Identity and Cybersecurity Engineer with 18+ years of IT experience in designing, securing, and modernizing enterprise identity ecosystems. Deep expertise across Ping Identity (PingFederate, PingAccess, PingOne MFA, Ping Directory), Azure Entra ID, SailPoint, Okta, and IBM Security Access Manager. Proven track record in leading large-scale IAM transformations, strengthening authentication and access controls, and architecting secure solutions aligned with NIST, SOC2, SOX, GLBA, OWASP, GDPR, HIPAA, and CIA frameworks. Strong background in middleware engineering (WebSphere, WebLogic, JBoss), LDAP administration, and SSO integrations using SAML, OAuth, and OIDC. Experienced in supporting high-availability environments across AIX, Solaris, Linux, and cloud platforms. Known for exceptional collaboration and cross-functional leadership in delivering scalable IAM architectures that enable secure enterprise operations.
Overview
22
22
years of professional experience
Work History
Senior IAM Security Consultant
UnitedHealth Group, MN
03.2012 - Current
IAM Architecture & Modernization: Designed enterprise IAM architectures using PingFederate, PingAccess, Ping One MFA, Ping Directory, Azure Entra ID, SCIM, OIDC, and SAML, strengthening and supporting large-scale identity transformation programs.
CIAM & Identity Governance: Implemented SailPoint Identity Now for lifecycle management, RBAC, and access certifications; integrated with Active Directory, HR systems, cloud apps, and enforced governance aligned with SOX, HIPAA, GDPR, and internal audit controls.
Okta Identity Cloud Engineering: Configured and maintained Okta SSO, MFA (Web Authn, Fast Pass, Okta Verify), SCIM provisioning, Universal Directory, adaptive policies, and application onboarding; automated workflows using Azure Entra ID and PowerShell.
Security Engineering & DevSecOps: Applied NIST, OWASP, SOX frameworks to identity controls; embedded automated security testing, vulnerability scanning, and compliance validation into CI/CD pipelines using DevSecOps practices.
Cloud Security & Zero Trust Controls: Enhanced cloud security by deploying protected workloads using Azure Functions, Fargate, EKS/ECS, micro-segmentation, hardened images, and least privilege role designs aligned with AWS Well-Architected principles.
Integration & Federation Engineering: Delivered complex integrations across web, mobile, APIs using PingFederate, Okta, SAML, OAuth2, OIDC; resolved cross-platform issues and established secure, scalable federation patterns across enterprise applications.
Configuration Standards & Documentation: Developed secure baseline configurations for IAM platforms, authored technical guides, installation playbooks, and architectural patterns, and maintained an organization-wide IAM knowledge base.
Strategic Advisory & Cross-Functional Leadership: Partnered with enterprise security, cloud, and architecture teams to define identity design standards; served as a technical advisor on IAM roadmap decisions and mentored engineering teams on Ping, Okta, and SailPoint implementations.
Identity Ping Federation: SAML 1.0 – SAML 2.0, Open ID and OAuth protocol messages, Authentication Request, Response, Logout Request, Logout Response, Artifact Profiles, and Attribute Query profiles for different bindings like POST, Redirect, Artifact. WS-FED, STS, WS-Trust.
Application configuration with Ping Access and defining Ping Access Sites, rules, Virtual hosts, Policies and Rules. Designed, deployed and supported highly available and scalable Ping Federate infrastructure and PingAccess. Integrated more than 200 applications with single sign on with Ping and Azure.
Environment: Ping Identity Suite, Ping Federate, Ping Access, Ping Directory, Azure Entra ID, MS LDAP, OKTA, Sail Point, CA SiteMinder, Layer 7, Oracle SOA, J Boss EAP 5.0/6.0/6.2, Tomcat, IBM WebSphere, Apache 1.3.20, Sun Solaris 10/9/8/7/2.x, Red Hat Linux 8/7/6/5.x, Resonate, Compuware Dynatrace, Service Now, Splunk, Zabbix, Grafana, SE, Remedy, PVCS, HCP Suite, Mercury Load Runner 9.0/8.0, Vantage Analyzer and Wily site scope
Sr. Infrastructure Consultant
UnitedHealth Group (Optum)
03.2008 - 02.2012
Supported WebSphere development, staging, QA, and production environments, ensuring smooth deployment for all UHG development and support teams.
Skilled in deploying and configuring applications across IBM WebSphere middleware platforms, ensuring high availability, reliability, and compliance for multiple business entities. Expertise includes J2EE deployments, Service Integration Bus, SiteMinder security, and infrastructure optimization across AIX, Solaris, Linux, and Windows environments.
Managed J2EE application deployments, including Service Integration Bus configuration, message activations, destinations, plug-in setup, data source creation, virtual host configuration, session management, clusters, and deployment manager/network deployment configurations in WebSphere 6.1, 7.0, and WebLogic 10gR1 across AIX, Sun Solaris, and Windows Server 2003.
Coordinated monthly implementation processes, maintained consolidated implementation plans, and executed source code migrations to production servers.
