Finn P

I test, break, and rebuild() systems until they're actually trustworthy...

Now

Transitioning from Software Engineering and Test Automation into Security Engineering, building on 9+ years across automation, APIs, CI/CD and financial systems.

Part-time Cyber Sleuth. Full-time believer that security works better when it's engineered in.

Email me, or find me on LinkedIn.

9+ years building reliable systems. Now focused on making them secure.

Legacy of Building, Testing, Breaking, Optimising, & Releasing

Leading teams through fintech, payments, and regulatory-grade delivery.

Currently conjuring code of conduct EDR - Zabta™

Build in Progress

Forensic assurance for enterprise endpoints

Security tools tell you what they can see. Zabta independently verifies it, capturing a structural fingerprint of a machine's live memory state, comparing it against a known-good baseline, and surfacing what changed. Built for the threats that leave nothing on disk: in-memory implants, kernel-level tampering, and compromised security agents.

Go collector, Python analysis workers, GCP. Currently building the kernel symbol corpus that makes automated Linux memory forensics work at scale.

In development · UK
View Zabta

Capstone and Hobby Build

Professional Experience

1
Barclays Plc
QA Automation Consultant (Staff Engineer) · Manchester, UK
Aug '22 - Present

Engineering and automation role across complex banking applications and APIs, with a focus on secure, reliable software delivery within a regulated environment.

  • Built and maintained automation frameworks using Java, JavaScript, Selenium and Cucumber, with REST Assured for API-level testing.
  • Validated API security controls including authentication, role-based access control, session management, input validation and negative testing.
  • Designed and executed OWASP-aligned security-focused tests covering injection, broken access control and improper input handling.
  • Integrated automated test suites into Jenkins and GitLab CI/CD pipelines to support continuous quality and security gates.
  • Collaborated across the SDLC to identify and remediate functional and security-related defects.
  • Performed API and system-level validation focused on reliability, performance and secure data handling.
  • Mentored team members on automation practices within an Agile delivery environment.
Bottom Line →Architected a Java/Selenium/Cucumber BDD framework that cut regression cycle time and killed the manual testing bottleneck. Mentored the team that now runs it.
2
Career Break
Relocation & postgraduate study
Jan '21 - Jul '22

Relocated to the UK; completed an MSc Cybersecurity at Staffordshire University (Distinction), alongside freelance mobile app development.

Bottom Line →Traded pure QA for security depth - network security and penetration testing, with the framework-building instincts carried straight through.
3
Capita Software
Associate Software Consultant (QA & Automation) · India / UK
Apr '18 - Dec '20

Owned SIT strategy across 20+ sub-organisations with fragmented legacy systems, centralising it all into one CRM.

  • Spearheaded continuous improvement initiatives to ensure seamless data integration across 20+ sub-organisations with diverse legacy systems, centralising operations in the primary CRM.
  • Designed and executed SIT testing strategies including test plan creation, script development, and defect management using Star Team and HP ALM.
  • Validated new backend Shell scripts for compatibility with existing schedulers; provided strategic guidance to third-party vendors on batch scheduler maintenance.
  • Ensured financial data integrity by resolving HMRC ledger discrepancies related to change requests.
  • Managed build promotions across 8 environments, ensuring stability and consistency across the deployment pipeline.
Bottom Line →Cut data refresh turnaround from 15 days to 7 through automation, while keeping HMRC ledger data clean across constant change requests.
4
Capgemini India Pvt. Ltd.
Associate Consultant - QA & Test Automation · India
Aug '17 - Apr '18

Built Selenium automation for EMIR-regulated reporting systems, with full requirement mapping and test planning in HP ALM.

  • Designed high-level and low-level test scenarios in JIRA, conducted requirement mapping, RTM preparation, and test planning using HP ALM.
  • Executed scripts for regulatory report generation (intra-day and EOD) and monitored DTCC portal uploads for compliance.
  • Conducted regression testing using Selenium, generating weekly and monthly quality trend reports for senior stakeholders.
Bottom Line →Kept intra-day and EOD regulatory reports compliant and DTCC uploads clean, with weekly quality trends stakeholders actually read.
5
Capita ITPS
Test Engineer · India
May '15 - Aug '17

Functional and integration testing on TCS BaNCS and Realex - real payment rails, real regulatory stakes.

  • Assessed and validated the Realex payment gateway end-to-end, covering backend systems and frontend extranet portals.
  • Developed test scripts for portfolio rebalancing features and created comprehensive test plans, estimations, and daily reports aligned to business requirements.
Bottom Line →Validated the Realex gateway end to end, backend through to the extranet portal, on systems where a missed defect means a failed transaction.

Core Skills

Security Engineering

Application SecurityAPI SecuritySecurity AutomationSecure SDLCOWASPSecurity ControlsRisk-Based Engineering

Software Engineering

JavaJavaScriptNode.jsPythonSQLBashREST APIsMicroservices

Cloud & DevSecOps

GitLab CI/CDJenkinsGitDockerMavenDependency ManagementBuild & Release PipelinesGoogle CloudAWSLinux

Quality Engineering & Automation

Test ArchitectureTest AutomationShift-Left TestingSelenium WebDriverPlaywrightRestAssuredAppiumCucumber (BDD/Gherkin)

Delivery & Leadership

Technical MentoringAgile (Scrum/Kanban)Regulated DeliveryFinTech & PaymentsRisk & Controls

Currently Working With

DFIR & Memory Forensics

Memory ForensicsDigital Evidence & Chain of CustodyLinux Memory AnalysisLinux Kernel InternalsBTF

Mobile Security

OWASP MASVSMobSFFridaCertificate Pinning AnalysisStatic & Dynamic Analysis

Cloud & Forensic Infrastructure

Google CloudCloud RunCloud StorageFirebaseIAMContainerised WorkloadsInfrastructure as Code

Security Research

Threat ModellingForensic Process ValidationISO/IEC 27037ISO/IEC 27041

Platform Engineering

PythonGoPowerShellPostgreSQLSQLiteBigQueryGitLab CI/CD

Education

BSc Computer Science
University of Pune
2009 - 2012
Computer Science foundations
MSc Computer Science
Maharashtra Institute of Technology
2013 - 2015
Core: Networks, RDBMS, C# / .NET, Programming Languages, Theory of Computation
MSc Cybersecurity
Staffordshire University
2021 - 2022
Specialisation: Network Security, Penetration Testing

This & That

A home baker who keeps iterating on the not-too-sweet chocolate cupcake, an amateur guitarist, and a weekend hiker. Also the odd freelance app build on the side. Based in Birmingham, UK, with my wife.

Lightning Round ⚡

🧁 Chocolate cupcakes - less sweet, always
🎸 Amateur guitarist, still improving
🥾 Weekend hiker
🧠 ADHD-brained, which is half the reason I'm good at spotting what breaks
🔐 Nine years of QA, now building toward mobile security
🤝 Volunteered with "Do it for the Hood," '18–'20
🎓 Guest lecturer at my home university, '18–'19
MY GO TO PLAYLIST

High-bandwidth soundscapes for an ADHD brain. Zero distractions, locked-in rhythm, pure flow state for deep-work coding sessions.