Ronnie Bailey
15 years shaping how enterprise organizations secure, govern, and scale identity. Across Fortune 500 firms, federal agencies, and critical infrastructure, the work has always been the same at its core: make identity the thing that holds when everything else is under pressure.
Perspective
The hardest problems in identity are rarely technical. The technical problems have answers. The hard problems are organizational: nobody owns the policy, the accountability structure was never defined, the exception became the rule, and by the time someone notices the debt is structural.
My value is in knowing how to walk into an environment where identity was built by ten different people over ten years and make it coherent, defensible, and owned.
Zero Trust is often used as a buzzword. In practice it is a posture you earn incrementally by making every access decision explicit and every privilege temporary. That is the difference between an organization that knows its exposure and one that finds out during an incident.
The most important work I do is translate. Technology decisions that are not understood by the people who fund them get defunded when priorities shift. Risk that is not legible to a CISO or a board does not get mitigated and usually ends up inherited by the next team. I own these programs end to end: governance, Zero Trust architecture, privileged access, federation, lifecycle management, and the CISO conversation that ties it all together. I can design the framework and I can also open a sign-in log and find what is breaking before it becomes an incident.
Career Evolution
Professional Experience
iHeartMedia is the largest audio company in America, with a portfolio spanning Katz Media Group, Triton Digital, Premiere Networks, and subsidiary brands across broadcast, ad-tech, syndication, and national advertising sales. I served as the senior identity authority across that portfolio, owning core components of the enterprise IAM program across a 30,000-user hybrid environment.
The most consequential work was organizational before it was technical. Security, IT, and HR had no shared framework connecting identity decisions across the business. I built the ownership model, the RACI structure, and the escalation paths that gave those teams a consistent foundation. That structure reduced cross-team escalations and gave the Conditional Access program the accountability it needed to hold under scrutiny.
I directed a 60-policy Conditional Access estate covering biometric authentication, geofencing, device compliance, and risk-based access decisions. The governance model I put in place reduced authentication incidents and policy violations across the application portfolio. I inherited the privileged access posture in a degraded state and rebuilt it around BeyondTrust and Entra ID PIM, designing the approval workflows and audit structure that turned a platform into a governed program.
I reported to the CISO every week, translating technical exposure into business decisions with named owners and defined outcomes. That reporting relationship kept identity on the leadership agenda and gave the program the organizational weight it needed to move forward.
- Owned core identity security components across the enterprise IAM program for a hybrid workforce of more than 30,000 users spanning iHeartMedia, Katz Media Group, Triton Digital, Premiere Networks, and subsidiary brands across broadcast, ad-tech, syndication, and media representation.
- Aligned security, IT, HR, and business stakeholders across a multi-subsidiary portfolio to drive identity maturity and risk reduction, establishing structured cross-functional communication between identity, SOC, and GRC teams that had historically operated in silos with limited coordination between them.
- Defined and maintained the IAM ownership model and RACI framework, assigning policy ownership, formalizing escalation paths, and creating cross-functional accountability across security, engineering, and business teams that had previously managed identity-related responsibilities independently.
- Directed Conditional Access strategy and enforcement across a 60-policy estate aligned to Zero Trust, governing controls that spanned biometric authentication, geofencing, device compliance, MFA enforcement, and risk-based access decisions across a workforce spanning broadcast operations, podcast production, digital ad-tech, and national advertising sales.
- Managed Mobile Application Management and Microsoft Defender Cloud Security policies across the enterprise, extending identity-aware access controls and security enforcement beyond traditional perimeter boundaries across the full corporate portfolio.
- Identified a persistent pattern of onboarding failures tied to gaps in conditional evaluation logic, including delayed start dates, mismatched HR status in Workday, and incomplete downstream system readiness. Designed and implemented decisioning and alerting logic in Azure Logic Apps that eliminated manual provisioning delays and brought the onboarding process into alignment with actual business workflows.
