About me

I’m George Coldham — a Cloud Solution Architect at Microsoft in the Security Solution area, based in Perth (Western Australia). I help teams reduce real-world risk in SaaS and AI-heavy environments, where generative and agentic AI amplify normal human behaviour into security incidents. My work sits at the intersection of threat protection, identity, SaaS, data protection, and automation — with a strong preference for controls that actually survive contact with humans.

Focus areas

Generative AI Security Agentic AI Risk & Controls Microsoft Security Copilot AI Security Posture Management (AISPM) AI Threat Protection & Abuse Scenarios Prompt, Data & Model Risk Microsoft Entra (Identity) Microsoft Threat Protection Browser & Session Security SaaS Governance & OAuth Risk Microsoft Defender XDR Zero Trust Architecture Cloud Security Posture Management (CSPM)
George Coldham

What I do

Now

Cloud Solution Architect

Microsoft (ANZ)

Partner with enterprise scale organisations to design and improve security outcomes across threat protection, identity, data, devices and cloud. I focus on the modern control plane: OAuth consent, session/token abuse, unmanaged browsers, and how AI tools accelerate productivity but could enable risky behaviour.

Ongoing

Speaker & community organiser

Global Security Community · Perth Global AI Community · Perth Microsoft Security Meetup · Perth GitHub Meetup

I present locally and internationally on emerging security topics, helping practitioners understand how new technologies and AI change risk at scale. I also build and enable professional communities — either by bringing practitioners together directly, or by creating repeatable formats and resources that others can reuse to run sustainable communities.

Always

Builder mindset

Automation, demos, and “show me” security

I like security that you can prove. I build small tools and repeatable workflows (often using Microsoft-first approaches) to document configuration, detect drift, and turn tribal knowledge into something you can hand to the next person without a two-hour meeting.