Consultant (Solution Architecture & Security Delivery)
My formal title is Consultant. In practice the work is solution architecture and security delivery: I am the sole architect and administrator across the whole Azure and Microsoft 365 estate of an Australian financial services licensee, an AFSL and ACL holder. I am employed by AppGenie and contracted to that client rather than billing them directly.
The estate was neglected when I arrived. No documented configuration standard existed, and work already done showed no apparent rationale, so repair came before uplift. Everything below is remediation of a neglected estate followed by the establishment of a standard.
- Architected an end-to-end Microsoft Defender XDR to Azure telemetry pipeline, running at roughly A$160 a month for the full monitored estate.
- Reduced Azure run-rate by approximately 81 per cent, from about A$1,826 to about A$340 a month, around A$18,000 annually.
- Cut privileged directory role assignments on the primary administrative account from 97 to 5.
- Raised tenant Microsoft Secure Score to 77.8 per cent against a 53.7 per cent all-tenant average.
- Replaced a credentialled deployment model with an Azure DevOps pipeline authenticating through Workload Identity Federation, closing a cleartext credential exposure.
- Authored an integrated compliance manual adding 13 policies across the IT, cyber and privacy layer, alongside an 18-sheet risk and control register.
- Wrote AI guidelines and an LLM usage register, then implemented AI usage policies in Microsoft Purview so the standard is enforced and not merely declared.
- Rethought the client’s business continuity and disaster recovery plans to cover the estate as actually rebuilt.
- Diagnosed a tenant-wide external file-sharing failure to a Microsoft platform change, verified independently against the vendor’s published change record before acting.