interested in cloud, identity & security
Darwin
Marmolejos
I like figuring out how things work.
I work in IT, mostly on the support side. Day to day that's troubleshooting, helping people, and keeping things running — and in my own time I'm usually building something or picking up a new tool in the cloud and security space.
# who
name: Darwin Marmolejos
role: Technical Support Engineer
focus: [ cloud, identity, endpoint ]
# stack
cloud: Azure · Entra ID · Intune
iac: Terraform · Azure Policy
certs: Network+ · AZ-900 · AWS CCP*
status: always learning
Project
Enterprise Cloud Security
Identity, endpoints & email — provisioned as code
A hands-on Azure lab that ties together identity, endpoint management, email security, and centralized monitoring — all provisioned as code with Terraform and documented decision-by-decision across four repos.
- Provisioned governance, identity groups, RBAC, and monitoring as Infrastructure as Code (azurerm / azuread).
- Conditional Access, PIM for just-in-time admin, and least-privilege RBAC across a 15-user, 5-department tenant.
- Windows 11 endpoints with Intune compliance baselines — BitLocker, Defender, firewall.
- Hardened the email domain against spoofing with SPF, DKIM, and DMARC — validated with alignment testing and header analysis.
github.com/Darewiin/enterprise-cloud-security-portfolio →
Documented across 4 linked repositories
What I work with
Skills
identity & access
Entra IDActive DirectorySAML/OIDC SSO
MFAConditional AccessPIMRBAC
cloud & iac
Microsoft AzureTerraformAWS
Azure PolicyLog Analytics
endpoint
IntuneJAMF ProWindows 11
BitLockerMicrosoft 365
networking & security
TCP/IPDNSVLANs
SPF/DKIM/DMARCWireshark
support & scripting
ZendeskPowerShellPythonBash
Credentials
Certifications
CompTIA Network+
Earned · Dec 2025
Microsoft Azure Fundamentals (AZ-900)
Earned · Jun 2026
AWS Cloud Practitioner
In progress · Jul 2026
TestOut Ethical Hacker Pro
Earned · May 2025