Curriculum vitae

Elliot Buckland-Weir

Junior Security Analyst with five years of combined IT and security experience. My background includes two years supporting 10 schools and three years at SOCOTEC, progressing from senior service desk work into security in September 2024.

LocationNottingham, UK
EmailElliot@elliotweir.co.uk
Current focusSAL1 and identity security
Professional experience5 years in IT and security

Professional profile

Junior Security Analyst with five years of combined professional experience across IT operations and security. My career began with two years managing on-site technology across 10 schools, followed by three years at SOCOTEC, where I progressed from senior service desk work into security in September 2024.

Experienced in Microsoft Intune, Entra ID, PAM/PIM, SOC/SIEM alert handling, and enterprise security tooling. Recognised for being proactive, reliable, and technically curious, with a strong focus on improving security processes, reducing risk, and supporting secure service delivery.

Strengths

Core areas

Security Operations

  • SOC/SIEM alert review
  • Incident response support
  • Vulnerability remediation

Microsoft Security

  • Intune and endpoint management
  • Entra ID and Conditional Access
  • PIM and PAM support

Governance

  • External sharing controls
  • SOP and policy creation
  • Executive security reporting

Automation

  • Jira workflow automation
  • Remediation scripting
  • Operational process improvement

Impact

Major achievements

Created policies and SOPs governing hardware compliance and external sharing across SharePoint Online, Microsoft Teams, and Entra B2B, improving governance and reducing data leakage risk.

Designed and implemented Jira workflow automations to streamline security support processes and reduce manual workload.

Produced the organisation's IT Security Executive Report, providing leadership with clear metrics, trends, and risk insights.

Played a key role in taking the Microsoft Intune project from initial setup to live service within three months.

Supported the implementation of BeyondTrust PAM and Microsoft PIM, strengthening privileged access control and just-in-time access governance.

Acted as the internal lead for a third-party SOC/SIEM service, reviewing, actioning, and escalating security events.

Became the team's email security platform SME, providing daily administration, troubleshooting, and B2B integration support.

Capability

Key skills

Microsoft Security & Endpoint Management

  • Microsoft Intune, Autopilot, Apple Business Manager
  • MobileIron to Intune migration
  • Configuration profiles, compliance policies, secure device enrolment

Identity & Access Management

  • Entra ID and Conditional Access
  • Privileged Identity Management (PIM)
  • Privileged Access Management (PAM)
  • External collaboration governance

Security Operations

  • SOC/SIEM alert review and escalation
  • Incident response support
  • Vulnerability management
  • Phishing simulation and user awareness

Email Security

  • Email security platform administration and policy design
  • Targeted Threat Protection
  • Secure Messaging and Large File Send
  • B2B integration support

Governance & Compliance

  • SOP and policy creation
  • External sharing controls
  • Hardware compliance processes

Automation & Reporting

  • Jira workflow automation
  • Executive-level security reporting
  • Remediation script deployment

Experience

Professional experience

Sep 2024 - Present

SOCOTEC - Junior Security Analyst

  • Acted as email security platform SME, owning configuration, optimisation, and troubleshooting.
  • Designed and implemented Gateway Policies, Targeted Threat Protection, and misaddressed email protection.
  • Investigated and resolved complex email security incidents with vendor support where required.
  • Implemented CIS benchmark hardening across servers and endpoints.
  • Supported Cyber Essentials and CE+ certification through vulnerability remediation.
  • Managed vulnerability and patching cycles across endpoints.
  • Monitored and investigated alerts using Microsoft Sentinel, Darktrace, and Varonis.
  • Conducted incident analysis and improved response processes.
  • Deployed and maintained WAF rules to protect against OWASP Top 10 threats.
  • Implemented PAM controls and supported rollout of PIM.
  • Designed and delivered phishing simulation campaigns.
  • Developed and enforced security policies and SOPs.
  • Authored the IT Security Executive Report for senior leadership.
  • Designed SMTP relay solutions and improved mail flow security.
  • Refined SPF, sharing controls, and other configurations to reduce attack surface.
2023 - Sep 2024

SOCOTEC - Senior Desktop Technician

  • Managed escalations across infrastructure and application support.
  • Conducted root cause analysis to reduce recurring incidents.
  • Administered user access across on-prem and cloud systems.
  • Delivered security-focused initiatives including phishing campaigns and VPN rollout.
  • Supported endpoint security, MDM, and secure software deployment.
  • Provided technical leadership and acted as an escalation point for complex issues.
2021 - 2023

Nottingham City Council - Managed Technician

  • Delivered on-site 1st and 2nd line support across 10 schools.
  • Managed mobile devices using MDM solutions and enforced secure configurations.
  • Ensured GDPR and organisational security compliance.
  • Collaborated with stakeholders and suppliers to maintain service delivery.
2018 - 2021

Home Bargains - Sales Assistant (Part-time)

Education

Education and qualifications

2017 - 2020

Nottingham College

  • Level 4 System Support & Peripherals - Merit
  • Level 3 System Support - Distinction
  • Level 2 System Support - Distinction
2012 - 2017

George Spencer Academy

  • GCSEs including ICT, Maths, Science

Certifications

Verified credentials and current study

TryHackMeVerified

Cyber Security 101 (SEC1)

Issued 15 August 2026 - expires 15 August 2029

Entry-level cyber security certification covering networking, operating systems, security principles, and core technical assessment.

TryHackMeVerified

Certified Pre Security (SEC0)

Issued June 2026 - expires June 2029

Foundation-level certification covering computer systems, operating systems, networking, web technologies, and cyber security fundamentals.

TryHackMeIn progress

Security Analyst Level 1 (SAL1)

Current study focus

Developing SOC fundamentals, alert triage, threat detection, practical investigation, and analyst report writing.

MicrosoftPlanned

Microsoft SC-300

Planned next focus

Planned study path for Microsoft Entra ID, Conditional Access, identity governance, privileged access, and Zero Trust identity controls.

Portfolio evidence

Writing and tools

Microsoft Defender for Office 365 write-up

Technical write-up covering investigation, licensing context, Safe Links, Safe Attachments, and practical rollout considerations.

SharePoint B2B external sharing research

Research and documentation around external sharing controls, Entra B2B governance, and reducing collaboration risk.

Browser-based security tools

Built practical tools including IP intelligence, domain lookup, and guest-risk calculation utilities.

Additional information

Active home lab focused on Active Directory, security tooling, network configuration, and improving my day-to-day security skills. I am also currently working towards TryHackMe Security Analyst Level 1 (SAL1) and planning Microsoft SC-300 as my next identity-focused certification. References are available on request.