Summary
Overview
Work history
Education
Skills
Certification
Projects/Experience
Tooling Proficiency
Affiliations
Languages
References
Timeline
Generic

Thom Robinson

Corsham,United Kingdom

Summary

Cyber Defence Analyst with extensive experience in security operations, incident response, and threat detection within military environments. Demonstrated proficiency in 24/7 SOC operations, utilizing SIEM platforms and forensic analysis to enhance security measures. Skilled in collaborating with cross-functional teams and briefing senior leadership to improve overall security posture. Committed to leveraging cybersecurity expertise to drive organizational success.

Overview

7
7
years of professional experience
1
1
year of post-secondary education
1
1
Certification

Work history

Cyber Defence Analyst (Defensive Monitoring and Incident Response)

Defence Digital Security Operations Centre
Corsham, United Kingdom
2024.12 - 2026.04
  • Operated within 24/7 Security Operations Centre (SOC), adhering to shift-based schedules to ensure continuous monitoring and rapid response.
  • Monitored real-time alerts, meticulously triaged potential security incidents, and escalated verified threats to appropriate teams for immediate action.
  • Collaborated effectively with cross-functional teams to contain and remediate security events, minimizing impact and restoring operations.
  • Refined incident response playbooks and meticulously documented lessons learned to continuously improve Standard Operating Procedures (SOPs) and organizational resilience.

Cyber Defence Analyst / Incident Responder

Strategic Command Rapid Reaction Team
Corsham, United Kingdom
2020.08 - 2024.11
  • Led threat detection and analysis initiatives utilizing industry-leading SIEM platforms including Splunk, Elastic Stack, and Security Onion.
  • Conducted comprehensive vulnerability assessments using OpenVAS and deployed targeted endpoint queries via Tanium to identify and address security weaknesses.
  • Managed and maintained virtual environments on both Windows and Linux operating systems to support hands-on threat hunting and forensic investigations.
  • Delivered actionable intelligence briefs to senior leadership, providing critical insights that drove proactive defence measures and strategic decision-making.

Military Intelligence Analyst

British Army
Pirbright & Chicksands, United Kingdom
2019.04 - 2020.07
  • Gathered and fused multi-source intelligence (OSINT, SIGINT, HUMINT, IMINT) to provide comprehensive support for operational planning.
  • Produced structured intelligence reports with meticulous attention to detail, leveraging military ethics and rigorous analytical methodologies.
  • Coordinated effectively with teams of various sizes in high-pressure environments, maintaining discipline, morale, and operational effectiveness.
  • Mentored junior analysts on advanced intelligence collection techniques and secure communications protocols, fostering team growth and capability.

Education

Foundation Degree - Dual Honours History and Politics

University Of Derby
Derby
2017.09 - 2018.07

A-Levels/AS-Levels - History, ICT, Media Studies, Mathematics

West Notts College
Mansfield

Skills

  • Ability To Work Under Pressure
  • Communication Skills
  • Critical Thinking
  • First Aid
  • Highly Motivated
  • Positive Attitude
  • Presentation Skills
  • Team Player

Certification

  • Security Blue Team Level 2 - Currently Studying
  • Certified Detection Analyst (GCDA) - September 2024
  • Elastic Certified Analyst - October 2023
  • Security Blue Team Level 1 - January 2023
  • Continuous Monitoring Certification (GMON) - May 2022
  • Certified Enterprise Defender (GCED) - June 2021
  • Splunk Foundation Courses 1-3 - November 2020 - May 2022
  • Tanium Training - February 2022
  • ElasticSearch Analyst Training - June - September 2022
  • Immersive Labs - Concurrent Training

Projects/Experience

Military Exercises, Participated in multiple international cyber exercises alongside teams from the USA, NATO countries, and Japan, while serving as a Cyber Defence Analyst at MOD Corsham. Assessed system vulnerabilities and actively performed incident response roles within simulated environments. Gained fundamental skills in network hardening, advanced analysis, and proactive threat hunting, concurrently rounding out individual capabilities. Honed expertise in SIEM tools, teamwork, and critical communication during high-stakes scenarios. Military Operations, Contributed to two significant military cyber operations at MOD Corsham, applying diverse cybersecurity skills to advance operational objectives. Part of a team that developed a portable Security Onion toolkit capable of recording PCAP data and facilitating live searching of imported data in various operational areas. Contributed to the analysis of collected network data, meticulously searching for indicators of compromise (IOCs). Led the implementation of a PacketRAID system for enhanced log collection and storage capabilities during a multi-visit deployment to a network location. Played a key role in the subsequent analysis of collected system data to identify potential indicators of compromise.

Tooling Proficiency

Within my job roles mentioned above, I have used a large set of tools to conduct differing job roles These include:

  • ELK - Primary use of this tool has been for the analysis of logs, however when part of the DFIR teams, the ability and understanding of building and configuring these tools was required and used in multiple instances
  • Tanium - Primarily used as a tooling to monitor live devices within the network monitored, with the ability to pull files for further analysis on 3rd party tooling.
  • Microsoft Defender - Tool which has been my primary tool over my experience within the MOD Core SOC. This allows for analysis of logs, network information, file information and other required tools for ticket completion within the SOC.
  • FTK Imager - Used primarily as an image capturing tool for both RAM and ROM devices.
  • Wireshark - Used to conduct analysis of network traffic within PCAP format.
  • Other tooling has been used sporadically throughout my career, giving me further understanding of differing tools standards and layouts.

Affiliations

  • Video and Board Games
  • Walking/Hiking
  • Astronomy

Languages

English
Native

References

References available upon request.

Timeline

Cyber Defence Analyst (Defensive Monitoring and Incident Response)

Defence Digital Security Operations Centre
2024.12 - 2026.04

Cyber Defence Analyst / Incident Responder

Strategic Command Rapid Reaction Team
2020.08 - 2024.11

Military Intelligence Analyst

British Army
2019.04 - 2020.07

Foundation Degree - Dual Honours History and Politics

University Of Derby
2017.09 - 2018.07

A-Levels/AS-Levels - History, ICT, Media Studies, Mathematics

West Notts College
Thom Robinson