Reviewed and edited deployment documentation created zip packages, and staged applications for production implementation while enforcing standardized processes and procedures for packaging and deployments.
Provided SiteMinder application support, including Web Agent integration, Policy Server configuration, and LDAP user store management for authentication and authorization.
Analyzed existing infrastructure and recommended enhancements for reliability, availability, serviceability, and scalability.
Supported vendor applications such as AUP, CIX, E3, ERC, UBH, UVP, UPS, URN, KIQ, SAS, DTL, CAG, PEGA, HDG, MA1 (hCentive), HIX on WebSphere 6.1/7.0/8.5 environments.
Collaborated with AIX Server Team for OS performance tuning and optimization.
Delivered 24x7 second-level help desk support for web application infrastructure across 1,000+ servers in heterogeneous environments (Sun Solaris, AIX, Red Hat Linux).
Conducted Proof of Concept (POC) for WebSphere 7.0/8.5 environments and provided solutions for vendor product installations and infrastructure setup.
Guided and delegated daily ITG tickets, mentoring team members on new technologies and processes.
Supported middleware stack including WebSphere 8.5/7.0/6.0.2, Sun One Web Server 6.1, Netscape Directory Server 4.0, WebSphere MQ 5.1, Microsoft Commerce 2002, IIS 6.0, and SQL Server 2000.
Recognized by project managers as “Make It Happen” and “Superhero” for exceptional problem-solving and customer support.
Environment: IBM Websphere8.5/7.0/6.1/6.0/5.1, Oracle WebLogic App Server 8/9/10, J Boss EAP 5.0/6.0/6.2, Tomcat, ATG Dynamo 2006.3, iPlanet 5.1, IBM HTTP Server, Apache 1.3.20, Sun Solaris 10/9/8/7/2.x, Red Hat Linux 8/7/6/5.x, Resonate, Compuware Dynatrace, Server Vantage, CA SiteMinder, Layer 7, Oracle SOA 11g, JBoss FUSE, Remedy, PVCS, Mercury Load Runner 9.0/8.0 and Oracle 11g/10g/9i/8/7/i, Compuware Dynatrace, Vantage View, Vantage Analyzer and Wily site scope
WebSphere Administrator
Deluxe Corporation, Minneapolis, MN
05.2004 - 02.2008
Deluxe has a requirement to implement a solution for their third-party applications in conjunction with SDK implementation on board all of them with their internal automated process through my accesses for a complete review. It provides different levels of authentication for their user requests to access the requested applications and also to update their information within system. The system architecture includes logical and deployment views of the system.
Performed system administration tasks on Sun Solaris, AIX, and Linux platforms to ensure optimal performance and reliability.
Installed and configured IBM WebSphere Application Server (6.0/5.1/5.0), iPlanet 5.1, and JDBC drivers for enterprise applications.
Supported 40+ servers in a heterogeneous environment including Sun Solaris, AIX, and Linux.
Led migration of WebSphere 5.0.2 to 5.1.1.3, creating detailed documentation outlining all migration steps.
Proof of Concept (POC) for WebSphere 6.1, configured application servers, and managed web servers with iPlanet for running applications.
Provided support for middleware stack including WebSphere 6.0.2, Sun One Web Server 6.1, Netscape Directory Server 4.0, WebSphere MQ 5.1, Microsoft Commerce 2002, IIS 6.0, and SQL Server 2000.
Migrated seven externally hosted websites from Windows NT 4.0, Site Server 3.0, SQL Server 7.0 to Windows 2003 R2, IIS 6.0, Commerce Server 2002, and SQL Server 2000 for Deluxe Pinpoint.
Participated in server consolidation efforts implementing WebSphere 6.x on Solaris Containers and Zones for improved resource utilization.
Configured applications on Anthill for build and deployment on WebSphere 5.1 and 6.x, scripted HTTP builds using shell scripting, and scheduled jobs via Control-M.
Installed and configured ATG Dynamo Modules (DCS, DSS) for Deluxe Market Store on WebSphere Application Server.
Environment: WebSphere 5.0, IBM Tivoli Federation, SIM, SAM, SUNONE, Java, Swings, J2EE, REST Web services, Java Script, HTML, PERL Scripts, Spring MVC, Spring Web Flow, JMS, Web logic 8.1, Oracle 10g, Eclipse
Education
Master of Science - Computer Engineering
International Technology University
San Jose
12-2012
Skills
Identity & Access Management (IAM) Architecture
Customer Identity & Access Management (CIAM)
Ping Identity Suite Ping Federate, Ping Access, Ping Directory and Ping One
Azure Entra ID OKTA Identity Cloud SailPoint Identity Now
Single Sign-On (SSO) & Federation Protocols Multi-Factor Authentication (MFA)
Senior Provider Relations Advocate, Account Manage at UnitedHealth Care, UnitedHealth GroupSenior Provider Relations Advocate, Account Manage at UnitedHealth Care, UnitedHealth Group