Cloud & cloud-security engineer based near Zurich π¨π. I work day-to-day across Azure platform engineering and cloud security, with a focus on Microsoft Entra ID, identity & RBAC, and Azure infrastructure-as-code. I build small, read-only tools that solve a real problem, test them against live tenants, and write them up at simonvedder.com.
Identity & security
- Least Privilege Studio β find the right least-privilege Azure RBAC role and generate the assignment.
- App Lifecycle Analyzer β read-only lifecycle audit of Entra ID app registrations (secrets, certs, federated creds, sign-in activity) in one HTML report.
Azure automation & cost
- Azure VM Power Management β tag-driven start/stop for Azure VMs; schedule power with an
AutoShutdowntag. - Terraform Secrets β rotate Terraform-provisioned VM credentials via Key Vault + Automation, no plaintext in state.
- Azure VM Self-Service Order β self-service VM / AVD ordering via a web form (Logic App + Queue + Function App).
AI on Azure
- Aria β RAG on Azure AI Foundry β enterprise RAG chatbot on Azure AI Foundry with private networking.
- Microsoft Entra ID Β· RBAC Β· least privilege Β· identity security
- Terraform / Bicep / ARM Β· PowerShell Β· Azure Policy
- Monitoring, landing zones, and secure-by-default Azure infrastructure
- Blog: simonvedder.com
- LinkedIn: linkedin.com/in/simon-vedder