Security engineered for operationsthat need to scale.
I design and operate security controls across identity, endpoints, cloud governance, and automation—turning policy into repeatable operational outcomes.
IDENTITYverifies who’s askingcurrent: Entra IDENDPOINTenforces the decisioncurrent: IntuneCLOUDhosts the control planecurrent: AzureDATArecords the outcomecurrent: GovernanceAUTOMATIONexecutes the responsecurrent: Power Automate · Logic Apps · n8nSIGNALSfeeds real-time riskcurrent: Telemetry
Automation choice: n8n over Power Automate / Logic Apps where self-hosted control, cost, and cross-platform triggers—WhatsApp and Claude API—outweigh native M365 integration.
20+
years shaping enterprise IT operations
14K+
managed endpoints across Windows, iOS, and Android
70K+
Microsoft FastTrack licenses supported
100%
of evaluated endpoint audit gaps closed
01
Security model
THE OPERATING MODEL
Security is not a product stack. It is a connected operating system.
Microsoft Zero Trust principles provide the architecture. My work translates them into policies, baselines, device trust, and workflows that engineering teams can actually operate.
01
Verify explicitly
Make identity, location, device health, workload, and risk signals part of every access decision.
02
Use least privilege
Limit standing access, constrain blast radius, and apply policies in context—not as a one-time project.
03
Assume breach
Design controls, telemetry, and response paths on the expectation that signals will change.
02
Endpoint security
MICROSOFT SECURITY IN PRACTICE
From identity signal to endpoint trust.
An endpoint program becomes a security program when its controls reinforce one another: identity establishes context, compliance establishes device trust, and policy governs access.
TRUST ENGINE
ENIdentity
INCompliance
PKCertificates
UPUpdates
01 / IDENTITY
Conditional access with context
Entra ID, MFA, RBAC, and Identity Protection establish a policy-aware entry point.
02 / DEVICE
Compliance that can enforce
Intune and security baselines make device health an access decision—not a report.
CIS-aligned hardening and audit-ready standards connect implementation to assurance.
03
Secure automation
AUTOMATION WITH GUARDRAILS
Automate the repeatable. Preserve the controls.
The valuable automation is not a disconnected bot. It is a governed path from a trusted event to an accountable action—with visibility for the people who operate it.
Authenticated trigger Least-privilege action Human escalation path Execution record
ITSM triage pattern. ServiceNow → n8n → Microsoft Teams, with AI-based classification to support a faster, enterprise-ready triage flow.
Customer operations pattern. Claude API and n8n integrated with WhatsApp Business and Azure SQL to remove manual first-contact overhead.
04
Built systems
SYSTEMS BUILT FOR OPERATIONS
Systems that turn intent into reliable action.
Each system is designed around a real operating need: clear ownership, trusted identity, deliberate automation, and outcomes that do not depend on someone being available at the right moment.
01 / CUSTOMER OPERATIONS
Andrés — conversational AI sales
Designed and deployed a bilingual AI agent that sells and supports customers across WhatsApp and web, without human involvement in the first contact.
WhatsApp · Web · AI agent02 / IDENTITY-AWARE IT
Nova — IT operations from Microsoft Teams
Brought UEM Solutions administration into Teams through a bot that operates with the correct identity and permissions for each user through Entra ID.
Teams · Entra ID · governed action03 / SERVICE DELIVERY
ServiceNow → Intune, without manual steps
Designed the bridge from a support ticket to a real Intune action—moving from “a problem was reported” to a resolved system state without manual handoffs in between.
Built and operate a personal automation layer on n8n and AI models. The infrastructure used for client systems is also the platform that runs the business.
n8n · AI models · self-hosted operations
05
Infrastructure
SELF-HOSTED ENGINEERING
Own the platform. Operate it responsibly.
Self-hosted automation is an engineering discipline, not just a deployment choice. The infrastructure layer has to be designed for access control, repeatability, recovery, and operational visibility.
01
Hardened Ubuntu VPSOperating system · access surface · patch discipline
Workflows & APIsn8n · integrations · business logic
OPERATIONS
04
Control recordsSecrets · backups · change traceability
ASSURANCE
06
Security radar
MICROSOFT SECURITY / 60-DAY SIGNALS
What is changing in the security control plane.
A focused view of product changes relevant to identity, AI security, and data protection. Sources are linked directly to Microsoft’s official announcements.
05 AUG 2026MICROSOFT DEFENDER
AI agent posture risk assessment
Defender now assesses posture risk for enterprise and local AI agents using configuration, access, runtime, context, and alert indicators.
Primary technical ownership of Intune expansion across Windows, iOS, and Android, using Cloud PKI, Conditional Access, and CIS-aligned controls.
100%evaluated audit gaps closed
02
MICROSOFT FASTTRACK DELIVERY
Architecture and adoption at enterprise scale
Endpoint Manager onboarding, identity integration, security configuration, and technical enablement across US customer and partner environments.
70K+licenses supported
03
OPERATIONAL AUTOMATION
Less manual effort, better engineering focus
PowerShell-led operational improvement alongside practical AI and workflow automation patterns for support and business operations.
30%manual task reduction
START A TECHNICAL CONVERSATION
Build security operations that can keep moving.
Whether you are modernizing endpoint management, strengthening identity controls, or planning automation that respects governance, I welcome a direct conversation.