Identity & Compliance Engineer
Designing and engineering identity security infrastructure for financial services, healthcare, and federal environments — from the identity provider to the compliance audit trail.
Engineering Tracks
Federated identity, OIDC/SAML, Joiner-Mover-Leaver automation, and PostgreSQL audit pipelines built on Keycloak and RHEL 10.
HashiCorp Vault credential vaulting, AppRole machine identity, Ansible-automated rotation, and tamper-evident SHA-256 audit trails.
AI-assisted access certification, continuous compliance monitoring, and cross-framework evidence generation across PCI DSS, SOX, NIST, and HIPAA.
Platform Projects
Enterprise IAM platform with OIDC/SAML, Python JML lifecycle automation, PostgreSQL audit schema, and 51 mapped compliance controls. Enhanced with Kubernetes Operator deployment, Prometheus/Grafana/Alertmanager observability stack, NetworkPolicy hardening, and per-workload ServiceAccounts — each fix traced to a verified root cause.
CyberArk-equivalent PAM environment with HashiCorp Vault, AppRole auth, Ansible rotation, TLS, and SHA-256 tamper evidence. Enhanced with Vault Agent Injector on Kubernetes — including root-cause investigation of a silent cert-rotation failure masked by a permissive webhook policy — plus RBAC and NetworkPolicy hardening.
Hybrid SIEM ingesting Okta logs via EC2 poller into Kinesis Firehose, S3, and Athena. Lambda + Bedrock AI threat analysis, EventBridge alerting, CloudTrail Insights anomaly detection, QuickSight SOC dashboard, and GitHub Actions GitOps CI/CD. Shared data lake consumed by P4, GRC P2, and MIG.
Audits AWS IAM policies for least-privilege violations via a 13-rule weighted engine. Bedrock AI risk narratives, async Flask job engine, cross-project Athena correlation, CRITICAL SNS alerts. ITDR Wave added Azure RBAC detection (6 rules), JIT access remediation, Prometheus/Grafana observability, and shared Alertmanager routing with MIG — catching two real production bugs via FP/FN testing before they shipped.
Access Certification (GRC1) — AI-hardened MFA certification pipeline pulling live identity state from Keycloak, evaluating compliance via Bedrock with prompt injection protection, writing immutable SQLite audit evidence, and firing SNS REVOKE alerts. Enhanced with full Kubernetes deployment, OIDC login gate, Jenkins CI/CD, and NetworkPolicy hardening. Maps to PCI DSS Req 8.4.2. | Compliance Monitor (GRC2) — EventBridge → Lambda → Bedrock pipeline generating XML-isolated risk narratives, idempotent SQLite evidence, and Flask reviewer UI with 30s auto-refresh. Maps to PCI DSS Req 6.4.3 + Req 10.4.1.1.
Reconciliation and entitlement engine pulling live state from Okta, AWS IAM, and GCP concurrently on a 6-hour cadence — detecting orphaned accounts, inactive credentials, and ungoverned service accounts across all three planes and auto-remediating under a circuit breaker. ITDR Wave added full Prometheus/Grafana/Alertmanager observability, cross-project Athena correlation with P4, and NHI governance that caught the engine's own service account as ungoverned in its first live run. GCP hosting for this site is a byproduct of this project — deployed via Terraform + WIF-federated GitHub Actions with zero stored credentials.
All repositories available upon request — contact me or connect on LinkedIn.
"Compliance shouldn't be a lagging, reactive check. It's an active architectural layer engineered directly into the infrastructure from day one."
Compliance Coverage