Experience #
Information Security Engineer · Educational Technology company
Apr 2024 – Present · Remote, UK
- Own SIEM operations end-to-end on Rapid7 InsightIDR: custom detection rules, alert triage, incident-response workflows, and security metrics across the organisation.
- Configure and manage AWS security services at scale (GuardDuty threat detection, Security Hub posture management, and Lambda-based automated remediation), with secure-by-default patterns for engineering teams.
- Led response to an active Storm-1811 / Black Basta-style vishing campaign: identified the attack pattern, coordinated cross-team containment, and hardened the environment afterwards.
- Built internal MCP registry infrastructure (Terraform, CloudFront) for controlled adoption of AI-assisted development tools, and led the security evaluation for the GitHub Copilot Enterprise rollout: IAM controls, policy, and governance.
- Drive the SOC 2 compliance programme through Drata and coordinate third-party penetration-testing engagements.
- Embedded security advisor to product teams: design reviews, secure-coding practice, and business risk in plain language.
Security & Compliance Engineer · Encord (YC 2021)
Nov 2022 – Oct 2023 · Remote, UK
- Configured GCP Security Command Center and Cloud Armor WAF rules for OWASP Top 10 protection across the Google Cloud environment.
- Hardened multi-cloud storage integrations across Azure, GCP, and AWS: IAM policies, network configuration, and access controls.
- Owned controls and compliance for the company's first SOC 2 Type II.
- Managed inbound vulnerability disclosures from external researchers and drove remediation.
- Brought security requirements into design reviews and automated security testing into CI/CD.
Security Engineer · Kobalt Music
Feb 2021 – Nov 2022 · London, UK
- Founded the Security Incident Response Team: identified the organisational gap, made the business case, recruited the responders, and delivered an operational SIRT.
- Led the emergency response to Log4Shell (CVE-2021-44228), coordinating cross-team remediation across production services under time pressure.
- Discovered and remediated a WAF bypass through independent security testing.
- Deployed OpsGenie alerting and DataDog security monitoring; drove preventive improvements out of root-cause analysis.
Support Engineer, Enterprise InfoSec GRC · Reciprocity (now ZenGRC)
Jul 2019 – Jan 2021 · Ljubljana, Slovenia
- Technical support for 250+ enterprise customers on a security GRC platform comparable to Drata or Vanta.
- Influenced the product roadmap through structured customer feedback on security-workflow UX.
- Debugged complex issues across REST APIs, SSO/SAML, and role-based access control.
Earlier career · Various
2011 – 2019
Paralegal work, data analysis and business intelligence, and enterprise customer operations. The grounding in regulatory detail, SQL, and stakeholder communication still informs the security work.
Founder · Arbiter Security #
Arbiter · web-application security
arbitersec.com
A Rust vulnerability scanner exposed as an MCP server for AI-agent orchestration. Models web applications as state graphs and uses constraint inference to discover and verify vulnerabilities across 52 classes; every finding is verified in a real browser with a full evidence chain. Scores 100% on Google's Firing Range benchmark (85/85 endpoints); real-world findings have been disclosed to Anthropic and Cloudflare. 267 MCP tools, 468K lines of Rust, 7,800+ tests.
Aletheia · binary analysis
arbitersec.com
A Rust reverse-engineering platform. Disassembles PE, ELF, and Mach-O binaries across four architectures, lifts to a 43-opcode IR, constructs SSA form, and decompiles to typed C. Concolic falsification removes false positives by constructing concrete exploit witnesses through SMT solving; hybrid fuzzing, taint analysis, and scanning across 14 CWE classes. 140 MCP tools, 2,800+ tests.
Open source #
- Narsil-MCP: a 90-tool Rust code-intelligence server with taint analysis, SBOM generation, and 32-language support; published on crates.io, Homebrew, and npm.
- Forgemax: a V8 sandbox for secure LLM-to-MCP tool execution: runtime isolation and permission boundaries for AI agents.
- Tightrope Tracker: a live UK fiscal dashboard built from OBR, ONS, Bank of England, and DMO data, with a public JSON API; featured on ITV's Peston.
- Veilguard and Sanctum: a clean-room Rust rebuild of a whistleblower submission system, and supply-chain verification tooling.
- Krait: a self-evolving AI agent (Elixir/OTP and Rust) with AST-based security validation.
Responsible disclosure #
- SecureDrop: CVE-2026-50000: a journalist API session token replayable against the Journalist Interface web UI. Credited as a reporter; fixed in 2.16.0.
- Anthropic: a vulnerability in their open-source MCP tooling; acknowledged by their security team.
- Cloudflare: a security issue in the Pingora HTTP proxy framework.
Details on the disclosures page.
Skills #
- Languages
- Python, Rust, TypeScript, Go, Elixir, SQL, Shell
- Security
- Cloud security, SIEM operations, detection engineering, incident response, threat modelling, IAM/RBAC, vulnerability management and research, supply-chain security
- Cloud & infra
- AWS (GuardDuty, Security Hub, Lambda, IAM), GCP (Security Command Center, Cloud Armor), Azure, Terraform, Docker, CI/CD
- Tooling
- Rapid7 InsightIDR, Drata, DataDog, OpsGenie, CrowdStrike, Cloudflare
- Formal methods
- Lean 4, proof-carrying certificates, constraint reasoning
- South West Chapter Lead and Chapters Vibe Coding Officer at Looking For Growth UK, a cross-party grassroots movement for UK economic growth.
- Maintainer of published open-source packages on crates.io, npm, and Homebrew.
Education #
BSc (Hons) Marine Studies (Merchant Shipping), 2:1 · University of Plymouth
2007 – 2011
Critical systems analysis, decision-making under uncertainty, positioning systems, and maritime communications. The operational discipline of safety-critical environments still shapes how I approach security engineering.
Away from the screen: surfing off the Cornish coast, hiking on Dartmoor, Filipino martial arts, CrossFit.
Based in Exeter, UK · laurence@arbitersec.com · LinkedIn · GitHub