RONNIE BAILEY
Identity Security Architect

RONNIEBAILEY

Enterprise IAM◆ PAM◆ NHI◆ Zero Trust◆ Agentic AI Governance

15 years shaping how enterprise organizations secure, govern and scale identity. Across Fortune 500 firms, federal agencies and critical infrastructure, the work has always been the same at its core: make identity the thing that holds when everything else is under pressure.

Ronnie Bailey
Perspective

The hardest problems in identity are rarely technical. The technical problems have answers. The hard problems are organizational: nobody owns the policy, the accountability structure was never defined, the exception became the rule, and by the time someone notices the debt is structural.

My value is in knowing how to walk into an environment where identity was built by ten different people over ten years and make it coherent, defensible, and owned.

Zero Trust is often used as a buzzword. In practice it is a posture you earn incrementally by making every access decision explicit and every privilege temporary. That is the difference between an organization that knows its exposure and one that finds out during an incident.

The most important work I do is translate. Technology decisions that are not understood by the people who fund them get defunded when priorities shift. Risk that is not legible to a CISO or a board does not get mitigated and usually ends up inherited by the next team. I own these programs end to end: governance, Zero Trust architecture, privileged access, federation, lifecycle management, and the CISO conversation that ties it all together. I can design the framework and I can also open a sign-in log and find what is breaking before it becomes an incident.

Architecture scope
WORKFORCE

Workforce Identity

Lifecycle integrity, federation, authentication, access policy, entitlement governance and hybrid directory architecture.

Applied across iHeartMedia, Kroger, Wells Fargo, DHS/USSS and enterprise consulting environments.
PRIVILEGED

Privileged Identity

JIT access, administrative trust, credential rotation, session controls, approval models and privilege reduction.

BeyondTrust, One Identity Safeguard, TPAM, Entra PIM, Delinea and vault governance.
MACHINE

Machine Identity

Service principals, API credentials, tokens, workload identity, secrets and lifecycle ownership for non-human identities.

Enterprise NHI governance, AKS workload identity, service account controls and exposed-credential remediation.
AUTONOMOUS

Agentic Systems

Trust boundaries for AI agents, autonomous workflows and credentials that act without a human present at each decision.

Current focus: governance models for agentic access, tokens, delegation and machine-scale identity risk.
Professional experience

Enterprise IAM Program Director

30,000-user hybrid enterprise
iHeartMedia·06/2025 – 06/2026FULL-TIME
Leadership & Expertise

Enterprise IAM leadership, technical escalation, governance design and executive communication across a complex multi-subsidiary environment.

Initiatives Led

Rebuilt accountability, privileged access, lifecycle integrity and authentication governance while keeping identity risk visible to senior leadership.

