Projects I implemented

Hands-on security engineering across privileged access, identity federation, and data protection. I build platforms from the ground up, translate access and data risks into practical controls, and refine those controls through investigation and testing.

Enterprise platform · Built from scratch

CyberArk PAM implementation

What I did

  • Built CyberArk PAM from the ground up, including server infrastructure design and the foundation for privileged-account governance.
  • Designed safe and RBAC structures to define who could access privileged accounts and which permissions each role required.
  • Established privileged-access policies that translated access requirements into defined account-governance controls.

Security value: a governed foundation for privileged access, with explicit ownership of roles, permissions, and account-access policies.

CyberArk · PAM · RBACImplementation details →

Enterprise platform · Built from scratch

PingFederate SSO & MFA

What I did

  • Implemented PingFederate from the ground up as the foundation for single sign-on and multifactor authentication integrations.
  • Configured IdP- and SP-initiated authentication flows, supporting sign-in journeys that begin at either the identity provider or the application.
  • Integrated SSO and MFA controls to bring identity federation and authentication requirements into the same implementation.

Security value: federated sign-in and MFA requirements implemented across both application-initiated and identity-provider-initiated access.

PingFederate · SSO · MFAImplementation details →

Enterprise platform · Built from scratch

Microsoft Purview DLP

What I did

  • Built Microsoft Purview DLP from the ground up and engineered policies to detect and prevent unauthorized movement of sensitive data.
  • Analyzed alert trends and investigated policy matches to identify detection gaps and separate actionable events from noisy alerts.
  • Refined policy logic to reduce false positives and improve detection quality as part of ongoing data-protection engineering.

Security value: sensitive-data controls that combine policy enforcement with investigation and tuning, rather than relying on default alerts alone.

Microsoft Purview · DLP · Policy tuningImplementation details →

Personal project · AI-assisted implementation

Hermes AI assistant deployment

What I did

  • Directed a security-focused Hermes deployment, defining access requirements and integration boundaries for a private AI assistant.
  • Delivered supporting services with AI assistance, combining origin JWT verification, least-privilege Linux hardening, and controlled credential access.
  • Validated failure paths with security tests, including rejected identities, missing consent, disallowed API calls, and mobile browser workflows.

Security value: identity checks and constrained service actions backed by negative-path tests—not trust in an AI response or a supplied identity header.

Python · Flask · Cloudflare · LinuxImplementation & tests →

Project scope: the platform summaries reflect my confirmed implementation work. Hermes uses the Nous Research framework; my contribution is deployment, integration architecture, security requirements, and AI-assisted implementation—not the underlying agent engine or language models.

Security expertise at a glance

Follow each security domain to the implementation or responsibility behind it.

Security responsibility Directly documented security work. Supporting IT foundation Operational experience supporting security engineering.

Security experience across my career

Security responsibilities appear throughout my career: privileged access, identity federation, sensitive-data protection, event investigation, authenticated server access, and network authentication. Systems administration and automation provide the operational foundation for that work. These are additional areas of work from my professional experience, not separate claims of building every platform from scratch.

Security operations and data protection

Security responsibility

Cloud controls · Enterprise data protection

Netskope CASB and DLP policy engineering

I managed cloud-security policies alongside enterprise DLP controls, with a focus on sensitive-data movement in SaaS and cloud usage. This work extended data protection beyond a single platform.

  • Managed Netskope CASB policies to address data-leakage risk across cloud applications.
  • Engineered and tuned Broadcom/Symantec DLP policies alongside Microsoft Purview to detect and prevent unauthorized data movement.
  • Used alert analysis and policy refinement to address false-positive noise and improve detection quality.

Demonstrates: cloud-security policy management, DLP engineering, and investigation-driven tuning.

Security responsibility

Sensitive-data discovery · Encryption

Securiti discovery and CipherTrust integration

I led sensitive-data discovery and classification and guided encryption and key-management integration. The responsibilities connected identifying sensitive information with decisions about how to protect it.

