Hands-on security engineering across privileged access, identity federation, and data protection. I build platforms from the ground up, translate access and data risks into practical controls, and refine those controls through investigation and testing.
Enterprise platform · Built from scratch
CyberArk PAM implementation
What I did
Built CyberArk PAM from the ground up, including server infrastructure design and the foundation for privileged-account governance.
Designed safe and RBAC structures to define who could access privileged accounts and which permissions each role required.
Established privileged-access policies that translated access requirements into defined account-governance controls.
Security value: a governed foundation for privileged access, with explicit ownership of roles, permissions, and account-access policies.
Directed a security-focused Hermes deployment, defining access requirements and integration boundaries for a private AI assistant.
Delivered supporting services with AI assistance, combining origin JWT verification, least-privilege Linux hardening, and controlled credential access.
Validated failure paths with security tests, including rejected identities, missing consent, disallowed API calls, and mobile browser workflows.
Security value: identity checks and constrained service actions backed by negative-path tests—not trust in an AI response or a supplied identity header.
Project scope: the platform summaries reflect my confirmed implementation work. Hermes uses the Nous Research framework; my contribution is deployment, integration architecture, security requirements, and AI-assisted implementation—not the underlying agent engine or language models.
Security expertise at a glance
Follow each security domain to the implementation or responsibility behind it.
Security responsibility Directly documented security work. Supporting IT foundation Operational experience supporting security engineering.
Security experience across my career
Security responsibilities appear throughout my career: privileged access, identity federation, sensitive-data protection, event investigation, authenticated server access, and network authentication. Systems administration and automation provide the operational foundation for that work. These are additional areas of work from my professional experience, not separate claims of building every platform from scratch.
Security operations and data protection
Security responsibility
Cloud controls · Enterprise data protection
Netskope CASB and DLP policy engineering
I managed cloud-security policies alongside enterprise DLP controls, with a focus on sensitive-data movement in SaaS and cloud usage. This work extended data protection beyond a single platform.
Managed Netskope CASB policies to address data-leakage risk across cloud applications.
Engineered and tuned Broadcom/Symantec DLP policies alongside Microsoft Purview to detect and prevent unauthorized data movement.
Used alert analysis and policy refinement to address false-positive noise and improve detection quality.
Demonstrates: cloud-security policy management, DLP engineering, and investigation-driven tuning.
Security responsibility
Sensitive-data discovery · Encryption
Securiti discovery and CipherTrust integration
I led sensitive-data discovery and classification and guided encryption and key-management integration. The responsibilities connected identifying sensitive information with decisions about how to protect it.
Led Securiti discovery and classification of personally identifiable information, protected health information, and payment-card data.
Guided CipherTrust encryption and key-management integration as part of the broader data-protection function.
Partnered with infrastructure, compliance, legal, and business teams to translate security risk into practical controls.
Demonstrates: data classification, encryption integration, and coordination across technical and business teams.
Security responsibility
Monitoring · Incident response
Splunk investigations and response workflows
I investigated security events and worked on the operational steps around those investigations. My experience includes interpreting alerts, adding context, and refining how events are escalated and handled.
Investigated security events with Splunk and added context to alerts to support analysis.
Refined escalation workflows and incident-response playbooks as part of security operations.
Analyzed DLP alert trends and used the findings to inform policy changes and false-positive reduction.
Demonstrates: event investigation, alert interpretation, and practical incident-response workflow development.
Security responsibility
Security management · Awareness
Security program leadership and stakeholder coordination
My security-management responsibilities span data protection, IAM, privileged access, incident response, and security awareness. I combine program coordination with hands-on platform and policy work.
Led enterprise data-protection and security-engineering responsibilities across DLP, CASB, encryption, discovery, and access controls.
Led the KnowBe4 awareness program across business units.
Worked with infrastructure, IAM, compliance, legal, and business teams to connect security requirements with controls teams could operate.
Demonstrates: security-program coordination, stakeholder communication, and technical implementation ownership.
Access controls and supporting IT engineering
Security responsibility
SAIC · Deployment and access administration
Active Directory access administration and endpoint deployment
My administration work covered software deployment, user accounts, and endpoint support. I handled the operational relationship between the applications people needed and the access required to use them.
Used PDQ and PowerShell to deploy application updates across a lab-computing environment.
Administered Active Directory accounts and access alongside endpoint-support responsibilities.
Applied scripting and deployment tooling to practical systems-administration work rather than limiting automation to standalone demonstrations.
Security contribution: Active Directory account and access administration. Supporting IT work: application updates, deployment tooling, and endpoint support.
Security responsibility
Hyundai Kia Motor Company · IT Support Specialist
IPsec authenticated server access and Citrix desktops
I implemented access restrictions at the infrastructure layer and deployed virtual desktops. These projects connect my earlier IT work with the access-control and platform-engineering responsibilities in my security roles.