Owned core identity security components across the enterprise IAM program for a hybrid workforce of more than 30,000 users spanning iHeartMedia, Katz Media Group, Triton Digital, Premiere Networks, and subsidiary brands across broadcast, ad-tech, syndication, and media representation.
Aligned security, IT, HR, and business stakeholders across a multi-subsidiary portfolio to drive identity maturity and risk reduction, establishing structured cross-functional communication between identity, SOC, and GRC teams that had historically operated in silos with limited coordination between them.
Defined and maintained the IAM ownership model and RACI framework, assigning policy ownership, formalizing escalation paths, and creating cross-functional accountability across security, engineering, and business teams that had previously managed identity-related responsibilities independently.
Directed Conditional Access strategy and enforcement across a 60-policy estate aligned to Zero Trust, governing controls that spanned biometric authentication, geofencing, device compliance, MFA enforcement, and risk-based access decisions across a workforce spanning broadcast operations, podcast production, digital ad-tech, and national advertising sales.
Managed Mobile Application Management and Microsoft Defender Cloud Security policies across the enterprise, extending identity-aware access controls and security enforcement beyond traditional perimeter boundaries across the full corporate portfolio.
Identified a persistent pattern of onboarding failures tied to gaps in conditional evaluation logic, including delayed start dates, mismatched HR status in Workday, and incomplete downstream system readiness. Designed and implemented decisioning and alerting logic in Azure Logic Apps that eliminated manual provisioning delays and brought the onboarding process into alignment with actual business workflows.
Re-established enterprise identity governance and lifecycle controls across HRIS-integrated systems after persistent data integrity failures were traced to UPN normalization conflicts between Workday attributes and downstream system expectations. The root cause had been producing silent provisioning breakdowns, dynamic group membership failures, and access control gaps across the environment. Resolved the conflicts and restored provisioning integrity and access governance across Entra ID and connected enterprise systems.
Defined and drove enterprise authentication and federation standards across critical business platforms including Workday, Genea, and GCP-integrated systems, resolving authentication failures involving claims mapping mismatches, token misconfiguration, certificate trust issues, and identity normalization conflicts that had been causing outages across subsidiary identity boundaries.
Owned the federation certificate lifecycle across all enterprise trust relationships, implementing proactive rotation processes that eliminated emergency renewals and prevented authentication outages tied to expired signing certificates across business-critical applications.
Inherited a degraded privileged access posture and restructured the enterprise PAM strategy using BeyondTrust and Entra ID PIM, eliminating standing privilege and enforcing just-in-time access and credential governance across all administrative tiers.
Designed approval workflows, session monitoring, and auditability processes that significantly improved organizational visibility into privileged activity and closed gaps left by the previous access control posture.
Governed secrets and credential management across BeyondTrust Secrets Safe, Password Safe, and Azure Key Vault, enforcing rotation policies, access controls, and auditability for privileged and non-human identities across a multi-subsidiary environment where service account sprawl had accumulated without governance.
Administered physical access governance through Genea, ensuring badge provisioning, access entitlements, and user lifecycle remained aligned with identity records across the enterprise.
Governed cross-boundary identity and access for international business partners and third-party collaborators across Triton Digital's global operations spanning more than 50 countries, managing federation trust, entitlement scoping, and access lifecycle across non-employee identity populations.
Managed identity governance for sensitive and high-profile personnel categories requiring elevated privacy controls, restricted administrative access, and non-standard lifecycle handling across the enterprise directory.
Investigated and resolved service account misuse tied to operational systems, enforcing separation between interactive and non-interactive access patterns and closing privileged access risks that had accumulated under the previous ownership.
Served as the senior technical escalation authority for IAM incidents across a workforce of more than 30,000 users, resolving AADSTS errors, Conditional Access misconfigurations, federation trust breakdowns, and access outages when standard support paths and resolution workflows could not close the incident.
Delivered weekly identity risk reporting directly to the CISO, translating technical exposure into prioritized business decisions with clear ownership, accountability, and measurable risk reduction.
Reason for Departure

iHeartMedia entered a broad restructuring and cost-reduction period in 2026, including nationwide layoffs and a $50 million cost-savings program, alongside earlier merger discussions with SiriusXM. Source ↗

Threat Detection / Security Automation

Zero Trust, multi-cloud security and privileged access
LexisNexis Reed Tech / USPTO·04/2024 – 06/2025CONTRACTPUBLIC TRUST

Worked across security architecture, identity and detection engineering in a federal-facing environment where design choices had to survive NIST controls, operational scrutiny and real incident conditions.

Leadership & Expertise

Zero Trust architecture, multi-cloud security design, privileged-access remediation, detection engineering and executive translation.

Initiatives Led

Reworked privileged access, standardized cloud controls, strengthened authentication and improved correlation across security platforms.

