my employer.

  • Leo Cunningham

    Providing insight and strategy to InfoSec, AI, Tech, Product Security, IT Risk, Cyber Security, Cloud Security, Engineering and Product development. Covering compliance remits within Banking, SaaS, FinTech, Digital Health, HealthTech, Startups and e-commerce across global remits.

    I am developing security-focused cultures, processes, and methodologies while building award-winning teams throughout my career. Keynote speaker and contributor.

    Specialities;
    • Providing CISO and CIO services.
    • Startup mentor and tech leader
    • Building engineering capability for Cloud Sec, GenAI, App Sec, DevSecOps, RM, GRC, Security Intelligence, Product Security, Vendor DD, Pen Testing, Compliance, Security and Risk functions from the ground up.
    • InfoSec / Cyber/ DP Policies, Frameworks, Road maps etc.
    • RCSA Management and Programme Delivery.
    • B2B/B2C
    • DevSecOps (SAST/DAST)
    • Security Architecture, LLM, Cloud, Mobile, App, Web and Cryptography.
    • Good understanding of Cloud Infrastructure AWS/GCP, Docker, Kubernetes, etc.
    • Implementing functions: Red, Blue, Purple Teams.
    • Audit Delivery and Performance.
    • Knowledge: ISO27001, NIS2, SOC1/2, NIST, EU GDPR, SOX, CCPA, HIPAA etc.
    • Building engaging cultures and collaboration towards cyber.
    • Gaining buy-in from senior stakeholders (ExCo, Directors and Risk Management committee members).

    Tools/systems used in my career: Wiz, Orca, Vanta, SCC, SecurityHub, ElasticSIEM, Sentinal One, Looker, Splunk, DataDog SIEM, Snyk, Auth0, Okta, 1Password, Cloudflare WAF/ZTN, OneTrust, Maltego, Shodan, Metacompliance, HackerOne, Bugcrowd, Kandji, Jamf, Malduino, Qualys, ZenGRC, AWS/Azure/GCP, Jira.

    Through my experiences, I understand the impact of what a business requires and how this affects customers and associated business partners while having a solid understanding of current and emerging technologies. Security should be a business enabler.

    Certified Data Privacy Solutions Engineer. Certified Social Engineering (Redgoat Cyber Security/GCHQ). Winner of ‘Best Information Security’ at the Scottish FinTech Awards 2019. Winner of the Snyk Influencer Award 2021. Runner up, 'Outstanding Leadership' Award via Scottish Cyber Awards x2. Nomination for ‘Best use of Security within a DevOps project’ via DevOps Industry awards. Runner up ‘Individual Contribution to Cyber Security’ via Computing Security Awards (top 15 CISO/Security Influencers). CISO Platform Top 100 (Time 100), Finalist 'CISO of the year' via Cyber OSPAs.

    Opinions and comments expressed are my own and do not express the views or opinions of my employer.