Jürgen Waldl

Jürgen Waldl

Lead Architect - Security @ base-IT GmbH

📍 Austria 🇦🇹

Ich unterstütze Unternehmen dabei, widerstandsfähige Sicherheitsarchitekturen im Microsoft-Ökosystem aufzubauen - von Identity über Detection bis Response.

Helping organizations build resilient security postures across the Microsoft ecosystem - from identity to detection to response.


Über mich

Ich bin Jürgen Waldl, Lead Architect für Security bei der base-IT GmbH in Österreich. Mit über 15 Jahren Erfahrung in der IT - davon der Großteil im Security- und Netzwerkumfeld - unterstütze ich Unternehmen zwischen 250 und 15.000+ Mitarbeitern dabei, ihre Microsoft-Infrastruktur wirklich sicher zu machen.

Mein Weg in die Security war kein geradliniger: Vom IT-Systemadministrator über den Network & Security Architect bis hin zum CISO-Agenden-Verantwortlichen bei einem internationalen Industriekonzern - ich habe die Herausforderungen auf allen Ebenen erlebt. Heute fließt diese Praxiserfahrung direkt in meine Consulting-Arbeit und in diesen Blog ein.

Mein Fokus liegt auf Entra ID, Active Directory Security, Microsoft Sentinel, Defender XDR und Azure Security - immer mit dem Ziel, reale Bedrohungen zu adressieren statt Compliance-Checklisten abzuhaken.

Ausbildung & Zertifizierungen

🎓 Studium

2014 – 2018
B.Sc. IT Security (berufsbegleitend)

FH St. Pölten

📜 Zertifizierungen

CCNP R&S CCNA Security ZScaler ZCCA-IA ITIL Foundation Meraki CMNA Checkpoint CCSA

Karriere-Highlights

2022 – heute

Lead Architect Security - base-IT GmbH

Microsoft Security Consulting: Sentinel, Defender XDR, Entra ID, Defender for Cloud. Architektur & Konzeption für Enterprise-Kunden.

2018 – 2022

Security Architect & Teamleitung - POLYTEC Holding AG

Aufbau ISMS & TISAX-Vorbereitung, globales SDWAN-Rollout, Zero-Trust Firewalling, Identity Management, CISO-Agenden. Fachliche und personelle Führung eines 6-köpfigen Infrastrukturteams.

2016 – 2018

Senior Architect & Teamlead - base-IT GmbH

Enterprise Network & Security Projekte: 802.1x Rollouts, PKI-Aufbau, Firewall-Migrationen, WLAN-Infrastruktur für internationale Kunden.

2008 – 2016

IT Systems & Network - Wacker Neuson / Dimension Data

Die Grundlagen: Systemadministration, Netzwerkbetrieb, Routing & Switching, Field Engineering bei internationalen Kunden.

Focus Areas

🔐

Entra ID & AD Security

Identity Governance, Privilege Escalation Prevention, Conditional Access Hardening, Hybrid AD Security.

☁️

Azure Security

Cloud Posture Management, Tenant Hardening, Workload Identity Security, Zero Trust Architecture.

🔍

Microsoft Sentinel

Detection Engineering, KQL Query Development, Threat Hunting, SIEM Optimization.

🛡️

Defender XDR

Extended Detection & Response, Incident Investigation, Threat Intelligence, SOC Operations.

🎤

Speaker & Community

Ich teile mein Wissen regelmäßig auf Konferenzen und Community-Events. Auf meinem Sessionize-Profil findest du aktuelle und vergangene Sessions rund um Microsoft Security, Threat Detection und Identity Protection.

→ Sessionize-Profil ansehen

Dieser Blog

whennotif• ist der Ort, an dem ich Findings aus der Praxis, Detection-Queries, Fehlkonfigurationen und hands-on Security-Guidance aus Enterprise-Projekten teile. Kein Marketing. Kein Buzzword-Bingo.

Jeder Beitrag basiert auf realen Szenarien, die mir in der Praxis begegnet sind - anonymisiert und in umsetzbare Inhalte verwandelt.

About Me

I'm Jürgen Waldl, Lead Architect for Security at base-IT GmbH in Austria. With over 15 years of experience in IT - most of it in security and networking - I help organizations with 250 to 15,000+ employees truly secure their Microsoft infrastructure.

My path into security wasn't a straight line: From IT Systems Administrator to Network & Security Architect to CISO responsibilities at an international industrial corporation - I've experienced the challenges at every level. Today, this hands-on experience flows directly into my consulting work and this blog.

My focus is on Entra ID, Active Directory Security, Microsoft Sentinel, Defender XDR, and Azure Security - always with the goal of addressing real threats rather than ticking compliance checkboxes.

Education & Certifications

🎓 Education

2014 – 2018
B.Sc. IT Security (part-time)

University of Applied Sciences St. Pölten

📜 Certifications

CCNP R&S CCNA Security ZScaler ZCCA-IA ITIL Foundation Meraki CMNA Checkpoint CCSA

Career Highlights

2022 – present

Lead Architect Security - base-IT GmbH

Microsoft Security Consulting: Sentinel, Defender XDR, Entra ID, Defender for Cloud. Architecture & design for enterprise customers.

2018 – 2022

Security Architect & Team Lead - POLYTEC Holding AG

Built ISMS & TISAX preparation, global SDWAN rollout, Zero Trust firewalling, Identity Management, CISO responsibilities. Technical and personnel leadership of a 6-person infrastructure team.

2016 – 2018

Senior Architect & Team Lead - base-IT GmbH

Enterprise Network & Security projects: 802.1x rollouts, PKI setup, firewall migrations, WLAN infrastructure for international customers.

2008 – 2016

IT Systems & Network - Wacker Neuson / Dimension Data

The foundations: Systems administration, network operations, routing & switching, field engineering for international customers.

Focus Areas

🔐

Entra ID & AD Security

Identity Governance, Privilege Escalation Prevention, Conditional Access Hardening, Hybrid AD Security.

☁️

Azure Security

Cloud Posture Management, Tenant Hardening, Workload Identity Security, Zero Trust Architecture.

🔍

Microsoft Sentinel

Detection Engineering, KQL Query Development, Threat Hunting, SIEM Optimization.

🛡️

Defender XDR

Extended Detection & Response, Incident Investigation, Threat Intelligence, SOC Operations.

🎤

Speaker & Community

I regularly share my knowledge at conferences and community events. On my Sessionize profile you'll find current and past sessions on Microsoft Security, Threat Detection and Identity Protection.

→ View Sessionize profile

This Blog

whennotif• is where I share real-world findings, detection queries, misconfigurations, and hands-on security guidance from enterprise engagements. No marketing. No buzzword bingo.

Every post is based on actual scenarios I've encountered in the field - anonymized and turned into actionable content.