Chima Mbaike, CCSP, CISSP

Security Engineer

United Kingdom8 yrs 5 mos experience
Most Likely To Switch

Key Highlights

  • Over 6 years of experience in cybersecurity.
  • Expertise in DevSecOps and cloud security architecture.
  • Proven track record in incident response and threat detection.
Stackforce AI infers this person is a Cybersecurity professional with a strong focus on DevSecOps and cloud security.

Contact

Skills

Core Skills

Incident ResponseThreat DetectionDevsecopsApplication SecurityInfrastructure SecurityCompliance

Other Skills

Application Security ArchitectureSecurity AuditsAzure SentinelGovernance, Risk Management, and Compliance (GRC)Cyber Threat Hunting (CTH)Threat ModelingSecurity Information and Event Management (SIEM)Cloud SecurityWeb Application SecurityNetwork Security ImplementationThreat & Vulnerability ManagementMicrosoft Entra IDIncident Response & Forensic InvestigationDLP insider threat managementCyber Insurance

About

Security Engineer with 6+ years of progressive experience designing and securing modern enterprise environments across threat detection & response, application security, cloud security architecture, DevSecOps, Identity & Access Management, Data Loss Prevention(DLP), Container & Infrastructure Security, threat modelling and vulnerability management. Core Technical Expertise Detection Engineering & Incident Response: Microsoft Sentinel, KQL (advanced), SentinelOne, Defender for Endpoint, MITRE ATT&CK mapping, threat hunting, detection use case development, SOAR (Azure Logic Apps, Python automation) Application Security (AppSec): OWASP Top 10, ASVS, secure SDLC, Threat modelling (microservices, APIs, distributed systems), Secure code review, API security, SAST, SCA, secrets detection integrated into CI/CD pipelines Cloud Security Architecture: Identity-first and cloud-native security design, AWS Well-Architected framework, Azure well-architected framework review, Multi-cloud architecture with security best practices Identity & Access Management: OAuth 2.0, OpenID Connect (OIDC), SAML, Entra ID (Azure AD), identity governance and access controls. Container & Infrastructure Security: Kubernetes, Docker, Terraform, Policy-as-Code (OPA Gatekeeper) Secure infrastructure design and runtime protection Vulnerability Management: Nessus, Qualys, Tenable One, CVE analysis, Risk-based vulnerability prioritisation, Detection engineering for vulnerabilities across hosts and containers Governance, Risk & Compliance: ISO 27001, SOC 2, PCI DSS, GDPR, NIST, Cyber Essentials Plus and Aligning technical controls with regulatory and business requirements Automation & Scripting: Python, PowerShell, Bash, Security automation, tooling, and workflow optimisation.

Experience

8 yrs 5 mos
Total Experience
1 yr 8 mos
Average Tenure
2 yrs 4 mos
Current Experience

Mott macdonald

Cyber Security Specialist

Jan 2024Present · 2 yrs 4 mos · Hybrid

  • Conducting advanced threat hunting using KQL (Kusto query language) and the MITRE ATT&CK framework to identify hidden and emerging threats and
  • improve overall incident response capabilities.
  • Developing and implementing DLP policies aligned with business requirements, while detecting anomalous behavior and potential insider threats.
  • Monitoring, investigating, and resolving DLP incidents using forensic analysis and root cause investigation, driving timely remediation and reducing data
  • exposure risks.
  • Implementing automated reporting to management, providing insights into security trends, incidents, and overall control performance
  • Supported CE Plus audit recertification by ensuring security measures met compliance and regulatory standards through collaboration with internal teams.
  • Led the onboarding of new Tenable One modules (vulnerable management) and delivered tailored training to enhance tool adoption and collaboration
  • across IT and non-IT team
  • Contributing to high-impact security projects, including enhancing security posture, fortifying cloud environments, and improving vulnerability management
  • for over 21,000+ employee organization
  • Led the implementation of a project to assess and validate baseline security controls across the Microsoft 365 environment
  • Attack surface management to proactively detect vulnerable public facing assets and ensure timely remediation.
  • Developed and implemented a comprehensive security operations incident management process, streamlining workflows for efficient detection, analysis,
  • and remediation of security incidents across the organization
  • Conducted IT risk assessments to ensure new applications to be purchased comply with ISMS requirement
Application Security ArchitectureSecurity AuditsApplication SecurityAzure SentinelGovernance, Risk Management, and Compliance (GRC)Cyber Threat Hunting (CTH)+13