Implemented IPsec server isolation to restrict server access to authenticated users without additional cost.
Deployed Citrix virtual desktops to consolidate hardware and support the computing environment.
Applied infrastructure controls to practical business needs: authenticated server access and a virtualized desktop deployment.
Security contribution: restricted server access to authenticated users through IPsec isolation. Supporting IT work: Citrix deployment and hardware consolidation.
Security responsibility
UCI Student Center and Event Services · IT Support
RADIUS network authentication and endpoint monitoring
I built and managed campus network authentication and designed network infrastructure for a business unit. The work included endpoint-management and monitoring tools as well as connectivity.
Built and managed RADIUS authentication for campus network access.
Designed and deployed 10Gb network infrastructure for the marketing business unit.
Administered AirWatch, IBM BigFix, and Splunk for endpoint management and monitoring.
Security contribution: RADIUS-based network authentication and Splunk monitoring. Supporting IT work: endpoint management and 10Gb infrastructure deployment.
Supporting IT foundation
SAIC · Systems administration
Python automation and VMware operations
I developed scripts for operational tasks in a systems-administration environment. This experience gave me a practical foundation in turning recurring administration needs into executable tooling.
Developed Python scripts for operational reporting to support systems-administration work.
Automated server-restart tasks through scripting.
Built scripts for VMware snapshot management, connecting automation work with virtualization operations.
Supporting IT foundation: Python automation and VMware operations. These tasks are not presented as a separate security-control implementation.
Supporting IT foundation
SAIC · Principal Desktop Technician
Enterprise support and endpoint lifecycle engineering
I provided Tier 2/3 support across Microsoft and Apple enterprise environments and built tools for endpoint operations. The role combined user-facing troubleshooting with deployment and lifecycle responsibilities.
Provided advanced enterprise desktop support for Microsoft and Apple environments.
Built PowerShell and Python tools for endpoint data capture, software deployment, asset inventory, and troubleshooting.
Managed endpoint imaging, rollout coordination, and lifecycle support across the computing environment.
Supporting IT foundation: endpoint visibility through inventory and data-capture tools, plus troubleshooting and lifecycle operations. No vulnerability-management or EDR deployment is claimed.
Career progression
The roles behind this work, ordered from security leadership back to my earlier IT foundation. My résumé carries the full employment timeline.
Hyundai Capital America
Security Manager, Data Protection & Security Engineering
Enterprise data protection and security engineering across DLP, CASB, encryption, discovery, IAM, and privileged access, with incident-response and awareness responsibilities. Hands-on implementations include CyberArk, PingFederate, and Microsoft Purview.
Security scope: Data protection, IAM/PAM, security investigations, and awareness.
SAIC
System Administrator
Python automation for reporting, server restarts, and VMware snapshots; application updates using PDQ and PowerShell; Active Directory account and access administration.
Security responsibility: Active Directory accounts and access administration.
SAIC
Principal Desktop Technician
Tier 2/3 enterprise support, Microsoft and Apple endpoint troubleshooting, PowerShell and Python tooling, imaging, asset inventory, and rollout coordination.
Supporting IT foundation: Endpoint inventory, data capture, troubleshooting, and deployment.
Hyundai Kia Motor Company
IT Support Specialist
IPsec server isolation for authenticated access and Citrix virtual-desktop deployment to consolidate hardware.
Security responsibility: IPsec isolation restricting access to authenticated users.
UCI Student Center and Event Services
IT Support
RADIUS network authentication, 10Gb infrastructure deployment, and administration of AirWatch, IBM BigFix, and Splunk.
Security responsibility: RADIUS authentication and Splunk monitoring.
These summaries describe documented responsibilities and implementation work. Confidential deployment sizes, employer configurations, and internal outcome metrics remain private.
Implementation approach and technical evidence
Explore the implementation work, the security problems it addresses, and the evidence available for a technical interview.
I built the CyberArk PAM implementation from scratch, including server infrastructure design, safe structure, role-based access, access policies, and privileged-account governance. My work connected the infrastructure foundation with the access model: who should be able to reach a privileged account, what they should be allowed to do, and how those permissions should be governed.
User→Access policy→Safe
Safe membership and permissions are platform mechanisms for defining the access boundary. Account rotation and session-control features depend on the deployment; this portfolio does not claim an unspecified rotation or recording implementation.
What this project demonstrates
Infrastructure-to-policy ownership: experience building the server foundation as well as designing the safe, role, and access-policy structure above it.
Least-privilege access design: the ability to translate account-access needs into role-specific permissions and defined governance.
