About
I combine eight years of federally regulated compliance experience with independent hands-on identity and access management experience in Microsoft Entra ID and Active Directory.
Across that professional work, I have performed identity verification and eligibility adjudication, reviewed supporting evidence, safeguarded sensitive PII, maintained regulatory documentation and decision traceability, and communicated with applicants, managers, and program stakeholders.
Separately, my independent hands-on IAM experience includes identity and access management implementation, testing, troubleshooting, and validation in Microsoft Entra ID and Active Directory. I am a Microsoft Certified Identity and Access Administrator (SC-300) with hands-on experience in Conditional Access policies and role-based access control.
My background supporting the U.S. Department of Labor as a contracting client gave me a strong foundation in data integrity, regulatory adherence, and the protection of sensitive personal and financial information — including HIPAA regulations and PII protection standards. I bring a detail-oriented, compliance-minded approach to IAM: understanding not just how access works, but why it matters for organizational security and regulatory accountability.
Seeking remote-first IAM Analyst and Identity Security roles. Open to local Atlanta opportunities and available for contract, contract-to-hire, and full-time engagements.
Certifications
Additional Training
Core Skills
Hands-On IAM Experience
Microsoft Entra ID & Active Directory — Hands-On Implementations
An ongoing body of hands-on identity and access management work in a live Microsoft Entra ID tenant integrated with an independently built AD DS lab environment hosted on an Azure Windows Server VM. The work covers privileged access governance, Conditional Access, identity risk management, application access, hybrid identity, and directory administration using the Entra admin center, Microsoft Graph PowerShell, Active Directory Users and Computers, and appropriate AD administrative tools.
Background: Transitioning into IAM from a compliance/GRC contractor role supporting a federal workforce program. This hands-on work translates governance and audit experience into practical identity infrastructure implementation, testing, and validation.
Access Governance, Privileged Access & Hybrid Identity
Layered policies built and staged in report-only before enforcement: blocking legacy authentication and requiring compliant-device status for Office 365 access. Validated using the What If tool and the Conditional Access insights workbook before going live. Added a location-based Conditional Access control and validated the configured location condition against sign-in data and What If results before enforcement.
Converted the Application Administrator role from standing access to just-in-time: PIM-eligible with a 90-day window, 8-hour max activation, and mandatory MFA plus written justification at activation. Verified through PIM audit logs confirming the full eligible-assignment and activation event trail.
Built risk-based Conditional Access policies (sign-in risk medium+ → MFA; user risk high → MFA + forced password change), both in report-only with break-glass exclusion. Extended with a live Tor simulation to generate real anonymous-IP risk signals, reviewed in Risky Users and Risk Detections reports.
Two recurring quarterly reviews — group membership and application role assignment — each with a 7-day window, auto-apply, and default decision of Deny, ensuring non-responsive reviewers result in automatic access removal.
Built a catalog and access package enabling self-service group membership requests through the My Access portal, gated by an approval workflow — replacing ad-hoc access grants with a governed, auditable process.
Installed Entra Connect in the Azure-hosted AD DS lab environment and configured Password Hash Synchronization for selected OUs. Monitored synchronization operations, confirmed synchronized users in Entra ID with OnPremisesSyncEnabled: true, and validated hybrid authentication and Conditional Access MFA for synchronized users. Enabled password writeback to support the tested SSPR workflow.
Scoped SSPR to a pilot security group, required registration and two authentication methods, and tested the reset workflow with a synchronized user. Confirmed password writeback to the Azure-hosted AD DS lab environment, validating the hybrid reset path end to end.
Application & Workload Identity
Configured an enterprise application to require assignment, assigned access to both a test user and a security group, and verified the resulting assignments and sign-in activity. Reviewed the application’s API permissions and admin-consent status as part of access validation.
Registered an application with delegated (User.Read) and application-level (User.ReadWrite.All, Group.Read.All) Microsoft Graph permissions, granted admin consent, then audited credentials and flagged elevated permissions requiring business justification.
Enabled a system-assigned managed identity on the domain controller VM, used the IMDS token flow to retrieve a Key Vault secret with zero stored credentials.
Built a least-privilege custom role (read-only on VM properties and instance view) and assigned it to a test user, rather than using a broader built-in role.
Configured a federated credential on the registered app simulating GitHub Actions OIDC trust — passwordless, certificate-free workload authentication.
Directory Administration
Independently built a Windows Server 2025 domain controller on an Azure VM, promoted it to a new AD DS forest (jamielabstech.local), and confirmed the AD DS and DNS roles.
Built a department-based OU hierarchy (IT/HR), created users and security groups, and configured GPOs including login banner and Control Panel restriction for both departments, with command-prompt restriction added for HR.
Assigned licenses through a security group and verified license propagation to member accounts. Used security-group membership for enterprise-application access and demonstrated joiner, mover, and leaver changes by adding, changing, and removing memberships, then validating the resulting access state.
Key Microsoft Entra ID configurations were independently validated with Microsoft Graph PowerShell, while Active Directory configurations were checked with appropriate AD administrative tools and cmdlets. This provided independent confirmation beyond a single administrative view.
Experience
- Serve as the initial compliance gate for applicant identity records, reconciling government-issued identification and supporting documentation against application data and preventing incomplete or inconsistent files from advancing.
- Adjudicate applicant eligibility using state and federal background-check findings, exercising final decision authority unless appealed and documenting determinations against Job Corps requirements.
- Safeguard high-risk PII — including Social Security, immigration, financial, medical, mental-health, educational, and criminal-background records — under HIPAA and USDOL privacy procedures.
- Maintain traceable case records documenting evidence received, verification actions, corrections, eligibility decisions, and stakeholder communications for managerial QA and periodic compliance examination.
- Applied document-based identity-verification and eligibility controls across a five-year tenure, reviewing applicant files for completeness and accuracy before managerial and Job Corps review.
- Prepared complete, organized application files for managerial, Job Corps, and periodic USDOL review, resolving missing or inconsistent evidence before submission.
- Maintained decision traceability in secure federal systems by documenting verification actions, application changes, eligibility outcomes, and stakeholder communications.
- Coordinated with applicants, managers, and Job Corps personnel to close documentation gaps and keep cases moving through the admissions process without bypassing requirements.
Contact
Seeking remote-first IAM Analyst and Identity Security roles. Open to Atlanta-area opportunities and available for contract, contract-to-hire, and full-time engagements.