Janice Aliten

Security, Compliance & Infrastructure Engineer  |  Identity & Access  |  Data Protection  |  Vulnerability Management  |  Hybrid Infrastructure  |  Cloud Security
Auckland, New Zealand — Full Working Rights janice@aliten.co github.com/janice-aliten
View Project Portfolio Security Control Mapping Template GitHub Portfolio Verified Credentials Contact

Profile

Security, Compliance & Infrastructure Engineer with 15+ years of experience across on-premises, co-location, hybrid Microsoft, Microsoft 365, and cloud-connected environments. Career built on deep hands-on ownership of Windows Server, Active Directory, ADFS, Exchange, SQL Server, IIS, Hyper-V, DNS/DHCP, VPN, SSL/TLS, Sophos firewall, Veeam, SCOM, Azure DevOps Server, backup and recovery, controlled change management, and vendor coordination across production commercial environments and multi-site MSP delivery.

Currently serves as the sole infrastructure, Microsoft 365 security, compliance, and governance owner for a production commercial software environment, with recent expansion of Microsoft 365 security and governance capability across Microsoft Purview Information Protection, DLP, Defender suite including Defender for Endpoint P2 in passive mode alongside ESET as primary endpoint protection, Microsoft Sentinel workspace readiness, Microsoft Priva, Microsoft Fabric / Power BI governance, and Power Platform CRM administration.

Sole owner of the EU Cyber Resilience Act (CRA) readiness programme covering SBOM analysis, CVE identification, Dependency-Track deployment, vulnerability disclosure workflow design, Article 14 CSIRT reporting readiness, and evidence organisation. Built a sanitised security control-mapping portfolio artefact aligning example security, identity, vulnerability-management, data-protection, incident-response, backup/DR, supplier, infrastructure, secure-development, and customer-assurance controls to EU CRA readiness themes, ISO/IEC 27001:2022 Annex A, NIST CSF 2.0, and SOC 2 Trust Services Criteria. Brings additional security-relevant context from data analytics study and practice, Python-based analysis, and blockchain and digital-asset workflow familiarity — supported by CI-validated DevSecOps, SBOM, compliance-mapping, and Linux operations labs.

Infrastructure Foundation

Server, Virtualisation & Hardware Lifecycle
Windows Server 2008–2025
Hyper-V on Windows Server 2016–2025
Hyper-V Server 2016/2019
VMware ESXi
Dell PowerEdge hardware lifecycle
Physical-to-Virtual (P2V) migration
Identity, Directory & Access
Active Directory (2008–2022)
ADFS — SSO & federation
DNS / DHCP
Group Policy / Certificate Services
Hybrid identity (Entra ID)
Conditional Access / MFA / RBAC
Messaging, Collaboration & SaaS Platforms
Exchange 2010–2019 / Subscription Edition / Exchange Online
SharePoint 2013–2019 / SharePoint Online
Google Workspace Admin / Gmail / Drive / Calendar
Dynamics CRM / Dynamics 365
Microsoft Teams / Zoom Phone
FogBugz / Manuscript / Freshdesk
Database, Web & Engineering Platforms
SQL Server 2008–2019
IIS (web services)
Azure DevOps Server
Code-signing & build pipeline
PowerShell automation
Networking, Perimeter & External Paths
Sophos Firewall & Sophos RED
MikroTik Router
Dual-WAN failover
VPN / NAT / VLAN
Allied Telesis, Cisco, Aruba, Ubiquiti
Ruckus, Aerohive wireless
Backup, Recovery & Monitoring
Veeam Backup & Replication
ShadowProtect
SCOM (Operations Manager)
Hyper-V passive replica / DR
Restore verification & DR readiness
Endpoint, MDM & Security Tooling
ESET ERA / ESMC / ESET PROTECT
Symantec SEPM
Apple iOS / iPad administration
MDM: Cisco Meraki / Lightspeed
MDT / WDS / SCCM deployment
Microsoft 365 Security & Governance
Purview DLP & Information Protection
Defender suite / Defender for Endpoint P2
Sentinel workspace readiness
Priva privacy-risk visibility
Fabric / Power BI governance
Cloud, Automation & DevSecOps
Azure (AZ-104) / AWS (Terraform)
Docker / GitHub Actions / Trivy
Gitleaks / Dependabot
CycloneDX / Dependency-Track
Python / Bash scripting