  • Led Securiti discovery and classification of personally identifiable information, protected health information, and payment-card data.
  • Guided CipherTrust encryption and key-management integration as part of the broader data-protection function.
  • Partnered with infrastructure, compliance, legal, and business teams to translate security risk into practical controls.

Demonstrates: data classification, encryption integration, and coordination across technical and business teams.

Security responsibility

Monitoring · Incident response

Splunk investigations and response workflows

I investigated security events and worked on the operational steps around those investigations. My experience includes interpreting alerts, adding context, and refining how events are escalated and handled.

  • Investigated security events with Splunk and added context to alerts to support analysis.
  • Refined escalation workflows and incident-response playbooks as part of security operations.
  • Analyzed DLP alert trends and used the findings to inform policy changes and false-positive reduction.

Demonstrates: event investigation, alert interpretation, and practical incident-response workflow development.

Security responsibility

Security management · Awareness

Security program leadership and stakeholder coordination

My security-management responsibilities span data protection, IAM, privileged access, incident response, and security awareness. I combine program coordination with hands-on platform and policy work.

  • Led enterprise data-protection and security-engineering responsibilities across DLP, CASB, encryption, discovery, and access controls.
  • Led the KnowBe4 awareness program across business units.
  • Worked with infrastructure, IAM, compliance, legal, and business teams to connect security requirements with controls teams could operate.

Demonstrates: security-program coordination, stakeholder communication, and technical implementation ownership.

Access controls and supporting IT engineering

Security responsibility

SAIC · Deployment and access administration

Active Directory access administration and endpoint deployment

My administration work covered software deployment, user accounts, and endpoint support. I handled the operational relationship between the applications people needed and the access required to use them.

  • Used PDQ and PowerShell to deploy application updates across a lab-computing environment.
  • Administered Active Directory accounts and access alongside endpoint-support responsibilities.
  • Applied scripting and deployment tooling to practical systems-administration work rather than limiting automation to standalone demonstrations.

Security contribution: Active Directory account and access administration. Supporting IT work: application updates, deployment tooling, and endpoint support.

Security responsibility

Hyundai Kia Motor Company · IT Support Specialist

IPsec authenticated server access and Citrix desktops

I implemented access restrictions at the infrastructure layer and deployed virtual desktops. These projects connect my earlier IT work with the access-control and platform-engineering responsibilities in my security roles.

  • Implemented IPsec server isolation to restrict server access to authenticated users without additional cost.
  • Deployed Citrix virtual desktops to consolidate hardware and support the computing environment.
  • Applied infrastructure controls to practical business needs: authenticated server access and a virtualized desktop deployment.

Security contribution: restricted server access to authenticated users through IPsec isolation. Supporting IT work: Citrix deployment and hardware consolidation.

Security responsibility

UCI Student Center and Event Services · IT Support

RADIUS network authentication and endpoint monitoring

I built and managed campus network authentication and designed network infrastructure for a business unit. The work included endpoint-management and monitoring tools as well as connectivity.

  • Built and managed RADIUS authentication for campus network access.
  • Designed and deployed 10Gb network infrastructure for the marketing business unit.
  • Administered AirWatch, IBM BigFix, and Splunk for endpoint management and monitoring.

Security contribution: RADIUS-based network authentication and Splunk monitoring. Supporting IT work: endpoint management and 10Gb infrastructure deployment.

Supporting IT foundation

SAIC · Systems administration

Python automation and VMware operations

I developed scripts for operational tasks in a systems-administration environment. This experience gave me a practical foundation in turning recurring administration needs into executable tooling.

  • Developed Python scripts for operational reporting to support systems-administration work.
  • Automated server-restart tasks through scripting.
  • Built scripts for VMware snapshot management, connecting automation work with virtualization operations.

Supporting IT foundation: Python automation and VMware operations. These tasks are not presented as a separate security-control implementation.

Supporting IT foundation

SAIC · Principal Desktop Technician

Enterprise support and endpoint lifecycle engineering

I provided Tier 2/3 support across Microsoft and Apple enterprise environments and built tools for endpoint operations. The role combined user-facing troubleshooting with deployment and lifecycle responsibilities.

