Non-Human Identity Governance · IGA Lifecycle Automation · Compliance Evidence · AWS Security
I design and automate IGA lifecycle systems, cloud IAM controls, and compliance evidence pipelines. Now extending identity governance into non-human and AI-agent identities, the fastest-growing gap in enterprise IAM.
Open to IGA Engineer · IAM Engineer · Cloud Security Engineer roles.
The full program is below. If you have a minute, start with these: machine-identity governance, human-identity lifecycle, and compliance evidence as code.
Seven projects across the identity and cloud security stack: non-human identity governance, IGA lifecycle automation, GRC engineering, policy-as-code guardrails, identity threat detection, Zero Trust, and multi-account architecture, with working code and outcomes from controlled AWS environments.
A non-human identity governance engine that scans an AWS account and scores the identities people forget — IAM roles, users, access keys, secrets, and trust policies — mapping every finding to the OWASP NHI Top 10 and NIST 800-53, and gating CI on unaccepted high-severity risk.
An end-to-end Identity Governance and Administration build: HR-sourced joiner, mover, and leaver lifecycle on midPoint and 389 Directory Server, with reconciliation, non-human identity disposition, and a Python evidence validator that proves the directory matches the source of truth.
An engineering-driven approach to Governance, Risk, and Compliance on AWS. This framework interrogates AWS APIs directly — producing structured evidence, risk-scored findings, and audit-style reporting across six major compliance frameworks simultaneously.
Preventive guardrails that evaluate a Terraform plan before apply and fail the build when a change would violate a security control. The shift-left counterpart to the NHI engine: the engine detects risky identities that already exist, these guardrails stop a class of misconfigurations from ever deploying.
terraform show -json plan outputopa test and enforced as a GitHub Actions CI gate that blocks violating plansAn event-driven detection pipeline that surfaces high-signal IAM anomalies in near real-time. Built with a QA engineer's approach to signal quality — systematic false positive tuning distinguishes legitimate activity from genuine risk.
A three-stack AWS serverless application built on Zero Trust design principles — every request authenticated, every resource encrypted, every action logged. Demonstrates the IAM and data protection controls validated by the GRC Engineering framework, built as infrastructure as code with AWS CDK.
A security-first AWS reference architecture for retail workloads — demonstrating architect-level thinking across trust boundary separation, multi-account org design, and layered security controls. Grounded in real retail business context: customer identity, order workflows, payment-adjacent services, and prod/non-prod isolation.
Identity governance is the center; cloud architecture, control automation, detection, and evidence engineering are the layers that support it. Every project answers one question in a complete program, from identity through architecture, detection, response, and governance.
Every repo answers one question in the security program. Together they form a complete cloud security governance narrative.
Eleven detectors that scan an AWS account for risky non-human identities — over-privilege, wildcard and cross-account trust, OIDC gaps, ownership, and static credentials — mapped to the OWASP NHI Top 10 and NIST 800-53. OIDC-federated CI, an exception register, and a CI gate on high-severity findings.
16 automated controls, risk scoring, framework mapping, immutable evidence vault. The anchor of the portfolio.
Event-driven pipeline targeting unauthorized AssumeRole activity. Tuned false-positive handling. MITRE ATT&CK mapped.
Multi-account org design with trust boundary separation, centralized logging, layered ingress, and prod/non-prod isolation. Grounded in Genesco retail domain — customer identity, order workflows, payment-adjacent services.
Cognito JWT auth with DynamoDB access scoped to authenticated sub claim. BOLA/IDOR prevention, split Lambda execution roles, KMS encryption, CDK IaC.
Security Hub → Step Functions response workflows. Automated containment with approval gates. IR runbooks as code.
OPA Rego guardrails run with Conftest against Terraform plans before apply. Denies public S3, open admin ports, wildcard IAM, unencrypted storage, and missing Owner tags. NIST-mapped, opa-tested, and enforced as a CI gate.
Compliance score, risk register, framework heatmap. Ingests GRC framework output. Designed for CISO and audit committee audiences.
Where each skill actually shows up in the work, so this portfolio maps to a role description in seconds.
| Skill | Project proof |
|---|---|
| AWS IAM | NHI Engine · Cross-Account Detection · Zero Trust Serverless |
| IGA lifecycle (joiner / mover / leaver) | Enterprise IAM Lifecycle Automation |
| Non-human identity governance | NHI Governance Engine |
| Python automation | NHI Engine · GRC Framework · Detection Pipeline |
| Terraform | GRC Project · Policy-as-Code Guardrails |
| Policy-as-code (OPA / Rego) | Policy-as-Code Guardrails |
| Detection engineering | IAM Cross-Account Detection Pipeline |
| Compliance evidence automation | GRC Framework · IAM Lifecycle Automation |
| Cloud security architecture | Secure Multi-Account Architecture · Zero Trust Serverless |
I bring a background in QA Automation Engineering and Linux Systems Administration into identity governance and cloud security engineering.
My QA background gives me something most cloud security engineers don't have: I understand how to build systems that prove they work, not just claim they do. Test cases became detection rules. Root cause analysis became alert triage. Regression tracking became detection coverage mapping.
"I can design, secure, govern, detect, respond to, and automate compliance for AWS environments — and explain why each layer matters to the business."
Before cloud security, I spent years in security-critical retail infrastructure — automated testing of authentication flows, RBAC enforcement, payment processing, and multi-tenant data integrity across 1,000+ retail locations. That's where I learned how systems fail from the inside out.
Now I apply that discipline to identity governance: building the IGA lifecycle systems, access controls, and evidence pipelines that make identity and compliance measurable and repeatable at scale. Based in Nashville, TN. Open to remote and hybrid roles.
These are portfolio projects built in controlled AWS and local lab environments to model real-world identity, cloud security, detection, policy-as-code, and compliance-evidence workflows. They include working code, tests, CI, sample outputs, and documented limitations. They are not presented as production systems operated inside a large enterprise.
Open to Identity Governance (IGA) Engineer, IAM Engineer, Cloud Security Engineer, and GRC Engineering roles. Nashville, TN. Remote and hybrid considered.