SECURITY LEADER · AI-NATIVE SECURITY OPERATIONS · UK

Enrique Cano

I build security teams from scratch and re-platform them for the AI era. The agents, MCP servers and LLM detection pipelines my team runs on in production are code I wrote. Nearly 30 years in engineering and security.

I'm a hands-on security leader who builds with AI. I re-platformed a 24×7 security operation around LLM agents, an MCP server and AI-based detection, so analysts and AI tools such as Claude Code work through the same controls, permissions and audit trail. I write that code myself.

Underneath sits the rest of the discipline: building security teams from scratch, security operations and platform defence under sustained attack, security engineering and architecture, and risk and board assurance. I have done it in a fast-growing marketplace and payments company and in heavily regulated software for electricity and telecom utilities.

Currently VP of Security, IT and Compliance at Fresha. Previously Cyber Security Architect at General Electric.

What I can do for a company

01

AI-native security operations

I can re-platform a security function so people and AI agents operate it together, through one set of controls, permissions and audit trail.

people & agents

  • SOC analysts
  • Customer-facing teams
  • Slack LLM agent
  • Claude Code

one control plane

Security Hub

web UI · MCP server

  • authorisation
  • permissions
  • audit trail
  • playbooks
  • guardrails

systems

  • Cloud SIEM
  • WAF & CDN
  • Threat intelligence
  • Production data
  • Tickets & runbooks

control-plane

A security operations platform with a web UI and an MCP server, so analysts and AI tools such as Claude Code run the SOC through the same tools.

agents

Production LLM agents with a tool and playbook architecture, an authorisation layer, guardrails and observability. Governed actions for non-engineers.

detection

LLM and vision-model pipelines for phishing and malicious content, benchmarked across providers and deployed into live approval paths.

workflows

AI-assisted triage, investigation, threat modelling and code review in the team's daily work, with the human accountable for the decision.

governance

The AI usage policy, AI spend governance and the security review of AI features for an engineering organisation.

writing

Articles on multi-agent incident response, LLM-driven WAF analysis, threat modelling with GenAI and hybrid human-and-agent SOC teams.

02

Build and lead security teams

I can start a security function from a standing start and grow it into a multi-team organisation that builds with AI by default.

from-zero

From the first hire to security engineering, security operations, GRC and IT teams spread across several countries.

strategy

Strategy, roadmap, budget, headcount and vendors. Hiring end to end, engineers developed into lead roles, leaders recruited to carry the function forward.

champions

Security as a team sport: a champion in every engineering team, threat modelling embedded in the SDLC, training compliance that runs itself.

it-as-a-product

Corporate IT run as a product: joiner/mover/leaver, devices, access and SaaS governance driven by automation and agents.

03

Security operations and platform defence

I can stand up detection, response and anti-abuse for a platform that is attacked every day, and run it 24×7 with AI in the loop.

soc

A SOC from zero: cloud SIEM, alerting, runbooks, on-call and 24×7 cover, an incident response plan, tabletop exercises and blameless post-mortems.

under-attack

Response to volumetric DDoS, distributed scraping, credential stuffing, account enumeration, BIN testing, SMS pumping, payout fraud and brand-impersonation phishing.

waf-as-code

A WAF estate as code across every CDN distribution: automated IP blocking from traffic analysis and OSINT, rate limiting, a maintenance page for use under attack, adaptive 2FA.

vuln-mgmt

Policy, scoring model and SLAs, LLM-assisted triage into per-team tickets, the external penetration testing programme and bug bounty intake.

04

Security engineering and architecture

I can design and build the security platforms other engineers build on, and I still ship code myself, with AI agents as part of the toolchain.

authority

The security authority for hundreds of engineers across a large product portfolio, including mission-critical grid software under heavy regulation.

platforms

Shared security platforms: OAuth2, role-based authorisation, API gateways and automated certificate management with PKI over EST and OCSP.

sdlc

A Secure Development Life Cycle, Privacy by Design, and authentication weaknesses fixed hands-on in Elixir, Ruby and Python.

supply-chain

CI pipeline hardening, a dependency firewall, secrets detection and rotation, rootless containers across a Kubernetes estate, and the response to a repository-borne worm.

