About

Charlie Dean

Founder & Principal Consultant

Founder
Security Consultant

Founder of SecureSync Labs. Principal consultant covering security engineering, offensive testing, and attack surface management.

Role at SecureSync Labs

Charlie founded SecureSync Labs in 2023 to do hands-on cyber security consulting: the work he had already been doing for more than a decade, without the overhead of a large firm.

He leads client engagements across testing, cloud, incident response, and attack surface management. Where organisations need software as well as advice, he also designs and builds it for them, including custom integrations with the tools they already run.

About

Charlie is a cyber security practitioner with more than a decade of experience across consulting and in-house security leadership. His work sits at the overlap of offensive testing, secure engineering, cloud security, and making those disciplines repeatable.

He is used to explaining risk in plain language and embedding with delivery teams rather than throwing findings over the wall.

Core skills

  • Stakeholder engagement
  • Team leadership and mentoring
  • Applied research
  • Problem solving
  • Adaptability
  • Effective time management

Technical skills

  • Penetration testing across web applications, web services, infrastructure, and red team exercises
  • Security threat intelligence
  • Network architecture and configuration
  • SecDevOps and secure software delivery
  • Windows and Linux systems
  • Secure development, source code review, and automation
  • Azure and AWS cloud platforms, including how to secure them
  • Incident response and investigation
  • Custom integrations with existing security tooling

Experience

Security leadership in financial services

Charlie spent several years leading security work inside a UK financial services organisation, covering cloud, product security, and operational response.

That included rolling out security tooling and standards across Azure and AWS; standing up a secure software development lifecycle so applications were built with security controls in the pipeline; and deploying and operating a range of enterprise security platforms.

He ran annual penetration tests and assessments when new functionality was introduced, planned red team exercises to test whether controls actually worked, and worked with the blue team to investigate and triage incidents. He also acted as an embedded security specialist across business projects, automated manual processes to reduce error, and improved how security data was analysed and reported.

He was promoted into a management role, completed managerial training, and led a team of five. That included interviewing and hiring for critical roles, and upskilling industrial placements and apprentices.

Independent security consulting

Before that, Charlie spent several years as a security consultant delivering detailed assessments across financial services, legal, energy, education, and government.

Typical work included penetration testing of web applications and infrastructure, vulnerability scanning, writing technical reports for a wide range of audiences, advising on IT projects, and helping organisations understand the practical impact of findings.

He also spent several years building open-source security tooling, and trained in exploit development and reverse engineering. A longer-term engagement focused on secure development lifecycle and static analysis, helping developers meet secure coding standards.

Building SecureSync Labs

Since founding the company, Charlie has been contracting with UK organisations — consulting first, and building custom security software where it helps.

That software work has included attack surface management for clients: an inside-out view of the estate, ingesting DNS from on-premises and cloud, combining IP, DNS, and cloud inventory, and integrating with the security tools already in place so that data can be used to judge risk on assets.

Those integrations are custom. Internal vulnerability scanning can show exposure on an asset; a WAF such as Akamai or Cloudflare can show whether a finding is already mitigated. The point is not a fixed list of vendors — it is fitting the tooling the organisation already has, including scanning that can scale in the cloud when the estate is large.