- Re-established enterprise identity governance and lifecycle controls across HRIS-integrated systems after persistent data integrity failures were traced to UPN normalization conflicts between Workday attributes and downstream system expectations. The root cause had been producing silent provisioning breakdowns, dynamic group membership failures, and access control gaps across the environment. Resolved the conflicts and restored provisioning integrity and access governance across Entra ID and connected enterprise systems.
- Defined and drove enterprise authentication and federation standards across critical business platforms including Workday, Genea, and GCP-integrated systems, resolving authentication failures involving claims mapping mismatches, token misconfiguration, certificate trust issues, and identity normalization conflicts that had been causing outages across subsidiary identity boundaries.
- Owned the federation certificate lifecycle across all enterprise trust relationships, implementing proactive rotation processes that eliminated emergency renewals and prevented authentication outages tied to expired signing certificates across business-critical applications.
- Inherited a degraded privileged access posture and restructured the enterprise PAM strategy using BeyondTrust and Entra ID PIM, eliminating standing privilege and enforcing just-in-time access and credential governance across all administrative tiers.
- Designed approval workflows, session monitoring, and auditability processes that significantly improved organizational visibility into privileged activity and closed gaps left by the previous access control posture.
- Governed secrets and credential management across BeyondTrust Secrets Safe, Password Safe, and Azure Key Vault, enforcing rotation policies, access controls, and auditability for privileged and non-human identities across a multi-subsidiary environment where service account sprawl had accumulated without governance.
- Administered physical access governance through Genea, ensuring badge provisioning, access entitlements, and user lifecycle remained aligned with identity records across the enterprise.
- Governed cross-boundary identity and access for international business partners and third-party collaborators across Triton Digital's global operations spanning more than 50 countries, managing federation trust, entitlement scoping, and access lifecycle across non-employee identity populations.
- Managed identity governance for sensitive and high-profile personnel categories requiring elevated privacy controls, restricted administrative access, and non-standard lifecycle handling across the enterprise directory.
- Investigated and resolved service account misuse tied to operational systems, enforcing separation between interactive and non-interactive access patterns and closing privileged access risks that had accumulated under the previous ownership.
- Served as the senior technical escalation authority for IAM incidents across a workforce of more than 30,000 users, resolving AADSTS errors, Conditional Access misconfigurations, federation trust breakdowns, and access outages when standard support paths and resolution workflows could not close the incident.
- Delivered weekly identity risk reporting directly to the CISO, translating technical exposure into prioritized business decisions with clear ownership, accountability, and measurable risk reduction.
This engagement ran across two distinct environments. LexisNexis is a global legal information and analytics company serving customers in more than 150 countries. The United States Patent and Trademark Office operates under Public Trust Clearance where compliance expectations are institutional and the architecture decisions I made had direct federal implications.
My work centered on Zero Trust design aligned to NIST 800-207, making foundational decisions about how trust gets established, under what conditions it gets revoked, and how behavioral signals feed into access decisions in real time. That architecture extended across Azure, AWS, and GCP with centralized CSPM integration and Infrastructure-as-Code policy enforcement that removed manual validation from the compliance lifecycle.
I rebuilt the One Identity Safeguard platform from scratch, fully offboarding and re-onboarding privileged assets, realigning session recording, and rewriting access policies against the actual security posture. I engineered threat correlation across CrowdStrike Falcon, Microsoft Defender, Palo Alto, and Checkpoint that improved detection quality and reduced response time through intelligent triage. I designed forensic response processes using Secureworks Taegis aligned to NIST 800-86 and translated technical findings into executive-level risk assessments that informed security investment decisions across both organizations.
- Designed Zero Trust architecture aligned to NIST 800-207, incorporating JIT provisioning, continuous authentication monitoring, behavioral risk signals, and contextual access decisions.
- Built behavioral risk evaluation models that dynamically adjusted access decisions based on user activity, authentication context, device posture, and identity risk.
