# Nathan Millwater

Cyber Security Engineer

nathan@millwater.io · https://www.linkedin.com/in/nmillwater/

## Profile

Security operations engineer and team lead with 12 years in cyber, currently running detection, vulnerability management, and identity controls at ClearBank, a UK clearing bank. Builds the SOC as infrastructure: SIEM content and log pipelines in Terraform, automated control testing, and a vulnerability programme that uses AI to triage findings and residual risk. Recently led the move to passkeys and IaC-managed conditional access. BTL2. Translates the same issue for engineers, auditors, and directors.

## Skills

**Engineering & Automation**
- Infrastructure as Code (Terraform)
- SIEM and detection engineering
- Python and cloud automation (Azure)
- AI-driven analysis and automation

**Security Operations & Risk**
- Vulnerability assessment and management
- Detection, response, and incident management
- Risk, governance, and audit attestation
- Security policy and standards

**Communication & Stakeholder Management**
- Technical through Director-level communication
- Client and cross-team relationship building
- Security team leadership

## Credentials

- **Blue Team Level 2 (BTL2)** — Centri — April 2026
- **Blue Team Level 1 (BTL1)** — Centri — February 2025

## Experience

### Security Operations Team Lead, ClearBank — August 2022 – Present

Diverse, automation-first security operations role covering detection, vulnerability management, identity, and audit in a regulated clearing bank.

- Matured internal SOC procedures and runbooks.
- Built and maintained SIEM detections and custom log ingestion as Infrastructure as Code, incorporating IoCs from penetration tests, purple team exercises, and incidents.
- Led design and implementation of a vulnerability assessment and management programme, using AI agents to analyse findings and assess residual risk.
- Led the organisation's shift to passwordless authentication with passkeys, and designed conditional access controls in IaC.
- Shaped cyber control and risk registers, automated control testing and reporting, and supported internal and external audit attestation.
- Supported business-wide AI governance and risk assessments.
- Managed email security controls for the organisation.

### Senior Vulnerability Management Analyst, Bridewell — September 2021 – August 2022

Managed vulnerability management service for clients in Critical National Infrastructure, including aviation and energy.

- Delivered vulnerability identification and assessment as part of a managed VMS for CNI clients in aviation and energy.
- Replaced a manual Tenable / Microsoft Defender report pipeline with Python automation and Power BI, giving deeper insight and faster turnaround.
- Worked with Cyber Threat Intelligence and SOC so new CVEs were assessed quickly and accurately.
- Integrated client critical-asset lists so remediation followed business context.
- Built client relationships that turned scan output into focused remediation.

### Cyber Security Officer, Pepper Money — 2019 – 2021

Bridged IT/development operations and the Information Security function in a financial-services lender.

- Implemented vulnerability management across IT assets using Azure Security Center with Tenable agent and network scans.
- Automated new findings into Azure DevOps and ran weekly vulnerability stand-ups to track remediation.
- Implemented and developed Azure Sentinel SIEM tooling.
- Implemented anti-phishing protections and ran phishing training campaigns.
- Performed cyber risk assessments for business operations and changes.
- Reviewed and maintained internal cyber security policy and standards.
- Produced security reporting with Logic Apps and Power BI for monthly Director-level Information Security forums.
- Used Logic Apps and M365 to automate wider business processes in a digital transformation drive.

### Senior Web Security Analyst, Alert Logic — 2015 – 2019

Managed-security team maintaining customer web application firewalls.

- Operated and maintained customer WAFs in a managed security service.
- Wrote WAF technical documentation and maintained the team wiki.
- Troubleshot WAF issues and reported product bugs to the internal development team.
- Advised customers using OWASP Top 10 and core web security principles.

### Technical Analyst, CGI — 2014 – 2015

First-line technical support for a health-sector client.

- First-line technical support and issue remediation for a health-sector client.

## Education

**University of South Wales** — MComp in Computer Security — 2010 – 2014
