Portfolio — IT Infrastructure & Industry AnalysisBad Homburg, Germany

Daokun Cao

 
20+
Years in IT
0→1
Greenfield Builds
10
Certifications
EnglishProfessionalDeutschProfessional中文Native
01

About

I own IT end-to-end for the German subsidiary of a global automotive group — from infrastructure architecture and Microsoft 365 governance to Zero Trust security and data-centre planning. I have built complete IT environments from nothing, and I am at my best turning operational friction into structured, scalable systems.

From that same seat I also write — long-form analysis on what the Chinese auto industry's push into Europe actually looks like at the operational layer: dealer DMS to factory ERP, residual-value to leasing risk, homologation to OTA. One track builds the systems; the other reads them. The vantage is the same.

MBA · Zhejiang UniversityB.E. in Electronic Information Engineering · Xiangtan UniversityExchange Program in Economics · CAU zu Kiel
03

Selected Work

Projects spanning infrastructure delivery, security, and internal software.

01New Office IT Infrastructure

2025–26

IT project lead for a 1,700 m² headquarters fit-out — server-room layout, structured cabling, VLAN segmentation, firewall zoning, and vendor coordination. Plan optimisation cut direct costs by over €30,000. On-site implementation in progress; acceptance targeted for June 2026.

Network ArchitectureVLAN DesignVendor ManagementProject Lead

02CRM Germany Localisation

2026

Local delivery lead for the German rollout of a global CRM (HQ + Deloitte programme) — SSO integration, EU-side GDPR DPIA, system integration, training, and cutover, plus defining the post-go-live L1 support boundary.

CRMSSOGDPR / DPIASystem Integration

03Internal Business Application Suite

2025–26

Designed and built five internal applications from scratch for a greenfield subsidiary — fleet, property, IT assets, service desk, and knowledge management — replacing manual coordination with structured digital workflows.

Web AppREST APIAutomationInternal Tooling

04Zero-Touch Endpoint Deployment

2025

Automated Windows 11 provisioning via Microsoft Autopilot and Intune with GroupTag-based device scoping. New devices ship directly to employees and self-configure — cutting manual deployment effort by over 70%.

Microsoft AutopilotIntuneEntra IDPowerShell

05M365 Identity & Security Baseline

2025

Zero Trust posture across identity and endpoints — enforced MFA, Conditional Access (geo / device / risk), Defender for Endpoint, silent BitLocker with key escrow, and a break-glass strategy, with incident reporting to the CISO.

Entra IDConditional AccessDefenderBitLocker

06ERP / WMS Integration Tool

2023

Automated data synchronisation between ERP and WMS systems for a logistics operation, eliminating manual entry and reducing labour costs by 25% while supporting 200+ tickets annually.

PythonAPI IntegrationSQLAutomation

07This Portfolio Website

2026

A full-stack personal portfolio with password-protected interview profiles, dynamic routing, and JWT-based authentication — self-hosted on a managed VPS.

Next.js 16TypeScriptTailwind CSSVPS
04

Core Expertise

  • 01IT Infrastructure Ownership
  • 02Microsoft 365 Architecture (Entra ID, Intune, Autopilot)
  • 03Security Governance & Zero Trust Implementation
  • 04VLAN & Network Segmentation Design
  • 05Identity & Access Management (RBAC, MFA, Conditional Access)
  • 06Endpoint Security & Compliance (Defender, BitLocker)
  • 07Infrastructure Project Management (PMP)
  • 08Vendor Coordination & Technical Approval
  • 09Cross-border IT Governance