Core Skills

Identity & Access Management
Microsoft Entra IDActive Directory ADFSConditional AccessMFA RBACApp Registrations Hybrid IdentityPrivileged-Role Governance
Vulnerability Management & DevSecOps
SBOM / CycloneDXDependency-Track CVE AnalysisCVSS Review Remediation Tracking TrivyGitleaks GitHub ActionsDependabotQualys VMDRQualys CSAM
Infrastructure & Network Security
Sophos FirewallMikroTik Hyper-VVMware ESXi Windows ServerSSL/TLS VPNDual-WANDNS Security VeeamSCOMCo-location
Microsoft Security, Compliance & Data Protection
Microsoft PurviewDLP Information ProtectionSensitivity Labels Microsoft DefenderDefender for Endpoint P2 Microsoft SentinelMicrosoft PrivaDefender XDR
Microsoft 365, Google Workspace & SaaS Collaboration
Microsoft 365 Admin CenterExchange Online SharePoint OnlineOneDriveTeams Power PlatformMicrosoft Fabric / Power BIDynamics 365 Google Workspace AdminGmailGoogle Drive Google CalendarGroupsDomain / DNS ReadinessSaaS User Lifecycle
Endpoint, Device & SaaS Administration
Apple iOS / iPad AdministrationMDM Cisco MerakiLightspeed Endpoint SecurityDevice Lifecycle App DeploymentSaaS Access Administration
Compliance, Governance & Evidence
EU Cyber Resilience Act (CRA) ReadinessArticle 14 CSIRT Readiness ISO/IEC 27001:2022 Control MappingNIST CSF 2.0 Mapping SOC 2 Customer-Assurance MappingRisk Register Gap TrackingMaturity Scoring Evidence RepositoryAudit Documentation Remediation TrackingControlled Change Microsoft Licensing Compliance
Cloud, Automation & Technical Validation
Azure (AZ-104)AWS (Terraform) PowerShellPython BashDocker TerraformGitHub Actions

