IAM and Cloud Security Engineer with hands-on enterprise experience in Azure AD / Entra ID, identity lifecycle management, endpoint security, and PowerShell automation.
At YNAP (Yoox Net-A-Porter), I administer Azure AD / Entra ID with MFA and Conditional Access, managed DLP/GDPR compliance across NA/EU/APAC, and led a 400+ machine Windows 11 migration. I've automated 1,000+ user accounts via PowerShell and built identity and cloud infrastructure from scratch.
Currently pursuing CompTIA Security+ (Sep 2026) and SC-300: Microsoft Identity & Access Administrator (Oct 2026). Targeting a fully remote IAM or Cloud Security Engineer role.
| Project | What I Built | Stack |
|---|---|---|
| AWS IAM Identity Center Lab | Entra ID as the single identity source for AWS: SAML federation plus SCIM provisioning into IAM Identity Center, job-function permission sets assigned to synced groups, an IAM permissions boundary that blocks role-creation privilege escalation, organization-wide SCPs denying root usage, region sprawl, and security-control tampering, PIM-backed just-in-time break-glass admin, plus Access Analyzer unused-access scoping and joint CloudTrail/Athena and Entra ID KQL detections | AWS IAM Identity Center · AWS Organizations · SCPs · Permissions Boundaries · IAM Access Analyzer · SCIM 2.0 · SAML · Athena · KQL |
| Workload Identity Federation Lab | Secretless workload identity build: OIDC federation from GitHub Actions to Entra ID scoped to a single repo and environment, managed identities for in-Azure workloads, a tenant-wide credential and app-permission audit, Conditional Access location locking for service principals, consent governance, and KQL detections for credential-addition persistence, federated-credential backdoors, and consent phishing | Entra ID · Workload Identity Federation · OIDC · Managed Identities · Graph PowerShell · KQL |
| Cloud Security Posture Management | End-to-end CSPM lab with Microsoft Defender for Cloud: enable the Defender CSPM plan and agentless scanning, baseline and drive up Secure Score, enforce Azure Policy guardrails (deny public storage, require encryption, audit open management ports), map to CIS and NIST 800-53, run attack path analysis on internet-exposed resources chaining to privileged identities, and self-heal drift with DeployIfNotExists plus continuous export and KQL posture hunts | Defender for Cloud · Azure Policy · Secure Score · Attack Path Analysis · KQL · Az PowerShell |
| Azure AD Connect Hybrid Identity | End-to-end hybrid identity bridge: Azure AD Connect with Password Hash Sync as the resilient auth model, Seamless SSO with automated 30-day Kerberos key rollover, group and password writeback, OU and attribute-scoped filtering, plus PowerShell for pre-sync UPN remediation, PHS heartbeat checks, and sync-health reporting, and KQL detections for sync-account and provisioning anomalies | Azure AD Connect · AD DS · Entra ID · Password Hash Sync · Seamless SSO · Graph PowerShell |
| Phishing-Resistant MFA Lab | Entra ID migration off phishable factors onto FIDO2, Windows Hello, and certificate-based auth: a custom Conditional Access authentication strength, number matching to kill MFA fatigue, AAGUID key allowlisting, a coverage-gated retirement of SMS and voice, and KQL detections for legacy-method sign-ins, prompt bombing, and policy blocks | Entra ID · Authentication Strengths · FIDO2/WebAuthn · Graph PowerShell |
| Identity Governance & Access Reviews | Entra ID Governance build: access packages with two-stage approval and 90 day expiry, separation-of-duties incompatible packages, recurring group, package, and guest access reviews with auto-apply removal, plus Graph reporting and KQL audit queries for grants, review decisions, and SoD denials | Entra ID Governance · Entitlement Management · Access Reviews · Graph PowerShell |
