Cloud & cloud-security engineer based near Zurich 🇨🇭. I work day-to-day across Azure platform engineering and cloud security, with a focus on Microsoft Entra ID, identity & RBAC, and Azure infrastructure-as-code. I build small, read-only tools that solve a real problem, test them against live tenants, and write them up at simonvedder.com.
Identity & security
- Least Privilege Studio — find the right least-privilege Azure RBAC role and generate the assignment.
- App Lifecycle Analyzer — read-only lifecycle audit of Entra ID app registrations (secrets, certs, federated creds, sign-in activity) in one HTML report.
Azure automation & cost
- Azure VM Power Management — tag-driven start/stop for Azure VMs; schedule power with an
AutoShutdowntag. - Terraform Secrets — rotate Terraform-provisioned VM credentials via Key Vault + Automation, no plaintext in state.
- Azure VM Self-Service Order — self-service VM / AVD ordering via a web form (Logic App + Queue + Function App).
AI on Azure
- Aria — RAG on Azure AI Foundry — enterprise RAG chatbot on Azure AI Foundry with private networking.
- Microsoft Entra ID · RBAC · least privilege · identity security
- Terraform / Bicep / ARM · PowerShell · Azure Policy
- Monitoring, landing zones, and secure-by-default Azure infrastructure
- Blog: simonvedder.com
- LinkedIn: linkedin.com/in/simon-vedder