Experience

Senior Systems Engineer
ActiveDocs Ltd — Auckland, New Zealand — 2017 – Present
  • Sole infrastructure, security, compliance, identity, and platform operations owner: End-to-end ownership for a production commercial software company across on-premises, co-location, hybrid Microsoft, Microsoft 365, and cloud-connected environments.
  • On-premises, co-location and hybrid platform operations: Multi-host Hyper-V environment (production, DR replica, test), Windows Server 2008–2025, SQL Server 2014–2019, Exchange 2013–2019, SharePoint 2013–2019, ADFS, Azure DevOps Server, Veeam, SCOM, Sophos firewall with Sophos RED dual-WAN, MikroTik routing, and co-location datacenter operations.
  • Microsoft 365 security, data protection & governance: Sole owner of Purview DLP and Information Protection, Defender suite with Defender for Endpoint P2 in passive mode alongside ESET as primary endpoint protection, Sentinel workspace readiness, Priva, Fabric / Power BI governance, Power Platform, Entra ID, Exchange Online, SharePoint Online, and Teams administration.
  • EU CRA compliance programme: Owned SBOM analysis, CVE management, Dependency-Track deployment, vulnerability disclosure workflow design, and Article 14 CSIRT reporting readiness aligned to the September 2026 deadline.
  • Vendor & delivery: Provider evaluation and coordination across co-location, certificates, Microsoft licensing, hardware, backup, firewall, and hosted-service dependencies; management-facing cost and risk recommendations.
  • Incident response: Production ADFS/Kerberos SSO outage root-caused and resolved after Windows Server cumulative-update encryption changes; full post-incident documentation and preventive control recommendations.
Senior Systems Engineer
Norrcom Ltd (MSP) — Auckland, New Zealand — 2015 – 2017
  • Senior project and technical engineer: Infrastructure, security, network, and device engineering across multiple Auckland school environments of 200–1,000+ users, operating across major migration, endpoint, MDM, and school network upgrade programmes.
  • Apple iOS & MDM administration: Deployed and administered Apple iPad fleets across multiple school environments with 500–1,000+ users; configured Cisco Meraki MDM for iOS supervised device management including DEP enrolment, configuration profiles, app deployment, content filtering, and policy enforcement; Lightspeed MDM for iOS and Android device administration; Apple device troubleshooting, hardware fault diagnosis, and full device lifecycle management.
  • Platform delivery: Google Workspace administration and deployment support, Google Workspace to Office 365 migrations, Windows Server upgrades, domain rebuilds, Hyper-V P2V migrations, MDT/WDS/SCCM endpoint deployment, ESET and Symantec endpoint security rollout, Veeam and ShadowProtect backup, and Papercut print management.
  • Network infrastructure: SNUP and WSNUP school network upgrade projects delivering Allied Telesis switching, Ruckus and Aerohive wireless access point deployments, VLAN configuration, routing, and multi-vendor firewall delivery across Allied Telesis, Cisco, Juniper, Fortinet, WatchGuard, and Palo Alto environments.
  • Security operations: Network security investigation in 500–1,000+ user environments; traced policy-breaching activity (Tor Browser, unauthorised tools) to specific devices and users; produced remediation documentation.
Network and Systems Engineer
H&T IT Development Pte. Ltd. (MSP) — Singapore — 2013 – 2015
  • Multi-client engineering: Primary on-site (70%) and remote (30%) engineer for approximately 30 Singapore client environments spanning Finance, Shipping, Logistics, Hotel, Pharmaceuticals, Automobile, Food & Beverage, and Manufacturing industries.
  • Infrastructure & hosted services: VMware ESXi, Windows Server 2003–2012 R2, Exchange 2010, Office 365, SQL Server, SonicWall, Cisco and Fortinet firewall, VPN, NAS, CPanel/Hosting, DNS, and SSL/TLS administration across multi-industry client environments.
  • Email security & incident response: Blacklist and reputation investigation, SPF/DKIM configuration, spam-delivery and email-flow troubleshooting; after-hours urgent support and vendor/provider escalation across multi-client environments.
Earlier Enterprise Experience
CSC Technology — Malaysia  |  Sutherland Global Services — Philippines  |  Dell International Services — Philippines  —  2007 – 2013
  • Senior escalation roles across Ingersoll Rand, Microsoft, and Dell environments, resolving complex endpoint, Active Directory, Cisco VPN, Citrix, Exchange ActiveSync, and authentication issues. Earned Microsoft certification stack (MCP through MCITP) during this period while completing the Bachelor of Science in Information Technology. Multiple Top Employee awards across all three roles. Built the enterprise endpoint and Microsoft troubleshooting foundation later applied to infrastructure, identity, security, compliance, and hybrid platform operations.

Selected Project Portfolio

Click any project to expand full detail.

ActiveDocs Ltd — Security, Compliance & Infrastructure Projects (2017 – Present)
Microsoft 365 Security, Compliance & Governance DeploymentProduction — 2026

Full-lifecycle deployment of Microsoft 365 security, compliance, and governance capabilities as sole owner of the company's production Microsoft 365 environment.

Purview Information Protection & DLP
  • Designed sensitivity-label classification scheme and deployed labels across Microsoft 365 workloads
  • Configured DLP policies with scoped rollout across Exchange Online, SharePoint, OneDrive, and Teams
  • Staged validation, user-impact review, and audit-ready operational documentation
Microsoft Defender Suite
  • Deployed Defender for Endpoint P2 in passive mode alongside ESET as the primary endpoint protection platform
  • Configured Defender portal, security posture review, alert visibility, and future transition planning toward full Defender EDR
Microsoft Sentinel, Priva & Fabric
  • Implemented Microsoft Sentinel workspace readiness supporting alert visibility and incident-review workflow development
  • Enabled Microsoft Priva for privacy-risk visibility and governance readiness
  • Implemented Microsoft Fabric / Power BI governance and controlled user enablement
Power Platform & M365 Administration
  • Set up, configured, and manages Power Platform access for the online Sales CRM including user access administration, service-health review, and operational support
  • Tenant administration across Entra ID, Exchange Online, SharePoint, OneDrive, and Teams
EU Cyber Resilience Act (CRA) Compliance ProgrammeSolo ownership — Active, Sept 2026 deadline

Sole owner of the CRA compliance programme covering EU customer markets.

