~/samuel-agyei-tuffour — zsh
whoami.sh
$ whoami
Zero Trust Architect // IAM Automation Engineer
$ cat ./summary.txt
MSc Cybersecurity. Expert-level Microsoft certified (SC-100, AZ-500). Design and enforce enterprise-wide Zero Trust architecture, build custom IAM platforms with Python / Django / Graph API, and automate compliance evidence generation for ISO 27001 / HIPAA.
$ ./connect --with samuel
base Rotterdam, NL
phone +31 6 30 74 69 33
status open to roles
# about

// what I do

I sit where security architecture meets software engineering. I design Zero Trust controls, then write the code — Python, Django, Microsoft Graph API, Logic Apps — that actually enforces them. The point: take slow, manual security work and turn it into code that runs itself and scales.

At Hunt&Hackett I rolled out enterprise-wide Zero Trust with Conditional Access, PIM, and Entra ID Governance, built a custom IAM automation platform that cut access-review effort by 25%, and automated audit evidence so nobody had to take screenshots by hand anymore.

compliance_frameworks.txt 1 KB
ISO 27001
HIPAA
NIS2
DORA
soft_skills_languages.txt 1 KB
Technical Stakeholder Management Problem Solving Collaboration
English — Fluent Dutch — Learning
committed to conversational Dutch within a year
# expertise

// core competencies

🛡 Architecture & Identity
// zero trust from design to enforcement
Zero Trust (MCRA) Entra ID PIM Conditional Access FIDO2 Lifecycle Workflows IAM Governance
Cloud Security
// microsoft 365 + azure, defender-grade
Microsoft Defender for Cloud Intune Purview Azure Policy
Automation & SecOps
// from reactive to engineered
Python Django Microsoft Graph API Logic Apps (SOAR) Google SecOps Carbon Black
📋 Compliance
// audit-ready, evidence on tap
ISO 27001 HIPAA NIS2 DORA
# experience

// git log --oneline career.log

feat(iam): scale zero trust to enterprise a7f3e21
Jan 2025 – Present
SecOps Engineer
Hunt&Hackett · The Hague, Netherlands
  • Architected enterprise-wide Zero Trust policies using Conditional Access, PIM, and Entra ID Governance, enforcing least-privilege across all cloud workloads.
  • Built a custom IAM automation platform with Django and Graph API, replacing manual employee lifecycle access reviews and reducing operational effort by 25%.
  • Deployed passwordless authentication (YubiKey) and Intune-managed workspaces, reducing identity-related risk metrics by 15%.
perf(soc): tune detections, cut noise c91bb04
Jan 2024 – Dec 2024
SOC Engineer
Hunt&Hackett · The Hague, Netherlands
  • Improved detection efficiency by 12% through rule tuning and playbook optimization, reducing false positives by 20%.
  • Kept a 24/7 watch on the SIEM — triaging alerts, digging into real incidents, and escalating what mattered.
  • Built and ran the shift rota, making sure every hour of the day had someone monitoring.
init: security foundation for the enterprise 3e0c8d5
Feb 2021 – Aug 2023
IT Security Engineer
SevenX · Kigali, Rwanda
  • Ran internal security audits that surfaced real vulnerabilities, then pushed the fixes through to completion.
  • Owned access control and identity provisioning across the company, keeping day-to-day operations running without added overhead.
  • Trained 30+ colleagues on security basics, and compliance with policy genuinely improved afterwards.
# projects

// build log — featured

grurpID production

A JML (joiners, movers, leavers) automation platform for managing employee account lifecycles and access end-to-end.

ExitScan production

Automates employee offboarding and detects orphaned cloud accounts, revoking access across downstream apps after departure.

AuditVault production

Automates ISO 27001 evidence collection from identity logs, turning raw access data into auditor-ready evidence packs.

# education

// academic.log

🎓
MSc Cybersecurity
National Forensic Sciences University · India
🎓
BSc (Hons) Computer Science
PDM University · India
🎓
Diploma, Telecommunication Engineering
Ghana Communication Technology University
🧠
Systemic Design
Digital Society School · Netherlands
connect.sh
$ ./initiate-contact
select a channel to open:
$