Designed Zero Trust architecture aligned to NIST 800-207 with JIT provisioning and continuous authentication monitoring, adjusting access decisions in real time based on behavioral risk signals.
Built behavioral risk evaluation models adjusting access decisions dynamically based on user activity and contextual identity signals.
Led Azure security architecture aligned to NIST 800-53 and CIS standards, authoring Infrastructure-as-Code security policies that enforce baseline configurations and surface configuration drift in real time.
Standardized identity and security controls across AWS, Azure, and GCP with centralized CSPM integration, delivering unified dashboards aggregating risk signals across all three platforms for executive visibility.
Redesigned OneIdentity Safeguard deployment for enterprise-wide privileged access control, executing a full offboarding and re-onboarding of privileged assets and realigning session recording, account rotation, and access policies from the ground up.
Integrated Auth0 to deliver OAuth2 and OIDC-based SSO across enterprise applications, supporting FedRAMP and NIST 800-53-compliant authentication workflows with certificate rotation and trust validation.
Engineered threat correlation across CrowdStrike Falcon, Microsoft Defender, Palo Alto, and Checkpoint, improving detection quality and reducing response time through intelligent alert triage and deduplication.
Designed forensic response processes using Secureworks Taegis aligned to NIST 800-86, ensuring defensible evidence handling and investigation integrity.
Translated complex architecture and security findings into business impact for executive stakeholders, enabling informed decision-making on risk and remediation priorities.
Reason for Departure

Reed Tech was folded more fully into LexisNexis Life Sciences Solutions, with the Reed Tech name retired as the businesses were consolidated under the LexisNexis brand, during a period that also included reported workforce reductions within Reed Tech. Source ↗

Identity & Access Management Architect

Large-scale identity modernization
Kroger·12/2022 – 02/2024FULL-TIME

Led identity architecture in a retail environment where workforce scale, compliance, legacy access patterns and application modernization all had to move together.

Leadership & Expertise

Large-scale identity architecture, workforce lifecycle design, PAM, workload identity and access-governance experience in a high-volume retail environment.

Initiatives Led

Modernized hybrid identity, reduced standing privilege, improved access certification and removed static credentials from container workloads.

Led identity provisioning for 32,000 users across US and UK operations while maintaining HIPAA compliance, implementing structured lifecycle controls and removing manual provisioning from the critical path.
Built role-aware provisioning workflows adapting access based on job function and peer access patterns, reducing inconsistent access assignments and privilege creep.
Implemented PAM using One Identity Safeguard and TPAM, enforcing just-in-time privilege elevation tied to ServiceNow approval workflows and significantly reducing standing privileged access.
Modernized identity using Entra ID across 12,000 hybrid users, eliminating legacy access models and improving authentication consistency across applications.
Integrated Ping SSO and MFA across more than 40 applications using risk-based authentication policies; behavioral analytics reduced password-reset volume while cutting unauthorized access attempts.
Designed AKS workload identity solution eliminating static credentials in containerized environments through workload identity federation.
Established continuous access certification processes using behavioral analytics to identify dormant accounts, excessive permissions, and separation-of-duties violations across 20,000 accounts.
Deployed CrowdStrike Falcon with threat hunting playbooks across a fleet of 2,000 endpoints, strengthening threat detection, visibility, and incident response capabilities.
Deployed Varonis for file access monitoring and data classification, strengthening SOX and GDPR audit readiness through continuous policy validation.
Streamlined Active Directory using RBAC and Conditional Access to reduce policy drift and improve access governance consistency.
Reason for Departure

Kroger’s proposed $25 billion merger with Albertsons was blocked and terminated in December 2024, followed by broader restructuring, cost realignment and corporate workforce reductions affecting nearly 1,000 employees. Source ↗

Customer Identity & Access Management Architect

Federal ICAM and Zero Trust
DHS OCIO / U.S. Secret Service·02/2022 – 12/2022CONTRACTPUBLIC TRUST

Worked inside federal infrastructure where identity had to connect large numbers of systems while staying aligned to agency governance, FedRAMP requirements and formal security management practices.

Leadership & Expertise

Federal ICAM architecture, Zero Trust, governance, cloud migration and compliance discipline across distributed systems.