SBOM Analysis
  • Component-level SBOM analysis of a production .NET component set (201 NuGet components, CycloneDX 1.7)
  • Active CVEs with CVSS severity scoring; third-party dependency and compliance risks
  • Identified end-of-support component risk, third-party SDK compliance considerations, and legacy component visibility gaps not fully detected by standard scanning tools
Dependency-Track Deployment
  • Deployed Dependency-Track on Ubuntu 24.04 LTS via Docker with PostgreSQL and nginx reverse proxy
  • Azure DevOps pipeline integration for automated SBOM ingestion and ongoing vulnerability monitoring
Article 14 CSIRT Readiness
  • Designed vulnerability disclosure workflow and CSIRT notification procedures
  • Researched EU authorised representative options and documented readiness considerations for CRA compliance planning
  • 13-folder evidence repository aligned to December 2027 full CRA conformity deadline
Framework Control Mapping
  • Built a sanitised control-mapping workbook linking example identity, vulnerability-management, data-protection, incident-response, backup/DR, supplier, infrastructure, secure-development, and customer-assurance controls to EU CRA readiness themes, ISO/IEC 27001:2022 Annex A, NIST CSF 2.0, and SOC 2 Trust Services Criteria
  • Used status, maturity, evidence-sensitivity, risk-addressed, and gap-tracking fields to avoid overclaiming certification, audit completion, or formal compliance attestation
Hybrid Identity Architecture & Microsoft 365 MigrationActiveDocs Ltd
  • On-premises Active Directory to hybrid Microsoft 365 / Entra ID transition: design, implementation, and ongoing administration
  • Directory synchronisation setup and validation; enterprise app registrations; Conditional Access policy design; MFA enforcement
  • Exchange Online migration: mailboxes, mail flow, recipients, and email security configuration
  • SharePoint Online and OneDrive migration with content governance controls
  • Dynamics 2016 to Dynamics 365 and Power Platform CRM transition
  • Ongoing hybrid identity operational administration and access troubleshooting
ADFS/Kerberos SSO Incident ResponseProduction incident
Root Cause
  • Windows Server cumulative-update encryption changes affected legacy Kerberos authentication behaviour for an ADFS-dependent service path
  • ADFS token issuance failed across SSO-dependent services until the affected service-account configuration and encryption attributes were corrected
Resolution
  • Root-caused through ADFS event-log analysis, Kerberos error review, and service-account attribute validation
  • Affected services migrated to a corrected dedicated service account with appropriate encryption attributes
  • SSO restored; preventive controls documented and implemented
Azure DevOps Server & Code-Signing ContinuityActiveDocs Ltd
  • Owns and administers Azure DevOps Server for the production software build and release pipeline
  • Resolved high-volume code-signing constraint supporting thousands of signatures per day
  • Evaluated DigiCert and Sectigo EV certificate options and associated enterprise-tier costs
  • Implemented USB-over-network hardware token signing path for the Hyper-V-hosted DevOps Server VM
  • Maintained full build workflow continuity while avoiding materially higher enterprise signing costs
  • Reviewed Azure DevOps Server licensing and supportability constraints to maintain compliant, cost-effective build-platform operations
Co-location Infrastructure & Perimeter SecurityActiveDocs Ltd
  • Designed and led full infrastructure migration from on-premises office to co-location datacenter: provider evaluation, rack layout, physical deployment, and operational handover
  • Sophos Firewall implementation, policy design, IPS, web/application/email controls, and zero-day protection
  • Sophos RED configured for dual-WAN failover; MikroTik Router deployed for main office and branch office
  • Routing, switching (Aruba, Cisco), VLAN, and NAT topology design and implementation
  • Controlled migration with rollback planning, post-migration validation, and ongoing perimeter security operations
Server & Platform Modernisation ProgrammeActiveDocs Ltd — Multi-year