Privileged-account governance: an implementation approach that considers how accounts are controlled, not only whether the platform is installed.
Disclosure: conceptual product context only. Actual safe names, role matrices, account identifiers, employer configurations, and internal measurements are not published.
I implemented PingFederate from scratch for SSO and MFA, including IdP-initiated and SP-initiated authentication flows. This work covered identity federation and the different entry points into a sign-in journey, rather than treating SSO as an isolated application setting. The implementation brought authentication requirements into both identity-provider-driven and application-driven access.
In the documented SAML examples, an SP-initiated flow starts with the application’s authentication request; an IdP-initiated flow starts from an authenticated identity provider. Authentication policies can route users through MFA.
What this project demonstrates
Hands-on IAM implementation: experience standing up a federation platform and integrating SSO and MFA requirements.
Authentication-flow design: understanding of both IdP-initiated and SP-initiated entry paths and their role in application access.
Security integration: the ability to connect identity-provider behavior, application sign-in, and additional authentication requirements.
Disclosure: those are platform concepts, not a list of every feature I deployed. Partner connections, adapters, mappings, certificates, factors, and environment-specific protocols remain private.
Microsoft Purview · policy engineering & detection qualityOpen details ↓
DLP policy design and tuning
I built Microsoft Purview DLP from scratch and engineered policies to detect and prevent unauthorized data movement. Beyond the initial implementation, I analyzed alert trends and refined policy logic to improve detection quality and reduce false-positive noise. That ongoing work connected the policy configuration to the events security teams actually needed to investigate.
Purview policies combine workload scope, sensitive-data conditions, actions, and alerting. Simulation is a documented way to inspect likely policy matches before enforcement; it is product context here, not a claim about a particular rollout I performed.
What this project demonstrates
Data-protection engineering: experience translating sensitive-data risk into DLP policies rather than relying only on a vendor tool inventory.
Investigation-driven tuning: use of alert trends and policy matches to inform changes to detection logic.
Operational judgment: attention to both unauthorized data movement and false-positive noise so that policy alerts support investigation.
Disclosure: internal detectors, workloads, exceptions, rollout stages, deployment outcomes, and confidential measurements are not included.
Hermes · security implementation and testsOpen details ↓
My role and implementation
I deployed a private assistant on Hermes Agent by Nous Research and directed an AI-assisted implementation of protected web services and integrations. My contribution covers security requirements, integration architecture, deployment decisions, implementation, and testing.
The diagram shows a conceptual web-service boundary, not the agent’s full tool access or a map of the deployed network.
Security controls implemented
Edge and origin verification: Cloudflare Access plus application validation of RS256 signatures through JWKS, issuer, audience, expiry, required claims, and the approved-user allowlist. A supplied email header alone is not proof of identity.
Service hardening: loopback-bound web origins behind an outbound tunnel, with Linux/systemd controls including NoNewPrivileges, ProtectSystem=strict, ProtectHome=read-only, and narrowly scoped ReadWritePaths.
Credential and API boundaries: encrypted credential storage, a fixed credential-reader origin/reference/executable, an explicit endpoint allowlist, rejected redirects, and error responses that omit credential values and raw upstream payloads.
Negative-path tests cover expired and tampered tokens, incorrect audiences, spoofed identity headers, unauthorized users, missing consent, and disallowed API paths.
Isolated fixtures use synthetic identities and test data rather than real credentials or private records.
Python tests check authorization and integration behavior. Browser checks exercise navigation, consent handling, mobile layouts, and local assets. Public access checks confirm the authentication gate.
A practical least-privilege trade-off
A hardened credential-entry service could not acquire its required runtime locks. The fix granted access to the specific lock and lease locations instead of making the application installation writable.
What this project demonstrates
Security architecture applied to AI: separation of user identity, service permissions, integration access, and actions that require consent.
Engineering judgment: narrowly scoped fixes for service-hardening problems instead of weakening the entire deployment.
Evidence-led validation: tests for rejected requests and unauthorized actions, not just a successful demonstration.
Scope and limits: personal lab, not an employer deployment or enterprise certification. Profiles separate configuration and session state; they are not an OS sandbox. Hardening selected services does not contain every agent tool or eliminate prompt injection. Synthetic tests are distinct from an actual user sign-in.
I bring hands-on implementation experience across PAM, IAM, and data protection, supported by a background in systems administration and security engineering. My work spans building security platforms, designing access and data controls, investigating alerts, and refining policies. In my broader role, I partner with infrastructure, IAM, compliance, legal, and business teams to translate security risk into practical controls. My résumé provides the career timeline and contact information.
This page keeps employer configuration details, private service addresses, credentials, and confidential project measurements out of the public portfolio. The diagrams are sanitized concepts; product capabilities are distinguished from the work I performed.