- Led Azure security architecture aligned to NIST 800-53 and CIS standards, embedding Infrastructure-as-Code security policies to enforce baseline configurations and detect configuration drift.
- Standardized identity and security controls across AWS, Azure, and GCP through centralized CSPM integration and unified risk reporting.
- Redesigned One Identity Safeguard from the ground up, fully offboarding and re-onboarding privileged assets while restructuring session recording, credential rotation, and privileged access policies.
- Integrated Auth0 using OAuth 2.0 and OIDC to support secure SSO and federation across enterprise applications operating under federal security requirements.
- Engineered threat correlation across CrowdStrike Falcon, Microsoft Defender, Palo Alto, and Check Point to improve alert fidelity and accelerate investigation.
- Designed forensic response processes in Secureworks Taegis aligned to NIST 800-86, establishing defensible evidence collection and investigation procedures.
- Developed security automation and enrichment workflows that reduced manual analyst effort during identity and endpoint investigations.
- Translated identity, cloud, and threat findings into executive-level risk assessments used to prioritize remediation and security investment.
Kroger is the largest supermarket chain in the United States, ranked 25th on the Fortune 500 with approximately 150 billion dollars in annual revenue. I came into the Technology and Digital Department as the IAM architect responsible for modernizing identity across a hybrid environment where legacy access models had accumulated over years of rapid growth across US and UK markets.
I architected identity provisioning across 32,000 users under HIPAA compliance, designing workflows that adapted access based on job function and peer patterns. That work removed manual provisioning from the critical path and measurably reduced both provisioning time and the inconsistent access assignments that had been generating compliance risk. I integrated Entra ID across 12,000 hybrid users, retiring legacy authentication patterns across the application landscape, and designed the AKS workload identity solution that eliminated static credentials from containerized environments through workload identity federation.
I implemented PAM through One Identity Safeguard and TPAM with JIT elevation tied to ServiceNow approval workflows, connecting privileged access to the change management process. I deployed CrowdStrike Falcon across 2,000 endpoints and implemented Varonis for file access monitoring and data classification that strengthened SOX and GDPR audit readiness.
- Led identity provisioning and lifecycle governance for approximately 32,000 users across U.S. and U.K. operations while maintaining HIPAA-aligned access controls.
- Designed role-aware provisioning workflows that adapted access based on job function, organizational context, and peer access patterns, reducing inconsistent entitlements and privilege creep.
- Modernized hybrid identity for approximately 12,000 users through Entra ID, improving authentication consistency and retiring legacy access patterns.
- Integrated Ping Identity SSO and MFA across more than 40 applications using SAML, OIDC, and risk-based authentication policies.
- Implemented One Identity Safeguard and TPAM for privileged access management, enforcing JIT elevation and ServiceNow-based approval workflows.
- Connected privileged access processes to enterprise change-management workflows, improving auditability and reducing standing administrative privilege.
- Designed AKS workload identity architecture using workload identity federation, eliminating static credentials from containerized workloads.
- Built continuous access-certification processes covering approximately 20,000 accounts to identify dormant access, excessive permissions, and separation-of-duties conflicts.
- Streamlined Active Directory RBAC and Conditional Access policies to reduce policy drift and improve consistency across hybrid environments.
- Deployed CrowdStrike Falcon across approximately 2,000 endpoints and developed threat-hunting playbooks supporting endpoint investigation and response.
- Implemented Varonis for file-access monitoring, data classification, and sensitive-data visibility supporting SOX and GDPR audit readiness.
- Automated identity and security administration using PowerShell and Python to reduce repetitive operational work and improve control consistency.
The US Secret Service operates within the Department of Homeland Security with one of the most demanding security profiles in the federal government. I worked within the OCIO under Public Trust Clearance, architecting identity solutions where compliance requirements were federal and the tolerance for gaps was effectively zero.
