Workforce Identity
Lifecycle integrity, federation, authentication, access policy, entitlement governance and hybrid directory architecture.
15 years shaping how enterprise organizations secure, govern and scale identity. Across Fortune 500 firms, federal agencies and critical infrastructure, the work has always been the same at its core: make identity the thing that holds when everything else is under pressure.
The hardest problems in identity are rarely technical. The technical problems have answers. The hard problems are organizational: nobody owns the policy, the accountability structure was never defined, the exception became the rule, and by the time someone notices the debt is structural.
My value is in knowing how to walk into an environment where identity was built by ten different people over ten years and make it coherent, defensible, and owned.
Zero Trust is often used as a buzzword. In practice it is a posture you earn incrementally by making every access decision explicit and every privilege temporary. That is the difference between an organization that knows its exposure and one that finds out during an incident.
The most important work I do is translate. Technology decisions that are not understood by the people who fund them get defunded when priorities shift. Risk that is not legible to a CISO or a board does not get mitigated and usually ends up inherited by the next team. I own these programs end to end: governance, Zero Trust architecture, privileged access, federation, lifecycle management, and the CISO conversation that ties it all together. I can design the framework and I can also open a sign-in log and find what is breaking before it becomes an incident.
Lifecycle integrity, federation, authentication, access policy, entitlement governance and hybrid directory architecture.
JIT access, administrative trust, credential rotation, session controls, approval models and privilege reduction.
Service principals, API credentials, tokens, workload identity, secrets and lifecycle ownership for non-human identities.
Trust boundaries for AI agents, autonomous workflows and credentials that act without a human present at each decision.
Enterprise IAM leadership, technical escalation, governance design and executive communication across a complex multi-subsidiary environment.
Rebuilt accountability, privileged access, lifecycle integrity and authentication governance while keeping identity risk visible to senior leadership.
iHeartMedia entered a broad restructuring and cost-reduction period in 2026, including nationwide layoffs and a $50 million cost-savings program, alongside earlier merger discussions with SiriusXM. Source ↗
Worked across security architecture, identity and detection engineering in a federal-facing environment where design choices had to survive NIST controls, operational scrutiny and real incident conditions.
Zero Trust architecture, multi-cloud security design, privileged-access remediation, detection engineering and executive translation.
Reworked privileged access, standardized cloud controls, strengthened authentication and improved correlation across security platforms.
Reed Tech was folded more fully into LexisNexis Life Sciences Solutions, with the Reed Tech name retired as the businesses were consolidated under the LexisNexis brand, during a period that also included reported workforce reductions within Reed Tech. Source ↗
Led identity architecture in a retail environment where workforce scale, compliance, legacy access patterns and application modernization all had to move together.
Large-scale identity architecture, workforce lifecycle design, PAM, workload identity and access-governance experience in a high-volume retail environment.
Modernized hybrid identity, reduced standing privilege, improved access certification and removed static credentials from container workloads.
Kroger’s proposed $25 billion merger with Albertsons was blocked and terminated in December 2024, followed by broader restructuring, cost realignment and corporate workforce reductions affecting nearly 1,000 employees. Source ↗
Worked inside federal infrastructure where identity had to connect large numbers of systems while staying aligned to agency governance, FedRAMP requirements and formal security management practices.
Federal ICAM architecture, Zero Trust, governance, cloud migration and compliance discipline across distributed systems.
Connected more than 100 systems, advanced agency governance, implemented Saviynt and moved workloads into FedRAMP-authorized cloud architecture.
Combined vulnerability management, identity-aware cloud controls and authentication infrastructure with compliance needs that had to remain auditable under HIPAA and NIST expectations.
Risk prioritization, authentication infrastructure, cloud security and compliance work shaped by healthcare requirements.
Improved vulnerability prioritization, authentication resilience, privileged credential handling and certificate lifecycle control.
Took on privileged access in a regulated pharmaceutical environment where excessive access, standing privilege and inconsistent administrative practices needed a structured model.
PAM engineering, least-privilege design, adaptive access, compliance and executive risk communication.
Reduced excessive privilege, formalized JIT workflows, centralized privileged-account governance and strengthened endpoint protection.
Worked inside banking controls where identity decisions had to align with regulatory requirements while supporting cloud adoption, customer-facing authentication and large-scale lifecycle operations.
Risk-based IAM, hybrid cloud controls, regulated banking experience and customer-facing authentication design.
Strengthened continuous verification, standardized cloud identity controls, automated response and maintained reliable lifecycle operations.
Worked across multiple enterprise client environments where identity was often fragmented across legacy directories, cloud platforms, customer-facing applications and several identity providers. The role combined hands-on CIAM/IAM engineering with escalation ownership for federation failures, certificate issues, provisioning breakdowns and identity-data drift.
Enterprise CIAM and IAM engineering across hybrid environments, with deep troubleshooting responsibility for federation, certificate lifecycle, identity data integrity, cloud authentication and customer-facing access. Repeated exposure to fragmented estates built practical experience stabilizing environments with multiple identity providers, legacy dependencies and inconsistent lifecycle logic.
Designed Zero Trust IAM across Azure, GCP and Microsoft 365; reduced standing privilege by more than 70 percent; built certificate lifecycle processes across 100+ applications; led ForgeRock migration and workflow standardization; resolved Workday, Active Directory and Entra ID synchronization issues; delivered Auth0 customer authentication; implemented OAuth2/OIDC token lifecycle management; integrated IAM telemetry with Splunk and DevOps pipelines; served as escalation authority for SAML failures, authentication loops, certificate expirations and provisioning outages.
Led cloud security operations across AWS and hybrid environments during a period when cloud operating models were still being established. The work spanned identity architecture, federation, privileged access, vulnerability management, forensic investigation and SOC response, creating a broad systems view before identity became the primary focus of later roles.
Cloud security leadership across IAM, federation, vulnerability management, forensics, privileged access and active incident response. Built foundational controls in environments that needed security architecture, governance and operational processes established from the ground up, with responsibility spanning both preventive design and hands-on investigation.
Built AWS and hybrid security programs aligned to NIST 800-53 and ISO 27001; designed federation across Okta, Auth0 and SaaS platforms; led forensic investigations with formal chain-of-custody practices; scaled vulnerability management beyond 15,000 assets across AWS and Azure; optimized Entra ID Connect synchronization and UPN conventions; administered BeyondTrust Password Safe with JIT and change-management controls; supported SOC containment and investigation involving token misuse and privileged-session activity.
Started close to the user and the system. Hardware, software, networks, tickets and service levels taught the practical side of technology before architecture entered the picture.
Operational discipline, customer-facing troubleshooting, prioritization and documentation at the system level.
Built the service and troubleshooting foundation that later informed architecture and security work.
Identity-centered security operations spanning incident investigation, threat analysis, vulnerability management, data protection, privileged access, and emerging AI/NHI security controls.
Federated IAM and public-cloud identity work supporting a nuclear-energy environment with strong authentication, least privilege and privileged access requirements.
Municipal identity-security engagement focused on Active Directory hardening, identity threat detection and privileged-access discipline.
Short-term federal ICAM engagement centered on identity governance, privileged access and authentication controls.
Provisioning automation and identity technical-debt remediation across a large automotive retail environment spanning multiple organizations, including UK operations.
Directory and external-user authentication work focused on reliable federation, account flows and lifecycle support.