About

Identity and access management professional with 8 years enforcing identity-verification and compliance gating for federally regulated PII under USDOL oversight — the front-end control point for identity lifecycle, recertification, and audit-evidence integrity.

Certified Microsoft Identity and Access Administrator (SC-300) with hands-on experience in Microsoft Entra ID, Active Directory, Conditional Access policies, and role-based access control.

My background supporting the U.S. Department of Labor as a contracting client gave me a strong foundation in data integrity, regulatory adherence, and the protection of sensitive personal and financial information — including HIPAA regulations and PII protection standards. I bring a detail-oriented, compliance-minded approach to IAM: understanding not just how access works, but why it matters for organizational security and regulatory accountability.

Seeking remote-first IAM Analyst and Identity Security roles. Open to local Atlanta opportunities and available for contract, contract-to-hire, and full-time engagements.

Certifications

Microsoft Certified: Identity and Access Administrator Associate
Microsoft
Issued Apr 2026 · Expires Apr 2027 · SC-300
Microsoft Certified: Azure Fundamentals
Microsoft
Issued Jan 2025 · AZ-900
CompTIA Security+ ce Certification
CompTIA
Issued Feb 2024 · Expires Feb 2027
Cybersecurity Foundations: Governance, Risk, and Compliance (GRC)
LinkedIn Learning
Issued Jul 2024
Cyber Security Governance, Risk, and Compliance (GRC) Mastery
GRC Mastery
Issued Apr 2024

Core Skills

Microsoft Entra ID Active Directory Conditional Access Privileged Identity Management Role-Based Access Control Zero Trust Identity Protection Microsoft Graph PowerShell Hybrid Identity Entitlement Management Azure RBAC HIPAA / PII Compliance Federal Compliance Audit Readiness

IAM Lab Project

Microsoft Entra ID & Active Directory — Hands-On IAM Build

A hands-on identity and access management build in a live Microsoft Entra ID tenant with a synced on-premises Active Directory forest, covering privileged access governance, Conditional Access, identity risk management, and hybrid identity — executed through the Entra admin center, Active Directory Users and Computers, and Microsoft Graph PowerShell.

Background: Transitioning into IAM from a compliance/GRC contractor role supporting a federal workforce program. This lab translates governance and audit experience into hands-on identity infrastructure work.

Access Governance, Privileged Access & Hybrid Identity

Conditional Access

Layered policies built and staged in report-only before enforcement: blocking legacy authentication and requiring compliant-device status for Office 365 access. Validated using the What If tool and the Conditional Access insights workbook before going live.

Privileged Identity Management (PIM)

Converted the Application Administrator role from standing access to just-in-time: PIM-eligible with a 90-day window, 8-hour max activation, and mandatory MFA plus written justification at activation. Verified through PIM audit logs confirming the full eligible-assignment and activation event trail.

Identity Protection

Built risk-based Conditional Access policies (sign-in risk medium+ → MFA; user risk high → MFA + forced password change), both in report-only with break-glass exclusion. Extended with a live Tor simulation to generate real anonymous-IP risk signals, reviewed in Risky Users and Risk Detections reports.

Access Reviews

Two recurring quarterly reviews — group membership and application role assignment — each with a 7-day window, auto-apply, and default decision of Deny, ensuring non-responsive reviewers result in automatic access removal.

Entitlement Management

Built a catalog and access package enabling self-service group membership requests through the My Access portal, gated by an approval workflow — replacing ad-hoc access grants with a governed, auditable process.

Hybrid Identity (Entra Connect)

Installed Entra Connect on the domain controller, configured Password Hash Sync scoped to specific OUs, confirmed all AD users landed in Entra ID with OnPremisesSyncEnabled: true. Validated hybrid sign-in end-to-end, enabled password writeback, and tested Conditional Access MFA against synced users.

Application & Workload Identity

App Registration & API Permissions

Registered an application with delegated (User.Read) and application-level (User.ReadWrite.All, Group.Read.All) Microsoft Graph permissions, granted admin consent, then audited credentials and flagged elevated permissions requiring business justification.

Managed Identity + Key Vault

Enabled a system-assigned managed identity on the domain controller VM, used the IMDS token flow to retrieve a Key Vault secret with zero stored credentials.

Custom Azure RBAC Role

Built a least-privilege custom role (read-only on VM properties and instance view) and assigned it to a test user, rather than using a broader built-in role.

Workload Identity Federation

Configured a federated credential on the registered app simulating GitHub Actions OIDC trust — passwordless, certificate-free workload authentication.

Directory Administration

Active Directory Build

Stood up a Windows Server 2025 domain controller from scratch on Azure, promoted to a new forest (jamielabstech.local), and confirmed AD DS and DNS roles.

OU Structure, GPOs & Group-Based Licensing

Built a department-based OU hierarchy (IT/HR), created users and security groups, and configured GPOs including login banner and Control Panel restriction for both departments, with command-prompt restriction added for HR.

Verification Pattern

Every change made in the portal was confirmed independently via Microsoft Graph PowerShell or AD cmdlets — mirroring real-world change validation rather than relying on a single source of truth.

Experience

Admissions Representative
Jul 2023 – Present
Adams and Associates, Inc. · Client: U.S. Department of Labor, Job Corps · Atlanta, GA
  • Collected, verified, and safeguarded highly sensitive PII — SSNs, passports, health records, criminal background records — received from applicants and referrals, applying strict confidentiality and need-to-know handling throughout.
  • Enforced HIPAA and USDOL data privacy requirements through rigorous verification of applicant identity documents at intake, certifying each file complete, accurate, and compliant before it could advance for review.
  • Maintained detailed case notes and audit trails documenting all access events, data reviews, and stakeholder communications across a continuously active caseload, supporting audit readiness on demand.
Outreach & Admissions Counselor
Jul 2018 – Jun 2023
Management & Training Corporation · Client: U.S. Department of Labor, Job Corps · Atlanta, GA
  • Managed sensitive case data through its full lifecycle within secure federal IT systems, operating under role-based permissions and maintaining strict data-handling compliance.
  • Supported internal and external compliance audits by compiling access records and producing audit-ready evidence packages aligned with USDOL security requirements.
  • Collaborated with IT, HR, and security teams to identify data protection and compliance gaps and advance data privacy program objectives.

Contact

Seeking remote-first IAM Analyst and Identity Security roles. Open to Atlanta-area opportunities and available for contract, contract-to-hire, and full-time engagements.