I designed CIAM architecture across more than 100 legacy federal systems integrating Active Directory, OAuth 2.0, and SAML 2.0 federation, enforcing consistent policy across environments with significantly different technical assumptions without disrupting operational continuity.
I led the ISO 27001 certification for the DHS Information Security Management System, building a governance framework that positioned the agency in a materially stronger compliance posture. The controls framework was adopted agency-wide. I orchestrated the GCP migration of more than 50 systems to FedRAMP Moderate authorization with continuous compliance monitoring and infrastructure-as-code security baselines. I implemented Saviynt for access governance across 15,000 users with entitlement reviews and separation-of-duties enforcement.
- Architected CIAM and federation controls across more than 100 legacy federal systems integrating Active Directory, OAuth 2.0, and SAML 2.0.
- Standardized authentication and identity-policy enforcement across distributed federal systems with significantly different legacy architectures.
- Led ISO 27001 certification efforts for the DHS Information Security Management System, establishing governance and control structures adopted across the organization.
- Developed automated control-validation processes supporting continuous compliance rather than point-in-time audit preparation.
- Orchestrated migration of more than 50 on-premises systems to GCP while supporting FedRAMP Moderate authorization requirements.
- Established SIEM integration and continuous compliance monitoring for migrated cloud workloads.
- Secured GCP serverless workloads through workload identity federation and least-privilege service permissions.
- Implemented Saviynt identity governance across more than 15,000 accounts, supporting entitlement reviews, access certifications, and separation-of-duties enforcement.
- Designed lifecycle and access-governance controls for federal identities operating across cloud and legacy environments.
- Automated security and identity workflows using PowerShell, Python, and Java in support of FISMA requirements.
- Produced reusable security automation modules and standardized workflows that could be adopted by other security teams.
- Supported Zero Trust modernization by connecting authentication, authorization, governance, and continuous monitoring controls across the federal environment.
Accessia Health is a national non-profit providing patient assistance programs for individuals who cannot afford prescription medications, carrying full HIPAA, SOX, and GDPR obligations across cloud infrastructure in AWS. A security failure here does not just create compliance exposure. It has downstream consequences for patients who depend on the organization's ability to operate.
I led vulnerability management aligned to NIST 800-53 and HIPAA, prioritizing risk by exploitability, business criticality, and threat intelligence. I deployed PingFederate and Citrix NetScaler for high-availability authentication across mission-critical applications, designed credential vaulting and rotation that eliminated static privileged credentials, and introduced certificate lifecycle management across 150 domains that replaced a manual tracking process. I embedded security review into the infrastructure change process using policy-as-code frameworks, moving compliance enforcement to the point of change rather than discovery at audit.
- Led vulnerability management across AWS and enterprise infrastructure aligned to NIST 800-53 and HIPAA security requirements.
- Prioritized vulnerabilities using exploitability, asset criticality, threat intelligence, and business impact rather than severity score alone.
- Coordinated remediation activity across infrastructure and application teams and maintained audit-ready vulnerability reporting.
- Built compliance reporting from PingFederate authentication logs supporting HIPAA, SOX, and GDPR monitoring requirements.
- Deployed and supported PingFederate and Citrix NetScaler for highly available authentication services across mission-critical applications.
- Designed privileged credential vaulting and automated rotation controls, reducing reliance on static administrative credentials.
- Secured AWS workloads using identity-aware access controls and service-mesh policy enforcement to support Zero Trust network access.
- Embedded security review into infrastructure-change workflows using policy-as-code controls, identifying compliance violations before production deployment.
- Managed certificate lifecycle across approximately 150 domains, introducing structured renewal and tracking processes that reduced expiration risk.
- Partnered with infrastructure teams to translate vulnerability findings into actionable remediation priorities and measurable risk reduction.
- Supported audit readiness across HIPAA, SOX, and GDPR by maintaining evidence of vulnerability remediation, authentication controls, and credential governance.
