Curriculum vitae

Naushad Saboor

Cyber security operations, incident response and investigation. Known professionally as “Hunter”.

The five most efficient cyber defenders are: Anticipation, Education, Detection, Reaction and Resilience. Cybersecurity is much more than an IT topic.

Profile

A cyber security leader who builds security operations rather than advising on them — in-house and managed SOC/SIEM, on open-source and commercial stacks, for organisations from startups to multinationals.

Day to day that means strategic planning, team oversight, process development, incident management, reporting, and gap analysis across tooling and technology. Across e-commerce, finance, healthcare, energy, defence and retail, including greenfield MSSP SOC services built from nothing.

Colleagues have called it "the Swiss Army knife" and "the Hunter" — versatility under complex conditions, working alongside CTOs, CISOs and architects to make security fit how the business actually runs.

Selected achievements

  • Built greenfield SOC operations in the UK and Europe, matured into world-class capability
  • Built the first piSOC — a Raspberry Pi security operations centre on free open-source software with Darktrace as the core data model, monitoring 1,000+ devices
  • Developed air-gapped industrial Intrusion Detection and Prevention Systems
  • Built complex interactive data visualisation for SOC/SIEM and incident response programmes
  • Championed zero-trust policy and controls across sensitive environments
  • Ran real-time incident response gamification for C-level executives, HR and administrators
  • Orchestrated security awareness training including phishing simulation and live attack demonstration
  • Automated cyber assessment using bots as a core component of a GDPR data protection certification scheme
  • Implemented SOC 2, ISO 27001, PCI-DSS and NIST frameworks with MDM and endpoint security deployment

Career history

The through-line

Apr 2019 — Present

Chief Technology Officer (CTO) & CISO

AcuityGroup LtdCurrent

Research lab and innovation hub — parent of Quantum Handshake Ltd (No. 17261924)

The through-line. The client engagements below ran alongside this, not instead of it — AcuityGroup is the lab where the R&D happens.

  • Chief Technology Officer (CTO) & CISO (Jun 2026 — Present)
  • CISO / Enterprise SOC Engineer (Mar 2020 — Jun 2026)
  • Interim CISO / Cyber Security Specialist (Apr 2019 — Mar 2020)
  • Digital Transformation Lead (Oct 2019 — Apr 2020)
  • Lead the technical vision, cyber security strategy and platform architecture behind the post-quantum digital trust ecosystem — QuantumHandshake™ and AiiDIS™, both incubated here from R&D begun in 2017
  • Own the complete security picture for the group: strategy and architecture through to daily SOC operations, incident response and threat intelligence
  • Built greenfield security operation centre service and on-boarding
  • 24x7 active monitoring, incident triage and handling
  • Drove SIEM engineering and fine tuning; SIEM detection analysis across the cyber kill chain
  • Designed strategic cyber security visualisation programmes and security architecture
  • Advanced persistent threat and insider threat monitoring, forensics and focused operations
  • Third-party technology assurance and advisory, ISAE 3402 (previously SAS 70)
  • Advanced IoT/IoE threat research with leading academics — detection, inspection and secure systems
  • Automated cyber assessment using bots for a new GDPR data protection certification scheme

Client engagements — run alongside

Nov 2023 — Aug 2024

Head of Cyber Security Engineering

SIG Technologies Limited

  • Designed and implemented security architectures, systems and networks; established 24/7 monitoring and response, recruiting and training the internal team
  • Developed and executed incident response plans for prompt breach handling
  • Ran security audits and vulnerability assessments to identify and mitigate weakness
  • Set up and managed security monitoring tooling for real-time threat detection
  • Developed and enforced security policy, ensuring compliance with industry standards
  • Performed penetration testing, code review and validation of security controls

Sep 2022 — Mar 2023

Cyber Security Specialist & Interim CISO

Cordial World

  • Responsible for global security operations centre resilience
  • Led incident response and built the incident playbooks
  • Ensured OT operations SIEM monitoring and fine tuning
  • Supported SOC engineers on alert sources and triage; escalation point for all technical issues
  • Worked with senior management to drive the crisis committee
  • Organised and conducted ethical hacks of the existing security architecture

Oct 2021 — Sep 2022

SOC Engineer / Cyber Security Specialist

Cyber DiligentiaContract

  • Investigated potential incidents, triaged and prioritised detections
  • Monitored client security infrastructure, identifying and reporting real-time attacks
  • Documented incidents in accordance with government policy and procedure
  • Set up and operated an investigator's lab, and processed computer crime scenes
  • Performed risk assessment and testing on live data processing activity
  • Provided on-the-job training to develop junior SOC team members

Nov 2020 — Oct 2021

Cyber Security Programme Manager

Shayype Ltd | Coltech GroupContract

  • Led enterprise infrastructure penetration testing to proactively identify weakness
  • Led web application source code review and network security architecture work
  • Presented results to technical and non-technical stakeholders and advised on remediation
  • Implemented Endpoint Detection & Response
  • Established cyber resilience and maturity assessment programmes — proactive threat hunting
  • Worked alongside development covering SDLC across applications and infrastructure

