IAM / Identity Security practitioner. I build hands-on labs in live tenants, document what breaks, and publish the evidence.
- U.S. Air Force veteran
- 🔐 TS/SCI cleared
- 🎓 M.S. Cybercrime Investigation · B.S. Criminal Justice
- 📍 San Antonio, TX
Certifications · Okta Certified Professional · CompTIA Security+ (SY0-701) · Microsoft SC-300 (in progress)
Two hands-on lab repositories, built in live tenants against a simulated defense contractor environment:
| Repository | Platform | Focus |
|---|---|---|
| entra-id-labs | Microsoft Entra ID | Conditional Access, PIM, SAML SSO, entitlement management, identity governance, PowerShell + Graph API automation |
| Okta-Labs | Okta | User lifecycle, profile and attribute mapping, RBAC, Org2Org federation, SCIM provisioning |
Every lab starts from a business requirement, gets implemented end to end, and is validated with evidence — sign-in logs, audit records, raw SAML assertions, or structured JSON artifacts. Each one documents what broke and why the design decision went the way it did.
Recent highlights:
- Measured a 2m41s exposure window in a manual offboarding, then closed it to 0.463s with a PowerShell + Graph API runbook
- Caught a user who would have been locked out tenant-wide, using report-only Conditional Access staging
- Traced
AADSTS501241to a claim transformation on an empty source attribute — a failure that kills the entire SAML assertion, not just the claim
🔐 Identity governance & entitlement management 🔐 Privileged access (PIM / just-in-time) 🔐 Federation — SAML 2.0, OIDC, SCIM 🔐 Identity lifecycle automation (Microsoft Graph API, PowerShell) 🔐 Zero Trust access architecture
IAM Analyst / Identity Security Engineer supporting enterprise or federal environments — with an interest in ICAM programs where clearance and identity governance intersect.