I was part of the founding team of the Microsoft Threat Intelligence Center.
I started on the provider side, leading a 15-person global MSSP analyst team running 24/7 operations—where I learned what security operations look like when you are accountable to customers around the clock.
I spent nearly 15 years at Microsoft, working across frontline cyber defense, threat intelligence, security operations, and security-product development. I built, trained, and mentored a 10-person SOC team with operational oversight for continuous coverage, contributed early detections to Microsoft Sentinel, led a detection engineering team in Microsoft Defender XDR, and conducted ISO/IEC 27001 audits.
After Microsoft, I delivered security work for Cisco through a consulting engagement before moving into independent practice. Eighteen years across both sides of the relationship—as the provider and as the enterprise—shape the advice I give today. I know what an MSSP can realistically deliver, and what an enterprise actually needs from one.
Today I advise CISOs and security leaders on enterprise security operations, incident command, detection engineering, identity security, exposure management, security-control validation, and operational resilience. My work increasingly covers AI-enabled security operations and the governance of AI applications, autonomous agents, and non-human identities, including ISO/IEC 42001 Artificial Intelligence Management System (AIMS) readiness.
My experience spans eight SIEM and two XDR platforms. I look first at whether telemetry, detection logic, analyst workflow, automation, incident command, and executive decision authority connect—and what happens to that chain under pressure.
I hold CISM, CISA, and the Certified ISO/IEC 42001 Lead Implementer credential.
Most of my work is advisory. I also consider senior in-house security leadership roles where the mandate is real and the organisation is ready to act on it.
My approach is grounded in a simple belief: cybersecurity extends beyond firewalls and systems—it begins with people, and often it begins at home.
Technology matters, but even the best tools can fall short when people are unprepared, responsibilities are unclear, or risk is poorly understood. That belief shapes how I advise leaders, support security teams, and communicate technical risk in business terms.
It also shapes my work as an author, researcher, and speaker. I co-authored Smart Parent’s Guide to Cybersecurity because digital safety should not be limited to security professionals. I am developing a second book and continuing to explore cybersecurity through independent research, articles, projects, and conversations with executive, professional, academic, and public audiences.
Selected research and practical resources: Cyber P&L for cyber risk quantification and security investment decisions, AI agent identity and authority, AI agent security and attack-path governance, the Cyber Incident Commander Toolkit, decision authority under machine-speed attack, pre-authorized cyber containment, and the Microsoft Sentinel Defender portal transition guide.
Whether I am advising an organization, writing for families, researching an emerging issue, or speaking to an audience, my goal is the same: to help people understand risk, make confident decisions, and become better prepared for what comes next.
For much of my career, I was making an impact from behind a computer screen. The work mattered, but I began to feel that something human was missing. I wanted to use the skills, time, and resources available to me to help people more directly. So I started a local community with exactly one member: me.
What began with one person has grown into a network of more than 42,000 members—and it is still growing. It has become a place where neighbors exchange information, find support, and step forward for one another when it matters most.
Members have helped families rebuild after hardship, supported mothers in need, reunited lost pets with their owners, provided food and clothing to people experiencing homelessness, brought attention to important local issues, and created space for honest conversations about mental health.
Leading this community has taught me that meaningful change does not always begin with a large organization or an ambitious plan. Sometimes it begins with one person deciding to contribute what they can. Sustaining that change requires listening, trust, responsible moderation, and consistent care.
I also mentor young people, coach high school students on career development, and speak about cybersecurity and digital safety. For me, leadership is ultimately about using what I know and what I have to help others move forward.
By Anand Shinde and Jessen Kurien · DevOM Publishing
Co-authored by Jessen Kurien and Anand Shinde, Smart Parent’s Guide to Cybersecurity translates complex digital risks into clear, practical guidance for parents, educators, and families.
It addresses cyberbullying, phishing, scams, privacy, online grooming, device security, screen habits, and responsible digital behavior—helping adults protect children while building trust, awareness, and sound judgment.
Published by DevOM Publishing, the book reflects Jessen’s belief that cybersecurity is ultimately about people. A second book is currently in development, alongside his continuing research, writing, and speaking.
To help create a world where organizations, professionals, and families understand digital risk and feel prepared to act with confidence.
To translate complex cybersecurity challenges into practical guidance through advisory work, research, writing, speaking, and education.