Nathan Millwater

Cyber Security Engineer

Greater Cardiff Areanathan@millwater.iohttps://www.linkedin.com/in/nmillwater/

Profile

Security operations engineer and team lead with 12 years in cyber, currently running detection, vulnerability management, and identity controls at ClearBank, a UK clearing bank. Builds the SOC as infrastructure: SIEM content and log pipelines in Terraform, automated control testing, and a vulnerability programme that uses AI to triage findings and residual risk. Recently led the move to passkeys and IaC-managed conditional access. BTL2. Translates the same issue for engineers, auditors, and directors.

  • Security operations
  • Detection engineering
  • Vulnerability management
  • Identity and access

Experience

  1. August 2022 – Present

    Security Operations Team Lead, ClearBank

    Diverse, automation-first security operations role covering detection, vulnerability management, identity, and audit in a regulated clearing bank.

    • Terraform
    • Azure
    • SIEM
    • Passkeys
    • Conditional Access
    1. Matured internal SOC procedures and runbooks.

    2. Built and maintained SIEM detections and custom log ingestion as Infrastructure as Code, incorporating IoCs from penetration tests, purple team exercises, and incidents.

    3. Led design and implementation of a vulnerability assessment and management programme, using AI agents to analyse findings and assess residual risk.

    4. Led the organisation's shift to passwordless authentication with passkeys, and designed conditional access controls in IaC.

    5. Shaped cyber control and risk registers, automated control testing and reporting, and supported internal and external audit attestation.

    6. Supported business-wide AI governance and risk assessments.

    7. Managed email security controls for the organisation.

  2. September 2021 – August 2022

    Senior Vulnerability Management Analyst, Bridewell

    Managed vulnerability management service for clients in Critical National Infrastructure, including aviation and energy.

    • Tenable
    • Microsoft Defender for Endpoint
    • Python
    • Power BI
    1. Delivered vulnerability identification and assessment as part of a managed VMS for CNI clients in aviation and energy.

    2. Replaced a manual Tenable / Microsoft Defender report pipeline with Python automation and Power BI, giving deeper insight and faster turnaround.

    3. Worked with Cyber Threat Intelligence and SOC so new CVEs were assessed quickly and accurately.

    4. Integrated client critical-asset lists so remediation followed business context.

    5. Built client relationships that turned scan output into focused remediation.

  3. 2019 – 2021

    Cyber Security Officer, Pepper Money

    Bridged IT/development operations and the Information Security function in a financial-services lender.

    • Azure Security Center
    • Tenable
    • Azure Sentinel
    • Azure DevOps
    • Logic Apps
    • Power BI
    • M365
    1. Implemented vulnerability management across IT assets using Azure Security Center with Tenable agent and network scans.

    2. Automated new findings into Azure DevOps and ran weekly vulnerability stand-ups to track remediation.

    3. Implemented and developed Azure Sentinel SIEM tooling.

    4. Implemented anti-phishing protections and ran phishing training campaigns.

    5. Performed cyber risk assessments for business operations and changes.

    6. Reviewed and maintained internal cyber security policy and standards.

    7. Produced security reporting with Logic Apps and Power BI for monthly Director-level Information Security forums.

    8. Used Logic Apps and M365 to automate wider business processes in a digital transformation drive.

  4. 2015 – 2019

    Senior Web Security Analyst, Alert Logic

    Managed-security team maintaining customer web application firewalls.

    • WAF
    • OWASP
    1. Operated and maintained customer WAFs in a managed security service.

    2. Wrote WAF technical documentation and maintained the team wiki.

    3. Troubleshot WAF issues and reported product bugs to the internal development team.

    4. Advised customers using OWASP Top 10 and core web security principles.

  5. 2014 – 2015

    Technical Analyst, CGI

    First-line technical support for a health-sector client.

    1. First-line technical support and issue remediation for a health-sector client.

Skills

Qualifications

  1. April 2026 – Present

  2. February 2025 – Present

  3. 2010 – 2014

    MComp in Computer Security

    University of South Wales