Nick Vo / Security Engineer

Security, verified.

I set up security platforms from the ground up. Here are three I can take apart—from privileged access and federation to data loss prevention—without exposing the environments behind them.

01 /CyberArk · PAM
02 /PingFederate · SSO
03 /Microsoft Purview · DLP

Selected projects / Three platform builds

Built from first principles.

I built these platforms from scratch. My résumé carries the career timeline; this page focuses on the controls and design questions. The diagrams show general concepts, not internal infrastructure.

Read mode
02 / Identity federationBuild · PingFederate

Make sign-in coherent.

I set up PingFederate from scratch for SSO and MFA integrations, including IdP- and SP-initiated sign-in flows. Both paths must deliver the right identity decision without making the trust boundary invisible.

Platform concepts ↗

In an SP-initiated SAML flow, an application starts the authentication request; in an IdP-initiated flow, an already-authenticated identity provider starts sign-in. PingFederate authentication policies can route users through MFA. These are platform concepts; specific partner connections, adapters, mappings, certificates, factors and protocols are not represented here.

PingFederate flow reference ↗
PingFederateSSO / MFAFederation
03 / Data protectionBuild · Microsoft Purview

Turn policy into protection.

I set up Microsoft Purview DLP from scratch, then worked on policy design, alert analysis, and false-positive tuning to help detect and prevent sensitive-data exposure. Deployment outcomes and internal policy details are not shown here.

Platform concepts ↗

Microsoft Purview DLP policies combine workload scope, sensitive-data conditions, actions, and alerting. Simulation can expose likely policy matches before enforcement and help tune false positives. Those are documented product capabilities, not a claim that I used every feature; environment-specific workloads, detectors, exceptions and rollout stages are not specified here.

Microsoft policy reference ↗
Microsoft PurviewDLPPolicy tuning

Method / Three decisions

Less theater. More proof.

  1. 01

    Define the trust boundary.

    Identify the accounts, applications, and sensitive data a control is meant to protect.

  2. 02

    Build for the real workflow.

    Give legitimate access a reliable path without making exceptions the default.

  3. 03

    Validate and refine.

    Examine the policy decision, investigation signal, and operational friction before calling the control complete.

About / Nick Vo

The résumé has the timeline. This is the work.

I work across privileged access, identity federation, and data protection—from getting a platform running to making its policies useful in practice.

On this page: CyberArk privileged-access design, PingFederate SSO/MFA integration, and Microsoft Purview DLP.

The project summaries reflect my résumé and my confirmation that I stood up these platforms from scratch. Platform-level technical context is not a claim about a specific employer’s configuration.

Next / The deeper conversation

The résumé starts it. The architecture explains it.

This portfolio accompanies my résumé. I can discuss design trade-offs, implementation decisions, and validation methods in an interview; private environment details and internal results remain off this page.

Deliberate disclosureNo contact details or confidential project measurements appear here. Please use the contact information on the résumé that accompanied this portfolio.