← Capabilities

Cybersecurity

Detection engineering against opponents who adapt to you.

Overview

Detection work is confidential by nature — no client names, no specifics of any detection, here or anywhere else. Anti-cheat and abuse detection, SIEM/SOAR platform work, threat hunting, detection automation and security architecture — grounded in defending consumer-scale systems against adversaries who iterate against your detections within days.

In practice

  • Anti-cheat and abuse detection
  • Petabyte-scale log analysis and near-real-time detections
  • SIEM/SOAR management
  • Threat hunting
  • Detection automation
  • Security architecture
  • Data engineering

Behind it: the founder’s background

Oz’s own career rather than the company’s work — running since 1997 and still going. It is here because it is why we can do the above.

  • Credited on 23 shipped titles across Battlefield, Star Wars Battlefront, Titanfall, Need for Speed, F1, Crysis and more — most recently as Application Security Analyst on Battlefield 6 and Battlefield: REDSEC, and Security Engineer on F1 22. Publicly checkable on MobyGames rather than asserted here.
  • Anti-cheat detection at consumer scale, against adversaries who adapt to your detections within days — the hardest version of detection engineering, because the other side is actively iterating against you.
  • SIEM and SOAR platform management and automation across Splunk, Splunk SOAR and the ELK stack — building and running the platform, not just querying someone else’s.
  • Threat hunting and detection engineering: writing the detections and the automation around them.
  • Security architecture across Linux and Windows estates — network and firewall telemetry, and certificate management.
  • Centralised dev-kit streaming, replacing kit sitting under desks with hardware served from one controlled location — tightening physical and access security while raising availability and uptime, and putting more kits in front of more developers. It won the internal innovation award at a Fortune 500 games company in 2018.
  • Two decades inside a Fortune 500 games company across seven roles, from game testing and IT into development, then into cybersecurity, anti-cheat and threat hunting.

Where it comes from

Nearly thirty years in the games industry, the last two decades inside a Fortune 500 games company, across seven roles spanning QA through threat hunting. That path built the discipline from inside the systems it protects, rather than arriving at security as a generalist would.

Let’s talk

A security assessment, a detection-engineering review, or a SIEM/SOAR health check — if you need an outside, technically fluent read on where you stand, that’s an audit sprint.

Scope a security assessment