Practice

Services

I deliver security engineering support built for practical results.

I organize engagements around identity security, cloud and endpoint hardening, network segmentation, DevSecOps, and secure platform operations. I document each phase so your team can run controls after delivery.

Service lines

01

What I help organizations strengthen.

I focus on access control, monitoring, remediation, network hardening, automation, and production support that your team can sustain.

01

Service

Identity and Access Security

I design and improve Microsoft identity controls so your team gets least-privilege access, reliable lifecycle workflows, and stronger authentication.

You get least-privilege access that is easier to audit and safer to operate, including a 19% excessive-permission reduction in prior work.

Capabilities

  • Microsoft Entra ID and Active Directory
  • RBAC, MFA, and Conditional Access
  • Onboarding, offboarding, and stale-account cleanup
  • Access reviews and privileged-access concepts

02

Service

Cloud and Endpoint Security Operations

I harden Azure and endpoint environments while keeping monitoring, remediation, and patch follow-through practical for your operations teams.

You get better visibility and faster response, including 150+ monthly security incidents mitigated and documented.

Capabilities

  • Azure VM, VNet, subnet, NSG, and VPN Gateway hardening
  • Microsoft Defender, M365 Defender, ESET, and SolarWinds workflows
  • Microsoft Sentinel, Log Analytics, and suspicious authentication review
  • Server patching and vulnerability remediation, including Log4j response

03

Service

Network Security and Segmentation

I strengthen hybrid and on-premises networks with secure access paths, segmented traffic, and validated firewall policy.

You get reliable networks with reduced attack surface, clearer approved flows, and stronger isolation between user and device groups.

Capabilities

  • Fortinet and Palo Alto firewall rule cleanup
  • VLAN segmentation for staff, guest, IoT, VoIP, and server traffic
  • WPA3 and Aerohive wireless isolation
  • VPN, Wireshark validation, and IDS/IPS concepts

04

Service

DevSecOps, Client Platforms, and Server Management

I build and maintain secure web platforms while applying security thinking to frontend, backend, hosting, and server operations.

You get production websites and services customers can rely on, backed by practical server management and secure deployment habits.

Capabilities

  • Next.js, React, TypeScript, and secure frontend delivery
  • Backend integration, DNS, SSL/TLS, hosting, and server administration
  • PowerShell, Python, SQL log queries, and event-log collection
  • Client support, troubleshooting, documentation, and deployment hygiene

How I work

02

A clear, evidence-driven engagement model.

01

Discover

Map the environment, identity paths, exposed services, monitoring gaps, and operational constraints before changing controls.

02

Harden and Validate

Implement least-privilege controls, hardening steps, automation, or segmentation changes, then validate the result with logs, packet flow, or documented evidence.

03

Document and Support

Create runbooks, communicate clearly with technical and non-technical users, and support the team through operation or handoff.

Need someone who can secure systems and still support the people using them?