IT Infrastructure & Cloud Security Engineer

Securing the Modern Workspace

Identity, Endpoint, & Data Security

Empowering organizations through robust Microsoft 365 security architectures, zero-trust implementation, and comprehensive threat defense utilizing Sophos and Entra ID frameworks.

Raphael Omisore Profile

Professional Summary

Raphael is an IT Infrastructure & Cloud Security Engineer specializing in securing hybrid environments using Microsoft 365 and Sophos solutions. His work focuses on implementing Zero Trust principles across identity, endpoints, and data to strengthen organizational security posture.

He has hands-on experience with Identity and Access Management (Entra ID), endpoint protection, and data security using Microsoft Purview (DLP, Insider Risk Management, Information Protection). He is skilled in designing and managing secure, scalable infrastructure while improving threat detection and response capabilities.

Technical Arsenal

Cloud Architecture

  • Microsoft 365
  • Microsoft Entra ID
  • Exchange Online

Security & IAM

  • Endpoint Security
  • Zero Trust & IAM
  • Information Protection
  • Threat Detection & Response

Networking & Access

  • Sophos Firewalls
  • VPN Architectures
  • IPS/IDS Configuration
  • Routing & Switching

Tools & Platforms

  • Microsoft Intune (MDM/MAM)
  • Microsoft Purview
  • Microsoft 365 Defender
  • Sophos Central
  • Windows Server & AD DS

Certifications

Microsoft Certified
Identity and Access Management (SC-300)
Sophos Certified
Endpoint Protection Engineer (ET-15 v5.0)
Sophos Certified
Endpoint Protection Engineer (ET-15 v6.0)
Sophos Certified
Endpoint Technician (S15 v6.0)
Sophos Certified
Endpoint Protection Architect (AT-15)

Featured Implementations

Microsoft 365 E5 Security Suite Deployment & Threat Protection Implementation

Problem Statement

The organization faced increasing security risks across identity, endpoints, cloud applications, and email systems. Users were vulnerable to phishing attacks, compromised credentials, anonymous IP access, and unauthorized cloud application usage. There was limited centralized visibility, no automated threat response, and security controls were fragmented across the environment.

Objective

To design and implement a unified security architecture using Microsoft 365 E5 Security solutions, enabling end-to-end protection, threat detection, and automated response across identity, endpoints, email, and cloud applications.

Implementation Workflow

Identity Security (Defender for Identity)
  • Integrated on-prem Active Directory with Defender for Identity
  • Detected suspicious login behavior including anonymous IP activity
  • Monitored identity-based threats and privileged account misuse
Endpoint Security (Defender for Endpoint)
  • Onboarded endpoints into Defender for Endpoint and EDR capabilities
  • Configured attack surface reduction (ASR) rules
  • Performed threat investigation and remediation
Email Security (Defender for Office 365)
  • Configured Safe Links, Safe Attachments, & Anti-Phishing policies
  • Set up Attack Simulation Training for phishing awareness
  • Enabled Automated Investigation and Response (AIR)
Cloud App Security (Defender for Cloud Apps)
  • Discovered shadow IT and monitored cloud application usage
  • Investigated risky sign-ins and applied conditional access app enforcement

Impact / Results

  • Achieved centralized visibility across identity, endpoint, email, and cloud environments via Microsoft 365 Defender portal.
  • Improved detection of advanced threats including phishing and credential compromise.
  • Reduced response time through automated investigation and remediation.
  • Strengthened overall security posture aligned with Zero Trust principles.
Defender for Endpoint Defender for Office 365 Defender for Identity Defender for Cloud Apps M365 Defender Portal Entra ID (Conditional Access)

Unified Threat Management Migration

Problem: Disparate AV solutions across global branches causing alert fatigue and missed localized ransomware threats.

Solution: Rolled out Sophos Central with Intercept X across 300+ endpoints. Configured synchronized security with Sophos Firewalls to automatically isolate compromised nodes.

Outcome: Achieved 100% unified visibility into endpoint health and automated threat isolation, reducing incident response time to seconds.

Sophos Central Intercept X Sophos Firewall

Data Loss Prevention (DLP) Initiative

Problem: Absence of structured classification for PII and IP, risking regulatory non-compliance during email transmission and external sharing.

Solution: Implemented Microsoft Purview Information Protection, creating auto-labeling policies for sensitive data across Exchange Online and SharePoint.

Outcome: Prevented data exfiltration incidents, ensured regulatory compliance, and provided comprehensive data flow auditing.

Purview Exchange Online DLP

Enterprise Network Security & Sophos Firewall Deployment

Problem: Enterprise environments had poorly structured networks, weak perimeter security, and limited visibility, failing to meet regulatory requirements.

Solution: Redesigned network architecture, deployed Sophos Firewall for perimeter protection, optimized routing and APs, and aligned with CBN compliance.

Outcome: Strengthened security and access control, improved network performance, enhanced traffic visibility, and supported regulatory compliance readiness.

Sophos Firewall Network Architecture VLANs Wireless Optimization

Professional Experience

May 2024 – Present

IT Infrastructure, Support & Security Specialist

Lotus Beta Analytics Nigeria Ltd.
  • Implemented Microsoft Purview solutions including Data Loss Prevention (DLP), Insider Risk Management, and Information Protection.
  • Designed and deployed endpoint security using Sophos Endpoint Protection and Microsoft security solutions.
  • Configured and managed Sophos Firewall (VPN, IPS, Web Filtering).
  • Administered Microsoft 365 (Exchange Online, Entra ID), including identity and access management.
  • Conducted security assessments, incident response, and vulnerability remediation.
  • Delivered security demonstrations to clients, translating technical solutions into business value.
  • Designed secure hybrid infrastructure aligned with Zero Trust principles.
  • Provided technical support across servers, endpoints, networks, and cloud services.
Feb 2023 – May 2024

Data Collection Assistant

Crownshield Nigeria Limited
  • Assessed construction sites for regulatory and safety compliance.
  • Defined and documented data collection standards for engineering teams.
  • Coordinated submissions to Lagos State Material Testing Laboratory.
  • Compiled and analyzed inspection reports for decision-making.
Jan 2022 – Jan 2023

ICT Instructor (NYSC)

De-Genius Olivet Schools
  • Improved student engagement using interactive and gamified teaching methods.
  • Enhanced student performance through structured assessments.
  • Managed ICT lab environment and enforced proper computer usage standards.
Oct 2019 – Sept 2021

Network Technician

Information Technology & Communications Unit, OAU
  • Maintained network documentation including cabling and configurations.
  • Troubleshot connectivity issues across multiple subnets.
  • Supported users and optimized network performance.
  • Mentored interns and supported team coordination.
  • Implemented basic network security measures to reduce vulnerabilities.

Educational Background

2018 – 2021

HND (Distinction) – Computer Engineering

Federal Polytechnic Ede, Osun State

Cybersecurity Training & Mentorship

Empowering the Next Generation of Defenders

Beyond implementing security architectures, I am passionate about elevating the industry's baseline knowledge. I coach a cybersecurity cohort on fundamental and advanced cybersecurity concepts, fostering hands-on technical skills and real-world implementation techniques.

Microsoft Defender for Endpoint

Guided students through endpoint protection concepts including threat detection, attack surface reduction, and real-world security scenarios.

Sophos Endpoint Protection

Conducted interactive workshops covering endpoint agent deployment, behavioral policy tuning, and ransomware mitigation tactics.

Let's Connect

Ready to secure your infrastructure? Let's discuss your next project.

© Raphael Omisore. All rights reserved. Designed with focus on Security & Aesthetics