Azure Security Architect

I design and build security for Microsoft Azure on Zero Trust principles — identity (Entra ID), network, Microsoft Sentinel, DevSecOps and automated detection & response. I ground the architecture in how attacks actually happen.

Matěj Hrabálek — Azure Security Architect

About me

I'm a security architect focused on cloud security in Microsoft Azure. I design the overall security posture of cloud environments as a whole, as well as the implementation of individual tools — Microsoft Sentinel, Defender XDR, Entra ID and Purview. My focus is on security that is not only compliant, but genuinely effective.

I have 5+ years of experience in cybersecurity — from SOC analysis through consulting to cloud architecture — backed by a master's degree. I've worked on Azure security and Microsoft Sentinel for 10+ clients.

Zero TrustNIS2 & DORAMicrosoft SentinelKQLMicrosoft AzureMicrosoft Defender XDRMicrosoft Entra IDMicrosoft PurviewDevSecOpsTerraform / IaCAzure AIThreat Modeling

Expertise

End-to-end cloud security in Microsoft Azure — from strategy and architecture to detection, automation and compliance.

SIEM & SOAR

Design and implementation of Microsoft Sentinel — from integrating logs across hybrid, on-prem and cloud sources to custom KQL detections and incident-response automation with Logic Apps and AI-assisted triage.

Zero Trust & Identity

Design and rollout of a Zero Trust model across the cloud — strict identity verification (Microsoft Entra ID, PIM), microsegmentation and network security (Azure Firewall, WAF, NSG).

DevSecOps & IaC

Security built into development — securing CI/CD pipelines, secret scanning, Defender for Containers & APIs, and infrastructure as code (Terraform, Policy-as-Code).

Data Security & Governance

Protecting data assets across Microsoft Azure and Microsoft 365 — classification, encryption, DLP and monitoring of sensitive-information flows with Microsoft Purview.

Security Strategy

Designing the overall security strategy for the platform — threat modeling (STRIDE, DREAD), a risk register, incident-response runbooks and continuous hardening of the environment's security posture.

Security Architecture

End-to-end security architecture design for cloud and hybrid environments — from risk assessment to target state and an adoption roadmap.

Projects

Selected projects from recent years. Client names are covered by NDA.

Zero Trust platform for a financial group

Designed and built a cloud security architecture in Microsoft Azure from the ground up for a group operating in insurance and fintech. Identity and privileged access (Entra ID, PIM), network segmentation, Microsoft Sentinel as the central SIEM, and alignment with NIS2, DORA and PSD2. Later took group-wide ownership of the SIEM platform and coordination of the external SOC.

Multi-tenant SOAR in the energy sector

Automated incident response on Microsoft Sentinel for an energy-sector client. Logic App playbooks, custom KQL detections, Sentinel-as-Code with CI/CD pipelines in Azure DevOps, and delegated cross-tenant management via Azure Lighthouse.

Microsoft Sentinel across 10+ enterprise environments

Deployed and tuned Sentinel across industries — integrating log sources from hybrid estates, building detection rules, and optimising data ingestion cost. Experience spans telecommunications, finance and energy, including supporting analysts during live incidents.

Working together

So you know what to expect before we even talk.

Focus

I work exclusively on security in Microsoft Azure and Microsoft 365 — Sentinel, Entra ID, Defender XDR, Purview, DevSecOps. I don't take engagements on other platforms or SIEMs.

Remote-first

I work primarily remotely. By arrangement I travel to Prague, Brno, Vienna and Bratislava.

Short and long engagements

Well-scoped work — assessing the current state, designing an architecture, implementing a specific solution — as well as long-term collaboration on developing security.

Ways of working together

Directly with the end client, through an agency, or as a subcontractor to a delivery partner.

Larger projects

For bigger scopes I can join a larger team or bring in colleagues with the same focus.

Capacity

I take on a limited number of engagements. Timing and scope are agreed individually based on current availability.

Certifications

Microsoft's complete security stack, complemented by industry standards.

Microsoft Certified

SC-100: Cybersecurity Architect Expert
AZ-500: Azure Security Engineer
SC-200: Security Operations Analyst
SC-300: Identity & Access Administrator
SC-400: Information Protection Admin
SC-900: Security Fundamentals
AZ-900: Azure Fundamentals

Industry Standard

CompTIA CySA+
CompTIA PenTest+
CompTIA Security+
ISC2 CC (Certified in Cybersecurity)

Let's schedule a call

Let's discuss the security of your cloud infrastructure together and map out the best path to modernizing it.

Open booking calendar

By booking a meeting you agree to the processing of personal data.

Contact

Ing. Matěj Hrabálek

Registered office: Třešňová 916/16, 669 04 Znojmo, Czech Republic

Phone: +420 733 665 123

Email: info@matejhrabalek.cz

Company ID (IČO): 24514616 | VAT ID (DIČ): CZ0009194075

Registered in the Trade Register at Znojmo Municipal Office

LinkedIn — Matěj Hrabálek

Contact form