Initiatives Led

Connected more than 100 systems, advanced agency governance, implemented Saviynt and moved workloads into FedRAMP-authorized cloud architecture.

Integrated identity across more than 100 federal systems using SAML, OAuth2, and Active Directory federation, supporting large-scale ICAM initiatives across distributed federal infrastructure.
Positioned IAM as a core security control within Zero Trust strategy across federal environments, improving authentication assurance and access control.
Led ISO 27001 certification for the DHS Information Security Management System, establishing governance frameworks and control validation processes adopted agency-wide.
Migrated more than 50 systems to GCP under FedRAMP Moderate authorization, implementing continuous compliance monitoring and infrastructure-as-code security baselines.
Enforced least privilege across serverless workloads using workload identity federation, with permissions adjusting dynamically based on runtime context.
Implemented Saviynt across a workforce of 15,000 users enabling access governance, entitlement reviews, and separation-of-duties enforcement, dramatically reducing manual certification effort.
Delivered security scripting using PowerShell and Python aligned to FISMA compliance, producing reusable modules adopted across DHS security teams.

Cloud Vulnerability Analyst

Security operations in a regulated healthcare environment
Accessia Health·07/2021 – 12/2021CONTRACT

Combined vulnerability management, identity-aware cloud controls and authentication infrastructure with compliance needs that had to remain auditable under HIPAA and NIST expectations.

Leadership & Expertise

Risk prioritization, authentication infrastructure, cloud security and compliance work shaped by healthcare requirements.

Initiatives Led

Improved vulnerability prioritization, authentication resilience, privileged credential handling and certificate lifecycle control.

Led vulnerability management aligned to NIST 800-53 and HIPAA across enterprise systems, prioritizing remediation based on exploitability, business criticality, and threat intelligence.
Built audit-ready compliance reporting via PingFederate logs supporting SOX, GDPR, and HIPAA requirements with real-time dashboards for continuous authentication visibility.
Deployed PingFederate and Citrix NetScaler supporting high-availability authentication services through failover and health monitoring.
Designed credential vaulting and rotation for privileged healthcare accounts, eliminating static privileged credentials across the environment.
Secured AWS workloads using identity-aware proxies and service mesh policy enforcement, enabling zero trust network access for containerized healthcare applications.
Embedded security review into the infrastructure change process using policy-as-code frameworks, catching compliance violations before deployment rather than after.
Managed certificate lifecycle across a portfolio of 150 domains ensuring continuous compliance and eliminating manual tracking overhead.

Privileged Access Management Security Engineer

Enterprise PAM transformation
Indivior Pharmaceuticals·10/2019 – 07/2021FULL-TIME

Took on privileged access in a regulated pharmaceutical environment where excessive access, standing privilege and inconsistent administrative practices needed a structured model.

Leadership & Expertise

PAM engineering, least-privilege design, adaptive access, compliance and executive risk communication.

Initiatives Led

Reduced excessive privilege, formalized JIT workflows, centralized privileged-account governance and strengthened endpoint protection.

Led enterprise PAM transformation, mapping more than 200 job functions into structured least privilege RBAC models to systematically reduce excessive access across enterprise applications.
Deployed BeyondTrust PAM securing approximately 1,200 privileged accounts, enforcing SOX-compliant credential rotation, session monitoring, and audit controls while eliminating standing privileged access for routine operations.
Designed adaptive access policies in Entra ID with risk-based scoring that enforces access controls dynamically based on real-time threat intelligence and user behavior.
Built privileged access workflows supporting just-in-time elevation, approval-based access, and administrative tier separation.
Established centralized governance for privileged accounts across legacy systems and business units.
Implemented BitLocker encryption with deployment and backup policies protecting ePHI across all endpoints in compliance with HIPAA requirements.
Integrated Terraform guardrails using policy validation, enforcing compliance from deployment through runtime with continuous scanning and drift detection.
Designed mobile device management using Microsoft Intune with enforcement policies for a distributed workforce, securing remote access without impeding productivity.
Supported incident response through analysis of privileged account activity and identification of misuse patterns across enterprise endpoints.
Briefed executive leadership on security risks, compliance gaps, and mitigation strategies, translating technical findings into business impact through data-driven risk dashboards.