Indivior is a publicly traded global specialty pharmaceutical company focused on treatments for opioid use disorder, operating across 14 locations worldwide under SOX, HIPAA, and GxP standards with annual revenue of approximately 1.2 billion dollars. Access failures in pharmaceutical environments carry regulatory consequences that touch the integrity of the drug development and manufacturing record.
I led the PAM transformation starting with role mapping across more than 200 job functions, establishing least privilege RBAC models that reflected actual work patterns rather than accumulated access history. I deployed BeyondTrust to secure approximately 1,200 privileged accounts with SOX-compliant credential rotation, session monitoring, and audit controls. The result was a privileged access program that was better documented, better aligned to SOX audit requirements, and no longer dependent on standing access for routine operations.
I designed Entra ID risk-based access policies with adaptive scoring, embedded Terraform guardrails with policy validation directly into the deployment pipeline, and briefed executive leadership regularly translating security risks into business impact through data-driven dashboards.
- Led enterprise PAM transformation, mapping more than 200 job functions into structured least privilege RBAC models to systematically reduce excessive access across enterprise applications.
- Deployed BeyondTrust PAM securing approximately 1,200 privileged accounts, enforcing SOX-compliant credential rotation, session monitoring, and audit controls while eliminating standing privileged access for routine operations.
- Designed adaptive access policies in Entra ID with risk-based scoring that enforces access controls dynamically based on real-time threat intelligence and user behavior.
- Built privileged access workflows supporting just-in-time elevation, approval-based access, and administrative tier separation.
- Established centralized governance for privileged accounts across legacy systems and business units.
- Built GCP security framework using Google IAM and Security Command Center, introducing centralized threat detection, policy enforcement, and access visibility across workloads.
- Implemented BitLocker encryption with deployment and backup policies protecting ePHI across all endpoints in compliance with HIPAA requirements.
- Integrated Terraform guardrails using policy validation, enforcing compliance from deployment through runtime with continuous scanning and drift detection.
- Designed mobile device management using Microsoft Intune with enforcement policies for a distributed workforce, securing remote access without impeding productivity.
- Supported incident response through analysis of privileged account activity and identification of misuse patterns across enterprise endpoints.
- Briefed executive leadership on security risks, compliance gaps, and mitigation strategies, translating technical findings into business impact through data-driven risk dashboards.
Wells Fargo is one of the largest banks in the United States, operating under FFIEC and GLBA compliance requirements with the examination scrutiny that federal financial regulation demands. I contributed identity controls to an environment where consistency and audit-readiness were baseline expectations across a hybrid infrastructure spanning AWS and Azure.
I designed a Zero Trust-aligned IAM framework with continuous verification and risk-based access controls synchronized across cloud platforms through infrastructure-as-code. I built ADFS progressive profiling workflows with intelligent session management and fraud detection for customer-facing banking applications. I maintained 12,000 accounts through lifecycle workflows that kept access aligned with HR system changes. I ran security education alongside phishing response workflows that reduced incident response time by a meaningful margin, giving staff both the awareness and the process to act on it.
- Designed a Zero Trust-aligned IAM framework with risk-based access controls, applying continuous verification and intelligent policy recommendations driven by historical access patterns.
- Built consistent identity controls across AWS and Azure environments using infrastructure-as-code for policy synchronization across cloud platforms.
- Enforced FFIEC and GLBA requirements via SCCM and Office 365 with access controls and continuous compliance monitoring across the banking environment.
- Extended Microsoft Defender's remediation capabilities through orchestrated threat response workflows and intelligent alert correlation, reducing analyst triage time.
- Engineered progressive profiling workflows using ADFS with failover for customer-facing banking applications, adding intelligent session management and fraud detection capabilities.
- Maintained a user base of 12,000 accounts across hybrid environments through lifecycle workflows, ensuring timely access grants and revocations via HR system integration.
- Ran staff security education alongside phishing response workflows, significantly reducing incident response time through orchestrated investigation and remediation.
