
Experienced IAM Engineer with 8+ years of experience designing, implementing, and securing enterprise identity solutions across Azure and hybrid environments. Skilled in Microsoft Entra ID (Azure AD), Okta, CyberArk, and SailPoint, with strong automation expertise using PowerShell, Python, REST APIs, and JSON—streamlining over 80% of provisioning and access governance processes.
Demonstrated success in implementing Zero Trust architectures, enhancing Conditional Access strategies, and managing hybrid identity synchronization with Azure AD Connect. Achieved a 35% reduction in privileged access risk and decreased audit remediation timelines by 50% through automation, governance optimization, and policy standardization.
Well-versed in aligning IAM frameworks with NIST, HIPAA, and ISO 27001 standards to deliver scalable, compliant, and resilient identity infrastructures that strengthen enterprise security and operational efficiency.
• Implemented and maintained Single Sign-On (SSO) integrations for 50+ enterprise SaaS applications weekly, including Salesforce, ServiceNow, and 500+ cloud-based platforms, leveraging Okta and Entra ID with SAML, OAuth 2.0, and OIDC to strengthen authentication security, enforce access governance, and enhance user experience.
• Managed and administered Microsoft Azure Entra-ID, including user provisioning and deprovisioning, RBAC, ABAC, and group management.
• Configured and managed Azure Active Directory (AD/Entra-ID) users, groups, and roles to control access to Azure resources.
• Redesigned enterprise identity architecture across on-prem Active Directory, Azure AD, and LDAP directories, shifting the organization from perimeter-based access to a Zero Trust model. Implemented Conditional Access, adaptive MFA, and risk-based authentication policies that reduced credential-based compromise attempts by 40% and improved access reliability.
• Automated full user lifecycle management for joiners, movers, and leavers, using PowerShell and Microsoft Graph API. Integrated with HR data flows to trigger provisioning logic via REST calls, dynamically enforcing role-based and ABAC policies, and updating security group assignments across hybrid AD environments.
• Implemented and maintained CyberArk Conjur, CyberArk PAM/EPM component EPV, PVWA, CPM, PSM, and PSM for SSH, AIM/AAM-CP/CCP, and PTA.
• Manage infrastructure secrets with CyberArk Conjur for applications onboarding, onboarding users, and deprovisioning, API Keys, secrets, and credentials management for DevOps operations.
• Monitor and review Privileged credentials activities using CyberArk’s Session Manager. (PSM)
• Integrate CyberArk with enterprise systems (Active Directory, SIEM, ServiceNow, Cisco Meraki, Network devices).
• Deployed and customized SailPoint IdentityIQ to unify identity governance across Active Directory (on-prem and Azure AD) and SaaS platforms. Built custom connectors for EHR, HRIS, and collaboration apps, enabling centralized access reviews and reducing orphaned accounts by 35%.
• Led enterprise-wide SSO modernization leveraging Azure AD and Okta as identity providers, integrating over 60+ applications (Workday, Bamboo HR, ServiceNow, Cerner, Epic, and Microsoft 365) with SAML, OAuth 2.0, and OpenID Connect, replacing legacy login methods and improving authentication success rates by 22% while maintaining HIPAA compliance.
• Instituted a Privileged Identity Management (PIM) and CyberArk framework for IT admins and third-party vendors. Enforced Just-in-Time (JIT) privilege elevation, vault-based credential rotation, and MFA reauthentication, cutting standing privileged accounts by 70% and achieving two consecutive zero-finding compliance audits.
• Engineered Conditional Access policies leveraging geolocation, device trust, and session behavior analytics. Built adaptive risk models that automatically block sign-ins from suspicious IPs and trigger step-up MFA for high-risk sessions, reducing unauthorized geographic access.
• Provided Tier 1 and Tier 2 technical support to over 2,500 enterprise users across corporate offices and remote branches, troubleshooting hardware failures, software conflicts, and network connectivity issues to maintain operational continuity and user productivity.
• Installed, configured, and maintained Windows-based desktop environments, mobile devices, and enterprise tools such as Microsoft 365, VPN clients, antivirus platforms, and remote desktop solutions, ensuring compliance with internal security and configuration standards.
• Monitored and managed IT assets including workstations, printers, and peripheral devices using centralized management tools, conducting preventive maintenance and reducing system downtime by over 25%.
• Documented incidents, root causes, and resolutions within ServiceNow and internal knowledge bases, improving issue resolution speed and reducing repetitive tickets by 30% through structured process documentation.
Identity & Access Management (IAM): Entra-ID, Azure AD B2C/B2B, RBAC, ABAC, Active Directory, Azure AD Connect, Microsoft Graph API, Okta, SailPoint IdentityIQ / Identity Now, CyberArk, Conditional Access, Privileged Identity Management, SCIM, SAML, OAuth 20, OpenID Connect, Single Sign-On, MFA, Identity Governance, Access Reviews, Zero Trust Framework, CyberArk PAM/EPM EPV, PVWA, CPM, PSM, and PSM for SSH, AIM, and CCP
Cloud Security & Compliance: Azure Security Center, Identity Protection, Conditional Access Policies, Risk-Based Access, NIST, ISO 27001, HIPAA, Splunk, LDAP
Automation & Integration: PowerShell, Microsoft Graph API, REST API, JSON, SCIM API, Python (automation scripting), Access Provisioning
Endpoint & Device Management: GPO and Microsoft Intune (Compliance & Security Policies), SCCM, Defender for Endpoint, Conditional Access with Device State
Networking & Hybrid Identity: DNS, VPN, RDP, Federation Services, Seamless SSO, Hybrid Identity Federation, Azure AD Connect Sync
Tools & Workflow Systems: ServiceNow, Jira, Ivanti, Zendesk, Azure Policy, IAM Log Analysis, Access Certifications
Cloud & Collaboration Platforms: Azure Resources, Microsoft 365 Admin, Exchange Online, SharePoint, Teams, Azure App Registrations, Enterprise App Management
CompTIA Security+ July 2023 – July 2026
CompTIA
AWS Certified Solutions Architect & Certified Cloud Practitioner December 2016 – June 2028
Amazon Web Services
Certified Information System Auditor December 2024 – December 2026
ISACA
Okta Administator december 2025- december 2027
Microsoft Identity and Access Administrator december 2025- december 2026