Assume breach
Design as if the attacker is already inside. Verify explicitly, limit blast radius, and detect fast.

I started my career deep in Systems Administration and Systems Security — building, hardening and operating enterprise IT environments at scale.
Working closely with Active Directory and Microsoft Entra ID security operations gave me a strong foundation in how real production environments behave, and how attackers exploit misconfigurations, weak identity controls, and visibility gaps.
Out of curiosity and a desire to understand software systems more holistically, I transitioned into software engineering — building and deploying real applications end to end. That experience taught me how developers think, how applications are designed and shipped, and where security naturally breaks down in fast-moving environments.
Over time, I combined both worlds. Today, I focus on Microsoft 365 and cloud security architecture across Microsoft and AWS environments — designing and securing modern platforms using Microsoft Defender XDR, Microsoft Sentinel (SIEM/SOAR), structured vulnerability management programs, and cloud-native security controls. On the Microsoft 365 side, I work extensively with Entra ID, Conditional Access, MFA, Intune device compliance, and Microsoft Purview for data protection and compliance.
I enjoy building detection engineering strategies that reduce dwell time (MTTD/MTTR), implementing Zero Trust architectures across identities, endpoints and workloads, and strengthening visibility across cloud and hybrid environments — often using KQL and MITRE ATT&CK-informed detections.
My work spans securing Microsoft 365, Azure and AWS workloads, automating incident response, and bridging the gap between infrastructure, cloud engineering and security operations (SecOps) — while aligning with compliance frameworks like NIST CSF, ISO 27001, GDPR and HIPAA.
I'm especially interested in Microsoft 365 security, cloud-native security architecture, threat-informed defense, and performance-driven security operations — and I enjoy sharing what I learn through writing and mentoring.
Infrastructure, software and security operations — brought together so nothing falls through the cracks.
Building, hardening and operating enterprise IT at scale — Active Directory, Entra ID and security operations from the ground up.
Designing, building and shipping real applications end to end — learning exactly where security breaks in fast-moving teams.
Securing Microsoft 365, Azure and AWS with Zero Trust, Defender XDR, Sentinel and threat-informed detection engineering.
Design as if the attacker is already inside. Verify explicitly, limit blast radius, and detect fast.
Secure Score, MTTD and MTTR aren't vanity metrics — they're how we prove security is actually improving.
I leave teams stronger than I found them — clear runbooks, real knowledge transfer, and no black boxes.
Book a free review and see what a threat-informed approach can do for your environment.