Skip to content
View abner-pena's full-sized avatar
  • YNAP (Yoox Net-A-Porter)
  • Saddle Brook, New Jersey

Highlights

  • Pro

Block or report abner-pena

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
abner-pena/README.md

Hey, I'm Abner Peña 👋

IAM & Cloud Security Engineer · Azure AD / Entra ID · PowerShell · Endpoint Security


About Me

IAM and Cloud Security Engineer with hands-on enterprise experience in Azure AD / Entra ID, identity lifecycle management, endpoint security, and PowerShell automation.

At YNAP (Yoox Net-A-Porter), I administer Azure AD / Entra ID with MFA and Conditional Access, managed DLP/GDPR compliance across NA/EU/APAC, and led a 400+ machine Windows 11 migration. I've automated 1,000+ user accounts via PowerShell and built identity and cloud infrastructure from scratch.

Currently pursuing CompTIA Security+ (Sep 2026) and SC-300: Microsoft Identity & Access Administrator (Oct 2026). Targeting a fully remote IAM or Cloud Security Engineer role.


🔐 Identity & Access Management

Project What I Built Stack
AWS IAM Identity Center Lab Entra ID as the single identity source for AWS: SAML federation plus SCIM provisioning into IAM Identity Center, job-function permission sets assigned to synced groups, an IAM permissions boundary that blocks role-creation privilege escalation, organization-wide SCPs denying root usage, region sprawl, and security-control tampering, PIM-backed just-in-time break-glass admin, plus Access Analyzer unused-access scoping and joint CloudTrail/Athena and Entra ID KQL detections AWS IAM Identity Center · AWS Organizations · SCPs · Permissions Boundaries · IAM Access Analyzer · SCIM 2.0 · SAML · Athena · KQL
Workload Identity Federation Lab Secretless workload identity build: OIDC federation from GitHub Actions to Entra ID scoped to a single repo and environment, managed identities for in-Azure workloads, a tenant-wide credential and app-permission audit, Conditional Access location locking for service principals, consent governance, and KQL detections for credential-addition persistence, federated-credential backdoors, and consent phishing Entra ID · Workload Identity Federation · OIDC · Managed Identities · Graph PowerShell · KQL
Cloud Security Posture Management End-to-end CSPM lab with Microsoft Defender for Cloud: enable the Defender CSPM plan and agentless scanning, baseline and drive up Secure Score, enforce Azure Policy guardrails (deny public storage, require encryption, audit open management ports), map to CIS and NIST 800-53, run attack path analysis on internet-exposed resources chaining to privileged identities, and self-heal drift with DeployIfNotExists plus continuous export and KQL posture hunts Defender for Cloud · Azure Policy · Secure Score · Attack Path Analysis · KQL · Az PowerShell
Azure AD Connect Hybrid Identity End-to-end hybrid identity bridge: Azure AD Connect with Password Hash Sync as the resilient auth model, Seamless SSO with automated 30-day Kerberos key rollover, group and password writeback, OU and attribute-scoped filtering, plus PowerShell for pre-sync UPN remediation, PHS heartbeat checks, and sync-health reporting, and KQL detections for sync-account and provisioning anomalies Azure AD Connect · AD DS · Entra ID · Password Hash Sync · Seamless SSO · Graph PowerShell
Phishing-Resistant MFA Lab Entra ID migration off phishable factors onto FIDO2, Windows Hello, and certificate-based auth: a custom Conditional Access authentication strength, number matching to kill MFA fatigue, AAGUID key allowlisting, a coverage-gated retirement of SMS and voice, and KQL detections for legacy-method sign-ins, prompt bombing, and policy blocks Entra ID · Authentication Strengths · FIDO2/WebAuthn · Graph PowerShell
Identity Governance & Access Reviews Entra ID Governance build: access packages with two-stage approval and 90 day expiry, separation-of-duties incompatible packages, recurring group, package, and guest access reviews with auto-apply removal, plus Graph reporting and KQL audit queries for grants, review decisions, and SoD denials Entra ID Governance · Entitlement Management · Access Reviews · Graph PowerShell
Privileged Access Workstation Tier 0 PAW build guide: AppLocker allowlisting, Credential Guard, zero cached credentials, ASR rules, outbound default-deny firewall, plus a Conditional Access policy enforcing PAW-only privileged sign-in and a PowerShell compliance auditor Windows 11 · AppLocker · Credential Guard · Conditional Access
SAML vs OIDC SSO Lab Side-by-side federation protocol lab in Entra ID: SAML enterprise app with custom claims mapping, OIDC app registration via Graph PowerShell, annotated token teardowns, cert expiry monitoring, and AADSTS failure triage scripts Entra ID · SAML 2.0 · OIDC/OAuth 2.0 · Graph PowerShell
Zero Trust Architecture Lab Zero Trust reference build in Azure: Conditional Access policy set (phishing-resistant MFA, legacy auth block, device compliance, risk-based), segmented VNet with default-deny NSGs, and KQL detections for policy bypass and tampering Entra ID · Conditional Access · Azure NSGs · KQL
Okta Lifecycle Management Full joiner-mover-leaver automation: CSV-driven provisioning, attribute-based group rules, SCIM 2.0 app provisioning, and two-stage deprovisioning with audit reporting Okta · SCIM 2.0 · PowerShell · Universal Directory
Azure PIM Lab Privileged Identity Management: eligible role assignments, MFA-gated activation, approval workflows, quarterly access reviews, and audit KQL queries Entra ID · PIM · Graph API · PowerShell
PowerShell AD Automation 3 production scripts: bulk user provisioning from CSV, inactive account deprovisioning with quarantine, and full access audit reporting PowerShell · AD DS · RBAC
Azure Entra ID Lab Conditional Access policies, MFA enforcement, SSPR, device compliance, and legacy auth blocking, with importable JSON policy templates Entra ID · Intune · Graph API
Configuring Active Directory in Azure Full AD domain from scratch: DCs, OUs, GPOs, user lifecycle, PowerShell bulk provisioning Azure VMs · AD DS · PowerShell
Network File Shares and Permissions RBAC-based file share access control using AD groups and permission inheritance Active Directory · RBAC · Windows Server

