About

The nerd behind the365nerd

Portrait of the365nerd
Entra IDConditional AccessIntunePurviewDefender XDRSentinelKQLAWSAzure

I started my career deep in Systems Administration and Systems Security — building, hardening and operating enterprise IT environments at scale.

Working closely with Active Directory and Microsoft Entra ID security operations gave me a strong foundation in how real production environments behave, and how attackers exploit misconfigurations, weak identity controls, and visibility gaps.

Out of curiosity and a desire to understand software systems more holistically, I transitioned into software engineering — building and deploying real applications end to end. That experience taught me how developers think, how applications are designed and shipped, and where security naturally breaks down in fast-moving environments.

Over time, I combined both worlds. Today, I focus on Microsoft 365 and cloud security architecture across Microsoft and AWS environments — designing and securing modern platforms using Microsoft Defender XDR, Microsoft Sentinel (SIEM/SOAR), structured vulnerability management programs, and cloud-native security controls. On the Microsoft 365 side, I work extensively with Entra ID, Conditional Access, MFA, Intune device compliance, and Microsoft Purview for data protection and compliance.

I enjoy building detection engineering strategies that reduce dwell time (MTTD/MTTR), implementing Zero Trust architectures across identities, endpoints and workloads, and strengthening visibility across cloud and hybrid environments — often using KQL and MITRE ATT&CK-informed detections.

My work spans securing Microsoft 365, Azure and AWS workloads, automating incident response, and bridging the gap between infrastructure, cloud engineering and security operations (SecOps) — while aligning with compliance frameworks like NIST CSF, ISO 27001, GDPR and HIPAA.

I'm especially interested in Microsoft 365 security, cloud-native security architecture, threat-informed defense, and performance-driven security operations — and I enjoy sharing what I learn through writing and mentoring.

The journey

Three worlds, one security mindset

Infrastructure, software and security operations — brought together so nothing falls through the cracks.

  • Systems Administration & Security

    Building, hardening and operating enterprise IT at scale — Active Directory, Entra ID and security operations from the ground up.

  • Software Engineering

    Designing, building and shipping real applications end to end — learning exactly where security breaks in fast-moving teams.

  • Cloud Security Architecture

    Securing Microsoft 365, Azure and AWS with Zero Trust, Defender XDR, Sentinel and threat-informed detection engineering.

How I think

Principles I bring to every engagement

Assume breach

Design as if the attacker is already inside. Verify explicitly, limit blast radius, and detect fast.

Measure everything

Secure Score, MTTD and MTTR aren't vanity metrics — they're how we prove security is actually improving.

Teach as I go

I leave teams stronger than I found them — clear runbooks, real knowledge transfer, and no black boxes.

Let's secure your Microsoft 365

Book a free review and see what a threat-informed approach can do for your environment.