- Briefed upper management on cloud security risks and mitigation strategies using risk dashboards that provided actionable recommendations and continuous visibility into posture trends.
Wellsecured IT served clients across financial services, healthcare, and regulated industries. As a CIAM engineer working across multiple client environments simultaneously, I built the diagnostic and engineering depth that shaped my approach to every senior role that followed.
I designed Zero Trust frameworks across Azure, GCP, and M365, reducing standing privilege by over 70 percent through Conditional Access, PIM, and JIT workflow design. I built certificate lifecycle management across more than 100 enterprise applications. Authentication outages caused by expired or misaligned certificates were a recurring problem across several client environments before this work. They were not after it.
Workday-to-Active Directory-to-Entra provisioning failures were a consistent escalation. I traced failures across the full hybrid identity stack to resolve them and built the provisioning diagnostic capability that became a defining strength at the senior level. I led the ForgeRock IAM migration with workflow standardization that reduced provisioning delays, and integrated Splunk for identity monitoring supporting ISO/IEC 27001 and NIST 800-53 compliance.
- Designed and implemented unified Zero Trust frameworks across Azure, GCP, and M365, aligning Conditional Access, PIM, and JIT workflows to reduce standing privileges by over 70% while strengthening overall security posture.
- Served as the technical escalation authority for business-critical IAM failures: certificate expirations, broken SAML trusts, provisioning system outages. When automated remediation and support tiers couldn't resolve it, the problem came to me.
- Mentored IAM engineers on automation frameworks, schema change management, and certificate lifecycle operations; created standardized runbooks and automation templates that reduced team dependency on senior resources for routine work.
- Built automated certificate monitoring and renewal systems for SAML, OIDC, and OAuth2 across 100+ enterprise applications; proactive 60-day alerts and direct SaaS vendor coordination eliminated authentication outages and manual tracking overhead entirely.
- Managed directory schema and attribute governance across Entra ID, Active Directory, and ActiveIDM to maintain data integrity in automated lifecycle processes; resolved sync failures between Workday, AD, and downstream identity repositories through intelligent data validation.
- Served as the primary escalation for Workday-to-AD-to-Entra provisioning failures, resolving complex attribute mapping errors and sync breakdowns that blocked joiner, mover, and leaver processes across the hybrid identity stack.
- Administered ActiveIDM's role-based provisioning engine with exception handling logic that routes edge cases to appropriate approvers automatically based on organizational hierarchy and risk level.
- Led migration to ForgeRock Identity Management with automated workflow standardization for hybrid environments, cutting provisioning delays through intelligent lifecycle automation and structured exception handling.
- Integrated Splunk with IAM tooling for automated security event monitoring and alerting, achieving ISO/IEC 27001 and NIST 800-53 compliance through centralized log correlation and threat detection.
- Delivered Auth0 integration for client-facing financial services portals, building intelligent authentication that balanced security requirements with user experience at scale.
- Authored Conditional Access policies using Microsoft Defender with automated recommendations for privileged account management, enforcing risk-based access decisions through continuous policy evaluation.
- Implemented OAuth 2.0 and OpenID Connect with automated token lifecycle management for cloud-native application APIs and microservices architectures.
- Built AWS IAM roles and encryption protocols across multi-cloud environments with automated policy enforcement ensuring consistent least-privilege patterns at scale.
- Partnered with DevOps to embed automated log analysis and incident response directly into CI/CD pipelines.
I started this work when cloud security was still finding its footing. I built identity and security programs across AWS and hybrid environments, establishing IAM controls, governance models, and policy-as-code frameworks aligned to NIST 800-53 and ISO 27001.
I scaled vulnerability management to an environment exceeding 15,000 assets across AWS and Azure, prioritizing by exploitability and business impact. I owned the federation infrastructure across SaaS platforms directly, managing SAML, OIDC, and OAuth2 trust relationships and resolving authentication failures and metadata exchange issues with SaaS vendors before they became outages.
