06/20/2026 updated

**** ******** ****
100 % available

Azure Security Architect | Zero Trust | Microsoft Sentinel | Identity & Access Management

Znojmo, Czech Republic
Only remote
Master's degree (Ing.), IT Security - Brno University of Technology, FEEC (2023-2025)
Znojmo, Czech Republic
Only remote
Master's degree (Ing.), IT Security - Brno University of Technology, FEEC (2023-2025)

Profile attachments

CV_Hrabalek_EN.pdf

Microsoft AzureNetwork SecurityAzure Active DirectoryAzure AutomationMicrosoft SentinelDevSecOps
Microsoft Azure Security Architecture
Expertise in designing and implementing end-to-end cloud and hybrid security architectures on Microsoft Azure, including Zero Trust models, network security (microsegmentation, Azure Firewall, WAF, NSGs), and compliance with NIS2, DORA, and PSD2 regulations.

Microsoft Sentinel & SIEM/SOAR
Expert-level proficiency in Microsoft Sentinel, including designing and deploying Sentinel environments from scratch, creating custom KQL detection rules, building Azure Logic App playbooks for automated incident response (SOAR), and implementing Sentinel-as-Code via Azure DevOps.

Identity & Access Management (IAM)
Deep knowledge of Identity and Access Management using Microsoft Entra ID (PIM), including handling complex identity incidents, PKI and IAM support, and implementing sensitivity labels and DLP policies in Microsoft Purview.

DevSecOps & Infrastructure-as-Code
Proficiency in DevSecOps practices including secure CI/CD gating, secret scanning, Defender for Containers and APIs, container hardening, and Infrastructure-as-Code using Terraform, Terragrunt, Policy-as-Code, and Entra-as-Code.

Threat Modelling & Risk Management
Application of threat modelling methodologies (STRIDE, DREAD) and risk management frameworks, including maintaining Risk Registers and developing incident response runbooks for scenarios such as identity compromise, data breach, DDoS, and malware.

Microsoft Defender XDR & Endpoint Security
Advanced endpoint threat investigation and response using Microsoft Defender XDR and CrowdStrike Falcon, including phishing response, escalation, and DDoS mitigation using NetScout Arbor.

Monitoring & Detection
Implementation of monitoring and detection solutions using Microsoft Sentinel, Azure Monitor, and Application Insights, as well as proactive threat hunting with tools such as FlowMon and GreyCortex MENDEL.

Compliance & Regulatory Frameworks
Knowledge and practical application of regulatory frameworks including NIS2, DORA, and PSD2, as well as security governance in regulated environments.

Azure AI & Automation
Integration of Azure AI agent capabilities and AI-assisted incident triage, as well as automation of security workflows using Logic Apps and SOAR platforms.

Languages

GermanGoodEnglishFluent

Project history

Cloud Security Engineer

Direct Fidoo
Azure Security Architect building a Zero Trust, NIS2/DORA/PSD2-compliant cloud platform from the ground up in Microsoft Azure. Responsibilities include implementing Zero Trust security models, network security (microsegmentation, Azure Firewall, WAF, NSGs), DevSecOps (secure CI/CD gating, secret scanning, Defender for Containers and APIs, container hardening), Infrastructure-as-Code (Terraform, Terragrunt, Policy-as-Code, Entra-as-Code), Azure AI agent integration, AI-assisted incident triage, monitoring and detection (Microsoft Sentinel, Azure Monitor, Application Insights), and incident response runbooks including threat modelling (STRIDE, DREAD) and security governance.

Cybersecurity Consultant

Seyfor Cloud & Security
Microsoft security consultant delivering Sentinel implementations and security engineering for 10+ enterprise clients. Designed and deployed Microsoft Sentinel environments from scratch with custom KQL detection rules, built Azure Logic App playbooks for automated incident response (SOAR), implemented Sentinel-as-Code via Azure DevOps, managed multi-tenant integration with Azure Lighthouse, optimized Sentinel cost and detection efficiency, and handled sensitivity labels and DLP policies in Microsoft Purview with analyst support during active incidents.

Cybersecurity Analyst, Senior

Deutsche Telekom
L3 SOC support for an external enterprise customer in a cross-border, multi-tenant environment. Handled complex identity incidents including PKI and IAM support, and conducted advanced endpoint threat investigation via Microsoft Defender XDR, including phishing response and escalation.

Cybersecurity Analyst, Senior

T-Mobile Czech Republic
Senior member of the enterprise SOC team responsible for threat detection, incident response, and platform optimization. Conducted incident investigation in Microsoft Sentinel, endpoint response via Defender XDR and CrowdStrike Falcon, DDoS mitigation using NetScout Arbor, and CrowdStrike Falcon detection and configuration optimization.

Cybersecurity Analyst

VISITECH a.s.
L1 SOC analyst performing proactive threat hunting using FlowMon and GreyCortex MENDEL, and conducting incident investigation in AlienVault and IBM QRadar SIEM.

Certificates

SC-100

Microsoft

2025

SC-300

Microsoft

2025

CySA+

CompTIA

2025

AZ-500

Microsoft

2024

SC-200

Microsoft

2024

PenTest+

CompTIA

2024


Contact form

Log in to get in touch

You need to be logged in to use the contact form.

Sign upLog in