// About

Background

Guillermo Cabanellas — IAM / Cloud Security Engineer.

I build and secure Identity & Access Management systems at the intersection of cloud, infrastructure and automation. My focus is Microsoft Entra ID, Zero Trust architectures, and the operational tooling around them.

Over the past several years I've led identity-provider migrations, replaced standing privilege with just-in-time access, and rolled out conditional access across hybrid Entra ID and AWS estates — the kind of work that has to be aggressive about least privilege without locking 2,000 colleagues out of production.

I work like an engineer who writes everything down — diagrams first, policies as code, and decisions documented. This site is the living index of my labs, automation work and case studies. When I'm not in a policy editor I write about the unglamorous half of IAM — deprovisioning, lifecycle, and the audit trail — on the blog.

Focus

Identity & Access

Domain

Cloud · Hybrid

Approach

Docs · Diagrams

Automation

  • Microsoft Graph API
  • PowerShell
  • Python
  • Terraform
  • Bicep
  • Ansible

Security

  • Conditional Access
  • PIM
  • Zero Trust
  • MFA / FIDO2
  • SIEM (Sentinel)
  • Defender for Identity

CISSP

(ISC)²

SC-300 — Identity and Access Administrator

Microsoft

AWS Certified Security — Specialty

Amazon Web Services

CompTIA Security+

CompTIA

See projects Resume · PDF