I led a forensic investigation that recovered stolen intellectual property. The evidence collection and chain-of-custody processes I built during that investigation were adopted as standard practice within the organization. I optimized Entra ID Connect sync logic and hybrid sync rules, normalizing attributes and UPN conventions across cloud and on-premises environments.
- Built cloud security and identity programs from the ground up across AWS and hybrid environments, establishing foundational IAM controls, governance models, and policy-as-code frameworks aligned to NIST 800-53 and ISO 27001.
- Designed identity federation across SaaS platforms including Okta, Auth0, and application providers, resolving authentication failures and enabling centralized access control.
- Led forensic investigations establishing chain-of-custody processes for security incidents, including recovery of stolen intellectual property that established cloud forensics protocols adopted as industry practice.
- Delivered AWS security architecture including identity design, access enforcement, and continuous validation across IaaS, PaaS, and serverless deployments.
- Scaled vulnerability management to an environment exceeding 15,000 assets across AWS and Azure, with prioritization by exploitability and business impact using Nessus-based assessments.
- Optimized Entra ID Connect sync logic and hybrid sync rules, normalizing attributes and UPN conventions to keep identity data consistent across cloud and on-premises environments.
- Administered BeyondTrust Password Safe with secret rotation and vault access workflows, eliminating credential sprawl through JIT tied to approved change management processes.
- Partnered with SOC teams during active incidents supporting containment, investigation, and remediation efforts including analysis of token misuse and privileged session activity.
- Technical Support: Delivered first-level support for hardware, software, and network issues via phone, email, and in-person.
- Incident Management: Assessed and prioritized tickets based on impact and urgency to meet SLA targets.
- Customer Service: Maintained high satisfaction through timely support and detailed documentation of service desk activities.
- Technical Support: Provided troubleshooting for computer and electronic products, resolving hardware and software issues.
- Product Setup: Assisted customers with initial configuration, software installations, and feature explanations.
- Hardware Repair: Conducted basic repairs or coordinated with authorized service providers.
- Inventory Management: Maintained stock of computer accessories and ensured product availability.
- Customer Engagement: Collaborated with sales team to align technology solutions with customer needs.
- Product Knowledge: Stayed current on technology trends and updated demo areas to reflect latest offerings.
Key Projects
- Coordinated an enterprise Non-Human Identity (NHI) security implementation across identity, security, cloud, and infrastructure teams.
- Drove delivery across four use cases: NHI offboarding, credential remediation, access segmentation, and token workflow automation.
- Partnered with the SailPoint identity team to align segmentation architecture to enterprise HCM structure.
- Documented and operationalized a proof-of-concept exposed-token workflow built in n8n with internal security engineering.
- Served as the sole dedicated resource on a CEO-priority NHI security initiative covering secrets, tokens, and AI agent credentials enterprise-wide.
- Supported IAM and identity security operations across Microsoft Entra ID, Active Directory, Conditional Access, Cisco ISE, PIM/PAM, and privileged access reviews.
- Investigated and resolved security incidents through ReliaQuest GreyMatter, correlating endpoint, identity, network, and SIEM telemetry to determine disposition and remediation.
- Performed security alert review, enrichment, and threat analysis across Microsoft Sentinel, Google SecOps/Chronicle, SentinelOne, Microsoft Defender, and ReliaQuest GreyMatter.
- Administered and supported privileged access and secrets-management controls through Delinea Secret Server, including credential governance and administrative access workflows.
- Supported phishing investigation and remediation through Abnormal Security, including message analysis, release decisions, threat hunting, and security reporting.
- Performed vulnerability and risk-management activities using Tenable, including vulnerability review, remediation tracking, risk assessment, and coordination with infrastructure teams.
- Supported Microsoft Purview data protection and DLP operations, including data classification, reporting, policy administration, and evaluation of data-flow controls.
- Monitored perimeter and network security activity through Palo Alto Panorama and correlated network findings with identity, endpoint, and SIEM telemetry during investigations.