Identity & Access Management Analyst

Hybrid identity and risk-based access
Wells Fargo·04/2019 – 10/2019CONTRACT

Worked inside banking controls where identity decisions had to align with regulatory requirements while supporting cloud adoption, customer-facing authentication and large-scale lifecycle operations.

Leadership & Expertise

Risk-based IAM, hybrid cloud controls, regulated banking experience and customer-facing authentication design.

Initiatives Led

Strengthened continuous verification, standardized cloud identity controls, automated response and maintained reliable lifecycle operations.

Designed a Zero Trust-aligned IAM framework with risk-based access controls, applying continuous verification and intelligent policy recommendations driven by historical access patterns.
Built consistent identity controls across AWS and Azure environments using infrastructure-as-code for policy synchronization across cloud platforms.
Enforced FFIEC and GLBA requirements via SCCM and Office 365 with access controls and continuous compliance monitoring across the banking environment.
Extended Microsoft Defender's remediation capabilities through orchestrated threat response workflows and intelligent alert correlation, reducing analyst triage time.
Engineered progressive profiling workflows using ADFS with failover for customer-facing banking applications, adding intelligent session management and fraud detection capabilities.
Maintained a user base of 12,000 accounts across hybrid environments through lifecycle workflows, ensuring timely access grants and revocations via HR system integration.
Ran staff security education alongside phishing response workflows, significantly reducing incident response time through orchestrated investigation and remediation.
Briefed upper management on cloud security risks and mitigation strategies using risk dashboards that provided actionable recommendations and continuous visibility into posture trends.

Customer Identity & Access Management Engineer

Multi-client IAM stabilization and modernization
Wellsecured IT·10/2015 – 01/2019FULL-TIME

Worked across multiple enterprise client environments where identity was often fragmented across legacy directories, cloud platforms, customer-facing applications and several identity providers. The role combined hands-on CIAM/IAM engineering with escalation ownership for federation failures, certificate issues, provisioning breakdowns and identity-data drift.

Leadership & Expertise

Enterprise CIAM and IAM engineering across hybrid environments, with deep troubleshooting responsibility for federation, certificate lifecycle, identity data integrity, cloud authentication and customer-facing access. Repeated exposure to fragmented estates built practical experience stabilizing environments with multiple identity providers, legacy dependencies and inconsistent lifecycle logic.

Initiatives Led

Designed Zero Trust IAM across Azure, GCP and Microsoft 365; reduced standing privilege by more than 70 percent; built certificate lifecycle processes across 100+ applications; led ForgeRock migration and workflow standardization; resolved Workday, Active Directory and Entra ID synchronization issues; delivered Auth0 customer authentication; implemented OAuth2/OIDC token lifecycle management; integrated IAM telemetry with Splunk and DevOps pipelines; served as escalation authority for SAML failures, authentication loops, certificate expirations and provisioning outages.