Server, Hypervisor & Hardware Lifecycle
  • Managed multi-generation Dell PowerEdge platform lifecycle including R710 to R730XD to R740XD to R650-class production hardware refreshes, covering migration planning, workload movement, validation, rollback awareness, and post-migration operational support
  • Deployed and maintained Hyper-V / Windows Server virtualisation platforms across 2016, 2019, 2022, and 2025 generations, supporting production, DR replica, and test workloads
  • Managed Windows Server Standard and Datacenter lifecycle across supported Microsoft versions, including file server, domain controller, application, database, management, and supporting infrastructure workloads
  • Modernised domain controller estate from Windows Server 2008 through later supported generations including 2012, 2016, 2019, and 2022
Messaging, Collaboration & Business Platforms
  • Managed Exchange Server lifecycle from Exchange 2013/2016/2019 through Exchange Server Subscription Edition planning and transition readiness, alongside Exchange Online and Microsoft 365 hybrid administration
  • Modernised SharePoint platform from SharePoint 2013/2019 toward SharePoint Online, supporting content migration, access control, governance, and user transition requirements
  • Supported Microsoft Dynamics / CRM transition from on-premises CRM to Dynamics 365 / CRM Online, including platform administration, access management, and operational support
  • Managed business-support platform transition from FogBugz / Manuscript to Freshdesk, including service transition, user enablement, and operational handover
Endpoint, Security & Communications Platform Lifecycle
  • Managed ESET endpoint security lifecycle from earlier ERA / ESMC platforms through current ESET PROTECT operations, including upgrades, endpoint policy administration, operational monitoring, and coexistence with Defender for Endpoint P2 in passive mode
  • Managed communications platform evolution from Cisco PABX and Cisco VoIP phone administration through Zoom Phone adoption, covering voice-platform support, user readiness, device/service transition, and ongoing operational administration
  • Maintained software currency and upgrade readiness across Microsoft partner-aligned infrastructure and business platforms, requiring recurring review of supported versions, renewal impacts, licensing considerations, security posture, compatibility, and operational change planning
Monitoring, Backup & Recovery OperationsActiveDocs Ltd
  • SCOM deployment and operational health monitoring across the full infrastructure stack
  • Veeam backup platform administration across production and DR environments
  • Daily restore verification checks, failed-job review, and escalation procedures
  • Hyper-V passive replica management on DR host; ongoing replication health monitoring
  • Disaster recovery readiness testing, DR documentation, and rollback-aware maintenance planning
Norrcom Ltd (MSP) — Auckland Education Infrastructure Projects (2015 – 2017)
Google Workspace to Office 365 MigrationsSenior Project Engineer — Multiple schools
  • Auckland college environment (1,000+ users): Full Google Workspace to Office 365 migration — email, calendar, documents, and user account readiness
  • Auckland intermediate school environment (700+ users): Full Google Workspace to Office 365 migration with post-migration support and handover documentation
  • Account readiness validation, data migration execution, and ongoing-administration handover
Windows Server, Domain Rebuilds & Hyper-V P2V MigrationsSenior Project Engineer — Multiple schools
  • Auckland college and primary school environment (600+ users): Physical-to-virtual server migration (Windows Server 2012 R2); school administration package migration
  • Auckland intermediate school environment (700+ users): Windows Server 2008 to 2012 R2 migration
  • Auckland primary school environment: Windows Server 2008 to 2016 migration (700+ users); domain controller and full domain rebuild (500+ users)
  • MDT, WDS, and SCCM used for Windows 7/8/8.1/10 mass deployment across primary schools and colleges
School Network Upgrade Projects — SNUP & WSNUPTechnical Engineer

