Open to Cloud Security Engineer roles · NJ / NY

Chinedu K. Asuzu — Cloud Security Engineer

Securing cloud identity, data and infrastructure.

Cloud Security Engineer with hands-on experience across Microsoft Azure and Microsoft 365 — Entra ID, Purview, Defender and Sentinel — automating with Terraform and PowerShell, and expanding into AWS. I'm looking to join a security team where I can protect identities, data and cloud workloads from day one.

CompTIA Security+ Microsoft SC-401
Platforms & tools I work with
Azure
Microsoft 365
Entra ID
Purview
Terraform
PowerShell
Security narrative

One portfolio story: protect the identity, mailbox, data and cloud.

My labs connect around a practical Microsoft cloud security model: secure access, defend communication, protect sensitive data, monitor activity and automate repeatable work.

01

Identity

Conditional Access, MFA, FIDO2, PIM and Zero Trust controls for Microsoft 365 access.

02

Email

Exchange Online and Defender for Office 365 controls for phishing, links and attachments.

03

Data

Microsoft Purview labels, custom sensitive information types, DLP, retention and audit.

04

Cloud

Azure infrastructure, network security, Azure Policy governance and Terraform automation.

05

Detection

Sentinel KQL detections, analytics rules, incident investigation and Splunk SIEM monitoring.

Featured work

Projects built to show real security and cloud engineering capability.

Each project is documented with implementation detail, validation evidence and lessons learned. GitHub holds the technical proof; this site tells the story.

Identity

Microsoft Entra Identity Security Lab

Built identity security controls around Conditional Access, MFA, FIDO2, PIM and Zero Trust principles to protect Microsoft 365 access.

Entra ID Conditional Access PIM MFA
View repository →
Email Security

Exchange Online & Email Security Lab

Configured Microsoft 365 email security controls including Defender for Office 365, anti-phishing protections, Safe Links, Safe Attachments and mailbox security policies.

Exchange Online Defender for Office 365 Anti-phishing
View repository →
Microsoft 365

Microsoft 365 Tenant Deployment

Full Microsoft 365 tenant build for a smart-manufacturing startup: domain integration, user provisioning, Exchange Online, Teams Premium, SharePoint, Copilot configuration and structured user acceptance testing.

Microsoft 365 Admin Teams SharePoint Exchange UAT
View repository →
Cloud

Azure AD Domain Controller with Terraform

Deployed a Windows Server 2022 domain controller on Azure in a single terraform apply: VNet, subnet, NSG and static-IP NIC in code, with AD DS install, forest promotion and integrated DNS automated through a Custom Script Extension, then verified with PowerShell.

Terraform Azure AD DS DNS PowerShell
View repository →
SecOps

Splunk SIEM & Threat Detection Lab

Deployed Splunk Enterprise on Azure, ingested Active Directory event logs through the Universal Forwarder, wrote SPL detection queries, built security dashboards and automated brute-force alerting.

Splunk SIEM SPL Active Directory
View repository →
SecOps 2-Part Series

Microsoft Sentinel SOC & Detection Engineering

Part 1: built the SOC foundation with Terraform (Windows Server 2025 endpoint, Log Analytics, Azure Monitor Agent, Data Collection Rules). Part 2: wrote three KQL detections mapped to MITRE ATT&CK, turned failed-logon detection into a scheduled analytics rule, investigated the incidents it raised and built a SOC workbook.

Microsoft Sentinel KQL Analytics Rules MITRE ATT&CK Terraform
Part 1: SOC infrastructure → Part 2: Detection engineering →
Endpoint

Windows Autopilot & Intune

End-to-end zero-touch Windows deployment: hardware hash registration, Autopilot profiles, OOBE provisioning, MFA enforcement, Windows Hello for Business and device compliance.

Intune Autopilot Entra ID Join Compliance
View repository →
Case study highlight

Microsoft Purview data protection pilot.

A controlled Purview implementation for a fictional organization inside a shared Microsoft 365 development tenant. Scoped to avoid tenant-wide impact, validated through negative tests and proven with a read-only PowerShell verification script.

15/15 Documented test cases passed
15/15 Scope checks passed after enforcement
4 Tiered DLP rules
4 Sensitivity labels
  • ✓Scoped labels to a dynamic administrative unit and scoped DLP/retention to one SharePoint pilot site.
  • ✓Built a custom sensitive information type for employee IDs using XML, confidence levels and supporting keywords.
  • ✓Moved DLP from simulation to enforcement through a recorded change and rollback plan.
  • ✓Validated low-risk warnings, medium-risk override with justification and high-risk blocks with no override.
  • ✓Investigated activity through Activity Explorer, the unified audit log and DLP alert triage.
  • ✓Documented limitations, future work and operational troubleshooting lessons.
Technical strengths

Skills grouped by evidence, not just keywords.

The portfolio is organized around capabilities that map directly to Azure, Microsoft 365, security operations and compliance engineering work.

Microsoft Purview & Compliance

Sensitivity labels, custom SITs, DLP, retention, Activity Explorer, audit investigation and compliance controls.

Certifications

Credentials behind the labs.

Security and Microsoft certifications that frame how I design, validate and document controls.

CompTIA Security+

Core security operations, threats, architecture, identity and risk management.

Microsoft SC-401

Information Security Administrator — Purview labels, DLP, retention and insider risk.

Microsoft AZ-104 · in progress

Azure Administrator — identity, governance, storage, compute and networking in Azure.

About

Security-first cloud engineering, documented with proof.

I'm a Cloud Security Engineer based in the New Jersey / New York area, focused on Azure, Microsoft 365, identity security and data protection, with infrastructure and security controls automated through Terraform and PowerShell. My portfolio is built around practical labs that simulate enterprise problems: controlling access, protecting email, preventing data exposure, validating governance controls and monitoring security activity.

I approach projects with an evidence-first mindset: define the problem, design the control, implement safely, validate the outcome, document the proof and record the lessons learned.

Cloud & Microsoft 365 security

Identity, email, Purview data protection and Azure infrastructure labs, each validated with test cases and documented on GitHub.

Infrastructure as code & automation

Terraform deployments of an Azure domain controller and the Sentinel SOC infrastructure, plus PowerShell build and read-only validation scripts in the Purview lab.

Security operations

Microsoft Sentinel detection engineering (KQL, analytics rules, incident investigation, workbooks) and Splunk SIEM work — ingestion, SPL detections, dashboards and alerting.

Education & certifications

New Jersey Institute of Technology · CompTIA Security+ · Microsoft SC-401 · AZ-104 in progress.

Contact

Let's talk about your cloud security needs.

I'm open to roles in cloud security, Microsoft 365 / Purview security, SOC analysis and IT administration in the NJ/NY area. The fastest way to reach me is email.

I usually reply within one business day.