Proficient in managing and configuring Okta Identity Cloud for Single Sign-On (SSO), Advanced Server Access (ASA), API security, and lifecycle management, with extensive knowledge of user provisioning, deprovisioning, and RoleBased Access Control (RBAC).
Conducted routine health checks, optimized performance, and managed system upgrades in the Okta environment while establishing security objectives, compliance standards, access control policies, and business requirements for users.
Deployed and enforced Multi-Factor Authentication (MFA) policies utilizing FIDO2, Google Authenticator, and YubiKey to strengthen security across all organizational access points.
Experienced in Cloud Identity Management with in-depth knowledge of AWS IAM, including policies, roles, user management, and security controls.
Integrated Directory Management Systems with IAM solutions to centralize identity management and streamline authentication processes while designing and implementing role-based access policies and risk profiles for user applications.
Implemented and managed SailPoint tasks, including aggregation, ID refresh, scheduled tasks, and correlation, while successfully migrating passwords from legacy applications to IDM, ensuring the retention of users' last password change dates.
Integrated third-party applications with identity providers (IdPs) using SAML to enhance secure access and user experience while developing and implementing access control guidelines based on the principle of least privilege.
Hands-on experience with platforms such as Okta, Azure AD, and SailPoint, while deploying and managing token lifecycles, including token revocation, introspection, and expiration policies to enhance API security.
Performed routine access reviews and audits to ensure compliance with organizational security policies and regulatory requirements.
Developed and documented standard operating procedures for user access reviews, provisioning, and deprovisioning processes.
Collaborated with product management teams to gather requirements and offer expertise in securing access to customer-facing platforms.
Provided training and documentation to end-user teams on secure access practices for the Okta platform while enhancing response times and user satisfaction by working closely with customer support teams to troubleshoot and resolve authentication issues.
Diagnosed and resolved token-related issues, including access token expiration, ID token validation, and refresh token failures, minimizing user downtime.
Regularly audited and reviewed user accounts and permissions to detect and remediate inactive accounts or unauthorized access.
Designed and implemented robust password policies, enforcing periodic resets and complexity requirements across the organization.
To improve security monitoring and centralize identity-related logs, Splunk was integrated with IAM systems such as Okta, Azure AD, and SailPoint.
Developed PowerShell scripts to automate password reset processes and self-service workflows, enhancing user experience and reducing IT workload.
Reviewed and validated token-based authentication mechanisms, including OAuth 2.0 and OpenID Connect, to ensure secure API and application integrations, while designing and implementing zero-trust frameworks to enhance the organization's security posture.
Expertise in deploying and managing Privileged Identity Management (PIM) solutions while developing Postman prerequest and test scripts for dynamic API parameterization and automated testing of IAM workflows.
IAM Specialist
Gate Gourmet
12.2022 - 01.2024
Experienced IAM Administrator specializing in Okta identity and access management solutions, with expertise in Single Sign-On, Multi-Factor Authentication, Lifecycle Management, and API integrations.
Enhanced identity governance by implementing policies based on Zero Trust principles while configuring and managing Group Policy Objects (GPOs) to enforce security and compliance standards.
Conducted periodic access reviews and audits to enforce the principle of least privilege (PoLP) while leading IAM security incident response by analyzing and mitigating identity-related threats.
Managed end-to-end Okta administrator workflows, including the deployment of SSO, MFA, and provisioning, while successfully migrating users from multiple Active Directory domains and OpenLDAP.
Administered and maintained Active Directory and DNS servers, monitored event logs, installed and troubleshot external and internal IP zones, and managed blacklist IP blocking in Okta for enhanced security.
Designed and implemented OIDC-based authentication workflows to enhance security and user experience while integrating OAuth 2.0.
Integrated IGA with cloud environments for seamless cross-platform identity synchronization while provisioning, deprovisioning, and managing users, groups, and service principals within Azure AD.
Monitored and optimized access reviews to ensure compliance and least privilege access while automating and streamlining user onboarding, access review, and termination workflows using SailPoint IIQ.
To improve security and operational effectiveness, I oversaw and improved ticket expiration procedures and renewals, and delegated.
Automated IAM administrative tasks using PowerShell, including user provisioning, deprovisioning, access reviews, and role-based access control (RBAC) enforcement across Active Directory, Okta, and Azure AD.
Developed and maintained documentation for IAM processes, configurations, and policies while implementing Multi-Factor Authentication strategies to enhance authentication security across cloud and on-premise environments.
Deployed Okta Advanced Server Access (ASA) for securing server authentication, implemented Okta Identity Threat Detection and Response (ITDR), and introduced passwordless authentication strategies using Okta.
Managed identity synchronization between on-premises and cloud directories while overseeing the federation of identities between Google Workspace and Okta.
Configured IdP self-service registration and user provisioning for administrators, analyzed system logs to identify and mitigate security threats, and implemented sign-on policies tailored for different user groups.
Implemented Okta's risk-based authentication (RBA) policies and monitored IAM activities through Okta System Logs and Splunk integration to maintain security compliance.