| Privileged Access Workstation | Tier 0 PAW build guide: AppLocker allowlisting, Credential Guard, zero cached credentials, ASR rules, outbound default-deny firewall, plus a Conditional Access policy enforcing PAW-only privileged sign-in and a PowerShell compliance auditor | Windows 11 · AppLocker · Credential Guard · Conditional Access |
| SAML vs OIDC SSO Lab | Side-by-side federation protocol lab in Entra ID: SAML enterprise app with custom claims mapping, OIDC app registration via Graph PowerShell, annotated token teardowns, cert expiry monitoring, and AADSTS failure triage scripts | Entra ID · SAML 2.0 · OIDC/OAuth 2.0 · Graph PowerShell |
| Zero Trust Architecture Lab | Zero Trust reference build in Azure: Conditional Access policy set (phishing-resistant MFA, legacy auth block, device compliance, risk-based), segmented VNet with default-deny NSGs, and KQL detections for policy bypass and tampering | Entra ID · Conditional Access · Azure NSGs · KQL |
| Okta Lifecycle Management | Full joiner-mover-leaver automation: CSV-driven provisioning, attribute-based group rules, SCIM 2.0 app provisioning, and two-stage deprovisioning with audit reporting | Okta · SCIM 2.0 · PowerShell · Universal Directory |
| Azure PIM Lab | Privileged Identity Management: eligible role assignments, MFA-gated activation, approval workflows, quarterly access reviews, and audit KQL queries | Entra ID · PIM · Graph API · PowerShell |
| PowerShell AD Automation | 3 production scripts: bulk user provisioning from CSV, inactive account deprovisioning with quarantine, and full access audit reporting | PowerShell · AD DS · RBAC |
| Azure Entra ID Lab | Conditional Access policies, MFA enforcement, SSPR, device compliance, and legacy auth blocking, with importable JSON policy templates | Entra ID · Intune · Graph API |
| Configuring Active Directory in Azure | Full AD domain from scratch: DCs, OUs, GPOs, user lifecycle, PowerShell bulk provisioning | Azure VMs · AD DS · PowerShell |
| Network File Shares and Permissions | RBAC-based file share access control using AD groups and permission inheritance | Active Directory · RBAC · Windows Server |
| Project | What I Built | Stack |
|---|---|---|
| Microsoft Sentinel SIEM Lab | Full SIEM deployment: log ingestion from Entra ID, 4 KQL detection queries (brute force, impossible travel, privileged activity, new admin alerts), and scheduled analytic rules | Sentinel · KQL · Log Analytics |
| Project | What I Built | Stack |
|---|---|---|
| Azure Network Protocols Lab | NSG rule configuration and live network traffic inspection across RDP, SSH, DNS, ICMP | Azure · NSGs · Wireshark |
| Azure Virtual Machine Setup | Foundation lab: provisioning and configuring Azure VMs for identity and cloud infra work | Azure · Windows Server |
Built and deployed an interactive Security+ SY0-701 practice quiz: timed exams, domain scoring, and instant answer explanations. Working toward CompTIA Security+ (Sep 2026) and SC-300 (Oct 2026); the IAM labs above double as hands-on exam prep.
Identity & Access Azure AD / Entra ID · Active Directory · Okta · AWS IAM Identity Center · Duo MFA · SSO · RBAC · Conditional Access · PIM
Cloud Azure (VMs, VNets, NSGs) · AWS (Organizations, IAM, SCPs) · DNS · DHCP · VPN · VDI · Microsoft Sentinel
Device Management SCCM · Jamf Pro · Intune · AirWatch · iOS/Android MDM · OS Imaging
Security DLP · GDPR · BitLocker · Zscaler · Endpoint Security · MFA · Firewall Policies · KQL
Automation PowerShell · AD Lifecycle Scripting · Bulk Provisioning · GitHub Actions
| Project | What I Built |
|---|---|
| osTicket: Installation | Full helpdesk stack on Azure (IIS, MySQL, PHP) |
| osTicket: Configuration | Roles, departments, SLAs, help topics |
| osTicket: Ticket Lifecycle | End-to-end ticket workflow simulation |
Open to fully remote IAM & Cloud Security Engineer roles · English / Spanish · Saddle Brook, NJ
