Overview
Detection work is confidential by nature — no client names, no specifics of any detection, here or anywhere else. Anti-cheat and abuse detection, SIEM/SOAR platform work, threat hunting, detection automation and security architecture — grounded in defending consumer-scale systems against adversaries who iterate against your detections within days.
In practice
- Anti-cheat and abuse detection
- Petabyte-scale log analysis and near-real-time detections
- SIEM/SOAR management
- Threat hunting
- Detection automation
- Security architecture
- Data engineering
Behind it: the founder’s background
Oz’s own career rather than the company’s work — running since 1997 and still going. It is here because it is why we can do the above.
- Credited on 23 shipped titles across Battlefield, Star Wars Battlefront, Titanfall, Need for Speed, F1, Crysis and more — most recently as Application Security Analyst on Battlefield 6 and Battlefield: REDSEC, and Security Engineer on F1 22. Publicly checkable on MobyGames rather than asserted here.
- Anti-cheat detection at consumer scale, against adversaries who adapt to your detections within days — the hardest version of detection engineering, because the other side is actively iterating against you.
- SIEM and SOAR platform management and automation across Splunk, Splunk SOAR and the ELK stack — building and running the platform, not just querying someone else’s.
- Threat hunting and detection engineering: writing the detections and the automation around them.
- Security architecture across Linux and Windows estates — network and firewall telemetry, and certificate management.
- Centralised dev-kit streaming, replacing kit sitting under desks with hardware served from one controlled location — tightening physical and access security while raising availability and uptime, and putting more kits in front of more developers. It won the internal innovation award at a Fortune 500 games company in 2018.
- Two decades inside a Fortune 500 games company across seven roles, from game testing and IT into development, then into cybersecurity, anti-cheat and threat hunting.
Where it comes from
Nearly thirty years in the games industry, the last two decades inside a Fortune 500 games company, across seven roles spanning QA through threat hunting. That path built the discipline from inside the systems it protects, rather than arriving at security as a generalist would.
Let’s talk
A security assessment, a detection-engineering review, or a SIEM/SOAR health check — if you need an outside, technically fluent read on where you stand, that’s an audit sprint.
Scope a security assessment