// IAM / Cloud Security Engineer
Guillermo Cabanellas
I design identity and access systems that make least privilege the default across Entra ID, AWS, and the messy hybrid in between.
// Selected work
Enterprise Entra ID Lab
A full-fidelity Entra ID tenant modeling enterprise identity: hybrid sync, Conditional Access, PIM, and break-glass procedures.
Zero Trust IAM for a Hybrid Cloud
Conditional access and least-privilege identity across Entra ID and AWS for a 2,000-person SaaS company.
Okta → Entra ID Workforce Migration
Consolidated two identity providers after a merger and migrated 120+ SSO apps with zero unplanned downtime.
Zero Trust Proxmox Architecture
A homelab Proxmox cluster rebuilt around Zero Trust principles: identity-aware access, micro-segmentation, and no implicit trust between tiers.
OPNsense Segmented Network
Multi-VLAN home/lab network with strict inter-segment policy on OPNsense — workstation, lab, IoT and DMZ tiers, each with explicit allow rules.