  • Provided advanced enterprise desktop support for Microsoft and Apple environments.
  • Built PowerShell and Python tools for endpoint data capture, software deployment, asset inventory, and troubleshooting.
  • Managed endpoint imaging, rollout coordination, and lifecycle support across the computing environment.

Supporting IT foundation: endpoint visibility through inventory and data-capture tools, plus troubleshooting and lifecycle operations. No vulnerability-management or EDR deployment is claimed.

Career progression

The roles behind this work, ordered from security leadership back to my earlier IT foundation. My résumé carries the full employment timeline.

  1. Hyundai Capital America

    Security Manager, Data Protection & Security Engineering

    Enterprise data protection and security engineering across DLP, CASB, encryption, discovery, IAM, and privileged access, with incident-response and awareness responsibilities. Hands-on implementations include CyberArk, PingFederate, and Microsoft Purview.

    Security scope: Data protection, IAM/PAM, security investigations, and awareness.

  2. SAIC

    System Administrator

    Python automation for reporting, server restarts, and VMware snapshots; application updates using PDQ and PowerShell; Active Directory account and access administration.

    Security responsibility: Active Directory accounts and access administration.

  3. SAIC

    Principal Desktop Technician

    Tier 2/3 enterprise support, Microsoft and Apple endpoint troubleshooting, PowerShell and Python tooling, imaging, asset inventory, and rollout coordination.

    Supporting IT foundation: Endpoint inventory, data capture, troubleshooting, and deployment.

  4. Hyundai Kia Motor Company

    IT Support Specialist

    IPsec server isolation for authenticated access and Citrix virtual-desktop deployment to consolidate hardware.

    Security responsibility: IPsec isolation restricting access to authenticated users.

  5. UCI Student Center and Event Services

    IT Support

    RADIUS network authentication, 10Gb infrastructure deployment, and administration of AirWatch, IBM BigFix, and Splunk.

    Security responsibility: RADIUS authentication and Splunk monitoring.

These summaries describe documented responsibilities and implementation work. Confidential deployment sizes, employer configurations, and internal outcome metrics remain private.

Implementation approach and technical evidence

Explore the implementation work, the security problems it addresses, and the evidence available for a technical interview.

CyberArk PAM · infrastructure, access design & governanceOpen details ↓

Implementation ownership

I built the CyberArk PAM implementation from scratch, including server infrastructure design, safe structure, role-based access, access policies, and privileged-account governance. My work connected the infrastructure foundation with the access model: who should be able to reach a privileged account, what they should be allowed to do, and how those permissions should be governed.

Safe membership and permissions are platform mechanisms for defining the access boundary. Account rotation and session-control features depend on the deployment; this portfolio does not claim an unspecified rotation or recording implementation.

What this project demonstrates

  • Infrastructure-to-policy ownership: experience building the server foundation as well as designing the safe, role, and access-policy structure above it.
  • Least-privilege access design: the ability to translate account-access needs into role-specific permissions and defined governance.
  • Privileged-account governance: an implementation approach that considers how accounts are controlled, not only whether the platform is installed.

Disclosure: conceptual product context only. Actual safe names, role matrices, account identifiers, employer configurations, and internal measurements are not published.

CyberArk safe-management reference ↗
PingFederate · federation & authentication integrationOpen details ↓

SSO and MFA integration

I implemented PingFederate from scratch for SSO and MFA, including IdP-initiated and SP-initiated authentication flows. This work covered identity federation and the different entry points into a sign-in journey, rather than treating SSO as an isolated application setting. The implementation brought authentication requirements into both identity-provider-driven and application-driven access.

In the documented SAML examples, an SP-initiated flow starts with the application’s authentication request; an IdP-initiated flow starts from an authenticated identity provider. Authentication policies can route users through MFA.

What this project demonstrates

  • Hands-on IAM implementation: experience standing up a federation platform and integrating SSO and MFA requirements.
  • Authentication-flow design: understanding of both IdP-initiated and SP-initiated entry paths and their role in application access.
  • Security integration: the ability to connect identity-provider behavior, application sign-in, and additional authentication requirements.

