Summary
Overview
Work history
Education
Skills
Timeline
Generic

OLIVER WEN

ABINGDON,UK

Summary

Experienced Cyber Security Consultant with SC clearance and CSTM and CREST certifications, specialising in offensive security, including web application and API penetration testing and infrastructure assessments. Former Security Analyst focused on identifying and mitigating threats, enhancing security capabilities through the evaluation and deployment of advanced detection and response tools. Ready to leverage diverse skills in a fast-paced environment.

Overview

3
3
years of post-secondary education
9
9
years of professional experience

Work history

Cyber Security Consultant

Air Sec (part of Air IT Group)
Nottingham
2023.06 - 2026.08
  • Executed Cyber Essentials Gap Analysis and reviewed and completed applications for clients to identify security gaps and recommend remediation strategies.
  • Conducted bespoke reviews of AWS, Azure DevOps, and Kubernetes environments to ensure compliance with CIS benchmarks.
  • Performed penetration tests on web applications and internal/external Active Directory infrastructure.
  • Collaborated with internal software development team leaders and project coordinators to strengthen vulnerability management and streamline remediation processes.
  • Authored PowerShell and Bash scripts for integration with Datto RMM and Addigy to gather key information for gap analysis and perform large-scale remediation tasks, such as removing unsupported software and detecting software library dependencies.

IT Security Analyst

UK Atomic Energy Authority
Culham
2020.09 - 2023.06
  • Monitored and responded to organisational threats, assessing security capability needs and evaluating/implementing new detection and response tools.
  • Reviewed and developed policies, procedures, and guidelines to ensure adherence to security best practices.
  • Worked closely with the head of IT and COO to deliver a tabletop exercise such as ransomware attacks, to identify gaps in existing systems and procedures across the whole IT team
  • Provided site-wide advice and guidance, assessing the cybersecurity risks associated with system and application implementations in new site projects.
  • Ran regular phishing simulations using Microsoft Defender Attack Simulator to educate all staff members
  • Tested new software before deployment; ensured they do not introduce any new vulnerabilities into the environment.
  • Assisted in the development of disaster recovery plans, ensured business continuity during a breach event.
  • Worked closely with software developers, integrated security features into applications.
  • Kept abreast of latest cyber threats and trends to update defence strategies accordingly.
  • Automated the creation and closure of departmental tickets using Power Automate, Microsoft SharePoint forms, and APIs for Nessus and Marval.

Security Consultant

NCC Group
Cheltenham
2020.02 - 2020.09
  • Conducted penetration testing on web applications, APIs, and external infrastructure to identify security vulnerabilities and enhance system resilience.

Technical Consultant

IRM
Cheltenham
2019.07 - 2020.01
  • Conducted penetration tests on web applications and external infrastructure to identify vulnerabilities and enhance security posture.
  • Performed build reviews to ensure compliance with security standards and best practices.
  • Reviewed AWS configurations for security and efficiency, optimising resource utilisation and safeguarding data integrity.
  • Conducted thorough assessments of thick client applications.

Consultant

Dionach
Oxford
2018.04 - 2019.06
  • Executed penetration testing on web applications and external infrastructure to identify vulnerabilities and enhance security posture.
  • Performed internal IT Health Checks and Cyber Essentials assessments.
  • Conducted firewall auditing and policy reviews to ensure compliance with best practices and improve network security.
  • Authored blog posts on mitigating Flash usage risks and firewall hardening techniques to educate peers and promote cybersecurity awareness.
  • Developed proposal for Bluetooth hacking research project

Junior Pentester

First Base Technologies
Hassocks
2017.07 - 2017.12
  • Conducted penetration testing on external infrastructures and web applications to identify security vulnerabilities.
  • Quickly learned and applied new skills to daily tasks, improving efficiency and productivity.
  • Successfully delivered on tasks within tight deadlines.

Education

BSc (Hons) - Ethical Hacking and Network Security

Coventry University
Coventry
2013.01 - 2016.01

Skills

  • Web application and API testing with Burp Suite, Postman and SOAP UI
  • Internal penetration testing with BloodHound, Responder and Impacket
  • Vulnerability scanning via Nessus tool and Qualys
  • CIS benchmark assessments
  • Cloud reviews against AWS, Azure/M365 and Kubernetes environments
  • Firewall auditing with Nipper
  • Scripting in Python, PowerShell and Bash
  • Workflow automation using Power Automate and system APIs
  • Data visualisation with Power BI, Elasticsearch and Kibana
  • Threat management tools
  • Network forensics techniques
  • Management of NGINX servers

Timeline

Cyber Security Consultant

Air Sec (part of Air IT Group)
2023.06 - 2026.08

IT Security Analyst

UK Atomic Energy Authority
2020.09 - 2023.06

Security Consultant

NCC Group
2020.02 - 2020.09

Technical Consultant

IRM
2019.07 - 2020.01

Consultant

Dionach
2018.04 - 2019.06

Junior Pentester

First Base Technologies
2017.07 - 2017.12

BSc (Hons) - Ethical Hacking and Network Security

Coventry University
2013.01 - 2016.01
OLIVER WEN