About
Identity and access management professional with 8 years enforcing identity-verification and compliance gating for federally regulated PII under USDOL oversight — the front-end control point for identity lifecycle, recertification, and audit-evidence integrity.
Certified Microsoft Identity and Access Administrator (SC-300) with hands-on experience in Microsoft Entra ID, Active Directory, Conditional Access policies, and role-based access control.
My background supporting the U.S. Department of Labor as a contracting client gave me a strong foundation in data integrity, regulatory adherence, and the protection of sensitive personal and financial information — including HIPAA regulations and PII protection standards. I bring a detail-oriented, compliance-minded approach to IAM: understanding not just how access works, but why it matters for organizational security and regulatory accountability.
Seeking remote-first IAM Analyst and Identity Security roles. Open to local Atlanta opportunities and available for contract, contract-to-hire, and full-time engagements.
Certifications
Core Skills
IAM Lab Project
Microsoft Entra ID & Active Directory — Hands-On IAM Build
A hands-on identity and access management build in a live Microsoft Entra ID tenant with a synced on-premises Active Directory forest, covering privileged access governance, Conditional Access, identity risk management, and hybrid identity — executed through the Entra admin center, Active Directory Users and Computers, and Microsoft Graph PowerShell.
Background: Transitioning into IAM from a compliance/GRC contractor role supporting a federal workforce program. This lab translates governance and audit experience into hands-on identity infrastructure work.
Access Governance, Privileged Access & Hybrid Identity
Layered policies built and staged in report-only before enforcement: blocking legacy authentication and requiring compliant-device status for Office 365 access. Validated using the What If tool and the Conditional Access insights workbook before going live.
Converted the Application Administrator role from standing access to just-in-time: PIM-eligible with a 90-day window, 8-hour max activation, and mandatory MFA plus written justification at activation. Verified through PIM audit logs confirming the full eligible-assignment and activation event trail.
Built risk-based Conditional Access policies (sign-in risk medium+ → MFA; user risk high → MFA + forced password change), both in report-only with break-glass exclusion. Extended with a live Tor simulation to generate real anonymous-IP risk signals, reviewed in Risky Users and Risk Detections reports.
Two recurring quarterly reviews — group membership and application role assignment — each with a 7-day window, auto-apply, and default decision of Deny, ensuring non-responsive reviewers result in automatic access removal.
Built a catalog and access package enabling self-service group membership requests through the My Access portal, gated by an approval workflow — replacing ad-hoc access grants with a governed, auditable process.
Installed Entra Connect on the domain controller, configured Password Hash Sync scoped to specific OUs, confirmed all AD users landed in Entra ID with OnPremisesSyncEnabled: true. Validated hybrid sign-in end-to-end, enabled password writeback, and tested Conditional Access MFA against synced users.
Application & Workload Identity
Registered an application with delegated (User.Read) and application-level (User.ReadWrite.All, Group.Read.All) Microsoft Graph permissions, granted admin consent, then audited credentials and flagged elevated permissions requiring business justification.
Enabled a system-assigned managed identity on the domain controller VM, used the IMDS token flow to retrieve a Key Vault secret with zero stored credentials.
Built a least-privilege custom role (read-only on VM properties and instance view) and assigned it to a test user, rather than using a broader built-in role.
Configured a federated credential on the registered app simulating GitHub Actions OIDC trust — passwordless, certificate-free workload authentication.
Directory Administration
Stood up a Windows Server 2025 domain controller from scratch on Azure, promoted to a new forest (jamielabstech.local), and confirmed AD DS and DNS roles.
Built a department-based OU hierarchy (IT/HR), created users and security groups, and configured GPOs including login banner and Control Panel restriction for both departments, with command-prompt restriction added for HR.
Every change made in the portal was confirmed independently via Microsoft Graph PowerShell or AD cmdlets — mirroring real-world change validation rather than relying on a single source of truth.
Experience
- Collected, verified, and safeguarded highly sensitive PII — SSNs, passports, health records, criminal background records — received from applicants and referrals, applying strict confidentiality and need-to-know handling throughout.
- Enforced HIPAA and USDOL data privacy requirements through rigorous verification of applicant identity documents at intake, certifying each file complete, accurate, and compliant before it could advance for review.
- Maintained detailed case notes and audit trails documenting all access events, data reviews, and stakeholder communications across a continuously active caseload, supporting audit readiness on demand.
- Managed sensitive case data through its full lifecycle within secure federal IT systems, operating under role-based permissions and maintaining strict data-handling compliance.
- Supported internal and external compliance audits by compiling access records and producing audit-ready evidence packages aligned with USDOL security requirements.
- Collaborated with IT, HR, and security teams to identify data protection and compliance gaps and advance data privacy program objectives.
Contact
Seeking remote-first IAM Analyst and Identity Security roles. Open to Atlanta-area opportunities and available for contract, contract-to-hire, and full-time engagements.