IT Systems & IAM Analst @ IntusCare
Portfolio Note
The projects in this portfolio are intentionally designed to simulate the real workflows of an Identity & Access Management (IAM) professional working in enterprise environments.
Each project focuses on practical security tasks such as identity lifecycle automation, RBAC design, access governance, privileged access management, and integration between systems like Active Directory, Okta, and Microsoft Entra ID.
The goal is to demonstrate how a security engineer designs, automates, and manages identity systems at scale, using scripting, identity platforms, and security best practices to enforce consistent access control across hybrid environments.
| Workflow Project | Proof | Purpose | Stack | Status |
|---|---|---|---|---|
| SaaS App Integration w/ Okta (SAML) | Video & Screenshots Included | This lab serves as a pre-requisite step before all proceeding labs. | Okta · SAML | |
| Implementing (RBAC) W/ Okta | Video & Screenshots Included | This lab demonstrates well designed RBAC. | AD · Okta · SAML | |
| Automated JML W/ Cert-Based AuthN | Video & Screenshots Included | This lab automates the JML lifecycle between Active Directory and Okta using RSA-signed JWTs for secure API communication. | AD · Okta PowerShell · OAuth 2.0 · RSA · JWT | |
| Entra ID & AD Configuration | Screenshots Only | In this project I configure a hybrid environment from scratch and create Operational Runbooks for common issues. This includes CA Policies, 3 Applications 2 different AuthN Protocols(OIDC + PKCE and SAML 2.0). I also do implementation testing with Microsoft Graph API, decoding SAML assertions to resolve issues, decoding JWTs to annotates ID/Access tokens, and testing CA enforcement. | Active Directory · Entra ID · Entra Connect · Conditional Access · MFA | |
| SSO & SCIM Automation: SaaS Pro/Deprovisioning | We'll be integrating SaaS applications with SSO and automates user provisioning and deprovisioning to maintain consistent identity lifecycle across systems. | Entra ID · Okta · SAML · OIDC · SCIM | In Progress | |
| Access Reviews: Certification and Audit Workflow | Here I Simulate periodic access reviews where permissions are approved or revoked, with audit logs generated for compliance and governance. | Entra ID · Access Reviews · Audit Logs · CSV | ||
| Privileged Access: Just-in-time Role Elevation (PIM) | Now I implement a workflow for requesting and granting temporary elevated access with approval and automatic expiration. | Entra ID · PIM · Approval Workflow · JIT | ||
| Identity Monitoring: Risky Sign-Ins and Incident Response | Finally I'll be Detecting and investigating suspicious login activity using identity logs and automated response mechanisms. | Entra ID · Sign-In Logs · Sentinel · KQL |
Focus area: Managing identity across hybrid environments. Bridging on-premises Active Directory and cloud platforms like Okta and Microsoft Entra ID. Projects cover the full IAM lifecycle: provisioning, access reviews, privileged access, and offboarding, with PowerShell automation at each stage to reduce manual effort and enforce consistent policy at scale.
| Project | Notes |
|---|---|
| Prerequisites & Installation | ▶ Video included |
| Post-Installation Configuration | ▶ Video included |
| Ticket Lifecycle & SLAs | ▶ Video included |
| Project | Notes |
|---|---|
| Configuring On-Premises Active Directory within Azure VMs | ▶ Video included |
| Network Security Groups (NSGs) & Network Protocol Analysis | Wireshark |
| Basic DNS Configuration & Testing | Azure |
| Project | Focus |
|---|---|
| Internal Security Audit — Botium Toys | Risk assessment · audit evidence · mitigation |
| Python Algorithm — User Access Management | Scripted RBAC logic |
| SQL Security Investigation — Login & Machine Access Patterns | Threat analysis · access logs |
| Linux — Enforcing Least Privilege via File Permissions | Hardening · principle of least privilege |
Earned
In Progress
Queued