Identity & Compliance Engineer

Renee Brathwaite
builds secure systems.

Designing and engineering identity security infrastructure for financial services, healthcare, and federal environments — from the identity provider to the compliance audit trail.

Google Cybersecurity· Google Data Analytics· MySQL Data Analysis· Security+ in progress

Three layers.
One platform.

IAM

Identity & Access Management

Federated identity, OIDC/SAML, Joiner-Mover-Leaver automation, and PostgreSQL audit pipelines built on Keycloak and RHEL 10.

PAM

Privileged Access Management

HashiCorp Vault credential vaulting, AppRole machine identity, Ansible-automated rotation, and tamper-evident SHA-256 audit trails.

GRC

Governance, Risk & Compliance

AI-assisted access certification, continuous compliance monitoring, and cross-framework evidence generation across PCI DSS, SOX, NIST, and HIPAA.

Seven projects.
One connected system.

P1 — IAMLive

Keycloak IAM Lab

Enterprise identity provider with OIDC/SAML, Python JML automation, PostgreSQL audit pipeline, and 51 mapped compliance controls.

Keycloak 26.2.4 · PostgreSQL 16 · Python · RHEL 10
View on GitHub →
P2 — PAMLive

PAM Simulation

CyberArk-equivalent PAM environment with HashiCorp Vault, AppRole auth, Ansible rotation, TLS, and SHA-256 tamper evidence.

HashiCorp Vault · Ansible · Python · TLS
View on GitHub →
P3 — SIEMComplete

Okta AWS SIEM Pipeline

Hybrid SIEM ingesting Okta logs via EC2 poller into Kinesis Firehose, S3, and Athena. Lambda + Bedrock AI threat analysis, EventBridge alerting, CloudTrail, QuickSight SOC dashboard, and GitHub Actions CI/CD.

Okta API · Firehose · Lambda · Bedrock · EventBridge · Terraform · GitHub Actions
P4 — AuditComplete

IAM Policy Auditor AI

Audits AWS IAM policies for least-privilege violations. Bedrock AI risk narratives, async Flask job engine, cross-project Athena queries, CRITICAL SNS alerts, QuickSight dashboard.

Bedrock · IAM · SQLite · Athena · QuickSight · Flask
View on GitHub →
GRC1 + GRC2 — Compliance PlatformComplete

GRC Platform

Access Certification (GRC1) — AI-hardened MFA certification pipeline pulling from Keycloak, evaluating compliance via Bedrock, writing immutable SQLite audit evidence, and firing SNS REVOKE alerts. Maps to PCI DSS Req 8.4.2.  |  Compliance Monitor (GRC2) — Five-layer EventBridge → Lambda → Bedrock pipeline generating XML-isolated risk narratives, idempotent SQLite evidence, and Flask reviewer UI. Maps to PCI DSS Req 6.4.3 + Req 10.4.1.1.

Bedrock · Keycloak · Lambda · EventBridge · SQLite · SNS · Athena · Flask
GRC1 Repo → GRC2 Repo → Full Detail →
P7 — IAMIn Progress

Tri-Cloud Identity Governance Engine

Programmatic identity governance across Okta, AWS IAM, Microsoft Entra ID, and GCP — concurrent drift detection, automated dual-plane remediation, JIT privilege escalation, risk-based Conditional Access, and a federated AWS data lake. Five ADRs documenting every major design decision. Portfolio site hosted on GCP with WIF-powered keyless deploy pipeline.

Entra ID · Graph API · PIM · Okta · AWS IAM · GCP Asset Inventory · WIF · Terraform · Python · RHEL 10
Target: July 2026
View All Projects →
Build
Philosophy
"Compliance shouldn't be a lagging, reactive check. It's an active architectural layer engineered directly into the infrastructure from day one."
PCI DSS v4.0 NIST SP 800-53 r5 NIST CSF SOX ITGC ISO 27001:2022 HIPAA Security Rule CIS RHEL 10 CIS AWS Foundations