🛡️ Security Operations

Project What I Built Stack
Microsoft Sentinel SIEM Lab Full SIEM deployment: log ingestion from Entra ID, 4 KQL detection queries (brute force, impossible travel, privileged activity, new admin alerts), and scheduled analytic rules Sentinel · KQL · Log Analytics

☁️ Cloud Infrastructure

Project What I Built Stack
Azure Network Protocols Lab NSG rule configuration and live network traffic inspection across RDP, SSH, DNS, ICMP Azure · NSGs · Wireshark
Azure Virtual Machine Setup Foundation lab: provisioning and configuring Azure VMs for identity and cloud infra work Azure · Windows Server

📓 Cert Prep

Security+ Practice Quiz

Built and deployed an interactive Security+ SY0-701 practice quiz: timed exams, domain scoring, and instant answer explanations. Working toward CompTIA Security+ (Sep 2026) and SC-300 (Oct 2026); the IAM labs above double as hands-on exam prep.


🧰 Core Stack

Identity & Access    Azure AD / Entra ID · Active Directory · Okta · AWS IAM Identity Center · Duo MFA · SSO · RBAC · Conditional Access · PIM
Cloud                Azure (VMs, VNets, NSGs) · AWS (Organizations, IAM, SCPs) · DNS · DHCP · VPN · VDI · Microsoft Sentinel
Device Management    SCCM · Jamf Pro · Intune · AirWatch · iOS/Android MDM · OS Imaging
Security             DLP · GDPR · BitLocker · Zscaler · Endpoint Security · MFA · Firewall Policies · KQL
Automation           PowerShell · AD Lifecycle Scripting · Bulk Provisioning · GitHub Actions

📊 GitHub Stats


🎫 IT Operations

Project What I Built
osTicket: Installation Full helpdesk stack on Azure (IIS, MySQL, PHP)
osTicket: Configuration Roles, departments, SLAs, help topics
osTicket: Ticket Lifecycle End-to-end ticket workflow simulation

Open to fully remote IAM & Cloud Security Engineer roles · English / Spanish · Saddle Brook, NJ

Pinned Loading

  1. Azure-Network-Protocols Azure-Network-Protocols Public

    Inspect and analyze network traffic in Azure using NSGs, Wireshark, DNS, and ICMP

  2. Configuring-Active-Directory-within-Azure-VMs Configuring-Active-Directory-within-Azure-VMs Public

    Deploy and configure on-premises Active Directory in Azure — users, OUs, GPOs, PowerShell bulk provisioning

  3. Network-File-Shares-and-Permissions-with-Active-Directory Network-File-Shares-and-Permissions-with-Active-Directory Public

    Configure RBAC-based file share access using Active Directory groups and permission inheritance

  4. Virtual-Machine Virtual-Machine Public

    Provision and configure Azure VMs for identity and cloud infrastructure labs