Self-employed

DevSecops Engineer

Mar 2023Dec 2023 · 9 mos

  • Strengthened threat detection and risk management capabilities by identifying and remediating security vulnerabilities across development, deployment processes, and production systems.
  • Integrated advanced Static Application Security Testing (SAST) tools such as TruffleHog, detect-secrets/Talisman, Bandit, Gosec, and Semgrep to proactively uncover code-level risks and prevent sensitive data exposure.
  • Enhanced application security posture through Dynamic Application Security Testing (DAST) using tools like Nikto, Nmap, SSLyze, and OWASP ZAP to simulate real-world attacks and detect runtime vulnerabilities.
  • Implemented DevSecOps principles by embedding continuous security testing, automated compliance checks, and infrastructure-as-code into CI/CD pipelines, ensuring secure and compliant software delivery.
  • Conducted ongoing risk assessments of applications and infrastructure, integrating security controls and monitoring solutions to reduce exposure and improve organizational resilience.
  • Collaborated with cross-functional teams to align development and operations with compliance frameworks and threat intelligence insights, improving visibility into emerging threats and mitigation strategies.
  • Deployed and managed Microsoft SQL Server environments with a focus on data integrity, access control, and compliance with security baselines.
  • Automated threat detection and remediation workflows using PowerShell and cloud automation tools (Terraform, Azure ARM, Bicep, Chef, Puppet), enhancing operational efficiency and incident response readiness.
  • Leveraged containerization (Docker) and continuous integration platforms to enforce secure, consistent environments that reduce misconfiguration risks and improve threat visibility across deployments.
Application Security ArchitectureScriptingGit BASHContinuous Integration and Continuous Delivery (CI/CD)OWASP ZAPPowershell+8

Claranet

Cybersecurity Analyst - Security Operation Center (SOC)

Apr 2022Jan 2023 · 9 mos · Bristol, England, United Kingdom

  • Security Operations Centre serving multiple customers from numerous different industries.
  • Monitoring and detecting potential threats, triage alerts and appropriately escalating them
  • Creating processes, procedures and automation to improve efficiency in daily tasks and projects.
  • Working with various EDR and MDR technologies such as Alien Vault, Sentinel One, Azure Sentinel, and ticketing systems (Service Now)
  • Analysing and handling logs from a multitude of sources: AWS, Azure, Windows Event / Defender, 0365, Palo Alto Firewalls
  • Reviewing CVE requests to ensure they conform to the CVE systems rules, assign CVE IDs, and ultimately push CVEs to MITRE
  • Supporting the investigation of security breaches and coordinating and managing all Incident Responses.
  • Performing security analysis using Azure Sentinel and gathering intel to perform threat hunting dashboards and reports to continuously improve security situational
  • Complete periodic security inspections to verify corporate compliance.
  • Identify program issues, security requirements, and optimal solutions for program needs.
  • Coordinating security assessments to spot and proactively correct problems
Security OperationsAzure SentinelSecurity Information and Event Management (SIEM)Endpoint SecurityThreat & Vulnerability ManagementOWASP+4