Jan 2020 — Jan 2021

vCISO, Technical Assistant to CEO and CTO

EURUSOG Ltd

Startup, short-term open contract

Jul 2013 — Apr 2019

Cyber Security Specialist — Red Team Engineer

Photobox Group Ltd

6 e-commerce brands, 22 factories, 8 technical teams, 1,200+ developers, 30+ SOC team members, 10 security champions, 12 countries

  • IT Security Specialist and Digital Transformation Lead (Jul 2013 — Jun 2015)
  • Penetration testing across 6 e-commerce brands and factories, with remediation management
  • Quarterly PCI-DSS penetration testing at level 1, level 2 and self-assessment
  • Built greenfield SOC operations in the UK and Europe, matured into world-class capability
  • Defined critical incident handling for phishing, DDoS, critical malware and complex triage
  • Regular auditing of Wi-Fi, wireless, LAN and external network leak signals
  • Signed off changes on IDPS, anti-spam, DNS firewall and content filtering
  • Chaired daily operations across security, DevOps, incident management and threat intelligence
  • Conducted regular cyber resilience programmes and red team attack scenarios

2011 — 2014

Cyber Intelligence Officer — Red Team Engineer

Government red team operationsUnder NDA

Period covers Royal Navy service and NATO-related work. Unit, rank and detail withheld.

  • Responsible for critical judgements about threats to national security
  • Red team specialist running reconnaissance assessment, identifying vulnerabilities and recommending corrective action
  • Planned and performed technical analysis and red team assessment on targeted intelligence

2010 — 2011

Red team operations lead

Government contractorUnder NDA

Period covers Royal Navy service and NATO-related work. Unit, rank and detail withheld.

  • Managed and assessed 17 team members plus 5 international operators
  • Scoped operations with stakeholders, defined objectives and developed a delivery approach that minimised operational risk
  • Accountable for plan execution, tracking, reporting and stakeholder management

2006 — 2014

Founder / Head of Information Security

AlWahy.com

Archived at the Wayback Machine

Certifications

  • CHFI — Computer Hacking Forensic InvestigatorEC-Council
  • CEH — Certified Ethical HackerEC-Council
  • CFA — Certified Forensic Analyst
  • CISP — Certified Information Security Professional
  • ITIL — Information Technology Infrastructure LibraryAXELOS
  • MTA — Windows Operating System FundamentalsMicrosoft · 2016
  • MTA — Windows Server Administration FundamentalsMicrosoft · 2016
  • MTA — Networking FundamentalsMicrosoft · 2016
  • MTA — Security FundamentalsMicrosoft · 2016
  • MTA — Database FundamentalsMicrosoft · 2016
  • MTA — Software Development FundamentalsMicrosoft · 2016
  • PRINCE2 — Projects in Controlled EnvironmentsAXELOS
  • CCNA — Cisco Certified Network AssociateexpiredCisco · Expired 25 Jun 2024
  • CS101 Computer ScienceStanford University

In progress

  • CISM and CISA — in progress, targeted for completion by the end of 2026
  • CISSP and OSCP — in progress
  • PhD research — military technology and advanced cyber security
  • MSc Cyber Security & Digital Forensics — Northumbria University and King's College (on hold)

Platforms and tooling

Deployed, evaluated or operated in production.

SIEM

ELK · Kibana · Splunk · LogRhythm · IBM QRadar · AlienVault (AT&T) · AlertLogic · LogPoint · FireEye · SolarWinds · ManageEngine · Fortinet · Exabeam · McAfee · RSA (Dell) · Rapid7 InsightIDR-UBA

Open source

Suricata · Corelight · OSSEC · OSSIM · Security Onion · Zeek · ELK · pfSense · NetFlow · OTX

Endpoint detection & response

enSilo · SentinelOne · Symantec Endpoint Protection · FireEye Endpoint Security · Bitdefender · Check Point CloudGuard · LANDesk · SolarWinds · Cybereason

Network monitoring

Darktrace · OpManager · SolarWinds · Site24x7 · Nagios Core · Prometheus · Nessus · Akamai · Arbor

Application security

Fortify SCA · WebInspect · Metasploit Pro · Armitage · Cobalt Strike · Nessus · Nexpose · IBM AppScan · SAINT Security · Core Impact · Vega · w3af · Carbon Black · Bit9 · Elasticsearch · Bro · Moloch · John the Ripper · Hydra · Medusa · NetSparker · Acunetix · Wireshark · DLP · SAST · DAST · SDLC

Security testing

MicroFocus Fortify SCA · WebInspect · App Defender · Black Duck · Snyk · SonaType · Qualys · TripWire IP360 · Wapiti

Email security

GlassWall · Microsoft Defender ATP · Mimecast · Microsoft 365 Security · Antigena · Symantec Email Security · Barracuda · Cisco Cloud Email Security

Identity & access

Shayype · Okta · Salesforce · LastPass · DUO

Cyber intelligence

Dark web · OTX · OSINT · MITRE ATT&CK · Cyber Range

Resilience programmes

OWASP · CWE Top 25 · Penetration testing · Bug bounty · Honeypots · Responsible disclosure

Service management

JIRA · Confluence · Slack · Spiceworks · Zendesk Suite · OryxAlign

Get in touch Services