Cloud fabric // nominal
OPEN TO CLOUD, IDENTITY & SECURITY ENGINEERING ROLES

Dhanush Velgonda. Cloud systems. Secure by design.

I work across Azure and AWS cloud operations, identity, security and infrastructure—spanning Entra ID, Microsoft 365, Linux, virtualisation, monitoring and backup. My current focus is secure identity, cloud security and practical automation.

// SYDNEY, AUSTRALIA  ·  AZURE  ·  AWS  ·  IDENTITY  ·  SECURITY  ·  INFRASTRUCTURE

CLOUD & IDENTITY CONTROL PLANE
azure.platformCONNECTED
aws.operationsMONITORED
identity.fabricENFORCED
AZURE // ADMIN
AWS // SYSOPS
LINUX // RHCSA
Scroll through the system
0+Years cloud & infrastructure
0Active certifications
0Portfolio projects published
IdentityPrimary engineering focus

01 // Cloud operations

Infrastructure across cloud, systems and recovery.

I have supported production infrastructure across Azure and AWS, Linux and Windows servers, VMware environments, cloud migrations, monitoring, vulnerability remediation and backup and recovery.

SELECTED PRODUCTION EXPERIENCEMULTI-CLOUD + HYBRID
VMware environmentVirtual workloads and on-premises infrastructure
AWS migrationServer movement, validation and service continuity
Cloud operationsEC2, S3, IAM and CloudWatch support
ResilienceMonitoring, Veeam backup and recovery checks
AzureCloud administration

Azure platform support, Azure Virtual Desktop troubleshooting and identity-connected services.

AWSOperational cloud experience

EC2, S3, IAM, CloudWatch and infrastructure migration support in production environments.

SystemsLinux and virtualisation

Linux, Windows Server, VMware, patching, vulnerability remediation and operational troubleshooting.

ContinuityBackup and disaster recovery

Veeam-backed resilience, recovery validation and continuity-focused infrastructure operations.

02 // Identity control plane

Access is evaluated, not assumed.

Every identity request moves through context, policy, risk and session controls. Scroll to run an access decision through the gateway.

CURRENT EVALUATIONAwaiting identity signal
Identity confidencePENDING
Device compliancePENDING
Sign-in riskPENDING
Session controlsPENDING
SESSION
RISK
DEVICE
IDENTITY
REQUEST
ACCESS DECISIONGRANTED // POLICY PASS

03 // Project constellation

See what each system actually does.

Select a project node to open a plain-English visual walkthrough: the problem, how the system works, what was built and why it matters.

SELECT ANY NODE // OPEN VISUAL STORY

NODE // 01

Zero Trust Landing Zone

A visual Azure lab showing how identity checks and policy guardrails reduce risky access.

TerraformEntra IDCA
NODE // 02

Manage-UserLOA

A safer way to pause employee access during leave and restore it without losing the original state.

PowerShellADEXO
NODE // 03

Security Triage Playbooks

Repeatable investigation maps that help analysts decide whether an alert is harmless or needs escalation.

KQLSentinelDefender
NODE // 04

Ryuk Memory OS

A privacy-first AI memory design where untrusted information cannot become permanent without human approval.

Local-firstAI governance
FLAGSHIP

Zero Trust Landing Zone

See how identity, device and risk checks protect company applications.

TerraformEntra ID
PUBLIC REPO

Manage-UserLOA

See how employee access is paused safely and restored after leave.

PowerShellIdentity lifecycle
PRODUCTION PRACTICE

Security Triage Playbooks

See how a raw alert becomes an evidence-based decision.

KQLSecurity operations
R&D

Ryuk Memory OS

See how human review prevents unsafe AI memory writes.

Privacy-firstAI governance
LIVE SIGNAL ROUTINGILLUSTRATIVE SIGNAL FLOW
USER SIGNALsign-in + device
ENTRA IDidentity context
DEFENDERendpoint context
SENTINELcorrelation
PURVIEWdata activity
RESPONSEcontain + escalate

04 // Security operations

Signals become decisions.

I investigate identity, endpoint and collaboration activity across Defender, Sentinel, Purview and CrowdStrike—then turn the reasoning into repeatable playbooks.

Previously unseen IP + anomalous sign-inINVESTIGATE
MFA denial + authentication method changeESCALATE
SharePoint activity after risky sessionCORRELATE
Containment + session revocation validationRESPOND

05 // Capability stack

Five domains. One operating model.

Cloud infrastructure provides the platform. Identity controls access. Workplace services enable users. Security monitors activity. Automation makes operations repeatable.

Cloud & Infrastructure

Production experience
  • Azure & AWS operations
  • EC2, S3, IAM & CloudWatch
  • Linux, Windows Server & VMware
  • Backup, recovery & resilience

Identity & Access

Primary focus
  • Entra ID & hybrid AD
  • Conditional Access
  • IAM lifecycle
  • SSO administration

Modern Workplace

Production experience
  • Microsoft 365
  • Intune & Autopilot
  • Exchange Online
  • Endpoint compliance

Security Operations

Production experience
  • Defender
  • Sentinel & Purview
  • CrowdStrike
  • Incident response & escalation

Automation & Engineering

Current focus
  • PowerShell & Microsoft Graph
  • KQL investigation workflows
  • Terraform & infrastructure as code
  • Git & GitHub workflows

06 // Credentials

Certified across cloud, identity, Linux and security.

Microsoft, AWS, Red Hat and cybersecurity credentials complementing hands-on infrastructure and operations experience.

SC-300

Identity & Access Administrator

MICROSOFT // IN PROGRESS

MD-102

Endpoint Administrator Associate

MICROSOFT // ACTIVE

AZ-104

Azure Administrator Associate

MICROSOFT // ACTIVE

SOA-C02

AWS SysOps Administrator Associate

AWS // ACTIVE

RHCSA

Red Hat Certified System Administrator

RED HAT // ACTIVE

ISC2 CC

Certified in Cybersecurity

ISC2 // ACTIVE

07 // Operator profile

Production operator. Architecture mindset.

I work across cloud infrastructure, identity, endpoint and security operations: Azure, AWS, Entra ID, hybrid Active Directory, Microsoft 365, Linux, virtualisation, Defender, CrowdStrike and incident escalation.

My strongest current focus is the identity layer, but the work sits inside a broader infrastructure context—platform reliability, monitoring, migration, backup, recovery and operational risk.

Outside the day job, I publish projects that make that thinking inspectable: identity lifecycle automation, a Terraform-based Zero Trust lab, security triage workflows and privacy-first AI architecture.

I use AI selectively for research, iteration and code refinement while retaining ownership of architecture, validation, testing and final implementation decisions.

dhanzlabs://operator
dhanz@labs:~$ whoami
Cloud Identity & Security Engineer
dhanz@labs:~$ cat focus.txt
Azure · AWS · Entra ID · security · automation
dhanz@labs:~$ cat principles.txt
least privilege · safe automation · visible proof
dhanz@labs:~$ systemctl status dhanzlabs
● active (running) // Sydney, NSW
dhanz@labs:~$

PROJECT VISUAL STORY

01

The problem

02

What I built

03

Why it matters

04

Design approach

Open repository

08 // Secure channel

Connection authorised.

Open to cloud infrastructure, identity, Microsoft 365 and security engineering opportunities in Sydney.