With a proven track record at Northern Trust Corporation, I excel in architecting secure IAM solutions, leveraging skills in PingFederate, Azure AD, and strategic leadership. My expertise in enhancing authentication security and operational productivity through innovative technologies and teamwork has significantly reduced security incidents, underscoring my commitment to excellence and proactive problem-solving.
Overview
7
7
years of professional experience
1
1
Certification
Work History
Security Technology Lead
Northern Trust Corporation
01.2022 - Current
Designed and implemented IAM architectures with PingFederate, Okta, and Azure AD for secure authentication and authorization across hybrid environments.
Developed scalable identity solutions using SAML, OAuth, OIDC, and SCIM, ensuring seamless user authentication.
Strengthened SSO and MFA implementations, reducing authentication failures and enhancing security.
Maintained zero downtime during IAM upgrades, ensuring continuous user access.
Configured RBAC, ABAC, and PBAC for precise access control and security compliance.
Managed IAM systems like Ping Identity, Okta, and Azure AD, optimizing identity governance.
Applied encryption techniques (AES/RSA), PKI, TLS, and JSON signing to secure web applications.
Partnered with clients and vendors to deliver IAM solutions within project deadlines and compliance requirements.
Led IAM process automation, reducing manual effort and improving efficiency.
Integrated Active Directory with PingFederate for secure authentication and LDAP attribute queries.
Deployed AWS KMS, Azure Key Vault, and Google KMS to secure sensitive data at rest and in transit.
Implemented Privileged Access Management (PAM) using CyberArk and SailPoint, ensuring secure privileged account handling.
Conducted security testing and compliance reviews, identifying and mitigating vulnerabilities.
IAM Engineer
Kaiser Permanente
, California
10.2017 - 01.2022
Administered IAM solutions (PingFederate, PingAccess, Okta, LDAP) to streamline authentication.
Integrated Active Directory with PingFederate for seamless credential validation.
Strengthened MFA and SSO security for enterprise applications.
Automated IAM workflows reduce manual provisioning efforts.
Enforced PKI and TLS/SSL encryption policies for secure communications.