IT Analyst focused on infrastructure automation, endpoint management, hybrid identity, and cybersecurity.
I build production-oriented tools for Microsoft environments, with an emphasis on safe automation, least privilege, observable operations, and reversible deployments. My current work spans Windows Server, Active Directory, Microsoft Entra ID, Intune, PowerShell, Python, Linux infrastructure, APIs, monitoring, and internal business systems.
I am currently studying Systems Analysis and Development and developing deeper expertise in cybersecurity, cloud identity, and endpoint security.
- Microsoft Intune and enterprise endpoint management
- Active Directory and Microsoft Entra hybrid identity
- PowerShell automation and Windows administration
- Python APIs, operational dashboards, and monitoring
- Linux servers, virtualization, backup, and observability
- Security engineering, least privilege, and controlled rollout design
| Project | Description | Engineering focus |
|---|---|---|
| DeviceLifecycle | PowerShell automation for identifying, reporting, quarantining, and removing stale devices across Active Directory, Microsoft Entra ID, and Intune. | Identity correlation, safe state transitions, bounded actions, auditability, recovery |
| DeviceLifecycle-API | Read-only FastAPI extension that securely publishes the latest DeviceLifecycle reports, logs, metadata, and health information. | API design, authentication, stable file reads, network restrictions, operational integration |
| WallpaperAgent | Windows agent that retrieves a versioned manifest, validates assets with SHA-256, and applies desktop and lock-screen images through Intune-managed deployment. | Privilege separation, content integrity, atomic promotion, endpoint packaging, rollback |
| RustDeskIntuneDeployment | PowerShell workflow for deploying and configuring RustDesk through Microsoft Intune in self-hosted environments. | Win32 application deployment, multi-profile configuration, detection, server trust, rollout governance |
- Fail safely: missing or ambiguous data must not trigger destructive actions.
- Automate with limits: privileged operations require explicit scope, thresholds, and action caps.
- Design for recovery: quarantine, rollback, diagnostics, and audit trails are part of the implementation.
- Separate responsibilities: machine context, user context, publishing systems, and consumers receive only the access they require.
- Document operational reality: architecture, deployment, security boundaries, and failure modes are treated as part of the product.
I am expanding from infrastructure and automation into cybersecurity, with particular interest in:
- identity and access security;
- endpoint security and hardening;
- security monitoring and incident response;
- secure automation and infrastructure engineering;
- cloud and hybrid-environment security.
- Portuguese: native
- English: advanced
Most projects in this profile are based on real operational problems, and maybe some personal projects I'd like to share. Organization-specific identifiers, credentials, addresses, certificates, and other sensitive information are removed or replaced before publication.


