About

I combine eight years of federally regulated compliance experience with independent hands-on identity and access management experience in Microsoft Entra ID and Active Directory.

Across that professional work, I have performed identity verification and eligibility adjudication, reviewed supporting evidence, safeguarded sensitive PII, maintained regulatory documentation and decision traceability, and communicated with applicants, managers, and program stakeholders.

Separately, my independent hands-on IAM experience includes identity and access management implementation, testing, troubleshooting, and validation in Microsoft Entra ID and Active Directory. I am a Microsoft Certified Identity and Access Administrator (SC-300) with hands-on experience in Conditional Access policies and role-based access control.

My background supporting the U.S. Department of Labor as a contracting client gave me a strong foundation in data integrity, regulatory adherence, and the protection of sensitive personal and financial information — including HIPAA regulations and PII protection standards. I bring a detail-oriented, compliance-minded approach to IAM: understanding not just how access works, but why it matters for organizational security and regulatory accountability.

Seeking remote-first IAM Analyst and Identity Security roles. Open to local Atlanta opportunities and available for contract, contract-to-hire, and full-time engagements.

Certifications

Microsoft Certified: Identity and Access Administrator Associate
Microsoft
Issued Apr 2026 · Expires Apr 2027 · SC-300
Microsoft Certified: Azure Fundamentals
Microsoft
Issued Jan 2025 · AZ-900
CompTIA Security+ ce Certification
CompTIA
Issued Feb 2024 · Expires Feb 2027

Additional Training

Cybersecurity Foundations: Governance, Risk, and Compliance (GRC)
LinkedIn Learning
Issued Jul 2024
Cyber Security Governance, Risk, and Compliance (GRC) Mastery
GRC Mastery
Issued Apr 2024

Core Skills

Microsoft Entra ID Active Directory Conditional Access Privileged Identity Management Role-Based Access Control Zero Trust Identity Protection Microsoft Graph PowerShell Hybrid Identity Entitlement Management Azure RBAC HIPAA / PII Compliance Federal Compliance Audit Readiness

Hands-On IAM Experience

Microsoft Entra ID & Active Directory — Hands-On Implementations

An ongoing body of hands-on identity and access management work in a live Microsoft Entra ID tenant integrated with an independently built AD DS lab environment hosted on an Azure Windows Server VM. The work covers privileged access governance, Conditional Access, identity risk management, application access, hybrid identity, and directory administration using the Entra admin center, Microsoft Graph PowerShell, Active Directory Users and Computers, and appropriate AD administrative tools.

Background: Transitioning into IAM from a compliance/GRC contractor role supporting a federal workforce program. This hands-on work translates governance and audit experience into practical identity infrastructure implementation, testing, and validation.

Access Governance, Privileged Access & Hybrid Identity

Conditional Access

Layered policies built and staged in report-only before enforcement: blocking legacy authentication and requiring compliant-device status for Office 365 access. Validated using the What If tool and the Conditional Access insights workbook before going live. Added a location-based Conditional Access control and validated the configured location condition against sign-in data and What If results before enforcement.

Privileged Identity Management (PIM)

Converted the Application Administrator role from standing access to just-in-time: PIM-eligible with a 90-day window, 8-hour max activation, and mandatory MFA plus written justification at activation. Verified through PIM audit logs confirming the full eligible-assignment and activation event trail.

Identity Protection

Built risk-based Conditional Access policies (sign-in risk medium+ → MFA; user risk high → MFA + forced password change), both in report-only with break-glass exclusion. Extended with a live Tor simulation to generate real anonymous-IP risk signals, reviewed in Risky Users and Risk Detections reports.

Access Reviews

Two recurring quarterly reviews — group membership and application role assignment — each with a 7-day window, auto-apply, and default decision of Deny, ensuring non-responsive reviewers result in automatic access removal.

Entitlement Management

Built a catalog and access package enabling self-service group membership requests through the My Access portal, gated by an approval workflow — replacing ad-hoc access grants with a governed, auditable process.