Disclosure: those are platform concepts, not a list of every feature I deployed. Partner connections, adapters, mappings, certificates, factors, and environment-specific protocols remain private.

PingFederate sign-in flow reference ↗
Microsoft Purview · policy engineering & detection qualityOpen details ↓

DLP policy design and tuning

I built Microsoft Purview DLP from scratch and engineered policies to detect and prevent unauthorized data movement. Beyond the initial implementation, I analyzed alert trends and refined policy logic to improve detection quality and reduce false-positive noise. That ongoing work connected the policy configuration to the events security teams actually needed to investigate.

Purview policies combine workload scope, sensitive-data conditions, actions, and alerting. Simulation is a documented way to inspect likely policy matches before enforcement; it is product context here, not a claim about a particular rollout I performed.

What this project demonstrates

  • Data-protection engineering: experience translating sensitive-data risk into DLP policies rather than relying only on a vendor tool inventory.
  • Investigation-driven tuning: use of alert trends and policy matches to inform changes to detection logic.
  • Operational judgment: attention to both unauthorized data movement and false-positive noise so that policy alerts support investigation.

Disclosure: internal detectors, workloads, exceptions, rollout stages, deployment outcomes, and confidential measurements are not included.

Microsoft DLP policy reference ↗
Hermes · security implementation and testsOpen details ↓

My role and implementation

I deployed a private assistant on Hermes Agent by Nous Research and directed an AI-assisted implementation of protected web services and integrations. My contribution covers security requirements, integration architecture, deployment decisions, implementation, and testing.

The diagram shows a conceptual web-service boundary, not the agent’s full tool access or a map of the deployed network.

Security controls implemented

  • Edge and origin verification: Cloudflare Access plus application validation of RS256 signatures through JWKS, issuer, audience, expiry, required claims, and the approved-user allowlist. A supplied email header alone is not proof of identity.
  • Service hardening: loopback-bound web origins behind an outbound tunnel, with Linux/systemd controls including NoNewPrivileges, ProtectSystem=strict, ProtectHome=read-only, and narrowly scoped ReadWritePaths.
  • Credential and API boundaries: encrypted credential storage, a fixed credential-reader origin/reference/executable, an explicit endpoint allowlist, rejected redirects, and error responses that omit credential values and raw upstream payloads.
  • Action controls: read-only dashboard HTTP routes, owner-only connection actions, affirmative consent, and origin/CSRF validation.

How the controls were checked

  • Negative-path tests cover expired and tampered tokens, incorrect audiences, spoofed identity headers, unauthorized users, missing consent, and disallowed API paths.
  • Isolated fixtures use synthetic identities and test data rather than real credentials or private records.
  • Python tests check authorization and integration behavior. Browser checks exercise navigation, consent handling, mobile layouts, and local assets. Public access checks confirm the authentication gate.

A practical least-privilege trade-off

A hardened credential-entry service could not acquire its required runtime locks. The fix granted access to the specific lock and lease locations instead of making the application installation writable.

What this project demonstrates

  • Security architecture applied to AI: separation of user identity, service permissions, integration access, and actions that require consent.
  • Engineering judgment: narrowly scoped fixes for service-hardening problems instead of weakening the entire deployment.
  • Evidence-led validation: tests for rejected requests and unauthorized actions, not just a successful demonstration.

Scope and limits: personal lab, not an employer deployment or enterprise certification. Profiles separate configuration and session state; they are not an OS sandbox. Hardening selected services does not contain every agent tool or eliminate prompt injection. Synthetic tests are distinct from an actual user sign-in.

Hermes framework documentation ↗Profile isolation limits ↗

About this portfolio

I bring hands-on implementation experience across PAM, IAM, and data protection, supported by a background in systems administration and security engineering. My work spans building security platforms, designing access and data controls, investigating alerts, and refining policies. In my broader role, I partner with infrastructure, IAM, compliance, legal, and business teams to translate security risk into practical controls. My résumé provides the career timeline and contact information.

This page keeps employer configuration details, private service addresses, credentials, and confidential project measurements out of the public portfolio. The diagrams are sanitized concepts; product capabilities are distinguished from the work I performed.