Delivered government-funded School Network and Wireless School Network Upgrade Projects across multiple Auckland schools.

  • College (1,000+ users) & Primary School (600+ users) — SNUP: 20 Allied Telesis switches, 55 Ruckus access points; switching, routing, VLAN, and wireless configuration
  • Primary School (200+ users) — WSNUP: 18 Aerohive access points with full wireless network configuration
  • Intermediate School (700+ users) — WSNUP: 23 Ruckus access points with full wireless network configuration
  • Papercut Print Management Software: primary, secondary, and sandbox server configuration in a 1,000+ user school environment
Apple iOS Administration, MDM & Endpoint Security DeliverySenior Project Engineer — Multiple schools
Apple iOS & iPad Administration
  • Deployed and administered Apple iPad fleets across school environments of 500–1,000+ users, managing the full device lifecycle from configuration and enrolment through policy enforcement and troubleshooting
  • Configured Cisco Meraki MDM for Apple iOS supervised device management: DEP enrolment, configuration profile creation, app deployment via volume purchasing, content filtering, and policy enforcement across iPad fleets
  • Lightspeed MDM deployment and ongoing management for iOS and Android device administration across primary schools and colleges
  • iOS hardware troubleshooting: fault diagnosis, restore and reset procedures, enrolment recovery, and connectivity issue resolution
  • App catalogue administration: app deployment, update management, restriction enforcement, and user support across large-scale iOS environments
Endpoint Security & Backup
  • Deployed Symantec SEPM and ESET Remote Administrator across primary schools and colleges; validated endpoint security policy enforcement and client application deployment
  • Deployed Veeam and ShadowProtect backup solutions across multiple school environments
Security Investigation
  • Investigated and traced policy-breaching network activity (Tor Browser, unauthorised tools) to specific devices and users; produced remediation documentation
H&T IT Development Pte. Ltd. (MSP) — Singapore Multi-Client Infrastructure (2013 – 2015)
Multi-Client Infrastructure, Hosted Services & Incident Response~30 client environments across Singapore

Primary on-site and remote engineer for approximately 30 Singapore client environments across Finance, Shipping, Logistics, Hotel, Pharmaceuticals, Automobile, Food & Beverage, and Manufacturing industries.

Infrastructure & Platform
  • VMware ESXi, Windows Server 2003/2008/2012 R2, Exchange 2010, Office 365, SQL Server, VPN, NAS, CPanel/Hosting
  • SonicWall, Cisco, Fortinet firewall administration; routing, switching, and network maintenance
  • DNS, domain, SSL/TLS certificate management, and hosted-service dependency administration across Cloudflare, GoDaddy, and upstream providers
Email Security & Incident Response
  • Blacklist and reputation investigation and remediation; SPF/DKIM configuration; spam-delivery and email-flow troubleshooting across multi-industry client environments
  • After-hours urgent support and vendor/provider escalation; incident documentation across approximately 30 concurrent client environments

Technical Labs & GitHub Portfolio

github.com/janice-aliten/security-control-mapping-template

Sanitised control-mapping workbook demonstrating an inventory-first approach across EU CRA readiness themes, ISO/IEC 27001:2022 Annex A, NIST CSF 2.0, and SOC 2 Trust Services Criteria. Includes 48 example controls across 10 domains, with risk addressed, evidence-sensitivity classification, status, maturity scoring, gap tracking, framework legend, and sanitisation log.

github.com/janice-aliten/cloud-devops-lab

GitHub Actions pipeline with Gitleaks secret scanning (full git history), Trivy IaC/container scanning for HIGH/CRITICAL findings on every push, Docker image build-and-push blocked on scan failure, and weekly Dependabot monitoring. Terraform lab validates AWS VPC, security groups, ECS cluster, and IAM task execution roles through CI without exposing credentials. Containerised FastAPI service with Prometheus metrics, Grafana dashboard, AppDown/restart-loop alert rules, deployment runbook, and incident-response scenario.

github.com/janice-aliten/sbom-lab

Sanitised real-world .NET SBOM analysis using CycloneDX, 201 NuGet components, CVE identification, compliance risk assessment, end-of-support component identification, and Dependency-Track integration for Azure DevOps pipeline. Findings report with remediation recommendations.

github.com/janice-aliten/linux-ops-lab

Linux administration, service management, user and permission administration, firewall and network configuration (nftables/iptables), log analysis, Nginx, and process/system monitoring with CI-validated broken/fixed service pairs and incident runbooks.

Technical Risk, Vendor Governance & Security Delivery

Owns technical delivery across infrastructure, security, Microsoft licensing, certificates, hardware, software, connectivity, backup, firewall, DNS, hosting, and cloud-service dependencies.

