EMPLOYED AT SPIRHED
I design and operate Microsoft security.
At Spirhed, I work with Microsoft Sentinel, Defender XDR and Entra ID for Norwegian organisations. The work covers architecture, implementation, detection and response.
- Microsoft Sentinel
- Defender XDR
- Entra ID
- Security operations

WHAT I DO
Design is only the start.
- 01 / DESIGN
Architecture and technical pilots
I design Microsoft security environments and run technical pilots before a broader rollout. The tools include Sentinel, Defender XDR, Entra and Intune.
- 02 / OPERATE
Detection and response
I write KQL detections, investigate hybrid environments and hunt threats. The result should be a response the team can explain and defend.
- 03 / EVOLVE
Identity and MDR operations
I connect identity controls, multi-tenant operations and service design so monitoring still works after the initial project ends.
PRIOR ROLE AT CRAYON
I built Crayon's MDR service from zero.
The work covered the offering, onboarding and multi-tenant operations.
PERSONAL WORK
I also publish what I can.
I publish and maintain the Microsoft Security Newsfeed and technical notes on this site. The custom detection validator is also personal work. All three are separate from delivery through Spirhed.
The CV has the full record.
My security consulting is delivered through Spirhed. The CV contains my role history, certifications and technical scope.