Designed and implemented Zero Trust IAM frameworks across Azure, GCP, and M365, reducing standing privilege by over 70 percent across enterprise environments.
Served as escalation authority for critical IAM failures including SAML trust breakdowns, authentication loops, certificate expirations, and provisioning outages. When support tiers could not resolve it, the problem came here.
Built certificate lifecycle management processes for SAML, OIDC, and OAuth2 across more than 100 enterprise applications; proactive 60-day alerts and direct SaaS vendor coordination eliminated authentication outages entirely.
Managed identity data integrity across Workday, Active Directory, and Entra ID, resolving sync failures and attribute inconsistencies that blocked joiner, mover, and leaver processes across the hybrid identity stack.
Led migration to ForgeRock Identity Management with workflow standardization for hybrid environments, cutting provisioning delays through intelligent lifecycle automation and structured exception handling.
Integrated Splunk with IAM tooling for security event monitoring and alerting, achieving ISO/IEC 27001 and NIST 800-53 compliance through centralized log correlation and threat detection.
Delivered Auth0 integration for client-facing financial services portals, building intelligent authentication that balanced security requirements with user experience at scale.
Implemented OAuth 2.0 and OpenID Connect with token lifecycle management for cloud-native application APIs and microservices architectures.
Built AWS IAM roles and encryption protocols across multi-cloud environments with policy enforcement ensuring consistent least-privilege patterns at scale.
Stabilized fragmented IAM environments across enterprise clients with multiple identity providers and legacy system dependencies.
Partnered with DevOps to embed log analysis and incident response directly into CI/CD pipelines.

Cloud Security Operations Lead

Cloud security foundations, identity and incident response
Cloudcentria Security·06/2011 – 12/2015FULL-TIME

Led cloud security operations across AWS and hybrid environments during a period when cloud operating models were still being established. The work spanned identity architecture, federation, privileged access, vulnerability management, forensic investigation and SOC response, creating a broad systems view before identity became the primary focus of later roles.

Leadership & Expertise

Cloud security leadership across IAM, federation, vulnerability management, forensics, privileged access and active incident response. Built foundational controls in environments that needed security architecture, governance and operational processes established from the ground up, with responsibility spanning both preventive design and hands-on investigation.

Initiatives Led

Built AWS and hybrid security programs aligned to NIST 800-53 and ISO 27001; designed federation across Okta, Auth0 and SaaS platforms; led forensic investigations with formal chain-of-custody practices; scaled vulnerability management beyond 15,000 assets across AWS and Azure; optimized Entra ID Connect synchronization and UPN conventions; administered BeyondTrust Password Safe with JIT and change-management controls; supported SOC containment and investigation involving token misuse and privileged-session activity.

Built cloud security and identity programs from the ground up across AWS and hybrid environments, establishing foundational IAM controls, governance models, and policy-as-code frameworks aligned to NIST 800-53 and ISO 27001.
Designed identity federation across SaaS platforms including Okta, Auth0, and application providers, resolving authentication failures and enabling centralized access control.
Led forensic investigations establishing chain-of-custody processes for security incidents, including recovery of stolen intellectual property that established cloud forensics protocols adopted as industry practice.
Delivered AWS security architecture including identity design, access enforcement, and continuous validation across IaaS, PaaS, and serverless deployments.
Scaled vulnerability management to an environment exceeding 15,000 assets across AWS and Azure, with prioritization by exploitability and business impact using Nessus-based assessments.
Optimized Entra ID Connect sync logic and hybrid sync rules, normalizing attributes and UPN conventions to keep identity data consistent across cloud and on-premises environments.
Administered BeyondTrust Password Safe with secret rotation and vault access workflows, eliminating credential sprawl through JIT tied to approved change management processes.
Partnered with SOC teams during active incidents supporting containment, investigation, and remediation efforts including analysis of token misuse and privileged session activity.

Systems Administrator

Operational foundation
uBreakiFix·2009 – 2011FULL-TIME

Started close to the user and the system. Hardware, software, networks, tickets and service levels taught the practical side of technology before architecture entered the picture.

Leadership & Expertise

Operational discipline, customer-facing troubleshooting, prioritization and documentation at the system level.

Initiatives Led

Built the service and troubleshooting foundation that later informed architecture and security work.

