Senior Engineer — Identity & Access Management
I work on the systems that decide who gets access to what.
Networking to identity engineering — one line of work, followed all the way in.
- 2017NetworkingRouters, switches, AAA — the first time access control was my job.
- 2019IT OperationsJoined Priority Technology Holdings; enterprise support at scale.
- ~2020Enterprise AccessSaaS administration and the phased OneLogin rollout.
- ~2021SSOSAML 2.0 and OIDC integrations across 15+ applications.
- ~2023IAM EngineeringOkta, MFA, RBAC and access governance as a discipline.
- NowAutomationScripting the routine and building internal identity tooling.
- NextIdentity EngineeringDeeper platform, protocol and governance architecture.
The layers around every identity.
Identity & Access Management
Okta, OneLogin and Ping Identity for a 1,200+ user environment.
Enterprise SSO
15+ SAML 2.0 and OIDC integrations, onboarded and supported end to end.
Identity Lifecycle
Joiner-Mover-Leaver, RBAC and least-privilege access across systems.
SaaS Administration
Google Workspace and Microsoft 365 provisioning, policy and security.
Automation
Scripting identity and operational tasks, and building internal tooling.
Access Governance
MFA, access requests, audit trails and certification-ready inventory.
A body of work in identity, access and the tools around them.
8 pieces — professional engineering, personal builds and clearly-labelled experiments. Open any one for the full case study.
- 01LifeCycleOneAn employee lifecycle & identity-operations platform.
- 02User360One employee view across identity, accounts, apps and assets.
- 03SailPoint × Atlassian ConnectorA custom REST connector feeding Atlassian identities into SailPoint ISC.
- 04IAM / SSO EngineeringEnterprise SSO, MFA, RBAC and authentication troubleshooting.
- 05Workspace OU Policy MapOU hierarchy & policy visibility for Google Workspace governance.
- 06Local Password ManagerA local-first vault: Tauri + Rust, a signed loopback bridge, a Chrome extension.
- 07Offline Payment RelayAn offline-first, device-to-device payment concept (BLE + QR fallback).
- 08NIFTY LensA deterministic chart-review companion — no broker, no trades.
Lifecycle, orchestrated.
Built an employee-lifecycle platform that centralizes onboarding, offboarding, identity visibility and operational workflows across enterprise SaaS systems.
- 01
Validate the request
An approved joiner, mover or leaver — fields checked, duplicates caught, before anything runs.
- 02
Execute connectors
System-specific actions fan out through one connector contract across the connected stack.
- 03
Collect per-system results
Every application reports back individually — a job never collapses into a single pass/fail.
Google WorkspaceActive DirectoryMicrosoft 365SlackAtlassianAssetSonar - 04
Review partial failures
Failed systems stay visible and individually retryable, with the full history kept.
Where the work happened.
Senior Engineer — Identity & Access Management
Priority Technology Holdings
Enterprise identity, access and SaaS operations across Okta, OneLogin, Ping Identity, Google Workspace and Microsoft 365.
- Managed IAM platforms (Okta, OneLogin, Ping Identity) for a 1,200+ user environment and acted as a primary point of contact for identity issues.
- Led a phased, organization-wide OneLogin rollout and integrated 15+ enterprise applications using SAML 2.0 and OIDC.
- Configured and enforced MFA, access policies, RBAC and least-privilege controls, and ran Joiner-Mover-Leaver processes.
Network Support Executive
DVOIS Convergent Communication
A networking foundation in authentication, access control and resilient 24/7 incident response.
- Supported enterprise network infrastructure — routers, switches and access points — for high availability and performance.
- Managed AAA (Authentication, Authorization, Accounting) systems, building foundational experience in access control and network security.
- Troubleshot connectivity and authentication issues and responded to incidents in a 24/7 support environment.
What I know, and what proves it.
Core
The discipline I'm hired for.
Hands-on
Platforms I operate day to day.
Project experience
Used to build the things on this site.
Learning / exploring
The next-chapter list — deliberately separated from experience.
→ Certifications
- AWS SAASolutions Architect — AssociateAmazon Web Services2022
- SC-900Security, Compliance & Identity FundamentalsMicrosoft2026
- SC-300Identity and Access Administrator AssociateMicrosoft2026
- SailPointIdentityNow / Identity Security Cloud — LeaderSailPoint2026
- SailPointIdentityNow / Identity Security Cloud — ProfessionalSailPoint2026
- AZ-500Azure Security Engineer AssociateMicrosoftIn progress · 2026
→ Education
- Bachelor of Computer Applications
- Diploma in Computer Science & Engineering
→ Recognition
- Received 5+ Kudos awards for consistent performance, ownership and team support.
- Received Spot Recognition for contributions to IAM initiatives, including SSO and access-management improvements.
- Recognized by leadership for resolving critical access issues and supporting reliable IAM operations.
The identity-engineering roadmap.
A deliberate learning plan — not completed experience. This is the direction I'm building toward next.
- 01
Control plane
Move from operating access to designing the conditions on it.
- Entra Conditional Access
- PIM
- Azure RBAC vs Entra roles
- Zero Trust
- 02
Protocol depth
Know the tokens well enough to debug them without the console.
- OAuth 2.0
- OIDC
- JWT
- SAML
- SCIM
- 03
Automation layer
Replace repeat clicks with reviewable, auditable code.
- Microsoft Graph
- PowerShell automation
- Python API automation
- REST APIs
- 04
Governance architecture
Design lifecycle and certification as a system, not a checklist.
- JML architecture
- RBAC vs ABAC
- Segregation of Duties
- Access Certification
- Identity architecture
Have a role in mind?