$ whoami

Andrew Conlin

IT & Security Professional

> ▋

Michigan-based IT and security professional working across Microsoft 365, Azure, and security operations — rooted in SOC and blue team work, focused on cloud security engineering.

scroll ↓

01.About Me

I'm Andrew Conlin, a Michigan-based IT and security professional who works across Microsoft 365, Azure, and security operations. My background is rooted in SOC and blue team work, with deep hands-on experience in Entra ID and hybrid Active Directory, Exchange Online, Intune, and Cortex XDR.

I'm focused on cloud security engineering — building things like Conditional Access as code, Sentinel/KQL detection pipelines, and identity attack labs, which I document here and on GitHub.

I learn by building, and I'm always looking for the next hard problem to dig into.

Security Operations

SOC and blue team work — incident response, threat detection, and building Sentinel / KQL detection pipelines.

Identity & Cloud

Entra ID and hybrid Active Directory, Conditional Access as code, and identity attack labs.

Microsoft 365 & Endpoint

Exchange Online, Intune endpoint management, email security, and Cortex XDR.

02.Skills & Tooling

Incident Response
Threat Detection
Email Security
Exchange Online
PowerShell
Python
Microsoft Entra ID
Identity & Access
Endpoint Management
ITSM & RMM
Information Security
Networking

04.Certifications & Education

Full Stack Web Developer

Wozniak University

Completed

AZ-104: Microsoft Azure Administrator

Microsoft

In progress

05.Resume

Want the full picture?

Download my resume for a complete breakdown of my experience, roles, and accomplishments across IT and security operations.

↓ Download Resume

06.Get in Touch

I'm always open to connecting about security operations, cloud engineering, or the next hard problem worth digging into. Reach out — my inbox is open.