Delivered first-level support for hardware, software, and network issues via phone, email, and in-person.
Assessed and prioritized tickets based on impact and urgency to meet SLA targets.
Maintained high customer satisfaction through timely support and detailed documentation of service desk activities.
Selected engagements
Career evolution
IT & Systems Support · Administration · Infrastructure
Cloud Security AWS · Azure · Vulnerability · Forensics
IAM & PAM Lifecycle · Privilege · Governance
CIAM & Zero Trust Federation · MFA · Continuous Access
Identity Architecture Hybrid · Multi-cloud · Enterprise Design
Enterprise IAM Leadership Strategy · Governance · CISO Alignment
NHI & AI Governance Machine Identity · Tokens · Agentic AI
Professional range
TECHNOLOGY, SECURITY & GOVERNANCE
Identity & Access Management
Microsoft Entra ID · Active Directory · Okta · Auth0 · SailPoint · Saviynt · ForgeRock · Ping Identity · Workday · Microsoft AD FS · Microsoft Entra Connect · Microsoft Graph API · Microsoft Identity Manager (MIM) · Active Directory Certificate Services (AD CS) · LDAP / LDAPS · Kerberos · Active Directory Administrative Center (ADAC) · PingFederate / PingAccess · One Identity Manager · Genea
Privileged Access Management
CyberArk · BeyondTrust · Bomgar · Delinea · One Identity Safeguard · Azure Key Vault · BeyondTrust Password Safe · BeyondTrust Secrets Safe · PVWA · TPAM
Security Operations & SIEM
ReliaQuest GreyMatter · Microsoft Sentinel · SentinelOne · Microsoft Defender · CrowdStrike Falcon · Google SecOps / Chronicle · Abnormal Security · Palantir · Microsoft Defender for Endpoint · Check Point · Splunk · Secureworks Taegis
Network & Infrastructure Security
Cisco ISE · Cisco AnyConnect · Palo Alto Networks · Tenable · Windows Server · Remote Desktop Protocol (RDP) · VMware vSphere · Palo Alto Panorama · Citrix NetScaler · Kubernetes · AKS
GOVERNANCE & SECURITY MANAGEMENT
Lepide · Microsoft Purview · Microsoft Intune · Bindplane · Microsoft Defender for Cloud · Microsoft Configuration Manager (SCCM) · Varonis
Development & Automation
PowerShell · Visual Studio Code · GitHub · Azure Logic Apps · Terraform · Git · Windows PowerShell ISE · SQL Server Management Studio (SSMS) · Python · Java · JavaScript · Postman · n8n · Azure Event Hub
IT Operations & Collaboration
ServiceNow · SolarWinds Service Desk · Asana · PuTTY · Worknovia · Microsoft Visio · Confluence · SharePoint · Jira · Microsoft Teams · Exchange Online · Microsoft Excel
Cloud Platforms
Microsoft Azure · AWS · Google Cloud
STANDARDS, FRAMEWORKS & COMPLIANCE
NIST Cybersecurity Framework (CSF) · NIST SP 800-53 · NIST SP 800-207 Zero Trust Architecture · NIST SP 800-86 · NIST Risk Management Framework (RMF) · ISO/IEC 27001 · CIS Controls / Benchmarks · FISMA · FedRAMP Moderate · HIPAA Security Rule · SOX · GLBA · FFIEC Guidance · GDPR · Zero Trust · Least Privilege · RBAC · ABAC · Privileged Access Governance · Identity Governance & Administration (IGA) · Access Certification / User Access Reviews · Separation of Duties (SoD) · Just-in-Time (JIT) Access · Continuous Monitoring · Incident Response · Vulnerability Management · Data Loss Prevention (DLP)
Current direction
Machine IdentityOwnership and lifecycle at software scale.
Agentic AccessDelegation, autonomy and bounded authority.
GovernanceControls that remain understandable as complexity grows.
Education & credentials

Education

Bachelor of Science in CybersecurityUniversity of Richmond · 2027
Associate of Applied Science in Information SystemsNetwork Administration · Reynolds College · Completed

Certifications

CISSP2027
Cisco Cybersecurity Essentials
IBM Cloud Essentials
Network AdministrationReynolds College