- Supported Defender for Identity and Defender for Cloud security operations, including identity threat detection, cloud security posture review, and investigation of suspicious authentication or account activity.
- Contributed to AI and non-human identity security governance, including infrastructure-as-code guardrails, AI/MCP gateway considerations, secrets, tokens, and emerging machine-identity controls.
- Designed and implemented federated identity architecture supporting deployment of an application handling nuclear data in the public cloud.
- Partnered with internal architects and product owners to translate deployment requirements into secure IAM and cloud architecture.
- Implemented SSO and MFA controls using Microsoft Entra ID to secure application access.
- Built and configured the Azure identity environment supporting the target cloud deployment.
- Tested security controls and validated IAM configurations prior to advancing the environment to the next deployment stage.
- Supported architecture readiness activities across identity, access, federation, and cloud security controls.
- Integrated CrowdStrike Falcon with identity systems to monitor authentication activity in real time.
- Implemented Active Directory tiered administrative model for privileged access control.
- Designed RBAC framework for critical municipal systems balancing security and operational continuity.
- Delivered identity threat detection training using real-world attack scenarios.
- Analyzed privileged accounts across federal systems using CyberArk PAM, identifying and categorizing access control gaps.
- Improved PIV compliance metrics by 35 percent through structured reporting and remediation.
- Designed SailPoint and Okta integration approach, establishing foundation for streamlined identity governance.
- Implemented CyberArk policies aligned to Azure Conditional Access enforcement.
- Established centralized identity event logging using Azure Event Hub.
- Led a large-scale identity provisioning initiative spanning three organizational environments, including U.S. and U.K. operations, supporting more than 32,000 end users.
- Addressed accumulated IAM technical debt from legacy provisioning practices by redesigning provisioning workflows, ownership models, and automation processes.
- Developed and implemented PowerShell automation for user account creation, modification, deactivation, and lifecycle management across Microsoft Entra ID and connected identity systems.
- Worked through a backlog of legacy provisioning automation, identifying broken or inefficient processes and rebuilding them into standardized, supportable workflows.
- Rationalized provisioning tools, process ownership, and operational responsibilities to reduce duplication and improve accountability across identity teams.
- Partnered with U.S. and U.K. infrastructure, security, architecture, and application teams to define provisioning requirements and coordinate implementation.
- Planned, built, tested, and validated automation scripts before production deployment to ensure security policy compliance and operational reliability.
- Led project execution across planning, implementation, testing, documentation, and stakeholder coordination for the broader identity modernization effort.
- Produced project status reporting and maintained technical documentation covering provisioning workflows, automation logic, dependencies, and ownership.
- Conducted knowledge-transfer and training sessions to improve operational consistency and reduce dependency on individual engineers.
- Supported remediation of legacy Microsoft identity architecture and provisioning processes across Entra ID and hybrid identity environments.
- Led Zero Trust implementation across more than 200 mission-critical applications with micro-segmentation and continuous verification.
- Reduced lateral movement risk by 80 percent while cutting incident response time by 60 percent.
- Completed 3 months ahead of schedule, establishing a new security baseline for federal systems.
- Integrated CyberArk, Fortinet, and identity governance frameworks aligned to NIST 800-53.
- Designed authentication directory with selective attribute filtering for secure external partner access.
- Built PingFederate authentication policies with MFA balancing usability and security requirements.
- Implemented OpenID Connect for customer-facing applications.
- Created ServiceNow-integrated troubleshooting tools for helpdesk teams, reducing resolution time for common issues.
Education & Certifications
Education
-
BS CybersecurityUniversity of RichmondIn Progress
-
AAS Information SystemsReynolds College
-
Network AdministrationReynolds College
Certifications
-
AZ-900: Microsoft Azure FundamentalsMicrosoftIn Progress
-
Cybersecurity EssentialsCisco
-
IBM Cloud EssentialsIBM