ZERO TRUST · IDENTITY · ENDPOINTS · AUTOMATION

UEMS — Unified Endpoint Management Solutions

Gerson F. Torres

Gerson F. Torres — Fort Worth, TX

Security engineered
for operations that need to scale.

I design and operate security controls across identity, endpoints, cloud governance, and automation—turning policy into repeatable operational outcomes.

CONTROL PLANE / 01
POLICYDECISIONalways verify
IDENTITYverifies who’s askingcurrent: Entra ID ENDPOINTenforces the decisioncurrent: Intune CLOUDhosts the control planecurrent: Azure DATArecords the outcomecurrent: Governance AUTOMATIONexecutes the responsecurrent: Power Automate · Logic Apps · n8n SIGNALSfeeds real-time riskcurrent: Telemetry

Automation choice: n8n over Power Automate / Logic Apps where self-hosted control, cost, and cross-platform triggers—WhatsApp and Claude API—outweigh native M365 integration.

20+

years shaping enterprise IT operations

14K+

managed endpoints across Windows, iOS, and Android

70K+

Microsoft FastTrack licenses supported

100%

of evaluated endpoint audit gaps closed

01

Security model

THE OPERATING MODEL

Security is not a product stack. It is a connected operating system.

Microsoft Zero Trust principles provide the architecture. My work translates them into policies, baselines, device trust, and workflows that engineering teams can actually operate.

01

Verify explicitly

Make identity, location, device health, workload, and risk signals part of every access decision.

02

Use least privilege

Limit standing access, constrain blast radius, and apply policies in context—not as a one-time project.

03

Assume breach

Design controls, telemetry, and response paths on the expectation that signals will change.

02

Endpoint security

MICROSOFT SECURITY IN PRACTICE

From identity signal
to endpoint trust.

An endpoint program becomes a security program when its controls reinforce one another: identity establishes context, compliance establishes device trust, and policy governs access.

01 / IDENTITY

Conditional access with context

Entra ID, MFA, RBAC, and Identity Protection establish a policy-aware entry point.

02 / DEVICE

Compliance that can enforce

Intune and security baselines make device health an access decision—not a report.

03 / PLATFORM

Modern endpoint foundations

Autopilot, Cloud PC, co-management, PKI, and GPO-to-Intune migration reduce legacy friction.

04 / ASSURANCE

Controls that stand up to scrutiny

CIS-aligned hardening and audit-ready standards connect implementation to assurance.

03

Secure automation

AUTOMATION WITH GUARDRAILS

Automate the repeatable. Preserve the controls.

The valuable automation is not a disconnected bot. It is a governed path from a trusted event to an accountable action—with visibility for the people who operate it.

SELECTED PATTERN / 03Secure operations workflowEvent → context → action → record
01Trusted
event
ITSM · Teams · Webhook
02Policy
context
Identity · scope · approval
03n8n
orchestration
Workflow · credentials · logs
04Accountable
outcome
Teams · Azure SQL · owner
Authenticated trigger Least-privilege action Human escalation path Execution record

ITSM triage pattern. ServiceNow → n8n → Microsoft Teams, with AI-based classification to support a faster, enterprise-ready triage flow.

Customer operations pattern. Claude API and n8n integrated with WhatsApp Business and Azure SQL to remove manual first-contact overhead.

04

Built systems

SYSTEMS BUILT FOR OPERATIONS

Systems that turn intent into reliable action.

Each system is designed around a real operating need: clear ownership, trusted identity, deliberate automation, and outcomes that do not depend on someone being available at the right moment.

01 / CUSTOMER OPERATIONS

Andrés — conversational AI sales

Designed and deployed a bilingual AI agent that sells and supports customers across WhatsApp and web, without human involvement in the first contact.

WhatsApp · Web · AI agent
02 / IDENTITY-AWARE IT

Nova — IT operations from Microsoft Teams

Brought UEM Solutions administration into Teams through a bot that operates with the correct identity and permissions for each user through Entra ID.

Teams · Entra ID · governed action
03 / SERVICE DELIVERY

ServiceNow → Intune, without manual steps

Designed the bridge from a support ticket to a real Intune action—moving from “a problem was reported” to a resolved system state without manual handoffs in between.

ServiceNow ↔ Jira · n8n · Intune
04 / OWNED PLATFORM

A private automation platform

Built and operate a personal automation layer on n8n and AI models. The infrastructure used for client systems is also the platform that runs the business.

n8n · AI models · self-hosted operations
05

Infrastructure

SELF-HOSTED ENGINEERING

Own the platform.
Operate it responsibly.

Self-hosted automation is an engineering discipline, not just a deployment choice. The infrastructure layer has to be designed for access control, repeatability, recovery, and operational visibility.

01
Hardened Ubuntu VPSOperating system · access surface · patch discipline
HOST
02
Docker containersIsolation · versioned services · repeatable deployment
RUNTIME
03
Workflows & APIsn8n · integrations · business logic
OPERATIONS
04
Control recordsSecrets · backups · change traceability
ASSURANCE
06

Security radar

MICROSOFT SECURITY / 60-DAY SIGNALS

What is changing in the security control plane.

A focused view of product changes relevant to identity, AI security, and data protection. Sources are linked directly to Microsoft’s official announcements.

05 AUG 2026MICROSOFT DEFENDER

AI agent posture risk assessment

Defender now assesses posture risk for enterprise and local AI agents using configuration, access, runtime, context, and alert indicators.

Read Microsoft source ↗
10 AUG 2026MICROSOFT ENTRA

Cloud Sync for on-premises devices

Public preview adds device synchronization from on-premises Active Directory to Entra ID through Cloud Sync for hybrid lifecycle management.

Read Microsoft source ↗
30 JUL 2026MICROSOFT PURVIEW

Data protection at the network layer

Purview now integrates with Entra Internet Access to help detect and block sensitive data moving to unmanaged cloud and AI applications.

Read Microsoft source ↗
07

Proven outcomes

EXPERIENCE AT SCALE

Proof lives in the operating outcome.

01
ENTERPRISE ENDPOINT MODERNIZATION

Security controls for 14,000+ endpoints

Primary technical ownership of Intune expansion across Windows, iOS, and Android, using Cloud PKI, Conditional Access, and CIS-aligned controls.

100%evaluated audit gaps closed
02
MICROSOFT FASTTRACK DELIVERY

Architecture and adoption at enterprise scale

Endpoint Manager onboarding, identity integration, security configuration, and technical enablement across US customer and partner environments.

70K+licenses supported
03
OPERATIONAL AUTOMATION

Less manual effort, better engineering focus

PowerShell-led operational improvement alongside practical AI and workflow automation patterns for support and business operations.

30%manual task reduction

START A TECHNICAL CONVERSATION

Build security operations
that can keep moving.

Whether you are modernizing endpoint management, strengthening identity controls, or planning automation that respects governance, I welcome a direct conversation.