Nathan Millwater

Security Operations Engineer

Wales, GB LinkedIn Hack The Box

Profile

  1. I am a security operations engineer, with 12 years experience designing and operating technical security controls. I have worked primarily at businesses within the regulated financial services sector, as well as within MSSP organisations.

    I currently build, operate, and automate security solutions at a UK clearing bank. I work across multiple domains from detection engineering, incident response, identity & access management, vulnerability management, and other cyber controls.

    I combine hands-on engineering with line management and stakeholder communication, translating technical risk into practical recommendations all areas of the business can follow.

  2. Outside work, I run a self-hosted homelab, take part in Capture the Flag challenges, and volunteer at a local cat rescue.

Experience

  1. Security Operations Engineer @ ClearBank

    AUG 2022 → Present

    • Delivered business-wide rollout of passwordless authentication; built enforcement with Terraform-managed Conditional Access Policies.

    • Managed SIEM detection engineering; introduced test-driven rule validation and measurably improved detection rule fidelity.

    • Designed the internal vulnerability-assessment and management programme; implemented custom-built AI Agent driven prioritisation automation workflows.

    • Engineered automated control testing and reporting; supported internal/external audit attestations (including ISO 27001).

  2. Senior Vulnerability Management Analyst @ Bridewell

    SEP 2021 → AUG 2022

    • Delivered managed vulnerability management for CNI clients across aviation, finance, and energy, managing large-scale vulnerability assessments across IT & OT environments.

    • Built reporting frameworks integrating different vulnerability assessment tooling into single-pane-of-glass views using Python and PowerBI.

    • Assessed emergent CVEs and produced executive summaries of risk; guided clients through prioritizing remediation actions tailored for their environments.

  3. Cyber Security Officer @ Pepper Money

    APR 2019 → SEP 2021

    • Designed and implemented end-to-end vulnerability-management procedures and automated remediation reporting across user endpoints and cloud estate.

    • Developed and maintained Microsoft Sentinel SIEM detections, improving detection coverage and establishing incident response for the business.

    • Performed cyber risk assessments, maintained security policies and standards, and presented cyber risk reports at monthly director-level information-security forums.

    • Enabled secure digital transformation by championing automation workflows and helping teams build and use solutions securely.

  4. Senior Web Security Analyst @ Alert Logic

    MAR 2015 → APR 2019

    • Operated customer WAF deployments in a managed security service, maintaining protection policies and controlled changes across a wide range of clients.

    • Advised customers on emerging web application vulnerabilities and deployed rulesets to mitigate threats.

    • Contributed bug fixes to a proprietary WAF product and built internal tooling, improving threat detection reliability for the managed service.

  5. Technical Analyst @ CGI

    JUL 2014 → MAR 2015

    • Delivered KPI-driven first-line technical support for a healthcare service, resolving tickets to meet strict SLAs.

Qualifications

  1. MComp in Computer Security (with Merit) awarded by University of South Wales

    SEP 2010 → JUN 2014

Skills

  1. Technologies
    • Azure Logic Apps
    • KQL
    • Microsoft Azure
    • Microsoft Defender
    • Microsoft Entra ID
    • Microsoft Sentinel
    • Power BI
    • Python
    • Tenable
    • Terraform
  2. Security Operations
    • Detection engineering
    • Incident response
    • Infrastructure as code (Terraform)
    • Security automation
  3. Identity and Access Management
    • Conditional Access
    • Passwordless / passkeys
  4. Vulnerability Management
    • AI-assisted vulnerability prioritisation
    • IT / OT vulnerability assessment
    • Risk-based prioritisation
    • Vulnerability management
    • Web application security / WAF
  5. Governance
    • Control testing
    • Cyber risk assessment
    • Cyber risk reporting
    • ISO 27001
  6. Leadership
    • Director-level reporting
    • Line management / mentoring