  • Performs needs analysis, solution research, quote and licensing review, cost/risk assessment, and management recommendation.
  • Implements approved solutions through controlled deployment, post-change validation, support escalation, renewal planning, and operational ownership.
  • Representative delivery areas include co-location datacenter transition, Sophos firewall and security-service operations, DigiCert/Sectigo code-signing certificate evaluation and hardware-token implementation, Microsoft licensing and entitlement review, SSL/TLS certificate lifecycle management, Veeam backup-platform coordination, DNS/hosting provider escalation, and reseller/service-provider coordination.
  • Balances technical suitability, operational risk, cost control, vendor supportability, and long-term ownership before implementation.

Additional Technical Depth

Data Analysis & Evidence Review

Completed a Graduate Diploma in Data Analysis while employed full time, building practical capability in Python, Pandas, NumPy, data cleaning, validation, exploratory analysis, dashboard outputs, and structured reporting. Applies this background to security and infrastructure work through evidence review, noisy-output investigation, vulnerability data interpretation, CVE and CVSS analysis, incident documentation, and operational decision support. Capstone project: AI-Driven Air Quality Forecasting System for Auckland CBD using machine-learning-based time-series modelling.

Digital Asset & Exchange Workflow Awareness

Maintains practical familiarity with digital-asset workflows across exchanges, wallets, exchange deposit and withdrawal flows, blockchain explorers, transaction-hash verification, token-contract review, network selection risk, and failed or pending transaction review. This adds practical domain fluency for security, trust-and-safety, platform-operations, and fintech or crypto environments where user-side risk, transaction verification, platform reliability, and abuse patterns need to be understood.

These areas complement the core profile: security, compliance, identity, data protection, vulnerability management, hybrid infrastructure, cloud-connected operations, and controlled technical delivery.

Certifications & Credentials

Qualys Specialist Certifications
Qualys TotalCloud — Cloud Security Posture ManagementCompleted June 2026 — expires June 2028
Active
Qualys KCS — Kubernetes & Container SecurityCompleted June 2026 — expires June 2028
Active
Qualys VMDR — Vulnerability Management, Detection & ResponseCompleted June 2026 — expires June 2028
Active
Qualys CSAM — CyberSecurity Asset ManagementCompleted June 2026 — expires June 2028
Active
Microsoft Applied Skills
Implement security through a pipeline using Azure DevOps
CompletedVerify →
Secure Azure services and workloads with Microsoft Defender for Cloud regulatory compliance controls
CompletedVerify →
Defend against cyberthreats with Microsoft Defender XDR
CompletedVerify →
Get started with identities and access using Microsoft Entra
CompletedVerify →
Microsoft Certifications
Microsoft Azure Administrator AssociateAZ-104 — Issued April 2024
Microsoft Certified Solutions Associate (MCSA)Issued April 2012
Microsoft Certified System AdministratorIssued June 2011
Microsoft Certified IT Professional (MCITP)Issued February 2011
Microsoft Certified Technology Specialist (MCTS)Issued January 2011
Microsoft Certified Desktop Support Technician (MCDST)Issued January 2011
Microsoft Certified Professional (MCP)Issued January 2011
Fortinet
Fortinet Certified Associate in Cybersecurity (FCA)
Fortinet Certified Fundamentals Cybersecurity (FCF)
CompTIA
CompTIA Network+Issued December 2010
CompTIA CySA+ — Cybersecurity Analyst+Study target: 2026
In preparation
Allied Telesis
Certified Allied Telesis Professional (CATP)Issued July 2016
Legacy
Certified Allied Telesis Technician (CATT)Issued July 2016
Legacy

Education

Graduate Diploma in Data Analysis, Level 7
New Zealand School of Education — Graduated July 2025 — Completed while employed full time
Capstone: AI-Driven Air Quality Forecasting System for Auckland CBD
Cybersecurity for IT Operations
New Zealand School of Education — Graduated June 2023 — Completed while employed full time
Bachelor of Science in Information Technology
Lyceum of the Philippines University — Graduated 2012 — Completed while employed full time
Diploma in Computer System Design and Programming
AMA Philippines — 2006