1234
ABC
DRG. NO. IAM-2026 · SCALE 1:1 · REV C
Gabriel Zehnder — Senior IAM Engineer

Identity,
engineered.

Rev C

Senior IAM Engineer moving deliberately into security architecture. I build from identity outward — how access is granted, endpoints are trusted, data is protected, and threats are caught.

IAMTRANSITION · 2024 → NOWSECURITY
Entra IDConditional AccessIntuneMicrosoft DefenderExchange Online ProtectionMicrosoft PurviewAzure AutomationCIS ControlsISO 27001NIS2Detection & Response
D-01 · FOUNDATION

Identity

Every identity authenticated with phishing-resistant MFA, authorized to least privilege, and provisioned from a single source of truth — human and non-human alike. Get this layer right and everything above inherits its discipline.

D-02

Endpoint

Every device in a known, compliant state before it touches a resource — hardened, patched, encrypted, monitored. Device health becomes a condition of access, and the point where most compromise actually lands.

D-03

Data

Classified by sensitivity, then discovered, labeled, and protected across every platform. Protection travels with the file, so collaboration doesn't quietly become exposure.

D-04 · PIVOT

Detection & Response

Where controlling access turns into defending it — identity and endpoint signal into SIEM and XDR, threats triaged and contained, increasingly through automation. The layer I'm building toward.

What I've Built

Four systems, built end to end · details generalised
WK-01

Identity Lifecycle Management

Joiner, mover, leaver driven from a single HR source of truth — access granted on day one, recalculated the moment a role changes, revoked the moment someone leaves. The account never outlives the person.

Entra ID / HR-driven / Automated
IdentityRev B
WK-02

Security Baseline & Hardening

A tenant measured against CIS controls and brought to baseline — email protection, MFA, and Conditional Access hardened — with every deviation risk-assessed, documented, and backed by an audit-ready evidence trail.

M365 / CIS / Evidence
HardeningRev C
WK-03

Access Governance

Entitlements recertified on a fixed cadence — every grant re-justified by the business, not assumed permanent. Least privilege held as a reviewed state, with dormant and over-privileged access surfaced for action.

Entra ID / Access Reviews / Recertification
GovernanceRev B
WK-04

Identity-Driven Detection

Identity, endpoint, and email signal correlated into one response flow — risky sign-ins, phishing, and behavioural anomalies feeding SIEM and XDR, with triage and containment automated to cut response time. Built from the ground up, end to end.

SIEM & XDR / UEBA / Automated Response
DetectionRev A · ●

Trajectory — IAM → Security Architecture

PHASE 01

Built The Function

Identity from zero — no directory, no lifecycle, no controls. Assessed what mattered, set the priorities, and built the foundation the rest of the stack now stands on.

PHASE 02

Hardened The Stack

Endpoint, email, and data brought under measured control — prioritised by risk, aligned to CIS, and backed by evidence. Each layer hardened in the order that reduced exposure fastest.

PHASE 03 · NOW

Crossing Into Detection

Extending from identity into full-stack detection and response — signal correlated across the environment into SIEM and XDR. Controlling access becomes defending it.

PHASE 04

Architecture & Ownership

Designing the standards, not just running them — owning the whole posture by design. The architect role the work has been building toward.

Principle

Note 01

Security isn't a setup you finish; it's a collection of controls that shrink the attack surface, and a plan for the breach you know is coming. But identity is the foundation beneath all of it — get identity right, and every layer above inherits the visibility, framework, and trust that make it worth defending.

Contact

Project
GABRIEL ZEHNDER — IAM → SECURITY
Location
COPENHAGEN, DK
Focus
SECURITY ARCHITECTURE
Rev
C