IDENTITY CONFIRMED

KELVIN VELDMAN

SECURITY / INFRASTRUCTURE / ARCHITECTURE

01 Security · Infrastructure · Architecture

KELVIN
VELDMAN

Security Officer. Infrastructure Architect. Practical Builder.

I turn complex IT environments into secure, workable systems.

Explore my work
System statusAll systems secure
Governance & risk
01User & accessMFA · SSO · RBAC
02Identity & securityPIM · CA · Policy
03Platform & servicesCompute · Data · Network
04InfrastructureHost · Virtualization · Backup
05OperationsMonitor · Automate · Respond
Telemetry & feedback
Data protection
01

Security leadership

Risk-aware strategy. Strong governance. Measurable outcomes.

02

Microsoft cloud & infrastructure

Architecture that is secure, resilient and built to scale.

03

MSP engineering

Practical systems and automation that make teams effective.

// OPERATING PRINCIPLE

Security only works when
people can work with it.

I connect strategy to implementation: from identifying risk and setting direction to configuring the platform, documenting the control and helping the team own it.

02 // CAREER LOG

Built from the
engine room up.

My route into security leadership runs through hands-on engineering. That means decisions stay grounded in how systems—and the people using them—actually behave.

JUN 2026 — NOW

Managed Service Provider

Security Officer

Setting the security direction for a growing MSP while staying close to engineering, architecture and operational reality.
Security strategyNIS2GovernanceZero Trust
2024 — MAY 2026

Westers Automatisering & Consultancy

Senior Network & Cloud Architect

Owned architecture choices and technical standards across networking, Microsoft 365 and Azure; led complex migrations, contributed to product development and guided engineers and interns.
ArchitectureTechnical leadershipProduct developmentStandards
SEP 2021 — 2024

Westers Automatisering & Consultancy

Network & Cloud Engineer

Worked across the full MSP stack: customer support, Microsoft cloud, Windows Server, networking, security, telephony, migrations and the stubborn issues that did not fit neatly into one product box.
All-round MSPMicrosoft cloudNetworkingInfrastructure
JUN 2019 — SEP 2021

Manetti IT

ICT All-round Engineer

Managed and troubleshot customer environments onsite and remotely, covering Windows Server, Microsoft 365, Exchange, Azure, VMware, networking, telephony, hardware lifecycle and monitoring.
Customer engineeringVMwareWindows ServerSolarWinds

03 // SELECTED WORK

Case files

Representative work, generalized to protect customer environments.

01M365 standardization

A security baseline designed to scale across 250+ tenants

Initiated and developed a standardized Microsoft 365 architecture spanning Conditional Access, compliance, device management, security controls and automated PowerShell deployment.

OUTCOME250+ tenants · Governance · Automation · Security maturity
02Network architecture

Designing multi-site infrastructure across 60+ locations

Designed and optimized scalable network environments using segmentation, routing, switching, secure VPN connectivity, firewalling and proactive monitoring.

OUTCOME60+ sites · BGP & OSPF · Segmentation · Secure connectivity
03Security programme

From inherited risk to a workable security roadmap

Mapped technical and process risks across endpoints, identities, networks and administrative access, then translated them into a prioritized improvement programme.

OUTCOMEIntune & Defender · Least privilege · Logging · Admin separation
04Security monitoring

Multi-tenant Microsoft 365 detection concept

Designed a monitoring approach for identity, file, mail and application activity, with actionable alerts for risky sign-ins, OAuth abuse and persistence techniques.

OUTCOMEIdentity · OAuth · Mail rules · Risk signals
05Microsoft 365 migrations

Moving 100+ customers from on-premises to Microsoft 365

Delivered customer migrations ranging from large, full on-premises cutovers to smaller hands-on transitions, then designed secure Microsoft 365-only foundations that customers could grow into.

OUTCOME100+ customers · Complex cutovers · Cloud-only foundations · Hands-on adoption
06Primary healthcare

Deep experience in Dutch first-line healthcare infrastructure

Supported and modernized infrastructure for primary healthcare organizations, where availability, secure access, specialized applications and reliable local operations directly affect patient-facing work.

OUTCOMEPrimary care · Specialized applications · Continuity · Secure operations

04 // CAPABILITY MAP

Where I operate

Broad enough to see the system. Deep enough to change it.

01

Security & governance

NIS2 readinessRisk & control designIncident responseZero TrustLeast privilegeSecurity roadmaps
02

Microsoft 365

Tenant architectureEntra IDConditional AccessIntune & AutopilotDefenderExchange OnlineTeams & SharePoint
03

Azure & hybrid cloud

Azure architectureHybrid identityRBACSecure networkingAVD & FSLogixCloud migrationsPowerShell deployment
04

Networking

CiscoFortinetMikroTikAruba & UbiquitiBGP & OSPFVPN & segmentationPacket analysis
05

Systems & MSP operations

Windows ServerActive DirectoryVMware & Hyper-VLinuxBackup & recoveryRMM toolingTelephony
06

Automation & improvement

PowerShellAPIsDockerMonitoringTechnical standardsProduct developmentProcess design

05 // PRODUCT KNOWLEDGE

The full
technical tree.

Search or explore the platforms, products and technical domains I have worked with throughout my MSP career.

103 knowledge nodes 23 visible
/m365

Microsoft 365

23 nodes
Architecture & governance5
  • End-to-end Microsoft 365 architecture
  • Standardized M365 baseline architecture
  • Security and governance frameworks
  • Tenant governance and lifecycle management
  • Compliance design
Baseline & standardization5
  • Security and configuration baselines
  • Conditional Access standardization
  • Compliance and device policies
  • PowerShell tenant deployments
  • Scalable multi-tenant management
Core services4
  • Exchange Online & hybrid mailflow
  • SharePoint Online & OneDrive
  • Microsoft Teams governance
  • Power Platform integrations
Identity & security4
  • Entra ID, IAM & RBAC
  • Zero Trust implementation
  • SOC / SIEM service development
  • Defender configuration & response flows
Endpoint management3
  • Microsoft Intune
  • Windows Autopilot
  • MDM & compliance policies
Innovation2
  • Microsoft Copilot governance
  • Security posture optimization

06 // CREDENTIALS

Built knowledge.
Proven practice.

A selected view of the technical education and certifications behind the hands-on experience.

012025

Certification

Fortinet NSE Level 1 & 2

Active
022021

Certification

MikroTik Certified Routing Engineer

Historical
032021

Certification

MikroTik Certified Network Associate

Historical
042019

Certification

ITIL v3

Active
052017 — 2020

LOI education

Server & Network Architect

Completed
062019

Technical education

System Engineer

Completed

07 // OUTSIDE THE RACK

A systems thinker,
even off the clock.

I’m a self-described geek from Lelystad who enjoys understanding how complicated things fit together. That shows up at work, but also in the worlds, games and small technical experiments I build for fun.

Direct, curious and practical: I like a difficult problem, honest communication and solutions that survive contact with reality.

01Dungeon Master

Complex systems, improvisation and bringing different personalities through one shared story.

02Game builder

Designing progression, balance and mechanics for long-running personal projects.

03Home-lab tinkerer

Linux, servers, Docker and Raspberry Pi projects—because learning rarely ends at 17:00.

04Competitive mindset

I enjoy mastery, iteration and the kind of challenge that makes the next attempt better.

AVAILABLE FOR A GOOD TECHNICAL CONVERSATION

08 // ESTABLISH CONNECTION

Have a complex environment
that needs clear direction?

Let’s talk security, architecture or the stubborn technical problem nobody has managed to untangle yet.