Public technical portfolio · Germany-focused · AI + Cloud Security Operations

AI automation for IT, cloud security operations, and agentic workflows.

A public technical portfolio concept: 14 years of infrastructure and systems experience, repositioned around Hermes/OpenClaw-style agents, Microsoft 365/Azure security, Copilot readiness, identity hardening, and practical automation that runs on a VPS through Telegram.

hermes-secops-agent / private VPS
$ run daily_m365_security_readiness
collect: Entra ID policy checklist, risky consent controls
inspect: SharePoint/Copilot readiness questions
generate: public-safe executive summary
! flag: manual tenant verification required before client use

agent.pipeline
├─ Telegram intake + notifications
├─ local memory / Obsidian-style notes
├─ Azure/M365 security checklist automation
├─ FinOps / GenAI cost-control module
└─ human approval gates for sensitive actions

positioning: senior IT infra + cloud security + AI agent operations
Not “AI chatbot”.Positioned as an operations layer: agents, memory, checklists, evidence, notifications, and safe handoffs.
Not pure DevOps.Anchored in real IT infrastructure, Windows/M365/Azure, identity, endpoint, support, VMware/labs, and troubleshooting.
Germany technical positioning.Targets Cloud Security Operations, AI Automation Engineer, M365/Azure Security, Infrastructure Automation, and Copilot Readiness roles.

Two portfolio angles, one coherent story.

Use Angle A for enterprise infrastructure/security audiences. Use Angle B for AI-forward teams, startups, and automation-heavy cloud/security roles.

Angle A — Enterprise Cloud Security Ops

Lead with Microsoft 365/Azure security, identity hardening, Copilot readiness, Zero Trust, Conditional Access, and operational checklists.

M365AzureEntra IDSecOps

Angle B — Hermes/OpenClaw-style Agent Operations

Lead with a 24/7 AI automation layer: VPS agent, Telegram interface, local memory, sub-agents, watchdogs, and human approval gates.

HermesAgentsTelegramVPS

Angle C — Hybrid AI Infrastructure

The strongest combined positioning: senior infra engineer who can make agentic automation reliable, auditable, and safe for IT/cloud operations.

Hybrid cloudFinOpsAutomationReliability

Flagship case study: Hermes SecOps Copilot.

A public-safe case study title. It sounds enterprise-relevant without exposing private implementation details.

Problem

  • Cloud/security teams drown in repetitive checks: identity, consent, mailbox rules, Copilot readiness, exposed management paths.
  • AI tools are useful but fragile without memory, auditability, operational guardrails, and human approvals.
  • The portfolio needs proof of current AI automation capability, not just years of infrastructure experience.

Solution architecture

A private Hermes/OpenClaw-style agent running on Linux VPS, reached via Telegram, backed by local memory and structured runbooks. The portfolio version demonstrates the operating model; client/tenant execution requires explicit authorization.

INPUT
Telegram / portfolio prompt / checklist request
AGENT
Hermes orchestration + sub-agent tasks
MEMORY
Local notes, evidence, decisions, reusable runbooks
SECURITY
Human approval gates for sensitive actions
MODULES
M365 readiness, FinOps, cloud posture checks
OUTPUT
Executive summary, risk list, next actions

Security operations themes for technical portfolios.

These are concrete enough for technical review and broad enough to fit Germany roles.

M365 / Azure security automation

Identity hardeningConditional Access, MFA posture, risky sign-ins, user consent restrictions, privileged access questions.
Copilot readinessSharePoint permissions, oversharing, Purview labels, DLP, data exposure risk before AI rollout.
Security visibilityDefender for Cloud/Sentinel posture questions, mailbox compromise checks, canary-token style detection ideas.
Cost and reliabilityFinOps and GenAI cost-control reminders, Azure OpenAI deployment cost gates, VPS/agent monitoring.

Agent operations discipline

Persistent interfaceTelegram-first access for quick operational prompts and alerts.
Local memoryMarkdown/Obsidian-style memory to avoid multi-day context drift and preserve decisions.
Safe autonomyHuman approval before irreversible actions, tenant changes, credential use, or outreach.
Evidence-oriented outputReadable summaries, artifacts, blockers, and implementation locations rather than vague AI responses.