Hybrid Identity (Entra Connect)

Installed Entra Connect in the Azure-hosted AD DS lab environment and configured Password Hash Synchronization for selected OUs. Monitored synchronization operations, confirmed synchronized users in Entra ID with OnPremisesSyncEnabled: true, and validated hybrid authentication and Conditional Access MFA for synchronized users. Enabled password writeback to support the tested SSPR workflow.

Self-Service Password Reset (SSPR)

Scoped SSPR to a pilot security group, required registration and two authentication methods, and tested the reset workflow with a synchronized user. Confirmed password writeback to the Azure-hosted AD DS lab environment, validating the hybrid reset path end to end.

Application & Workload Identity

Enterprise Application Access

Configured an enterprise application to require assignment, assigned access to both a test user and a security group, and verified the resulting assignments and sign-in activity. Reviewed the application’s API permissions and admin-consent status as part of access validation.

App Registration & API Permissions

Registered an application with delegated (User.Read) and application-level (User.ReadWrite.All, Group.Read.All) Microsoft Graph permissions, granted admin consent, then audited credentials and flagged elevated permissions requiring business justification.

Managed Identity + Key Vault

Enabled a system-assigned managed identity on the domain controller VM, used the IMDS token flow to retrieve a Key Vault secret with zero stored credentials.

Custom Azure RBAC Role

Built a least-privilege custom role (read-only on VM properties and instance view) and assigned it to a test user, rather than using a broader built-in role.

Workload Identity Federation

Configured a federated credential on the registered app simulating GitHub Actions OIDC trust — passwordless, certificate-free workload authentication.

Directory Administration

Active Directory Build

Independently built a Windows Server 2025 domain controller on an Azure VM, promoted it to a new AD DS forest (jamielabstech.local), and confirmed the AD DS and DNS roles.

OU Structure, GPOs, Licensing & Group-Based Access

Built a department-based OU hierarchy (IT/HR), created users and security groups, and configured GPOs including login banner and Control Panel restriction for both departments, with command-prompt restriction added for HR.

Assigned licenses through a security group and verified license propagation to member accounts. Used security-group membership for enterprise-application access and demonstrated joiner, mover, and leaver changes by adding, changing, and removing memberships, then validating the resulting access state.

Verification Pattern

Key Microsoft Entra ID configurations were independently validated with Microsoft Graph PowerShell, while Active Directory configurations were checked with appropriate AD administrative tools and cmdlets. This provided independent confirmation beyond a single administrative view.

Experience

Admissions Representative
Jul 2023 – Present
Adams and Associates, Inc. · Client: U.S. Department of Labor, Job Corps · Atlanta, GA
  • Serve as the initial compliance gate for applicant identity records, reconciling government-issued identification and supporting documentation against application data and preventing incomplete or inconsistent files from advancing.
  • Adjudicate applicant eligibility using state and federal background-check findings, exercising final decision authority unless appealed and documenting determinations against Job Corps requirements.
  • Safeguard high-risk PII — including Social Security, immigration, financial, medical, mental-health, educational, and criminal-background records — under HIPAA and USDOL privacy procedures.
  • Maintain traceable case records documenting evidence received, verification actions, corrections, eligibility decisions, and stakeholder communications for managerial QA and periodic compliance examination.
Outreach & Admissions Counselor
Jul 2018 – Jun 2023
Management & Training Corporation · Client: U.S. Department of Labor, Job Corps · Atlanta, GA
  • Applied document-based identity-verification and eligibility controls across a five-year tenure, reviewing applicant files for completeness and accuracy before managerial and Job Corps review.
  • Prepared complete, organized application files for managerial, Job Corps, and periodic USDOL review, resolving missing or inconsistent evidence before submission.
  • Maintained decision traceability in secure federal systems by documenting verification actions, application changes, eligibility outcomes, and stakeholder communications.
  • Coordinated with applicants, managers, and Job Corps personnel to close documentation gaps and keep cases moving through the admissions process without bypassing requirements.

Contact

Seeking remote-first IAM Analyst and Identity Security roles. Open to Atlanta-area opportunities and available for contract, contract-to-hire, and full-time engagements.