Identity & Compliance Engineer
Designing and engineering identity security infrastructure for financial services, healthcare, and federal environments — from the identity provider to the compliance audit trail.
Engineering Tracks
Federated identity, OIDC/SAML, Joiner-Mover-Leaver automation, and PostgreSQL audit pipelines built on Keycloak and RHEL 10.
HashiCorp Vault credential vaulting, AppRole machine identity, Ansible-automated rotation, and tamper-evident SHA-256 audit trails.
AI-assisted access certification, continuous compliance monitoring, and cross-framework evidence generation across PCI DSS, SOX, NIST, and HIPAA.
Platform Projects
Enterprise identity provider with OIDC/SAML, Python JML automation, PostgreSQL audit pipeline, and 51 mapped compliance controls.
CyberArk-equivalent PAM environment with HashiCorp Vault, AppRole auth, Ansible rotation, TLS, and SHA-256 tamper evidence.
Hybrid SIEM ingesting Okta logs via EC2 poller into Kinesis Firehose, S3, and Athena. Lambda + Bedrock AI threat analysis, EventBridge alerting, CloudTrail, QuickSight SOC dashboard, and GitHub Actions CI/CD.
Audits AWS IAM policies for least-privilege violations. Bedrock AI risk narratives, async Flask job engine, cross-project Athena queries, CRITICAL SNS alerts, QuickSight dashboard.
Access Certification (GRC1) — AI-hardened MFA certification pipeline pulling from Keycloak, evaluating compliance via Bedrock, writing immutable SQLite audit evidence, and firing SNS REVOKE alerts. Maps to PCI DSS Req 8.4.2. | Compliance Monitor (GRC2) — Five-layer EventBridge → Lambda → Bedrock pipeline generating XML-isolated risk narratives, idempotent SQLite evidence, and Flask reviewer UI. Maps to PCI DSS Req 6.4.3 + Req 10.4.1.1.
Programmatic identity governance across Okta, AWS IAM, Microsoft Entra ID, and GCP — concurrent drift detection, automated dual-plane remediation, JIT privilege escalation, risk-based Conditional Access, and a federated AWS data lake. Five ADRs documenting every major design decision. Portfolio site hosted on GCP with WIF-powered keyless deploy pipeline.
"Compliance shouldn't be a lagging, reactive check. It's an active architectural layer engineered directly into the infrastructure from day one."
Compliance Coverage