Login to profile

CREST Security Operations Centre (SOC) Focus Group

Meet our SOC Focus Group

Juan Betancourt,
CPX

Cybersecurity executive and technical leader with over 15 years of experience designing, operating, and scaling mission-critical 24/7 engineering and security environments for national security programs and global enterprises. Proven expertise in managing large-scale infrastructure, complex data operations, and diverse vendor ecosystems in high-pressure settings. Over the past two years, has led the strategic adoption of AI within cybersecurity operations, focusing on tightly governed, auditable implementations. More recently, has developed hands-on expertise in Agentic AI and AI-assisted engineering, building multi-agent frameworks, semantic routing systems, and automated evaluation platforms. Combines executive-level governance and risk management with deep technical capability to effectively deploy and control AI within mission-critical environments.

Michael Dunlap,
The Missing Link

Michael is a Senior Security Analyst and GSOC Training Lead at The Missing Link, an Infosys company, working within a follow-the-sun global security operations centre that delivers managed detection and response to clients based across Australia, New Zealand, and the UK, with monitored operations spanning further countries worldwide. He specialises in cyber threat intelligence and OSINT, and is actively involved in integration of applied and agentic AI into analyst workflows, building governed automation that reduces alert fatigue and sharpens detection. As training lead, he designs certification pathways and on-the-job mentoring that lift analyst capability and flatten the learning curve for those entering the field. He is a certified ISO 27001 Lead Auditor and an IAFIE-certified intelligence analyst through ALCON’s IACC. Within the SOC community, Michael’s focus is on the practical, well-governed application of AI to strengthen both the services clients receive and the working lives of the analysts who deliver them

Jed Kafetz,
Claranet

Jed spearheads the cyber practice at Claranet, with roots in penetration testing, red teaming, and offensive security management. Having worked at several CREST member companies, he has developed and implemented pentesting and red teaming programs for numerous global organisations. Jed is dedicated to enhancing cybersecurity strategies in collaboration with CREST and its members. He is deeply interested in the integration of generative AI and machine learning into existing processes, aiming to provide customers with a more enriched and insightful service. He is currently leading in-house projects that incorporate generative AI into the scoping process.

Ramesh Naidu,
Vigilant Asia Sdn Bhd

Vice-Chair

Ramesh has more than 20 years’ experience in IT, managing large technology operations from endpoint management to distributed network. He has designed and built data centres and complex technology environments which include the management of Information Security and Cyber Security. Ramesh played a pivotal role in the setup of Vigilant Asia as an MDR player in Malaysia and was responsible for the end-to-end business and technical setup of the SOC operations.

Petar Perkovic,
Wizlynx

A cybersecurity leader with 20+ years of ICT and Information Security experience, specializing in designing, implementing, and managing Security Operations Centers (SOC) for global organizations and mega-events. Proven track record in enhancing SOC maturity, optimizing operations, and delivering measurable improvements in service quality, resilience, and customer experience.  Skilled in managing hybrid teams, driving cyber resilience strategies, aligning operations with international standards, and engaging with C-level stakeholders to influence business-critical security decisions.

Martin Riley,
Bridewell
Consulting Ltd

Chair & International Council Representative

As the Director of Managed Security at Bridewell Consulting, I have the role of developing the defensive and offensive teams. During my time at Bridewell I have focused on maturing security operations, achieving the CREST SOC accreditation and driving a culture of performance and continual learning whilst doubling the size of the SOC.

Prior to Bridewell I have bridged security and technology as CTO of UK Mid-market organisations, focusing on cloud and applications transformations.

Throughout my career I have been a leader of technology and security disciplines, building successful, large operational practices.

Andy Winters,
Obrela Security (Saudi Arabia)

A senior cyber security and technology leader with over 23 years’ experience across government and enterprise environments, combining a strong technical foundation in networking, IT, and telecommunications with proven leadership in cyber security services and cyber resilience. Experienced in building and leading high-performing national and international teams, delivering complex projects, and managing large-scale services. Recognised for motivating and developing teams through mentoring and coaching, while maintaining strong stakeholder communication and a customer-focused, results-driven approach. Expertise includes cyber security services, risk and compliance, IT service management (ITIL), project management, infrastructure governance, and vendor and service delivery management.

2025 key dates

Security Operations Centre (SOC) Focus Group meeting dates:

  • 22 May 2026, 11:00 am (BST)
  • 21 July 2026, 11:00 am (BST)
  • 24 September 2026, 11:00 (BST)
  • 10 December 2026, 11:00 am (GMT)
CREST Security Operations Centre (SOC) Certifications CREST Security Operations Centre (SOC) Buyers’ Guides CREST Security Operations Centre (SOC) Research Maximising SOAR in SOC's