05

Risk and board assurance

I can give a board, investors and customers a clear, evidenced view of security and AI risk, and carry the governance that comes with it.

board

Risk posture, incident performance and roadmap presented to boards and C-suites. The security workstream of investor due diligence fronted, evidence pack included.

risk-framework

An enterprise risk framework with a standing executive review forum, and a third-party risk programme that covers AI vendors and model providers.

certification

ISO 27001, HIPAA or PCI DSS from a standing start, with evidence collection automated rather than run from spreadsheets.

privacy

Privacy operations through international growth: subject access, law-enforcement and regulator requests, transfer agreements and retention.

Code I wrote, running in production. Most of it is AI.

security-hub

Security Hub

A web UI and MCP server aggregating threat intelligence, operational metrics and controls in one place, so analysts and AI tools such as Claude Code operate the SOC through the same controls, permissions and audit trail.

agent

Agentic security assistant

A Slack-native LLM agent with a tool and playbook architecture, authorisation layer, guardrails and observability. Governed access to investigation and response actions that previously needed an engineer.

detection

AI-based detection

LLM and vision-model pipelines for phishing-campaign and malicious-content detection, benchmarked across providers and deployed into the live campaign approval path.

security-platform

Shared security platform

OAuth2, role-based authorisation, an API gateway and automated certificate management with PKI over EST and OCSP, built for the next generation of a 60-product grid software portfolio.

waf-as-code

WAF estate as code

AWS WAF and Shield Advanced across every CloudFront distribution, with automated IP/CIDR blocking driven by traffic analysis and OSINT feeds.

it-hub

IT Hub

The Security Hub's counterpart for corporate IT: joiner/mover/leaver provisioning, device management, access provisioning and SaaS governance.

Fresha

2021 — now · London

Global beauty and wellness marketplace and payments platform. 140,000+ partner businesses in 120+ countries, 35m+ appointments a month, ~$1.4bn monthly marketplace value. Engineering across the UK, Poland and Kosovo.

Vice President of Security, IT and Compliance

2024 —

Accountable for cyber security, privacy, compliance and corporate IT across the group. Board and investor reporting, ISO 27001, HIPAA and PCI DSS, enterprise and third-party risk, AI governance, and the re-platforming of security operations around the Security Hub and the agentic assistant.

Head of Security

2022 — 2024

Built the operational security capability for a platform under continuous attack: the SOC, the WAF estate, anti-abuse and fraud defences, vulnerability management and the security champions network.

Principal Security Engineer

2021 — 2022

First dedicated security hire. Threat modelling across every team, the GDPR data inventory and obfuscation pipeline, the penetration test backlog and hands-on authentication fixes.

General Electric

2008 — 2021 · Cambridge

Grid Software Solutions: 60+ commercial products for electricity, telecom and utility companies, including mission-critical Energy and Distribution Management Systems under heavy regulation.

Cyber Security Architect

2018 — 2021

Cyber security authority for the portfolio. Architecture and hands-on development of the shared security platform, ownership of the Secure Development Life Cycle, and Privacy by Design for GDPR.

Technical Lead / Senior Staff / Staff Software Engineer

2012 — 2018

Technical lead and architect for microservices and web apps on Predix, GE's Industrial IoT platform. Site security lead for the Cambridge office across ~30 products. Gold Award for technical leadership; co-inventor on a filed patent.

Earlier

British Telecommunications · Database Administrator2004 — 2008
Centro Rural de Comercio y Actividades · Software Developer2002 — 2003
Implemental Systems · Project Manager, Services Consultant1999 — 2002
Sainco · Software Developer1997 — 1999

All writing ↗