International data management services plc - nigeria

Infrastructure Engineer

Dec 2019Feb 2022 · 2 yrs 2 mos

  • Implemented Windows and Linux Patch management and related information security functions (authentication, encryption, iptables)
  • Managed events generated from all security monitoring environments, including anti-virus, DLP, SIEM, intrusion detection, vulnerability management, and content filtering systems.
  • Implementation of security initiatives aligned with security standards including but not limited to ISO 27000 series, NIST, PCI DSS, SOX and OWASP
  • Performed root cause analysis (RCA) and incident reviews
  • Provided excellent IT technical engineering security expertise for servers, clients, services and applications, hybrid and public cloud
  • Developed and monitor the adoption of sound cloud security practices
  • Utilized log ingestion platform for security analytics and identification of tactics, techniques, and patterns of attackers
  • Provided IT technical engineering security expertise and support for the network infrastructure, implementation and operation
  • Proactively worked with Architects, Security teams, Risk, Compliance, and other engineering teams to develop enterprise security principles and strategies that support the business development initiative
  • Coordinated and performed vulnerability assessments through the use of automated and manual tools (Tenable, NMAP, etc)
  • Participated in the design of service automation in the cloud towards Infrastructure-as-code and engineering of new cloud/on-prem technologies
  • Provided support and documentation to assist in sustaining projects during the transition to production
VMware vSphereISO 27001WindowsAnsibleInfrastructure as a Service (IaaS)Microsoft Entra ID+3

Prime atlantic cegelec (pace)

Network System Engineer

Mar 2018Sep 2019 · 1 yr 6 mos · Lagos, Nigeria

  • Wireless access point security configuration
  • Oversaw active Incidents, the operation and optimisation of security tooling/products, including network security (IDS/IPS/Firewalls), logging and Network monitoring for intrusion and anomaly detection
  • Designed and implemented security solutions for network infrastructure.
  • Demonstrated thorough understanding of networking concepts and systems including routing, switching, WAN/LAN, WLANs, Cisco & HP network device.
  • Tracked and reported identified information system vulnerabilities and recommended actionable solutions to decrease risk.
  • Device network Policy assignment and network controls
  • Documented network switching and routing equipment and connected IP-addressable devices and cabling to maintain current records.
  • Monitored, reviewed and analyzed network optimization solutions.
  • Performed troubleshooting and diagnosis for LAN/WAN performance and connectivity.

Virtual nigeria

3 roles

Enterprise Support Engineer

Jun 2017Mar 2018 · 9 mos

  • Oversaw and managed company’s information, technological project and documentation creation.
  • Managed Support System Engineers performing on-site customer service and maintenance.
  • Researched on technical needs from the market and created a sample installation/POC (Proof of
  • Concepts)
  • Utilized in-depth technical knowledge and business requirement to design and implement secure
  • solutions to meet customer/client needs while protecting company’s assets
  • Coordinated project phases from development to installation
  • Provided technical support of cross-connected multi-platform networ systems
  • Performed network integration and system tests
  • Oversaw the development of customized software and hardware requirement

Linux System Administrator

Promoted

Apr 2016May 2017 · 1 yr 1 mo

  • Administered UNIX/LINUX machines
  • Updated Unix OS patches and ensured compliance with STIG requirements
  • Trained clients on Red Hat Linux Administration
  • Operated computer help desk assisting users with problems and solutions
  • Provided solutions and technical guidance to clients facing technical issues and difficulties
  • Participated in meetings on planned projects with clients

Graduate Intern

Oct 2015Apr 2016 · 6 mos

  • Worked with the Planning Committee of the Open Source IT conference
  • Received training on Red Hat Linux Administration
  • Hardware and software installation
  • Contributed proactively to new service development
  • Participated in meetings on planned projects with client

Education

University of the West of England

Master's degree — Cyber Security

Jan 2021Jan 2022

University of Lagos

Bachelor of Science - B.Sc. — Systems Engineering

Jan 2010Jan 2015

Yaba College of Technology, Yaba, Lagos

National Diploma - ND — Electrical and Electronics Engineering

Jan 2008Jan 2010

Stackforce found 100+ more professionals with Incident Response & Threat Detection

Explore similar profiles based on matching skills and experience