Cloud Security & Identity Engineer · Chicago, IL

I secure identities, and the cloud they live in.

I design least-privilege access on AWS and Azure, run hybrid identity across Active Directory, Entra ID and Okta, keep secrets in HashiCorp Vault, and build the detection that catches what slips through. Then I write it down so someone else could rebuild it.

Currently
Working in IT security in Chicago, and building a regulated-bank identity and network lab on the side. Now page
Credentials
AWS Security Specialty · CCSP · SC-300 · Okta Certified Professional and Administrator · Security+ · all eighteen
Education
M.S. Cybersecurity & Digital Forensics, Illinois Institute of Technology · B.Sc. Computer Science & Engineering, University of Mines and Technology
Elsewhere
GitHub · LinkedIn · Email
internetpfSensedefault deny802.1Q trunkVLAN 10ManagementANS01 · PVEVLAN 20BlueTeamSIEM01VLAN 30RedTeamKALI01VLAN 40DevOpsVAULT01VLAN 50EnterpriseLANDC01VLAN 60MonitoringMON01AD Agent · outbound onlyOktaEntra ID
The lab at a glance: a default-deny firewall, six segments, and a domain controller that reaches the cloud identity providers but is never reached from them.
Selected work

Labs built like production, documented like an audit.

All projects
Hybrid identity architecture diagram: network zones and authentication policies above Okta and Entra ID, with Active Directory on premises reached by the Okta AD Agent
Identity · Hybrid identity · Biira Bank

Enterprise IAM Lab: Hybrid Identity for a Regulated Bank

On-prem Active Directory with a tiered admin model, federated to Okta Workforce Identity and Microsoft Entra ID over SAML, OIDC and SWA, with network-aware conditional access and graduated MFA. Built to the regulatory drivers a real bank would have to satisfy.

Active DirectoryWindows Server 2025Okta Workforce IdentityMicrosoft Entra IDSAML 2.0OIDC
Read the case study
Network architecture diagram: internet, pfSense, two switches and six VLAN security zones with firewall status
Infrastructure · Detection · Biira Bank

Enterprise Security Homelab

A six-VLAN, default-deny network for a fictional regional bank: pfSense, managed switching, a Proxmox hypervisor on a trunk port, a Windows Server 2025 domain controller, Wazuh as the SIEM, and every firewall rule justified and mapped to a NIST control.

pfSense802.1Q VLANsProxmox VEWindows Server 2025WazuhAnsible
Read the case study
Writing

Notes from the lab and the study desk.

Written as I go, so they contain the mistakes as well as the fixes. 3 series so far: AZ-900, from zero to 873, HashiCorp Vault, hands on, Identity certifications.

All writing
Credentials

Eighteen, weighted toward identity and cloud security.

All credentials