Identity Governance & Cloud Security Engineer · Nashville, TN

I build identity governance
that proves itself.

Identity Governance · IGA Lifecycle Automation · Compliance Evidence · AWS Security

AWS Security Specialty Solutions Architect Associate CompTIA Security+ RHCE / RHCSA PMP

I design and automate IGA lifecycle systems, cloud IAM controls, and compliance evidence pipelines. Now extending identity governance into non-human and AI-agent identities, the fastest-growing gap in enterprise IAM.

16
Controls automated
6
Frameworks mapped
6
Certifications
17K+
Impressions
The Security Program

One system. Seven layers.

Every project answers one question in a complete cloud security program. Together they form an integrated narrative — from identity through architecture, detection, response, and governance.

Layer 1 · Identity
IAM Governance
"Who can touch what? How is the lifecycle governed?"
Enterprise IAM Lifecycle Automation  ·  Complete
HR-sourced joiner-mover-leaver lifecycle on midPoint and 389 Directory Server. Reconciliation, non-human identity disposition, and a Python evidence validator that proves the directory matches the source of truth.
Zero Trust Serverless Architecture  ·  Complete
Identity governance at the application layer — Cognito JWT auth with DynamoDB access scoped to the authenticated sub claim. BOLA/IDOR prevention on every request.
AWS NHI Governance Engine  ·  Building
Discovers and scores non-human identities (IAM roles, access keys, secrets) across an AWS account, mapping findings to the OWASP NHI Top 10 and NIST 800-53. Includes OIDC-federated workload identity, and extends toward AI-agent identity governance.
Partial
Layer 2 · Architecture
Secure Environment
"What are we governing? How is the environment structured?"
Secure Multi-Account AWS Architecture for Retail Platforms
Multi-account org design, trust boundary separation, centralized logging, and layered ingress — grounded in real retail domain context. Customer identity, order workflows, payment-adjacent services, and prod/non-prod isolation.
Complete
Layer 3 · GRC
Control & Evidence
"Are the controls actually working? Can we prove it?"
AWS GRC Engineering Project
16 automated controls across IAM, S3, CloudTrail, GuardDuty, and Security Hub. Risk scoring, framework mapping, and immutable evidence storage.
Complete
Layer 4 · Detection
Identity Threat Detection
"How do we know when something goes wrong?"
IAM Cross-Account Detection Pipeline
Event-driven detection rules mapped to MITRE ATT&CK. CloudTrail → EventBridge → Lambda enrichment → structured findings with false positive tuning.
Complete
Layer 5 · Response
Incident Response
"What happens automatically when a control fails?"
AWS Incident Response Automation
Security Hub → Step Functions response workflows. Automated containment with approval gates. Runbooks as code.
Planned
Layer 6 · Prevention
Policy as Code
"How do we stop non-compliant infrastructure before it deploys?"
AWS Policy as Code
AWS Config custom rules, SCPs, Checkov pre-commit scanning, OPA Terraform validation. Compliance shifted left.
Planned
Layer 7 · Leadership
Executive Dashboard
"How do we translate technical controls into business risk language?"
AWS Executive Risk Dashboard
Compliance score, risk register, framework heatmap. Ingests GRC framework output. Designed for CISO and audit committee audiences.
Planned
Full Portfolio

All projects.

Every repo answers one question in the security program. Together they form a complete cloud security governance narrative.

Layer 3 · GRC Engineering
AWS GRC Engineering Project
"Proves the controls are working."

16 automated controls, risk scoring, framework mapping, immutable evidence vault. The anchor of the portfolio.

Layer 4 · Identity Threat Detection
IAM Cross-Account Detection Pipeline
"Detects when IAM controls are violated."

Event-driven pipeline targeting unauthorized AssumeRole activity. Production-grade false positive tuning. MITRE ATT&CK mapped.

Layer 2 · Architecture
Secure Multi-Account AWS Architecture for Retail
"Defines the environment these controls govern."

Multi-account org design with trust boundary separation, centralized logging, layered ingress, and prod/non-prod isolation. Grounded in Genesco retail domain — customer identity, order workflows, payment-adjacent services.

Layer 1 · Identity Governance
Zero Trust Serverless Architecture
"Governs identity on every request at the workload level."

Cognito JWT auth with DynamoDB access scoped to authenticated sub claim. BOLA/IDOR prevention, split Lambda execution roles, KMS encryption, CDK IaC.

Layer 1 · Identity Governance
AWS NHI Governance Engine
"Governs the identities people forget: machines, workloads, and AI agents."

Discovers and scores non-human identities across an AWS account (IAM roles, access keys, secrets), mapping findings to the OWASP NHI Top 10 and NIST 800-53. Includes OIDC-federated workload identity and extends toward AI-agent identity governance.

Layer 5 · Response
AWS Incident Response Automation
"Automates what happens when a control fails."

Security Hub → Step Functions response workflows. Automated containment with approval gates. IR runbooks as code.

Layer 6 · Prevention
AWS Policy as Code
"Prevents non-compliant infrastructure before it deploys."

Config custom rules, SCPs, Checkov pre-commit hooks, OPA Terraform validation. Compliance shifted left.

Layer 7 · Leadership
AWS Executive Risk Dashboard
"Translates technical controls into business risk language."

Compliance score, risk register, framework heatmap. Ingests GRC framework output. Designed for CISO and audit committee audiences.

About

The background
behind the builds.

I am a cloud security professional transitioning from QA Automation Engineering and Linux Systems Administration into identity governance and cloud security.

My QA background gives me something most cloud security engineers don't have: I understand how to build systems that prove they work, not just claim they do. Test cases became detection rules. Root cause analysis became alert triage. Regression tracking became detection coverage mapping.

"I can design, secure, govern, detect, respond to, and automate compliance for AWS environments — and explain why each layer matters to the business."

Before cloud security, I spent years in security-critical retail infrastructure — automated testing of authentication flows, RBAC enforcement, payment processing, and multi-tenant data integrity across 1,000+ retail locations. That's where I learned how systems fail from the inside out.

Now I apply that discipline to identity governance: building the IGA lifecycle systems, access controls, and evidence pipelines that make identity and compliance measurable and repeatable at scale. Based in Nashville, TN. Open to remote and hybrid roles.

Certifications
AWS Security Specialty
Amazon Web Services
Solutions Architect Associate
Amazon Web Services
CompTIA Security+
CompTIA
RHCE / RHCSA
Red Hat
PMP
Project Management Professional
In Progress
AWS Solutions Architect Professional (SAP-C02)
Microsoft SC-300 · Identity & Access
Contact

Let's work together.

Open to Identity Governance (IGA) Engineer, IAM Engineer, Cloud Security Engineer, and GRC Engineering roles. Nashville, TN — remote and hybrid considered.