I design and build security for Microsoft Azure on Zero Trust principles — identity (Entra ID), network, Microsoft Sentinel, DevSecOps and automated detection & response. I ground the architecture in how attacks actually happen.
I'm a security architect focused on cloud security in Microsoft Azure. I design the overall security posture of cloud environments as a whole, as well as the implementation of individual tools — Microsoft Sentinel, Defender XDR, Entra ID and Purview. My focus is on security that is not only compliant, but genuinely effective.
I have 5+ years of experience in cybersecurity — from SOC analysis through consulting to cloud architecture — backed by a master's degree. I've worked on Azure security and Microsoft Sentinel for 10+ clients.
End-to-end cloud security in Microsoft Azure — from strategy and architecture to detection, automation and compliance.
Design and implementation of Microsoft Sentinel — from integrating logs across hybrid, on-prem and cloud sources to custom KQL detections and incident-response automation with Logic Apps and AI-assisted triage.
Design and rollout of a Zero Trust model across the cloud — strict identity verification (Microsoft Entra ID, PIM), microsegmentation and network security (Azure Firewall, WAF, NSG).
Security built into development — securing CI/CD pipelines, secret scanning, Defender for Containers & APIs, and infrastructure as code (Terraform, Policy-as-Code).
Protecting data assets across Microsoft Azure and Microsoft 365 — classification, encryption, DLP and monitoring of sensitive-information flows with Microsoft Purview.
Designing the overall security strategy for the platform — threat modeling (STRIDE, DREAD), a risk register, incident-response runbooks and continuous hardening of the environment's security posture.
End-to-end security architecture design for cloud and hybrid environments — from risk assessment to target state and an adoption roadmap.
Selected projects from recent years. Client names are covered by NDA.
Designed and built a cloud security architecture in Microsoft Azure from the ground up for a group operating in insurance and fintech. Identity and privileged access (Entra ID, PIM), network segmentation, Microsoft Sentinel as the central SIEM, and alignment with NIS2, DORA and PSD2. Later took group-wide ownership of the SIEM platform and coordination of the external SOC.
Automated incident response on Microsoft Sentinel for an energy-sector client. Logic App playbooks, custom KQL detections, Sentinel-as-Code with CI/CD pipelines in Azure DevOps, and delegated cross-tenant management via Azure Lighthouse.
Deployed and tuned Sentinel across industries — integrating log sources from hybrid estates, building detection rules, and optimising data ingestion cost. Experience spans telecommunications, finance and energy, including supporting analysts during live incidents.
So you know what to expect before we even talk.
I work exclusively on security in Microsoft Azure and Microsoft 365 — Sentinel, Entra ID, Defender XDR, Purview, DevSecOps. I don't take engagements on other platforms or SIEMs.
I work primarily remotely. By arrangement I travel to Prague, Brno, Vienna and Bratislava.
Well-scoped work — assessing the current state, designing an architecture, implementing a specific solution — as well as long-term collaboration on developing security.
Directly with the end client, through an agency, or as a subcontractor to a delivery partner.
For bigger scopes I can join a larger team or bring in colleagues with the same focus.
I take on a limited number of engagements. Timing and scope are agreed individually based on current availability.
Microsoft's complete security stack, complemented by industry standards.
Let's discuss the security of your cloud infrastructure together and map out the best path to modernizing it.
Open booking calendarBy booking a meeting you agree to the processing of personal data.