Implemented (OIG) for enhanced visibility and control over user access while automating password rotation and credential management to ensure compliance with enterprise security policies.
SailPoint IAM Engineer
Smith and Nephew
08.2020 - 11.2022
Configured and implemented SailPoint IdentityIQ (IIQ) and Identity Now for user lifecycle management, access certification, and compliance enforcement.
Developed SailPoint reports and dashboards using JDBC data sources to analyze user access and compliance metrics.
Led SailPoint version upgrades and patch management to maintain system stability and performance while configuring and managing Access Reviews and Certifications to ensure regulatory compliance and enforce least privilege access.
Collaborated with business teams, security analysts, and IT administrators to design and implement IAM policies and workflows.
Designed and implemented pre- and post-provisioning rules using PowerShell to enhance the functionality of JDBC connectors.
Streamlined role and attribute-based provisioning to strengthen security and reduce manual efforts while implementing access reviews and certification campaigns in SailPoint to detect and revoke unnecessary access.
Collaborated with stakeholders to establish identity governance requirements and develop automation strategies.
Enforced adaptive authentication by implementing risk-based authentication (RBA) policies while integrating Single Sign-On (SSO) solutions with SailPoint for seamless authentication across enterprise applications.
Worked closely with security teams to analyze authentication logs, identify anomalies, and troubleshoot authentication-related issues while providing technical support for end-users and applications.
Improved authentication flows to reduce login latency and enhance the user experience while implementing security best practices to strengthen access controls and prevent unauthorized access.
To simplify access management and security, SailPoint was set up as the identity governance and provisioning spoke, and Okta as the central authentication hub.
Implemented Multi-Factor Authentication (MFA) and Conditional Access Policies to enhance security in identity federation.
Reduced onboarding and offboarding time by automating workflows in SailPoint and Okta while providing training and documentation to internal teams for managing identities across multiple spokes.
Hands-on experience with SailPoint connectors, including AD, LDAP, while implementing real-time monitoring and alerting for access anomalies using SailPoint analytics.
Managed privileged access governance through PAM integration for critical applications, developed and customized SailPoint connectors for seamless application integration, and implemented policy violation detection and remediation to strengthen security and compliance.
Automated SailPoint identity management processes using PowerShell, including user provisioning, access certification, role assignments, and connector integrations, to improve efficiency and ensure compliance.
Performed access reviews and audits for Active Directory accounts to enforce the principle of least privilege.
Education
Master's - Computer Science
University of Bridgeport
Bridgeport, CT
Skills
IAM tools: Okta and SailPoint IdentityIQ
Azure Active Directory
LDAP and authentication protocols
Single sign-on and MFA
SAML, OIDC, and OAuth 20
Scripting and automation: PowerShell and Postman
Cloud platforms: AWS IAM, Azure, and Google IAM
Security governance: RBAC and risk-based authentication
Access reviews and zero trust frameworks
Monitoring tools: Splunk and Okta system logs
Python programming
Certification
Certified in CompTIA Security+
Certified in Azure Security Engineer AZ-500
Work Summary
Around 5 years of experience in Information Technology and Security, specializing in Identity and Access Management (IAM), SAML, OIDC, Active Directory, OAuth, LDAP, SSO, MFA, and provisioning, along with expertise in IAM tools such as Okta, Azure AD, and hands-on experience as an Okta administrator.
Proficient in Directory Management Services (DMS), identity governance, and managing identity repositories.
Experienced in installing and configuring Okta developer tenants, as well as setting up Active Directory on Windows Server and Linux environments.
Strong understanding of user life cycle management and (API Security) Application programming interface.
Knowledgeable about user identity authentication and authorization, and well-versed in IAM integration.
Responsible for designing and implementing role-based access policies and risk profiles for associated applications.
Competent in Identity Provider (IdP) and Service Provider (SP) SAML implementation. Well-versed and experienced in Identity Provider (IdP) solutions, particularly Okta.
Specializes in managing and securing user identities and controlling access to organizational resources.
Skilled, leading the implementation and management of Identity and Access Management (IAM) systems, including Single Sign-On (SSO), Adaptive MFA, and Role-Based Access Control (RBAC).
Developed PowerShell scripts to automate reporting on user activity, login attempts, and compliance audits for security and IAM monitoring.
Aware of user lifecycle management, which includes account reconciliation for compliance, user provisioning and deprovisioning, and managing connectors for seamless user administration. Diagnose and resolve access, permission, and authentication issues while developing and enforcing access policies to ensure appropriate user access levels.
Experienced in implementing and managing SailPoint IdentityIQ, including user lifecycle management, role-based access control (RBAC), access certifications, and policy enforcement, while developing automation workflows for provisioning and deprovisioning, integrating SailPoint with enterprise applications, and conducting access reviews to ensure compliance with security policies and regulatory standards.
Implemented security best practices, automated user lifecycle management, integrated Azure AD with third-party applications, and conducted access reviews to ensure compliance with organizational policies and regulatory standards.
Diagnosed and resolved IAM-related incidents, such as access issues, authentication failures, and security breaches, while ensuring minimal disruption to business operations.